Updated September 30, 2026
"I started last August as a mere book keeper," one poster wrote on a CMMC forum. By the time they wrote it, they were the shop's IT admin. That's how CMMC usually gets staffed in a 20-person shop. Nobody chooses. It falls on whoever is closest.
Give it to one named person with 4 to 6 hours a week protected on the calendar, have the owner sign off on it, and pay outside help only for the technical work that person can't do. Usually that person is the quality manager. Sometimes it's the office manager. Almost never is it the co-op.
CMMC (the Cybersecurity Maturity Model Certification) is the Defense Department's program for checking that suppliers protect CUI, controlled unclassified information: in a machine shop, the drawings and models the customer marks as sensitive. Most shops that hold CUI answer to Level 2, which is 110 security requirements. This post is about who does that work. What the work touches, stop by stop →
The three people it lands on
The quality manager inherits it most often, because the shop already runs AS9100 or ISO 9001 and "that's a standard, so it's yours." It's a reasonable pick. A quality manager already writes procedures, keeps records, handles an auditor, and closes corrective actions. CMMC is those same habits applied to computers. The weakness is technical: they won't know how to set up multi-factor login or split the network. That part goes to the MSP (the managed service provider that runs your computers for a monthly fee).
There's another reason the quality manager should be in the room. In the first False Claims Act case against a subcontractor over cybersecurity, Swiss Automation, an Illinois machining company, paid $421,234 in December 2025. The whistleblower who brought the case was its former quality-control manager (DOJ). The person closest to your records knows whether your score is true. Make them the one who writes it down.
The office manager or bookkeeper is the second most common. Also workable, if they have authority to ask the shop floor for things and get answers. Without that authority it stalls, because half the work is getting a programmer to stop using a USB stick.
The co-op or new hire is the pick to avoid. One poster described their shop's program as "blind leading the blind." A student can collect screenshots and file evidence. They can't tell the owner no, and they'll be gone in six months with everything in their head.
Why the owner can't hand it off entirely
The CMMC rule requires an Affirming Official: "the senior level representative" of the company who has "the authority to affirm" that it meets the requirements (32 CFR 170.4). Every year that person states in SPRS, the DoD's supplier database, that the score and the controls are real. In a 20-person shop that's the owner.
When a shop's CMMC project stalls, it usually stalls at the owner's desk, in small ways: the owner who says yes to CMMC and no to making machinists log in individually, or who approves the MSP quote but won't give the quality manager Friday mornings. The practical form of buy-in is three things in writing: who owns the program, how many hours a week they get, and a 30-minute monthly meeting where the owner sees the fix list and decides the ones that cost money.
How many hours
These are our planning numbers for a 10 to 50 person shop starting with no security plan:
- The build phase, usually 6 to 12 months: 4 to 6 hours a week from the program owner, plus the MSP's billed time for the technical changes.
- After you're done: 2 hours a week, plus a few heavier days a year for the annual self-assessment, training, and incident-response exercise.
- The owner: 30 minutes a month, and an afternoon a year to read and sign the affirmation.
If the program owner can't get 4 hours a week, the plan slips a quarter at a time and nobody notices until a prime asks for the score.
Hiring an MSP or consultant
Most shops need help. What they hire is often the problem, like GCC High licenses for all 30 people when eight open drawings. Shops have posted quotes of $20,000 to $40,000 for a gap analysis and $28,000 to $60,000 for assessment work. Some have been quoted far more, and some have paid for nothing. What CMMC really costs a small shop → One owner wrote of a provider: "They did absolutely nothing other than show us their tools."
Four red flags we see over and over:
- The demo is the deliverable. A consultant walks you through a compliance dashboard, you sign, and three months later you have a login and no changes to your systems.
- Advice that reads like a chatbot wrote it. One shop found its consultant "filtering all their advice through AI." Ask them a specific question about your shop, like "Do our Okuma controls count against the 110?" A real answer names Specialized Assets and your network. A generic one recites the framework.
- A $110,000 quote for documents. A shop posted exactly that. A security plan and policies for a 25-person shop are a few weeks of writing, and they only have value if they describe your actual systems. A price by the page is a price for paper.
- A "$2,500 Level 1 certification." No such thing exists. Level 1 is a self-assessment: you check your own shop against 15 basic requirements every year, post the result in SPRS, and affirm it (32 CFR 170.15). Nobody outside your company issues it. You can pay someone to help, but what you're buying is help, and the certificate they hand you means nothing to the DoD.
Your MSP doesn't need a CMMC certificate. Its tools are still in scope.
A common myth is that you can only hire an MSP that is itself CMMC certified. The rule says the provider "may voluntarily undergo a CMMC certification assessment." It isn't required (32 CFR 170.19(c)(2)(ii)). A certified MSP saves some time at your assessment. It doesn't pass it for you.
What the rule does require: if the MSP manages your security, its services are in your assessment scope as Security Protection Assets, the tools that protect the systems holding CUI. That means their remote-management agent on your PCs, their admin accounts, their backup service, their antivirus console. Those get checked against the requirements that apply to them, as part of your assessment. The MSP's role and a table of who does what must also be written into your security plan. How to split the day-to-day work is covered in who owns CMMC work when we use an MSP.
The interview scorecard
Ask every candidate these eight questions. Score each 2 for the good answer, 1 for partial, 0 for the red flag. Below 11 of 16, keep looking.
| Question | Good answer (2) | Red flag (0) |
|---|---|---|
| Show me your customer responsibility matrix. | A control-by-control table of what they do and what's left to you | "We handle all 110" |
| Which of your tools will run on our systems, and where do they store our data? | A named list: RMM agent, backup, antivirus, with where each one's data lives | "Our stack is proprietary" |
| Who, by name, will do our work? Can I call two machine shops you've done this for? | Two names and two phone numbers | A sales rep and a logo wall |
| What will our score be? | "We don't know until we look at your systems." | A number before they've seen anything |
| How is the security plan written, and how do you check it against our setup? | They interview your people, walk the shop, and test settings | A template with your name dropped in |
| How did you build this price? | Hours by task, based on your headcount and scope | A flat package price |
| What do we keep if we leave? | Every document, config export, and log, in files you can open | Access ends with the contract |
| Will you sign our annual affirmation? | "No. Your senior official does." | "Yes, we take care of that" |
The 300-page security plan
"Our SSP alone was 300+ pages," one poster wrote. Another: "Documentation is what killed us, not the actual technical controls." The SSP, or system security plan, is the document that describes your systems and how you meet each requirement. It's required (3.12.4). Long doesn't help.
An assessor doesn't grade the plan's weight. They work through 320 assessment objectives, the specific checkpoints the 110 requirements break into (NIST SP 800-171A). For each one they read what the plan says, interview the person who does it, and test the system. Every sentence in a 300-page plan is a promise they can check. Say "we review logs weekly" and they will ask to see last Tuesday's review. A shorter plan that matches the shop floor beats a long one that describes a company you aren't. Nobody has ever passed an assessment because the binder was heavy.
The free help, in order
Before you sign a five-figure quote, spend a month on the help taxpayers already paid for.
- Your APEX Accelerator. DoD-funded offices, formerly called PTACs, that give free counseling to businesses selling to the government. Many now run CMMC training and one-on-one counseling. Find yours at apexaccelerators.us.
- Project Spectrum. Free from the DoD Office of Small Business Programs: training, and a cyber readiness check that walks the requirements and helps you estimate a starting score. Sign up at projectspectrum.io.
- Your state's MEP center. The Manufacturing Extension Partnership is a NIST-backed network that works specifically with manufacturers. It isn't always free, but it's subsidized and often knows the state grants. NH MEP took Baron Machine, a 44-person shop in Laconia, through a gap analysis and policy work, and connected it to a CARES Act grant to offset the cost (NIST MEP).
Then hire the MSP for the technical work, using the scorecard above.
The weekly routine for the person who owns it
Two to six hours, depending on the phase. Put it on the calendar as a standing block, the way you'd block time for first-article inspection.
- Monday, 30 minutes. Compare last week's hires, departures, and role changes against the MSP's account list. Every departed person's logins are gone; every new person has only what the job needs.
- Tuesday, 1 to 2 hours. Close one item on the fix list. One. Pick by points and by what blocks your status, and write down what changed.
- Wednesday, 30 minutes. Go through the MSP's tickets from the week with them. Anything that changed a setting on a CUI system gets a line in the change log.
- Thursday, 1 hour. File the evidence: this week's screenshots, the access review, the ticket exports, each in the folder for its requirement.
- Friday, 15 minutes. Send the owner three lines: what closed, what's next, what needs a decision or money.
On top of that: a monthly security review with the owner, a quarterly review of admin accounts, and once a year the training, the incident-response exercise, the risk assessment, and the self-assessment that feeds the affirmation. Garde1 schedules those recurring procedures with owners and due dates, and writes the security plan and 14 policies from your scope so the program owner's hours go to the shop floor instead of the word processor.
