← All Articles
Organizational

The Executive Burden: What I Learned as an Affirming Official for a Woman-Owned Small Business

What signing the annual affirmation actually demands of an executive, from one who signed through a DIBCAC assessment.

KE
Kate Ehrle
August 5, 2026
7 min read

As affirming officials navigating the implementation of the Cybersecurity Maturity Model Certification (CMMC), we share a unique and high-stakes burden. The days of treating cybersecurity as a back-room IT issue are officially over. For small and mid-sized defense contractors, taking on this mantle means balancing the strict, unyielding demands of federal compliance with the agile, resource-conscious reality of running a growing business.

When I signed as the affirming official for a woman-owned small business (WOSB) undergoing an assessment by the Department of Defense's own assessors at DIBCAC, I quickly realized that compliance in the Defense Industrial Base (DIB) is no longer a check-the-box exercise. It is a core boardroom liability that requires active corporate governance.

Dismantling the "Rubber Stamp" Culture

For years, the DIB operated under a system of self-attestation that was highly vulnerable to "rubber-stamping." Executive leaders often delegated cybersecurity entirely to an internal IT manager or an outsourced provider, signed the necessary paperwork, and assumed everything was handled.

The finalized framework completely dismantles that approach. Under 32 CFR Part 170, the affirming official must be a senior executive or designated leader within the organization who possesses the authority to represent the corporation legally. This role cannot be outsourced to a Managed Service Provider (MSP).

When we submit our compliance scores to the Department of Defense (DoD) Supplier Performance Risk System (SPRS), our signatures mean we personally verify that our System Security Plan (SSP) is an accurate, honest reflection of reality. In a smaller enterprise, where the distance between leadership and day-to-day operations is incredibly narrow, this responsibility hits differently. You know your team personally. You know exactly what it takes to win a contract, and you know that an inaccurate assessment carries the massive legal weight of the False Claims Act (FCA). The Department of Justice has made it clear that they will hold corporations, and potentially individual executives, accountable for knowingly misrepresenting their cybersecurity posture.

That obligation did not pause when the DoD suspended the CMMC Phase II third-party assessment requirements in mid-2026.

The assessment gate moved; the signature did not. SPRS self-assessments, annual affirmations, DFARS 252.204-7012, and FCA exposure all remain fully in effect.

The June 2026 LOGZONE settlement was built on exactly this gap: an attested SPRS score of 110 against an actual posture assessed at negative 170. Self-assessment scores are legal records, and the government treats them that way.

Operationalizing Active Governance: A Roadmap for Leaders

Navigating this role requires moving away from blind trust and moving toward active, evidence-based governance. Based on my experience leading a WOSB through this journey, here are the core strategies we must adopt as DIB leaders to successfully manage our obligations:

1. Implement a "Trust, But Verify" Framework

Do not accept a green status report or a vague assurance at face value. Before signing your annual re-attestation, ask your internal teams or MSPs for tangible evidence. Demand to see the audit logs, review the written policy documents, and look at the configuration screenshots. If a control is marked as implemented, ask to see the proof.

2. Separate Implementation from Validation

Your daily IT operations might be handled brilliantly by an MSP, but implementation and validation are two different jobs, and the people who built your system should not be the only ones vouching for it. Whoever validates your posture, whether a qualified third party or an internal function with genuine separation from the implementers, must understand the exact nuances of NIST SP 800-171. An objective gap analysis against that standard tells you whether your documentation holds up under scrutiny before you sign, not after.

3. Bridge the Language Gap

Challenge your security teams to translate technical jargon into business and operational risk. If your IT team tells you they have implemented a secure enclave, make them explain exactly how Controlled Unclassified Information (CUI) flows through your company, who has access to it, and how it is isolated. If you do not understand how a control is implemented, you cannot confidently affirm its validity to the government.

4. Own the Resource Allocation

Compliance fails when IT and security teams are underfunded, understaffed, or starved for time. As affirming officials, we must ensure our organizations provide the budget and personnel necessary to maintain these controls continuously. CMMC compliance is not a point-in-time event; it is an ongoing operational cost. We have to resource it as such.

5. Establish a Dynamic System Security Plan (SSP)

Your SSP is a living document, not a static binder on a shelf. Ensure your team updates it every time your operational environment changes, whether you hire new staff, adopt new software, or shift to a hybrid work model. An outdated SSP is an inaccurate SSP, which creates immediate liability during an annual re-attestation.

Turning Compliance into a Competitive Advantage

Large defense primes have entire departments dedicated exclusively to compliance, legal, and risk management. Small and mid-sized contractors must be far more strategic with their resources.

Standing behind our security posture isn't just about avoiding penalties or dodging lawsuits. It is about proving to prime contractors and federal program managers that an agile, diverse business can deliver the exact same cybersecurity maturity as an aerospace giant. When a prime contractor looks to award a subcontract, a mid-sized DIB company with a fully verified, audit-ready CMMC posture becomes the lowest-risk, highest-value choice.

Serving as an affirming official is a demanding, high-pressure commitment. However, by taking hands-on ownership of the CMMC journey and insisting on independent validation of our progress, we do more than just protect our federal contracts. We fortify our companies' futures, protect the integrity of the defense supply chain, and contribute directly to national security.

Want to know where your organization stands?

Take our 3-minute Readiness Check and get an instant gap summary based on your environment.

Start Readiness Check →

An independent firm focused exclusively on CMMC compliance for defense contractors and the DIB.

Fredericksburg, VA