Funding and Cybersecurity Rules: Shaping the Defense Market Like Contracts

0
1

Key Takeaways

  • PSC submitted comments on the CMMC reform proposal, emphasizing the need for consistent cybersecurity standards across all federal agencies.
  • The organization’s three overarching concerns are: (1) uniformity of standards, (2) realistic cost‑benefit analysis of cyber hygiene and reporting, and (3) fair treatment of existing certifications when standards change.
  • The current pause in CMMC creates uncertainty for companies that have already invested in certification and those still in the queue, but many view completed work as a valuable asset to build on.
  • Consistent, predictable guidance is essential for contractors’ long‑term business planning and investment decisions.
  • Continuing resolutions (CRs) have become the norm; a Senate‑passed CR extending funding to December 11 offers temporary stability, yet its fate in the House remains uncertain.
  • Reconciliation is critical for the defense budget, providing roughly $350 billion to backfill munitions, operations‑and‑maintenance, and other accounts that have already incurred expenses.
  • Federal contractors face a triad of uncertainty: funding instability (CRs and possible shutdowns), regulatory flux (ongoing FAR overhaul and CMMC changes), and delayed government payments.
  • Small businesses are disproportionately affected by payment delays because they lack the financial flexibility of larger firms.
  • PSC urges that any reforms prioritize actual cybersecurity improvement over mere compliance paperwork and that existing certifications be recognized as assets during transitions.

CMMC Reform Comments and Industry Concerns
The Professional Services Council (PSC) recently submitted its comments on the CMMC reform proposal after the deadline for public input passed. Representing roughly 400 member companies—many of which are technology‑focused service providers—PSC drew on its long‑standing involvement with the CMMC program, which originated seven years ago. The council stressed that any revisions must be examined through the lens of industry’s practical experience, especially because many firms simultaneously serve multiple agencies such as the Department of Defense, Homeland Security, and Health and Human Services. Consistency across these domains emerged as a top priority in PSC’s feedback.


Core Overarching Concerns of PSC
PSC identified three broad concerns that shape its stance on CMMC reform. First, the council advocates for a single, federal cybersecurity standard that applies uniformly to all contractors, arguing that differing requirements for Defense, DHS, or HHS contractors create unnecessary complexity and cost. Second, PSC urges the government to weigh the full cost of implementing basic cyber hygiene, additional controls, and associated reporting against the actual security gains achieved; the focus should be on delivering measurable improvements, not merely checking boxes. Third, the council highlights the plight of firms that have already earned CMMC certifications: if the standard changes, those certifications should retain value and be treated as assets rather than discarded work.


Impact of the CMMC Pause on Certified and Pending Contractors
The current pause in CMMC implementation has produced mixed reactions among contractors. Companies that have already undergone third‑party assessments through a C3PAO and obtained certification view their efforts as a foundation to build on, not as wasted investment. Likewise, firms that remain in the certification queue—having made partial investments but not yet completed the process—continue to pursue certification, anticipating that any eventual standard will recognize the work already done. PSC notes that this attitude reflects a shared desire to ensure that the pause does not erode confidence in the program’s ultimate goal: genuine cybersecurity improvement.


Need for Consistent Guidance in Business Planning
Stephanie Kostro emphasized that predictable, consistent guidance is indispensable for contractors engaged in long‑term business planning. When requirements shift unpredictably, firms struggle to allocate resources, schedule upgrades, or justify expenditures to shareholders. Consistent standards enable companies to forecast costs, schedule audits, and align internal roadmaps with federal expectations. In the context of CMMC, Kostro argued that the work already performed should count toward future compliance, thereby reducing redundant effort and preserving trust between industry and government.


Continuing Resolutions and Funding Predictability
Turning to fiscal matters, Kostro observed that continuing resolutions (CRs) have become the de facto norm for federal funding, with the last regular appropriations passed by October 1 occurring rarely in the past three decades. The Senate‑passed CR, which would extend government operations to December 11—past the midterm elections—offers a window of stability that many contractors welcome. However, the measure faces an uphill battle in the House, despite presidential support. Without a CR, the government risks a shutdown, a scenario PSC prepares for by providing members with pre‑shutdown checklists; the council hopes to avoid needing them.


Reconciliation and Defense Budget Pressures
Reconciliation plays a pivotal role in fulfilling already‑incurred defense expenses. The President’s budget request totals roughly $1.5 trillion, of which about $1.1 trillion constitutes the base FY27 budget, while the remaining $350 billion resides in the reconciliation package. This allocation is earmarked to backfill munitions, operations‑and‑maintenance, and other accounts that have already accrued costs. Kostro warned that securing the necessary votes for reconciliation remains uncertain, leaving the defense industrial base in a holding pattern until legislators return from their August district work period.


Triad of Uncertainties: Funding, Regulation, and Payment Delays
Contractors currently navigate a “messy middle” defined by three interlocking uncertainties. First, funding instability stems from reliance on CRs and the looming threat of a shutdown. Second, regulatory flux arises from the ongoing FAR overhaul—including base FAR, DEFARS, and supplemental clauses—combined with proposed rule changes and class deviations that leave unclear which compliance standard will apply at any given moment. Third, payment delays persist: agencies sometimes lag in settling invoices for costs already incurred, and termination settlement proposals can linger for over a year. These delays hit small businesses hardest, as they lack the cash reserves or credit lines to absorb prolonged receivables.


Small Business Vulnerability
The cumulative effect of funding, regulatory, and payment uncertainties disproportionately affects small contractors. Unlike larger firms that can shift internal funds or access lines of credit, small businesses often operate on thin margins and depend heavily on timely government payments to sustain operations. Delays in invoice settlement or sudden changes in compliance requirements can force them to divert scarce resources from growth initiatives to crisis management, undermining their ability to innovate and compete. PSC’s advocacy includes urging the government to adopt faster payment mechanisms and to provide transition relief for small firms during regulatory shifts.


Overall Outlook and Path Forward
Despite the challenges, a common thread runs through PSC’s messaging: the ultimate objective must be enhanced cybersecurity, not merely compliance paperwork. The council calls for any CMMC revisions to honor prior investments, to apply a single standard across agencies, and to balance costs against tangible security gains. On the fiscal side, PSC advocates for a reliable appropriations process that minimizes reliance on stop‑gap funding and ensures timely passage of reconciliation bills to meet existing defense obligations. Finally, addressing payment delays—especially for small businesses—will reduce financial strain and allow contractors to focus on delivering secure, innovative solutions to the federal mission. By aligning funding predictability, regulatory consistency, and fair treatment of past work, the government and industry can move toward a more secure and stable acquisition environment.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here