The Department of War’s pause and review of the CMMC program can be viewed through an interesting lens: what if the review itself were treated like a C3PAO Level 2 assessment?
That analogy exposes a fundamental concern.
In a normal certification assessment, we expect the assessment team to understand the environment, the applicable requirements, the evidence, the operational realities, and the methodology being used to reach a conclusion.
So consider the current review as though it were an assessment engagement.
Assessment scenario
In-scope information system / scope:
The CMMC Program
Assessment objective:
Determine whether the program effectively validates implementation of NIST SP 800-171 while remaining sustainable for the Defense Industrial Base
Lead Assessor:
DoW CIO
Assessment team members:
SBA and other stakeholders participating in the review
Now ask the same question we would ask of any C3PAO assessment team:
Does the assessment team possess sufficient relevant competence and practical experience to reach a defensible conclusion?
That is where the concern begins.
General Cybersecurity Experience Is Not the Same as CMMC Assessment Experience
A person may be highly qualified in:
- Cybersecurity
- Federal acquisition
- Policy
- Small-business advocacy
- Enterprise IT
- Risk management
- Government operations
And still not understand the practical details involved in conducting a CMMC Level 2 assessment.
Those details matter.
A Level 2 assessment is not simply a review of whether an organization has security products or policies. It involves evaluating 110 NIST SP 800-171 requirements across 320 assessment objectives and determining whether each applicable objective is satisfied through appropriate combinations of:
- Examine
- Interview
- Test
- Evidence validation
- Sampling
- Scoping
- Shared-responsibility analysis
- External Service Provider evaluation
- Inheritance analysis
- Configuration review
- Operational validation
- Quality assurance
Those mechanics materially affect cost, duration, evidence burden, staffing, and assessment outcomes.
An assessment team that lacks practical experience in those areas may still be technically qualified in a broader sense, but it may not be positioned to evaluate the program accurately.
Would We Accept This Assessment Team for an OSC?
Imagine an OSC entering a Level 2 assessment.
Suppose the assessment team had:
- Little or no direct CMMC assessment experience
- Limited practical experience assessing NIST SP 800-171
- No history of evaluating evidence against the 320 assessment objectives
- Minimal experience determining inheritance and ESP responsibilities
- No practical understanding of assessment-team composition, QA, Tier 3 constraints, or real assessment throughput
- Limited exposure to small-business Level 2 implementations
- A primary concern centered on perceived cost
Would we accept the resulting assessment as reliable?
Probably not.
We would ask whether the assessors were competent to assess the environment.
We would ask whether they understood the standard.
We would ask whether they understood the assessment methodology.
We would ask whether they had examined objective evidence.
We would ask whether their conclusions were based on validated facts or assumptions.
That is exactly the standard that should be applied to the review of CMMC itself.
Cost Cannot Be the Primary Assessment Objective
Cost is a legitimate factor.
Small businesses face real burdens.
Implementation costs matter.
Assessment costs matter.
Managed security costs matter.
Market-entry barriers matter.
But cost is only one factor.
If an assessment team begins with the premise that the primary problem is cost, then the assessment can quickly become biased toward reducing cost rather than determining whether the program is achieving its intended security outcome.
That would be no different from an OSC telling its C3PAO:
“Our primary concern is that these controls cost too much, so please evaluate whether we really need them.”
That is not how an independent assessment works.
An assessment begins with criteria and evidence.
It should not begin with the desired conclusion.
The Assessment Criteria Should Be Broader
A credible review of CMMC should evaluate at least five dimensions.
1. Security effectiveness
Has independent verification improved the reliability of NIST SP 800-171 implementation?
Are assessed organizations materially more secure than organizations relying only on self-attestation?
Does independent assessment identify deficiencies that self-assessments miss?
2. Cost
What costs are actually attributable to:
- Assessment
- Readiness consulting
- Remediation
- Technology
- Licensing
- Managed services
- Cloud migration
- Internal labor
- Provider markups
These costs must be separated rather than combined into a single “CMMC cost.”
3. Operational scalability
Can the current assessment ecosystem meet demand?
That requires evaluating:
- Active C3PAOs
- Actual assessment throughput
- CCA and Lead CCA availability
- Tier 3 completion
- QA capacity
- Employee versus contractor staffing
- Recertification demand
4. Small-business impact
The review should include companies that actually represent much of the DIB, including:
- Microbusinesses
- Companies with fewer than 100 users
- Organizations with fewer than 500 users
- Small manufacturers
- Smaller MSPs
- Smaller C3PAOs
- OSCs that have completed assessments successfully
Enterprise-focused data alone cannot adequately represent this population.
5. Program clarity
The review should determine whether ambiguity in:
- 32 CFR
- ESP treatment
- Inheritance
- Security Protection Data
- Significant-change triggers
- CUI flow-down
- Phase timing
is creating unnecessary burden that could be reduced without weakening security.
The Assessment Team Needs Practitioners
If the CMMC program is being assessed, then the assessment team should include people who have actually performed the work.
That should include:
- Experienced Lead CCAs
- CCAs with multiple completed assessments
- QA personnel
- Authorized C3PAOs
- MSPs and MSSPs managing Level 2 environments
- OSCs that have completed certification assessments
- Small-business implementers
- Cybersecurity engineers
- Acquisition officials
- DoW policy personnel
- Independent reviewers
No single stakeholder group should dominate.
C3PAOs should not control the review.
Neither should MSPs.
Neither should large contractors.
Neither should the SBA.
Neither should DoW alone.
The strongest assessment team would be multidisciplinary and balanced.
Practical Experience Matters
During our own recruiting activity, we saw firsthand that even credentials do not always equal practical competence.
Some individuals may meet the formal requirements for a role but lack meaningful assessment experience.
The same principle applies at the program level.
Holding a senior cybersecurity, policy, acquisition, or administrative role does not automatically mean someone understands the operational details of a CMMC assessment.
That is not criticism of those individuals.
It is simply an assessment principle:
Competence must match the scope being assessed.
Perceived Cost Is Not Objective Evidence
One of the largest risks in the current review is reliance on perceived cost rather than validated cost data.
Examples include:
- Treating GCC High as a mandatory Level 2 cost
- Treating readiness consulting as assessment cost
- Treating internal labor as C3PAO fees
- Treating modernization as compliance cost
- Using high consultant rates as universal assessor labor assumptions
- Using enterprise environments as representative small-business examples
Those errors materially affect the conclusion.
An assessor would never accept unsupported assumptions from an OSC.
The review should not accept them either.
Apply the Same Rules to the Program That We Apply to OSCs
A C3PAO assessment follows a basic discipline:
Define the scope.
Use qualified assessors.
Apply the correct criteria.
Examine objective evidence.
Interview knowledgeable personnel.
Test implementation.
Validate assumptions.
Document findings.
Perform QA.
Reach the conclusion last.
That same discipline should apply to the review of CMMC.
If the review begins with a conclusion—that the program is too expensive, too burdensome, or unnecessary—then the process ceases to resemble an assessment and starts to resemble justification for a predetermined policy decision.
Conclusion
The pause presents an opportunity to improve CMMC.
There are legitimate problems to fix:
- Cost transparency
- Assessment capacity
- Tier 3 delays
- ESP ambiguity
- Regulatory complexity
- Vendor-driven architectures
- Workforce quality
- Accreditation concentration
- Small-business assistance
- Rollout timing
Those issues should be addressed.
But the validity of independent verification should be evaluated by people who understand what independent verification actually entails.
If CMMC itself is the system under assessment, then the Department should apply the same standard it expects from every C3PAO:
Qualified assessors. Relevant experience. Objective evidence. Balanced sampling. Independent QA. No predetermined conclusion.
Otherwise, we risk failing the very assessment principles the program was designed to enforce.


