August 2026

CMMC Connect August 2026: The CMMC Pause, GCC High, and NIST SP 800-171 Rev. 3

Executive Summary

The temporary CMMC pause continues to create questions across the Defense Industrial Base (DIB). Contractors want to know whether assessments are still taking place, whether certifications completed during the pause will remain valid, and how organizations should prepare for future changes to CMMC and NIST SP 800-171.

In this month’s CMMC Connect, Redspin’s assessors and consultants were joined by Microsoft specialists to discuss ongoing CMMC Level 2 assessments, the transition toward NIST SP 800-171 Rev. 3, Microsoft GCC and GCC High environments, CUI handling, subcontractor flowdown, and certification maintenance.

The panel’s message was clear: the pause may affect the CMMC rollout timeline, but it does not eliminate existing cybersecurity obligations. Contractors should continue implementing NIST SP 800-171, preparing for assessments, strengthening evidence, and making cloud and CUI decisions based on their contracts and long-term business goals.

In This Discussion

This session answers questions including:

Are CMMC Level 2 Assessments Continuing During the Pause?

Yes.

Redspin continues conducting CMMC Level 2 certification assessments and submitting successful assessment results through the required government systems.

The panel explains that the Department of War and The Cyber AB have not instructed C3PAOs to slow or stop certification activity. Instead, the current pause is focused primarily on reviewing the program’s rollout timeline and identifying opportunities to improve implementation.

Robert Teague: “Business is driving as normal. We are still loading certificates, and we are still doing assessments.”

Some contractors have chosen to delay formal assessments until more information becomes available. However, many organizations continue moving forward because they have already invested years in preparing and want to complete certification.

The panel also notes that Department of War assessment activity is continuing. Organizations are still being contacted regarding assessments based on their SPRS scores and scheduled certification activity.

Does the CMMC Pause Mean Contractors Should Slow Down?

No.

The panel describes the current action as a pause rather than a suspension. The review appears to focus on whether the planned rollout schedule is realistic based on the number of organizations that still need certification.

For contractors that are not yet ready for assessment, the pause may provide additional time to close gaps, improve documentation, and strengthen technical implementation.

Jeremy Mares: “If you are still in the readiness phase, this essentially just gave you a longer runway. Definitely don’t take your foot off the gas.”

NIST SP 800-171 implementation remains an existing DFARS requirement. Organizations should use the additional time to prepare rather than treating the pause as permission to stop.

Are Prime Contractors Still Expecting Third-Party Validation?

According to the panel, many are.

Redspin continues hearing from large prime contractors that supply chain assurance remains a priority. Even if the federal CMMC rollout changes, primes still need confidence that subcontractors are protecting CUI and reporting accurate SPRS scores.

For many primes, an assessment completed by an experienced third party provides greater assurance than a self-assessment alone.

The panel also discusses solicitations that award additional evaluation points to contractors with a CMMC Level 2 certification recorded in government systems. These scoring practices will vary by contract, but certification may help organizations differentiate themselves from competitors.

This means CMMC certification can provide business value even before it becomes a mandatory condition of contract award across the entire Defense Industrial Base.

How Should Contractors Prepare for NIST SP 800-171 Rev. 3?

The panel expects the transition to NIST SP 800-171 Rev. 3 to require additional rulemaking, updated assessment guidance, and new training for CMMC assessors.

Although an exact implementation date has not been established, organizations can begin preparing now.

One recommended starting point is reviewing the Department of War’s organizationally defined parameters (ODPs) for Rev. 3. These parameters provide more specific expectations for how certain requirements should be implemented.

Organizations should compare the ODPs with their existing architecture, policies, procedures, and technical controls to identify potential gaps.

Dr. Thomas Graham: “Using those ODPs to help you on Rev. 2 for the items that correlate just saves you work once Rev. 3 is codified.”

Preparing early can reduce the amount of remediation required when Rev. 3 is formally incorporated into contracting and assessment requirements.

How Could the Federal CUI Rule Affect Contractors?

The proposed Federal Acquisition Regulation CUI rule could help create more consistent CUI requirements across federal agencies.

Dr. Thomas Graham: “CUI is a federal designation. It’s not a Department of Defense designation.”

The panel explains that future rules may require program managers and contracting officers to provide clearer information about:

Clearer contract-level CUI identification could help contractors better understand their responsibilities and avoid protecting information based on assumptions or incomplete guidance.

What Is the Difference Between Microsoft GCC and GCC High?

Microsoft GCC and GCC High are different Microsoft 365 environments designed to support different government security and compliance needs.

Carley Salmon: “GCC sits on Azure Commercial, and GCC High sits on Azure Government.”

The panel describes GCC as a potential option for organizations handling Federal Contract Information (FCI) or certain basic CUI use cases. GCC High is generally the stronger option when contracts involve CUI Specified, ITAR-controlled information, higher impact-level requirements, or restrictions involving foreign access.

The right environment depends on:

The panel encourages contractors to ask contracting officers and program offices what type of CUI a contract will involve instead of assuming all CUI has identical handling requirements.

Should Organizations Choose GCC or GCC High Based on Current Contracts?

Current contracts are important, but organizations should also consider future business plans.

Moving from GCC to GCC High later can require a costly and time-consuming migration. An organization that expects to pursue contracts involving CUI Specified, ITAR, Department of Energy information, or other restricted data may decide that GCC High is the better long-term investment.

Robert Teague: “Make that business decision early, and pick which one you want based on where you want your business to go in the future.”

The decision should balance current requirements, future opportunities, migration costs, customer communication needs, and the organization’s risk tolerance.

Should Organizations Choose G3 or G5 Licensing?

There is no single licensing configuration required for every CMMC environment.

The panel explains that G5 licensing can simplify security and compliance implementation by including additional native capabilities and automation. This may be especially valuable for organizations without a large internal cloud security or DevOps team.

G3 licensing combined with established security platforms may also support CMMC requirements when the organization can integrate those tools, address capability gaps, and produce clear assessment evidence.

John Fitch: “It’s a tool versus automation versus presentation decision at the end of the day.”

Organizations should evaluate:

Assessors are focused on whether the control objectives are implemented and supported by evidence, not whether the organization purchased one specific product or license.

How Can Organizations Prevent CUI From Entering the Wrong Environment?

Organizations that operate both commercial and government cloud environments need a documented process for handling CUI sent to the wrong mailbox, device, or system.

Employees should understand how to:

Technical controls can strengthen this process. The panel discusses data loss prevention, Microsoft Purview information-protection labels, conditional access, cloud access security broker capabilities, and domain-specific restrictions.

Depending on how these tools are configured, organizations may be able to block downloads, prevent external sharing, restrict access from unmanaged devices, or keep protected files from opening outside an authorized environment.

Can Contractors Use a Subcontractor That Is Not CMMC Level 2 Certified?

The answer depends on whether the subcontractor will process, store, transmit, or physically receive CUI.

If the subcontractor does not receive CUI, the related DFARS 252.204-7012 and CMMC Level 2 flowdown requirements may not apply.

Damian Golladay: “The most important question is: are you sending them CUI? If you don’t know, always reach out to the contracting officer for clarification.”

The panel cautions contractors against removing CUI markings or extracting portions of controlled drawings without confirming whether the underlying information remains CUI. Information may still be controlled even when a header or label is removed.

Physical components may also require contractual handling, tracking, return, reclamation, or destruction procedures, even when the subcontractor does not hold a CMMC certification.

Contractors should use controlled procedures and obtain contract-specific guidance before sharing information or components with an uncertified vendor.

What Happens After CMMC Level 2 Certification?

Certification begins a three-year maintenance cycle. It does not end the organization’s compliance responsibilities.

Redspin is seeing certified organizations review policies and procedures, adjust the frequency of tabletop exercises, improve reporting to leadership, and integrate CMMC activities into broader enterprise risk management.

Felice Flake: “They’re starting to understand deeply the value and how it can up their game overall for the organization.”

Maintenance activities should be sustainable and appropriate for the organization. One contractor may benefit from semiannual tabletop exercises, while another may determine that annual exercises are sufficient based on risk, resources, and operational needs.

The goal is to maintain a repeatable program that keeps controls effective, documentation accurate, personnel prepared, and leadership informed throughout the certification period.

What Training Evidence Is Needed for a CMMC Assessment?

Organizations may use government-provided training, third-party courses, or internally developed materials. However, the training must address the required awareness and training elements.

If the System Security Plan states that the organization provides additional training, such as phishing detection or social engineering awareness, the organization should be able to demonstrate that the training occurs.

Dr. Thomas Graham: “Tell us what you do, and prove to us you’re doing it that way.”

Evidence does not always require a formal certificate from a learning management system. Acceptable evidence may include:

The key is consistency between what the organization documents, what it actually does, and the evidence presented during assessment.

Common Misconceptions

Myth: CMMC Level 2 assessments have stopped.

Reality: Redspin and other C3PAOs continue conducting assessments and submitting successful certification results through the required government systems.

Myth: The pause means organizations can stop implementing NIST SP 800-171.

Reality: NIST SP 800-171 and DFARS 252.204-7012 remain applicable contractual requirements for organizations handling CUI.

Myth: Every defense contractor must use GCC High and G5 licensing.

Reality: Cloud environment and licensing decisions depend on the organization’s data, contracts, technical capabilities, existing tools, and future business plans.

Myth: CMMC work ends after certification.

Reality: Certification begins an ongoing maintenance cycle that requires continued testing, documentation, evidence collection, and leadership involvement.

Practical Recommendations

Based on the discussion, Redspin recommends that contractors:

Questions Answered

About CMMC Connect

CMMC Connect is Redspin’s monthly live Q&A series featuring experienced CMMC assessors, consultants, and industry specialists who have completed more than 100 CMMC assessments. Each session addresses the questions defense contractors are asking today, shares observations from active assessments, and provides practical guidance for navigating evolving CMMC requirements.

This month’s discussion focuses on ongoing certification activity during the CMMC pause, Microsoft GCC and GCC High decisions, CUI handling, subcontractor flowdown, certification maintenance, and preparing for NIST SP 800-171 Rev. 3.