---
title: "CMMC Insiders Say the Quiet Part Out Loud: Passing Doesn't Mean Protected"
description: Organizations are achieving CMMC Level 2 compliance while remaining fundamentally insecure. And it's happening for five specific, fixable reasons.
image: https://www.virtru.com/hubfs/assets/temporary%20(use%20this%20for%20uploading%20unoptimized%20images,%20videos,%20etc)/blog%20-%20DCMMC%202026%20Recaps/dcmmc-panel-recap.png
---

[Skip to Main Content](https://www.virtru.com/blog/compliance/cmmc-insiders-say-the-quiet-part-out-loud-passing-doesnt-mean-protected#main-content)

[Sign In](https://secure.virtru.com/dashboard) [I received a Virtru email](https://www.virtru.com/data-protection-platform/email-encryption/send)

[![Virtru](https://www.virtru.com/hubfs/assets/images/logos/virtru/blue/virtru_LOGOMASTER_BLUE.svg) ](https://www.virtru.com/)

- Products
- Solutions
- Developers
- Company
- Resources
- [Support](https://support.virtru.com)
- [Pricing](https://www.virtru.com/data-security-platform/pricing-packages)
- Book a Demo
- Search all Virtru content
  
  ![](https://www.virtru.com/hubfs/assets/images/icons/link-arrow-black.svg)

Email Workflows

Protect data shared via email

- [Virtru for Gmail 
  
  ](https://www.virtru.com/data-security-platform/email-encryption/gmail)
- [Virtru for Outlook 
  
  ](https://www.virtru.com/data-security-platform/email-encryption/outlook)
- [Virtru Gateway 
  
  ](https://www.virtru.com/data-security-platform/virtru-data-gateway)
- [Email Integrations 
  
  ](https://www.virtru.com/products/integrations?product=data_protection_gateway&category=email)

File Workflows

Protect files shared across your workflows

- [Virtru Secure Share 
  
  ](https://www.virtru.com/data-security-platform/virtru-secure-share)
- [Virtru for Desktop 
  
  ](https://www.virtru.com/data-security-platform/desktop)
- [File Integrations 
  
  ](https://www.virtru.com/products/integrations?category=file_sharing)

Collaboration Workflows

FedRAMP authorized file storage and collaboration

- [Virtru Collaborate 
  
  ](https://www.virtru.com/data-security-platform/virtru-collaborate)

Manage Private Encryption Keys

Maintain complete sovereignty and governance

- [Virtru Private Keystore 
  
  ](https://www.virtru.com/data-security-platform/virtru-private-keystore)
- [Google Client Side Encryption (CSE) 
  
  ](https://www.virtru.com/data-security-platform/google-workspace-client-side-encryption)

Develop Data Security Solutions

Data-centric security, built on open standards

- [Virtru Data Security Platform 
  
  ](https://www.virtru.com/data-security-platform)
- [Developer Experience 
  
  ](https://www.virtru.com/data-security-platform/developer-experience)
- [Platform Integrations 
  
  ](https://www.virtru.com/partners/technology)

6,100+ Customers Trust Virtru for Data Security and Privacy Protection

![Omada Logo](https://www.virtru.com/hubfs/assets/images/logos/customers/omada-logo.webp) ![UC Berkley Logo](https://www.virtru.com/hubfs/assets/images/logos/customers/ucberkley-logo.webp) ![Associated Press Logo](https://www.virtru.com/hubfs/assets/images/logos/customers/associatedpress-logo.webp) ![US Department of Defense Logo](https://www.virtru.com/hubfs/assets/images/logos/customers/dod-logo.webp)

- Compliance
  
    - [CJIS 
      
      ](https://www.virtru.com/compliance/cjis)
    - [CMMC / NIST / DFARS 
      
      ](https://www.virtru.com/compliance/cmmc)
    - [FERPA 
      
      ](https://www.virtru.com/compliance/ferpa)
    - [FTC Safeguards Rule 
      
      ](https://www.virtru.com/compliance/data-encryption-ftc-safeguards-rule)
    - [GDPR 
      
      ](https://www.virtru.com/compliance/gdpr)
    - [HIPAA 
      
      ](https://www.virtru.com/compliance/hipaa-email)
    - [ISO 27001 
      
      ](https://www.virtru.com/compliance/iso-27001)
    - [ITAR 
      
      ](https://www.virtru.com/compliance/itar)
    - [PCI / GLBA / FINRA / SOX 
      
      ](https://www.virtru.com/compliance/financial)
- Commercial
  
    - [Aerospace 
      
      ](https://www.virtru.com/industry-solutions/aerospace-and-defense/)
    - [Education 
      
      ](https://www.virtru.com/industry-solutions/education/)
    - [Finance 
      
      ](https://www.virtru.com/industry-solutions/financial-services/)
    - [Healthcare 
      
      ](https://www.virtru.com/industry-solutions/healthcare/)
    - [Legal 
      
      ](https://www.virtru.com/industry-solutions/legal)
    - [Technology & Telecom 
      
      ](https://www.virtru.com/industry-solutions/telecom-it-and-software)
    - [Threat Intelligence 
      
      ](https://www.virtru.com/industry-solutions/threat-intelligence)
- Global Public Sector
  
    - [Federal - Defense 
      
      ](https://www.virtru.com/global-public-sector/defense)
    - [Federal - Intelligence 
      
      ](https://www.virtru.com/global-public-sector/intelligence)
    - [State & Local Government 
      
      ](https://www.virtru.com/industry-solutions/state-local-government)
    - [Systems Integrators 
      
      ](https://www.virtru.com/global-public-sector/systems-integrators)
    - [Mission Partner Environments 
      
      ](https://www.virtru.com/industry-solutions/mission-partner-environments)

[View All Solutions](https://www.virtru.com/compliance)

[![Three rings forming three overlaps in a triangle formation](https://www.virtru.com/hubfs/assets/images/icons/rings-navicon.svg)

Virtru for Global Mission Partners

Data-centric security aligned with ACP-240 and TDF

Learn More ](https://www.virtru.com/industry-solutions/mission-partner-environments) [![Microsoft Icon](https://www.virtru.com/hubfs/assets/images/icons/microsoft-navicon.svg)

Virtru for Microsoft 365

Protect data stored and shared via Microsoft 365

Learn More ](https://www.virtru.com/data-security-platform/microsoft-365) [![Google Icon](https://www.virtru.com/hubfs/assets/images/icons/google-navicon.svg)

Virtru for Google Workspace

Protect data stored and shared via Google Workspace

Learn More ](https://www.virtru.com/data-security-platform/google-workspace)

- Developers
  
    - [Virtru Data Security Platform The Security Standard that Powers Our Products 
      
      ](https://www.virtru.com/data-security-platform)
    - [Trusted Data Format Secure Collaboration and Policy Enforcement 
      
      ](https://www.virtru.com/data-security-platform/trusted-data-format)
    - [Virtru Developer Experience Build Secure Solutions from the Ground Up 
      
      ](https://www.virtru.com/data-security-platform/developer-experience)
- Developer Community
  
    - [OpenTDF: Open Source Project Open Standard Now Available on GitHub 
      
      ](https://opentdf.io/)
    - [Technology Partners Building integrations with the Virtru Platform 
      
      ](https://www.virtru.com/partners/technology)
    - [Partner Training Bootcamp Request training on the Virtru Data Security Platform 
      
      ](https://www.virtru.com/data-security-platform/training-request)

![Looking over the shoulder of somebody on their smart phone. ](https://www.virtru.com/hubfs/assets/images/stock%20photos/People%20On%20Device/person-on-phone.webp)

A trusted platform for secure data sharing

Built on the open TDF standard, the Virtru Data Security Platform provides persistent control over the information you share with others.

[Virtru Data Security Platform](https://www.virtru.com/data-security-platform)

- About Virtru
  
    - [About Us 
      
      ](https://www.virtru.com/about-us)
    - [Leadership 
      
      ](https://www.virtru.com/leadership/)
    - [Careers & Culture 
      
      ](https://www.virtru.com/careers)
    - [Contact Us 
      
      ](https://www.virtru.com/contact-us)
- In the News
  
    - [Headlines & Press Releases 
      
      ](https://www.virtru.com/newsroom)
    - [Decrypted Blog 
      
      ](https://www.virtru.com/blog)
    - [Hash It Out Podcast 
      
      ](https://www.virtru.com/hash-it-out)

Award-winning security solutions for every organization

![Cyber Security Breakthrough Award Logo for 2023](https://www.virtru.com/hubfs/assets/images/logos/award%20badges/cybersecurity-breakthrough-award-badge-2023.webp) ![Virtru wins a G2 Top 50 Security Products Award for 2024](https://www.virtru.com/hubfs/assets/images/logos/award%20badges/G2-Leader-2025.webp) ![Washington Post Top Work Places 2023 Award](https://www.virtru.com/hubfs/assets/images/logos/award%20badges/twp-washington-2023.webp) ![Inc Power Partner 2024](https://www.virtru.com/hubfs/assets/images/logos/award%20badges/IncPowerPartner-2024.webp) 

[Read Customer Reviews](https://www.virtru.com/why-virtru/reviews)

- Resources
  
    - [Decrypted Blog Tips, Takes, and Expertise 
      
      ](https://www.virtru.com/blog)
    - [Hash It Out Podcast Join us as we talk about cybersecurity 
      
      ](https://www.virtru.com/hash-it-out)
    - [Voice of the Customer Case Studies, Webinars, and Videos 
      
      ](https://www.virtru.com/resources?type=webinar,case-study)
    - [Events & Webinars Upcoming Events, Conferences, and Digital Webinars 
      
      ](https://www.virtru.com/events-and-webinars/)
    - [Resource Library Whitepapers, Guides, and Videos 
      
      ](https://www.virtru.com/resources)
    - [DMV Rising Our annual event bringing together the cyber community in the DMV 
      
      ](https://dmvrising.com/)
    - [Headlines & Press Virtru in the News 
      
      ](https://www.virtru.com/newsroom)
    - [Product Updates The latest on new products, features, and fixes 
      
      ](https://www.virtru.com/products/updates)
    - [Virtru Academy Live Helpful how-to content for admins and end users 
      
      ](https://www.virtru.com/virtru-academy-live)

![Professional on a laptop](https://www.virtru.com/hubfs/assets/images/stock%20photos/business/Business-3.webp)

![Wealthforge Logo](https://www.virtru.com/hubfs/assets/images/logos/customers/Wealthforge%20Logo.webp)

100% Increase in delivery rate for a broker-dealer working to comply with SEC regulations.

[Read the Case Study](https://www.virtru.com/case-studies/wealthforge-sec-compliance-gateway)

- Products 
  
    - Email Workflows
      
      Protect data shared via email
      
          - [Virtru for Gmail 
            
            ](https://www.virtru.com/data-security-platform/email-encryption/gmail)
          - [Virtru for Outlook 
            
            ](https://www.virtru.com/data-security-platform/email-encryption/outlook)
          - [Virtru Gateway 
            
            ](https://www.virtru.com/data-security-platform/virtru-data-gateway)
          - [Email Integrations 
            
            ](https://www.virtru.com/products/integrations?product=data_protection_gateway&category=email)
    - File Workflows
      
      Protect files shared across your workflows
      
          - [Virtru Secure Share 
            
            ](https://www.virtru.com/data-security-platform/virtru-secure-share)
          - [Virtru for Desktop 
            
            ](https://www.virtru.com/data-security-platform/desktop)
          - [File Integrations 
            
            ](https://www.virtru.com/products/integrations?category=file_sharing)
    - Collaboration Workflows
      
      FedRAMP authorized file storage and collaboration
      
          - [Virtru Collaborate 
            
            ](https://www.virtru.com/data-security-platform/virtru-collaborate)
    - Manage Private Encryption Keys
      
      Maintain complete sovereignty and governance
      
          - [Virtru Private Keystore 
            
            ](https://www.virtru.com/data-security-platform/virtru-private-keystore)
          - [Google Client Side Encryption (CSE) 
            
            ](https://www.virtru.com/data-security-platform/google-workspace-client-side-encryption)
    - Develop Data Security Solutions
      
      Data-centric security, built on open standards
      
          - [Virtru Data Security Platform 
            
            ](https://www.virtru.com/data-security-platform)
          - [Developer Experience 
            
            ](https://www.virtru.com/data-security-platform/developer-experience)
          - [Platform Integrations 
            
            ](https://www.virtru.com/partners/technology)
- Solutions 
  
    - Compliance
      
          - [CJIS 
            
            ](https://www.virtru.com/compliance/cjis)
          - [CMMC / NIST / DFARS 
            
            ](https://www.virtru.com/compliance/cmmc)
          - [FERPA 
            
            ](https://www.virtru.com/compliance/ferpa)
          - [FTC Safeguards Rule 
            
            ](https://www.virtru.com/compliance/data-encryption-ftc-safeguards-rule)
          - [GDPR 
            
            ](https://www.virtru.com/compliance/gdpr)
          - [HIPAA 
            
            ](https://www.virtru.com/compliance/hipaa-email)
          - [ISO 27001 
            
            ](https://www.virtru.com/compliance/iso-27001)
          - [ITAR 
            
            ](https://www.virtru.com/compliance/itar)
          - [PCI / GLBA / FINRA / SOX 
            
            ](https://www.virtru.com/compliance/financial)
    - Commercial
      
          - [Aerospace 
            
            ](https://www.virtru.com/industry-solutions/aerospace-and-defense/)
          - [Education 
            
            ](https://www.virtru.com/industry-solutions/education/)
          - [Finance 
            
            ](https://www.virtru.com/industry-solutions/financial-services/)
          - [Healthcare 
            
            ](https://www.virtru.com/industry-solutions/healthcare/)
          - [Legal 
            
            ](https://www.virtru.com/industry-solutions/legal)
          - [Technology & Telecom 
            
            ](https://www.virtru.com/industry-solutions/telecom-it-and-software)
          - [Threat Intelligence 
            
            ](https://www.virtru.com/industry-solutions/threat-intelligence)
    - Global Public Sector
      
          - [Federal - Defense 
            
            ](https://www.virtru.com/global-public-sector/defense)
          - [Federal - Intelligence 
            
            ](https://www.virtru.com/global-public-sector/intelligence)
          - [State & Local Government 
            
            ](https://www.virtru.com/industry-solutions/state-local-government)
          - [Systems Integrators 
            
            ](https://www.virtru.com/global-public-sector/systems-integrators)
          - [Mission Partner Environments 
            
            ](https://www.virtru.com/industry-solutions/mission-partner-environments)
- Developers 
  
    - Developers
      
          - [Virtru Data Security Platform The Security Standard that Powers Our Products 
            
            ](https://www.virtru.com/data-security-platform)
          - [Trusted Data Format Secure Collaboration and Policy Enforcement 
            
            ](https://www.virtru.com/data-security-platform/trusted-data-format)
          - [Virtru Developer Experience Build Secure Solutions from the Ground Up 
            
            ](https://www.virtru.com/data-security-platform/developer-experience)
    - Developer Community
      
          - [OpenTDF: Open Source Project Open Standard Now Available on GitHub 
            
            ](https://opentdf.io/)
          - [Technology Partners Building integrations with the Virtru Platform 
            
            ](https://www.virtru.com/partners/technology)
          - [Partner Training Bootcamp Request training on the Virtru Data Security Platform 
            
            ](https://www.virtru.com/data-security-platform/training-request)
- Company 
  
    - About Virtru
      
          - [About Us 
            
            ](https://www.virtru.com/about-us)
          - [Leadership 
            
            ](https://www.virtru.com/leadership/)
          - [Careers & Culture 
            
            ](https://www.virtru.com/careers)
          - [Contact Us 
            
            ](https://www.virtru.com/contact-us)
    - In the News
      
          - [Headlines & Press Releases 
            
            ](https://www.virtru.com/newsroom)
          - [Decrypted Blog 
            
            ](https://www.virtru.com/blog)
          - [Hash It Out Podcast 
            
            ](https://www.virtru.com/hash-it-out)
- Resources 
  
    - Resources
      
          - [Decrypted Blog Tips, Takes, and Expertise 
            
            ](https://www.virtru.com/blog)
          - [Hash It Out Podcast Join us as we talk about cybersecurity 
            
            ](https://www.virtru.com/hash-it-out)
          - [Voice of the Customer Case Studies, Webinars, and Videos 
            
            ](https://www.virtru.com/resources?type=webinar,case-study)
          - [Events & Webinars Upcoming Events, Conferences, and Digital Webinars 
            
            ](https://www.virtru.com/events-and-webinars/)
          - [Resource Library Whitepapers, Guides, and Videos 
            
            ](https://www.virtru.com/resources)
          - [DMV Rising Our annual event bringing together the cyber community in the DMV 
            
            ](https://dmvrising.com/)
          - [Headlines & Press Virtru in the News 
            
            ](https://www.virtru.com/newsroom)
          - [Product Updates The latest on new products, features, and fixes 
            
            ](https://www.virtru.com/products/updates)
          - [Virtru Academy Live Helpful how-to content for admins and end users 
            
            ](https://www.virtru.com/virtru-academy-live)
- [Support](https://support.virtru.com)
- [Pricing](https://www.virtru.com/data-security-platform/pricing-packages)
- Book a Demo
- Search all Virtru content
  
  ![](https://www.virtru.com/hubfs/assets/images/icons/link-arrow-black.svg)

Public Sector. CMMC/NIST/DFARS

March 09, 2026

# CMMC Insiders Say the Quiet Part Out Loud: Passing Doesn't Mean Protected

![Editorial Team](https://www.virtru.com/hubfs/assets/images/logos/virtru/logomark/blue/virtru_LOGOMARKMASTER_BLUE_FINAL.svg)

By Editorial Team

Share post:

[![Share on Facebook](https://www.lean-labs.com/hs-fs/hubfs/LLv2/images/icon-blog-facebook.png?noresize&width=24&name=icon-blog-facebook.png)](http://www.facebook.com/share.php?u=https%3A%2F%2Fwww.virtru.com%2Fblog%2Fcompliance%2Fcmmc-insiders-say-the-quiet-part-out-loud-passing-doesnt-mean-protected%3Futm_medium%3Dsocial%26utm_source%3Dfacebook) [![Share on LinkedIn](https://www.lean-labs.com/hs-fs/hubfs/LLv2/images/icon-blog-linkedin.png?noresize&width=24&name=icon-blog-linkedin.png)](http://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww.virtru.com%2Fblog%2Fcompliance%2Fcmmc-insiders-say-the-quiet-part-out-loud-passing-doesnt-mean-protected%3Futm_medium%3Dsocial%26utm_source%3Dlinkedin) [![Share on Twitter](https://www.virtru.com/hs-fs/hubfs/opentdf/assets/images/icons/x-logo.webp?width=24&name=x-logo.webp)](https://twitter.com/intent/tweet?original_referer=https%3A%2F%2Fwww.virtru.com%2Fblog%2Fcompliance%2Fcmmc-insiders-say-the-quiet-part-out-loud-passing-doesnt-mean-protected%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&url=https%3A%2F%2Fwww.virtru.com%2Fblog%2Fcompliance%2Fcmmc-insiders-say-the-quiet-part-out-loud-passing-doesnt-mean-protected%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&source=tweetbutton&text=CMMC%20Insiders%20Say%20the%20Quiet%20Part%20Out%20Loud%3A%20Passing%20Doesn%27t%20Mean%20Protected)

## TABLE OF CONTENTS

See Virtru In Action

Book a Demo

Share post:

[![Share on Facebook](https://www.lean-labs.com/hs-fs/hubfs/LLv2/images/icon-blog-facebook.png?noresize&width=24&name=icon-blog-facebook.png)](http://www.facebook.com/share.php?u=https%3A%2F%2Fwww.virtru.com%2Fblog%2Fcompliance%2Fcmmc-insiders-say-the-quiet-part-out-loud-passing-doesnt-mean-protected%3Futm_medium%3Dsocial%26utm_source%3Dfacebook) [![Share on LinkedIn](https://www.lean-labs.com/hs-fs/hubfs/LLv2/images/icon-blog-linkedin.png?noresize&width=24&name=icon-blog-linkedin.png)](http://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww.virtru.com%2Fblog%2Fcompliance%2Fcmmc-insiders-say-the-quiet-part-out-loud-passing-doesnt-mean-protected%3Futm_medium%3Dsocial%26utm_source%3Dlinkedin) [![Share on Twitter](https://www.virtru.com/hs-fs/hubfs/opentdf/assets/images/icons/x-logo.webp?width=24&name=x-logo.webp)](https://twitter.com/intent/tweet?original_referer=https%3A%2F%2Fwww.virtru.com%2Fblog%2Fcompliance%2Fcmmc-insiders-say-the-quiet-part-out-loud-passing-doesnt-mean-protected%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&url=https%3A%2F%2Fwww.virtru.com%2Fblog%2Fcompliance%2Fcmmc-insiders-say-the-quiet-part-out-loud-passing-doesnt-mean-protected%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&source=tweetbutton&text=CMMC%20Insiders%20Say%20the%20Quiet%20Part%20Out%20Loud%3A%20Passing%20Doesn%27t%20Mean%20Protected)

![Analysts attempt to log into a computer that says "DENIED" on screen](https://www.virtru.com/hubfs/assets/temporary%20(use%20this%20for%20uploading%20unoptimized%20images,%20videos,%20etc)/blog%20-%20DCMMC%202026%20Recaps/dcmmc-panel-recap.png)

There's a dangerous delusion spreading through the Defense Industrial Base: that passing a CMMC Level 2 assessment means you're secure.

Three experts who live in the trenches of CMMC assessments—a C3PAO CEO who's delivered 18 Level 2 certifications, a partner at a major consulting firm running their CMMC practice, and a GRC platform chief security officer who helped establish the CMMC Accreditation Body—gathered in Washington D.C. with a stark message: If a control can't stop data exfiltration or reduce risk to CUI, it shouldn't be in your System Security Plan.

Their collective thesis? Organizations are achieving compliance while remaining fundamentally insecure. And it's happening for five specific, fixable reasons.

![](https://fast.wistia.com/embed/medias/ge2zwksoj6/swatch)

*This blog covers a DCMMC panel: "Defense Over Pretense: Making Audits Easy and Exfiltration Hard."   
**Watch the full panel above or keep reading for the recap. *

## Reason #1: The Framework Rewards Documentation Over Defense

The first crack in CMMC's armor is structural: it's dangerously easy to satisfy assessors with paperwork that has zero correlation to actual security posture.

Andy Sauer, CEO of [Sentinel Blue](https://www.sentinelblue.com/), was blunt about what he sees across 18 Level 2 certifications: "It is very easy to game your way through CMMC L2 with process and documentation that is entirely impractical. You can write a 500-page SSP that no one can action and you can just do enough shallow work that it'll pass and we're really not moving the needle."

He pointed to control [3.1.3](https://dodcio.defense.gov/Portals/0/Documents/CMMC/AssessmentGuideL3.pdf)—controlling the flow of CUI—as a prime example. "Most people demonstrate a CUI flow diagram, the assessor says 'Oh I see a diagram, you pass 3.1.3, good to go,'" Sauer explained. "But there's a whole lot more to controlling the flow of CUI… protecting against exfiltration, making sure the right people have access to it."

This isn't just one control. Sauer noted that Level 1 and 2 controls across domains "tend to be the high level" statements that are inherently vague. "You can get away with some pretty basic stuff, especially around process and policy statements without having to demonstrate really a lot of technical depth."

Sauer advocates for an inverted priority: "Do 80% technical and 20% documentation. Very often I see people pushing 80% documentation and 20% technical." It’s simple; you can revise a document between assessment sessions. You cannot fix fundamentally broken security architecture overnight.

This creates a perverse incentive structure where organizations optimize for audit performance rather than threat resistance. Which leads directly to the second problem.

## Reason #2: Security Theater Has No Consequences... Until It Does

When compliance becomes disconnected from security culture, even "implemented" controls become meaningless checkboxes. And unlike failed audits, failed security culture doesn't show up until after the breach.

Michael Lipinski from [Plante Moran](https://www.plantemoran.com/) shared a cautionary tale that perfectly illustrates this gap: A client deployed multi-factor authentication across their entire organization—a clear CMMC requirement, properly documented, fully implemented. Six months in, their frequently traveling CFO found MFA burdensome and requested an exemption. It was granted.

Six months after that, $3 million left the organization, presumably through the compromised account.

"Security is really more of a culture thing than it is tech stack or control framework," Lipinski emphasized. "It really comes down to the culture of the organization top down."

The organization had the right control. They had the right documentation. They even had the right technology deployed. But one cultural failure, prioritizing executive convenience over security, rendered it all meaningless. And here's the critical part: that exemption would likely never surface in a standard CMMC assessment.

The assessor would see MFA deployed organization-wide. They'd see the policy requiring it. They'd check the box and move on. The cultural rot that actually compromised security would remain invisible until the money disappeared.

Stuart Itkin from [FutureFeed](https://futurefeed.co/) expanded on this, noting that when organizations view compliance as a checkbox exercise, "there's little consequences for people to look at this as simply check the box,” at least until the breach happens. Then the consequences are severe: contractual fines, regulatory penalties, and loss of the sensitive information you were entrusted to protect.

## Reason #3: The Framework Ignores How Organizations Actually Get Compromised

Perhaps the most damning indictment of CMMC's current state is this: the framework is nearly silent on the threats that actually breach defense contractors.

Itkin brought the threat intelligence perspective: "Bad actors are certainly trying to exploit any area they can find within an organization, but the one that seems to be most frequently exploited are those that relate to people controls and not the technical controls."

Consider phishing—the number one attack vector. Major defense contractors like Stark Industries and General Dynamics (GDIT) have reported significant breaches starting with phishing attacks. Yet as Sauer noted, "Does anyone ever control-F 800-171 for the word 'phishing'? You won't find it."

Think about that. The most common way defense contractors get breached doesn't appear in the control framework.

Control 3.2.1 requires security awareness training, but Itkin observed organizations treating this as "a 20-minute video for individuals to go through, take a two-question test at the end to be able to document that they've completed the security training." Meanwhile, other organizations implement year-round phishing simulations with real consequences, including dismissal after three failures.

Both approaches "pass" the control. Only one actually reduces risk.

The disconnect gets worse when you look at insider threats and social engineering. Itkin highlighted the [North Korean Bad Actor Scheme](https://www.justice.gov/opa/pr/justice-department-announces-nationwide-actions-combat-illicit-north-korean-government), where over 100 companies have been prosecuted for inadvertently hiring North Korean nationals using forged or stolen credentials. These individuals, working from North Korean office buildings, passed background checks and interviews—often using AI assistance—and gained access to CUI and ITAR information.

Control 3.9.1 requires "appropriate background screening," but clearly "appropriate" has dramatically different interpretations. One defense contractor's "appropriate" gave a foreign intelligence operative remote access to classified materials.

The framework assumes certain baseline competencies that don't exist in practice. Which is exacerbated by the next problem.

## Reason #4: Assessor Quality Is Wildly Inconsistent

Even a perfect framework fails if the people assessing compliance lack the technical depth to distinguish theater from substance. And the rapid growth of the C3PAO marketplace has created exactly this problem.

The panel identified a fundamental split in assessor backgrounds: some come from consulting with deep technical skills but less audit rigor; others come from accounting firms with audit expertise but shallow technical knowledge.

"Some firms will be a little less technical," Lipinski admitted about audit-focused firms. "These may be CPAs that are looking at this and may not have the technical depth to understand the difference between Google Cloud and Azure cloud."

Itkin recounted being in an assessment where "an assessor came in asking to see our endpoint logs and I explained to the assessor we were actually using this new technology called cloud and a product called Windows Defender. It didn't have logs. We were doing this all in real time for analysis. They didn't understand the Microsoft stack."

This fundamentally compromises assessment validity. An assessor who doesn't understand your technology stack cannot properly evaluate whether your implementation of controls actually provides security value.

Sauer emphasized this from the assessor perspective: "Don't be afraid to say no. Turn away the thing that you don't understand because there's liability in saying 'We'll evaluate your Google environment' when your assessors have only ever looked at GCC High."

But many don't say no. The economic incentives push C3PAOs to take on work beyond their technical competency, leading to surface-level assessments that miss critical security gaps.

But there’s good news: there's a built-in quality check coming. Lipinski noted that while C3PAOs are currently certified against the CMMC framework, "the next step is to accredit them against [ISO 17020](https://www.iso.org/standard/52994.html), which is an audit framework" that requires demonstrating "a defined quality process, an audit process, understanding of what independence is."

But that's a future fix. Today's problem remains: organizations shopping primarily on price are getting assessors who lack the depth to properly evaluate their security posture.

## Reason #5: We've Forgotten What the Documentation Is Actually For

The final dysfunction might be the most fundamental: a complete misunderstanding of why we create security documentation in the first place.

Itkin reframed it powerfully: "When anybody talks about documentation in the context of 'we're developing this so we can get through the assessment,' they're doing you a huge disservice. You're developing the documentation for yourself, for your organization."

He continued: "The word 'plan' is pretty operative. A plan is something that you develop to be able to follow. You're not developing a plan so that you can hand it over to an assessor and ensure it's adequate, it's sufficient, we check all the boxes, we can pass our assessment."

This gets to the core of why compliance theater persists: organizations have reoriented their entire CMMC effort around satisfying an assessor rather than protecting information.

Your System Security Plan should be an operational blueprint that your team actually follows. Your policies and procedures should reflect decisions you've made about how to protect CUI in your specific environment. Your documentation should enable new employees to understand your security posture and their role in maintaining it.

Instead, most SSPs are 500-page documents generated to satisfy assessment objectives, filled with generic AI-written policies that bear little resemblance to how the organization actually operates.

"If you're going to use AI to write your policies, they're going to stomp on that," Lipinski warned. "The policies have to be very specific. They can't be generic. They've got to be unique and they've got to flow. You've got to show that you've operationalized them and that's the way your business is functioning."

But operationalization requires actually following the plan, which requires the plan to be realistic and actionable, which requires viewing documentation as a tool for your organization rather than a performance for an assessor.

## What Defense Over Pretense Actually Looks Like

Understanding why CMMC compliance often fails to deliver security is only valuable if we can chart a different path. The panel offered specific, actionable guidance that moves beyond checkbox compliance:

**Stop shopping on price alone.** The cheapest assessor may cost you far more when their superficial assessment misses gaps that lead to a breach. Ask potential assessors how many organizations with your specific tech stack they've assessed, what credentials their team holds, and how they handle incomplete controls.

**Invest in technical implementation over documentation.** Sauer's 80/20 rule isn't about ignoring documentation, it's about priorities. "You know what I can fix between session one and session two? A document. You know what I can't fix? A bad security configuration, a bad baseline being deployed."

**Eliminate on-premises infrastructure wherever possible.** Cloud solutions address dozens of controls more effectively and reduce the assessment complexity significantly.

**Deploy force multiplier technologies.** Zero Trust Network Access tools like Cloudflare Zero Trust and Zscaler can impact multiple controls while genuinely improving your security posture.

**Demand partners who speak in concepts, not control numbers.** If an assessor talks about "3.1.1, 3.1.2" instead of "how we evaluate least privilege across AD groups, local accounts, and SaaS applications," they lack the technical depth you need.

**Be willing to fire underperforming partners.** Whether your assessor, RPO, or MSP, if they lack the technical depth or business understanding to properly support you 30 days in, move on. You're not stuck with them.

**Know your current state honestly.** If you're just starting your gap assessment now, you're a year from readiness. Plan accordingly rather than rushing to check boxes.

**Get involved in the community.** LinkedIn, Discord, and Reddit have generous experts who've been focused on this for years and openly share lived experience.

Most importantly: **Remember that your SSP is for you.** When you shift from "what do I need to pass the assessment" to "what do I need to protect the information I've been entrusted with," everything else falls into place.

## The Stakes Are Real

When the panel concluded, Salinas summarized the core message perfectly: organizations need to demand "not just documentation; a partner as you're an OSC starting your CMMC Level 2 journey to make sure they are adequate to handle not just your business but your tech stack, how you are handling CUI."

Because ultimately, when adversaries bypass your "compliant" controls and exfiltrate your CUI, the assessor might lose their C3PAO status. But you'll face contractual fines, regulatory penalties, loss of business, and the compromise of sensitive information that directly impacts national security.

Defense over pretense isn't just a catchy panel title. It's the only defensible approach to CMMC compliance—and it requires fundamentally rethinking what compliance is actually for.

Organizations that treat their SSP as an operational plan, invest in technical implementation, partner with assessors who have genuine depth, and build a security culture that values protection over convenience—those organizations will be both compliant and secure.

The rest will pass their audits right up until the day they get breached.

---

DCMMC is an annual practitioner-led, vendor-neutral CMMC community event focused on delivering real security outcomes for the DIB and was a chance to connect with DC’s defense peers. [Learn more and watch the other panels here](https://www.virtru.com/dcmmc-event). 

![Editorial Team](https://www.virtru.com/hubfs/assets/images/logos/virtru/logomark/blue/virtru_LOGOMARKMASTER_BLUE_FINAL.svg)

### Editorial Team

The editorial team consists of Virtru brand experts, content editors, and vetted field authorities. We ensure quality, accuracy, and integrity through robust editorial oversight, review, and optimization of content from trusted sources, including use of generative AI tools.

[View more posts by Editorial Team](https://www.virtru.com/blog/author/editorial-team)

See Virtru In Action

Book a Demo

Sign Up for the Virtru Newsletter

## Dive Deeper

![](https://www.virtru.com/hubfs/assets/images/icons/left-arrow-circle-blue.webp)

[![](https://www.virtru.com/hubfs/assets/temporary%20(use%20this%20for%20uploading%20unoptimized%20images,%20videos,%20etc)/blog%20-%20cyera%20oasis/cyera-oasis.webp)

Commentary

July 29, 2026

### The Coin Has Two Sides: What Cyera's Acquisition of Oasis Tells Us About the Future of Security

](https://www.virtru.com/blog/data-centric-security/cyera-oasis) [![](https://www.virtru.com/hubfs/26-Competitor-Blog%20-%20Virtru%20vs%20Box%20copy.webp)

File Encryption

July 28, 2026

### Virtru Collaborate vs. Box: Secure File Sharing for Businesses of Any Size

](https://www.virtru.com/blog/virtru-collaborate-vs-box-enterprise) [![](https://www.virtru.com/hubfs/assets/temporary%20(use%20this%20for%20uploading%20unoptimized%20images,%20videos,%20etc)/blog%20-%20william%20mcborrough%20recap/cmmc-compass-will-mcborrough.webp)

Compliance

July 22, 2026

### The $600,000 Problem: What the CMMC Pause Actually Revealed About the Defense Industrial Base

](https://www.virtru.com/blog/compliance/mcglobaltech-cmmc-compass) [![](https://www.virtru.com/hubfs/assets/temporary%20(use%20this%20for%20uploading%20unoptimized%20images,%20videos,%20etc)/blog%20-%20three%20stories/three-stories.webp)

Zero Trust

July 21, 2026

### Last Week in Critical Infrastructure: Three Stories You Should Read as One

](https://www.virtru.com/blog/data-centric-security/three-stories-converge) [![](https://www.virtru.com/hubfs/assets/temporary%20(use%20this%20for%20uploading%20unoptimized%20images,%20videos,%20etc)/blog%20-%20cmmc%20on%20hold/CMMC-Pause-CUI-Not.webp)

Public Sector

July 14, 2026

### CMMC Phase II Is Officially on Hold. NIST and DFARS aren't.

](https://www.virtru.com/blog/compliance/cmmc-phase-2-on-hold-nist-dfars) [![](https://www.virtru.com/hubfs/assets/temporary%20(use%20this%20for%20uploading%20unoptimized%20images,%20videos,%20etc)/2026%20Newsletter%20Assets/jk-HIO.png)

Zero Trust

July 10, 2026

### We Asked Kindervag: Why Are So Many Organizations Still Getting Zero Trust Wrong?

](https://www.virtru.com/blog/zero-trust/kindervag-yeske) [![](https://www.virtru.com/hubfs/assets/temporary%20(use%20this%20for%20uploading%20unoptimized%20images,%20videos,%20etc)/blog%20-%20ShareFile%20Takedown/26-Competitor-Blog-Blog%20-%20Virtru%20vs%20Sharefile.jpg)

File Encryption

July 10, 2026

### Looking for a ShareFile Alternative? Here's What Regulated Organizations Need to Know.

](https://www.virtru.com/blog/file-encryption/citrix-progress-sharefile) [![](https://www.virtru.com/hubfs/assets/temporary%20(use%20this%20for%20uploading%20unoptimized%20images,%20videos,%20etc)/blog%20-%20sendsafely%20takedown/26-Competitor-Blog-Blog%20-%20Virtru%20vs%20SendSafely%20(1).jpg)

File Encryption

July 08, 2026

### SendSafely vs. Virtru: Which Secure File Sharing Platform Protects Your Data After Download?

](https://www.virtru.com/blog/file-encryption/sendsafely) [![](https://www.virtru.com/hubfs/assets/images/blog/26-Competitor-Blog-Blog%20-%20Virtru%20vs%20Dropbox.webp)

File Encryption

July 07, 2026

### Dropbox Alternatives for Secure File Sharing: What IT Teams Are Missing

](https://www.virtru.com/blog/dropbox-alternatives-secure-file-sharing) [![](https://www.virtru.com/hubfs/assets/temporary%20(use%20this%20for%20uploading%20unoptimized%20images,%20videos,%20etc)/blog%20-%20alex%20karp/alex-karp.jpg)

Commentary

July 07, 2026

### Alex Karp Is Right About the AI Problem. He's Missing the Solution.

](https://www.virtru.com/blog/zero-trust/alex-karp-palantir-data-sovereignty) [![](https://www.virtru.com/hubfs/assets/temporary%20(use%20this%20for%20uploading%20unoptimized%20images,%20videos,%20etc)/blog%20-%20SACR%20Report/anna-perrone-commentary%20copy.webp)

Email Encryption

June 29, 2026

### The Email Security Report Every CISO Should Read, And the Questions It Should Inspire

](https://www.virtru.com/blog/email-security/sacr-anna-perrone-report-2026)

![](https://www.virtru.com/hubfs/assets/images/icons/right-arrow-circle-blue.webp)

## Book a Demo

## Become a Partner

Contact us to learn more about our partnership opportunities.

## Become a Compliance Champion

Contact us to learn more about our partnership opportunities.

- Products
  
    - [Product Overview](https://www.virtru.com/data-security-platform/product-overview)
    - [Virtru for Google Workspace](https://www.virtru.com/data-security-platform/google-workspace)
    - [Virtru for Microsoft 365](https://www.virtru.com/data-security-platform/microsoft-365)
    - [Data Protection Gateway](https://www.virtru.com/data-security-platform/virtru-data-gateway)
    - [Pricing](https://www.virtru.com/data-security-platform/pricing-packages)
- Compliance
  
    - [HIPAA](https://www.virtru.com/compliance/hipaa-email)
    - [ITAR](https://www.virtru.com/compliance/itar)
    - [GDPR](https://www.virtru.com/compliance/gdpr)
    - [CJIS](https://www.virtru.com/compliance/cjis)
    - [NIST CUI](https://www.virtru.com/compliance/nist)
    - [CCPA](https://www.virtru.com/compliance/ccpa)
    - [FERPA](https://www.virtru.com/compliance/ferpa)
    - [CMMC](https://www.virtru.com/compliance/cmmc)
- Industries
  
    - [Healthcare](https://www.virtru.com/industry-solutions/healthcare/)
    - [Education](https://www.virtru.com/industry-solutions/education/)
    - [IT & Software](https://www.virtru.com/industry-solutions/telecom-it-and-software)
    - [Federal Government](https://www.virtru.com/global-public-sector)
    - [State & Local Government](https://www.virtru.com/industry-solutions/state-local-government)
    - [Manufacturing](https://www.virtru.com/industry-solutions/manufacturing)
    - [Financial Services](https://www.virtru.com/industry-solutions/financial-services/)
- Platform
  
    - [Email Encryption](https://www.virtru.com/data-security-platform/email-encryption)
    - [File Encryption](https://www.virtru.com/data-security-platform/file-encryption)
    - [Platform Architecture](https://www.virtru.com/data-security-platform/saas)
    - [Trusted Data Format](https://www.virtru.com/data-security-platform/trusted-data-format)
    - [Secure Reader](https://www.virtru.com/data-security-platform/secure-collaboration)
    - [Audit and Control](https://www.virtru.com/data-security-platform/audit-and-control)
    - [Encryption Key Management](https://www.virtru.com/data-security-platform/virtru-private-keystore)
- Resources
  
    - [About Virtru](https://www.virtru.com/about-us)
    - [Blog](https://www.virtru.com/blog)
    - [Careers](https://www.virtru.com/careers)
    - [Leadership & Investors](https://www.virtru.com/leadership/)
    - [News & Press](https://www.virtru.com/press)
    - [Partners](https://www.virtru.com/partners/)
    - [Intellectual Property](https://www.virtru.com/intellectual-property/)
    - [Security Certifications](https://www.virtru.com/data-security-platform/compliance)
    - Resource Library
- Contact Us
  
    - [Contact Us](https://www.virtru.com/contact-us)
    - [Support](https://support.virtru.com/)
    - [Sales](https://www.virtru.com/contact-us)
    - [Become a Partner](https://www.virtru.com/blog/compliance/cmmc-insiders-say-the-quiet-part-out-loud-passing-doesnt-mean-protected#footer)
    - [Report a Vulnerability](https://www.virtru.com/responsible-disclosure/)

[![Virtur Logo](https://www.virtru.com/hubfs/assets/images/logos/virtru/white/tagline/virtru_TAGLINE_LOGOMASTER_WHITE-01.svg)](https://www.virtru.com/)

Subscribe to Our Newsletter

[![X Icon](https://www.virtru.com/hubfs/assets/images/icons/x-white.svg)](https://x.com/virtruprivacy) [![LinkedIn Icon](https://www.virtru.com/hubfs/assets/images/icons/linkedin-white.svg)](https://www.linkedin.com/company/virtru) [![Youtube Icon](https://www.virtru.com/hubfs/assets/images/icons/youtube-white.svg)](https://www.youtube.com/@Virtru)

© 2026 Virtru · 1801 Pennsylvania Ave NW, 5th Floor, Washington, DC 20006

[Terms](https://www.virtru.com/terms-of-service) & [Privacy](https://www.virtru.com/privacy-policy) | [Cookie Policy](https://www.virtru.com/cookie-policy) & [Preferences ![Pivacy Options logo](https://oag.ca.gov/sites/all/files/agweb/images/privacy/privacyoptions.svg)](https://www.virtru.com/blog/compliance/cmmc-insiders-say-the-quiet-part-out-loud-passing-doesnt-mean-protected#footer) | [Do Not Sell My Personal Information](https://www.virtru.com/blog/compliance/cmmc-insiders-say-the-quiet-part-out-loud-passing-doesnt-mean-protected#footer) | [Virtru Trust Center](https://trust.virtru.com/?_ga=2.215796503.1200908638.1747067694-1753239414.1744322796&_gac=1.175361302.1744660048.EAIaIQobChMIppzvranJjAMVN0pHAR3F7gNdEAAYAiAAEgL4qfD_BwE)

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://www.virtru.com/#organization",
  "@type" : "Organization",
  "description" : "Virtru is a data security platform delivering end-to-end encryption and access control for email, files and apps. Trusted by enterprise and defense leaders",
  "logo" : "https://www.virtru.com/hubfs/assets/images/logos/virtru/blue/virtru_LOGOMASTER_BLUE_HighRes.png",
  "name" : "Virtru",
  "sameAs" : [ "https://www.facebook.com/virtruprivacy", "https://www.x.com/virtruprivacy", "https://www.linkedin.com/company/virtru", "https://www.reddit.com/user/virtru_privacy", "https://www.youtube.com/@Virtru" ],
  "url" : "https://www.virtru.com/"
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Editorial Team",
    "url" : "https://www.virtru.com/blog/author/editorial-team"
  },
  "dateModified" : "2026-03-09T23:00:02.001Z",
  "datePublished" : "2026-03-09T21:42:46.000Z",
  "headline" : "CMMC Insiders Say the Quiet Part Out Loud: Passing Doesn't Mean Protected",
  "image" : [ "https://www.virtru.com/hubfs/assets/temporary%20(use%20this%20for%20uploading%20unoptimized%20images,%20videos,%20etc)/blog%20-%20DCMMC%202026%20Recaps/dcmmc-panel-recap.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://www.virtru.com/blog/compliance/cmmc-insiders-say-the-quiet-part-out-loud-passing-doesnt-mean-protected",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://www.virtru.com/hubfs/virtru2022/images/Virtru%20Logo%20Blue%20(2).svg"
    },
    "name" : "Virtru"
  }
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "ItemList",
  "itemListElement" : [ {
    "@type" : "SiteNavigationElement",
    "name" : "Products",
    "position" : 1
  }, {
    "@type" : "SiteNavigationElement",
    "name" : "Solutions",
    "position" : 2
  }, {
    "@type" : "SiteNavigationElement",
    "name" : "Developers",
    "position" : 3
  }, {
    "@type" : "SiteNavigationElement",
    "name" : "Company",
    "position" : 4
  }, {
    "@type" : "SiteNavigationElement",
    "name" : "Resources",
    "position" : 5
  }, {
    "@type" : "SiteNavigationElement",
    "name" : "Support",
    "position" : 6,
    "url" : "https://support.virtru.com"
  }, {
    "@type" : "SiteNavigationElement",
    "name" : "Pricing",
    "position" : 7
  } ],
  "name" : "Main Navigation"
}
```