
OT Security Is Key to DIB Resilience: What the DoW CIO Signaled about CMMC Reform at DIBX 2026
Six weeks after the Department of War (DoW) paused the transition to CMMC Phase 2, Chief Information Officer Kirsten Davies spent most of her fireside chat at DIBX 2026 talking about a threat that CMMC was never built to address: operational technology attacks.
On day two of the DoW's inaugural event in Philadelphia, Davies drew a line between information security and OT security. Protecting federal data is "table stakes," she said, and a regulatory requirement “that never went away." Protecting the systems on a production floor that allow contractors to “actually produce what they produce for [the Department]” is where she wants the government and contractor attention to shift to now.
For defense contractors and subcontractors, that is the clearest signal yet of what CMMC reform might look like. The CMMC Phase 2 pause put third-party assessment requirements on hold while a Reform Task Force reviews the program. It did not lower the existing cybersecurity requirements under DFARS 7012. In fact, the CIO’s remarks suggest the Department's expectations for OT security are moving in the other direction.
The latest update on the CMMC task force and review
The Reform Task Force closed its request for information on August 14 with roughly 1,100 responses. By Davies’ count, these amounted to more than 11,000 pages of feedback and more than half were supportive of reform. The task force is going offsite for three days to work through the responses before assembling recommendations for her and Under Secretary Michael Duffey.
The dominant theme was cost. Based on the responses, the Department estimates that small businesses on average are spending anywhere from $250,000 to $500,000 across a three-year window “to achieve the assessment and the status needed to compete for contracts with us.” Davies described a letter from a ten-person, veteran-owned shipbuilding supplier whose CEO was spending half his time on CMMC and had successfully completed a self-assessment and remediation, but was now facing the possibility of having to lay off his employees and close the company because of the cost of Level 2 (C3PAO) certification.
That’s why the task force is focused on making cybersecurity a dynamic process where contractors continue to reduce risk and improve their cyber posture, and do business with the Department.
“We're looking at how we actually do cybersecurity writ large, and still balance that out with compliance,” she said. “What we want is results, not red tape. We want performance, not paperwork.”
She described a cross-functional, cross-Department, interagency team participating in the task force and review, including the Small Business Administration and CISA. She also said they’ve been meeting with the Cyber AB and C3PAOs, holding listening tables across the country, and running social media campaigns to collect as much feedback as possible.
She did not give a firm date for the report or for potential reform but did emphasize that they’re moving at a rapid pace. “We don't want this to be a six- to twelve-month study, and then we think about what we're going to do, and then we think about implementing change.”
If the task force keeps to the original timeline of 60 days for review and 15 days to deliver their recommendations, a final report is expected by late September or early October 2026.
Why operational technology is driving the CIO's thinking and potential reform
Davies framed information security as a baseline obligation and OT security as the harder problem. Protecting federal data is already a regulatory requirement. The part she described as underserved is the resilience and readiness of manufacturing operations: the controllers, workstations, and production systems that determine whether a supplier can actually deliver on their contracts.
Davies came to the role from industry, including a stint as deputy global chief information security officer at Siemens, and she reaches for manufacturing examples rather than data-breach ones. At DIBX, she walked through a short history of cyber-physical attacks:
- Stuxnet attack against programmable logic controllers that controlled the spinning in the Iranian uranium centrifuges.
- a steel mill where a cyberattack drove furnace conditions to the point of causing physical injuries to employees nearby
- bridge controllers in Amsterdam manipulated to raise spans that should have stayed down
The current example is closer to home. Since late July 2026, water and wastewater utilities in at least seven states have reported incidents to the FBI, with activity that degraded operations through pressure loss and flooding. The FBI and EPA public service announcement named internet-facing Rockwell Automation/Allen-Bradley MicroLogix PLCs as the targeted devices. Subsequent reporting put the number of affected states at a dozen or more, with some utilities losing remote control and reverting to manual operation.
The relevance to a defense supplier is not the water sector itself. It is the attack pattern: internet-exposed controllers, weak or reused credentials, and flat networks where a foothold in one place reaches machinery in another. Most small and mid-sized manufacturers in the Defense Industrial Base run some version of that environment.
“These are the threats that are top of mind for me, coming from manufacturing, and top of mind for you all, because you make things for our warfighters,” she said.
The goal of reform is figuring out how to address these very real cybersecurity risks but “still drive market share, revenue generation, and competition… in a safe and resilient way.”
What OT security requirements exist today
Under current rules, OT is largely a documentation exercise rather than an implementation one.
The CMMC Level 2 Scoping Guide and 32 CFR § 170.19 categorize operational technology as a Specialized Asset, alongside IoT and Industrial IoT devices and government-furnished equipment. Specialized Assets are documented in your System Security Plan, managed through risk-based policies and procedures, and subject to a limited check rather than assessment against all 110 NIST 800-171 Rev 2 requirements for CMMC Level 2.
But the Department has since launched the Brilliant at the Basics campaign, the same day it announced the Phase 2 pause, with a list of the top 10 best practices for IT and OT. The OT one-pager is the one that matters if you have a production floor, and the ranking offers a priority order for implementation.
- Identity and access control: Verify every user before OT access, require MFA on sensitive systems, and grant least privilege. "Never trust, always verify" applied to machinery, not just laptops.
- Validated asset inventory: An as-operated inventory of PLCs, RTUs, HMIs, engineering workstations, DCS, and safety instrumented systems, down to firmware versions, protocols, and remote-access entry points. Validated by passive monitoring and physical walk-downs, not a spreadsheet from last year.
- Strict network segmentation: Logical separation between the business network and control systems, so a compromised office endpoint cannot reach the line. A flat network is the single most common finding here.
- OT-specific incident response plan: A plan that prioritizes life safety and physical availability, because shutting everything down is rarely an option. Offline backups, segregated safety systems, a path to manual control, and rehearsed tabletops.
- Manage known exploitable vulnerabilities: Compensating controls when patching means taking a machine offline: firewall rules, micro-segmentation, application allowlisting until a maintenance window opens.
- Remote access pathways: Vendor and remote-employee access granted only when needed, for the shortest time possible, with strong authentication. Always-on connections and cellular gateways are called out specifically.
- Continuous monitoring: Extend logging and review to the production floor. Existing firewall and antivirus logging often covers more than teams realize.
- System resiliency: Design industrial networks to fail safely: fault tolerance, physical redundancy, localized manual overrides, assets grouped by location and sensitivity.
- Supply chain security: Hold suppliers to your own security standard, buy equipment engineered to Department standards, and set a hard replacement schedule for undefendable legacy OT.
- Formal review process: A safety and security review before any significant change, including security updates, so a control change does not create an unsafe condition.
What defense manufacturers should do now
Nothing said at DIBX changes what your contracts require this quarter. DFARS 252.204-7012 is untouched, NIST SP 800-171 Rev 2 implementation is still required, Phase 1 self-assessment requirements are still in contracts, your SPRS score and annual affirmation are still legal representations, and primes are still flowing requirements down on their own timelines.
But that’s the baseline for information security. What defense contractors and manufacturers need to focus on now is enhancing their OT security and resilience. Here are some next steps:
- Inventory the production floor before anything else. Every other item on the OT list depends on knowing what is out there, including firmware versions and remote-access paths. This is also the item most likely to surface something nobody knew was internet-facing.
- Check for internet-exposed controllers. The water sector incidents came through PLCs that were reachable from the internet and generally should not have been. This is a priority to identify and secure now, before an incident.
- Look at IT/OT segmentation as a scoping question too. Strong segmentation improves security and can also keep OT out of your CUI boundary. If you use a CUI enclave, confirm where the production network actually sits relative to it.
- Add OT to your incident response plan. Most CMMC incident response plans only cover IT incidents. If you’re at risk of cyber-physical events, ensure your incident response capabilities and plan covers OT as well.
- Keep closing POA&M items to get to 110. If you have not run a CMMC gap analysis against NIST 800-171 Rev 2 yet, prioritize that. A maximum SRPS score can determine whether you win or lose a bid now, not whenever a revised CMMC assessment timeline is put in place.
Trying to work out your IT and OT scope and strengthen your NIST 800-171 and CMMC program while the task force is at work? Talk to a CMMC expert for guidance.