CMMC gets described as basic cyber hygiene, sometimes by the people who wrote the rules. Vincent Scott, CEO of Defense Cybersecurity Group and a retired Navy cryptologist who spent his career on offense, explains why he considers it the hardest cybersecurity standard in the world, and what that means for how you plan the work.
Key Takeaways
- The most damaging idea in circulation is that CMMC is just the basics. It disengages the executives who need to own the program and licenses the last-minute approach to compliance that this standard is specifically designed to catch.
- The difficulty is in the assessment methodology rather than the individual controls. CMMC asks for adequate and sufficient evidence of full implementation everywhere with no exceptions, which is a zero-defect bar.
- Device control on everything connecting to the system is a Level One requirement and one of the harder things to implement with real rigor across an entire environment.
- Fast, right, cheap: pick any two. The advice for five years was slow and steady. Compressed timelines change which of the three quietly gets sacrificed.
- Picking the right leader matters more than picking the right methodology, and evaluating a partner's expertise requires expertise the buyer usually does not have yet.
- The requirements are going to continue, and the exposure runs past any single company to national defense capability.
Table of Contents
- Why the Pause Was Always Going to Happen
- The Foundational Myth Is That This Is Just the Basics
- The Hardest Cybersecurity Standard in the World
- Fast, Right, Cheap: Pick Any Two
- Hard Problems Are Solved by People, Not Methodologies
- The Business Argument Does Not Always Land
- The Requirements Continue, and So Does the Risk
Most of the CMMC conversation right now is about timing. What the pause means, when the third-party assessment requirement comes back, and what a contractor should be doing in the gap.
Vincent Scott has an unusual vantage point on that question. He is a retired US Navy cryptologist and information warfare officer, twenty-one years in, whose last military role was deputy chief of intelligence collection for Europe and Africa. He describes his career in one line: he used to play offense, and now he coaches defense. Today he runs Defense Cybersecurity Group, where every client is a company that has to comply with CMMC, and he teaches the certified assessor course on the side.
What follows is less about the schedule and more about the shape of the standard itself, which in his view almost nobody describes accurately.
Why the Pause Was Always Going to Happen
Scott's read on the pause is structural, and he is direct that it differs from where a lot of industry commentary landed.
"I think this pause was inevitable," he says. "The rollout plan for CMMC, the phased rollout, when I first read it, my first thought was, this isn't a phased rollout, it's a cliff implementation."
The cliff was a single date. Nobody had to be certified the day before it, and everybody did the day after, for all new contracts and awards. Officially that was not a deadline, and Scott is aware of how loudly that was said. He is also clear about how it read from the other side of the table.
"If I look at that from a contractor perspective who has a pipeline of government contracts that we're continuously trying to win in order to stay in business, and you tell me that I cannot win any contracts after this date unless I am certified, that now becomes a deadline for me."
The arithmetic is what makes his argument hold. By his estimate, roughly two percent of the defense industrial base was certified in July, and perhaps three percent by year end. Those figures are his own read on the market rather than a published count, but the direction is not really in dispute. A department cannot remove the overwhelming majority of its own supply chain from competition on a single day.
He is careful about where the fault sits. This is not a capacity problem with the C3PAOs and not their failure. It is that the rollout plan was written without correlating how many companies needed certification against how quickly certification could realistically happen, which is a different exercise from the earlier regulation where the number of certifications per year was controlled directly.
"In no world could the DoD do that to themselves," he says. Regardless of the reasons eventually put forward, something like this was always going to have to occur.
The Foundational Myth Is That This Is Just the Basics
Asked for the biggest pitfall he sees, Scott does not name a control family. He names a belief.
"The number one problem is what I call the foundational CMMC myth, that this is just the basics."
He attributes the myth to the people best positioned to spread it. Senior government officials have described the standard as something they do at home in thirty days, and as what you need to protect your Netflix account. Scott quotes both lines directly and does not soften his reaction. It still makes him angry.
What bothers him is the downstream effect rather than the inaccuracy. "You put industry leadership back to sleep," he says. An executive who believes this is basic sees no reason to own it, and the organization defaults to what he calls the standard approach to compliance.
His description of that approach is worth quoting in full, because it is recognizable to anyone who has been through a certification. The weekend before the assessor shows up, you lock the team in a conference room, shove pizza under the door, and tell them they cannot come out until the policies are done. The following week you show the assessor a set of shiny new policies. The assessor calls them brilliant and issues the certification.
That routine works more often than the industry likes to admit. In Scott's experience most certification assessments never look for evidence of implementation at all, much less evidence of implementation throughout the assessed system.
CMMC asks a second question. Show me your policy, and then show me you are doing this for real, with evidence. He considers that level of rigor a genuine improvement in the standard, and also the reason the weekend approach collapses against it.
As for the claim that the controls themselves are elementary, he offers a specific counterexample: device control over everything connecting to the system. That is a Level One requirement, described as foundational, and in his words a really hard control to implement with rigor and evidence across an entire environment.
The Hardest Cybersecurity Standard in the World
When people ask him to characterize CMMC, Scott gives an answer he knows is contentious.
"I consider CMMC to be the hardest cybersecurity standard in the world because of its demand for adequate and sufficient evidence of full implementation everywhere with no exceptions."
The mechanism he points to is not the requirements list. "It's not the individual controls per se, it's the zero-defect approach of the assessment methodology that makes it truly extraordinarily challenging."
That distinction changes how a program should be planned. Under a standard that evaluates posture and intent, a control implemented across most of the environment is a reasonable position to defend. Under a zero-defect methodology, the remainder is the finding. Coverage gaps that would be footnotes elsewhere are the entire outcome here.
Scott expects disagreement on this and says so plainly. He also does not usually lead a client conversation with it, because nobody wants to hear that the thing in front of them is the hardest version of itself. People want to hear it can be done cheaply, easily and quickly.
Which brings the conversation to what that actually costs.
Fast, Right, Cheap: Pick Any Two
Scott reaches for a line he uses constantly, and it comes from outside the industry entirely.
Red Adair made his name putting out oil well fires. In 1992 the Kuwaitis called him in after the Iraqis blew the wells, with hundreds of them burning across the country. Rumor has it Adair told them: have it done fast, have it done right, have it done cheap. Pick any two.
"And I think it goes for CMMC," Scott says.
For the five years running up to certifications becoming real, the advice he gave clients was slow and steady wins the race. Take a methodical approach. Spread the work and the cost. You do not have to solve every problem today.
That changed. Increasingly in 2026 the request is to have it done in two months, and to have it done right, and to have it cheaply. All three at once.
His response is not a complaint about clients. It is a point about how projects work. "The reality of almost every project in the world is that you can't have all three." He compares it to wanting a new aircraft carrier quickly. The desire is understandable and the real-world constraints do not move much.
The practical value of naming the tradeoff is that it forces the choice into the open. Every compressed program sacrifices one of the three. The question is whether the organization decided which one, or found out later.
Hard Problems Are Solved by People, Not Methodologies
Asked what a good process looks like, Scott declines the premise. There is no shortage of published methodologies, and he does not think that is where programs are won.
"Whenever you have a hard problem, the most important part of solving your hard problem is picking the right people. This isn't a CMMC thing, it's an everything thing."
He is blunt about how little the surrounding apparatus rescues a program without the right leader. "It doesn't matter how good your methodology is or how many spreadsheets you have or how much technology you buy. If you don't have the right person or persons leading this effort, you are headed for problems."
That makes partner selection the pivotal decision, and it is where his frustration is sharpest, because expertise has become the default claim rather than a differentiator. He describes walking the floor at the VETS-26 conference in New Orleans in April, where every other booth with IT in it advertised CMMC expertise or words to that effect.
"You go up and ask them some questions, and expertise is not what I saw." His test is unforgiving and effective. Someone tells him there is a deadline in April. He knows there is no deadline in April. At that point the conversation is over.
The structural problem is that the buyer usually cannot run that test. Evaluating expertise requires expertise, and a contractor working through this for the first time does not have it. What Scott recommends instead is verifiable evidence rather than assertion: whether the firm has certified assessors, whether it has real assessment experience, whether it has customers who passed using its approach.
He also points to the scale of the reading involved. His own list of documents required to do this properly runs to roughly three times the New Testament, covering DFARS 7012 and 7021, 32 CFR, NIST 800-171 and 171A, 172 and 172A, plus two major FAQs that meaningfully inform implementation decisions. It changes and updates, which makes fluency a continuous exercise rather than a credential.
His recommendation for the internal owner is specific. Send somebody through the CMMC Certified Professional course. That person will not become the expert, but they will be able to evaluate whether the outside advice arriving at the table is any good. Which matters, because a lot of it is not, particularly the advice that everyone must migrate to GCC High and spend two hundred thousand dollars doing it. That may be right for a specific organization. It is frequently overkill for a particular set of use cases.
The Business Argument Does Not Always Land
Scott splits the case for doing this work into two halves.
The first is contractual. At some point you will need this to win work, it is hard, so start now. The second is the security argument itself: this represents risk to your company, your intellectual property will be stolen, your business will be damaged, your money will be taken.
Both are true. Neither is universally persuasive.
"I've had the CEO of a billion-dollar company look me in the eye and say, I don't really care that much about cybersecurity because I'll pay the ransom if I need to, and otherwise I'm not gonna worry about it."
The detail that gives the anecdote weight is what the company does. It performs genuinely sensitive Department of Defense supply chain work. Not a prime, a tiered sub, but the kind of work Scott says he would have cared about a great deal from an offensive perspective. Which is not a hypothetical framing coming from him.
His assessment of the exchange is one sentence long. "You don't always win."
For anyone building the internal case, the useful lesson is that the ransom calculation ignores most of the actual loss. Stolen intellectual property does not get returned when the invoice clears, and neither does a damaged position in a supply chain that people are watching.
The Requirements Continue, and So Does the Risk
Asked what he most wants contractors to take away, Scott moves past the schedule entirely.
"The biggest thing in the CMMC space is that the requirements are gonna continue."
The stakes, as he frames them, are not contained by the company. "There is a risk to not only your company, but the nation as a whole and our defense capability in the cyber arena."
That is a familiar sentence from a vendor and a different sentence from someone who spent two decades collecting intelligence against exactly this kind of target. His conclusion is cooperative rather than commercial. "It's going to take all of us to better defend not only our information, but our companies and our country. And that means we're gonna need to work together in order to do a better job than we have to this point in erecting effective defenses."
He returns to detection when the frame widens beyond compliance. In his view it is the least appreciated capability in cybersecurity, underfunded and underloved across both government and industry, and the gap between prevention and incident response sits exactly there. The reason is simple enough to state in one line: you cannot respond to a breach or attack that you do not know is happening.
Read together, his position is coherent. The rollout structure was never going to survive contact with the size of the defense industrial base. The standard is considerably harder than its public description. Compressed timelines force a tradeoff whether or not anyone names it. And the decision that determines the outcome is which people you put on the problem.
The question is not whether CMMC is basic. It is whether the controls you claim are actually operating everywhere, with evidence, on the day someone qualified comes to look. A standard that allows no exceptions is not one you prepare for in a weekend.
BEMO builds the security program first and operates it continuously, implementing the controls, maintaining the evidence, and coordinating the C3PAO directly. That way full implementation is a description of the environment rather than a claim made shortly before an assessment.
Frequently Asked Questions
Why does Vincent Scott think the CMMC pause was inevitable?
Because the rollout functioned as a cliff rather than a phase. Certification was not required one day and required the next for all new contracts and awards, while only a small percentage of the defense industrial base was certified. Removing the overwhelming majority of its own supply chain from competition was not something the department could realistically do to itself.
Is CMMC really just basic cyber hygiene?
Scott calls that the foundational CMMC myth and traces it to senior officials comparing the standard to protecting a home Netflix account. He points to device control over everything connecting to the system, a Level One requirement, as an example of something described as basic that is difficult to implement with rigor and evidence across an entire environment.
What makes CMMC harder than other cybersecurity standards?
The assessment methodology rather than the controls. CMMC demands adequate and sufficient evidence of full implementation everywhere with no exceptions, which Scott describes as a zero-defect approach. Most certification assessments do not test whether a control is genuinely operating throughout the assessed system.
Why does the weekend-before approach to compliance fail here?
Because CMMC asks a second question. Other assessments frequently stop at the policy. This one asks for proof the policy is being executed, with evidence, across the impacted system. Documentation written days before an assessment cannot produce that evidence retroactively.
Can a CMMC program be done fast, well and cheaply?
Scott borrows Red Adair's line and says pick any two. For years his advice was methodical and unhurried, which protected both quality and cost. Compressed timelines force one of the three to give, and the value of naming the tradeoff is deciding which one rather than discovering it later.
How should a contractor evaluate a CMMC partner?
Look for what can be verified rather than what is claimed: certified assessors on staff, real assessment experience, customers who passed using that approach. Scott also recommends putting someone internal through the CMMC Certified Professional course, so the company has its own basis for judging whether outside advice is sound.
Top 10 Posts
-
Office 365 MFA Setup: Step-by-Step Instructions
-
CMMC Phase 2 Suspended: What the Compliance Pause Changed
-
Google Workspace to Office 365 Migration: A Step-by-Step Guide
-
What is The CIA Triad?
-
How Much Does ISO/IEC 27001 Lead Auditor Certification Cost in 2025?
-
SharePoint vs. OneDrive (What's the Difference Again?)
-
What is Microsoft Purview ? Your A to Z Guide to Getting Secure Fast
-
How to Migrate from GoDaddy to Office 365
-
When Will CMMC 2.0 Be Required for DoD Contracts?
-
How to Set Up Office Message Encryption (OME)


Leave us a comment!