<img src="https://ad.doubleclick.net/ddm/activity/src=11631230;type=pagevw0;cat=pw_allpg;dc_lat=;dc_rdid=;tag_for_child_directed_treatment=;tfua=;npa=;gdpr=${GDPR};gdpr_consent=${GDPR_CONSENT_755};ord=1;num=1?" width="1" height="1" alt="">

The $600,000 Problem: What the CMMC Pause Actually Revealed About the Defense Industrial Base

Editorial Team
By Editorial Team

TABLE OF CONTENTS

    See Virtru In Action

    The problem was never the audit. It was everything that came before it.

    On July 13, the Department of Defense announced the immediate suspension of CMMC Phase 2, the mandatory third-party C3PAO assessments that were set to go into effect in November. Within hours, inboxes across the defense industrial base lit up. Some contractors exhaled. Others panicked. Most weren't sure what to think.

    William McBorrough had a different reaction. As a lead CMMC assessor, CISO, and head of MC Global Tech (a small business defense contractor that has itself been through a C3PAO audit) McBorrough has spent the better part of a decade inside this problem. His clients, when they started calling him that day, mostly shrugged.

    "Big yawn," as he describes their collective response. "This is the government being the government. Our compliance requirements haven't changed."

    That reaction, more than anything in the announcement itself, captures what the CMMC pause actually revealed: the organizations best positioned to weather this uncertainty are the ones who were never treating CMMC as the point.

    McBorrough joined Virtru's Andrew Lynch for a live webinar shortly after the announcement to unpack what happened, what didn't change, and what the suspension says about the state of the defense industrial base. Together, they recap the policy, and honestly assess the structural problem the DIB has been deferring for years.

    CMMC Compass - William McBorrough

    Watch Full Conversation

    The Bottleneck Isn't Auditors

    The math behind CMMC Phase 2 was always uncomfortable. Close to 100,000 defense contractors would ultimately need to be certified. The assessor community numbered roughly 1,000. The gap between those two numbers was one of the factors the DoW cited when launching its 60-day program review.

    The instinct is to read that as a supply problem: not enough auditors, not enough C3PAOs, not enough capacity to process the queue. McBorrough pushes back on that framing directly.

    "The challenge that we have is not a lack of audit capacity," he said. "It's a lack of capacity to implement the security requirements."

     

    That's a different problem, and a harder one. You can train more assessors. You can stand up more C3PAOs. You cannot quickly close the gap between where most small defense contractors actually are, from a security posture standpoint, and where the standard requires them to be. That gap exists because of how the industry has approached CMMC from the beginning.

    CMMC Is a Governance Problem. The Industry Sold It as an IT Problem.

    McBorrough is direct about where he assigns responsibility, and he includes the industry itself.

    "CMMC is not an IT problem," he said. "It's a governance problem. So unless you tackle the governance, there's no way — you have to align the right tools to implement that governance program."

    The market responded to CMMC the way it responds to most mandates: by selling things. Checklists. Gap assessments. Audit readiness platforms. Technology that promises to close specific controls. Each of those has a role. None of them, alone or assembled piecemeal, produces a compliant organization.

    "Just selling them technology or doing a gap assessment or doing a webinar or giving them a checklist... that is not sufficient," McBorrough said. "That has not met the moment."

    What he describes instead is a governance discipline — one that requires ongoing program management, daily and weekly and monthly commitments, and someone accountable inside the organization for making sure the program is actually running. Governance is not a product you buy. It is a discipline you build. And for a small manufacturing firm or a five-person professional services company in the DIB, that discipline doesn't exist by default.

    "Governance is a discipline," McBorrough said. "It's not something that a small business just does."

    That gap — between what compliance actually requires and what the market has made available — is what the Phase 2 suspension put on full display. Organizations that approached CMMC as a security program were barely affected by the announcement. Organizations that approached it as an audit to survive are now left with neither the certification nor the compliance.

    The Pricing Problem and What It Signals

    The DoW's announcement referenced organizations being quoted $600,000 for CMMC compliance. McBorrough, who runs a small business that has completed a C3PAO audit, is blunt about what those numbers represent.

    "CMMC should not cost you $600,000," he said. "CMMC should not cost you $500,000 or $400,000."

    Numbers like that don't emerge from thin air. They reflect what happens when organizations come to the compliance process late, without foundational governance in place, and need to build everything from scratch under time pressure. They also reflect an ecosystem that, in McBorrough's assessment, has been oriented primarily around audit readiness rather than sustained compliance.

    "Because of the need for CMMC compliance, we have an entire ecosystem of providers that are operating in sort of the audit readiness space with a focus on helping you pass your audit," he said. "A lot of the solutions are focused on helping you pass your audit, and a lot of providers are seeing this as a check mark that they have to get passed."

    That orientation produces a particular kind of work: expensive, compressed, and largely invisible once the audit is over. It does not produce a compliance program. It produces a moment of compliance.

    McBorrough's own approach at MC Global Tech is built around what he calls a fully managed security compliance operations model — specifically because the organizations that hire outside help to build their programs typically have no internal capability to sustain them afterward. "When you are doing CMMC," he said, "you are committing to doing things on a daily basis, weekly basis, monthly basis, quarterly basis."

    That commitment doesn't end with a certification. It doesn't end at all.

    Two Words: Affirming Official

    The most pointed part of McBorrough's analysis isn't about pricing or governance or implementation capacity. It's about personal accountability.

    Under current requirements — requirements the July 13 announcement explicitly left intact — defense contractors must submit self-assessments attesting to their compliance with NIST 800-171 in the Supplier Performance Risk System. Those assessments aren't filed by the company in the abstract. They're signed by a specific individual.

    "The affirming official is the senior leader within the government contractor that signs their name personally on their self-attestation," McBorrough said, "and they say that I am attesting that my company has implemented all of these controls — under threat of False Claims Act prosecution if this is found not to be true."

    That liability hasn't changed. If anything, the pause quietly increases the risk it creates. A mandatory C3PAO audit carries no legal penalty for failure;you don't get certified, you potentially wasted your money, and you try again. A false self-attestation is a different matter entirely.

    "There is significant legal risk for submitting a compliant attestation to the government that is not true," McBorrough said. "Taking away the driver for firms to get certified, I believe, increases that risk."

    The Department of Justice has already pursued a number of well-publicized False Claims Act cases against defense contractors whose self-attestations didn't match their actual security posture. In more than one case, the settlement amount exceeded what it would have cost to become compliant in the first place. The pause doesn't reduce that exposure. For organizations that use it as a reason to stand down on compliance work, it may increase it.

    The Direction of Travel

    One other detail in McBorrough's analysis deserves attention: the security requirements aren't standing still.

    CMMC Level 2 is currently built on NIST 800-171 Revision 2. A transition to Revision 3 is already announced. Revision 3 doesn't reduce the burden — it increases the number of assessment objectives and adds domains including supply chain security.

     

    "Security requirements are increasing," McBorrough said. "They're not decreasing. It's just how the government verifies it that is in question."

    The direction of travel has been consistent across administrations, across program iterations, across pauses and phase adjustments. The DoW is grappling with verification — with how to confirm that close to 100,000 contractors are meeting the standard. They are not grappling with whether the standard should exist.

    "We are under threat," McBorrough said. "The defense supply chain is on a constant threat, and we need to come up with better means of protecting controlled unclassified information."

    What the Industry Owes the DIB

    McBorrough's closing argument is an industry-level one, and it's worth stating plainly.

    Small defense contractors — the thousands of manufacturers, professional services firms, and specialized suppliers that make up the bulk of the DIB — are being asked to meet governance requirements that large enterprises have entire security organizations to address. Most have no CISO. Many have no dedicated IT staff. They are being approached by a market that sells them one piece at a time and leaves them responsible for assembling it into something that actually works.

    "As an industry, we need to come up with better solutions, and especially those that can be acquired by small businesses that have very limited capacity and very limited financial resources," McBorrough said.

     

    The pause is an opportunity to do that. The RFI the DoW released alongside the announcement accepts public comment through August 14 — an invitation for the industry to weigh in on what scalable, affordable, and meaningful compliance support actually looks like.

    What it doesn't look like, as McBorrough makes clear, is a six-figure engagement that produces a certification and nothing else. "Defense contractors, especially the small ones, need better solutions — not just piecemeal technology here, advisory here, gap assessment there, training there, and all that adding up. I think they need a more comprehensive approach to how we're going to tackle this problem."

    The announcement on July 13 didn't resolve that problem. But it named it. And for an industry that has spent years selling audit readiness instead of building compliance programs, that's a harder truth than any phase delay.



    This post is based on a recent CMMC Compass webinar featuring William McBorrough, Lead CMMC Assessor, CISO, and CEO of MCGlobalTech, and Andrew Lynch, VP of Channel Sales at Virtru. Defense contractors can submit comments on the CMMC program review via SAM.gov through August 14, 2026. Watch the full conversation with Andrew and William here

    Editorial Team

    Editorial Team

    The editorial team consists of Virtru brand experts, content editors, and vetted field authorities. We ensure quality, accuracy, and integrity through robust editorial oversight, review, and optimization of content from trusted sources, including use of generative AI tools.

    View more posts by Editorial Team

    See Virtru In Action