Key Takeaways
- The Department of War’s suspension of CMMC Phase 2 offers a chance to redesign cybersecurity accountability for the defense industrial base (DIB).
- Current compliance relies heavily on self‑attestation of NIST SP 800‑171 controls, which lacks verification and creates an honor‑system gap.
- An enterprise‑wide model that couples independent assessment, continuous external monitoring, and shared remediation can reduce administrative burden while improving real‑time risk visibility.
- Shared funding for monitoring and remediation—such as the proposed $50 million assessment grant—should be expanded into sustained support for small suppliers.
- Prioritizing mission risk over procedural checkboxes will make cybersecurity more effective, especially against AI‑enabled adversaries that quickly exploit weak links in the supply chain.
Overview of the CMMC Phase 2 Suspension
The Department of War’s decision to pause Phase 2 of the Cybersecurity Maturity Model Certification (CMMC) program interrupts a rollout that many contractors found costly and complex. This hiatus is not a setback but an opening to rethink how the DIB is protected. By stepping back, the department can evaluate whether the current framework truly mitigates cyber threats or merely adds paperwork without measurable security gains.
Why the Existing Model Falls Short
Before the suspension, the author viewed CMMC as a misaligned effort: America’s cyber defenses had been tuned for audit success rather than threat resistance. The DIB, a sprawling, loosely coupled network of suppliers, cannot be secured by documentation alone. Adversaries equipped with AI‑driven reconnaissance can locate and exploit weak points faster than traditional compliance cycles can respond.
The Persistent Threat Landscape
While the DOW reviews CMMC, hostile actors continuously scan internet‑facing systems for exposed services, weak identity controls, unpatched software, misconfigured clouds, and suppliers whose advertised security posture does not match reality. These probing activities underline the core lesson behind CMMC: attestation without verification leaves critical gaps that adversaries are eager to exploit.
What CMMC Actually Adds
CMMC did not create new cybersecurity requirements; contractors already must implement NIST SP 800‑171 for handling Controlled Unclassified Information (CUI) and attest to that implementation. What CMMC introduced was a mechanism to test those attestations. Without independent verification, self‑assessment functions as an honor system backed only by a federal contract—a fragile foundation for protecting national‑security data.
Limitations of Internal Controls
Many NIST SP 800‑171 controls—such as policies, training, access reviews, and incident‑response drills—produce evidence that is internal and document‑based. External observers cannot directly see whether these practices are effective. Conversely, certain risks are most visible from outside the network: expired or self‑signed TLS certificates, exposed FTP servers, or outdated communication channels. Detecting these outward signs can signal where CUI protection may be failing, even if internal documentation looks satisfactory.
A Synchronized, Risk‑First Approach
If external monitoring highlights a problem—say, an exposed service transmitting CUI—teams can prioritize mitigation before a breach escalates. This synchronized strategy turns early warning signs into targeted actions, preventing a localized weakness from cascading into a full supply‑chain compromise. By focusing on mission‑critical risk rather than checking every procedural box, the DIB can allocate limited resources where they matter most.
Reducing Duplicative Burdens
An enterprise model would streamline compliance by eliminating repetitive queries from multiple prime contractors and government offices. Suppliers would undergo a single, rigorous independent assessment, after which continuous monitoring would keep the security posture current. This approach reduces administrative overhead, especially for small and mid‑sized firms that struggle to absorb the cost of multiple, overlapping audits.
Shared Responsibility Across the Supply Chain
Cybersecurity in the DIB is a collective duty of the War Department, prime contractors, and sub‑tier suppliers. Program offices must identify critical suppliers—even those buried four or five tiers down—that support essential platforms or hold sensitive technical data. A department‑led enterprise strategy can map risk concentrations, set priorities, and hold primes accountable for the security of their entire supply chain, ensuring that weaknesses at any layer are addressed.
Funding Continuous Monitoring and Remediation
The department should establish an enterprise fund that finances ongoing cyber monitoring and remediation for vital small businesses that cannot afford these services alone. Legislative efforts are already underway; the Senate’s FY 2027 National Defense Authorization Act proposes $50 million in CMMC assessment grants. However, a one‑time subsidy does not equal sustained protection. Continuous funding would enable real‑time threat detection, rapid patching, and coordinated incident response, lowering overall costs by preventing duplicated effort and reducing the likelihood of costly breaches.
Seizing the Moment for a Resilient DIB
Artificial intelligence will only accelerate the speed at which adversaries discover and exploit vulnerabilities. The pause in CMMC Phase 2 provides a unique window to institute a modern, enterprise‑wide accountability system that balances independent validation, continuous external surveillance, and shared remedial support. If the War Department adopts this approach—reducing unnecessary administrative burdens, preserving credible verification, leveraging enterprise monitoring to spotlight risk, and executing swift remediation—the pause will prove time well spent and will restore integrity to a faltering system. Failure to act will leave the DIB exposed, and the nation will eventually pay the price in compromised defense capabilities and eroded trust.
About the Author
Lonny Anderson, former Chief Technology Officer of the National Security Agency and current President of BlueVoyant Government Solutions, authored this analysis. His background in national‑security cyber operations informs his critique of existing compliance frameworks and his call for a more effective, threat‑focused strategy for protecting the defense industrial base.

