← Back to Military
CMMC Needs Precision and Support for Small Businesses
Military By Michael A.G. · Aug 17, 2026

CMMC Needs Precision and Support for Small Businesses

Katie Arrington, former Department of Defense Cybersecurity Executive, has called for refining the Cybersecurity Maturity Model Certification (CMMC) to better protect sensitive defense data from cyber threats. Introduced in 2019, CMMC was designed to address the inadequacy of self-attestation practices by requiring contractors to prove their cybersecurity measures rather than merely promising compliance. However, Arrington now argues that while the core requirements should remain unchanged, there is room for improvement in how these standards are applied.

Arrington highlights a critical issue within the current CMMC framework: inconsistent application of Controlled Unclassified Information (CUI) determinations across contractors. This inconsistency can result in either overburdening small businesses with unnecessary compliance measures or leaving sensitive data unprotected due to insufficient scrutiny. To address this, she advocates for leveraging artificial intelligence to automate initial assessments and ensure that CUI designations align more accurately with actual data flows within the defense supply chain.

Furthermore, Arrington emphasizes the need to support small businesses in their cybersecurity efforts beyond just training programs. Small businesses constitute nearly 99.9% of American companies and employ almost half of the private workforce. They face significant threats such as ransomware attacks, AI-enabled fraud, and quantum computing vulnerabilities that could compromise future data security. While initiatives like the SBA's Cybersecurity for Small Business Pilot Program have provided valuable training resources, Arrington argues that financial support is also essential.

To bolster small businesses' cybersecurity capabilities, she proposes establishing a dedicated Small Business Administration (SBA) loan program specifically aimed at funding necessary cybersecurity improvements. This would enable small enterprises to invest in critical security measures such as multi-factor authentication, endpoint detection systems, incident response plans, and quantum-resistant encryption technologies before these issues become urgent crises.

By integrating AI-driven precision into CMMC's implementation and providing financial support for small businesses to enhance their cybersecurity posture, Arrington believes the United States can better protect its defense industrial base from increasingly sophisticated cyber threats. These measures aim not only to maintain but also to strengthen national security by ensuring that all contractors adhere to robust cybersecurity standards while supporting the broader economic ecosystem.

Arrington's recommendations underscore a balanced approach to cybersecurity that combines technological innovation with financial support, aiming to make CMMC more effective and sustainable in safeguarding sensitive defense information against evolving cyber threats.

← Back to Military