Blog
CMMC Is Delayed. Your Responsibility to Protect CUI Is Not!
Christopher Souza | CEO
On July 13, 2026, the Department of Defense announced a 60-day suspension of CMMC 2.0 Phase II. That same day, the NSA and its international partners warned that Russian state-sponsored actors were actively exploiting vulnerable and poorly configured networks.
Although the NSA warning focused primarily on routers, the threat was not limited to network equipment, as Russia, China, North Korea, Iran, and other nation-state adversaries continue to actively target defense contractors of ALL SIZES as well as MSPs, MSSPs and other trusted third-party providers.
The DoD has cited cost and administrative burdens in connection with its decision to postpone Phase II, but those concerns should not justify delaying implementation, as defense contractors have been contractually required to safeguard CUI and implement NIST SP 800-171 since 2017.
Building and maintaining a compliant environment undoubtedly requires significant investment however, postponing efforts does not remove contractors’ existing contractual obligations, and it certainly does not delay our adversaries from targeting our Defense Industrial Base.
The Postponement Creates a National-Security Risk
Nation-state actors are not relying on a single vulnerability or attack method as they are targeting every layer of the technology environment to gain access, exploit and steal FCI, CUI, intellectual property, and other sensitive defense information.
- Russian state-sponsored actors have used password spraying, spear-phishing, stolen credentials, known software vulnerabilities, compromised VPNs, and unauthorized changes to email systems. They also target logistics companies, MSPs, software providers, subcontractors, and other trusted partners that can provide indirect access to defense contractors.
- NPRK state-sponsored actors have targeted defense, aerospace, nuclear, and engineering organizations by exploiting vulnerable internet-facing servers and known software flaws to exfiltrate engineering documents, designs, manufacturing information, contract data, and other sensitive intellectual property.
- CCP state-sponsored actors, including Volt Typhoon, frequently use valid accounts and legitimate Windows and network-administration tools to blend into normal activity allowing attackers to remain undetected for extended periods without introducing malware that traditional antivirus software would easily identify.
- IRGC affiliated actors have targeted internet-connected programmable logic controllers and other operational-technology systems to provide pathways to sensitive information or cause operational disruption.
The safeguards required by NIST SP 800-171 are not just abstract compliance requirements, they are foundational cybersecurity protections designed to combat these real vulnerabilities Nation State threat actors present to the DIB.
For years, the DoD largely relied on contractors to self-assess and report their implementation of NIST SP 800-171, but it’s been made abundantly clear that model has failed to provide sufficient assurances that adequate safeguards are consistently implemented and operating effectively.
DoD Inspector General audits have regularly identified contractors failing to consistently implement fundamental protections, while acknowledging that the DoD lacks the effective processes to accurately verify contractor systems have met the required standards. These findings do not prove that every defense contractor is non-compliant, but they do demonstrate that the self-assessment processes has failed to provide reliable and consistent assurance across the defense supply chain.
CMMC Level 2, C3PAO certification addresses these weaknesses, but with this postponement, nation-state adversaries continue benefiting from exploiting vulnerabilities that would otherwise be remediated.
A Delay in CMMC Is Not a Delay in Responsibility
These Requirements Are Not New and the suspension of CMMC Phase II does not eliminate the contractual requirements that preceded CMMC.
Nation state threat actors pose an active threat and every one of their campaigns reinforces the need for the safeguards NIST SP 800-171 requires and CMMC is intended to validate. The most prudent use of the DoD’s review period is not to wait but continue implementing NIST SP 800-171, remediate known weaknesses, organize supporting evidence, and prepare for independent assessment. CMMC’s implementation schedule may be temporarily uncertain, but the existing contractual obligations to protect CUI, and the very real threats to our national security today, remain unchanged.
What Defense Contractors Should Be Doing Now
Organizations should use the suspension period to accelerate implementation—not pause it!
As a CMMC Registered Provider Organization, MSP, and MSSP, TSI helps contractors address both the compliance (documentation & security program) and technical requirements (IT & cybersecurity) necessary to protect FCI and CUI. TSI has helped numerous clients achieve certification and has had its own CMMC readiness independently assessed by an authorized C3PAO. We highly recommend – if you haven’t been doing so already- to use the time to evaluate the following areas:
- Identify Where CUI Exists & Shared
- Inventory Your Technology
- Fix Known Security Weaknesses
- Strengthen User Access
- Monitor Your Environment
- Separate Sensitive Systems
- Review Third-Party Access
- Prepare for a Cyber Incident
- Maintain Your Documentation
If you find yourself struggling with any of these action items, TSI has the expertise and resources to help guide you from start to finish. TSI can help contractors use this time to remediate known weaknesses, complete NIST SP 800-171 implementation, strengthen your cybersecurity posture, and prepare for C3PAO CMMC certification.
Take a look at our CMMC support plans here!
Contact TSI Today!
The path to CMMC certification is a considerable undertaking, but organizations do not have to navigate it alone. As an experienced MSP, MSSP, and CMMC Registered Provider Organization, TSI has had its own readiness independently assessed by an authorized C3PAO and has helped clients achieve certification, strengthen their cybersecurity posture, and simplify the certification process. From the day you begin developing your implementation strategy through the day you successfully complete your assessment, our team of cybersecurity and compliance experts will be there to provide the technical guidance, documentation support, remediation assistance, and validation necessary to help ensure a favorable certification outcome. Contact TSI today to discuss your CMMC readiness and take the next step toward protecting your organization, your customers, and our nation’s sensitive defense information.
About Technical Support International
TSI is 37-year old cybersecurity (MSSP) and IT support (MSP) company specializing in helping DIB organizations address their NIST 800-171 and CMMC compliance obligations. As a CMMC-AB Registered Provider Organization (RPO), TSI offers a complete NIST 800-171 and CMMC support solution to help guide our clients toward a successful certification audit and provide the assurance that they’re adhering to these expansive compliance requirements.
Categories
- Backup & Disaster Recovery
- Business Operations
- Case Studies
- Cloud Services
- Cyber Security
- Employee Spotlight
- Finance & Budgeting
- Glossary Term
- Governance & IT Compliance
- Managed Services
- Mobile Device Management
- Network Infrastructure
- NIST 800-171 & CMMC 2.0
- PCI
- Podcast
- Project Management
- TSI
- Uncategorized
- vCIO
Cyber Security Policy Starter Kit:
10 Critical Policies That Every Company Should Have in Place
