Why Most MSPs Aren’t Ready for CMMC And What to Do About It: (Andrew Lally from KTL)

If your organization handles Controlled Unclassified Information (CUI) and relies on Microsoft cloud services, this podcast episode covers the practical realities you need to understand. Andrew Lally, Director of IT Services at KTL Solutions, walks through how KTL grew from an enterprise resource planning (ERP) implementation shop into a full-service managed service provider (MSP), Cybersecurity Maturity Model Certification (CMMC) Third Party Assessor Organization (C3PAO), and Microsoft Cloud Solution Provider (CSP) supporting defense contractors and commercial clients alike.

Andrew brings a lifelong IT background to the table, from earning his Cisco Certified Network Associate (CCNA) certification in high school to building out KTL’s entire managed services practice.

Watch the full episode here.

From ERP Roots to Full Service IT and Compliance

KTL Solutions started as a Dynamics enterprise resource planning implementation and consulting firm based in Frederick, Maryland. Over the years, the company expanded into Dynamics Customer Relationship Management (CRM), Office 365 tenant management, custom .NET software development, Power Platform consulting, and full managed IT services. When the Microsoft ecosystem grew to include Government Community Cloud (GCC) and Government Community Cloud High (GCC High) environments, KTL followed its customers into compliance territory.

Andrew described how many people in the defense contracting space know KTL primarily for its GCC High support and compliance consulting, but the company’s capabilities extend well beyond that. KTL also operates as a C3PAO listed on CyberAB’s marketplace, employs certified CMMC assessors (CCAs) and lead CCAs, and holds its own CMMC Level 2 certification. On top of that, the company maintains a .NET development team, a Power Platform practice, and a Dynamics Business Central implementation team.

Andrew put it simply: if you started with nothing, KTL could build your entire business technology stack from finances and inventory management to business applications, cloud infrastructure, and compliance.

That breadth creates a practical advantage. When an ERP issue affects network performance or a compliance finding requires a configuration change, the teams sit under one roof. No finger pointing between vendors. Problems get identified and resolved by people who share context across disciplines.

How a COTS Exemption Disappeared Overnight

One of the most striking stories Andrew shared involved a KTL customer that sold what it believed were commercial off the shelf (COTS) products to the federal government. The company also performed routine equipment calibration as part of its contracts. For years, both the customer and the government agreed that COTS exemptions applied. No CUI flowed through the engagement. No compliance program existed.

Then a contracting officer sent a memo. The memo stated that any services bundled with a product order, even basic maintenance, disqualified the contract from COTS treatment. The customer received a Supplier Performance Risk System (SPRS) score requirement and suddenly needed to demonstrate compliance with NIST SP 800-171.

The contracting officer could not identify what CUI might flow through the engagement. The customer had no documentation, no compliance baseline, and a ticketing system that could theoretically receive CUI from a government user at any time.

Andrew warned that this pattern will likely repeat as contracting officers apply Defense Federal Acquisition Regulation Supplement (DFARS) clauses more broadly during CMMC Phase 1 and Phase 2 rollouts. He noted the memo appeared to come from the Navy side, but the logic behind it, that any services component eliminates the COTS exemption, could easily extend across the Department of Defense (DoD).

For organizations that currently believe they fall outside CMMC requirements, this is a wake up call. Andrew recommended that every company review its existing contracts carefully, read the clauses rather than defaulting to assumptions, and consult with compliance professionals before assuming exemption status still holds.

Business Development Teams Need Governance, Risk, and Compliance at the Table

Andrew described real situations where business development (BD) teams won contract awards that committed internal IT departments to compliance obligations nobody had planned or budgeted for. In some cases, research and development projects required specialized infrastructure that no one thought through before the contract start date.

The result was predictable: internal teams scrambled to deploy systems, nobody had allocated budget for the IT overhead, and tensions escalated over who bore responsibility for meeting the new requirements.

His advice is straightforward. Every organization that bids on government work should maintain a pre approved checklist of contract clauses it can actually satisfy. Governance, risk, and compliance (GRC) professionals should participate in the bidding process alongside BD staff. If a clause falls outside the pre approved list, the team should either confirm the gap can be closed or move on to the next Request for Proposal (RFP).

This is not just about avoiding compliance failures. It is about protecting the organization from committing to obligations that create unfunded mandates for the IT and security teams who must deliver on them.

Why Standardized Onboarding Policies Protect Both the MSP and the Customer

KTL requires customers to accept certain baseline policies before managed services begin. Andrew explained the reasoning clearly: if every customer operates under different rules, the MSP’s people must constantly check which policies apply to which environment. That increases risk, slows response times, and drives up costs.

Standard policies cover areas like local administrator rights, approved application lists, hardware baselines, and change management processes. When a user requests new software, the request goes through a documented review. The system owner or a delegated authority must approve the change before the IT team deploys it. That process might take a week depending on the complexity of the software and the availability of the approver.

Andrew acknowledged that flexibility is sometimes necessary. Some manufacturers need legacy machines running older operating systems to support production equipment. Some customers recently signed multi year contracts on firewalls that may not match the Federal Information Processing Standards (FIPS) certificate requirements for their compliance boundary. KTL works through those situations, but it starts from a defined baseline rather than building a custom framework for every engagement.

The compliance dimension makes this even more valuable. Documented change management processes, approved software lists, and role based access controls are not just operational best practices. They map directly to NIST SP 800-171 requirements. When customers push back on restrictions, Andrew’s team walks them through the regulatory reasoning. The frameworks exist because uncontrolled environments led to security failures. The restrictions protect the customer, not just the MSP.

The Trickiest Customers to Onboard

Andrew identified software development organizations and engineering consultants as the most challenging customers to bring into a compliant managed services environment. These teams routinely request elevated permissions, use integrated development environments (IDEs) that pull libraries from open ecosystems, and adopt cutting edge tools that lack enterprise documentation or compliance track records.

The challenge extends beyond permissions. Mobile code, software bills of materials (SBOMs), and supply chain security requirements are all maturing on the defense side. Making a system that allows developers to do their jobs efficiently while maintaining compliance boundaries requires careful architecture that varies significantly based on the tools and platforms each team uses.

Manufacturers present a different kind of complexity. They typically have on premises servers, dark equipment, machines connected to the network, and legacy systems that rely on features like VBScript execution from file servers, features that every reputable security baseline blocks by default. Onboarding these environments requires physical site visits, thorough documentation, and careful exception handling for configurations that deviate from standard baselines.

The Biggest Problem: What Customers Do Not Know

When asked to identify the single biggest challenge defense contractors face in preparing for CMMC, Andrew pointed to knowledge gaps. Customers frequently arrive with tools and multi year commitments to products that cannot be used in their compliance boundary. Backup solutions that store data in commercial clouds. Firewalls that do not match the model listed on the relevant FIPS validation certificate. Security features that must be disabled because the product was not purchased at the right tier.

KTL ends up delivering difficult news in those situations, and sometimes the customer does not have the budget to replace what was just purchased. Andrew noted that the fault often lies with a previous MSP or consultant who assessed the environment against NIST SP 800-171 controls without considering Federal Risk and Authorization Management Program (FedRAMP) requirements for cloud service providers. From a pure cybersecurity standpoint, the tools might have checked every box. But in a CMMC compliance context, the wrong cloud, the wrong certificate, or the wrong license tier renders the investment unusable.

Microsoft Licensing in GCC High: Complexity That Demands Expertise

Andrew spent significant time discussing the nuances of Microsoft licensing for defense contractors operating in GCC High. The licensing landscape has grown more complex as Microsoft introduced new SKUs and retired others.

Key points for organizations navigating this space:

GCC High licenses cost significantly more than commercial equivalents. Historically, only Enterprise SKUs were available. Earlier this year, Microsoft introduced Business Premium into GCC High, which opened a more cost effective path for smaller organizations. However, Business Premium does not include Windows Enterprise licensing, which creates complications for organizations that need features like Windows Store controls or Windows 365 configurations that depend on Enterprise entitlements.

Andrew noted that the most cost effective arrangement for many organizations today is Government Business Premium combined with G5 Security and Compliance add ons. But even that combination required Microsoft to create special SKUs (BP Security and BP Purview) because the original G5 add ons could not be applied to Business Premium licenses as initially promised.

The broader lesson is that Microsoft licensing in GCC High requires someone who understands the specific SKU landscape, knows which features each license tier includes, and can map those capabilities against both the organization’s operational needs and its CMMC compliance requirements. Organizations that try to navigate this independently frequently end up with mismatched licenses, missing capabilities, and higher total costs than if they had purchased the right bundle from the start.

AI in the Defense Contracting Space

KTL’s teams actively use artificial intelligence (AI) across multiple practice areas. On the commercial side, the company integrates customer data from SQL Server into Power BI and Microsoft Fabric so AI tools can enable conversational interactions with manufacturing schedules, customer orders, and operational data. The Power Platform team builds Copilot enabled applications, Power Apps, and Power Pages that let customers interact with their systems more efficiently.

On the defense side, adoption is growing but constrained. Microsoft Copilot recently became available in GCC High. Azure OpenAI components have been available in Azure Government for some time, though models arrive slowly compared to the commercial cloud. Customers want to leverage AI for internal operations and federal projects, but the tools available in FedRAMP authorized environments still lag behind their commercial counterparts.

Andrew also addressed the practical reality of AI governance. When employees use AI tools, their name goes on the output. AI can speed up research, automate repetitive tasks, and surface insights from large data sets. But the human remains responsible for reviewing, validating, and approving everything before it goes out the door. KTL reinforces this internally: if something breaks because you followed an AI recommendation without understanding why, that is on you, not the AI.

What Is Coming: Microsoft 365 Local and Azure Virtual Desktop Hybrid

Andrew highlighted two Microsoft developments that he expects will significantly affect defense contractors:

Microsoft 365 Local addresses a persistent gap for foreign entities that subcontract on defense programs. Most FedRAMP environments require a United States based entity to purchase access, which excludes international partners from GCC High. Microsoft 365 Local would allow organizations to run a local server with similar functionality. One unexpected detail: the current documentation lists Skype for Business rather than Microsoft Teams as the collaboration tool, which Andrew found surprising.

Azure Virtual Desktop (AVD) Hybrid is currently in private preview. It allows organizations to run Azure Virtual Desktop workloads on their own servers enrolled through Azure Arc, connected to the Azure Government environment. This addresses several pain points at once: GPU machine shortages in Azure Government, latency for customers with limited internet connectivity, and the high cost of Azure Local (formerly Azure Stack HCI) hardware, which Andrew noted routinely reaches mid six figures for hardware alone. AVD Hybrid could let defense contractors take advantage of local GPUs, better latency, and lower costs while maintaining their Azure Government compliance posture.

Get a GRC Tool Early: Andrew’s Top Advice

Andrew closed the conversation with direct advice for Organizations Seeking Certification (OSCs) and MSPs preparing for CMMC.

First, invest in a GRC tool early. Many organizations start with spreadsheets and plan to adopt a platform later. When they eventually make the switch, they spend significant time migrating data, learning the tool, and cleaning up inconsistencies. KTL uses IntelliGRC as part of its assessment and compliance workflow. The platform holds evidence, tracks review cycles, documents audit logs, and maps findings to specific controls. Andrew noted that the tool becomes part of the evidence itself, showing assessors that Paige reviewed a finding, flagged a deficiency, and generated a change ticket to resolve it.

Second, choose your support team carefully. Andrew described situations where other C3PAOs turned away organizations that believed they were assessment ready. Their previous MSP or consultant told them they were prepared, but the C3PAO’s preliminary review revealed that the documentation, configurations, or scope did not meet the standard. In many of those cases, the organization had to start over with a new provider and lost months of time.

The organizations that succeed treat compliance as an ongoing operational discipline rather than a one time project. They invest in the right tools, engage qualified partners, and build processes that create auditable, defensible evidence from day one.

You Do Not Have to Navigate CMMC Alone

Every conversation on this podcast reinforces the same truth: the organizations that succeed with CMMC stop guessing and start working with people who have been through it.

Andrew and the KTL Solutions team bring deep Microsoft expertise, hands on assessment experience, and a full service approach that covers everything from cloud architecture to compliance documentation. And they use IntelliGRC to keep it all organized, auditable, and ready for review.

If you need help navigating CMMC, cloud migration, or Microsoft licensing for the defense industrial base, reach out to KTL Solutions or schedule a call with IntelliGRC. Be sure to subscribe to our podcast for more conversations with the practitioners and assessors shaping the CMMC ecosystem.

Frequently Asked Questions About CMMC, Cloud Migration, and Microsoft Licensing

What services does KTL Solutions provide beyond CMMC consulting?

KTL Solutions offers Dynamics Business Central and CRM implementations, custom .NET software development, Power Platform consulting, full managed IT services, Microsoft 365 migrations, CSP licensing, and CMMC Level 2 assessments as an authorized C3PAO listed on CyberAB’s marketplace.

Can a COTS exemption protect my organization from CMMC requirements?

Not necessarily. Recent memos from contracting officers indicate that any services component bundled with a product order, including routine maintenance or calibration, may disqualify a contract from COTS treatment. Organizations should review their contracts carefully and consult with compliance professionals before assuming exemption.

What is the most cost effective Microsoft license for GCC High?

For many organizations, Government Business Premium combined with the BP Security and BP Purview add ons provides the most cost effective path. However, Business Premium does not include Windows Enterprise licensing, which may require additional SKUs depending on your configuration needs. Work with a Microsoft licensing specialist to map your requirements before committing.

Why should I adopt a GRC tool before my CMMC assessment?

A GRC platform like IntelliGRC documents your compliance activities as you perform them, creating an auditable trail of reviews, findings, and remediation actions. Starting early means your data is clean, your team knows the tool, and your evidence is organized before the assessment clock starts. Organizations that delay adoption often spend significant time migrating and cleaning up data under pressure.