CMMC: The Security Theater We Need
Compliance is not security—but perhaps it can facilitate it.
The current state of Defense Industrial Base (DIB) cybersecurity is not great—and it’s not for lack of money. We routinely see billion-dollar organizations with enterprise-grade security tooling and a massive, invisible vulnerability that threatens the heart of the defense supply chain.
We call it security theater: the appearance of being secure without consistently locking the doors that matter.
Using risk data captured by our VikelaAI Research Tool and analyzing hundreds of DoD contractors with contracts expiring within the next 15 months, we found a pattern that should make any prime, subcontractor, and assessor pause: many organizations are “playing the part” of being secure without hardening the identity layer that attackers exploit every day.
The DMARC enforcement gap
Identity is the new perimeter, yet one of the most basic forms of identity protection—DMARC (Domain-based Message Authentication, Reporting, and Conformance)—is still being ignored by many companies entrusted with national security data.
Among contractors (or partners) approaching a compliance cliff:
- 71.8% of analyzed contractors do not have DMARC enforced.
- Only 28.2% have moved beyond “monitor mode” (
p=none) to a policy that actually quarantines or rejects spoofed emails.
This matters because p=none is observation, not protection. Attackers don’t care that you can see the problem after the fact—only that they can send convincing emails right now.
The “enclave” excuse vs. supply chain reality
Contractors often hide behind a “secure enclave” strategy: if Controlled Unclassified Information (CUI) is isolated, they argue that the corporate email domain’s security is secondary.
The technical hole: attackers don’t need to breach your enclave if they can successfully impersonate your identity to someone who trusts you. By spoofing a “legitimate” request for quote (RFQ) or a technical drawing update from a prime’s corporate domain, an attacker can trick the recipient into taking action that compromises your supply chain—through an adjacent, sibling vector.
In other words: the enclave might be well-defended, but the workflow around the enclave often isn’t.
The paradox: premium tools, weak policies
Perhaps the most damning evidence of security theater is the investment gap. Some organizations are spending millions on enterprise-grade email security and still leaving DMARC in “demo mode.”
The “tools without teeth” problem
- 26.8% of companies with a weak or missing DMARC policy already have advanced security tools in place (e.g., Proofpoint, Mimecast, or Microsoft 365 G5).
- In contrast, companies with strong DMARC policies are significantly more mature, with 64.8% utilizing a full stack of security tools.
This isn't a lack of investment. On the contrary, these contractors are using the "Gold Standard" of security tooling. Our data shows a heavy reliance on:
- Enterprise Gateways: Industry-leading email security proxies.
- Cloud-Native Titans: High-tier Microsoft 365 and Google Workspace environments.
- Specialized Protection: Advanced threat defense layers.
In this context, staying in "Monitor Mode" indefinitely is like having a Ferrari in the garage with the keys in the ignition and the door open. You are receiving the telemetry and seeing the "security cameras" of who is spoofing your domain, but the final step of "locking the door" remains.
Why the 15-month window matters
CMMC 2.0 is no longer a distant “maybe.” It is a “when.” For contractors with renewals coming up in the next year and a quarter, the enforcement of NIST SP 800-171 requirements will increasingly determine whether you win follow-on work or get screened out.
While there is no explicit “thou shall implement DMARC” requirement in the model, moving from p=none to p=reject is not a nice-to-have. It can be the difference between being a trusted node in the defense network and being a preventable risk.
Moving beyond the theater
The DoD is moving away from self-attestation because theater doesn’t protect. Resilience does.
Under CMMC, real C3PAOs will fail organizations that have not met the letter of the law. Observable gaps—like failing to verify and enforce security functions—can become indicators of audit failure, or serve as primary evidence tied to controls such as SI.L2-3.14.3 (verifying security functions).
It’s not just about having a policy statement. It’s about the audit trail that proves you are actually monitoring—and enforcing—your boundaries.