August 23, 2026 · Security
The Pentagon Just Proved a Compliance Mandate Can Price Out the Small Guy
The government just admitted, in its own words, that a security mandate got too expensive for the businesses it was written to protect.
On July 13, the Department of War suspended Phase 2 of the Cybersecurity Maturity Model Certification program, the rule that would have forced defense contractors handling controlled information to pay an outside assessor for a formal audit starting November 10. WilmerHale's summary of the announcement states the reason plainly: excessive cost and administrative burden, especially on small and mid-size contractors, was pushing them to exit or avoid the defense industrial base altogether. A newly formed CMMC Reform Task Force now has 60 days to report back, on or about September 13, after taking public comment.
That is worth sitting with. A federal security requirement got expensive enough, fast enough, that the agency writing it paused its own rule rather than watch the supply chain shrink. This is the free-market case against heavy compliance mandates playing out in real time, not as theory. The businesses big enough to absorb a six-figure audit bill stayed in the program. The businesses that could not, left, by the Department's own account. That is exactly the dynamic that entrenches large primes and locks out the leaner subcontractor who might have done the work for less.
Before I run further with that, the other side deserves its say, and it is a real case. Third-party assessment did not appear out of nowhere. For eight years the Pentagon relied on contractors to self-report compliance with NIST security standards, and a 2022 DoD Inspector General review examined 10 research contractors and found every one of them in violation of the standards they had attested to meeting. That is not a rounding error, it is the entire premise of self-attestation failing a real test, against adversaries who actively target the defense supply chain. The Government Accountability Office has warned that leaning on waivers and self-assessment during this pause undermines the reason CMMC exists. I am not arguing the security requirement itself is wrong. I am arguing the price tag broke it, and the price tag is a separate problem from the goal.
Here is why the price tag broke it. The Department's own baseline estimate for Level 1, the lower tier, ran $4,000 to nearly $6,000 for a small entity, for self-assessment alone. Level 2, the tier covering most defense subcontractors handling sensitive data, carried a DoD baseline of $105,000 to $118,000 for the assessment cycle, before remediation, tooling, or consulting, which the same estimate says routinely pushes the real number into the hundreds of thousands. A prime contractor books that as a rounding error against a nine-figure contract. A small machine shop or software vendor subcontracting into that same program cannot, and small subcontractors are who the Department says left.
The same math shows up outside defense work, just at lower stakes, and it is worth knowing before you sign a consultant's statement of work. A SOC 2 Type 2 audit, the credential SaaS vendors need to sell into enterprise customers, runs $12,000 to $20,000 in audit fees for a small to midsize company, with a realistic all-in first year, tools, readiness work, and internal time included, closer to $25,000 to $35,000. HIPAA compliance for a small medical practice is comparatively lighter: $5,000 to $15,000 in year one, with $3,000 to $8,000 a year to maintain it.
The lesson from CMMC applies to all three. Know what you are actually buying before an assessor shows up. Run a gap assessment first, ideally with a firm that is not also the one selling you the remediation hours, so the incentive to find more work is not built into the finding. That gap, not the framework's reputation for being expensive, is what actually drives your bill. Do not buy a full compliance automation platform before you know which controls you are missing. And confirm you need the specific framework being pitched to you: a HIPAA-covered practice does not need SOC 2, and a business with no federal contracts does not need CMMC at any level, no matter what a security vendor's cold email implies.
That gap-first approach is the audit readiness work my security team runs before a client pays an outside assessor a dollar: figure out what you actually need, close the real gaps, then walk into the audit instead of discovering it during one. Tell me which framework you are staring down and I will tell you honestly what it should cost.
Sources
Every factual claim above is drawn from these independently published sources, linked inline where first referenced.
Tell us what's on your mind.
You don't need a polished brief to reach out. A two-line email about what's bugging you is plenty; we'll tell you straight if we're the right fit, and what we'd tackle first.
We'll scope the work around your workflow, goals, and timeline before quoting anything, so you know what's included before committing.