Our small IT department recently completed CMMC Level 2 certification after nearly two years of implementing controls, writing policies, collecting evidence, coordinating with other departments, and preparing for assessments—all while handling normal IT operations. I'm proud of what we accomplished, but maintaining compliance now feels like it takes roughly 80% of my time.
I'm constantly reviewing documentation, refreshing evidence, tracking requirements, answering questions, coordinating reviews, and following up with people across the company. As a result, important IT initiatives such as infrastructure improvements, security hardening, automation, and new systems keep getting delayed.
IT needs to own the technical controls, but we've also become the default owners of the entire compliance program, including tasks that require accountability from other departments. It feels like I'm doing two jobs without any adjustment to the expectations for my original role.
For smaller organizations handling CMMC or similar requirements, how are you dividing the work? Do you have dedicated compliance staff, use outside assistance, or leave everything with IT? If you convinced leadership to fund a compliance role, what evidence or arguments made the workload clear?
5 Answers
This is a common problem for small shops. Some organizations push through the initial assessment with an already-overloaded IT team, only to discover that maintaining the program is a permanent operational workload. Tools can make documentation and evidence management less painful, and consultants can fill expertise gaps, but neither solves the ownership problem by itself. Someone needs clear responsibility for coordinating the whole program while IT remains accountable for the technical work.
A dedicated compliance function makes a huge difference. One organization described putting together a small team of three or four people to own the program, which allowed IT to focus on the technical controls instead of coordinating every policy review and evidence request. Even if a full team isn’t realistic, assigning one person primary ownership—with authority to get responses from other departments—is better than making IT absorb all of it.
The ongoing workload is easy to underestimate. Certification is only the beginning: evidence has to be refreshed, controls monitored, findings closed, affirmations maintained, and processes followed consistently. Smaller companies often need outside compliance assistance or a governance platform to organize the documentation and recurring tasks. Automation can also help with technical hardening and evidence collection, but it won’t replace assigning people to own the business processes.
Be careful—successfully carrying both responsibilities for two years may have convinced leadership that the arrangement is sustainable. Put together a concrete case before your next one-on-one: track your compliance hours for a couple of weeks and list the IT projects, deadlines, and improvements that were delayed. Separate technical implementation from the administrative work of chasing owners, scheduling reviews, maintaining documents, and assembling evidence. Then ask leadership to decide what gets funded and which IT priorities move if compliance remains your responsibility.
Put an actual number on the work rather than presenting it as a general feeling. Track hours spent each quarter on evidence refreshes, control reviews, POA&M work, assessments, documentation, and coordination across the roughly 110 requirements. Show the cost of delayed IT projects and compare it with the cost of a compliance hire or external provider. Leadership is more likely to act when the request is tied to capacity, deadlines, and business risk.

That’s exactly what I’m worried about. We finished certification recently, and it has still been nonstop. I’m planning to make this a major topic in my next meeting with my manager.