DoD Says CMMC Costs Too Much. What Comes Next Could Cost More.

Jacob and Jason argue that while everyone’s distracted by the CMMC Phase 2 suspension, the DoD has already telegraphed a far bigger and costlier requirement: migrating the entire defense industrial base to post-quantum cryptography (PQC). And it’s not optional — Congress mandated it.

Key takeaways:

  • Encryption is the whole foundation. It’s not just hiding data — it’s how systems establish trust (your bank, software updates, logins). Quantum computers threaten to break today’s math-based locks, so PQC swaps in new math problems designed to resist them. If encryption fails, everything fails.
  • “Harvest now, decrypt later” is why the clock is already ticking. Adversaries can steal encrypted data today and decrypt it once quantum computers arrive — so migration has to start before those machines are operational.
  • This is law, not a suggestion. Congress passed the Quantum Computing Cybersecurity Preparedness Act (2022); the White House scoped the federal migration at $7B+ (2025–2035, likely 2–3× that); the DoD’s April 2026 strategy calls PQC an “existential threat,” says CMMC will be updated to include PQC requirements, and warns “costs will be incurred”; and a June executive order directs a FAR rule pushing PQC into all federal contracts.
  • The cost problem undercuts the “reduce burden” message. Background cloud/vendor updates may be ~$10–50K, but internal PKI, legacy infrastructure, embedded systems, old ERP, and OT that can’t be upgraded mean rip-and-replace — hundreds of thousands to millions. Any savings from trimming CMMC assessments won’t come close to offsetting that.
  • Watch for the leapfrog. Rev 3’s crypto ODP plus a presidential mandate could let the DoD move the encryption baseline straight to PQC — and, as with DFARS 7012 arriving a decade before the FAR CUI rule, they may impose it ahead of formal rulemaking. Suspending assessments doesn’t suspend the threat.

Transcript

Jacob: All right, folks. It is August of 2026, and the DoD CIO recently published their idea of basic cybersecurity best practices. Among the 20 best practices, one thing is conspicuously missing: encryption. Does that mean that the bedrock of modern digital life — the thing that almost everything in cybersecurity depends on — isn’t basic, or somehow isn’t expected by the DoD? Well, back in April, months before the CMMC Phase 2 suspension announcement, the DoD showed us exactly what’s coming for defense contractors. And what’s coming will require defense contractors to replace the cryptography underlying their networks, their cloud services, their applications, their identity systems, and potentially even the actual products they build for the department in the first place. And that’s what we’re going to talk about today.

Jason, we recently discussed on the show how the DoD CIO’s “brilliant at the basics” campaign aren’t really basic at all, and definitely represent an increase in the requirements that defense contractors have had since 2016. Post-quantum cryptography — or PQC, as the kids are referring to it — would definitely fit that pattern, even though it’s not specifically mentioned in this “brilliant at the basics” campaign.

Jason: Well, first and foremost, Jacob — “brilliant at the basics.” People hear “basic” and automatically shift back and think, “This is supposed to be easy.” And when we first came out, we were like, “No, no, no, that’s not what this is at all, you’re completely misinterpreting this.” And then I was able to go listen to the CIO explain “brilliant at the basics.” This is very important, because the words were: this is not meant to be easy. This represents foundational controls or concepts that should not only be present in systems that do business with the government, but realistically in every information system worldwide. And we want to be brilliant at it — we want to be the best at doing the most basic concepts of cybersecurity, because that’s where most of the network intrusions happening to the DIB are happening. They just so happen to be things that are included. PQC is the new buzzword everybody is talking about. There’s a whole strategy for it, and now it’s going to be the basic requirement.

Jacob: Yeah. Talking about the basics as not being easy, but being foundational — borderline assumptions about what the baseline ought to be — sounds a lot like NFO controls to me. If you all remember that episode from back in the day, we’ll link it below. NIST has been haunted by their assumptions about what they thought were basic, foundational things that they shouldn’t have even had to specify as a requirement. Sounds like it kind of rhymes. That’s a show for another day, though.

Let’s get into a quick primer on encryption. I know encryption sounds scary, but it’s a pretty easy concept to understand. At a very high level: encryption protects information using math problems that are incredibly difficult for computers to solve. Encryption not only hides information — which is what people normally think of — but it’s also the basis for how computers establish trust relationships. Is this really my bank I’m logging into? Is this really you trying to log in? Is this software update really from Microsoft? Has any of this information been altered in some way? Encryption is the foundation of pretty much every system you can possibly imagine at this point. The entire system around the world — the internet, everything you think of around technology — underneath all of it really is the system of modern encryption, even if you don’t see it directly.

Problem is, quantum computers threaten to make today’s really hard math problems really, really easy. Do you remember back in math class — school’s almost back in for everybody — you remember factoring? Remember how much fun factoring was? Y’all remember prime numbers? Well, it turns out we can create a really good lock to encrypt information based on factoring really, really big prime numbers, and that’s something essentially impossible for even today’s supercomputers to reverse the math for. That’s the basis for how this system works. Post-quantum cryptography replaces today’s math problems with new math problems, because quantum computers can solve that really hard math problem super, super easily. So post-quantum crypto is a new set of math problems designed specifically to be difficult for even quantum computers. You don’t have to know how quantum works — it’s super cool, you should definitely look into it — but essentially, post-quantum crypto is math problems that are hard for even the quantum, crazy sci-fi alien computers that are about to be a reality.

So the lock — the mathematical lock we have today for encryption — isn’t bad. There’s nothing wrong with it. But quantum computers are like a hyper lockpicking machine, and post-quantum cryptography, or PQC, is going to change the lock. They’re going to change the math problems before that hyper lockpicking machine exists — because without reliable cryptography, without reliable encryption, the entire system of trust that underpins the internet and all its technologies, and the basis for today’s civilization, collapses. So if you’re interested more in what PQC is, NIST has a great page — very high-level, very easy to understand, some awesome resources, we’ll link it below. But that’s the primer on encryption. It’s a big deal.

Jason: So yes, I agree, it’s a big deal. I have to explain this a little differently on the math concept. You used the math concept — I got lost. You started talking about prime numbers and factors. I understand PQC, but for the people at home, and for me, so I can keep up, I think about it like this: Do you know the Zach Galifianakis character from The Hangover, when he’s processing the numbers in his brain and they start highlighting and coming to life? Regular cryptography is two Zach Galifianakises and the same number highlighting at the same exact time. PQC is: replace Zach Galifianakis with my wife, and we’re trying to think of what my wife is thinking and highlighting those numbers twice at the same time — and just when the super-fast computers get there, my wife changes the thought, and the numbers change, and different things are highlighted. Did I nail it?

Jacob: Yeah.

Jason: Did I nail it?

Jacob: I think that’s a good one. I think that’s a good one. Maybe we can get NIST to update their page with those. Sure — “my wife.”

Okay, so encryption is a big deal. If encryption no longer works, nothing works. Quantum computers represent that threat. So we need a post-quantum form of encryption to make sure the world doesn’t burst into flames. So people in charge know this is a problem, and they’ve known it’s a problem for a while. Let’s talk about the sequence of events that led up to this issue — we love a history lesson around here. Congress told the government to prepare for this back in 2022, with the Quantum Computing Cybersecurity Preparedness Act. They are very worried about something known as “harvest now, decrypt later.” Essentially, you can take a bunch of data that’s encrypted, that you cannot decrypt today, hang on to it for a couple years, and then when you get a quantum computer, you can decrypt this information. Sound familiar, everybody? Just because they took your encrypted data now doesn’t mean that in two or three years they won’t be able to just press the button and decrypt it when the hyper lockpicking machine becomes a reality. So the threat means that post-quantum crypto migration has to start before the lockpicking machines are known to be operational. Just to let you think about how big of a deal this is — when was the last time you saw a real, legitimate effort by Congress before the bad thing happened, rather than after? That should be your immediate signal that this isn’t a joke.

Jason: Yeah, we 100% are reactionary in administrative nature, right? Something happens, and there are big efforts afterwards. So what you’re saying is, the harvesting method is essentially like — instead of taking the ATM machine and trying to crack it with the wrong tools at the 7-Eleven, you take it back to a warehouse where nobody knows where it’s at, the police won’t come, and you get the right tools — or when you can secure the right tools — to crack it under safety, right?

Jacob: Yep. “I’m just going to steal a bunch of ATMs that I can’t open right now, put them in a warehouse, and then in a couple years I’m going to have a perfect ATM-breaking machine, and then I get all the money.” So, give you a good example for current events. Congress waited until after the water stopped working in a bunch of towns across the country to start thinking about passing a law to require cybersecurity for water treatment centers. They didn’t wait until after the cryptography issue to pass a law to say we have to deal with this. They dealt with this before they dealt with the water getting turned off. It’s a big deal.

So after that law gets passed, it directs a bunch of people to do a bunch of things. The White House quantified the problem of PQC migration and laid out a federal migration plan in 2024, with the congressionally mandated report on post-quantum cryptography. We’ll link it below — it’s actually not that bad of a read, and this is going to affect you, so you should definitely read it. Long story short, they estimated the cost of converting everybody — the government, contractors, everybody — over to post-quantum crypto would be $7 billion, which definitely means it’s going to be two or three times that. So to migrate everybody, primarily the federal systems, between 2025 and 2035: $7 billion-plus, no questions asked. The reason they said it would be so expensive: some systems can be upgraded to support PQC; a lot cannot be upgraded to support PQC, for various reasons. And if the underlying technology can’t support PQC, it’s got to go. That was the vast majority of the reason they said it’s going to be in the billions of dollars to get everybody to switch over to PQC. And 2035 is not very far away.

Jason: So you’re saying that not all technology — and they’re aware of this — that’s deployed in the affected or impacted environment is capable of supporting what this baseline requirement is going to be. And for the ones that can’t, they’re going to have to be replaced, which is costly. $7 billion is already a big number, dude.

Jacob: It’s already a big number. And you know their estimate is going to be on the low end, for lots of reasons. Think about it — we see this all the time. People in contracting environments have struggled to turn on just basic FIPS validation, and it breaks systems. Now the algorithm, in addition to the validated module, has to be different — definitely going to break certain things, or just not be available at all. But we’re going to get to that in a little while.

So we have the act from Congress. We had the report from the White House. And then in April of 2026, the DoD published its subsequent post-quantum crypto implementation strategy for the department. They describe post-quantum crypto as an existential threat. They say the defense industrial base needs to catch up along with the rest of the department. They specifically say that CMMC will be updated to include PQC requirements. Remember, folks, this is in April, not July. And they straight up say — and I quote — “costs will be incurred,” before they set deadlines and say that by December 31st of 2030, DoD systems must support post-quantum crypto or get phased out. And by December 31st of 2031, those systems must use PQC, or they’re getting ripped out.

Jason: So DoD systems — that’s just specifically government-owned, right? Not the contractor systems?

Jacob: That’s right. That’s inside the DoD systems. But here’s the problem: the CMMC updating to the PQC requirements is troubling, because right now, isn’t FIPS-validated — FIPS 140-3 validated — encryption, like, number one of the “other than satisfied”?

Jason: Yep.

Jacob: And so we’re going to skip past 140-3 as the baseline and go straight to PQC? Apparently — we don’t know. It’s not in the basics. It’s not in the RFI. This was the strategy that came down from on high, from a law that Congress passed, back in April, and nobody was really talking about it. We’ll get to that wrinkle in a second. But anyways, in June there was an executive order signed that accelerated the transition and explicitly directed the government to develop a FAR rule and begin putting PQC requirements into all federal contracts — not just the Department of Defense. It’s going out to everybody. So it ain’t just going to be 800-171’s FIPS-validated requirements. Something’s going to change. You can bet your bottom dollar that NIST is going to update their guidance to include PQC, because they’ve already written standards for PQC-compliant encryption algorithms. But essentially, the last four years have been: Congress said, “This is a big deal, you need to prepare.” The White House scoped and priced the problem and said, “Yeah, this is going to be super expensive.” The DoD developed their implementation strategy and said it’s going to be super expensive, and you need to do it or you’re gone. And then the president came out with an executive order and said start putting this in contracts immediately.

Jason: So, obviously, one, it’s a big deal. But the question is, not how is it enforced, but — we know for a fact it has to be prescribed. If contractors aren’t told, “This is exactly what you need to do,” then sometimes it’s not what gets done. The “other than satisfied” once again proves that. So I ask you: how do they plan to make this shift?

Jacob: Well, there are still some open questions here. We can look at the DoD PQC strategy document itself, but it doesn’t answer a lot of the questions that are going to come up naturally. So — their strategy from April, remember, April, not July, this is nothing to do with the CMMC suspension, this is in April — they said, “To ensure the security of department information hosted on defense-industrial-base systems, the department will ensure that the DIB migrates to post-quantum crypto across the enterprise. The department will update CMMC to include requirements for post-quantum crypto.” Not “will consider,” not “will review,” not “will recommend,” not “will urge people to adopt.” They will update the requirements. The DIB will shift to these requirements across the enterprise. They don’t say “we’re going to think about it,” “we’re going to recommend it,” “we’re going to graduate the requirements,” “we’re going to have a phased rollout.” They don’t say any of the how it’s going to work. Clearly, that has to happen through DFARS clauses and specific requirements.

I’ll be honest — when this thing came out in April, I was like, “Okay, the PQC effort is a big deal.” But when I read on page 20 — which you can read for yourself — when the strategy document said, “We’re going to update CMMC to include requirements for post-quantum crypto,” I dismissed it, because I’m like, CMMC is a verification program. It’s not a set of requirements. There is no updating CMMC requirements. There is CMMC assessment guidance to validate that you’ve met the requirements, but the requirements exist outside of CMMC. They belong to NIST. They belong to DFARS. They belong to FedRAMP. They belong to ITAR. They belong to all these other things. CMMC just fits that hole left in DoD policy to verify that you’re doing those things. So I was like, that doesn’t make any sense, I’m not sure what’s going on here, let’s wait and see if there’s more info from the department about what they meant. And then July came around, and they were like, “We’re suspending assessments and reviewing the program,” and all their questions in the RFI — which we talked about on the show — are about requirements. So they’re clearly willing to bend the rules, ignore what’s in scope of the program and what’s not in scope, to bring in new ideas for what the requirements are going to be. Are they going to use this CMMC program review to then say you now have PQC encryption requirements? Because they’re going to do that eventually.

Jason: Dude, this is all tracking, because the vibe I’m getting — not just based off documents being released — like I said, I went to the listening session, and I came away from that listening session further confident that requirements aren’t disappearing. They’re modernizing. They’re becoming more applicable to today’s threats and things that affect and impact the DIB. But more importantly, now that I think about this, one of the underlying things I thought — and that was discussed in that listening session — was the overlap of requirements, and harmonizing requirements. Rev 3 stands out. Why does Rev 3 stand out? Because there’s an ODP that specifically calls out what, Jacob?

Jacob: Crypto. Encryption.

Jason: And so what if the crypto baseline — this pause allows us to move to Rev 3, and the encryption baseline is PQC, because it’s directed by the president?

Jacob: That’s a real thing. That is a real thing. And that tracks with the theme, because everything the CIO said was: there’s not enough requirements, 800-171 doesn’t go far enough.

Jason: “Brilliant at the basics is the source of all network intrusions. However, we think this is foundational for every information system. And there’s proof that it’s not happening.”

Jacob: And whether you think it’s foundational or not — Congress said you’re going to do this. This isn’t a “good idea.” This isn’t even the executive order saying it. Congress passed a law that said you’re going to migrate to PQC. There’s not a lot of wiggle room when it comes to stuff like that. That’s going to happen. But talking about that against the backdrop of the justification for the suspension — it was all about cost. It was all about cost. “This is too expensive.” Let’s talk about cost. The PQC strategy that the current DoD CIO signed — the same lady who was out there talking about cost a couple months later with the suspension — signed a strategy that says “costs will be incurred.” Costs will be incurred. The DIB will move to PQC. Problem is, there’s no cost estimate in the strategy. There’s no cost estimate for contractors. There’s no FAR rule. There’s no DFARS rule around moving to PQC. So they don’t know what the cost estimate is going to be. We’ve got that 2024 report that said for everything it’s going to be billions of dollars, but we can extrapolate from how that report got to billions to think about how this might be costly for contractors — because it ain’t going to be free.

So there are lots of current commercial post-quantum crypto solutions out there right now. Most of them are transparent, because they’re implemented by major cloud providers, infrastructure providers, things like that. So a lot of this stuff you won’t notice, because it’ll just be in the background. So a lot of ordinary vendor updates are going to cover a lot of PQC requirements, if you will, rather than “I need a specific PQC solution.” However, as we all know, when those infrastructure providers start to add new stuff, it ain’t free. So what do we think — $10,000? $50,000? Licensing costs go up, tenant costs go up, usage costs go up. They’re not going to migrate everything over to PQC — especially when there are big government mandates from Congress — and just do it out of the goodness of their hearts. It’s not going to be zero dollars. There’s going to be some cost associated with that.

Jason: Yeah, there’s no doubt. But do you think that the CIO’s office was cognizant of this — “we’ve got to trim fat”? It’s like — I don’t want to say “girl math,” but, you know, the term — or, golf math, right? Let’s use golf math so we’re not offending anybody. Golf math: I really got seven strokes, but you gave me that free drop because you talked during my backswing or you sneezed, so really I got a par, right?

Jacob: That birdie? Yeah.

Jason: Yeah, yeah, exactly. And so is that the case — like, if we take away from maybe the documentation overhead, or the assessment and stuff, then we can justify some of these more mandatory upgrades to keep us up with today’s [threats]? That’s what it’s feeling like — more than “this is such a burden, C3PAOs are so bad.” I still have yet to hear anything that said the CMMC assessor, the C3PAO, was the source of the reason why things…

Jacob: Well — I mean, that’s 10 to 50K if all your updates are just transparent in the background. If you’re dealing with anything internal with crypto setups — applications, internal PKI, legacy infrastructure — that 10 to 50,000, you might as well just 10x it right now. Now we’re not even anywhere close to what a CMMC C3PAO assessment was going to cost. I don’t know how much you’re going to trim from 800-171, if you were even willing to reduce the requirements, but it ain’t going to come anywhere close to offsetting that. If you’re dealing with manufacturing environments, legacy-heavy environments, embedded systems that cannot be upgraded, old ERP, operational technology — which the DoD CIO is very, very excited to have requirements for — straight-up replacement of those systems is going to stretch from hundreds of thousands of dollars to millions of dollars, without question. That’s how that estimate from the White House report got into the billions of dollars. They’re not going to grant waivers for a legacy manufacturing environment when Congress was like, “This is the threat,” because anywhere the data is existing can just be picked up and then decrypted later. It’s not about you, the small business — it’s about the data.

Jason: So the term you were looking for — “strategic technical debt reduction” — is what…

Jacob: Oh, is that the term? “Basics”? What do you know.

Jason: Yeah, because that — no, but literally that’s what it is. Strategically, we have to get rid of the technical stuff we’re paying for that doesn’t meet the requirements we must meet. This legacy system has to go. It can’t be upgraded to the standard we need it to be.

Jacob: Well, I cannot wait. I’ve said this before, said it in other forums — I cannot wait to see how they thread the needle on this one, because they came out guns blazing in July saying cost, cost, overhead, overhead, complexity, and now they’re clearly going to do PQC mandates that are going to cost a ton of money. How do you make those two things square up? I’m not saying it’s a bad idea, or that it shouldn’t happen — but I’m not the one that came out demonizing the cost of requirements from 10 years ago as being too expensive. You think this is going to be cheaper? The government’s own resources here say this is going to be crazy expensive. You want companies to leave the DIB? A great way to make companies leave the DIB is to tell them they’ve got to rip and replace their entire manufacturing environment.

Jason: Yes. If people have to completely replace their entire system, I agree with that. I do have a question for you. Does the financial impact of this shift — is that a review that has to take place before the shift takes place?

Jacob: Yeah. As part of the FAR and theoretical DFARS clauses, wherever this shows up, they would have to estimate the cost impact — especially if there’s going to be a FAR rule, there will absolutely be a regulatory impact analysis that will have the cost estimates. So we’ll have to see what it comes up with. That’s definitely coming. Here’s the thing: the DoD in the past has used opportunities to impose requirements ahead of the FAR. That’s how we ended up with DFARS 7012 ten years before the FAR CUI rule. Are they going to do the same behavior here and go in front of the FAR with their post-quantum crypto requirements, with this opportunity that is the CMMC Phase 2 suspension? I don’t know, but based off what we’ve heard, it seems like there’s an appetite for that to be a possibility. So you guys need to be aware of the fact that this could be a thing. And for all you guys out there who were spiking the football about how CMMC’s dead, so these evil costs are going to die — I don’t know if that’s actually true. I don’t think that’s how this is going to work.

But, wrapping up here: suspending CMMC assessments doesn’t suspend the threat that motivated Congress to proactively pass a law saying that we’re going to be replacing technologies with PQC regardless of the cost. It certainly doesn’t suspend the next generation of requirements that DoD talked about in the strategy they published before the suspension. So, I guess, big picture — are we just going to spend the next four years actually getting ready, or is everybody going to wake up in 2030 and be like, “Nobody saw this coming, this is all a big surprise”?

Jason: Like and subscribe for more breaking news that we’ll be able to point back to in the future. But this is the same pattern over and over again, right? People don’t know that this is coming. The DoD is putting all this information out. They’re going to wake up to a new requirement in a year or two — maybe, maybe sooner — and then they’re going to go, “This is ridiculous, we’re not going to do it,” and we’re going to go around and around a circle. And I don’t think they’re going to be able to suspend a PQC requirement until PQC-2, right?

Jacob: Oh my god. Well, there you go. Before you know it, folks, now you’ve got to be aware of PQC stuff. There are some awesome links below — make sure you go check those out and get familiar with what’s going on. This definitely won’t be the last time that we’re talking about it. But, like and subscribe. We’ll see you next week.

Jason: See you next week.

Contact

Speak With Our Team

Scroll to Top