CMMC phase II is paused, but the adversary threats are not

Gettyimages.com/Dragos Condrea
Contractors still holding sensitive defense data need visibility, segmentation, and containment — CMMC or not.
Nation-state actors are not pausing their operations or waiting for contractors to get their plans in order. They are attacking now, targeting sensitive defense information that can strengthen their capabilities and weaken ours.
The Department of Defense recently suspended Phase II of its Cybersecurity Maturity Model Certification program, pausing the expansion of third-party assessments for contractors handling controlled unclassified information. While the compliance process may have paused, the threats have not.
That pause reinforces that contractors cannot treat compliance as the finish line. Meeting compliance requirements does not guarantee resilience; it only establishes a baseline. To remain truly resilient, contractors need visibility into how critical systems communicate, segmentation to eliminate unnecessary pathways, and containment capabilities to stop an attack from becoming a mission-wide failure.
Attackers are stealing a strategic advantage
Defense contractors hold sensitive government information, including weapons-system designs, technical specifications, operational data, supply chain communications, and critical infrastructure details.
Nation-state actors target this information because it can strengthen both their offensive and defensive capabilities. Stolen technical data can help an adversary replicate or improve advanced systems, refine its own military capabilities, and better understand how U.S. technologies are designed to operate.
That same information can also reveal weaknesses, dependencies, and potential points of failure, enabling adversaries to develop countermeasures and improve their defenses against U.S. weapons and systems.
Because contractors often support multiple defense programs, one attack can give adversaries access to a broader set of sensitive systems and data, increasing the potential impact on national security and mission readiness.
AI is shrinking the defense window
Artificial intelligence is making the threat move faster. We have seen that evolution with Anthropic’s Mythos and the OpenAI–Hugging Face incident. While AI may make attacks faster and more automated, the underlying techniques remain familiar: exploiting vulnerabilities, abusing credentials, bypassing traditional prevention, and moving through connected systems to reach valuable data.
AI increases the speed and scale of an attack without changing the basic path. Patching and prevention remain essential, but contractors must also be prepared to contain attacks before they move laterally and reach mission-critical data.
Containment must be the priority
Recent research highlights the containment gap: While 95% of IT and cybersecurity leaders are confident they can detect unauthorized lateral movement, 46% struggle to stop attackers once they are inside, and only 17% can isolate a compromised asset in near real time.
Detection alone cannot protect the mission when security teams lack the ability to restrict lateral movement. Contractors need to isolate compromised systems, close unnecessary pathways, and protect critical assets.
Contractors must identify which information is most sensitive, which systems cannot go down, how critical workloads communicate, and which controls can stop lateral movement.
Risk-based visibility makes those decisions possible. Understanding how users, applications, workloads, and systems connect allows teams to identify dangerous pathways and focus protections on the assets that matter most. The goal is to keep one compromised workload from becoming an enterprise-wide breach or a pathway into multiple government programs.
Segmentation is risk management
Segmentation is a strong component of CMMC, particularly for contractors supporting multiple government customers. Strong boundaries help prevent information associated with one program from becoming accessible from another environment, reducing unauthorized access and cross-program exposure.
However, many contractors are approaching segmentation in ways that make an already difficult problem unmanageable. Segmentation isn’t simple. Contractor environments include workloads with complex dependencies. Understanding those relationships and applying policies without disrupting operations takes real effort. The problem grows when contractors assume they must tackle the entire network at once, driving costly redesigns and stalled projects.
A more practical approach treats segmentation as risk management rather than an infrastructure overhaul. Contractors should start by understanding which systems actually need to communicate. Network visibility can reveal legitimate dependencies, unnecessary connections, and pathways an attacker could use to move laterally.
Teams can then prioritize the systems, users, and environments carrying the greatest mission and national security risk. They can reduce unnecessary connectivity, enforce least-privilege communication, and establish stronger boundaries around sensitive program data.
During an attack, those boundaries become enforcement policies. They isolate affected assets, restrict lateral movement, and reduce the blast radius before an adversary reaches additional systems or steals more information.
Despite the pause of CMMC, contractors remain responsible for protecting sensitive defense information. Strengthening visibility, segmentation, and containment can limit the impact of a breach, protect critical data, and keep the mission running.
By