CMMC Third-Party Certification Is Paused. Your Affirmation Isn’t.
You didn’t design the network, write the code, or build the systems that hold CUI, and you likely weren’t in the room for your own self-assessment. But as the Affirming Official under CMMC, you’re accountable for all of it anyway. Your name goes on the legal attestation, with your title and email, recorded in SPRS against that affirmation.
You’re vouching for conclusions you didn’t reach, about systems you don’t administer, to a customer that can come after you if any of them turn out to be wrong.
That obligation didn’t change when the Department of War suspended CMMC Phase II third-party certification. The pause only removed the independent validation layer that would have caught a mistake before the government did.
Before affirming this year and putting your name on the line, it’s worth knowing exactly what that signature rests on.
False Claims Act settlements
On September 1, 2026, Honeywell Aerospace agreed to pay $2,042,518 to settle False Claims Act allegations that a business unit failed to meet NIST SP 800-171 requirements on a Defense Department contract. A former employee brought the case and received $375,823 as the whistleblower.
Ten weeks earlier, a 26-person Alabama contractor paid $507,144 over similar allegations. It had reported a perfect SPRS score of 110. The Defense Industrial Base Cybersecurity Assessment Center assessed the same environment at negative 170, a 280-point difference.
Neither company had a breach. The exposure came entirely from the gap between what was reported and what was true and provable.
The gap between installed and working
The people who could catch potential gaps are spread across separate functions, each holding one piece of the picture. IT knows the technology, not the contract terms. Contracts knows the clauses, not where CUI moves. Your MSP runs the systems but doesn’t own the compliance decision. Business teams do the work without always recognizing the information as CUI.
The affirming official owns all of it, and no single person holds the whole picture.
Three ways to answer the same question
A gap assessment tells you what might be missing. It doesn’t tell you whether what you’ve already claimed is true. For that, there are three assurance options that test whether your controls are real. What changes is who’s answering, and who can rely on the answer.
Option 1: Self-assessment. This is where an organization learns its own CUI environment, often for the first time, by building the SSP and working through all 110 requirements. Its limit is structural: you can’t audit your own scope. The same people who drew the boundary are the ones checking it, which is how a self-reported score of 110 becomes a negative 170 when reviewed by an external party.
Option 2: Validated self-assessment. An independent party challenges your scope instead of accepting it, tests the evidence behind each determination, and confirms your providers did what their responsibility matrix says they did. This is a non-certification activity following the formal CMMC Assessment Process and Methodology, making it an affordable risk-reduction option for organizations that want greater confidence in their self-assessment results without committing to a full third-party certification assessment. It tells you plainly which parts of your score would survive a real assessment.
Option 3: Third-party certification. The technical work of a third-party certification overlaps heavily with a validated self-assessment. What certification adds is portability: a conclusion that holds up with a customer who has never met you. The assessor’s accreditation is on the line if the result is wrong, the findings go to the government, and the assessor can’t help you fix anything they find. That separation is what makes the result more trustworthy to someone outside your organization.
The CMMC pause removed the third option, which is the highest assurance. But, it didn’t remove the obligation to make a transferable claim with only non-transferable evidence behind it. That’s why the validated self-assessment matters more now than it did when certification was still coming. It’s the only layer left that can test your claim before someone else does, and it gives you the confidence and defensibility to affirm that you’re meeting your obligations.
One question to ask this week
Don’t ask your team if you’re compliant. Ask: if we had to prove this number tomorrow, what exactly would we put on the table?
Listen to the shape of the answer. “Our MSP has us covered” is a red flag. So is any version of “we’re good” that doesn’t come with evidence attached.
This is worth getting right, for you personally and for your organization. That’s what leadership accountability means, and it’s why the Affirming Official role was built into CMMC in the first place.
The bottom line
The information in scope here describes how this country builds, moves, and sustains what the warfighter depends on. The suspension handed Affirming Officials something they rarely get: time to validate the claim without a certification deadline forcing the timeline. The obligation to affirm accurately didn’t move. Use the time to find out what’s true, fix what isn’t, and sign knowing exactly what’s behind the yes.
A-LIGN is an authorized CMMC Third-Party Assessment Organization. If you have a score but not the confidence to defend it, a validated self-assessment or full third-party assessment will show you where you stand before someone else does. Talk to our CMMC team today.





