BlueVoyant exec: use CMMC pause to build enterprise monitoring
Lonny Anderson, a former CMMC skeptic, argues the Phase 2 suspension is the right moment to replace self-attestation with continuous external monitoring, and that reverting to the honor system while DOD deliberates is the real risk.
TL;DR
Former NSA chief technology officer Lonny Anderson, now president of BlueVoyant Government Solutions, published an open argument Wednesday urging the Defense Department to use the CMMC Phase 2 suspension to adopt an enterprise accountability model (independent assessment plus continuous external monitoring and shared remediation funding) rather than letting the pause lapse into pure self-attestation. The piece marks a public shift from CMMC skeptic to conditional supporter. Anderson's central claim: many NIST SP 800-171 failures, like expired TLS certificates and exposed misconfigured services, are visible from the outside right now, regardless of whether formal C3PAO assessments are running.

The argument lands while the Pentagon's CMMC Reform Task Force is mid-sprint (stood up July 17 with a 60-day clock) and while DOD CIO Kirsten Davies has solicited RFI responses from the defense industrial base on how to structure whatever comes next. Anderson's piece is, in effect, a preemptive submission: don't waste the pause on procedural review alone; build the monitoring architecture now.
The diagnosis: attestation without verification is the vulnerability
Anderson's core framing is worth quoting directly because it's sharper than most contractor advocacy: "CMMC exists because self-assessment, absent verification, is an honor system with a federal contract attached to it." He concedes that not every NIST SP 800-171 control can be externally observed (policies, training records, and access reviews require documentation) but draws a line at what is visible from the outside. Expired certificates, self-signed certificates, exposed FTP services, and misconfigured internet-facing systems don't prove CUI has been compromised, but they do prove that a supplier's attested posture doesn't match reality. In Anderson's view, continuous external monitoring catches that delta before an adversary does.
The money question: who pays for the small suppliers
Where the piece breaks from the standard prime-contractor talking point is its willingness to name the subsidy problem. Anderson calls for "an enterprise fund that supports continuous cyber monitoring and remediation for critical small businesses" and notes that the Senate's FY2027 NDAA draft already authorizes $50 million in CMMC assessment grants, but a one-time assessment check is not the same as sustained monitoring. His argument: the government is already paying for fragmented compliance activity indirectly through contract costs, so funding a shared baseline upfront reduces duplication and improves outcomes. That's a claim that'll face scrutiny from appropriators, but it's at least a concrete ask rather than the usual hand-waving about "burden."
What the piece doesn't answer
Anderson's proposed model leans heavily on continuous external monitoring, but he doesn't specify who does it, DOD directly, a federally funded R&D center, or a contracted commercial provider (like, say, BlueVoyant). That gap is material. If the monitoring is performed by vendors who also sell remediation services, the enterprise fund structure needs firewalls to prevent the monitor from becoming the remediation contractor by default. Anderson doesn't address that.
He also sidesteps the question of what happens to contractors who already paid for C3PAO assessments under Phase 2's original November 10 deadline. DOD CIO Davies told reporters in July that "every dollar spent on security is a wise dollar spent," but contractors who fronted tens of thousands for assessments that may now be irrelevant under a reformed model are unlikely to find that comforting. Anderson's argument that the pause should produce a stronger accountability mechanism is coherent, but it doesn't reckon with the stranded costs.
Still, the piece matters because it's the first public position from a defense contractor executive that treats the Phase 2 pause as a governance design window rather than a setback. Anderson isn't asking DOD to scrap CMMC. He's asking it to make the verification mechanism harder to spoof than the status quo, and to start doing it while the task force is still taking notes.
Published ·Deep Fathom