A pause in the CMMC rollout changes the timing of one verification mechanism. It does not cancel the contractual responsibility to protect controlled unclassified information. Jason Palmer, Owner at Palmer Computer Services, explains why contractors should use the pause to document what already exists, close the gaps, and build a security program they can defend.
Key Takeaways
- A pause is not a cancellation. NIST 800-171 and contractual requirements for protecting CUI predate the current CMMC rollout.
- CMMC becomes a business problem when certification determines whether a contractor can compete for multimillion-dollar defense work.
- Most companies already have many security basics in place. Their largest readiness gap is often formal documentation.
- The framework can create a useful security baseline, but it is not the end of a mature security program.
- CUI location and the real system boundary should guide technical control decisions, including how FIPS encryption is applied.
- Six plain-English actions can simplify much of the evidence problem: identify, authenticate, authorize, monitor, document, and prove periodicity.
Table of Contents
- A Pause Is Not a Cancellation
- Why CMMC Is a Business Problem
- Compliance Can Create a Security Baseline
- Documentation Is Where Most Companies Fall Short
- Start With Where the CUI Lives
- Read the Control Verbs Literally
- Build a Program You Can Explain and Defend
The announcement of a CMMC pause produced two very different reactions. Some contractors saw additional time to improve their programs. Others treated the pause as evidence that the underlying requirement had disappeared.
Jason Palmer, Owner at Palmer Computer Services, sees the second interpretation as the dangerous one. The rollout of an assessment or certification mechanism can move. The contractual responsibility to protect controlled information remains.
His advice for contractors is not built around a countdown. It is built around the environment they already operate, the representations they already make, and the evidence they will eventually need to produce. The most useful work during a pause is the same work that improves security at any other time: understand where CUI lives, document the controls already in place, close the missing gaps, and make every important practice repeatable.
A Pause Is Not a Cancellation
“The most important aspect of the pause that people seem to forget is it is a pause, not a cancellation,” Palmer says.
The distinction is simple, but its implications are easy to miss. Palmer points back to the contract requirements surrounding NIST 800-171 and the protection of controlled unclassified information. Those requirements were already present before the current CMMC rollout became the center of the conversation.
A contractor may receive more time before a particular certification event, but that does not create permission to stop protecting CUI. The contract remains the first source of truth.
Why CMMC Is a Business Problem
“Unfortunately, it is a business problem, and the government made it a business problem even though they framed it as a cybersecurity problem,” Palmer says.
The business consequence becomes clearest when CMMC Level 2 appears inside a multimillion-dollar opportunity. Certification is no longer an abstract security goal. It is a condition attached to the work the company wants to win.
That moves ownership beyond IT. Technical teams still implement and operate many of the controls, but executives own the contract risk, the investment decision, and the consequence of being unable to bid.
For the C-suite, the useful question is not whether CMMC belongs to cybersecurity or compliance. It is whether the organization can protect the information it receives and prove that protection well enough to remain eligible for the work.
Compliance Can Create a Security Baseline
Palmer does not treat compliance and security as opposing goals. Done well, the framework forces a company to organize and improve security work that may already be happening informally.
“Once you meet the framework requirements, you will be cyber secure, at least to the limits of that particular framework,” he says.
Following the framework means documenting existing controls, cleaning up inconsistent practices, understanding where evidence lives, and filling missing buckets. The result is not perfect security. No framework can define every action an organization should take against every threat.
It is, however, a meaningful baseline. The certificate becomes the visible outcome of a program that is easier to understand, operate, and improve.
Documentation Is Where Most Companies Fall Short
Many contractors approach CMMC as if they are starting from zero. Palmer's experience is often the opposite. Companies already have endpoint protection, backups, multi-factor authentication, complex passwords, incident response planning, and controls required by cyber insurance.
What they may not have is a formal record that describes those controls, assigns ownership, and preserves the knowledge required to operate them.
“CMMC is the ability for the C-suite, the people in charge, management, to be able to document their network and leave behind institutional knowledge,” Palmer says.
That institutional knowledge matters beyond an assessment. If an IT director or another key person becomes unavailable, leadership should be able to open the documentation and understand what the organization is supposed to be doing.
Documentation is not paperwork added after the security program is built. It is part of the operating system for the program itself.
Start With Where the CUI Lives
Technical control decisions become difficult when teams discuss the requirement without first defining the boundary.
“You need to understand where the CUI sits to determine whether or not it's a problem,” Palmer says.
His FIPS encryption example shows why. A set of machines could not enable FIPS encryption because of an application conflict. The answer required more than reading a FAQ. The team had to understand the enclave, who could access it, where data could leave, and where information could be intercepted.
Wireless traffic, external media, internet connections, VDI, and cloud services were FIPS encrypted. Inside the highly secure, air-gapped enclave, Palmer made a different determination after the position was heavily vetted. The control was trending met, and the client passed.
The lesson is not that contractors should search for exceptions. It is that a control implementation has to be defensible against the real environment, not an imagined one.
Read the Control Verbs Literally
CMMC can feel complicated because each control arrives with technical language, evidence requirements, and assessment objectives. Palmer simplifies much of that work by focusing on the actions the control asks the organization to perform.
Those actions usually fall into six categories:
- Identify: show a detailed list.
- Authenticate: confirm the user identity and validity of credentials.
- Authorize: demonstrate permission and role-based access.
- Monitor: show logging, alerting, and proactive scanning tools.
- Document: show a policy, procedure, plan, ticket, workflow, or sign-off.
- Periodicity: prove that the required task happens within the specified timeframe.
“Follow the English definitions and you are 95% of the way to solving all your documentation problems and evidence problems,” Palmer says.
The words are not trying to hide a second meaning. Each verb points toward an action and the evidence required to prove it happened.
Build a Program You Can Explain and Defend
The most productive response to a CMMC pause is not to stop. It is to improve the parts of the program that remain valuable regardless of when the next verification event arrives.
That means knowing which contractual requirements apply, where CUI lives and moves, which controls already operate, which gaps remain, and who owns the evidence. It also means ensuring the documentation describes the same environment the technical team actually runs.
BEMO's security-first approach starts from that operating reality. BEMO helps defense contractors configure the Microsoft 365 environment, organize the compliance layer, coordinate the C3PAO, and operate the program after certification. The goal is not to produce a certificate that sits apart from the business. It is to build security that can be explained, demonstrated, and maintained.
The CMMC timeline can change. The need to protect controlled information, preserve institutional knowledge, and defend the organization's security representations does not.
Frequently Asked Questions
Does the CMMC pause cancel a contractor's obligation to protect CUI?
No. Palmer distinguishes the pause from a cancellation and points to the NIST 800-171 and contractual requirements that were already in place before the current rollout.
Why is CMMC a business problem?
Because a CMMC Level 2 requirement can determine whether a contractor is eligible to compete for defense work. That makes readiness an executive and revenue concern, not only a technical assignment.
Are most companies starting their CMMC programs from zero?
Not necessarily. Many already have endpoint protection, backups, multi-factor authentication, incident response planning, and other security basics. The missing piece is often formal documentation that accurately describes those controls.
Does meeting the framework make an organization completely secure?
No. Palmer describes the framework as a good baseline. It can improve the security program, but it does not represent everything an organization should do.
Why does CUI location matter?
The location and movement of CUI define the system boundary and help determine where controls such as FIPS encryption need to operate.
How can teams simplify CMMC evidence collection?
Palmer recommends reading the control verbs literally: identify, authenticate, authorize, monitor, document, and prove periodicity. Each verb indicates the action and evidence the assessor expects.
Top 10 Posts
-
Office 365 MFA Setup: Step-by-Step Instructions
-
CMMC Phase 2 Suspended: What the Compliance Pause Changed
-
Google Workspace to Office 365 Migration: A Step-by-Step Guide
-
What is The CIA Triad?
-
SharePoint vs. OneDrive (What's the Difference Again?)
-
How Much Does ISO/IEC 27001 Lead Auditor Certification Cost in 2025?
-
What is Microsoft Purview ? Your A to Z Guide to Getting Secure Fast
-
How to Migrate from GoDaddy to Office 365
-
How to Set Up Office Message Encryption (OME)
-
When Will CMMC 2.0 Be Required for DoD Contracts?



Leave us a comment!