A Week After the CMMC Pause, Some Contractors Are Already Pulling Ahead

A week ago, the CMMC Phase II pause landed, and most defense contractors exhaled. The November deadline slipped, the third-party audit went on hold, and a lot of people quietly moved compliance to the back burner.

A few didn’t. They read the same news and got to work. One week in, the gap between those two groups is already showing, and it’s going to be hard to close by fall.

We are working and paying attention to any update on CMMC like this recent announcement. As our President and CEO, Horacio Maysonet emphasize:

“The third-party audit is paused; the work isn’t. NIST SP 800-171, your SPRS score, your annual affirmation, and your DFARS 252.204-7012 obligations are all still in force. And with no assessor in the loop, an inaccurate self-attestation arguably carries MORE risk right now, not less.

The smart move: treat this pause as runway. Get an honest read on your posture, close your gaps, finalize your SSP and POA&M, and be ready the moment certification comes back.”

Here are the three moves the sharp ones made first.

Move 1: They pulled their real SPRS score before anyone asked

Most contractors think they know their SPRS score. Fewer can tell you when it was last calculated or whether it still matches the systems they run today.

The contractors pulling ahead checked the date first. If the score predated a new tool, a cloud migration, or a staffing change, they treated it as stale and recalculated. Then they did the uncomfortable part: they read their self-assessment the way an outside reviewer would. For every control marked “met,” they asked one question. Could I hand over the proof today? Not explain it. Hand it over. If not, that control wasn’t met. It was a wish.

That honest read is the single most useful thing you can do this week, and almost nobody does it.

Move 2: They fixed the paperwork that actually creates liability

Two documents do the most damage when they’re wrong: your System Security Plan (SSP) and your Plan of Action and Milestones (POA&M).

Your SSP is supposed to describe how you protect information as it exists now, not the company you were two years ago. The contractors ahead of you rewrote theirs to match reality. Their POA&M isn’t blank either. A blank POA&M usually means nobody looked hard enough. A real one, with honest dates and named owners, protects you more than a spotless self-assessment that quietly skips three open gaps.

Here’s the part people miss. With no assessor in the loop during the CMMC suspension, your self-attestation is the entire story. Nobody’s there to catch an optimistic guess. That means an inaccurate self-assessment arguably carries more risk right now, not less, because you signed it and no one checked it but you.

Move 3: They closed the cheap gaps and called their primes

Not every gap costs money. Multi-factor authentication turned on everywhere. Access reviews that actually happen. Logging switched on and pointed somewhere. Accounts killed the day someone leaves. The contractors ahead knocked these out first because they cost time, not budget, and a reviewer can see them.

Then they picked up the phone. The primes above them didn’t get a memo lowering their standards. DFARS 252.204-7012 and NIST 800-171 still flow downhill, and many primes will keep gating subcontract awards on posture no matter what the task force decides. A ten-minute call now tells you whether your next award depends on a posture you don’t yet have. That’s information you want in July, not the week a proposal is due.

What did not change during the CMMC Phase II pause

Say it plainly, because the relief is outrunning the facts. The pause hit the audit, not the standard. NIST SP 800-171 is still the baseline. DFARS 252.204-7012 still binds you. The Department of War can still assess you on its own timeline, and your primes can still choose someone else.

What changed is that you got time you didn’t have last month. The work was always coming. Now you can do it calmly instead of in a panic.

Frequently asked questions

Is CMMC cancelled? No. Phase II is paused for a 60-day review, not repealed. Treat it as a pause on the audit mechanism, not the end of the program.

Do I still need to meet NIST 800-171? Yes. NIST SP 800-171 Rev. 2 remains the contractual baseline, and your DFARS 252.204-7012 obligations are unchanged.

Can the government still assess me during the pause? Yes. Enforcement continues through self-assessments and selects government-led reviews. “Paused” does not mean “unwatched.”

Does my SPRS score still matter? Yes. Primes can gate subcontract awards on your posture right now, so your score is a competitive factor this quarter.

Want a hand running these three moves? We’ll give you an honest read on your posture and a clear path to close your gaps. Start with a Validation Score Assessment – Cyber Security Solutions

 

Enough Talks, Let’s find the solutions

Recent Posts:

(Sign up)

Ready to
close your gaps?

From your first scan to full remediation, we guide you through every step before the CMMC clock runs out.