CMMC 2.0's Always-On Mandate Outruns Its Tooling: The Compliance Automation Gap

When I picture CMMC, I picture the audit: a C3PAO assessor walking an enclave, a binder of evidence, a score posted to SPRS. That picture is incomplete, and the rule has been trying to say so since it was published. CMMC 2.0 was never a point-in-time check. It pairs a triennial assessment with an annual affirmation of continuous compliance, and one of its 110 Level 2 controls is an instruction to monitor information system security on an ongoing basis. The rule asks contractors to be continuously compliant. The tools most of them use to prove it are still built around the audit.

I have written about the other side of this problem, that a point-in-time audit cannot certify agentic software that decides its own tool calls at runtime. This post is the inverse. Instead of asking how you certify an agent, it asks how you use automation and agents to meet an obligation that was already continuous when the rule was written.

The rule was never point-in-time

The final rule landed on October 15, 2024, as 32 C.F.R. Part 170, and took effect that December. It is tiered: Level 1 carries 15 basic safeguarding requirements, Level 2 carries 110 NIST SP 800-171 Rev 2 requirements, Level 3 adds 24 NIST SP 800-172 requirements on top. The assessment cadence is what everyone remembers: every year at Level 1, every three years at Levels 2 and 3.

What sits on top of that cadence is the part that matters for this argument. At every level, a senior official has to submit an annual affirmation of continuous compliance to the Supplier Performance Risk System. The Department’s own language about that affirmation is worth reading closely, because it is trying to have something and not pay for it. The affirmation confirms that the contractor “is actively maintaining its CMMC level status, which is more than a checkbox exercise,” and “attests that they have implemented, and are maintaining their implementation of, the security requirements.” When the Department was asked to drop the affirmation to save contractors money, it declined, and insisted the affirmation does not “equate to an annual assessment.”

The Department will not make contractors pay for an annual assessment, because that would be expensive and the final rule says so. But it also will not let contractors prove compliance once every three years and go dark in between. The compromise is an annual signature on a statement of continuous compliance. The “how” of being continuously compliant, the mechanism that would make the signature true, is left to the contractor.

What “ongoing” means in practice

One of the Level 2 controls spells out that mechanism, and it is telemetry, not paperwork. CA.L2-3.12.3, drawn from NIST SP 800-171 Rev 2, says the organization must “monitor information system security on an ongoing basis.” The point of the control, in the implementation guidance vendors publish around it, is to show that controls “remain effective over time,” not that they passed a one-time check.

In practice that means sensors and centralized logs: SIEM, EDR, file-integrity monitoring, agent coverage. The metrics the guidance names are observability metrics. Mean time to detect, mean time to respond, patch compliance, the percentage of assets with an agent installed. A contractor can sign the annual affirmation without any of this. The affirmation is only as good as the telemetry behind it, and nothing in the rule forces the telemetry to exist.

The tooling still runs on the audit

The GRC market has noticed this gap and mostly responded with a narrative. Scrut, a compliance-automation vendor, frames the shift as “the era of preparing for a single audit is over; compliance must be a sustained, daily operation.” The failure mode they name is compliance drift, “the gradual loss of security posture over time, caused by undocumented changes, system updates, or misconfigurations.” Their answer is continuous control monitoring, which “replaces manual checks with 24/7 monitoring of technical controls across the environment,” collecting logs, timestamps, and configuration evidence and alerting on deviation.

I am naming Scrut and LakeRidge, the two vendors behind most of this framing, because they sell the tools that close the gap they describe. Read their claims as the vendor narrative, not independent analysis. The regulatory facts they lean on, the triennial assessment plus the annual affirmation, are corroborated by the primary rule text, and I have linked it above. The narrative itself is sales.

The observation underneath it is still hard to argue with, because it matches what the rule asks for. Most small and mid-size contractors are not running continuous control monitoring. They are running a spreadsheet and a folder of screenshots, refreshed once a year when the affirmation comes due. The tooling the market has mostly been selling, point-in-time assessment preparation, is organized around the audit the rule de-emphasized, not the continuous state the rule requires.

Three threads arriving at once

The pieces that would close the gap are showing up now, from three directions, and none of them is CMMC-specific. The architectural framing has been around longer: Gartner named the “cybersecurity mesh” in 2021, on the premise that assets and users are now everywhere and security tools have to work as a cooperative ecosystem rather than a perimeter. That is a research firm’s forecast, not an observed outcome, but it names the substrate the rest of this sits on.

The first thread is software-defined compliance. NIST’s Open Security Controls Assessment Language, or OSCAL, is a set of machine-readable formats in XML, JSON, and YAML for expressing control catalogs, system security plans, and assessment results. NIST’s pitch is that you can “translate policies incorporating regulatory requirements into standardized, machine-readable OSCAL to operationalize the ‘policy-as-code,’” and that doing so lets you “automate the monitoring and assessment of your system control implementation effectiveness.” NIST’s own claim is that OSCAL “dramatically reduces audit durations from months to minutes.” That is policy-as-code for the auditor’s side of the table. The control framework becomes something a machine can read, so the assessment becomes something a machine can run.

The second thread is AI that maps technical controls to frameworks. On August 19, 2026, NIST released the initial public draft of SP 1353, a quick-start guide for using AI in Cybersecurity Framework analysis and reporting, with comments due October 15. Its use cases include producing a draft current-state profile by mapping artifacts and personnel interview notes to CSF 2.0 outcomes. A companion document, SP 1347, notes that AI can support reference-data work when it is implemented with continuous evaluation and improvement. The job these documents describe, turning scattered evidence into a structured read on framework conformance, is the job a contractor has to do for the annual affirmation.

The third thread is agentic GRC, and it is the least proven of the three. The pitch has moved past dashboards. Scrut’s framing, from a webinar on the subject: “Most teams do not need another dashboard telling them what is broken. They already have that. The real problem starts after the alert shows up: evidence needs to be updated, risks need to be routed, engineering needs to act, and someone still has to push the work through.” The term they use is execution debt, the reason GRC stays manual even after a team buys a platform. The honest boundary is that agents help now, but human judgment stays in the loop on approvals, auditability, provenance, and ownership.

The symmetry

I keep coming back to how this lines up with the post I wrote about certifying agents. That post argued the stack for certifying agentic software has three pieces: observation of what the system did, constraint on what it could do, and a chokepoint where both get applied. The three threads above are the same three pieces, aimed the other way. Observation is the telemetry that CA.L2-3.12.3 and the AI-mapping work describe. Constraint is OSCAL, the framework written as policy-as-code. The chokepoint is the agentic layer where a detected drift becomes a routed, fixed control instead of a dashboard entry nobody acts on. One post asks how you observe an agent you cannot predict. This one asks how you get software to observe you continuously enough to satisfy a control that never stops.

The suspension makes the gap binding

The July 2026 suspension sharpens all of this. The Department of War (DoW, formerly the Department of Defense) paused third-party C3PAO certification for Level 2 and stood up a reform task force, while keeping the self-assessment and affirmation obligations live. I have covered what that means for contractors, including the False Claims Act exposure, so I will not repeat it here. The stated rationale is to “replace bureaucratic compliance with scalable, resilient cybersecurity measures.”

Put the two facts next to each other. Independent third-party verification is paused, possibly for good, and the Department is describing the future as continuous, machine-verifiable security rather than periodic audits. If that direction holds, the thing standing between a contractor and a False Claims Act claim is the quality of the evidence its own systems generate and a human signs. That is what makes the automation gap a constraint rather than a feature request. The rule asks for continuous compliance, the Department says it wants scalable assurance, and the only way to produce either is automation that does not yet reliably exist for the contractors who need it most.

What I am not claiming

A few boundaries, because the honest version of this argument is narrower than the sales version.

The rule is in limbo. Everything above describes 32 C.F.R. Part 170 as written. The two suspension memoranda did not change the text, but the reform task force could recommend a rewrite, and the Department has signaled it wants to move away from bureaucratic compliance. Treat the affirmation and continuous-monitoring obligations as current law, not a settled future.

OSCAL and the AI guidance are CMMC-adjacent, not CMMC-native. Nothing in the rule mandates OSCAL-format evidence, and SP 1353 is scoped to the Cybersecurity Framework, not 800-171. These are enabling pieces. They are not already required.

Agentic GRC is a direction, not an accepted capability. Nothing in the sources shows an assessor accepting an agent’s output as control evidence, and the vendors themselves keep human judgment in the loop on approvals and provenance. Anyone selling you a fully autonomous compliance pipeline today is describing a product roadmap.

Bottom line

CMMC 2.0 legislated continuous compliance years before most defense contractors had a realistic way to produce it. The rule pairs a triennial assessment with an annual affirmation and a control that asks for ongoing monitoring, then leaves the mechanism to the contractor. The tooling market is still organized around the audit, and the pieces that would close the gap, OSCAL policy-as-code, AI control mapping, agentic execution, are only now arriving, all of them CMMC-adjacent and none of them proven in front of an assessor. The suspension raises the stakes because it removes the independent verification while leaving the self-attestation and its False Claims Act exposure in place. A contractor can sign the annual affirmation every year while doing nothing between assessments. The only thing that makes the signature true is telemetry, and the telemetry is the part most of them do not have yet.

Sources

  1. Cybersecurity Maturity Model Certification (CMMC) Program — Final Rule — Federal Register, 89 FR 83092, Oct. 15, 2024
  2. About CMMC — Department of War CIO
  3. CMMC 2.0 Details and Links to Key Resources — Office of Small Business Programs
  4. DOD Crystalizes CMMC 2.0 Program Rule — Wiley Rein, Oct. 2024
  5. CMMC continuous compliance explained — Scrut
  6. How to Implement Continuous Monitoring for NIST SP 800-171 Rev 2 CMMC 2.0 Level 2 Control CA.L2-3.12.3 — LakeRidge
  7. NIST SP 800-171 Rev. 2 — NIST CSRC
  8. OSCAL — Open Security Controls Assessment Language — NIST
  9. Gartner Identifies the Top Strategic Technology Trends for 2022 — Gartner, Oct. 18, 2021
  10. From Dashboards to Action: The Rise of Agentic GRC — Scrut webinar
  11. NIST SP 1353 ipd: Quick-Start Guide for Using AI for CSF Analysis and Reporting — NIST CSRC, Aug. 19, 2026
  12. Cybersecurity Framework 2.0 — NIST