Home / Article
Did the CMMC Phase 2 Suspension Mean We Can Stop Doing 800-171?
Your CFO saw the CMMC pause headline and asked why the compliance budget is still there. This article gives you the answer, with sources you can forward.
What actually paused?
On July 13, 2026, the Department of War suspended CMMC Phase 2. CMMC is the Cybersecurity Maturity Model Certification. Phase 2 would have made third-party certification a condition of award starting November 10, 2026.
A policy memo alone does not change contracts. The binding step came on September 3, 2026. That day the department issued Revision 3 of Class Deviation 2026-O0025. John Tenaglia signed it. He is the principal director for defense pricing, contracting, and acquisition policy. The deviation directs contracting officers to remove third-party CMMC assessment requirements from solicitations and contracts (Washington Technology).
The pause covers the audit. It does not cover the rules. Level 1 and Level 2 self-assessments remain. NIST SP 800-171 Revision 2 stays the baseline (GovConFeed).
What never paused?
DFARS 252.204-7012 never paused. DFARS is the Defense Federal Acquisition Regulation Supplement. The clause requires adequate security for covered defense information. For covered contractor systems, that means implementing the NIST SP 800-171 controls (DFARS 252.204-7012).
The rest of the clause never paused either. Report cyber incidents to DoD rapidly. Post your 800-171 assessment score to SPRS. SPRS is the Supplier Performance Risk System. Affirm compliance every year with a senior official's signature. Flow the requirements down to your subcontractors.
The CMMC program rule itself is still law. It is codified at 32 CFR Part 170. The suspension froze the phase-in schedule. It did not repeal the rule.
Why does this matter more now?
Self-attestation is now the government's main view of your security posture. There is no third-party audit between your posted score and the government. That score is a claim. False claims get punished.
On September 1, 2026, the Department of Justice announced that Honeywell Aerospace agreed to pay $2,042,518. The allegations: a business unit failed to meet NIST SP 800-171 controls under a defense contract. The period ran from April 2020 through December 2023. The case started with a 2022 whistleblower suit filed by a former employee under the False Claims Act (Constantine LLP). No breach was alleged. The gap between the contract promise and the real controls was enough (Bass Berry and Sims).
Honeywell is the latest, not the first. A DOJ official recently testified that the Cyber-Fraud Initiative has produced 15 settlements. The total was more than $73.5 million over five years (LexBlog). Cases have surfaced through DCMA audits and whistleblowers alike.
Read the timing together. The audit paused. The enforcement did not. An unsupported SPRS score carries the same legal exposure it carried before July 13. There is just no auditor to catch the error first.
What should you do this week?
First, keep your 800-171 implementation current. The pause changed the audit, not the obligation. Close the gaps you already know about.
Second, recheck your posted SPRS score against your live systems. If the score is higher than your real controls, fix one of them this week. Either raise the controls or lower the score.
Third, confirm your annual affirmation is done. A senior official signs it. That signature is the claim the government sees.
Fourth, make sure your System Security Plan (SSP) matches reality. An SSP that describes controls you do not have is a liability, not a shield.
Fifth, collect proof you can recheck. Screenshots go stale the day after you take them. Evidence pulled from your live tenant stays current, and it reruns after every fix. PolicyCortex does this on Azure. 33 collectors read live configuration and check it against NIST 800-53 and 800-171. It re-verifies after each fix and builds the SSP, SAR, and POA&M documents from the evidence.
Sources
- DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting
- 32 CFR Part 170, Cybersecurity Maturity Model Certification (CMMC) Program
- Washington Technology: CMMC's Phase 2 suspension locked in with binding regulation
- GovConFeed: CMMC Class Deviation, what Rev 3 changed for contractors
- Constantine LLP: Honeywell Aerospace to pay over $2M to resolve whistleblower-initiated False Claims Act case
- Bass Berry and Sims: DOJ's $2 million Honeywell settlement under the Civil Cyber-Fraud Initiative
- LexBlog: DOJ Cyber-FCA settlements and DoW CMMC Phase II suspension
Next step
Worried your posted score would not survive a second look? See how PolicyCortex collects the proof from your Azure tenant.