Where does Department of War CIO Kirsten Davies want CMMC to go? Her September 9 remarks at the Billington CyberSecurity Summit emphasized ongoing security and manufacturing resilience, while acknowledging unresolved questions about verification. These were statements of direction, not a final replacement program. DefenseScoop's September 9 reporting documents those remarks.
HostBreach's threat-informed CMMC readiness approach uses threat context to prioritize security improvements and connect them to applicable CMMC requirements and evidence. Our analysis below considers Davies's reform priorities alongside the DoW CIO's Brilliant at the Basics guidance, with the goal of making every security dollar produce meaningful risk reduction.
Start with the announced policy
On July 13, 2026, the Department announced the immediate suspension of CMMC Phase II requirements, previously scheduled for November 10, 2026. Its release said Phase I self-assessment requirements remained in place and that the pause did not eliminate obligations to protect federal data. The Department also announced a comprehensive review intended to reduce barriers for smaller and nontraditional businesses. Official Department release, July 13.
In that release, Davies stated:
“Robust cybersecurity and operational resilience remain critical to protecting American innovation and supporting warfighter readiness.”
That quotation comes directly from the official July 13 release. It describes the Department's objective; it does not define a new assessment method. Contractors should check their specific solicitations, contracts, and current official guidance before changing readiness commitments.
What Davies's September comments signal
Security must continue between assessments
As reported by GovCIO Media & Research on September 9, Davies said:
“Compliance equals compliance. Compliance doesn’t equal security,”
She called for a dynamic approach that keeps pace with threats, rather than treating an assessment as a complete picture of security. GovCIO's reporting from Billington.
HostBreach analysis: A readiness program should connect documentation to repeatable operating practices. Ask what changed since the last review, which exposure was reduced, and what evidence shows the improvement is still working. Assessment preparation and ongoing risk management should reinforce each other.
Manufacturing resilience deserves attention
Davies also emphasized the importance of operational technology and the resilience of manufacturing lines, alongside information protection. GovCIO reported that her team was working through those concerns during the reform effort. GovCIO, September 9.
HostBreach analysis: For a manufacturer, readiness discussions should include production dependencies and recovery priorities. This is our operational recommendation, not a claim that Davies announced new OT controls or that existing CMMC scoping guidance excludes OT. Bring production owners into the discussion before choosing security changes that could affect availability or safety.
How to verify security remains an open design question
DefenseScoop reported that Davies described more than 1,100 feedback responses and over 10,000 pages of documentation being reviewed. She also discussed assessor concerns about demonstrating that the defense industrial base follows federal policy. On that verification question, she said:
“This is still something that we need to resolve for,”
HostBreach analysis: Those remarks should not be read as an announcement that independent assurance will disappear or that a particular monitoring product will replace certification. Preserve evidence and keep remediation work moving while the policy process develops.
Brilliant at the Basics and threat-informed CMMC readiness
The DoW CIO's Brilliant at the Basics campaign provides IT and OT cybersecurity guidance for defense industrial base partners, including smaller and nontraditional businesses. Its IT priorities include phishing-resistant MFA, asset inventory, reducing legacy technology exposure, segmentation, risk-based vulnerability management, and resilient backups. The campaign also provides a separate OT list addressing the needs of physical operations. Official DoW CIO campaign and guidance.
HostBreach analysis: These priorities give leaders a practical starting point for the security outcomes discussed above. Our approach to threat-informed CMMC readiness connects those fundamentals to the organization's applicable CMMC requirements and assessment evidence. The campaign's best-practice lists should not be treated as a substitute control set, a certification, or proof that every CMMC objective has been met.
Consider an externally visible remote-access service. The outside observation can prompt ownership and scope validation, followed by an internal review of authentication and access restrictions. The team should then document the relevant CMMC requirement, what was tested, any remediation, and the evidence supporting its conclusion. Passive visibility alone cannot determine whether MFA is enforced or whether the service is compliant.
That is how HostBreach recommends putting Brilliant at the Basics into practice within a CMMC readiness engagement: use threat context to prioritize investigation, strengthen the fundamentals, and maintain traceability to applicable requirements. This is HostBreach's interpretation of the connection, not a claim that the Department endorses our services or has adopted threat-informed CMMC as an official program.
How threat-informed CMMC connects to CMMC
HostBreach analysis: Threat-informed CMMC is our approach to doing CMMC readiness work with threat context. It is not a separate certification, a new compliance level, or a Department-endorsed framework. The connection must remain traceable: an observed exposure or relevant threat should lead to a validation question, an applicable CMMC requirement or assessment objective, a remediation decision, and supporting evidence.
For example, a passive observation of a remote-access service should prompt the team to confirm ownership and scope, then review the applicable access-control and authentication requirements using internal evidence. The observation alone does not establish that a control is missing or ineffective. Likewise, a resilience concern should lead to a review of relevant response and recovery practices, with the exact CMMC mapping verified against the requirements applicable to that environment.
In a readiness workplan, we recommend recording the applicable requirement and objective beside each action, its owner, its evidence, and the reason for its priority. Threat intelligence helps decide where to investigate and improve first; it does not justify omitting other applicable requirements. That is the link between threat-informed CMMC readiness and defensible CMMC preparation.
A practical plan for threat-informed CMMC readiness
The following actions are HostBreach recommendations, not newly announced Department requirements.
- Keep an obligations register. Record the requirements applicable to each contract, the responsible owner, supporting evidence, and questions needing clarification. Separate confirmed requirements from proposed reforms.
- Review the organization's outside view. Use passive external intelligence to identify observations that warrant investigation. Validate asset ownership, business purpose, and relevance internally before assigning a remediation priority.
- Connect each investment to an outcome. For every proposed change, state whether it is intended to reduce initial-access opportunities, limit blast radius, improve detection and response, or speed recovery. Assign an owner and a way to check the result.
- Include production and recovery owners. Document which services matter most to delivery and what evidence supports recovery expectations. Coordinate operational changes with the people responsible for safe production.
- Maintain an evidence rhythm. Review material changes regularly and update the supporting records. A useful management review should show what was observed, what was validated, what was changed, and what remains unresolved.
This is the approach behind HostBreach's Threat-Informed CMMC Advisory: use intelligence to sharpen security decisions while keeping readiness work grounded in the organization's actual obligations and environment.
Continue the Brilliant at the Basics discussion
HostBreach principal Francisco “Franco” Velasquez recently presented DoW's Brilliant at the Basics: What DIB Companies Should Prioritize First. Watch the webinar on YouTube.
This article carries that discussion forward by connecting security fundamentals to threat-informed CMMC readiness, applicable requirements, and evidence preparation.
Where a CMMC Cyber Snapshot fits
A CMMC Cyber Snapshot provides passive external intelligence to help frame follow-up questions. It is not a penetration test, certification, or formal assessment. External observations alone cannot establish compromise, determine CMMC requirements, or demonstrate compliance or noncompliance.
HostBreach is a threat-informed cybersecurity advisory firm providing CMMC and vCISO services powered by its proprietary Cyber Intel Engine. The engine supports advisory judgment; it does not replace internal validation or assessment evidence. HostBreach provides advisory and readiness support, not C3PAO certification.
To discuss your organization's priorities, book a conversation with HostBreach.
Source and interpretation note
Prepared September 16, 2026. The July policy announcement is sourced to the Department's own release; the Brilliant at the Basics description is sourced to the DoW CIO's official campaign page. September quotations and descriptions are attributed to the linked reporting by Carten Cordell at GovCIO Media & Research and Jon Harper at DefenseScoop; they are not presented as an official Department transcript. Sections marked HostBreach analysis and recommendations express our interpretation, not government endorsement or a prediction of final rules.
