Cybersecurity Blog

Build What You Can Defend, Not What You Can Certify

Written by BEMO | Sep 17, 2026

 CMMC didn't invent the obligation to protect controlled information, and a paused rollout doesn't retire it either. Scott Palmer, a lead CMMC assessor at Lifecycle Engineering, explains why the compliance programs that survive scrutiny are the ones built to be defended, not just certified. 

Key Takeaways

  • DFARS 7012, 7019, and 7020 required contractors to safeguard covered information years before CMMC existed, and a pause in the CMMC rollout does not pause those underlying obligations.
  • DIBCAC assessments move through three confidence levels: basic (self-reported), medium (documented and explained), and high (demonstrated), and each level raises the bar on what has to hold up.
  • A weak assessment score does not automatically mean fraud. False Claims Act exposure requires a knowing misrepresentation, not merely a gap in the program.
  • Checking your own work means reconciling your SPRS score against your SSP, your evidence, your POA&M items, and any architectural changes, not just repeating the number.
  • Compliance programs that live entirely inside IT create a bottleneck. Protecting CUI requires the FSO, cybersecurity, contracts, and legal working from the same picture.
  • The standard to build toward isn't whether you can pass an assessment, it's whether you can defend what you've represented if the government asks you to demonstrate it tomorrow.

Table of Contents

  1. CMMC Is Not Where the Obligation Begins
  2. The Contractual Backbone Nobody Reads Twice
  3. When a Bad Score Isn't Fraud (and When It Could Be)
  4. How to Check Your Own Work Before the Government Does
  5. Why This Can't Stay an IT Problem
  6. Build What You Can Defend

Most conversations about defense-sector cybersecurity start and end with CMMC. That's understandable. It's the newest name, the one with a certification attached, the one that shows up in RFPs.

Scott Palmer, lead ISSO and lead CMMC assessor at Lifecycle Engineering, a C3PAO, thinks that's the wrong place to start. In his view, CMMC is a relatively recent chapter in an obligation that has existed for years, and treating it as the whole story is exactly what leaves contractors exposed when a pause, a DIBCAC visit, or a government inquiry arrives.

His read on the current CMMC Phase 2 pause is practical rather than reassuring. It's not new, it's not the end of the underlying requirement, and it's not a reason to slow down. What follows is his walkthrough of where the obligation actually comes from, what the government can already do to verify it, and what a defensible program looks like in practice.

 

CMMC Is Not Where the Obligation Begins

"CMMC is not the beginning of the story," Palmer says. "When we talk about cybersecurity in the defense industrial base, lately almost every conversation seems to begin with CMMC. But CMMC isn't where cybersecurity obligations began when it comes to protecting CUI."

That distinction matters because it changes what a pause in the CMMC rollout actually means. CMMC is one mechanism for verifying an obligation. It isn't the obligation itself. Palmer's approach with clients navigating the current pause is to work backward from the questions he's fielding most: DIBCAC's involuntary assessments, and the DOJ's use of the False Claims Act in cybersecurity matters, both of which sit alongside CMMC rather than inside it.

 

 

The Contractual Backbone Nobody Reads Twice

The obligation Palmer is describing starts with DFARS 7012, which requires contractors to provide adequate security on covered contractor information systems. NIST 800-171 is the best-known piece of that, but 7012 also covers incident reporting, evidence preservation, forensic cooperation, cloud service requirements, and flow-down obligations to subcontractors.

"No matter what happens after the pause, you have to look at your contracts," Palmer says. "If 7012 applies, the underlying safeguarding obligation doesn't disappear. The current DFARS clauses still require adequate security."

DFARS 7019 is what makes that obligation visible to the government: contractors need a current NIST 800-171 DoD assessment on file, scored in SPRS, before they can be considered for award. Palmer is careful about the label. "A basic assessment is a self-assessment," he says. "The current DFARS explicitly assigns it a low confidence level because it is self-generated. Low confidence is not an insult to the contractor. It's the nature of the self-assessment."

DFARS 7020 is where that confidence gets tested. It gives the government a mechanism to verify what a contractor has reported, through DIBCAC assessments at three levels:

  • Basic: the contractor's own self-assessment. Low confidence by design.
  • Medium: DIBCAC reviews the basic assessment, conducts a thorough document review, and discusses the environment with the contractor.
  • High: adds a verification, examination, and demonstration of the SSP, confirming the NIST 800-171 requirements are actually implemented as described.

Palmer summarizes the progression simply: "Basic, tell me what you implemented. Medium, show me the documentation and explain it. High, show me, explain it, and demonstrate that the environment actually operates the way you've described. This is why evidence matters."

 

 

When a Bad Score Isn't Fraud (and When It Could Be)

The DOJ's Civil Cyber Fraud Initiative, launched in 2021, put a sharper edge on what happens when a cybersecurity representation turns out to be wrong. Palmer's read on it is deliberately calibrated, because he sees the fear-based version of this conversation doing more harm than good.

"I'm not a legal expert, but what I can tell you as an assessor is a bad assessment score does not automatically mean fraud," he says. "Failing a cybersecurity requirement does not automatically create False Claims Act liability."

The word doing the work in the DOJ's enforcement language is knowingly. "This is why I don't like fear-based messaging around the False Claims Act," Palmer says. "The message should not be miss a NIST control, and you're committing fraud. That's not accurate. But the opposite extreme isn't responsible either."

Every cybersecurity program has gaps, Palmer says, and he sees it constantly as an assessor. The distinction he draws is about what happens after a gap is found: "The lesson is know what you're representing, and when you discover that a material representation is inaccurate, treat that as a governance issue, not merely a technical ticket sitting in someone's queue."

 

How to Check Your Own Work Before the Government Does

Knowing what you're representing isn't a one-time exercise. Palmer's advice is to treat an SPRS score as a claim that has to be actively defended, not a number that gets filed and forgotten.

"Don't just say, our SPRS score is one ten, we're good," he says. "You have to follow up on that." That means going back to the SSP the score corresponds to: which systems it covers, when the assessment was performed, what evidence supports it, whether any POA&M items are still open, whether any significant architectural changes have happened since, and whether new cloud providers or external service providers have entered the picture.

The test Palmer recommends applying is direct: "Would we be comfortable defending this score if the government asked us to demonstrate the implementation tomorrow? That's not distrust in your own environment, that's governance."

That same discipline extends past the score itself. The SSP, the asset inventory, the network and system diagrams, the data flows, the policies, and the technical configuration all need to describe the same environment. When they don't agree with each other, Palmer says, that's the gap worth finding before an assessor does.

 

Why This Can't Stay an IT Problem

Palmer's closing point is about ownership rather than technique. "When you place the burden on one department like IT, you've created a bottleneck," he says.

Protecting CUI touches more of the business than the technical stack. "To properly protect CUI, you need to bring people in from various departments," Palmer says. "The FSO has to be involved. Obviously your cybersecurity people have to be involved. Contracts, legal. You need to create a cross-functional team where all these departments are talking, all these departments are communicating."

Leaving it with one department, he says, means the business is relying on people who "don't always have the resources or the expertise to cover down on everything that ultimately CUI protection really involves." It's the same reason Palmer pushes back on business owners who treat this as purely a technical line item: a cross-functional team with executive visibility is what actually holds up when a customer questionnaire, a bid requirement, or a DIBCAC letter arrives.

 

 

Build What You Can Defend

Palmer's guidance for contractors navigating the current pause comes down to five habits: understand which contractual clauses actually apply, know exactly where CUI lives and moves, validate the score against real evidence rather than a target number, reconcile the SSP against the actual environment, and put a named owner and a review process behind every cybersecurity representation the company makes to the government.

None of that is specific to CMMC, which is Palmer's point. "DFARS 7012 established a safeguarding obligation. 7019 made the assessment visible to the acquisition process. 7020 gave the DoD mechanisms for increasing its confidence in what contractors report," he says. CMMC is one more layer on top of a structure that was already there, and a pause in one layer doesn't relieve the others.

His advice isn't to prepare for the assessor or prepare for the assessment. It's to build a cybersecurity program whose implementation and representations you can defend, because CMMC is only one form of verification, and it's not the last one the government will use.

 

Frequently Asked Questions

Does the CMMC Phase 2 pause mean contractors can stop working toward compliance?

No. Palmer is direct that the pause affects the CMMC rollout, not the underlying DFARS 7012 safeguarding obligation or the NIST 800-171 assessment and SPRS reporting requirements, which were already in place and remain active.

What's the difference between a basic, medium, and high NIST 800-171 DoD assessment?

A basic assessment is the contractor's own self-assessment and carries low confidence by design. A medium assessment adds a DIBCAC document review and discussion. A high assessment adds verification, examination, and demonstration that the environment actually operates as the SSP describes.

Does a low SPRS score or a failed control automatically create False Claims Act risk?

No. Palmer emphasizes that DOJ enforcement under the Civil Cyber Fraud Initiative turns on knowing misrepresentation, not the mere existence of a gap. Every cybersecurity program has gaps; the risk comes from misrepresenting what's actually in place.

How should a contractor check its own SPRS score?

By reconciling it against the SSP it corresponds to: confirming which systems it covers, when it was performed, what evidence supports it, whether POA&M items remain open, and whether architectural or vendor changes since the last assessment would change the answer.

Why shouldn't CMMC compliance sit entirely with the IT department?

Because protecting CUI touches contracts, legal, and facility security as much as it touches technical controls. Concentrating the work in one department creates a bottleneck and leaves the company relying on people who were never resourced to own the whole picture.

What's the standard a defensible compliance program should meet?

Palmer's test: would the organization be comfortable defending its current representations if the government asked it to demonstrate them tomorrow. That standard applies regardless of what happens to the CMMC timeline.