When the Department of War's (DoW) CIO Kirstin A. Davies announced the immediate suspension of CMMC Phase 2, the department also began their "Brilliant at the Basics (BatB)" campaign. Brilliant at the Basics is being promoted as a practical and foundational set of cybersecurity practices intended to help small-medium sized business "rapidly secure their networks and protect sensitive DoW information" while also "stripping away administrative complexity and compliance overhead". BatB promotes two "Top 10 best-practice" lists for both IT and OT environments. This blog will explain what the Brilliant at the Basics campaign is, how it works, and its relation to existing frameworks such as NIST 800-171 SP Rev. 2 and Rev. 3.
The BatB campaign was launched alongside the suspension/review of CMMC Phase 2. The stated objective is to give small-medium sized and nontraditional businesses practical cybersecurity guidance they can understand and implement while reducing administrative complexity and compliance overhead. BatB is more focused on operational cybersecurity outcomes and foundational practices organizations should have operating effectively within their environments. The campaign introduces two tracks: IT Top 10 and OT Top 10. These tracks provide 10 foundational or "basic" cybersecurity practices contractors can implement to better secure sensitive information.
BatB is not a new rule or compliance obligation. There is no third-party audit or even self-attestation to submit to the DoW proving that an organization has implemented all 10 practices. BatB is guidance and recommendations on how contractors can better secure their IT and OT environments utilizing best practices. It also does not replace existing contractual or regulatory cybersecurity requirements (specifically CMMC or NIST 800-171). Contractors must still understand and meet the requirements applicable to their organization and the information they handle.
The IT Top 10:
The OT Top 10:
No. BatB should not be treated as a replacement for CMMC, NIST SP 800-171, or any existing contractual cybersecurity obligations. The CMMC model is an assessment/certification mechanism intended to affirm contractors' implementation of NIST SP 800-171 requirements. When applicable through DoW contracting requirements, CMMC assessment status can affect an organization's eligibility for covered contract awards. BatB does not carry the same contractual or assessment requirements. BatB is currently presented by the DoW as a cybersecurity set of best practices with the DoW's own page clarifying that these security practices need to be tailored to an organization's individual technical, operational, and regulatory requirements.
BatB and NIST SP 800-171 do not align on a one-to-one, practice-to-control basis. BatB is not intended to address all 110 NIST SP 800-171 Rev. 2 requirements; instead, its recommended practices reinforce many of the same cybersecurity objectives while, in some areas, introducing recommendations that extend beyond specific NIST requirements.
The examples below illustrate general areas of alignment rather than a formal mapping between BatB practices and NIST SP 800-171 requirements.
| BatB Priority | Related NIST 800-171 Area |
| Phishing-resistant MFA | Identification & Authentication / Access Control |
| Asset Inventory | Configuration Management / System & Information Integrity |
| Network Segmentation | Access Control / System & Communications Protection |
| Vulnerability Management | Risk Assessment / System & Information Integrity |
| Backup & Recovery | Broader operational resilience; may extend beyond specific Rev. 2 requirements |
| Workforce Readiness | Awareness & Training |
| Continuous Monitoring | System & Information Integrity / Risk Assessment |
BatB reinforces many of the cybersecurity outcomes contractors should already be working toward, while in some areas recommending technologies or practices that may go beyond the minimum implementation needed for a particular NIST requirement. However, alignment does not mean equivalency. Implementing a BatB practice does not necessarily satisfy a corresponding NIST requirement, nor does implementing NIST SP 800-171 necessarily address every BatB recommendation.
Contractors should remember that BatB is not a new requirement or certification to achieve. It is a set of recommendations organizations can consider implementing. Rather than launching a separate "BatB compliance project", contractors should view this as a security maturity exercise. If Brilliant at the Basics appeals to your organization, here are several suggestions for how to move forward:
BatB doesn't mean starting over. It reinforces the importance of doing the cybersecurity fundamentals well and maintaining them over time. For organizations already implementing NIST SP 800-171 and preparing for CMMC, BatB provides another perspective for evaluating whether their cybersecurity controls are not only documented, but operationally effective.
CorpInfoTech is a CMMC L2 certified MSP that helps contractors achieve and maintain CMMC compliance. Through our managed service offering, we provide contractors with a practical approach to meeting and maintaining their cybersecurity and compliance obligations. CorpInfoTech helps organizations navigate that process through our Define – Assess – Implement – Validate – Maintain roadmap.
CorpInfoTech supports both the strategy and execution behind this roadmap. Our goal is not simply to get you through a CMMC assessment, but to help you build and maintain a secure, compliant environment that supports your defense contracts today and prepares you for whatever comes next.
BatB does not replace CMMC, NIST SP 800-171, or existing contractual cybersecurity obligations.
BatB is guidance, not a new compliance requirement. There is currently no BatB assessment, certification, or self-attestation.
BatB and NIST SP 800-171 align in several cybersecurity areas, but they are not equivalent and do not map one-to-one.
Contractors should not abandon existing CMMC/NIST SP 800-171 efforts. BatB can be used as another lens for evaluating and strengthening their cybersecurity environment.
CorpInfoTech, a Managed Service Provider (MSP) with over 25 years in the SMB space, is a trusted partner for business pursuing compliance and cybersecurity. We are a CMMC Level 2 certified MSP and a Cyber AB Registered Provider Organization (RPO). Also, as the first CIS accredited organization, we help organizations implement the CIS controls as it pertains to CMMC and your overall cybersecurity posture. CorpInfoTech is your trusted partner for secure, compliant growth in every changing digital landscape.