The fastest way to make CMMC expensive is to treat 110 security requirements as 110 separate tasks. The approach starts logically enough: identify the requirement, determine whether a control exists, document the implementation, collect evidence, close the gap, and move on. An organization can finish with policies, screenshots, configurations, remediation records, and assessment artifacts without having a CMMC program that works as part of the business.
CMMC Level 2 is based on the 110 security requirements in NIST SP 800-171 Revision 2. Those requirements intersect every time Controlled Unclassified Information, or CUI, moves through email, collaboration platforms, endpoints, cloud services, engineering systems, employees, customers, and subcontractors. A contractor can address individual requirements while leaving weak connections between the technologies, people, processes, and evidence that are supposed to protect the information.
The better question is whether the organization has built an operating environment that keeps those requirements addressed during normal business.
The Phase II Pause Creates Time to Fix the Underlying System
On July 13, 2026, the Department suspended CMMC Phase II requirements, which had been scheduled to begin November 10, 2026, while it conducts a broader program review. Phase I self-assessment requirements remain in place.1 The pause changes the CMMC implementation schedule. It does not remove the underlying requirement to protect CUI. During the review, the Department says it will continue enforcing NIST SP 800-171 Revision 2 through self-assessments and selected government-led assessments.
For contractors, the pause creates room to separate remediation that improves the CUI environment from work performed mainly to meet an assessment date. CUI still has to be scoped correctly, access controlled, sensitive information moved through protected channels, and evidence available to support the cybersecurity representations contractors make.
For organizations that already allocated cybersecurity or compliance funding for 2026, this can be a useful investment window. Instead of compressing remediation around an approaching Phase II date, teams can close known gaps, simplify the CUI boundary, improve secure collaboration, establish repeatable evidence practices, and correct ownership problems while there is more room to make deliberate decisions.
A practical funding test is whether the remediation would still be worth doing if the CMMC assessment mechanics changed tomorrow. If the answer is yes, the investment is probably improving the underlying security program rather than merely preparing for a deadline.
Normal Business Behavior Can Expand Your CUI Boundary
Most organizations can draw a CUI boundary. The harder exercise is following a real piece of CUI through the business.
A contract document arrives by email. Someone sends part of it to engineering. A supplier needs information from it. A project manager creates another version. The completed material is returned to the customer and retained. Each step involves a routine decision about where the information goes next.
Architecture diagrams, asset inventories, and System Security Plans describe where CUI is expected to exist. Business activity determines where it actually goes, and normal work can quietly expand the environment beyond the boundary used to design the controls.
A new collaboration platform, subcontractor, cloud migration, customer request, or convenient file-sharing workaround can all alter CMMC scope without arriving as cybersecurity projects. The goal is therefore not simply to make the protected environment as small as possible. It is to make the approved way of handling CUI easier to understand and easier to use than the workaround.
PreVeil’s work with defense contractors illustrates the operational side of this problem. Its encrypted email and file-sharing platform can provide a controlled path for CUI while allowing organizations to retain existing Microsoft 365 or Google Workspace environments for other business activities. In a published PreVeil customer example, Logical Systems, Inc. used PreVeil to create a dedicated CUI enclave, clarify where CUI could flow, and reduce assessment scope without rebuilding its broader Microsoft environment.2
Technology can establish a controlled place for CUI. The organization still has to decide what belongs there, who should have access, how information may leave, how exceptions are handled, and which changes require the boundary to be reviewed. Without that governance, a sound boundary can become a historical description of the environment that existed when the program was designed.
CMMC Drift Often Starts Outside the Security Team
Security and compliance teams tend to look for drift in controls. Many of the changes that alter CMMC posture originate elsewhere.
Sales wins a contract with different information-handling requirements. Procurement introduces a subcontractor. Engineering adopts another tool. IT migrates a workload. A customer sends CUI through a new channel. Each event can change access, CUI flow, scope, evidence, or ownership without changing a line in the control matrix.
Consider a new subcontractor. Procurement sees vendor onboarding and the project team sees added capacity. CMMC adds different questions. Will the subcontractor receive CUI? Through which system? What requirements flow down? Who approves and removes access? What evidence proves the process was followed?
A sustainable CMMC program needs a way for those business events to trigger the right security and governance questions before they become scope problems. That does not mean routing every operational decision through security. It means identifying the relatively small set of events that can materially change the CUI environment and routing them to someone with the authority to evaluate the impact.
CMMC maintenance therefore depends on detecting business change that alters the environment the controls are supposed to protect. The controls remain the compliance foundation. Change governance keeps that foundation connected to the business.
Evidence Is Operating Telemetry
Evidence is often treated as the administrative side of compliance, which leaves organizations with one workflow for performing security activities and another for proving those activities occurred.
If a security requirement operates as part of normal business, it should leave something behind. Access approvals, account changes, configuration reviews, training records, incident records, patching activity, and documented risk decisions become evidence because the underlying processes operated, not because someone started preparing for an assessment.
The disconnect becomes visible when an assessment approaches and teams search tickets, shared drives, email, spreadsheets, and consoles to reconstruct what happened months earlier. They may produce enough evidence, but the effort shows that evidence management is separate from control operation.
A stronger model defines the evidence while designing the process. What should exist if the requirement operates correctly? Where will it live? Who owns it? How often should it be reviewed? What does it mean if expected evidence stops appearing?
That turns evidence into operating telemetry. If quarterly access reviews are expected and no review record appears, the control may not have operated. If technical records conflict with the documented CUI workflow, the documented and operating environments may have diverged. Technology generates records from the protected environment. Governance connects those records to requirements, owners, expected frequency, decisions, and exceptions.
The assessor eventually benefits, but the organization benefits first because missing or inconsistent evidence becomes an early warning that something changed.
A Secure Platform Does Not Own the CMMC Program
Technology vendors and advisors often emphasize different parts of the same problem. A functioning CMMC environment needs both usable technical controls and governance that keeps them aligned with the business.
PreVeil provides encrypted email and file sharing designed for organizations that need to protect CUI while integrating with existing user workflows. That can establish a controlled path for sensitive information without requiring every corporate workload to move into the same environment.
The platform still operates inside a business. Someone has to decide who should be enrolled, what information belongs there, which endpoints are in scope, and who approves access. Someone also has to respond when an employee changes roles, a subcontractor joins the project, or CUI starts flowing through a process that was not included in the original scope.
The reverse is also true. A governance program can define strong policies, assign ownership, document workflows, and establish review cadences. None of that compensates for an inadequate technical environment. Secure handling becomes fragile when approved tools make required business activity difficult and users resort to workarounds.
CMMC works when the technical environment and the governance model describe the same reality.
“PreVeil is designed to protect CUI and ITAR data using end-to-end encryption, but most customers are handling CUI prior to engaging with us.”
Gregg Laroche, VP of Product Management, PreVeil3
The operational goal is to make the secure path normal and make deviations visible before they become findings or unmanaged CUI exposure.
The SSP Should Describe the Environment You Have Today
Compliance documentation often begins as an accurate representation of the environment. Systems, vendors, people, contracts, and CUI flows change. When those changes do not feed back into the compliance program, the System Security Plan and supporting documentation gradually describe how the organization used to operate or how it intends to operate rather than how it operates now.
That can leave a contractor with sound controls and current-looking documentation that describe different environments. The issue may not surface until an assessor traces a workflow or compares evidence with the SSP.
Change management should identify changes with potential CMMC implications before they become documentation problems. Procurement should know when a vendor relationship needs CUI review. IT and project teams should know when systems or workflows change the protected environment. Control owners should know when their responsibilities change.
The goal is not continuous rewriting. When a material change occurs, governance should determine what scope, control, evidence, or documentation changes are required. The SSP can then remain a description of the operating environment instead of an increasingly optimistic prediction of it.
Start With One Piece of CUI
Organizations do not need another 110-row spreadsheet to begin finding these problems. They can start with one real business transaction.
Pick a piece of CUI that recently entered the organization and follow it until the work involving it is complete. Compare the actual path with the documented CUI boundary and the control assumptions built around it.
Ask eight questions:
- How did the CUI enter the organization, and was that the expected channel?
- Who received it, and how was that person’s authorization established?
- Where was it stored, copied, downloaded, or synchronized?
- How was it shared with other employees, systems, customers, and subcontractors?
- Which security controls protected it at each stage?
- What evidence was generated because those controls operated?
- Where did someone make a judgment call, create an exception, or use a workaround?
- Who is responsible for detecting when any part of that path changes?
This exercise connects CMMC requirements to actual work. It can expose unknown systems, informal sharing, unclear ownership, undocumented exceptions, and evidence gaps that control reviews miss. It also shows where the organization still relies on people to remember the correct handling process every time.
If the actual path matches the documented environment, controls produce usable evidence, and ownership remains clear from beginning to end, the organization has a repeatable operating model for protecting CUI. If the exercise exposes gaps, it gives the organization a practical starting point for remediation by showing how a control deficiency connects to the business process that created it.
Build the Program Around the Work
CMMC is usually framed as a cybersecurity project because its requirements are cybersecurity requirements. For defense contractors, it is also an operating model problem. CUI has to move through the organization so people can perform contract work. The objective is to make that authorized path clear, secure, practical, and observable enough that the organization can demonstrate how protection works without reconstructing the story later.
This is where the Cyturity and PreVeil perspectives meet. PreVeil focuses on the technical environment used to protect CUI in email and file collaboration. Cyturity focuses on the governance surrounding that environment, including CUI scope, ownership, evidence, change management, and the operating structure that keeps the documented program aligned with the business.
A technically secure environment with weak governance eventually drifts. Strong governance without usable technical capability creates pressure for workarounds. A compliance program disconnected from both becomes an assessment exercise that has to be rebuilt every time someone asks for proof.
The Phase II pause gives contractors time to address those connections without treating the next assessment date as the architecture of the program. Remediation that improves how CUI is scoped, protected, shared, governed, and evidenced remains useful even if implementation mechanics change. Contractors that strengthen those fundamentals will be better positioned for what comes next because they will have improved the system the requirements are intended to govern.
The checklist matters. It should not be the operating model.
Sources
Footnotes
-
Chief Information Officer, CMMC Contact page. On July 13, 2026, the Department announced immediate suspension of Phase II requirements while stating that Phase I self-assessment requirements remain in place. https://dodcio.defense.gov/cmmc/Contact/ ↩
-
PreVeil, “From -71 to 110/110: How LSI Achieved CMMC with PreVeil.” The case study describes a PreVeil-centered CUI enclave used alongside the company’s existing Microsoft environment, with CUI strictly scoped to PreVeil. https://www.preveil.com/resources/how-lsi-achieved-cmmc-with-preveil/ ↩
-
Gregg Laroche quote from PreVeil, “PreVeil and Teramis Partner to Solve the First Problem in CMMC Compliance: Finding Your CUI,” June 22, 2026. https://www.preveil.com/blog/preveil-and-teramis-partner-to-solve-the-first-problem-in-cmmc-compliance-finding-your-cui/ ↩

