I may ruffle some feathers here but these things but be said.
The current review of CMMC presents an important opportunity to reduce unnecessary cost and complexity across the Defense Industrial Base. But reform must be based on complete data and must preserve the independent verification needed to protect sensitive defense information.
The concerns raised by small businesses are real. Compliance can be expensive, confusing, and difficult to navigate. However, many costs currently labeled as “CMMC costs” are actually a combination of:
- Previously required security remediation
- Internal labor
- Readiness consulting
- Cloud migrations
- Software licensing
- Managed security services
- Optional modernization
- C3PAO assessment fees
- Vendor markups
- Work created by unclear government guidance
Those categories should not be combined into one headline number.
In the current market, a Level 2 C3PAO assessment may reasonably range from the mid-to-upper $30,000s to the mid-to-upper $60,000s, sometimes more depending on the OSC’s size, scope, architecture, complexity, organizational structure, number of locations, external-provider dependencies, and evidence readiness.
Ongoing managed services for an environment designed to support CMMC Level 2 commonly cost more than traditional MSP services because the provider must operate a broader and more rigorous set of security, documentation, monitoring, evidence, and accountability functions.
Traditional MSP services that are not specifically focused on compliance, NIST SP 800-171, or advanced cybersecurity commonly range from approximately $40 to $250 per user per month. By comparison, a managed environment designed to support Level 2 may fall closer to approximately $200 to $375 per user per month, depending on architecture, scope, complexity, service levels, CUI workflows, security tooling, monitoring requirements, and operational maturity.
That comparison matters. The additional cost is not simply a “CMMC markup.” It may include capabilities that are often outside a traditional MSP engagement, such as:
- Security-focused identity and access management
- Endpoint detection and response
- Centralized logging and active monitoring
- Vulnerability and patch-management oversight
- Controlled administrative access
- Evidence retention and reporting
- Incident-response support
- CUI boundary and data-flow management
- Policy, procedure, and SSP support
- Ongoing validation of security configurations
These are meaningful costs, especially for microbusinesses. But they are not the same as claims that every contractor must spend six figures on an assessment or move its entire company into Microsoft 365 GCC High.
The Small-Business Record Must Be More Representative
The data used to evaluate CMMC should include the companies that make up much of the actual DIB:
- Contractors with fewer than 500 users
- Microbusinesses and small manufacturers
- Smaller MSPs and MSSPs
- Authorized C3PAOs serving small organizations
- Companies that have successfully implemented the requirements
- Businesses using commercial, enclave, hybrid, on-premises, and government-cloud architectures
Large enterprises have legitimate concerns, but their environments, budgets, staffing, and complexity are not representative of a 20-, 50-, or 100-person contractor.
A sound reform effort must hear from both organizations struggling with compliance and those that have implemented it successfully.
Why CMMC Exists
CMMC was created because self-attestation did not provide adequate assurance.
For years, contractors were expected to implement NIST SP 800-171 under DFARS 252.204-7012, but the model relied heavily on organizations evaluating their own performance. Some misunderstood the requirements. Some treated policies or purchased products as proof of implementation. Others reduced the process to a checkbox exercise.
Meanwhile, contractors continued to be compromised and sensitive defense information continued to be exposed.
That does not mean every contractor acted improperly. It means self-assessment has inherent limitations when the evaluator lacks training, evidence, independence, or an incentive to identify uncomfortable deficiencies.
Other major audit and certification programs required third-party verification from the beginning. CMMC has faced unusual resistance partly because independent assessment was introduced after years of self-reporting.
The solution is not to return to a model that already proved insufficient.
GCC High Is Not the Only Level 2 Path
Microsoft 365 GCC High can be the right solution for some organizations. It is not a universal requirement for CMMC Level 2.
Depending on the contract, information type, export-control obligations, data flows, and risk decisions, an organization may use:
- Eligible commercial cloud services
- Government cloud
- On-premises systems
- Limited CUI enclaves
- Virtual desktops
- Hybrid environments
- Properly managed service-provider architectures
CMMC should remain vendor-neutral. The government should define required outcomes and acceptable evidence, not prescribe one product, licensing tier, reseller, or architecture.
External Service Providers Need Clearer Rules
The treatment of ESPs remains one of the least clearly understood areas of the program.
The OSC remains accountable for protecting its information regardless of which cloud provider, MSP, MSSP, identity provider, or security platform it uses.
No provider should be presumed to supply complete inheritance. The OSC must still configure the service correctly, control its users and endpoints, document its data flows, and maintain policies, procedures, and an SSP written for its actual operations.
At the same time, independently assessed providers should reduce redundant testing.
A practical trust-but-verify model could use presumptive sampling ranges such as:
- C3PAO-certified / FedRAMP Moderate Equivalent ESP: 0–25%
- Independently C3PAO-attested ESP: 26–50%
- Self-attested ESP: 51–75%
- ESP with no applicable assurance: 76–100%
The C3PAO should retain discretion to increase testing based on scope, evidence quality, deficiencies, exceptions, or the OSC’s implementation.
Consider a Progressive Middle Tier
The jump from the lowest CMMC tier to Level 2 is significant: from 15 requirements and 57 assessment objectives to 110 requirements and 320 objectives.
A properly designed intermediate tier could provide a more sustainable path for small and non-traditional businesses.
Anything above the lowest tier should still require independent third-party attestation or certification. The middle tier should not weaken protection for CUI, but it could provide a progressive path based on information sensitivity, contract risk, and organizational maturity.
Define “Significant Change”
The government should also clarify when reassessment is required.
A significant change should mean a change reasonably capable of affecting the scope, ownership, operation, responsibility, or effectiveness of previously assessed safeguards.
Examples include:
- Moving CUI to a materially different cloud platform
- Replacing a major MSP, MSSP, CSP, identity provider, or security platform
- Replacing major components with substantially different technologies
- Materially changing network boundaries or CUI flows
- Mergers, acquisitions, divestitures, or major reorganizations
- A major incident showing that assessed safeguards did not operate as represented
Routine patching, like-for-like replacements, normal staffing changes, and minor upgrades should not automatically trigger a full reassessment.
Where the impact can be bounded, reassessment should focus only on the affected requirements.
The Right Reform Path
CMMC should be improved through:
- Clearer plain-English rules
- Representative small-business data
- Vendor-neutral reference architectures
- Standardized ESP documentation
- Evidence reciprocity
- Transparent assessment-cost models
- Better CUI identification and flow-down
- A progressive compliance pathway
- Targeted assistance for small and new suppliers
- Proportional reassessment after significant changes
- Continued independent verification for CUI environments
The choice is not between excessive bureaucracy and unsupported self-attestation.
The right path is to preserve independent assurance while making CMMC clearer, more proportionate, more transparent, and more affordable.
That approach supports small business, strengthens the DIB, protects taxpayer investment, and reduces risk to the warfighter.
Kevin Mann
President, Resilient IT
Lead CCA, CCI, CISA
Authorized C3PAO | Managed Service Provider | CMMC Level 2 Certified Organization


