Since the July 13 pause, most of the CMMC conversation has centered on assessor capacity — too few C3PAOs, too much demand. But two pieces of new reporting this month complicate that story. Federal News Network reported on August 19 that DoD’s own inconsistent CUI marking practices are a root cause of program dysfunction: officials either slap default CUI labels on everything or leave genuinely sensitive data unmarked, leaving contractors to guess. The SBA’s Office of Advocacy called this the “most frequently cited concern” among small businesses responding to the Reform Task Force’s RFI.
That guessing game has real costs. When contractors can’t tell what actually qualifies as CUI, most default to protecting everything — which pulls unrelated systems into audit scope and inflates compliance spend. Primes compound it by imposing blanket Level 2 requirements on subcontractors who may not handle CUI at all.
A separate report from assessor Sentinel Blue, published August 11 after interviews with five C3PAOs, backs this up from the other side of the table: assessors say they’ve been turning away prospective clients not because their calendars are full, but because those companies simply weren’t ready — undone by cost, complexity, and confusion about scope, not scheduling.
NIST 800-171 Rev. 3 just got a real regulatory vehicle
Last week we flagged the FAR Council’s move to upgrade the government-wide CUI baseline to NIST SP 800-171 Revision 3. Now DoD’s own side of the house is catching up: the Department has scheduled an interim final rule amending the CMMC Program itself (32 CFR Part 170) to formally transition assessments from Revision 2 to Revision 3. DoD estimates the re-scoped baseline will shrink the population of contractors subject to CMMC by roughly 20% — a re-scoping of applicability, not a loosening of security obligations for those still in scope.
- Aug 14, 2026Reform Task Force RFI closed — comment period for “Reforming CMMC and Reducing Compliance Burden” wrapped.
- Aug 2026 (targeted)DFARS clause update expected as a Notice of Proposed Rulemaking, laying groundwork for the Rev. 2 → Rev. 3 shift.
- Sep 2026 (targeted)A separate federal rule on cyber threat and incident reporting is aimed at finalization.
- Mid-Sep 2026 (expected)CMMC Reform Task Force recommendations due to the DoW CIO — still the single most important date on the calendar.
- Mid-Oct 2026 (earliest)Formal determinations on program changes — actual rule text, not just a memo.
CMMC is paused. False Claims Act enforcement is not.
It’s tempting to read the CMMC pause as a signal to relax. The Department of Justice’s enforcement numbers argue the opposite. Cybersecurity-related False Claims Act settlements hit a record in FY2025 — and DOJ has been explicit that these cases are “not about data breaches” but about misrepresentation. A company doesn’t need to be hacked to face liability; it just needs to have claimed a compliance posture it didn’t actually have.
The pattern is already continuing into FY2026: in June, Alabama logistics contractor LOGZONE settled for $507,144 after a DIBCAC review found its self-reported SPRS score of a perfect 110 was, in reality, -171. That’s the exposure a paused certification program does nothing to change — your SPRS affirmation is still a legal representation the government can and does test.
| Metric | Prior years | FY2025 |
|---|---|---|
| Cyber-related FCA settlements | 2–3 per year (avg.) | 9 |
| Cyber-related FCA recoveries | ~$15–17M per year | $52M+ |
| Whistleblower (qui tam) filings | Elevated | 1,297 — highest on record |
| Basis for liability | Often tied to an incident | Misrepresentation alone, no breach required |
What to do this week
The theme this issue: precision. Vague CUI scope and a stale SPRS score are now your two biggest liabilities.
- Get your CUI inventory in writing. If a prime hands you a blanket Level 2 flow-down requirement, ask them to specify exactly which CUI categories apply to your scope of work.
- Re-check your SPRS score against reality. LOGZONE’s gap between claimed and actual score is exactly the kind of discrepancy DIBCAC reviews — and DOJ — are now built to catch.
- Start reading for Rev. 3. Ahead of the DFARS NPRM expected this month, the control changes are real, independent of whatever the Reform Task Force ultimately recommends.
- Circle mid-September. Task Force recommendations are still the single biggest fork in the road for this program — we’ll break down what they mean for you the week they drop.
Quick hits
- Aug 11, 2026Assessors push back on the capacity narrative.Sentinel Blue’s report, based on interviews with five C3PAOs, says cost and readiness — not scheduling — are turning away the most prospective clients.
- Jun 18, 2026LOGZONE settles for $507,144.Navy logistics contractor’s claimed SPRS score of 110 didn’t match DIBCAC’s finding of -171 — restitution made up roughly half the settlement.
- OngoingEarly-certified contractors still in limbo.DoD has not issued formal guidance on whether Phase 2 certifications completed before the July pause are grandfathered, voided, or something in between. Still no word — we’re watching.
Not sure where your organization stands?
CUI Vault gives you a live, always-audit-ready picture of your CUI environment and NIST 800-171 posture — so headlines like today’s are a footnote, not a fire drill. Reach out to your NtelSec team to talk through your current gaps.
