• videocam Live Webinar with Live Q&A
  • calendar_month November 19, 2026 @ 1:00 PM ET/10:00 AM PT
  • signal_cellular_alt Intermediate
  • card_travel Cybersecurity and Data Privacy
  • schedule 90 minutes

CMMC Crossroads: Navigating the Phase 2 Pause, Mitigating FCA Exposure, and Improving Compliance

Subcontractor and Contractor Strategies for Safeguarding FCI and CUI

About the Course

Introduction

This CLE course will analyze the ongoing implementation of the Cyber Maturity Model Certification (CMMC) program and its requirements for safeguarding federal contract information (FCI) and controlled unclassified information (CUI). Time will be spent examining the recent Phase 2 suspension and the role of the CMMC Reform Task Force—including impacts on new and existing contractor and subcontractor arrangements, FAR and DFARS reporting obligations, and False Claims Act and administrative enforcement risks—and practical risk mitigation strategies will also be addressed during this comprehensive program.

Description

The CMMC program is designed to ensure government contractors and subcontractors handling FCI or CUI are implementing proper safeguards consistent with their contractual obligations under the Federal Acquisition Regulation's (FAR) clause 52.204-21 and the Defense Federal Acquisition Regulation Supplement's (DFARS) clause 252.204-7012. For years, the Department of War (DOW) relied on self-attestations of compliance, while continued reports of threat actors successfully targeting the defense supply chain remained at the top of news headlines. CMMC represents DOW's response to the systemic cybersecurity noncompliance, requiring varying levels of assurance on compliance based on the sensitivity of the information being handled by the contractor.

In July 2026, the DOW suspended Phase 2 of the CMMC program, pausing the requirement for contractors handling certain categories of CUI to obtain third-party assessments (Level 2 - High) by Nov. 10, 2026. The DOW also established a CMMC Reform Task Force to conduct a 60-day review of the CMMC program, synthesize industry feedback, and issue recommendations. However, contractors' and subcontractors' obligations to implement the proper safeguards remain intact. During this presentation, our esteemed faculty will discuss the suspension and its implications for existing and new contracts, including the information subject to safeguarding, the contractual obligations relevant to CMMC compliance, and the corresponding safeguarding and self-reporting standards mandated by those obligations.

Defense contractors and subcontractors subject to CMMC's requirements face potential False Claims Act (FCA) exposure for noncompliance. The Department of Justice, through its Civil Cyber-Fraud Initiative, uses the FCA to investigate and pursue civilly contractors for knowingly misrepresenting CMMC compliance. During this presentation, our faculty will outline key elements of FCA claims, relevant case law, and evidentiary considerations for DOW contractors and subcontractors. Our faculty will highlight what the suspension means for existing compliance efforts as it relates to government enforcement risk. Time will be spent discussing other administrative actions and repercussions for noncompliance and misrepresentations, including potential suspension, contract termination, or debarment, along with risk mitigation measures contractors and subcontractors should consider.

Listen as our authoritative panel reviews what constitutes FCI and CUI, what safeguarding requirements are imposed by the FAR and DFARS, how those obligations are impacted by DOW's current pause on Phase 2 of the CMMC program, and strategies for mitigating government enforcement risk under the CMMC program.

Credit Information
  • This 90-minute webinar is eligible in most states for 1.5 CLE credits.


  • Live Online


    On Demand

Date + Time

  • event

    Thursday, November 19, 2026

  • schedule

    1:00 PM ET/10:00 AM PT

I. CMMC program requirements and the current landscape: Phase 2 suspension and the CMMC Reform Task Force

II. Phase 2 suspension: existing and new government contractor impacts, including business development, operations, and agreement drafting

III. Breaking down CMMC contractual, safeguarding, and self-reporting obligations before and after Phase 2 suspension

IV. FCI and CUI: contractor and subcontractor identification of data subject to safeguarding requirements

V. FCA and how CMMC noncompliance poses FCA risk

VI. Important evidentiary considerations for FCA claims and case law developments

VII. Evaluating other CMMC-related administrative repercussions, risk mitigation considerations, and compliance program efforts moving forward

The panel will address these and other key considerations:

  • What do the CMMC program's recent developments mean for subcontractor and contractor business moving forward?
  • What safeguarding requirements are imposed by the FAR and DFARS?
  • How are obligations impacted by DOW's current pause on Phase 2 of the CMMC program?
  • Which strategies will be most effective to mitigate government enforcement risk under the CMMC program?
  • In what ways can contractors and subcontractors anticipate and mitigate FCA risk?