Manav.id
Compliance · 4 min read

Buying identity assurance when CMMC is paused: a procurement guide for primes

Buying identity assurance when CMMC is paused: a procurement guide for primes

Primes built supplier assurance plans around certification dates that no longer apply. The obligation to protect controlled information did not pause, which leaves a gap that has to be filled with something — and the default is the thing that did not work.

What should a prime buy while CMMC is paused?

Evidence, not certification. The programme's sequencing changed; the safeguarding clauses in the contract did not, and neither did the annual affirmation. A prime that buys per-access and per-change records from its critical suppliers has something that survives whatever the programme does next.

Key takeaways
  • Assurance was outsourced to a certification regime. With the regime suspended, the default fallback is self-assessment questionnaires — the mechanism certification was created to replace.
  • The useful distinction for interim requirements is attested versus verifiable, and only the second gives a prime something to sample.
  • Requirements language should be scenario-neutral, because the suspension's duration is unknown and nobody should forecast it.

What primes actually did in the weeks after

Certification-shapedWait for assessment cadenceBinary status per supplierPoint in timeStops when the programme pausesEvidence-shapedPer-access and per-change recordsMeasurable coverageContinuousSurvives any programme changevs
One depends on programme timing. The other does not.

Three responses, observable across the sector.

  1. Pause. Supplier assurance activity deferred pending clarity. Lowest effort, highest exposure, and the most common.
  2. Revert. Return to self-assessment questionnaires and SPRS score collection. Familiar, cheap, and known not to work — which is why the certification programme was created.
  3. Substitute. Build an interim requirement set. Highest effort, and the only one that actually maintains assurance.

This article is about the third, and specifically about what to put in a supplier agreement when you cannot point to a certificate.

Attested versus verifiable

The organising distinction. An attested requirement produces a claim; a verifiable requirement produces an artefact the prime can check without an audit visit.

RequirementAttested formVerifiable form
Safeguarding implementationSupplier states its SPRS scoreSupplier provides a signed control-state record with a scope hash
Access to our CUISupplier states access is limited to authorised personnelSupplier provides per-access receipts naming individuals
Incident reporting readinessSupplier states it has a processSupplier demonstrates a signed test-report from an exercise
Flow-down to sub-tiersSupplier states it flows downSupplier provides delegation artefacts issued to sub-tiers
Affirmation basisSupplier provides its affirmationSupplier provides the signed control-state record the affirmation covered

The right column costs the supplier more and costs the prime less. That is the trade, and it should be negotiated as one rather than imposed.

Interim requirements language

Scenario-neutral, so it survives whatever happens to the programme:

During any period in which third-party certification under the Cybersecurity Maturity Model Certification programme is not required or not available, Supplier shall provide, annually and upon material change, a cryptographically signed control-state record covering the systems within the scope of this agreement, verifiable by Buyer against Supplier's published verification key, together with the signed affirmation to which that record relates. Supplier shall provide equivalent records from any sub-tier supplier to which covered defense information is disclosed.

Note what it does not say. It does not predict the programme's return, does not reference a date, and does not become obsolete if certification resumes — it simply stops applying.

A verification protocol a supply chain team can run

  1. On receipt, verify the signature against the supplier's published key. Minutes, using open-source tooling.
  2. Check the scope hash against the boundary document the supplier provided. A record covering a narrower boundary than your work is the most common finding.
  3. Record three observations: coverage of in-scope systems, POA&M open item count, and change since the prior record.
  4. Sample sub-tier delegations for the suppliers who disclose onward. This is where flow-down assurance currently disappears entirely.

What to do about suppliers who cannot comply

Small suppliers — machine shops, specialty fabricators, single-product component makers — may have no capability to produce any of this, and they are frequently irreplaceable.

Two workable approaches. Tier the requirement by the sensitivity of what they hold, so a supplier who never receives covered defense information is not asked for records about protecting it. And offer assistance: a prime that helps a critical small supplier stand this up has bought assurance and goodwill for less than the cost of qualifying an alternate source.

Do not rebuild twice

The strongest argument for the interim requirement set is that it is not interim. A control-state record and access receipts remain useful if certification resumes — they are what a certified supplier would produce anyway, and they cover the 364 days a year on which no assessor is present.

A prime that builds this now builds it once. A prime that waits builds questionnaires now and something else later.

What to ask a supplier for

Four asks, in order of acceptability to a supplier
AskWhy they can usually agree
A correlation identifier that round-tripsCheap, and it makes reconciliation possible
Receipts for a defined access classBounded, not general logging
Retention matching your contractA contract term rather than engineering work
Verification without contacting themReduces their support burden too

Objections and honest limits

“Suppliers will resist anything extra during a pause.” Frame it as reducing their assessment burden later, and bound the ask to a defined access class. A scoped ask is agreeable in a way that ‘send us your logs’ is not.

“We should just wait for the programme.” The affirmation is annual and the clauses are in force. Waiting means signing statements about facts you cannot evidence.

A prime that has been collecting this through the pause is also the prime that can complete an assessment quickly when the cadence resumes.

Interim supplier assurance

  1. Rank suppliers by what they can reach. Not by spend. The data they touch is the exposure.
  2. Scope the ask to a defined access class. Bounded asks get agreed.
  3. Put retention in the contract. Not in a policy either side can change.
  4. Measure coverage, not status. A percentage tells you more than a binary certification flag.

Terms used here

Flow-down
The contractual mechanism passing safeguarding obligations to suppliers, which operates independently of assessment programme timing.
Coverage
The proportion of in-scope access or changes that produced evidence. More informative than a binary compliance status.
Critical supplier
One whose access to your data or systems would matter if abused, which is rarely the same ranking as spend.

Frequently asked questions

When will CMMC Phase II return? Nobody knows, and this article deliberately does not forecast it. The requirements language is written to be scenario-neutral for that reason.

Can we require more than the contract flows down? Primes routinely impose requirements beyond the minimum flow-down through their own terms. Whether to do so is a commercial decision informed by counsel.

What about suppliers who refuse? Tier the requirement by what they actually hold. A supplier who never receives covered defense information should not be asked for records about protecting it.

Is this wasted if certification resumes? No. The artefacts are what a certified supplier produces anyway, and they cover the period between assessments, which is most of the time.

Does a programme pause remove the obligation? No. Safeguarding clauses sit in the contract and the annual affirmation continues. Sequencing changed, not the requirement.

What is realistic to ask a supplier for? A correlation identifier, receipts for a bounded access class, contractual retention, and verification that does not require contacting them.

How should suppliers be ranked? By what they can reach, not by spend. Data access is the exposure.

Where this fits in Manav

Manav binds the authorising individual to the exact record being released or approved, and produces a receipt a prime, a government customer or an auditor can verify without access to your systems.

See approval receipts →

Sources and further reading