The Pentagon is actively surveying small businesses to assess their readiness for the upcoming Cybersecurity Maturity Model Certification requirements, which will officially become mandatory in contracts starting November 10. The Defense Department’s Office of Small Business Programs aims to understand how these companies are adapting to the new standards, with a pulse survey launched last week to gather insights on their concerns and challenges. As of now, nearly 500 organizations have achieved a level two certification through evaluations by third-party assessment organizations. The Cyber Accreditation Body has trained 567 certified assessors to support the upcoming increase in compliance evaluations for defense contractors. The CMMC program is expected to expand beyond just Department of Defense contractors, potentially influencing other federal agencies and international partners to adopt similar cybersecurity standards, according to Matthew Travis, CEO of the Cyber Accreditation Body.
Small business owners are increasingly facing lawsuits for alleged violations of the Americans with Disabilities Act, with over 12,000 lawsuits filed in 2021 alone, reflecting a nearly 400% increase since 2013. Many entrepreneurs, such as Clay, share their distressing experiences of being targeted without clear compliance guidelines, highlighting a growing concern that these legal actions prioritize settlements over actual accessibility improvements. According to the U.S. Chamber of Commerce Institute for Legal Reform, much of the recent ADA litigation has shifted focus away from enhancing accessibility. The emotional and financial toll on small businesses is significant, as owners often feel pressured to settle lawsuits rather than engage in costly legal battles. Advocacy groups are pushing for legislative reforms that would allow business owners the opportunity to address accessibility issues before facing legal action, promoting a more collaborative approach to compliance.
Why do we care?
The Pentagon’s checking in on small businesses — asking if they’re ready for CMMC. And come November 10, it won’t be optional anymore. Nearly 500 companies are certified already, and hundreds of assessors are trained, so this is happening.
Here’s what’s big: once CMMC hits defense, expect it to ripple across other agencies and maybe even internationally. If you’re an MSP supporting contractors, that’s a compliance wave coming right at you.
And while that’s happening, small businesses are drowning in ADA lawsuits — up 400% in less than a decade — often more about settlements than real accessibility fixes. The explosion in ADA lawsuits highlights another compliance burden small businesses face—this time in accessibility rather than cybersecurity. These dramatic numbers suggest a shift from public-interest enforcement to legal opportunism. The pattern is the same: unclear standards, high costs, and small firms caught in the middle.
The message? Compliance is no longer a checkbox — it’s a business risk. For MSPs, this is the time to own the “compliance-as-a-service” space. Build CMMC readiness packages, tighten your documentation processes, and use ADA chaos as a cautionary example.

