Status alert — verified August 17, 2026. Brilliant at the Basics is a voluntary Department of War CIO campaign. It is not a rule, not a contract clause, and has no standalone assessment or score. The Department's July 13, 2026 action suspended the planned transition to CMMC Phase II; Phase I self-assessment requirements remain in place. DFARS 252.204-7012 and the CMMC Level 2 baseline of NIST SP 800-171 Revision 2 remain operative.
By The Defense Compliance Report Editorial Team — an independent trade publication on CMMC and Defense Industrial Base compliance
Published: August 17, 2026 · Last reviewed: August 17, 2026
Educational research for the Defense Industrial Base — not legal, contractual, assessment, or compliance advice. Confirm scope and applicability with a qualified CMMC practitioner and contract interpretation with a qualified federal-contracts attorney before acting.
Brilliant at the Basics cybersecurity guidance is a Department of War Chief Information Officer campaign containing two lists of voluntary security practices for Defense Industrial Base companies: an IT Top 10 and an OT Top 10. It creates no standalone contract obligation, appears in no Federal Register rule, and produces no Brilliant at the Basics score or certificate. The campaign page describes the material as “for educational and informational purposes only.”
Bottom line: we mapped all 20 practices against the Department's published NIST SP 800-171 scoring methodology, requirement by requirement. The ten IT practices touch 19 of the 110 NIST SP 800-171 Revision 2 requirements, with an upper-bound exposure of 71 weighted points. The campaign alone still produces no valid SPRS assessment score, because it does not supply the current System Security Plan required to complete the assessment. Add that SSP, give the campaign the most generous defensible mapping, and do nothing else: the best-case ceiling is roughly negative 132 out of 110. Two of the ten IT practices map to no direct scored requirement at all.
The OT answer is not “all ten count” or “none of them count.” It depends on how each OT asset is classified inside your Level 2 scope. An OT system that processes CUI may be assessed as a CUI Asset. An OT system that provides a security function may be assessed as a Security Protection Asset. An OT system that can handle CUI but is not intended to may be a Contractor Risk Managed Asset. An OT system that can handle CUI but cannot be fully secured may be a Specialized Asset, documented and reviewed but not assessed against the other Level 2 requirements. An isolated OT system that cannot handle CUI may be out of scope. That distinction changes the score, the evidence, and the work.
That is not a criticism of the campaign. It is the most useful thing on this page, and we will show you exactly where it comes from in the regulation.
The Defense Compliance Report is an independent trade publication and decision resource for CMMC and Defense Industrial Base compliance — explaining the CMMC rule with primary-source citation and mapping a contractor's level, CUI scope, assessment type, and timeline to the right provider category before the contractor spends six figures. We are not affiliated with the Cyber AB, the Department of War, the Department of Defense, DCMA DIBCAC, NIST, or any U.S. government agency.
The 30-second verdict
Last verified August 17, 2026
| Question | Direct answer |
|---|---|
| What is it? | A Department of War CIO campaign with 10 IT and 10 OT voluntary security practices for DIB companies. |
| Is it mandatory? | No, not by itself. A specific practice may still be required by NIST SP 800-171, another clause, a prime's flow-down, or a negotiated contract term. |
| Is it a certification? | No. There is no Brilliant at the Basics assessment method, status, score, or certificate. |
| Did it replace CMMC? | No. CMMC comes from 32 CFR Part 170 and the DFARS acquisition rule, solicitation provision, and contract clause. A campaign webpage cannot amend them. |
| Did it replace NIST SP 800-171 Revision 2? | No. Revision 2 remains the CMMC Level 2 assessment baseline under the current rule. |
| Is it the interim enforcement standard during the Phase II suspension? | No — and this is the most repeated error about it. The July 13 release names NIST SP 800-171 Revision 2, enforced through self-assessments and select government-led assessments. |
| Does it change my SPRS score? | Not directly. Our editorial IT mapping reaches at most 71 weighted points. Without a current SSP, there is no valid assessment score; with one and generous assumptions, the ceiling is about −132. |
| Does CMMC score the OT list? | Sometimes. It depends on the asset category. CUI Assets and relevant Security Protection Assets are assessed; Specialized Assets are documented and reviewed but not assessed against the other Level 2 requirements. |
| Should you use it? | Yes, selectively. It is a strong security-prioritization list. It is not a complete CMMC program. |
| What sets your actual obligations? | Your solicitation, contract, subcontract or purchase-order flow-down, the information you handle, the systems that touch it, and the required CMMC level and assessment type. |
Start where you are
| Your situation right now | Go here first |
|---|---|
| “I saw this and I can't tell if it's a new requirement.” | Is Brilliant at the Basics mandatory? |
| “My MSP sent me the PDF and wants to quote the whole list.” | What each IT practice is worth |
| “Someone told me this is the new standard during the pause.” | What the July 13 release actually says |
| “We run machines. Does the OT list count for anything?” | The OT asset-category decision |
| “My prime is asking about phishing-resistant MFA.” | Why MFA is item number one |
| “Just tell me what to do in the next month.” | The first 30 days |
| “I don't know whether I need an advisor, an MSP, software, an enclave, or an assessor.” | Choose the provider category first |
What is Brilliant at the Basics cybersecurity guidance?
Brilliant at the Basics is a voluntary cybersecurity campaign published by the Department of War Chief Information Officer for Defense Industrial Base contractors. It contains two numbered lists — ten practices for information technology environments and ten for operational technology environments — plus a library of linked resources from NIST, CISA, NSA, DC3, and the Department. It is security guidance, not a compliance status, and the campaign carries no assessment, no score, and no certificate.
We read the campaign page on August 17, 2026 and pulled both source documents. Here is what is actually there.
The page describes itself as a Department of War CIO initiative for DIB partners, with an explicit focus on small, mid-sized, and non-traditional companies. It publishes two downloadable one-pagers:
- IT Top 10 —
Brilliant-at-the-Basics_IT-Tipsv1.pdf - OT Top 10 —
Brilliant-at-the-Basics_OT-Tipsv2.pdf
A small detail worth noting because it gives you a version-control problem immediately: the OT sheet is already on version 2 while the IT sheet is still on version 1. Neither PDF carried a visible revision date when we reviewed it. If you are keeping a compliance or governance file, save both with the retrieval date. A filename changing quietly is not a change-control system.
Below the lists sit 19 curated resources, including the Department's Zero Trust Strategy, NIST's Cybersecurity Framework 2.0 Small Business Quick-Start Guide, NIST SP 800-82 Revision 3 for operational technology security, CISA and NSA material, DC3's DIB Collaborative Information Sharing Environment, and Project Spectrum.
The disclaimer the Department wrote about its own guidance
This answers the mandatory question before you scroll any further. The campaign calls the material “for educational and informational purposes only.” It also says implementation does not guarantee immunity from threats and that practices must be tailored to the organization's technical, operational, and regulatory requirements.
A document that tells you to tailor it to your actual regulatory requirements is not itself the instrument that creates those requirements. That is the whole answer, and it comes from the publisher.
Why the July 13 press release is the actual reason you are confused
Here is the thing that explains the entire wave of misunderstanding, and we have not seen it stated this plainly elsewhere.
The Department's July 13, 2026 release announces the immediate suspension of the planned transition to CMMC Phase II, confirms that Phase I self-assessment requirements remain, establishes a 60-day CMMC Reform Task Force, and says DFARS 252.204-7012 obligations are unchanged.
It never names Brilliant at the Basics as a standard, benchmark, assessment basis, or replacement for CMMC.
But its final “more information” link points to the Brilliant at the Basics campaign page.
So a contractor reads the suspension notice, clicks the one link offered, lands on a government page with twenty numbered cybersecurity practices, and draws the obvious conclusion: this must be what replaces it.
It isn't. But you can see how a reasonable person gets there in ten seconds.
Is Brilliant at the Basics mandatory?
No. Brilliant at the Basics is voluntary guidance with no standalone contractual force. It was not published as a Federal Register rule, is not incorporated into 32 CFR Part 170 as an assessment standard, does not appear as a named requirement in the current DFARS cybersecurity clauses, and has no status an offeror can post in SPRS. Your binding obligations come from the solicitation, contract, subcontract or purchase-order terms that apply to you — commonly DFARS 252.204-7012, 252.204-7019, 252.204-7020, 252.204-7021, and 252.204-7025.
The clearest way to see this is side by side. This table is ours; the legal instruments are the Department's.
Two documents, two very different legal weights
Last verified August 17, 2026
| Question | Brilliant at the Basics | Instruments that can actually bind you |
|---|---|---|
| What is it? | A CIO campaign webpage plus two PDF one-pagers | A final rule, solicitation provisions, contract clauses, flow-downs, and incorporated standards |
| Where does it live? | dowcio.war.gov/BrilliantBasics | 32 CFR Part 170; DFARS 252.204-7012, -7019, -7020, -7021, and -7025; NIST SP 800-171 Revision 2 |
| Published as a Federal Register rule? | No | Yes, for 32 CFR Part 170 and the CMMC DFARS acquisition rule |
| Creates a standalone contract obligation? | No | Yes, when the applicable provision or clause is in the solicitation, contract, or flow-down |
| Can completion itself gate award? | No standalone Brilliant at the Basics status exists | Yes. For example, DFARS 252.204-7019 can require a current NIST SP 800-171 assessment in SPRS, and 252.204-7025 identifies the required CMMC status for award |
| Scored in SPRS? | No | NIST SP 800-171 DoD assessment scores and relevant CMMC statuses, UIDs, and affirmations are recorded in or transmitted to SPRS |
| Annual affirmation? | No | CMMC requires an affirmation after assessment and annually thereafter under 32 CFR § 170.22 and DFARS 252.204-7021 |
| False Claims Act exposure? | Not from failing a voluntary campaign by itself | Potentially, when claims for payment or cybersecurity representations are knowingly false and legally material; outcomes depend on the facts and law |
| Number of items | 20 practices | 15 FAR-derived requirements at Level 1; 110 NIST SP 800-171 Revision 2 requirements across 14 families at Level 2 |
| What does the text sound like? | Recommendations and best practices | “The Contractor shall…” and award-eligibility conditions |
That final row is the tell. One document recommends. The other creates conditions and duties.
The five DFARS provisions people collapse into one sentence
These provisions do different jobs. Treating them as interchangeable is how contractors miss a requirement that is already in their paperwork.
| Provision or clause | What it actually does |
|---|---|
| DFARS 252.204-7012 | Requires adequate security for covered contractor information systems; incorporates NIST SP 800-171 for covered defense information; requires rapid cyber-incident reporting within 72 hours; requires 90-day preservation of specified incident media; imposes cloud conditions; and contains flow-down duties. |
| DFARS 252.204-7019 | Makes a current NIST SP 800-171 DoD assessment a condition of award when applicable and requires the relevant summary score to be posted in SPRS. “Current” ordinarily means not more than three years old unless the solicitation specifies less. |
| DFARS 252.204-7020 | Requires contractor access for government Medium or High assessments, provides for scores in SPRS, and restricts awards of covered subcontracts unless the subcontractor has a current assessment. |
| DFARS 252.204-7021 | Requires the contractor to maintain the CMMC status designated for the contract, maintain annual affirmations, identify CMMC UIDs, notify the contracting officer of specified changes, and flow the appropriate requirement to subcontractors. |
| DFARS 252.204-7025 | Tells offerors which CMMC level and assessment type the solicitation requires, makes the required current status and affirmation award conditions, and requires CMMC UIDs in the proposal. |
Brilliant at the Basics does none of those jobs.
What some published summaries got wrong
Several published summaries of the July 13 announcement described Brilliant at the Basics as the interim enforcement benchmark during the suspension — that the Department would now measure contractors against the IT and OT Top 10 lists while third-party assessment implementation was paused.
The release says the opposite: during the interim period, the Department will enforce compliance with NIST SP 800-171 Revision 2 through self-assessments and select government-led assessments. Brilliant at the Basics is not named as the standard, benchmark, or assessment basis.
We are not naming the outlets. Everyone covering a fast-moving policy story writes some sentences they would tighten later, and this one is an easy inference to make when the release's final link points at the campaign. But if your compliance plan changed because you read that Brilliant at the Basics is now the standard, that plan was built on a sentence the Department did not write.
The four things that actually set your obligations
Before you spend a dollar reacting to this campaign, answer these:
- Which document requires cybersecurity of us — the solicitation, the contract, a subcontract, a prime's purchase-order terms, or another agreement?
- What information enters our systems — Federal Contract Information, Controlled Unclassified Information, covered defense information, export-controlled data, classified information, or paper only?
- Which systems and workflows touch that information — including external service providers, cloud services, the shop floor, removable media, and the file cabinet?
- Has our written requirement changed since the July 13, 2026 suspension action?
Nothing on the Brilliant at the Basics page answers any of those four, and it does not claim to.
Did Brilliant at the Basics replace CMMC or NIST SP 800-171?
No. Brilliant at the Basics is a prioritized security-guidance campaign. CMMC is a program established by 32 CFR Part 170 and implemented through the DFARS acquisition rule, solicitation provision, contract clause, and flow-downs. NIST SP 800-171 Revision 2 supplies the 110 security requirements assessed at CMMC Level 2. They overlap in substance, but completing 20 voluntary practices does not complete 110 contractual requirements, and no part of the campaign amends the rule.
Four instruments, four different jobs. People conflate them constantly, so here they are separated.
Last verified August 17, 2026
| Instrument | What it does | Authority | Structure | How it gets checked |
|---|---|---|---|---|
| Brilliant at the Basics | Prioritizes foundational IT and OT security improvements | Informational CIO campaign | 10 IT + 10 OT practices | No Brilliant at the Basics assessment mechanism |
| NIST SP 800-171 Revision 2 | Specifies security requirements for protecting CUI in nonfederal systems | Incorporated by 32 CFR Part 170 and required through applicable contract terms, including DFARS 252.204-7012 | 110 requirements across 14 families | Contractor Basic assessment; government Medium or High assessment; CMMC Level 2 self or certification assessment, depending on the applicable requirement |
| CMMC, 32 CFR Part 170 | Establishes CMMC levels, scope, assessment findings, statuses, POA&M limits, affirmations, and ecosystem duties | 32 CFR Part 170, effective December 16, 2024 | Levels 1, 2, and 3 with defined assessment types | Self-assessment, C3PAO assessment, or DIBCAC assessment according to the required status |
| DFARS cybersecurity provisions and clauses | Put assessment, status, reporting, flow-down, and award conditions into the acquisition and contract | Current DFARS text | 252.204-7012, -7019, -7020, -7021, -7025 and related prescriptions | Contracting-officer verification, SPRS, government assessment, C3PAO assessment when required, and contractual enforcement |
Two definitions before we go further, because the rest of this page uses them freely. A C3PAO is a CMMC Third-Party Assessment Organization — an organization authorized or accredited to conduct formal Level 2 certification assessments. DIBCAC is the Defense Contract Management Agency's Defense Industrial Base Cybersecurity Assessment Center, the government team that performs NIST SP 800-171 Medium and High assessments and CMMC Level 3 assessments. SPRS is the Supplier Performance Risk System, where NIST SP 800-171 DoD assessment scores and relevant CMMC statuses, UIDs, and affirmations are recorded in or transmitted to SPRS for acquisition use.
What happened to the Phase 1 dates after the Phase II suspension?
The original four-phase implementation schedule made Phase 1 run from November 10, 2025 through November 9, 2026, with Phase 2 scheduled to begin November 10, 2026. On July 13, 2026, the Department suspended the transition to Phase II and pending and future CMMC implementation milestones. Its current CMMC pages state that all Phase I self-assessment requirements remain in place.
That means the clean sentence for today is not “Phase 2 begins November 10, 2026.” It is this:
Phase 1 began November 10, 2025. The July 13, 2026 suspension stopped the planned transition to Phase II, so Phase I self-assessment implementation remains operative pending further official action.
The suspension did not erase 32 CFR Part 170, delete the current DFARS clauses, or suspend DFARS 252.204-7012. It changed the Department's implementation direction for the transition and future milestones. Your actual obligation still has to be read from your current solicitation, contract, modification, and flow-down.
The Revision 2 versus Revision 3 question, settled
This one trips up smart people, and both halves have to be said together or the answer is wrong.
NIST published SP 800-171 Revision 3 on May 14, 2024. Revision 3 supersedes Revision 2 in NIST's publication catalog and contains 17 requirement families.
It is also true that CMMC Level 2 assessments remain tied to Revision 2 because 32 CFR Part 170 incorporates the February 2020 Revision 2 publication, including its January 28, 2021 updates. Current Department guidance also continues to identify Revision 2 as the CMMC assessment baseline until the Department changes the controlling requirements through the appropriate legal mechanism.
You may implement Revision 3 as future-facing architecture. That does not remove the need for Revision 2 traceability when Revision 2 is the requirement being assessed or represented under your current contract.
So: “Revision 2 is the newest NIST publication” is wrong. “Revision 3 is automatically the CMMC baseline now” is also wrong. The accurate sentence is that Revision 3 is NIST's newer publication while Revision 2 remains the controlling CMMC Level 2 assessment baseline under the current rule.
Our Revision 2 versus Revision 3 breakdown handles the requirement-family and transition details.
The same version trap now exists at Level 3
NIST published SP 800-172 Revision 3 in May 2026, superseding the February 2021 edition in NIST's catalog. That does not automatically change CMMC Level 3. The current CMMC rule still incorporates the February 2021 SP 800-172 and selects 24 enhanced requirements for Level 3.
A new NIST publication does not silently rewrite an incorporated regulatory baseline. Watch the rule, the DFARS, and official Department implementation documents — not the publication date alone.
Can you say your company is “Brilliant at the Basics compliant”?
No, and please don't. There is no Brilliant at the Basics standard to be compliant with, no assessment method, no defined passing criteria, no assessor, and no certificate. Writing that phrase in a capability statement, supplier questionnaire, or proposal creates a representation you cannot tie to an official status.
Say what you actually did instead: “We implemented phishing-resistant MFA for privileged cloud accounts,” “we completed a full-system restoration test on August 4,” or “we maintain a validated OT inventory.” Evidence-backed statements are stronger than a label the Department never created.
The right provider isn't the same for every contractor
The right CMMC provider isn't the same for every contractor — the category you need may be a C3PAO, an RP or RPO, an MSP or MSSP, an OT specialist, a GRC platform, or a CUI enclave provider. That depends on your required CMMC level, whether you handle FCI or CUI, your assessment type, your cloud and IT environment, your OT boundary, and your contract timeline. The solicitation, contract, or flow-down sets the required status; a checklist does not.
Because a general answer cannot resolve those inputs for you, use Find My CMMC Path to map your situation to the right provider category before you request quotes — and do not submit CUI, drawings, export-controlled content, system credentials, or sensitive contract details.
Full names on first use, since we will keep referring to them: RPO/RP is a Registered Provider Organization or Registered Practitioner listed in the Cyber AB Marketplace to provide CMMC readiness assistance. MSP/MSSP is a Managed Service Provider or Managed Security Service Provider. A GRC platform is governance, risk, and compliance software for tracking requirements, ownership, and evidence. A CUI enclave is a deliberately separated environment intended to contain CUI and reduce the assessment boundary, provided the real workflows, integrations, administration, printing, backups, and export paths support that boundary.
The honest part: some of these “basics” are better security than what CMMC scores
We are about to spend several thousand words showing you which practices earn compliance credit and which earn none. Before that, we owe you the other side of it.
The Department is right about the security. Immutable backups with tested restores, phishing-resistant authentication, guardrails on what employees paste into public AI tools, and deliberate segmentation between a business network and a production floor can reduce risks that NIST SP 800-171 Revision 2 addresses only partially or not directly. In several places this campaign is more specific, more modern, or more operationally resilient than the scored baseline.
That is not the problem.
The problem is that you have finite money and two masters. One is the threat. The other is a contract clause that gates revenue and may carry an assessment result and affirmation somebody in leadership has to stand behind. Nothing on the campaign page tells you where those two overlap, where they do not, or which OT assets are even assessed.
That is the gap we built this page to close. Everything below is the map.
A second admission, since we are here: The Defense Compliance Report may earn compensation when readers request introductions to providers. We are about to tell you that several items on a government list may not be where you should spend first. That is us arguing against our own routing interest, and we would rather you trust the analysis than buy something you do not need.
Check what your current posture is actually worth
The CMMC Readiness Checklist walks all 110 NIST SP 800-171 Revision 2 requirements, the evidence each one needs, and the gaps a twenty-item campaign cannot cover.
Open the readiness checklist →
Do not upload CUI, drawings, export-controlled content, credentials, or contract attachments to any general intake form.
What are the 10 Brilliant at the Basics IT practices worth under CMMC?
The IT Top 10 covers phishing-resistant multi-factor authentication, asset inventory, technical debt reduction, a flexible technology stack, logical segmentation, risk-based vulnerability management, secure development, secure AI adoption, resilient backup, and workforce readiness. In our editorial upper-bound mapping, those ten practices touch 19 of the 110 NIST SP 800-171 Revision 2 requirements, representing at most 71 weighted points. Two practices map to no direct scored requirement.
What is official and what is ours
The official material is the Department's ten-item list, the 110 Revision 2 requirements, and the 1-, 3-, and 5-point values in the NIST SP 800-171 DoD Assessment Methodology, Version 1.2.1. The mapping between them is our editorial analysis.
We found no official Brilliant at the Basics-to-NIST-SP-800-171 crosswalk on the campaign page, the Department's CMMC resources page, or NIST's publication pages as of August 17, 2026. Treat the “closest requirement” column as a first-pass investigative map, not an assessment determination.
How we built this table
Every point value comes from Annex A of the Department's assessment methodology. The methodology assigns a potential deduction of 1, 3, or 5 points to each scored requirement based on the effect of nonimplementation. 32 CFR § 170.24 uses the same weighting structure for CMMC Level 2.
“Points at stake” does not mean the campaign sentence automatically earns those points. A requirement is MET only when all applicable assessment objectives are satisfied with final evidence. The numbers below are ceilings.
Table 1 — The IT Top 10 credit ledger
Point values verified against DoD Assessment Methodology v1.2.1, Annex A, on August 17, 2026
| # | IT practice — official name | Closest NIST SP 800-171 Revision 2 requirement(s) | Upper-bound points | What the campaign adds | Verdict |
|---|---|---|---|---|---|
| 1 | Phishing-Resistant Multi-Factor Authentication | 3.5.3 MFA (5, with a narrow partial-scoring treatment in the methodology); 3.5.4 replay-resistant authentication (1); 3.1.5 least privilege (3) | Up to 9 | Specifies phishing resistance, which Revision 2 does not require, and ties identity to least privilege | Exceeds the baseline. Ordinary qualifying MFA can satisfy 3.5.3 without being phishing-resistant. The stronger method earns no extra SPRS points by itself. |
| 2 | Comprehensive Asset Inventory Management | 3.4.1 baseline configurations and inventories (5) | 5 | Adds continuous discovery plus identities and data as tracked asset classes | Partial. 3.4.1 addresses system inventories and baseline configurations; the campaign's identity and data inventory is broader. |
| 3 | Strategic Technical Debt Reduction | 3.4.6 least functionality (5); 3.4.7 restrict nonessential functions, ports, protocols, and services (5); 3.4.9 control user-installed software (1) | 11 | Adds retirement, consolidation, modernization, unsupported-technology removal, and shadow-IT reduction | Adjacent. Revision 2 makes you restrict and control. It does not create a full modernization portfolio. |
| 4 | Flexible Technology Stack | No direct mapped requirement | 0 | Open standards, interoperability, portability, and avoidance of vendor lock-in | No direct scored requirement. Good architecture advice can still support other requirements and reduce business risk. |
| 5 | Logical Segmentation to Limit Adversary Lateral Movement | 3.13.1 boundary protection (5); 3.13.5 separation of publicly accessible components (5 when applicable); 3.13.6 deny network communications by default and allow by exception (5) | Up to 15 | Adds blast-radius thinking, identity-aware zones, and a more explicit lateral-movement goal | Highest potential value. The full 15 assumes 3.13.5 applies. Segmentation can also support scope reduction when the actual architecture and data flows justify it. |
| 6 | Risk-Based Vulnerability Management | 3.11.1 periodic risk assessment (3); 3.11.2 vulnerability scanning (5); 3.11.3 remediation in accordance with risk assessments (1); 3.14.1 flaw remediation (5) | 14 | Prioritizes exploitability, asset importance, exposure, and compensating controls over generic severity alone | Strong overlap. The campaign adds operational prioritization to an already scored cluster. |
| 7 | Integrate Security Early in the Development Lifecycle | 3.13.2 architectural designs, software-development techniques, and systems-engineering principles (5), partially | Up to 5 | Adds secure coding, automated pipeline scanning, and third-party dependency risk | Mostly beyond Revision 2. Revision 2 has no System and Services Acquisition family and no complete software-supply-chain program. |
| 8 | Secure AI Adoption and Data Protection | No direct AI-specific requirement | 0 | AI inventory, approved-use rules, content controls, and a direct prohibition on putting sensitive Department data into public commercial AI systems | No direct AI score line. Existing access, media, incident, cloud, and CUI-handling duties can still apply to the conduct. |
| 9 | Resilient Backup and Disaster Recovery Architecture | 3.8.9 protect the confidentiality of backup CUI at storage locations (1) | 1 | Immutability, isolated credentials, redundant copies, and full-system restoration drills | Barely covered by the score. The campaign's availability and recovery value is much larger than its direct Revision 2 point value. |
| 10 | Continuous Technical Workforce Readiness | 3.2.1 security awareness (5); 3.2.2 role-based training (5); 3.2.3 insider-threat awareness (1) | 11 | Ongoing technical proficiency in architecture, data protection, and defensive operations | Partial. Revision 2 requires awareness and role-based training; the campaign pushes continuous technical capability. |
Upper-bound total: 19 of the 110 requirements, representing 71 weighted points. Two practices have no direct scored requirement.
The 19 requirements, if you want to check our work: 3.1.5, 3.2.1, 3.2.2, 3.2.3, 3.4.1, 3.4.6, 3.4.7, 3.4.9, 3.5.3, 3.5.4, 3.8.9, 3.11.1, 3.11.2, 3.11.3, 3.13.1, 3.13.2, 3.13.5, 3.13.6, and 3.14.1.
The two items with no direct scored requirement
Item 4, Flexible Technology Stack, has no direct counterpart in Revision 2. The standard does not require open standards, interoperability, data portability, or freedom from vendor lock-in. It is good architecture advice with real business value and no direct line item in the score.
Item 8, Secure AI Adoption, is the one to read twice. Revision 2 has no AI-specific requirement. But that does not make public-AI use safe.
If an employee pastes CUI into a public commercial AI service, you have an immediate unauthorized-disclosure and system-boundary problem to investigate. DFARS 252.204-7012 requires a 72-hour report when a discovered cyber incident affects a covered contractor information system or covered defense information. Whether a particular AI disclosure meets that definition is a fact-specific incident determination, not an automatic conclusion from the paste alone. If the external service stores, processes, or transmits covered defense information, the clause's cloud-security conditions also matter.
Zero direct AI score credit. Real contractual and security exposure. That combination is the strongest argument for doing an unscored item anyway.
The one to do first if you only do one
Item 5, Logical Segmentation, at up to 15 points. It is the highest-scoring IT cluster on the list, and it can do double duty: boundary protection is a scored control, and a genuinely separated CUI workflow can reduce what belongs inside the assessment boundary. Fewer in-scope systems can mean less evidence, less remediation, and a smaller bill on every future engagement.
But “we have VLANs” is not a scoping determination. The architecture, administrative paths, identities, data flows, security services, backups, and endpoints have to support the boundary. Our CMMC scoping guide covers that decision.
The backup gap, stated plainly
Revision 2 is centered on protecting the confidentiality of CUI. It is not a full business-continuity or disaster-recovery standard. That is why the campaign's immutable-backup, isolated-credential, and full-restoration practice maps directly to one backup-specific, 1-point requirement about protecting the confidentiality of backup CUI at storage locations.
If you have never restored a backup, you do not have a backup; you have an assumption. That is worth fixing on its own merits. Just go in knowing the directly mapped SPRS exposure is one point.
What does Brilliant at the Basics do to your SPRS score?
Nothing directly — the campaign itself is not scored. Our editorial mapping gives the ten IT practices an upper-bound exposure of 71 weighted points. But the campaign alone does not produce a valid SPRS score because it does not provide the current System Security Plan required by security requirement 3.12.4. If you add that SSP solely to make the assessment completable, then grant full credit for every mapped requirement and nothing else, the generous ceiling is roughly negative 132 out of 110.
Here is the arithmetic. Every input is public, and you can redo it from Annex A.
Table 2 — The Brilliant at the Basics score ceiling
Our computation on the Department's published weights. Verified August 17, 2026.
| Step | Value | Source or implication |
|---|---|---|
| Maximum NIST SP 800-171 DoD assessment score | 110 | All scored requirements implemented |
| Minimum possible score | −203 | Published assessment range |
| Total weighted deduction pool | 313 | Independent sum of Annex A's scored deductions; also 110 − (−203) |
| Upper-bound points represented by the ten IT practices | 71 | Table 1 editorial mapping |
| Campaign alone, with no current SSP | No valid score | The assessment methodology and 32 CFR § 170.24 say an assessment cannot be completed without an up-to-date SSP |
| Generous ceiling with a current SSP plus full credit for all 19 mapped requirements | 110 − (313 − 71) = −132 | DCR computation; ceiling, not forecast |
Read the caveat before you quote the number
This is a ceiling, not a forecast. Three reasons the real result can be lower or simply not exist:
First, assessment objectives are more granular than a bullet point. NIST SP 800-171A breaks each requirement into discrete objectives. A requirement is MET only when every applicable objective is satisfied by final evidence. A one-sentence practice on a government one-pager will rarely do that by itself.
Second, a POA&M does not turn a NOT MET requirement into points. A requirement that is not implemented remains NOT MET and loses its weighted value. Under CMMC, a narrowly limited set of NOT MET findings can support a Conditional Level 2 status, but only when the score is at least 88 out of 110, the open items meet the point-value restrictions, six named requirements are not on the POA&M, and the closeout is completed within 180 days. Brilliant at the Basics plus an SSP does not come close to that threshold.
Third, if the System Security Plan is absent or not up to date, the assessment cannot be completed. Twenty perfectly executed campaign practices with no SSP do not produce a low score. They produce no valid assessment result.
POA&M, temporary deficiency, and enduring exception are three different things
This distinction matters most on legacy and operational systems.
| Situation | Assessment treatment under the current rule |
|---|---|
| Initial security requirement is not implemented | It is NOT MET. A CMMC POA&M may support Conditional status only if the strict § 170.21 eligibility rules are met. The requirement receives no point credit until closed. |
| Temporary deficiency after a requirement was implemented | If it is appropriately addressed in an operational plan of action that shows review and progress toward correction, § 170.24 says it is assessed MET. An operational plan of action is not the same as the 180-day CMMC POA&M. |
| Enduring exception where full remediation is not feasible | When the exception and mitigations are described in the SSP, § 170.24 says it is assessed MET. The assessor still evaluates whether the classification and evidence support that treatment. |
That is a much better answer than “POA&Ms do not count.” They do not earn points for unimplemented requirements, but the rule separately recognizes temporary deficiencies and enduring exceptions that can be assessed MET when the facts and documentation fit.
What the number actually tells you
Not “the campaign is useless.” What it tells you is that Brilliant at the Basics is a prioritization lens, not a program. It points at high-leverage security work. It does not, and does not claim to, get you to a defensible assessment result.
If you were hoping to work the list and be done, this is the sentence that saves you six months: the gap between a generous negative 132 and positive 110 is not just effort. It is coverage, scope, documentation, and evidence — 91 untouched requirements, a current SSP, final artifacts, accountable owners, and an assessment result you can defend.
Close the other 91 requirements
The CMMC Readiness Checklist walks all 110 NIST SP 800-171 Revision 2 requirements across the 14 families, with the evidence each one needs and where programs usually stall.
Free educational resource. Never upload CUI, drawings, credentials, or contract attachments.
Why is phishing-resistant MFA priority 1 if it isn't even a requirement?
NIST SP 800-171 Revision 2 requires multi-factor authentication in requirement 3.5.3 and replay-resistant authentication in requirement 3.5.4. It does not require phishing-resistant authentication. Phishing resistance is a stronger, technically distinct property defined in NIST SP 800-63B. The campaign can recommend that stronger protection immediately without changing the CMMC score or the Revision 2 text. A solicitation, prime, customer, or other contract term can still require it separately, so answer the written requirement you actually have.
This is the first item on the Department's list of “basics,” and it is one of the least basic migrations on either page. Worth understanding properly, because your prime may start asking about it.
Replay resistance and phishing resistance are not the same thing
Replay resistance means a captured authentication message cannot simply be reused successfully. NIST identifies one-time passwords and cryptographic challenge-response methods as examples of replay-resistant authentication.
Phishing resistance means the authentication protocol prevents an impostor verifier from obtaining a usable authenticator output without relying on the user's vigilance. NIST SP 800-63B says this requires cryptographic authentication and recognizes channel binding and verifier-name binding as the two methods.
Most of what people call MFA can be replay-resistant and still not be phishing-resistant:
| Authentication method | Replay-resistant? | Phishing-resistant? |
|---|---|---|
| Password alone | No | No |
| SMS or voice one-time code | Yes when the verifier accepts the code only once | No |
| Authenticator-app time-based one-time code | Yes | No |
| Push approval | Implementation-dependent; basic push can be replay-resistant but remains vulnerable to fatigue and relay attacks | Not inherently |
| Hardware one-time-password token | Yes | No |
| PIV or CAC smart card using a bound cryptographic protocol | Yes | Yes |
| FIDO2 or WebAuthn security key | Yes | Yes |
| Passkey using verifier-bound WebAuthn | Yes | Yes |
| Windows Hello for Business | Can be, in supported key- or certificate-based, verifier-bound deployments | Can be; verify the actual deployment |
The phishing-resistant methods at the bottom of the table are not just a checkbox swap for every small contractor. A 30-person machine shop running Microsoft 365, a legacy ERP, vendor portals, and authenticator-app codes may need identity architecture, application compatibility work, recovery design, hardware enrollment, exception handling, and user support. It is a project.
Why the campaign can recommend more than the rule requires
Guidance can move at webpage speed. A regulatory baseline does not.
To make phishing resistance part of the universal CMMC Level 2 baseline, the Department would need to change the controlling requirement through the appropriate rulemaking, incorporation, deviation, or contractual mechanism. Until that happens, an assessor cannot award extra CMMC points because your MFA is stronger than 3.5.3 requires.
That does not make the stronger control irrational. It means you should know which business case is funding it:
- Close ordinary MFA coverage first. A missing 3.5.3 implementation can cost 5 points. Phishing resistance adds security but no extra score line.
- Meet a written customer requirement accurately. A prime can ask for phishing-resistant MFA even when Revision 2 does not.
- Reduce credential-phishing risk. That value exists outside the score.
- Prepare for a future baseline. That is a strategy, not a current assessment substitute.
What to actually do about item 1
Editorial judgment, derived from the verified facts above:
- Inventory your authentication methods before buying anything. Privileged accounts, remote access, CUI applications, administrative interfaces, and external service providers first. You may find gaps in ordinary MFA coverage before you spend on phishing resistance.
- Check whether your business applications support verifier-bound authentication. Legacy ERP, VPN, shop-floor, and vendor applications frequently do not. That determines whether this is a configuration change, a federation project, an exception, or a migration.
- Separate user populations. Privileged and high-risk cloud accounts may be the first practical deployment even if a legacy application blocks universal rollout.
- If a prime asks in writing whether you use phishing-resistant MFA, answer accurately. “We use MFA across the assessed environment; phishing-resistant methods are deployed for these account classes” is defensible. “Yes” when every user is entering a six-digit code is not.
What are the 10 OT practices, and when do they count under CMMC?
The OT Top 10 adapts foundational security to environments where a change can affect production, equipment, safety, product quality, and mission delivery. Whether an OT practice earns CMMC credit depends on the asset's Level 2 category. An OT system assessed as a CUI Asset or relevant Security Protection Asset can carry scored requirements. A Contractor Risk Managed Asset receives SSP review and may receive a limited check. A Specialized Asset is documented, diagrammed, and managed under risk-based policy but is not assessed against the other Level 2 requirements. An Out-of-Scope Asset receives no Level 2 assessment.
This is the finding that matters most on the page: “OT” is a technology description. It is not, by itself, the final CMMC asset-category decision.
What “Specialized Asset” actually means for your shop floor
32 CFR § 170.19(c)(1), Table 3 establishes five Level 2 asset categories. OT appears inside the definition of a Specialized Asset, but only when the asset can process, store, or transmit CUI and is unable to be fully secured. The same OT device can land in a different category when its actual use and security function differ.
| Level 2 asset category | What makes an OT asset fit | What must be documented | What gets assessed |
|---|---|---|---|
| CUI Asset | The OT asset processes, stores, or transmits CUI | Asset inventory, SSP treatment, network diagram | All applicable Level 2 requirements |
| Security Protection Asset | The OT asset or connected component provides security functions or capabilities to the CMMC scope | Asset inventory, SSP treatment, network diagram | Requirements relevant to the security capabilities provided |
| Contractor Risk Managed Asset | It can handle CUI but is not intended to because policies, procedures, and practices prevent that use | Asset inventory, SSP treatment, network diagram, risk-based controls | SSP review; no other assessment if sufficiently documented, but a limited check is permitted if the documentation or findings raise questions |
| Specialized Asset | It can handle CUI but cannot be fully secured; OT, IIoT, test equipment, GFE, and other listed types may fit | Asset inventory, SSP treatment, network diagram, and evidence it is managed under risk-based policies, procedures, and practices | SSP review; not assessed against the other Level 2 requirements |
| Out-of-Scope Asset | It cannot process, store, or transmit CUI, does not protect CUI Assets, and is physically or logically separated as required | Be prepared to justify the classification | No Level 2 assessment |
The original shortcut — “all OT is Specialized and none of it is assessed” — sounds clean and is wrong. A historian server holding CUI, an engineering workstation controlling equipment while storing CUI, a firewall protecting the OT/CUI boundary, and an isolated controller with no CUI pathway are not the same asset.
The rule also incorporates NIST SP 800-82 Revision 3 for its OT and SCADA definitions, and the Brilliant at the Basics resource library links to that same NIST OT guide. The campaign and the rule are speaking about the same technology class. The scoping rule decides how each asset is treated.
Table 3 — The OT Top 10 conditional credit ledger
Point values from DoD Assessment Methodology v1.2.1, Annex A. Requirement mapping is our editorial analysis. Verified August 17, 2026.
| # | OT practice — official name | Closest Revision 2 requirement(s) if the affected asset is assessed | Potential weighted points | What changes by asset category |
|---|---|---|---|---|
| 1 | Identity and Access Control | 3.1.1 authorized users (5); 3.1.2 authorized transactions and functions (5); 3.1.5 least privilege (3); 3.5.3 MFA (5) | Up to 18 | Potentially scored for CUI Assets and relevant Security Protection Assets; no direct requirement assessment for a Specialized Asset |
| 2 | Validated Asset Inventory | 3.4.1 baseline configurations and inventories (5) | 5 | Inventory and SSP documentation matter across in-scope categories; a Specialized Asset is still documented even though 3.4.1 is not assessed against that asset |
| 3 | Strict Network Segmentation | 3.13.1 boundary protection at external and key internal boundaries (5) | 5 | Can be a scored boundary control and can support an out-of-scope or risk-managed classification when the architecture actually prevents CUI handling |
| 4 | OT-Specific Incident Response and Recovery Plan | 3.6.1 incident-handling capability (5); 3.6.2 track, document, and report incidents (5); 3.6.3 test the capability (1) | 11 | The scored requirements apply to the assessed environment; DFARS 252.204-7012 reporting can still apply when a cyber incident affects covered systems or covered defense information |
| 5 | Manage Known Vulnerabilities | 3.11.3 remediate vulnerabilities in accordance with risk assessments (1); 3.14.1 identify, report, and correct system flaws (5) | 6 | The asset category and the enduring-exception or temporary-deficiency analysis determine whether inability to patch is a finding, a documented MET treatment, or an unimplemented requirement |
| 6 | Remote Access Pathways | 3.1.12 monitor and control remote access (5); 3.1.13 cryptographically protect remote sessions (5); 3.1.14 route remote access through managed access points (1); 3.1.15 authorize remote privileged commands (1); 3.7.5 MFA for nonlocal maintenance (5) | 17 | High point exposure when the pathway enters an assessed environment; vendor tunnels can also defeat an attempted scope boundary |
| 7 | Continuous Monitoring | 3.3.1 create and retain audit records (5); 3.3.5 correlate audit review and analysis (5); 3.14.6 monitor systems and communications for attacks (5); 3.14.7 identify unauthorized use (3) | 18 | Potentially the largest OT cluster for assessed systems; a Specialized Asset still needs risk-based management even though these requirements are not assessed against it |
| 8 | System Resiliency | No direct availability or fail-safe requirement in Revision 2 | 0 | Pure security, safety, and operational value unless another contract or system requirement supplies the obligation |
| 9 | Supply Chain Security | No direct supply-chain requirement family in Revision 2 | 0 | Other clauses, procurement terms, flow-downs, and vendor-access controls may still create duties; Revision 3's newer supply-chain family is not automatically the current CMMC baseline |
| 10 | Review Processes | 3.4.3 track, review, approve or disapprove, and log changes (1); 3.4.4 analyze security impact before implementation (1); 3.4.5 define and enforce access restrictions associated with changes (5) | 7 | Revision 2 addresses change control; the campaign adds the OT safety and mission-assurance review that stops a security change from creating a physical hazard |
The OT mapping represents 87 raw points before overlap with the IT table. After removing overlap, it adds at most 63 weighted points and 17 unique requirements beyond the IT mapping. Combined, the two editorial mappings touch 36 unique requirements representing 134 weighted points.
If — and only if — the relevant OT systems are assessed assets, a current SSP exists, and every mapped objective is fully met, the combined theoretical ceiling is:
110 − (313 − 134) = negative 69.
That is not a universal “IT plus OT score.” A Specialized Asset earns none of those direct requirement points because the rule tells the assessor not to assess it against the other Level 2 requirements. An Out-of-Scope Asset earns none because it is outside the assessment. The number applies only to the mapped requirements that are actually in the assessed scope.
The enduring exception: the most useful line for unpatchable equipment
OT practice 5 — compensating controls where you cannot immediately patch — has a real regulatory home, but it is narrower than “old controller equals MET.”
32 CFR § 170.24(b)(1)(i) states that enduring exceptions, when described along with mitigations in the SSP, are assessed MET. The rule defines an enduring exception as a special circumstance or system where remediation and full compliance are not feasible; examples may include OT, IoT, test equipment, medical devices, and fielded-system replicas.
Read that again if you own a plate line running a 2009 controller. The answer is not automatically “patch the unpatchable,” and it is not automatically “call it specialized.” The sequence is:
- Classify the asset correctly under § 170.19.
- Identify which requirement and assessment objectives are affected.
- Determine whether this is an enduring exception, a temporary deficiency, or an initially unimplemented requirement.
- Document why full remediation is not feasible.
- Document the mitigations — firewall rules, micro-segmentation, application allowlisting, restricted remote access, monitoring, physical controls, or replacement planning.
- Put the treatment in the SSP and keep evidence that the mitigations operate.
The assessment team decides whether the facts support MET. A label in a spreadsheet does not.
The Department distinguishes an enduring exception from a temporary deficiency and from a CMMC POA&M. Getting that classification right can preserve points honestly. Getting it wrong can turn an engineering constraint into an unsupported representation.
If you run machines, read the industry version too
The shop-floor translation of these ten practices — burn tables, crane HMIs, weld cells, paint booths, metrology, vendor remote support, and engineering workstations — is on our CMMC for shipbuilders and CMMC for machine shops pages. This page handles requirement-level and scoring logic; those pages handle what it looks like on the floor.
Which of the 20 practices apply to your company?
Not every contractor should work these twenty items in the same order. The right starting track depends on whether you run only enterprise IT or also operate physical systems, whether you handle FCI or CUI, whether you develop software, whether outside vendors reach into your environment, and whether you already have reliable inventory, identity, segmentation, and recovery.
Find yourself here first. It will save you from working someone else's list.
| Your situation | Start with | Skip or defer | The assumption that costs you money |
|---|---|---|---|
| Small office-based contractor handling CUI — engineering or professional services, no plant | IT item 5 (segmentation), item 2 (inventory), item 6 (vulnerability management), item 1 (MFA coverage), then item 9 (restore test) | The OT list; IT item 7 unless you develop software | Assuming the ten IT items complete Revision 2. They touch 19 of 110 requirements. |
| Manufacturer or machine shop with IT and OT | Classify each OT asset first; build separate IT and OT inventories; review remote pathways; then segment IT, OT, CUI, and vendor access based on the real data flow | Any blanket “all OT is specialized” decision; IT item 7 unless you develop software or firmware | Applying enterprise scanning and patching directly to production systems, or excluding an OT workstation that actually stores CUI |
| Defense software or SaaS supplier | IT item 7 (secure development), item 1 (identity), item 8 (AI governance), item 5 (segmentation), item 9 (recovery) | The OT list unless you ship embedded or control-system products | Assuming a commercial compliance platform determines contractual applicability or secures your development pipeline |
| Subcontractor unsure whether it has FCI or CUI | None of the twenty. Start with the subcontract, flow-down language, data sources, and actual workflows | Everything else until scope is answered | Using any checklist — this one included — to decide the required CMMC level or assessment type |
| Level 1 contractor handling FCI but no CUI | The 15 FAR-derived Level 1 requirements and the systems that process, store, or transmit FCI | The 110-point Level 2 scoring exercise unless another clause requires it | Spending against a Level 2 map when your present requirement is Level 1 — or assuming FCI means “no cybersecurity requirement” |
That subcontractor row is not a throwaway. If you do not know what information enters your systems, working a security checklist is the second job. The first is reading the agreement and tracing the data. Our CMMC for subcontractors page covers the flow-down mechanics under 32 CFR § 170.23.
What should you actually do in the first 30 days?
The goal of the first 30 days is not to finish Brilliant at the Basics. It is to establish what applies to you, get ownership and visibility in place, reduce the most obvious identity and remote-access exposure, prove you can restore a system, and produce an evidence-backed plan for the rest — in that order, because each step makes the next one cheaper.
Every step below names a deliverable, because a month of activity with nothing written down is a month you cannot show anyone.
Days 1–5: Authority and scope
Pull the solicitation, award, subcontracts, purchase orders, amendments, prime notices, and any contract modifications. Identify the applicable DFARS provisions and clauses. Determine whether FCI, CUI, covered defense information, or neither enters your systems. Sketch the data flows. Pick your working track: IT, OT, or both. Name one executive owner. Write down every legal or contractual question you cannot answer internally.
Deliverable: an applicability memo, a clause matrix, a first-pass data-flow sketch, and an owner list.
Days 6–10: Identities and assets
Inventory privileged, remote, service, vendor, shared, emergency, and inactive accounts. Reconcile your IT asset list against at least one discovery source and investigate every difference. If you have OT, build a separate as-operated inventory — controllers, HMIs, engineering workstations, safety systems, test equipment, firmware versions, protocols, remote-access points, owners, and whether each asset can touch CUI. Find the systems nobody owns.
Deliverable: an account register, a reconciled IT inventory, an OT inventory with proposed CMMC asset categories, and a written list of unknowns.
Days 11–15: Boundaries and access paths
Update your network and data-flow diagram. Identify every path into sensitive or operational environments — vendor tunnels, VPNs, cellular gateways, remote-support tools, forgotten modems, cloud administration, service accounts, backup consoles, and identity providers. Map where a compromised business laptop could reach a CUI system or production asset.
Deliverable: a boundary diagram, an administrative-path diagram, a remote-access pathway list, and a remote-access review record.
Days 16–20: Vulnerabilities and visibility
Take existing scan output and re-rank it by asset importance, exploitability, exposure, mission impact, and compensating controls rather than raw severity alone. Record patch constraints and classify them correctly: initial gap, temporary deficiency, or possible enduring exception. Inventory which systems produce usable logs and which do not. Assign someone to review the alerts.
Deliverable: a risk-ranked remediation queue, documented exception analyses, and a monitoring-coverage list.
Days 21–25: Prove you can recover
Restore one critical system from backup and time it. Run one tabletop — an IT incident if you are office-based, or a loss-of-critical-OT-asset, malicious-logic, or vendor-remote-access-compromise scenario if you run machines. Document escalation contacts, reporting decision points, vendor numbers, and the manual operating procedure if the system is down.
Deliverable: a restoration test record with the actual result, an exercise report, reporting decision criteria, and corrective actions. Record the failures honestly — an exercise that found nothing found nothing.
Days 26–30: Approve the rest
Assign every material gap to a named owner. Identify where you genuinely lack internal capability rather than time. Set evidence-retention expectations. Book the leadership review. Confirm the score or status somebody is expected to affirm. Set the next verification date.
Deliverable: a 60/90-day roadmap, an evidence register, a score-validation record, and a written decision about outside help.
One caution: this sequence is a default, not a prescription. If you already know you have an exposed vendor pathway into OT, an identity compromise, an unreported incident, an unsupported SPRS score, or a live proposal requiring a status you do not have, handle that now and come back to the calendar afterward.
What evidence should you keep?
Keep evidence that shows what you decided, what you implemented, who owns it, when you tested it, and what happened. Policies alone are not enough: CMMC assessment methods include examining artifacts, interviewing responsible people, and testing whether safeguards operate as described. Documentation states intent. Evidence shows operation.
There is one hard rule worth internalizing. 32 CFR § 170.24(b)(1) requires evidence used to support a MET finding to be in final form, not draft. Working papers, drafts, and unofficial or unapproved policies are expressly unacceptable. A polished draft policy scores the same as no final policy for that finding.
| Evidence category | What it looks like | What it demonstrates |
|---|---|---|
| Authority and scope | Clause review, FCI/CUI determination, contract-flow map, data-flow diagram, scope memo | Why systems and providers are in or out of the boundary |
| Ownership | Named system owners, requirement owners, executive approval, affirming-official review | Accountability — the thing interviews expose quickly |
| Configuration | Identity export, firewall rules, backup configuration, secure baselines, segmentation rules | The technical state you claim |
| Operation | Tickets, scan results, access reviews, monitoring records, approvals, exception reviews | That the safeguard keeps working rather than existing once |
| Testing | Restoration report, segmentation test, tabletop results, authentication test, alert-validation record | That the intended outcome actually occurs |
| Exception handling | Enduring-exception analysis, temporary-deficiency record, mitigation evidence, maintenance-window decision | Reasoned treatment of constraints rather than a label |
| Improvement | Corrective-action plans, completion records, retests, closed findings | Closure and continuous maintenance |
How long do you keep CMMC assessment evidence?
For CMMC Level 1 and Level 2 assessments, the rule is not vague: the artifacts used as evidence must be retained for six years from the CMMC Status Date. For a Level 2 certification assessment, the relevant artifacts are also hashed and the artifact names, hash values, and algorithm are recorded for the assessment process. See 32 CFR §§ 170.15–170.17.
Do not confuse that six-year assessment-artifact rule with the separate DFARS 252.204-7012 incident rule requiring specified images and monitoring or packet-capture data to be preserved for at least 90 days from submission of the cyber-incident report. One is assessment evidence retention. The other is incident-media preservation.
Your contract, records schedule, litigation hold, export-control duties, insurance policy, or another law may require longer. Six years is the CMMC floor for the artifacts used in the assessment, not permission to delete everything else the moment that period ends.
What are the biggest Brilliant at the Basics mistakes?
The most expensive mistake is treating the campaign as either meaningless because it is voluntary, or as a complete substitute for contractual CMMC and NIST SP 800-171 work. Both readings cost money. The useful position is to treat it as a prioritization lens while keeping a documented line between recommendations, binding requirements, scope, score, status, and evidence.
| Mistake | Why it happens | What it costs |
|---|---|---|
| Calling your company “Brilliant at the Basics compliant” | It sounds like a standard | A representation you cannot tie to an official assessment, status, or certificate |
| Assuming the 20 items equal the 110 requirements | The lists overlap with visible, high-value controls | An unsupported score, incomplete evidence set, and a program that fails when objectives are tested |
| Treating it as the interim enforcement benchmark | The July 13 release's final link points to the campaign | Working the wrong document. The release names NIST SP 800-171 Revision 2. |
| Stopping Revision 2 work because Revision 3 exists | NIST superseded Revision 2 in its own catalog | Building against a newer publication while losing traceability to the baseline currently assessed under CMMC |
| Reading the Phase II suspension as relief from safeguarding duties | Headlines said “suspended” | DFARS 252.204-7012, current SPRS-assessment duties, incident reporting, and contractual flow-downs do not disappear |
| Calling every OT asset “specialized” | OT appears in the Specialized Asset definition | Misclassified CUI Assets, Security Protection Assets, or Contractor Risk Managed Assets; missing requirement testing; a boundary you cannot defend |
| Applying enterprise scanning and patching methods straight to OT | The IT team owns “security” | Safety incidents, unplanned downtime, broken processes, and unsupported equipment |
| Buying software before scope and ownership are settled | A purchase feels like progress | A platform organizing evidence for a boundary you have not defined |
| Treating an editorial crosswalk — ours included — as an assessment determination | Tables look authoritative | A score or scope decision the source never made |
| Calling every patch constraint an enduring exception | The phrase sounds like permanent permission | A MET claim that fails because remediation was feasible, mitigations were weak, or the SSP never supported it |
| Manufacturing urgency from a date on a vendor slide | The old Phase II date still appears everywhere | Buying against a superseded implementation assumption rather than your current contract and official direction |
The dates that should drive spending are current proposal deadlines, award conditions, contract modifications, option exercises, prime deadlines, assessment expirations, annual affirmations, POA&M closeouts, and new official implementation action. A stale November 10 slide is not authority.
Who should ignore this page
We would rather lose you here than waste your quarter.
- If you handle no FCI and no CUI in contract performance, CMMC likely does not apply to those systems. Verify that against the actual procurement and data flow, document why, then read CMMC Levels and stop buying Level 2 work.
- If you handle FCI but no CUI and your requirement is Level 1, the 110-point ledger is the wrong universe. Start with the 15 FAR-derived Level 1 requirements and your annual self-assessment and affirmation.
- If your problem is “I don't know what level or assessment type my solicitation requires,” this is the wrong page. Start with CMMC Levels, self-assessment versus C3PAO assessment, and the exact DFARS 252.204-7025 language in your solicitation.
- If you already hold a Final Level 2 C3PAO status, the July 13 release did not state that your status was revoked. Maintain the status and annual affirmation requirements that apply, watch official implementation changes, and do not let a voluntary campaign overwrite the assessed scope you already have.
- If you handle classified information, CMMC is the FCI/CUI program, not the classified-system authorization regime. Separate the systems, rules, and program-security conversation correctly.
- If someone told you a Brilliant at the Basics countdown is running, there is no campaign deadline, no campaign certificate, and no campaign enforcement date. Ask them to identify the solicitation, clause, modification, or written customer term that creates the deadline.
When do you need outside help, and what kind?
Choose outside help based on the capability gap you actually have, not on which provider reached you first. Readiness advisory, ongoing managed security, OT engineering, evidence software, enclave architecture, and formal assessment are different functions — and one purchase should never be presented as satisfying all of them.
Nothing on the Brilliant at the Basics page requires you to hire anyone. Most of the first 30 days above is internal work. But outside help makes sense when the missing capability is real and the category is right.
| Category | Hire when | Do not confuse it with | Verify before you sign |
|---|---|---|---|
| Internal team only | You understand the contract and scope, owners are assigned, technical capability exists, and evidence discipline is real | Independent review | Who performs a second-person review of the implementer's work |
| RP or RPO | Level, scope, gap analysis, SSP, evidence planning, or remediation sequencing is unclear | A certifying assessor. An RP or RPO does not issue a CMMC status | Current Cyber AB Marketplace status, named personnel, deliverables you own afterward, data-handling terms, and conflict position |
| CMMC-focused MSP or MSSP | Controls need to be implemented and operated continuously | Proof that you are compliant or that every requirement is “handled” | Shared-responsibility matrix, ESP scope, evidence output, tenant ownership, incident duties, and administrative access paths |
| OT security specialist | Legacy machinery, IIoT, safety systems, vendor access, or test equipment materially affects scope or risk | A complete CMMC program owner | Real OT experience, safe validation methods, change-control coordination, and who owns the CMMC mapping |
| CUI enclave provider | CUI workflows can credibly be contained and separated | A universal answer. Connected endpoints, administration, printing, exports, backups, and integrations can remain in scope | Customer-responsibility matrix, CSP or ESP treatment, FedRAMP position where applicable, integrations, identity model, export paths, and recurring cost |
| GRC platform | Evidence, SSP and POA&M workflow, ownership, and recurring operations need structure | Implementation. Software cannot configure a firewall, classify a CNC, or make weak evidence true | Revision 2 mapping, evidence export, data ownership, access controls, OT and Specialized Asset support, and vendor exit plan |
| C3PAO | A formal Level 2 certification assessment is required or strategically justified and the organization is ready | Readiness consulting for the same assessment or a guaranteed certificate | Current authorized or accredited status in the Cyber AB Marketplace, scope, assessor assignment, conflicts, fees, appeals, data handling, and assessment contract terms |
The independence rule, stated precisely
Under 32 CFR § 170.8, a CMMC ecosystem member may not participate in a Level 2 certification assessment of an organization when that member served as a consultant preparing that organization for a CMMC assessment within the previous three years.
The Cyber AB CMMC Assessment Process, Version 2.0 puts responsibility on the C3PAO to identify and manage conflicts. If a conflict cannot be sufficiently mitigated, the C3PAO does not proceed. Verify the specific organizations, people, and roles; a marketing statement about “separate teams” does not override the legal and process rules.
The same CAP prohibits a C3PAO from offering guarantees or promises about the result of a Level 2 certification assessment and prohibits incentives or bonus payments contingent on issuance of a Certificate of CMMC Status. “Guaranteed certification” is not aggressive marketing. It conflicts with the assessment-process rules and should stop the buying conversation.
The cost reality, from the Department's own analysis
The regulatory impact analysis accompanying the CMMC final rule published per-entity estimates for assessment and affirmation activity. It expressly assumes the underlying security requirements are already implemented, so these are not full remediation budgets.
| Path | Small-entity estimate | Other-than-small estimate | What the estimate covers |
|---|---|---|---|
| Level 1 self-assessment | $5,977 per year | $4,042 per year | Annual self-assessment and affirmation under the rule's assumptions |
| Level 2 self-assessment | $37,196 over three years | $48,827 over three years | Triennial self-assessment plus annual affirmations |
| Level 2 C3PAO assessment | $104,670 over three years | $117,768 over three years | Certification-assessment preparation, assessment, reporting, C3PAO activity, and annual affirmations under the model |
Every one of those estimates assumes the security work is already done. The Department did not count the cost of implementing existing safeguarding requirements such as DFARS 252.204-7012 as a new CMMC cost because those obligations predated the CMMC rule. Our CMMC Level 2 cost guide separates assessment cost from implementation, operations, cloud, enclave, OT, and evidence cost.
Where the enforcement risk actually sits
We are not going to use fear as a closing tool, but you should know the shape of the risk, because it is what makes accurate paperwork matter more than a checklist.
On June 18, 2026, the Department of Justice announced that Alabama defense contractor LOGZONE Inc. agreed to pay $507,144 to resolve False Claims Act allegations involving cybersecurity requirements on two Navy contracts. The settlement agreement states that LOGZONE submitted a perfect self-assessment score of 110 to SPRS on October 13, 2021, while a DIBCAC Medium Assessment completed February 2, 2024 resulted in a score of negative 170 on the −203 to 110 range. DOJ said the relevant conduct ran from May 2021 to March 2025. The claims were allegations, and DOJ stated there had been no determination of liability.
Note what that matter turned on: not a Brilliant at the Basics practice and not a campaign certificate. It involved contractual cybersecurity requirements, claims for payment, a self-reported score, and an assessment result that did not match it.
The suspension of the planned Phase II transition does not make an unsupported self-assessment safer. The Department can still conduct government-led assessments under DFARS 252.204-7020, and CMMC affirmations remain representations that must match the status being maintained. Our CMMC non-compliance penalties and enforcement guide covers the broader landscape.
Map the work to the right category before you collect a single quote
Tell us the level and assessment type in your paperwork, whether you handle FCI or CUI, your cloud and IT environment, whether OT is involved, and your contract timeline. Find My CMMC Path shows the category logic before it shows provider options, so the quotes you collect are for the same kind of work.
Find the right CMMC provider category →
Do not submit CUI, drawings, export-controlled content, credentials, system names, IP addresses, or sensitive contract attachments. The intake is for category routing, not compliance evidence.
Disclosure: The Defense Compliance Report is an independent trade publication. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category framework, or Cyber AB status verification. See our Editorial and Advertising Policy.
Free help first, since you are paying for enough already
Before you buy anything, use the no-cost sources the Department and ecosystem already maintain:
- the Cyber AB Marketplace to verify current C3PAO, RPO, and practitioner status;
- the Department's CMMC Resources and Documentation page for the current scoping and assessment guides;
- DC3 DCISE for DIB cybersecurity services and information-sharing support; and
- Project Spectrum for no-cost tools, training, and resources aimed at small DIB businesses.
We receive nothing from any of them.
What we actually verified
We do not ask you to take our word for any of this. Here is what we read and cross-checked on August 17, 2026, and what each source supports.
| Primary source | What it supports |
|---|---|
| DoW CIO Brilliant at the Basics campaign page | The two Top 10 lists and official practice names; the IT v1 and OT v2 filenames; 19 linked resources; the educational-and-informational disclaimer |
| DoW release, July 13, 2026 | Immediate suspension of the planned Phase II transition and pending/future milestones; Phase I self-assessment requirements remain; interim enforcement against NIST SP 800-171 Revision 2 through self-assessments and select government-led assessments; DFARS 252.204-7012 remains |
| DoW CMMC About page and Resources page | Current public implementation status and official CMMC scoping, assessment, NIST, DFARS, and SPRS resources |
| 32 CFR Part 170 | CMMC levels and assessment types; Revision 2 incorporation; asset categories; scoring; final-evidence rule; enduring exceptions; temporary deficiencies; POA&M limits; six-year artifact retention; affirmations; subcontract application; ecosystem independence |
| DFARS 252.204-7012 | NIST SP 800-171 safeguarding duty, cloud conditions, 72-hour incident reporting, 90-day media preservation, government access, and flow-down |
| DFARS 252.204-7019 and 252.204-7020 | Current NIST SP 800-171 DoD assessment and SPRS requirements, government Medium/High assessment access, and subcontract assessment conditions |
| DFARS 252.204-7021 and 252.204-7025 | CMMC status, UID, affirmation, maintenance, flow-down, solicitation designation, and award-eligibility mechanics |
| NIST SP 800-171 DoD Assessment Methodology v1.2.1 | Annex A point values; 1/3/5 weighting; assessment range; SSP requirement; scoring treatment and definitions used in the ledgers |
| NIST SP 800-171 Revision 2 and Revision 3 | Publication dates, supersession history, Revision 2's 14-family baseline, and Revision 3's 17-family structure |
| NIST SP 800-172, February 2021 and SP 800-172 Revision 3 | The separate NIST version history that does not automatically amend the Level 3 baseline incorporated in 32 CFR Part 170 |
| NIST SP 800-63B | Replay resistance, phishing resistance, out-of-band and OTP limitations, PIV/CAC channel binding, and WebAuthn verifier-name binding |
| Cyber AB CMMC Assessment Process v2.0 | C3PAO conflict management, unmitigable-conflict treatment, assessment contract rules, and prohibition on guaranteed outcomes or certificate-contingent incentives |
| CMMC final rule and regulatory impact analysis | December 16, 2024 effective date and the assessment/affirmation cost estimates used in the cost table |
| DOJ LOGZONE announcement and settlement agreement | Settlement amount, alleged conduct dates, 110 self-score, −170 DIBCAC score, assessment range, contract clauses, and allegation/no-determination posture |
What we could not establish, and will not pretend to
- Whether the CMMC Reform Task Force will elevate any Brilliant at the Basics practice into a requirement. The Department announced a 60-day review. The outcome requires an official document, not prediction.
- Whether either campaign PDF was revised before the version currently posted. The IT filename is v1, the OT filename is v2, and neither showed a visible revision date when we reviewed it.
- Any official Brilliant at the Basics-to-NIST-SP-800-171 crosswalk. We found none on the official campaign, Department CMMC resources, or NIST publication pages as of August 17, 2026. Our mapping is editorial.
- Your contract, amendment status, CMMC designation, prime flow-down, or current customer position. No general page can resolve those.
- Whether a specific file, drawing, email, model, or shop-floor dataset is CUI. That requires the governing authority, markings, contract context, and facts.
- A universal implementation cost or timeline. Scope, architecture, current posture, OT, cloud, external providers, and evidence maturity vary too much for an honest single number.
- That a named product, provider, or architecture guarantees certification. The Cyber AB assessment process prohibits C3PAO guarantees about assessment results.
A note on our own numbers
The 71-point IT figure, 87-point raw OT figure, 63-point nonoverlapping OT addition, and 134-point combined figure are ours, computed from the Department's published weights. We independently summed Annex A's scored deductions to 313; the published −203 floor yields the same total when subtracted from the 110 maximum.
The negative 132 and negative 69 figures are best-case ceilings under generous editorial mappings and only after a current SSP makes the assessment completable. They are not predictions of what an assessor would score, not CMMC statuses, and not an official crosswalk.
See our Methodology, Editorial Standards, and Corrections Policy.
Brilliant at the Basics: frequently asked questions
Is Brilliant at the Basics cybersecurity guidance mandatory? No. It is voluntary guidance published by the Department of War CIO. The campaign describes its content as educational and informational. Your binding obligations come from applicable solicitation, contract, subcontract, purchase-order, and flow-down terms.
Is it a new cybersecurity regulation? No. It was not published as a Federal Register rule, is not codified as a new assessment baseline in 32 CFR Part 170, and is not a named requirement in the current DFARS cybersecurity clauses. It is a campaign webpage with two downloadable one-page references.
Did Brilliant at the Basics replace CMMC? No. CMMC is established by 32 CFR Part 170 and implemented through the acquisition and contract framework. A CIO campaign cannot amend the rule or your contract.
Is Brilliant at the Basics the interim standard during the CMMC Phase II suspension? No. The July 13, 2026 release says the Department will enforce cybersecurity compliance with NIST SP 800-171 Revision 2 through self-assessments and select government-led assessments. The campaign is not named as the assessment standard.
What happened to the November 10, 2026 Phase II date? It was the original start date for Phase II. The Department suspended the transition to Phase II on July 13, 2026. Phase I began November 10, 2025 and its self-assessment requirements remain in place pending further official action.
How many Brilliant at the Basics practices are there? Twenty: ten for IT environments and ten for OT environments. Coverage that mentions only ten has missed half the campaign.
Does implementing the IT list raise my SPRS score? Indirectly, if implementation fully satisfies mapped Revision 2 requirements and the requirements are in scope. Our upper-bound mapping touches 19 requirements representing 71 weighted points. The campaign itself is not scored.
What score do all ten IT practices produce? The campaign alone produces no valid assessment score because it does not supply the required current SSP. Add the SSP, grant full credit for all 19 mapped requirements, and nothing else: the generous ceiling is approximately −132 out of 110.
Does Brilliant at the Basics satisfy DFARS 252.204-7012? No. DFARS 252.204-7012 requires adequate security, applicable NIST SP 800-171 implementation, incident reporting, cloud conditions, and flow-down duties. Twenty voluntary practices do not satisfy the full clause.
What do DFARS 252.204-7019 and 252.204-7020 add? They add current NIST SP 800-171 DoD assessment and SPRS requirements, government access for Medium or High assessments, and subcontract assessment conditions. They do not turn Brilliant at the Basics into the scorecard.
What do DFARS 252.204-7021 and 252.204-7025 add? They handle the CMMC status and affirmation framework in the contract and the required CMMC level, assessment type, status, affirmation, and UID conditions in the solicitation and proposal.
Can we say we are “Brilliant at the Basics compliant”? No. There is no official standard, passing criterion, assessment, status, or certificate behind that phrase. State the specific practices you implemented and the evidence instead.
Is phishing-resistant MFA required by NIST SP 800-171 Revision 2? No. Revision 2 requires MFA and replay-resistant authentication; it does not require phishing resistance. A separate customer, prime, solicitation, or contract term may still require it.
Does ordinary MFA count as phishing-resistant? Usually not. SMS, voice codes, authenticator-app OTPs, and basic push approvals are not phishing-resistant. PIV/CAC, FIDO2/WebAuthn security keys, and verifier-bound passkeys can be. Verify the actual protocol and deployment rather than the product label.
Does the OT list apply to my shop-floor equipment? The security guidance may. The CMMC scoring treatment depends on each asset's category. An OT system may be a CUI Asset, Security Protection Asset, Contractor Risk Managed Asset, Specialized Asset, or Out-of-Scope Asset.
Are all OT assets Specialized Assets? No. OT appears in the Specialized Asset definition, but the asset must be able to handle CUI and be unable to be fully secured. An OT asset that stores CUI can be a CUI Asset; a firewall protecting the CUI boundary can be a Security Protection Asset; an isolated machine that cannot handle CUI can be out of scope.
If a Specialized Asset is not assessed against the other Level 2 requirements, why document it? Because the rule requires the asset inventory, SSP treatment, network-diagram treatment, and risk-based management. The assessor reviews that SSP coverage. “Not assessed against the other requirements” does not mean “do not document.”
We cannot patch a production controller. What do we do? Classify the asset and the gap first. A true enduring exception, with mitigations described in the SSP, is assessed MET under § 170.24. A temporary deficiency may be MET when appropriately managed in an operational plan of action. An initially unimplemented requirement is NOT MET and only qualifies for a CMMC POA&M under strict conditions. “Legacy” alone does not decide which one applies.
Do office-based contractors need the OT list? Usually not if they operate no systems that monitor or control physical processes. Do not infer OT applicability from an industry label, and do not ignore building-control, physical-access, laboratory, test, or embedded systems that actually fit the OT definition.
Is NIST SP 800-171 Revision 3 the CMMC baseline now? No. Revision 3 is NIST's newer publication, but current CMMC Level 2 assessments remain tied to Revision 2 under 32 CFR Part 170. Future-facing Revision 3 work does not replace Revision 2 traceability today.
Is NIST SP 800-172 Revision 3 automatically the CMMC Level 3 baseline? No. NIST published Revision 3 in May 2026, but the current CMMC rule incorporates the February 2021 SP 800-172 and selects 24 enhanced requirements. The rule must change before the Level 3 baseline changes automatically.
Does completing all 20 practices make us CMMC compliant? No. Our two ledgers touch 36 unique Revision 2 requirements under generous and conditional mappings. The campaign does not supply the other requirements, an SSP, a complete scope, final evidence, an assessment, an affirmation, or a CMMC status.
Who published Brilliant at the Basics, and when? The Department of War Chief Information Officer published the campaign. The Department's July 13, 2026 Phase II suspension release linked to the campaign as its “more information” destination.
Will Brilliant at the Basics become mandatory? We do not know. A future rule, DFARS change, class deviation, contract term, or other authorized action could make specific practices binding. Until an official instrument does that, prediction is not authority.
Should we hire a C3PAO to implement the list? Not if that organization or ecosystem member will later participate in your Level 2 certification assessment and the work creates a prohibited conflict. Use a readiness category for implementation and keep formal assessment independence clear. A C3PAO cannot guarantee the assessment outcome.
Can a GRC platform implement this for us? No. Software can assign requirements, organize evidence, maintain workflows, and expose gaps. It cannot segment a network, replace an unsupported controller, decide contractual applicability, make a configuration operate, or turn weak evidence into a MET finding. See our CMMC software breakdown.
These answers are educational. For binding answers about your contracts, consult qualified CMMC and federal-contracts professionals.
Your next step
You do not need to do twenty things this month.
You need four, in this order: confirm what the written requirement actually is, find out what information enters your systems, put a defensible boundary around it, and then decide whether you need help — and what kind.
The first three are internal work. The fourth is where contractors lose six figures, usually by hiring the wrong category first or buying a platform before they know the boundary.
Find My CMMC Path → Map the level, assessment type, data, environment, and timeline to the right provider category.
Get the CMMC Readiness Checklist → Review all 110 NIST SP 800-171 Revision 2 requirements across the 14 families and the evidence each one needs.
Compare provider categories → Understand what an RPO, MSP/MSSP, enclave provider, GRC platform, OT specialist, and C3PAO can and cannot do.
Request matched quotes → Use this only after the category and scope are clear enough that providers will quote the same job.
Do not submit CUI, drawings, export-controlled content, credentials, system names, IP addresses, or sensitive contract details. General routing forms are not compliance repositories.
Related reading
- CMMC Phase 2 suspended: what changed on July 13, 2026
- CMMC Level 1 vs. Level 2 vs. Level 3
- CMMC self-assessment vs. C3PAO assessment
- CMMC scoping guide
- SPRS score: what contractors need to know
- How to improve an SPRS score without inflating it
- CMMC Level 2 assessment guide
- CMMC Level 2 cost guide
- Who to hire first for CMMC
- CMMC provider categories compared
- CMMC non-compliance penalties and enforcement
- NIST SP 800-171 Revision 2 vs. Revision 3
- CMMC for machine shops
- CMMC for shipbuilders
- CMMC for manufacturers
- CMMC for subcontractors
About this report
The Defense Compliance Report Editorial Team covers CMMC and Defense Industrial Base compliance as an independent trade publication. We do not accept editorial-approval rights from sponsors. This guide is editorial research and has not been formally reviewed by a CMMC Subject Matter Advisor.
We are not affiliated with the Cyber AB, the Department of War, the Department of Defense, DCMA DIBCAC, NIST, or any U.S. government agency. Provider compensation and sponsorship rules are explained in our Editorial and Advertising Policy.
Change log
- August 17, 2026 — Initial publication and production audit. Verified against the DoW CIO Brilliant at the Basics campaign and both IT and OT one-pagers; the July 13, 2026 DoW release; current 32 CFR Part 170; current DFARS 252.204-7012, -7019, -7020, -7021, and -7025; the NIST SP 800-171 DoD Assessment Methodology v1.2.1; NIST SP 800-171 Revisions 2 and 3; NIST SP 800-172 and Revision 3; NIST SP 800-63B; the Cyber AB CAP v2.0; the CMMC final-rule regulatory impact analysis; and the June 18, 2026 DOJ LOGZONE materials. Corrected the OT asset-category analysis, score-versus-status treatment, POA&M distinctions, evidence-retention period, MFA claims, cost figures, and source attributions.
Found an error? Our Corrections Policy explains how we handle it.
Content on The Defense Compliance Report is educational and is not legal, contractual, assessment, or compliance advice. Consult qualified CMMC and federal-contracts professionals before making compliance or contract decisions.