# DoD Suspends CMMC Third-Party Assessments

The Department of Defense has paused the expansion of third-party cybersecurity assessments under CMMC Phase Two, continuing to require contractors handling controlled unclassified information (CUI) to perform self-assessments for compliance. This decision maintains the current self-attestation framework, which carries inherent risks under the False Claims Act (FCA) if contractors misrepresent their cybersecurity posture. Procurement professionals and contractors should prioritize robust internal controls, continuous monitoring, and independent validation to mitigate FCA exposure and ensure accurate compliance documentation.

- **Why this matters:** Contractors must maintain thorough and current cybersecurity evidence to support self-attestation and avoid FCA liability.
- The DoD's suspension delays mandatory third-party assessments, preserving the self-assessment model for now.
- Organizations should enhance internal audits and validation processes to reduce risks associated with self-attestation.
- Legal and compliance teams need to be aware of FCA implications tied to cybersecurity claims in DoD contracts.

**Jurisdictions:** federal
**Industries:** Defense & Military
**Topics:** Cybersecurity
**Published:** September 22, 2026

### Government Entities
- Department of Defense (DoD)
- Justice Department
- Navy

### Vendors
- MORSECORP Inc. (alleged violator of FCA due to cybersecurity compliance misrepresentation)

### Key Quotes
> The hidden FCA trap in CMMC self-attestation emerges when there is a gap between what an enterprise reports and what it can demonstrate.
> — Dylan Berger, Digital Content Consultant

### Sources
- [
        Navigating the hidden False Claims Act trap in CMMC self-attestation | Federal News Network](https://federalnewsnetwork.com/commentary/2026/09/navigating-the-hidden-false-claims-act-trap-in-cmmc-self-attestation) - Federal News Network