Cybersecurity Maturity Model Certification (CMMC) Unlocked
All Episodes

Why CMMC Certification Could Take 97.5 Years

Eric Marquette and Paul Netopski unpack the staggering backlog behind CMMC Level 2 certification, from the 97.5-year pace of assessments to the looming 2028 rollout that could jam the defense supply chain. They also dig into the assessor shortage, the cost of staying credentialed, and why a grow-your-own workforce strategy may be the only way to break the cycle.


Chapter 1

The Bottleneck in Black and White

Eric Marquette

Welcome to the show everybody! I'm Eric Marquette, and I'm here with Paul Netopski. Paul, I was looking through some recent industry data, and I stumbled on a number from the May 2026 Elysian Technology snapshot that completely blew my mind. If we keep going at our current pace of assessments, it is going to take ninety-seven point five years to get the remaining defense contractors certified. Ninety-seven and a half years!

Paul Netopski

Ninety-seven point five. Think about that, Eric. That means we would wrap up these certifications somewhere around the year 2123. The Department of Defense wants this fully implemented by 2028, and we're looking at a timeline that stretches into the next century because we are currently certifying only about one hundred companies a month.

Eric Marquette

It is wild when you look at the actual scale of the remaining backlog. The data shows there are one hundred and sixteen thousand, eight hundred and fifty-one Level 2 organizations still waiting for their certifications. Out of an original pool of over one hundred and eighteen thousand!

Paul Netopski

Exactly, the exact number is one hundred and sixteen thousand eight hundred and fifty-one. And here is the paradox, the demand illusion: contractors think there's no rush because they see the 2028 phased rollout as some kind of hall pass to delay. But they're ignoring the reality of the math. We're seeing fewer than two hundred active assessments per month right now because companies are caught in this loop of "false starts" where they prep, realize they aren't ready, and push the audit back.

Eric Marquette

Right, like those "false starts" are completely invisible in the official numbers. The snapshot mentioned that unless we're averaging nine false starts per C3PAO per month, there's basically no real, active demand pulling on the system right now. But once that 2028 deadline hits, everyone's going to rush the door at once.

Paul Netopski

And that is when the entire defense supply chain grinds to a screeching halt. If you are a subcontractor on a major weapon system or a critical logistics program, and you don't have that Level 2 certification, you will not be allowed to handle Controlled Unclassified Information. Period. The contract stops. It's a self-inflicted bottleneck, and it drives me absolutely crazy to watch companies treat this like a college term paper they can pull an all-nighter to finish.

Chapter 2

The Lead CCA Obsession and the Junior Assessor Desert

Eric Marquette

Well, let's talk about the people who actually have to do these audits. Because even if all one hundred and sixteen thousand companies suddenly lined up tomorrow, we have a massive staffing problem. C3PAOs seem to be completely obsessed with hiring only top-tier Lead Certified CMMC Assessors, or LCCAs. Why is that?

Paul Netopski

It's a unicorn hunt, Eric. The C3PAOs want Lead CCAs because they are the only ones authorized to actually lead the assessment teams and sign off on the final package. So you have a tiny, highly expensive pool of elite talent, while the rest of the workforce is left out in the cold. In May 2026, we only had five hundred and sixty-two LCCAs in the entire ecosystem.

Eric Marquette

Five hundred and sixty-two LCCAs to cover over one hundred and sixteen thousand companies. That is an absurd ratio. Meanwhile, we have one thousand, seven hundred and fifty Certified CMMC Professionals, or CCPs, and nine hundred and eighty-eight regular CCAs. Why aren't they out in the field doing the heavy lifting?

Paul Netopski

Because they're stuck in an "experience desert." To get certified as a Lead, or even just to maintain your credentials, you need actual, on-site assessment hours. But because the assessment volume is so low right now, C3PAOs can't afford to put junior CCPs or CCAs on a billable engagement. If you only have one assessment per C3PAO per month, you can't justify deploying a multi-tier team.

Eric Marquette

So the junior assessors can't get the hours they need to advance, which means we can't grow the pool of Lead Assessors. It's a classic chicken-and-egg workforce development failure.

Paul Netopski

It is a complete failure of the apprenticeship model. If we aren't structured to train the next generation of cyber defenders in the field, we are bottlenecking our own security posture before the audits even begin.

Chapter 3

The Toll of the Transition: ISACA, CCIs, and the Cost Barrier

Eric Marquette

And it's not just a lack of field hours that's holding people back. The professional and financial hurdles to stay in this ecosystem are incredibly steep. We recently saw a major administrative shift with the CMMC Assessor and Instructor Certification Organization, or CAICO, handing over responsibilities to ISACA. What's the strategic impact of that move?

Paul Netopski

Well, bringing in ISACA is an attempt to standardize professional credentials on a global scale. They have the infrastructure. But the transition itself has taken a real toll on the individual practitioners. Even with ISACA revising the pricing, the cost of just keeping your credentials active is a major barrier.

Eric Marquette

Right, the three-year cost for a CCP or CCA went down from thirty-one hundred and seventy-five dollars to twenty-two hundred and eighty dollars. But that's still over two thousand dollars out of pocket for an individual, on top of exams, training courses, and annual maintenance fees.

Paul Netopski

Exactly. Twenty-two hundred and eighty dollars is a lot of money for a credential that you might not even be actively billable on yet because of the lack of assessment volume. It's pushing independent assessors out of the market entirely. And then you have the instructor side of the house.

Eric Marquette

Yes! The training pipeline. The provisional instructor program is officially sunsetting in December 2026, right?

Paul Netopski

Yes, December 2026. All one hundred and twenty-four Provisional Instructors have to transition to the CMMC Credentialed Instructor, or CCI, pathway. But only thirty-seven qualify for the fast track, while eighty-seven have to go through the full application process. And the operational bar for these trainers to maintain their status under ISACA is incredibly high. If we lose our trainers, we lose any hope of scaling the assessor workforce to meet that forty-times increase we need.

Chapter 4

Breaking the Loop: Lessons from History

Eric Marquette

You know, this whole situation feels like history repeating itself. We've seen similar rollouts in other frameworks, like the early days of FedRAMP with their Third-Party Assessment Organizations, or the Qualified Security Assessor shortages in the PCI-DSS market.

Paul Netopski

It is the exact same playbook, Eric. In the early days of PCI and FedRAMP, everyone waited until the last minute. The demand spiked overnight, the assessor pools were tiny, and backlogs skyrocketed. The only way to break this loop now is for C3PAOs to adopt a "grow your own" assessor strategy.

Eric Marquette

Meaning, instead of poaching those expensive Lead CCAs from each other, they need to actively pair junior CCPs with veterans on these early, slower-paced assessments.

Paul Netopski

Precisely. Treat these current assessments as training grounds. Build the capacity now so you have the team ready when the floodgates open. Because let me be blunt with the defense industrial base: the assessor pool cannot scale forty-fold overnight. If you sit on your hands and wait until the 2028 deadline to schedule your Level 2 audit, you are going to find yourself locked out of DoD contracts, holding a very expensive, very late ticket to a game that's already started.

Eric Marquette

A powerful warning to end on. Paul, thanks for the masterclass. And to everyone listening, don't wait for the bottleneck to pinch before you take action. We'll see you next time.

Paul Netopski

Stay secure, everyone.