The core mechanism discussed is the regulatory pressure and resulting operational risk created by the Department of Defense’s (DoD) abrupt suspension of the CMMC Level 2 third-party certification mandate. IntelliGenesis, led operationally by Jeremiah Jensen, illustrates how rapidly shifting compliance expectations can expose defense contractors and their MSP partners to unrecoverable sunk costs, increased governance complexity, and unclear accountability. The episode highlights the structural disconnect between government-mandated cybersecurity standards and the practical realities of implementing and maintaining those requirements at scale.
According to Jeremiah Jensen, IntelliGenesis incurred more than $200,000 in direct costs, invested four months of intensive labor, and committed a team of five to six staff to achieve early CMMC Level 2 certification—including significant documentation, hardware upgrades, and consultant fees. Despite this investment, the DoD paused the entire third-party assessment program on July 13, citing small business cost burdens and insufficient assessor capacity. This left companies like IntelliGenesis having already completed—and paid for—requirements that were no longer mandated for the time being, but with underlying security obligations still in effect.
Secondary issues reinforce the underlying risk: the audit process was described as inflexible and expensive, with a binary pass/fail outcome that offered no remediation for minor deficiencies—requiring full re-audit at the original cost if any portion was not met. Further, both Dave Sobel and Jeremiah Jensen noted a lack of clarity in ongoing expectations, as large defense primes were previously flowing down certification pressures to subcontractors, but have gone quiet since the mandate was paused. The temporary pause, coupled with ongoing self-attestation requirements and a comment period through August 14, creates a regulatory gray area with uneven impacts across the defense supply chain.
For MSPs and IT providers supporting government contractors, these developments translate to increased contract risk, ongoing uncertainty in governance requirements, and exposure to costs that may not deliver a return if regulations shift again. The episode clarifies that self-attestation standards are still in place, but the lack of authoritative third-party oversight introduces ambiguity and potential liability. Providers should anticipate further regulatory refinement, engage with clients regarding their compliance posture, and treat sunk certification costs and compliance-driven operational overhead as persistent risks rather than guaranteed business advantages.
Supported by:
💼 All Our Sponsors
MSP Radio is supported by our partners:
ABC Solutions · CometBackup · GoTo · Guardz · Opentext · Pax8 · Rythmz · ScalePad · TimeZest · Transit AI
Supporting the IT services community through insights, analysis, and transparency.
🚀 Join Business of Tech Plus
Get exclusive access to investigative reports, vendor analysis, leadership briefings, and more.
👉 https://businessof.tech/plus
🎧 Subscribe to the Business of Tech
Want the show on your favorite podcast app or prefer the written versions of each story?
📲 https://www.businessof.tech/subscribe
📰 Story Links & Sources
Looking for the links from today’s stories?
Every episode script — with full source links — is posted at:
🎙 Want to Be a Guest?
Pitch your story or appear on Business of Tech: Daily 10-Minute IT Services Insights:
💬 https://www.podmatch.com/hostdetailpreview/businessoftech
🔗 Follow Business of Tech
LinkedIn: https://www.linkedin.com/company/28908079
YouTube: https://youtube.com/mspradio
Bluesky: https://bsky.app/profile/businessof.tech
Instagram: https://www.instagram.com/mspradio
TikTok: https://www.tiktok.com/@businessoftech
Facebook: https://www.facebook.com/mspradionews
Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
[00:00:00] For two years, every defense contractor in America was told the same thing. Get certified before November or stop bidding. Then, on July 13th, the Department of Defense switched it off. My guest already paid. He went through the full third-party audit, passed it early, and said out loud at the time that it cost too much and took too long. Six weeks later, the government agreed with him after he had written the check. So, was it wasted?
[00:00:30] This is the Business of Tech. I'm Dave Sobel. Jeremiah Jensen, you are the Chief Operating Officer at Intelligensys. Welcome to the Business of Tech. Oh, good to be here. So, let's start with the bill, right? Because that feels like we have to start talking about it there. Intelligensys got its CMMC Level 2 certification early, right? You moved ahead of most of the defense industrial base.
[00:00:56] But I want to talk before we get into everything else, like what did that cost you? Like dollars, months, people time, like how much investment did it take to get that certification? Yeah, that was a huge lift. So, we're probably looking over $200,000 initial money that we ended up paying. Now, that included money for the audit, included to bring in consultants to kind of help us work through the audit.
[00:01:26] Through the processes. And then it just included upgrading a lot of our products to make sure that they're FedRAMP compliant and buying our additional licenses that we needed.
[00:01:43] So, you had the initial cost dollar-wise, but then we had basically four months. I had a team of five, six people. We're running about seven days a week. In order to kind of build the process and procedures that we really needed to kind of incorporate and pass the audit that we were going to get audited on.
[00:02:09] So, I think we ended up writing almost 50 procedures all together and then building out the SSP. I think our SSP was around 400 to 500 pages. So, a lot of the paperwork kind of get in place for this audit coming up. So, that's not even including all the time that we ended up putting in for this.
[00:02:34] And that SSP, that's the system security plan, right? So, you had to really invest in expanding that. And my understanding is that was like the single most labor-intensive part of that. Like, who wrote those pages and what were they supposed to be doing instead of doing that? Yeah. So, working along with our security team, the security folks, they love doing things, but not actually kind of writing things down and keeping track of things.
[00:03:01] So, I kind of brought in some of my proposal writers where we could have been working on proposals and other things. We kind of went in there, helped them set up the process, built out the templates, got them started, and then sat down with them, kind of got the information so we could actually help build out the SSP and get that stood up.
[00:03:24] And, you know, basically, it was kind of going back and forth with them. So, we could get all the documents. We needed, with the CUI, we needed to show how the CUI flow worked within the company, how it was going in, how we're storing it, protecting it.
[00:03:42] All of our hardware, we had to basically record and put in there, and then basically show all the security that was wrapped around it. So, it was a pretty big lift. And I understand you also had to bring in an outside consultant at additional cost, particularly because the assessors themselves aren't allowed to give you any guidance. Like, when you look at that, is that the cost of getting certified, or is that a cost of how the program was designed?
[00:04:10] Yeah, I mean, the people that were doing the audit, they were basically saying they could not consult. So, and we had a lot of questions. You know, I have my, basically, my team had a lot of questions. They were reading the requirements and trying to come up with a solution.
[00:04:34] We really needed that, basically, that other entity to kind of come in and give us that guidance, kind of break the tie. Because I viewed it in a different way than my team. Sometimes my team went way too strict with the security controls. But at the end of the day, we still have to manage those and make sure that the company can function.
[00:04:56] So, it was a huge cost in the sense that, you know, if we had better guidance, I don't think we would have really needed the consultant to come in and kind of be that tiebreaker that we're looking for. Now, obviously, you passed. But I know that the audit itself was a weak. It was super technical. Your IT person having to go through everything. I'm confident there was at least one point that wasn't perfectly smooth.
[00:05:26] Can you give me some insight in, like, something that the assessor asked for that you couldn't produce or where there was some of the stumbling bit during the assessment? Yeah, some of the stumbling bits. We prepared for everything. So, kind of going through this audit, the one thing we did not prepare for, we had an outage. So, we lost our power for the entire building. And we had the auditors. They were all virtual. Everything went down.
[00:05:55] And we didn't get our power back for, like, two to three hours. So, that is something that we really didn't prepare for for the audit. Kind of having a contingency plan in place. We basically kind of moved the requirements down when they did the physical visit. But everything else, we were pretty good for the audit. Like I said, we had a lot of detail.
[00:06:22] And so, we did fairly good, you know, going through. And they didn't have any findings. We'll be right back after this message. The MSPs getting ahead in security aren't adding more tools. They're getting the work off their plate. Guards consolidates the stack, endpoint, email identity. And then puts an autonomous analyst on top of it.
[00:06:49] Triaging the alerts, correlating the signals, drafting the client reporting automatically. It's purpose-built for MSPs protecting S&B clients month to month. Real SecOps without hiring a SecOps team. Start at guards.com. That's G-U-A-R-D-Z dot com. And we're back. So, you do the process.
[00:07:17] And now we get into the part that's almost like, I couldn't have scripted this, right? So, July 13th. You know, when you find out what was going on, you found out that Phase 2 was suspended. Like, what's the first thing that goes through your head? Yeah, I was... I wasn't too happy. I had some choice words. But it was kind of disappointing because, you know, they basically set a date we had to hit.
[00:07:47] You know, we're a security company. So, we made all the investments. We put in the time. And, you know, we ended up pushing through it. And just kind of seeing that it was kind of put on the pause. They released the RFI so we can provide comments back and things. Kind of disheartening. I was... But I could see why. You know, they started pushing all the requirements to the contracts.
[00:08:14] And I don't think all the companies would have got through basically the assessments in time. So... Well, and you were pretty blunt about this. Back in February, you called this all out. You couldn't get an assessor. The paperwork was overwhelming. You put 50 documents through. And my understanding is your CEO had deliberately waited as long as she could, hoping the Department of Defense would offer small businesses like a sliding scale
[00:08:42] and move forward only when she decided that help really wasn't coming. Five months later, the department paused the whole program, citing small business costs. So, I kind of have to ask, was she right to wait and wrong to stop waiting? Like, what's your take on the feeling of how you left? Um, you know, we made the best decision that we could with the information that we had. And, you know, we have a lot of prime work.
[00:09:08] And these requirements were getting written into the contracts as they get recompeted. So, as the business choice, you know, we had to do this. Um, even though that they put the pause on this, I, I believe, you know, they're going to take some feedback, refine the process. Um, it's the security requirements are still there. You know, they, they, they just don't disappear. So, I, we, we, I believe we made the right decision.
[00:09:38] It's just seeing it come down and getting paused like this. And then now they're asking for kind of comments on the process. That should have happened way before this, before we got to this point. So, now we're at this point, right? You've been on the record saying you thought the program was too expensive, too slow, short of assessors. And government now effectively agrees with you, switching off the program, yet still keeping the requirements in place.
[00:10:06] So, I kind of want to know, like, is this a badly built program? Or is this a stumbling? Like, what, what's the actual view of what this program needs to do? I think there's some refinements that can happen for this program. I, I think the documentation is way too extensive of kind of what we had to put together.
[00:10:31] I always think about smaller businesses that are in this with like five, 10 employees. How are they going to get through this process? I mean, it's definitely going to create a barrier to entry. Um, also with the audit itself, the one thing I, I really didn't like, we're going through this process is, if you fail the audit, then you're done.
[00:10:58] Um, you have to get another audit and it's the same price. There is no, okay, these are the portions you failed and they can basically scale that up to say, oh, well, you fix these and then you can get your service. It's, if you don't meet it, you fail and then you got to get another audit. So there was no chance. We, there was no chance for us to, um, not pass, you know?
[00:11:28] Right. So, um, I, I do think that they could build some efficiencies into that. Um, definitely decrease, you know, some of the requirements. There's a lot of duplicate requirements that they had, um, within there. Um, but, and then basically getting more assessors. Um, so hopefully getting more assessors, it might drive down the cost.
[00:11:52] But, you know, at this point right now, um, you know, it's not a lot of assessors and the cost is still pretty high. So. Now you, before the pause, you'd said that the big primes were already forcing smaller companies to comply, right? And that, that was the, the pressure before. Has that pressure stopped? Like, do the primes still care about the certificate now that the mandate is paused? What's the, the feel in the market? Yeah.
[00:12:18] So, we haven't heard anything from the primes, but prior to this, the, the primes were adding a lot of pressure. They're like, hey, we need to make sure that you, you have your certification. Um, and they were flowing it down. Of course, that's what they were asked to do. And, you know, if we were bringing on subs, uh, we'd have to flow that down to our subs also. Um, but with the, with the pause, I haven't had anybody reach out to us yet. So.
[00:12:49] Gotcha. All right. Now we're going to, we're going to have a fun, you can Monday morning, Monday morning quarterback this question a little bit. We can get in the DeLorean. We can go back in time and we can tell you back in the first of January that the requirement will be suspended in July. Would you make a different decision?
[00:13:10] Um, I would, I would probably still push through with it, but it would just be an extended timeline. We had a short timeline to do it in. So within a couple months, I would probably have, instead of working on the weekends, um, just extended my timeline. I, I believe in security. I think it's a great thing. Um, I, I see the, I see what they're trying to do.
[00:13:39] Um, with this. Um, I believe in it. Um, I still would have gone through it. It would have just taken me a little bit longer to get through this process instead of jamming it all in within a couple months. We'll be right back after this message. I track conversations from the MSP community every week. And the frustration I keep seeing isn't that MSPs don't know what AI can do.
[00:14:07] It's that no one clearly explains how to start building and monetizing AI for their business and clients. Pax8 does it differently. A curated cloud marketplace where AI works for you. Education built for MSPs and the infrastructure to deliver managed services and intelligence at scale. 47,000 partners have already made it the center of their operations.
[00:14:30] If you're ready to cut through the AI noise and grow with agentic solutions, start at Pax8.com. That's P-A-X, the number 8, dot com. And we're back. Let's talk a little bit about the market right now. So the third-party audit is paused, but the obligations to safeguard the covered defense information isn't. So neither is really a standard, right? And there's still exposure there.
[00:14:59] Walk me through what a defense contractor is still legally on the hook for right now. Yeah. So basically, we still have to protect the COOE. So all the information and everything like that that comes down, it still has to be protected. We do our basically SPRS. We do our self-assessment, basically saying that we are safeguarding this information and still protecting it.
[00:15:27] Now, what it put on pause is basically the third-party assessment so you can get to your level two. So basically, you still have to protect your COOE. You still have to do all the security stuff. But getting your level two certification, that was put on pause. And there's still a self-attestation portion here, right, where they can self-certify.
[00:15:57] Like, based on this, do you think there's a little bit of confusion now? Because you have a mix of previously assessed and self-attestation now can kind of be lumped together. Is there potential confusion in the market? Yeah, I think so. Yeah.
[00:16:18] As you're going through and they say people are doing their self-assessments and on the RFI, they said they've called out people and companies that haven't held up to their self-assessments. I don't know about that. But, you know, going through the assessment, we were going through, like I said, security company, making sure that everything was correct.
[00:16:43] If we're checking on something, we're making sure that, you know, we adhere to whatever we're checking to. So I want to get your take on kind of the cynical case of this, right, because I've heard this out there in the space. The government builds an entire certification industry, tells thousands of small companies to spend billions on paperwork to prove they're secure, and then turns it off, potentially because it's politically inconvenient.
[00:17:09] Like, does the suspension prove the critics were right, that this was compliance theater, or do you think this was, you know, it's still a good investment of people's time? Yeah, that's a loaded question. So I definitely believe in the security. I believe what they were doing is trying to protect the supply chain.
[00:17:38] Being in the security, we see the supply chain getting attacked. I think this is their best way of trying to address it. The best way the government can address it. Every time a lot of documentation, I mean, they could have probably gone doing it a better way. But how do you get a standard to get everybody in line to make sure that they are putting the protections in place?
[00:18:10] That's kind of hard. I don't know if they fought everything through going through the process, because as companies are going through and we're actually getting the costs and stuff, I think they were realizing that, you know, there's not enough auditors, you know, and people started talking about the costs.
[00:18:33] I think that's when they realized they had to kind of put a pause on it to kind of figure out what they're kind of dealing with. Like I said, I believe protecting the supply chain has to be done. I just don't know of a better way to do it at this point. Totally fair. So last question, and I want to make it a little bit practical, right?
[00:18:59] So this is we're in the 60-day review comment period, and the window closes August 14th. Like for a defense contractor, like what do you want to see happen? Like what are the comments that you're focused on making sure that they can address? And what do you want to see come out of this pause period?
[00:19:22] I would, so we downloaded the RFI, so we're definitely going to respond to it, kind of talk about our pain points. I definitely would like to see definitely more assessors getting pushed through. And talking about the audit process in general, I mean, I don't like how the audit is set up where you miss a couple things and you fail it,
[00:19:49] and then you have to pay the entire price to go through the audit again just for those few things. I would like to almost see the audit as you're going through it and you have basically things that you could poem and you could fix, and then you could still pass the audit without just failing the thing entirely. I think there's a lot of improvements that could happen with this. Like I said, we downloaded the RFI. It came out.
[00:20:17] We're definitely, I think they said about 10 pages. We're definitely going to offer our comments to try to make the process better and hopefully we'll be heard. Jeremiah Jensen is the Chief Operating Officer and Program Manager at Intelligensys, with more than 20 years in the intelligence community and a background as a signals collection and identification analyst in the U.S. Army. He ran Intelligensys through its CMMC Level 2 third-party certification,
[00:20:46] one of the earlier completions in the Defense Industrial Base. Jeremiah, if people are interested in continuing the conversation, reaching out, how can they do so? They can just reach out to my email address, jeremiah.jensen at intelligenesis.us. Jeremiah, thanks so much for joining me today. All right. Thank you. What would you fix in your business with the right playbook?
[00:21:12] Small Biz Thoughts members get a library of templates and operational resources, recorded member calls, and classes through IT Service Provider University. Operational education built specifically for independent MSPs. Start at smallbizthoughts.org. Interested in advertising? Head to mspradio.com slash engage.
[00:21:37] The Business of Tech is written and produced by me, Dave Sobel, under ethics guidelines posted at businessof.tech. Thanks for listening. I'll see you on the next episode. Proud member of the MSP Radio Network. Produced by Picture This Video. Proud member of the MSP Radio Network.

