The assessment calendar may have changed, but the obligation to protect sensitive defense information has not. Aaron Gilmore of Bees Computing explains how contractors can use the pause to stress-test their CMMC programs, close real gaps, and build readiness that does not depend on a deadline.
A pause in CMMC assessments can feel like permission to wait. For defense contractors already balancing delivery, staffing, and compliance costs, a little extra runway may look like a reason to slow implementation until the government provides more certainty.
Aaron Gilmore sees the opposite.
Aaron works in AI and automation implementation at Bees Computing, a veteran-owned consultancy helping small and midsize businesses navigate CMMC, NIST, and RMF compliance. He describes himself as a “security and technology MacGyver”—a perspective shaped in the U.S. Army Signal Corps, where he worked across communications technology, COMSEC, courier-program management, training, and security operations. Later work in classified environments reinforced the lesson that now anchors his CMMC guidance: security responsibilities do not disappear because an auditor is not scheduled to arrive.
“It’s a pause for audits, and that’s it.” — Aaron Gilmore
For Aaron, the pause changes timing and mechanics. It does not erase the obligation to protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). More importantly, it does not make a weak program safer.
Contractors that treat the pause as a readiness window can emerge with cleaner documentation, stronger evidence, clearer ownership, and fewer surprises. Those that treat it as a reprieve risk facing the same gaps under a shorter timeline when assessments resume.
The CMMC assessment delay can affect budgets, sequencing, and the order in which a contractor closes remediation items.
The mistake is translating a pause in verification into a pause in responsibility.
“They said they’re paused today. What if after this interview they announce, ‘No more pause, we’re back on,’ and now an assessor’s knocking at your door?” — Aaron Gilmore
Waiting for perfect guidance creates two problems. First, it leaves sensitive information exposed to the same operational risks that existed before the announcement. Second, it converts extra preparation time into future compression. When the external deadline returns, the organization may still need to close POA&Ms, improve its System Security Plan, clarify control ownership, train personnel, and assemble evidence—all at once.
“We still have legal obligations. We can’t wait until we have guidance. We have to act.” — Aaron Gilmore
The downside is not limited to an uncomfortable assessment. Aaron warns that knowingly ignoring obligations can threaten contracts and, in serious cases, a contractor’s ability to participate in federal work. The commercial consequence works in the other direction, too: when another supplier cannot meet a contract’s requirements, a prepared contractor may be positioned to replace it.
Readiness is therefore both defensive and strategic. It protects the work already on the books while preserving the ability to compete for what comes next.
Aaron’s classified-security background gives him a different starting point from teams that encounter CMMC primarily as a compliance exercise. In classified environments, the mission is not to pass a scheduled test. It is to protect information, people, and property every day—including when nobody is watching.
That mindset changes the central question.
Instead of asking, What do we need to do before the assessor arrives?, ask:
Would our program protect the organization and produce convincing evidence if someone checked today?
This does not make the assessment irrelevant. It puts the assessment in its proper role: an external test of a program that should already be functioning.
“If you’re looking at this not to check a box and you look at, ‘How can I improve my security program?’ you’re going to be in a much better space.” — Aaron Gilmore
That shift also makes the pause useful. Without the immediate pressure of an assessment date, teams can be more honest about what is missing. They can fail internally, learn why, and fix the problem before an external assessor turns it into a finding.
Aaron recommends using the window like a concentrated program review: establish the current state, test it rigorously, and work through improvements in coherent groups rather than bouncing randomly between requirements.
Start with the records that describe the program today:
The goal is not to produce a reassuring summary. It is to expose the real starting point.
A score or document can create false confidence if it does not match how the organization actually operates. Aaron’s approach begins by comparing the reported state with observable practice.
One of the recurring audit failures Aaron has seen is surprisingly basic: people who are supposed to own a process do not know that they own it.
Use the pause to confirm responsibility at the control and process level. For every important activity, ask:
If the answer lives only in one leader’s head, the program is fragile even when the control appears to be implemented.
This is also the right time for focused training. Do not teach CMMC only as a list of requirements. Teach each person what they are responsible for, why it matters, and what evidence their work should produce.
Aaron recommends a dry run with enough rigor to reveal uncomfortable gaps.
“Would you pass an audit? Be hard on yourself. It’s okay to fail, especially if you’re failing internally. Now you know how you failed and why.” — Aaron Gilmore
The most useful internal test is not one designed to confirm the team’s assumptions. It is one designed to challenge them.
Where possible, involve someone who is not steeped in the program. Give them a requirement and ask them to locate the evidence. If an informed outsider cannot understand what the requirement means, who owns it, how it is implemented, and where proof lives, an assessor may encounter the same problem.
A dry run should test two distinct questions:
Those are not interchangeable. Teams sometimes perform the right activity but fail to record it. Others write polished documentation that does not reflect actual practice. Assessment readiness requires the two to agree.
Aaron favors reviewing CMMC by domain rather than jumping between isolated practices or moving mechanically through levels.
“If you holistically go domain at a time—‘What do we have? Are we good?’—it’ll keep you in the mindset.” — Aaron Gilmore
This approach keeps related ideas together. A media-protection review, for example, can examine the connected policies, handling procedures, technical safeguards, roles, and evidence in one pass. An access-control review can do the same for authorization, authentication, account management, and the records that prove those activities occur.
Working domain by domain offers three advantages:
Free government and industry resources can help teams interpret individual requirements. But Aaron’s method turns those resources into a repeatable operating rhythm: choose a domain, understand the requirements, inspect implementation, inspect reporting, remediate the gaps, and retest.
A shifted assessment timeline may give teams more flexibility in how they sequence remediation. Use that flexibility deliberately.
Rather than letting the pause stall progress, evaluate which open items can be closed efficiently based on risk, dependencies, available staff, and operational impact. Some remediation work unlocks several related practices. Other work depends on a process owner, vendor, or technology change and should begin early.
The objective is not activity for activity’s sake. It is a steadily shrinking set of known weaknesses, with evidence that each correction is implemented and sustainable.
Before the last step makes sense, Aaron asks leaders to reconsider a word. He argues that cybersecurity unintentionally narrows how CMMC gets understood, because it sounds like a technical assignment for IT or a CISO. In practice, much of what the program requires concerns governance, authority, risk, personnel, physical access, media handling, and training.
Technology remains necessary, but it is one component of a broader security system. That is why ownership cannot sit with a single department, or a single person. As Aaron puts it, the goal is a culture where everyone understands that security is part of their job.
Which leads to his closing test, borrowed from software engineering: If the person who holds critical knowledge were suddenly unavailable, could someone else continue the work?
“If your CISO or your CSIM, or whoever is in charge, gets hit by the bus and is in the hospital, are you going to be able to continue your CMMC program without them? If the answer is no, you need to use the next 60 to 90 days to make that a yes.” — Aaron Gilmore
For CMMC, passing the bus test means:
This is more than business continuity. It is evidence that security has become an organizational capability rather than one person’s project.
Aaron’s playbook works because it uses uncertainty to build resilience rather than excuse delay.
It replaces deadline-driven activity with a practical operating cycle:
This sequence reduces the risk of discovering late that the SSP, the evidence, and the real environment tell three different stories. It also focuses scarce time on improvements that matter whether the next assessment happens soon, later, or under revised mechanics.
Most of all, it restores the reason the requirements exist. The purpose is not to produce paperwork for an auditor. It is to protect sensitive information, preserve the organization’s ability to perform federal work, and build a security culture that functions when no deadline is creating urgency.
Extra time only becomes an advantage when it produces a stronger program.
BEMO helps defense contractors turn CMMC requirements into an operating system the whole organization can follow—from reviewing the current state and prioritizing POA&Ms to aligning the SSP, implementation, ownership, and evidence for assessment.
Instead of waiting for the next announcement, use the window to answer the harder question: If the assessment restarted tomorrow, what would break?
Talk to BEMO about CMMC readiness → bemopro.com/compliance
No. As Aaron explains, the pause changes the timing and mechanics of audits, not the underlying responsibility to protect FCI and CUI. Contractors should evaluate their specific legal and contractual obligations with qualified counsel or compliance advisors rather than treating an assessment delay as permission to stop.
Establish an honest baseline. Review the SPRS score, SSP, open POA&Ms, control ownership, and available evidence. Then run an internal test to compare the documented program with actual operations.
Related requirements often depend on the same people, processes, technology, and evidence. Grouping the work by domain reduces context switching and makes it easier to identify dependencies and remediate gaps coherently.
It should test both whether each requirement is implemented and whether the organization can prove that implementation. A practice without evidence and documentation without real execution are both readiness gaps.
No. Technical teams play an important role, but CMMC also depends on governance, personnel, physical security, operations, training, documentation, and leadership. Aaron’s guidance is to treat it as an organization-wide security program.
The program should continue if its primary leader becomes unavailable. Roles, procedures, evidence, decisions, and backup ownership should be clear enough that another qualified person can keep essential activities running.