The Department of War realized it was dealing with a supply chain risk of vulnerable vendors; back in 2019 they launched the Cybersecurity Maturity Model Certification. The goal was to ensure defense contractors protected sensitive unclassified information.

Over the years it has transitioned from being a "checkbox" compliance to moving way beyond the minimum to pass.

During today's interview with Travis Goldbach from Coalfire Federal, he gives us overview of how CMMC has made the transition to building a security program that protects the mission, supports growth, and earns trust.

Goldbach continue by stating the cybersecurity is going to impact just about everybody – from sales, to legal, to operations, to finance and even executive leadership.

Travis highlights the importance of CMMC for acquisition, noting that many defense contractors are unprepared. CMMC 2.0, implemented in November 2025, simplified the framework from five levels to three, focusing on basic cyber hygiene, CUI protection, and advanced protection.

He also discusses the impact of remote work and AI on CMMC readiness and the importance of a robust ecosystem of trusted partners for sustained compliance.

Rather than detailing the number of controls in the varying levels of CMMC, the discussion moved on to the concept of documentation. The challenge Goldbach sees is the conflation of documentation with readiness.

More must be added to documentation to make it viable. For example, companies need ownership, governance, and accountability in a repeatable process.