It’s 5PM somewhere. I had just passed the bottom of the J in Jefferson’s Bourbon and was thinking to myself about the land of misfit toys. I’ve got my phone open looking at the brawl between industry and the assessors over CMMC and I really need some popcorn to get this grudge match into context.
On one side you have the C3PAO crowd screaming into every microphone they can find. “You’ve had three years! All of this applied to you the whole time! The ecosystem had enough capacity! The numbers are wrong!” They are furious. They built businesses around this. Trained assessors, got background investigations, stood up teams. And the DoW CIO pulled the rug without even telling the Cyber AB before the press release dropped.
They’re completely wrong. Assessors, meet my friendly swamp puppy. He’s going to eat that logic while you watch.
These credentialed guardians of the assessment gospel are missing the whole target of the 60-day pause. It isn’t the people already in the DIB. It’s the companies who aren’t interested in selling to the government at all. The ones who looked at the compliance stack, looked at their margins, looked at the procurement timeline, and said no thanks. The ones the DoW desperately needs because they build things that go fast and blow up and see in the dark and the current supply chain can’t deliver any of it on schedule or at cost.
The assessor argument works if you think the defense industrial base is a fixed population that simply needs to be whipped into compliance. Get in line. Do the work. Pass the audit. That’s not the problem Kirsten Davies described. She described a shrinking pool. Companies leaving. Companies never arriving. The small business that makes a component nobody else makes and would rather sell it to three commercial buyers this quarter than spend a year and six figures trying to sell it to the Pentagon through a process that treats them like a suspect.
The C3PAOs keep saying DFARS 7012 has been in contracts since 2017, so you should already be compliant. For the existing DIB, that’s true. Nine years. If you’re still not there, the assessment wasn’t the thing holding you back. You just weren’t doing it. The audit was going to be the moment you got caught, and now you’re relieved it’s postponed. That’s a real problem and the assessors are right to point at it.
But here’s where the swamp puppy gets hungry.
That argument assumes the universe of defense contractors is the universe of companies the DoW wants. It isn’t. The whole point of the pause is that the universe needs to get bigger, and the on-ramp is blocked. Not by the assessment. By everything the assessment sits on top of.
You want to sell the government a widget? Here’s what you need before anyone talks price. A NIST 800-171 compliant environment. System security plan. Plan of action and milestones. Enclave architecture or a full environment rebuild. GCC High licensing if you touch anything in the cloud. FIPS-validated encryption. Controlled access. Audit logging. Incident response capability. Supply chain risk management program. A SPRS score posted. An affirming official who will personally sign that you meet the standard, under penalty of the False Claims Act. Working knowledge of DFARS 252.204-7012 and everything it drags with it. ITAR and EAR if your widget touches anything with export controls. And if you’re doing this on a cost-plus contract, every dollar of that overhead gets itemized, audited by DCAA, reviewed by DCMA, and negotiated by a contracting officer who thinks your indirect rates are too high.
A commercial company buries compliance costs in G&A and nobody asks questions. A defense contractor on cost-plus has to prove every dollar is allowable, allocable, and reasonable. The compliance spend doesn’t just cost money. It costs money to prove the money was spent correctly. That’s a tax on a tax.
Now add the timeline. Commercial sale: demo, negotiate, sign, ship. Maybe 90 days. Defense sale: find the solicitation, figure out whether you’re on the right vehicle, respond to the RFP, wait for evaluation, maybe get a LPTA that craters your margin anyway, negotiate terms, deal with protests, and if everything goes perfectly you might see a contract award in 18 months. Your three commercial customers have already paid you twice by then.
The assessors want to argue about whether there were enough C3PAOs. That’s like arguing about the quality of the toll booth on a road nobody wants to drive on.
Redspin published a response saying the real fix is to shrink the scope of who needs a C3PAO assessment. Get it down from 76,000 entities to 15,000 or 20,000 by being disciplined about who actually needs CUI flowing to them. That’s the first honest thing anyone on the assessor side has said in this whole food fight. The scoping problem is upstream of every other complaint. If your tier-three sub who machines one bracket from one drawing carries the same compliance burden as Lockheed Martin, you haven’t built a security program. You’ve built a barrier reef. And the fish you want inside it are swimming the other way.
And the primes keep making it worse. Every major prime contractor has gotten a big case of the stupids about flow-down. They blanket every subcontract with every cybersecurity requirement they can think of regardless of whether the sub actually touches CUI. So Ralph in Traverse City running his machine shop gets a 40-page questionnaire from a prime’s supply chain compliance office telling him he needs to demonstrate CMMC readiness to keep making brackets. Ralph doesn’t handle CUI. Ralph has never seen CUI. Ralph machines metal to a drawing and ships parts in a box. But somebody at the prime decided it was easier to flow everything down to everybody than to do the hard work of figuring out who actually needs what. Every time a prime pulls that move they’re not protecting national security. They’re building the barrier reef one coral head at a time and daring the small fish to swim through it. Every time they do it we should release a swamp puppy into the boardroom.
The SBA threw out $594,000 as the cost per certification. The assessors correctly point out that two-thirds of that is implementation cost that DFARS 7012 already requires. The actual assessment runs $20K to $50K. Fair point. But it cuts the other direction too. If two-thirds of the cost has nothing to do with the assessment, then the assessment was never the main barrier. The main barrier is building a compliant environment from zero, which the DoW isn’t paying for, which flows down regardless of company size, and which makes the business case worse the smaller you are.
The assessors keep framing this as a cybersecurity problem. It’s a market problem. The DoW needs products and capabilities that exist in the commercial market. The companies that make them have choices. Selling to the government is one choice. It is increasingly the worst choice. Not because the government is a bad customer, but because the government has made itself the most expensive customer to serve while capping what it will pay.
The swamp puppy named George (he’s the fat one like me) mentioned something else. These guys are smart.
We are going to have to rearm. The munitions math was already ugly before the Secretary of Defense started throwing missiles at Iranians like a toddler throws peas and carrots at the dog. Precision guided munitions don’t grow on trees. Interceptors don’t materialize from a spreadsheet. Rocket motors, guidance assemblies, seekers, warheads, propellant, castings, circuit boards, wiring harnesses. Deep breath. Every one of those has a supply chain, and huge stretches of those supply chains run through small companies that are either already in the DIB and stretched thin or sitting outside it because the juice wasn’t worth the squeeze. We fought the Gulf War without CMMC. We fought Afghanistan and Iraq without CMMC. We ran the entire Cold War without CMMC. Nobody is arguing those were models of cybersecurity discipline, but the weapons got built and the magazines got filled because the industrial base could actually produce at scale. Right now we need production. We need companies making things. And somebody decided the most urgent conversation to have about the defense industrial base is whether those companies have their FIPS-validated encryption documented in a system security plan that a certified assessor can review for $40,000 every three years. It’s not just bits and bytes that make things go boom. Somebody forgot that part.
I refilled the bourbon. The swamp puppy was full. The chicken was happy to participate. The assessors were still on LinkedIn yelling about capacity numbers and process integrity and how self-attestation is just a False Claims Act trap waiting to spring. They’re not wrong about any of that. They’re answering a question nobody asked.
The question isn’t “can we verify the current DIB?” The question is “why won’t anyone new come play?” And the answer has nothing to do with how many CCAs passed their background checks.
Somewhere in Michigan a machine shop is making a part that would solve a readiness problem for a weapons system that’s three years behind schedule. The owner looked at CMMC, looked at DFARS, looked at DCAA, looked at the margin on a cost-plus contract after overhead allocation, and went back to selling to automotive. The DoW doesn’t even know they didn’t show up. They’ve never heard of this company because reading a RFI and answering an RFP means choosing between a no-profit win with a high-risk budget-pressured customer and watching your kid play football against those scumbags from across town with a beer in your hand. That is not a hard choice. That’s the land of misfit toys. Capability the DoW can’t reach because the entrance fee is a joke and the prize for getting in is a surveillance state dressed up as a customer relationship.
The 60-day task force isn’t going to fix that. You don’t fix a business case problem with a compliance reform. But at least somebody in the building said out loud that the problem exists. That’s worth more than another 200 certified assessors and a three-year recertification cycle.
The bourbon’s gone. The swamp puppy is sleeping. Somewhere on LinkedIn a Lead CCA is writing a post about how the ecosystem was ready. Nobody tell him.
Dead cold sober, I know there are companies out there producing products, services, and capabilities that the Department of War needs. They aren’t going to jump through a lot of hoops to sell them. The establishment primes aren’t going hunting for these companies, and if they do, they’ll drown them in flow-down requirements that cost more than the contract is worth.
If you’re a sub-billion-dollar company, CMMC is expensive and might not float your boat. If you’re sub-hundred-million with no current DoW business, it’s a differentiator you can’t afford to buy. And if you just cracked a million with three to five employees making something nobody else makes, you are not giving up 40 percent of your margin so a GS-13 can argue about your indirect rates.
Those are the misfit toys. The DoW needs them. The primes won’t find them. The assessors can’t see them. And the compliance stack makes sure they never show up.