The CMMC Phase 2 pause moved one thing: the assessment. Raul Rosado, Partner at CyberCheck.One and a sitting CIO who has built security programs under GLBA, FERPA and federal banking requirements, explains what did not move, why deferring the work creates false savings, and the five steps he runs with clients before anyone calls a self-assessment complete.
Key Takeaways
- The pause reads as the government acknowledging it was moving too fast. What paused is Phase 2, the assessment. The requirements did not pause with it.
- The useful distinction is certification versus obligation. The security clauses were never removed from the contracts, so the contracts still govern what has to be true about the environment.
- Treating a pause as a slowdown produces what Raul calls false savings. The spending is deferred, but the technical debt, the missing evidence and the unsolved risk keep accumulating.
- His sequence starts with the contract, not the framework. Companies study the standard and skip the document they signed, which is the step that determines everything downstream.
- Policy describes what should happen. Evidence describes what is actually happening. An information security program is what closes the distance, and it carries across frameworks rather than one at a time.
- Technology is the enabler, not the driver. The frameworks exist to catch malicious activity, fraud and misuse of information, which is a different goal from producing documentation.
Table of Contents
- The Pause Is the Government Saying It Was Going Too Fast
- Separate the Certification From the Obligation
- Don't Make a Strategic Decision Based on the Word Pause
- The Five Steps Before Any Self-Assessment
- Policy Says What Should Happen. Evidence Says What Does.
- Technology Is the Enabler, Not the Driver
- Frequently Asked Questions
Most of the commentary on the CMMC Phase 2 pause is a timing conversation. When the third-party assessment requirement returns, what the phases look like on the other side, and how long the window is.
Raul Rosado reads it differently, and his vantage point is part of why. He is a Partner at CyberCheck.One, Puerto Rico's bilingual CMMC Registered Provider Organization, and he does that work while serving as CIO at Universidad del Sagrado Corazón. Before that he spent years in banking and fintech IT and cybersecurity, which means CMMC is not the first regulator he has had to satisfy with evidence rather than intent.
That history shows up in how he talks about the pause. He is not especially interested in the schedule. He is interested in what a contractor owes today, what an organization loses by waiting, and what separates a security program from a set of documents describing one.
The Pause Is the Government Saying It Was Going Too Fast
Raul's read on the pause is unsentimental and, in his framing, not unusual.
"How I see the pause is just a reflection on the government saying, hey, we were going too fast," he says. "This happens a lot in not just cybersecurity, but multiple sectors within the industry."
What concerns him is not the decision but the interpretation of it. "The biggest misunderstanding is treating the pause as if CMMC were canceled."
He draws the boundary precisely. What paused is Phase 2, the assessment. The requirements behind it did not go anywhere, and the work a contractor should be doing is the same work it was doing before. In his words, we are still going to be doing all the work that we should be doing.
The practical consequence is that a pause on the assessment is not permission to stop. It is a change in when someone external comes to look, and nothing else.
Separate the Certification From the Obligation
The distinction Raul uses with clients is a two-column one, and it resolves most of the confusion on its own.
"I always like to separate the certification from obligation," he says. The certification is the thing the government paused. The obligation is the thing nobody touched.
His reasoning goes to the paperwork rather than the framework. "They didn't remove the security clauses from the contracts, so we still need to look at those contracts and the information that the customers handle and all of the contractors out there."
That is the part he sees clients skip. The news covered a pause, so the pause becomes the operating assumption, and the signed agreement sitting in the contracts folder goes unread. The clauses in that agreement did not change status when the assessment timeline did.
His instruction is to keep the two categories separate on purpose: always make a key distinction between what is paused and what is still relevant.
Don't Make a Strategic Decision Based on the Word Pause
Raul opens most client conversations with one sentence now.
"Don't make a strategic decision based on the word pause."
The problem he describes is a translation error with a budget attached. It is a pause, but people are treating it as a slowdown, and a slowdown is something you can plan around. So the work moves to later, and the savings get booked today.
"This creates a sense of false savings," he says. "And that is the main issue with clients right now."
His accounting of what the deferral actually leaves behind is specific. They may defer the spending today, but the technical debt is still there, along with the missing evidence and the unsolved risk, and all of it just keeps accumulating.
That is the argument against waiting, and it is a cost argument rather than a compliance one. None of those three items gets cheaper while it sits. Evidence in particular cannot be produced retroactively for a period during which nothing was being maintained.
The Five Steps Before Any Self-Assessment
When a client asks how to use this period well, Raul gives the same five steps in the same order. The order carries as much weight as the list.
First, confirm what the contracts actually require. This is where he sees the most waste. "We've seen a lot of people just not looking at the contract and trying to see the framework per se, instead of actually following what they were signing up for." The framework describes a general standard. The contract describes the specific obligation.
Second, identify what information you are handling. Without that inventory you do not know what applies to you, or what is moving in and out of the organization. As he puts it, like any other security program, the inventory is very important.
Third, validate the boundary and the environment against what is on paper. He has seen the two diverge repeatedly, because architecture and engineering sometimes do not converge. The diagram is a description of intent. The environment is the system that exists.
Fourth, test whether the controls are actually there. Not present in the documentation, but operating and producing evidence you could show the government. That is the point at which a self-assessment starts meaning something.
Fifth, reconcile the findings and implement a remediation plan. Everything falls within continuous improvement, and knowing what is in the environment is what allows the organization to make it better and to show that it is safeguarding the information.
Notice what the sequence rules out. Steps two through five all depend on step one. Scope, boundary, evidence and remediation are all defined by an obligation that has to be read before the technical work starts.
Policy Says What Should Happen. Evidence Says What Does.
Raul does not run CMMC engagements as CMMC engagements.
"I never see my CMMC clients as just CMMC. I just treat them as any other client that I would do in any other industry."
The list behind that statement is why it holds. GLBA. FERPA. Federal requirements for the financial industry. There are a lot of regulations and frameworks out there, and in his view CMMC is just another part of how you look at the work. Building a program around one assessment is the expensive way to arrive at the same place.
Which leads to the line that defines his approach, and the one clients tend to repeat back:
"The policy just tells you what should happen, but the evidence tells what is actually happening."
Out of policy, testing and evidence together you build an information security program, and that program is what makes an organization compliant down the road. Not with one framework. With multiple frameworks.
He has a test for whether the thing exists at all, and it is deliberately uncomfortable. If your security program doesn't stop an assessor from coming in, you never had a security program. You had an assessment policy, which is a totally different thing.
The upside he points to is commercial rather than defensive. Once this is operationalized, the organization can say it has an information security program it can act on, with policies tied to it and processes actually being performed. That is business value, not paperwork.
Technology Is the Enabler, Not the Driver
The same standard applies to policy documents and to tooling, and Raul is short with both.
"If you have a policy and nobody's following it, you just have a placeholder there just saying that this is what we should be doing."
On technology, he refuses the common sequence where a purchase defines the program. "I don't see it as the main driver because the thing is that the technology shouldn't dictate what you're doing on your business." Its role is to be the enabler that lets the organization be efficient and also resilient.
He also reframes why any of this exists. Most companies are thinking about complying with cybersecurity compliance frameworks. But all of these are placed there so an organization can catch malicious activity, catch fraud, prevent misuse of information, or handle other cybersecurity issues. Compliance is the record of that capability, not the purpose of it.
Between the policy people follow and the outcomes the frameworks were built to produce, technology sits in the middle as the enabler.
Read together, Raul's position is consistent from the first sentence to the last. The pause applies to the assessment. The contract clauses stayed where they were. Deferring the work converts spending into technical debt, missing evidence and accumulating risk. And the thing worth building is a program that produces evidence across frameworks, with technology supporting it rather than defining it.
A pause on the assessment is not a pause on the obligation. The contracts still say what they said, the information still moves the way it moves, and the evidence either exists for this period or it does not. That gap cannot be filled in retroactively.
BEMO builds the security program first and operates it continuously, implementing the controls, maintaining the evidence, and coordinating the C3PAO directly. That way the program describes the environment as it runs, rather than as it was documented before someone came to look.
Frequently Asked Questions
Does the CMMC Phase 2 pause mean CMMC is canceled?
No. Raul calls treating the pause as a cancellation the biggest misunderstanding he encounters. What paused is Phase 2, the assessment. The underlying requirements and the work behind them continue.
What is still required during the pause?
The contract obligations. The security clauses were never removed from the contracts, so a contractor still has to look at what it signed, what information it handles, and what that combination requires of the environment.
What does Raul mean by false savings?
The money a company appears to save by deferring the work. The spending is postponed, but the technical debt, the missing evidence and the unsolved risk stay in place and keep accumulating, which makes the eventual cost higher rather than lower.
Where should a contractor start?
With the contract, not the framework. Raul sees organizations studying the standard while skipping the document they signed. Scope, boundary, evidence and remediation are all defined by that obligation, so reading it first determines whether the rest of the work is aimed correctly.
Why is evidence treated as more important than policy?
Because they answer different questions. The policy tells you what should happen; the evidence tells you what is actually happening. A policy nobody follows is a placeholder, and an assessment cannot verify intent.
Does a CMMC program help with other frameworks?
That is the argument for building a program rather than passing an assessment. Raul works across GLBA, FERPA and federal financial requirements, and treats CMMC as one more framework. An information security program built on tested controls and maintained evidence is what carries across all of them.
What role should technology play?
The enabler, not the driver. Technology should not dictate how the business operates. It should make the organization efficient and resilient so the practices behind the policy are sustainable.
Top 10 Posts
-
Office 365 MFA Setup: Step-by-Step Instructions
-
CMMC Phase 2 Suspended: What the Compliance Pause Changed
-
Google Workspace to Office 365 Migration: A Step-by-Step Guide
-
SharePoint vs. OneDrive (What's the Difference Again?)
-
How Much Does ISO/IEC 27001 Lead Auditor Certification Cost in 2025?
-
What is The CIA Triad?
-
What is Microsoft Purview ? Your A to Z Guide to Getting Secure Fast
-
How to Migrate from GoDaddy to Office 365
-
How to Set Up Office Message Encryption (OME)
-
Who Needs ISO 27001: Is This Critical Security Certification Right for Your Business?


Leave us a comment!