Brilliant at the Basics vs. NIST SP 800-171: What the DoW's New Campaign Means for Your Compliance Strategy
The Department of War CIO recently launched "Brilliant at the Basics," a campaign built to help small and mid-sized Defense Industrial Base (DIB) contractors secure their networks without drowning in compliance overhead. It is practical, well-intentioned, and worth your attention. But if you hold Controlled Unclassified Information (CUI), you may be asking the obvious question: does following this guidance get me closer to NIST SP 800-171 compliance, or is it something else entirely?
Sera Brynn has been answering questions like this since 2011. As an Authorized C3PAO (CyberAB CPN 59175) and an accredited FedRAMP and GovRAMP 3PAO, our assessors work inside NIST SP 800-171 every day, both preparing defense contractors for CMMC and formally assessing them against it. What follows is our practitioner's read on where the DoW's new campaign lines up with 800-171, and where it deliberately does not.
The Short Version: What You'll Take Away
If you read this article, you will learn:
- What Brilliant at the Basics is and who it is written for
- How each of the campaign's IT Top 10 practices maps to specific NIST SP 800-171 control families
- Where the campaign goes beyond 800-171, and where it stops well short of it
- Why "Brilliant at the Basics" is a strong security starting point but not a substitute for compliance
- How to use the campaign as a springboard toward CMMC readiness
What Is Brilliant at the Basics?
Brilliant at the Basics is a DoW CIO initiative aimed squarely at small, mid-sized, and non-traditional DIB companies. It distills cybersecurity into two Top 10 lists, one for IT environments and one for Operational Technology (OT), plus a library of supporting resources from NIST, CISA, NSA, and DC3. Both lists are available as downloadable one-page references: the IT Top 10 PDF and the OT Top 10 PDF are worth circulating to your IT and security leads.
The campaign's stated goal is to strip away administrative complexity so contractors can secure networks and protect sensitive DoW information quickly. That framing matters. This is security guidance, not compliance guidance. The distinction runs through everything that follows.
How the IT Top 10 Maps to NIST SP 800-171
NIST SP 800-171 Rev 2 organizes 110 security requirements into 14 control families. Here is how the campaign's IT practices line up.
1. Phishing-resistant MFA
Direct hit on the Identification and Authentication family. 800-171 requires multifactor authentication for network and privileged access (3.5.3). The campaign actually raises the bar by pushing contractors past legacy SMS and push-based MFA toward phishing-resistant methods, which anticipates where DoW expectations are heading.
2. Comprehensive asset inventory
Maps to Configuration Management, specifically the requirement to establish and maintain baseline configurations and system inventories (3.4.1). You cannot scope a CUI environment, let alone defend one, without knowing what you own. Assessors check this early because everything else depends on it.
3. Strategic technical debt reduction
Aligns with the least functionality requirements in Configuration Management (3.4.6 through 3.4.9). Retiring unsupported software and shadow IT shrinks both your attack surface and your assessment scope. Fewer systems touching CUI means a cleaner, faster assessment.
4. Flexible technology stack
This one has no direct 800-171 counterpart. It is architecture strategy, aimed at avoiding vendor lock-in and enabling interoperability. This is sound advice, and a business practice that supports growth and stability.
5. Logical segmentation
Maps cleanly to System and Communications Protection (3.13.1, 3.13.5). Segmentation is also the single most powerful scoping tool in a CMMC context. A well-segmented CUI enclave can dramatically reduce what falls inside your assessment boundary.
6. Risk-based vulnerability management
Covers Risk Assessment (3.11.2, 3.11.3) and flaw remediation under System and Information Integrity (3.14.1). The campaign's push to prioritize by actual exploitability rather than raw severity scores reflects how mature programs, and mature assessors, think.
7. Security early in the development lifecycle
Touches the security engineering principles in 3.13.2. For most DIB contractors this applies narrowly, but for software and systems developers it is foundational.
8. Secure AI adoption
Here the campaign is ahead of the standard. 800-171 Rev 2 predates enterprise AI and says nothing about it. But the underlying obligation is familiar: sensitive data must not flow into uncontrolled systems. Feeding CUI into a public AI tool is a CUI handling failure regardless of what any control number says. Expect future guidance to formalize this.
9. Resilient backup and disaster recovery
Partial overlap with Media Protection, which requires protecting backup CUI at storage locations (3.8.9). Notably, 800-171 is a confidentiality standard and treats availability lightly. The campaign's emphasis on immutable backups and restoration drills goes beyond 800-171 and reflects ransomware reality.
10. Continuous workforce readiness
Maps to Awareness and Training (3.2.1 through 3.2.3). The campaign frames it more ambitiously, treating workforce capability as an operational bottleneck rather than a training checkbox.
The Honest Assessment: Strong Overlap, Different Purpose
Roughly eight of the ten IT practices land directly on 800-171 territory. If you execute the campaign well, you will have made real progress against the standard's most consequential families: access control, configuration management, system protection, and training.
But here is what the campaign will not give you:
Documentation. 800-171 and CMMC assessments run on evidence. A System Security Plan, policies, procedures, and artifacts proving each control is implemented. Brilliant at the Basics deliberately strips this out. That is precisely what makes it approachable, and precisely why it is not a compliance program.
Full control coverage. The campaign is a Top 10. The standard has 110 requirements. Entire families, including Audit and Accountability, Incident Response reporting obligations, Media Protection, Personnel Security, and Physical Protection, get little or no coverage.
Scoping discipline. Knowing where CUI lives, flows, and is stored is the foundation of every assessment. The campaign assumes you will figure that out yourself.
Think of it this way: Brilliant at the Basics tells you how to be secure. NIST SP 800-171 tells you how to prove it.
Why This Matters Right Now
With CMMC Phase 2 requirements suspended as of July 2026, some contractors are tempted to let compliance work drift. That is a mistake. Contractual obligations under DFARS 252.204-7012 to implement 800-171 have not gone anywhere, and the DoW publishing a campaign like this signals the Department's expectations for the DIB are rising, not relaxing.
Contractors who use this window to get brilliant at the basics and close their 800-171 gaps will walk into the next phase of enforcement with a competitive advantage. Those who wait will be scrambling alongside everyone else.
Talk to the People Who Assess This for a Living
Whether you are just starting your NIST SP 800-171 journey or preparing for a formal CMMC assessment, Sera Brynn can help. As an Authorized C3PAO, we conduct official CMMC assessments. As readiness advisors, we help contractors close gaps, build defensible documentation, and scope their environments intelligently before assessment day.
If you have questions about CMMC, 800-171, or what Brilliant at the Basics means for your organization, call Sera Brynn. We will give you a straight answer from a team that lives on both sides of the assessment table.
Frequently Asked Questions
Does following Brilliant at the Basics make me NIST SP 800-171 compliant?
No. It builds genuine security maturity and overlaps with many 800-171 requirements, but compliance requires implementing all 110 controls and documenting them in a System Security Plan with supporting evidence.
Is Brilliant at the Basics mandatory for DoW contractors?
No. It is voluntary educational guidance. Your binding obligations come from your contract clauses, most commonly DFARS 252.204-7012, which requires 800-171 implementation.
Should I start with Brilliant at the Basics or with 800-171?
If you handle CUI, start with 800-171 because it is a contractual requirement. Use the campaign as a prioritization lens: its Top 10 highlights the controls that deliver the most security value fastest.
Does the campaign apply to OT environments?
Yes. The campaign page includes a separate OT Top 10 covering segmentation, asset inventory, remote access, and incident response for industrial and manufacturing environments. If OT systems process or protect CUI, they belong in your 800-171 conversation too.
With CMMC Phase 2 suspended, why should I keep working on this?
Because your DFARS obligations remain in force, cyber threats have not paused, and assessment-ready contractors will be positioned to win work the moment enforcement resumes.
