CMMC Phase II Is Paused. Attackers Aren't. Could You Prove Your Controls Are MET Today?
CMMC Phase II is paused, but DFARS 7012, NIST 800-171 and SPRS still apply. How defense contractors can prove edge-device and AI controls are MET today.
CMMC Phase II Is Paused. Attackers Aren't. Could You Prove Your Controls Are MET Today?
By Felipe Isaza, FUNCSHUN | Companion to CyberScope Weekly Vol 67
The question we hear most from defense subcontractors this month is: "With CMMC Phase II on hold, can we slow down?"
No. The pause changes the timeline for third-party certification. It does not change what you have already agreed to in your contracts, and it does not change what attackers are doing to the systems that hold your Controlled Unclassified Information (CUI). This post explains what still applies, where this week's threats land, what an assessor or prime will ask you, and six actions to take now.
Why the pause doesn't pause your obligations
If your contracts include DFARS 252.204-7012, you are still required to:
- Implement NIST SP 800-171 on every system that processes, stores or transmits CUI.
- Report cyber incidents to DoD within 72 hours of discovery.
- Preserve images of affected systems for 90 days, and give DoD access when it asks.
If you have a DFARS 252.204-7019/7020 clause, your SPRS score is a signed self-attestation. DoD CIO guidance on the CMMC program states that the Phase II pause does not remove these DFARS obligations.
So the real risk isn't a missed certification date. The risk is an SSP that says a control is MET when the evidence says otherwise. You find out which one is true on the day an incident starts the 72-hour clock.
This week's threat pattern: the edge and the agent
Vol 67 covers five stories, and they all follow one pattern. Attackers are going after the systems that sit between the internet and your CUI, and they are using automation to move faster.
Remote-access gateways. CISA confirmed active exploitation of critical zero-days in Citrix NetScaler ADC and Gateway. It told organizations to check for compromise before patching so they don't destroy evidence. For a DIB company, that gateway is often the front door to the CUI enclave.
VPN credentials, not just CVEs. In a joint advisory, the FBI and U.S. Secret Service warned that the FortiBleed campaign against exposed FortiGate VPNs is causing account lockouts and opening the door to ransomware. It relies on reused credentials and legacy password storage. Patching alone doesn't fix stolen credentials.
Build servers as a supply-chain path. BleepingComputer reported that CISA has flagged a critical, unauthenticated TeamCity flaw as being used in ransomware attacks. If you or your subcontractors build software for DoD programs, a compromised CI/CD server puts your code, signing keys and stored secrets at risk.
AI on both sides. Anthropic's threat intelligence reporting describes threat groups running autonomous AI attack frameworks. That means faster reconnaissance and exploitation of anything you expose to the internet. Separately, ABC News (Australia) reported that OpenAI notified dozens of third parties after AI agents used leaked passwords and got around controls on real systems. Any AI agent or API key that can reach CUI is now part of your attack surface. It belongs in your SSP.
None of these are exotic. They target remote access, authentication, patching, logging and incident response, which are the controls that hold up most of your SPRS score.
What a C3PAO or your prime will ask
Certification may be delayed, but scrutiny isn't. Primes are sending supplier cyber questionnaires now, and a DCMA DIBCAC assessment can happen with or without Phase II. Expect questions like these:
- "Show me your internet-facing asset inventory." Can you list every gateway, VPN, firewall and CI server, along with its firmware version and patch date? (3.4.1, 3.11.2, 3.14.1)
- "How is remote access controlled and monitored?" Show the logs, the alerting and who reviews them. (3.1.12, 3.3.1)
- "Is MFA enforced on every remote and privileged login?" That includes VPN admin interfaces and service accounts, not just Microsoft 365. (3.5.3)
- "Who has admin rights, and why?" Show least-privilege evidence for both people and non-human identities, including AI agents. (3.1.5, 3.1.7)
- "Walk me through your last incident or tabletop." Who declares the incident, who files the DIBNet report and how are forensic images preserved? (3.6.1, 3.6.2)
- "Show me the date your last vulnerability scan ran and what you did with the findings." (3.11.2, 3.11.3)
A policy document doesn't answer any of these. You need screenshots, exports, tickets and logs, with dates on them.
Six concrete actions for this week
-
Inventory and patch the edge. List every internet-facing NetScaler, FortiGate, VPN, remote-access tool and TeamCity or CI instance. Prioritize anything on CISA's Known Exploited Vulnerabilities catalog. Record the patch date as evidence. (3.11.2, 3.14.1)
-
Hunt and image before you remediate. Follow CISA's guidance and check for signs of compromise first. If anything looks wrong, capture forensic images before patching or rebuilding. That keeps your 7012 preservation duty intact. (3.6.1, 3.3.1)
-
Reset and harden edge credentials. Rotate VPN and appliance admin passwords and local accounts. Enforce phishing-resistant MFA, and remove admin interfaces from the public internet. (3.5.3, 3.1.12)
-
Review admin accounts and remote-access logs. Look for unknown accounts, unexpected configuration changes and logins from unusual locations. Document what you reviewed and when. (3.1.7, 3.3.1)
-
Close the supply-chain gap. Ask subcontractors and software vendors to attest to the patch status of their CI/CD and remote-access systems. Rotate any secrets stored in build servers. Restrict CI exposure to trusted networks. (3.13.1)
-
Put AI agents in your SSP. For every AI tool, agent or API key that could touch CUI, record an owner, its scopes and permissions, logging and an approved-use policy. If you can't name its permissions, it doesn't meet least privilege. (3.1.5, 3.3.2)
The bottom line
The pause buys time on certification. It doesn't buy time on breaches, reporting or the accuracy of your SPRS score. Run this week as an evidence check: pick five controls your SSP marks MET and try to produce the proof in under an hour. Wherever you can't, that's your priority list.
Not sure your edge devices, logs or SPRS score would hold up?
- Book a Cyber Risk Strategy Call: https://start.funcshun.com
- Run the FUNCSHUN CMMC readiness checklist: https://funcshun.com/cmmc-checklist
Felipe Isaza helps defense contractors protect CUI and stay CMMC-ready. Get threats like these every week in CyberScope Weekly.



