Even with CMMC timelines in flux, protecting Controlled Unclassified Information (CUI) remains a binding obligation under your contracts. The pause affects how and when formal certifications are enforced — not whether you must safeguard CUI. If you hold DoD work involving CUI, your legal and operational risk hasn't been paused at all.
The Department of Defense has not suspended DFARS or NIST requirements. DFARS clause 252.204-7012 still requires contractors to provide "adequate security" for covered defense information and CUI on any system that supports the contract. That obligation exists today, regardless of when your first CMMC assessment is scheduled.
NIST's own guidance stresses that protecting CUI on nonfederal systems is critical to federal missions — not a nice-to-have that can wait for the next rulemaking cycle. The release of NIST SP 800-171 Revision 3, along with the enhanced requirements in SP 800-172r3, makes clear that expectations are rising, not fading.
The practical implication: slowing down your CUI work because CMMC is delayed doesn't reduce risk. It only compresses the time you have to close gaps before an incident, a False Claims Act inquiry, or a customer due-diligence request exposes them.
The most important clause in most defense contracts dealing with CUI is DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting. It requires you to implement the NIST SP 800-171 security requirements and to report certain cyber incidents affecting CUI.
NIST illustrates this obligation clearly in its small business and manufacturing case studies. In one Manufacturing Extension Partnership example, a supplier that drew more than 20 percent of its revenue from defense products had to implement SP 800-171 simply because DFARS 252.204-7012 applied to the systems supporting that contract (NIST MEP case study).
Similarly, NIST SP 1318 — the Small Business Primer for SP 800-171 Revision 3 — makes clear that any nonfederal organization handling CUI on an agency's behalf is responsible for applying these requirements (NIST SP 1318). CMMC doesn't replace this obligation; it layers an assessment model on top of requirements that already exist under DFARS.
If your contracts reference CUI, covered defense information, incident reporting, or NIST SP 800-171, you already have a live responsibility. The CMMC schedule only changes how — and when — the government verifies you're doing what you said you would do.
"Adequate security" is a specific term, not a vague aspiration. Under DFARS 252.204-7012, it effectively means implementing the applicable NIST SP 800-171 requirements on any system where CUI is processed, stored, or transmitted. For higher-risk programs, agencies may also require the enhanced controls in NIST SP 800-172r3 (NIST SP 800-172r3).
For a typical 100-person manufacturer or engineering firm, "adequate security" rarely means building a next-generation security operations center. More often, it means disciplined follow-through on a handful of foundational steps: defined access control, multi-factor authentication on remote and privileged access, reliable logging, timely patching, and a basic incident-response process.
NIST's small business primer breaks SP 800-171 into families that map cleanly onto real-world projects — access control, awareness and training, configuration management, and so on. In practice, that often looks like turning on multi-factor authentication in your identity provider, tightening who can see which shared drives, and documenting service-account use instead of leaving it to tribal knowledge.
The contractors who run into trouble aren't the ones missing some niche tool. They're the ones with no current System Security Plan, no Plan of Action and Milestones, and no evidence that their controls actually operate day to day.
Most leadership teams underestimate where CUI lives. They picture a single secure file share or one application. In real assessments, CUI often turns up in six or seven unexpected places across a mid-sized environment, each carrying its own risk.
CUI can sit in email threads with engineering drawings attached, in CRM notes where staff record program names and system details, or in shared drives with loosely controlled access. It can be embedded in manufacturing work instructions or machine programs that reference part numbers tied to sensitive platforms. It can even show up indirectly — in logs or ticketing systems that capture detailed error messages from CUI-bearing systems.
A practical first step: pick one key program and run a focused CUI data-flow exercise. Map how a drawing, specification, or test result moves from the DoD customer into your network, through your teams, and back out again. In many organizations, this single exercise surfaces at least three additional in-scope systems that weren't part of the original CMMC boundary.
Without that visibility, you can't credibly claim that CMMC delays reduce your risk — you may simply not know where your most sensitive contractual data is exposed.
If your team has treated the CMMC delay as a reason to pause, use the next 90 days to build momentum instead. You don't need to "finish CMMC" in this window. You do need measurable progress against obligations that are already live.
Days 1–30: Update or create your System Security Plan and run an honest self-assessment against NIST SP 800-171. Use the SP 1318 primer as a guide, especially if resources are limited. Document every gap — even a simple spreadsheet tracking each requirement, current status, and planned action is a real improvement.
Days 31–60: Focus on a small set of high-impact controls: multi-factor authentication, administrator account hygiene, regular backups, and basic incident-response steps aligned to DFARS reporting expectations. NIST's enhanced requirements in SP 800-172r3 can help you prioritize where segmentation or extra monitoring will matter most for critical programs.
Days 61–90: Run a targeted internal review. Pick one contract and trace the evidence — policies, technical configurations, and logs — that show your controls are actually operating. This is the mindset your CMMC assessor will bring, whether the visit happens in six months or two years.
This article is meant to show you that the CMMC schedule doesn't change your core responsibility: protecting CUI wherever it lives in your business. It also outlines, at a high level, what "adequate security" and a 90-day response can look like for a mid-sized contractor.
What it doesn't do is walk line by line through every NIST SP 800-171 requirement, translate each control into plain-language tasks, or hand you the sample artifacts your assessor will ask for. There's no example System Security Plan language here, no pre-assessment evidence checklist, no model incident-reporting workflow.
That's where most organizations stall — translating standards into specific documents and recurring processes takes time, and it's also where a small improvement has an outsized impact on both assessment outcomes and real security. Our downloadable guide goes deeper into those details, with concrete templates and examples tuned for aerospace, defense, manufacturing, and IT contractors.
If your team is unsure whether the current CMMC pause gives you room to wait, consider this: your contracts, your DFARS clauses, and your exposure to CUI haven't paused. The only question is whether you use this window to get ahead — or leave that decision to your next incident or audit.