posted in

Sustaining CMMC Readiness

Achieving CMMC compliance is a significant milestone, but sustaining it over time requires far more than implementing technical controls. As outlined throughout the DoD CMMC Documentation, organizations continuously evolve through personnel changes, technology upgrades, business growth, and operational shifts, making alignment between governance, documentation, and day-to-day practices increasingly important.

Effective governance provides the structure needed to ensure security processes remain consistent, documentation reflects the current environment, and responsibilities remain clearly defined across the organization. While technical implementation establishes the foundation, long-term CMMC readiness is often sustained through disciplined governance, accountability, and continuous operational oversight.

Organizations that invest in strong governance today are often better positioned to sustain compliance well into the future.

Sustaining CMMC Readiness

posted in

💼 Career Opportunity | CMMC Assessor

Looking for your next opportunity in the CMMC ecosystem?

Smithers, an authorized Cyber AB Certified Third-Party Assessment Organization (C3PAO), is hiring CMMC Assessors (Independent Contractor and Full-Time) to support Defense Industrial Base (DIB) manufacturers through CMMC assessments and cybersecurity compliance services.

📍 Location: Remote (Fairlawn, OH, United States)

💼 Employment Type: Independent Contractor and Full-Time

Key Qualifications

• Meet and maintain Cyber AB Certified CMMC Assessor (CCA) or Lead CCA requirements

• Experience conducting CMMC assessments, surveillance, or related cybersecurity compliance activities

• Strong technical writing, assessment reporting, and documentation skills

• Excellent communication and client-facing experience

• Knowledge of CMMC assessment procedures and Cyber AB requirements

ISO/IEC 27001 Lead Auditor certification is desirable

Benefits

• Compensation based on experience and qualifications

• Medical, dental, and vision insurance

• 401(k) retirement savings plan

• Life insurance and AD&D coverage

• Wellness program

• Employee Assistance Program (EAP)

• Training and professional development support

• Hybrid work schedule

About the Organization

Smithers is a global testing, inspection, certification, and consulting organization founded in 1925. As an authorized Cyber AB C3PAO, Smithers provides independent CMMC assessment services that help organizations across the Defense Industrial Base demonstrate cybersecurity compliance.

Career Insight

This opportunity highlights the growing demand for qualified CMMC Assessors who combine technical expertise with strong communication, documentation, and assessment skills. As the CMMC program continues to mature, organizations are seeking professionals who can confidently support formal cybersecurity assessments.

🔗 Job Posting:

CMMC Assessor Opportunity at Smithers

💼 Career Opportunity | CMMC Assessor

posted in

Phase 2 Suspension

My two cents and personal opinions only:

The Phase 2 suspension feels more like a postponement than a halt of any kind.

"Additionally, the Department will begin a comprehensive review of CMMC aimed at aligning with Secretary of War Pete Hegseth's Acquisition Transformation System (ATS) directives prioritizing speed to capability, lowering barriers for small, medium, and non-traditional businesses, and replacing bureaucratic compliance with scalable, resilient cybersecurity measures."

I think this quote is the heart of the matter. I've seen estimates of ~80,000 contractors with level 2 requirements. According to this analysis it lists for CMMC Level 2:
Adoption rate: 8% (certified), 42% (in progress)
Average implementation time: 12-18 months
Compliance cost range: $75,000 – $300,000
(sources in link)

... which leads me to believe there's an estimated half (~40,000) of contractors where level 2 isn't on their radar.

Of course these aren’t official DoW numbers, but they paint a reasonable picture of the landscape.

I believe C3PAOs and assessors are still needed, and how/where they fit in will be realized during this 60-day window (or at least, eventually).

Speaking as someone who's not yet CMMC certified, I'm confident saying that the pursuit of becoming certified is worthwhile and I plan on doing so as soon as I can (because those T3 background checks won't be getting any shorter!)

Scroll to load more

Back

posted in

Announcements

Phase 2 Suspension

My two cents and personal opinions only:

The Phase 2 suspension feels more like a postponement than a halt of any kind.

"Additionally, the Department will begin a comprehensive review of CMMC aimed at aligning with Secretary of War Pete Hegseth's Acquisition Transformation System (ATS) directives prioritizing speed to capability, lowering barriers for small, medium, and non-traditional businesses, and replacing bureaucratic compliance with scalable, resilient cybersecurity measures."

I think this quote is the heart of the matter. I've seen estimates of ~80,000 contractors with level 2 requirements. According to this analysis it lists for CMMC Level 2:
Adoption rate: 8% (certified), 42% (in progress)
Average implementation time: 12-18 months
Compliance cost range: $75,000 – $300,000
(sources in link)

... which leads me to believe there's an estimated half (~40,000) of contractors where level 2 isn't on their radar.

Of course these aren’t official DoW numbers, but they paint a reasonable picture of the landscape.

I believe C3PAOs and assessors are still needed, and how/where they fit in will be realized during this 60-day window (or at least, eventually).

Speaking as someone who's not yet CMMC certified, I'm confident saying that the pursuit of becoming certified is worthwhile and I plan on doing so as soon as I can (because those T3 background checks won't be getting any shorter!)