ITSecurityGuru

Margarita Howard’s HX5 Operationalizes CMMC Compliance Before AI Rules Arrive


Margarita Howard has spent two decades running a company in a government contracting market where the rules rarely hold still.

HX5, the defense and aerospace services firm she founded in 2004 and still leads, supports Department of Defense and NASA missions and has employed over 1,000 people across 34 states and 90 government locations over the course of its history.

For most of that span, the price of remaining eligible to do the work has been a requirement that keeps changing shape. Its current form is the Pentagon’s Cybersecurity Maturity Model Certification, known as CMMC, and behind it a second, still-forming set of rules aimed at artificial intelligence. How HX5 has prepared for both is a case study in the need to prepare for sudden shifts in security technology.

The CMMC

For years, contractors handling sensitive government data attested to their own cybersecurity practices. CMMC replaces much of that self-attestation with graded, checkable proof. The framework, which took effect under a Defense Department rule in 2025, sorts contractor obligations into three levels tied to the sensitivity of the information involved.

Level 1 covers basic Federal Contract Information and allows an annual self-assessment. Level 2 applies to Controlled Unclassified Information (the sensitive-but-unclassified material that runs through most substantive defense work) and, depending on the program, requires verification by an accredited outside assessor. Level 3 covers the government’s most critical programs and is assessed by the Pentagon itself.

The schedule is what gives the program its teeth. Phase 1 took effect on November 10, 2025, and the first certification requirements entered new contracts. Phase 2 follows exactly one year later, on November 10, 2026, when independent third-party certification becomes a condition of award for contractors handling Controlled Unclassified Information. At Level 2, that means demonstrating all 110 security practices drawn from the NIST SP 800-171 standard, backed by evidence an assessor can test rather than a contractor’s word.

That evidentiary bar is where many contractors are finding a gap between feeling compliant and being audit-ready. By early 2026 the assessment market had become a bottleneck. Industry trackers counted only about 1,000 contractors certified at Level 2, far short of the tens of thousands expected to need it, with roughly 80 accredited assessment organizations available to do the work. Wait times now stretch into months.

HX5 entered that crunch from the front of the line. The company was among a limited group of contractors to hold CMMC Level 2 certification by the end of 2025, well ahead of the Phase 2 mandate.

The distinction at the center of the scramble is between being aligned and being audit-ready. Many contractors hold documentation showing they meet the NIST practices on paper; far fewer can produce the evidence a certified third-party assessor will demand to confirm each control is implemented and operating. Early assessments can falter on the unglamorous fundamentals: access control, audit and accountability, incident response. The program also limits how much a contractor can defer through a plan to fix gaps later. Critical practices have to be working at the time of assessment, not promised. Closing that gap typically takes six to 12 months of focused work.

HX5’s Distributed Footprint and the Audit-Ready Bar

Firms like HX5 work across dozens of government locations, supporting research and development, engineering, information technology, and mission operations for federal customers. Holding a single, defensible compliance posture across distributed operations is an exercise in standardization: building the same expectations into vendor qualification, contract management, and the daily routines of each location, rather than reconstructing them program by program.

Certification is not a perimeter a contractor can defend alone, either. CMMC obligations flow down a contract: a prime that handles controlled data is responsible for confirming that the subcontractors and vendors it shares that data with meet the level required of them before the information changes hands. For a firm spread across dozens of programs, that turns compliance into a procurement function as much as a technical one. The company has to qualify partners against the standard, write the expectation into agreements, and verify it rather than assume it. The administrative weight of that work scales with the number of relationships a contractor maintains, which is part of why a footprint as broad as HX5’s makes the discipline harder to retrofit and more valuable once it’s in place.

Margarita Howard points to the pandemic as the stress test that proved the model. When operations went remote in 2020, the company had to keep meeting the government’s security and reporting standards while its workforce scattered. “We very quickly had to set up our employees to work remotely … to ensure the security standards that we have to report on,” she said, crediting a flexible, secure infrastructure the company had already paid for. The episode reinforced a lesson that maps directly onto CMMC: the firms that weather a sudden change in requirements are usually the ones that built the capacity before they needed it.

Howard frames the work as a matter of record-keeping discipline as much as technology. “It’s important that a company’s records are impeccable when working with the government due to the compliance reporting and audits that companies have to agree to in order to perform on government contracts,” she said.

She explained that HX5 put money into accounting and management systems built for government-contracting environments early on, and it keeps standing advisory capacity on hand for the regulatory questions that surface as programs evolve.

“We have built and maintained a team of advisers that specialize in the government industry,” Howard said. “They help us stay current with the policies and regulations that govern the defense sector.”

Workforce composition reinforces the same habit. Veterans make up more than 30% of HX5’s employees. Many arrive having already worked inside government security environments, with a built-in sense of why controls exist and what an audit will ask for. The company has taken part in the Defense Department’s SkillBridge initiative and the Hiring Our Heroes Corporate Fellowship Program since 2021, and the Department of Labor recognized its veteran-hiring record with a 2025 HIRE Vets Gold Medallion.

The capability also depends on a steady supply of people who can do the technical work behind the controls. Howard pointed to university partnerships as one of the company’s more productive and less expected investments. Those collaborations keep HX5 close to emerging technology and feed a pipeline of graduates into roles that, in this market, are hard to fill and harder to clear. A compliance program is only as strong as the staff who implement it day to day, and the same recruiting channels that bring in cleared engineers and technicians supply the people who keep audit evidence current between assessments.

The same rising bar that burdens HX5 also reshapes the field it competes on. Compliance has become a fixed cost of doing defense work, and fixed costs fall hardest on firms without the scale or the standing infrastructure to absorb them. Some smaller contractors may decide the controlled-data work is no longer worth the overhead; some larger primes have narrowed the lower-margin contracts they pursue. A mid-tier company that has already paid for the capability sits in the gap that opens between those two retreats, potentially able to take on work that requires certification without treating each new requirement as a fresh capital project.

But for contractors that deferred the investment, Phase 2 arrives as both a timeline problem and a cost problem. Assessor capacity is finite, the queue is long, and assembling a compliance foundation under deadline pressure costs more than building it in calmer conditions.

Howard’s read on that math reflects a market she has worked in since the company’s small-business beginnings. “There are heightened cybersecurity requirements,” she said, “and contractors will not have a choice but to implement them if they want to be a government contractor.”

The AI Layer Arriving on Top of CMMC

The next requirement is already visible. The FY2026 National Defense Authorization Act, signed in December 2025, directs the Pentagon to build a cybersecurity and physical-security framework for artificial-intelligence and machine-learning systems and to fold it into the existing CMMC program, a step often shorthanded as “CMMC for AI.”

Section 1513 of the law tells the Defense Department to address workforce, supply-chain, and adversarial-tampering risks in AI systems acquired for government work, drawing on established NIST standards. The provision does not set a final implementation date, but it required a status report to Congress on the plan in June 2026, with the new requirements ultimately expected to reach contractors through the same acquisition rules that carry CMMC.

The framework Congress has in mind is broad. As drafted, it reaches “covered” AI and machine-learning systems acquired by the Defense Department along with their components (source code, model weights, and the data and methods used to build them), and concentrates the most stringent requirements on the highly capable systems likeliest to draw the attention of sophisticated adversaries. It extends the logic of CMMC, protecting sensitive information, into a new category of asset the original program was not written to address.

The timing is what makes the moment unusual. The third-party certification requirement and the new AI rules are advancing through the same window, on the same acquisition machinery, aimed at overlapping populations of contractors. A firm that treats them as two separate fire drills faces a doubled burden in a compressed period. A firm that treats compliance as one continuous capability sees the AI framework as an extension of work already under way rather than a second front.

How fast the AI requirements bind on contractors is still unsettled. Section 1513 sets a planning process in motion rather than a finished rule, and the report due to Congress is a milestone in that process rather than the finalized rule itself. The practical questions will be answered in rulemaking still to come: which systems count as covered, how the requirements map onto CMMC levels, and when they appear in contract clauses.

For HX5, that uncertainty is an argument for the posture it already holds. A contractor with mature compliance machinery can wait for the specifics without falling behind, because adapting an existing program is a smaller task than building one.

The point is less whether the AI rules are wise than that they will arrive on top of an obligation the company already meets, through machinery it has already built. A contractor that has internalized CMMC should have the assessment discipline, documentation habits, and advisory bench to absorb an added layer without starting over. One still scrambling for its first Level 2 certification will be asked to take on a second, harder problem before finishing the first.

Howard has been pointing in this direction for some time. She, like many others in the industry, has stressed that government agencies will increasingly use AI to streamline procurement and evaluate contractor performance, and that compliance itself will grow more automated.

“Contractors will be required to integrate systems that provide continuous reporting and real-time audit capabilities,” she said. “We’ve invested heavily in technology infrastructure to meet these future demands.”



Source link