For years, the Department of Defense's cybersecurity certification program has been a future problem. Something to plan for. Something on the roadmap. Contractors talked about CMMC the way people talk about getting in shape — vaguely, eventually, with a PowerPoint deck they'd update every quarter.
That era just ended.
On November 10, 2025, CMMC became a contractual requirement in new Pentagon solicitations. On November 10 of this year, it enters Phase 2: contractors handling sensitive defense information will increasingly need an independent certification from an authorized assessor before they can even bid. The planning phase is over. The enforcement phase is here.
Why this matters more than most compliance deadlines
This isn't like renewing a certification or updating a policy document. CMMC Level 2 — the tier most defense contractors will need — requires a full independent assessment against 110 security controls. The Pentagon estimates the cost at $105,000 to $118,000 per three-year cycle for a small business. Industry practitioners who've been through the process put the real number closer to $150,000 to $400,000 once you include fixing the gaps the assessment finds, buying the tools you're missing, and documenting everything properly.
Here's the problem: 70% of defense contractors budgeted less than the Pentagon's own minimum estimate, according to a 2026 survey of more than 2,000 companies. That's not a readiness gap. That's most of the market not understanding what they signed up for.
The Colorado angle is ugly
Colorado's aerospace and defense sector employs 55,000 people and brings in $23 billion a year in federal contracts. The primes — Lockheed Martin in Littleton, the former Ball Aerospace in Boulder, Raytheon in Aurora — will be fine. They have compliance teams and legal departments. The supply chain underneath them won't be.
Consider a machine shop in Colorado Springs with $2 million in annual revenue, $400,000 of which comes from defense subcontracts. To stay eligible, that shop needs to spend somewhere between $75,000 and $250,000 on remediation and assessment, plus $17,000 to $50,000 a year on ongoing maintenance. The compliance cost approaches or exceeds the entire profit margin on their defense work. The math doesn't improve if you're smaller.
Strikegraph, a firm tracking the rollout, projects that 33,000 to 44,000 companies — 15 to 20% of the entire defense industrial base — will exit between now and 2027. The smallest subcontractors will take the heaviest losses. That includes machine shops, testing labs, electronics suppliers, software subcontractors. The quiet backbone of the defense supply chain.
It's not just money. There's a capacity problem.
As of January, there were 97 authorized assessment organizations in the entire country. An estimated 80,000 contractors will eventually need Level 2 certification. Fewer than 1,000 organizations have achieved it so far — about 1%. Even if every contractor had the budget tomorrow, there aren't enough assessors to get them all certified by next November.
The Pentagon's own guidance acknowledges that early enforcement may "limit competitors or drive cost." Translation: some companies will lose contracts not because their security is bad, but because an assessor hasn't gotten to them yet.
What contractors should do right now
If you're a defense contractor or subcontractor — or even a company that occasionally takes on defense-adjacent work — here's where to start:
Find out which level you need. CMMC Level 1 is a self-assessment. Level 2 requires an independent third-party certification for most contractors. The level depends on what kind of information you handle, not how big your company is. Don't guess — and don't assume being small exempts you.
Do a gap assessment now. Not a full audit — just an honest look at your current security posture against the 110 controls in NIST SP 800-171. You need to know how big the gap is before you budget for it. Most contractors underestimate this by a lot.
Get in the assessor queue early. There are 97 assessment organizations for 80,000 contractors. That queue is only going to get longer. If you wait until the contract requires it, you'll be too late.
Budget realistically. The Pentagon's $105,000 estimate is for the assessment itself. You also need remediation, tools, documentation, and ongoing maintenance. Plan for $150,000 to $250,000 as a small business. If your defense contracts can't support that, you need to make a business decision — not a compliance one — about whether that work still makes sense.
This isn't a cybersecurity problem disguised as a business problem. It's a business problem with cybersecurity costs attached. The contractors who handle it well won't be the ones with the best firewalls. They'll be the ones who did the math early enough to do something about it.
If you're a defense contractor or supplier and you haven't done a CMMC gap assessment yet, have a conversation with someone who understands both the technical requirements and the business math. The clock is running, and November comes faster than most people think.