The $488K Parsing Problem

The $488K Parsing Problem
*The control chain is on every whiteboard. The traversal is in nobody's budget.*
—-
A few months ago, a CMMC practitioner cried on a call with a friend of mine.
Not because he'd failed an assessment. Not because he'd lost a contract. Because someone showed him that tools existed that could automate what he'd been doing by hand for over a year. He realized he might actually pass. On time. That his job – the one supporting his family – wasn't on the line anymore.
That's the part nobody puts in the compliance frameworks. The person. The one staring at 320 assessment objectives and a spreadsheet that hasn't been updated since last quarter, wondering if this is the week the whole thing falls apart.
I've spent 22 years in this space. I built the Unified Compliance Framework. I helped define OCIL, worked on SCAP, and sit on committees at NIST. I work with DCSA field agents. I came out of retirement specifically to solve this problem. And what I keep hearing – from 3PAOs, from RPOs, from the people actually conducting assessments – is the same thing, over and over.
The *data* is there. The frameworks exist. The mappings are documented. But organizations aren't implementing CMMC technical controls correctly.
Three reasons. Every time. They don't know about STIGs. They want to argue about whether STIGs are effective. Or they're trying to manually implement each XCCDF or JSON STIG file one at a time.
What a waste.
The Desire Everyone Shares
Every defense contractor in the supply chain wants the same thing. Win contracts. Prove security. Stay in the game.
CMMC Level 2 is the gatekeeper now. The 32 CFR Part 170 final rule, published October 2024, made that official (Department of Defense, 2024). Not a suggestion. Not a best practice. A condition of contract eligibility. And by October 2026, CMMC clauses become mandatory in all new DoD solicitations.
The path is supposed to be straightforward. CMMC Level 2 maps to 110 security requirements in NIST SP 800-171 (Ross et al., 2020). Those requirements trace to specific controls in NIST SP 800-53 Rev 5 – over 1,000 controls across 20 families (Joint Task Force, 2020). And those controls land as specific configuration settings in DISA's Security Technical Implementation Guides (DISA, 2025).
Four layers. Clean hierarchy. Every 3PAO I talk to can sketch it on a whiteboard from memory.
But the practitioner who cried? He wasn't confused about the hierarchy. He understood it perfectly. His problem was something else entirely.
The Obstacle Nobody Budgeted For
I was working with an organization recently – I can't name them, you just don't name folks who are failing CMMC audits – and I asked them to walk me through where they were stuck.
Their staff was spending an inordinate amount of time *understanding* which STIGs applied. Then figuring out *how to apply them*. Reading. Cross-referencing. Building internal documentation that would be outdated in 90 days when DISA dropped the next quarterly release (DISA Supplemental Automation Content, 2025).
Smart people doing dumb work.
I told them straight: you don't have a technical problem. You have a staffing problem. Your people are spending their time reading and understanding when they should be spending their time *deciding*. Deciding which paths to take for technical control implementations. Deciding where to accept risk. Deciding how to prioritize when you can't do everything at once.
But here's what most people don't want to hear. A huge chunk of organizations don't misunderstand STIGs.
They skip them entirely.
Just... ignore them. Then they're shocked when the 3PAO shows up and the technical controls aren't there. Sundararajan, Ghodousi, and Dietz (2022) analyzed 127 DoD contractors pursuing CMMC and found the same control deficiencies showing up over and over. Not because the controls are conceptually hard. Because the mapping between "what CMMC requires" and "what to actually configure on a system" is a manual process that breaks down at scale.
And the cost numbers prove it. Atlantic Digital's 2025 framework projects $487,970 over three years for a small defense contractor (Atlantic Digital, 2025). Kiteworks puts the range at $30,000 to $150,000 depending on starting maturity (Kiteworks, 2025). Wide spread. Same cost driver across every analysis.
Labor.
Not technology. Not the C3PAO assessment fee. Labor. Someone maps the requirements. Someone finds the right STIG. Someone verifies the settings. Someone does it again in 90 days. And someone does it *again* when NIST updates 800-171 from Rev 2 to Rev 3 – which just happened – and every mapping in the organization shifts (NIST, 2024).
That practitioner who cried? His labor. His late nights. His stress about whether he'd have a job next quarter. That's where the $488K goes.
The Battle That's Already Started
The problem doesn't hit once. It compounds. Every quarter.
DISA releases new STIG versions four times a year. Each release can change hundreds of configuration settings across dozens of products. And here's the part that should make every GRC vendor uncomfortable: every organization, every scanning tool, every compliance platform that consumes STIG data has to absorb those changes independently.
ComplianceAsCode – the open-source project behind most STIG automation – achieves 92% coverage of STIG controls (ComplianceAsCode, 2011-present). Red Hat maintains it for RHEL (Red Hat, 2023). The community maintains it for everything else. Anchore reviewed eight STIG compliance tools in 2026 – SCC, Evaluate-STIG, MITRE SAF, OpenSCAP – and every single one implements its own STIG data parser (Anchore, 2026).
Nine tools. Nine parsers. Same data. Every quarter.
That's not a tooling problem. That's an architecture problem. And I've been staring at it long enough to know exactly where the missing piece is.
I helped build SCAP. I was in the room when we defined OCIL. I understand – at the protocol level – how STIG data is structured. NISTIR 7343 laid out the Security Content Automation Protocol back in 2007 (Waltermire et al., 2007). The format is technically machine-readable.
But there's a canyon between "machine-readable format" and "live, queryable service."
STIG data today lives in ZIP archives on cyber.mil. XML files in XCCDF format. Benchmarks in SCAP bundles. Every CI/CD pipeline that needs to validate STIG compliance downloads a ZIP, parses the XML, extracts the rules, and maps them to its own internal model. Every GRC platform that claims STIG coverage did that same thing once – then hired a team to maintain it. Every small contractor who can't afford a GRC platform opens STIG Viewer and does it by hand.
The "compliance multiplier" that Cimcor describes – where one hardening effort satisfies CMMC, PCI DSS, SOC 2, and HIPAA simultaneously (Cimcor, 2024) – only works if you can programmatically map between frameworks. If you can query "which STIG settings satisfy both CMMC AC.L2-3.1.1 and PCI DSS Requirement 7?" and get an answer in milliseconds.
Right now, that query takes a consultant and a week.
Multiple GRC vendors *could* solve this. They could present compliance paths instead of raw data. They could absorb quarterly updates automatically instead of manually rebuilding parsers. They could eliminate the reading-and-understanding phase entirely, letting practitioners skip straight to deciding.
They could. If they had a STIG data layer to build on.
The Decision You're Already Making
DoDI 8510.01 mandates the Risk Management Framework for all DoD IT systems, with STIGs as the primary technical implementation mechanism (DoD CIO, 2022). Therrien and Hastings (2026) found significant inconsistencies in how CMMC assessors sample evidence – partly because the mapping between requirements and technical controls isn't standardized at the data level.
The chain is documented. The law is in place. The tools exist in fragments.
What's missing is the infrastructure underneath all of it.
I think about that practitioner a lot. The one who cried. He didn't need a better framework. He didn't need another PDF. He didn't need a more expensive consultant. He needed his tools to present him with *paths* – here are the STIG settings that satisfy your CMMC requirements, here are your options, now *decide*.
That infrastructure is being built right now. At STIGViewer.com.
But here's the thing about infrastructure shifts: they don't wait for everyone to be ready. The organizations automating STIG compliance today are already reporting 70-90% effort reductions and compressing their timelines from 6-12 months to around 100 days (SteelCloud, 2026). The ones still doing it by hand are watching October 2026 get closer while their spreadsheets get further behind.
The question isn't whether the data layer gets built. The question is whether your organization finds it before your competitor does – and before the deadline makes the decision for you.
Because every contract clause, every tightened assessment requirement, every vendor that builds STIG automation into their core offering – they're all voting on the same outcome. And the result is already visible.
You can participate in that shift. Or you can explain to your contracts team why you're still doing gap assessments by hand while your competitors are shipping continuous evidence streams.
Which story do you want to tell?
—-
*Dorian is the founder of MoxyWolf LLC and creator of the Unified Compliance Framework. He helped define SCAP and OCIL, serves on NIST committees, and works with DCSA field agents. He came out of retirement because this problem wasn't going to solve itself. Visit STIGViewer.com to see what's next.*
—-
References
Anchore. "8 Best STIG Compliance Tools 2026: Automate RMF & Audits." *Anchore Blog*, 2026. https://anchore.com/blog/top-stig-compliance-tools/.
Atlantic Digital. "Updated 2025 Cost Framework for CMMC Level 2 Compliance." *Atlantic Digital*, 2025. https://www.adiit.com/cmmc-level-2-cost-framework-2025/.
Cimcor. "The Compliance Multiplier: Hardening with CIS & STIGs Drives Adherence to PCI, SOC 2, CMMC & More." *Cimcor Blog*, 2024. https://www.cimcor.com/blog/the-compliance-multiplier.
Department of Defense. "32 CFR Part 170: Cybersecurity Maturity Model Certification (CMMC) Program; Final Rule." *Federal Register*, October 15, 2024. https://www.federalregister.gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-certification-cmmc-program.
Defense Information Systems Agency (DISA). "DISA STIG Library and SRG Downloads." 2025. https://public.cyber.mil/stigs/downloads/.
Defense Information Systems Agency (DISA). "Supplemental Automation Content (SAC)." 2025. https://public.cyber.mil/stigs/supplemental-automation-content/.
DoD CIO. "DoDI 8510.01: Risk Management Framework for DoD Information Technology." *DoD Issuances*, 2022. https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/851001p.pdf.
Joint Task Force. "Security and Privacy Controls for Information Systems and Organizations." NIST SP 800-53, Rev. 5. *NIST Special Publication*, 2020. https://doi.org/10.6028/NIST.SP.800-53r5.
Kiteworks. "The True Cost of CMMC Compliance: Complete Budget Guide." *Kiteworks*, 2025. https://www.kiteworks.com/cmmc-compliance/compliance-costs/.
MindPoint Group. "STIG vs CIS: Selecting the Best Baseline for Your Business." *MindPoint Group Blog*, 2023. https://www.mindpointgroup.com/blog/stig-vs-cis-part-2-selecting-the-best-baseline-for-your-business.
Red Hat. "Automating Security Compliance with Ease." *Red Hat Blog*, 2023. https://www.redhat.com/en/blog/automating-security-compliance-ease.
Red Hat, NSA, and DISA contributors. "ComplianceAsCode / SCAP Security Guide." GitHub, 2011–present. https://github.com/ComplianceAsCode/content.
Ross, Ron, et al. "Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations." NIST SP 800-171, Rev. 2. *NIST Special Publication*, 2020. https://doi.org/10.6028/NIST.SP.800-171r2.
Ross, Ron, et al. "Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations." NIST SP 800-171, Rev. 3. *NIST Special Publication*, 2024. https://doi.org/10.6028/NIST.SP.800-171r3.
SteelCloud. "STIG & CMMC Control Matrix for Windows 10." *SteelCloud Whitepaper*, June 2020. https://www.steelcloud.com/wp-content/uploads/STIG-and-CMMC-Control-Matrix-for-WINDOWS-10-June-2020.pdf.
SteelCloud. "The Unified Automation Advantage for 2026 Cyber Readiness." *SteelCloud Whitepaper*, 2026. https://www.steelcloud.com/wp-content/uploads/WP-CyberReadiness2026-01.05.26OL-PP.pdf.
Sundararajan, Vijay, Arman Ghodousi, and Jason E. Dietz. "The Most Common Control Deficiencies in CMMC Non-Compliant DoD Contractors." In *2022 IEEE International Symposium on Technologies for Homeland Security (HST)*, 2022. https://doi.org/10.1109/HST56032.2022.10025445.
Therrien, Logan, and John D. Hastings. "The Need for Standardized Evidence Sampling in CMMC Assessments: A Survey-Based Analysis of Assessor Practices." *arXiv preprint*, 2026. https://arxiv.org/abs/2602.09905.
Waltermire, David, et al. "Security Content Automation Protocol (SCAP)." NISTIR 7343. *NIST Internal Report*, 2007. https://csrc.nist.gov/CSRC/media/Projects/Security-Content-Automation-Protocol/documents/docs/scap-nistir-7343.pdf.