
One common mistake government contractors make when scoring their own Cybersecurity Maturity Model Certification (CMMC) compliance is thinking they’re better off than they actually are in reality. You go down the list of 110 controls, you recognize most of them, you check off the ones that look handled, and you settle on a number that feels surprisingly good. The problem is the distance between that number and what an actual assessment would find. That score isn't just a gut check for yourself. You're sending it to the government, and your name is on it.
Key Takeaways
- Your self-scored CMMC assessment can often be higher than what an assessment from an outside observer assessment would find, and you're the one signing it to the government.
- You can overstate your SPRS score in two ways: giving yourself credit for controls you only partly meet, and counting controls that stopped working.
- Incorrectly certifiying can trigger the False Claims Act: three times what the government lost, plus a fine for each false claim, which can be enough to end a company.
- The assessor suspension didn't lower the bar. You still have to meet all 110 controls, so stopping now only sets you back.
- Your CMMC requirements reach your subcontractors, and a prime can still require an assessment in the contract even with the mandate paused.
- Get an honest outside read before you certify, so you catch the gaps while you can still fix them.
This got riskier recently when the federal government suspended the requirement to bring in a third-party assessor. Some GovCons heard that and figured they could ease off. But the 110 controls didn't change. The only thing that changed is that you're the one signing off now, with nobody from the outside double-checking you first. So getting expert help matters more than it used to, not less. Here are the mistakes I'd tell any contractor to watch out for.
What Happens If You Overstate Your CMMC SPRS Score?
Overstating your CMMC Supplier Performance Risk System (SPRS) score is common, but potentially dangerous, mistake GovCons make. Most people who overstate their score aren't trying to. It happens two ways:
- The first is giving yourself full credit for a control you only partially meet. You turned on multifactor authentication, so you check the box, but the control also wanted it enforced everywhere and documented, and you've only got part of that covered.
- The second is counting a control that used to work and stopped. You configured audit logging on your servers to track who accesses CUI, and it passed when you set it up. Then during a migration last year, logging didn't get turned back on for two of those servers. It's been dark ever since, but you're still counting the control as met.
On its own, an inflated score on your self-assessment is just a number in your files. Certifying it is what creates the risk. Self-attestation means you're signing a statement to the federal government that all 110 controls are in place. If you can't prove that, you've put an incorrect claim on the record. Before you post anything, have an expert go through your score with you.
What Are the Legal Consequences of Falsely Certifying CMMC Compliance?
The most fatal mistake a GovCon can make is incorrectly certifying its CMMC compliance. This is the one that can actually sink you and it's due to the False Claims Act. It's a law that goes after companies for knowingly lying to the government.
Since 2021, the Department of Justice (DOJ) has run a Civil Cyber-Fraud Initiative that uses it specifically against contractors who overstate their cybersecurity to win or keep federal work. And its application is not merely hypothetical: DOJ settled with Raytheon for $8.4 million over claims it falsely represented compliance with NIST 800-171 across about thirty DoD contracts.
The consequences are rough if you incorrectly certify. Consider the following:
- You're on the hook for three times whatever the government says it lost, plus a per-claim civil penalty that currently runs from about $14,000 to $28,000 for each false claim (adjusted for inflation annually).
- Because that fine hits per claim, the total can climb far past the actual loss in a hurry. For plenty of contractors, that's a company-ending number.
- The word "knowingly" trips people up too, because it's a lower bar than it sounds. You don't have to be running a scam. If you inadvertently signed off on a score you had no business signing off on, that can be enough.
The good news is this is easy to avoid. Get somebody who evaluates these controls every day to look at your setup and tell you the truth about where you stand. They'll catch the things you gave yourself too much credit on while you can still fix it, instead of you finding out the hard way after you've already certified.
Should You Pause CMMC Compliance During the Third-Party Certification Suspension?
Another mistake many GovCons may feel tempted to make is to pause their own CMMC compliance activities on account of the federal government suspending the requirement to pay an assessor. It might feel like the pressure is off. Here’s why it’s not:
- CMMC is still coming, there's new guidance on the way, and none of this changes what you have to meet in the meantime. You still have to hit the controls.
- Your work will build on itself. The policies you write and the proof you gather don't expire. They're what you build your foundation on. Every security gap you close is one less headache later.
- Halt activity for six months and your cybersecurity program will get stale. The GovCons who keep chipping away while the rules settle are going to be ready when the guidance comes through. The ones who stopped are going to be scrambling.
- If you're a prime, it's easy to forget that these requirements reach the subs you've hired. The second a sub handles controlled unclassified information (CUI) they're on the hook for the same things you are, and usually you're the one who has to make sure that actually happens.
- If you're a sub, the mistake is never picking up the phone to ask your prime what you're responsible for. And the suspension makes this harder. Your prime can still put a C3PAO assessment in your contract even though the government isn't requiring it anymore, because nothing stops them from holding you to a higher bar than the government does. If you figured the suspension let you off the hook, that clause is going to be a nasty surprise when it shows up. Either way, nail down who's responsible for what, in writing, before you sign.
Am I Spending More on CMMC Than I Need To?
Some teams go the other way and overdo it. The stakes finally hit them, and they want to buy every tool and knock out every requirement all at once, including ones that don't even apply to them yet. The reflex is understandable, but it wastes a lot of money. A good partner should be telling you to slow down as often as speed up and be straight with you about what your setup actually needs so your money goes where it counts.
Spending a ton isn't the same as spending smart, and nobody's giving you extra points for spending in areas where you don't really need to.
Do CMMC Requirements Flow Down to Subcontractors?
It’s a mistake to think your CMMC requirements won’t extend to your subcontractors. They do, and it burns people on both ends. Think about it from both perspectives:
- If you're a prime, it's easy to forget that these requirements reach the subs you've hired. The second a sub handles controlled unclassified information (CUI) they're on the hook for the same things you are, and usually you're the one who has to make sure that actually happens.
- If you're a sub, the mistake is never picking up the phone to ask your prime what you're responsible for. And the suspension makes this harder. Your prime can still put a C3PAO assessment in your contract even though the government isn't requiring it anymore, because nothing stops them from holding you to a higher bar than the government does. If you figured the suspension let you off the hook, that clause is going to be a nasty surprise when it shows up. Either way, nail down who's responsible for what, in writing, before you sign.
For smart GovCons, none of these are hard mistakes to avoid. What they take is an honest look at where you actually stand against the controls rather than the score you'd like to have. Get that read before you certify anything to avoid a lot of problems down the line.
If you’re looking to complete a thorough, comprehensive self-assessment while avoiding these mistakes, our team can help. Talk to us to learn more about how Ntiva supports government contractors with CMMC compliance.
About the author
Michael Diab is Ntiva's Director of Regulatory & Compliance, where he supports the company's GovCon practice and its CMMC readiness and compliance-as-a-service work for regulated clients. He’s helped take Ntiva through its own CMMC Level 2 certification via an accredited C3PAO and advises defense contractors from firsthand, auditor-tested experience.

.png?width=420&height=210&name=Hero%20-%20Inside%20the%20Audit%20-%20CMMC%20self%20assessment%201%20(1).png)



