

President and CEO, E-N Computers
25+ years experience solving business IT problems in Virginia and Washington, D.C.
Somebody at your company is already the default owner of your CMMC program. The only question is whether anyone decided that on purpose.
For most small defense contractors, CMMC sounds like a computer problem, so it gets handed to whoever runs IT. Instead, the owner should be whoever can coordinate people across the company and keep decisions moving.
I run E-N Computers, a CMMC Registered Practitioner Organization that works with small and mid-sized defense contractors across Virginia and the DC metro area, and I’ve sat across the table with dozens of companies working through this decision. Some already have a project manager or a quality manager who’s an obvious fit. Others have neither — no IT department, no one else to hand it to.
QUICK ANSWER:
Who should own your CMMC program?
The owner should be whoever can coordinate people across your company and get a decision made quickly — not necessarily whoever runs your IT. What matters more than the job title is whether that person has the authority to change how the company already works, and executive backing when they use it. Whoever that is also has to be willing to personally sign the annual affirmation. In many small contractors, that’s a project manager who’s good at clearing roadblocks, or a quality manager who already runs an ISO 9001 or AS9100 audit cycle. If your company has neither, the owner is usually the business owner or a senior operations lead, working alongside an outside compliance partner that handles the technical build. Whoever owns the program, it still needs engineers who can do the work — most of the 110 practices are technical.
Table of Contents
- What CMMC requires, in plain terms
- Why CMMC defaults to your IT person, and where that goes wrong
- What makes a CMMC program work, whoever owns it
- The seats that tend to have authority
- What if the answer is you?
- How your internal owner works with an outside RPO or MSP
- How ownership works, month to month
What CMMC requires, in plain terms
CMMC — the Cybersecurity Maturity Model Certification — is the Department of Defense’s way of checking that contractors who handle sensitive government information are protecting it, not just saying they are. Most of the small contractors we work with end up at Level 2, which is the tier that applies once you handle CUI: controlled unclassified information, a category for government data that isn’t classified but still needs protecting — think technical drawings or unreleased program specifications.
Level 2 means a real assessment against 110 security practices. Depending on your contract, you might do the assessment yourself or you may need a DoD-authorized assessor for a third-party audit — though which of those applies to you is shifting right now (see below). Either way, once you’re certified, someone at your company must sign an annual affirmation as the Affirming Official, the senior representative with the authority to state that the company is still meeting the requirements. The affirmation gets filed in SPRS, the federal contractor scoring system, and it has to be renewed every year. It isn’t a form IT fills out. It’s a promise your company is making to the federal government.
[UPDATED July 14, 2026]Phase 1 — self-assessment against Level 1 or Level 2 — is in effect, and every contractor handling FCI (Federal Contract Information) or CUI is still on the hook for protecting it under DFARS 252.204-7012. Phase 2, which would have added a required third-party certification starting in November 2026, was suspended by the Department of Defense on July 13, 2026. A 60-day review of the program is underway, with options reportedly ranging from a scaled-back certification requirement to dropping it. For now, the self-assessment and the annual affirmation are required, while the outside audit is on hold.
If you want the control-by-control version of what NIST 800-171 requires, we’ve written the plain-English version of that.
Why CMMC defaults to your IT person, and where that goes wrong
Most people start with the same assumption: CMMC is a computer thing, so that’s IT’s job. Reasonable first guess, and plenty of the work is IT work. But that arrangement is where I hear the most complaints, and the reason has almost nothing to do with technical skill.
Your IT person does real, necessary work. They’ll configure systems, manage access, and handle a good chunk of the 110 practices Level 2 asks for.
But owning the program is a different job. It means setting company policy and coordinating people who have nothing to do with computers — the shop floor, contracts, HR, anyone who touches a federal contract. Under a deadline, someone still has to decide what’s in scope and what isn’t. And somebody has to sign that annual affirmation personally, putting a name, not a department, on the line.
No matter how capable your IT person is, none of that falls within their role or authority. When the IT person is in charge, what they tell me is that it’s above their pay grade to make some of these changes to how things operate in the company. Compliance work reaches into onboarding, physical security, who can take what home — decisions an IT manager usually isn’t authorized to make on their own.
So, technicians will work around it. Rather than improve the systems the company already runs on, they build a walled-off enclave alongside it — a separate setup for the people who touch federal work. That’s a classic move when someone has responsibility without authorization. The catch is that most of what the compliance program asks for would make perfect sense in the commercial setup too — if anyone were allowed to have that conversation.
What the assessor hears when IT answers the questions
Another drawback of putting CMMC compliance solely onto the IT team is that during an assessment, the assessor talks to both sides — the people who own the information and the people who own the IT systems. IT people sometimes make their descriptions more complicated than they need to be, and that opens up more questions than the assessment needs. In my experience, the best setup is a non-IT person as the point of contact with someone from quality or HR on the team — people who know the processes and can answer for them.
How much of CMMC is really IT work?
39of 110 controls aren’t a setting your IT provider can flip
What makes a CMMC program work, whoever owns it
I have watched programs succeed under a project manager, a quality lead, a federal program lead, and yes, occasionally an IT manager. A successful program needs three things: executive buy-in, one person who can make a decision quickly, and people who can build the thing.
Executive buy-in, because compliance changes how the company runs
Compliance work forces real structural changes, and without leadership behind those changes, programs go sideways. Part of the problem is how my own industry frames this. We treat operations as one thing and compliance as another. What you want is compliant operations — one set of systems that happens to meet the standard. Buy-in also has to be visible. If you’re the executive, say out loud and in front of people that this person can make these calls — otherwise you’ve delegated the task without the authority to do it.
Somebody has to bring the executive team a clear analysis of what each option for reaching compliance costs. I recently had a meeting with a 150-person company that illustrates what can happen if nobody does. The company has 130 computer users, and they’re considering a walled-off enclave for 50 of them.
That’s nearly 40% of the people who use a computer there, each of them working across two setups, onboarded twice, with two places to look for a file. They’d also be migrating off their on-premises servers into the new enclave at the same time. An enclave makes sense when federal work sits with a small group that’s already separate from the rest of the company. At 50 out of 130, that’s too large for an enclave. Crunch the numbers and I think you’re usually better off putting everybody in one setup.
Nobody has run those numbers. The decision never reached the people who could weigh it against the cost of running the business.
Somebody who can get a decision made quickly
If an owner is delegating this to someone, the process will involve structural changes, so the two of them need open communication and quick decisions. Without that, the person in charge can’t get a yes or a no on changing the status quo, and you get the workaround described above.
People who can build it
I’ve been in a surprising number of compliance meetings attended mostly by paper pushers. You can’t just have the project manager, the quality control person, and the CFO show up. Roughly 70% of CMMC is technical controls. A compliance person can be in charge, but that person needs doers. If you’re an IT organization and it’s just the help desk showing up, that’s a red flag too. Where’s the engineer who’s ready to build it out? That person probably shouldn’t own the program — they’ll be busy building, and they run into the same wall as the IT manager does the moment the work touches how the rest of the company operates. But somebody has to turn the screws.
The seats that tend to have the authority
A handful of roles come up again and again, and any of them can work as long as the three things above are in place.
A project manager is often a strong fit, not because they know security, but because their whole job is surfacing blockers and keeping things moving. Some companies keep floating project managers who aren’t tied to one job.
Quality, compliance, and HR roles also come up often, and usually together. Quality and compliance have training requirements for employees, documentation for processes, background checks and physical security, and those are all major parts of the program. A shop that already runs ISO 9001 or AS9100 often has exactly this kind of person already in place.
If a company does both commercial and government work, I’ve also seen ownership fall to whoever leads the federal side of the business — a natural fit, since that person is already accountable for the government relationship.
If you have both, think about phase. A project manager is the better fit for getting the program running the first time. A quality manager is the better fit for keeping it running afterward — training records, documentation, the audit cycle — and for facing an assessor.
What if the answer is you?
The smallest shops have no quality manager, project manager, or IT department to hand this to. You’re the business owner and you own the CMMC compliance program.
You don’t have to become a cybersecurity expert. You do have to stay on top of scope and keep people moving toward deadlines. When the time comes, you’re the one who signs the affirmation. The technical work — configuring systems and closing gaps day to day — gets handed to a Registered Practitioner Organization (RPO) or managed IT services provider authorized to do that work.
Every owner is different, so my honest advice is know thyself. Stay involved in the initial scoping and in any decision that changes how the whole company operates. The enclave question is the one to watch: do you put everybody in one setup, or split the team off and run onboarding twice? That’s your call, not your IT provider’s. The good news is that the government has done a fair bit of the work, spelling out what the end result should look like. There’s a blueprint, so you don’t have to weigh in on every step to get there. Be the one in the room for the big-picture decisions, then delegate the rest.
How your internal owner works with an outside RPO or MSP
The internal owner — whether you or someone else — doesn’t do everything themselves. They coordinate and decide, and they’re the one accountable when something’s missed. An outside RPO or MSP handles the technical build and the compliance guidance that goes with it.
The clearest way to split that work is a shared responsibility matrix. This document spells out, line by line, who’s responsible for what between your company, your outside partner, and any local IT contractor you already use.
How to choose outside help without paying for more than you need
If your answer is “we’ll have to hire someone,” don’t default to the cheapest option or the enterprise-scale assessment a prime contractor recommends. A 30-person shop almost never needs what a prime needs. Start small and use the technology you’re already paying for — most companies have Microsoft features they’ve never switched on, and that’s the cheapest ground you’ll ever cover.
Watch the licensing conversation in particular. Vendors will offer to save you a few dollars per user by dropping to a cheaper tier, and my question is always: at what cost, with staffing? Those savings tend to come back as hours somebody has to work.
Make sure whoever you hire is sized to a business your size. If you want a realistic sense of the timeline before you start shopping, see our article on how long CMMC compliance can take.
How ownership works, month to month
Once the program is running, ownership settles into a rhythm.
Every month, check in with your outside partner on what’s done and what’s stuck, and work the open items on your plan of action.
Every quarter, review scope. This is where you settle what’s genuinely in scope versus what someone wants to add “just in case,” and sign off on new policies before they go out to the rest of the company.
Every year, file the affirmation in SPRS and confirm your training records are current. Read it closely before signing — don’t rubber-stamp it. You’re the Affirming Official, and you’re telling the federal government that what’s in there is true.
Frequently asked questions
Is CMMC an IT project?
Partly. Around 70% of the Level 2 controls are technical, so you need engineers who can build. But owning the program means setting policy and coordinating people across the whole business and personally signing the annual affirmation — none of which sits inside IT’s authority.
Can the business owner be the CMMC program owner?
Yes, and in shops under about 50 people it’s often the only realistic option. The owner keeps people moving and signs off personally, while the technical build gets handed to an outside partner.
Can we hire someone outside the company to own our CMMC program?
You can hire out the technical build and most of the compliance guidance. You can’t hire out the affirmation. The rule requires your Affirming Official to be a senior representative from inside your own organization, so somebody on your payroll signs no matter who does the work.
Does the Phase 2 suspension change who should own this?
No. Phase 1 self-assessments and the annual affirmation are still required, and the affirmation still needs a senior signature. The suspension moved the deadline for third-party assessment. It didn’t move who’s accountable inside your company.
Where to go from here
Pick a name. Don’t leave this role vacant while you sort out the rest of it — an unowned program is how these things stall for months over questions nobody has the authority to answer.
If you already know who it should be, the next step is figuring out what falls on them and what doesn’t. If you’re still not sure, settle that before you spend money on anything else.
FREE CMMC CONSULTATION
Who owns this, and what falls on them?

A short call with me can tell you what stays on your internal owner’s plate and what an outside partner should handle.
CMMC RESOURCES
If you need CMMC managed IT services
- Virginia CMMC Managed IT Services
- Best CMMC managed IT services providers in the DMV
- Best Virginia CMMC managed IT services providers
If you need to better understand CMMC requirements:
- The Ultimate Guide to CMMC
- The Ultimate Guide to DFARS and NIST 800-171 (in plain English)
- What is FCI and should I worry about it?
- What is CUI and should I worry about it?
- CMMC compliance deadlines: Key dates and what they mean
If you’re looking for CMMC tools and training:
- We found the best GRC tool for CMMC
- What is Microsoft GCC High and do I need it?
- Best CMMC training resources
- CMMC Level 1 guide as audio book
- CMMC Level 2 guide as audio book
- CUI enclaves in CMMC compliance: Are they right for your business?
If you’re looking for a CMMC consultant or Registered Practitioner Organization:
- Best CMMC consultants
- Best CMMC RPOs near Washington, DC
- Best Virginia Registered Practitioner Organizations
- Case Study: Virginia Government Contractor Nears CMMC Compliance
- CMMC Gap Analysis
If you’re looking for a CMMC assessor:
If you’re looking for information about CMMC that is targeted toward smaller businesses:

Industries
Locations
Waynesboro, VA
Corporate HQ
215 Fifth St.
Waynesboro, VA 22980
Sales: 540-217-6261
Service: 540-885-3129
Accounting: 540-217-6260
Fax: 703-935-2665
Washington D.C.
1126 11th ST. NW
Suite 603
Washington, DC 20001-4366
Sales: 202-888-2770
Service: 866-692-9082
VA DCJS # 11-6604
Locations
Harrisonburg, VA
45 Newman Ave.
Harrisonburg, VA 22801
Sales: 540-569-3465
Service: 866-692-9082
Richmond, VA
3026A W. Cary St.
Richmond, VA 23221
Sales: 804-729-8835
Service: 866-692-9082
