Pending changes to the defense contracting regulations won’t change vendors’ responsibility to secure sensitive information.
By: Dave Dimlich
President of SD3IT
Defense contractors who have spent the last couple months in limbo over the Pentagon’s requirements for protecting Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) will soon find out, for better or worse, how those requirements will change.
On July 13, the Pentagon suspended the Phase II requirements of the Cybersecurity Maturity Model Certification (CMMC) program, which had been scheduled to take effect Nov. 10, 2026, Phase I self-assessment requirements remain in place while a task force conducts a comprehensive 60-day review of the program.
The Pentagon also set a 60-day review period, during which a task force is to develop “realistic, scalable” security measures that would lower barriers for small businesses and startups to compete for contracts, according to its announcement of the pause. The statement said CMMC has created “prohibitive compliance costs” and administrative hurdles that could force those small, innovative and non-traditional businesses out of the running for contracts and thus delay the process of getting critical capabilities to warfighters.
When the task force completes its review, Phase II assessments could look considerably different from those envisioned under the existing program. The review could also lead to broader changes in CMMC.
But what will not go away is the need to protect sensitive information. Contractors and defense officials may have objected to the process and the costs involved with CMMC, but security remains paramount. Regardless of the change in requirements, contractors still need to adhere to the essential steps of protecting sensitive information.
The Paths to CMMC Certification
CMMC has always been something of a thorn in the side of defense contractors and officials who want to streamline the procurement process. The Pentagon’s July 13 announcement, in fact, echoed many of the same complaints that have dogged CMMC since its inception in 2019. Those objections about an arduous, expensive certification process prompted a 2021 review by the Biden administration, which took eight months and resulted in the current shape of CMMC, known as version 2.0.
In anticipation of whatever changes come down the road, it’s worth taking a look at CMMC’s three current levels (down from five in its original form), and what impact they have on the contracting landscape.
At Level 1, contractors are responsible for basic safeguarding of FCI, and they must complete the applicable self-assessment and affirmation requirements. Level 1 is currently in place.
Level 2 is where things become considerably more demanding. Contractors handling CUI must meet the 110 security requirements adopted by the Defense Federal Acquisition Regulation Supplement (DFARS), Safeguarding Covered Defense Information and Cyber Incident Reporting, which are based on the National Institute of Standards and Technology (NIST)’s SP 800-171 Rev. 2. Depending on the contract, verification can involve self-assessment or third-party assessment.
The third-party assessments, involving information critical to national security, appear to be the main sticking point with the proposed CMMC changes. A C3PAO review would likely be time-consuming and expensive, and could potentially limit the number of contractors that could take part. The C3PAO audits have been paused, along with any future CMMC implementation milestones that would happen during the review.
Level 3 adds another layer of protection for the most sensitive environments, building on Level 2 with an additional 24 requirements from NIST’s guidance, and an assessment by DIBCAC, the latter of which has been paused.
Whatever shape CMMC eventually takes, the important point is that the assessment mechanism does not define the security obligation. Securing FCI and CUI should not become a checklist exercise, regardless of assessments, audits and certifications. The pause and/or transition to what CMMC will be is a good opportunity to revisit the critical issues of protecting sensitive information, including one increasingly important element.
Identity Remains a Critical Control
Managing and securing CUI involves some basic but essential questions, including:
- Where is your data?
- Who can access it?
- Which systems exchange or interact with that data?
- What happens when a device, application or machine needs to communicate with another machine?
- What happens when something changes?
- And how quickly can you identify and respond when something goes wrong?
Those are both operational and cybersecurity questions. But they are also, increasingly, about identities.
As networks outgrew traditional perimeters and expanded into the cloud, government and commercial organizations recognized the importance of focusing security on the continuous authentication and authorization of user identities, which is at the core of zero trust. But keeping up with identities can be a challenge these days.
Modern environments are full of machines talking to machines. Applications communicate through APIs. Industrial equipment communicates with control systems. Devices connect to cloud services. Artificial intelligence and other automated entities exchange data without a person involved. The number of network machine identities now outnumber human users by 109 to 1.
But many organizations still rely on static credentials, certificates, API keys and network rules to manage those relationships, which can create problems. A credential can be stolen, for instance, or an encryption key can be compromised. A device can be moved into a different environment. A legacy system may have little or no native ability to support modern security controls.
This is one reason SD3IT works with Corsha among our many partners in defense and federal civilian contracting. Corsha’s machine identity platform is designed to give organizations greater visibility and control over machine-to-machine communications, using identity-based security rather than relying solely on traditional network boundaries.
For us, the essential component isn’t a new security product. It’s the architectural approach. If you’re trying to build a zero-trust environment, for example, you need to know who is communicating with whom (or what is communicating with what) and whether that communication should be allowed. That becomes especially important in operational technology, critical infrastructure and tactical-edge environments where replacing legacy equipment isn’t always practical. Sometimes you have to secure what you already have.
Integration, a specialty of SD3IT, is essential to making this work. CMMC, like any other policy mandate requiring security and compliance, isn’t a product category but a systems challenge.
This is where integration matters, and where SD3IT’s role comes into the picture. Compliance involves infrastructure, identity, networks, applications, endpoints, data, monitoring, policies and people. And all of those pieces have to work together.
As a solutions aggregator, SD3IT works across that technology ecosystem to help organizations integrate those pieces into an environment that is secure, scalable and operationally practical. We maintain CMMC and NIST-aligned capabilities, and we understand that compliance is not something you achieve once and then forget about. The cyber landscape, threats and requirements are always shifting. An effective security program has to change with them.
Security Can’t Pause With CMMC
Whatever form CMMC takes after the current review, protecting FCI and CUI will remain an operational requirement. Assessment schedules may change, certification processes may evolve and the program itself may look different, but organizations will still need strong identity management, zero trust architectures, continuous monitoring and integrated security controls that protect sensitive information wherever it resides.
That is why organizations should use the current pause to strengthen security rather than wait for the next version of the rules.
Because the CMMC rollout can pause. The threats it was designed to address won’t.
About SD3IT
At SD3IT, we help federal agencies, defense organizations and commercial enterprises build secure, resilient technology environments that accelerate mission success. From AI-ready infrastructure and zero trust architectures to edge computing, data center modernization and systems integration, we design, drive and deliver solutions that help customers operate with confidence across today’s increasingly complex mission environments.