Cybersecurity Maturity Model Certification (CMMC) self-attestation can create False Claims Act (FCA) exposure when annual compliance affirmations lack supporting evidence.
Understanding how to support self-attestation may help contractors reduce risk and maintain confidence in their compliance posture.
The hidden risk in CMMC self-attestation
As CMMC requirements continue rolling out across the defense industrial base (DIB), contractors are facing a significant change in the program’s implementation timeline. The Defense Department on July 13, 2026, putting the planned Nov. 10 expansion of third-party assessments on hold effectively immediately while the department conducts a 60-day review of the program. Phase One requirements, including applicable self-assessments, remain in force. Phase Two was scheduled to expand mandatory certified third-party assessor organization (C3PAO) assessments across a broader range of contracts beginning Nov. 10, 2026, but DoD has now suspended those requirements until further notice.
For most defense contractors, Level 2 certification is the primary requirement because it applies to entities that handle controlled unclassified information (CUI) and requires implementing all 110 security requirements in National Institute of Standards and Technology Special Publication 800-171 Rev. 2. However, DoD’s July suspension means the broader rollout of third-party assessments is currently on hold. During the suspension, DoD says it and select...
Read Full Story:
https://news.google.com/rss/articles/CBMiuwFBVV95cUxNaGxUTExMX3p4ekE0MV9xM1RX...