Sorry to keep hammering on this. Almost every bit of CMMC is focused on the C in the CIA triad. Of course the burden is focused on protecting the gov’s data. That’s the point. It’s not keeping your machines running, it’s data doesn’t get stolen.
Davies: "What we found is that burdensome compliance requirements that are duplicative, that are focusing on confidentiality of the data rather than manufacturing or operational resiliency, are keeping innovators — and especially small businesses — out of [DIB] competition."