What is "Brilliant at the Basics"? How Does This Impact Defense Contractors?

When the Department of War's (DoW) CIO Kirstin A. Davies announced the immediate suspension of CMMC Phase 2, the department also began their "Brilliant at the Basics (BatB)" campaign. Brilliant at the Basics is being promoted as a practical and foundational set of cybersecurity practices intended to help small-medium sized business "rapidly secure their networks and protect sensitive DoW information" while also "stripping away administrative complexity and compliance overhead". BatB promotes two "Top 10 best-practice" lists for both IT and OT environments. This blog will explain what the Brilliant at the Basics campaign is, how it works, and its relation to existing frameworks such as NIST 800-171 SP Rev. 2 and Rev. 3.

What is Brilliant at the Basics?

The BatB campaign was launched alongside the suspension/review of CMMC Phase 2. The stated objective is to give small-medium sized and nontraditional businesses practical cybersecurity guidance they can understand and implement while reducing administrative complexity and compliance overhead. BatB is more focused on operational cybersecurity outcomes and foundational practices organizations should have operating effectively within their environments. The campaign introduces two tracks: IT Top 10 and OT Top 10. These tracks provide 10 foundational or "basic" cybersecurity practices contractors can implement to better secure sensitive information.

What Brilliant at the Basics is Not...

BatB is not a new rule or compliance obligation. There is no third-party audit or even self-attestation to submit to the DoW proving that an organization has implemented all 10 practices. BatB is guidance and recommendations on how contractors can better secure their IT and OT environments utilizing best practices. It also does not replace existing contractual or regulatory cybersecurity requirements (specifically CMMC or NIST 800-171). Contractors must still understand and meet the requirements applicable to their organization and the information they handle.

What Are the Brilliant at the Basics Top 10?

The IT Top 10:

  1. Phishing-Resistant MFA: Move away from legacy MFA methods such as SMS text messages or push notifications. 
  2. Comprehensive Asset Inventory Management: Maintain a dynamically updated inventory of enterprise assets.
  3. Strategic Technical Debt Reduction: Identify, modernize, consolidate, or retire unused legacy infrastructure.
  4. Flexible Technology Stack: Maintain a flexible, interoperable stack that supports modular integration of best-in-class commercial technologies. 
  5. Logical Segmentation to Limit Adversary Lateral Movement: Implement software-defined segmentation to divide your environment into secure, isolated logical zones. 
  6. Risk-Based Vulnerability Management: Establish a continuous, risk-based vulnerability management program driven by operational context and impact rather than generic severity scores. 
  7. Integrate Security Early in the Development Lifecycle: Integrate secure coding standards and automated vulnerability scanning directly into the earliest phases of your engineering lifecycle. 
  8. Secure AI Adoption and Data Protection: Establish clear policies and technical guardrails governing the use of artificial intelligence and automation tools across your workforce. 
  9. Resilient Backup and Disaster Recovery Architecture: Protect critical data from adversarial destruction and ransomware by establishing a secure, immutable backup architecture. 
  10. Continuous Technical Workforce Readiness: Continuously develop your technical and security personnel on modern enterprise architecture, data protection, and defensive security operations.

The OT Top 10:

  1. Identity and Access Control: Manage who has access to your OT by enforcing strict identity and access control.  
  2. Validated Asset Inventory: Create and maintain a rigorous, "as-operated" inventory of all physical and logical components within your OT environment. 
  3. Strict Network Segmentation: A key architectural step is to logically separate your business IT network from your critical operational systems. 
  4. OT-Specific Incident Response and Recovery Plan: A well-rehearsed, OT-specific Incident Response Plan (IRP) is critical for safeguarding mission assurance and maintaining operational resilience against cyber-physical disruptions.  
  5. Manage Known Vulnerabilities: To protect critical infrastructure, prioritize compensating controls when you cannot immediately patch operational equipment.  
  6. Remote Access Pathways: Grant remote access to your OT only when needed, for the shortest time possible, and with strong authentication.  
  7. Continuous Monitoring: Extend basic monitoring to the production floor to detect unusual traffic or unauthorized access to machinery. 
  8. System Resiliency: Build your systems to be resilient from the start by mandating secure, composable architecture. 
  9. Supply Chain Security: This is accomplished through things like proactive procurement, lifecycle management, and supply chain illumination. 
  10. Review Processes: Before making any significant changes to your systems, including security updates, it's crucial to have a formal review process.
Review the IT/OT Top 10 in detail 

Is Brilliant at the Basics Replacing CMMC or NIST SP 800-171?

No. BatB should not be treated as a replacement for CMMC, NIST SP 800-171, or any existing contractual cybersecurity obligations. The CMMC model is an assessment/certification mechanism intended to affirm contractors' implementation of NIST SP 800-171 requirements. When applicable through DoW contracting requirements, CMMC assessment status can affect an organization's eligibility for covered contract awards. BatB does not carry the same contractual or assessment requirements. BatB is currently presented by the DoW as a cybersecurity set of best practices with the DoW's own page clarifying that these security practices need to be tailored to an organization's individual technical, operational, and regulatory requirements.

Where do BatB and NIST SP 800-171 Overlap?

BatB and NIST SP 800-171 do not align on a one-to-one, practice-to-control basis. BatB is not intended to address all 110 NIST SP 800-171 Rev. 2 requirements; instead, its recommended practices reinforce many of the same cybersecurity objectives while, in some areas, introducing recommendations that extend beyond specific NIST requirements.

The examples below illustrate general areas of alignment rather than a formal mapping between BatB practices and NIST SP 800-171 requirements. 

BatB Priority Related NIST 800-171 Area
Phishing-resistant MFA Identification & Authentication / Access Control
Asset Inventory Configuration Management / System & Information Integrity
Network Segmentation Access Control / System & Communications Protection
Vulnerability Management Risk Assessment / System & Information Integrity
Backup & Recovery Broader operational resilience; may extend beyond specific Rev. 2 requirements
Workforce Readiness Awareness & Training
Continuous Monitoring System & Information Integrity / Risk Assessment

BatB reinforces many of the cybersecurity outcomes contractors should already be working toward, while in some areas recommending technologies or practices that may go beyond the minimum implementation needed for a particular NIST requirement. However, alignment does not mean equivalency. Implementing a BatB practice does not necessarily satisfy a corresponding NIST requirement, nor does implementing NIST SP 800-171 necessarily address every BatB recommendation. 

How Should Contractors Respond to Brilliant at the Basics?

Contractors should remember that BatB is not a new requirement or certification to achieve. It is a set of recommendations organizations can consider implementing. Rather than launching a separate "BatB compliance project", contractors should view this as a security maturity exercise. If Brilliant at the Basics appeals to your organization, here are several suggestions for how to move forward:

  1. Don't abandon your existing CMMC/NIST work: As previously mentioned, BatB does not replace prior regulatory obligations. You should continue to implement the necessary requirements outlined in NIST SP 800-171.
  2. Compare BatB against your current environment: Determine which practices are already implemented, partially implemented, or missing.
  3. Identify overlap with your existing compliance roadmap: Avoid creating two separate cybersecurity programs where the same investment can support both.
  4. Treat cybersecurity as an ongoing operating model: Policies, inventories, configurations, monitoring and controls need to remain effective after an assessment. 

BatB doesn't mean starting over. It reinforces the importance of doing the cybersecurity fundamentals well and maintaining them over time.  For organizations already implementing NIST SP 800-171 and preparing for CMMC, BatB provides another perspective for evaluating whether their cybersecurity controls are not only documented, but operationally effective.

How CorpInfoTech Helps Contractors Maintain Meaningful Cybersecurity and Compliance Practices

CorpInfoTech is a CMMC L2 certified MSP that helps contractors achieve and maintain CMMC compliance. Through our managed service offering, we provide contractors with a practical approach to meeting and maintaining their cybersecurity and compliance obligations.  CorpInfoTech helps organizations navigate that process through our Define – Assess – Implement – Validate – Maintain roadmap.

  • Define – Understand your requirements, CUI environment, scope, and compliance objectives.
  • Assess – Evaluate your current environment against applicable NIST SP 800-171 and CMMC requirements and identify gaps.
  • Implement – Remediate gaps and put the necessary security controls, technology, policies, and processes in place.
  • Validate – Confirm controls are operating as intended and prepare the organization and supporting evidence for assessment.
  • Maintain – Continuously manage, monitor, and improve the environment to support ongoing compliance.

CorpInfoTech supports both the strategy and execution behind this roadmap. Our goal is not simply to get you through a CMMC assessment, but to help you build and maintain a secure, compliant environment that supports your defense contracts today and prepares you for whatever comes next.

Key Takeaways

  •  BatB does not replace CMMC, NIST SP 800-171, or existing contractual cybersecurity obligations.

  •  BatB is guidance, not a new compliance requirement. There is currently no BatB assessment, certification, or self-attestation.

  •  BatB and NIST SP 800-171 align in several cybersecurity areas, but they are not equivalent and do not map one-to-one.

  • Contractors should not abandon existing CMMC/NIST SP 800-171 efforts. BatB can be used as another lens for evaluating and strengthening their cybersecurity environment. 

CorpInfoTech_Logo_noC3PAO

 CorpInfoTech, a Managed Service Provider (MSP) with over 25 years in the SMB space, is a trusted partner for business pursuing compliance and cybersecurity. We are a CMMC Level 2 certified MSP and a Cyber AB Registered Provider Organization (RPO). Also, as the first CIS accredited organization, we help organizations implement the CIS controls as it pertains to CMMC and your overall cybersecurity posture. CorpInfoTech is your trusted partner for secure, compliant growth in every changing digital landscape.  

It's Time to Achieve CMMC Compliance and Strengthen Your Security

Take control of your security and CMMC compliance. Connect with CorpInfoTech now for expert advice and a clear remediation roadmap.