Some contractors got CMMC certified early. Now the implementation is on hold. | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


Terry Gerton Angie, you at IntelliGenesis made the decision to pursue CMMC Level 2 certification before it was required. That’s certainly a topic of interest these days. Why did you decide to move early rather than wait and see?

Angie Lienert We decided to move early because we were starting to see some of the CMMC requirements language coming out in some of the most recent contract solicitations. And we realized at that point that we don’t anticipate any changes. We do see that the government is going to move forward with their plans. And we want to make sure that we are going to be in the position to be awarded some of those contracts. And in order to ensure that availability of reward, we need to go ahead and with the steps and secure our CMMC level two certification. So we did.

Terry Gerton So you viewed it as a source of competitive advantage.

Angie Lienert Not only competitive advantage, I mean, really out of necessity. If the government is mandating, this is a requirement for you, for contractors to be able to perform and win awards, to be able to do the work that we’ve been doing for the past 19 years, as other requirements, we have to make sure that those requirements are satisfied. And we also, as a small business, started to see with some of our other larger partners. They were pushing the requirements down a lot earlier, trying to make sure that the small businesses were going through with the certifications. And if not, I don’t want to say threatening, but that’s the word I’m going to use, threatening, to remove the businesses from the team and from the work. So again, it was out of necessity that we moved forward and went ahead and made the huge investment to make sure that we were going to be compliant and be able to be eligible for this work.

Terry Gerton Jeremiah, Angie’s just called this a huge investment. There’ve been a lot of concerns about exactly how heavy of a lift this is for small businesses. You were in charge of it. What did the certification actually require in terms of time and effort and resources?

Jeremiah Jensen Yeah, good question. Yeah, the time, effort, resources. It was pretty intense to take the company. And looking at all the requirements that we had to answer, I ended up working with our technical team. Of course, they understand how to put together all the technical documentation, secure infrastructure and do the patching and everything. But one of the things that we really had to look at was our documentation. We had to update a SSP, we had to basically write over 50 documents in order to kind of support all these policies and processes that they were calling for within CMMC. So it was a huge effort of trying to get the requirements and kind of taking a lift off of the technical folks so they could work on kind of doing the updates and making sure we were moving all our CUI information into the GCC high while on the other side we ended up writing the backbone kind of the documentation in order to kind of support everything. So we had four months in order to really kind of put this together and, I mean, the team was working seven days a week on it to try to get this to the finish line.

Terry Gerton Angie, when given the level of work and the level of investment that Jeremiah has just described, when DOD suspended the phase two requirements, what was your immediate reaction?

Angie Lienert Let me see. Let me clean that up a little bit. I was very frustrated at the decision, because again, this is something that they’ve been talking about for a very long time. We, IntelliGenesis, as well as other companies have mentioned some of the concerns we have. I mean, let me be clear, we are a cybersecurity company. We understand the risk associated with companies not being protected and the supply chain and all the risks that are associated with that. That is what we do, we understand it completely. But the CMMC is a lot more involved in just cybersecurity. I mean, as Jeremiah mentioned, there’s all the policies that have to be addressed. The documentation, it’s typical, I don’t wanna say bureaucracy, but a lot of the policies that govern it that are necessary to have a baseline, but don’t necessarily guarantee that cybersecurity, but it is a step in the right direction, right? It is a very heavy lift though. So for us, I mean that we invested, including our, our own team’s time, a few hundred thousand dollars, I means over $200,000 to be a little more specific and for a small business, that’s significant. So I was very frustrated that that $200,000+ and all the amount of time that the team spent on that could have been used in other areas of the company. That time we spent with the CMMC instead of the seven days a week for months at a time could have been used winning other work, building new technologies in other areas. So it was just, it was very frustrating and disappointing to say the least.

Terry Gerton Angie Lienert is owner president and CEO of IntelliGenesis and Jeremiah Jensen is their COO. Angie, let me just follow up. The companies that waited to pursue CMMC avoided the cost and the uncertainty that you’re dealing with now. What lessons do you worry that industry is taking from this experience?

Angie Lienert Well, I’m very worried that this is going to cause future delays and problems for any kind of policy that’s going to be rolled out or mandate. Why should we believe that we actually have to do it, even when we’re seeing it in the solicitations, if we know that all of a sudden it can just change or it can be delayed. Again, there are no grants. There are very limited resources, vendors, auditors that are available for this and to think that we just went through this and had to pay all this money out. There’s no tax credits. I mean, this is just money out the door and this time that’s wasted. So honestly, what will happen next time? I and probably many other companies will wait. We will probably wait and let that deadline pass and then worry about it. Because again, that is time, resources, money, investments that could have been placed in other areas of the business that are now just, for what?

Terry Gerton The NIST standards have been around for a while here, the standards that CMMC is based on. What’s your take on the approach that may come out of this, which is companies still continue to self attest that they’re compliant with those NIST standard?

Jeremiah Jensen Yeah. So, I mean, that’s been going on for a while. We’ve been self-attesting to CMMC and going forward, and it takes a lot of the paperwork and kind of the burden of going to that next level where we really had to kind of do all the paperwork and put that in place. So, I think the self-attestation, as they’re moving through it, I think that’s a good starting point, but going to the next level, I mean, if they’re going to look at adding this into the contracts and stuff, you know, having that next layer at the level, but then you got to realize all this paperwork and all the processes are going to come when you go up to the next level.

Terry Gerton Angie, as the owner of the company, how do you feel about the risks that you take on with that self attestation approach?

Angie Lienert That’s a great question. And that’s, I was actually wanting to say something about that again, we’re a cybersecurity company. So we understand the risk associated. We make sure that we are already protected and we are very good at what we do. The concern that I have and that with this, and I know it’s been around for a while, that self attestation, some people, I mean, there’s no auditing of that. There’s no guarantee that people are even doing it other than signing a piece of paper. Yeah, my network’s good. Yeah, we’re good to go. I mean, that’s the whole point and the principle behind having these different certifications is to make sure that somebody is coming in behind you and making sure that yes, your network actually is safe. Yes, you are secure enough to be able to handle these government contracts. I mean, having the NIST requirements for companies that take it seriously, that’s great. But how many of them are there really that do that? And how can we verify that they are doing it correctly unless there is this other layer? And so honestly, it’s terrifying.

Terry Gerton And so what do you wish or hope that DoD does differently as a result of this 60 day review that they’re conducting now?

Angie Lienert Well, I hope that they realize that this requirement’s been out there for a few years now. So, this is kind of late in the game. If people are complaining about it, that’s too bad. They need to move forward with the requirement and the deadlines they set. Don’t set a deadline and make contractors adhere to it, if you’re not going to follow through with it. So you set a deadline. Stick to what you’ve done and everybody else, they’re either going to have to catch up or they’re not going to do business with the government.

Terry Gerton Do you see future challenges in the market, especially for small businesses, if the requirement continues as a certification requirement and primes continue to have to force the compliance standards down through their supply chains?

Angie Lienert I do. I think that it’s important. I think as a small business, there should be some other kind of resources or something available because the pricing again, it doesn’t seem to be controlled. So there’s only a few companies that can perform these services so that the prices are outrageous. I’d really like to see some kind of interference or involvement from the government to try to help lower some of those costs. So small businesses can feel comfortable with the service that they’re receiving and also be able to afford it or have some type of tax credits associated with it. Just some way to kind of help reduce that cost that is required for the small businesses. That would be ideal.

Copyright
© 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.



——————————————————-


Click Here For The Original Source.

National Cyber Security

FREE
VIEW