Skip to main content
ComplianceData Protection

Sharpening Cybersecurity Standards

Person standing in front of blank whiteboard with subtle security theme in background.

"This is not the moment to loosen the standard," writes Katie Arrington.

CMMC exists because self‑attestation failed the war industrial base

Katie Arrington, who led the Pentagon’s initial effort to create the Cybersecurity Maturity Model Certification (CMMC), frames the program as a corrective to a failed promise model. She says contractors had been allowed to “simply promise they were following basic cybersecurity practices, with no verification behind that promise,” and that adversaries noticed and exploited that gap. For that reason, Arrington argues the Defense Federal Acquisition Regulation Supplement requirements behind CMMC should not change now that CMMC is a final rule moving into real contracts.

Controlled Unclassified Information is the hinge — but determinations are inconsistent

At the center of CMMC enforcement is whether work involves controlled unclassified information (CUI). Arrington highlights a practical problem: CUI determinations across the war industrial base are inconsistent. Two subcontractors doing nearly identical work can receive completely different assessments because the call "still depends on manual judgment with incomplete visibility into how data actually flows down." The inconsistency produces two unhelpful outcomes, she warns: some small businesses are pushed into heavy assessment burdens for data that is not really CUI, while others handling genuinely sensitive data receive lighter requirements and thus greater exposure.

Use AI to improve CUI targeting, not to lower the bar

Arrington proposes a concrete role for artificial intelligence: perform a consistent, first‑pass analysis of contract language and statements of work to flag likely CUI and to detect mismatches between a prime contract’s designation and what actually flows to subcontractors. In her formulation, AI would not make final decisions. A human contracting authority would still make the call—but that human would begin with a more consistent, higher‑quality set of flags than today’s “patchwork of manual reviews.” She explicitly frames this as sharpening targeting rather than loosening standards: precision in where CMMC applies, without changing the cybersecurity bar itself.

Small businesses face acute threats and lack capital for cybersecurity

Arrington broadens the argument beyond the defense supply chain. She notes small businesses are "99.9% of American companies and employ nearly half the private workforce," and that they face threats few are equipped to handle: ransomware that can shut down operations overnight, AI‑enabled fraud that is increasingly hard to spot, and a looming quantum threat because "data harvested now can simply be decrypted later." She acknowledges the Small Business Administration is "leaning into this" through its Cybersecurity for Small Business Pilot Program, which has funded training through state partners. But she stresses limits: "training grants aren't capital," and counseling alone will not carry a small manufacturer through ransomware recovery or fund a migration to quantum‑resistant encryption.

A dedicated SBA cybersecurity loan program

To address the financing gap, Arrington calls for a dedicated SBA loan program for cybersecurity investment, open to every small business and not limited to those working with "the Department of War." The list of eligible investments she outlines is specific: multi‑factor authentication rollouts, endpoint detection, incident response, and early migration toward quantum‑resistant encryption. The point is to fund preventive, structural upgrades "before it's an emergency instead of a plan," because many lenders "don't know how to underwrite" cybersecurity the way they do physical equipment.

What this means for contracting officers, small manufacturers, and primes

  • Contracting officers: Expect a role where AI provides consistent, machine‑assisted flags about likely CUI and flow‑down mismatches, but retains human final authority over CUI designation.
  • Small manufacturers and non‑DOD small businesses: Training support exists through the SBA pilot program, but capital needs remain; a dedicated SBA loan product would change the finance equation for ransomware recovery and quantum‑resistant upgrades if adopted.
  • Prime contractors and subcontractors in the war industrial base: Improved targeting could reduce unnecessary heavy assessment burdens for some small subcontractors while tightening coverage where sensitive data actually flows, altering compliance cost and risk profiles without lowering CMMC requirements.

Arrington’s argument is straightforward and narrowly focused: keep the CMMC bar where it is, but sharpen how it is applied. The proposal pairs two tracks — AI to make CUI designation and flow‑down alignment more consistent inside the defense supply chain, and a capital mechanism through the SBA to give all small businesses the means to harden against contemporary and future threats. The claim is not that standards should be eased; it is that precision and support will make the standards more effective.

https://www.defenseone.com/ideas/2026/08/cmmc-works-now-lets-sharpen-it/415470/