**Navigating CMMC: Lessons from Early Adoption and the Path Forward**
In a landscape where cybersecurity compliance is increasingly tied to government contracting, the journey toward CMMC (Cybersecurity Maturity Model Compliance) certification has become a pivotal decision for contractors. Recently, *Federal News Network* hosted a discussion featuring industry leaders Terry Gerton, Angie Lienert (Owner, President, and CEO of IntelliGenesis), and Jeremiah Jensen (COO of IntelliGenesis). The dialogue centered on IntelliGenesis’ proactive pursuit of CMMC Level 2 certification before it became a mandatory requirement, shedding light on the challenges, frustrations, and lessons learned from their experience. Below, we explore key insights from the discussion, address frequently asked questions, and conclude with the implications for the future of CMMC compliance.
—
### Key Insights from Industry Leaders
IntelliGenesis decided to pursue CMMC Level 2 certification early, driven by clear signals from the Department of Defense (DoD) that CMMC requirements were becoming embedded in contract solicitations. Angie Lienert emphasized the necessity of staying ahead of compliance curves to remain eligible for awarded contracts, highlighting the potential competitive advantage of early action. Jeremiah Jensen detailed the intensive effort involved, noting that the certification process required over 50 documents, technical updates, and a significant investment of time and resources—so much so that the team worked seven days a week for four months to meet the standards.
When the DoD suspended Phase 2 requirements, Lienert expressed frustration, viewing the move as a setback for companies that had already invested substantial resources. She warned that the uncertainty could discourage future compliance efforts, creating a challenging environment for policy implementation. The discussion also underscored concerns about self-attestation under NIST standards, with Lienert and Jensen emphasizing the lack of auditing and verification, which undermines the credibility of self-assessed compliance.
—
### FAQ Section
**1. Why did IntelliGenesis decide to pursue CMMC certification early?**
IntelliGenesis chose to pursue CMMC Level 2 certification early because they saw language related to CMMC requirements in recent contract solicitations. They recognized that the government was committed to implementing these standards and wanted to position themselves to win contracts. Early certification was also driven by pressure from larger partners pushing compliance down the supply chain, with threats to remove non-compliant vendors from teams.
**2. What did the CMMC certification process involve for IntelliGenesis?**
The certification process was resource-intensive, requiring over 50 documents to support policies and processes outlined by CMMC. The technical team updated infrastructure, ensured proper patching, and moved Controlled Unclassified Information (CUI) into GCC High, while the administrative team focused on documentation. The timeline was tight, with four months to complete the effort, demanding significant time and effort from the team.
**3. How did the DoD’s suspension of Phase 2 requirements impact IntelliGenesis?**
The suspension was met with frustration, as the company had already invested over $200,000 and months of effort into achieving certification. Lienert argued that such delays undermine confidence in future mandates, especially when contractors are required to adhere to deadlines that may later change or stall.
**4. What are the concerns around self-attestation for NIST standards?**
Self-attestation lacks auditing and verification, raising questions about whether companies are genuinely compliant. While NIST standards have been around for years, the absence of third-party validation weakens the assurance that contractors are adequately protecting government data.
**5. What does Angie Lienert hope for from the DoD’s ongoing review of CMMC?**
Lienert hopes the DoD will recognize that its requirements are already years in the making and move forward decisively. She stressed the importance of consistency and accountability, urging the government to stick to deadlines and provide resources—such as grants or tax credits—to help small businesses manage the high costs of compliance.
**6. What challenges do small businesses face with CMMC requirements?**
Small businesses face significant financial and operational hurdles, including high certification costs, limited access to affordable auditing services, and the burden of documentation. Without government intervention to reduce costs or provide support, small businesses may struggle to remain competitive in contract bidding.
—
### Conclusion
The discussion surrounding CMMC certification reveals a complex balance between cybersecurity necessity and practical implementation. IntelliGenesis’ experience highlights both the value of early adoption and the risks of delayed or inconsistent policy enforcement. While CMMC aims to strengthen supply chain security, the burden on small businesses and the uncertainty created by shifting deadlines threaten to undermine its effectiveness.
For the DoD and other stakeholders, the path forward must include greater transparency, consistent timelines, and financial support to ease the compliance burden. Without these measures, companies may hesitate to pursue certification, leaving government contracts and critical data at risk. As the cybersecurity landscape continues to evolve, collaboration between the government and industry will be essential to ensure that security goals are met without stifling innovation or small business growth.



