CMMC Affirmation and the False Claims Act: The Pause Left One Signature Holding All the Risk
The July 13 suspension took the third-party assessor out of the picture. It did not touch the annual affirmation, the SPRS score behind it, or the False Claims Act enforcement machine that ran up record numbers last year. For most contractors, that leaves exactly one compliance statement flowing to the Department of Defense, and one person’s name on it.
A CMMC affirmation carries False Claims Act exposure because it is a signed federal attestation, submitted in the Supplier Performance Risk System (SPRS) under 32 CFR 170.22, that your organization has implemented and will maintain all applicable CMMC security requirements. When that statement does not match reality, the Department of Justice does not need a breach to act. Its cyber fraud cases are built on the misrepresentation itself, and in fiscal year 2025 DOJ recovered more than $52 million across nine such settlements, with recoveries more than tripling in each of the past two years.
- The July 13, 2026 suspension paused Phase 2 C3PAO certification requirements and all later rollout milestones. It did not pause the annual affirmation under 32 CFR 170.22, SPRS score obligations under DFARS 252.204-7019/-7020, or False Claims Act liability under 31 U.S.C. 3729.
- DOJ recovered over $52 million across nine cybersecurity False Claims Act settlements in FY2025, and its top FCA official has said these cases are "premised on misrepresentations," not on data breaches.
- The MORSECORP settlement ($4.6 million, March 2025) was triggered by the company's own Head of Security, who filed the whistleblower complaint and received $851,000. The first assessor to compare your affirmation against reality is usually already on your payroll.
- Field data from assessment calendars after the pause shows contractors converting official assessments to mock assessments and others moving up into vacated slots, while some C3PAOs report cancellations and layoffs. The market is splitting into contractors who treat this as a pause and contractors who treat it as a pass.
- Before your next affirmation cycle: reconcile your SPRS score against your current SSP, close the gap between what is written and what is implemented, and document the basis for every point claimed.
What July 13 removed, and what it left running
On July 13, 2026, the Department of Defense suspended CMMC Phase 2, which had been scheduled to make third-party (C3PAO) Level 2 certification a condition of award for contracts involving Controlled Unclassified Information starting November 10, 2026. The suspension also froze Phases 3 and 4 and all future implementation milestones. A CMMC Reform Task Force is reviewing the program and is expected to report to the DoD CIO in the mid-September timeframe. We covered the mechanics of the suspension in Is CMMC Still Required? What the Phase 2 Suspension Did and Did Not Change.
What the suspension did not touch is the part that matters for this article. Phase 1 remains in effect: solicitations involving FCI or CUI still carry Level 1 or Level 2 self-assessment requirements. DFARS 252.204-7012 still requires adequate security and 72-hour incident reporting. DFARS 252.204-7019 and -7020 still require a current NIST SP 800-171 assessment score in SPRS. And 32 CFR 170.22 still requires a named senior executive, the Affirming Official, to attest annually that the organization has implemented and will maintain implementation of all applicable CMMC security requirements.

Here is the structural change nobody planned: before July 13, a contractor heading toward Phase 2 could expect an independent assessor to eventually check their work. The C3PAO assessment functioned as a backstop, an external event that would surface gaps before the government relied on the contractor’s own statements indefinitely. The suspension removed that backstop for the foreseeable future. The affirmation was always legally binding. Now, for most of the Defense Industrial Base, it is also the only compliance verification DoD receives. The signature did not get riskier because the rules changed. It got riskier because everything that used to stand next to it was taken away.
The affirmation runs on its own clock
The affirmation requirement is short and specific. Under 32 CFR 170.22, the Affirming Official must affirm continuing compliance after every assessment, including POA&M closeout, and annually thereafter, with all affirmations entered electronically in SPRS. The requirement applies to primes and subcontractors alike, and it applies to self-assessed statuses, not just certified ones. If your organization has ever posted a Level 1 or Level 2 self-assessment, an affirmation clock is running, and the pause did not stop it.
The submission mechanics, the schedule, and the award consequences under DFARS 252.204-7021 are covered in CMMC Annual Affirmation Requirements. Who the Affirming Official is and why the signature carries personal exposure is covered in Who Signs Your CMMC Affirmation Is Personally on the Hook. What follows is about what changed in the six weeks since the pause: the enforcement environment that signature now sits in.
The enforcement side never paused
In January 2026, DOJ published its False Claims Act statistics for fiscal year 2025, a record year overall at more than $6.8 billion in recoveries. Inside that number: more than $52 million recovered across nine cybersecurity fraud settlements, with cyber settlement totals more than tripling in each of the past two years.
Two details in that release matter more than the headline figure.
First, the theory of the cases. DOJ’s top False Claims Act official, Deputy Assistant Attorney General Brenna Jenny, said in early 2026 that the department’s cyber fraud cases are “premised on misrepresentations.” Not on breaches. No incident has to occur, no data has to leave the building. The gap between what a contractor certified and what the contractor actually implemented is the entire case. In a self-assessment-only environment, every certification the government receives from you is one you wrote yourself.
Second, who brings the cases. Whistleblowers continue to drive cyber fraud enforcement, and the FCA pays them 15 to 30 percent of the government’s recovery. Which brings us to the settlement every Affirming Official should know by name.
The first assessor already works for you
In March 2025, MORSECORP Inc., a Cambridge, Massachusetts defense contractor, agreed to pay $4.6 million to resolve False Claims Act allegations tied to cybersecurity requirements in its Army and Air Force contracts. It was the first FCA settlement based on a contractor’s failure to reevaluate and promptly update its SPRS self-assessment score after a third-party assessment came in lower. A third-party score of 57 was not posted to SPRS until June 14, 2023; the score was later revised to 82 in October 2023 and 110 in May 2024.

The detail that should reorganize how you think about the pause: the whistleblower was MORSE’s own Head of Security and Facility Security Officer. He filed the qui tam complaint in January 2023 and received an $851,000 share of the settlement, 18.5 percent.
Run the economics from the inside. The person best positioned to compare your affirmation against your actual environment is not a C3PAO with a booked calendar slot. It is the employee who maintains your systems, reads your SSP, and knows exactly which controls are implemented on paper only. The False Claims Act gives that person a direct financial incentive, protected by anti-retaliation provisions, to report the gap. The suspension removed the assessor you would have hired. It did nothing to the assessors you already employ.
This is also why internal compliance complaints deserve careful, documented handling. An employee who raises a control gap and watches it get ignored is the opening scene of most of these cases.
What assessment calendars actually did after the pause
The trade press has covered the supply side: at AFCEA’s TechNet Augusta conference in mid-August, third-party assessment firms reported cancelled contracts and layoffs following the pause, and National Defense reported ongoing anxiety among small businesses about program costs. Assessor capacity, already thin, is contracting while the review plays out.
The demand side is harder to see, and it is where the field data gets interesting. Brent Gallo, a CISSP and Lead Assessor, described to me how assessment calendars he has visibility into actually moved in the weeks after July 13: one official assessment converted to a mock assessment, one cancelled outright, another contractor moved up into the vacated slot, and one C3PAO was still booking roughly ten assessment dates out through December.
Read those four data points together and the market splits cleanly in two. One group of contractors treats July 13 as a pass: cancel the assessment, stop the spend, wait for the Task Force to make it all go away. The other group treats it as a pause: convert the engagement to a mock assessment, keep the evidence work moving, or grab the calendar slot someone else abandoned. The second group is betting that the affirmation obligation, the SPRS score, and the FCA caseload continue regardless of what the September report recommends, because all three are running today. The first group is betting a 60-day review memo overrides a federal regulation. That is a bet, not a plan.
If the Task Force report lands in mid-September with the program intact in any form, the contractors who kept moving will be holding current evidence, defensible scores, and in some cases completed mock assessments, in a market with fewer assessors than it had in June. We flagged what small contractors should have told the Task Force in our RFI response breakdown; the report is the next trigger to watch.
What to do before your next affirmation
The work here is not new controls. It is closing the distance between what your organization has claimed and what it can prove.
Reconcile your SPRS score against your current SSP. MORSECORP’s exposure came from a score that no longer matched reality and was not promptly corrected. Pull your posted score, walk each claimed control against the System Security Plan, and correct SPRS if they disagree. A lower accurate score is defensible. A higher stale one is a misrepresentation with a date stamp. The NIST 800-171 SPRS Score Workbook for CMMC Level 2 ($87) walks the full 110-control scoring methodology, including the weighted deductions, so the number you post is one you can reconstruct under questioning.
Put evidence behind every point claimed. An affirmation attesting to “implemented and maintained” compliance is only as strong as the artifacts behind it. For each control marked implemented, know which document, configuration, or log proves it. The CMMC Level 2 Evidence Tracker for NIST 800-171 Audit ($67) maps evidence to assessment objectives so the proof exists before anyone asks.
Give your Affirming Official a real basis to sign. The signature should sit on top of a documented review, not an email from IT saying “we’re good.” A short internal memo summarizing the score reconciliation, open POA&M items, and evidence status, dated before each affirmation, is the difference between a defensible attestation and a bare one.
Handle internal compliance concerns like they are legal events. Log them, investigate them, document the resolution. The relator in the MORSECORP case was the person whose concerns went unresolved.
If you are starting from further back, with an affirmation cycle approaching and no organized scoping, scoring, or evidence structure behind it, the CMMC Level 2 Readiness Kit: 5 NIST 800-171 Tools ($147) bundles the SPRS workbook, SSP template, evidence tracker, scoping worksheet, and POA&M tracker into one working set, built for a small contractor doing this without a consultant.
The bottom line
The suspension changed who checks your work. It did not change what you certified, who signed it, or who profits from reporting the gap. Until the Task Force report says otherwise, the annual affirmation under 32 CFR 170.22 is the entire compliance statement DoD receives from a self-assessed contractor, the FCA enforcement apparatus behind it just posted its third straight record year, and the person most likely to test your affirmation against reality already has a badge to your building. The contractors converting to mock assessments understand exactly what they are protecting: not a certification, a signature.
Sources
- U.S. Department of Justice, “Defense Contractor MORSECORP Inc. Agrees to Pay $4.6 Million to Settle Cybersecurity Fraud Allegations,” press release, March 26, 2025
- U.S. Department of Justice, False Claims Act settlements and judgments statistics for fiscal year 2025, announced January 2026
- Remarks of Deputy Assistant Attorney General Brenna Jenny on FCA cyber enforcement, as reported by Akin Gump, February 2026
- 32 CFR 170.22 (Affirmation), eCFR, current edition
- DFARS 252.204-7012, -7019, -7020, -7021, acquisition.gov
- Department of Defense, CMMC Phase 2 suspension announcement, July 13, 2026
- National Defense Magazine, “Assessors Report Contract Cancellations, Layoffs After CMMC Pause,” August 17, 2026
- Federal News Network, CMMC Reform Task Force RFI coverage, August 2026
- Assessment calendar pattern attributed to Brent Gallo, CISSP, Lead Assessor, shared directly and referenced with permission
Get CMMC deadline updates
Plain-English alerts when CMMC requirements, scoring, or deadlines change. Sent only when something actually moves.