It only took a few days, and the CMMC grifters have already shifted their posture. This comes after the Dept. of Defense (DBA Dept. of War) announced a 60-day pause on third-party CMMC certifications, moving the program back towards the self-attestation posture we had prior to Katie Arrington’s corrupt grift scam.

For the first days, the CMMC teat-milkers like Summit7, Redspin, Preveil and others, were trying to find their new footing. After years of insisting CMMC was necessary because the DIB never did what they were told to under NIST 800, so a law was needed, now those folks are saying that DIB companies will gladly pursue third-party assessments anyway, just because. Jacob Horne built an entire career around falsely accusing everyone or prior crimes, but has now already pivoted so much, I had to turn him into a cartoon:

The other meme put forth by the CMMC teaters is that everyone out there is insisting that they can stop implementing CMMC entirely now. Dudes, no one is saying that. The DoW’s notice was pretty clear, only the scammy, price-gouging, C3PAO aspect is on pause, not actual implementation of the controls. You consultants can relax for a minute, jeesh.

But let’s see how all of this is changing as of July 24. A few weeks ago, on June 22, the President signed Executive Order 14413 on “post-quantum cryptography.” You can read that here. In super-layman’s terms, there is grave (and legitimate) concern over the rise of God-tier quantum computers which will be able to hack complex passwords in mere milliseconds, where current non-quantum computers would take years to do so. This breaks all traditional cryptography: passwords, two-factor authentication, 256-bit hashes, even biometrics. In May of 2026, Google warned that quantum computing technology may become mainstream enough to break all banking.

From The Guardian:

Banks, governments and technology providers need to be prepared for quantum computer hackers capable of breaking most existing encryption systems by 2029, Google has warned. The tech company said in a blogpost that quantum computers would pose a “significant threat to current cryptographic standards” before the end of the decade and urged other companies to follow its lead.

The company… said: “The encryption currently used to keep your information confidential and secure could easily be broken by a large-scale quantum computer in coming years.”

It took a few weeks, as I said, but the DoW handed the floundering CMMC consultant community a new juicy fudburger to gnaw on, and gnaw they will.

In just the past two days, a flood of (largely AI-generated) posts on LinkedIn have popped up, trying to justify “post-quantum cryptography” (PQC) as the next thing that companies will have to adopt on top of CMMC. Because scaring the bejeezus out of people with a problem they cannot possibly solve has worked so well for them to date. Have a look (click to enlarge):


Only two of those (the posts by John Rodriguez and EnQuanta) were dated back closer to when the DoW announcement hit. The others, from CMMC shills, were all from the past few days. You can see a meme arising.

As always, it’s the same consultant-driven “Impossible Problem / Improbable Solution” script:

  1. Identify a problem that is massive in scale and pose it as threatening one’s way of life
  2. Suggest a consultant-led solution that cannot possibly resolve the problem being proposed, but say it will anyway
  3. Sell as much as possible in the short term
  4. When it fails, pivot to a new impossible problem/improbably solution scenario

One somewhat thoughtful take on this comes from a post by Oleg Popenko of ECS Tek who pointed out an interesting truth. Emphasis added by me:

Upon reviewing the recent PQC document, it is evident that its writing style diverges from the traditional formats seen in DoD policy, big four consulting firms, major cloud providers, or startup organizations. This document appears to reflect influence from Silicon Valley thinking.

This is telling. It suggests — rightly, I think — that a new variation of advisor stepped in to assist the DoW in the drafting of the EO and that suggests the old guard (the largely unqualified CMMC architects like Katie Arrington, Kevin Fahey and Katie Stewart) have been officially aged-out. But the Silicon Valley Military Industrial Complex is lousy with some pretty whacked-out characters, like Musk and Thiel and would-be mass murderer Palmer Luckey (seriously), so this may be a worse development, not a better one.

Popenko goes on to note that while “the previous transition from CMMC to CMMC 2.0, which was significantly less complex, it took five years to finalize,” the “integration of the PQC plan into the CMMC framework—potentially termed CMMC 3.0—could span decades.

For sure, this is a real emergency. But, like Y2K and the IP4 crises before it, this will be resolved by actual experts in technology. It cannot be flowed down to machine shops. But, of course, that is exactly what the CMMC shills are suggesting. Per an article from DefenseScoop (which cringingly still quotes Horne as if he is at all relevant):

Although quantum computing is relatively nascent, leaders across the U.S. government have raised concerns about how the technology could be exploited by adversaries in the future. Capabilities like quantum algorithms could easily bypass modern encryption, while quantum cryptography can create nearly impenetrable networks and databases.

And given the Pentagon’s work to ensure defense contractors have proper cybersecurity controls on their own networks, experts asserted that the move to introduce PQC into CMMC isn’t out of left field.

As usual, the posture is the same: we have a huge problem and a Dept. of War with a $1 trillion annual budget, but let’s solve this on the cheap by flowing down responsibility to the supply chain and justify the unfunded mandate by using patriotic jingoism. I mean, CMMC has been such a success, right?

Fortunately, behind the scenes real tech experts are working on the software and hardware which will be needed to defeat quantum hacks. The end user will simply implement those, in the same way we buy firewall hardware and install antivirus software on our system to defeat legacy-era hacks. It won’t be foolproof, and will require constant updates, but it will work overall.

But CMMC shills won’t be able to sell themselves without some form of skyfall, so here we are again.

The real winner? The guys selling these shills their ketamine.

 

Advertisements

Traditional Tri-System