Navigating CMMC Compliance: A Small Business Owner’s Journey
When I first set out to document my experience with the Cybersecurity Maturity Model Certification (CMMC), I wasn’t even sure if our company would go through with it. The uncertainty made me pause, and for a while, I stepped away from writing about it. However, in November, we secured a significant military contract, which solidified my decision to commit to the defense industrial base. Looking ahead at my company’s long-term trajectory, I knew that pursuing CMMC certification was an investment worth making. It wasn’t just about compliance—it was about future-proofing my business and securing future bids.
The truth is, the process was chaotic at first. I had no idea where to start or what it would take to get certified. Now, after working closely with experts, I’ve dived into the details, making necessary changes to ensure compliance. As a small business owner, I wear many hats—CEO, president, marketing, HR, IT, and anything else that needs to be done that day. It’s a challenging balancing act, but given my company’s current sales levels, hiring a full staff for each role simply isn’t feasible.
Embracing Change & Delegation
The first major realization I had was that my company of 16 employees was going to undergo a significant transformation. To stay on top of the compliance process, I needed to delegate tasks more efficiently. Hiring an office manager was a game-changer. I handed off accounting and invoicing to her, and more recently, she has taken on many HR responsibilities. With two open positions, hiring had become overwhelming, and her support made a big difference.
Beyond HR and accounting, I also put her in charge of a newly formed Culture Committee. I recognized that while I was buried in compliance work, I would neglect the softer aspects of company culture—like team gatherings and events. This year, our third annual chili cook-off was fully organized by the committee, and it went off without a hitch. Normally, I would have been the one coordinating the event, but this time, I was hands-off, and the team did an amazing job. Keeping workplace culture alive amidst compliance changes is crucial, and I plan to continue relying on this committee moving forward.
Transparent Communication with My Team
As I navigated policy changes, I made it a priority to keep my employees informed—not just for transparency, but also for compliance. Under CMMC, documenting and distributing policies while ensuring employee acknowledgment is critical. To streamline this process, I instituted a weekly company-wide meeting every Tuesday at 9 AM. In just 15 minutes, I provide updates on key projects, policy changes, and high-level company developments. These meetings help my employees understand what I’m working on and give them a broader view of the company’s direction.
In addition to the company-wide meetings, I also meet weekly with my Managed Service Provider (MSP), as we form the core of our information security team. These discussions have been invaluable in understanding the compliance requirements and security risks my business faces. It’s been eye-opening to realize just how vulnerable my company was—from external threats like foreign cyber-attacks to internal risks from employees, vendors, and even USB devices. The sheer number of cybersecurity considerations is overwhelming, but I’m hopeful that the investment will be worth it in the long run.
Investing in a New ERP System
Another major shift we undertook was the implementation of a new Enterprise Resource Planning (ERP) system—Epicor. Our previous ERP system was a good first step in transitioning from paper-based processes, but as our business grew, its limitations became obvious. It lacked a “parts directory”, failed to track revisions properly, and didn’t incorporate ISO 9001:2015 quality factors like non-conformances and RMAs. Initially, I wasn’t looking for a new system, but CMMC compliance made it necessary.
The ERP transition is a massive investment for a small company, and while I hadn’t planned on making this move so soon, I realized that getting it done now would set us up or long-term success. The restructuring required for implementation has been intense, and I expect this year to be a tough one, but my hope is that once we get through this, our company will be stronger, more mature, and better positioned for growth.
Looking Ahead
The journey to CMMC compliance is far from over, but I’m committed to sharing my experiences along the way. From policy overhauls to cybersecurity enhancements and major infrastructure investments, this process is reshaping my company in ways I never anticipated. It’s a daunting and expensive endeavor, but I believe it will pay off in the long run.
For fellow small business owners considering CMMC certification, my advice is this: embrace change, delegate where you can, communicate openly with your team, and be prepared for unexpected challenges. Stay tuned as I continue to document this journey—hopefully, my experiences can help others navigate this complex but important path to compliance.
-Nicole
