CYBERSECURITY Readiness Pivotal as CMMC Assessor Capacity Squeezed By Tabitha Reeves iStock illustration As Nov. 10 ushers in a new round of Cybersecurity Maturity Model Certification requirements, third-party assessors have a straight-forward message for defense contractors seeking Level 2 certification — be prepared. While Level 1 and some Level 2 contracts allow for self-assessments, achieving Level 2 certification often requires an official review provided by a CMMC third-party assessment organization, or C3PAO. Companies might feel an urgency to pencil in an official assessment in the calendar as soon as possible, but ensuring readiness beforehand is a must, executives at cybersecurity firms said. Depending on a company’s complexity and resources, achieving Level 2 can take a year or more, said Vince Scott, founder and CEO of Defense Cybersecurity Group. “Even the longest journey starts with the first step,” Scott said during a panel hosted by the National Defense Industrial Association. “If you have not started yet, you’re probably already in the window of seeing a lack of certification impact your ability to win contracts. You want to narrow that window as much as possible.” The Defense Department’s CMMC final rule that took effect in November stated that it ultimately expects roughly 118,000 organizations to need Level 2 certification, noted Logan Therrien, chief strategy officer at Kieri Solutions. By comparison, Therrien’s latest estimate for Level 2-certified companies came to just over 1,100, indicating a sizable group yet to complete the process. C3PAOs are likely to become a bottleneck for Level 2 credentials. Kieri Solutions, for example, can conduct a maximum of about 250 assessments per year, “and that doesn’t begin to make a dent in the total number,” he said during the panel. “I’m afraid not everybody who wants to get certified can get certified in October this year,” Scott said. “There’s