Webinar Recap: Beyond the Audit, CMMC, FedRAMP, and Compliance at Mission Speed

2 minutes
September 29, 2026

Procurement Sciences recently joined GovConWire and Executive Mosaic for a practical session on where CMMC and FedRAMP stand right now, what the phase two pause actually changed, and what government contractors should be doing today to stay compliant and ready.

John Bullough, Chief Information Security Officer at Procurement Sciences, led the session. Unlike most CMMC presentations, this one came from someone who lives on the security side of an AI platform used by government contractors every day, not a consultant selling assessments. The perspective was operational and candid throughout.

Where CMMC Actually Stands Right Now

The headline is straightforward: phase two is paused, but phase one remains in effect.

What phase two would have done was make level two third-party certifications a standard requirement for applicable procurements beginning November 2025. On July 13 of this year, the Department of Defense suspended that transition and any later implementation milestones. A class deviation on September 3 carried that directive into acquisition instructions. The sixty-day task force review period ended September 11 without creating a new contractor deadline.

As of the webinar, the official CMMC program page still describes the program as paused in phase one.

Why did this happen? The core problem was not with the cybersecurity requirements themselves. It was a scaling problem. The final CMMC rule estimated roughly 8,000 medium and large entities would require level two certification. The broader defense industrial base is closer to 100,000 companies. As of August, there were only about 110 capable C3PAOs available to conduct assessments. The math did not work, particularly with the November deadline approaching and smaller suppliers disproportionately affected by the timeline pressure.

What this means practically: the pause changed the schedule, not the underlying obligations. Contractors still have to protect CUI, maintain adequate security controls, keep SPRS scores current, submit annual affirmations, and comply with DFARS requirements. Level one and level two self-assessments remain in effect. In some cases, government-led assessments are required. The pause does not give anyone a clean pass.

The Terminology Has Changed Too

Two numbering systems in CMMC are easy to confuse and worth clarifying.

Phases one through four describe the acquisition rollout timeline. Levels one through three describe safeguards and assessment requirements for a specific contractor. Phase two and level two are not the same thing.

FedRAMP terminology has also shifted in 2026. What was previously called FedRAMP authorized moderate is now FedRAMP certified class C. The marketplace currently shows a hybrid listing with "moderate" in parentheses, which the program has indicated will be removed by end of year. The legacy FedRAMP Ready designation goes away entirely. There is also a new concept called FedRAMP moderate equivalent, recognized by the Department of Defense, for providers that meet the requirements and have had a recognized third-party assessment but do not yet have an authorizing agency.

If you have been using the old terminology, now is a good time to update your internal language and verify that the marketplace listings you are relying on reflect the current designations.

CUI Scope: Start Here Before Anything Else

One of the most consistent findings from contractors going through the CMMC process is that CUI is almost always more widespread than they expected. John was direct about this: a reliable compliance boundary starts with understanding the full CUI lifecycle, not just where the main application sits.

CUI can enter your environment through a contract attachment. It can move into email or collaboration tools, into engineering or business systems, into audit logs and backups, through integrations, and eventually require retention or deletion. Each step in that chain can add systems, people, facilities, and service providers to your assessment boundary.

A diagram that shows only the primary application and ignores endpoints, identities, security tools, backups, and integrations will understate the real environment. Every time. The scoping guide distinguishes assets that handle CUI, assets that provide security functions, contractor risk-managed assets, specialized assets, and out-of-scope assets. All of those categories affect how assessors review your environment, and they all depend on having accurate architecture and segmentation information.

If you have not mapped your CUI flows, that is where to start. Where does CUI arrive? Where does it move? Where does it get stored, shared, backed up, and eventually disposed of? Transmission and backup were the two stages attendees most commonly flagged as hardest to map. That tracks with practical experience.

FedRAMP: What It Does and Does Not Do For You

John described FedRAMP as genuinely useful for government contractors going through CMMC, and the analogy he used is worth keeping: FedRAMP is like renting space in a building. The landlord handles the structure, the HVAC, and the foundation. You are still responsible for who has keys, what you put inside, which doors you open, and how you respond when something happens in your space.

A FedRAMP certified service gives you a defined boundary, an independent assessment, a reusable evidence package, and an ongoing assurance program through continuous monitoring and incident reporting. That evidence can significantly accelerate your CMMC process because you are not starting from scratch on the provider side. But it does not eliminate your contractor-side responsibilities.

Specifically, you still own:

  • Decisions about what CUI enters the environment and who accesses it
  • Endpoint and identity security
  • Tenant configuration and policies
  • Monitoring integration and internal incident response procedures
  • Your SSP, SPRS submission, and annual affirmations

The shared responsibility matrix from your cloud provider lays out exactly where the line sits between provider obligations and contractor obligations. Getting that document early, reviewing it carefully, and assigning internal owners to every contractor-side control is essential.

Five Questions to Ask Any FedRAMP Provider

John offered a practical checklist for evaluating cloud providers in the context of CMMC compliance:

1. What exactly is the boundary that will hold our CUI?You want a specific answer, ideally a link to the current marketplace listing. A red flag is an old screenshot, a roadmap item, or anything described as "in process."

2. What is the current status on the marketplace?Verify this yourself. Adobe, for example, has multiple marketplace listings for different products, some FedRAMP certified and some not. The same applies to AI services: Google's Vertex AI can be hosted inside their FedRAMP-covered assured workloads, but only with the correct configuration. Azure's AI Foundry can be hosted inside GCC High. Know exactly which service and which configuration applies to your boundary.

3. What are our responsibilities under the customer responsibility matrix?A good answer is a current, mapped CRM tied to the specific product configuration. A red flag is a provider who delays sharing the CRM until after purchase or treats every shared control as fully inherited.

4. Can our team and assessors access current evidence and incident terms?This should be documented and readily available. Vague answers or generic documentation that does not cover your specific configuration are red flags.

5. How will the provider report material changes, vulnerabilities, or incidents?You want contractual notice periods and documented security contact paths. A red flag is notice limited to a public status page or notification that comes after your own compliance deadlines.

A Practical 90-Day Starting Point

For teams that are early in the process or recalibrating after the phase two pause, John offered a staged approach:

First 30 days: establish the facts. Confirm your contracts and their flow-down requirements. Map your CUI flows. Inventory all cloud services and external providers that might touch CUI. Verify your current SPRS status and boundary documentation.

Days 30-60: assign ownership. Collect CRMs from all your cloud providers. Map what your contractor-side responsibilities are across each one. Assign internal owners to each responsibility. Update your architecture diagrams and SSP references accordingly. If nobody owns a control, it will not get maintained.

Days 60-90: close the gaps. Fix configuration issues, and expect to find them. Remove or restrict any cloud services that are not FedRAMP certified but are touching CUI flows. Test your incident coordination to verify it actually works. Gather and organize the evidence that supports your record.

The underlying message: it is significantly easier to maintain compliance as an ongoing practice than to reconstruct the evidence record before an assessment. Start now, even if the phase two deadline has moved.

The Bottom Line

The phase two pause created breathing room on the timeline. It did not change the underlying requirement to protect CUI, maintain an accurate self-assessment, and keep your compliance record current.

Three things to take back to your team: map every CUI flow and know exactly where that data goes, verify every cloud service you rely on against the FedRAMP marketplace and review its CRM, and keep your SSP evidence current as an ongoing practice rather than a pre-audit scramble.

The compliance obligations that remain in force are real, and in some procurements, a government-led assessment can still be required. If you have not reviewed your specific contract requirements recently, that is where to start.

Procurement Sciences is FedRAMP authorized and built to handle CUI flows in a compliant environment. If you want to understand how an AI platform for government contracting can support your compliance program, [book a demo] at procurementsciences.com.

Click here to schedule a demo to get the full scoop on how our product actually works and discover how AI can transform your approach to government contracting.

Explore More Resources

Sep 30, 2026
Blog

What Is SEWP VI? A Guide to NASA's Next-Generation IT GWAC

NASA SEWP VI is the sixth generation of one of the federal government's oldest and largest IT acquisition vehicles, a Government-Wide Acquisition Contract (GWAC) that lets any federal agency buy commercial IT, communications, audio/visual, cloud, cybersecurity, and enterprise IT services without running its own competition.

Learn More

What Is SEWP VI? A Guide to NASA's Next-Generation IT GWAC

Sep 25, 2026
Blog

Claude for Government Contracting: Claude vs. Purpose-Built AI

Claude has become a widely used generative AI platform for research, writing, document analysis, coding, and complex reasoning. For government contractors, however, evaluating Claude involves more than asking what the model can do.

Learn More

Claude for Government Contracting: Claude vs. Purpose-Built AI

Sep 23, 2026
Blog

How to Find IDIQ Contracts and Task Order Opportunities

Open IDIQ solicitations are posted on SAM.gov like any other contract opportunity. Task orders issued under IDIQs you already hold are a different problem entirely, since most never touch SAM.gov at all.

Learn More

How to Find IDIQ Contracts and Task Order Opportunities

Save time. Deliver faster. Win more.