Our IT department spent two years getting the company through CMMC Level 2 certification. We implemented controls, wrote policies and procedures, gathered evidence, coordinated with other departments, prepared for assessments, and kept normal IT operations running at the same time. I'm proud that we finished, but maintaining compliance has been even more demanding than expected.
At this point, roughly 80% of my time goes toward reviewing documentation, refreshing evidence, tracking requirements, answering questions, coordinating reviews, and following up with people across the company. There is always something to update, verify, or document. That leaves very little time for infrastructure improvements, security hardening, automation, new systems, or other projects that would improve the IT environment.
IT should own the technical controls and support the program, but we have also become the default owners of compliance coordination and accountability for other departments. It feels like I'm doing two jobs while the expectations for my original role have not changed.
For smaller organizations dealing with CMMC or similar requirements, how are you handling the ongoing workload? Do you have dedicated compliance staff, use outside assistance, or leave everything with IT? If you successfully convinced leadership to add resources, what evidence helped them understand the actual effort involved?
4 Answers
Be careful not to confuse an assessment pause or a change in third-party review requirements with the compliance obligation disappearing. The underlying controls, documentation, and ongoing accountability still matter. Smaller shops that simply claim everything is in place without doing the work are taking a serious business and contractual risk. If leadership wants the certification, they need to fund the recurring labor instead of treating the assessment as the finish line.
We went through the same realization after certification. A small compliance team of three or four people now owns the program, while IT handles the technical controls and provides support. It has made a huge difference because evidence refreshes, policy maintenance, and cross-department follow-up no longer compete with every infrastructure project. Even one dedicated program manager would probably remove a lot of the burden.
The biggest challenge is that leadership may interpret two years of success as proof that the existing team can keep doing both jobs. Before your next one-on-one, track a couple of weeks of compliance work and list the IT projects that were delayed. Break it down into technical implementation versus coordination, evidence collection, document maintenance, scheduling, and chasing owners. Concrete hours and displaced deliverables are much harder to dismiss than saying compliance takes most of your time.
Also ask leadership to decide which IT priorities move if compliance remains your responsibility. The company needs a named compliance owner with enough authority to get information and action from other departments; otherwise the same workload simply gets renamed.
A lot of smaller organizations underestimate the maintenance effort. Certification is not a one-time project; recurring evidence collection, assessments, plan-of-action tracking, affirmations, and process reviews continue afterward. If you cannot add a full-time employee, an external compliance consultant or managed service can handle much of the coordination and provide structure. Automation and compliance tooling can also reduce repetitive evidence work, but tools do not replace someone who owns the process.
That was our experience too. Better tooling helped organize evidence and recurring tasks, but we still needed a clearly assigned owner to keep departments responding and make sure the documentation matched what people actually did.

That’s exactly what I’m planning to bring up. I want to separate the technical work from all the coordination and follow-up so the scope is clear instead of just describing it as an overwhelming feeling.