TRANSMISSION ACTIVE
// FREQ: GOVCON EPISODE: 023 STATUS: SECURE

023 Ransomware-as-a-Service, AI Phishing, and Everything You Need to Know About CMMC Level 3

JUMP POINTS //

00:32

Ransomware-as-a-Service — Cybercrime Went Corporate

Ransomware has evolved from a lone hacker in a basement into an industrialized subscription business. Developers build the malware and rent it to affiliates, so the attacker no longer needs to be sophisticated — anyone can buy the service. The result is an exponential jump in the number of attackers, all running the same repeatable, profitable playbook against every sector.

04:09

AI Phishing Erased the Warning Signs

The tells we spent a decade teaching people to spot — bad grammar, misspellings, the wrong sender address — are gone. AI writes phishing that perfectly mimics your internal communication style, and deepfake voice needs only about eight seconds of audio to clone an executive. IBM found roughly 16% of breaches now involve AI-driven attacks. AI is the entry; ransomware-as-a-service is the payload.

07:24

The Three Universal Marching Orders

You can’t trust your eyes and ears anymore, so the defense has to be automated controls: phishing-resistant MFA and verification protocols for high-value transactions, immutable and tested backups that an attacker can’t reach or encrypt, and network segmentation that shrinks the blast radius so one foothold can’t become your whole environment.

09:05

CMMC Level 2 Is Mandatory Now — Self-Attestation Is Over

As of Phase 2, Level 2 can no longer be self-attested. You need a certified third-party assessment organization — a C3PAO — to audit and certify you, and there are only around 100 of them. Level 2 applies to everyone touching CUI: primes, subs, and joint ventures all have to be certified independently. “We’re just a sub” and “our partner is certified” are two of the most expensive assumptions in GovCon.

14:13

Why Level 3 Makes Level 2 Urgent — The Dependency

Level 3 arrives in 2027, but you cannot even begin a Level 3 assessment without already holding Final Level 2 (C3PAO) certification. Level 3 is government-assessed by DIBCAC, applies to fewer than 1,000 contractors on the most sensitive programs, and costs a DoD-estimated $500K or more over three years. Push off Level 2 and you push off everything above it.

21:03

The Affirmation on Your Signature — False Claims Act Exposure

CMMC requires a senior official to sign an annual affirmation of compliance in SPRS. If you self-attested Level 2 last year and can’t pass a C3PAO assessment now, that prior affirmation becomes a potential False Claims Act problem — and the DOJ’s Civil Cyber-Fraud Initiative is built to pursue exactly that. The verified assessment is what protects the executive who signs.

// INCOMING SITREP

The episode explains why Level 2 has to happen now. The companion Sitrep is the operational timeline — how to scope your CUI, run the gap assessment, navigate conditional certification, and book a C3PAO before the queue closes. Read the SITREP dossier.

ACCESS THE BRIEF »

TRANSMISSION LOG //

Two Threats, One Framework, and a Clock That’s Already Running

This transmission covers the two threats reshaping the attack landscape in 2026 — the ransomware-as-a-service economy and AI-generated phishing — and then the government’s answer for the defense industrial base: CMMC. The through-line for every GovCon contractor listening is the deadline math: Level 2 third-party certification is mandatory right now, Level 3 arrives in 2027, and because there is no Level 3 without Level 2 first, the 2027 clock has already started.

Ransomware-as-a-Service: Cybercrime Became a Business

Rewind a few years and the mental model of a ransomware attacker was a single person in a basement. That model is gone. Like any maturing industry, cybercrime got monetized, scaled, and industrialized — and the result is ransomware-as-a-service. Developers build the malware and rent it out to affiliates, which means the attacker hitting you no longer needs to be a skilled coder or hacker. They just need to buy the service. That single shift multiplies the number of attackers exponentially by erasing the skill barrier that used to limit the field.

And the playbook has changed with it. For years, organizations treated backups as their ransomware insurance: if we get hit, we’ll just restore. That logic no longer holds, because the modern attack steals your data before it encrypts anything. The attacker gets in, exfiltrates your data, and then deploys the ransomware. Now they can encrypt your systems and threaten to publish or sell the data they already took — so a clean backup restores your operations but does nothing about the copy of your data sitting on the market. The clearest example is the DarkSide operation behind the Colonial Pipeline attack: it ran an affiliate program, a help desk, and negotiated ransoms like a business, because it was one.

This hits every sector, because every sector has something to monetize. Healthcare has patient data and operations. Finance has payment and account data. Tech has source code and customer data. And GovCon has CUI and contract data. No industry sits this one out.

AI Phishing: The Tells Are Gone

Sitting on top of the ransomware economy is the thing that has fundamentally changed how attackers get in the door: AI-generated phishing. For years, security training taught people to spot the signs — the email address with a number swapped for a letter, the generic non-personalized greeting, bad grammar, misspellings, a link that hovers to some strange URL. Train on those long enough and you could reliably catch a phishing email.

AI erased all of it. The phishing emails now look exactly like legitimate internal company communication — same style, same tone — because AI can go out, research the target, and tailor the message specifically to them. The signs we taught everyone to look for simply aren’t there anymore. And it goes a layer deeper with deepfake voice: synthetic audio that needs only about eight seconds of a person’s voice to clone them almost perfectly. It’s convincing enough that one of the only reliable tells left is listening for breathing — and no one is on a call analyzing whether the other person is breathing. IBM’s research found that roughly 16% of breaches now involve AI-driven attacks, and that number is only climbing.

Put the two together and you have a machine. AI phishing is the entry — cheaper, more convincing, and harder to catch — and ransomware-as-a-service is the payload. One feeds the other into a repeatable, industrialized extortion process that gets faster and more profitable every cycle.

The Three Things to Do About It

Because you can no longer trust your own eyes and ears, the defense can’t be human judgment — it has to be automated controls. Three marching orders apply to every organization, in every sector:

Enforce phishing-resistant MFA and verification protocols.

Multi-factor authentication with hardware keys, plus documented procedures so that high-value transactions require multiple approvers — and a process that confirms each approval is coming from an authorized, valid source rather than a cloned voice or a perfect-looking email.

Keep immutable, tested backups.

Backups an attacker can’t reach or encrypt, and a restore you’ve actually verified. This won’t stop stolen data from being sold — there’s little you can do about that once it’s taken — but it removes the operational hostage, so you’re not forced to pay ransom just to get your environment back.

Segment the network to shrink the blast radius.

Flat, legacy network architecture is why one foothold becomes a full-environment compromise. Segmentation is what contains an intrusion to a corner of the network instead of letting it spread everywhere.

CMMC: The Government’s Answer, and Where the Calendar Stands

For contractors in the defense space, the government’s response to this threat environment is CMMC — the Cybersecurity Maturity Model Certification, which took effect November 10, 2025 and rolls out in annual phases. Understanding which phase you’re standing in is the whole game.

Last year, under Phase 1, you could self-attest to Level 2 — simply declare that you had the 110 controls from NIST SP 800-171 in place. That era is ending. As of Phase 2, you can no longer self-attest to Level 2. You have to be certified by a C3PAO — a Certified Third-Party Assessment Organization — that conducts the audit and certifies you. There are only around 100 of them, listed on the DoD CIO website, and that scarcity is about to become a scheduling problem for the entire defense industrial base at once.

Level 2 applies to everyone who stores, processes, or transmits CUI — and this is where contractors get burned. If you’re a subcontractor on a contract that requires Level 2, you must be certified; your prime’s certification does not cover you. If you’re in a joint venture, both entities must be certified independently. “We’re just a sub” and “our partner is already certified” are two of the most expensive misconceptions in GovCon right now.

Why Level 3 Makes Level 2 Urgent

Here is the point of the whole episode. Level 3 — the Expert tier — arrives in Phase 3, November 2027. But you cannot get Level 3 without already holding Level 2. A Final Level 2 (C3PAO) certification is a hard prerequisite; you can’t even initiate a Level 3 assessment without it. So pushing off Level 2 doesn’t just delay Level 2 — it delays everything above it.

A few things every contractor should understand about Level 3:

  • It’s assessed by the government — specifically DIBCAC, the Defense Industrial Base Cybersecurity Assessment Center — not a private third party. That makes it substantially more rigorous.
  • It applies to a narrow subset: the DoD estimates fewer than 1,000 contractors will need it, for the most sensitive programs. The requirement will be stated explicitly in the solicitation, and you can ask the agency what criteria triggered it.
  • It’s expensive: a DoD-estimated $500,000 or more over three years depending on organization size, because it layers 24 additional NIST SP 800-172 controls on top of Level 2.

So the message isn’t “everyone needs Level 3.” Most contractors need Level 2. But everyone who might need Level 3 needs Level 2 first — and the timeline to get there is longer than it looks.

The Liability on the Signature

CMMC isn’t only technical — it’s legal, and it lands on a specific person. The program requires a senior official to sign an annual affirmation of continuous compliance in SPRS. That’s a named executive personally attesting the controls are real and operating.

Consider the trap the phased rollout creates. Last year, a contractor could self-attest Level 2 to bid on a contract. If that same contractor now can’t pass a C3PAO assessment for the Level 2 status they already claimed, that prior affirmation is retroactively suspect — which means potential False Claims Act liability, and the DOJ’s Civil Cyber-Fraud Initiative is built to pursue exactly this. Self-attesting to a posture you don’t actually hold isn’t just a lost contract; it’s a potential fraud claim against the person who signed. The verified C3PAO assessment is precisely what protects that executive from signing something they can’t back up. As Actual noted on the episode, this is the same “the executive whose name is on the document” pattern the show has traced through CMMC, the PowerSchool ruling, healthcare, and finance — the framework changes, but the personal accountability doesn’t.

Worth noting: the government is arguably playing catch-up here. The private sector has run this way for years — SOC 2 Type 1 is a point-in-time attestation, but serious buyers demand Type 2, which proves controls operate over time. CMMC’s shift from self-attestation to third-party certification is the same maturation, and the phased rollout is the runway the DoD is giving contractors to catch up to a standard the private sector already treats as table stakes.

The Marching Orders

Three actions every defense contractor should execute now:

Scope your CUI and run the gap assessment.

You can’t protect — or certify — what you haven’t scoped. Identify where CUI lives, then benchmark against the 110 NIST 800-171 controls to know exactly which are in place, which are operating effectively, and where the gaps are.

Book your C3PAO path now.

Once you know your gaps and your remediation strategy, get on a C3PAO calendar immediately. With only ~100 assessors and the whole DIB moving at once, you may wait six to eight months for a slot before the audit period even begins — and your certificate has to be valid at contract award.

Decide now whether Level 3 is in your future.

Level 2 is required for everyone, but it’s also the prerequisite for Level 3 — and Level 3 readiness can’t be stood up in six months. If your pipeline points toward the most sensitive programs, the planning starts now.

Ransomware-as-a-service and AI phishing are the prominent threats right now — cheaper to launch, harder to spot, industrialized to scale. For the defense industrial base, CMMC is the government’s answer, and the calendar is no longer theoretical. Level 2 is mandatory. Level 3 arrives in 2027. And there is no Level 3 without Level 2 first. Mission success starts with closing the gap between the threat and the framework — and between the affirmation you sign and the controls actually running on your network.

Go Deeper: The Certification Timeline

This episode explains why Level 2 has to happen now. Our companion Sitrep is how you actually get there — the operational certification timeline: how to scope your CUI to control cost, run the NIST 800-171 gap assessment, build a defensible POA&M without triggering the conditional-certification trap, and book a C3PAO before the queue closes. If this briefing gave you the strategic picture, the Sitrep gives you the step-by-step path.

Trust but verify your own posture. Scope your CUI. Run the gap assessment. Book your C3PAO path before the queue and the deadline close on you. Execute the standard.

// DECODED TRANSCRIPT

Access the full text logs of this transmission for compliance and review purposes.

SILENCE THE NOISE. AMPLIFY THE SIGNAL.

INTELLIGENCE IS USELESS IF YOU AREN'T LISTENING.

Join The Watch to receive New Episode Alerts, Strategic Breakdowns, and Guest Intel delivered to your inbox.