Policy Evidence Triangle

Evidence for each policy recommendation

For every proposed reform to CMMC and the Defense Industrial Base cybersecurity ecosystem, we look for three things: evidence the problem exists, evidence of measurable impact, and evidence of stakeholder support. Anything less can be dismissed as "interesting but unsupported."

24
Total responses
Updated
hubzone 9small_no_designation 6sdvosb 5cyber_pro 2other 18a 1
Signal strength:StrongModerateWeakNo data
Recommendation 1

Accredited Shared CMMC Service Provider Program

Strong evidence

A DoD-approved, FedRAMP-style program that lets accredited MSPs/MSSPs host multiple small businesses inside standardized, validated CMMC environments with inherited infrastructure controls.

Problem exists

Small businesses that delayed, declined, reduced scope, or exited DoD work due to cyber requirements

52%
n = 21

11 of 21 small-business respondents

Building internally or unsure how they'll meet CMMC technical requirements

5%
n = 21

1 of 21 small businesses

Measurable impact

Expect ≥25% implementation cost reduction from an accredited shared environment

48%
n = 21

10 of 21 small businesses

Would participate in a DoD-piloted shared program (case study)

86%
n = 21

18 of 21 small businesses

Stakeholder support

Would likely adopt an accredited MSP/MSSP standardized CMMC environment

76%
n = 21

16 of 21 small businesses

Support DoD piloting the accredited shared program

4.5 / 5
n = 20

1 = strongly oppose, 5 = strongly support

All-respondent support for accredited shared provider program

4.3 / 5
n = 19

1 = strongly oppose, 5 = strongly support

Recommendation 2

Expand the Assessor Workforce (Equivalency Pathways)

Insufficient data

Recognize equivalent experience and expand qualification pathways (challenge exams, apprenticeships, prior-certification credit) so the assessor pool can match projected DIB demand.

Problem exists

C3PAO/assessor organizations reporting assessment wait times over 6 months

n = 0

0 of 0 assessor orgs

Cybersecurity professionals holding neither CCP nor CCA

100%
n = 2

2 of 2 cyber pros

Measurable impact

Cyber pros willing to spend 100+ hours becoming qualified as an assessor

0%
n = 2

0 of 2 cyber pros

Stakeholder support

Cyber pros who would pursue assessor qualification if equivalent experience were recognized

100%
n = 2

2 of 2 cyber pros

Support recognizing prior certifications toward assessor qualification

100%
n = 2

2 of 2 cyber pros

All-respondent support for challenge exams / equivalency pathways

3.9 / 5
n = 19

also: expand assessment capacity 4.1 / 5

Recommendation 3

DoD-Validated Reference Architectures

Strong evidence

Publish validated reference architectures (small office, manufacturer, MSP-hosted, OT/ICS, hybrid, R&D) to reduce implementation uncertainty and rework.

Problem exists

Most time-consuming CMMC implementation activity across small businesses

Policies
n = 16

weighted rank score 83

Measurable impact

Small-business rating of impact validated reference architectures would have on uncertainty

3.6 / 5
n = 19

1 = no impact, 5 = major impact

Most-requested architecture to publish first

Small office / professional services
n = 1

1 small businesses answered

Stakeholder support

All-respondent support for DoD-validated reference architectures

4.4 / 5
n = 19

1 = strongly oppose, 5 = strongly support

Recommendation 4

Standardized Acquisition Guidance for Contracting Officers

Strong evidence

Publish DoD-wide guidance so contracting officers apply CMMC consistently — level selection, timing, flow-down, waivers, and subcontractor verification.

Problem exists

Encountered CMMC requirements that appeared inconsistent with the sensitivity of the work

67%
n = 21

14 of 21 small businesses

Report differing interpretations between contracting officers affected their business

5%
n = 21

1 of 21 small businesses

Measurable impact

Small businesses that avoided bidding because of unclear acquisition requirements

48%
n = 21

10 of 21 small businesses

Acquisition issue creating the greatest uncertainty

n = 0
Stakeholder support

Small-business support for standardized DoD acquisition guidance

4.5 / 5
n = 20

1 = strongly oppose, 5 = strongly support

All-respondent support for standardized CO guidance

4.4 / 5
n = 18

1 = strongly oppose, 5 = strongly support

Recommendation 5

Continuous Assurance & Inherited / Shared-Responsibility Controls

Strong evidence

Expand inheritance and continuous-assurance models — automated evidence, continuous monitoring, and shared-responsibility credit from accredited providers, FedRAMP, cloud, and validated architectures.

Problem exists

Rank of 'Evidence collection' among most time-consuming CMMC activities

#4 of 7
n = 16

16 small businesses ranked

Measurable impact

Average perceived value of continuous-assurance & inheritance activities

4.1 / 5
n = 100

across 5 activities (automated evidence, continuous monitoring, inheritance credit)

Highest-valued single activity

Inherited controls from an accredited provider counting toward your assessment (4.3 / 5)
n = 100
Stakeholder support

All-respondent support for expanded inheritance / shared-responsibility

4.4 / 5
n = 19

1 = strongly oppose, 5 = strongly support

Support for continuous assurance / monitoring recognition

4.1 / 5
n = 19

Support for AI-assisted evidence collection

4.1 / 5
n = 19

Aggregated from survey responses. Metrics update every 30 seconds.