I built the Cybersecurity Maturity Model Certification because self-attestation was failing our war industrial base. Contractors could simply promise they were following basic cybersecurity practices, with no verification behind that promise. Our adversaries noticed that gap long before Washington did—and they have not eased up since. If anything, the opposite is true.
Nation-state actors and the ransomware crews they tolerate or direct are more aggressive, better funded, and faster than they were five years ago. This is not the moment to loosen the standard. The Defense Federal Acquisition Regulation Supplement requirements behind CMMC should not change, and I would not support it if they did.
But defending a program doesn’t mean pretending it’s perfectly aimed. Now that CMMC is a final rule moving into real contracts, it’s the right time to ask: are we targeting it precisely enough? I don’t think we are yet—and artificial intelligence, used correctly, can help fix that without touching the cybersecurity bar itself.
The problem is targeting, not the standard
CMMC’s requirements hinge on controlled unclassified information. But CUI determinations across the war industrial base are inconsistent: Two subcontractors doing nearly identical work can end up with completely different assessments because the call still depends on manual judgment with incomplete visibility into how data actually flows down. Some small businesses get pushed into heavy assessment burdens for data that isn’t really CUI. Others handling real, sensitive data slip through with a lighter requirement. Neither outcome helps national security; the first wastes compliance dollars, the second leaves real exposure unaddressed.
AI can do the first-pass sorting here—flagging likely CUI from contract language and statements of work and catching mismatches between what a prime contract designates and what actually flows down to subcontractors — far more consistently than today’s patchwork of manual reviews. In this scenario, a human with contracting authority still makes the final call. But that human should be working from a much better starting point than we give them now.
Small business is the economy, not just the supply chain
Small businesses are 99.9% of American companies and employ nearly half the private workforce. And right now, they face threats most aren’t equipped to handle: ransomware that can shut down operations overnight; AI-enabled fraud that’s harder to spot every year, and a coming reckoning when quantum computing breaks today’s standard encryption. The quantum threat is already real, since data harvested now can simply be decrypted later.
I’m glad the Small Business Administration is leaning into this. Its Cybersecurity for Small Business Pilot Program has done real work funding training through state partners. But training grants aren’t capital, and no amount of counseling gets a small manufacturer through a ransomware recovery or a quantum-resistant encryption upgrade. Small businesses can’t get favorable financing for cybersecurity the way they can for equipment because most lenders don’t know how to underwrite it.
We need a dedicated SBA loan program for cybersecurity investment—open to every small business, not just those working with the Department of War—to fund things like multi-factor authentication rollouts, endpoint detection, incident response, and early migration toward quantum-resistant encryption, before it’s an emergency instead of a plan.
Same mission, two fronts
Inside the war industrial base, use AI to make sure CUI calls and flow-down match reality. Outside it, give the broader small business economy the capital to defend itself against adversaries who are only getting more aggressive. I still believe unverified promises are not a security strategy. But precision and support aren’t the enemies of security—they’re what make it sustainable.
Sharpen how we target CMMC, and open the door for every small business to invest in its own war footing. That’s not lowering the bar. That’s making sure the bar is doing its job.
Katie Arrington is a former South Carolina state legislator and cybersecurity executive who served as DOD CISO for Acquisition and Sustainment starting in 2019, and later returned as DOD CISO/PTDO DOD CIO under the second Trump administration. She spearheaded the Pentagon’s initial efforts to create the CMMC program for defense contractors beginning in 2019, driven by a conviction that contractors needed to actually prove — not just self-attest to — their cybersecurity compliance in order to protect sensitive defense data from adversaries. Her commitment to the program has been described as stemming from a deeply personal mission to secure the Defense Industrial Base from cyber threats that jeopardize national security.
