Reforming CMMC and Reducing Compliance Burden for the DIB

We recently responded to the Department of War’s Request for Information supporting the CMMC Reform Task Force from an unusual position: we are an authorized CMMC Third-Party Assessment Organization (C3PAO); we build and operate CMMC Space, a low-cost compliant enclave used by more than 350 small businesses across the Defense Industrial Base, more than 100 of which are CMMC Level 2 certified; we are an awardee on the U.S. Army’s NCODE contract vehicle and a selected enclave provider under the Defense Innovation Unit’s Certificate Shepherd initiative for DIU portfolio companies.

We are also a small business that has carried the full weight of these requirements.

We recommend two specific, immediately actionable reforms that bend the cost curve of compliance for small businesses:

    1. A randomized, assigned-audit model that sets the price of assessments, and
    2. A department-wide, NCODE-style program that sets a hard affordability ceiling for compliant solutions.

    We note plainly that several of these recommendations would reduce our own revenue; we make them anyway.

    Our advice to the Task Force is simple: do not scrap CMMC, and do not try to shrink it into affordability. Fix the two prices that lock small businesses out: assessments, through randomized audits at a government-set rate, and compliant solutions, through an NCODE-style program with a hard affordability ceiling.

    Verification exists because self-attestation already failed. Since 2017, DFARS clause 252.204-7012 has required contractors handling sensitive defense information to implement the NIST SP 800-171 controls, the same controls CMMC Level 2 verifies, on the honor system: companies assessed themselves and attested to their own scores. By 2024, the results were in. A survey of the Defense Industrial Base found the average self-reported SPRS score was negative 12 against a passing mark of 110, only 4% of contractors were fully prepared for certification — and 75% claimed compliance anyway. 

    In 2024, only 4% of contractors were prepared for certification, and 75% claimed compliance anyway.

    Whatever the Task Force recommends, it should not rebuild a system the Department has already watched fail. The instinct to verify was right. What failed was the price of everything built around it.

    For seven years, the program’s working assumption has been that the defense industrial base would commoditize compliance down to a price small businesses can afford. But the math runs the other way: more than one hundred thousand companies need these services, and only about one hundred authorized C3PAOs exist to assess them. With demand that high and supply that scarce, sellers have no reason to compete prices down. 

    Low-cost solutions are finally emerging, our own enclave among them, but not at critical mass. It is time for the government to stop waiting for the DIB to organize itself and to put in place programs that bend the cost curve directly. 

    Reform Requires More than Marginal Change

    Defending an organization against sophisticated nation-state cyber threats requires a cybersecurity specialist — and most small businesses do not have one and cannot afford one. That single fact, not any individual control or reporting form, is what drives the cost of CMMC. No matter how much the program trims controls or documentation, compliance will still be too hard for most small businesses to achieve without hiring a specialist or engaging an MSSP. It follows that the only reforms that can significantly change what small businesses pay are policies that create incentives or requirements to bend the cost curve directly, on the two costs where all of the money actually goes:

    Implementation and upkeep of a CMMC solution. Every path to a compliant Level 2 environment is a way of buying the missing expertise: engage an outside firm (MSP/MSSP), hire an employee or contractor to manage it, or adopt a Cloud Service Offering (CSO) enclave. This cost can be reduced significantly through the government intervention we describe in the next section.

    Third-party C3PAO assessments. The market price of an assessment today runs $30,000 to $70,000 depending on complexity, down from $60,000 to $90,000 in early 2025, but still far above the cost of the work delivered. These costs can also be reduced dramatically through the intervention described in the next section.

    Widely cited estimates putting CMMC compliance near $600,000 per company are, in our direct experience as both an assessor and a solution provider, heavily inflated. The real costs are far lower, and still a real barrier. Reform should be built on the real numbers and aimed at the two drivers above, because reform that does not change that math does not change the outcome.

    We expect the Task Force will receive hundreds of responses identifying specific security controls and regulatory requirements, and some marginal value can be derived from consolidating them. A leaner program might even allow MSSPs to lower their prices, though we would not count on it. But even if those changes reduced the administrative burden considerably, they would not reform the program in a way that significantly reduces what a small business pays to be compliant. 

    We learned this firsthand. In 2023, ATX Defense was a small business holding prime contracts with the Army and Marine Corps, facing the CMMC requirement ourselves. The most affordable compliant options ran north of $100,000 annually, some as high as $250,000. The cost was not the complexity of the program. It was the overhead of expertise relative to the size of the business: most companies do not bring on a full-time IT specialist until roughly $5 to $10 million in revenue and 20 to 50 employees, and dedicated cybersecurity specialists are hired later still. Below that size, every dollar of compliance is a dollar spent buying expertise the business cannot yet carry on payroll. This is why we built CMMC Space, and its adoption by more than 350 small businesses confirms the diagnosis: the barrier is the cost of expertise, not the will to comply.

    In August 2026, the 100th organization running on our managed CMMC service, CMMC Space, passed its Level 2 assessment. Most of them are under 50 employees. Many under 10.

    Every one of them now operating a verified, third-party-assessed security program that protects CUI in accordance with federal regulations. And they did it at $299 per user per month.

    Likewise, streamlining self-assessment is worthwhile, but it is not where reform succeeds or fails. Under the model we propose in the next section, self-assessment becomes more important, not less: every company will self-assess, and only a random subset will be audited. The practical challenges are the ones the Task Force would expect: compiling evidence by hand from dozens of systems, translating it into score-sheet form, and repeating that work every reporting cycle. And even a perfectly streamlined self-assessment still requires the specialist who built and maintains the environment being assessed. Streamline it all; the cost problem remains.

    Roughly 90% of DIB small businesses interested in ATX Defense’s services have already performed a self-attestation. The conversations are remarkably consistent: “We just did our attestation and scored a 91, but some of the questions were confusing and we are probably more in the 60s. We figured we had better get this under control, so we went looking for an affordable CMMC solution.” These businesses are doing the best they can. But without a cybersecurity or IT specialist to begin with, the self-attestation functions as a wake-up call that something must be done, not as the start of a more dynamic security practice. 

    Recommended Policy Reforms

    Reform succeeds only if it bends the overall cost curve down for small businesses, and the government holds exactly two levers: the price of verification and the price of implementation. We therefore recommend that the Department come out of the 60-day review with an announcement of two major reforms, and they are deliberately different kinds of government action: the first is regulatory, changing how compliance is verified; the second is programmatic, changing what compliance costs to implement, and requires no rulemaking at all. Both can be launched inside the review window using interim instruments; the permanent rule changes behind Reform One then follow on defined dates.

    What follows is a detailed description of each program, including its phased rollout plan, written in the form of an announcement of the plan. Following each description is a detailed list of the specific policy changes required to implement it, with responsible parties and not-later-than dates defined.

    Reform One – The CMMC Randomized Assessment Program

    The Department overhauls how CMMC third-party assessment works. Going forward, the annual self-attestation carries a new clause: by attesting, the company consents to enter a pool from which it can be randomly selected for a C3PAO third-party assessment. The attestation also carries a checkbox by which a company can self-select for assessment, for companies whose contracts or prime contractors specifically require CMMC Level 2 certification. When a company is selected or self-selects, the assigned C3PAO performs the assessment at a fixed program fee of $20,000, plus $5,000 for each additional physical location in a different city. Companies remain free to arrange assessments with C3PAOs outside the program at whatever price they agree.

    The Rollout

    November 1, 2026 — C3PAO enrollment opens. Every C3PAO has the option to join the CMMC Randomized Assessment Program. As conditions of joining, a C3PAO agrees to perform program assessments at the fixed fee of $20,000 plus $5,000 per additional physical location, to complete each assessment within 60 days of notification, and to report weekly to the Cyber AB the maximum number of new assessments it can accept the following week and complete within 60 days. In return, each participating C3PAO is guaranteed up to two assigned assessments per week; to remain in the program, a C3PAO must perform at least 12 program assessments annually. C3PAOs price all non-program work as they see fit.

    January 2027 — self-selected assessments begin. The Cyber AB begins assigning C3PAOs to companies that checked the self-selection box on their attestation, giving the program a running start on live volume while the randomized pool builds.

    November 2027 — randomized selection begins. The Cyber AB conducts a weekly randomized draw from the pool of all attested companies, and the size of each week’s selection is the greater of two numbers. The first is 0.15 percent of the pool. The second is the sum of the guaranteed baselines: in its weekly capacity report, each participating C3PAO claims a baseline of one or two assessments for the coming week, and those claims are added up across every participating C3PAO. Whichever number is larger sets that week’s selection. Self-selected companies are assigned first, and the randomized draw fills the remainder; assignments beyond the baselines are distributed round-robin to C3PAOs that requested more than two, never exceeding any C3PAO’s reported capacity.

    Sizing the draw.

    With 100 participating C3PAOs each claiming a baseline of two per week, the floor is 200 assessments per week, roughly 10,000 per year: about 10 percent of a 100,000-company pool, and better than a one-in-four chance that any company is assessed within each 36-month certification window.

    At the fixed fee, the baseline guarantees each C3PAO roughly $2 million per year of predictable program revenue. Because the draw is capped by reported capacity, the system can never assign more work than the assessor base can absorb.

    Selection Mechanics: A selected or self-selected company is notified that it has been chosen for third-party assessment and has been assigned a C3PAO, and it has 60 days from notification to complete the assessment. The assigned C3PAO has 48 hours from notification to make contact and offer at least three different weeks within that 60-day period. No assessor shopping, no scheduling limbo.

    On passing. The C3PAO issues the company its CMMC Level 2 certification and reports the result to the Cyber AB. The certification is valid for 36 months. The company continues to self-attest annually, exactly as under the current program.

    On failing. The C3PAO reports the assessed score to the Cyber AB, and the response is tiered to the assessed SPRS score (ranges illustrative here; the program rule sets the final bands):

    • 109 to 88 — Limited gaps. Conditional status: a corrective action plan with a 180-day cure period and re-assessment of the affected controls, mirroring today’s conditional certification mechanics. No interruption to award eligibility.
    • 87 to 60 — Significant gaps. A corrective action plan plus a pause on new-award eligibility until re-assessment is passed.
    • 59 to 38 — Critical failure. Where CUI is left exposed, a work stoppage on affected contracts, subject to standardized review and appeal.
    • Below 38 — Fraud review. The company is submitted to the fraud review track the Justice Department already operates, in addition to the contract remedies above.

    The logic of the bottom band: every company in the pool has attested to at least an 88, the minimum score for conditional Level 2 self-assessment status with a 180-day plan of action. An assessed score below 38 sits more than 50 points beneath anything that could have been attested in good faith, so it moves from remediation to fraud review. Every band above that line begins as a contract administration and remediation matter, not a penalty proceeding.

    Re-assessment. The path back to good standing is always open. A company may resubmit its attestation at any time as it remediates, and may self-select for a new third-party assessment at any time using the attestation checkbox, at the same fixed program fee. Eligibility restrictions lift when the re-assessment is passed.

    Reform Two – The CMMC Affordability Program

    The Department establishes a DoW-wide program, modeled on the Army’s NCODE, that attacks the other cost driver: what it costs to implement and maintain a compliant environment. The program admits compliance solutions only if they meet a hard affordability requirement, subsidizes small businesses that adopt an admitted solution through their first two years, and holds solutions accountable for whether their customers actually pass assessments. The price ceiling is the point: it forces the industrial base to engineer affordable solutions rather than bill whatever the market will bear. Without that forcing function, the market remains at the impasse it is at today.

    The Rollout

    NLT December 2026 — the program is chartered. The DoW CIO, with the Office of Small Business Programs and Industrial Base Policy, charters the CMMC Affordability Program and defines eligibility: DIB small businesses handling CUI under defense contracts or subcontracts.

    NLT January 2027 — the solution solicitation opens. Providers apply for admission by demonstrating four things: a total price that makes a 10-user business CMMC Level 2 assessment-ready for under $90,000 in year one, including implementation; sustainment of the service for under $50,000 per year thereafter; a documented path to full 110-control coverage with a published shared-responsibility matrix, because partial solutions that cover 80 percent of the program leave small businesses stranded on the hardest 20 percent; and evidence support for the annual attestation and for randomized assessment under Reform One.

    NLT April 2027 — the first solutions are admitted and the catalog is published. Small businesses shop from a vetted, price-capped catalog of admitted solutions, with the Army’s NCODE vehicle as the pathfinder and template for Department-wide expansion. Enclaves, MSSP offerings, and hybrid models all compete inside the same ceiling; the program is solution-agnostic and priced by outcome.

    Subsidy mechanics. For a business adopting an admitted solution, the program pays $50,000 of the year-one cost and $25,000 in year two, paid directly to the provider on the business’s behalf; from year three the business carries the cost on its own. Illustratively, every $150 million of program funding carries 2,000 small businesses through their first two years of compliance, a fraction of what those same businesses would pay at the $100,000-plus annual market prices that have been driving them out of the defense industrial base. And because Reform One’s assessments are paid by the assessed companies at the fixed fee, the government’s spending concentrates here, where it buys actual security rather than paperwork.

    Staying admitted. Admission is revalidated annually against two tests: the solution still meets the price ceiling, and its customers pass their randomized assessments at or above a published threshold rate. A solution that fails either test is removed from the catalog, and its customers’ remaining subsidy transfers with them to any other admitted solution. Accountability rides on outcomes, not marketing claims.

    Together with Reform One, this closes the loop: a small business can now buy its way to real security at a known, bounded, partially subsidized price, and the government can trust the scores it receives because a real probability of verification stands behind them.

    Is a government-set program fee price-fixing? No, and the precedents are everywhere.

    Antitrust law restricts private agreements among competitors; it does not restrict the government from setting the price of participation in a voluntary federal program. Medicare and TRICARE reimbursement rates, GSA Schedule ceiling prices, and the SBA’s caps on lender fees all work this way. Three design features keep this reform in that tradition: the Department, not the Cyber AB, sets the fee (the Cyber AB only administers assignment under it); participation is voluntary; and C3PAOs price all non-program work freely. The same logic covers Reform Two: an affordability gate on a subsidized program is an ordinary eligibility criterion.

    Together, these two reforms attack both cost drivers at once: a small business adopting a program-admitted solution and subject to randomized assigned assessments faces a known, bounded, partially subsidized cost to get secure and stay secure instead of an open-ended six-figure gamble.

    Two companion measures matter equally. First, honor the investment already made: companies that achieved Level 2 certification under the current rule should be grandfathered into whatever framework emerges (a transition provision in the amended 32 CFR Part 170, with interim effect by DoW CIO memorandum). Second, set the new timeline once, realistically, and hold it in the amended DFARS 252.204-7021, so companies plan against a date instead of paying for uncertainty.

    Feasibility, Risks, and Challenges

    Both reforms are feasible within the Task Force’s 60-day window because neither requires new legislation, new enforcement authority, or broad new spending: Reform 1 runs on amendments to existing rules with a class deviation for interim effect, and Reform 2 stands up by program charter on an existing pathfinder vehicle. In candor, the risks we would flag are these:

    • Program-fee participation. If the fixed fee is set too low, C3PAOs may decline to opt in. The guaranteed baseline of up to two assignments per week, roughly $2 million per year of predictable program revenue per C3PAO, is designed to offset this; the fee should still be validated against actual assessment labor and revisited annually.
    • Sampling rate. Randomized verification deters false attestation only if the probability of audit is meaningful. The greater-of sizing rule sets a floor on verification tempo, and the methodology and annual selection percentage should be published.
    • Ceiling gaming. A price ceiling invites scope-cutting. Admission to the NCODE-style program should be conditioned on outcomes: a solution stays admitted only while its customers pass their audits.
    • Transition equity. Companies that invested early must be grandfathered, or the Department teaches the market that early compliance is punished.

    The innovations the Department should lean on are the ones already working in the commercial market: shared-responsibility enclaves with formally recognized control inheritance, and machine-generated compliance evidence that replaces static documentation.

    Closing

    Securing an organization against nation-state adversaries cannot be made easy, but the government can make it affordable. Bend the cost curve at its two sources: fix the price of verification through a randomized, assigned-audit model, and fix the price of implementation through an affordability-gated, NCODE-style program. Both can be piloted within the Task Force’s 60-day window using authorities the Department already holds. The requirement to protect defense information is not going away, because the theft is not going away.

    A final note on our interest in this outcome. Nearly every recommendation in this response works against our own revenue. We are a C3PAO proposing to cut the price of assessments, and a solution provider proposing a program that invites competitors into the affordable-compliance market we currently lead. We make these recommendations anyway, because we built this company to get small businesses secured, and the program as it stands is failing them. We would rather compete inside a market that works.

    Specific Policy & Actions Required – Reform One

    • NLT Oct 2026, DPCAP, issues a Class Deviation to DFARS 252.204-7019 / -7020 / -7021: Defense Pricing, Contracting, and Acquisition Policy provides interim effect while rulemaking proceeds, so C3PAO enrollment can open on November 1, 2026 and self-selected assessments can begin in January 2027.
    • NLT Oct 2026, SPRS Program Office, updates the attestation workflow concurrent with the program announcement: the Supplier Performance Risk System score-submission workflow is updated the day the reforms are announced, so that every attestation filed from that day forward includes consent to randomized selection beginning in November 2027 and offers the self-selection option for assessments beginning in January 2027. Rolling the clause out with the announcement is what builds the selection pool: because every company must self-attest annually, the entire attesting DIB passes through the updated workflow within twelve months, so by the time the first randomized draw runs in November 2027, the pool is complete and every company in it has consented.
    • NLT Oct 2026, DoW CIO and Cyber AB, revise the DoW–Cyber AB Agreement and the CMMC Assessment Process (CAP): adds assignment authority, the weekly capacity report, the weekly randomized draw, and the 48-hour contact and 60-day completion clocks to the Cyber AB’s existing responsibilities for C3PAO accreditation and credentialing, assessment rules, and the assessor community. The fixed fee is administered, not set, by the Cyber AB.
    • NLT Oct 2026, Cyber AB, publishes the Program Participation Agreement and enrollment package: the updated CAP sections, the participation agreement itself (fixed fee, 60-day completion, weekly capacity reporting), the assignment and scheduling procedures, and enrollment instructions, so every C3PAO can review the terms and sign up when enrollment opens on November 1, 2026.
    • NLT Jan 2027, Defense Acquisition Regulations Council, amends DFARS 252.204-7019 / -7020: under the Under Secretary of War for Acquisition and Sustainment, the annual attestation carries the selection-pool consent clause and the self-selection option, and verified findings connect to award eligibility.
    • NLT Oct 2027, DoW CIO, amends 32 CFR Part 170 (CMMC Program rule): through notice-and-comment rulemaking, establishes the randomized assessment track, the assignment mechanism, the 36-month certification term, and C3PAO program participation terms (including the C3PAO requirements at § 170.9), with the fixed fee set by the Department. Interim operation does not depend on this rule: contractor obligations run through the deviated DFARS clauses and assessor participation is contractual. The 36-month certification term and the permanent program structure do require it.
    • NLT Oct 2027, Defense Acquisition Regulations Council, amends DFARS 252.204-7021 (CMMC clause): replaces the universal phase-in schedule with the randomized assessment model and the program’s published timeline, in place ahead of the first randomized draw in November 2027.
    • NLT Jan 2027, DoW and Department of Justice, sign a Memorandum of Understanding on fraud referral: the MOU defines the referral pathway from the Cyber AB and the Department to DOJ’s Civil Cyber-Fraud Initiative, the misrepresentation threshold that triggers automatic referral, and evidence-handling procedures. No new fraud authority is required, because knowing misrepresentation is already reachable under the False Claims Act; the MOU simply makes the referral track explicit and predictable for industry.

    These are the load-bearing instruments, not the complete paper trail. The amended rule and the revised CAP will carry the full implementing detail beyond this announcement, including the published sampling methodology and annual selection percentage, the attestation clause language, updated assessment guides, and the cadence for reviewing the fixed fee against assessment labor. The Task Force’s report should task each owner above with those subordinate publications.

    Specific Policy & Actions Required – Reform Two

    • NLT Dec 2026, DoW CIO with OUSD(A&S), issues the Program Charter and Policy Memorandum: the DoW CIO, with the Office of Small Business Programs and Industrial Base Policy within OUSD(A&S), establishes the CMMC Affordability Program by charter; no regulatory amendment is required to stand it up.
    • NLT Jan 2027, Program Office, publishes the Program Solicitation: the affordability gate ($90,000 year one for a 10-user business; $50,000 out-years), the full-coverage and shared-responsibility documentation requirements, and the annual revalidation and customer pass-rate retention criteria are published as the admission terms, using the Army’s NCODE vehicle as the pathfinder.
    • NLT Apr 2027, Program Office, publishes the Admitted Solutions Catalog: the vetted, price-capped catalog small businesses buy from, updated as solutions are admitted, revalidated, or removed.
    • NLT Jan 2027, Office of Small Business Programs, aligns Subsidy Funding: the $50,000 year-one and $25,000 year-two payments flow through existing small-business and industrial-base assistance authorities and programs (the same family of authorities that funds NCODE, APEX Accelerators, and Project Spectrum), rather than a new appropriation.