Former Pentagon CISO Katie Arrington proposed integrating artificial intelligence into the Cybersecurity Maturity Model Certification program and called for a dedicated Small Business Administration loan program for cybersecurity investment. Arrington, who served as DOD CISO/PTDO DOD CIO under the second Trump administration, outlined these measures in a podcast interview.
Arrington spearheaded the Pentagon’s initial efforts to create the Cybersecurity Maturity Model Certification program beginning in 2019. The CMMC is an assessment framework and assessor certification program designed to verify cybersecurity practices among defense contractors. She served as DOD CISO for Acquisition and Sustainment starting in 2019, a role that placed her at the center of these early development efforts.
"I built the Cybersecurity Maturity Model Certification because self-attestation was failing our war industrial base," Arrington said. "Nation-state actors and the ransomware crews they tolerate or direct are more aggressive, better funded, and faster than they were five years ago."
CMMC's requirements hinge on controlled unclassified information, which often appears in complex contract language. "Two subcontractors doing nearly identical work can end up with completely different assessments because the call still depends on manual judgment with incomplete visibility into how data actually flows down," she said. This inconsistency creates gaps in security posture across the industrial base.
Arrington proposed using technology to standardize this process. "AI can do the first-pass sorting here—flagging likely CUI from contract language and statements of work and catching mismatches between what a prime contract designates and what actually flows down to subcontractors — far more consistently than today's patchwork of manual reviews." Despite these technological additions, she maintained that the core regulatory standards must remain intact.
The Defense Federal Acquisition Regulation Supplement requirements behind CMMC should not change, and I would not support it if they did," she said. She argued that while the methods of verification could evolve, the underlying security requirements established by the Department of War should stay constant to ensure baseline protection."
Beyond defense contractors, Arrington emphasized the need for broader cybersecurity support. Small businesses are a major part of the American economy and employ nearly half the private workforce. As a former South Carolina state legislator, she noted the economic scale of these enterprises and their vulnerability to cyber threats.
"We need a dedicated SBA loan program for cybersecurity investment—open to every small business, not just those working with the Department of War—to fund things like multi-factor authentication rollouts, endpoint detection, incident response, and early migration toward quantum-resistant encryption, before it's an emergency instead of a plan." She noted that existing initiatives have shown promise, stating that the SBA's Cybersecurity for Small Business Pilot Program has done real work funding training through state partners.
Why It Matters
The proposals address two distinct but connected vulnerabilities in the national cybersecurity infrastructure: inconsistent verification of defense contractors and underfunded security postures among small businesses. By integrating AI into the CMMC process, the aim is to reduce human error and increase the consistency of identifying controlled unclassified information across complex supply chains. This shift responds to the increased aggression and funding of nation-state actors and ransomware crews.
The call for a dedicated SBA loan program expands the scope of federal cybersecurity support beyond the defense industrial base. With small businesses comprising a major part of the American economy and employing nearly half the private workforce, their security failures can have widespread economic consequences. The proposed loans would allow these entities to proactively invest in multi-factor authentication, endpoint detection, and quantum-resistant encryption rather than reacting after a breach occurs.
Timeline
Katie Arrington spearheaded the Pentagon’s initial efforts to create the Cybersecurity Maturity Model Certification program beginning in 2019. She also served as DOD CISO for Acquisition and Sustainment starting in 2019. On a recent date, Arrington stated, "I built the Cybersecurity Maturity Model Certification because self-attestation was failing our war industrial base." On that same date, she noted that "CMMC's requirements hinge on controlled unclassified information." Also on that date, she said, Small businesses are a major part of the American economy and employ nearly half the private workforce. She added on that date that "The Defense Federal Acquisition Regulation Supplement requirements behind CMMC should not change, and I would not support it if they did." She further stated on that date that "Nation-state actors and the ransomware crews they tolerate or direct are more aggressive, better funded, and faster than they were five years ago." Finally, on that date, Arrington remarked that "Its Cybersecurity for Small Business Pilot Program has done real work funding training through state partners."
forum Comments (0)
No comments yet. Be the first to comment.