Some contractors heard “CMMC Phase Two suspension” and decided they could relax. That is a dangerous read.
In this episode of Trust Issues, Brandon and Bruno Lecoq speak with Dr. Beloved Smart about why the audit timeline may have shifted, but the responsibility to protect CUI has not gone away.
Listen to the full episode:
The suspension is not permission to relax
Dr. Smart is clear: CMMC is not disappearing.
The Phase Two rollout may be paused, but NIST 800-171 and DFARS 7012 obligations still exist for contractors handling CUI. That means companies still have to protect the data they agreed to protect.
The risk is that some organizations will relax, report inaccurate compliance, and expose themselves to bigger problems later.
The audit requirement may change but the security requirement did not.
Tools are not the same as compliance
One of the biggest gaps Dr. Smart sees is the difference between implementation and documentation.
Some organizations have the tools in place, but they cannot translate that into policies, procedures, an SSP, or a POA&M. Others have the documents, but the actual controls are not working.
Both are a problem.
CMMC is not just about buying security tools. It is about being able to show how those tools are used, managed, monitored, and connected to the requirements.
Level 1 is the bare minimum
Dr. Smart also makes an important point about CMMC Level 1.
These are foundational cybersecurity practices. They are things organizations should ideally have in place even without a CMMC requirement.
She shares the example of a $10 billion company with no real cybersecurity framework, no information security policy, and local admin everywhere.
That is not a CMMC problem. That is a basic security problem.
AI governance is already behind
The second half of the conversation moves into AI governance, and the same warning applies.
Companies may think they have not adopted AI yet, but employees are already using it. That means AI risk may already exist inside the business before leadership has created a policy, risk assessment, training program, or governance structure.
Dr. Smart’s point is not to ban AI.
It is to govern it properly.
That means understanding what tools are being used, training employees on responsible use, and making AI risk part of enterprise risk management.
Because whether the topic is CMMC or AI, the lesson is the same: saying you are secure is not enough.
FAQs
1. Does the CMMC suspension mean contractors can pause security work?
No. The audit timeline may have changed, but obligations under NIST 800-171 and DFARS 7012 still matter.
2. What is the documentation vs. implementation gap?
It is when a company either has tools without the policies and evidence to prove them, or documents that do not match what is actually implemented.
3. Is CMMC Level 1 optional?
No. Level 1 reflects basic cybersecurity hygiene that organizations should already have in place.
4. Why is security a C-suite issue?
Because security depends on budget, risk decisions, culture, and accountability, not just technical implementation.
5. Why does AI governance matter now?
Because employees may already be using AI tools, even if the company has not formally approved or governed them.
Top 10 Posts
-
Google Workspace to Office 365 Migration: A Step-by-Step Guide
-
Office 365 MFA Setup: Step-by-Step Instructions
-
CMMC Compliance Timeline: Dates, Deadlines & Phases
-
What is The CIA Triad?
-
What is Microsoft Purview ? Your A to Z Guide to Getting Secure Fast
-
SharePoint vs. OneDrive (What's the Difference Again?)
-
How Much Does ISO/IEC 27001 Lead Auditor Certification Cost in 2025?
-
When Will CMMC 2.0 Be Required for DoD Contracts?
-
How to Migrate from GoDaddy to Office 365
-
How to Set Up Office Message Encryption (OME)


Leave us a comment!