Cybersecurity Blog

Why CMMC Exists: The Cost of Weak Cybersecurity in the Defense Industrial Base

Written by BEMO | Aug 24, 2026

Quick Answer: CMMC was created because self-attestation alone was not providing sufficient confidence that defense contractors were adequately protecting sensitive government information. In this episode of Trust Issues, Stacy Bostjanick, former Director of CMMC Policy at the Pentagon, explains how decades of inconsistent cybersecurity practices, weak documentation, and unverified compliance led to the need for independent assessments. The conversation highlights why contractor cybersecurity is more than a compliance issue. It is critical to protecting innovation, supply chains, and national security.

Key Takeaways

  • CMMC was introduced because self-attestation was no longer providing reliable assurance.
  • Many organizations claimed compliance without effectively implementing required controls.
  • Stolen defense information can undermine years of taxpayer-funded research and development.
  • Small contractors are frequent targets because they often hold valuable information and supply chain access.
  • A single compromised supplier can affect an entire defense program.
  • CMMC represents the beginning of a broader shift toward continuous security and zero trust.
  • Organizations cannot wait for a future solution to address cybersecurity risks that exist today.

Table of Contents

  1. Why CMMC Became Necessary
  2. The Failure of Self-Attestation
  3. The Real Cost of Stolen Innovation
  4. Why Small Contractors Are Prime Targets
  5. Cybersecurity and Supply Chain Resilience
  6. CMMC Is Only the Beginning
  7. The Bottom Line for Defense Contractors
  8. Listen to the Full Episode
  9. Frequently Asked Questions

 

Why CMMC Became Necessary

For years, defense contractors were expected to protect Controlled Unclassified Information (CUI) and other sensitive government data through compliance with requirements such as DFARS 252.204-7012 and NIST SP 800-171.

On paper, many organizations reported they were meeting those obligations.

In practice, the situation was often different.

In this episode of Trust Issues, Brandon and Bruno Lecoq sit down with Stacy Bostjanick, former Director of CMMC Policy at the Pentagon, to discuss why the Department of Defense ultimately determined that additional validation was necessary.

The conversation reveals how years of inconsistent cybersecurity practices contributed to the development of CMMC and why independent verification became an important part of the defense contracting ecosystem.

 

The Failure of Self-Attestation

Prior to CMMC, many contractors relied on self-attestation to demonstrate compliance with cybersecurity requirements.

The process depended largely on organizations accurately evaluating their own security posture and honestly reporting the results.

According to Stacy, that approach frequently failed.

Organizations sometimes relied on generic System Security Plans copied from publicly available templates, incomplete remediation plans, or documentation that did not accurately reflect operational reality. While paperwork existed, implemented security practices often did not align with documented claims.

As confidence in self-attestation declined, the Department of Defense introduced CMMC to provide independent verification that required controls were operating as intended.

The goal was not simply to generate more documentation. The goal was to validate that cybersecurity processes were actually being performed and maintained.

 

The Real Cost of Stolen Innovation

Cybersecurity failures in the defense industrial base carry consequences beyond individual organizations.

Stacy emphasizes that taxpayers fund significant investments in research, engineering, testing, and development that support national defense capabilities. When adversaries gain access to sensitive technical information, they may benefit from years of innovation without making the same investment.

Rather than starting from the beginning, competitors and nation-state actors can leverage stolen information to accelerate development, improve manufacturing capabilities, or reduce the costs associated with creating similar technologies.

This creates broader national security implications.

Contractor cybersecurity is not simply a contractual requirement. It is part of protecting the strategic advantage built through years of research and investment.

 

Why Small Contractors Are Prime Targets

Many small and mid-sized defense contractors assume they are unlikely targets because they are not large prime contractors.

That assumption can be dangerous.

Attackers recognize that smaller organizations may have fewer cybersecurity resources while still possessing highly valuable information. Engineering specifications, manufacturing processes, credentials, controlled information, and supply chain access can all be attractive targets.

For cybercriminals and nation-state actors, smaller contractors may represent a more accessible path into larger defense ecosystems.

Every organization within the defense supply chain plays a role in protecting sensitive information, regardless of size.

 

Cybersecurity and Supply Chain Resilience

The impact of a cyber incident often extends far beyond the organization directly affected.

Many defense programs depend on suppliers, subcontractors, manufacturers, and specialized vendors delivering critical products or services on schedule.

When a supplier experiences a cybersecurity incident such as ransomware, production delays, data loss, or operational disruption, those consequences can cascade throughout the supply chain.

A single compromised supplier can affect downstream organizations, contractual obligations, production schedules, and mission-critical operations.

This is one reason CMMC focuses on strengthening cybersecurity across the broader defense industrial base rather than concentrating exclusively on prime contractors.

 

CMMC Is Only the Beginning

While CMMC represents a significant change for many organizations, Stacy describes it as an early stage in a longer cybersecurity journey.

Many contractors excel at engineering, manufacturing, and operational execution but may not possess deep internal cybersecurity expertise.

As technologies evolve, organizations will likely benefit from improved automation, managed security services, cloud-native protections, and tools that reduce compliance complexity.

However, the long-term direction is not toward occasional assessments.

It is toward continuous security monitoring, stronger cybersecurity maturity, and greater adoption of zero-trust principles.

The future of compliance will increasingly emphasize ongoing risk management rather than point-in-time validation.

 

The Bottom Line for Defense Contractors

The defense industrial base does not have the luxury of waiting for an easier path to cybersecurity.

Threat actors are already targeting organizations of every size, searching for opportunities to steal information, disrupt operations, and gain access to sensitive systems.

CMMC was created as a response to a very real challenge: not all contractors were doing what they claimed they were doing when it came to cybersecurity.

For organizations handling sensitive government information, the objective should not be passing an assessment.

The objective should be building a security program capable of protecting critical information, supporting operational resilience, and maintaining trust throughout the defense supply chain.

CMMC is simply one step toward that larger goal.

 

Ready to Strengthen Your CMMC Readiness?

Whether you're preparing for a future CMMC assessment or working to improve your NIST SP 800-171 compliance program, building sustainable cybersecurity practices today can reduce risk tomorrow.

👉 Book a meeting with BEMO's compliance experts to discuss your readiness strategy and identify potential gaps before an assessment.

Want more insights from government, compliance, and cybersecurity leaders? Subscribe to the Trust Issues podcast for practical conversations on CMMC, risk management, and protecting the defense industrial base.

Frequently Asked Questions

Why was CMMC created?

CMMC was introduced to provide independent validation that defense contractors are effectively implementing required cybersecurity controls rather than relying solely on self-attestation.

Why are small contractors targeted by cyber attackers?

Small contractors may have fewer cybersecurity resources while still possessing valuable intellectual property, controlled information, and supply chain access that can be attractive to attackers.

Is the CMMC assessment itself the largest compliance expense?

Often, the larger investment involves implementing and maintaining cybersecurity improvements that organizations may have postponed over time.

How does stolen defense information affect taxpayers?

When sensitive research and development information is stolen, adversaries may benefit from years of taxpayer-funded innovation without incurring the same costs of development and testing.

What comes after today's CMMC requirements?

The broader direction of the industry includes greater automation, managed security services, continuous compliance practices, ongoing monitoring, and increased adoption of zero-trust security models.