News
Pentagon’s CMMC Pause Trades Audit Costs for Legal Risk
The Pentagon’s CMMC review team met this week, but the self-assessment scores it now favors are already driving costly False Claims Act settlements.
The Pentagon’s new CMMC Reform Task Force held its first meeting on July 16, four days after the Defense Department froze the third party cybersecurity audits it had spent five years building toward. Defense officials call the pause relief for small businesses drowning in compliance paperwork. But the tool they are now leaning on more heavily, the contractor self assessment, is the same one already fueling a run of costly False Claims Act settlements.
That tension sat underneath a factory floor tour in Sterling, Virginia, this week, where the department’s top technology official framed the review as a rescue mission for small manufacturers. Whether it also opens a bigger legal exposure for those same companies is the question nobody in the room fully answered.
A Factory Tour Kicks Off the Pentagon’s CMMC Review
Kirsten Davies, the Defense Department’s chief information officer, toured the factory floor at Kform, a small defense manufacturer in Sterling, Virginia, on July 16. She was joined by Kelly Loeffler, the Small Business Administrator, and Michael Duffey, the Under Secretary of Defense for Acquisition and Sustainment. Afterward, Davies told reporters the review team had met for the first time that same day.
The visit followed its July 13 suspension of Phase 2 audits, the third party assessments that were due to become mandatory for contracts touching controlled unclassified information starting November 10. Davies said small business considerations were central to that call and to the “top to bottom” review that followed.
“We took this action because data, including the reports from the Small Business Administration, makes one thing very clear: our planned compliance requirements progression was creating prohibitive costs and unacceptable burdens to the defense industrial base,” Davies said.
The Pentagon has published a request for information and plans listening sessions around the country, seeking input “especially the small businesses, and from the cybersecurity operators and executives who serve your companies,” Davies said. The review team has 60 days to gather feedback, then 15 more to hand Davies and Duffey a report, a timeline that points to late September. Davies said she hopes to make the findings public soon after.
She did not commit to any outcome. “It could include everything from an overhaul to small tweaks here and there,” she said, adding that the department will not pursue “death by a thousand cuts” or change for its own sake. Under the current framework, contractors handling covered unclassified information must meet standards defined in clauses like DFARS 252.204-7021, which still requires an annual affirmation of compliance even without a third party audit behind it.
The Cost Fight, by the Numbers
Pentagon officials have been blunt about why they hit pause. Davies called the third party assessment model “burdensome, red tape ridden, check the box” and pointed to a “severe shortage of third party assessors.” Loeffler went further, saying compliance costs “exceeding half a million dollars” were pushing small firms out of defense work entirely.
Eric Crusius, a partner and government contracts practice chair at Hunton Andrews Kurth, pushed back on that framing. He said many people conflate the cost of actually implementing required cybersecurity controls with the cost of getting certified, and pointed to the Pentagon’s own estimate that a Level 2 third party assessment runs about $105,000. He also said the assessor market has kept pace better than critics suggest, with more completed audits than the rulemaking anticipated.
The numbers behind the fight are scattered across different metrics, which is part of why the debate keeps talking past itself.
| Metric | Figure |
|---|---|
| Request for information deadline | August 14, 2026 |
| Task force report expected | Late September 2026 |
| Individually certified third party assessors | Just over 1,000; Cyber AB has said the program needs 2,000 to 3,000 |
| Authorized assessment organizations (C3PAOs) | Roughly 100 |
| Contractors certified at CMMC Level 2 | Nearly 2,000 |
| DoD’s own cost estimate for one Level 2 audit | About $105,000 |
A separate legal analysis of the suspension reported that Small Business Administration data cited by DoD’s CIO put future compliance costs above $7 billion annually for small and midsize contractors industry wide, against an assessor pool that today covers roughly 100 authorized firms for a base of well over 100,000 companies that may eventually need some form of assessment.
Self-Assessment’s Return Reopens a Legal Trapdoor
Here is the part the cost debate skips past. With third party audits suspended, DoD is leaning almost entirely on the scores contractors give themselves, the same self attestation model the department has spent years trying to move away from because the Justice Department keeps finding it wrong.
A Score of 110 Meets a Score of Negative 170
In October 2021, LOGZONE Inc., a logistics contractor in Huntsville, Alabama, reported a perfect self assessment score of 110 on its NIST SP 800-171 controls. A government assessment by the Defense Contract Management Agency in February 2024 put the same systems at negative 170, near the bottom of the scoring range. The Justice Department announced in June 2026 that LOGZONE would pay $507,144 to resolve the resulting False Claims Act case, a settlement that did not even originate from a whistleblower tip, but from the government’s own audit process.
It is not an isolated case. In September 2025, Georgia Tech Research Corporation agreed to pay $875,000 after the government alleged its cybersecurity score rested on a campus wide system that did not actually exist. Raytheon and its former cyber unit Nightwing Group paid $8.4 million in a settlement over an internal system that skipped required controls, and Verizon Business Network Services paid just over $4 million in a similar case. Under the Justice Department’s Civil Cyber-Fraud Initiative, cybersecurity related recoveries have kept climbing, not falling.
| Contractor | Settlement | Alleged Trigger |
|---|---|---|
| LOGZONE Inc. | $507,144 (June 2026) | Self score of 110 versus a government score of negative 170 |
| Georgia Tech Research Corp. | $875,000 (September 2025) | Score based on a nonexistent campus wide system |
| Raytheon / Nightwing Group | $8.4 million (July 2025) | Uncontrolled internal development system |
| Verizon Business Network Services | $4,091,317 | Incomplete controls on a federal IT contract |
Kate Growley, a partner at the law firm Crowell & Moring, said the shift back toward self certification carries a specific kind of exposure.
Any time where you are relying on your own assessment and representation instead of one of an accredited third party, which the DoD has stood up an entire ecosystem to create assurances around the evaluation and the reliability of that third party, that will create FCA risk for contractors who are misrepresenting what that score should be because they are relying on the self-assessment methodology.
Growley made that comment to Federal News Network. Her firm has separately noted that the Justice Department remains active on this front and could expand its focus to inaccurate Phase 1 self scores as the review plays out.
Why Was CMMC Created in the First Place?
CMMC exists because self attestation already failed once. DoD began building the program in 2019, during the first Trump administration, after inspector general audits found contractors were falsely claiming to meet existing cybersecurity rules.
A 2020 federal rulemaking pointed directly to that failure, citing findings from DoD Inspector General report DODIG-2019-105, which concluded that contractors did not consistently implement required security measures for protecting sensitive unclassified information. Crusius put it simply: “The rulemaking is largely based on the fact that the self attestations were not working, and proof of that were the significant cybersecurity incidents that the department has been a victim of through various nation state actors.”
The Biden administration ran its own CMMC review five years ago, also driven by small business cost complaints, and the result was a simplified version the department branded CMMC 2.0. DoD finalized that rule in 2024 and the matching contract clauses last year. Now a third review, under Defense Secretary Pete Hegseth’s Acquisition Transformation System push, which some department communications refer to under the newer Department of War branding, is asking many of the same questions again.
Not everyone inside the CMMC ecosystem sees the same problem.
- DoD leadership calls the current model a bureaucratic drag; Davies described it as a “burdensome, red tape ridden, check the box” snapshot of a company’s defenses.
- The Cyber AB, the nonprofit that oversees the assessor network, disagrees. Chief executive Matthew Travis said in a statement that his organization is “both surprised and disappointed in yet another momentary pause,” and argued third party verification will “prove itself indispensable under a rigorous review.”
- Government contracts lawyers like Growley warn that leaning harder on self scores, without the third party check DoD built specifically because self scoring failed before, invites the same enforcement risk the department was trying to escape.
The Cyber Accreditation Body, known as the Cyber AB, says nearly 2,000 contractors have already reached Level 2 certification, work that companies and assessors will not get refunded if the model changes again.
What Comes Next for Small Contractors
Nothing about the suspension erases a contractor’s underlying obligations. Several things remain firmly in place while the task force works.
- Level 1 and Level 2 self-assessments, which contractors must still submit and affirm annually.
- NIST cybersecurity controls for protecting controlled unclassified information, unchanged by the pause.
- Government-led reviews through the Defense Industrial Base Cybersecurity Assessment Center, which can still show up at a contractor’s door regardless of the review’s outcome.
- Support services through the National Security Agency’s Cybersecurity Director and DoD’s Cyber Crime Center, though Davies acknowledged those cover only a small slice of the required controls.
Duffey has already directed program officers to strip third party certification requirements out of active solicitations. Sandeep Kathuria, a partner at the law firm Saul Ewing, said that if the review recommends a bigger overhaul, the department has fast tools available. “We have seen in many areas that this administration can move very quickly to make regulatory changes,” Kathuria said, pointing to class deviations and interim rules as ways to act before a full rulemaking.
Justice Department enforcement is not waiting for that outcome. Cybersecurity related False Claims Act recoveries topped $52 million across nine settlements in fiscal year 2025, more than triple the total from two years earlier, and a new DOJ fraud enforcement division stood up in January adds another layer of scrutiny aimed squarely at the scores contractors file themselves. The listening sessions Davies promised will tell DoD what small businesses want. The DIBCAC inspectors and DOJ trial attorneys will keep working from what contractors actually submit.
Frequently Asked Questions
What is the Cybersecurity Maturity Model Certification?
CMMC is a Pentagon framework for verifying that defense contractors protect sensitive government data. Level 1 covers 15 basic safeguards for federal contract information. Level 2 requires meeting 110 NIST SP 800-171 controls for controlled unclassified information. Level 3 adds 17 more advanced controls, assessed directly by government reviewers rather than contractors themselves.
Is CMMC canceled?
No. DoD suspended the Phase 2 requirement for third party audits and froze later phases, but it has not repealed the CMMC program rule or the underlying DFARS clauses. Contractors still must protect covered data under DFARS 252.204-7012 and submit Level 1 and Level 2 self-assessments.
What is a C3PAO?
A C3PAO is a CMMC Third-Party Assessment Organization, a firm authorized to conduct independent Level 2 audits. Roughly 100 of these organizations are currently authorized, employing the pool of just over 1,000 individually certified assessors who perform the on-site reviews.
How can a contractor weigh in before the review ends?
Contractors can submit written comments to DoD’s request for information by August 14, 2026, or attend one of the listening sessions the department is holding around the country for small businesses, cybersecurity operators, and assessors.
Does a self-assessment carry legal risk?
Yes. A false or inflated self-assessment score can trigger False Claims Act liability, which carries treble damages. The LOGZONE case shows that risk is not limited to whistleblower tips; that settlement began with a routine government audit that contradicted the company’s own reported score.
-
TECHNOLOGY3 years agoHow to Adjust a Bulova Watch Band – An Easy Guide
-
News3 years agoFred Pentland: Athletic Bilbao’s English mentor who changed the essence of Spanish football
-
FINANCE3 years agoTax Planning for Every Season: Guide to Maximizing Your Tax Benefits
-
Education3 years agoAfrican Ministers New Education Plan
-
BUSINESS3 years agoWhat is Entrepreneurial Operating System? A Comprehensive Guide to EOS
-
Education3 years agoInnovate Your Learning Journey with Technology and Enhance Education
-
News3 years agoRussians formally out of World Athletics Championships
-
BUSINESS3 years agoTop 9 Most Expensive American Cities to Rent an Apartment
