top of page

We've Seen This Movie Before: What Sarbanes-Oxley Tells Us About the CMMC Pause

  • Jul 27
  • 4 min read

Terrence McGraw Chief Executive Officer @ Cape Endeavors Inc | CMMC Compliance Experts | CMMC L2/3 Compliant Enclaves | CUI Scanning | Security Operations | Incident Response | vCISO consulting


In 2004, serious people were certain Sarbanes-Oxley would destroy American capital markets.


The objections to Section 404 went like this: compliance costs came in far above the original estimates, there weren't enough qualified auditors to meet demand, the burden fell hardest on small filers, and companies would go private or list overseas rather than comply. Contemporary analyses from the Government Accountability Office and SEC staff studies documented these exact pressures on smaller public companies in the first years of implementation.


Now read the Department of War's July 13 memo suspending CMMC Phase II. The stated reasons are prohibitive compliance costs, severe shortages of C3PAO assessment capacity, and small businesses opting out of defense work rather than certify. The memo, signed by DoW Chief Information Officer Kirsten Davies (publication case 26-P-1023), suspends the November 2026 transition to Phase II third-party assessments and freezes pending and future milestones pending a 60-day review by a newly established CMMC Reform Task Force.


Same four arguments. Twenty-two years apart.


That's worth sitting with, because we already know how the first one ended.


Congress didn't repeal SOX. It scaled it.


This is the part everyone forgets.


The relief came in three moves, and not one of them lowered the standard:


2007: The PCAOB scrapped its original audit standard (AS 2) and replaced it with Auditing Standard No. 5, a top-down, risk-based approach. Same requirement, proportionate effort focused on higher-risk areas.


2010: The Dodd-Frank Wall Street Reform and Consumer Protection Act (Section 989G) permanently exempted non-accelerated filers from the external auditor attestation under SOX 404(b). Management's obligation to assess its own internal controls under 404(a) stayed. Small companies still had to do the work and sign their name to it. They just didn't have to buy the audit.


2012: The JOBS Act gave newly public emerging growth companies a five-year on-ramp from certain SOX requirements.


The control baseline survived. The verification got tiered to size and risk. Two decades later, SOX is broadly credited with restoring the trust that Enron and WorldCom destroyed.


That's the template sitting in front of the CMMC Reform Task Force right now. Not repeal. An AS5 moment. The Task Force is charged with delivering recommendations within 60 days on scalable measures that lower barriers for small and non-traditional businesses while protecting federal data.


Why did any of this happen: self-attestations don't work


SOX exists because pre-2002, management asserted its own numbers were fine and investors took it on faith.


CMMC exists for the same reason. Since 2017, DFARS has required defense contractors to implement the 110 controls in NIST SP 800-171 and self-report a score to SPRS. Honor system.

Here's what the honor system produced.


In June 2026, DOJ settled with LOGZONE Inc., a Navy contractor that self-reported a perfect score of 110 in 2021. When the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) assessed them in 2024, the score came back at -170.


A 280-point gap between what a company said about itself and what an assessor found.


That gap is the entire argument for third-party assessment. It is precisely the argument that produced SOX 404(b) auditor attestation. And it doesn't disappear because a certification deadline moved.


Where the analogy breaks


I'd rather say this than have someone say it in the comments.


SOX applied to public companies:, every one of them had a CFO, an audit committee, and access to capital markets. CMMC reaches 12-person machine shops with no IT staff. The burden asymmetry is genuinely worse, and that criticism is legitimate.


And the adversary is different. Financial fraud is an insider choosing to lie. Cyber intrusion is a funded nation-state working against you on purpose. Controls that deter an insider don't automatically stop a PLA unit. "Compliance is not security" bites harder here than it ever did with SOX.


Fair points, both. Neither one is an argument for standing down.


What to do with the next 60 days


Not celebrate. Not coast.


The underlying obligations never left. DFARS 252.204-7012 is in force. Phase I self-assessments and SPRS scores are in force. And enforcement has not slowed for a single day, Raytheon and successor Nightwing paid $8.4 million, MORSE Corp $4.6 million, Georgia Tech Research Corp $875,000, LOGZONE $507,144. In December, a grand jury indicted a former contractor executive individually for misleading federal agencies and obstructing audits.


An inaccurate SPRS score was False Claims Act exposure on July 12. It still is today.


More to the point: NIST SP 800-171 is not a compliance regime with a security veneer. It's a technical best-practice guide with a government wrapper on it. Identity and Privileged Access Management. Least privilege. Asset inventory. Logging. Patching. Backups you have actually restored from. Incident response you have actually rehearsed.


Companies that implement those things are measurably harder to ransom, harder to extort, and harder to steal from whether or not a C3PAO ever walks through the door. The certificate is the receipt. The risk reduction is the product.


SOX ended the era of "trust me, the books are fine."


CMMC ends the era of "trust me, the network is fine."


That 110-versus-negative-170 gap is why.

 
 
 

Recent Posts

See All

Comments


bottom of page