Skip to content
SAUTERASAUTERA

For defense contractors

You signed a number.
What proves it’s still true?

Certification is paused. Your annual affirmation isn’t, and DIBCAC is still assessing. SAUTERA™ scores whether your infrastructure can actually be trusted — continuously, with evidence you can hand to someone who asks.

No card. First score in about an hour. Windows and Linux.

July 13, 2026

The certificate moved. The exposure didn't.

The Department of War suspended CMMC Phase 2 — the third-party assessment that was to take effect in November — and stood up a reform task force. That is all that was suspended.

NIST SP 800-171 implementation

An unchanged contractual obligation. The suspension touched how compliance is assessed, not what is required.

SPRS self-assessment and annual affirmation

The contractor attests. Personally. Every year. This is the requirement that did not move.

DFARS 252.204-7012 — safeguarding CUI

Unchanged. CUI arriving under prime flow-down carries the same handling obligations it did in June.

DIBCAC assessments

Still being conducted. Medium assessments run virtually against your SSP and supporting documentation, and contractors are still being selected.

The risk did not disappear. It moved off the certificate and onto your own attestation — which is the harder version, not the easier one. A certificate is a point in time somebody else signs. An affirmation is you, personally, every year.

Why the wording matters

A false attestation isn't a compliance ding

Under the Department of Justice Civil Cyber-Fraud Initiative, it is False Claims Act exposure — and the cases are already settled and public.

In June 2026 a defense contractor settled for $507,144 after self-reporting a perfect SPRS score of 110 in October 2021. A subsequent government assessment scored the same environment at −170.

An earlier settlement followed the same pattern: a score submitted materially higher than the figure a consultant had calculated, and then left uncorrected for nearly a year.

Both cases turn on the same thing — not whether a control existed on the day of the assessment, but whether the number stayed true afterwards, and whether anyone was positioned to notice that it hadn’t. That gap, between what you attested to and what your environment is actually doing today, is what SAUTERA measures.

Where the number drifts

Four things that make an honest score go stale

None of these are exotic. They are the ordinary physics of a real estate over twelve months.

Unsupported software

Which machines are running something the vendor no longer patches — and where that number comes from. Most answers are estimates. Past end-of-life can never score as trusted here; the math decides, not an opinion.

Configuration drift

A baseline that was true when you scored it and has since moved. Drift is silent by nature, which is precisely why an annual snapshot cannot catch it.

Coverage you do not have

Estates almost always contain systems nobody is watching. Where coverage is thin, SAUTERA reports Unknown rather than guessing — because a report that rounds uncertainty up to green is worth nothing to an assessor.

The interval between assessments

An assessment is a point in time. The affirmation covers a year. Everything that happens in between is the part you are attesting to without evidence.

What SAUTERA does about it

Evidence generated from real cycles — not a questionnaire

Continuous per-device trust scoring across Windows and Linux, installed sensor or fully agentless over SSH, WMI or SNMP. Every finding written to a tamper-evident record.

Control-mapped evidence for NIST 800-53 Rev 5, NIST CSF 2.0, SOC 2 Type 2 and ISO/IEC 27001:2022 is generated as a by-product of scoring your fleet. Nothing is pre-filled and nothing is sample data — every row traces to a real change on a real machine, and every export is itself audit-logged.

Where SAUTERA has no coverage, it says Unknown. That is a deliberate design decision. An assessor who finds one confident-but-wrong claim in your evidence will re-examine all of it.

SAUTERA informs the trust decision; enforcement stays at your existing policy enforcement point. Remediation is closed-loop and human-approved — every action signed, reversible, and gated on a person saying yes.

Free download

The SPRS Self-Assessment Evidence Checklist

All 14 NIST 800-171 families, and what evidence you must actually be able to produce behind the score you post — not merely attest to. Includes the scoring trap (why most first honest scores are negative, and why that is the defensible position) and the continuous-evidence playbook for whenever Phase 2 returns.

The download starts right away, and we email you the link so you keep it. No drip sequence.

Find out what your number actually is.

Ten devices free, no card. Pro at $5,000/yr with the first 50 devices included. We don’t know your SPRS score — nobody outside your organisation does. That is rather the point of the conversation.

Sources

Every factual claim on this page is drawn from public reporting. SAUTERA asserts no company’s SPRS score and characterises no company’s compliance posture. SPRS scores are not public.

  • WilmerHale — Pentagon Suspends CMMC Phase 2 Requirements and Launches Review
  • Arnold & Porter — DOD Suspends CMMC Phase II, But Core DFARS Obligations Endure
  • Crowell & Moring — DoW Immediately Suspends CMMC Phase II, Launches 60-Day Reform Review
  • Sidley FCA Blog and Mayer Brown — reporting on the June 2026 $507,144 False Claims Act settlement
  • Arnold & Porter — Civil Cyber-Fraud Initiative Strikes Again

Related reading: CMMC compliance and NIST 800-171 evidence · Windows end-of-life exposure · What a compliance evidence package looks like