Lionfish Cyber Security Decision Support Empower · Lead · Defend

CMMC ROI Calculator

Is CMMC worth it?
Run your numbers.

CMMC is now written into Department of War contracts. Certifying costs real money — but walking away costs your War Department revenue, and every competitor who opts out leaves contracts on the table for the companies that stay in the fight.

Three numbers. Sixty seconds. A straight Go/No-Go answer.

Go/No-Go Assessment Step 1 / 3

What's your total annual revenue?

All revenue, across every customer — commercial and government. This sets the baseline for how much of your business rides on defense work.

$

Why the window favors early movers

48 CFR

The CMMC acquisition rule is final — certification requirements are being written directly into DoW contract clauses as rollout phases in.

120,000+

Small businesses in the defense industrial base face CMMC obligations. Even with Phase II paused for the DoW's reform review (through ~Sept 13, 2026), contractors must still protect CUI, self-assess, and affirm their scores today.

Exits = openings

SBA reports many firms are leaving defense work over compliance costs. Every exit shrinks the compliant supplier pool — and enlarges the share for those who stay.

Sources: SBA on the CMMC Phase II suspension (Jul 2026) · CSIS: What the CMMC pause means for the DIB · DoW CIO — CMMC program

You already agreed to this

The audit may be paused. The obligations aren't. When you registered in SAM.gov and accepted a Department of War contract, these clauses came with your signature — whether or not anyone ever audits you:

FAR 52.204-21

Basic safeguarding. Fifteen baseline security controls on any system that touches federal contract information. The floor for every federal contractor.

DFARS 252.204-7012

Safeguard covered defense information. Implement all 110 controls of NIST SP 800-171 and report cyber incidents to the DoW within 72 hours. In nearly every contract that touches CUI.

DFARS 252.204-7019 / 7020

Prove it in SPRS. Post a current NIST 800-171 self-assessment score to the government's Supplier Performance Risk System — and let the DoW come verify it (DIBCAC assessments continue through the pause).

DFARS 252.204-7021

The CMMC clause. Certification requirements phasing into contracts under the 48 CFR rule. Phase II is paused for review — the clause is not repealed.

The annual affirmation — 31 U.S.C. § 3729

Every year, a named executive at your company — the Affirming Official — certifies to the federal government that your SPRS score is accurate. That's a federal representation. If you're breached, investigators pull your score and compare it to reality. If your score was fiction, that's not a compliance gap anymore — it's a False Claims Act case, with treble damages and per-claim penalties. The Department of Justice built its Civil Cyber-Fraud Initiative for exactly this. Skipping the audit doesn't make that risk smaller. It makes you the only one who ever checked.

What certifying falsely has cost

These aren't hypotheticals. DOJ has already collected from contractors whose cybersecurity claims didn't survive scrutiny — most were caught by whistleblowers or after an incident, not by an audit:

ContractorPaidYearWhat happened
Aerojet Rocketdyne$9,000,0002022Whistleblower suit: misrepresented cybersecurity compliance on DoW and NASA contracts.
Raytheon / Nightwing$8,400,0002025Development system used on 29 defense contracts didn't meet required DFARS controls.
MORSECORP$4,600,0002025Reported a SPRS score of 104 out of 110. A third-party assessment put the real score at −142.
Penn State$1,250,0002024Misrepresented remediation dates on its plans of action — and never followed through.
Georgia Tech Research Corp$875,0002024Submitted a score of 98 for an environment DOJ called "fictitious" — it didn't match the systems doing the work.

Sources: DOJ — Aerojet Rocketdyne · DOJ — Raytheon/Nightwing · DOJ — MORSECORP · FCA cybersecurity case roundup · CyberScoop — Georgia Tech