The 60-Day Pause Might Be the Last Chance to Save the DIB

The 60-Day Pause Might Be the Last Chance to Save the DIB
Photo by Cook aynne / Unsplash

I applaud the 60-day pause. I don't say that lightly, and I don't say it as someone who thinks CUI shouldn't be protected. I say it because I sat in a room with our executives during a mock C3PAO assessment, and I watched the lead assessor deliver an out-brief line that has been stuck in my head ever since: "we expect 30% of the DIB to disappear because they cannot pass an assessment."
Thirty percent. Said flatly, like a weather forecast. That's not a compliance gap. That's an extinction event for a meaningful slice of the industrial base the Pentagon claims it needs to stay innovative.


And it's not a random 30%. Look at who's actually exposed and a pattern shows up fast: a real portion of that slice is small, firmly entrenched in research, development, and engineering work — companies whose entire business model is built around solving hard technical problems, not around running a compliance department. These aren't marginal players skating by on thin contracts. They're the shops doing the specialized, bleeding-edge work a prime often can't replicate in-house, and they're exactly the companies with the least slack — financially, operationally, in headcount — to absorb a six-figure compliance lift on top of everything else. They are at risk, and losing them isn't a rounding error. It's losing the R&D engine the DIB depends on.


"Just don't print CUI"


One of the suggestions that came out of that same mock assessment was to stop printing CUI entirely. On its face, sure, fewer printed copies means fewer physical control problems. In practice, for a lot of shops, that means unwinding workflows that have existed since before CMMC was a rulemaking, and doing it without the network upgrades that make a paperless workflow actually viable — upgrades that run into the hundreds of thousands of dollars for companies that were never capitalized like a prime.
That's the pattern across almost every recommendation we got: technically correct, operationally divorced from what it costs a mid-size DIB company to actually implement.


This isn't an IT problem, and IT can't fix it


Here's the thing nobody says out loud in the sales decks: CMMC, in a lot of real-world cases, doesn't require a network change. It requires a business culture change. And IT departments — however good, however well-funded — are not equipped to change how a business has operated for twenty years. That's a leadership and operations problem wearing an IT costume.
By the time executives figure that out, it's usually too late. The contract has already gone to a competitor — one bigger, better capitalized, with a compliance department instead of a stretched IT team wearing five hats. Which raises the actual question underneath all of this: is the intent here to secure CUI, or is the practical effect to consolidate the DIB into a smaller number of larger, more expensive partners?
Because right now, those two outcomes look identical from where we're sitting.


A CMMC audit feels like a tax audit


The volume of documentation a CMMC assessment demands is enormous — and a lot of it isn't a proxy for whether your data is actually secure. It's a proxy for whether you can prove, in triplicate, that you thought about securing it. Those aren't the same thing, and the gap between them costs real time. Every hour spent generating evidence artifacts is an hour not spent hardening a system, watching a log, or patching something that actually matters. Documentation takes time away from security. That should not be a controversial sentence, but say it in the wrong room and watch the reaction.


We spent hundreds of thousands of dollars pursuing compliance. We did not, in that process, eliminate the years of business practices the company actually survives on — because you can't rip those out and still be the company your customers hired. The business process, frankly, refuses to be changed. Not out of stubbornness. Out of survival.


The vendor ecosystem knows exactly what's happening


After the assessment, we got the inevitable follow-up: a parade of vendors in the compliance ecosystem, all willing to get us "to compliance," all terribly expensive, and more than a few asking for credentials into our internal network so they could set the controls themselves. Ask yourself honestly — do you think a third-party vendor configuring your environment from the outside cares about preserving the business processes that keep your company alive? Or do they care about getting you to a passing assessment as efficiently as possible for them?
This was after years of paying consultants $250–$300 an hour for direction on how to set controls in the first place. The compliance industry around CMMC isn't struggling. It's thriving. It's the companies actually trying to comply that are bleeding out.


Square peg, round hole, and the innovation nobody's pricing in
Our company operates, in a lot of areas, on the bleeding edge — new software adopted as new technology gets tested and formulated for the customer, baselines shifting constantly because the work demands it. CMMC, as written, forces a lot of that into a static, backward-looking control set. Square peg, round hole. And what gets lost in the process is innovation — the exact thing the DIB is supposed to bring to the table that a prime with a slower, heavier process structurally can't.


A smaller DIB doesn't mean a safer DIB. It means bigger partners charging millions more for work a smaller, more agile partner used to do faster and cheaper — because that agility is precisely what CMMC, as currently structured, punishes.


What this actually is


This isn't an argument against securing CUI. It's a request: review this thing as written, for the companies in the DIB that still want to be innovative, and bring it a little closer to an RMF feel — risk-based, tailorable, focused on outcomes instead of documentation volume. The 60-day pause is the first real opening in a while to have that conversation before the deadline arrives and attrition, not policy, makes the decision.
Thirty percent of the DIB disappearing isn't a compliance win. It's just a smaller DIB.


If someone inside the CMMC policy-making ecosystem happens to read this: that's really who this is written for. Not as a complaint from the sidelines, but as a hope that the people with the pen still have room, during this pause, to weigh innovation as heavily as they weigh checkboxes — because right now the requirement rewards whoever can produce the most documentation, not whoever can most reliably keep CUI safe while still doing the work the DIB exists to do.