Steptoe·GOVERNMENT CONTRACTS / DEFENSE

CMMC Pause, Supply Chain Risks, and FCA Exposure Reshape Defense Contracting

Defense contractors and suppliers must reassess cybersecurity compliance, supply-chain vetting, and FCA exposure as DoD enforcement tightens.

The Department of Defense has paused the CMMC cybersecurity certification rollout, creating uncertainty for primes and subcontractors awaiting assessment timelines. Meanwhile, supply-chain chokepoints—particularly around critical components and foreign-sourced materials—continue to draw scrutiny under procurement integrity rules. Compounding the risk, False Claims Act enforcement is escalating, with DOJ targeting misrepresentations in cybersecurity self-assessments, country-of-origin disclosures, and tariff-related certifications. Recent qui tam settlements signal that contractors should expect heightened whistleblower activity. Practical steps: document CMMC readiness gaps, audit supply-chain disclosures, refresh FCA compliance training, and review representations made in recent solicitations. Companies should also evaluate voluntary disclosure options where noncompliance is identified, as cooperation credit is increasingly material to penalty outcomes.

cmmc-cybersecuritysupply-chain-riskfalse-claims-act
Read the original firm alert →Tuesday, July 28, 2026

Stay ahead

Join the digest.

One email when the daily AmLaw 100 briefing ships. No noise, no pitch decks — just the grade 4–5 signal.