Demand Has a Due Date

6 min read strategy
By

On July 13, the Pentagon suspended the second phase of its CMMC assessment program, four months before it was scheduled to begin. Defense contractors read the announcement as relief. The department wrote one sentence that should have stopped them: the action does not eliminate the requirement to protect covered information under the existing DFARS clause. The deadline moved. The obligation did not.

That sentence is the most useful thing the compliance news produced all summer, because it describes a class of demand most MSPs never organize: demand with a date attached. Referrals arrive when they arrive. Inbound converts when the buyer gets around to it. Regulated demand is different. Somebody in a government building put a date on it and attached a penalty, then published both.

A revenue organization that builds its territory plan around that calendar gets urgency without inventing it. An investor evaluating that organization gets something rarer: pipeline that can be checked against a public schedule. Here is the calendar as it stands in August 2026, and the operating system that turns it into revenue.

The calendar, four entries deep

September 22, 2026. NIST places every remaining FIPS 140-2 certificate on its historical list. Validated modules already deployed can keep running; the pressure lands on new purchases, which shift to FIPS 140-3. The move: inventory which clients sell into federal supply chains, and open the module-refresh conversation before the fall procurement cycle opens it without you.

The CMMC pause. Phase 2 was scheduled for November 10, 2026 and is now suspended while a task force reviews the program. Scope stays what it was: the defense supply chain, about 220,000 contractors and subcontractors by the department’s own analysis, three-quarters of them small businesses. A Level 2 certification assessment runs $101,752 for a small entity, again by the department’s estimate. The DFARS security clauses stay in force through the pause. The move: build the defense-adjacent account list now and sell readiness against the obligation, because a pitch built on the obligation survives a paused deadline. A pitch built on deadline panic died in July.

The proposed HIPAA overhaul. The Security Rule amendments published in January 2025 remain a proposed rule, and the HHS regulatory agenda now points to July 2027 for final action. The department priced the first year of compliance at roughly $9 billion. The move: healthcare clients get a gap assessment against the proposed text, sold as exactly that, so the remediation backlog gets scheduled before the rule lands instead of after.

The column of dates already passed. PCI DSS 4.0.1’s future-dated requirements became mandatory in March 2025. Indiana, Kentucky, and Rhode Island privacy laws took effect this January 1. Public-company clients have answered to the SEC’s cyber incident disclosure rule since December 2023. A passed date is remediation demand: the client who missed it is further behind than they believe, and an assessment against a live requirement closes faster than one against a rumor.

The demand is funded and under-sold

None of this works if buyers resent the subject, and the record says they do not. WatchGuard’s April 2026 survey found 67 percent of organizations need additional support to meet growing compliance demands. The same survey found 75 percent expecting security budgets to increase over the next two years. The need is stated and the money is planned.

Now the supply side. Kaseya’s 2026 State of the MSP puts regulatory and compliance reporting at 8 percent of the MSP revenue mix. The same report clocks the category’s growth at 36 percent year over year, among the faster lines in the book. Two-thirds of buyers say they need the help; providers book it at 8 percent of revenue. The distance between those numbers is unsold work.

The insurance column

Cyber insurance belongs on the calendar for one reason: renewals recur on a date. Handle the story around it with care. Premiums are falling. Marsh’s index recorded a 4 percent decline in cyber rates in the second quarter, the twelfth consecutive quarterly decline, so the spiraling-premiums pitch is dead, and a buyer who reads the market will hold it against the seller who tries it.

What remains true is better material. Insurers keep tightening the controls they require attested at renewal, a pattern operators report consistently even though no published study quantifies it. And the claims justify the controls: Coalition’s March 2026 claims report found dual extortion in 70 percent of ransomware events, with initial demands up 47 percent to an average above $1 million. The move: a renewal-date field on every account record, and a standing meeting 90 days ahead of each one to walk the attestation together before the broker’s questionnaire arrives.

Running it as a system

A calendar taped to the wall is decoration. The operating version lives in the CRM as four dated fields on every account: regulatory framework and its next date, insurance renewal, contract end, budget cycle. Territory plans and quarterly sequencing get built from those fields, and account reviews open with them.

Ownership matters as much as the fields. Each calendar entry gets one owner on the revenue team, and entry status gets read out in the same weekly meeting that reads out pipeline. A calendar reviewed quarterly is a calendar discovered late.

Pipeline created from a date behaves differently. The close date belongs to the buyer’s regulator or insurer, so neither the rep’s optimism nor the buyer’s stall can move it far. Forecast reviews stop litigating rep conviction and start tracking one number: the share of open pipeline with an external date attached. That share is the figure to put in front of an investment committee, because a date-sourced pipeline survives diligence.

One discipline holds the system together: sell the obligation, never the deadline theater. Deadlines pause, as CMMC just demonstrated. Obligations persist, as the department confirmed in the same announcement. Build on the second and a suspended deadline costs you nothing but a talking point.

The benchmark nobody owns

No analyst report quantifies compliance-driven MSP revenue beyond Kaseya’s single line; the search comes back empty. That absence is an opening. The operator who instruments this motion first will own the benchmark the rest of the industry quotes, and the investor who backs that operator gets a demand engine with dates on it.

Worth an hour of your next operating review: pull ten open opportunities and count how many carry a date the buyer did not choose. A pipeline full of self-set close dates runs on hope. The calendar is public and the penalties are published. The buyers have already said they need the help. Put dates on your demand.

Frequently Asked Questions

Did the CMMC pause remove security obligations for defense contractors?

No. The July 13, 2026 suspension covers Phase 2 third-party assessments while a task force reviews the program, and the department stated the action does not eliminate the requirement to protect covered information under the existing DFARS clause. About 220,000 contractors and subcontractors sit in the program's scope per the department's own analysis, and a Level 2 certification assessment runs $101,752 for a small entity by the department's estimate.

Is the new HIPAA Security Rule final?

No. The Security Rule amendments published in January 2025 remain a proposed rule, and the HHS regulatory agenda anticipates final action in July 2027. The department priced the first year of compliance at roughly $9 billion. The current Security Rule stays in effect, which is why a gap assessment against the proposed text should be sold as exactly that.

When does FIPS 140-2 retire?

NIST places all FIPS 140-2 certificates on its historical list on September 22, 2026. Validated modules already deployed can remain in use, so the date creates procurement pressure on new purchases, which shift to FIPS 140-3. Clients selling into federal supply chains need the module inventory conversation before the fall procurement cycle.

Back to blog