A pause in the CMMC rollout can slow assessments without removing the obligations contractors and primes are already enforcing. Ari Margolin, Cyber Security Consultant at Corniche Consulting, explains why the market has shifted rather than stopped, where readiness breaks during assessment, and why CMMC has to be owned as a business program.
The word “pause” sounds like permission to wait. Inside the defense industrial base, the reality is more complicated.
Some organizations are treating the CMMC Phase 2 pause as extra implementation time. Others believe the program may be suspended entirely. At the same time, primes are still telling suppliers that their contractual obligations remain in place and that they need to be ready to demonstrate compliance.
Ari Margolin has spent eight years in cybersecurity and IT, including three years working in CMMC as both an implementer and a lead assessor. That experience gives her a view from both sides of the table. She sees where contractors struggle before an assessment and what happens when their documentation, scope, and leadership structure are tested in practice.
Her conclusion is not that nothing changed. Assessment activity has slowed in parts of the market. Her conclusion is that the market shifted rather than stopped, and contractors should not confuse a change in rollout timing with the disappearance of the underlying business requirement.
Ari was actively conducting assessments when she heard about the pause. The first response she observed was confusion.
Some OSCs assumed they no longer had to implement CMMC. Others interpreted the pause as more time. Primes were taking a different position, pointing suppliers back to contracts that already included DFARS obligations and continuing to request SSPs, POA&Ms, and readiness for third-party assessment.
“So it has not been suspended,” Ari says. “And in fact, I think that the market has shifted.”
She is currently helping an organization that needs its assessment completed within three months. That demand exists even while C3PAOs experience a broader slowdown.
“But within the OSC world and within the DIB, it is still very much in force,” she says. “People who think that it won't be in force, I vehemently disagree.”
The practical lesson is to start with the contract and the customer, not the headline. A rollout schedule may affect when a certification mechanism appears in an award. It does not automatically change what a prime expects a supplier to demonstrate today.
When Ari evaluates an organization as an assessor, the system security plan is often the first warning sign.
“Their SSPs are not at a standard that I would consider assessable,” she says.
One common pattern is a document that refers the reader to a policy, which then refers to another policy or procedure. The contractor has technically documented where information should exist, but the organization cannot retrieve the answer quickly when an assessor asks how a control operates.
That problem becomes sharper when the SSP is written only at the control level. The control provides the general subject, but the assessment examines the underlying objectives line by line. For NIST 800-171 Revision 2, that means an organization is preparing for 320 objectives, not merely 110 control headings.
Ari’s shorthand for the warning sign is memorable: “I already know if the SSP is interesting, we're gonna have a bad time.”
An assessable SSP should describe the real environment clearly enough that the organization can answer questions, locate evidence, and explain how each objective is met without chasing a chain of references.
After kickoff, Ari moves into scoping. That is where she catches many of the most important mistakes and, in some cases, tells an organization it is not ready to spend money on an assessment.
“The scoping is where we catch most of the mistakes,” she says.
The first question is basic: where do you keep your CUI? Contractors often struggle to answer because the information was not labeled correctly by the government or the prime, or because the organization has never traced how the data moves through its environment.
The next problem is the boundary. Legacy machinery, warehouses, specialized assets, on-premises systems, VLANs, cloud services, and government-furnished equipment can all complicate the picture. A device may interact with CUI without being designed to process it. That does not make it irrelevant. It means the organization needs to understand the interaction and manage the risk.
A scope that exists only in a diagram will not survive a live assessment. The SSP, asset inventory, network architecture, data flow, and actual operating environment need to tell the same story.
The largest organizational problem Ari sees is leadership treating CMMC as IT’s responsibility.
“The organization says ‘this is an IT project,’ and CMMC is not.”
Many technical controls can be inherited from platforms such as GCC High or AWS GovCloud. Ari calls that the easy part. The harder questions sit with organizational leadership.
How does the business characterize risk? Is there a disaster recovery plan or business impact analysis? Does everyone know who to call after an incident? Can the company meet a 72-hour reporting obligation? Who is accountable for the SPRS score and other representations made to the government?
These decisions cannot be delegated to technology. IT can configure tools and operate controls, but leadership has to establish risk tolerance, ownership, and accountability.
This is also why treating CMMC as a checklist fails. A checklist can show that a task was marked complete. It cannot prove that leadership understands the risk, that the response process works, or that the environment operates the way the documentation claims.
As an implementer, Ari explains CMMC as a set of concentric shells.
At the core is CUI. “You are specifically doing this CMMC to protect CUI,” she says. The first implementation question is therefore where that information will live. Will it be printed, stored in SharePoint, sent through email, received through priority mail, or saved on a desktop?
The next shell contains the security protection assets. These include SIEM platforms, DLP, encryption, MFA, storage controls, and the other capabilities used to protect the information at the center.
Outside that sit specialized assets and contractor risk-managed assets. Machinery, legacy technology, and other devices may interact with CUI even if they were not designed to do so. Those interactions have to be understood and mitigated through technical controls, policies, procedures, and the risk register.
Once the organization can map those layers, it can establish the boundary. Everything outside the boundary is out of scope. Everything inside is in scope, even though not every in-scope asset is itself a CUI asset.
This method starts with the information and the real workflow rather than starting at the top of a control list. It gives technical teams and business leaders a shared picture of what they are protecting and why.
CMMC is usually presented as a cost, deadline, or threat to contract eligibility. Ari also sees a positive business effect.
“What CMMC allows is actually a level playing field,” she says.
Defense contracting was historically a closed door dominated by a limited group of large companies. CMMC and NIST 800-171 do not remove every barrier, but they give smaller businesses a defined standard they can choose to meet. That creates a way to demonstrate readiness and compete for pieces of government contracts.
Ari helped one organization achieve a 110 score. It later participated in a major contract replacing infrastructure for the FAA. Compliance was not the only reason the relationship developed, but the organization’s initiative and foresight helped establish credibility.
For an executive, that changes the business case. Readiness protects existing eligibility, but it can also support entry into opportunities that once felt inaccessible.
Ari describes her work as translation. She translates CMMC language into plain English and into processes that organizations already understand.
That often starts with familiar practices. Personnel security begins with background checks. Security awareness begins with the training employees already complete. Harder control families come later, after the organization understands why policies and procedures have to be written down rather than left as convention.
Most organizations already have ways of working. The assessment problem is that those ways of working may not be documented, consistently applied, or connected to objective-level evidence.
The goal is not to create paperwork around an IT project. It is to build a business system that leadership can explain, employees can follow, and assessors can verify.
A pause may change timing, but it does not change the need to know where CUI lives, how it is protected, who owns the risk, and whether the organization can prove what it has represented.
BEMO builds and operates the security program continuously, maintains the SSP and evidence alongside the environment they describe, and coordinates the C3PAO process so contractors are prepared whenever the requirement reaches their contract.
Does the CMMC pause mean contractors can stop implementing controls?
Not necessarily. Ari sees primes continuing to enforce contractual expectations and organizations still working toward assessments on short timelines. Contractors should review their contracts and customer requirements before slowing down.
What is the most common SSP problem?
Many SSPs contain chains of references rather than objective-level explanations of how controls operate. That makes it difficult for the organization to answer assessor questions and produce evidence efficiently.
Why is CMMC scoping difficult?
Organizations may not know exactly what information qualifies as CUI or where it is stored, processed, and transmitted. Legacy systems, machinery, cloud tools, and specialized assets can make the boundary more complex.
Why is CMMC not an IT project?
Technical implementation is only one part of the program. Risk decisions, incident reporting, business continuity, contractual representations, and accountability require organizational leadership and cross-functional ownership.
How should an organization begin scoping CMMC?
Start with CUI. Identify where it enters the business, where it is stored, how it moves, and which assets protect or interact with it. Build the scope outward from that core.
Can CMMC create a competitive advantage?
Yes. A defined, demonstrable readiness standard can help smaller businesses establish credibility with primes and pursue government contract opportunities that might otherwise remain inaccessible.