6 min read

Why Most CMMC Preparation Fails Before the Technical Work Even Starts

Featured Image

 CMMC consultant and CPISys Co-Founder Victoria Delaney explains why competence, not credentials, decides whether a compliance program actually holds up under assessment, and lays out the four-step path she uses to get contractors from confused to audit ready. 

 

Key Takeaways

  • Most companies don't know what they don't know: NIST 171's 110 headline controls hide roughly 200 additional objectives that assessors actually evaluate.
  • Industry-specific experience matters more than generic credentials. Twenty years of Army cybersecurity experience doesn't tell you how a machine shop's CAD or ERP systems are wired together.
  • Cybersecurity is a business decision, not an IT decision, and treating it as an afterthought has a real dollar cost.
  • A four-step path (standard, consultant, gap assessment, POAM) turns an overwhelming standard into a manageable project.
  • The best compliance help doubles as an education session for the business owner, not just a checklist exercise.

Table of Contents

  1. Why Most CMMC Preparation Fails Before the Technical Work Starts
  2. Credentials Aren't Competence
  3. Compliance Is a Business Decision, Not an IT Project
  4. The Four-Step Path to CMMC Readiness
  5. Why This Approach Works

Victoria Delaney didn't set out to become a CMMC consultant. She spent decades as a mechanical engineer and ISO auditor, working inside more than 300 companies before CMMC existed as a framework. That background is exactly why her read on the compliance industry is different from most.

Her diagnosis is blunt: the biggest reason CMMC programs stall isn't the technology. It's that almost nobody, including the people hired to help, actually understands the standard as deeply as they claim to.

As Co-Founder of CPISys, a CMMC Registered Provider Organization, Victoria has run more than 25 gap assessments and helped two C3PAOs become the first accredited through the Cyber AB. She's seen exactly where compliance programs go sideways, and exactly what it takes to fix it.

Here's how she thinks about the problem, and the four-step path she uses to get contractors from overwhelmed to audit ready.

 

Why Most CMMC Preparation Fails Before the Technical Work Starts

According to Victoria, the single biggest problem she sees across every standard, not just CMMC, is that companies don't know what they don't know. They move forward confident in their understanding, with no idea where to find the answers to what's actually right.

NIST 171 is the clearest example. On paper, it's 110 controls. In practice, it's closer to 310.

"That standard is layers deep. There's 110 controls, but below that, there's another 200 objectives. And for the average subcontractor to try to figure out what that means, it's next to impossible."

— Victoria Delaney

Victoria has watched this play out in more than 25 gap assessments. A company brings in its IT lead to walk through the assessment, and halfway through he's asking what half the language even means. That's not a knock on the IT lead. It's what happens when a standard this dense gets summarized into a single headline number.

 

Credentials Aren't Competence

The same blind spot shows up on the vendor side. Victoria sees resumes that list twenty years of military cybersecurity experience and nothing else, and she's blunt about what that credential does and doesn't prove.

"I know how the Army does cybersecurity. I don't know how a machine shop does cybersecurity."

— Victoria Delaney

A background in defense cybersecurity doesn't tell you how a CAD/CAM system talks to an ERP system on a shop floor, or what a logistics company's shipping workflow actually looks like. Every industry has its own nuances, and a consultant or C3PAO assessor needs to know enough about yours to ask the right questions, not just recite the framework.

That's what Victoria means when she talks about quality. It's not a checkbox or a job title. It's whether the person helping you actually has the competence to do the job, measured across three things: communication skills, real technical understanding, and time management.

"Time is money. If you're working with someone that really doesn't know what they're doing, they're gonna eat your time up too."

— Victoria Delaney

Compliance Is a Business Decision, Not an IT Project

Victoria doesn't make the case for cybersecurity investment on emotion. She makes it on dollars.

She points to a machine shop she worked with, thirty employees, that assumed ransomware would never happen to them. It did. Sixty thousand dollars later, they got out from under it, and the owner still had trouble figuring out how to implement the cybersecurity requirements that could have prevented it in the first place.

The threat isn't limited to sophisticated state actors, either. Any employee using a personal cellphone on-site is a potential entry point. And the business case is expanding beyond the contracts themselves: insurance carriers are increasingly asking about cybersecurity controls before they'll write a policy, and they don't like paying ransomware claims.

As Victoria puts it, the decision to defer cybersecurity investment is not an IT decision. It's a business decision, and one that eventually comes due for every company that puts it off.

 

The Four-Step Path to CMMC Readiness

Once a company accepts that compliance is a business decision, the next question is where to actually start. Victoria breaks the path into four steps.

1. Get the Standard

NIST 171 is free to download. Victoria recommends getting it, with a warning: you will not enjoy reading it. That's fine. The point of this step isn't comprehension, it's having the source document in hand.

2. Find a Consultant Who Speaks Your Language

This is where most companies get burned. A lot of consultants explain compliance in IT language to a business owner who has no interest in learning IT language and shouldn't have to. Victoria's team built free YouTube videos covering every section of NIST 171 in plain English specifically because of this gap. The right consultant translates the standard into decisions a business owner can actually make.

3. Run a Real Gap Assessment

Done well, a gap assessment is not just a checklist exercise. It's an education session, for the business owner and for whoever is handling IT internally. Victoria has found that most companies already have more of the basics in place than they expect. What's usually missing isn't the fundamentals, it's the advanced controls nobody explained clearly.

4. Build the POAM

The gap assessment produces a Plan of Action and Milestones, a prioritized list of what's left to fix. Three things make a POAM actually usable: a real budget for anything that needs to be purchased, a priority ranking for which gaps matter most, and a hard due date for every item. Without a date, Victoria says, most business owners will find something else to focus on.

 

Why This Approach Works

Victoria compares the process to eating an elephant.

"How do you eat an elephant? One bite at a time. That's the only way you can do it."

— Victoria Delaney

NIST 171 is too dense to absorb all at once, and trying to tackle it that way is exactly what causes companies to freeze or hand the whole problem to an underqualified vendor. Breaking it into a standard, a translator, an assessment, and a prioritized action list turns an intimidating framework into a sequence of manageable decisions, each with a clear owner and a clear deadline.

 

Getting the Right Help, From Start to Finish

Victoria's path doesn't require picking any specific provider. It requires picking someone who can actually walk you through all four steps in a language you understand, and who sticks around long enough to help you execute the POAM instead of handing you a report and disappearing.

That's the same model BEMO built its own CMMC Level 2 certification on, and it's the model BEMO runs for the small and mid-sized contractors it works with: a plain-English gap assessment, a prioritized POAM with real budget and due dates attached, and ongoing support through implementation instead of a one-time audit hand-off.

If you're staring at NIST 171 wondering where to even start, that's exactly the conversation worth having.

Talk to BEMO about a gap assessment → Speak with us

 

Frequently Asked Questions

Is CMMC compliance primarily an IT responsibility?

No. While IT plays a critical role in implementation, Victoria is direct that treating compliance as purely an IT project is one of the most common and costly mistakes a business owner can make. It's a business decision that affects revenue, risk, and contract eligibility.

How many controls does NIST 171 actually require?

The standard is often summarized as 110 controls, but underneath those sit roughly 200 additional objectives that assessors evaluate directly. The real scope is closer to 310 individual items.

What's the first step in preparing for CMMC?

Get the standard. NIST 171 is free to download, though Victoria recommends pairing it immediately with a consultant who can translate it into plain English.

How do I know if a consultant or assessor is actually qualified?

Look past certifications and years of experience to industry-specific competence. Ask whether they understand your specific systems and workflows, not just the general framework. Victoria evaluates this through communication skills, real technical understanding, and time management.

What is a POAM and why does it matter?

A Plan of Action and Milestones is the output of a gap assessment: a prioritized list of remaining gaps, each with an estimated cost, a priority level, and a firm due date. Without all three elements, Victoria has found the plan tends to stall.

What happens if a company waits too long to invest in cybersecurity?

The cost compounds. Victoria points to a thirty-employee machine shop that paid $60,000 to recover from a ransomware attack it never expected. Beyond direct incident costs, insurance carriers are increasingly requiring proof of cybersecurity controls before underwriting a policy at all.

Leave us a comment!