Direct answers
Questions an operator hears before the first conversation.
Straight answers on CMMC timing and cost, the Hidden Factory, SPRS exposure, how a fractional engagement starts, and why there is no rate card. Every figure cites its primary source.
Frequently asked
The questions, answered the way an engineer would want them.
A fractional COO is an embedded operating leader who runs your operations part-time, not an advisor who hands you a report and leaves.
I sit with your direct reports, own outcomes against your numbers, and stay until the system holds on its own. A consultant recommends. An operator runs.
It does not, as of July 2026.
On July 13, 2026 the Department suspended CMMC Phase II, the mandatory third-party certification step originally scheduled for November 10, 2026, and stood up a reform task force. No replacement date has been announced. What remains firmly in place is Phase I, which began November 10, 2025: a Level 2 self-assessment every three years against the 110 NIST SP 800-171 Rev 2 requirements, with annual affirmation into SPRS. The Department was explicit that the suspension does not eliminate the requirement to protect information under DFARS clause 252.204-7012. The certificate paused. The obligation did not.
No.
DFARS 252.204-7012 still requires you to safeguard covered defense information and report incidents, and the Department said so explicitly when it announced the suspension on July 13, 2026. Phase I self-assessment and annual affirmation remain in force, your prime cannot award you covered work without a current assessment posted, and a false affirmation carries False Claims Act exposure today rather than on some future date. The reform task force is aimed at lowering barriers for small, medium, and non-traditional businesses and replacing bureaucratic compliance with scalable, resilient cybersecurity measures. Less paperwork theater, more working security. A shop that built the 110 controls into the daily workflow is ready for whatever the review returns. A shop that was buying a certificate against a deadline is holding a binder.
Most small defense manufacturers spend roughly 100,000 to 200,000 dollars to reach Level 2, per CMMC.com.
The DoD published assessment estimates put a Level 2 self-assessment at 37,000 to 49,000 dollars and a Level 2 C3PAO assessment at 105,000 to 118,000 dollars, before remediation. With Phase 2 suspended as of July 2026, the self-assessment is the live path and the third-party assessment is paused. Either way the money goes into the same 110 controls, so I build them into your workflow and that spend buys a working system instead of a binder.
The Hidden Factory is the undocumented rework, tribal knowledge, and off-the-books problem solving your ERP never records.
Quality pioneer Armand Feigenbaum estimated this loss can reach 40 percent of total company effort. The 30-Day Operational Triage exists to find it and convert it back into capacity and cash.
Every engagement is scoped to the specific constraint, so a rate card would price the wrong thing.
The 30-Day Triage is fixed-price against a defined deliverable, the fractional COO work is a retainer, and a strategic consult is a paid time-boxed session. We agree the scope and the number in the strategic conversation, before any work begins.
I work in ITAR, DFARS, CMMC 2.0, AS9100, and CUI handling directly, as part of the operating system rather than as a separate workstream.
Where a CMMC IT partner is the right tool for a specific control, I bring one in and run them as one input into the system I architect. The operations layer stays mine.
A paid strategic consult is available now, without waiting for a full slot.
Full engagements open as an existing engagement reaches Phase 3, because I run a maximum of four at a time. If your trigger is time-critical, name it when you request the conversation and I respond within 48 hours with a realistic window.
Most engineering-led shops can do the work but cannot see the constraint, because the people closest to it are inside it.
I bring an outside operator's read of your value stream plus the defense-compliance fluency most internal teams have not had to build yet. The 30-Day Triage is designed precisely for a team that is capable but operationally bottlenecked.
The Supplier Performance Risk System holds your self-assessed NIST SP 800-171 score.
Your prime cannot see it, whatever you have been told. Under DFARS 252.204-7020(f) the score is visible to DoD personnel and to you, and that clause is the whole list. The lever your prime actually holds is harder: under 252.204-7020(g)(2) it may not award you a subcontract subject to NIST SP 800-171 unless you have completed at least a Basic assessment within the last three years. A stale assessment does not cost you points. It takes you off the award entirely. A wrong or stale score is also a false-affirmation risk, and the DOJ Civil Cyber-Fraud Initiative pursues exactly that under the False Claims Act. With CMMC Phase 2 suspended as of July 2026, that self-assessment and its annual affirmation are the mechanism actually being enforced. Getting the score right, and being able to defend it, is part of the Sovereign Tier pillar.
Yes, this is an active engagement type.
I am currently standing up US defense manufacturing operations for a Canadian-parent subsidiary. The work covers the operating model, the IT and OT build, and the FOCI and compliance posture you need to qualify for US defense business against the gate your prime set.
A facility clearance is what a company needs to access classified information, and Foreign Ownership, Control, or Influence mitigation is what a foreign-owned company negotiates with the Defense Counterintelligence and Security Agency to hold that clearance despite its foreign parent.
Most sub-tier defense manufacturing is unclassified CUI and ITAR-controlled work that never needs a facility clearance at all. Knowing which class of work you are chasing decides whether FOCI mitigation and a clearance are even in scope. I build and run the unclassified operation; the clearance and the FOCI instrument stay with your cleared-facility counsel and DCSA.
A DFARS qualifying country is a nation with a reciprocal defense-procurement agreement with the Department of Defense, which lets its end products and components bypass Buy-American restrictions.
All nine countries I serve are qualifying countries. It is a procurement preference and nothing more: it does not waive ITAR, it does not waive CMMC, and it does not clear FOCI. A qualifying-country parent still builds the full compliance posture, and that build is the work.
Usually not without a boundary.
If your US operation holds controlled technical data, that data stays inside a US-person data boundary, so a shared ERP that gives the foreign parent open access to CUI or ITAR-controlled technical data is a problem. I build the US entity and the data boundary so the American operation holds controlled data compliantly, and transfers to the parent happen under DDTC authorization or not at all. Sometimes that means a segregated instance, sometimes a separate system, and the architecture decision is part of the build.
On-site operating work is concentrated across New England, where the defense industrial base and the prime relationships I know best are dense, and it is a strong landing zone for an allied manufacturer entering the US market.
Diagnostic and strategic work runs nationally. If your US site is going elsewhere, we scope the mix of on-site and remote at the start.
I am the operations partner.
I stand up and run the compliant US operation: the floor, the operating model, the IT and OT build, the US-person data boundary, and the readiness evidence for the gate your prime set. Entity formation, ITAR and DDTC registration, FOCI mitigation, and CFIUS questions stay with your corporate and export-control counsel. I coordinate with them and own the operating outcome.
It means your order book is growing while your working capital tightens, because long-lead inventory and rework trap cash between the sale and the deposit.
AlixPartners found the aerospace and defense cash conversion cycle lengthened by 21 days between 2018 and 2022. Margin Engineering targets that cycle directly, recovering cash conversion days you can redeploy.
Both, and the mix depends on the work.
Floor work, Gemba walks, Kaizen events, and the first 90 days of a fractional engagement need me on-site across New England. The analysis, the reporting, and the steady-state cadence run remote. I am based in Brookline, NH, and serve Greater Boston and Southern New Hampshire on-site.
It is a method with four named pillars and a defined delivery sequence.
IT/OT Convergence, Margin Engineering, Human-in-the-Loop, and Sovereign Tier are each a set of operations, delivered through the 90-Day Strategy Formulation Framework of Diagnostic, Stabilization, and Commercial Scale. The named hooks are there so the work is memorable, not so it sounds impressive.
Self-diagnostic
Six questions name the fault you are actually fighting. The result restates your own situation back to you and points to the right starting line. No email, no follow-up sequence.
