CMMC’s implementation has been fraught with delays and pauses. Now, Phase 2 has once again been paused, changes might be on the way, and you have the chance to influence them!
Why? Let’s consider this hypothetical company, Mike’s Machine Shop. While it’s hypothetical, it is typical of the problem we’re exploring here.
Mike’s Machine Shop has forty-one employees. They make a handful of precision brackets that end up inside a military vehicle, and they’ve done it well for two decades. A prime contractor had just sent over a contract clause requiring them to earn CMMC (Cybersecurity Maturity Model Certification) Level 2 before the next purchase order.
Which would be fine, if not for the price tag.
The Small Business Administration (SBA) estimates that clearing the third-party certification bar can run a small firm close to $593,800. While I suspect that the number is inflated, Mike’s entire annual profit on the defense work is likely a fraction of that.
The choice Mike and many other small subcontractors face: spend more than they make on this contract to keep it, or walk away from defense work entirely.
Yikes.
The story is not unusual, Small businesses make up a large share of the Defense Industrial Base (DIB), the network of companies that supply the U.S. military. When the compliance bill outruns the contract, those firms do the rational thing and leave. The SBA flagged that this was already happening, and in July 2026 the Pentagon agreed the structure was broken.
On July 13, the Department of Defense suspended CMMC Phase 2, the phase that would have made third-party certification a condition of winning a contract, and stood up a 60-day CMMC Reform Task Force to find a better approach. Then it did something more useful for the rest of us: it opened a Request for Information (RFI) asking industry how to fix the program. That comment window closes August 14, 2026.
So here’s the short answer to “how do we make CMMC survivable for a 41-person shop”: you change who pays for the expensive parts and who does the work, without lowering the actual security bar.
Three coordinated reforms would do exactly that. I’ll explain them below, but first let’s examine the problems in a little more detail.
Where do the costs come from?
Three cost centers drive small contractors out of defense work: licensing, assessment, and control implementation. CMMC Level 2 asks a contractor to implement all 110 controls in NIST SP 800-171 (a federal catalog of practices for protecting sensitive government information), prove it to an outside assessor, and often run the whole operation inside a specialized Microsoft cloud. Each of those three pieces carries a price tag.
Licensing comes first, and it hits Microsoft shops hardest. Handling CUI in email means the commercial Microsoft 365 most businesses run no longer clears the federal bar, so those firms move to a government-grade tenant like GCC High (Government Community Cloud High), which has historically cost 40% to 70% more per seat. Same software, higher bill, because the customer pool is smaller and the compliance overhead is real.
Assessment comes next, and it’s the one that stings. A CMMC Third-Party Assessment Organization (C3PAO) is a private firm authorized to sign off on your certification. There are fewer than 100 of them, and they serve tens of thousands of contractors. You don’t need an economics degree to guess what scarce supply and captive demand do to price: the assessment fee alone commonly runs $30,000 to $75,000, and the wait just to get on the calendar stretches into months.
Then comes control implementation: the multi-factor authentication (MFA), endpoint detection, logging, backups, and the dozen other tools you buy and configure to satisfy those 110 controls. Add it all up and a small contractor’s first year of Level 2 compliance lands somewhere between $50,000 and $200,000, with the SBA’s high-end estimate approaching $600,000.
For a 750-person enterprise company, that’s a line item. For our 41-person machine shop, it’s the whole contract.
Why the Pentagon Hit Pause in July 2026
The suspension is a rare chance to fix the structure. It is not a reprieve from security requirements!
Read the fine print and you’ll see that Phase 1 self-assessments, the DFARS clause requiring NIST SP 800-171, and the cyber incident-reporting rules all still apply. If you handle Controlled Unclassified Information (CUI) or Federal Contract Information (FCI), you’re still on the hook to protect it. What paused is the specific requirement to pay a private assessor to certify you.
The Pentagon hasn’t decided that the security requirements are too expensive, rather it decided this particular delivery mechanism was pricing out the small, innovative firms it depends on.
The Reform Task Force has 60 days to propose something better, and the RFI explicitly asks which cost drivers hurt most and how commercial tools and managed services might count toward compliance.
Translation: they’re asking for the kind of structural fix I’m about to describe. If you’ve ever wanted a say in a federal cybersecurity rule, this is the moment! The clock runs out on August 14.
These Reforms are Just for Small Businesses
A line for these potential savings has to be narrowly drawn, or it stops being a reform and turns into a giveaway. Companies like Lockheed Martin and Raytheon can already spread compliance costs across billions of dollars in contracts, and they don’t need any more government largess. So before the fixes, here’s the fence that keeps the break aimed where it belongs. To qualify, a company would need to meet all four of these tests:
- Fewer than 250 employees total. This keeps the benefit with genuinely small firms, the tier that can’t spread six-figure compliance costs across a big contract base.
- Headquartered and primarily operating in the United States. The reforms exist to strengthen the domestic industrial base, so a qualifying company has to actually be part of it.
- A workforce made up largely of Americans or U.S.-based employees. This ties the help to firms that can realistically meet the personnel and data-handling expectations that come with CUI in the first place.
- A current contract, or a credible near-term path to one, involving FCI or CUI. The company is already CMMC-scoped or plausibly about to be, so the help reaches real and prospective defense vendors rather than any small business that fills out a form.
Those thresholds borrow the spirit of the small-business set-aside rules the government already uses, then add two tests the standard definitions don’t: a U.S.-workforce test and a government-nexus test. Both exist to aim the benefit at the population it’s meant for instead of small firms generally.
Is the line arbitrary at the edges? Of course. A 260-person shop will feel hard done by, and someone will always land just outside the fence. But a bright line the government can actually administer beats a perfect line it can’t, and every one of these criteria can be verified without a forensic audit.
With the eligible group defined, here’s what should change for them:
Reform 1: Negotiate Affordable Microsoft Email for CUI
The first fix targets a problem that is specifically a Microsoft problem. Handling CUI in email means leaving the commercial Microsoft 365 most businesses run, which doesn’t clear the federal bar for CUI, and moving into a government-grade Microsoft tenant like GCC High (Government Community Cloud High). That tenant has historically cost up to 70% more per seat, and for a small contractor already built on the Microsoft stack, switching vendors wholesale isn’t realistic.
Does the premium actually need to be that high to protect valuable government data? No, and here’s the proof: Google.
A CUI-capable Google Workspace, hardened with Google’s Assured Controls, is a legitimate Level 2 email option for contractors without export-controlled data, and its cost is not prohibitive. Same security outcome, without the government-cloud markup that pushes Microsoft-committed firms toward the high end of the cost range from earlier. If Google can price a compliant CUI email option affordably, then so can Microsoft.
The reform needed here is narrow and specific: the government negotiates a special licensing arrangement with Microsoft so eligible small businesses can buy a CUI-capable Microsoft email environment (GCC High or a functional equivalent) without the government-cloud premium, using the scale of a centralized agreement to absorb it. Microsoft already runs its commercial and government tenants on separate infrastructure, so this normalizes a price for a defined group. It doesn’t require a new product tier.
The obvious objection: isn’t the government picking Microsoft as a winner?
I’d argue the reverse. Google’s compliant option is already affordable, so it needs no help. The firms getting squeezed are the ones locked into Microsoft, and a negotiated license levels an uneven field instead of tilting it. The design still has to stay open to functionally equivalent providers so it doesn’t harden into a permanent single-vendor deal, but that’s a guardrail, not a reason to leave Microsoft-committed small businesses paying the premium alone.
Reform 2: Let the Government Run the Assessment
This is the fastest, highest-impact reform, and already has a working precedent!
Instead of forcing a small contractor to hire one of fewer than 100 private assessors, the government performs the assessment directly, through DIBCAC (the Defense Industrial Base Cybersecurity Assessment Center), which already handles the highest-tier assessments today, or a dedicated small-business unit. The methodology doesn’t change; the same NIST SP 800-171A controls still get applied. The only change is the removal of the assessor, their $30,000 – $75,000 fees, and their waitlist.
If that sounds far-fetched, look at Texas. Under TX-RAMP (the Texas Risk and Authorization Management Program), the state’s Department of Information Resources (DIR) performs cloud-security assessments itself rather than making vendors hire a private third party. It cut costs and cleared the bottleneck for in-scope vendors. Same disease, same cure, different level of government.
There are two risks with this proposal.
First, a government assessor only helps if the government actually staffs it. Shift the work to an understaffed federal office and you’ve simply moved the six-month wait to a new building. This reform lives or dies on real investment in assessor headcount, and I wouldn’t support it without that commitment attached.
Second, it risks introducing a conflict of interest. Independent assessors exist partly so the referee isn’t on the payroll of the team being judged. A government-run assessment has to build in guardrails for consistency and rigor so it doesn’t drift toward rubber-stamping.
Neither of these kill the idea, but they both need to be considered in its implementation.
Reform 3: Pre-Approve the Security Vendors
The third fix is about streamlining.
Today, every small contractor (and every consultant they hire) re-solves the same puzzle. Does this endpoint detection tool actually satisfy the system-integrity controls? Does that logging tool cover the audit requirements?
The reform is to have the government pre-approve a slate of vendors in each required category: managed detection, identity and MFA, SIEM (Security Information and Event Management, the tooling that collects and analyzes security logs), backup, and the rest.
Verify once that each offering maps to the relevant NIST SP 800-171 controls when configured correctly, then let eligible small firms shop from a vetted list. FedRAMP (Federal Risk and Authorization Management Program) does this with its marketplace for pre-vetted cloud services.
This moves the compliance-mapping burden from thousands of small firms to the government, one review per vendor. For vendors, a spot on the approved list becomes a real competitive prize which could push them towards small-business friendly pricing.
It’s important that this list doesn’t become a moat for approved vendors. Keep it competitive by keeping it open for any vendors that meet the requirements and want to throw their hats into the ring.
What to Do Before August 14
Calling all security, GRC, and defense industry professionals!
The RFI is open until August 14, and the Pentagon is specifically looking for input on cost drivers and reforms.
Small business stories, like the hypothetical machine shop owner’s $593,800 compliance estimate set against a contract that doesn’t come close to clearing it, is exactly the input the Task Force says it wants.
Whether these three specific reforms make the final cut, I don’t know. But small and midsize voices will be underrepresented in that RFI unless they show up, and the firms that stay quiet now will live with whatever the firms that spoke up helped design.
If you’re a small defense contractor staring at a CMMC clause and a number that doesn’t add up, you have a rare, time-boxed chance to shape the rules instead of just absorbing them. Take it!
The SBA provided information on how to submit comments here.
____
Sorting out what CMMC actually requires for your business, and what “good enough” looks like at your size and budget, is squarely where organizations such as Fractional CISO help defense contractors every day. If you’d like a hand mapping your path (or drafting that RFI comment before the window closes), that’s what our Virtual CISO Services are for.
Want to get great cybersecurity content delivered to your inbox? Click here to sign up for our monthly newsletter, Tales from the Click!