Contact Us
Services
Services
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
Sustainability Services
Sustainability Services
AI Governance
AI Governance
About Us
About Us
Leadership Team
Leadership Team
Corporate Social Responsibility
Corporate Social Responsibility
Careers
Careers
Strategic Partnerships
Strategic Partnerships

What CMMC Can Learn from PCI DSS: Making Security and Compliance Available for Small Businesses

CMMC | PCI DSS

Published: Jul 27, 2026

I lead Schellman’s PCI practice, not our CMMC practice, so I'll say upfront: I'm not the person to weigh in on assessment mechanics or how any specific contractor should meet its DFARS and/or NIST 800-171 requirements. But I've spent years watching an eerily similar challenge play out in the PCI landscape that ultimately got solved in payments. The Department of War's (DoW's) recent suspension of CMMC Phase II appears to be approaching the same fork in the road that the card industry faced years ago.

The DoW’s Suspension of CMMC Phase II

For context, on July 13, 2026, the DoW immediately suspended CMMC Phase II, the third-party assessment requirements that were set to take effect November 10, 2026, and launched a 60-day review of the program. The move follows warnings from small business stakeholders that the framework imposes costly bureaucratic burdens on the small contractors essential to growing the Defense Industrial Base.

The Department has made clear its objective is to reduce compliance burden while maintaining strong cybersecurity, not to lower the security bar, which is exactly the distinction PCI DSS had to make. PCI DSS didn't become affordable by lowering the compliance bar, it got affordable by shrinking the surface area that had to clear it.

How PCI DSS Reduced Compliance Burden Without Lowering Security Standards

In short, a merchant that completely outsources payment processing, never touching cardholder data itself, can qualify for SAQ-A-a short self-assessment instead of a full assessment. The provider performs the security functions; the paperwork simply confirms the merchant is using them correctly. In addition, advanced solutions like P2PE and tokenization extended the same logic to merchants still in the transaction flow, using validated solutions that remove cardholder data from the merchant's environment entirely, so most of the standard becomes not applicable rather than waived.

Either way, the bar didn't move. The target got smaller. Experts built secure architectures once, and merchants simply consumed them rather than each engineering compliance from scratch.

Why CMMC Compliance Is Still a Heavy Lift for Small Businesses

By comparison, CMMC has largely taken the opposite path. Significant investment has gone into expanding the assessor ecosystem, but the Defense Industrial Base still expects each small manufacturer, supplier, and subcontractor to design, build, secure, and maintain its own Controlled Unclassified Information (CUI) environment, none of which is assessor driven.

The building blocks for a better model already exist, and they map onto both tiers of the PCI analogy. Hyperscale cloud providers (Microsoft, Amazon, and Google chief among them) operate FedRAMP-authorized environments a defense contractor can already host workloads in today. That said, these enclave solutions still require the contractor, or its MSP integrator, to configure and align that environment against all 110 requirements in NIST 800-171. The hosting environment is validated, the enclave built on top of it generally is not. That's a meaningful difference from outsourced payment processing, where the terminal arrives validated, and the merchant's job is deployment, not configuration.

What CMMC Needs: A PCI-Style Reliance Model for ESPs

That gap points to something PCI has that CMMC doesn't yet: an assurance model built around reliance. When a payment processor is PCI validated, merchants using it can rely on those controls rather than re-proving them. CMMC has no clear equivalent at the enclave layer. FedRAMP gives confidence in the underlying cloud infrastructure, but validation of the focused enclave solutions built on top of it, what CMMC calls External Service Providers, or ESPs, has been inconsistent. Without a consistent way to rely on an ESP's validation, each contractor is still responsible for proving its own configuration is correct, even on infrastructure already validated once.

The Future of CMMC

The long-term solution doesn’t involve weaker assessments or fewer security requirements. It's an ecosystem with both tiers built out: fully outsourced, VDI-style access for contractors who don't need CUI to reside locally, and pre-validated, turnkey enclaves - built on the hyperscale infrastructure already in place - for those who do, backed by a reliance model that lets a small contractor trust an ESP's validation the way a merchant trusts its processor's. Delivered by cloud providers, primes, and technology vendors, either approach shrinks the compliance footprint, turning compliance into a deployment decision rather than engineering project.

I'll leave the mechanics of CMMC assessments to colleagues who perform them every day. But having watched the payments industry solve this exact tradeoff, I'd offer one observation: the focus should shift from scaling assessors alone to scaling compliant architectures and the assurance model behind them that make security simpler, repeatable, and affordable. The next evolution of CMMC is an ecosystem that makes a strong standard dramatically easier to achieve. If you have any questions or want to continue the conversation, contact us today.

Adam Bush leads Schellman's PCI practice. The views above reflect an outside perspective on CMMC, informed by parallel experience in payments compliance rather than direct CMMC assessment work.