
The Department of War suspended CMMC Phase II requirements in July, citing cost as the central problem. The Reform Task Force reviewing what comes next is due to report back to the Department CIO this fall, which means the shape of whatever replaces Phase II is being decided now.
For the manufacturers and small suppliers in the defense industrial base who will live with that decision, the cost number driving it deserves a harder look than it's gotten.
A Number That Doesn't Match Reality
The Small Business Administration put compliance at roughly $593,800 per certification for a small firm that needs a third-party assessment, and around $388,600 for firms that qualify for self-assessment. That estimate, publicly credited by SBA Administrator Kelly Loeffler as approaching $600,000, is the number that justified pausing the program for small businesses across the defense industrial base.
IntelliGenesis is a small business. We needed a third-party assessment. We got certified for a little over $200,000.
That's not a rounding difference. It's a gap wide enough to raise a real question: either the SBA estimate was never grounded in what companies were actually paying, or the true cost swings so widely between small manufacturers and suppliers that no single number should have justified pausing the program for all of them.
Both possibilities are a problem. Neither has gotten serious scrutiny.
What Certification Actually Costs
I was in charge of carrying out our certification process, which is why I can give you the exact details about where the money was spent. Of course, the audit fees were included, but frankly that wasn't the largest component.
We needed to hire an external consultant since the assessors themselves can't tell you how to pass; all they do is check whether you have done so. We upgraded our environment to comply with FedRAMP requirements and transferred everything to GCC High.
We were forced to draw up about 50 procedures from scratch, since at Level 2 it's not enough to just state your intentions, you have to have documented and repeatable processes. Our system security plan grew to 400 or 500 pages. The entire exercise took around four months and involved a team of five or six people, with periods when we were working seven days a week just to keep up.
It does involve a real and considerable cost, but this cost has a definite form — namely, particular line items, specific hours, and specific decisions regarding the most efficient way to achieve it. A manufacturer starting with a different IT infrastructure or with other existing security measures would end up at a completely different point.
The SBA's figure doesn't show its workings in this way; instead, it takes a single average and applies it to a market comprising small businesses which differ immensely in size, in their existing infrastructure, and in the amount of the work they can carry out themselves as opposed to outsourcing it. By reducing this wide range of circumstances to one headline figure and then using that headline number to halt the program for all businesses, it treats a spread out distribution as if it were a fixed price.
The Real Bottleneck May Be Assessors, Not Requirements
Our CEO, Angie Lienert, agrees the cost problem is real. She just doesn't think certification work is what's driving it. Her view is that the pricing problem sits upstream, with the assessor market itself.
By SBA's own count, roughly 100 approved assessors are serving a defense industrial base of more than 120,000 small businesses. There are no grants to offset the cost, no tax credits, and nothing structurally holding prices down in a market that concentrated. If that's the actual driver, the number used to justify the pause was measuring a symptom, not the cause.
The importance of that distinction rests in the situation that follows: if the Task Force regards the SBA's estimate as the true cost of compliance, then the solution currently available will involve scaling back the obligations placed on manufacturers.
However, if the actual cost is more in line with what companies such as ours have actually paid and the figure of $600,000 is due to a supply-constrained assessor market rather than anything else, the necessary remedy should aim at the market for assessors rather than at the requirements themselves. If that is misunderstood, the Department will end up addressing a pricing issue by weakening a security requirement which wasn't the costly element to begin with.
A Pause That May Be Making the Problem Worse
There's also a shorter-term cost to the suspension itself. Assessors who built their business around Phase II now have less work while the review plays out, which pushes some of them out of the field. Fewer assessors serving the same enormous pool of manufacturers and suppliers is the opposite of what would bring prices down whenever the requirement returns.
Small businesses that already invested in certification, IntelliGenesis included, aren't asking for the requirement to disappear. We're asking that the number used to justify pausing it hold up to the same scrutiny the requirement itself was held to. Before the Task Force decides what replaces Phase II, it should look at what manufacturers are actually paying to get certified, not just the estimate that paused the program in the first place.
Jeremiah Jensen is Chief Operating Officer of IntelliGenesis LLC, a veteran-led, woman-owned defense AI and cybersecurity firm.






















