When CMMC Compliance Becomes a Substitute for Cybersecurity
Federal cybersecurity policy has spent years trying to convert security expectations into an auditable condition of contract eligibility. In his Washington Technology commentary, “Not Again! CMMC’s Comprehensive Review Is Déjà Vu All Over Again,” David Berteau argues that the Pentagon’s latest pause exposes a more fundamental problem: after repeated redesigns, reviews, and delays, the Cybersecurity Maturity Model Certification program has produced more compliance architecture than demonstrable improvement in cyber protection. (Washington Technology)
The immediate policy change is significant but narrow. On July 13, 2026, the Pentagon suspended CMMC Phase II, retained Phase I self-assessments, and created a task force to complete a comprehensive review within 60 days. During the interim, contractors remain subject to NIST SP 800-171 Revision 2 self-assessments, selected government-led assessments, and the safeguarding obligations imposed by DFARS 252.204-7012. The pause therefore changes the near-term certification pathway; it does not eliminate the underlying duty to protect covered defense information. (Defense Business Website)
Berteau’s distinctive contribution is to question whether CMMC is aimed at the full operational problem. He notes that the framework concentrates heavily on technical information at the program level, while commercial support contractors generate operational data revealing what will be delivered, where, when, and in what quantity. Food, fuel, transportation, storage, and similar services may create information with genuine mission sensitivity even when the vendors involved are not traditional defense technology companies and may never fit comfortably within a certification model designed around controlled technical information. (Washington Technology)
That observation shifts the contractor question from “What CMMC level applies?” to “What information could harm the mission if exposed?” The first question remains contractually essential. The second is the better foundation for operational security. Contractors should map data flows across invoices, schedules, logistics platforms, mobile devices, subcontractors, and cloud services; identify information whose aggregation creates sensitivity; and establish controls for detection, response, escalation, and recovery rather than relying exclusively on an assessment score. This is a practical inference from Berteau’s analysis of operational-data exposure. (Washington Technology)
This focus differs from existing FedContractPros coverage. Prior articles explain the final DFARS rule, contracting officers’ verification procedures, FCI and CUI handling, and the burdens created by fragmented cybersecurity regimes. Berteau’s commentary raises the next-order issue: whether the government is measuring the implementation of prescribed controls while remaining insufficiently attentive to changing threats, operational exposure, and actual resilience.
Contractors should not treat the review as permission to pause their own programs. A company that slows remediation because third-party certification has been delayed may remain exposed under existing DFARS clauses, inaccurate SPRS representations, incident-reporting obligations, and potential False Claims Act theories. The prudent response is to separate compliance readiness from security maturity. Maintain the evidence needed to support contractual representations, but also test whether the organization can detect an intrusion, understand what information was compromised, contain the event, preserve evidence, notify required parties, and continue mission-critical performance. (Defense Business Website)
Credit is due to Berteau for identifying the central policy risk. Certification can validate whether specified controls exist at a point in time. It cannot, by itself, guarantee that a contractor can withstand the threats of today or adapt to those of tomorrow. (Washington Technology)
Recommended FedContractPros.com Product
The FedClause360 FAR & DFARS Compliance Tracker is the most directly relevant product because the Phase II suspension does not erase the contractor’s existing clause obligations. FedClause360 separately tracks FAR 52.204-21 and DFARS 252.204-7012, 252.204-7019, 252.204-7020, and 252.204-7021, with fields for responsible owners, required actions, status, and supporting evidence. Its proper role is to establish traceable compliance governance—not to substitute documentation for effective cybersecurity controls.
Disclaimer
This blog post summarizes and comments on David Berteau’s Washington Technology article and related publicly available materials. It is not guaranteed to be complete, current, or accurate and does not constitute legal, cybersecurity, CMMC, procurement, or False Claims Act advice. Contractors should review their specific contracts, system architecture, SPRS representations, applicable clauses, and current government guidance with qualified legal and cybersecurity professionals.