Blog→The Contractor Security Audit Bill Lands on the Wrong Shops
policy4 min read

The Contractor Security Audit Bill Lands on the Wrong Shops

BySurucka

The Pentagon paused CMMC Phase 2 and stood up a review. Good. The program is right and the bill is wrong, and sixty days is enough time to fix the second thing without losing the first.

What the Pentagon Paused

The Pentagon runs a program called the Cybersecurity Maturity Model Certification (CMMC). It sets the computer security rules a company must meet before it can hold defense work. Phase 2 of the program was set to start on 10 Nov 26. That phase would have required an outside assessor to certify a contractor before the contractor could take covered jobs. On 13 Jul 26 the Pentagon paused Phase 2, DefenseScoop reported, and the start date sits parked while a task force reviews the program. The group met for the first time on 17 Jul 26, working out of offices across from the department's chief information officer (CIO). The review runs sixty days and ends with a public report. The department is also planning listening sessions, open meetings where contractors get to talk back. The CIO says the outcome could be anything from small tweaks to a full overhaul.

I run a small shop in this market, so I will say where I stand before I complain about the money. The program is right and the bill is wrong. The pause is a sixty-day window to fix the second thing without losing the first.

What the Audit Costs a Small Shop

This market is short on people before compliance ever enters the room. Finding a worker who can pass a background check is hard enough. Paying 50 to 100 thousand dollars for a full Level 2 preparation and audit sits on top of that. Level 2 is the program's middle tier, the one a shop handling sensitive files would need. That is the going rate once the preparation work and the assessor's invoice are added up. Published cost breakdowns from PreVeil, a security company that sells to defense contractors, land in the same range. A fee that size decides who enters the market before anybody's security ever gets measured.

The task force saw this on its first site visit. Kform is a small manufacturer in Virginia. Its owner walked the CIO through the yearly budget fight and put it plain. "Year after year, we have to make the decision: Do I buy another piece of equipment? Do I invest in a robot?" The audit sits in that same budget line. A prime contractor, the big company holding the main contract, books the audit as overhead. A six-man shop pays for it with the truck that did not get bought, or the apprentice seat that stayed empty.

The government put a new cost of entry on a market that already cannot find enough people to do the work.

The Part Worth Keeping

None of this argues against the security itself. This week a contractor's exposed file storage leaked 14.3 gigabytes of records from India's biggest nuclear plant, The Hacker News reported. The set included cooling system blueprints. That same class of paperwork sits in job folders at every contractor shop in this country, mine included. Good security habits also pay a shop back on their own. They mean fewer stolen payment transfers and a network you can still trust after somebody clicks a bad email. A contractor gains from that whether a contract demands it or not.

Split the Bill by Size

Here is what I would hand the task force. Split the program by company size and put the cost where the profit sits. Large businesses pay the whole bill, because the contracts make them plenty of money. Small businesses certify themselves to the same standard, meaning the owner signs a statement that the shop meets the rules. Then the government runs random audits at its own expense as part of the program. A random audit gives that signed statement real consequences, without billing every shop that never gets picked.

The CIO says this review is about lowering the barriers that keep companies out of defense work. The audit invoice is that barrier. Fund the audit for the small shops, or let them certify themselves and check the proof at random. Either way the security is worth having and the work is worth protecting. Getting the bill right means more shops come through with their security intact. That is the outcome everybody says they want.

Next: this week's report, A Nuclear Plant's Drawings Leaked Through a Contractor, on what leaked and why the labels matter.

Works Cited

  1. DOD halts cybersecurity requirements for CMMC Phase 2 (DefenseScoop, 13 Jul 26)
  2. Pentagon announces 'immediate suspension' of CMMC Phase II mandates (Breaking Defense, 13 Jul 26)
  3. Pentagon task force to review CMMC hits the ground running (DefenseScoop, 17 Jul 26)
  4. DoD plans CMMC listening sessions as questions swirl around review (Federal News Network, Jul 26)
  5. CMMC Certification Costs; Estimates and Ways to Save (PreVeil)
  6. Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More (The Hacker News, 20 Jul 26)
#cmmc#small-business#dib#compliance-cost#self-attestation#pentagon#cyber-hygiene
90A LLC

Need CMMC help?

90A LLC works in the CMMC trenches with defense contractors every day. We do readiness assessments, gap analysis, and SSP development for the supply chain.