NEW  —  The C3PAO Report 2026 is here. Read it now → NEW  —  The C3PAO Report 2026 is here. Read it now → NEW  —  The C3PAO Report 2026 is here. Read it now → NEW  —  The C3PAO Report 2026 is here. Read it now →

Home / Blog / CMMC

CMMC September 1, 2026 4 min read

They Should Have Just Started With MFA

Andy Sauer
Andy Sauer 4 min read
They Should Have Just Started With MFA

The DoD should have just started with MFA.

That’s it; that’s the whole post.

Even before the Phase II suspension, CMMC was always going to be a hard sell to a defense industrial base full of small organizations with no dedicated IT staff. Now, with all the uncertainty around the suspension, it feels like we’re having the same conversations we had four or five years ago. What do we do next? If we don’t resume CMMC Level 2 assessments, where will we go from here?

Our suggestion is the same as it was four or five years ago: Multifactor authentication, especially replay-resistant and phishing-resistant multifactor authentication that is universally enforced, would close off one of the most common risk vectors, and it would do so without asking anyone to overhaul their entire security program overnight.

The DoD’s new Brilliant at the Basics campaign begins with phishing-resistant MFA, and the reality is that C3PAO audits could too. The ecosystem could overhaul its approach and have 1000 DIB companies a week go through a one-hour C3PAO assessment to verify they’ve turned on MFA everywhere… and it would produce a more secure DIB than what we have today.

How did we get here?

It’s been a chaotic few weeks. On July 13, 2026, the Department of War suspended CMMC Phase II effective immediately. Pending a 60-day review from a new task force, there are currently no mandatory third-party C3PAO assessments and no November 2026 timeline for Phase II.

The truth that the suspension acknowledges is that CMMC compliance (and especially the C3PAO assessment required for Level 2 certification) is hard. Unlike implementing MFA, it’s expensive, it’s document-heavy, and it demands a level of expertise that many small contractors can’t easily access.

At the same time, cybersecurity in the DIB is essential. We’re not saying “throw MFA at the problem and call it a day,” or that one control is a substitute for a real security program. Good security is our lifeblood, and more importantly, it’s crucial for protecting our national security.

What we are saying is that the DIB could have eased into CMMC with a few small, high-leverage steps first, instead of asking tens of thousands of small manufacturers to find the budget for CMMC Level 2 assessments. And if we had to pick one control to begin with, MFA works for several reasons.

Why MFA?

It’s relatively easy to implement. Turning on MFA doesn’t require a SOC or a six-figure IT budget. For a mom-and-pop machine shop or a similar small business in the DIB, it’s achievable in a weekend. It’s familiar to pretty much any employee who’s ever used online banking or a personal email account, and it builds momentum and confidence.

It complements your other security initiatives. MFA isn’t a panacea against every kind of cyberattack, and it won’t replace the diligent work of continuous monitoring, anomaly detection, and rapid incident response that a good SOC team can do. But it closes off the single most common door attackers walk through. It’s the cheapest, fastest control a contractor can put in place, and it buys the SOC team room to focus on the threats that actually require human judgment instead of firefighting credential theft.

It works. According to CISA, implementing MFA makes an account roughly 99% less likely to be compromised. And the number of adversaries who want to compromise DIB accounts is not negligible. In the past few years alone, Russian state-linked hackers have targeted defense contractor networks to obtain sensitive U.S. defense information; used email phishing to gain access to drone, missile, and stealth fighter programs via employees at firms like Lockheed and Boeing; and carried out the infamous SolarWinds supply chain attack.

It addresses an extremely dumb, extremely common problem. According to CISA, the most common password in the country is still 123456. Parrots can count that high. Pigeons can count that high. And for millions of people using that password or a similarly weak one, MFA is the only thing standing between the adversary and their account or network. It’s a crucial safety net for the “my password is ‘password'” crew.

The DIB agrees. Practitioners inside the industry describe MFA as the single greatest reduction in cyber risk and the most tangible improvement to their security posture.

Well, now what?

At the moment, we’re in a “hurry up and wait” holding pattern. Until more guidance is released, no one really knows the future of CMMC Phase II or C3PAO assessments.

The idea worth carrying forward here, regardless of what happens with the Phase II suspension, is that security programs succeed when they start with the highest-leverage, lowest-friction control and build trust from there. If we created a system where 1000 DIB companies a week went through a one-hour assessment to prove they’d turned on phishing-resistant MFA everywhere, the DIB would be measurably harder to breach within a year.

MFA isn’t everything… but it could still be the on-ramp that gets a lot more of the DIB moving in the right direction, a lot sooner.

Share: LinkedIn X / Twitter Email

Ready to get to work? So are we.

Our cyber adversaries aren't waiting and neither are we. Let's get the conversation started.

Contact Us Today