By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: AppgatePublished July 29, 2026

TL;DR: The Department of Defense has paused the mandatory C3PAO third-party assessment for CMMC Level 2 contracts while keeping Phase I requirements, self-assessments, NIST SP 800-171 controls, DFARS reporting, and enforcement in place, according to AppGate. The governance problem has shifted from audit timing to proving defensible access control, because compliance obligations did not disappear with the paused assessment requirement.


At a glance

What this is: The DoW has paused only the mandatory third-party assessment requirement for CMMC Level 2, while keeping the rest of the current compliance stack intact.

Why it matters: This matters because contractors still need to prove access control, incident reporting, and continuous compliance across human and non-human identity estates even without an external audit date.

By the numbers:

  • Building the necessary security controls and reaching full Level 2 compliance can take six to 12 months.

👉 Read AppGate's analysis of the DoW CMMC pause and access-control implications


Context

CMMC is a defense contracting access-control and compliance framework, and the practical issue in this update is narrow but important: the Department of Defense has paused only the mandatory C3PAO third-party assessment for Level 2 contracts. The rest of the obligation set still applies, which means contractors cannot treat the pause as a compliance reset.

For IAM and security teams, the signal is that external assessment cadence may change, but the underlying control expectations do not. That keeps focus on who can access Federal Contract Information and Controlled Unclassified Information, how that access is governed, and whether evidence can still support self-assessments, SPRS reporting, and continuous compliance obligations.


Key questions

Q: What fails when organisations treat the CMMC pause as a reason to stop preparing?

A: The failure is usually evidence, not technology. Contractors can end up with controls that are partly implemented but not documented well enough to support self-assessments, SPRS scores, or later third-party review. That creates a compliance backlog that becomes harder to clear when the programme resumes or when a government spot check occurs.

Q: Why do access controls still matter if the third-party CMMC assessment is paused?

A: Because the security obligations remain in force. The pause changes who verifies compliance, not what compliance requires. If a contractor handles FCI or CUI, it still has to govern access, report incidents, and prove that its identity and access controls actually work in practice.

Q: How do organisations know whether their CMMC posture is actually defensible?

A: They should be able to produce evidence for every control they claim, including access restrictions, authentication, segmentation, incident handling, and continuous compliance activities. A defensible posture is one that survives internal challenge, government review, and a future return to mandatory external assessment.

Q: Who is accountable when a contractor cannot prove CMMC identity controls?

A: The contractor remains accountable, because CMMC shifts eligibility from self-reporting to third-party assessment. If identity controls are incomplete, poorly documented, or not aligned to the target maturity level, the organisation can lose the ability to bid at the contract level it is pursuing.


Technical breakdown

What the CMMC pause actually changes in assessment flow

The Department of Defense has suspended only one element: the mandatory third-party assessor organization requirement for CMMC Level 2 contracts. That does not remove the Level 2 control baseline, and it does not eliminate self-assessments or government-led spot checks. In practice, the assessment model becomes more flexible while the control objective remains fixed. Contractors still need evidence that the required controls exist and that posted scores are defensible. The difference is procedural, not structural: the audit bottleneck is delayed, but the access-control and reporting obligations are still live.

Practical implication: treat the pause as a change in assessment timing, not as a reduction in control scope or evidence requirements.

Why access control and identity proof still anchor compliance

CMMC and NIST SP 800-171 both center on who can access what, under what conditions, and with what traceability. That is why identity assurance, least privilege, multi-factor authentication, and segmentation remain relevant even when assessment mechanics shift. The DoW update also leaves DFARS reporting and annual affirmations intact, which means access governance must remain supportable under scrutiny. For contractors handling FCI or CUI, the control problem is not only security posture but evidentiary posture: can you show that access is constrained, monitored, and revocable across users, devices, and environments.

Practical implication: map identity and access evidence directly to the controls you must defend in self-assessment, reporting, and later external review.

How self-assessment changes the evidence burden for contractors

When external certification is delayed, self-assessment carries more weight, not less. The organisation must be able to prove that scores in SPRS reflect real operating conditions, especially because the Justice Department continues to pursue False Claims Act cases for inaccurate attestations. That makes control design, evidence retention, and internal review discipline essential. The operational challenge is not simply implementation but continuous substantiation. A self-assessed control set that cannot produce logs, policy records, or access proofs behaves like a weak control even if the technology is present.

Practical implication: build an evidence pack that can survive government spot checks, False Claims scrutiny, and any later return to mandatory third-party assessment.


Threat narrative

Attacker objective: The objective is to exploit the gap between claimed compliance and actual control state, creating regulatory, contractual, or legal exposure.

  1. Entry occurs through weak or misrepresented access-control posture rather than a single exploit, because the article centers on compliance exposure when contractors cannot substantiate their claims. Escalation follows when inaccurate SPRS scores or unsupported attestations create regulatory and contractual risk beyond the technical control gap. Impact is loss of contract eligibility, enforcement action, or False Claims exposure if the organisation claims compliance it cannot prove.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Assessment delays do not change the underlying governance problem. The DoW pause removes one verification step, but it does not alter the need to control access to FCI and CUI, maintain defensible self-assessments, and preserve evidence for later scrutiny. That means the real issue is not whether an assessor is present on a given date, but whether the organisation can prove that its access model still matches the contract obligation. Practitioners should read this as a warning against treating audit timing as a substitute for control maturity.

CMMC is really an identity and access governance test disguised as a compliance programme. The controls highlighted in the article center on least privilege, authentication, segmentation, and reporting evidence. Those are identity discipline problems before they are certification problems. For defence contractors, the practical conclusion is that IAM, PAM, and lifecycle controls need to be run as continuous programmes, not as project work tied only to an external assessment window.

Evidence debt: is the hidden risk created when organisations pause preparation because the audit clock moved. If the controls take six to 12 months to build, and the evidence required to defend them is not already in place, the organisation accrues a backlog that becomes harder to clear when the programme resumes. That turns the pause into a future assurance problem, not a relief valve. Practitioners should keep measuring whether the control state and the evidence state are both improving.

The policy signal is broader than CMMC. The article points to a government trend toward balancing compliance burden against demonstrable security outcomes, which can reshape how contractors think about lifecycle evidence, self-attestation, and post-incident accountability. That does not reduce the need for control rigour. It increases the value of identity programmes that can produce proof on demand, across human users and non-human access alike.

From our research:

  • The average estimated time to remediate a leaked secret is 27 days, despite 75% of organisations expressing strong confidence in their secrets management capabilities, according to The State of Secrets in AppSec.
  • Only 44% of developers are reported to follow security best practices for secrets management, exposing a significant developer behaviour gap.
  • That pattern aligns with 52 NHI Breaches Analysis, which is useful when contractors need to connect identity evidence, secret handling, and audit readiness.

What this signals

Evidence debt is the programme risk this pause can hide. If a contractor waits for the next assessment cycle to tighten controls, it may discover that the real gap is not security capability but the absence of supportable evidence when a score, attestation, or spot check arrives.

The wider signal is that identity teams supporting regulated environments need to treat access proofs, secret governance, and lifecycle evidence as continuous operational outputs. That is where access decisions become defensible under both compliance review and incident scrutiny.

When non-human identities can access contract data, the same governance discipline must extend beyond employees. That is where the 52 NHI Breaches Report becomes relevant, because it shows how quickly identity sprawl becomes an assurance problem when controls are not continuously evidenced.


For practitioners

  • Separate assessment timing from control readiness Keep CMMC Level 2 control work moving even while the mandatory C3PAO assessment is paused. Focus on the controls that support access restriction, authentication, logging, and evidence retention so the programme does not stall behind the review calendar.
  • Build a defensible self-assessment evidence pack Collect policy records, access proofs, SPRS supporting evidence, and incident-reporting artefacts in one reviewable set. The goal is to make the self-assessment supportable under a government spot check or later third-party assessment.
  • Reconcile access governance with contract scope Inventory every identity that can touch FCI or CUI, including service accounts and other non-human identities, and verify that their access matches contract need. Remove broad entitlements that cannot be justified in a self-assessment or audit trail.
  • Test your attestation before you sign it Run an internal challenge process against the SPRS score and annual affirmation before submission. If the team cannot recreate the evidence for a claimed control, the posture is not ready for external scrutiny.

Key takeaways

  • The DoW pause affects assessment timing, not the underlying requirement to protect FCI and CUI.
  • Contractors still face self-assessment, reporting, and False Claims exposure, which makes evidence quality as important as control design.
  • Teams that keep building access, authentication, and proof-of-control discipline now will be better positioned when external assessment returns.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-6Least privilege and access restriction sit at the center of the article's control discussion.
NIST CSF 2.0PR.AC-4The article focuses on identity-based access governance for protected contract data.

Map contractor access to AC-6 and verify every privileged path is justified and reviewable.


Key terms

  • CMMC Level 2 Self-Assessment: A contractor-led evaluation of whether implemented controls meet CMMC Level 2 requirements. The organisation scores its own environment and submits the result, so the quality of the evidence, scope, and interpretation directly affects whether the attestation is defensible.
  • Self-assessment questionnaire: A self-assessment questionnaire is a PCI compliance form used by organisations that are permitted to validate controls internally. It is not a substitute for security work, but a structured way to document scope, control coverage, and evidence for lower-tier PCI environments.
  • Controlled Unclassified Information: Controlled Unclassified Information, or CUI, is sensitive federal information that must be protected according to defined handling rules outside federal systems. For practitioners, the key issue is not only storage security but also proving that every system, identity, and data path in scope preserves those rules.
  • Evidence Debt: Evidence debt is the accumulation of missing, fragmented, or hard-to-assemble proof needed to show that identity controls are working. It becomes visible during audit, incident response, or investigation, and it usually signals that governance processes are not producing durable, auditable records.

What's in the full article

AppGate's full article covers the operational detail this post intentionally leaves for the source:

  • The specific CMMC 2.0 and NIST SP 800-171 access-control mapping AppGate uses for defence contractors.
  • The practical ZTNA controls discussed for least privilege, MFA, SPA, and micro-segmentation in hybrid environments.
  • The contractor-facing explanation of how self-assessments and SPRS posting relate to current DoW expectations.
  • The eBook linkage showing how the access model aligns to CUI protection requirements in practice.

👉 AppGate's full post covers the CMMC control mapping, ZTNA alignment, and contractor readiness details.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM or identity governance programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on July 30, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org