Summary
Jacob and Jason reviewed the latest CMMC Level 2 certification numbers, arguing that the ecosystem has more than enough assessment capacity and that contractor readiness—not assessor availability—is the primary bottleneck. They contended that organizations’ failure to fully implement DFARS 252.204-7012 requirements, rather than a shortage of C3PAOs, is limiting the pace of certifications.
Key Takeaways
- CMMC Level 2 certifications reached 1,717, with 279 new certifications in June—the largest monthly increase since the phased rollout began.
- Assessment capacity is not the bottleneck. Based on conservative assumptions, the hosts estimate the ecosystem could have supported significantly more assessments each month.
- Contractor readiness is the limiting factor. Organizations that haven’t fully implemented DFARS 252.204-7012 requirements aren’t ready to enter assessments.
- Assessment capacity continues to grow faster than demand, with certified assessors and assessment teams increasing alongside certification output.
- The hosts argue the phased rollout is working as intended, encouraging organizations to focus on implementation readiness rather than blaming a lack of assessors.
Another 279 companies achieved CMMC Level 2 certification in June 2026, bringing the total to 1,717 certified organizations.
That’s a record month and far ahead of DoD’s original projections. But the data also shows something surprising: the industry still isn’t using all of its available assessment capacity.
In this episode, we break down the latest Cyber AB numbers, explain our assessment capacity methodology, and discuss why contractor readiness, not assessor availability, remains the biggest constraint on CMMC adoption.
Transcript
[00:00] — Jacob
All right, folks. It is July 2026, and another 279 companies achieved CMMC Level 2 certification last month.
That’s the single largest increase since the phased rollout began in November 2025 and brings the total to 1,717 Level 2 certifications.
But that number could have been much larger.
Conservatively, we should have more than 2,900 Level 2 certifications by now—not 1,700.
Contrary to popular belief, there is no shortage of assessors.
The problem is contractor readiness, not assessment capacity.
That’s what we’re going to talk about today.
[00:51] — Jacob
Jason, after eight months of the phased rollout, 1,717 companies have achieved CMMC Level 2 certification.
That’s incredible.
It’s about 1,200 more certifications than the DoD expected during the first year of the rollout.
It’s a huge accomplishment.
At the same time, I can’t help wondering how much higher that number would be if we fully utilized the assessors already available.
[01:27] — Jason
We did some “fuzzy math” about a month and a half ago.
We assumed half the assessors weren’t available, then cut the numbers down even further.
At first we thought it was just a rough estimate.
Now, month after month, certification output keeps setting records.
We saw roughly 15% growth one month and 20% growth the next.
Whatever needed to happen to get the engine running has happened.
The system is moving.
[02:12] — Jacob
There are really two stories here.
First, far more companies are achieving Level 2 certification than the DoD originally expected.
Second, even more companies could be achieving certification because we’re not using all the available assessment capacity.
Meanwhile, people continue saying there aren’t enough assessors.
That simply isn’t true.
[02:40] — Jason
Market forces are interesting.
Let’s explain the math because we received a lot of feedback on last month’s video.
[02:52] — Jacob
For the eighth consecutive month, overall Level 2 assessment capacity exceeded the number of companies ready for assessment.
Here’s how we estimated capacity.
Each assessment team requires:
- One Certified Assessor (CCA)
- One Lead Certified Assessor (Lead CCA)
We assume each assessment team completes two assessments per month on average after accounting for vacations, scheduling, and other delays.
Every assessment also requires a separate assessor to perform quality assurance.
Based on conversations with multiple C3PAOs, we estimate each QA assessor can review four assessments per month.
Using those assumptions, we divide the total number of certified assessors by 2.5.
As of June 2026:
- 1,013 Certified Assessors
- 596 Lead CCAs
That results in approximately 405 potential assessment teams.
Then we cut that number in half and round down to 202 assessment teams because we know not every certified assessor is actively performing assessments.
Even after reducing the numbers by 50%, we still estimate enough capacity for approximately 405 Level 2 assessments during June.
Instead, only 279 certifications were completed.
The issue wasn’t a shortage of assessors.
[05:18] — Jason
What’s important here is that we intentionally made assumptions that reduced the estimated capacity.
Most people inflate numbers to support their argument.
We did the opposite.
Even after assuming half the assessors aren’t available, the ecosystem still has more capacity than demand.
At 279 certifications, we’re using only a fraction of the available assessment teams.
C3PAOs continue reporting available assessment slots.
That tells us capacity isn’t fully utilized.
[06:44] — Jacob
Let’s look at the broader picture.
Using this conservative 50% model, between November 2025 and June 2026, the ecosystem had enough capacity to complete roughly 2,487 Level 2 assessments.
Instead, only 1,265 certifications were added.
That’s about 1,222 fewer certifications than the available assessment capacity could have supported.
Again, assessment capacity isn’t the bottleneck.
It hasn’t been since November.
[07:36] — Jason
I think it comes down to two things.
Either organizations don’t know where to find available C3PAOs, or they know where they are but aren’t ready for what the assessment will reveal.
[07:58] — Jacob
That’s exactly it.
The challenge isn’t CMMC itself.
The challenge is whether companies have actually complied with DFARS 252.204-7012, which is what CMMC is validating.
The program is working as intended.
More companies are becoming certified every month.
Assessment capacity has exceeded demand throughout the rollout.
The number of assessors continues growing faster than organizations are ready to use them.
[08:42] — Jason
That’s another part of the conversation people overlook.
Implementation professionals and assessors continue entering the ecosystem at record rates.
Assessment output keeps breaking records as well.
[09:06] — Jacob
If organizations had already implemented NIST SP 800-171 to satisfy their existing DoD contractual obligations, they could have scheduled assessments any time since November.
That hasn’t happened because many organizations still aren’t compliant with DFARS 252.204-7012.
Share this episode with anyone who says assessment capacity is the problem.
The Cyber AB publishes these numbers every month.
We’ll continue reviewing them every month until people stop claiming there’s an assessor shortage.
If you disagree with our methodology, let us know.
Should we refine the assumptions?
Personally, I think cutting available assessment teams in half is already extremely conservative.
One thing is clear:
We’re not fully utilizing the assessors that already exist, and we haven’t been.
[09:59] — Jason
I agree.
[10:00] — Jacob
Thanks, everybody.
We’ll see you next week.
Contact
Speak With Our Team
Our team of compliance and cybersecurity experts are on standby and ready to help. We’ll walk you through what you need and what to expect.
