Skip to content

Defense industrial base

Nobody is coming to check your SPRS score. That is the problem.

On 13 July 2026 the Department of War suspended CMMC Phase II, pausing the third-party C3PAO assessments that were due to start appearing in contracts on 10 November 2026. The stated reason was arithmetic: over 100,000 companies in the defense industrial base, roughly 100 accredited assessors.

Your obligations did not pause. DFARS 252.204-7012 still applies, the 110 controls of NIST SP 800-171 are still mandatory, and you still submit a self-assessed score to SPRS. What changed is that nobody external verifies that score any more, and the Department of Justice has been prosecuting contractors whose scores were wrong.

Exposure

A self-attestation is a certification to the federal government.

The DOJ Civil Cyber-Fraud Initiative treats an inaccurate SPRS score as a false claim. These cases are not about breaches. They are about misrepresentation, and they are brought under the False Claims Act, which carries treble damages and lets a whistleblower file on your behalf.

$52M

Recovered across nine cybersecurity False Claims Act settlements in the fiscal year ending September 2025, announced January 2026.

$4.6M

MORSECORP settlement. The company had submitted a self-assessed SPRS score of 104. An actual consultant assessment put it at −142.

$507K

LOGZONE Inc., Huntsville AL, June 2026, the first publicly reported settlement of this fiscal year. Enforcement is described by DOJ as on a significant upward trajectory.

Service

Validate the score before you attest to it.

Independent technical testing against the controls you are claiming, so the number you submit is one you can defend.

  • Scope and boundary review

    Where CUI actually lives, which systems are inside the assessment boundary, and where the boundary leaks. Scoping errors are the most expensive mistake in a CMMC programme and they are usually found late.

  • Technical validation of claimed controls

    The difference between a control being configured and a control working. Testing what an attacker reaches, not what the documentation says they should not.

  • SPRS score review

    Your self-assessed score against what the testing actually shows, with the delta itemised per control so you can correct it before submission rather than explain it afterwards.

  • Practice-to-evidence mapping

    Findings mapped to the NIST SP 800-171 practices, so the report works as evidence rather than needing translation.

  • Attestation letter

    A signed letter naming the practitioner, credentials, scope, dates and methodology. An independent record that you did more than score yourself.

  • Remediation retest

    One round included. You fix, Zero Harbor Security verifies, the report is reissued.

CMMC readiness pentest

from $18,000

Independent testing against the NIST SP 800-171 practices you self-assess, so the SPRS score you affirm is one you can defend. Mapped practice by practice, with an attestation letter.

  • Scope and boundary review
  • CUI enclave testing
  • Practice-to-evidence mapping
  • Attestation letter

Typical duration · 7–8 days

Priced for a single CUI enclave in one environment. Multiple sites, several enclaves or a large estate scope higher. You get that number before you commit, not after.

Scope a validation

Status

Where the programme stands.

Reviewed 15 September 2026. The programme is under active review, so the date matters.

  • In effect

    DFARS 252.204-7012. NIST SP 800-171 Rev 2, all 110 controls. CMMC Level 1 and Level 2 self-assessment, annual affirmation and SPRS score submission. Flow-down from primes to subcontractors. Select government-led assessments continue, and existing contracts keep a Level 2 (C3PAO) requirement until the contracting officer modifies it out.

  • Suspended

    Mandatory third-party C3PAO assessment (Phase II), previously due 10 November 2026, and the phased rollout after it. New solicitations may not require Level 2 (C3PAO) or Level 3 (DIBCAC) assessments, and no waivers are granted during the review.

  • Under review

    On 13 July 2026 the Department of War CIO began a 60-day review of the programme, which drew more than 1,100 industry responses. As of 15 September 2026, no recommendations had been published, and what replaces Phase II, and when, had not been announced.

Fit

Whether this is for you.

A good fit

  • You handle CUI and submit an SPRS score
  • Your score was self-assessed and never independently checked
  • Between roughly 10 and 200 people, with no internal security team
  • A prime has flowed requirements down to you
  • You are being acquired, or acquiring: self-attestation is now diligence

Not a fit

  • You need a C3PAO certification: that is not what this is
  • You want your SSP and POA&M written from scratch
  • You need managed detection, monitoring or a SOC
  • You want the whole programme run for you end to end
  • You need it inside three weeks