NEW  —  The C3PAO Report 2026 is here. Read it now → NEW  —  The C3PAO Report 2026 is here. Read it now → NEW  —  The C3PAO Report 2026 is here. Read it now → NEW  —  The C3PAO Report 2026 is here. Read it now →

Home / Blog / CMMC

CMMC September 4, 2026 7 min read

Brilliant at the Basics… But “Basic” for Who?

Sentinel Blue
Sentinel Blue 7 min read
Brilliant at the Basics… But “Basic” for Who?

The Phase II suspension in July has dominated the CMMC news cycle, but it’s not the only news to come out of the DoD this summer. Last month, CIO Kirsten Davies launched the new “Brilliant at the Basics” campaign, intended to provide streamlined cybersecurity suggestions for small, mid-sized, and non-traditional contractors.

If you haven’t seen it, Brilliant at the Basics is essentially a Top 10 list of IT practices (plus a companion OT list) meant to distill important cybersecurity principles into clear, actionable steps. (It’s important to note that it’s not a framework, it doesn’t replace CMMC or NIST SP 800-171, and it doesn’t currently have any legal or regulatory force.)

There are several things to like in the new campaign. The list opens with phishing-resistant MFA, which (as we’ve written elsewhere) is generally the highest-value cybersecurity practice a DIB organization can implement. Reducing technical debt earns its place too, since unsupported legacy systems are behind a large share of the findings we see in the field. And risk-based vulnerability management gives small teams permission to triage instead of chasing every alert.

But “basic” is doing a lot of work in the DoD’s messaging. What we want to know is: basic for who?

The campaign was designed for “innovative small and mid-sized businesses” and was intended as a response to the high costs of CMMC compliance for small subcontractors. But several of its items are assuming a level of in-house architecture and engineering capacity that most small contractors don’t have and can’t easily get. Something that’s foundational for a major prime with a 50-person IT organization will often be more or less impossible for a 20-person machine shop.

If you ask us, the campaign’s language of “basics” dramatically undersells what it’s actually asking small subcontractors to do, and it overlooks a potential ally in the fight for better DIB cybersecurity.

Not so basic after all

Every small contractor’s environment is different, but three items on the Brilliant at the Basics list tend to be particularly challenging for small teams.

  1. Flexible technology stack. First, the campaign calls for small contractors to design and maintain a flexible, interoperable tech stack to avoid vendor lock-in and ensure ongoing agility. Systems should be modular enough to swap out a tool or provider without rebuilding everything around it. That’s great in theory… but for most small businesses, their tech stack is whatever got set up years ago. Replacing a functioning machine or designing a new system just to gain interoperability isn’t in the budget, and it’s not realistic to expect. For many small subs, the entire strategy is to buy what’s affordable and what already works with the systems and equipment you have.
  2. Logical segmentation. A well-segmented CUI enclave can shrink an assessment boundary dramatically, but it’s also a technically demanding ask that requires a network engineering skill set. Standing up segmentation correctly means understanding data flows, choosing the right enforcement points, and maintaining the segmentation as the network changes. Unfortunately, most small DIB companies don’t have a network engineer; they have someone who’s good with computers wearing six other IT-related hats.
  3. Security in the development lifecycle. For prime contractors running software development shops, it absolutely makes sense to integrate automated vulnerability scanning and monitoring directly into the earliest phases of your engineering lifecycle. For subcontractors like machine shops, precision manufacturers, and parts suppliers, it’s close to irrelevant, since they aren’t writing code. But for small subcontractors that develop software or firmware, this item assumes a secure SDLC program and dedicated security engineering resources that a small team is unlikely to have.

Ultimately, none of the ten items in the Brilliant at the Basics campaign are bad recommendations from a security standpoint. It’s just that several of them require a maturity level that the campaign’s stated audience typically doesn’t have.

A note on AI

The eighth entry on the Brilliant at the Basics list, secure AI adoption and data protection, deserves its own mention. Securing AI is a major challenge that extends well beyond small contractors.

NIST SP 800-171 Rev. 2 predates enterprise AI entirely, so there’s no existing control language to lean on. There’s only a looming list of unanswered questions: Which public AI tools are approved to handle CUI? How do you audit AI use after the fact? Can a vendor quietly enable a new AI feature in a routine software update? What happens when a contract flow-down includes an AI-specific clause?

Even the federal government is still sorting out what to do. Last month, the bipartisan AI Kill Switch Act was introduced to require AI developers to build in the ability to restrict, throttle, or fully shut down their systems. If Congress is still writing the rules for how the most advanced AI systems get switched off, it’s a safe bet that the rest of the DIB is just trying to keep up.

We know that large primes are actively working through these questions with dedicated security and legal teams. But where does that leave small subcontractors? They’re being asked to solve the same problem with none of the enterprise infrastructure, and with far less room to absorb a mistake.

What could the DIB do instead?

If the goal is to close the security gap across the DIB, a more honest starting point is acknowledging that most small contractors won’t be able to build items like segmentation, secure SDLC, or AI governance in-house.

Nor should they have to, because that capability already exists. It’s what managed service providers and managed security service providers are already delivering to the DIB every day.

In Sentinel Blue’s response to the CMMC Reform Task Force RFI, our CEO Andy Sauer made the same case directly to the DoD: MSPs and MSSPs are the ones actually closing this gap today, and the Department barely acknowledges we exist.

Most small and mid-sized contractors would be completely unable to reach CMMC certification without an MSP standing behind them. Firms like ours already hold at least partial responsibility for the majority of the 110 requirements in NIST SP 800-171 for our DIB clients, and the same will be true if Brilliant at the Basics is adopted as the new standard.

The MSP model lets multiple small organizations share the cost of an IT team and a tech stack that none of them could build alone. And yet, historically, the DoD hasn’t provided any formal channels or frameworks to account for how much of the DIB’s actual security posture runs through service providers.

Our recommendation to the Task Force was direct: build a certification model for MSPs specifically. Hold providers like Sentinel Blue to a higher standard of scrutiny, and in exchange, let that scrutiny reduce the level of effort a small subcontractor has to carry on their own. Then, put formal mechanisms in place to recognize MSPs as the invaluable security partners they already are to the DIB.

Conclusion

“Brilliant at the Basics” gets the priorities right: do MFA first, reduce technical debt, manage risk, etcetera. Where it falls short is treating a 20-person machine shop like it has the resources of a Lockheed Martin or a Boeing.

Without more attention to the realities of small-business cybersecurity, Brilliant at the Basics leaves DIB subcontractors on their own to manage the maturity gap. To help close that gap, the DoD could offer cost-sharing programs or subsidies for tooling and MSP support to make the “basics” achievable on a shop-floor budget. The Department could also provide sample SSPs and POA&M templates scaled to a 15-person IT footprint rather than an enterprise one, as well as clearer guidance on what “good enough” looks like for a subcontractor that touches CUI only occasionally, instead of a one-size-fits-all bar.

At the end of the day, if the DoD is going to ask small contractors to do things that aren’t structurally feasible, we hope it will also find a formal way to recognize the partners already helping them to do the impossible.

There’s nothing basic about that.

Share: LinkedIn X / Twitter Email

Ready to get to work? So are we.

Our cyber adversaries aren't waiting and neither are we. Let's get the conversation started.

Contact Us Today