A project has a finish line. It has a final deliverable, a closing meeting, and a team that gets released to work on something else. A program has none of that. A program has a Watch Bill, a Logbook, and a relief who shows up on schedule to take the next shift.
That distinction sounds academic until the recertification clock starts running. Here is what it actually costs a contractor who gets it wrong. An organization builds CMMC compliance as a project. They pass their assessment, close the binder, and move on to the next thing on the list, because that is what you do when a project ends.
Three years later, the assessor comes back, and the trouble starts. There is no one left who remembers why a control was built a certain way. There is no Logbook showing it was maintained since, and no evidence the System Security Plan still matches what is actually running in production. So they rebuild the entire program from scratch, at full cost, under a deadline, while whatever staff happens to still be around tries to explain decisions nobody ever wrote down.
Organizations that build CMMC compliance as a program live a different story. They recertify at roughly half the marginal cost, because the record was never lost, only maintained. They absorb regulatory changes without panic, because someone was already watching for them. They answer a prime contractor’s SPRS questionnaire inside an afternoon, because the answer was logged the day it happened, not reconstructed from memory three years later.
A Watch Bill is not a metaphor for a schedule. It is the schedule: who owns which control, who reviews it, and when. A Logbook is not a metaphor for documentation, either. It is the record proving the Watch Bill was actually followed, day after day. Contractors who skip either one are not running a leaner program. They are running no program at all, and the assessor will eventually find out which one it was.
Why this is not a technology problem
Most of the contractors we work with in the Defense Industrial Base (DIB) already have reasonable security requirements in place: cloud security, endpoint security, antivirus software, some version of access management. The controls in NIST SP 800-171, published by the National Institute of Standards and Technology (NIST), are designed to protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). They were never designed to run a security and compliance program.
So if the technology is usually already there, why do contractors still fail recertification? Because passing an assessment measures more than whether a technology existed on one specific day. It measures whether anyone kept watching after the assessor packed up and left the building. What breaks down is not the tooling. What breaks down is the watch.
A watch is continuous. A watch is assigned. A watch is logged. A watch has reliefs, and a watch has drills. A project has none of those things, because a project was never designed to have them. A project is designed to end. That is the whole point of running something as a project: define the scope, hit the milestones, declare victory, and disband the team.
Try applying that structure to cybersecurity, where the threat does not pause to check whether you passed an audit before it shows up. You get what we see across the DIB, over and over: a gap after certification where nobody owns incident response, nobody reviews the access management logs, and nobody is positioned to catch a social engineering attempt or stop ransomware attacks before they succeed. The controls were real. No one was standing the watch.
What the Program-Not-a-Project Rule actually covers
CMMC touches every one of the types of cybersecurity work a contractor runs: supply chain risk, endpoint protection, cloud security, incident response, access management. None of those domains has a natural stopping point, and that is the part most contractors miss.
A supply chain does not stop being a supply chain the day after certification. A ransomware threat does not check your CMMC Level before deciding whether your network is worth attacking. Regulatory guidance does not freeze in place because a contractor already has a certificate on file, and the 320 assessment objectives in NIST SP 800-171A do not get easier to satisfy just because you satisfied them once, eighteen months ago, under different staff and a different threat landscape.
That distinction, between what CMMC actually requires and what most contractors assume it requires, is worth its own conversation. It is why we anchor a program to the 320, not the 110.
A Program keeps the Watch Bill current. A Program keeps the Logbook written, week after week, not reconstructed the week before an assessment. A Program keeps sensitive data and sensitive information inventoried, not guessed at from memory. A Program keeps access management reviewed on a schedule, not whenever someone happens to remember.
This is the gap we see most often in mid-size DIB contractors working toward CMMC Level 2: the security requirements are mostly in place, the technology mostly works, and the program still fails, because nobody built a Watch Bill for what happens after the assessor leaves the room.
Why most CMMC budgets are upside down
Picture a typical budget conversation. Ninety percent of the spend goes to technology. Ten percent goes to operations, process, and the documentation needed for assessments. That program is inverted before it ever gets tested, and it will fail the next assessment the same way it may have barely scraped by on the last one, not because the technology was missing, but because there is no Logbook proving it was maintained in between.
We call this the 70% Logbook principle, and it exists for a simple reason: the assessor is not grading your intentions. The assessor is grading your evidence. This is also why we built Program Sustainment as its own service line, separate from the initial assessment work. A Watch Bill that nobody keeps current is not a Watch Bill. It is a document that used to be true.
Some of our clients call this the workout-buddy model, and the comparison holds up better than it sounds. You do not go to the gym once and stay in shape for three years. You do the reps, on a schedule, with someone checking that you actually showed up. Contractors who treat sustainment as an afterthought are, without meaning to, rebuilding the project model one budget cycle at a time. They pass the audit, they stop watching, and they act surprised when the rebuild bill comes due.
A note on what this doesn’t mean
None of this means throwing more money at technology, hiring more people, or buying a more expensive audit. We are bad salesmen and good consultants. The two go together. It means treating the Watch Bill and the Logbook as load-bearing parts of the business, the same way payroll or insurance are load-bearing, instead of treating them as paperwork left over from the last assessment cycle.
We are painfully aware of how that sounds coming from a firm that gets paid to help run the watch. We have read the rule the same way you would, looking for the catch, and found none that lets us off easy either. The argument holds regardless of who is making it, because the assessor does not care who built the Watch Bill. The assessor cares whether it is current.
The takeaway for contractors
We do not build a project for our clients and hand them a certificate. We build a program and hand them a Watch Bill. That is not a marketing claim. It is the difference between passing an assessment once and passing every assessment for the life of the contract, at a fraction of the cost and none of the panic.
If you want the plain-English version of what CMMC actually requires, or a straight definition of Controlled Unclassified Information without the acronym soup, those are the next two questions worth answering, and we have already written both of them down.
We stand the watch for you. Come stand it with us. The first conversation is free.
CMMC is a program, not a project. The watch never ends.