Blog Post

When Certification Decides Who Can Bid

September 22, 2026

Table of Contents

In defense supply chains a certification level decides eligibility to compete. A contractor that cannot demonstrate the required level at award is ineligible, so the consequence of falling short is not a penalty. It is the removal of access to a pipeline.

The shape of that gate changed in July, when the Department of War suspended the second phase of its certification program along with later milestones, and referred the program to a task force for review. The gate did not disappear. It narrowed to the part a contractor asserts about itself.

What Remains a Condition of Award?

Self-assessment, which the Department confirmed remains firmly in place.

The first phase took effect in November 2025 and requires offerors on applicable solicitations to complete and post a self-assessment at the level the contract specifies, with a senior official affirming that the score is accurate. Under the suspension, requiring activities were directed to include only self-assessed levels in solicitations and not third-party or government-assessed levels.

Existing Contracts Are Being Amended

Guidance issued alongside the suspension directs that active solicitations and contracts already carrying third-party assessment requirements must be amended to remove them, while contractors on existing contracts continue meeting those requirements until those modifications issue.

Why Was It Suspended?

Assessment capacity rather than a change of position on security, and the distinction matters for anybody treating this as relief.

Control assessment results against a framework with the weakest identified areas listed alongside the maturity scores
A self-assessed position is the artifact the current requirement rests on, which puts the weight on whether the score is defensible.

Officials pointed to a mismatch between the number of contractors that would eventually need assessment, in the region of a hundred thousand, and the small number of accredited assessment organizations available to perform them. Cost estimates for smaller businesses and a government accountability report warning that the requirements could push them out of the industrial base informed the decision. What the certification levels require sets out the underlying model.

The Obligation Is Not Going Away

The underlying security requirements are unaffected, and the Department has been explicit that it is reducing certification burden rather than lowering the baseline. The verification mechanism is therefore being redesigned while the substance stays. Third-party assessment may return in its current form, with different dates, or replaced by another verification model.

Where Did the Risk Move To?

From a certification cost to an attestation exposure, which is the most consequential effect and the least discussed.

A third-party assessment transfers part of the assertion to an accredited assessor. A self-assessment does not. A score posted with a senior official's affirmation is the contractor stating its own compliance, and misrepresenting compliance carries exposure under false claims legislation rather than being a compliance finding.

Which Makes This a Personal Exposure

Somebody signs the affirmation. A score assembled by a security team and affirmed by an executive who cannot independently evaluate it puts that individual behind a statement they are relying on others for, and the suspension increased rather than reduced how much rests on that signature.

How Is the Pipeline Loss Measured?

Measure it by the addressable opportunity requiring a level you cannot demonstrate, over the period it would take to reach it, and both halves already exist inside the organization.

Control recommendations ranked by the annual loss each improvement removes, with current and target implementation levels shown per item
Ranking by what each improvement unlocks is the same calculation whether the outcome is loss avoided or eligibility gained.

Business development holds the pipeline with the requirement level per opportunity. Security holds the current position and the time to close the difference. Multiplying the value of opportunities you would be ineligible for by the probability of winning them produces the figure, and it is the one number nobody computes because it sits between two functions.

Why Does the Lead Time Dominate?

Because the interval between a solicitation appearing and an award is short, commonly around a month, while reaching a defensible position against the underlying control set takes many months. So the decision that costs you an opportunity was taken roughly a year before the opportunity existed.

Why Is This Loss Invisible?

Because nothing happened. No incident, no outage, no disclosure, and therefore nothing that appears in any security metric.

The loss surfaces as revenue that did not arrive, in a pipeline report owned by business development, attributed to competitiveness or pricing rather than to a control position. A security function reporting zero incidents and a sales function reporting a lost bid are describing the same event from two sides and neither connects them. Proving what a security budget returns runs into the same reporting boundary.

What Makes It Visible?

Tagging opportunities by required level and reporting the excluded proportion monthly. The tag is a field in a pipeline system rather than a project, and once it exists the figure reports itself, which connecting investment to what it returns depends on.

What Should Be Done With a Booked Assessment?

Reassessed rather than canceled, since the review may reinstate a verification requirement in some form and the preparation retains its value either way.

Converting a booked third-party engagement into a readiness exercise preserves most of the benefit at lower cost, and it produces evidence supporting the self-assessment score that is now the operative requirement. An organization that cancels outright and finds a verification requirement returning faces the same capacity constraint that caused the suspension, from a worse starting position.

What Should the Decision Rule Be?

Reversible preparation continues and irreversible commitments wait for whatever verification model emerges. Work improving the underlying control position is valuable under any outcome, since the security requirements were never suspended. Spending that only makes sense against one particular assessment mechanism should wait until that mechanism is settled.

Does the Requirement Reach Subcontractors?

Yes, and the flow-down is where the pipeline loss reaches organizations that never bid directly.

The clause obliges a contractor to insert its substance into subcontracts and to satisfy itself before award that a subcontractor holds a current status at the level appropriate to the information being passed down. So a prime evaluating a supplier is applying the same eligibility test the government applied to it, one layer further out.

Primes Are the Enforcement Mechanism

A subcontractor loses access to a pipeline through a commercial decision by a prime rather than through a contracting officer. A commercial decision moves faster than a regulatory process and with no notice requirement, and the supplier frequently learns about it as an absence of invitations rather than as a communication.

What Should a Supplier Establish?

Which of its primes have asked, what level each expects, and whether the answer given was a posted score or an assurance. A supplier that has provided assurances rather than a posted self-assessment is relying on a prime not checking, and assessing and being assessed runs in both directions here.

What Should Be Established Now?

Four things, and the second is the one that turns this from a compliance topic into a quantifiable one.

Whether the posted self-assessment score is defensible against the underlying control set, since that is what an affirmation asserts. What proportion of the pipeline requires a level not currently held, valued and weighted by win probability. Whether the person signing the affirmation understands what they are signing. Then whether any existing contract still carries a suspended requirement pending a modification. The clause itself sets out what must be held and maintained for the duration of performance, and cyber risk quantification turns the pipeline exposure into a figure that competes for budget on the same terms as anything else.

The Gate Narrowed, It Did Not Close

Certification still decides eligibility, and since July the requirement in new solicitations is limited to self-assessed levels while third-party and government assessment sit suspended pending a review reporting in September. The reason was assessment capacity rather than a softening on security, so the verification mechanism is being redesigned and the obligation is not being withdrawn. The consequence is that risk moved from a certification cost to an attestation exposure, since a self-assessed score carries a senior affirmation and misrepresentation carries false claims exposure rather than a compliance finding. The pipeline loss is measurable from data two functions already hold, and invisible because nothing happened. Kovrr's cyber risk quantification prices eligibility alongside loss.

To see pipeline exposure priced alongside conventional loss scenarios, book a demo with our risk experts.

Yakir Golan

CEO

Certification Eligibility FAQs

Speak to an Expert

What remains a condition of award after the July suspension?

Why was the second phase suspended?

Does the suspension reduce the obligation?

Where did the risk move to?

How is the pipeline loss measured?

What should be done with a booked third-party assessment?