Patrick Parker, Chief AI Officer at Altiri, explains why an honest current state assessment, a tight scope, and a complete security posture protect defense contractors long before an assessor ever shows up.
At many small defense contractors, CMMC readiness does not belong to a compliance department. It belongs to one person who is already busy keeping the business running.
Patrick Parker, Chief AI Officer at Altiri, has spent more than 20 years in cybersecurity and advises defense contractors as a CMMC Registered Practitioner. In BEMO's Security + Compliance Field Guide, he walked through where readiness really begins, why scope drives cost, and why a self-assessment can carry more risk than most leaders realize.
His message is practical. Know where you stand today, shrink what you have to protect, and treat compliance as a business decision rather than a side project for IT.
Most small contractors do not have a dedicated compliance team. "For small businesses, a lot of times you have a system administrator that's just wearing all the hats, and it's up to him to do all this," Parker says.
How much work lands on that person depends on the size of the company and how much controlled unclassified information (CUI) it handles. That is why every readiness effort should begin with a current state assessment: an honest look at where the environment stands today and which gaps exist against NIST 800-171.
Without that baseline, budgets, timelines, and tool decisions are guesses.
Once the gaps are clear, the next question is how much of the business actually needs to meet the controls. Scoping is where many contractors find their biggest savings.
"Sometimes the easiest way to remediate the identified gaps is to rethink your structure," Parker says. Legacy on-premise systems that are inherently insecure may cost more to fix than to replace or move out of scope.
Drawing a clear boundary around CUI keeps the assessment focused on the systems, people, and processes that handle sensitive data, instead of the entire company.
Scoping only works if you know what you own. "First start with an asset inventory. That's part of the scoping exercise," Parker says.
The problem is that many inventories live in a spreadsheet that gets updated every six months or once a year. Parker has seen teams discover late in the process that they forgot about a new printer or a new manufacturing system. Every surprise asset can pull more of the environment into scope and add cost.
A current, accurate inventory keeps the scope honest and the budget predictable.
Many contractors today only need a self-assessment and an SPRS score. Parker notes that it's "a lower bar than having a third party come in and pick at every particular objective and say, 'Prove it.'"
A lower bar does not mean lower risk. If CUI is compromised and the government investigates, the reported score gets compared against reality. Parker describes the worst case: a contractor that "claimed a certain number, like a perfect 110 on your SPRS submission, however, you're actually a negative 150."
At that point, "the official who attested to the truthfulness of the SPRS submission is in trouble, criminal trouble under the False Claims Act," Parker says. He points to a recent case where he believes the fines reached about half a million dollars.
A self-assessment should be treated with the same rigor as a third-party review, because the signature on it is personal.
Parker hears the same concern often. "A lot of people are scared of the cost of doing the assessment and the compliance documentation and all of that," he says. In many cases, the real cost comes from systems and a security posture that have fallen out of date.
Some organizations have told themselves, "Well if it ain't broke, don't fix it." Parker's response is direct: "But it really needed fixing."
The threat environment is changing that math. "The state actors are becoming more sophisticated. They're using AI to attack these contractors, and they will probably get in if you don't have your controls in place," Parker says.
Shifting CMMC timelines can tempt leaders to wait. Parker's advice is to keep moving.
"Not being clear about your objectives is very expensive," he says. Uncertainty leads to "maybe we'll do it next year" thinking, and teams end up without a clear plan or budget.
Contractors who continue their readiness work during a pause are not wasting effort. The controls still protect the business, and when certification becomes a requirement in more contracts, those contractors are positioned to compete while others scramble.
Readiness is not only a technical exercise. "This isn't just a technical thing. It's also policies, procedures, training, physical security," Parker says.
For teams already stretched by day-to-day work, Parker recommends bringing in someone who knows the finer details of the requirements and can find ways to save money. From there, "invest in whatever you need to do to be able to meet the controls," whether that means upgrading a firewall or moving some systems into a pre-certified cloud enclave, which he notes can be a better, cheaper, and quicker solution.
Contractors that work with a managed service provider should also make sure responsibilities are clearly defined in a shared responsibility matrix, so nothing falls between the provider and the internal team.
BEMO's security-first approach helps defense contractors turn this guidance into a working program. BEMO can assess the current environment, configure the Microsoft 365 environment, organize the compliance layer, coordinate the C3PAO, and operate the program after certification, so small teams are not carrying CMMC alone.
Where should a small defense contractor start with CMMC?
Start with a current state assessment against NIST 800-171. It shows where the environment stands today and which gaps need to be closed before any other decisions are made.
How can contractors reduce the cost of CMMC?
Scope carefully. Drawing a clear boundary around CUI and rethinking structure, such as retiring insecure legacy systems or using a pre-certified cloud enclave, can shrink the number of systems that must meet the controls.
Why does the asset inventory matter?
The asset inventory drives scoping. An outdated inventory leads to late surprises, like forgotten devices or systems, that expand scope and add cost.
Is a self-assessment less risky than a third-party assessment?
It is a lower bar, but not lower risk. The official who attests to an SPRS score can face liability under the False Claims Act if the score does not reflect reality.
Should contractors wait for CMMC timelines to settle?
No. Readiness work protects the business now and positions contractors to compete when certification becomes a contract requirement.
Is CMMC just an IT project?
No. A complete security posture includes policies, procedures, training, and physical security, along with technical controls and clearly defined responsibilities with any managed service provider.