Stacy Bostjanick
December 2025
Chief, Defense Industrial Base Cybersecurity & Deputy CIO for Cybersecurity
DoW Office of the Chief Information Officer
Long-term government career spanning decades
Stacy Bostjanick serves as Chief for Defense Industrial Base Cybersecurity and Deputy Chief Information Officer for Cybersecurity within the DoD Office of the Chief Information Officer. As a Senior Executive Service leader, she is the primary authority responsible for leading and executing the Cybersecurity Maturity
Model Certification (CMMC) program across the Defense Industrial Base, ensuring consistent implementation and strengthening the cybersecurity posture of DoD partners handling sensitive information
The architect behind CMMC
Stacy Bostjanick played a pivotal role in creating the Cybersecurity Maturity Model Certification (CMMC)program from the ground up. After DoD IG and Navy Cyber Readiness assessments in 2018 revealed widespread noncompliance with cybersecurity requirements among defense contractors, she worked directly with Katie Arrington to address the crisis. Her work with experts at Carnegie Mellon University’s Software Engineering Institute and Johns Hopkins Applied Physics Laboratory helped establish the foundational framework that became CMMC.
Stacy Bostjanick’s government career spans decades across multiple defense and intelligence organizations, beginning with administrative roles and evolving into senior contracting and cybersecurity leadership positions.
Details available upon request
Appropriate for senior DoW role
Under Stacy Bostjanick’s leadership, the DoD has transformed from NIST 800-171 rev 2 to CMMC 2.0, simplifying compliance requirements from five levels to three. She introduced processes such as Plans of Action and Milestones (PoAMs) and conditional award statuses, successfully advocating for risk-based waivers when contractors face technological or resource constraints. Her approach balances security needs with program feasibility while maintaining stringent protection standards.
Stacy Bostjanick has been instrumental in developing creative solutions to help small businesses meet CMMC requirements without overwhelming their limited resources. Her leadership has driven multiple innovative approaches to cybersecurity compliance, including partnerships with cloud service providers and managed security providers.
Key initiatives:
Modernization programs: Leading DoD’s efforts to provide low-cost cybersecurity solutions and cloud-basedplatforms that enable small and medium businesses to participate in defense programs securely
Risk-based approach: Advocating for tailored cybersecurity requirements that assess program-specific vulnerabilities rather than applying one-size-fits-all solutions
Industry collaboration: Working extensively with cloud service providers to create scalable solutions that help contractors achieve compliance while maintaining operational efficiency
|
Attribute
46419_3d8b3b-7f>
|
Details
46419_aae6f3-a0>
|
|---|---|
|
Portfolio scope 46419_b6b30a-2e> |
Oversight of 220,000-300,000 companies in Defense Industrial Base 46419_7fbac8-68> |
|
CMMC Level 2 46419_45c2bc-b2> |
~880,000 companies handling Controlled Unclassified Information 46419_af97f9-01> |
|
CMMC Level 3 46419_a139b2-c9> |
~300,000 companies managing higher-sensitivity CUI 46419_4e1f42-cd> |
|
Key programs 46419_aae314-ed> |
F-35, F-22, Standard Missile 3, missile defense programs 46419_3dbafb-c8> |
|
Geographic reach 46419_dc9629-17> |
United States plus international allies (UK, Norway, France, Japan, Israel, Australia) 46419_4a871a-4f> |
|
Career focus 46419_60fc4d-85> |
Contracting, cybersecurity, supply chain risk management 46419_f87382-35> |
For contractors working with DoD or pursuing defense opportunities:
Stacy Bostjanick’s leadership signals major procurement shifts toward cybersecurity-first contracting. Her emphasis on CMMC compliance creates opportunities for cybersecurity service providers, cloud platforms, and managed security providers. The transition from five CMMC levels to three streamlines certification paths, while Plans of Action and Milestones (PoAMs) offer flexible compliance timelines for contractors.
Key contracting areas to watch:
Her risk-based waiver approach suggests DoD values practical cybersecurity solutions over rigid compliance frameworks. Contractors demonstrating innovative approaches to protecting sensitive defense data while maintaining program feasibility will find favor under her leadership.