Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

CMMC audit pause: are defense contractors still ready for Level 2?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 12518
Topic starter  

TL;DR: The Department of Defense has paused the mandatory C3PAO third-party assessment for CMMC Level 2 contracts while keeping Phase I requirements, self-assessments, NIST SP 800-171 controls, DFARS reporting, and enforcement in place, according to AppGate. The governance problem has shifted from audit timing to proving defensible access control, because compliance obligations did not disappear with the paused assessment requirement.

NHIMG editorial — based on content published by AppGate: What the DOW Actually Paused

By the numbers:

  • Building the necessary security controls and reaching full Level 2 compliance can take six to 12 months.

Questions worth separating out

Q: What fails when organisations treat the CMMC pause as a reason to stop preparing?

A: The failure is usually evidence, not technology.

Q: Why do access controls still matter if the third-party CMMC assessment is paused?

A: Because the security obligations remain in force.

Q: How do organisations know whether their CMMC posture is actually defensible?

A: They should be able to produce evidence for every control they claim, including access restrictions, authentication, segmentation, incident handling, and continuous compliance activities.

Practitioner guidance

  • Separate assessment timing from control readiness Keep CMMC Level 2 control work moving even while the mandatory C3PAO assessment is paused.
  • Build a defensible self-assessment evidence pack Collect policy records, access proofs, SPRS supporting evidence, and incident-reporting artefacts in one reviewable set.
  • Reconcile access governance with contract scope Inventory every identity that can touch FCI or CUI, including service accounts and other non-human identities, and verify that their access matches contract need.

What's in the full article

AppGate's full article covers the operational detail this post intentionally leaves for the source:

  • The specific CMMC 2.0 and NIST SP 800-171 access-control mapping AppGate uses for defence contractors.
  • The practical ZTNA controls discussed for least privilege, MFA, SPA, and micro-segmentation in hybrid environments.
  • The contractor-facing explanation of how self-assessments and SPRS posting relate to current DoW expectations.
  • The eBook linkage showing how the access model aligns to CUI protection requirements in practice.

👉 Read AppGate's analysis of the DoW CMMC pause and access-control implications →

CMMC audit pause: are defense contractors still ready for Level 2?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 12102
 

Assessment delays do not change the underlying governance problem. The DoW pause removes one verification step, but it does not alter the need to control access to FCI and CUI, maintain defensible self-assessments, and preserve evidence for later scrutiny. That means the real issue is not whether an assessor is present on a given date, but whether the organisation can prove that its access model still matches the contract obligation. Practitioners should read this as a warning against treating audit timing as a substitute for control maturity.

A few things that frame the scale:

  • The average estimated time to remediate a leaked secret is 27 days, despite 75% of organisations expressing strong confidence in their secrets management capabilities, according to The State of Secrets in AppSec.
  • Only 44% of developers are reported to follow security best practices for secrets management, exposing a significant developer behaviour gap.

A question worth separating out:

Q: Who is accountable when a contractor cannot prove CMMC identity controls?

A: The contractor remains accountable, because CMMC shifts eligibility from self-reporting to third-party assessment. If identity controls are incomplete, poorly documented, or not aligned to the target maturity level, the organisation can lose the ability to bid at the contract level it is pursuing.

👉 Read our full editorial: DoW pauses C3PAO audits: what CMMC changes for contractors



   
ReplyQuote
Share: