CMMC Phase II Is Paused. Here Are Five Actions Contractors Should Take Now.

CMMC Phase II Is Paused. Here Are Five Actions Contractors Should Take Now.

The pause in CMMC Phase II may have changed the assessment timeline, but it has not changed the cybersecurity responsibilities facing Defense Industrial Base contractors.

Organizations that handle Controlled Unclassified Information (CUI) still need to protect sensitive data, maintain accurate documentation and support their cybersecurity claims with defensible evidence. Existing contractual obligations remain in effect, and prime contractors will continue to evaluate the cybersecurity maturity of their suppliers.

For contractors, this is not a reason to stop preparing. It is an opportunity to shift from deadline-driven compliance work to a more sustainable model of operational readiness.

Red River’s latest viewpoint, CMMC Phase II Is Paused. Your Cybersecurity Obligation Is Not., outlines five actions contractors can take during this period to reduce risk, improve readiness and prepare for whatever verification model follows the review.

1. Validate the CUI boundary

A strong cybersecurity program begins with a clear understanding of where CUI exists and how it moves through the organization.

Contractors should confirm where CUI is stored, processed and transmitted, then identify every user, device, application and supporting system that interacts with that information.

The scope matters. An overly broad boundary can add unnecessary cost and complexity. An incomplete boundary can leave sensitive systems outside required protections.

This review should answer several practical questions:

  • Which systems contain or process CUI?
  • Who has access to those systems?
  • Which devices, applications and third parties interact with the data?
  • Are data flows documented and current?
  • Have recent technology or business changes altered the boundary?

A clearly defined CUI environment gives contractors a more accurate foundation for security planning, remediation and future assessments.

2. Reconcile documentation with reality

Cybersecurity documentation should describe the environment as it operates today, not as it existed when the documents were first created.

Contractors should review their System Security Plan, Supplier Performance Risk System score, policies and Plans of Action and Milestones against the current environment. Any differences between documented controls and actual practices should be identified and resolved.

The objective is not to produce documentation that appears compliant. The objective is to ensure the documentation and the environment tell the same story.

This is particularly important as organizations adopt new cloud services, add users, change permissions and modernize infrastructure. Without ongoing maintenance, even accurate documentation can quickly become outdated.

By making documentation updates part of normal operations, contractors can reduce the risk of last-minute reconstruction before an assessment, contractual review or customer request.

3. Prioritize high-risk gasps

Not every gap creates the same level of exposure.

Rather than addressing controls in an arbitrary order, contractors should focus first on weaknesses that present the greatest risk to sensitive information, operations and contractual performance.

Common priority areas include:

  • Identity and access controls
  • Vulnerability management
  • Security logging
  • Incident response
  • Unsupported systems
  • Unmanaged assets

This risk-based approach helps organizations direct limited time, budget and personnel toward the issues that matter most.

It also creates a more useful measure of progress. Closing a large number of low-impact items may improve a checklist, but addressing a serious access control or vulnerability management weakness can produce far greater operational value.

The goal should be measurable risk reduction, not activity for its own sake.

4. Build continuous evidence collection

Contractors should not wait until an assessment is approaching to begin gathering evidence.

Evidence should be created and maintained through routine operations. Accurate asset inventories, access records, configuration data, vulnerability results and incident response records can help demonstrate that required controls are functioning as described.

A continuous approach also reduces the burden placed on security and IT teams. Instead of recreating months of records under deadline pressure, organizations can maintain an organized body of evidence as work is performed.

Automation can support this effort by helping teams:

  • Collect and organize control evidence
  • Track assets and configuration changes
  • Identify gaps in required records
  • Map evidence to security requirements
  • Keep documentation aligned with the environment

Continuous visibility is especially important as systems change. It can help contractors detect configuration drift, track CUI interactions and maintain a more accurate view of their compliance boundary.

5. Define a sustainable operating model

Technology alone cannot sustain cybersecurity compliance.

Contractors also need clear ownership, repeatable workflows and enough operational capacity to perform the work consistently. That means determining which responsibilities will remain internal and which may require support from a managed services provider.

Key responsibilities include monitoring, vulnerability remediation, documentation maintenance, evidence collection, access reviews, incident response and continuous improvement.

Leaders should consider:

  • Who owns each cybersecurity and compliance function?
  • Are responsibilities documented and understood?
  • Does the organization have enough capacity to complete the work consistently?
  • How are issues escalated?
  • How will controls and documentation be maintained as the environment changes?

A defined operating model helps prevent critical activities from falling behind when compliance work competes with daily IT operations, modernization initiatives and customer commitments. 

Move from certification readiness to operational readiness

The most important shift contractors can make during the pause is to stop treating CMMC preparation as a one-time project tied to an assessment date.

Operational readiness means making cybersecurity controls, evidence and documentation part of the organization’s daily discipline. It requires current asset inventories, clear data boundaries, strong access controls, continuous monitoring, tested response procedures and defined accountability.

These capabilities support more than CMMC. They can also strengthen cyber resilience, improve business continuity and build confidence among government customers and prime contractors.

The assessment schedule may continue to evolve. Cyber threats, contractual requirements and the responsibility to protect mission information will not.

Contractors that use this period to strengthen their environments will be better prepared for current obligations and whatever comes next.

Read the full Red River viewpoint, CMMC Phase II Is Paused. Your Cybersecurity Obligation Is Not., to explore the five actions in greater detail and learn how Red River Managed Services can help organizations build and sustain operational readiness.

 

About Red River

Red River brings together the ideal combination of talent, partners and products to disrupt the status quo in technology and drive success for business and government in ways previously unattainable. Red River serves organizations well beyond traditional technology integration, bringing more than 30 years of experience and mission-critical expertise in managed services, AI, cybersecurity, modern infrastructure, collaboration and cloud solutions. Learn more at redriver.com.

 

 

written by

Ed Levens

As Chief Marketing Officer, Ed Levens oversees Red River’s marketing organization and leads the company’s government relations efforts. He is responsible for strengthening the Red River brand, enhancing market visibility, and expanding the company’s presence across its partner ecosystem. Learn more about Ed on our Leadership Page.