The CMMC Pause Did Not Pause the Evidence Problem

Kiteworks' latest CMMC preparedness survey lands on a number that should make every DIB contractor, MSP, and RPO slow down: 96% of surveyed contractors said they were confident their self-attested SPRS score would hold up under review, but only 29% could point to both a current SPRS submission and use of a FedRAMP-authorized platform.

That is not proof that those contractors are careless. It is not proof that their scores are wrong. It is proof that confidence and evidence are not the same thing.

96% Confident their self-attested SPRS score would hold up under review.
60% Had a current SPRS submission, according to the same survey group.
29% Could point to both a current SPRS submission and a FedRAMP-authorized platform.

The timing matters. The Department announced on July 13, 2026 that CMMC Phase II requirements were immediately suspended. That phase had been scheduled for November 10, 2026. The same official CMMC page also says Phase I self-assessment requirements remain in place. In other words, the third-party assessment timeline changed, but the need to understand and support what you are claiming did not disappear.

The pause did not create the readiness gap. It gave teams a cleaner view of where claims still need evidence.

For MSPs and RPOs, the Risk Is Not Just Technical

Most MSPs do not wake up intending to document something false. Most contractors do not deliberately inflate a score. The common problem is more ordinary: inherited tenants, rushed onboarding, old screenshots, policy language copied from a template, and control answers that were true for one system but not for the actual covered environment.

That ordinary mismatch can still matter. The Justice Department's Civil Cyber-Fraud Initiative uses the False Claims Act to pursue cybersecurity-related fraud involving government contractors and grant recipients. Recent DOJ settlements have involved alleged failures to follow cybersecurity requirements, unsupported or false assessment scores, cloud-service compliance issues, missing security plans, and other gaps between contractual claims and implementation reality.

That does not mean every failed control is a False Claims Act case. It means the direction of travel is clear: when money, contract eligibility, and cybersecurity representations meet, evidence quality matters.

A Small Example: MS.AAD.3.1v1

Take a single Microsoft Entra ID control from CISA's SCuBA baseline: MS.AAD.3.1v1. The policy requires phishing-resistant MFA for all users. The implementation instructions point to a Conditional Access policy that includes all users, targets all resources, and grants access only with a phishing-resistant MFA authentication strength.

A checkbox answer might say: "MFA is enabled." That may be directionally useful, but it is not the same as showing that phishing-resistant MFA is enforced for all users in the relevant tenant.

Layer Weak Evidence Stronger Evidence
Policy A written access-control policy says MFA is required. The policy language identifies phishing-resistant methods and the user population it applies to.
Configuration A screenshot shows one MFA setting enabled somewhere in the tenant. Conditional Access export or ScubaGear output shows whether the required policy exists, is enabled, and applies broadly enough.
Scope The answer assumes the tenant being checked is the one that handles CUI. The evidence ties the tenant, users, privileged roles, and covered system boundary back to the readiness scope.
Remediation The POA&M says "enable MFA" with no technical target. The POA&M names the specific gap, owner, target configuration, validation method, and retest date.

This is where a technically sophisticated reader will poke holes. They will ask whether the exported result came from the right tenant, whether emergency access accounts were handled correctly, whether exclusions exist, whether report-only policies were mistaken for enforced policies, whether guest users and privileged roles are treated consistently, and whether the evidence is fresh enough to support the claim being made.

What ScubaGear Can and Cannot Prove

ScubaGear is useful because it can check a Microsoft 365 tenant against CISA's secure configuration baselines. That gives teams a much better starting point than a spreadsheet cell. But a pass/fail result for a SCuBA policy is still not a CMMC certification decision.

A clean result can support a specific assertion about a specific configuration at a specific time. It does not prove that every NIST SP 800-171 requirement is implemented. It does not prove that the system boundary is right. It does not prove that policies, procedures, training, incident response, asset inventory, evidence retention, and shared responsibility are all mature. And it does not replace the work of an assessor where an assessment is required.

That distinction is the whole point. Evidence-backed readiness is valuable because it is narrower than a promise and stronger than an opinion.

The Better Readiness Question

The useful question is not "Are we confident?" Most teams are. The useful question is: "Which claims can we substantiate today, and which ones are still resting on assumption?"

For MSPs managing multiple client tenants, this becomes an operating problem. You need a repeatable way to ingest configuration evidence, compare it against a known control expectation, identify the gap, generate a remediation item, and keep the result tied to the client, tenant, date, and scope. Without that chain, every client review turns back into archaeology.

For RPOs and consultants, the same discipline protects the advisory relationship. It keeps the conversation centered on what the evidence shows instead of what everyone hoped was true. It also makes the eventual handoff cleaner: the client can see which findings are document gaps, which are configuration gaps, and which are scope questions that need human judgment.

Try One Check Before You Trust the Whole Story

ViKeLaAi is built to help teams compare CMMC readiness claims with collected evidence and technical telemetry. Start with one concrete signal, such as a Microsoft 365 configuration check, and see whether the evidence supports the answer you would put in a readiness package.

Open CISA ScubaGear See the CMMC AI Agent

The Bottom Line

The CMMC Phase II pause may reduce immediate assessment pressure for some contractors, but it does not make unsupported claims safer. If anything, it gives the DIB a chance to fix the evidence layer before the next milestone arrives.

The teams that use this window well will not just rewrite policies. They will test the claims those policies make.

Sources