Subscribe to our mailing list today.

Defense Contractor Cybersecurity San Diego: How to Get Your SPRS Score Right While CMMC Phase II Is Paused

defense-contractor-cybersecurity-san-diego-sprs-score-poam-hero

On September 1, 2026, the Department of Justice announced that Honeywell Aerospace had agreed to pay $2,042,518 to resolve False Claims Act allegations that one of its networks failed to comply with NIST SP 800-171 cybersecurity requirements. No breach, no stolen data — the gap between the posture the company attested to and the posture it actually had was enough.

For defense contractor cybersecurity in San Diego and nationwide, that settlement matters more than the CMMC Phase II suspension. The suspension gets the headlines; the False Claims Act gets the settlements. While the Phase II third-party assessments sit on pause, the obligation to protect CUI, to self-assess honestly, and to post an accurate SPRS score has not moved an inch.

The pause changed the audit, not the obligation

On July 13, 2026, the Department of War suspended the CMMC Phase II requirements that would have made third-party C3PAO assessments a condition of award starting November 10, 2026. A September 3 class deviation told contracting officers to strip third-party CMMC requirements from solicitations and allow Level 1 and Level 2 self-assessments, with NIST SP 800-171 kept as the baseline.

What did not change at any point:

  • Phase 1 self-assessments remain fully in force, including annual senior-official affirmations.
  • SPRS submissions are still required — offerors generally need a current score and affirmation in the Supplier Performance Risk System to be eligible for award.
  • DFARS 252.204-7012 still requires contractors to safeguard covered defense information and report cyber incidents to DoD within 72 hours.
  • NIST SP 800-171 Rev 2 — all 110 security practices — is still the technical baseline for Level 2.

Companies that use the pause to get their house in order will be best positioned when the reformed requirements land.

Your SPRS score is the number contracting officers actually see

CMMC gets the attention, but the Supplier Performance Risk System is the working machinery. Before most DoD awards, a contracting officer checks your SPRS entry: your assessment level, your score, and your affirmation that the information is current and accurate.

The scoring model is simple and unforgiving. You start at +110 — one point for each of the 110 NIST SP 800-171 practices implemented — and every unmet practice subtracts points. Scores run from +110 down to -203, and anything short of perfect must be backed by a Plan of Action and Milestones (POA&M) showing how and when you will close the gap.

This is where many contractors quietly go wrong. The score is self-reported, so the temptation is to be generous: mark borderline controls as implemented, count a policy that was written but never enforced, claim a control that covers only part of the CUI environment. Then a contracting officer, a prime, or — as Honeywell learned — the DOJ asks for the evidence behind the number, and the score collapses. Your SPRS score is a representation to the federal government — treat it with the care of a signed financial statement.

How SPRS scoring actually works

The honest version of the process:

  1. Scope your CUI environment. Map exactly where Controlled Unclassified Information lives, flows, and is processed — including cloud services, subcontractor systems, and the endpoints everyone forgot about. Everything outside the boundary is out of scope; everything inside must be assessed.
  2. Assess all 110 practices against NIST SP 800-171 Rev 2 with evidence in hand — not memory. For each practice, show it is implemented, how, and that it operates as described.
  3. Score it. Start at +110, subtract for every unmet practice, and document every deduction.
  4. Build your POA&M. Every gap gets a remediation action, an owner, a milestone, and a due date. CMMC guidance generally gives POA&M items a 180-day window to close, so date milestones realistically.
  5. Update your System Security Plan. The SSP describes your CUI boundary and how each practice is implemented — the first document anyone verifying your score will ask to see.
  6. Post the score and affirm it through SPRS with a senior official’s annual affirmation, and update the score when anything material changes.

The contractors who struggle most discover in step 2 that their environment grew unnoticed: a cloud migration never assessed, an MSP with unreviewed access, endpoints that drifted out of policy. Step 1 is where the real work happens.

POA&Ms: your remediation paper trail

Every item needs the specific finding, the remediation action, the person responsible, and a dated milestone. What it should never have: vague language ("improve access controls"), no owner, or milestones that quietly slip quarter after quarter.

Two practical notes. First, POA&Ms are discoverable evidence of what you knew and when — a gap that sits unaddressed for two years becomes Exhibit A if an incident lands in it. Second, keep evidence organized as you go: screenshots, configurations, logs, test results.

The False Claims Act exposure nobody budgeted for

According to the DOJ announcement, the allegations concerned a business unit’s failure to comply with NIST SP 800-171 on one network from April 2020 through December 2023 — and the case was initiated by a whistleblower, a former employee. The claims were allegations only, with no liability determination, but $2,042,518 is what it cost to resolve them.

The lesson for a 30-person machine shop in Kearny Mesa or a 50-person engineering firm in Sorrento Valley: you do not need a breach to have a False Claims Act problem. You need a representation to the government — an invoice, a certification, a score, an affirmation — that does not match reality. In a suspension era built on self-attestation, that risk grows, not shrinks.

What to do now

  • Re-scope your CUI boundary for your current environment, including cloud and remote-work changes.
  • Run a gap assessment against all 110 NIST SP 800-171 practices with real evidence, not recollection.
  • Score yourself honestly and document every deduction.
  • Build POA&Ms with owners and 180-day milestones for every gap, and start closing them.
  • Update your System Security Plan so it describes the environment you actually have.
  • Review who touches your CUI — MSPs, cloud providers, subcontractors — and confirm their posture is covered.
  • Calendar your annual affirmation.

None of this requires waiting for the reformed requirements.

When to bring in help

The 110 controls of NIST SP 800-171 span identity management, incident response, audit logging, configuration management, and media protection — each deserving a specialist. A partner providing CMMC and government-contractor IT support can run the gap assessment, build the POA&Ms, and keep evidence current, while managed cybersecurity services with 24/7 monitoring handle day-to-day detection and response. For the full foundation under one roof, managed IT services built around compliance keep the environment in scope between assessments.

The self-attestation regime is here now. Get the score right.

Protect your contracts before the reformed requirements land.

FIT Solutions is a San Diego managed IT and cybersecurity provider supporting defense contractors with CMMC readiness, NIST SP 800-171 assessments, and 24/7 monitoring from our California Security Operations Center. Call (888) 339-5694.

What our clients say.

What our clients say.

What our clients say.

Get in touch.

Reach out and our team will get
back to you as soon as we can!

Who we are.

Our mission is to impact the lives touched by
technology. To that end, our vision is to help 6,000
businesses realize their goals through technology. 

What we do.

FIT Solutions offers managed IT services and cybersecurity services to
help organizations reduce IT costs and downtime, increase efficiency
by up to 40%, and protect against cyberattacks.

Who we are.

Our mission is to impact the lives
touched by technology.

What we do.

We offer managed IT services
and cybersecurity services.

Privacy Policy

© 2020 by FIT Solutions. IT Consulting, Cloud Hosting, Cybersecurity, and Managed IT Services

HIPAA

Get in touch.

Fill out the form and our team will get
back to you as soon as we can!