When CMMC Phase II certification paused, a lot of defense contractors understandably read that as license to pause their compliance work too. That’s a reasonable reaction to a confusing announcement, but it misreads what actually happened. The certification requirement paused. The underlying obligation, DFARS 7012, which has required compliance with NIST SP 800-171’s 110 security controls for years, did not.
What DFARS 7012 Requires
DFARS 7012 is the Defense Federal Acquisition Regulation Supplement clause requiring contractors handling Controlled Unclassified Information to implement NIST SP 800-171’s 110 security controls and report their compliance status through the Supplier Performance Risk System, or SPRS. It also requires reporting a cyber incident to the Department of Defense within 72 hours of discovery. The clause has been standard in applicable defense contracts since 2017, well before CMMC existed as a concept, and it doesn’t reference CMMC certification as a prerequisite for compliance. A contractor can be fully out of compliance with DFARS 7012 while CMMC certification is paused for everyone; the pause doesn’t create a grace period.
What the Pause Paused
CMMC Phase II, the formal third-party certification requirement layered on top of DFARS 7012, is currently on hold for a portion of the contractor base. That pause affects the certification mechanism: the third-party assessment process that was meant to verify compliance independently. It does not touch the underlying self-attestation requirement, the SPRS scoring obligation, or DOJ’s authority to pursue a contractor whose reported compliance doesn’t match reality.
What It Didn’t Pause
That distinction matters because DFARS 7012 is what’s actually enforceable right now, and DOJ has been active this year settling False Claims Act cases against contractors whose self-reported SPRS scores didn’t match their real security posture, with penalties ranging from the mid six figures into the millions. None of those cases required a failed CMMC certification. They came from the same underlying NIST SP 800-171 gap CMMC was designed to catch, found a different way: a DIBCAC review, a whistleblower complaint, or a routine audit that asked a question the paperwork couldn’t answer.
A DIBCAC review is the mechanism most likely to surface that gap directly. It’s a pass/fail comparison between a contractor’s actual practices and what’s already been self-reported in SPRS, and a mismatch isn’t treated as a paperwork error, it’s the basis for a referral. A perfect self-reported score is one of the more common triggers for a closer look, precisely because reviewers know how rarely a genuinely perfect score reflects reality across all 110 controls.
Why This Is Easy to Let Slide
Nobody has to have done anything wrong for this gap to open up. A program that was accurate two contract renewals ago, built by a team that has since moved on or gotten busy with other priorities, drifts quietly out of alignment with the environment it describes, and a certification pause that reads like permission to deprioritize the work makes that drift easy to miss. The organizations that get caught off guard by a review are rarely the ones with an obviously broken program. They’re the ones whose program was accurate once and simply never got revisited on a schedule.
Three Questions Worth Asking Your Program Right Now
- Is your current SPRS score based on a real, recent assessment, or an estimate carried forward from a prior year?
- Does your Plan of Action and Milestones have a named owner and a real date on every open item, or are some effectively parked?
- If a DIBCAC reviewer asked for the evidence behind any one of your 110 controls tomorrow, could you produce it without a scramble?
None of this means restarting a certification push that’s paused for good reason. It means the documentation and readiness work behind that certification, the gap analysis, the System Security Plan, the POA&M, the pre-assessment review, is worth doing on its own terms. That work doesn’t expire when a certification timeline does, and it’s the actual thing a reviewer checks.
Common Questions About DFARS 7012 and the CMMC Pause
Does the CMMC pause mean DFARS 7012 compliance is optional right now? No. DFARS 7012 is a separate, self-attested contractual requirement that has applied since 2017. The CMMC pause affects third-party certification, not the underlying obligation to meet NIST SP 800-171 and report accurately in SPRS.
What triggers a DIBCAC review? DIBCAC reviews can be triggered by a contracting officer request, a routine audit cycle, a whistleblower complaint, or, in some cases, simply by a self-reported score that looks inconsistent with a contractor’s size or history.
What happens if my SPRS score doesn’t match my actual posture? A mismatch discovered through a DIBCAC review or an audit can form the basis of a False Claims Act referral, since submitting an inaccurate compliance score to the government is treated as a false statement, independent of intent.
Do I need an RPO if I’m not pursuing CMMC certification right now? Readiness work, gap analysis, documentation, and pre-assessment review, applies to your DFARS 7012 posture regardless of certification timing. An RPO engagement doesn’t require an active certification push to be worthwhile.
Contact us to schedule a scoping call, or read the full guide below for a practical framework covering every stage of DFARS 7012 readiness.

