CMMC: The Security Theater We Need

Compliance is not security—but perhaps it can facilitate it.

Meme about CMMC and security theater
Security outcomes beat security optics.

The current state of Defense Industrial Base (DIB) cybersecurity is not great—and it’s not for lack of money. We routinely see billion-dollar organizations with enterprise-grade security tooling and a massive, invisible vulnerability that threatens the heart of the defense supply chain.

We call it security theater: the appearance of being secure without consistently locking the doors that matter.

Using risk data captured by our VikelaAI Research Tool and analyzing hundreds of DoD contractors with contracts expiring within the next 15 months, we found a pattern that should make any prime, subcontractor, and assessor pause: many organizations are “playing the part” of being secure without hardening the identity layer that attackers exploit every day.

The DMARC enforcement gap

Identity is the new perimeter, yet one of the most basic forms of identity protection—DMARC (Domain-based Message Authentication, Reporting, and Conformance)—is still being ignored by many companies entrusted with national security data.

Among contractors (or partners) approaching a compliance cliff:

71.8% Not enforced (missing DMARC enforcement or still in monitor mode).
28.2% Enforced (policy set to quarantine or reject spoofed emails).
DMARC enforcement status across analyzed contractors approaching a near-term renewal window.

This matters because p=none is observation, not protection. Attackers don’t care that you can see the problem after the fact—only that they can send convincing emails right now.

The “enclave” excuse vs. supply chain reality

Contractors often hide behind a “secure enclave” strategy: if Controlled Unclassified Information (CUI) is isolated, they argue that the corporate email domain’s security is secondary.

The technical hole: attackers don’t need to breach your enclave if they can successfully impersonate your identity to someone who trusts you. By spoofing a “legitimate” request for quote (RFQ) or a technical drawing update from a prime’s corporate domain, an attacker can trick the recipient into taking action that compromises your supply chain—through an adjacent, sibling vector.

In other words: the enclave might be well-defended, but the workflow around the enclave often isn’t.

The paradox: premium tools, weak policies

Perhaps the most damning evidence of security theater is the investment gap. Some organizations are spending millions on enterprise-grade email security and still leaving DMARC in “demo mode.”

The “tools without teeth” problem

Tools present (advanced/full stack, as labeled per row)
Not present / not full stack
Tooling maturity vs. DMARC policy strength (VikelaAI dataset).

This isn't a lack of investment. On the contrary, these contractors are using the "Gold Standard" of security tooling. Our data shows a heavy reliance on:

In this context, staying in "Monitor Mode" indefinitely is like having a Ferrari in the garage with the keys in the ignition and the door open. You are receiving the telemetry and seeing the "security cameras" of who is spoofing your domain, but the final step of "locking the door" remains.

Why the 15-month window matters

CMMC 2.0 is no longer a distant “maybe.” It is a “when.” For contractors with renewals coming up in the next year and a quarter, the enforcement of NIST SP 800-171 requirements will increasingly determine whether you win follow-on work or get screened out.

While there is no explicit “thou shall implement DMARC” requirement in the model, moving from p=none to p=reject is not a nice-to-have. It can be the difference between being a trusted node in the defense network and being a preventable risk.

Moving beyond the theater

The DoD is moving away from self-attestation because theater doesn’t protect. Resilience does.

Under CMMC, real C3PAOs will fail organizations that have not met the letter of the law. Observable gaps—like failing to verify and enforce security functions—can become indicators of audit failure, or serve as primary evidence tied to controls such as SI.L2-3.14.3 (verifying security functions).

It’s not just about having a policy statement. It’s about the audit trail that proves you are actually monitoring—and enforcing—your boundaries.