Heads They Win, Tails They Win: The CMMC Trap and the Way Out

46 minutes ago 3
Chattythat Icon

Here is a prediction from inside the compliance trenches: the CMMC Reform Task Force closed its sixty-day review on September 11 and is now finalizing recommendations for the Department of War's Chief Information Officer, with a public report expected within weeks. When that report lands, read it knowing what its authors cannot quite say aloud — there is no good answer. Every option in front of them loses. The program they were convened to fix is not a regulation that went wrong. It is one move in a game an adversary designed.

The task force was stood up on July 13, when the Department abruptly suspended Phase 2 of the Cybersecurity Maturity Model Certification program — the requirement, set to begin appearing in contracts this November, that companies handling controlled unclassified information (CUI) pass a third-party certification before winning defense work. The Department's stated reasons: prohibitive compliance costs, a severe shortage of assessment capacity, and a Small Business Administration finding that the program is structurally incompatible with rapidly expanding the defense industrial base. The task force spent the summer digesting more than 1,100 responses to its request for information, and the department is reportedly moving to codify the pause in binding regulation — not the behavior of an institution planning a tune-up. The CIO herself has described the assessments as a 'burdensome, red-tape ridden, check-the-box, point-in-time view' of contractor security: the program's owner, describing her own program in the language of its critics. The patient's physician is confirming the diagnosis. Understanding why none of the options can work — and what to do instead — requires seeing the whole game.


The dial that cannot be tuned

The task force's mandate frames the problem as a tradeoff: cybersecurity assurance on one side, small-business burden on the other. Turn the dial toward assurance and the math is grim. The Pentagon's own rulemaking priced a single Level 2 assessment at roughly $102,000 for a small business, every three years — a floor, since the government counted only the assessment itself and treated the underlying security work as a cost contractors already owed. Real first-year figures run two or three times higher.

Spread across roughly 80,000 companies in scope — nearly three-quarters of them small businesses — the program costs, every year, what a major weapons system costs. Companies at the bottom of the supply chain do the arithmetic and exit defense work entirely, shrinking the industrial base the Department has declared it must grow.

Turn the dial the other way — relieve the burden, rely on self-attestation. We ran that experiment. NIST SP 800-171 has been contractually mandatory for defense contractors handling covered defense information since the end of 2017, enforced by self-attestation. When the government's own assessors began checking, self-reported scores collapsed on contact: companies attesting to full implementation were found, on inspection, to be far from it. Eight years of the honor system produced paperwork, not protection. That failure is the reason CMMC exists.

And here is the part the certification debate politely ignores: the assurance being purchased is weaker than advertised. A Level 2 assessment fans 110 security controls into 320 individually judged objectives. Only nine of the 110 can be satisfied by configuring a system; after two years of industry effort to automate verification, barely a quarter have any machine-checkable test at all. The rest — 85 of 110 — turn on an assessor reading documents, weighing evidence, and interviewing people.

Judgment at that volume carries an irreducible error rate, and errors compound across 320 determinations: even a superb assessor is unlikely to get all 320 calls right. The certification is a probabilistic judgment dressed as a binary guarantee — and we are proposing to charge small businesses six figures for it.

Every setting of the dial loses. That is not because the rule-writers were careless. It is because the dial's axis — assurance versus burden — was chosen by the adversary.

Their coin, our coin

Consider the campaign from the adversary's side of the table. A sustained intelligence effort against the defense supply chain wins on either branch. If exfiltration succeeds, the adversary harvests the output of America's research enterprise — the Department's research, development, test, and evaluation accounts now run to roughly $150 billion a year, and nearly all that work materializes as CUI on contractor networks: designs, test data, specifications. The results are visible in the air: F-35 design data stolen in the operation behind Su Bin's 2016 federal conviction later resurfaced in the lines of a rival stealth fighter. If exfiltration is resisted, the United States burns weapons-system-scale money on compliance overhead, small suppliers flee the industrial base, and defense modernization slows under its own administrative weight. Heads they win, tails they win.

This is cost imposition — the competitive-strategies logic the United States once ran against the Soviet Union, most famously with the Strategic Defense Initiative, which threatened to obsolete Moscow's missile force and pulled it toward countermeasure spending it could not afford. The same logic now runs against us at machine speed and negligible marginal cost. An intrusion attempt costs the attacker thousands of dollars; the defensive apparatus it provokes costs the defender billions. The exchange ratio is the attack. And no certification regime, however well designed, changes that ratio. It just selects which branch of the adversary's win condition we take. That is why the task force cannot regulate its way out: it is being asked to find the winning setting on a dial that has none.

The solution we forgot

The way out is not a better tradeoff. It is to stop playing this game — and the United States already knows how, because it solved this exact problem once and then forgot.

For eight decades, the National Industrial Security Program and its predecessors handled sensitive information in contractor hands on a simple two-tier logic. Information that genuinely mattered was classified: the government cleared the facilities, inspected them, provided counterintelligence support, and bore the cost — because assurance of its own supply chain was understood to be the government's problem, a cost of defense like any other. Information that did not rise to that level circulated freely. Both tiers were coherent, and the system carried the country through a fifty-year great-power competition.

Then came CUI — a third tier of 'sensitive but unclassified' created by executive order in 2010 — and with it a decision that looks stranger every year: push national-security-relevant information onto 80,000 private networks with none of the industrial security program's machinery. No facility oversight, no counterintelligence support, no government cost-sharing, and for eight years no verification at all.

CMMC is the decade-late patch on that omission — an attempt to rebuild a shadow industrial-security program on contractor money and commercial assessors. It is failing because the original lesson still holds: protecting information at national-security scale requires the government to run and fund the assurance, or the information does not stay protected.

Restore, don't invent

The reform the task force should recommend is not a better CUI regime. It is the end of CUI as a protection category — a return to the binary the country defended for eighty years: classified, or released.

The government has been trying to triage CUI honestly for sixteen years and has proven incapable of it. Since the 2010 executive order, the registry has swelled to dozens of categories applied so promiscuously that routine engineering data carries the same handling burden as weapon-system design detail. The incentive structure guarantees the outcome: marking is free, unmarking is career risk, and no official is ever punished for protecting too much. A bureaucracy that could not resist over-marking will not now triage its way to discipline. The proof arrived on September 2, mid-review: sixteen years after the executive order created CUI, the National Archives had to issue fresh guidance re-teaching agencies day one of the program — how to designate and mark consistently, and how to tell contractors what is actually controlled. A program whose executive agent must re-explain its founding act sixteen years in is not maturing toward discipline; it is demonstrating that it cannot get there.

So retire the category. Information whose loss would buy an adversary military capability moves up into classified channels, where cleared facilities, real defenses, and counterintelligence support already exist. The rest is released and protected by ordinary commercial hygiene. The classified system has room for this: every review from the Moynihan Commission onward has found it bloated with material of merely sensitive grade — declassify downward as the crown jewels move up, and the classified world need not grow at all. And to the objection that unclassified details aggregate into sensitive wholes: we ran the aggregate-everything experiment. It produced an unpayable mandate, an unprotectable perimeter, and eight years of uncontested collection. That is not risk management; it is risk relabeling.

The binary has one irreducible residue: export-controlled technical data. ITAR and the Export Administration Regulations restrict the largest slice of defense CUI by statute — the Department cannot release it by memo, and it cannot all be classified. That residue is where the second move lives: defend it wholesale, not retail. Eighty thousand self-defended machine shops is retail defense at the worst possible exchange ratio. A few hundred hardened, government-assured environments — enclaves and authorized platforms in which small contractors work with controlled technical data rather than each hosting it themselves — is wholesale defense: the defender finally gets economies of scale, verification shrinks to a population the assessment ecosystem can actually service, and the attacker's cost per useful intrusion rises instead of falling. Concentration creates high-value targets, yes. But a few hundred professionally defended environments with real detection beat 80,000 undefended networks even against a focused adversary — we know, because the adversary has treated the current arrangement as a self-service library since 2017.

Third, verify by sampling, with consequences. Keep self-attestation for the residual population, but back it with random government-led assessment at a rate high enough to deter — the model that keeps the tax system honest without auditing every return.

None of this is invention. Each element has decades of precedent; the task force is being asked to remember, not to imagine. The suspension of CMMC was not an admission that cybersecurity costs too much. It was an admission — perhaps not yet a conscious one — that the game as structured cannot be won at any price. The only winning move is to change the game: shrink what needs protecting, protect it the way we protected what mattered for eighty years, and stop letting an adversary's cost-imposition strategy set the terms of our industrial policy.

James Novakoff, MSTM, CCA, is an enterprise computer and security architect and Certified CMMC Assessor who provides engineering and security services to defense industrial base contractors. The views expressed are his own.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

Read Entire Article