CMMC Pause Exposes High Compliance Costs for Small Defense Contractors — Jeremiah Jensen episode artwork

EPISODE · Aug 5, 2026 · 22 MIN

CMMC Pause Exposes High Compliance Costs for Small Defense Contractors — Jeremiah Jensen

from Business of Tech: Daily 10-Minute IT Services Insights · host Dave Sobel

The core mechanism discussed is the regulatory pressure and resulting operational risk created by the Department of Defense’s (DoD) abrupt suspension of the CMMC Level 2 third-party certification mandate. IntelliGenesis, led operationally by Jeremiah Jensen, illustrates how rapidly shifting compliance expectations can expose defense contractors and their MSP partners to unrecoverable sunk costs, increased governance complexity, and unclear accountability. The episode highlights the structural disconnect between government-mandated cybersecurity standards and the practical realities of implementing and maintaining those requirements at scale. According to Jeremiah Jensen, IntelliGenesis incurred more than $200,000 in direct costs, invested four months of intensive labor, and committed a team of five to six staff to achieve early CMMC Level 2 certification—including significant documentation, hardware upgrades, and consultant fees. Despite this investment, the DoD paused the entire third-party assessment program on July 13, citing small business cost burdens and insufficient assessor capacity. This left companies like IntelliGenesis having already completed—and paid for—requirements that were no longer mandated for the time being, but with underlying security obligations still in effect. Secondary issues reinforce the underlying risk: the audit process was described as inflexible and expensive, with a binary pass/fail outcome that offered no remediation for minor deficiencies—requiring full re-audit at the original cost if any portion was not met. Further, both Dave Sobel and Jeremiah Jensen noted a lack of clarity in ongoing expectations, as large defense primes were previously flowing down certification pressures to subcontractors, but have gone quiet since the mandate was paused. The temporary pause, coupled with ongoing self-attestation requirements and a comment period through August 14, creates a regulatory gray area with uneven impacts across the defense supply chain. For MSPs and IT providers supporting government contractors, these developments translate to increased contract risk, ongoing uncertainty in governance requirements, and exposure to costs that may not deliver a return if regulations shift again. The episode clarifies that self-attestation standards are still in place, but the lack of authoritative third-party oversight introduces ambiguity and potential liability. Providers should anticipate further regulatory refinement, engage with clients regarding their compliance posture, and treat sunk certification costs and compliance-driven operational overhead as persistent risks rather than guaranteed business advantages. Supported by:  Pax8 Guardz 💼 All Our SponsorsMSP Radio is supported by our partners: ABC Solutions · CometBackup · Guardz · HaloPSA · LogMeIn · Mailprotector · OpenText · Pax8 · Proofpoint · Rythmz · ScalePad · TimeZest · Transit AI · USecureSupporting the IT services community through insights, analysis, and transparency. 🚀 Join Business of Tech PlusGet exclusive access to investigative reports, vendor analysis, leadership briefings, and more.👉 https://businessof.tech/plus 🎧 Subscribe to the Business of TechWant the show on your favorite podcast app or prefer the written versions of each story?📲 https://www.businessof.tech/subscribe 📰 Story Links & SourcesLooking for the links from today’s stories?Every episode script — with full source links — is posted at:🌐 https://www.businessof.tech 🎙 Want to Be a Guest?Pitch your story or appear on Business of Tech: Daily 10-Minute IT Services Insights:💬 https://www.podmatch.com/hostdetailpreview/businessoftech 🔗 Follow Business of Tech LinkedIn: https://www.linkedin.com/company/28908079YouTube: https://youtube.com/mspradioBluesky: https://bsky.app/profile/businessof.techInstagram: https://www.instagram.com/mspradioTikTok: https://www.tiktok.com/@businessoftechFacebook: https://www.facebook.com/mspradionews Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Episode metadata supplied by the publisher feed · Published Aug 5, 2026

Embed this episode

Ready to play

CMMC Pause Exposes High Compliance Costs for Small Defense Contractors — Jeremiah Jensen

0:00 22:01

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Business of Tech: Daily 10-Minute IT Services Insights?

This episode is 22 minutes long.

When was this Business of Tech: Daily 10-Minute IT Services Insights episode published?

This episode was published on August 5, 2026.

Can I download this Business of Tech: Daily 10-Minute IT Services Insights episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!