Understanding the 'Class Deviation' and What it Means for CMMC Compliance
Climbing Mount CMMCSeptember 10, 2026x
21
01:01:0542 MB

Understanding the 'Class Deviation' and What it Means for CMMC Compliance

In this episode of Climbing Mount CMMC, hosts Kaleigh Floyd and Bobby Guerra welcome back Koren Wise from Wise Technical Innovations. The conversation delves into the latest developments surrounding the CMMC program, particularly the recent class deviation affecting contractors. Class Deviation: https://media.licdn.com/dms/document/media/v2/D561FAQGSCWrODbSmhA/feedshare-document-url-metadata-scrapper-pdf/B56aCGfVqAI8A4-/0/1788962760218?e=1789581600&v=beta&t=fLrdB7f9FoKMQJuaLxv3guuCih4...

In this episode of Climbing Mount CMMC, hosts Kaleigh Floyd and Bobby Guerra welcome back Koren Wise from Wise Technical Innovations. The conversation delves into the latest developments surrounding the CMMC program, particularly the recent class deviation affecting contractors.

Class Deviation: https://media.licdn.com/dms/document/media/v2/D561FAQGSCWrODbSmhA/feedshare-document-url-metadata-scrapper-pdf/B56aCGfVqAI8A4-/0/1788962760218?e=1789581600&v=beta&t=fLrdB7f9FoKMQJuaLxv3guuCih4B5M8Dp4DlPgARP68

CUI Categories and Abbreviations: https://www.dodcui.mil/CUI-Categories-and-Abbreviations/

Follow Koren on Linkedln: https://www.linkedin.com/in/koren-wise/


Website: https://www.axiom.tech/
YouTube: https://www.youtube.com/channel/UCaJagoDasNG3MqLqw2Af_ZQ

Axiom's LinkedIn: https://www.linkedin.com/company/axiomtech/

Bobby's LinkedIn: https://www.linkedin.com/in/bobbyguerra/

Kaleigh's LinkedIn: https://www.linkedin.com/in/kaleigh-floyd-079a52190/

[00:00:00] Hello, climbers, and welcome back to another episode of Climbing Mount CMMC, the podcast. My name is Kaylee Floyd, and I'm here with Bobby Guerra, but we also have a special guest today with us, Corinne Wise. Corinne is a part of Wise Technical Innovations, Zara's C3PAO, and a training provider for CMMC, and we are thrilled to have her. Corinne, thank you so much for taking the time to be with us today. Thank you for having me. Oh, of course. It's always a pleasure.

[00:00:27] And you actually got to meet the Honorable Ms. Davies in person to talk about this, too. So, I mean, that's... I did. It was an honor to meet the Honorable Ms. Davies. So, yeah, hopefully we can sprinkle a little bit of that conversation into today as we go to talk, so. Yeah, so for many of you guys that are listening to this, I bet you're probably in the ecosystem and have seen this already a bunch on LinkedIn.

[00:00:53] But what we wanted to talk about today is the class deviation that did come out. Mentioning a few different things in it, but the big heavy hitter is the circling back to the pause of CMMC Phase 1 and suspension of Phase 2, which was already discussed by the Honorable Ms. Davies and the DOD CIO in their memo that recently came out as well. And we were in a 60-day review.

[00:01:22] And that is... Is it done yet? It's almost done. Is it almost done, right? You have a few more days of that 60 days? I think the 11th is the actual 60-day mark. So, as of when we're reading this, then that's tomorrow, huh? Yeah. So, I don't know if they're going to release anything tomorrow, but... Okay. Well, there was a lot of meetings, a lot of discussions with small businesses, communities.

[00:01:45] I know I even sat in on a discussion that the DOD CIO had with... It was ISACA, I think, even had one too. So, there was a few different conversations that they were having throughout the community to kind of get the impact of CMMC, C3PAOs, NIST 800-171 controls, all different types of things.

[00:02:08] And they even had the RFI that you were able to respond to. Obviously, it's closed now, but you were able to respond to that with your opinions. And so, you know, we're just going to talk about what the... Basically, the newest document, which, you know, which just came out, implies with the rest of what is going on. I know there's really a lot that's kind of hit us, but also kind of a lot of vagueness of what's going to happen next. So, we're going to talk about a lot of that today.

[00:02:37] Should we all, like, raise our hand and not claim CMMC Jesus before we start? You know, so people don't, like... Yeah, we're not confessing that we know everything that's happening. It's very hard for anybody to be right right now. It's quite difficult. So, again, this is just our interpretations of what has happened so far. And the true fears that I, you know, what's wonderful to see is that we are an MSP that has it from a different perspective as well as Corinne has from another perspective.

[00:03:07] And we're getting real-world scenarios of what's happening with all of us right now. So, really, we're just going to share our perspectives, what we heard, and go from there. And, yeah, let's get started and talk about that, Bobby. Did you want to open up and start the discussion with that? The thing is kind of the first salvo of this sort of transition, and I think Corinne probably would agree, is like we were just, we were all kind of caught flat-footed by the memo that Ms. Davies released back in July. Everybody was like, what?

[00:03:35] And it basically said, we're pausing the CMMC program, and we're doing it until further notice, and we're going to hunker down in phase one. So, for those that may not know, phase one basically allows for self-attestation. So, you can either, and they basically put them in contracts, and they'll require you to go on under, you know, threat of perjury that you have to attest that you're doing the DFAR clauses that are required in your contracts.

[00:04:00] And at that point, you submit it into your SPRS system, which Corinne does a wonderful thing every Friday-ish, every other Friday. Is that right, Corinne? Yeah, I do it when I can, but it's always on a Friday. Always on a Friday. And I always advertise on LinkedIn and send out a reminder. She does a great class about just explaining how SPRS sort of works and how you use it. And it can be a bit of an enigma if you're not used to it, but that's where you're supposed to go. You go in there, and you put in there.

[00:04:24] So, if you haven't ever done SPRS and you know that you're going to have to do your phase one, sit in on Corinne's class, hit her on that, because that'll be very helpful, because you want to make sure, because there's lots of things where you could go. You could go to the NIST tab, which would not be where you're going to do that if you're doing the test station piece. So, she'll cover that in the class, which is very, very helpful. So, that's the memo. And we all sort of talked in our previous podcast, which maybe we might link, maybe we might not. And we said, this memo is not effective enough. They're either going to have to do some type of class deviation or walk back the memo.

[00:04:52] But, you know, it's not going to be authoritative. And then we have the deviation where they just basically effectively pointed right to the memo and said this and incorporated it. And then that really charges everybody more from official perspective. And so, I think that kind of sets the stage of there. But you, Corinne, had mentioned that there were some wording that concerned you as well. So, maybe you can kind of talk more about your thoughts in that as well.

[00:05:22] Yeah. I mean, you know, I think yesterday we had a lot of activity related to this deviation, even though, you know, folks were making it abundantly clear that the deviation actually, in its second version, Rev. 2, came out three days after the memo. So, the memo came out on 13th, deviation on the 16th. And yesterday, there was an update to that deviation.

[00:05:44] But what I think a lot of folks may not have understood is nothing changed from the one that was put out on the 16th to the one that was published yesterday related to CMMC. That's an 83-page deviation, which deals with many, many more things than just CMMC. It has, I mean, the things that changed were related to semiconductors, employee restrictions, Chinese military company definition, all these things that have nothing to do with CMMC.

[00:06:11] So, the deviation update yesterday had nothing to do with CMMC. And that's fine and great. But I think a lot of people never realized that it became a deviation at all. So, that flew under many, many folks' radar. And yesterday was the first time a lot of people became aware that it went from memo to deviation at all. And I think that's why we got the shock, the scaredness. They thought it was something new. They thought it was a result of the task force. It was not at all. It was not related.

[00:06:40] The task force is still working. And that was completely unrelated to any of those events. But with that said, you know, why a memo becomes a deviation is another great question. For example, if you take the FedRAMP equivalency memo, that didn't become a deviation. And this is a great comparison. The memo about FedRAMP equivalency versus the memo about the CMMC to pause. What's the difference and why did one get entered into a deviation?

[00:07:08] And the answer is because one conflicts and actually affects the DFARS clauses. The equivalency memo does not. It expands on an already existing concept in a DFARS clause 252-204-7012 and says, hey, just to clarify, this is what we mean. So, they didn't have to create or inject that into some official deviation.

[00:07:31] However, the memo severely conflicts with current, you know, codified code of federal regulation. And so, that's why it goes straight to a deviation from the 13th to the 16th. But I think you were mentioning earlier, Bobby, the word deviation is scary. It feels, and this was what my post was about, it feels very concrete and it feels very permanent. And words matter. So, one of the things we always worry about with this is things getting lost in translation like the telephone game.

[00:08:00] You know, whoever's writing that, do they understand how much the word permit versus require is a huge difference. And I'd like to expand on, you know, later on when we get into it, why the word permit could be so dangerous as opposed to the word required. And there's a little bit of a loophole going on right now that if not dealt with soon, they'll begin to realize, oh, we got a problem here.

[00:08:26] So, the loophole that it creates, you have to go back to 7019, which was before the CMMC program and said, you know, you must, you know, if you have this clause, you must self-assess and you must enter the results in the SPRS system under the 800-171 assessments tab.

[00:08:45] And then we got the notice that that was going, I think that was another deviation, that 7019 is going to, its use is discontinued and replaced by 252-204-7025. The provision, by the way, 7019 was a provision, not a clause. The provision that replaced it is our famous 7025 CMMC clause with the most important blank that there is. And that blank says, in order to win this work, you're going to have to be CMMC level one. Going to have to be CMMC level two self.

[00:09:15] Going to have to be CMMC level two third party assessed and certified in order to win. And we're always looking for that blank as DOW contractors. What's it going to say? What's it going to say? Well, because they are saying that contracting officers may or can or are permitted to put a level two self-assessment requirement on a CUI contract that involves data that needs it, it leaves the possibility for contracts involving controlled and classified information to not have it at all.

[00:09:45] And I guess you could say that was true of 7019, but that means like somebody was blasting this all over LinkedIn yesterday and they're actually right. There, no one needs to be entering or, and lawyers are going to tell people, hey, don't enter your SPRS score unless you've got that provision that's telling you you have to do it. Because nothing else is driving you to do that other than this provision.

[00:10:07] And some people would say, oh, there's 252, 204, 70, 24, which was a different thing that came out years ago that said, hey, contracting officers or users of the SPRS system that are government users, you can now include the SPRS cyber score among many other factors that you're considering in competitive award. And you might be looking at past performance and cost and this and that.

[00:10:34] And it said, you can also consider this SPRS cyber score as well. And, but it still doesn't say you must require, that's not going to require people to enter a SPRS cyber score. That was written to the acquisition officer and what they can consider and what the SPRS system is used for, blah, blah, blah.

[00:10:55] So the loophole is that I think you're going to find folks are advised not to enter their SPRS score unless required to do so, which would happen with the self-assessment requirement. And if they're saying you may, but you don't have to, well, that's the loophole. Yeah, and me not being an attorney, I do see that and I look at those and it does make me raise my eyebrow.

[00:11:17] And I think looking to see how the different agencies inside the DOW, right, how they start to interpret that could be, like you said, different. They might look at it and say, oh, I think I have flexibility here. And then they make a decision one way and then they look at it and say, well, I don't.

[00:11:36] I think the one area where they could potentially correct that, Corinne, would be when they send the actual orders down from the class deviation, how that's going to go through that provisioning. Like, you know what I mean? Because it like doesn't it does that you have the deviation and then they then they put something in to kind of like put more official guidance beyond to the contracting officers.

[00:11:58] Right. Is that I think there's some additional comms that come down and perhaps maybe they might provide clarity there that it still has to be in alignment with with the phase one. Maybe they don't and let people choose. They need to. Yeah, I don't. The requirements are still there. Don't get me wrong. I'm not saying like we all know you have to comply with 7012. But the big driver and the scary part of that is a testing that you did so. And that testament is is being undervalued.

[00:12:24] But yeah, the CMMC program, in case anyone's not known this and you lived on a rock, is just to validate you've been doing it all along. The CMMC program is not the actual framework that you have. That is not the compliance. 7012 is the DFAR clause that you have in your contract that says you have to be doing this. CMMC is just validating that you are whether you're self-attesting or you're having a third party test that. So a lot of people conflate or confuse those two together, like thinking somehow they're related. They're they are different things.

[00:13:22] Yeah. That you're needing to validate. But I'm so glad, Corinne, that you brought up the difference between like and how words matter. Because to me, when I first read it, I was kind of just thinking, you know, logically in my brain, I was like, oh, well, this is similar to, you know, they can't say you have to have level one or you have to have level two self. It depends on what the contracting officer thinks that this contract will need.

[00:13:50] And that's why there's a blank and there's not something specific in that in that sentence is because they have to pick, you know. So it's like basically saying they're permitting like, OK, you know, you can pick what is what is needed. But what you're saying is a very interesting perspective where if somebody is going to have an opportunity for a loophole that they can get around something and use it to their advantage, they probably will in a negative way. You know, which is which is a scary thought. And you don't want to give that opportunity.

[00:14:19] I mean, the contracting officer wants to put that requirement in there when they can. Right. So I'm not saying they would ever not want to. But, you know, if you have COI on a contract and you have 7012 and you have the requirement to protect it, the natural minimum standard for the provision 252-204-7025, I would think should be. And this is where they were headed in the phase rollout.

[00:14:46] It's got to have at least a CMMC level two self-assessment requirement. And I. Right. Well, you're exactly right. That is what they meant. They meant what you said, but it doesn't it may not be interpreted that way. Yeah. And they meant it exactly like that. And that's what Joy Beeland was commenting on my post. Like, hey, all they meant was this. And I'm like, yeah, I get it. You know, you're right. That is what they meant. But it's not. You got to be super clear here and you got to follow the words that were, you know, originally there.

[00:15:15] Well, and then you have the guidelines and a memo they did before Miss Davies took office, if I remember correctly, that kind of defined. If you have this type of CUI that said you have to you have to go ahead and start controlling it. That was a memo. I can't man. I can't remember the exact one, but it provided some clarity. I can write that down. We have it in his memo. Yeah. Yeah. And it went through and defined those and said, hey, look, you know, you have this. Guess what? That's going to hit that provision. You have to make those decisions based on that.

[00:15:43] And so I think the line is very clear from the path. It says this there's a precedence to say very clearly what they meant. But again, Corinne, like you're right, is like, but could that be a situation where they they do what they they're hoping versus what they think? You're bringing up such a great point when you bring up that other memo, because did did the folks who wrote this memo and then put it into a deviation? Do they even know about that other memo?

[00:16:13] Is it lost in and nobody everybody forgot about it or because really, if you bring that memo and put it side by side and plug it into an AI and say, hey, look at this memo deviation and then look at this memo. Should they have written this deviation a bit differently since this memo is here? You know, I think it would say, yeah, they probably should have written that a little different. Yeah.

[00:16:37] Does the DOD CIO have a CRM like, you know, like Monday.com that they put all their info in so they can cross reference back to the other? I don't know. I don't know the answer to that. Yeah. They need one of those stat people you see in baseball. It's like, oh, this person took this many bases and they need to have a person always there that they can go back to. Yeah. Is there anything that we did over the past that happened when I wasn't here important? Well, you're bringing up a funny but sorry. You say.

[00:17:06] A funny but important point that you're you both are touching on right now. The scariest part of all of this is the talented folks with the historical information that is extremely important. Some of them are leaving or they're not being listened to. And this is the most scary thing about what is occurring right now is this tradition, these lessons learned.

[00:17:35] To ignore them is like ignoring the elderly wisdom of your, you know, ancestors who already went through all the pain. And that's why they're passing this information on to you. I worry that, you know, with James Galooly leaving and just really smart folks either being displaced or leaving, are we missing some critical pieces of information when things like this are written? I think it's going to.

[00:18:04] I think, yes. I think I think that is. I think there's perhaps some belief. I got this. Hold my beer kind of idea towards some of it. I know that's a loose translation, but I think some of that's probably going to happen. And I think we'll we'll get a good idea when they give us the report of what they did. You know, are they going to listen to people that are in there swinging? And if they're going to make some changes, are they going to make the changes that we suggest? Are they going to be like, oh, that's cool.

[00:18:28] I'm going to follow that right in the waste bin and then go ahead and do what we want to do, not based on any of the suggestions that anybody's made during those listening sessions. I know they did one at like Black Hat, I think, or something. Or Wild West Hackathon or something. They did one over there. I think they did a few others. Then they did one at the ISACA, which was the one that we were able to attend. And it was great. I felt heard. But I think really the reality is hearing and acting could be two different things.

[00:18:57] And I hope that that's not the case. I hope they do. There were so many great suggestions people had. I mean, a lot. Some that I had not even thought of. And I was like, gosh, man, if they could just implement this. But they would really juice up the program in a way, in a very positive way that could make, you know, they're like nuke Phipps. You know, like many people are like, yes, kill it like the dog it is. I mean, like so many people were cheering about that one. Like, you know, don't make G-code CUI. You know, things like that. Like if you could like clearly define that's not the case.

[00:19:26] There's a lot of boundary options that you could explore then. Things like that. I mean, just stuff if they could just provide clarity or just kind of let off the gas and some of that. And it would make a significant difference in the ecosystem being easier to adopt. And yeah. So let's transition if we can to I think what this is going to impact into the ecosystem. Mm hmm.

[00:19:52] And first off, I'd like to hear, Corinne, from you, if you don't mind, about how you think this is going to impact being being under the consideration that since they put it in a class deviation, that's not just go down the street and get some milk real quick kind of thing. They're putting it into class deviation because it's going to be substantial. It's going to be some type of time frame. And it's going to be more than, you know, months. It's going to be probably perhaps years for that pause process.

[00:20:22] What is that going to impact on the C-3PO since you're a C-3PO? And how do you think that's going to affect the teaching organizations, in your opinion, and what's your opinion about? You know, it's so hard to predict right now because what we're seeing, to me, doesn't make a whole lot of sense, right? And there's a lot of inconsistent messaging going on.

[00:20:49] So you mentioned the different listening sessions, and there's one right now happening at a different conference. But one thing that everyone says is the message is extremely inconsistent. So we started with a concern for small businesses. We don't hear a whole lot about that. And it doesn't make a whole lot of sense with the other concerns how they're going to bring these things together. And so that part is confusing.

[00:21:20] And how does the ecosystem survive if the worst-case scenario happens is what you're asking. So let's just say that the deviation did not change. And by the way, I think they have a tremendous amount of information to go through. So I'm not sure if we'll hear anything, you know, soon. Because hopefully they're doing the responsible thing and going through all of it. And I don't know how hard it is to reverse a deviation.

[00:21:49] Probably not that hard if they wanted to. But what is hard to reverse is they went and had a bunch of contracting officers remove stuff from contracts. What a major pain in the butt, right? And so they've inconvenienced a lot of folks. They've confused a lot of folks. And now they've got inertia. They were all headed in this direction. And they went, okay, now go in this direction.

[00:22:16] So now everybody's like slowly speeding up their car going in this other direction. I just can't see them saying, okay, now immediately go back in the other direction. Stop your car again and now go this way again. I just don't see her doing that politically, right? Because she has now been in that deviation. One of the most forceful things that's being done is this language that says, get every last trace of C-3PO. The word is a curse word. Get it out of all contracts right now, right?

[00:22:45] That's how we feel anyway. I know she doesn't mean it that way. But it's like, we don't want any remnant of that anywhere. Get it out of there for now until we figure out what we're going to do here. To reverse that, that is the part why we're going to be stuck here for a while. So I think we could see some give and take here where Miss Davies is out there listening and she has learned so much about the community. I hope that it, and she appears to be super receptive to it.

[00:23:15] She appears to be very interested in learning. That is the positive thing. And so maybe she keeps that one thing going the way it is where no new requirements are inserted. But she, again, advocates for the importance of a third-party assessment and confirms that, indeed, it will be back on this date, whether that is six months from now, two years from now. That would allow the ecosystem to have something to work towards, to understand.

[00:23:45] It would allow ISACA to say, okay, this is our plan. It would allow everybody to plan, right? Right now, I think ISACA said they're pausing all movement, right? They made that announcement because they have no idea what they're moving towards. And we've got a pause in general on the program. I mean, accreditation is affected by this, although they say just keep moving on, keep getting accredited. C3PAOs are scared to go get, I'm scared. I need to go pay my bill right now and start accreditation immediately.

[00:24:15] And yet, I'm not because what if I put down $35,000 and tomorrow the news is not so great? It is a very scary thing to know that I need to get in line immediately. I don't know, I don't expect them to understand what the timelines are like for C3PAOs or the amount of work it takes to get accredited or the 27 months that's written into the rule that we have to be accredited by. And I know nobody wants to hear the sob stories of the C3PAOs,

[00:24:44] but it's not as easy as everyone thinks. I disagree. I think you need to share that, Corinne, because nobody talks about that. And it's like everybody just assumes that C3PAOs are just this thing that magically has all the understandings. Like you didn't come up with C3PAO. You're like, Corinne, you didn't think, wake up one day and say, let me steal contractors' money and just come up with this thing called C3PAO. And I'm just going to make it and just like make millions. Like, no, it was literally created and designed

[00:25:13] and told for us to do by the same people that went and took it away. And so it is so conflicting. And I think your voice should be heard. I think these people's voices should be heard because they heard the calling that the government needed, took the time and effort and did it right to try to work hard and get these things validated, which is what the government wanted, was validation of these things happening.

[00:25:43] And they weren't happening. That's why there was so many false starts and things not happening because they weren't happening. And it was pushing it to happen. So it's so, so needed. And even like what you were saying, Honorable Kirsten Davies, like Ms. Davies was saying that third-party assessments are very important. Like even herself, she said that, you know? And so it is so needed. And I think many people underestimate like why C3 PAOs exist and the reason that the people are doing it,

[00:26:13] you know, and how hard it is to do that. Exactly. And it's one of the biggest misunderstandings when I visited with, at the Pentagon with the DOD-CIO, I would say that my, if I were to say there was one misunderstanding that still prevails, it's the misunderstanding of what an assessment involves and how unbelievably effective and deep it is and how difficult it is, as it should be, because you are trying to keep bad people from stealing data. And so she'll, let me first address the part about being a C3 PAO.

[00:26:43] Many C3 PAOs have not yet been able to reap the business rewards of becoming one because it takes so much investment time, money to become one. And so some of them are even having to work out and thank God the cyber AB has been super generous in just, I won't say generous because I know that everyone's gonna be like, generous, they make a killing, but they've been flexible. Let's say that's a better word.

[00:27:11] They've been flexible trying to work with C3 PAOs who just became C3 PAOs, never got to get the ball rolling, aren't stable and strong financially yet because it takes so much money to become one. And so, yes, you're exactly right. I became a C3 PAO. I was doing great with the MVP enclave, great with training, but there was a calling every single meeting, every single town hall, we come, you know, try to be a C3 PAO, partake, you know, meet the need. And I was like, you know, I can definitely do this.

[00:27:41] So that's how that happened. But one of the misunderstandings on the part of many is what's in a CCP class, what's in a CCA class, and what's in an assessment. Anyone who's been through one that was done properly will tell you that, you know, I've never been part of something more meaningful where the before and after effect is so grand. I mean, it's unbelievable when we first meet companies and they want to get assessed

[00:28:08] the violations in the state that they're in when it comes to securing this data and they are wanting to fix that. They're stressed out about it and maybe they're not ready for assessment. They go get help, come back. They go through the rigorous process of assessment, which they seem to think, the DOW CIO seems to think that AI penetration testing and automated processes could match. It is not possible. It is not possible for them to see some of the things that we're seeing,

[00:28:38] detecting, writing up, putting in the findings. They're having to correct. They're having to poem. There's no way any of the, those tools are awesome. Don't get me wrong. I'm a pen. I, you know, that is my, where my history comes from is in all of that is finding weaknesses, investigating theft, all that stuff. But there's a place for those things, but there are places they're never going to get. They'll never be able to get to. The assessment covers 14 domains and they will get to the part that has to do with vulnerabilities,

[00:29:08] risks, open doors, open ports, open services, open protocols. They will be able to see all of that. They will not be able to get into the part that shows a very jacked up process that leaves the company extremely vulnerable to insider threat or that, you know, there's tremendous problems with authorization, which in the AC domain, you know, the way that they assign roles, groups, permissions,

[00:29:37] privileged users, the AC domain is all about insider threat. And then a lot of folks don't realize that. So there's a huge misunderstanding about the technical depth of this assessment. And Bobby, you know better than anybody. And Kaylee, you know better than anybody being on the other side of the table. I think you could speak to that. Yeah, I think part of the, you know, if we could just go back a little bit in time and look at how we got to this point from the perspective of the DOW at the time created a very aggressive timeline from when they said

[00:30:07] the CMMC program is going and we're going to start doing in the phase rollout with the assumption everybody must already be doing it because they've had it in their contracts. And if not, then screw you sort of was sort of how that was. The ecosystem wasn't, you can see, isn't mature. And so, and neither was the infrastructure to support it. And so there was this cry in every town hall like you had mentioned. We need more C3PO's. We need more CCA's. And people are like, we'll do it, we'll do it. People were raising their hand

[00:30:36] because they saw that if these organizations really listened to the first warnings that were, the CMMC's coming, they were going to have to start moving. And there was going to a lot of people and then someone's going to scream fire in a large room and they're going to have to make a whole bunch more doors to let these people out in a time frame they're wanting to get them out in. And what ended up happening is so many people answered the call and then the government said, oh, we just don't have enough doors. You know what? Let's go ahead and just pull this thing back. And the people that listened are like left holding the bag

[00:31:06] and kind of like, what the frick? Like I just built a whole door here and you said, yeah, you don't have to come through right now. And so the damage that it's going to do potentially to the C3PO I think is untold. I think it is actually criminal in my opinion and I don't use that word lightly because these people and I think sometimes and I'm not a C3PO but I think a lot of times they, people sort of assumed that the C3PO, a lot of those organizations

[00:31:36] it was more of a, here's an opportunity for me to sell water when a hurricane's coming, you know, or sheet rock or plywood, you know, because everybody's going to need it. Woo! I mean, most of those companies that stepped up as C3PO's did it because they felt there was a need and it was coming and if they didn't do it someone else was going to have to or this thing was just going to go off the cliff and so many people stepped in, really good people to really try to do the right thing and I know C3PO's and organizations that have, you know, refinanced,

[00:32:06] reached, you know, for them because of the cost like you're saying to become a C3PO, the liability and risk that they have to assume to be a C3PO, can they survive two or three years? I don't know. I mean, and what is the ecosystem going to look like after that? Exactly. Do you have an idea, Corinne? How do you see this ecosystem if they just keep it paused and just expect there to be a passive desire to get third-party assessed? It would be a self-fulfilling prophecy

[00:32:35] for them. They would make it so that there weren't enough C3PO's because half of them would not survive. Right. And, you know, we're strong. I think we could make it through a tough time. We ran very thin and carefully over this time period. I mean, yeah, it's hard to even process the, it's more hurt than anything. It's like, wow, this is like, you know what hurts the most is that

[00:33:04] I thought we were doing this like we were, everyone thinks that they're supporting the most important cause. They're part of, this is their way to participate. This is their way to support the Department of War. Come to find out they don't even like us. Like what we do. And we're sitting there being strict and towing the line and being like, no, this data is important. And, you know, never were we, we were lost out in no man's land getting no guidance. There was a moratorium on communication with us.

[00:33:34] That's so cruel to do to people that, you know, have invested so much to not communicate with them, for them to not know what's going on for six months prior to this happening and then get this nuclear bomb dropped on them. Yeah. And they'll just leave them out there hanging and be like, yeah, they're all money hungry, greedy, you know, you know, this and that. It's just really, really unfair what's happening there. So, yeah, I don't think, Bob, the answer to your question is I don't think a lot of C3PO's could make it through

[00:34:04] that lull unless she created a safety net for them that still valued a third-party assessment and that there was some value in it. If there's no value, no one's going to do it. If there's value, people are going to do it. And the throttling of the number of C3PAOs is dependent on the need and the value. And if there's not a lot of need, the C3PO pool is going to adjust accordingly. So, it's just survival

[00:34:33] of the fittest. And that's so true. Like, if, the other biggest complaint that I had about the CMC program with the DOD at the time was they didn't provide a good, clear ramp-up process that gave numbers about what you would expect contracts, totals to be. They said there might be, there's going to be a phased rollout. It's going to be at some type of percentage, perhaps. But they weren't giving a very good, clear,

[00:35:03] yeah, we're going to apply handbrakes. We could do, you know, we could push things perhaps further. And that started causing people thinking November is the deadline. Like, we have to be ready and have our third party. No, when you hit into phase two, there was still going to be a percentage of contracts that were going to have. What that was going to be wasn't like clearly defined for people like, hey, don't freak out everybody. They weren't really attacking that problem. They sort of just let the fear-mongering, and I think to some extent that pushed back up the chain. And they were like, we're going to have to be

[00:35:33] fully level two by November of this year or we're not getting contracts. And I think this is a bit of the consequence of the lack of communication. Had they said, look, guys, just calm down. Someone yelled fire, but we got plenty of exits. It's going to be fine. We're going to be going through here. Not everybody's got, you know, I mean, like if they would have just had a better metering process for them, I think we could have rid it out better if they would have communicated the primes a little better about what that rollout was going to look like and what real implications that was going to be to the contracts they were trying to bid for.

[00:36:03] I think it would have provided a lot more clear perspective to them about what they were facing after November. And so now we have a pause. So one of the important aspects that I think about that is like how it's going to impact MSPs, how it's going to impact C-3PO's. You talked about how that's going to be for C-3PO's. I want to just touch on how I think it's going to be impactful for MSPs that have stepped into the space to continue to help people

[00:36:33] to stand on the podium to get their level 2 or be ready for self-assessment. And then I'd like to circle back, Corinne, and talk about how that's going to impact you as an LTP because you're playing those dual roles because I really want to get your perspective about how you think that's going to be impactful because you already talked about ISACA pausing things, right, to some extent on the new content rollout and some of those things, right? Is that what you just said? Because that was news to me. I didn't hear it until you just said that. That was the first time. I did say that at one meeting that they're pausing

[00:37:02] curriculum development at this time. I don't know if he stuck with it or if something changed. Maybe they got, they were probably just waiting on guidance from the DAW. Yeah, I would too if I was them. Yeah, I mean like, oh, we're going to make a development for something that might be paused and we're not even sure how that rollout is going to be. I can only imagine how that's going to be. So, but the MSP perspective, I think organizations are being required. They have a serious illness. It's called noncompliance

[00:37:32] and they have to be doctors to fix their problem and they're not. They're people that are manufacturers. They build bolts and frameworks and do research and R&D. They are not doctors. They might be doctors, but they're just not doctors in compliance. And because of that, they want to get this treatment process over as fast as possible and they're going to very ignorantly, even with perhaps the right intent, get that wrong.

[00:38:02] I have never in all the years of my work ever seen an organization, even with the right attitude and heart, have ever gotten it right when they did it themselves. So, what does that mean? History dictates that these organizations are self-assessing and have a massive risk to themselves because they don't realize they are still vulnerable. Even they might have tried to do it the right way. And, they could find that out by the knock of the DIPCAC at their door. Okay? Now, granted, DIPCAC's only going to see the primes

[00:38:31] and subprimes that are really kind of at their touch, but, you have that employee or someone that says, you know, as I'm leaving, I'm going to, I'm going to, I'm going to go ahead and poke at you and I'm just going to call the DOJ because I don't think you're compliant. They'll show up for that too. And it doesn't matter whether you're visible to them or not. If you're in the DOJ and they report it and they say you have contracts, they're obligated to show up and investigate it. So, and they seem to have traditionally been very active at that. So, you know, organizations have either knowingly or unknowingly

[00:39:01] been swimming across an alligator-infested water and they haven't been bitten yet because there's so many people swimming. And that's what they are doing whether they realize it or not. But there is a percentage of organizations that do realize that and they reach out to us as MSPs and they want us to get them ready to be self-assessed correctly. And we've been seeing that, but it is vastly slower than what we have been seeing as a third-party pressure. And that makes sense because the organizations don't want to do it

[00:39:30] if they don't have to. And if they can do it themselves, they figure, I'll just take the risk and do it. Not really realizing how dangerous that is. And they are doing that left and right. So we've seen the inquiries drop by probably 60% in the pipeline of inquiries of organizations just quieting down. But we've seen a lot of courageous few that are like, this still scares me because now I have to do it myself and I don't know what I'm doing. And if they come knocking, I'm going to be screwed,

[00:40:00] I think. And it's not going to go well. So can you help at least get us there? And if we have to get assessed, then we're going to do it. But you hear that last statement I said, if we have to get assessed, they don't want to spend the money, which means they're not going to C-3PO's unless they have to. And so that's where Ms. Davies is going to have to create, like you said, an incentive factor for people to still go to the C-3PO's. Some type of additional warranted validation on the bid process to say, if you have this,

[00:40:30] this attestation of a third party is much higher so we feel the Dibcac's not going to show up and yank out this contractor because they haven't been doing it all along and now we're caught in the lurch of our contract process. But if she doesn't do that, it is going to not only impact the C-3PO's, but it's going to continue to impact the MSP's. Not as bad. I think we'll be fine. Well, here's something that's interesting though about that I do want to just say is like coming from somebody who has to think about this very strategically

[00:41:00] as an MSP. So we have not received a new CMMC client since our last one in June. Is that a shocker that July seemed to affect something as far as people saying yes? No, not a surprise. But a lot of them were very, very interested. They want to do this. They want to say, and then all of a sudden they go, we're trying to figure out what's going on. We're still trying to figure out what's happening. And I'm like, just to be clear, you are already not doing what you're supposed to be doing.

[00:41:30] It has actually no bearing on what we are, like what our company does. Tell the story about the person that said they were at a 99. My Lord. There was, well, I have too many stories to count, but there was this one company that said, we're really close, we're almost there, we did a self-assessment, our SPRS score was at a 99. Then they proceeded to ask me after that, so how do I know where my CUI is? Corinne, Corinne,

[00:42:00] how do I answer that question? How do I answer that, you know? And so, these are the things, these are the everyday. I'm a great parent, I just don't know how many kids I have. I'm not sure. But I'm doing great. They could be anywhere. I'm doing great. I'm doing really good. They could be anywhere. Maybe I have to pick up at school, daycare, I don't know. I don't know. You know? But it's so true that like, even with us, right, so we're not a C3 PAO. We're just implementers

[00:42:28] of NIST 800-171 controls. Like, no matter what, you have to implement these controls and assessment objectives. Like, we are an MSP that has helped us support and we help you make sure to stay compliant with NIST 800-171. So, whether you have a C3 PAO assessment or not, you still have to do that. And they stopped coming to us because they think they're trying to figure it out during this pause. I can almost guarantee you they're not figuring out anything. They're just not doing anything because they don't

[00:42:58] have to do it. Every client that has ever come to us has always been in a negative SPRS position. Yeah. Every one of them. Yeah. Every one of them. And I'm like, it's like shooting fish in a barrel for DIPCAC if they wanted to. They could pick anyone. And they're just like, pop, pop, pop, pop, pop. I mean, it is not hard. Yeah. And it's, and it's, I mean, it's everybody's fault, right? I mean, you can sit there and say, oh, it's OSC's fault. I think it's just everybody's fault that we're kind of in this boat. It is what it is.

[00:43:28] We need to get through this, but this ain't helping. Yeah, well, that's actually a really good transition to ISACA because part of the problem, and if I were a defense lawyer, I would say, how is it that takes an assessor, three classes, a CISSP, and a year or two of experience to come up with this score, and we were expected to have it accurate, not now that all

[00:43:57] this information's been out, but let's go back to five years ago, right, or four years ago or three years ago. How in the snikies was the Dib supposed to properly self-assess? And that is why I started SPRS Friday because there is nothing out there for them, and the true sin of it all is that CCP isn't targeted towards the Dib. They have to self-assess. They have to understand the requirements. They have to understand scoping. So why are they not being given and offered

[00:44:26] and advertised this training every day, all day, before an assessor, and how are they supposed to ever have any other results aside from incorrect ones without that training? It just is crazy. Don't call it CCP. Call it Dib self-assessment training. I don't care what you call it. Call it bring your score from negative 203 to 88. I don't care what the title of the course is or who offers it, but they need

[00:44:55] the exact same training minus the ecosystem lesson, right? They need to understand everything else and I just, that's, and if I saw, I think ISACA knows this, right? They're super smart at marketing training and I can guarantee you one of the things that is coming is a major shift in marketing to account for the fact that the Dib needs this training and so ISACA will be fine because the ISACA will probably turn around and be like, hey Dib, all you self-assessors,

[00:45:25] you need this class and this is what we call it. So true. So, so true and I think, you know, for us as an MSP, like we're that insurance policy for the organization that realizes the risk so that's going to be our calm change that we're going to have. Look, you have the risk. It's there whether you realize it or not. Let us help you get to the, at least the self-assessment level so that you can be ready if you are tapped on the shoulder or if Dibcat comes knocking that you can, you, you can move forward without threat without it being

[00:45:54] an extinction level event for your organization. And they do need, by the way, I didn't mean to devalue MSPs because that is how they expected them to do it is find somebody who does know but that's still the same problem because for a while there, MSPs weren't even targeted with that training. And Bobby, people like you and your group, you know, you came to the training even when you didn't have to and so did a lot of other MSPs but there are plenty out there that have never had the proper training

[00:46:24] and can't do what you're talking about. And to your point, like, I didn't feel like it devalued. I feel like, like, I'm just layering on to kind of what you're saying because I feel like they need to have that fighting chance to even understand. Like, it is still difficult even for us when we're working with organizations to move them through because they don't, there's, they know so little. We have to spend a lot of time educating our users about what the heck they just bought from us, right? It's like, hey, I bought a thing and that thing's

[00:46:53] going to get me to CMMC level two. Go. And I'm like, you don't understand, like, it's a team effort. We're climbing this hill together. We're going to Everest and this is what it's going to, well, what's a belay? What's, you know, what are, what is, what is a parka? You know, and like, oh boy, we're going to need some oxygen too, by the way. Do you know how that, and they're like, well, I'm, you know, 450 pounds. How am I going to get up to, you know, Everest? Well, it's going to be interesting, but I can't carry you the whole way. We're going to have to work on this together.

[00:47:23] You know, and it's, and when I was an MSP and I went through my CCP course, the first thing I did when I was done is threw out everything I had written about CMMC. And I'm an MSP and started all over again from scratch. And, and so I think you're absolutely right, Corinne, like, they need to educate those because I think at the minimum it will help either them to have a fighting chance or know what they're doing when they're interfacing with someone like me or you if you're doing consulting to kind of get a better idea

[00:47:53] of what they're looking down the barrel of doing or whether or not they even want to be involved in the ecosystem and take those types of contracts because you're like, what the frick did I just sign up for? Right. You know, and, and then realize that might make things a little iffy. that might make things a little iffy. So, just understanding that and I just, I feel that having that educational piece would, would just be so helpful and I just, yeah, I don't know why they have that. I'm giggling thinking of Kaylee taking all these calls and having to,

[00:48:22] you're such a good teacher so I'm sure that part of, of these, these conversations is an education that must be really hard to have over and over and over again. It's fun. Yeah, exactly and I've heard you talk about it on, I watch the podcast all the time and I listen to the stories of your calls with the Dib and I was curious for you, like for every 10 people that call and let's do pre-nuclear bomb time so before all this happened, for every 10 people that call,

[00:48:52] how many make the cut I want to say and are actually accepted as customers because I've heard you kind of talk about it and those, you don't say those words but it kind of feels like that is where we're at. Yeah, well, so kind of going based off of what Bobby is saying, there is a joint effort that many do not realize is the case and it's not that we just don't want to put all the work in. We actually, I mean, you know,

[00:49:21] I care very much about our team so we might be, I might be a little biased but our team puts in a lot of effort to do as much as they possibly can for the clients but they still have their organization and they have to do their part as the company to get ready for NIST 800-171 compliance. We cannot do everything for them and many people do not truly get get that. They want to go

[00:49:51] and sign on the dotted line and give it to somebody else and think and now I'm done and I can just go back to my job and I never have to do anything and let me just say we'd get a lot more deals and a lot more companies and we would get a lot more sales if I just said what they wanted to hear which I know exactly what they want to hear but I'm not going to say it because one, I care about them and two, I care about my team and it is not

[00:50:20] going to be a beautiful story when they realize that they still have to put in the effort to actually get their company compliant because again, we're still an external party. We are not their company. They still have to adhere to these things and we cannot and we won't hold them down to the fire and just beg them to do every single little thing they have to want. I would say pre-detonation we were probably at 60% conversion rate of people understanding what they were doing

[00:50:50] and they were really on board and were really doing it. Post or coming into last year and this year like kind of coming in more to the end it flipped to like 80-20 and Kaylee doesn't is using a lot of the same methodologies as she's attacking it but she doesn't like, God bless her because this is great like it's not about getting them in the boat and figuring out how to skin them you know, if they were a fish if they were a fish right, not, no, no, but the, like it's,

[00:51:19] she really does try to say here's the reality and we're not going to hunt you down to convert you to that understanding like you need to understand what you're signing up for because if not then they're going to hate us through the whole process and kicking and screaming and fighting and you know, there's only about 30 of us so we're not a large MSP to be able to handle someone that's like, you know, if you're, if you're gonna, if you're gonna try

[00:51:48] to save people in the water you want the people that are gonna lean back and you can pull them to shore fast because you can grab some more but if they're just sitting there flailing the whole time you can't save as many people you know, and that's what our goal is is really to, to, to, to save as many people and get them to 110 is really is what we're trying to do. We've had people come to EBSS or, you know, during their discovery calls and they'll say, well, we need to be there like, well, we need to be present and that owner, not the owner but like the, the people that would,

[00:52:18] you know, the company itself, its representatives are like, well, you need us to be present. I'm like, yeah. Yeah, yeah, you do have to be there because it is your organization. Yeah. And we've had people during assessments say, you know, can, we have like a child event this afternoon at the school. They're like a, you know, a husband-wife type company. So, we're going to get going and you guys can continue on. I was like, this will be ending now. Yeah. And we'll resume

[00:52:47] when you can be here tomorrow. So, have a good time at your event and like, no, we're not just sitting with the MSP and letting them answer all your questions because you have to be authoritative and you have to have authoritative statements for a lot of the domains and a lot of the, people don't realize that a lot of the define is your, even if someone else writes it for you on MSP, you are stating, yes, this is our rule. This is our value. This is our stance on this. And,

[00:53:18] you know, I don't mind how much the MSP talks or helps or whatever it is, but there are some things that, like you said, it's nothing to do with the MSP. This is all you, buddy. You got to answer this one or you have to be able to speak to it. Yeah. Yeah. Well, I know we're getting to the hour mark and honestly, to be honest, I could talk for another hour about this, but we, I want to close us today. And the one thing

[00:53:47] I want to say, and I'll let you two, you know, say your last things for the episode as well to share, but one thing just from my perspective is, you know, I'm very fearful about the engagement, especially with us implementers as MSPs, and I'm sure you feel the same way, Corinne, from the C3PAO side of with the back and forth and the back and forth, you know, how much are we going to keep up with the compliance standards and having, you know, being able to even

[00:54:17] afford people on our staff that have that level of capability for, you know, to be able to do assessments with our clients, to be able to write that documentation, to do those technical compliance, you know, requirements. And I'm very fearful if we keep going back and forth on what that's going to do to companies like us and then, like kind of what you said, Corinne, a self-fulfilling prophecy of by the next time they want to start this back up, we don't have enough people to do that stuff and we'll have to do it, you know,

[00:54:47] all over again. So I really, really hope and I truly hope that the DOD CIO office and all of them there are really listening to these things and take it seriously as it should be taken seriously and hopefully come back with a solution that can help us during this time because it's important and we do want to keep this data controlled, unclassified information secure and protected and we do believe in the calling of it. So I really do hope that that happens.

[00:55:17] Corinne, would you like to say like any last year thoughts or anything that you weren't able to say to before we close today as well? Yeah, I just, just piggybacking on what you've just said, the security of the data has a direct relationship to the number of assessments. That's a fact. So we know that people secure the data when they have to. It's expensive, it's hard, they're not going to do it unless they have to. They only have to if someone is coming to check. They do not have to

[00:55:46] if the odds of someone coming to check is less than being struck by lightning. So all of us will suffer by the exact proportion by which the assessments are reduced and that includes DIPCAC assessments. So for you all, you'll be fine if they ramp up DIPCAC assessments and they do as many of those as C3PAOs were doing, MSPs will be great. I don't care who does the assessments because I want the data to be as secure. Well, I shouldn't say I don't care. I want to be a C3PO. It's one of the most

[00:56:16] meaningful things I've ever done. But for the security of the data, it doesn't matter who does it as long as they are done by a third party and unfortunately that is what is needed to kick people into action and then to have them seek the services to help them secure the data. This isn't, you know, we want everyone to make a million bucks like you said earlier. This is, you know, the services and the ecosystem that was built up was built up to secure the data

[00:56:45] and without the assessments checking. This reminds me of that senator when his two kids came in. Did you ever see that? Or it was like a British like... Yeah, and the mom. The mom comes like... We're not going to edit that out but that's my wife Judy coming in to grab our dog. We're keeping that in and there was a time where she did crawl. She did crawl on the floor and you could... Slid some food right here on my table and then crawled back out and I'm like, what are you doing? You could see her the entire time. It was great. That is a good woman

[00:57:15] right there. Oh yeah, I'm like, honey, just walk in, it's fine. But yeah. Yeah, I, you know, Corinne, I want to end this I think on a potential positive note that if they provide that training to the OSCs, it's... CMMC is literally the hardest thing I have ever done to try to do to work with companies and organizations and helping them understand the magnitude of what they're about to try to do would be such a help. So, like, to try to do a shot in the arm of the ecosystem is like,

[00:57:45] just train OSCs better, like provide free training, do those things, cut ISACA loose to start having maybe even a sponsored course or something for them to go through to have a better understanding because what's going to happen is if they don't if they don't add an emphasis on the third party component, the C3POs are going to just become the... They're going to go the way of the Dodo if they don't. You know, the dinosaurs. They're going to have to try to keep them... They're going to have to have a value component for them to exist if not in the next two years

[00:58:14] if they don't do something. Then they're going to just go out of the... You know, go into extinction because it's just people aren't going to do it because there isn't going to be a value for them to do it. And they'll just through negligence of that area just let it die. And that just... That is like super... That's sad and dangerous and I hope they don't do that. But if they... If they do add value to that, if they do train the OSCs, if they start trying to do this, I think we can all

[00:58:44] get through this together. I think we can all understand that the ecosystem's not perfect. It needs a change. And hopefully this is a step in that direction of doing the pause to allow that to happen through the changes that they're going to come through with, perhaps. I don't know. You know how they can fix it in the short term and actually do exactly what you're saying? I would love to hear. Come see you and me on Monday, September 14th. That's CCP. Right, yeah. Take a CCP class with us. Yeah, yeah. I love that.

[00:59:13] Put it on the CC class. Register at WTI.us. I could not agree more. Could not agree more. Yeah, I love that. And I couldn't, honestly, coming from even somebody operationally that watches this through the company and watches clients go through it, the training, training, training is a word that we hear constantly. They need to be trained more. We need to be able to teach this better. We need to be able. So I could not echo that more. And I really do hope for positive change

[00:59:43] and positive growth with this as well. And hopefully we'll get some more answers soon. And honestly, we do not have the answer to that. So don't ask us. But we will be vigilant with keeping an eye out for what's happening and pay attention. And by that, I mean I'm just going to watch Corinne's LinkedIn. So when she posts, I'll know about it. So you can just follow Corinne as well. Thank you for having me, by the way. Yes. No, thank you for always coming on and being willing.

[01:00:13] It's great to connect with you always. Guys, make sure to follow Corinne and what she's doing. And hey, if you're not educated about CMMC, like she is a wonderful teacher. How do I know? Because she was my teacher too. So I can say that. And also, Bobby was there sometimes. So, you know, whatever. You might run to me as an instructor as well. Yeah, you might sometimes. But yeah, guys, I hope you guys enjoyed today's episode. It was a little bit different. It was a little bit later because we're doing it real time trying to get this out to you.

[01:00:42] Make sure to tune in next Thursday for another episode of Climbing Mount CMMC, the podcast. Make sure to also tune in to everything that's going on with the DOD CIO office and what they're announcing. You can look at their website as well. I'll have that linked down below. And all of the things that we discussed and the documents that we discussed will be linked down below for you guys to check out. Thank you guys for watching. And remember, as always, to keep on climbing. We'll see you. Yay!