BlogWho Pays for the Proof
policy3 min read

Who Pays for the Proof

ByRucka

The Pentagon paused CMMC Phase 2 and stood up a review. Good. The program is right and the bill is wrong, and sixty days is enough time to fix the second thing without losing the first.

The Pause Came With a Clock

The Pentagon paused CMMC Phase 2 on 13 Jul 26. That was the stage that would have required a certified third-party assessment before a contractor could take covered work, and its 10 Nov 26 start date is parked while a task force reviews the program. The group met for the first time on 17 Jul 26 across from the CIO's office, the review runs sixty days with a public report to follow, and the department is planning listening sessions so the base can talk back. The CIO says the outcome could be anything from small tweaks to an overhaul, and the decisions come when the sixty days are up.

I run a small shop in this market, so my cards go on the table before I complain about the money. The program is right and the bill is wrong, and the pause is a sixty-day window to fix the second thing without losing the first.

The Math on a Small Shop

This market is scarce before compliance ever enters the room. It's hard to get a worker who can pass a background check, let alone pay 50 to 100 grand for a full Level 2 prep and audit. That's the going rate once the prep work and the assessor's invoice are added up, and published cost breakdowns from vendors like PreVeil land in the same range. A fee that size decides who enters the market before anybody's security ever gets measured.

The task force saw this on its first site visit. Kform, a small Virginia manufacturer, walked the CIO through the annual budget fight, and the owner put it plain: "Year after year, we have to make the decision: Do I buy another piece of equipment? Do I invest in a robot?" The audit sits in that same budget line. For a prime it's overhead, and for a six-man shop it's the truck that didn't get bought or the apprentice seat that stayed empty.

The government put a new cost of entry on a market that already can't find enough people to do the work.

The Part Worth Keeping

None of this argues against the maturity itself. This week a contractor's exposed storage put 14.3 gigabytes from India's biggest nuclear plant onto the open internet, cooling blueprints included, and that same class of document sits in job folders at every shop in the base, mine included. Good hygiene also pays a shop back on its own, in fewer hijacked payment runs and a network you can still trust after a bad email. Contractors will benefit from good cyber hygiene whether a contract demands it or not.

Send the Bill Upstairs

Here's what I'd hand the task force. Split the program by size and put the cost where the margin lives. Large businesses foot the whole bill, they're making plenty of money from the contracts. Small businesses self-attest to the same standard, and the government runs random audits on its own dime as part of the program. A random audit puts real teeth behind a self-attestation without billing every shop that never gets picked.

The CIO says this review is about reducing barriers to entry, and the audit invoice is the barrier. Fund it for the small end of the base, or let the small end prove itself and check the proof at random. Either way the maturity is worth having and the work is worth protecting, and getting the bill right means more shops make it through with their hygiene intact, which is the outcome everybody says they want.

Next: this week's Zero Hundred Hrs, The Drawings Left the Fence, on what leaked and why the labels matter.

Works Cited

  1. DOD halts cybersecurity requirements for CMMC Phase 2 (DefenseScoop, 13 Jul 26)
  2. Pentagon announces 'immediate suspension' of CMMC Phase II mandates (Breaking Defense, 13 Jul 26)
  3. Pentagon task force to review CMMC hits the ground running (DefenseScoop, 17 Jul 26)
  4. DoD plans CMMC listening sessions as questions swirl around review (Federal News Network, Jul 26)
  5. CMMC Certification Costs; Estimates and Ways to Save (PreVeil)
  6. Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More (The Hacker News, 20 Jul 26)
#cmmc#small-business#dib#compliance-cost#self-attestation#pentagon#cyber-hygiene
90A LLC

Need CMMC help?

90A LLC works in the CMMC trenches with defense contractors every day. We do readiness assessments, gap analysis, and SSP development for the supply chain.