DoD Paused CMMC Due to Costs. Now Costs Are Going Up.

The hosts dissect a National Defense Magazine article in which anonymous DoD officials defend “brilliant at the basics.” Their verdict: the defense is a self-contradiction — the DoD suspended CMMC over cost and burden, then handed contractors a list of more advanced, more expensive requirements, and dismissed anyone who points that out as not “understanding the modern threat.”

Key takeaways:

  • Everything’s anonymous. The DoD’s premier post-suspension recommendations are defended entirely by unnamed sources — “a player to be named later.” If you want buy-in on a new initiative, put a name behind it.
  • The MFA contradiction. Phishing-resistant MFA is better security — that’s not the debate. The problem: plain MFA is already the #2 most-failed requirement in DIBCAC findings (pre-CMMC), so suspending assessments won’t magically get people to adopt an even harder version. If CMMC verification were the blocker, why weren’t people doing MFA before CMMC existed?
  • “You don’t understand the threat” isn’t an argument. The official’s line — that calling this contradictory reflects a “fundamental misunderstanding of the modern threat” — dodges the actual cost/burden point.
  • OT expansion = CMMC Level 3 by another name. “Secure from the factory floor to the tactical edge” pulls OT fully into scope, which at Level 3 the DoD’s own final rule estimated would cost millions — the opposite of reducing burden. And “dynamically updated asset inventory for your entire enterprise” has no scoping in it.
  • The real costs are 800-171, not the assessment. Per NDIA’s 2024 survey (unrelated to assessment cost): ~49% spent >$100K to implement 171, and ~45% spend >$100K/year just maintaining it. Expanding requirements makes those numbers go up — while claiming to cut costs.
  • Quick-start guides won’t fix a staffing gap. NDIA found ~21–31% of respondents have less than one full-time person for IT or cybersecurity. Handing them a how-to flyer, with no verification, lands you right back where you started — which is exactly why a verification program exists.
  • Bottom line: if the DoD could, it would raise requirements tomorrow and hope for the best — worse for taxpayers, warfighters, and the companies that actually did the work, since their competitors don’t have to prove anything.

Transcript

Jacob: All right, folks. It is the end of August, and the only thing crazier than taking Rashee Rice over Saquon Barkley in your fantasy draft is what the DoD has to say about their “brilliant at the basics” cybersecurity campaign in a recent article by National Defense Magazine. Apparently, if people didn’t have to spend any money on CMMC verification, they would happily spend their time, money, and effort on cybersecurity controls that are more complex and more burdensome than what’s already in their contracts. And if that sounds stunningly unrealistic and completely out of touch to you — you’re right. And that’s what we’re going to talk about today.

Jason, DoD cracked the case. Man, I cannot get enough of the statements in this article. They cracked the case, they figured it out. Tell everybody.

Jason: Everybody share this article. The reason that cybersecurity in the DIB was so bad was that everybody was spending all of their time and money proving that they were doing cybersecurity in the first place, rather than actually doing cybersecurity. And now that third-party assessments are suspended, everyone’s going to go out and not just implement their current requirements — they’re going to go beyond what was even in 171 Rev 3, and even in CMMC Level 3. Case closed, everybody. We solved the problem.

Jason: Oh, who solved the problem, Jacob? Because I read the same article that you read, and apparently the person that solved the problem on the DoD side doesn’t want to be named. And this is a classic case. You brought up football, right? We’re going to go there. This is a classic case of an asset that is very valuable in one aspect being traded to a team for a player to be named later. And we’re going to decide how valuable that player is once we decide how valuable the quotes they put forward are. The truth here is: never in history has an anonymous source been super valuable at anything. Never in history has a player to be named later been better than the player that was traded before. And this blows my mind, because everybody is thinking that these “brilliant at the basics” steps that are going to be taken now are going to be made much easier — “we’re going to defend things because now we don’t have to get assessed.” Nobody was ready to get assessed in the first place. And the people that got assessed that weren’t ready weren’t doing these things.

Jacob: I mean, yeah. Oh, I just cannot get over the facts, folks. We’ll link to the article below, you have to read it. Please. I know we link a lot of stuff in the notes — you have to check this out. All of the statements that DoD gives about why “brilliant at the basics” isn’t a contradictory, expensive, completely nonsensical idea compared to the exact wording they gave for justifying CMMC — all of the statements are given by anonymous DoD sources. What’s wrong, guys? What anonymous sources? What are you talking about? This is your premier set of recommendations in lieu of the CMMC suspension. Why is no one putting their name to it?

Jason: Can we think about this for a second? I just had to tell my management that we’re not going to do CMMC Level 2 implementation anymore, because we have to do the “brilliant at the basics.” And they’re going to be like, “Well, who said that ‘brilliant at the basics’ thing?” Nobody knows.

Jacob: Nobody knows. Okay, let’s just do the— It’s a new initiative, right? You want people to buy into an initiative, put a face behind it. This is the thing, this is the answer. Okay. Let’s just talk about “brilliant at the basics” real quick, get everybody caught up in case you’re not familiar. Back in July, the DoD suspended CMMC Phase 2 and launched a review of the program. That’s the part that got everybody’s attention, that got all the headlines. The same day — the thing that didn’t get as much attention — the DoD published their “brilliant at the basics” campaign, a top 10 list of IT cybersecurity best practices, and a catalog of 10 ways to secure operational technology. 20 different items that they said, “These are the brilliant basics. These are the basics you need to be brilliant at, or whatever. These are the things we want people doing.” And as we talked about in a recent episode, there’s one big problem: the recommendations are more advanced, more expensive, more expansive versions of existing requirements. And some of the recommendations are entirely new requirements.

Jason: And the ones that aren’t entirely new requirements, they’re enhancements to already-existing requirements that nobody’s doing. MFA — we just boosted MFA. Nobody’s doing MFA better than the people that are in a better place, right?

Jacob: Hey, we’re going to talk about it. We’re going to talk about the MFA thing. We’re going to talk about this stuff. And then you said they published a catalog — it’s not a catalog. It just says “do this.” Do phishing-resistant MFA.

Jason: Do phishing-resistant MFA. It’s “do what it says.” Yeah. Update your legacy systems, right? And prove—

Jacob: Well, hey, let’s be fair — let’s look at what this anonymous DoD source told the reporter for this article about what’s going on here.

Jason: Oh, okay.

Jacob: First contradiction — because my quotes in the article talk about how this is a blatant contradiction to what the DoD is saying everywhere else, right? So, the first contradiction: phishing-resistant multifactor authentication. Right off the bat, just like we said in the previous episode, phishing-resistant multifactor authentication is better security than replay-resistant multifactor authentication, both of which are better security than vanilla multifactor authentication. It is better security. If you wanted to have better security, you would do phishing-resistant MFA. That’s not the debate here. So, like I told National Defense Magazine, the Pentagon cited the cost of compliance as a reason for the pause of the CMMC program, but at the same time it has provided companies these lists of practices that would dramatically expand the scope of the program. And that’s contradictory — to suspend CMMC verification because of the costs and the burden it places on small businesses, then turn around and tell them that we’re actually increasing your requirements at the same time. It’s going to be burdensome and it’s going to cost money.

So in the article, the unnamed Pentagon official said the premise that implementing high-impact security measures such as phishing-resistant MFA is too burdensome compared to standard compliance preparation “represents a fundamental misunderstanding of the modern threat.” I’m sorry — apparently, according to this anonymous DoD person, pointing out that this is a contradiction, whether it’s me or any of you listening, is a misunderstanding of the modern threat. You just don’t know what you’re talking about, if you think they are being inconsistent by increasing what they want people to do while also talking about things being too expensive and burdensome. This official goes on to say that “brilliant at the basics” empowers defense-industrial-base partners to redirect critical time and resources to the core technical controls that actively stop threat actors, and that by removing paralyzing administrative costs, the department ensures companies can invest directly in the technical defenses that actually secure the supply chain. Apparently, according to this anonymous DoD person in the DoD CIO’s office, the only thing that was preventing people from implementing a form of multifactor authentication that isn’t required was preparing for a CMMC assessment. And if you think that’s too burdensome, you’re the problem, because you don’t understand the threat.

And here’s the best part, here is my favorite part, everybody. The weird thing is that multifactor authentication of any form is the number two most commonly failed requirement in DIBCAC audits — that come from findings before CMMC started showing up in contracts. So how does suspending CMMC assessments give people more time and money to comply with a form of requirement that people weren’t doing before CMMC existed?

Jason: Yeah. So it’s redirective parenting. It’s what it is. I’m redirecting your attention and your energy to something else that will be more fruitful to the outcome than having you direct the energy to this thing that I don’t want you to direct the energy to. And for no reason whatsoever — I just don’t want you to direct the energy to it. “Here, go bang on the pot real quick.” So now, essentially, the time and money and people that were dedicated to preparing documentation and getting evidence ready and sitting through an assessment to prove that controls were implemented and in place are now being redirected to the burden of the overhead attached to transferring from a regular MFA to a phishing-resistant MFA — making sure the technology is aligned. And that’s not the only thing here. So, okay, we understand the threat, we said it’s better security, better positioned for today’s day and age. What we’re telling you is that the burden to implement and maintain is where it’s going to lie. But the solution in the article, right — it’s a how-to guide. I mean, if it were true that the burden of CMMC [was the issue], we just needed a flyer, Jacob?

Jacob: If the burden of CMMC verification is what was preventing people from doing this, then why weren’t people doing it before CMMC verification existed? Oh, I’m sorry — I just don’t understand the modern threat, apparently. And that’s why I don’t get it, and you don’t get it, and all of you listening and watching out there don’t get it. You’re the problem, not this logic, which is clearly not logical. Let’s move on here. Why are there not 10,000 false starts? Why are there not all of these things where people tried and were like, “You know what, the burden of the CMMC, it’s just too much for me”? Why would the DoD IG have found in 2019 that contractors weren’t complying with their requirements? Was that because they were too busy dealing with CMMC — a program that didn’t start showing up in contracts until the end of 2020, five, six years later?

Jason: All right, all right.

Jacob: All right, let’s move on. We talked about phishing-resistant MFA. We haven’t talked about really any of the other requirements yet — we’ll go into more detail in future podcast episodes. But let’s talk about this operational technology scope expansion. So according to the article, the anonymous department official said that the operational technology top 10 list was included because “adversaries do not differentiate between IT and OT. They target the entire manufacturing and sustainment pipeline. The critical machinery used to design, produce, and maintain our weapon systems relies on OT that, if compromised, could halt national defense production.” The anonymous official said the practices in the OT top 10 list ensure that when critical systems are delivered to our warfighters, they are secure from the factory floor to the tactical edge, “shifting the focus from checking compliance boxes to establishing defensible, threat-resistant operational architecture.” You know what that sounds like? That sounds like CMMC Level 3, everybody. Because at CMMC Level 2, operational technology assets are classified as specialized assets, which means not all the requirements will apply to them — sometimes they might not even be included in your assessment scope. There’s all kinds of ways for you to carve out difficult, complex, advanced, expensive security considerations for operational technology, for a purposeful reason — to reduce cost, burden, money, and impact on people affected by CMMC Level 2. Those rules do not apply at CMMC Level 3. OT is in scope. All the requirements are in scope. More advanced requirements are in scope. And you know what the DoD said when they decided to do that? It’s going to cost people millions of dollars. Their cost estimates in the final rule for CMMC Level 3 — which actually are the only new requirements that were forced on contractors — were to the tune of millions and millions of dollars. Here, this anonymous DoD official, this program, these recommendations endorsed by the DoD CIO, are tantamount to CMMC Level 3 impacts that are going to cost millions of dollars. But don’t point out that that’s a massive, blatant contradiction to the cost, burden, and impact concerns that led to the suspension of CMMC Level 2, because you just don’t understand the threat, everybody.

Jason: All right. So, understanding more of the threat here probably is what needs to take place. And more of the threat is the availability of the systems to make the missiles, or whatever it is that goes to the warfighter, right? What this anonymous official, I think, was trying to say is that’s what we’re concerned about — the availability of the—

Jacob: Well, of course, as you should be.

Jason: And the reports — I’ve been in the listening sessions, I’ve been at SBA roundtables, I’ve been in different things — and the one theme that has come from manufacturers, people with OT, from this perspective, has been the widespread applicability of the requirements to things that don’t necessarily need it. Now, if you could scope that down — but that’s not the reality.

Jacob: That doesn’t sound like scoping to me. They say validate “floor to the tactical edge.” I mean, it sounds like everything. If you look at their “brilliant at the basics” number two for IT, they talk about asset inventory — they want it dynamically updated for your entire enterprise. There ain’t nothing in there about scoping.

Jason: So “dynamic” doesn’t mean that. So once a year — is that dynamic? Is there a dynamic update?

Jacob: You know, listen — DoD apparently says we don’t understand how the threat works. Apparently they don’t understand how a freaking contract works, because all the stuff they’re talking about ain’t in the contracts, right? We’re just hoping that people are going to do it, because we didn’t make them do the verification. But let’s talk about that for a moment. These are not our numbers. These are not DoD’s estimates. Let’s talk about cost as reported from NDIA’s members. So, in response to the CMMC review request for information, NDIA included some data from their 2024 cyber survey of defense contractors. They specifically asked companies about the costs to implement and maintain NIST SP 800-171, unrelated to the cost of CMMC assessment and certification. Just the cost of complying with 800-171. The results from NDIA: 49% of contractors spent more than $100,000 to implement the requirements in 171 Rev 2; 28% spent more than $500 grand; 16% spent more than a million; and 12% spent more than $2 million. And those aren’t just the startup costs, because NDIA went on to say that 45% of respondents spent more than $100 grand maintaining the requirements, and that 20% spent more than $500,000 a year maintaining compliance with NIST SP 800-171. Again, none of that has anything to do with the cost of a CMMC assessment. Those are the costs, as reported by NDIA, of complying with what’s required in DFARS 252.204-7012.

The department suspended third-party assessments, but now the DoD wants to expand the requirements, which means those numbers, independent of CMMC, are going to go up. They’re going to get bigger. But you suspended it because the costs are too high.

Jason: Let’s be clear here. The burden that was reduced by the pause is not any of these numbers that were just reported right here. These numbers still exist — the things that they say you still have to do.

Jacob: These are the reported numbers from NDIA’s member base in 2024. This is what it costs to maintain and implement it.

Jason: None of it is maintaining— I guess obviously you’ve got to maintain the requirements for a CMMC assessment, but realistically none of it is directly linked to the CMMC assessment, and none of it’s going to get reduced now that this pause has happened.

Jacob: It is stunning to me. Based on what’s still in place right now — let’s not be absolute here with any of our estimates. This is all just talk, this is all just posturing, because they haven’t gone through rulemaking. Take those “brilliant at the basics” requirements and put them through the rulemaking cycle, please. I cannot wait to see them try to put those requirements through rulemaking, because you know what you have to do in rulemaking? You’ve got to estimate cost and impact. Good freaking luck taking this massive expansion of requirements and making it look like it’s going to cost less, and then telling everybody in the public comment responses that they just don’t understand the threat.

Jason: Can I ask what would cost less? What would cost less — all of the things that have to happen to go through that rulemaking process, or bringing the basics to be evaluated, blah blah blah? Or teaching your people how to mark CUI appropriately? What would cost—

Jacob: Hey, I mean, yeah. And by “your people,” we mean it costs everybody less. By “your people,” we mean the people that don’t even work for you — because the program doesn’t work for the DoD CIO. So that’s a topic for another day. But okay, let’s just say we don’t have any idea what we’re talking about. We don’t understand the threat. These are ridiculous accusations, that they’re contradicting themselves, and that by suspending third-party CMMC assessments, we have now unleashed all of these contractors to have clearly piles of money to dedicate toward implementing things that aren’t even required in the contract. How exactly are they going to do it? So, the department — and this is a quote — “the department plans to convert the top 10 lists into companion resources, such as quick-start guides, to help companies rapidly adopt key controls like phishing-resistant MFA without requiring expensive external consultants.” The anonymous DoD official said, “By integrating these straightforward materials into our ongoing industry outreach” — you didn’t go to Gold Coast — “and acquisition reform efforts, we are ensuring that basic cyber hygiene becomes a standard, accessible starting point for any business partnering with the department.” Back over to the NDIA findings, folks. Over 21% of the respondents have less than one full-time-equivalent employee who manages or supports IT for the organization. And over 31% of respondents have less than one full-time-equivalent employee who manages or supports the organization’s cybersecurity efforts. “And despite the challenges of complying with department cybersecurity standards, many organizations do not have a full-time person on staff to even manage these efforts.” End quote. So I ask you, everyone out there — who exactly is going to be using these quick-start guides?

Jason: Given the fact that you are a non-DoD official giving quick-start guides to an environment that you now know, as a result of NDIA’s comments to you, that they can’t do anything with — how do you have any confidence that it’s going to get done? It’s almost like you need a verification program regardless of what the requirements are.

Jacob: Hey, we’re right back where we started, everybody.

Jason: I think what the anonymous official was trying to say is that we actually don’t understand the threat to us as a customer. Clearly. And the threat to you, of us as a customer, is: you’re going to assume that people are going to do all of these more expansive things — which I do not disagree are better for today’s modern threat. 100%.

Jacob: They’re only better if they’re implemented and maintained, and the workforce to do it does not exist. I’ve seen it for almost the past decade. You’ve seen it. The DoD IG has seen it. GAO has seen it. DoD’s sponsored industry research through the MxD manufacturing report has seen it. Every industry report, from Merrill Research to Sera-Brynn and everybody else, has seen it. Congress has seen it. We’ve all seen it. We all know what’s going on here. But according to this anonymous DoD official, you’re the problem, folks. So make sure you read this article. Make sure you send it to everybody. Please share it out there. Because if DoD could press a magic button, they would increase your requirements to this higher, more expensive, more complex standard tomorrow, and they would just hope for the best. They’re not solving the problem that they claim they wanted to solve, and they have less assurance that any of it’s actually getting done — which is bad for the taxpayer, bad for the warfighter, bad for everything. It’s bad for people who are actually doing the requirements, because the people you’re competing against don’t have to prove that they’re doing the same thing that you are. On and on and on again. It’s like we’ve done rulemaking for this since 2011, and we’ve covered all these issues before. I can’t believe it, folks. I cannot believe that they said what they said in this article. It is unbelievable to me. Typically, these are the things that they say not on the record. It was from an anonymous source. What an early Christmas present. I cannot believe it.

Jason: You say Christmas, I say Groundhog Day. I feel like Bill Murray.

Jacob: There you go. Well, folks, happy August. We’ll see you next month — technically. And make sure you like and subscribe. We’ll see you next week.

Jason: See you next week.

Contact

Speak With Our Team

Scroll to Top