Quick Answer: CMMC was created because self-attestation alone was not providing sufficient confidence that defense contractors were adequately protecting sensitive government information. In this episode of Trust Issues, Stacy Bostjanick, former Director of CMMC Policy at the Pentagon, explains how decades of inconsistent cybersecurity practices, weak documentation, and unverified compliance led to the need for independent assessments. The conversation highlights why contractor cybersecurity is more than a compliance issue. It is critical to protecting innovation, supply chains, and national security.
For years, defense contractors were expected to protect Controlled Unclassified Information (CUI) and other sensitive government data through compliance with requirements such as DFARS 252.204-7012 and NIST SP 800-171.
On paper, many organizations reported they were meeting those obligations.
In practice, the situation was often different.
In this episode of Trust Issues, Brandon and Bruno Lecoq sit down with Stacy Bostjanick, former Director of CMMC Policy at the Pentagon, to discuss why the Department of Defense ultimately determined that additional validation was necessary.
The conversation reveals how years of inconsistent cybersecurity practices contributed to the development of CMMC and why independent verification became an important part of the defense contracting ecosystem.
Prior to CMMC, many contractors relied on self-attestation to demonstrate compliance with cybersecurity requirements.
The process depended largely on organizations accurately evaluating their own security posture and honestly reporting the results.
According to Stacy, that approach frequently failed.
Organizations sometimes relied on generic System Security Plans copied from publicly available templates, incomplete remediation plans, or documentation that did not accurately reflect operational reality. While paperwork existed, implemented security practices often did not align with documented claims.
As confidence in self-attestation declined, the Department of Defense introduced CMMC to provide independent verification that required controls were operating as intended.
The goal was not simply to generate more documentation. The goal was to validate that cybersecurity processes were actually being performed and maintained.
Cybersecurity failures in the defense industrial base carry consequences beyond individual organizations.
Stacy emphasizes that taxpayers fund significant investments in research, engineering, testing, and development that support national defense capabilities. When adversaries gain access to sensitive technical information, they may benefit from years of innovation without making the same investment.
Rather than starting from the beginning, competitors and nation-state actors can leverage stolen information to accelerate development, improve manufacturing capabilities, or reduce the costs associated with creating similar technologies.
This creates broader national security implications.
Contractor cybersecurity is not simply a contractual requirement. It is part of protecting the strategic advantage built through years of research and investment.
Many small and mid-sized defense contractors assume they are unlikely targets because they are not large prime contractors.
That assumption can be dangerous.
Attackers recognize that smaller organizations may have fewer cybersecurity resources while still possessing highly valuable information. Engineering specifications, manufacturing processes, credentials, controlled information, and supply chain access can all be attractive targets.
For cybercriminals and nation-state actors, smaller contractors may represent a more accessible path into larger defense ecosystems.
Every organization within the defense supply chain plays a role in protecting sensitive information, regardless of size.
The impact of a cyber incident often extends far beyond the organization directly affected.
Many defense programs depend on suppliers, subcontractors, manufacturers, and specialized vendors delivering critical products or services on schedule.
When a supplier experiences a cybersecurity incident such as ransomware, production delays, data loss, or operational disruption, those consequences can cascade throughout the supply chain.
A single compromised supplier can affect downstream organizations, contractual obligations, production schedules, and mission-critical operations.
This is one reason CMMC focuses on strengthening cybersecurity across the broader defense industrial base rather than concentrating exclusively on prime contractors.
While CMMC represents a significant change for many organizations, Stacy describes it as an early stage in a longer cybersecurity journey.
Many contractors excel at engineering, manufacturing, and operational execution but may not possess deep internal cybersecurity expertise.
As technologies evolve, organizations will likely benefit from improved automation, managed security services, cloud-native protections, and tools that reduce compliance complexity.
However, the long-term direction is not toward occasional assessments.
It is toward continuous security monitoring, stronger cybersecurity maturity, and greater adoption of zero-trust principles.
The future of compliance will increasingly emphasize ongoing risk management rather than point-in-time validation.
The defense industrial base does not have the luxury of waiting for an easier path to cybersecurity.
Threat actors are already targeting organizations of every size, searching for opportunities to steal information, disrupt operations, and gain access to sensitive systems.
CMMC was created as a response to a very real challenge: not all contractors were doing what they claimed they were doing when it came to cybersecurity.
For organizations handling sensitive government information, the objective should not be passing an assessment.
The objective should be building a security program capable of protecting critical information, supporting operational resilience, and maintaining trust throughout the defense supply chain.
CMMC is simply one step toward that larger goal.
Whether you're preparing for a future CMMC assessment or working to improve your NIST SP 800-171 compliance program, building sustainable cybersecurity practices today can reduce risk tomorrow.
👉 Book a meeting with BEMO's compliance experts to discuss your readiness strategy and identify potential gaps before an assessment.
Want more insights from government, compliance, and cybersecurity leaders? Subscribe to the Trust Issues podcast for practical conversations on CMMC, risk management, and protecting the defense industrial base.
CMMC was introduced to provide independent validation that defense contractors are effectively implementing required cybersecurity controls rather than relying solely on self-attestation.
Small contractors may have fewer cybersecurity resources while still possessing valuable intellectual property, controlled information, and supply chain access that can be attractive to attackers.
Often, the larger investment involves implementing and maintaining cybersecurity improvements that organizations may have postponed over time.
When sensitive research and development information is stolen, adversaries may benefit from years of taxpayer-funded innovation without incurring the same costs of development and testing.
The broader direction of the industry includes greater automation, managed security services, continuous compliance practices, ongoing monitoring, and increased adoption of zero-trust security models.