
Brilliant at the Basics Isn't Basic: What the DoW CIO's Top 10 Lists Signal About CMMC Reform
When the Department of War paused the transition to CMMC Phase 2 and launched a 60-day program review on July 13, 2026, it also published something new: the "Brilliant at the Basics" campaign. This DoW CIO initiative is aimed squarely at the small, mid-sized, and non-traditional contractors the Reform Task Force is also trying to help.
The campaign provides two Top 10 lists of cybersecurity best practices, one for IT environments and one for operational technology (OT), that are designed to strip away “administrative complexity and compliance overhead.” However, some of these foundational core practices aren’t as basic as they seem and ask for more than what’s required in NIST SP 800-171 Rev 2 today.
That gap matters right now for a specific reason. With the Reform Task Force report expected in October (15 days after the 60-day program review) and the RFI comment window closing at 12:00 PM ET on Friday, August 14, Brilliant at the Basics is the clearest signal of what the Department thinks good cybersecurity looks like in suppliers and partners that need to secure their networks and protect sensitive defense information.
A note on naming: CMMC rules, clauses, and source documents still read "Department of Defense (DoD)," so this article uses the statutory name where it cites those, and DoW or “the Department” where it refers to current activity.
What Brilliant at the Basics is, and what it is not
Brilliant at the Basics is a voluntary DoW CIO awareness campaign, not a rule, a contract clause, or a compliance framework. There is no assessment methodology, no scoring rubric, no evidence standard, and no certification. Nothing about it is enforceable, and no contract requires it.
It lists the top 10 practices for IT as:
- Upgrading legacy methods to phishing-resistant multi-factor authentication
- Establishing and maintaining a comprehensive asset inventory management
- Reducing technical debt (legacy systems, shadow IT, unsupported software)
- Maintaining a flexible, modular technology stack incorporating best-in-class commercial solutions
- Implementing logical segmentation to limit adversary lateral movement
- Establishing a continuous, risk-based vulnerability management program
- Integrating security early in the development lifecycle
- Putting policies and technical guardrails in place to secure AI adoption and data
- Building resilient backup and disaster recovery architecture
- Continuously training and developing your technical and security personnel
It lists the top 10 practices for OT as:
- Enforcing identity and access control for your OT
- Creating and maintaining a validated inventory of all physical and logical components within your OT environment
- Strict network segmentation between your IT and critical operating systems
- OT-specific Incident Response and Recovery Plan (IRP)
- Managing known exploitable vulnerabilities
- Establishing timed remote access pathways with strong authentication
- Extending basic continuous monitoring to the production floor
- Taking a secure, modular approach to building and updating for system resiliency
- Managing supply chain security and replacing legacy OT
- Establishing formal review process for significant changes to OT systems
Takeaway: You cannot become "BatB certified," and no one is going to ask you to. Treat the lists as the DoW telling you where it wants your attention during the review period, not as a new obligation.
What the Cyber EF said about the Phase 2 pause
The answer echoed what we’ve heard from the DoW, primes, and other industry stakeholders: no implementation requirement has been removed.
The pause stops third-party assessment requirements from being written onto new contracts by a DoW contracting officer. It does not remove existing obligations to protect federal data, including DFARS 252.204-7012, NIST SP 800-171, and the Phase 1 CMMC self-assessment and affirmation requirements, which are already in contracts and still being put in awards. It also does not stop primes from flowing requirements down to their supply chain on their own schedule.
The Cyber EF speculated that one possible direction of the CMMC program review and proposed reform will be shifting from checklist- to risk-based.
Under this model, a contractor and its practitioner may focus on implementing the most high-risk requirements and document why others are not yet met, what compensating controls are in place, and what the remediation path is, instead of treating all 110 requirements as equally weighted. Future assessments would be more likely to focus on critical requirements and on validating that testing was performed against the environment where CUI actually lives.
Where the "basics" sit above NIST 800-171 Rev 2
Most of the IT Top 10 maps onto control families you already know from NIST 800-171. But at least four items ask for a materially higher technical bar than the Rev 2 language they resemble.
- Phishing-resistant MFA. Requirement 3.5.3 is satisfied by multifactor authentication generally. The campaign specifically calls for moving off SMS codes and push notifications, which points toward hardware-backed or FIDO2-style authenticators most contractors have not deployed or budgeted for.
- Dynamically updated asset inventory. Requirement 3.4.1 expects baseline configurations and a system inventory. Brilliant at the Basics asks for continuously tracked and validated assets across hardware, software, identities, and data, which is a discovery-and-tooling problem, not a spreadsheet problem.
- Secure AI adoption and data protection. There is no Rev 2 analog. This is a new category: acceptable-use policy, content filtering, endpoint controls, and an approved enterprise AI environment, plus an explicit prohibition on putting Department data into public commercial AI tools.
- Resilient backup and disaster recovery. Requirement 3.8.9 asks you to protect backups of CUI. The campaign asks for immutable, logically vaulted copies with isolated credentials and regular full-system restoration drills.
The pattern holds across most of the list: the items are recognizable, the expectations are higher. Continuous technical workforce readiness, for example, is a long way past the annual awareness training that satisfies 3.2.1 and 3.2.2.
Takeaway: If you are using the IT Top 10 as a self-check, score yourself against the campaign language, not against the requirement number it resembles. The two are not the same test.
What the lists leave out says more than what they include
Here is the part worth paying attention to. Scan both Top 10 lists for the words system security plan, POA&M, audit log retention, personnel screening, or physical access records. They are not there.
Those are exactly the documentation and governance controls that drive the compliance staffing and consulting spend the RFI is asking industry to price. The RFI's seven questions ask which controls deliver real risk reduction and which impose the greatest burden relative to the security they add. Brilliant at the Basics reads like an early answer to that question, published a day before the RFI itself.
It is also written differently. NIST 800-171 is prescriptive and evidence-based: each requirement specifies what must be in place and an assessor evaluates documented proof. The campaign language is outcomes-oriented throughout. It says minimize your attack surface and design your systems to fail safely, and leaves the implementation path to you.
In an August Cyber EF webinar, the Cyber EF's Mike Snyder described the reform model he expects based on his own observations: instead of requiring 110 out of 110 controls on day one, the Department could let contractors bid and perform with most requirements implemented, carry POA&Ms or compensating controls for the rest, and report the residual risk back to the government. He characterized the Department's target as a roughly 50-50 split on risk acceptance, with the government willing to share risk where a contractor's compensating controls are sound. That model would trade administrative proof of full 800-171 implementation for honest, ongoing risk reporting, which is consistent with what the Top 10 lists emphasize and what they omit.
Takeaway: The likeliest shape of reform is fewer administrative artifacts and a harder technical floor, not a smaller program overall. Contractors betting on "less work" may be reading the signal backwards.
The OT Top 10 is the bigger change for manufacturers
If you run production, the OT list deserves a closer read than the IT one. The CMMC Level 2 Scoping Guide currently categorizes operational technology as a Specialized Asset, which carries a lighter implementation burden and leans on risk treatment and documentation in the SSP rather than full control implementation.
The Brilliant at the Basics OT list is not lighter. It asks for an as-operated inventory covering PLCs, RTUs, HMIs, engineering workstations, and safety instrumented systems, down to firmware versions and communication protocols. It asks for strict IT/OT segmentation, OT-specific incident response with offline backups and manual-control transitions, elimination of always-on remote access, compensating controls where patching is impossible, and continuous monitoring on the production floor.
There's precedent for these expectations. Several items on the OT list, along with practices like resilient backup and disaster recovery on the IT side, appeared in the original version of CMMC 1.0 before being stripped out in CMMC 2.0.
The Cyber EF’s Matt Snyder noted during the August webinar that these requirements were removed largely because they were considered too costly and burdensome for small and mid-sized contractors to implement. Their return in Brilliant at the Basics suggests the Department never stopped viewing them as necessary, it just needed a lighter-weight vehicle to reintroduce them.
Takeaway: Defense manufacturers that have treated OT as out of scope through the Specialized Asset path should read the OT Top 10 as notice that the Department's expectations for those environments are moving.
What to do before the Task Force reports
Nothing in this campaign changes what your contracts require this quarter. DFARS 252.204-7012 is untouched, NIST 800-171 Rev 2 implementation is still required, your SPRS score and annual affirmation are still legal representations, and primes are still flowing requirements down on their own timelines.
With that as the baseline:
- Run the IT Top 10 as a supplementary gap check. Not as a replacement for a gap analysis against all 110 requirements, but as a second pass that catches the four or five places where the Department is signaling the bar will rise.
- Price the four uplift items. Phishing-resistant authenticators, continuous asset discovery, immutable backups, and AI governance all have real cost and lead time. Knowing those numbers is useful for your RFI response and for your FY27 budget either way.
- Read the OT list if you have a production floor. Then check how your current scoping treats those assets.
- Keep closing POA&Ms. A paused verification deadline is the cheapest remediation window you are going to get, and open items are the first thing a prime's supplier questionnaire asks about.
Where to start: This NIST 800-171 compliance checklist walks all 110 requirements, and free SSP, POA&M, and policy templates are in the CMMC.com Resources library. You can check any individual requirement in the Requirement Explorer.
Trying to figure out what your program should look like while the Task Force works? Talk to a CMMC expert. No sales pitch, just answers.
FAQs
Is Brilliant at the Basics required? No. It is a voluntary DoW CIO awareness campaign with no rule, clause, assessment methodology, or certification behind it. Your binding requirements are still DFARS 252.204-7012, NIST SP 800-171 Rev 2, SPRS scoring, and your annual affirmation.
Does Brilliant at the Basics replace CMMC or NIST 800-171? No. It does not replace either one. It covers 20 prioritized practices across IT and OT, while NIST 800-171 Rev 2 contains 110 requirements assessed against 320 objectives, including the documentation and governance controls the campaign does not address.
Is Brilliant at the Basics easier than NIST 800-171? Not uniformly. It is shorter and it drops most documentation requirements, but several individual practices, including phishing-resistant MFA, continuous asset inventory, immutable backup architecture, and AI governance, ask for more than the Rev 2 requirements they resemble.
Where can I find the official Brilliant at the Basics lists? The DoW CIO publishes both on its campaign page, with downloadable PDFs for the IT Top 10 and the OT Top 10.