Advertisement

Pausing CMMC cannot mean pausing accountability

The answer is to modernize accountability through an enterprise model that combines a formalized independent assessment, continuous external monitoring, and shared remediation support where small suppliers cannot reasonably carry the burden alone.
Listen to this article
0:00
Learn more. This feature uses an automated voice, which may result in occasional errors in pronunciation, tone, or sentiment.
(Getty Images)

The Department of War’s decision to suspend Phase 2 of the Cybersecurity Maturity Model Certification (CMMC) program creates an opportunity to strengthen — not weaken — how we protect the defense industrial base (DIB). Many small and mid-sized defense contractors struggle to absorb the cost, complexity, and administrative burden of the current compliance model, while defense programs that depend on a supplier base are already under significant pressure to maintain readiness.   

Before this announcement, I was a CMMC skeptic. I argued that America’s cyber defenses had been optimized for audits, not threats. The DIB is a fundamental example of the challenge facing every supply chain critical to national security: it is too large, too distributed, and too important to be secured by paperwork alone, especially as AI-enabled adversaries become faster at finding and exploiting weak links. 

While the DOW reviews CMMC, our adversaries will continue probing internet-facing systems for exposure, weak identity controls, unpatched infrastructure, misconfigured services, and suppliers whose promised cyber posture differs from their actual one. That reality reinforces the lesson behind CMMC. 

The answer is to modernize accountability through an enterprise model that combines a formalized independent assessment, continuous external monitoring, and shared remediation support where small suppliers cannot reasonably carry the burden alone.

Advertisement

CMMC did not invent new requirements. Contractors handling controlled unclassified information (CUI) have been contractually obligated to implement NIST SP 800-171 for years, and to attest to that implementation in writing. What was missing was any mechanism to test the attestation. CMMC exists because self-assessment, absent verification, is an honor system with a federal contract attached to it.

Not every NIST SP 800-171 control can be externally observed. Policies, training, access reviews, and incident response exercises require assessment data and documentation, but many risks are most visible from the outside, where many of these efforts don’t touch. 

Consider NIST SP 800-171’s requirement to protect CUI when transmitted. A contractor can attest that they use proper encryption, but some parts of that claim can be tested without documentation. Expired certificates, self-signed certificates, exposed FTP services, or other outdated communications pathways visible from the internet do not prove that CUI has been compromised, nor do they prove whether every internal transmission path is protected. In a synchronized approach, early signals would highlight pressure points to ensure swift and targeted mitigation to avert a full supply chain meltdown. 

In the above strategy, the DOW would insist on prioritizing mission risk over administrative sequence. This would complement CMMC and NIST-based framework controls — making them more useful and easier for smaller suppliers to implement by removing duplicative queries from multiple prime contractors and government offices. 

An enterprise approach also recognizes that cybersecurity is a shared responsibility across the War Department, primes, and sub-tier suppliers. Program offices and mission owners would have to prioritize suppliers, some of which sit four or five layers down but support multiple critical platforms or hold sensitive technical data. A department-led enterprise strategy would be best positioned to identify concentrations of risk, set priorities accordingly, and hold prime contractors to account for the security of their supply chains. 

Advertisement

Concurrently, the department should consider an enterprise fund that supports continuous cyber monitoring and remediation for critical small businesses who often struggle with the cost of monitoring and remediation through vetted providers. Congress has already begun this work; the Senate version of the Fiscal Year 2027 National Defense Authorization Act would authorize $50 million in CMMC assessment grants — but a one-time assessment subsidy is not the same as sustained monitoring and remediation.

The government is already paying for fragmented compliance activity indirectly through contract costs. Funding a baseline level of shared monitoring and remediation up front could reduce duplication, lower total cost, and improve security outcomes. As AI advances, we will only have one opportunity to set the conditions for the future of DIB cybersecurity, and that time is now. 

Hopefully the War Department will take this time to lower unnecessary administrative burdens, preserve independent validation under a system small suppliers can afford, utilize continuous enterprise-wide monitoring to highlight risk, and implement rapid remediation of the exposures adversaries are most likely to exploit. If it does, this pause will be time well spent and will reinstate integrity into a broken system. If it does not, our adversaries continue to exploit the DIB. And one day, we will pay the price.

Lonny Anderson, the former chief technology officer for the National Security Agency, is the president of BlueVoyant Government Solutions.

Latest Podcasts