
Brilliant at the Basics vs. NIST 800-171: What Defense Contractors Need to Know About the DoW's Cybersecurity Campaign
Emily Bonnie
Senior Content Marketing Manager
On July 13, 2026, the Department of War paused Phase 2 of the CMMC program rollout, which included the requirement for C3PAO assessments for CMMC Level 2 that was set to take effect in November. At the same time, it launched a CMMC Reform Task Force and introduced the "Brilliant at the Basics" initiative.
If you're a defense contractor trying to figure out what these changes mean for your security and compliance program, this guide covers what your obligations are right now, what Brilliant at the Basics actually is, how it compares to the NIST 800-171 framework you've been working toward, and what the reform process might mean for the future of CMMC.
Your cybersecurity obligations under DFARS and the False Claims Act
The Phase 2 pause removed the C3PAO certification requirement from the near-term picture. It didn't remove the underlying security expectations.
DFARS 252.204-7012 is still in force
Incorporated into most DoD contracts since 2016, DFARS 252.204-7012 requires contractors to implement all 110 NIST SP 800-171 Rev 2 security controls, maintain a System Security Plan documenting how those controls are met, report cyber incidents to DoD within 72 hours of discovery, and preserve images of compromised systems for 90 days. The clause applies to any contractor or subcontractor whose systems process, store, or transmit covered defense information.
NIST SP 800-171 Rev 2 compliance is still required
NIST SP 800-171 is the underlying technical standard that DFARS 7012 requires. It defines 110 security controls across 14 control families that protect controlled unclassified information (CUI) on non-federal contractor systems. Compliance is self-assessed, which is where SPRS comes in.
SPRS scores still matter
The Supplier Performance Risk System (SPRS) is the DoD database where contractors submit their NIST 800-171 self-assessment scores. Scores range from -203 to 110, with 110 representing full compliance across all controls. Contracting officers can see your score when making source selection decisions, which means a low or inaccurate score can affect your ability to compete for contracts. If your score is below 110, you're required to have a Plan of Action and Milestones (POA&M) documenting how and when you'll close remaining gaps.
False Claims Act exposure
The DOJ's Civil Cyber-Fraud Initiative, launched in 2021, uses the False Claims Act to pursue contractors who knowingly misrepresent their cybersecurity practices or compliance status. This includes overstating your SPRS score, attesting to controls you haven't implemented, or failing to disclose known gaps. FCA cases can result in significant financial penalties, and qui tam provisions allow whistleblowers to file suits on behalf of the government, which means the exposure isn't limited to what DoD itself discovers.
DoW CIO Kirsten Davies was explicit that the department is still actively enforcing cybersecurity requirements through self-assessments and targeted government-led assessments. The message from DoW is clear: the Phase 2 pause is a reform of the validation mechanism, not a change to cybersecurity expectations.
For contractors who had been working toward a C3PAO assessment, your NIST 800-171 remediation work remains legally and contractually required. A gap between your attested SPRS score and your actual security posture is an FCA exposure, regardless of what happens with the CMMC certification framework.

That's the regulatory picture. So where does Brilliant at the Basics fit in? Think of it less as a new compliance standard and more as DoW communicating what it wants contractors to prioritize during this 60-day program review.
Recommended reading
CMMC Phase 2 Paused: Which Requirements Still Apply After the Latest DoW Announcement and Prime Notices?
What is Brilliant at the Basics?
Brilliant at the Basics is a DoW CIO cybersecurity campaign launched alongside the Phase 2 pause announcement. It provides two separate "Top 10" best-practices lists: one for IT environments and one for Operational Technology (OT). They're designed to give DIB partners, especially small and mid-sized contractors, a practical security baseline to work from during this interim period.
The IT Top 10 covers:
- Phishing-resistant multi-factor authentication
- Comprehensive asset inventory management
- Strategic technical debt reduction (retiring legacy systems, shadow IT, unsupported software)
- Maintaining a flexible, modular technology stack
- Logical segmentation to limit adversary lateral movement
- Risk-based vulnerability management
- Integrating security early in the development lifecycle
- Secure AI adoption and data protection
- Resilient backup and disaster recovery architecture
- Continuous technical workforce readiness
The OT Top 10 covers similar ground but is tailored for industrial control systems and operational environments: asset inventory for PLCs and HMIs, strict IT/OT network segmentation, compensating controls for equipment that can't be patched, supply chain security for physical systems, and OT-specific incident response. If your organization has manufacturing, defense electronics, or weapons component production, the OT list is the more directly relevant one.
A few important clarifications: Brilliant at the Basics is a cybersecurity campaign, not a compliance framework. There is no assessment methodology, no scoring rubric, no evidence standard, and no certification pathway. You can’t become "BatB certified." The DoW built it as a practical interim benchmark, not as a replacement for existing regulatory requirements.
How Brilliant at the Basics relates to NIST 800-171 + Crosswalk
The relationship between BatB and NIST 800-171 is best understood along two lines: which NIST 800-171 controls BatB also covers, and how the two approach cybersecurity differently.
Where the two frameworks overlap
Brilliant at the Basics covers meaningful ground within the NIST 800-171 control set, but it doesn't cover all 110 requirements. Based on the IT Top 10, here's how the BatB items map to NIST 800-171 Rev 2 control families:
| BatB IT Top 10 | NIST 800-171 Rev 2 Family | Related 800-171 Rev 2 Controls |
|---|---|---|
| Phishing-resistant MFA | Identification and Authentication (IA) |
|
| Asset inventory | Configuration Management (CM) |
|
| Technical debt reduction | Configuration Management (CM) |
|
| Flexible/modular architecture | System and Communications Protection (SC) |
|
| Logical segmentation | System and Communications Protection (SC) |
|
| Risk-based vulnerability management | Risk Assessment (RA); System and Information Integrity (SI) |
|
| Security in the development lifecycle | Configuration Management (CM); Security Assessment (CA) |
|
| Secure AI / data protection | No direct Rev 2 analog | No direct NIST 800-171 Rev 2 analog. The closest controls (3.13.16, 3.13.8, 3.8.1–3.8.2) address CUI data protection broadly but predate AI governance as a defined practice area. This item represents a new category of expectation. |
| Backup and disaster recovery | Media Protection (MP); System and Information Integrity (SI) |
|
| Continuous workforce readiness | Awareness and Training (AT) |
|
Note: This crosswalk reflects our analysis based on control language. No official DoW mapping between BatB and NIST 800-171 has been published.
For several IT Top 10 items, BatB doesn't rely on existing 800-171 requirements — it raises the technical bar. For example:
- Standard MFA satisfies NIST 800-171 control 3.5.3, but BatB calls specifically for phishing-resistant authentication. This typically means hardware-backed authenticators or FIDO2-style methods that most contractors haven't deployed.
- The asset inventory item pushes toward continuous, automated discovery well beyond the baseline configuration inventory that 3.4.1 describes.
- Secure AI adoption has no 800-171 Rev 2 analog. For these items, BatB is signaling where the technical baseline is heading.
How the two approaches differ: Less emphasis on governance, documentation, and procedural controls
BatB's focus on technical outcomes comes with a notable omission: the governance, documentation, and procedural controls that make up a significant share of NIST 800-171 compliance work. Audit log management, SSPs, POA&Ms, physical access records, personnel screening documentation — none of these appear in the IT Top 10.
These are also the controls that traditionally require dedicated compliance staff or outside consultants to implement and sustain, and they're a major driver of the cost burden that pushed smaller contractors out of the DIB.
BatB’s lack of emphasis on these controls is significant because it signals how DoD could be approaching the access problem: by separating the cybersecurity controls that deliver real risk reduction from the administrative controls that stall compliance programs.
Outcomes-based approach
BatB and NIST 800-171 also differ in how they define what "done" looks like.
NIST 800-171 is prescriptive. Each of its 110 controls specifies a security requirement that must be met, and assessors evaluate compliance against documented evidence of implementation. The framework tells you what you must have in place and creates an expectation that you can demonstrate it.
BatB is outcomes-oriented throughout. The language across the IT Top 10 focuses on goals rather than methods: "minimize your attack surface," "establish and maintain," "design for resilience." It doesn't specify which technology, configuration, or evidence artifact satisfies a given item. A contractor could meet the MFA requirement with any phishing-resistant authentication mechanism that fits their environment. The framework cares about the outcome, not the implementation path.
In that sense, BatB has more in common with the SOC 2 Trust Services Criteria, where organizations can demonstrate that a control objective is met through a range of methods and evidence types, than with NIST 800-171.
Takeaways for defense contractors navigating federal cybersecurity and compliance
The Reform Task Force report isn't due until late September or early October. Until then, here's what defense contractors can confidently act on.
Don't pause NIST 800-171 remediation. The self-assessment requirement and your SPRS score are still live, and both carry legal weight. Any gap between your attested score and your actual security posture is a False Claims Act exposure.
Use the BatB IT Top 10 as a gap analysis tool. Work through each of the ten items and assess your current state honestly. If you can't clearly answer how your organization satisfies a given item, that's a useful signal about where your biggest risks are, independent of any formal certification program.
Check whether the OT Top 10 applies to your environment. If you have manufacturing operations, industrial control systems, or any operational technology in scope, the OT list addresses considerations that the IT list doesn't.
Respond to the RFI before August 14. DoW published a Request for Information seeking industry input on CMMC compliance challenges, cost drivers, and alternative approaches. Comments are due by 12:00 PM ET on August 14, 2026. If your organization has direct experience with compliance costs or operational barriers, that's exactly the input DoW says it's looking for.
The next phase of federal cybersecurity
Whether the question is "can you certify compliance with 110 NIST 800-171 controls" or "are you executing the security fundamentals that meaningfully reduce risk," the underlying goal is the same: a DIB that's more resilient and secure.
It's also the same problem Secureframe Defense was built to solve. Building and maintaining a cybersecurity posture strong enough to protect sensitive information and satisfy government requirements has traditionally meant large compliance teams, expensive consultants, or both. That cost falls hardest on small and mid-sized contractors, and it's exactly what the DoD is now trying to address through reform.
Secureframe Defense automates the evidence collection, control monitoring, and documentation work that makes NIST 800-171 compliance expensive, so organizations can demonstrate a defensible security posture without the overhead that has put full participation in the DIB out of reach for so many small businesses.
Learn how Secureframe Defense can help your team.
Get compliant. Stay secure.
FAQs
What is the CMMC Reform Task Force?
The CMMC Reform Task Force is a body established by the Department of War on July 13, 2026 to review the CMMC program and deliver recommendations for a reformed framework that is more scalable and accessible for small and mid-sized defense contractors. Its report is expected in late September or early October 2026.
Is CMMC Level 2 certification still required in 2026?
The C3PAO assessment requirement for CMMC Level 2 has been paused while the Reform Task Force conducts its review. The underlying cybersecurity obligations remain in effect: DFARS 252.204-7012 compliance, NIST SP 800-171 implementation, SPRS self-assessments, and cyber incident reporting are all still required.
What is the difference between Brilliant at the Basics and NIST 800-171?
NIST SP 800-171 is a prescriptive 110-control standard requiring documented evidence of implementation. Brilliant at the Basics is an outcomes-oriented campaign covering 10 prioritized technical practices with no assessment methodology or evidence standard. BatB overlaps with several 800-171 control families but doesn't address the governance and documentation controls that make 800-171 compliance costly to sustain.
Does Brilliant at the Basics replace CMMC?
No. Brilliant at the Basics is a cybersecurity campaign, not a compliance framework, and it doesn't replace CMMC or NIST 800-171. The DoW introduced it as a practical interim benchmark during the Task Force review period.
What is an SPRS score?
An SPRS score is a contractor's NIST 800-171 self-assessment score, submitted to the DoD's Supplier Performance Risk System. Scores range from -203 to 110, with 110 representing full compliance. Contracting officers review SPRS scores during source selection, and inaccurate scores carry False Claims Act exposure.

Emily Bonnie
Senior Content Marketing Manager
Emily Bonnie is a seasoned digital marketing strategist with over ten years of experience creating content that attracts, engages, and converts for leading SaaS companies. At Secureframe, she helps demystify complex governance, risk, and compliance (GRC) topics, turning technical frameworks and regulations into accessible, actionable guidance. Her work aims to empower organizations of all sizes to strengthen their security posture, streamline compliance, and build lasting trust with customers.