Hold the Line: Leveling Up Cybersecurity Through TTX While CMMC Phase II is Paused

Incident Response Strategy & Best Practices
CLICK HERE TO DOWNLOAD THIS IMAGE & COLOR IT IN!

Shields up! CMMC Phase II may be on pause, but federal contractors shouldn’t let their guard down. There are still plenty of dragons to fend off while awaiting marching orders from the Department of Defense.

Kingdoms across the realm should already be self-assessing and tempering incident response plans through practice, as required by CMMC Phase I. By regularly drilling in the training yard, orgs can keep their cyber skills sharp, and ultimately ensure that they’re ready for the day when the DoD sounds the horns for Phase II.

Cybersecurity tabletop exercises offer a practical path to CMMC preparedness for government contractors. By dropping teams into realistic incident scenarios, Facilitators can test where shield walls hold and give organizations concrete actions to strengthen defenses before an assessor (or a real attacker) puts them to the test. Read on to learn how TTX can help Facilitators hold the line during the CMMC Phase II pause.

Keeping Up With Cybersecurity Practice

CMMC 2.0 may be locked in limbo (for now), but threat actors never signed a ceasefire accord. It may be tempting to toss your escutcheon back on the rack, but now is the time to train your shield arm. It will only make things easier when CMMC Phase II resumes, or if cyber bandits decide to raid your village.

What the Pause Changes vs. What Remains the Same

The pause delays independent C3PAO assessments for some organizations, but the protections behind CMMC Level 2 still stand. CUI is a crown jewel that still needs guarding, and the goblins beyond the walls are no less tempted to mount an assault.

Think of this as an unexpected rest at camp. It’s your chance to continue mending shields, replenishing potions, and shoring up weak defenses through self-assessment before the party is called to the next level by the Department of Defense.

Think Beyond the CUI Environment

As your kingdom continues to undergo self-assessment as part of CMMC Phase I, it’s critical that you examine how the wards put in place to satisfy compliance requirements in the CUI environment can benefit other villages throughout the organization.

For example, perhaps MFA has been cast to protect CUI. Extending that MFA company-wide would create an added layer of protection against bandits who are eyeing crown jewels in corners of the realm, from supply chain to IT. Access controls, security awareness, logging, monitoring, and other foundational defenses can provide the same type of aegis.

Level Up Incident Response and CMMC Readiness With TTX

Once your shield wall is set, it’s time to test what happens when a fire-breathing problem lands on the other side. The best way to test the formation? You guessed it: tabletop exercises.

Start by Introducing IR.L2-3.6.3

Before charging headfirst into your first TTX campaign, it’s important to create shared understanding surrounding why the tabletop exercise needs to happen in the first place. To accomplish this, crack open the CMMC codex and turn to control IR.L2-3.6.3, which calls on orgs to “test the organizational incident response capability.” Dig a little deeper into the lore book, and you’ll find several acceptable trials. These include tabletop exercises, walkthroughs, simulations, and full-interrupt exercises.

The humble tabletop exercise puts this CMMC requirement into motion by dropping participants into a realistic incident and asking them to make the decisions they would face in battle. Through trial by fire (and trial by error), weak points are revealed and the party learns how to tighten the line around points of exposure.

Test Whether the Incident Response Plan Works in Practice

An IR plan gathering dust in the royal archives does little good when dragons soar overhead. Cybersecurity tabletop exercises pull that plan off of the parchment and toss it into the fray, revealing how well party members can actually execute on it when conditions get hairy.

“One thing we know is that incidents will happen. The question is: will you be ready, or will you be fumbling around in an already stressful moment trying to figure out what to do?”

Jordon Darling, vCISO at Cyberdelic

A well-designed exercise can test whether the kingdom’s wards, sentries, and spellbooks work in concert. An effective TTX quest should test:

  • How CUI is protected
  • Whether party members understand their roles
  • How quickly monitoring detects dangers
  • Who holds the keys and controls access
  • How word travels when trouble strikes
  • What happens when the smoke clears
  • How remediations are handled and business functionality is restored

CMMC Controls That Exercises Can Support

A strong incident response plan draws power from CMMC controls beyond IR.L2-3.6.3. Be it access controls or malware protection, a potent exercise should help orgs work toward multiple CMMC requirements while steadily leveling up the maturity of the broader incident response program. The table below illuminates some of the most important controls Facilitators can put to the test.

Use TTX to Practice CUI Handling

An epic CMMC tabletop exercise asks the party to determine what qualifies as CUI, where it can travel, who is allowed to touch it, and what info can be shared when the kingdom is in chaos. Those choices transform CUI guidance from words on a scroll into decisions the party has actually practiced by reinforcing requirements around security awareness, role-based training, and controlling how CUI flows throughout the realm.

“TTXs aren’t just a compliance exercise. They’re a way to make sure that when something goes wrong, the organization already knows how to respond and that the incident response plan works.”

— Jordon Darling, vCISO at Cyberdelic

Turn TTX Findings Into Measurable Security Improvements

With each exercise, your shield wall should grow stronger. As you track what happens during each TTX, you can unlock the true power of tabletops by turning those findings into defensive upgrades you can justify to leadership.

Establish a Baseline, Then Test Again

Before you can measure anything, you must establish a baseline. Think of the first TTX as Session 0, where you draft a character sheet with base stats for the org. It’s critical that you take note of where the defensive formation buckles during this debut TTX. You’ll want to document the conversion of these weak points into strongholds as the CMMC campaign progresses.

With your baseline set, send the party back into a comparable encounter after new controls, training, and processes have been equipped. Compare the new stats against Session 0 and answer important questions like these:

  • Are roles clearer?
  • Does word travel faster once the alarm bell is rung?
  • Can the party find evidence, protect CUI, and contain the threat with fewer fumbled rolls?

That before-and-after view helps answer the two questions that kings, queens, and execs actually care about: Did CMMC make the entire kingdom more secure, and what else needs to be done?

Fill in the Gaps

Once the final die is cast in a session, every crack in the bulwark should be noted. Assign each gap to a party member, and charge him or her with a quest to make upgrades in that area. Be sure to infuse priority level, target date, and clear victory conditions into these quests so the party knows exactly what “fixed” looks like.

Those quests can feed directly into CMMC control assessments, corrective-action plans, continuous monitoring, SSP updates, and risk assessments under CA.L2-3.12.1–4 and RA.L2-3.11.1. Once upgrades have been made, summon the party back for another comparable encounter. If an old weak point holds under pressure this time around, you’ve got proof that the phalanx has grown mightier.

Craft a Defensible Evidence Package

As you complete TTXs and boost defensive stats across the kingdom, be sure to maintain a well-kept quest log. Preserve the evidence which tells the tale of each tabletop exercise by chronicling the following in your After-Action Report:

  • Quest charter: Exercise plan and objectives
  • Scenario script: Scenario description and injects
  • Party roster: Participant roles and attendance
  • Battle log: Decisions and actions taken
  • Strengths and weak points: What’s working and what needs to be addressed
  • Action Items: Recommended improvements following the exercise
  • Upgrade ledger: Corrective-action log with owners and dates
  • Updated maps and spellbooks: IR plan, contact lists, SSP, data-flow diagrams, or procedures
  • Training records: Where the exercise was used as role-based training

This is where Ally comes in. Our tool was purposefully crafted to help Facilitators capture these findings, track quests to completion, and illuminate how the kingdom’s defenses grew stronger from one encounter to the next.

Three CMMC TTX Scenarios to Get You Started

Run these scenarios at the onset of your CMMC journey to establish base stats, then summon them again down the road to discover if new controls, training, and processes have helped the party level up.

Scenario 1: A Compromised Account Exposes CUI

A cyber rogue pickpockets an employee’s credentials and uses the stolen sigil to access or send CUI beyond the castle walls.

What to test

Use this encounter to test how quickly sentries spot the intrusion, who can revoke the stolen keys, how the party determines what CUI escaped, and whether the right reporting spells are cast. Pay particular attention to MFA, authorized access, audit logs, monitoring, and incident reporting.

Inspiration

U.S. Department of Justice: Iranian National Charged for Multi-Year Hacking Campaign Targeting U.S. Defense Contractors and Private Sector Companies

Scenario 2: Ransomware Impacts CUI Systems and Backups

A digital curse spreads through systems that store or process CUI. As the party reaches for its recovery spellbook, signs emerge that the backup vault may have been compromised too.

What to test

Use this encounter to test containment priorities, who has authority to make disruptive decisions, how evidence is preserved, and whether clean backups can resurrect affected systems. Pay particular attention to malware protection, privileged access, logging, backup resilience, and recovery readiness.

Inspiration

TechCrunch: Defense Contractor CPI Knocked Offline by Ransomware Attack

Scenario 3: A Departing Contractor Removes CUI

A departing contractor begins hoarding technical data and smuggling it out of the kingdom through portable storage or a personal cloud account.

What to test

Use this encounter to test whether the party recognizes insider-threat warning signs, who can revoke access, how quickly suspicious activity is escalated, and whether evidence can be preserved before the bandit slips beyond the gates. Pay particular attention to offboarding, CUI handling, access control, removable media, monitoring, and user accountability.

Inspiration

U.S. Department of Justice: Two Men Charged with Stealing Trade Secrets from Connecticut Defense Contractor

Takeaway

CMMC Phase II may be paused, but there are still Phase I compliance oaths to fulfill. It’s for that reason that all kingdoms should stay the course. Continue self-assessing, strengthening shield walls through practice, and testing whether CMMC investments are actually improving resilience.

Cybersecurity tabletop exercises provide the proving ground for such feats. Run them now, track how the party levels up, ensure that your orgs are ready when the horns of Phase II sound again.

The Next Step on Your Journey

Ally was forged to help Facilitators craft tabletop exercises and conjure After-Action Reports in a flash. From running your first TTX to showing how preparedness improves from one encounter to the next, Ally helps keep the campaign moving.

Ready to help your clients hold the line? Start your next TTX with Ally.

Frequently Asked Questions

What does the CMMC Phase 2 pause mean for defense contractors?

The CMMC Phase 2 pause delays the expansion of mandatory third-party Level 2 assessments, but it does not erase existing cybersecurity obligations. Defense contractors have already been required to self-assess against applicable NIST SP 800-171 requirements, so practices like incident response testing and tabletop exercises should already be part of the cybersecurity program.

What should defense contractors do while CMMC Phase 2 is paused?

Defense contractors should keep improving their cybersecurity posture while CMMC Phase 2 is paused. This includes implementing required controls, testing incident response plans, addressing identified gaps, and using exercises such as TTX to determine whether people, processes, and controls work together during a real incident.

Does CMMC require tabletop exercises?

CMMC Level 2 requires organizations to test their incident response capability under IR.L2-3.6.3. TTX is one accepted testing method, alongside walkthroughs, simulations, and full-interrupt exercises.

What evidence do CMMC assessors want to see for incident response testing?

For incident response testing, CMMC assessors may look for evidence such as the exercise plan and objectives, scenario and injects, participant records, decisions made, observed deficiencies, an After-Action Report, corrective actions, and proof that significant improvements were completed and retested.

Matthew Carson
Matthew Carson
Matthew Carson is a cybersecurity leader with over 17 years of experience helping defense and government contractors navigate complex compliance requirements and building practical, defensible security programs that scale.
Read more

About Ally Security

Ally is here to support facilitators, which in turn creates a virtuous cycle where exercises take less time, provide more value, are run more frequently, and can make every organization can be better prepared.

Book a demo!
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Have a great IR story? Tell Asa!

The unexpected wins. The client curveballs. The chaos you couldn’t have scripted if you tried. Dear Asa is your space to share the stories that don’t make it into the official post-incident report. Script, submit, and enjoy a chance to be featured or quoted in an upcoming post.

Share my story