Press
Applying Y2K Lessons to the CMMC Crunch
The July 2026 issue of National Defense carries a viewpoint piece on the capacity problem facing CMMC certification, and on what an earlier industry deadline can teach the defense industrial base about meeting it.
The defense industrial base has roughly 20 months to certify an estimated 80,000 contractors against a cybersecurity standard that fewer than 100 organizations are currently authorized to assess. The arithmetic does not resolve inside the enforcement window, and the raw gap understates the problem, because a meaningful share of assessor capacity is consumed by engagements that never reach a certification outcome.
The closest analog is the Y2K remediation effort in financial services in the late 1990s. That industry faced a deadline that could not move, a remediation scope larger than the early estimates suggested, and a shortage of people with the required skills, and it met the deadline anyway. It did so by changing how it approached the problem rather than by improving the underlying math. Three things made the difference. A coordinated industry response, regulatory flexibility on peripheral requirements, and clear communication about what compliance actually required. The piece examines why none of those three is fully present in the CMMC response today.
The November 10 enforcement date does not reduce demand so much as concentrate it into a narrower window, where readiness work and limited assessment capacity arrive at the same time.
The full viewpoint appears in the July 2026 issue.
Read the full piece in National Defense