Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
No Result
View All Result
Home Articles

Pentagon Needs More CMMC Third-Party Assessors to Increase Compliance Rates, Slash Waits & Costs—Experts Weigh in

by Pat Host
May 5, 2026
in Articles, Cybersecurity
Pentagon Needs More CMMC Third-Party Assessors to Increase Compliance Rates

Pentagon Needs More CMMC Third-Party Assessors to Increase Compliance Rates

  • The Pentagon needs additional Cybersecurity Maturity Model Certification third-party assessors to reduce long waits for mandatory audits and increase compliance rates.
  • Firms that don’t follow the CMMC compliance schedule risk losing Pentagon business
  • Get the latest update on CMMC implementation at the Potomac Officers Club’s 2026 Cyber Summit on May 21!

The Pentagon needs more Cybersecurity Maturity Model Certification certified third-party assessors, or C3PAOs, to reduce long waits and costs for mandatory CMMC audits and increase the low rate of businesses achieving CMMC compliance ahead of a key deadline, according to experts who spoke with ExecutiveGov.

Table of Contents

    • You might also like
    • Lt. Gen. Paul Stanton Outlines 4 Priorities to Strengthen DOW-Industry Collaboration
    • Audit Identifies 8 Improvement Areas in DOE Cybersecurity & IT Governance Program
    • Supriya Ahuja Assumes Acting Deputy CISO Role at DHS
  • What Are Key CMMC Deadlines?
  • How Much Do CMMC Third-Party Assessments Cost?
  • What Could the DOW Do Differently With CMMC?
  • How Can the DOW Reduce CMMC Compliance Costs?
  • One C3PAO’s Perspective

You might also like

Lt. Gen. Paul Stanton Outlines 4 Priorities to Strengthen DOW-Industry Collaboration

Audit Identifies 8 Improvement Areas in DOE Cybersecurity & IT Governance Program

Supriya Ahuja Assumes Acting Deputy CISO Role at DHS

This lack of CMMC compliance among small and mid-sized contractors could reduce the Department of War’s ability to grow business among smaller and innovative firms, a key initiative of President Trump during his second term. There are 103 C3PAOs authorized to perform CMMC assessments, according to the CyberAB, the sole authorized non-governmental partner of the Pentagon in implementing and overseeing CMMC conformance.

Payam Pourkhomami, OSIbeyond president and CEO and one of Executive Mosaic’s GovCon Experts, told ExecutiveGov that roughly 1 percent of 100,000 defense industrial base customers that are supposed to be CMMC Level 2 certified have achieved Level 2 certification. OSIbeyond is not a CMMC C3PAO.

Dig into the latest Pentagon cybersecurity business opportunities at the Potomac Officers Club’s 2026 Cyber Summit on May 21! Hear directly from three top national security cyber executives during their illuminating keynote addresses:

  • Aaron Bishop, chief information security officer and acting principal deputy chief information officer
  • Katherine Sutton, assistant secretary for cyber policy
  • Rear Adm. Jason Tama, Coast Guard Cyber Command chief

Sign up now!

What Are Key CMMC Deadlines?

A key deadline in CMMC implementation, known as Phase 3, begins on Nov. 10, 2027. This is when contractors who want to do business with the Pentagon must have an independent assessment performed by a C3PAO every three years.

Another important deadline, known as Phase 2, takes place on Nov. 10. This is when the Pentagon can start requiring Level 2 certification, which can be achieved via self-assessment or by C3PAO. The Pentagon can choose to delay both Level 2 and Level 3 certification requirements in a contract to an option period if it chooses. Phase 1, which began on Nov. 10 of last year, can require Level 1 or 2 self-assessment in individual contracts.

Trey Hodgkins, CEO of Hodgkins Consulting LLC and an adviser to Fortune 500 companies about the federal technology marketplace, told ExecutiveGov that the Pentagon needs thousands of C3PAOs to reduce high fees associated with C3PAO assessments.

How Much Do CMMC Third-Party Assessments Cost?

Many small businesses, he said, pay $50,000 to $100,000 individually for both a C3PAO assessment and as consulting to help them prepare for the assessment. These fees may not be steep for larger businesses, but Hodgkins said they are for sixth- or seventh-tier subcontractors in the automotive supply business who might make a couple of parts that go into a tank and whose annual revenue may be around $150,000.

Though the Pentagon may give a short term extension on CMMC compliance requirements, Hodgkins said that might not be enough for these firms further down in the supply chain.

“Now the government is telling them they need to put in something that will cost $50,000 to $100,0000 a year,”  — Trey Hodgkins, CEO of Hodgkins Consulting LLC

Bill Greenwalt, senior fellow at the American Enterprise Institute think tank, also believes that CMMC needs thousands of C3PAOs to reduce fees and wait times and encourage more small businesses to pursue CMMC compliance.

Greenwalt told ExecutiveGov that he is a supporter of better cyber hygiene between the Pentagon and its contractors, but he’s not a fan of CMMC and its “check the box” approach. He believes it’s forcing contractors to comply with a standard that is already outdated.

Greenwalt also doesn’t like the adversarial nature of the program with its audits and banishments for not achieving compliance. He dislikes the unfunded mandate nature of the fees, which he said will deter small businesses from entering the federal workforce.

“If there were thousands of [C3PAOs] and things were going fast and it was cheap, most companies wouldn’t be complaining,” Greenwalt said. “They would say ‘here’s a paper exercise thing I have to go through, but it doesn’t cost [an excessive amount of money] that’s going to affect my bottom line.”

What Could the DOW Do Differently With CMMC?

Instead, Greenwalt believes the Pentagon should take a more collaborative approach with contractors for better cyber hygiene to help keep small contractors doing business with the department. He proposes the department offer system penetration testing to assess firms’ cyber vulnerabilities and provide them step-by-step processes to improve their cyber defenses.

Greenwalt said that long waits and high fees for C3PAOs could be a silver lining for CMMC in that it could demonstrate that the program is unimplementable and inspire the Pentagon or Congress to make changes or scrap the program. Pentagon spokesman Joseph Loewy declined to comment for this article.

Are you a GovCon technology executive? Then you cannot afford to miss the Potomac Officers Club’s 2026 Cyber Summit on May 21. Examine meeting CMMC, National Institute of Standards and Technology and zero trust requirements and transitioning prototypes into secure mission systems at the Cybersecurity at Commercial Speed panel discussion. It features

  • John Baase, Defense Information Systems Agency DOW enterprise identity, credential and access management, or E-ICAM, program manager
  • Khoi Nguyen, Cyber Command Cyber Acquisition and Technology Directorate (J9) command acquisition executive

Secure your seat today!

How Can the DOW Reduce CMMC Compliance Costs?

There are a variety of ways the DOW could reduce CMMC compliance costs for small businesses. Pourkhomami suggested the department financially subsidize the program, though he declined to provide details. The government, he said, is going to “front the bill” in the end through contractors including fees in their bids, so figuring out how to get contractors moving will be key and a challenge in the short term.

Hodgkins said the Pentagon should approve a cloud computing provider that would allow businesses to run programs like email, data storage and computer assisted design through it.

One C3PAO’s Perspective

Redspin of Nashville, Tenn., is a C3PAO and has been involved in the CMMC ecosystem since its early development in 2020. It was also among the first organizations authorized as a C3PAO to conduct assessments under the initial version of CMMC.

Both Pourkhomami and Thomas Graham, Redspin senior principal consultant and CISO, disagree with the perception that there are long wait times for C3PAO assessments. Graham told ExecutiveGov that the company’s next available assessment window is around November, though schedules shift and earlier availability can, and often does, open up as Redspin’s assessor team grows.

Graham said booking an assessment 6 to 10 months in advance isn’t unusual for a program of this scale, he said, and this timeline often works in an organization’s favor. This is because the period leading up to an assessment is critical for finalizing documentation, validating controls, practicing interviews with your team and ensuring overall readiness. Graham said organizations that use that time effectively tend to have much smoother assessment experiences.

Pourkhomami said companies don’t become assessment-ready in timeframes less than three months. Pourkhomami would be more concerned if assessment waits were 18 months long. Additionally, Pourkhomami the number of CP3AOs are growing, he said, which should help alleviate this bottleneck.

“It’s not impossible to get an assessment right now,” — Payam Pourkhomami, OSIbeyond president and CEO and one of Executive Mosaic’s GovCon Experts.

Redspin has completed over 1,000 assessments, Graham said, and continues to support a large and growing pipeline of organizations preparing for certification. He said the company’s completed assessment count grows almost daily and is a good indicator that the DIB has woken up to the requirement.

Pentagon Needs More CMMC Third-Party Assessors to Increase Compliance Rates, Slash Waits & Costs—Experts Weigh in

Graham said Redspin doesn’t offer flat-rate pricing because CMMC Level 2 assessments are highly dependent on the size, scope and complexity of an organization’s controlled unclassified information environment. Factors like subsidiaries, number of physical locations and additional in-scope networks can all impact the overall assessment cost.

Assessments are also dependent on the operational nature of the environment as a research and development organization may be vastly different from a manufacturing organization.

“These assessments are not checklist assessments,” Graham said. “They require validated evidence across all 110 requirements and the 320 associated objectives.”

A GovCon attorney called CMMC the latest shakeup to an industry that has experienced vast changes since President Trump started his second term in January of last year. Cherylyn Harley LeBon, partner at Cohen Seglias, told ExecutiveGov that reduced federal budgets outside of the Pentagon and the intelligence community has business owners reexamining federal business opportunities.

CMMC, she said, is making these business decisions even more difficult.

“Either you’re going to play the [Pentagon] game and intelligence with CMMC compliance, and go along with it, or you’re going to pivot to something else,” LeBon said. “[But] budgets have decreased in these other agencies and there are fewer opportunities. So where does that leave you? With commercial opportunities and state and local [governments].”

Pentagon Needs More CMMC Third-Party Assessors to Increase Compliance Rates, Slash Waits & Costs—Experts Weigh in
Share5Tweet19

Recommended For You

Lt. Gen. Paul Stanton Outlines 4 Priorities to Strengthen DOW-Industry Collaboration

by Jane Edwards
June 4, 2026
Paul Stanton. The DISA director outlined four priorities to strengthen DOW-industry collaboration and secure the DOWIN.

Lt. Gen. Paul Stanton has outlined four priorities to strengthen DOW-industry collaboration in securing DOWINPriorities include readiness and continuous modernizationStanton said AI-driven challenges require a team-based approach to...

Read moreDetails

Audit Identifies 8 Improvement Areas in DOE Cybersecurity & IT Governance Program

by Jane Edwards
June 4, 2026
Department of Energy seal. The DOE OIG disclosed the findings of a KPMG audit of the cyber and IT governnance program.

DOE OIG has identified eight areas for improvement in cybersecurity and IT governanceKPMG has issued 11 recommendations to strengthen oversight, risk management and complianceThe 2026 FedCiv Summit will...

Read moreDetails

Supriya Ahuja Assumes Acting Deputy CISO Role at DHS

by Kristen Smith
June 3, 2026
Supriya Ahuja. DHS appointed cybersecurity leader Supriya Ahuja as acting deputy chief information security officer.

Supriya Ahuja was named acting deputy chief information security officer at DHSThe cybersecurity leader brings extensive experience in risk management, compliance and vulnerability programsThe appointment follows Ahuja's years...

Read moreDetails

GAO Flags Federal EHR Cybersecurity Coordination Gaps

by Kristen Smith
June 3, 2026
GAO logo. The watchdog has called for stronger cybersecurity oversight of the federal EHR system.

GAO has called for stronger cybersecurity oversight of the federal electronic health record systemThe audit found gaps in how agencies define and measure joint cybersecurity and privacy effortsThe...

Read moreDetails

NSA Selects David Imbordino, Holly Baroody to Lead Cybersecurity Directorate

by Kristen Smith
June 2, 2026
NSA logo. NSA selected David Imbordino and Holly Baroody to lead its Cybersecurity Directorate.

NSA has appointed David Imbordino and Holly Baroody to cyber leadership roles, according to The RecordImbordino brings decades of experience spanning cybersecurity, intelligence and election security missionsThe changes...

Read moreDetails
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Sponsors

About ExecutiveGov

ExecutiveGov, published by Executive Mosaic, is a site dedicated to the news and headlines in the federal government. ExecutiveGov serves as a news source for the hot topics and issues facing federal government departments and agencies such as Gov 2.0, cybersecurity policy, health IT, green IT and national security. We also aim to spotlight various federal government employees and interview key government executives whose impact resonates beyond their agency.

CATEGORIES

  • Acquisition & Procurement
  • Announcements
  • Articles
  • Artificial Intelligence
  • Awards
  • Big Data & Analytics News
  • C4ISR
  • Civilian
  • Cloud
  • Contract Awards
  • Cybersecurity
  • Defense And Intelligence
  • Defense Security Cooperation
  • DHS
  • Digital Modernization
  • DoD
  • Events
  • Executive Moves
  • Executive Spotlights
  • Federal Civilian
  • Financial Reports
  • General News
  • GovCon Expert
  • Government Technology
  • GSA
  • Healthcare IT
  • Industry News
  • Intelligence
  • Legislation
  • M&A Activity
  • National Security
  • News
  • Policy Updates
  • Press Releases
  • Profiles
  • Space
  • Videos
  • Wash100
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Copyright 2026 Executive Mosaic. All Rights Reserved.

No Result
View All Result
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news

Copyright 2026 Executive Mosaic. All Rights Reserved.

Get your free GovCon news!

Get your latest GovCon news and insights. Become a VIP and subscribe to the GovConWire Daily News.

Invalid email address
We promise not to spam you. You can unsubscribe at any time.
Thanks for subscribing!