CYBERSECURITY

Consultants Warn of Overconfidence as CMMC Phase 2 Deadline Looms

6/30/2026
By Laura Heckmann

iStock illustration

The second implementation phase of the Defense Department’s Cybersecurity Maturity Model Certification program is fast approaching, and many companies are scrambling toward the deadline unprepared and overconfident, consultants said.

The program, known as CMMC, is the Pentagon’s mechanism for verifying contractors are compliant with its cybersecurity requirements, consisting of different levels being implemented in phases.

Phase 1, which started last November, dealt primarily with CMMC Level 1, which requires companies to submit an annual self-assessment and annual affirmation of compliance that they are doing “basic safeguarding” of federal contract information, according to the Defense Department’s Chief Information Officer website.

Perry Keating, managing director and president of Protiviti Government Services, described Level 1 as “pretty basic hygiene. It’s kind of like brushing your teeth,” covering 15 basic controls that “a lot of people pass.”

Level 2, however, jumps to 110 controls outlined in National Institute of Standards and Technology Special Publication 800-171 to protect controlled unclassified information, or CUI. The Defense Department estimates some 80,000 companies will require Level 2 certification.

While some Level 2 contracts allow for a self-assessment, most are expected to require certification by a CMMC third-party assessment organization, or C3PAO — and come Nov. 10, Pentagon solicitations will begin requiring Level 2 C3PAO certification where applicable.

Many companies will hire cybersecurity experts and consulting firms to guide them through the Level 2 requirements labyrinth and prepare for a C3PAO audit. “This is all we do,” said Emil Sayegh, CEO of CyberSheath, one such company that is entirely dedicated to helping Defense Department contractors comply with CMMC.

Part of CyberSheath’s process when working with companies is to perform a gap analysis. Sayegh said in an interview most companies are “nowhere near ready to be audited,” and it takes about six to nine months to get them ready, which many companies have not taken into account.

This timeframe is necessary because most environments are much more customized and complex than customers realize, he said. One of the most consistent problems he finds during gap analysis is overconfidence.

Sayegh said internal information technology departments will perform a self-assessment and determine their company’s Supplier Performance Risk Score — a Defense Department metric used to evaluate cybersecurity compliance — “and it is always overstated.”

For example, some companies claiming they use multi-factor authentication may not employ it across all systems that handle controlled unclassified information, he said.

Overconfidence goes hand in hand with defense contractors’ number one issue, Keating said — identifying controlled unclassified information.

Protiviti also helps companies prepare for CMMC assessment, and in working with clients, the firm has found that not only do many struggle to identify if they have controlled unclassified information in the first place, but also how to mark it when they do and what to do with it, he said.

By comparison, a framework for protecting credit card data simply requires users to recognize the standard 16-digit credit card number format and an expiration date, Keating said. “The problem with CUI is there are 84 categories.”

For prime contractors like Lockheed Martin and General Dynamics, controlled unclassified information is nothing new. These companies “knew this was coming. They invested in it. They already got their certifications previously,” Keating said.

Then there’s the “center mass” of companies realizing “I guess we better get with it,” he said. And lastly, there are the “latecomers” — companies that didn’t even know they needed Level 2 certification.

Suppliers of services such as critical infrastructure and research data that did not think CMMC would pertain to them are “kind of in a world of hurt, because they’re trying to sprint at the beginning of the marathon to get caught up,” Keating said.

The companies making gaskets, the bulletproof glass for Humvees or castings for the brakes on a fighter jet are still dealing with confidential information, Sayegh said. It all needs to be protected.

Once identified, controlled unclassified information needs to be tracked, and a custom environment needs to be built to protect it, he said — one of the reasons preparing for Level 2 takes six to nine months. Otherwise, the company runs the risk of committing another common mistake — incorrect scoping.

If controlled unclassified information is not identified and tracked correctly, CMMC compliance can become very expensive and interfere with day-to-day operations, Sayegh said.

An online event hosted by secure network provider Exostar in May, “The Path to CMMC Level 2,” hammered home the necessity of proper scoping.

Doug Berry, director of strategic programs and information security manager at information technology solutions company Synertex, told participants during the event to “minimize scope ruthlessly,” calling it the single biggest cost driver in CMMC.

“What I’ve seen is that with this increase in CUI and the mention of it, a lot of organizations are trying to respond by securing everything and securing it equally,” Berry said.

While this likely comes from good intentions, it also comes with unintended consequences, he said. “When you try to do that, suddenly, you’ve got more systems that are in scope. You’ve got more users that are impacted. You’ve got costs that go up dramatically.”

In addition to overscoping and CUI confusion, one of the biggest mistakes Keating sees companies make is thinking certification is just a documentation exercise.

“A lot of people have lots of problems with their documentation,” he said — such as keeping it up to date and with it being used as evidence. For example, if a document claims a 16-digit password is being used, but users are seen not using 16-digit passwords, they get dinged on documentation that says one thing, but practically they do another.

Another pitfall is thinking certification is a one-and-done process, Keating said. “I did the framework, I did the thing, I’m done.” In reality, “you have to be protecting the data, you have to forever be reviewing it.”

As companies sprint towards the November deadline, about 1,000 have successfully navigated the trenches of Level 2 certification and can both attest to its challenges and offer insight to panicking businesses.

IntelliGenesis, a provider of advanced artificial intelligence and machine learning cybersecurity solutions, achieved Level 2 certification in March, said Jeremiah Jensen, the company’s chief operating officer.

For IntelliGenesis, the process from preparation through successful audit was about four months, Jensen said in an interview, which was a slightly more accelerated timeline than he would recommend, noting that Sayegh’s six-to-nine-month timeframe is ideal.

Jensen’s experience leading up to the audit largely reflected what Keating and Sayegh reported — CUI is confusing, and documentation is underestimated.

“One of the things we kind of discovered was that it’s just not an IT thing; it was a company-wide audit. It affected everything,” Jensen said. “It affected how we store data, how we pass data” and everyone from the contracts department to human resources.

One surprising factor during the company’s gap analysis was the number of process and policy documents needed to support the audit, which totaled more than 50, he said.

A system security plan is an integral part of the CMMC audit, something IntelliGenesis already had, but needed to modify. The document essentially outlines how the company is implementing security requirements, and IntelliGenesis’ grew from a few hundred pages to 400 to 500, Jensen said, and was the most time-consuming and labor-intensive part of the process.

Jensen also attested to the CUI struggle, adding that an outside consultant was helpful.

The audit itself was a week-long process and very technical, Jensen said. The company’s IT person showed controls, data mapping and performed live demos. The assessor needs to see how the company is storing controlled unclassified information, if it’s being printed, how it’s controlled, and “come and visually walk through all those processes within the office.”

Jensen also echoed Keating’s caution that the process does not end after a successful audit.

“It’s all about the process of policies now,” such as how controlled unclassified information flows and is controlled, he said. “It’s become kind of ingrained into the company now, like our processes, so it’s kind of like an ongoing, continuous thing.”

Once certified, the certification is good for three years and recorded in a government system called the Supplier Performance Risk System, Keating said. Government officials can easily look in the system to see if a company is eligible or not to win a contract.

Without certification, “they will start to be ineligible to win new work, which for most people means the beginning of death,” he said.

At this point in the game, however, given the limited number of C3PAOs available, the reality is that every company that needs Level 2 certification is not going to achieve it by Nov. 10, he said.

“It’s a race against time,” he said — the website of CMMC’s official accreditation body, the Cyber AB, shows about 100 C3PAOs. The math “just doesn’t work,” and most assessors are booked solid six months out.

Organizations like CyberSheath and Protiviti can help companies find their controlled unclassified information, prepare documentation and avoid scoping issues, but they cannot alter time.

“We’re in the red zone,” Sayegh said. “The goal is not to just pass an audit — it’s for them to have a culture of cybersecurity where this information is truly protected, and we’re not going to take shortcuts.” 

 

Topics: Defense Department, Industrial Base