Anyone can claim their environment is secure. Michael Peters, Founder and CEO of Lazarus Alliance, a C3PAO, explains why third-party validation exists, where readiness actually breaks, and what separates the companies that walk into an assessment prepared from the ones that don't.
Key Takeaways
- Security in the defense supply chain should not be treated as a matter of opinion. Demonstrating conformity to NIST 800-171 and validating it through a third party is what turns a claim into something verifiable.
- Self-attestation has carried most of this program for most of its existence, and the structural problem with it is not dishonesty. It is that expertise varies widely and a company grading its own work cannot show anyone else the grade is accurate.
- The most common readiness gap is not technical. It is the system security plan, the document that ties everything together for certification, and the same gap appears across every framework, not just CMMC.
- Preparedness is the number one obstacle to certification. Finding out a control is inadequate during preparation costs an afternoon. Finding out during an assessment costs months.
- CMMC carries unusually heavy overhead on the assessor side, including three certified and background-verified assessors per engagement, and those costs eventually land in contractor pricing.
- A repeatable methodology is what keeps an assessment on schedule, because it removes guesswork for assessors, project teams, and the customer at the same time.
Table of Contents
- Security Is Not Supposed to Be a Discussion Point
- The Problem With Grading Your Own Work
- Readiness Breaks at the System Security Plan
- Preparedness Is the Number One Obstacle
- What It Actually Costs to Run This Program
- Methodology Is What Protects the Timeline
- Prove It Before Someone Asks You To
Most of the current conversation in the defense industrial base is about timing. What the CMMC pause means, what it doesn't mean, when the third-party assessment requirement comes back, and what a contractor should do in the meantime.
Michael Peters, Founder and CEO of Lazarus Alliance, a C3PAO, and founder of the GRC platform Continuum GRC, spends his days on the other side of that table. His firm runs security assessments, risk assessments, and penetration testing to support compliance programs for customers across the world, and its core focus is what he calls turning over rocks: completing the assessment and helping customers demonstrate conformity to the standards that matter in their business.
From that seat, the timing question is less interesting than a more basic one. If a company says it is secure, what makes that statement worth anything to the customer, the prime, or the government reading it? What follows is his answer, and what he sees going wrong before an assessment ever starts.
Security Is Not Supposed to Be a Discussion Point
Peters starts from a position that leaves very little room for negotiation.
"Security across the board should not even be a discussion point," he says. "Demonstrating conformity to industry standards, in this case it's the NIST 800-171, demonstrating conformity to that and validating it through a third party is really the best and only reasonable course of action."
The reason he puts it that strongly is the size of what sits behind it. "This is national security. This is supply chain. This is the livelihoods of countless employees and important to shareholders. And it's the life's work represented by founders. So the stakes are high."
That framing matters for how a contractor should think about the current pause. If the requirement exists because of what is at stake rather than because of a date on a rollout schedule, then the schedule moving does not change the underlying reason the requirement exists.
The Problem With Grading Your Own Work
For most of this program's existence, the mechanism for proving security has been self-attestation. Peters does not think that mechanism survives contact with the stakes he just described.
"To contemplate leaving that up to self-attestation, which has been in place for most of the existence of this program, that's just the fox is guarding the henhouse," he says. "That's ludicrous."
His objection is structural rather than accusatory, and the distinction is worth holding onto. He is not arguing that contractors lie. He is arguing that a self-generated claim carries no information for the person reading it.
"Expertise varies wildly," he says. "I can say that I do something. It doesn't mean that it's correct. It doesn't mean that it's accurate. It doesn't mean that it's the truth. What are my motivators?"
Three separate failure points sit inside that. A company can be wrong about whether a control is implemented correctly. It can be wrong about whether its description is accurate. And it can have an incentive, even an unconscious one, to read its own evidence generously. None of those require bad faith, and none of them are visible from the outside without someone else looking.
That is the gap third-party attestation closes. "The need for third-party attestations, or certification bodies like Lazarus Alliance, is just vital to the transparency and the honesty and the success of these endeavors," Peters says.
Readiness Breaks at the System Security Plan
When Peters is asked what companies most often get wrong, he does not name a control family or a piece of technology. He names a document.
"One of the biggest things is just basic readiness," he says. "Your system security plan, that's the seminal document that ties everything together for certification."
He is specific about what that document has to be. "It's a technical document that describes how you conform, how you've implemented people, processes, policies, and technology, in some combination, to eliminate that risk or to address that requirement."
Read carefully, that is a description of a real environment, written by someone who understands it, covering four different dimensions of implementation at once. It is not a form. And when it is treated like one, everything downstream inherits the problem: the evidence does not match the narrative, the POA&M does not reflect what is genuinely open, and the assessor ends up comparing a document about one environment to a different environment in practice.
Peters is clear that this is not a CMMC-specific failure. "This is not unique to CMMC, it's 100% across the board, all frameworks, all standards that we support." When the same gap appears in every program a firm assesses against, it stops looking like a quirk of one rule and starts looking like how organizations behave under documentation pressure.
https://drive.google.com/file/d/1PShUd0Ob6lZ6tw4_UXa0qFJ9YdOCbu_9/view?usp=sharing
Preparedness Is the Number One Obstacle
If the SSP is where readiness breaks, preparedness is the broader category Peters puts it in. "The number one obstacle is preparedness," he says, and his description of what happens when a company arrives without it is blunt.
A customer comes to Lazarus Alliance wanting to sign a contract to be audited, and has not written an SSP, has not documented vulnerabilities in a POA&M, and does not have policies and procedures in place. At that point the engagement stalls, because there is nothing to examine yet. Those customers get referred out to readiness partners for technical writing and implementation work, and the assessment waits.
What Peters built in response is a feedback loop that runs during preparation rather than after it. Customers work inside a portal to assemble the certification package: the SSP, the POA&Ms, the policies and procedures. The system evaluates the material as it goes in.
"If what they're doing will not meet the requirements, Continuum lets them know: hey, this is failing, here's why, here's what you can do to improve it," he says. "So they can take that information away, make improvements, and then the system will reevaluate it." Requirements move to green one at a time, and a fully green status is the signal that it is time to engage the auditors.
The underlying principle travels beyond any one platform. A gap discovered while you are still writing is a small problem. The same gap discovered while an assessor is examining your environment is a schedule, a budget, and a reassessment.
https://drive.google.com/file/d/1UywJ_OzoBT0qD8UurUG0jM7JWeM0n-Lo/view?usp=sharing
What It Actually Costs to Run This Program
Peters is candid about something contractors rarely get to see, which is what the assessment side costs to operate. He describes CMMC as the most expensive program his firm participates in anywhere.
The government requires three CCA certified, background verified assessors per engagement. Each one costs roughly $9,000 to bring up to speed, and the government takes around nine months to clear them through background checks. The certification itself is narrow. "That CCA certification, that's a little unicorn certification in our industry. It is not useful anywhere else."
He contrasts that with the CISSP, which every Lazarus Alliance auditor is required to hold. "It's a globally recognized industry certification, a measurement of competency and capabilities. I can take that with me. It's my own personal cert." One credential builds a career. The other exists only inside a single program and requires a chain of third-party training organizations, testing bodies, and accreditation providers to sustain it.
On top of the staffing, C3PAOs carry accreditation costs from the Cyber AB, which Peters estimates at around 17 thousand dollars in the second year. "More costs associated with this program than anything else we experience anywhere else on the planet," he says. Those costs get absorbed somewhere, and his description of the path is direct: they land in what he charges customers, which contractors bake into their government contracts, which means the taxpayer ultimately carries them.
His criticism is aimed at the overhead, not the requirement. He expects reform to address a meaningful share of it, and he is explicit that the fundamentals about the frameworks and the need for certification will get back on track. For a contractor budgeting a program right now, the practical takeaway is that a large portion of the price is structural rather than negotiable, which is a good argument for knowing the full cost before committing rather than discovering it midway.
https://drive.google.com/file/d/1_RwxmYNG9LUgK9n8hlAN6ebKrnCk4PA0/view?usp=sharing
Methodology Is What Protects the Timeline
Given how much of the cost is fixed, the variable a contractor can actually influence is how efficiently the engagement runs. Peters attributes his firm's consistency to a unified methodology, and he is unpretentious about the analogy.
"I wanna say it's like making hamburgers at McDonald's. There's a formula," he says. "You take any sort of efficient, repeatable, sustainable process and the fundamentals are the same."
What makes it hold is that the methodology is not left to memory. "Our project management methodology, in part, is enforced by automation. Our projects are granularly structured to enforce our methodology, to make these efficient and repeatable."
The benefit he emphasizes is not speed. It is the removal of ambiguity for everyone in the engagement at once. "It also helps to eliminate a lot of guesswork from the assessors and the other team members participating, and customers for that part, because you absolutely know what comes next and what comes after that and when that's supposed to occur."
The outcome follows from that. "So customers that keep up, they will be on time and successful and spot on their budget." The condition in that sentence is doing real work. The process creates predictability, and the customer still has to keep pace with it.
Prove It Before Someone Asks You To
The part of this that gets undersold, in Peters' view, is that the preparation work is valuable on its own terms.
"By improving the basic documentation, that enhances the customer's knowledge about themselves, their organization," he says. "It's providing expert advice on how to improve things. That makes them better overall, makes them less vulnerable to external threats or internal threats, as sometimes is the case. It reduces risks to that organization."
That is the argument for doing the work regardless of where the rollout timeline lands. A company that has honestly documented how it implements its controls understands itself better, and is harder to compromise, before any assessor confirms it.
The certification follows from that rather than substituting for it. "Without naming customers, one easy fact is 100% of our CMMC customers have passed the DIB inspections the first time," Peters says, and he immediately closes the obvious door. "No, we're not rubber-stamping anybody. This is the DIBCAC, not us." He attributes the result to expertise, tooling, and methodology giving customers the room to prepare and gain confidence before anyone examines them.
https://drive.google.com/file/d/1Cuilxu7M0eGJFiLtxg9YiK998THvJXY_/view?usp=sharing
Read together, his position is consistent. Security is not a matter of opinion, a self-issued claim is not evidence, readiness is built in the documentation long before an assessment window opens, and a predictable process is what keeps the whole thing on schedule and on budget.
The standard is not whether you can say your environment is secure. It's whether someone qualified, looking at your documentation and your evidence, would independently reach the same conclusion. Everything else is an assertion waiting to be tested.
BEMO builds the security program first and operates it continuously, maintaining the SSP, the evidence, and the controls alongside the environment they describe, and coordinating the C3PAO directly. That way what a client represents is something they can demonstrate, whenever someone asks.
Frequently Asked Questions
Why isn't self-attestation good enough for demonstrating security?
Peters' objection is structural rather than about honesty. Expertise varies widely across contractors, a company can be genuinely wrong about whether a control is implemented correctly, and the party making the claim has an incentive to read its own evidence generously. A self-generated claim gives the reader no independent basis for trusting it.
What is a system security plan and why does it matter so much?
Peters calls the SSP the seminal document that ties everything together for certification. It is a technical document describing how an organization conforms, specifically how it has implemented people, processes, policies, and technology to address each requirement. When it doesn't describe the real environment, the evidence and the POA&M stop lining up with it.
What is the most common reason companies aren't ready to be assessed?
Preparedness. Peters regularly sees customers who want to contract for an audit without having written an SSP, documented vulnerabilities in a POA&M, or established policies and procedures. Those engagements stall, because an assessor cannot examine work that doesn't exist yet.
Is this readiness problem specific to CMMC?
No. Peters is explicit that it appears across every framework and standard his firm supports, which is a long list. The pattern is about how organizations handle documentation under pressure rather than anything unique to one rule.
Why is CMMC more expensive than other compliance programs?
The overhead sits largely on the assessor side. Each engagement requires three CCA certified, background verified assessors, each costing roughly $9,000 to train with around nine months of government background checks, for a certification not recognized outside the program. Cyber AB accreditation fees sit on top. Those costs flow into contractor pricing and ultimately into government contracts.
What keeps an assessment on schedule and on budget?
A repeatable methodology, enforced rather than remembered. Peters' firm structures projects granularly and uses automation to hold the process in place, which removes guesswork for assessors, project teams, and customers at the same time. Customers who keep pace with that process finish on time and on budget.
Top 10 Posts
-
Office 365 MFA Setup: Step-by-Step Instructions
-
CMMC Phase 2 Suspended: What the Compliance Pause Changed
-
Google Workspace to Office 365 Migration: A Step-by-Step Guide
-
SharePoint vs. OneDrive (What's the Difference Again?)
-
How Much Does ISO/IEC 27001 Lead Auditor Certification Cost in 2025?
-
What is The CIA Triad?
-
What is Microsoft Purview ? Your A to Z Guide to Getting Secure Fast
-
How to Migrate from GoDaddy to Office 365
-
How to Set Up Office Message Encryption (OME)
-
Who Needs ISO 27001: Is This Critical Security Certification Right for Your Business?


Leave us a comment!