The Department of War recently requested public feedback on potential improvements to the CMMC program. In response, David Fraley, Founder and CTO of SecureITSM, presents several recommendations based on years of cybersecurity consulting, CMMC implementation, and successful Level 2 certification experience.
These recommendations are intended to improve cybersecurity across the Defense Industrial Base (DIB) while reducing unnecessary complexity for contractors.
Point 1: Never Back Down on NIST SP 800-171 Compliance
The first recommendation is straightforward: maintain the requirement for every contractor handling Controlled Unclassified Information (CUI) to implement NIST SP 800-171, regardless of organization size.
Based on SecureITSM's experience working with defense contractors, several recurring problems continue to appear:
- SPRS self-assessment scores are frequently overestimated.
- Many organizations lack a complete System Security Plan (SSP).
- Continuous monitoring programs are often missing.
- Basic cybersecurity practices such as Multi-Factor Authentication (MFA), secure identity management, and proper documentation remain inconsistent across the Defense Industrial Base.
David references the recent LogZone settlement as an example where a reported SPRS score of 110 was determined during assessment to actually be -173, demonstrating the importance of accurate cybersecurity reporting rather than self-estimated compliance.
Point 2: Require SSP Submission to SPRS
The second recommendation proposes requiring contractors to upload their System Security Plan whenever submitting a CMMC self-assessment in SPRS.
Rather than simply reporting a compliance score, organizations would provide documented evidence describing how each NIST SP 800-171 control is implemented.
Making SSP submission mandatory would:
- Improve transparency
- Increase accountability
- Provide better documentation for future assessments
- Create a stronger foundation for validating compliance claims
David explains that this could be implemented relatively quickly and would significantly improve the quality of information submitted through SPRS.
Point 3: AI-Enabled SPRS Reviews
One of the video most forward-looking recommendations is adding Artificial Intelligence to SPRS for automated SSP reviews.
Rather than replacing C3PAO assessments, AI would provide an initial validation process that reviews submitted System Security Plans against standardized requirements.
Potential AI capabilities include:
- Reviewing SSP implementation statements
- Identifying missing NIST SP 800-171 controls
- Detecting incomplete documentation
- Checking supporting evidence
- Sending automated clarification requests
- Emailing required corrections to Organization Security Administrators (OSAs)
- Revalidating updated SSPs after resubmission
David compares this concept to automated review processes already used by government agencies such as the IRS, where missing information can be automatically identified before final processing.
The goal is not to replace formal assessments, but to improve submission quality and reduce preventable documentation issues before certification.
Point 4: Allow Contracting Officers to Decide When CMMC Certification Is Required & Loosen Assessment Constraints
SecureITSM recommends giving Contracting Officers (KOs) greater flexibility to determine when formal CMMC certification is necessary based on acquisition risk.
Low-Risk Contracts
For lower-risk acquisitions, organizations could rely on:
- Self-assessments
- AI-validated SSPs
without requiring a full C3PAO assessment.
Moderate-Risk Contracts
For contracts involving moderate cybersecurity risk, CMMC maturity could become part of the proposal evaluation process.
For example:
- AI-validated SSP → Limited Confidence
- C3PAO Certification → High Confidence
This allows contracting agencies to consider cybersecurity maturity during source selection rather than treating certification as an absolute requirement.
High-Risk Contracts
For weapon systems, sensitive acquisitions, software development involving non-government systems, and other high-risk work, CMMC certification should continue to be mandatory.
According to David, this approach would maintain strong protection for critical programs while reducing unnecessary barriers for lower-risk contractors and preserving small business participation.
Loosen Current Assessment Constraints
Another recommendation focuses on improving the assessment process itself.
Currently, many of the most important 3-point and 5-point controls do not allow Plans of Action and Milestones (POA&Ms), making certification effectively "pass or fail."
David recommends allowing limited POA&Ms for selected higher-value controls rather than only allowing them for 1-point controls.
However, one important exception should remain:
CA.13.12.4 — the System Security Plan requirement — should continue to result in automatic assessment failure if missing.
He emphasizes that if an organization cannot properly document its security program, then it has not adequately implemented it.
This recommendation would make assessments more practical while maintaining accountability for core documentation requirements.
Point 5: Technical Recommendations
The video concludes with two technical recommendations aimed at reducing unnecessary implementation complexity.
Waive FIPS Requirements
David recommends indefinitely waiving mandatory FIPS requirements.
During SecureITSM's own implementation, enabling FIPS compatibility introduced operational challenges with IT management tools, requiring replacement of existing software despite otherwise meeting security objectives.
He argues that organizations can still achieve strong encryption without limiting operational flexibility.
Simplify NIST SP 800-171 Revision 3
The presentation also recommends simplifying or delaying Revision 3 of NIST SP 800-171.
Compared with Revision 2, Revision 3 significantly increases complexity:
- Assessment Objectives increase from 320 to 422
- Organizationally Defined Parameters increase from 0 to 88
David believes modernization is important but recommends reducing implementation complexity rather than expanding it.
We'd love to hear your thoughts on these recommendations. If you have questions about your CMMC readiness, NIST SP 800-171 implementation, SPRS submission, or managed cybersecurity program, the SecureITSM team is here to help you understand your options and determine the right path forward.