For every proposed reform to CMMC and the Defense Industrial Base cybersecurity ecosystem, we look for three things: evidence the problem exists, evidence of measurable impact, and evidence of stakeholder support. Anything less can be dismissed as "interesting but unsupported."
A DoD-approved, FedRAMP-style program that lets accredited MSPs/MSSPs host multiple small businesses inside standardized, validated CMMC environments with inherited infrastructure controls.
Small businesses that delayed, declined, reduced scope, or exited DoD work due to cyber requirements
11 of 21 small-business respondents
Building internally or unsure how they'll meet CMMC technical requirements
1 of 21 small businesses
Expect ≥25% implementation cost reduction from an accredited shared environment
10 of 21 small businesses
Would participate in a DoD-piloted shared program (case study)
18 of 21 small businesses
Would likely adopt an accredited MSP/MSSP standardized CMMC environment
16 of 21 small businesses
Support DoD piloting the accredited shared program
1 = strongly oppose, 5 = strongly support
All-respondent support for accredited shared provider program
1 = strongly oppose, 5 = strongly support
Recognize equivalent experience and expand qualification pathways (challenge exams, apprenticeships, prior-certification credit) so the assessor pool can match projected DIB demand.
C3PAO/assessor organizations reporting assessment wait times over 6 months
0 of 0 assessor orgs
Cybersecurity professionals holding neither CCP nor CCA
2 of 2 cyber pros
Cyber pros willing to spend 100+ hours becoming qualified as an assessor
0 of 2 cyber pros
Cyber pros who would pursue assessor qualification if equivalent experience were recognized
2 of 2 cyber pros
Support recognizing prior certifications toward assessor qualification
2 of 2 cyber pros
All-respondent support for challenge exams / equivalency pathways
also: expand assessment capacity 4.1 / 5
Publish validated reference architectures (small office, manufacturer, MSP-hosted, OT/ICS, hybrid, R&D) to reduce implementation uncertainty and rework.
Most time-consuming CMMC implementation activity across small businesses
weighted rank score 83
Small-business rating of impact validated reference architectures would have on uncertainty
1 = no impact, 5 = major impact
Most-requested architecture to publish first
1 small businesses answered
All-respondent support for DoD-validated reference architectures
1 = strongly oppose, 5 = strongly support
Publish DoD-wide guidance so contracting officers apply CMMC consistently — level selection, timing, flow-down, waivers, and subcontractor verification.
Encountered CMMC requirements that appeared inconsistent with the sensitivity of the work
14 of 21 small businesses
Report differing interpretations between contracting officers affected their business
1 of 21 small businesses
Small businesses that avoided bidding because of unclear acquisition requirements
10 of 21 small businesses
Acquisition issue creating the greatest uncertainty
Small-business support for standardized DoD acquisition guidance
1 = strongly oppose, 5 = strongly support
All-respondent support for standardized CO guidance
1 = strongly oppose, 5 = strongly support
Expand inheritance and continuous-assurance models — automated evidence, continuous monitoring, and shared-responsibility credit from accredited providers, FedRAMP, cloud, and validated architectures.
Rank of 'Evidence collection' among most time-consuming CMMC activities
16 small businesses ranked
Average perceived value of continuous-assurance & inheritance activities
across 5 activities (automated evidence, continuous monitoring, inheritance credit)
Highest-valued single activity
All-respondent support for expanded inheritance / shared-responsibility
1 = strongly oppose, 5 = strongly support
Support for continuous assurance / monitoring recognition
Support for AI-assisted evidence collection
Aggregated from survey responses. Metrics update every 30 seconds.