The Cavalry Is Not Coming : CMMC Is Up to Us

For New Jersey businesses in the defense industrial base, cybersecurity is no longer a back-office concern. It is part of the contract, part of the supply chain, and part of the mission.
The recent decision by the U.S. Department of War to suspend CMMC Phase II requirements and establish a CMMC Reform Task Force is an important development. The government deserves credit for recognizing that compliance costs and administrative burdens can create roadblocks for small, medium-sized, and non-traditional defense contractors.
That reform effort is a good-faith move to keep the Defense Industrial Base: often called the DIB: strong, agile, and secure.
But New Jersey businesses should not mistake reform for relief from responsibility.
The cavalry may be reviewing the program. It is not coming to manage your security program for you.
What Changed With CMMC Phase II?
In support of the Secretary of War’s “Arsenal of Freedom” vision, the Department of War CIO suspended CMMC Phase II requirements and created a CMMC Reform Task Force. The stated goal is to reduce unnecessary compliance burden and cost while continuing to protect federal information and improve operational resilience.
The Reform Task Force is reviewing how CMMC can better use existing commercial cybersecurity capabilities, streamline requirements, and make compliance more practical for smaller defense suppliers.
The Department’s approach is reasonable. Minimum cybersecurity standards are necessary when businesses handle federal contract information or controlled unclassified information, including information related to Department of War materials and programs.
At the same time, the suspension does not mean that New Jersey contractors can stop protecting sensitive information. Existing contractual obligations, NIST SP 800-171 requirements, self-assessments, System Security Plan documentation, Plans of Action and Milestones, SPRS scores, and annual affirmations may still apply.
Businesses must also read their contracts and solicitations carefully. If CMMC requirements are already written into a contract, the contract language remains important until an official modification changes it.
For current program information, contractors should monitor the Department of War CMMC resource page and consult qualified cybersecurity and legal professionals regarding their specific obligations.
Why New Jersey Businesses Should Pay Attention
New Jersey has a substantial and diverse defense industrial base.
That includes major defense organizations with a presence in the state, research and manufacturing activity connected to Picatinny Arsenal in Morris County, and hundreds of smaller suppliers, subcontractors, engineering firms, manufacturers, technology companies, and professional services businesses supporting government programs.
Many of these organizations do not think of themselves as “defense contractors.” They may produce a component, provide engineering support, manage logistics, maintain equipment, or process data for a larger prime contractor.
But if their systems touch protected federal information, they are part of the security chain.
A supply chain is like a relay team. The largest organization may have excellent security, but one weak handoff can compromise the entire race. Attackers understand this. They often target smaller suppliers because those businesses may have fewer security resources, less formal oversight, or limited internal IT leadership.
CMMC is intended to establish a minimum baseline so every runner on the team can protect the baton.
That baseline may be reformed. It should not be ignored.
Reform Is Welcome. Waiting Is Not.
The Department of War’s reform effort should be viewed as an opportunity: not an excuse to delay.
The government is acknowledging a genuine problem: compliance that is too expensive, too complex, or too administrative can discourage capable companies from participating in the DIB. That can reduce competition, slow innovation, and weaken the industrial base the program is intended to protect.
A more scalable CMMC program can help New Jersey businesses remain competitive while improving national security.
However, no government reform can answer basic questions for your company:
- Where does CUI exist in your environment?
- Who can access it?
- Which systems are in scope?
- Are your controls operating every day?
- Can you produce evidence that they are working?
- What happens if an employee clicks a malicious link?
- How quickly would you detect an intrusion?
- Can you recover without interrupting a critical contract?
Those answers belong to company leadership.
CMMC is not just a certification event. It is a management responsibility.
The Eight Layers of Protection
A practical CMMC program should be built as a system of connected defenses. Think of your business as a castle protecting both people and valuable cargo. A strong outer wall is helpful, but it is not enough. You also need guards, locks, interior controls, surveillance, training, and a recovery plan.
1. Leadership and Accountability
Security begins with executive ownership.
The CEO, COO, CFO, CIO, CTO, general counsel, and business owners need a clear understanding of what information is protected, what compliance requires, and what risks could affect revenue, contracts, EBITDA, and strategic goals.
A vCISO or cybersecurity advisor can provide leadership without requiring a full-time executive hire.
2. Governance and Compliance
Policies, procedures, risk registers, system boundaries, evidence, and corrective action plans turn good intentions into an operating program.
MEASURERISK helps organizations manage CMMC and NIST requirements through gap analysis, evidence collection, policy development, remediation guidance, audit-ready documentation, and ongoing monitoring.
The goal is not to create paperwork for its own sake. The goal is to make your security program understandable, repeatable, and defensible.

3. Identity and Access Control
Every user should have the access necessary to do the job: and no more.
Use strong authentication, least privilege, role-based access, timely account removal, and regular access reviews. If a former employee still has access to a sensitive system, your castle has an unlocked side door.
4. Endpoint, Network, and System Security
Laptops, servers, cloud applications, manufacturing systems, and network devices must be securely configured and maintained.
Patch management, secure configurations, malware protection, segmentation, encryption, backups, and vulnerability management all contribute to this layer.
5. CUI and Data Protection
Businesses must know where CUI is stored, processed, transmitted, and shared.
Data should not be scattered across personal devices, unmanaged cloud storage, email inboxes, and unknown applications. Define the environment, limit unnecessary movement, control removable media, and protect information throughout its lifecycle.
6. Continuous Monitoring and Response
A burglar alarm that no one watches is not a security program.
ManageIT/MSOC provides 24/7 monitoring, threat detection, threat hunting, response support, endpoint protection, Microsoft 365 administration, and executive reporting. Continuous monitoring helps identify suspicious activity before a small incident becomes a contract-threatening event.
7. People, Awareness, and Resilience
Employees are not the weakest link. Untrained employees are simply being asked to defend the castle without knowing where the gates are.
PhishIT uses phishing simulations, role-based education, click-rate tracking, and behavioral measurement. CyberTrain uses tabletop exercises and incident rehearsals so executives and departments can practice decisions before an actual disruption.
8. Validation, Adversarial Testing, and Supply Chain Oversight
A checklist tells you what should work. Testing tells you what actually works.
CATSCAN®, a registered trademark of Proactive Risk, is an intelligence-led adversarial assessment that examines cyber, physical, and social weaknesses. It helps identify how a real attacker may enter, move through, and affect the organization.
RISKWatch extends that visibility to vendors and partners through structured assessments, evidence collection, risk scoring, annual verification, and executive reporting.

Why It Matters
CMMC affects more than an audit schedule.
It can influence whether a New Jersey business qualifies for work, remains eligible for a subcontract, wins a renewal, or becomes a trusted partner to a larger prime contractor.
It also affects business continuity. A cyber incident can interrupt manufacturing, delay delivery, expose sensitive information, trigger contractual reporting obligations, and damage customer confidence.
For leadership, the financial question is straightforward: Does the cost of a mature security program protect: or threaten: EBITDA and strategic goals?
The answer is usually found in preparation. A well-managed cybersecurity program reduces avoidable surprises, supports contract readiness, and helps the organization invest in growth with greater confidence.
This is the central objective: Secure the Future of Your Strategic Goals.
How We Deliver It
PROACTIVE RISK helps New Jersey organizations turn CMMC from a confusing compliance project into an operating discipline.
Our team supports defense and government organizations through:
- MEASURERISK for CMMC, NIST, HIPAA, NY DFS 500, and broader compliance management
- vCISO leadership for executive guidance, program oversight, risk prioritization, and board reporting
- ManageIT/MSOC for 24/7 managed detection, response, monitoring, and IT operations
- CATSCAN® adversarial testing across cyber, physical, and social domains
- RISKWatch third-party risk management and supply chain oversight
- PhishIT security awareness and phishing simulation programs
- CyberTrain incident rehearsals, tabletop exercises, and corrective action planning
We also recognize that the DIB needs more qualified people. Proactive Risk is hiring to help meet the growing demand for CMMC assessors, compliance professionals, security practitioners, and people who can assist with cybersecurity program oversight.
If you have experience with CMMC, NIST SP 800-171, assessment preparation, security operations, governance, risk, or executive program management, we encourage you to contact Proactive Risk. Organizations seeking assistance can also schedule a complimentary Risk Briefing with a senior advisor.
The Takeaway
The Department of War’s CMMC reform effort is welcome. Reducing unnecessary cost and administrative burden can make the DIB more competitive and bring more small and organizations into the mission.
The government is right to seek minimum standards for protecting federal information. It is also right to examine whether the current approach is practical, scalable, and aligned with operational resilience.
But reform will not replace ownership.
New Jersey defense contractors should continue assessing their environment, protecting CUI, documenting their controls, monitoring for threats, training their people, testing their defenses, and preparing for whatever the final CMMC model requires.
The cavalry may improve the road. Your organization still has to build and defend the fort.
PROACTIVE RISK Intelligence-Led Cybersecurity & Risk Management ANTICIPATE. DEFEND. PREVAIL.
36 First Avenue, Suite 203, Denville, NJ 07834 973-298-1160 · www.proactiverisk.com
