Sell the affirmation. The certificate can wait. Contracts that carry CMMC still require a self-assessment, and a senior official at the supplier still affirms continuing compliance every year. Skadden's July analysis put it plainly: with self-assessment now the primary enforcement mechanism, False Claims Act exposure is, "if anything, sharper." An affirmation nobody can back up with evidence is now a legal exposure for the supplier.
The work is also unfinished. One 2025 survey by a security vendor, of 364 IT practitioners at small and mid-size defense suppliers, found 71% had started CMMC work, yet just 17% described themselves as Level 2 compliant. The answers are self-reported and not every respondent was a manufacturer, but the gap between started and done is where you sell.
Pitch by role. C3PAOs: Skadden expects an assessment backlog if third-party requirements return, and Covington's September update said there may be benefits to a third-party review even now. RPOs and consultants: scoping, the system security plan, POA&M close-out and the evidence behind each affirmation. Managed security providers: in the same survey, 52% planned changes to their outsourced security provider within a year, but more of those planned to bring security in-house (38%) than to find a new provider (33%).