Auditen
enforcement wrap

Defense Contractors Still Bound by Security Rules Despite CMMC Phase II Pause

If you're a defense contractor and you think the pause on CMMC Phase II means you can stop spending on security controls, you've fundamentally misunderstood how this works. The rule implementation is on ice, but your data-security obligations aren't.

This is the most dangerous piece of news this week because it invites a specific kind of complacency. I saw this in 2003 during the first wave of SOX implementations. Companies thought that as long as they didn't have an active audit on the calendar, they could let their documentation slide and "clean it up" before the auditors arrived. They didn't realize that a failure in the interim isn't a paperwork error; it's a material weakness.

The claim from the NIST side is simple: the obligations remain. The evidence is in your contract. If you have federal data, you have to protect it regardless of whether there's a formal certification badge to hang on your wall this quarter.

The implication here is massive. If you stop maintaining your controls now and suffer a breach, "the phase was paused" is not a legal defense. It's an admission of negligence. You'll be looking at contract termination or, worse, False Claims Act litigation if you've been certifying compliance while secretly idling your security spend.

Some will argue that without the pressure of a formal certification deadline, there's no incentive to over-engineer controls. They'll say they're just "right-sizing" their approach.

Wrong. Right-sizing is a design conversation. Stopping work because the regulator hit the pause button is just lazy management. The cost of this mistake isn't a fine; it's the loss of your primary revenue stream at year-end when you can't prove you're a safe pair of hands.

The second-order effect here lands squarely on the insurers. Cyber insurance providers aren't going to care about the CMMC pause. They'll keep asking for proof of control effectiveness. If your internal telemetry shows a dip in security activity because you're waiting for NIST to wake up, expect your premiums to spike or your coverage to vanish.

Then we have the reality check from Kenya, where three entities were just hit with fines totaling over Sh9 million following data breaches. Toss in the Nigerian court awarding N15 million to former customers of Stanbic IBTC over privacy failures, and a pattern emerges.

Privacy enforcement isn't a Western luxury anymore. It's becoming a global tax on poor design. The cost of these findings is predictable: you pay for the records you failed to protect. If you're operating in those markets with "lite" versions of your controls, you're just budgeting for future losses.

I'm also seeing a surge in what I call control theatre regarding AI coding tools in HIPAA environments. There's a lot of talk about "zero data retention" promises from AI vendors.

A promise isn't a control.

If an AI tool claims it doesn't retain your PHI, I want to see the technical architecture that prevents it. I want to see the audit logs proving the data was purged. A marketing slide saying "we don't store your data" is worth exactly zero during a HHS OCR investigation. If you're relying on a vendor's word without a verifiable mechanism to prove the deletion, you haven't designed a control; you've just outsourced your risk to a black box.

We also have the usual noise about Flock license plate cameras in Ohio and North Carolina. The debate is currently focused on "privacy versus public safety," which is a philosophical argument. The actual controls question is simpler: who has the keys, what's the access log, and who is auditing the auditors? When an officer gets charged with a crime, as we saw in North Carolina, the first thing a competent investigator does is check if the system logs were tampered with. If you can't prove the integrity of those logs, your entire surveillance apparatus becomes a liability.

Then there's the SEC pushing MSMEs to incorporate to get better financing. This isn't about growth; it's about visibility. The SEC wants these entities in a framework where they can actually be tracked and regulated. It's easier to catch a fish in a net than one swimming in open water.

The common thread this week is the gap between what people think "compliance" is and what it actually costs when it breaks. Compliance isn't a checkbox you tick once a year; it's the constant, boring work of ensuring your design matches your reality.

If you're waiting for a regulator to tell you to start caring about your data again, you've already lost.

Watch the CMMC pause closely over the next few months. If contractors start reporting "budgetary reallocations" away from security and toward other projects, we'll see exactly who is preparing for a breach and who is just hoping they won't get caught.