Summary
Brilliant at the Basics significantly expands DoW expectations beyond NIST 800‑171 r2/r3, adding tougher identity, asset, AI, OT, and resilience requirements. Despite being framed as “simplification,” it increases complexity, tooling, staffing, and cost for DIB contractors already struggling with existing baselines and CMMC readiness.
The Department of War (DoW) Chief Information Officer’s (CIO’s) “Brilliant at the Basics” campaign is positioned as a simplified set of foundational cybersecurity practices meant to help small, midsize, and nontraditional Defense Industrial Base (DIB) suppliers secure their networks and deliver superior technology to the warfighter.
The problem is, calling something ‘basic’ doesn’t actually make it simpler:
- The initiative promises reduced administrative burden, with less compliance overhead and a clearer path to cybersecurity maturity.
- In reality, “Brilliant at the Basics” expands expectations well beyond National Institute of Standards and Technology (NIST) SP 800-171 Revisions 2 and 3 (r2 and r3).
Had these suggested capabilities been mapped out to controls, it would be evident how much more difficult these suggestions are. To be enforceable, there would need to be something to be measured against, and that doesn’t exist yet for brilliant at the basics.
On the surface it is being passed off as basic, but underneath (depending on exactly what is defined as required later on) contractors would have to implement increasingly more difficult-to-execute solutions than what’s currently required.
Brilliant at the Basics vs. Cybersecurity Maturity Model Certification (CMMC)
Most DIB contractors are still trying to put NIST 800-171 r2 in place; almost none of them are even considering NIST 800-171 r3, which is soon to be the baseline for protecting Controlled Unclassified Information (CUI) under FAR CUI. Even so, the “Brilliant at the Basics” framework sits above both versions in terms of technical expectations.
While messaging emphasizes “simplification,” 9/10 IT practices extend well past what is required today.
Brilliant at the Basics
- Informal guidance campaign, from the DoW CIO; not a new rule or contractual requirement
- Extends beyond NIST 800-171 r2 requirements that the DoW has called too expensive
CMMC
- Ties directly to contract eligibility
- Contains assessable practices
- Would be pushed to the NIST 800-171 r3 baseline with Federal Acquisition Regulation (FAR) CUI
As the upcoming FAR CUI rule will soon move NIST SP 800-171 r3 as the baseline for CMMC, “Brilliant at the Basics” (BATB) could function as an overlay in addition to those requirements.
How Brilliant at the Basics Expands DoW Expectations
The “Brilliant at the Basics” (BATB) IT Top 10 is framed as foundational cybersecurity, but most items expand requirements for DIB organizations well beyond NIST SP 800‑171 r3 while many contractors still struggle to catch up to r2. Instead of simplifying cybersecurity, these practices introduce new complexity, new tooling, new staffing demands, and significant cost increases. They reshape identity, networks, development workflows, resilience planning, AI governance, and workforce expectations beyond what small and mid‑sized contractors are built to support.
How the IT Top 10 expands what’s in place:
- “Phishing-Resistant MFA”
- Relevant NIST Control:
- 3.5.3 – Multifactor Authentication
- A major uplift from standard multifactor authentication (MFA), requiring hardware-backed authenticators and identity modernization most contractors haven’t budgeted for.
- Relevant NIST Control:
- “Dynamically Updated Asset Inventory”
- Relevant NIST Control:
- 3.4.1 – System Inventory (Configuration Management)
- Unlike the simple inventory required by NIST 800‑171 r2, this calls for continuous discovery, automated scanning, and enterprise-grade asset management systems.
- Relevant NIST Control:
- “Strategic Technical Debt Reduction”
- Relevant NIST Controls:
- 3.4.6–3.4.9 – Least Functionality + Configuration Settings (Configuration Management)
- Here, technical ‘debt’ refers to the risks incurred by not updating or replacing legacy systems. This would effectively mandate system modernization and complete re-architecture, not incremental configuration improvements. Burden of proof would likely include an extended multi-year budget and replacement/upgrade plan.
- Relevant NIST Controls:
- “Flexible Technology Stack”
- Relevant NIST Controls:
- 3.16.01 – Systems Security Engineering Principles
- 3.16.02 – Unsupported System Components
Mandates - 3.16.03 – External System Services
- BATB pushes for multi-vendor interoperability and modular architectures. While nice in theory, integrating products from multiple vendors introduces significant cost and complexity.
- Relevant NIST Controls:
- “Logical Segmentation”
- Relevant NIST Controls:
- 3.13.1 – Boundary Protection
- 3.13.5 – Separation of Duties / Network
- True segmentation requires redesigning networks, identities, and workloads, not just enhanced boundary controls.
- Relevant NIST Controls:
- “Risk-Based Vulnerability Management”
- Relevant NIST Controls:
- 3.11.2 – Risk Assessment
- 3.11.3 – Risk Response
- 3.14.1 – Flaw Remediation (System & Information Integrity)
- This item aligns closely with 800‑171 r3, but BATB advocating for continuous, exploitability-driven prioritization.
- Relevant NIST Controls:
- “Shift-Left Security in the Development Lifecycle”
- Relevant NIST Control:
- 3.13.2 – Security Engineering Principles (System & Communications Protection)
- A significant expansion that demands tooling, pipelines, training, and development + security + operations (DevSecOps) processes.
- Relevant NIST Control:
- “Secure AI Adoption and Data Protection”
- No Relevant NIST Control
- A brand-new category that introduces AI governance, data governance and controls, endpoint restrictions, and new policies that most contractors do not currently have.
- “Resilient Backup and Disaster Recovery”
- Relevant NIST Control:
- 3.8.9 – Protection of Backup CUI (Media Protection)
- Immutability, isolation of credentials, and restoration drills represent modern resilience practices, not the more basic backup requirements of NIST 800‑171.
- Relevant NIST Control:
- “Continuous Technical Workforce Readiness”
- Relevant NIST Controls:
- 3.2.1 – Awareness Training
- 3.2.2 – Role‑Based Training
- 3.2.3 – Training Records (Awareness & Training)
- Moves awareness training to continuous, role-based technical development dramatically expanding workforce obligations. This is a substantial expansion of expectations under the guise of simplification placing new burdens on DIB organizations already struggling to meet NIST 800‑171 r2 and are far from prepared for r3.
- Relevant NIST Controls:
OT: A Parallel Expansion for Manufacturing Environments
The DoW CIO also introduced an Operational Technology (OT) Top 10 aimed at industrial environments such as Supervisory Control and Data Acquisition (SCADA) systems, robotics, and weapon system manufacturing. These expectations include validated OT inventory, strict segmentation, OT-specific incident response, system resiliency, supply chain security, and continuous monitoring.
Per the CMMC Level 2 scoping guide, OT has been included in the Specialized Asset (SA) category with a lower burden of control implementation and more focus on risk treatment. Many DIB manufacturers have never been required to secure OT environments at this depth. This list represents a major shift in operational cyber expectations.
What Changes
“Brilliant at the Basics” introduces several meaningful changes that could shape DIB cybersecurity over the next few years:
- Higher technical expectations across the board.
Many of the new practices require modern tooling, architectural redesign, or new processes.
- Identity expectations rise to phishing-resistant levels.
This will require stronger authenticators and changes to identity governance.
- AI security enters the mainstream.
The DIB will need to adopt guardrails for models, data access, and generative AI usage.
- Include resilient backup and disaster recovery architecture.
This means immutable backups, restoration drills, and availability planning rather than only protecting CUI backups - Continuous Technical Workforce Readiness.
Continuous readiness demands ongoing role‑based drills and upskilling, not just annual security awareness training
Note: OT systems will no longer be treated as separate or special. Manufacturers will face new security expectations for their production environments. OT requirements are well beyond current requirements and that the BatB program expects significant coverage of increased OT requirements.
What Stays the Same
Despite the expansion, several core elements of federal cybersecurity remain unchanged:
- NIST 800-171 is still the foundation.
R2 currently sets the minimum baseline for protecting CUI, and organizations must continue to implement and maintain those controls; r3 is still expected to become the baseline in 2026 with the upcoming FAR CUI Rule. Even if the DoW were to remove NIST 800-171 as the baseline entirely, many of the BATB requirements would still rely on the tooling put in place to meet the 800-171 requirements.
- Compliance documentation still matters.
Even as the government moves toward outcome driven procurement, system security plans, policies, and evidence remain essential.
- Risk management remains central.
The federal posture continues to emphasize risk-based decision making, prioritization, and resource allocation.
- Zero Trust stays the guiding philosophy.
“Brilliant at the Basics” does not replace Zero Trust; it reinforces and accelerates it.
- Identity, access control, logging, and vulnerability management remain foundational.
“Brilliant at the Basics” expands these, but the core principles stay intact.
Organizations should understand that their existing compliance work is not invalidated.
The Paradox: Reduced Burden, Higher Expectations
The DoW CIO messaging emphasizes reduced compliance burden. Yet simultaneously, “Brilliant at the Basics” requires significantly more sophisticated cybersecurity practices. While on their own, increased capabilities and better security sound great, the industry this guidance is meant to help does not have the tooling nor the capacity to do what’s laid out here.
What This Means for the DIB
If “Brilliant at the Basics” is enforced, the expanded guidance would outclass the upcoming standard of NIST 800-171 r3 before the majority of the DIB is ready for even r2, the standard currently linked to CMMC.
Summit 7 will continue analyzing “Brilliant at the Basics” and NIST 800-171 r3 to help you prepare for the evolving expectations across federal cybersecurity.


