The 5 Stages of Grief with CMMC
1. Denial — “This Doesn’t Apply to Us”
Typical Quotes:
-
“We don’t work directly with the DoD, so we’re fine.”
-
“Boeing wouldn’t cut us over cybersecurity.”
-
“Our ERP’s in the cloud; that covers us, right?”
Reality Check:
-
If you receive technical data, drawings, NC code, or TDPs from a prime, you’re in scope.
-
The flow-down requirement means CMMC doesn’t care if you’re Tier 1 or Tier 12 — if CUI touches your shop, you need compliance.
-
Denial often ends abruptly when a prime sends a Supplier Cybersecurity Questionnaire or threatens to reassign work.
2. Anger — “This Is Ridiculous”
Typical Quotes:
-
“The government is out of control.”
-
“We’ve been making these parts for 30 years without a problem.”
-
“Why should we spend money on IT when we could buy another Haas?”
Reality Check:
-
Attacks on defense suppliers are skyrocketing.
-
CMMC isn’t just paperwork — it addresses real vulnerabilities like unpatched CAD stations, stolen NC programs, and ransomware on shop floors.
-
Without compliance, primes legally can’t send you certain drawings or NC files.
What Helps:
-
Break down CMMC into bite-sized milestones.
-
Show leadership exactly what’s optional vs. non-negotiable.
-
Reframe it: CMMC isn’t an IT tax — it’s the price of staying in the game.
3. Bargaining — “We’ll Find a Shortcut”
Typical Quotes:
-
“Can’t we just sign a self-attestation form?”
-
“If we delete the CUI after we print it, we don’t need security, right?”
-
“What if we just buy a firewall and tell the auditor we’re secure?”
Reality Check:
-
Level 1 does allow self-attestation, but Level 2 — which most machine shops fall under — requires third-party certification (C3PAO).
-
Primes are demanding evidence — POA&Ms aren’t good enough anymore.
-
Half-measures like throwing a firewall on the network won’t protect offline CNCs, CAD stations, and traveler workflows.
What Helps:
-
Build a segmented CMMC enclave (like what you’re doing with Core Vault).
-
Keep CNC machines offline and isolate them from IT networks.
-
Use FIPS 140-2 USBs for NC transfers.
-
Set a realistic roadmap instead of scrambling during audits.
4. Depression — “We Can’t Afford This”
Typical Quotes:
-
“This is going to bankrupt us.”
-
“We’ll lose our biggest customer.”
-
“I’m too small for this — there’s no way we can compete.”
Reality Check:
-
The costs are real:
-
Enclave builds: $20k–$100k+
-
Annual audits: $10k–$20k
-
Policies, training, logging — time sucks
-
-
But not doing it is worse:
-
Loss of DoD contracts
-
Reduced eligibility for prime work
-
Increased cyber risk = higher insurance rates
-
What Helps:
-
Start small: protect the minimum in-scope environment.
-
Use outsourced enclaves — lower cost than trying to DIY.
-
Prioritize high-value programs first; you don’t have to CMMC-secure your entire shop.
5. Acceptance — “Let’s Do This”
Typical Quotes:
-
“Okay, we’ll build the enclave.”
-
“Let’s train everyone on MFA and FIPS drives.”
-
“We’re scheduling our C3PAO assessment next quarter.”
Reality Check:
-
Acceptance = leverage.
-
Shops that get compliant early become strategic suppliers:
-
Preferred by primes
-
Attract better-margin programs
-
Less competition, because many suppliers get cut
-
The Winning Formula:
-
Use a phased roadmap
-
Leverage specialized vendors (Core Vault, Overton, Exostar)
-
Align policies, IT, and plant-floor workflows before auditors arrive





