Jeremy Sadler, Lead Cyber Security Maturity Model Certified Assessor at ComplyUSA, explains why CMMC programs go off course before the technical work begins—and why a shared definition of “done” is the best defense against overspending, under-scoping, and assessment-day rework.
A pause in CMMC assessments can sound like permission to pause the work.
For defense contractors, that is the wrong lesson.
The timing may have changed, but the underlying responsibility to protect Controlled Unclassified Information did not appear with CMMC—and it does not disappear when an assessment phase slows down. What the pause has made visible is a readiness gap that was already there: too many organizations started buying tools, writing policies, or delegating controls before leadership, IT, vendors, and assessors shared the same definition of what compliance would require.
Jeremy Sadler, Lead Cyber Security Maturity Model Certified Assessor at ComplyUSA, puts the challenge in a question:
“Why weren’t you ready for it, if this has been in every DIB contract for over twenty years?”
His point is not that every contractor should already have a perfect CMMC program. It is that the obligations behind the program are not new. If readiness still collapses under scrutiny, the problem is bigger than the latest rule, tool, or deadline.
It is an expectations problem.
CMMC programs fail when “done” is undefined
A control can look simple on paper. Take password management. Ask several cybersecurity providers what a compliant implementation requires and the answers can range from a sophisticated monitoring platform that checks credentials against curated breach data to a tightly managed configuration in Active Directory with a documented review process.
Those answers may differ dramatically in cost and complexity. Neither is automatically right or wrong in every environment.
The real risk is starting implementation before anyone has established which interpretation is appropriate, defensible, and aligned with what an assessor will evaluate.
“If you and your assessor never agreed on the definition before you started building, you don’t find out you’re misaligned until it’s expensive to fix.”
That ambiguity creates two predictable failure modes.
The overbuilt program
A contractor hears that CMMC is demanding and assumes the safest path is to buy the most comprehensive solution available. A vendor recommends a premium platform, a larger managed-service package, or controls that exceed what the environment actually requires.
The organization spends more, adds operational complexity, and still may not know whether the implementation maps cleanly to the assessment objective.
Sophisticated technology can be valuable. But complexity is not the same as compliance, and expense is not evidence of readiness.
The under-scoped fix
At the other extreme, an internal team reads the same requirement, enables a setting, documents a policy, and considers the control complete. The implementation may be reasonable, but the team has not tested whether the policy, procedure, technical configuration, and evidence all tell the same story.
That gap stays hidden until an assessor asks someone to explain the control, demonstrate it, and produce proof that it operates consistently.
The problem in both cases is the same: the solution came before the standard.
Define the standard before you shop for the solution
Sadler’s strongest guidance is also the simplest: establish the definition of “done” before implementation begins.
In practice, that means the contractor should be able to answer five questions for every requirement:
- What does the control require in plain language?
- What does an acceptable implementation look like in this environment?
- Who owns the policy, operation, and evidence?
- How will the organization prove the control is working?
- What will an assessor expect to see, hear, or test?
This is not a request for an assessor to design the contractor’s system or pre-approve every implementation decision. It is a discipline for aligning the people responsible for the program around a defensible interpretation before money and time are committed.
It also changes how a contractor evaluates vendors. Instead of asking, “Can your product make us compliant?” the organization can ask:
- Which assessment objective does this recommendation address?
- Why is this level of tooling appropriate for our environment?
- What evidence will it produce?
- What process still has to exist around the technology?
- What would a simpler implementation fail to cover?
A provider that can answer those questions clearly is helping the buyer make an assessment-informed decision. A provider that relies on fear, certainty without explanation, or a one-size-fits-all package is asking the buyer to purchase confidence without a shared standard behind it.
Define the standard before you shop for the solution.
The pause exposed the cost of misplaced confidence
The most dangerous CMMC program is not always the one that has done nothing. It may be the one that has completed a checklist, purchased a platform, and accumulated documentation without testing whether the system operates as described.
That creates misplaced confidence at every level:
- Executives believe the compliance project is handled because a vendor is engaged.
- IT believes a control is complete because a setting is enabled.
- Compliance believes the evidence is sufficient because a document exists.
- Operations assumes the program belongs to security.
- Vendors assume their preferred implementation is the standard.
Assessment is where those assumptions collide.
For executives at owner-led defense contractors, the consequence is not merely a technical finding. CMMC is tied to the organization’s ability to compete for and retain work involving CUI. Misalignment can create rework, added spend, operational disruption, and uncertainty around revenue eligibility.
For IT and operations leaders, the cost appears in work that has to be redone after months of configuration and documentation. A control that was “complete” becomes a new project because the original team and the assessor were working from different definitions.
That is why speed without alignment is rarely fast. The quickest-looking route at the beginning can become the longest route to a defensible result.
Strong readiness is a shared operating standard
Sadler estimates that close to 90% of whether a CMMC program succeeds or fails comes down to whether expectations were set properly at the start.
“Not the tooling. Not the budget. Whether everyone agreed early on what ‘compliant’ actually meant.”
That does not make technology or budget unimportant. It puts them in the right order.
First, define the requirement. Then choose the implementation. Then operate the control. Then maintain evidence that the policy and the real environment match.
This is also why CMMC cannot be delegated to IT as a closed technical project. Leadership owns the business risk. Compliance interprets and organizes the requirements. IT implements technical controls. Operations and other control owners have to follow the procedures. The provider helps connect the work. The assessor evaluates whether the full system is operating as claimed.
Readiness becomes durable when all of those groups work from the same standard.
That is the larger narrative the pause should reinforce. CMMC is not a deadline exercise. It is a security and operating discipline whose assessment component verifies whether the organization can prove what it says is true.
Use the runway to replace ambiguity with evidence
A contractor does not need to respond to changing timelines with panic. It should respond with clarity.
The useful work during any pause is the work that would still matter if the assessment date moved again:
- Clarify the CUI boundary and which systems are in scope.
- Translate each requirement into language control owners understand.
- Align policy, procedure, configuration, and evidence.
- Identify where implementation choices were based on assumption.
- Test whether the person who owns a control can explain and demonstrate it.
- Challenge vendors to connect recommendations to assessment objectives.
- Document the agreed definition of “done” so it does not change with the person in the room.
None of that work depends on a countdown. It builds a stronger security program and reduces the chance that readiness has to be rediscovered under assessment pressure.
“The pause is a window, not a reprieve.”
Where BEMO fits
BEMO’s approach follows the same sequence: define the standard, build the security program, operate the controls, and maintain the evidence that shows the environment works as described.
BEMO has also completed its own CMMC Level 2 certification. That experience matters because the team has lived through the scoping, documentation, mock-audit, and assessment work it helps clients navigate. Rather than handing a contractor a checklist or a GRC platform and leaving the organization to connect the pieces, BEMO coordinates the path from gap assessment and implementation through assessment readiness and C3PAO coordination.
The objective is not to buy the most technology or produce the most paperwork. It is to create a defensible program in which leadership, IT, operations, policies, controls, and evidence all agree on what “done” means.
Find out whether your definition of “ready” will hold up.
If your team is using the current assessment pause to review its CMMC program, BEMO can help identify where expectations, implementation, and evidence are out of alignment.
Talk to BEMO about CMMC readiness → bemopro.com/compliance
Frequently asked questions
Does a CMMC assessment pause remove a contractor’s security obligations?
No. The obligations to safeguard CUI predate CMMC assessment timing. Contractors should review the requirements in their contracts and continue operating the controls that apply to their environments.
What does “define done” mean for a CMMC control?
It means agreeing on the requirement, the implementation appropriate to the environment, the responsible owner, the evidence the control will produce, and how the organization will demonstrate that the control operates as described.
Can a software platform make an organization CMMC compliant?
A platform can support control management, monitoring, documentation, and evidence collection. It cannot replace ownership, implementation, operating procedures, or the need to prove that controls work in practice.
Why is early alignment so important?
Without a shared interpretation, teams can overbuild, under-scope, or create documentation that does not match the live environment. Discovering that gap during an assessment creates avoidable rework, cost, and delay.
Who should own CMMC readiness?
Leadership should own the business outcome, while compliance, IT, operations, and other control owners share responsibility for implementation and evidence. A durable program is cross-functional rather than delegated to a single department.
Top 10 Posts
-
Office 365 MFA Setup: Step-by-Step Instructions
-
CMMC Phase 2 Suspended: What the Compliance Pause Changed
-
Google Workspace to Office 365 Migration: A Step-by-Step Guide
-
What is The CIA Triad?
-
How Much Does ISO/IEC 27001 Lead Auditor Certification Cost in 2025?
-
SharePoint vs. OneDrive (What's the Difference Again?)
-
What is Microsoft Purview ? Your A to Z Guide to Getting Secure Fast
-
How to Migrate from GoDaddy to Office 365
-
When Will CMMC 2.0 Be Required for DoD Contracts?
-
How to Set Up Office Message Encryption (OME)


Leave us a comment!