5 min read
CMMC Structure Matters as Much as the Controls
upwardadmin , Devon Nevius August 21, 2026
CMMC Structure Matters as Much as the controls
In the early 2010s, office equipment companies began entering the Managed IT Services space en masse. Copier dealers saw a new revenue stream in IT management and flooded the market — yet the transition proved disastrous for most. Research from Quocirca found that the channel was fundamentally split between copier dealers who had billing infrastructure but no IT expertise, and IT resellers who had technical skill but no managed services framework. Few bridged that gap successfully. I had a front-row seat to this, having been charged with standing up just such a division at one of the largest privately held office equipment companies in the country. It was a disaster. The culture, workflows, and momentum of the existing business were completely misaligned with what managed services required. No matter how much effort we poured in, the messy processes, internal confusion, and lack of organizational alignment made it impossible to build a streamlined service delivery engine. I left that company to start my own business and watched from the outside as they struggled for years to build a reputable IT practice — and whether they ever truly got there remains an open question.
The graveyard of professional services is littered with companies that chased the "one-stop shop" dream: the belief that bolting a specialized practice area onto an existing service business would unlock effortless cross-sell and make clients' lives simpler. Today, we are watching the same movie play out in the MSP channel as providers rush to stand up in-house CMMC consulting practices. The logic sounds familiar — "We already manage their IT, so we should assess and remediate their compliance too." But being a great MSP, built on efficiency, automation, and recurring delivery, is a fundamentally different discipline than being a great cybersecurity consultancy, which demands deep advisory expertise, audit independence, and a willingness to tell clients hard truths about the very environments you built. Trying to be both does not make you a one-stop shop. It makes you mediocre at two things.
The MSSP Gold Rush
As CMMC requirements ramped up in the United States, hundreds of MSPs rushed to morph their practices into becoming an MSSP — a Managed Security Services Provider. The concept was straightforward: develop CMMC expertise and tooling in-house, build a certification readiness program, and raise rates accordingly. The managed security services market has grown from $30.6 billion in 2023 to a projected $87.5 billion by 2030 (Grand View Research), and the financial incentive is obvious — the average monthly recurring revenue per managed security client reached $8,900 in 2024, more than double that of a traditional IT client.
The promise for manufacturers was equally compelling. With security touching every corner of your business and every employee, consolidating your service delivery, compliance strategy, and tooling under one provider makes a certain degree of intuitive sense. According to the DFARS final rule published in September 2025, approximately 118,289 entities require Level 2 CMMC certification through a third-party assessor, with roughly 80,000 of those being small entities handling Controlled Unclassified Information (CUI). The demand is enormous.
However, just as the "eggs in one basket" argument suggests, this consolidation has proven fraught for a great many manufacturers. Survey data consistently reveals the scope of the problem: 73% of SMBs lack confidence that their MSP could fully protect them during an attack, and 45% would consider switching providers if their current MSP fails to demonstrate the necessary expertise for comprehensive security support (ConnectWise; Discover Cyber Solutions). In our direct experience working with defense manufacturers, the dissatisfaction rate tracks closely with these figures — roughly one in three organizations we encounter is unhappy with their combined MSP/MSSP arrangement.
Why CMMC Manufacturers Are Struggling
Many IT services companies were not particularly strong at IT support *before* they layered on the enormous complexity of NIST 800-171 compliance. Imagine adding a brand-new production line for a completely different product category when you cannot reliably track your existing inventory or backflush your current jobs. That is what has happened as these MSSPs moved quickly to promise clients they are great at both disciplines simultaneously.
In reality, it is extraordinarily difficult to be genuinely excellent at either, so only a small subset of providers actually pull off both — and they charge a significant premium while quickly moving upstream to larger clients. According to industry data, managed EDR services deliver gross margins of approximately 42%, nearly 18 percentage points higher than traditional IT support (CyVent 2025). That margin differential creates powerful incentives to *claim* security expertise whether or not the underlying capability exists.
The Private Equity Problem
Due to the allure of higher engagement fees and stickier client relationships, private equity firms have rushed into the space. In 2025 alone, 169 publicly announced MSP M&A deals closed, with PE firms involved in roughly 69% of them (CT Acquisitions). The results are predictable: as PE-backed platforms begin to squeeze operational costs and standardize delivery across dozens of acquired practices, the personalized advisory work that CMMC demands gets reduced to a checkbox exercise. The specialized talent that made those firms valuable in the first place often leaves within the first 18 months.
The Fox Guarding the Henhouse
Perhaps the most significant structural issue is the inherent conflict of interest. When the same provider builds and manages your IT environment *and* assesses your compliance posture against that environment, the incentive to identify and escalate deficiencies is fundamentally compromised. Research has found that 64.5% of companies discovered unsecured devices that their MSP's tools claimed to be covering (Zip Security 2026). When nobody external is checking the work, gaps persist quietly until an assessor — or an attacker — finds them first.
The Flexibility Trap
The real problem at the end of the day with this structure is mobility. When your IT support, tooling, and compliance momentum are all wrapped up with a single provider, it becomes extraordinarily difficult and painful to make a change — regardless of how much pain you are experiencing. You are effectively locked in, and that provider knows it.
The Recommended Structure
Hire an MSP and a Compliance Advisory firm separately.
This creates several meaningful advantages for a small or mid-sized manufacturer:
Natural checks and balances
When your compliance advisor governs the controls and your MSP aligns the technology, you have two independent parties whose work validates the other. Neither is grading their own homework. Your advisor identifies what needs to be true; your MSP makes it true; your advisor verifies that it is.
Flexibility
If you are dissatisfied with either party, you can far more easily replace them without upending the other relationship. If you like your MSP, they should be able to help you find and vet a strong compliance advisor. If you trust your advisor, they should be able to recommend an alternative MSP. Neither transition requires starting from zero.
Cost transparency
This may seem counterintuitive — many MSSPs will argue that consolidating services is more cost-effective and efficient. In our experience, the opposite is true. By separating the two agreements, you gain the ability to explore more solutions and strategies independently, validate pricing against the broader market, and identify the most reasonable path forward without a single provider controlling the narrative around what is necessary and what it should cost.
Looking Ahead
As CMMC continues to evolve — and with Phase 2 implementation timelines still in flux following the July 2026 suspension — it is more important than ever that you give your business the structural flexibility it needs to adapt. The manufacturers who will navigate this landscape most successfully are not the ones with the most convenient vendor arrangement. They are the ones who built a structure that allows them to evolve, challenge assumptions, and stay competitive without asking permission from a single gatekeeper.
Sources: Grand View Research (2023 MSS Market Report); DFARS Final Rule 90 FR 43560 (September 2025); ConnectWise SMB Cybersecurity Statistics; CyVent 100+ Cybersecurity & MSP Market Stats 2025; CT Acquisitions PE MSP Report 2026; Zip Security 2026 Security Survey; Quocirca Channels to Managed Print Services in Europe (2010); Discover Cyber Solutions.