CMMC is an industry game changer for the 300,000 Defense Industrial Base organizations. CMMC implementation will have more impact on industry then PCI, SOX, and ISO 9000 combined with the goal of stopping the $600 Billion annual of exfiltrated by foreign nation adversaries and criminal originations.
This impact is a result of the DOD is taking direct action to stop the information loss by introducing CMMC and requiring a pre-award audit and certification prior to award. Most small and medium sized business estimated at 285,000 are not prepared to meet the audit requirements and will need specific guidance and solutions that meet requirements and position them to grow their information protection maturity as the criminals increase attacks on the Defense supply chain.
Microsoft is in an optimal position to provide small and medium sized business with information protection solutions across its government cloud services. The challenge will be for these DIB to find advisors to assist them in their compliance journey and select and implement the correct solutions that are cost affective and support their business operations. If Microsoft can develop short term solutions targeted at small and medium DIB that are cost effective and easy to adopt, the long term opportunity is significant.