Updated October 7, 2026
The Department of War suspended CMMC Phase 2 on July 13. Alongside the review that followed, the CIO's office published something else: a campaign page called Brilliant at the Basics, with a Top 10 list for IT, a Top 10 list for operational technology, and a reading list that includes NIST's Cybersecurity Framework 2.0 Small Business Quick-Start Guide (DoW CIO, Brilliant at the Basics). The suspension got the headlines. The campaign the CIO published alongside the review is the better clue to what comes next.
This piece does two things. It reads the public record on why Kirsten Davies is steering this way, and it tells you which of the twenty items to act on before the task force report lands. The opinion parts are marked as ours.
What was actually published
The campaign page says it exists to help "small, mid-sized, and non-traditional companies" in the defense industrial base secure their networks and protect DoW information. It is a CIO awareness campaign, voluntary, with no score and no contract clause. Nothing on it changes DFARS 252.204-7012, which still requires the 110 controls of NIST SP 800-171 Rev 2 in any contract that carries it (DFARS 252.204-7012). If you want the contractual picture of the pause, that guide is here.
The IT list, in the department's order:
- Phishing-resistant multi-factor authentication
- Comprehensive asset inventory management
- Strategic technical debt reduction
- Flexible technology stack
- Logical segmentation to limit adversary lateral movement
- Risk-based vulnerability management
- Security integrated early in the development lifecycle
- Secure AI adoption and data protection
- Resilient backup and disaster recovery architecture
- Continuous technical workforce readiness
The OT list, paraphrased here rather than quoted, covers identity and access control, a validated asset inventory, strict network segmentation, an OT-specific incident response and recovery plan, known-vulnerability management, remote access pathways, continuous monitoring, system resiliency, supply chain security, and review processes. Its reference document is NIST SP 800-82 Rev 3, the federal guide to OT security.
Two things stand out about that list if you have spent two years staring at 800-171. It is written in outcomes, the way CSF 2.0 is written. And three items ask for more than Rev 2 does.
Why CSF 2.0, in the CIO's own words
NIST released CSF 2.0 in February 2024. It organizes security into six functions: Govern, Identify, Protect, Detect, Respond, Recover. It does not list controls. It describes outcomes and lets an organization pick the profile and tier it needs, which is why it travels across sectors, and why a small shop can start from a quick-start guide instead of a 110-row spreadsheet (NIST CSF 2.0).
Davies has not published a memo that says "CSF 2.0 replaces CMMC." What she has said, on the record, points that way.
At the July 13 announcement she gave the arithmetic: SBA data put compliance cost for small and medium businesses above $7 billion a year, against roughly 100 certified assessors for more than 100,000 companies that would need them. "So the math just simply doesn't math for small to medium-sized businesses to even get compliant by the transition date" (DefenseScoop, July 13, 2026). The task force she created was told to recommend a framework that "prioritizes speed to capability, lowers barriers for small, medium and non-traditional businesses and replaces prohibitive, third-party compliance models with scalable, realistic security measures."
At DIBX in Philadelphia in late August she called protecting federal data "table stakes" and a requirement "that never went away," then said where she wants attention to go: the systems on the production floor that let contractors "actually produce what they produce" for the department. "What we want is results, not red tape. We want performance, not paperwork" (CMMC.com on DIBX 2026). In September she told DefenseScoop the department had more than 1,100 RFI responses and that she wanted to move away from point-in-time assessments toward continuous evaluation.
At the Cyber AB's September town hall, Matt Travis listed what the CIO's office appears to favor: industrial resiliency, operational technology, continuous validation, automation, Brilliant at the Basics, NIST CSF 2.0, and reciprocity with other frameworks (Cyber AB town hall recap, September 30, 2026). The same recap put the certification ecosystem at 2,362 final Level 2 certificates and 117 authorized C3PAOs at the end of September. Against a six-figure population of suppliers, that is the capacity problem in one line.
Our read on why she is going there
Three reasons, all grounded in the record above. This is our interpretation, not a department position. Davies has not said the framework is CSF 2.0; the reading list on the campaign page is the evidence, and Travis's list is the corroboration.
She is an operator, and operators distrust certificates. Davies spent her career as a corporate CISO before the CIO job (ExecutiveGov on her confirmation), and everything she has said on the record is what an operator says: results, continuous evaluation, the production floor. A certificate dated eighteen months ago answers none of the questions a CISO asks daily. CSF 2.0 is written in those questions.
CMMC had no vocabulary for the production floor. The 110 controls are about CUI: where it sits, who reaches it, how it moves. A five-axis mill with a ten-year-old controller that never touches a drawing is out of scope, and it is also the thing a ransomware crew shuts down. Davies's DIBX remarks were about exactly that machine. CSF 2.0 covers it without a new rule, because its functions apply to any system, and SP 800-82 gives the OT specifics. An OT Top 10 list is the first time the department has told a machine shop what good looks like on the floor.
CSF 2.0 lets the department change the test without changing the law. 32 CFR Part 170 and the 7012 clause are still in force. Rewriting them is a multi-year rulemaking. A campaign built on a NIST framework the government already owns, with a Govern function that puts accountability on the owner rather than on an assessor, can move expectations this quarter. The task force report went to the CIO around September 11 and has not been published; Travis's guess for release was the back half of October at the earliest. Whatever it says, the department has already told you what it values.
The three items that outrun 800-171 Rev 2
This is where the campaign stops being an awareness poster. Three of the IT practices ask for things Rev 2 does not, and a contractor who is "fully compliant" on paper can fail all three (analysis at The Defense Compliance Report).
Phishing-resistant MFA. Rev 2 requires multifactor and replay-resistant authentication for network access to privileged and non-privileged accounts (3.5.3, 3.5.4). A one-time code from an authenticator app satisfies that. The campaign asks for phishing-resistant methods, which in practice means FIDO2 security keys or passkeys, or certificate-based sign-in. If your administrators approve a push notification, you meet Rev 2 and miss item one.
Resilient backup. Rev 2 has one backup requirement, 3.8.9, which asks you to protect the confidentiality of CUI at storage locations. The campaign asks for immutable copies, isolated credentials, redundancy, and full-system restoration drills. A nightly backup to a share the domain admin can delete meets 3.8.9 and would not survive the second hour of a ransomware event.
Secure AI adoption. Rev 2 was written in 2020 and says nothing about AI. The campaign asks for approved-use rules and a prohibition on putting sensitive department data into public commercial AI tools. If your staff can paste a drawing note into a consumer chatbot today, you have a gap the current assessment would never find.
What to do before the report lands
The costly mistake right now is treating the pause as permission to stop. The second costly mistake is waiting for the report before touching anything, because the twenty items above are the published expectation for the interim and the three gaps are real regardless of what the task force recommends.
A decision rule for the next sixty days: finish anything that is both in 800-171 Rev 2 and on the IT Top 10, then close the three gaps that Rev 2 misses, in that order. Concretely, that is enforcing MFA on every account with a phishing-resistant method for administrators, finishing the asset inventory so every device that touches CUI has an owner and a patch owner, segmenting the CUI systems from the office network, moving backups to immutable storage with a restore test on the calendar, and writing a one-page AI use rule that names the approved tools.
Your Level 2 self-assessment and SPRS score still have to be true (how the self-assessment works after the pause), and continuous monitoring is the posture every version of the future program rewards (what continuous monitoring looks like for a small contractor). If a prime is still asking for a certificate, this guide covers the conversation.
Garde1 already works the way the CIO is describing. It reads your actual configuration from Entra, Intune, Google Workspace and the rest, scores all 110 requirements continuously instead of on assessment day, and shows the fix list blockers first. The three gaps above land where they belong: phishing-resistant MFA as a finding on IA.L2-3.5.3, with the sign-in method to change; backup resilience on MP.L2-3.8.9, with the storage and the restore test it is missing; and the AI rule, which has no Rev 2 control to attach to, as the acceptable-use clause your policy does not yet have.
