[{"data":1,"prerenderedAt":223},["ShallowReactive",2],{"navigation":3,"\u002Fblog\u002Fcmmc-phase-2-suspended-the-evidence-problem-isnt":48,"\u002Fblog\u002Fcmmc-phase-2-suspended-the-evidence-problem-isnt-surround":216},[4,23],{"title":5,"path":6,"stem":7,"children":8,"icon":22},"Getting Started","\u002Fdocs\u002Fgetting-started","1.docs\u002F1.getting-started\u002F1.index",[9,12,17],{"title":10,"path":6,"stem":7,"icon":11},"Introduction","i-lucide-house",{"title":13,"path":14,"stem":15,"icon":16},"Installation","\u002Fdocs\u002Fgetting-started\u002Finstallation","1.docs\u002F1.getting-started\u002F2.installation","i-lucide-download",{"title":18,"path":19,"stem":20,"icon":21},"Usage","\u002Fdocs\u002Fgetting-started\u002Fusage","1.docs\u002F1.getting-started\u002F3.usage","i-lucide-sliders",false,{"title":24,"path":25,"stem":26,"children":27,"page":22},"Essentials","\u002Fdocs\u002Fessentials","1.docs\u002F2.essentials",[28,33,38,43],{"title":29,"path":30,"stem":31,"icon":32},"Markdown Syntax","\u002Fdocs\u002Fessentials\u002Fmarkdown-syntax","1.docs\u002F2.essentials\u002F1.markdown-syntax","i-lucide-heading-1",{"title":34,"path":35,"stem":36,"icon":37},"Code Blocks","\u002Fdocs\u002Fessentials\u002Fcode-blocks","1.docs\u002F2.essentials\u002F2.code-blocks","i-lucide-code-xml",{"title":39,"path":40,"stem":41,"icon":42},"Prose Components","\u002Fdocs\u002Fessentials\u002Fprose-components","1.docs\u002F2.essentials\u002F3.prose-components","i-lucide-component",{"title":44,"path":45,"stem":46,"icon":47},"Images and Embeds","\u002Fdocs\u002Fessentials\u002Fimages-embeds","1.docs\u002F2.essentials\u002F4.images-embeds","i-lucide-image",{"id":49,"title":50,"authors":51,"badge":56,"body":58,"date":205,"description":206,"extension":207,"image":208,"meta":210,"navigation":211,"path":212,"seo":213,"stem":214,"__hash__":215},"posts\u002F3.blog\u002F3.cmmc-phase-2-suspended-the-evidence-problem-isnt.md","CMMC Phase 2 Is Suspended. The Evidence Problem Isn't.",[52],{"name":53,"avatar":54},"Aesir Systems Team",{"src":55},"\u002Fbrand\u002Faesir-shield.svg",{"label":57},"Insights",{"type":59,"value":60,"toc":197},"minimark",[61,73,76,79,84,99,102,105,109,112,115,118,121,124,127,131,134,137,140,143,147,150,153,161,167,188,191],[62,63,64,65,72],"p",{},"First, the short version for anyone not steeped in the national defense cyber world. The federal government built the Cybersecurity Maturity Model Certification (CMMC) program to confirm that defense contractors are protecting sensitive data. Phase 1 of the CMMC rollout requires companies in the Defense Industrial Base (DIB) to self-assess and report on their own security controls. Phase II was the step that would have brought in outside auditors to check that work. As of Monday, July 13, ",[66,67,71],"a",{"href":68,"rel":69},"https:\u002F\u002Fwww.war.gov\u002FNews\u002FReleases\u002FRelease\u002FArticle\u002F4542329\u002Fforging-the-arsenal-of-freedom-department-of-war-suspends-cmmc-phase-ii-require\u002F",[70],"nofollow","that step is now on pause, pending a 60-day review of the program",".",[62,74,75],{},"Before this Monday, many companies were working to prepare for CMMC Phase 2 external audit, so news of the pause generated quite a bit of buzz. Most of the industry analysis on this pause concerns whether formal external audits lead to a more or less secure and efficient DIB. But that conversation stops short of the real lesson here: preparing for audits as specific events is not enough. Regardless of who runs an audit and when.",[62,77,78],{},"The job of proving your security controls your work, and you must prove it continuously, not patch it together after the fact.",[80,81,83],"h2",{"id":82},"what-does-the-pause-on-cmmc-phase-2-mean","What does the pause on CMMC Phase 2 mean?",[62,85,86,87,92,93,98],{},"On July 13, 2026, the Department of War suspended CMMC Phase 2 — the stage where independent, outside auditors would have checked contractors' security before they could win certain contracts. That check was set to become mandatory on November 10, 2026. The Department's CIO ",[66,88,91],{"href":89,"rel":90},"https:\u002F\u002Fwww.linkedin.com\u002Fposts\u002Fdow-cio_today-the-united-states-department-of-war-ugcPost-7482534774574608384-dwfk",[70],"Kirsten Davies announced the pause"," and launched a 60-day task force to review the program, along with a ",[66,94,97],{"href":95,"rel":96},"https:\u002F\u002Fsam.gov\u002Fworkspace\u002Fcontract\u002Fopp\u002F89ef9bfb0834473791e991c712698d94\u002Fview",[70],"public request for input from industry"," (responses are due by August 14).",[62,100,101],{},"Note that only CMMC Phase 2 was impacted. The Phase 1 requirement for companies to attest to their own security is still in place. More importantly, the actual federal regulations that require contractors to protect federal data in the first place haven't moved an inch. The contract clause requiring the DIB to safeguard sensitive government data (DFARS 252.204-7012), the security standard behind it (NIST SP 800-171, with its 110 required controls), the yearly self-check imposed by Phase 1 — all of it still applies. Only the outside audit was paused.",[62,103,104],{},"The CMMC pause is a result of tension in the industry and the government over whether a formal external audit's security benefits are worth the cost, versus permitting companies in the DIB to run audits in-house. However, this tension still assumes that security compliance is fundamentally about being able to pass a yearly audit, with the debate being over who is conducting that audit. This is not the right way to think about compliance.",[80,106,108],{"id":107},"cybersecurity-compliance-is-a-moving-target","Cybersecurity compliance is a moving target",[62,110,111],{},"Stop thinking of compliance as something you pass and start seeing it as something you hold.",[62,113,114],{},"Your security level is constantly moving. You install a fix and it improves. A new software flaw appears, and it drops. Settings quietly drift out of place, and it drops again. Any assessment — outside or self-run — is just a snapshot of that moving picture. The outside audit was always just a snapshot someone else took at a single moment in time. Delaying the external audit requirement didn't change that picture.",[62,116,117],{},"So regardless of where the 60-day CMMC review eventually lands, the DIB still will need to deal with the burden of compliance. Adversaries do not care that you checked your controls and attested them to the government six months ago; they're going to test them right now, tomorrow, and the next day. If a cyber incident happens at your organization, the question will not be, \"Are you compliant today?\" It will be, \"Can you prove the controls you affirmed were actually operating on the day of the incident?\"",[62,119,120],{},"That question is difficult to answer well after the fact. You're in far better shape if you already have time-stamped records, captured as things happened, showing your protections were actually running that day. You want enough data to show trend lines of compliance, hopefully going up over time, showing that your organization really can handle vulnerabilities as they occur. Evidence you piece together later is weaker, harder to verify, and easier to challenge.",[62,122,123],{},"None of this is new to how the government already works. Years ago, federal security policy shifted away from one-time approvals toward ongoing, continuous oversight — the official guidance has said \"monitor security constantly\" for a long time. Taking active control means measuring continuously and fixing problems promptly, so drift stays within the risk you've actually accepted, instead of discovering, under investigation, that it didn't. The unit of work shifts from audit prep as a sprint-before-the-deadline to evidence production, a standing capability that runs whether or not anyone is looking.",[62,125,126],{},"The practical meaning of the Phase 2 suspension is not \"less compliance work.\" It is that point-in-time, audit-prep evidence is a materially weaker defense than it was. The evidence that best defends a continuous claim is evidence produced continuously.",[80,128,130],{"id":129},"what-should-the-dib-do-during-the-cmmc-phase-2-pause","What should the DIB do during the CMMC Phase 2 pause?",[62,132,133],{},"Phase 2, and the wider CMMC program, are currently in limbo. No one knows what the 60-day review task force will produce, but there are some elements to watch.",[62,135,136],{},"If the task force recommends reinstating third-party audits — perhaps with a later date or a tiered approach for smaller firms — the contractors who kept producing continuous evidence and assessment as a report they generate, not a scramble, will survive the strongest.",[62,138,139],{},"The RFI explicitly asks whether commercial cybersecurity tools could substitute for standalone assessments and whether some of the 110 controls matter more than others for actual risk reduction. If this path wins, demonstrated, current evidence of your controls becomes the currency of the new model.",[62,141,142],{},"The government has signaled real concern about smaller firms being priced out. If a tiered or streamlined version of CMMC emerges for smaller contractors, the firms that built sustainable, lower-cost evidence practices are better positioned than those who leaned on a scheduled audit date to define their compliance work. Automation makes that sustainable practice achievable without a large team.",[80,144,146],{"id":145},"how-is-aesir-systems-reducing-the-compliance-burden","How is Aesir Systems reducing the compliance burden?",[62,148,149],{},"The compliance reporting costs often overwhelm even larger and more established companies, to say nothing of the small and new businesses that the Phase 2 pause was meant to provide with some breathing room. Whatever happens to CMMC, the DoW and industry do need to find ways to reduce the burden on smaller players to ensure that innovative new companies are not boxed out of the DIB entirely.",[62,151,152],{},"We'll be direct about our position here: we build continuous compliance tooling, so we have a stake in how this conversation goes. What we can offer is the technical perspective of a team whose founders helped architect the standards that CMMC is built on — the STIGs, OSCAL, and SCAP that underpin the measurement frameworks in use today. That background informs the argument above, and it informs how our automation platform is built.",[62,154,155,156,160],{},"Traditional cybersecurity compliance verification, such as a company might struggle to do in advance of an audit, can take more than a year and cost millions. Our ",[66,157,159],{"href":158},"\u002Fplatform","platform"," and services can reduce that timeline and cost by as much as 90% — same rigor, but at mission speed.",[62,162,163],{},[164,165,166],"strong",{},"What the Aesir Systems Automation Platform does:",[168,169,170,174,181],"ul",{},[171,172,173],"li",{},"The platform automates evidence collection, analysis, and reporting across the full software lifecycle — replacing manual, sprint-based compliance work with a standing, continuous process.",[171,175,176,180],{},[66,177,179],{"href":178},"\u002Fplatform\u002Fmimir-ai","Mimir AI"," produces compliance answers with a cited source for every claim — so evidence is reviewable, auditable, and traceable to a primary standard, not generated from a generic model.",[171,182,183,187],{},[66,184,186],{"href":185},"\u002Fplatform\u002Fmimir-wellspring","Wellspring"," runs the full platform on-premises, inside your security boundary — classified and sensitive compliance data never leaves your perimeter.",[62,189,190],{},"Keep producing the evidence. Whatever gets defined next, you'll be positioned to meet it.",[62,192,193],{},[66,194,196],{"href":195},"\u002Fhow-to-engage","Talk to us about continuous compliance evidence. →",{"title":198,"searchDepth":199,"depth":199,"links":200},"",2,[201,202,203,204],{"id":82,"depth":199,"text":83},{"id":107,"depth":199,"text":108},{"id":129,"depth":199,"text":130},{"id":145,"depth":199,"text":146},"2026-07-16","The outside auditor is gone. What remains is your duty to continuously prove that your security is real.","md",{"src":209},"\u002Fimages\u002Fcompany\u002Fcmmc-model.png",{},true,"\u002Fblog\u002Fcmmc-phase-2-suspended-the-evidence-problem-isnt",{"title":50,"description":206},"3.blog\u002F3.cmmc-phase-2-suspended-the-evidence-problem-isnt","uZ0Tjjlf3xNN68clXUB3xAOgslU5QgAzKl6DQ35TM8A",[217,222],{"title":218,"path":219,"stem":220,"description":221,"children":-1},"How to Save Money, Time & Resources in Cybersecurity Compliance","\u002Fblog\u002Fhow-to-save-money-time-resources-in-cybersecurity-compliance","3.blog\u002F2.how-to-save-money-time-resources-in-cybersecurity-compliance","DevSecOps programs need an AI-native automation platform to achieve continuous authorization to operate (ATO).",null,1784603141820]