TroutTrout
Back to Glossary
DIBDefense industrial baseDefense supply chain

Defense Industrial Base

3 min read

The Defense Industrial Base (DIB) is the worldwide network of private companies that research, develop, produce, deliver, and maintain military weapons systems, subsystems, and components for the U.S. military. It spans large prime contractors down to the small machine shops that make a single part. The Department of Defense counts it as one of the 16 critical infrastructure sectors, and it is a standing target for foreign cyber espionage aimed at stealing designs and disrupting supply.

Who is part of the Defense Industrial Base?

More than 200,000 companies, from the primes like Lockheed Martin, RTX, and General Dynamics to the second- and third-tier suppliers and subcontractors beneath them. Most are small businesses. That long tail is the point of most concern: a subcontractor with weak security can expose the Controlled Unclassified Information (CUI) that flows down the chain, and attackers know to aim there rather than at the well-defended primes.

Why is the DIB a cybersecurity focus?

Because the payoff for an attacker is high and the surface is wide. The information is sensitive, the number of stakeholders is large, and many suppliers run older operational technology on the shop floor next to the IT systems that hold contract data. When those two networks converge without segmentation, a foothold in email or a workstation can reach the machines that make the parts. Years of breaches, from the F-35 design theft to the SolarWinds supply chain compromise, have kept the DIB near the top of the threat list.

What standards apply to the Defense Industrial Base?

The core requirement is NIST SP 800-171, which sets the controls for protecting CUI in non-federal systems, made contractual through DFARS clause 252.204-7012. On top of it, the Cybersecurity Maturity Model Certification (CMMC) adds third-party assessment so contractors have to prove the controls are in place, not just self-attest. Suppliers handling OT also map to IEC 62443 for their industrial control systems.

How is CMMC different from NIST 800-171 for the DIB?

NIST 800-171 is the list of 110 controls. CMMC is how the DoD verifies you actually meet them. Under the old model, a contractor self-attested to 800-171 compliance. CMMC Level 2 requires an assessment by a certified third party (a C3PAO) before award on contracts involving CUI. Same controls underneath, higher bar of proof.

Related terms