
For many defense contractors, the path to compliance feels like building an aircraft that’s already in flight. With the Department of Defense (DoD) rolling out a multi-phase implementation plan, the pressure on Organizations Seeking Certification (OSCs) to secure their position in the defense industrial base is facing a CMMC Assessment Bottleneck. Below are crucial insights from KLC Consulting’s March 2026 “Ask the Experts” webinar, including practical wisdom to understand the assessment timeline, risk reduction, and recommendations to prepare.
Timing the CMMC Assessment Market
The defense industry is currently facing a significant logistical CMMC Assessment Bottleneck. With approximately 77,000 contractors requiring certification and about 100 authorized C3PAOs currently active, the math for 2026 and 2027 is clear: The system still works if demand is distributed. It breaks if behavior clusters. While the DoD has established a phased implementation plan, the reality is that contracting officers already have the discretion to require a CMMC Level 2 Certification Assessment in current solicitations.
Don’t wait until you’ve lost DoD contract opportunities. KLC Consulting is already booking Authorized C3PAO Assessment Services well into 2027. By engaging now, you ensure that when a multi-million dollar contract hits the street, your certification is a competitive advantage rather than a barrier to entry.
- Ramp-up over 7 years
- Peak demand years (Years 3–5) show ~8k → 16k → 16k certifications/year
- That’s where scheduling friction is most likely
- Stabilization by Year 7
- If contractors cluster late, bottlenecks are inevitable
Number of Total Entities Over Phase-In Period
| Yr | Level 1 Self-Assess | Level 2 Self-Assess | Level 2 Certification | Level 3 Certification | Total |
|---|---|---|---|---|---|
| 1 | 945 | 27 | 517 | 4 | 1,493 |
| 2 | 4,720 | 136 | 2,599 | 50 | 7,505 |
| 3 | 15,748 | 453 | 8,666 | 169 | 25,036 |
| 4 | 30,184 | 867 | 16,610 | 323 | 47,984 |
| 5 | 30,179 | 867 | 16,606 | 323 | 47,975 |
| 6 | 30,179 | 867 | 16,606 | 323 | 47,975 |
| 7 | 27,246 | 783 | 14,994 | 295 | 43,318 |
| Total | 139,201 | 4,000 | 76,598 | 1,487 | 221,286 |
Assure Certification Success with a CMMC Mock Assessment Bundle
Surprises are the enemy of a successful certification. To mitigate this risk, KLC Consulting offers a comprehensive CMMC Mock Assessment Bundle. Think of this as a practice test that mirrors the intensity of the real exam without the permanent record. During a mock assessment, our team identifies deficiencies in a collaborative setting, enabling you to self-remediate before the official assessment. And we perform a POA&M review before the official assessment to verify your fully prepared before we create the official record in the DoD’s eMASS system.
Beyond the peace of mind, there is a financial incentive: OSCs can save up to 50% on total costs when they bundle their mock review with their final certification through KLC Consulting. This approach provides assurance for your business, as it familiarizes your team with the assessment process and significantly alleviates the anxiety of an official CMMC Level 2 Certification Assessment.
Prepare for What the Timeline Demands
CMMC Level 2 Certification is both a compliance challenge and a scheduling challenge because 77,000 other companies are also vying for C3PAO assessment services, it’s a clear CMMC Assessment Bottleneck
KLC Consulting provides authorized C3PAO assessment services designed to help organizations navigate both challenges. Download the CMMC Level 2 Readiness Checklist or contact our team to begin planning your assessment within a system that rewards preparation and punishes delay.
Capacity Is a Known Risk, the CMMC Assessment Bottleneck is real
A recent GAO review highlights a structural dependency in the CMMC program: the Department of Defense relies on private sector assessors to execute certification at scale, but has not fully documented how it will mitigate the risk if that capacity proves insufficient.
This matters in practice. The rollout model assumes steady growth and consistent throughput. If assessor capacity lags or demand clusters: delays are inevitable. For organizations pursuing certification, this shifts the question to – can I get assessed in time to meet my contract requirements? Timing becomes an important strategic variable.
Collaboration instead of Friction
At KLC Consulting, we believe an assessment should be a collaborative engagement between the OSC and the C3PAO. To support this, we provide our Objective Evidence List (The Assessor’s Playbook) to ensure total transparency. We want you to know exactly what we are looking for before we ever step foot in your environment.
Whether you are managing a complex on-premise manufacturing facility or a streamlined cloud-based enclave, our goal is to help you articulate how you satisfy your security requirements. The transition to CMMC is a compliance shift that prioritizes constant monitoring and senior management support over “one-and-done” compliance. Avoid the CMMC Assessment Bottleneck and get started.
CMMC Town Hall – March Session. Read the Transcript.
Cyber AB CMMC Town Hall – March Session
Cyber AB Town Hall Summary: March 2026
The March 2026 Cyber AB Town Hall addressed significant transitions within the CMMC ecosystem, specifically focusing on the final handover of training and credentialing to ISACA, a deep dive into the recent GAO report, and the emergence of CMMC requirements in active solicitations.
Strategic Program Updates
- GAO Report Findings: The GAO’s “deep dive” into CMMC success factors found the program has a strong mission statement and clearly defined roles. However, it flagged “key external factors” as a risk, specifically regarding whether the private sector ecosystem has the capacity to meet demand.
- Congressional Testimony: Kirsten Davies, CIO, recently testified before Congress, addressing the balance between small business implementation costs and the imperative to protect Controlled Unclassified Information (CUI).
- Leadership Changes: Stacey Boschanick has announced her retirement from federal service after 27 years, having served as a primary lead for the CMMC PMO. Locally, Emily Ermellini has joined the Cyber AB as Director of Executive Administration.
Ecosystem Growth & Metrics
- Certificates Issued: The ecosystem has eclipsed 1,074 Level 2 certificates issued by C3PAOs.
- Professional Cadre: There are currently 103 authorized C3PAOs, 759 CCAs, and 1,564 CCPs. Lead CCAs saw a 7% growth this month.
The ISACA Transition (Effective April 1, 2026)
The CAICO (CyberAB Accreditation Body) officially completes its handover to ISACA tomorrow.
- Platform Integration: Starting at 10:00 AM Central tomorrow, candidates can manage certifications via the “My ISACA” page.
- Fee Structure: Exam fees will transition to ISACA’s standard pricing ($575 for members / $760 for non-members). However, those who completed training in the last six months will have the previous Cyber AB pricing honored.
- New Content & NIST 800-171 Rev 3: ISACA will release new training content in Q4 2026 aligned with NIST 800-171 Rev 3.
- Bridge Courses: To manage the transition, “bridge courses” will be developed to allow Rev 3-trained assessors to perform Rev 2 assessments and vice versa.
Operational Insights: CUI and Flow Down
Guest speaker Ryan Bonner highlighted that CMMC requirements are now appearing “in the wild” within active solicitations from the Army Corps of Engineers, Air Force, and Navy.
- CUI Position: Contractors are encouraged to define their “CUI Position” to navigate ambiguity in data markings.
- Flow Down Logic: CMMC flow down is designed to “follow the data” rather than just the contract.
Scoping Strategy: Bonner advised focusing on a “Minimum Viable Product” for certification—identifying a core, defensible environment to get certified first, rather than attempting to cover 100% of a complex organization immediately.
Speaker 1 – 00:00
Welcome to the March Town Hall. It’s the last day of the month and the last day of the quarter. I hope everyone is doing well across the United States and around the world as the CMMC ecosystem gathers for our monthly touchpoint.
As always, we aim to provide a full hour of high-quality CMMC programming. Before we begin, a quick reminder: the Cyber AB is an independent nonprofit 501(c)(3) organization that supports the Department of Defense through a no-cost contract. Nothing shared tonight should be interpreted as official Pentagon or U.S. government policy.
We’re also pleased to acknowledge our partners at NCMS, the Society for Industrial Security Professionals, who are simulcasting tonight’s Town Hall to their membership.
We have a strong agenda tonight. I’ll start with a program update, followed by a fireside chat with Ryan Bonner on emerging CMMC requirements and how flowdown is working in practice. Then Todd Gagnon from ISACA will join us to discuss the transition of responsibilities from the Cyber AB to ISACA.
Speaker 1 – 01:34
I need to begin with an important announcement. Earlier this week, it was announced that Stacey Boschanick is retiring from federal service after 27 years.
Stacey has been a central figure in this program. She served as the senior executive overseeing the PMO and most recently led DIB cybersecurity efforts. Throughout her tenure, she provided consistent leadership and support to the Cyber AB and the broader ecosystem.
Those of you who have seen her at Town Halls or conferences know she brought energy, transparency, and a genuine commitment to sharing information, even during the most challenging phases of rulemaking.
We hope to have her join a future Town Hall to reflect on her time in the program. For now, if you’re watching with a drink in hand, please join me in raising a toast to Stacey Boschanick. We wish her the very best.
Speaker 1 – 03:00
Turning to recent developments, CIO Kirsten Davies testified before both the Senate and House Armed Services Committees last week. CMMC was part of her remarks, including discussion on balancing certification costs with the need to protect CUI.
I encourage everyone to review the testimony and Q&A sessions available on the committee websites.
Additionally, the GAO released its report on CMMC earlier this month. This was not an audit, but a strategic review focused on program success factors and whether sufficient planning exists.
The report found that CMMC has a clear mission, defined scope, methodology, and assigned roles. One area identified for improvement is managing external dependencies, particularly reliance on private sector capacity.
Overall, the report was positive, and we recommend reading it for deeper insight.
Speaker 1 – 06:24
Let’s look at ecosystem capacity.
We’ve surpassed 1,000 Level 2 certifications issued by C3PAOs, now at 1,074 and growing. There are also 39 conditional certifications pending POA&M closeout and 116 Level 2 assessments in progress.
On the ecosystem side:
- 103 C3PAOs (up 5%)
- 759 CCAs
- 1,564 CCPs
- Continued growth in Lead CCAs and training providers
The key metric remains assessor growth, and we’re seeing steady progress.
Speaker 1 – 08:56
We’ve also expanded our internal team. Emily has joined as Director of Executive Administration, helping manage scheduling and board operations.
We’re also hiring for a Director of Compliance and Security, with interviews underway.
Speaker 1 – 10:02
Upcoming events include:
- Summit Business Technologies webinar on CMMC pitfalls (tomorrow)
- CS2 West in April
- CMMC Midwest in Wichita
- CMMC Day in the National Capital Region
- Cybersecurity Association Summit in June
Speaker 1 – 13:25
We are now seeing active CMMC requirements in real contracts across agencies like the Army Corps of Engineers, Air Force, and others.
CMMC is no longer theoretical. The rule is active, and requirements are appearing in solicitations.
Fireside Chat with Ryan Bonner
Speaker 4 – 15:40
We’re seeing CMMC requirements appear in RFIs, Sources Sought notices, and formal solicitations. Some agencies are phasing requirements differently than the official rollout schedule.
In some cases, contractors are being denied access to preliminary information unless they demonstrate near-complete Level 2 readiness.
Speaker 4 – 17:43
Primes are aggressively driving awareness. They’re sending strong communications and pushing subcontractors to act.
They can’t afford to wait. If their supply chain isn’t ready, they risk losing contract eligibility.
Speaker 4 – 19:07
Subcontractor awareness varies widely. Some are only now reacting after receiving strong pressure from primes. Others have been preparing for years.
The deeper you go into the supply chain, the lower the awareness tends to be.
Speaker 4 – 20:25
Flowdown follows data. Requirements flow where CUI flows.
Organizations are beginning to segment suppliers:
- Those capable of handling CUI
- Those limited to Level 1
- Those handling only public or non-FCI data
This segmentation allows flexibility but requires planning.
Speaker 4 – 22:09
There’s still confusion around identifying CUI.
Part of the issue is degraded communication as information passes through multiple layers. On the government side, the shift from classified frameworks to CUI requires understanding a wide range of laws and regulations.
Speaker 4 – 23:56
Organizations need a defined “CUI position.”
This includes:
- Identifying where CUI exists in their environment
- Applying consistent handling rules
- Understanding exclusions (like publicly available data)
- Aligning internal interpretation with federal definitions
Speaker 4 – 26:44
A common misconception is that everything is CUI. That’s not true.
Another misconception is that the government has perfect clarity and just isn’t sharing it. In reality, ambiguity exists on both sides.
Organizations need to engage, ask better questions, and refine their understanding.
Speaker 4 – 28:37
Final advice:
Define your scope. Build a minimum viable compliant environment. Focus on what’s required for contract performance first.
Don’t try to certify everything at once. Start with what matters most and expand if time allows.
ISACA Transition – Todd Gagnon
Speaker 5 – 29:29
The transition to ISACA goes live tomorrow at 10 AM Central.
Users will log into their ISACA accounts to:
- View certifications
- Manage renewals
- Continue training
All certification processes now begin with ISACA and transition to Cyber AB for Tier 3.
Speaker 5 – 34:30
Exam fees will align with ISACA standards:
- $575 (members)
- $760 (non-members)
Renewal costs are lower, so long-term cost balances out.
Speaker 5 – 36:00+
Key points:
- No immediate changes to training delivery
- New training aligned to NIST 800-171 Rev. 3 coming late 2026
- Bridge courses will support transition between Rev. 2 and Rev. 3
- ISACA will become the sole training publisher for consistency and speed of updates
Speaker 5 – 42:28
The PI to CCI transition process will begin shortly, with full implementation targeted by June 2026.
Q&A Highlights
Ryan Bonner
- Email headers alone do not make content CUI
- Proper marking requires full designation and category identification
- Organizations must understand CUI categories due to legal implications
He also emphasized better communication:
Low-quality questions produce low-quality answers. Be specific when engaging with upstream partners.
Todd Gagnon
- Certification reviews will typically take about one week
- Renewal functionality will be available immediately
- ISACA will be the system of record, with synchronization to Cyber AB
- Discrepancies should be reported through support channels
Closing
The next Town Hall will be held on April 28 at 6 PM Eastern.
About KLC Consulting
KLC Consulting is an Authorized C3PAO specializing in CMMC assessments and NIST 800-171 compliance for the Defense Industrial Base (DIB). Our team of Cyber AB-authorized Lead CMMC Certified Assessors has a combined 75 years of experience in the cybersecurity field, allowing us to deliver objective, high-quality CMMC Level 2 assessments and readiness services for organizations from Fortune 500s to small subcontractors. Read more about us here.




