Cybersecurity protects your systems. Cybersecurity risk management protects your business.®

The Information Highway

The Information Highway

Font size: +
5 minutes reading time (1066 words)

CMMC Audits Are Paused: Here's Why Your Compliance Risk Just Went Up, Not Down

The Pentagon just paused third-party CMMC audits and made it permanent policy, but a $507,000 settlement from June shows that "paused" doesn't mean "off the hook," and the lesson applies well beyond defense contracting.
Cybersecurity Maturity Model Certification Level 2

If you sell to the Department of Defense, or you're one of the thousands of small and mid-sized businesses sitting somewhere in a defense prime's supply chain, you may have heard the news and breathed a sigh of relief: the Pentagon has paused third-party CMMC (Cybersecurity Maturity Model Certification) audits. No more scrambling to book a C3PAO. No more five-figure assessment invoices. Problem solved, right?

Not quite. And the details of how this happened are worth understanding, because they say something important about where compliance risk is headed for every regulated small business, not just defense contractors.

 What actually changed

On September 3, 2026, the Department of Defense's Office of Defense Pricing and Contracting issued a formal class deviation instructing contracting officers to strip CMMC third-party assessment requirements out of contracts. This wasn't a quiet, temporary pause it was a binding regulatory action, which makes it considerably harder to reverse than the informal "policy review" language coming out of the Pentagon over the summer suggested.

The move follows a 60-day review of the CMMC program that DoD launched in mid-July, which drew more than 1,100 public comments many from small businesses warning that the cost and complexity of third-party certification was becoming a barrier to competing for federal work at all. A CMMC Reform Task Force wrapped up its review this week, and DoD's CIO has said her office will decide when, or if, its recommendations become public.

So, for now: no independent audits. That's the headline. Here's the part that should actually get your attention.

Self-attestation didn't go away and it just got riskier

Pausing third-party assessments doesn't pause the underlying requirement. Contractors handling controlled unclassified information still have to self-certify their compliance with NIST 800-171, the security standard CMMC was built to verify. In some ways, removing the independent check makes the self-attestation itself matter more, not less because it's now the primary thing regulators and prosecutors have to go on.

That's not a hypothetical concern. In June, an Alabama-based defense contractor agreed to pay $507,144 to settle Department of Justice allegations that it had submitted a false cybersecurity score into the government's contractor scoring system. The company had reported a near-perfect self-assessment score; a subsequent DoD audit found the real picture was dramatically worse. The case was brought under the False Claims Act the same statute the DOJ has been using more aggressively across its Civil Cyber-Fraud Initiative to pursue contractors who misrepresent their security posture to win or keep federal business.

Put those two developments side by side and the message for any business touching federal contracts is blunt: the paperwork you file about your own cybersecurity may now carry more legal exposure than an outside audit ever did, because there's no third party left to catch an honest mistake before it becomes a false claim.

U.S. Department Of Defense

 Why this matters even if you've never touched a DoD contract

This story is about CMMC specifically, but the underlying dynamic isn't unique to defense contracting, and that's the real reason SMB leaders in every regulated industry should be paying attention.

Across healthcare (HIPAA), education (FERPA), and general data protection (state breach-notification laws, the FTC Safeguards Rule), the pattern is the same: regulators increasingly rely on organizations to self-report their compliance posture, and enforcement shows up later, after an incident or a whistleblower complaint, when it's far more expensive to fix. A thin or aspirational self-assessment the kind built from a template nobody has revisited in two years is a liability sitting quietly on the books until it isn't.

For a small or mid-sized business, that risk is compounded by a resource gap. Larger organizations can absorb the cost of a dedicated compliance function that keeps documentation current and defensible. Most SMBs can't, which is exactly why third-party frameworks like CMMC existed in the first place and exactly why removing that external check matters more for smaller companies than larger ones.

What SMBs should actually do right now

A few practical takeaways, regardless of whether CMMC applies to your business directly:

If you hold DoD contracts or subcontracts involving controlled unclassified information, don't treat the assessment pause as a reason to deprioritize NIST 800-171 work. Your self-attestation is now doing more legal heavy lifting, not less, and DoD has made clear the requirement itself hasn't moved.

If you're not sure whether your last self-assessment reflects your actual environment, that's worth fixing before it's tested by an audit, an incident, or a competitor's protest not after. Score inflation, even unintentional, is the exact pattern the DOJ pursued in the Logzone case.

If compliance obligations in your industry HIPAA, FERPA, state privacy law, cyber insurance attestations rely on your own representations rather than a third-party check, treat this as a reminder to have someone independent validate what you're telling regulators, auditors, and insurers about your security posture.

And if you're working with an outside IT or security partner, ask directly whether your current documentation would hold up if someone else's audit a client's, an insurer's, or a federal investigators pulled it apart.

The Bottom Line

A regulatory pause can look like relief. Often, it's actually a signal that responsibility has shifted rather than disappeared from an external auditor's judgment to your own paperwork, and from a compliance cost to a legal one. For SMBs navigating CMMC, HIPAA, FERPA, or any framework built on self-reported security, the safest move this month is the same as it would have been under stricter rules: know exactly what your compliance documentation says and make sure it's actually true.  

Related Resources

Cybersecurity Threat Advisory 31-26: SonicWall ze...
22,000 Exchange Servers Are Still Exposed to a Liv...

Related Posts

Top Breaches Cost ($) of 2024

HEALTHCARE
FINANCIAL
INDUSTRIAL
TECHNOLOGY
ENERGY
Source: IBM Cost of a Data Breach Report 2024