DoD suspended CMMC Phase 2 amid concerns about cost and burden on small businesses. Now it is hoping those same contractors will embrace cybersecurity practices that are broader, more complex, and potentially more expensive than their existing requirements.
We break down DoD's remarkable explanation for its “Brilliant at the Basics” campaign, the push toward phishing-resistant MFA and broader operational technology security, and NDIA survey data showing what defense contractors already spend implementing and maintaining NIST SP 800-171 and how many lack the resources to manage those requirements.
Will the result of the CMMC Review be a more expensive cybersecurity baseline with less assurance that it is actually being implemented?
Register for Summit 7 Live: https://www.summit7.us/s7live
National Defense Magazine: https://www.nationaldefensemagazine.org/articles/2026/8/25/new-cyber-campaign-contradicts-cmmc-pause-expert-says
Brilliant at the Basics: https://dowcio.war.gov/BrilliantBasics/
DIBCAC Top 10: https://summit7.us/blog/tools-to-take-on-nist-800-171
2019 DoD IG Report: https://www.dodig.mil/reports.html/Article/1916036/audit-of-protection-of-dod-controlled-unclassified-information-on-contractor-ow/
Podden och tillhörande omslagsbild på den här sidan tillhör
Summit 7. Innehållet i podden är skapat av Summit 7 och inte av,
eller tillsammans med, Poddtoppen.