September 2, 2026
The Stern Report: The Requirement Never Moved. The Model Should.
Scores went up. Confidence went down.
CyberSheath and Merrill Research surveyed 302 U.S. defense contractors in May 2026. The mean self-reported SPRS score came back at +51, up from +33 last year, the highest since the study began in 2022.
Confidence that those scores are accurate came back at 65%. It was 89% in 2025. It was 94% in 2024.
The median contractor rates itself 70% ready for certification. One percent say they are completely ready. Average annual compliance spend is $155,204, roughly a quarter of the per-company certification cost the SBA has cited.
Read those four numbers together. The Defense Industrial Base is getting better at scoring itself and less sure the score means anything. That is a measurement system that has drifted away from the thing it was built to measure.
A number that climbs while trust in it falls is not a metric. It is a mood.
An eight-year-old requirement is not a new burden.
DFARS 252.204-7012 has required contractors to implement NIST SP 800-171 and safeguard covered defense information since December 31, 2017. FAR 52.204-21 has covered federal contract information alongside it. Nothing announced on July 13 touched either one.
So when the DoW CIO describes CMMC as a compliance checklist and says the math simply does not math, read what is actually being said. She is not calling the protection of CUI a burden. She is calling the proof architecture a burden, and on that, the numbers back her. More than 100,000 firms would need assessment from roughly 100 authorized C3PAOs. SBA figures put individual compliance costs approaching $600,000 and the aggregate bill on small and mid-sized businesses above $7 billion a year. GAO warned in March 2026 that the requirements could push small firms out of the base entirely. The Under Secretary for Acquisition and Sustainment was explicit that the Department is removing the bureaucracy of the third-party assessment, not relaxing the NIST standard.
Most of the coverage collapsed that distinction. It matters. The requirement is not the burden. The evidence-production regime built around the requirement is the burden.
Here is my problem with the framing anyway. We spent eight years letting the DIB treat a 2017 obligation as a 2026 project. The cost shock did not arrive because the standard arrived. It arrived because most of the market deferred the standard until somebody announced a date to check.
You do not get to call an eight-year-old requirement a surprise cost.
The obligation is moral before it is contractual. We trained the base out of thinking that way.
Let me be direct about something. The DIB does not build widgets. It builds what a 22-year-old carries into a place they may not come home from. A technical data package that leaks does not become a compliance finding. It becomes a capability an adversary fields against that servicemember, often years later, at a fraction of what we paid to invent it.
If that is true, and it is, why does it not land? Why does a supplier treat CUI protection as a line item to be minimized rather than an obligation to be met?
Not because they do not care. A 40-person machine shop in Ohio holding a subcontract three tiers down from the prime has a quality manager who understands AS9100, a controller who understands DCAA, and no one who has ever been told what happened downstream of the last breach in their sector. The intelligence that would make the obligation real to them is classified away from them. We ask for mission-level ownership from companies we keep at arm's length from the mission.
And then we compounded it. We made security a procurement artifact: a clause, a rep and cert, a score in a database. We told the market to satisfy the clause. The market satisfied the clause. The CyberSheath confidence gap is what that instruction produces at scale, executed faithfully.
The fix is not a lecture about patriotism. It is feedback. Give a supplier a declassified, sector-specific account of what their tier actually lost last quarter and their behavior changes inside a budget cycle. I have watched it happen. It works because it converts an abstraction into a fact about their own shop.
You cannot hold a company morally accountable for a loss you never told them happened.
We built a reporting portal and called it a network.
Disclosure before I make this argument: Hypori sells virtual mobile infrastructure. What follows would benefit companies in that category, mine included. Weigh it accordingly.
DIBNet is a useful place to start, because the name has always oversold the thing. dibnet.dod.mil was a reporting portal, where you filed your DFARS 7012 incident report inside 72 hours with a DoD-approved medium assurance certificate, alongside a voluntary threat-sharing program. It was decommissioned in June 2025 and reporting moved to DC3's DCISE Incident Collection Format process. It was never a network. It was a portal and email with a certificate requirement.
So ask the counterfactual. What if the Department had partnered with industry to build the thing the name implies?
Picture a government-accredited enclave operating at IL5-equivalent, where CUI and controlled technical information live on accredited government infrastructure rather than on 100,000 private networks of wildly varying quality. Companies do not take custody of the data. Vetted individuals reach it through remote channels, VDI, VMI, with nothing at rest on the contractor endpoint. Access is the deliverable, not the data.
Consider what that moves. Spend shifts from per-company audit to per-person vetting and per-company access provisioning: you accredit one environment once instead of paying 100,000 firms to independently rebuild and independently prove the same 110 practices. Scope collapses, because the assessment boundary becomes the enclave rather than every laptop, phone, file server, and fourth-tier subcontractor in the chain. Revocation becomes real. Today, ending a subcontract does not retrieve the CUI that already landed; cutting access does. And monitoring becomes continuous and government-side, because you no longer have to trust an attestation about a system you were never allowed to instrument.
Now the objections, because this idea does not survive without them.
It does not fit every workload. High-fidelity CAD, large simulation runs, shop-floor OT, and manufacturing execution systems do not all tolerate a remote channel at acceptable latency today. A serious design scopes to the data classes that can live this way and leaves a smaller, honest assessment regime for the rest. Anyone who tells you it covers everything is selling.
Intellectual property commingling is the real blocker. No innovator puts proprietary designs into a government enclave without enforceable, written limits on government access, retention, and downstream use. That is a contracting and policy problem, not a technical one, and it has to be solved first rather than last. Get this wrong and the companies you most want will simply decline.
Concentration risk is real. One enclave is one target. The mitigation is aggressive segmentation, identity-bound access, and per-program isolation, not pretending a centralized model has no downside. It trades a hundred thousand soft targets for one hard one, and that trade has to be made deliberately.
Governance has to be shared. The government accredits and governs. Industry builds and operates. Structured any other way, this becomes a decade-long program of record that ships after the threat has moved. The Task Force asked for industry input through an RFI. This is the kind of input it should be looking for.
This is harder than trimming CMMC. It is also the only version of this problem that scales to 100,000 companies, and the Department has never seriously costed it against the alternative it is currently defending.
An assessment is a photograph. Your network is a film.
Under 32 CFR 170.17, a Level 2 certification runs three years. In years two and three there is no third-party assessment at all. An Affirming Official, a named human being, signs an annual affirmation that the controls still hold. Assessment artifacts are retained for six years.
Now think about what three years does to an enterprise. A cloud migration. An acquisition. A managed service provider swap. A domain consolidation. Half the security team turns over. A POA&M item quietly reopens and nobody updates the SSP. Compliance rarely fails loudly. It erodes, and the erosion is invisible until someone looks.
So even the pre-suspension model was verified once and asserted twice. The person carrying False Claims Act exposure for years two and three is attesting to an environment that moved underneath them. MORSECORP paid $4.6 million after a third-party assessment showed the self-reported score was far off. LOGZONE settled as well. Both were caught by the mechanism that is now paused.
The suspension did not create the self-attestation problem. It removed the one year in three where somebody outside the building checked.
A certification tells you what was true on the day of the assessment. Nothing in the framework tells you what is true today.
CMMC does not model an adversary operating at machine tempo.
In November 2025, Anthropic disclosed a campaign it designated GTG-1002 and attributed with high confidence to a Chinese state-sponsored group. Roughly 30 organizations targeted. Artificial intelligence executed 80 to 90 percent of tactical operations, reconnaissance, vulnerability discovery, exploitation, lateral movement, credential harvesting, exfiltration, with human operators intervening at four to six decision points across the campaign. The Congressional Research Service has since briefed Congress on agentic AI and cyberattacks. CrowdStrike's 2026 report puts AI-enabled attacks up 89 percent year over year.
The detail that should worry you is not the sophistication. It is the absence of it. The operators used open-source penetration testing tooling and standard utilities. No novel malware. What changed was tempo and unit cost. Work that required a funded, skilled team now requires a prompt and patience.
So ask the honest question about the framework. CMMC Level 2 is 110 practices derived from NIST SP 800-171, assessed against a documented boundary on a three-year cycle. It is a control baseline, and a defensible one.
I want to be precise here, because the overclaim is tempting. Those controls are not nullified by AI. Access control, multifactor authentication, least privilege, and logging still raise the cost of an autonomous intrusion, and a contractor who genuinely implements them is meaningfully harder to breach than one who does not. That part holds.
What does not hold is the assumption underneath the assessment schedule: that a defender's posture and an attacker's capability change at roughly comparable speed. They no longer do. There is no practice in Level 2 written for an adversary that can enumerate your entire external surface in an afternoon and re-derive an attack path every time you patch. There is no affirmation cycle short enough to matter against that, and no volume of paperwork that closes the gap.
CMMC was designed to catch the contractor who did not do the work. It was never designed to catch an attacker who does not need a person in the loop.
Security and access are not opposed. Compliance and access are.
This is where the argument lands, and it is bigger than CMMC.
The capabilities the Department needs most right now, autonomy, applied AI, advanced sensing, space, novel materials, sit disproportionately in companies that will not absorb a $600,000 certification bill and an 18-month readiness project before their first award. They have commercial customers who do not ask. GAO warned about small firms exiting the base. The exit that should worry us more is the firms that never enter, because they never show up in a report.
The real problem statement carries four constraints at once: protect CUI and controlled technical information against a machine-speed threat; preserve the innovating company's own intellectual property, which we currently ask them to defend using a framework we do not fund; keep the contractual relationship enforceable and auditable; and move a non-traditional company from first conversation to real work in weeks rather than years.
The current model optimizes exactly one of those four. And any model that requires every company to become a security organization before it can contribute will keep failing this test, because most of them should not be security organizations. They should be excellent at the thing we are buying.
What I would tell the Task Force.
Separate the standard from the proof. NIST SP 800-171 stays. It is the floor and it should be. What has to change is how a company demonstrates it, because a per-company, per-three-year, per-assessor model cannot scale to 100,000 firms and roughly 100 assessors, and no amount of reform to the assessment process fixes arithmetic.
Make government-furnished secure access an alternative path, not an added cost. If CUI never lands on the contractor's system, the assessment boundary should shrink accordingly, and the rules should say so explicitly, in writing, before a contractor bets a bid on that interpretation. Today the framework allows scope reduction in principle and provides no durable assurance in practice. That ambiguity is why companies over-scope and overpay.
Reward continuous evidence over periodic attestation. A firm streaming control telemetry from an accredited environment carries less risk than a firm signing an annual affirmation, and the framework should price that difference. Right now it treats them identically, which tells the market that documentation and defense are worth the same. They are not.
This deserves more than a 60-day trim.
The audit paused. The requirement did not. I wrote that in July and it is still the operative fact.
But the pause put something larger on the table, and the 60-day review is too small a container for it. The question is not whether a third party or the contractor signs the form. The question is why, eight years after DFARS 252.204-7012, we are still asking 100,000 companies to each independently build, staff, and prove a defense-grade security program as the price of admission, while the adversary automates the attack side and we debate the audit calendar.
We spent eight years building a way to prove the CUI is protected. We never built a way to keep it.
Notes: Sourcing: CyberSheath/Merrill 2026 State of the DIB (302 contractors, May 2026 fielding); DoW July 13, 2026 suspension memo and CIO statements; Under Secretary Duffey remarks via Breaking Defense, July 13, 2026; SBA cost figures; GAO-26-107955 (March 2026); 32 CFR 170.17 for the three-year cycle and annual affirmation; DC3/DCISE for the DIBNet decommissioning in June 2025; Anthropic's November 2025 GTG-1002 disclosure; CRS IF13151 on agentic AI; CrowdStrike 2026 threat report.
Recent articles
Security
September 1, 2026
Zero Day Is the New Every Day
Zero-day exploits used to require a nation-state budget. Now they take a laptop and a grudge. Here's why "patch faster" isn't the fix anymore.
August 27, 2026
The Perfect (Outsider) Trade
Board packs travel to personal devices before every meeting, and a copied device at a hotel or border crossing doesn't need to be decrypted right away. Jim Cushman lays out how that gap lets someone trade on material nonpublic information without ever qualifying as an insider, and why the fix is keeping the data off the device in the first place.
Security
August 20, 2026
Filed First, Invented Second
A researcher's laptop doesn't need to be hacked to leak a breakthrough. It just needs to be copied on a conference WiFi or imaged at a border crossing, then decrypted years down the line, by whoever files the patent first.
The Stern Report: The Audit Paused. The Requirement Didn't.
DoW suspended CMMC Phase 2 third-party assessments, but NIST 800-171 and DFARS obligations remain. Matt Stern on why the requirement never paused.
The Stern Report: Q&A Recap of CMMC Accelerate 2026
500 DIB professionals. One clear message: CMMC compliance is no longer optional. Get the top takeaways from CMMC Accelerate 2026 - from audit prep and documentation pitfalls to AI-powered compliance and insurance benefits most contractors don't know about.
The Stern Report: FIPS-Validated Cryptography
FIPS validated does not mean one thing. See why Hypori's narrow cryptographic claim differs from Intune MAM's borrowed, older-standard FIPS 140-2 certification.
