Submit any questions you would like answered on the podcast!
What does CMMC Level 2 actually require, and how does it connect to the four-phase rollout, the POA&M process, and the assessment you'll eventually go through? Austin and Brooke break down Level 2 in plain English, a few days ahead of the DoD's September update on the Phase 2 pause.
In this episode:
- Where things stand with the Phase 2 pause right now, and what's not paused (your obligation to be compliant with NIST 800-171 R2)
- Why "just give me the CMMC checklist" doesn't work, and what CMMC actually is (a collection of DFARS rules built on NIST 800-171)
- The four-phase rollout explained: what phase you're actually in, what's paused, and what flows down regardless of the pause
- What CMMC Level 2 requires: 110 controls, 320 assessment objectives, and the "CMMC overlay" on top of NIST 800-171
- POA&M rules explained: the 180-day clock, the minimum 88 score, and which controls can never go on a POA&M
- What "ready for assessment" actually means (hint: it's a lot more than an SSP and a POA&M, often 400+ documents and artifacts)
- Self-assessment vs. C3PAO certification: what a real assessment guide-based self-assessment looks like, and why assessors can't consult or advise you
- Why the "100 assessors" claim used to justify the pause doesn't hold up (there are over 1,000 CCAs)
- Level 1 vs. Level 2 vs. Level 3: what determines which level actually applies to you, and why most companies who think they need Level 3 don't
- Why asking your IT person to self-score your own compliance program is a liability risk, even with good intentions
Welcome And What We Cover
SPEAKER_01Hey there and welcome to the CMMC Compliance Guide Podcast. I'm Austin and I'm Brooke from Justice IT Consulting, where we help businesses like yours navigate CMMC and NIST 800-171 compliance. We're hire guns getting companies fast-tracked to compliance. But today, we're here to give you all the secrets for free. So if you want to tackle it yourself, you're equipped to do so. Let's dive into today's episode and keep your business on track. Today, we're going to deep dive a little bit into some questions we've been getting about level two lately. Um, what's required of it, um, what some things actually are, clarifying um what levels and what actual assessments are required. And we're about a week out or so um from the uh September, is it 14th?
BrookeUh September 11th, September 14th. You know, I whenever they decide their 60 days is up, then I guess that's when it'll happen. I think technically uh Stacy added it up, and it was uh uh, you know, that's actually the 11th. So they might release something on the 11th. Uh I figure the 14th because that's a Monday, but who knows? We'll we'll find out. Soon.
SPEAKER_01Couple days out um from the uh deadline that they gave themselves for an update on what phase two is gonna mean. So we'll touch on that briefly as well. Um, kind of where things stand uh and uh where uh the pause is currently, um, and we'll get into the
The Level 2 Pause Explained
SPEAKER_01rest. So let's do it. Let's do it. So, real quickly, we'll check in on what the current state of play is um and what's actually suspended right now uh and where the the rollout stands today, uh a couple days before we're supposed to get some updates.
BrookeAbsolutely. So, y'all uh this this will probably be posted, like you said, a couple of days before. So um where it stands, and I know we did a whole episode on this, but where it stands right now, uh because people keep asking and and everything. So um the uh they paused the level two certification requirement on contracts. Uh interestingly enough, almost 60 days ago, so 50, 50 days ago, whatever, however many days ago, they uh they announced the pause and that it was gonna be a 60-day pause, which is what they could do by law. And then uh, but interestingly enough, the actual implementation of the level two certification on contract requirement uh was uh almost 120 days out. So um they had a 60-day pause for something that was 120 days out, so um or 10 whatever days out, 115, I don't remember. I didn't count them all up, but uh close to close to 120 days out. Uh but right now it's paused. I expect that they'll uh come back on the 11th or September 11th, September 14th, or sometime around then, uh and uh release another statement. And they'll either do a who knows what they'll do, an interim final rule uh or uh I don't know what legal ways they have to further uh pause this without a um without some sort of uh interim rule or something, but uh they may come out with an interim rule uh that basically implements the pause for longer. Um but I expect them to keep the pause on and not not move forward yet. Uh but on September 11th or 14th or so they will uh they will release their findings, what they uh came up with or what they're so far what they've come up with uh from all of the responses to the RFI, the request for information. Um so they had a whopping 30 days or so to go through all that. I'm sure they did. Uh sure they thoroughly went through all that with AI to get some recommendations. Uh but in any case, right now uh the uh level two certification requirement on contracts from the federal government uh is in place. So there's a pause in place. Excuse me, there's a pause in place for that. So uh what's not paused is compliance with NIST 800-171 R2. Uh you you still have to uh comply with CMMC, you still have to uh cover all your bases, you still have to make sure that you're covering all your controls, all your assessment objectives. That compliance is not paused. They specifically said that in the uh in their um in their statement. They said it's not paused, you still have to be compliant. They're just pausing the certification requirement. So um so that's what's in place and what's not in place for right now. There's still a few people out there saying, oh, they canceled CMMC or they paused CMMC, they didn't pause CMC. That's a shorthand way to say it, but they didn't pause CMMC, they just paused the certification requirements on contracts. Um if you do work for a prime or you're a subcontractor of of uh some other contractor, right, uh then they s they certainly may require or ask of you uh that you have a certification or have that on the calendar or or something like that. Uh I've seen lots of uh primes that are are saying they they still want people to have certifications. And really, when you get down to it, uh that reduces their risk. If they can say, here's a list of our subs and here's the ones that have level two certifications, uh they've had a third party come in and certify those, right? Or not the the prime didn't, but the the subs did. So their risk for using those those subs has is very low. Um if it's just a self-assessment, then it's a lot higher risk because who knows? Uh that that's where the problem was before is people were self-assessing and not actually assessing. So that's where we're at.
What Is Not Paused
SPEAKER_01Or uh people self-assess and don't know what that means.
BrookeYes. And there's a lot of that where they don't, you know, you look through the controls and say, authorized user list? Yeah, sure, we've got Active Directory. Check. So uh a little more than that.
SPEAKER_01Or worse yet, you put 110 in uh Spurs or SPRS and you don't even have an SSP.
BrookeCorrect.
SPEAKER_01See that quite a bit as well. Yeah.
BrookeSo yes, we did an assessment. We meet all these, that's great. We got 110. Uh and then they didn't actually create an SSP, so really they just flunked the whole thing. So we we do see that, yes.
SPEAKER_01And so uh, you know, make sure you understand what you're doing whenever uh you do a self-attestment. Uh it's not um there's there's a specific definition to w the government, what it means to them whenever you self-attest, and it's important that you know what you're signing up for. It is I don't know how many times I can say that. Um but I find it very important for people to at least understand what it means when they do that, because a lot of times they don't. Most of the time they don't.
BrookeYeah, and the the risk there is a false claims act investigation or uh settlement or however wherever it goes after that. Uh you know, is the risk of being investigated for a false claim high? Probably not, but it ain't zero. Uh you can look out, look and see all of the false claims act uh um settlements they've had. And uh there's there's quite a few, and they're ramping those up, and they're adding more uh DIPCAC, the DIP DIBCAC as the are the ones who um investigate, and so they're adding more uh staff to that uh to the DIBCAC. So they're basically letting you know that there's gonna be more and more of these coming.
SPEAKER_01So you don't have to pay your taxes, you may not be checked. You know? I mean, what's the risk of the IRS coming and auditing, right?
BrookeYeah, you don't have to pay your taxes. Yeah. Not that I would not pay my taxes. No.
SPEAKER_01Yeah. It's a similar sort of deal, you know. Exactly. So uh you know, it's it's better um to pay your taxes and not, you know, have to worry about it, right? Yeah. You sleep at night, yes. Exactly. I like being able to sleep at night. Absolutely. Um anyway. People always mention CMMC, CMMC compliance. We gotta do CMMC, you know, um, and it's uh almost as if it's just one thing, you know, or a checklist. Uh that's what I hear a lot, is like I just need the CMMC checklist. Can you just give that to me? Um I hear that all the time. Um, and so uh and I wish it was that easy and I wish I could just give it to them.
BrookeSure. Um go to the d go to the D uh DOD website and download the assessment guide. There's your checklist.
SPEAKER_01Yeah. The closest thing you could get, right? Um so you know, point is people often talk like it is just like, you know, one rule or just one thing, you
Why Self Attestments Go Wrong
SPEAKER_01know. So um what is it? What is CMMC?
BrookeUh good question. Uh CMMC is a collection of uh uh DFARS rules, really, that go into the uh 32 and 48 uh CFAR. What is a D FAR? DFAR is Defense Federal Acquisition Regulation Standard. So uh they're rules uh created by the uh federal government, in this case since they're DFARS, defense, they're for the DOD DOW. Um so they go into the uh the Code of Federal Regulations, uh specifically uh 32 CFR and and a 48 CFR. The 48 CFR rule um, well, step back. The 32 CFR is the one that defined uh CMMC and said what CMMC is. Um and then the 48 CFR actually put that into effect on contracts. The 32 CFR is actually where uh it defines the phases. There's four phases to it. We're in phase one. Uh now with the pause that's uh just happened, uh, well not just, but the with the pause that happened, uh we're stuck in phase one instead of heading to phase two. Uh we'll see in a few days where that goes. Um but uh so that's that's what that is. It's DFAR's rules uh go into the Federal Register.
SPEAKER_01Um whenever I think about CMMC, I think uh there was a it was actually sales training I did way back when uh Sandler sales training is what it was called. So hopefully I'm not giving away any prior proprietary information. I think it's in a book you can buy somewhere, but anyway, and they have this thing called the dummy curve. And the dummy curve is um is uh it is a graph, you know, it looks like a U and it just documents your level of competency. So at the beginning, when you first learn something, you come in with a lot of confidence, like I know CMMC, right? You know, and um and and from their perspective, it's like I know sales and I'm real great, you know. And then but um it works for you know a lot of things, and but as you get more competent, your confidence goes lower and lower and lower till the bottom's out, and you realize I'm competent enough to know that I'm not competent, and I love lost my competence, right? Right. So that's the bottom of the dummy curve, and then then you start to rise again as you get more competence um and learn even more about it, and your level of confidence starts to rise again to the other side of the U. And I just think whenever you start starting off the 32 CFR, the DFAR, 712, 7021, blah, blah, blah, blah, blah, all this other stuff, and you realize it's not just CMNC, you know, and there's all these uh, you know, different regulations and standards that mix and match and point to each other.
BrookeAll sorts of stuff you have to read.
SPEAKER_01You know, um, and as you dig into that, you just go, you start to realize how much you don't know, and it starts to get really frustrating and confusing until you start to make sense of it and you start to be able to, you know, um put all the things together, you start to feel a lot more confident as you as you go through it. So um, when you first learn about CMMC or you first start going on the journey, um expect the dummy curve.
BrookeYou know. Absolutely. Absolutely. You learn a little bit about it, and you're like, all right, I'm good. I I understand, I know. And uh and then you start really getting into it and going, holy cow, there is a lot to this. You know. Uh I'm still waiting to uh feel really confident about everything, you know. Uh wonder when that comes. Uh just kidding. But uh there is a lot to it. There's a lot to learn, a lot to remember. Um it's it's in several different things are in several different places. It's a NIST 800-171, it's DFAR's, you know, 252, 204, 70, 12, 70, 19, 7021, it's 32 CFR and the 48 CFR, it's you know, some of the things you have to kind of read back and figure out what the uh NIST 853 is saying about something to figure out what the 800-171 means. Then you gotta look at the DOD uh CMMC fax or the DOW CMMC fax FAQs, uh, you know, to see how they're thinking about things. Not that those are binding, but everybody kind of looks at them like they are, right? Um so you know, a VDI solution or um, you know, where is that defined at? Well, it's defined in a CMMC uh FAQ by the uh Department of War, right? Um whereas uh where do they talk about FedRAMP equivalency? What that's in that's in the one CMMC document you have to read, right? No, it's buried somewhere else. So uh there it's in all all sorts of places, and you have to make sure you read all these documents and everything that we're just like you were saying. Uh where is this referenced at? Where does it come from? So yes, you that's this 8171 is one thing that is one document you can read. Uh if you want to get the full understanding, it's probably more than one document. It's you know the 8171 and then the assessment guide, scoping guide. Uh those all help you understand it, but then you gotta understand the CMMC overlay on top of that.
SPEAKER_01Mm-hmm. Yep. And don't forget the assessment objectives, you know. Absolutely. I don't know why I always uh seem to feel like I need to bring that up, you know, but it's always look at the assessment objectives. I don't know, it's something always people miss. But anyway.
BrookeWell that's what when we do our CMMC boot camps with clients, that's the the first thing, and we I'm sure you know we talk about it before this, but I make sure I go over and say, look, uh we're not really gonna talk about the control itself. Uh and because assessors don't, we're gonna talk about the assessment objectives inside the control, and then we'll figure out if that control is met or what needs to be done to make it met, all that kind of fun stuff. So uh yeah, assessment objectives are where it's at.
SPEAKER_01Mm-hmm. Yep, absolutely. Um, which is another reason why a uh checklist doesn't always work. Yes. Because you know, checklists can be mapped down into the controls, but really you're shooting for the assessment objectives. Um and then you have to know what the words and the assessment objectives mean. You know, so anyway. Um it's part of the reason why we a couple podcast episodes ago we had said just watching our podcast alone. Hopefully it's great information and hopefully we provided that for you, but you know, we only roughly have an hour with you every week. Um, so if you're really, you know, trying to DIY this or something inside your organization, there is no supplement um for actually going and getting some training, you know. Absolutely formal training. Um uh because it would really helps. And even that's not enough, really. It's not you have a lot of practitioners or um people that come out of those that they're educated, but now they need to apply it to the real world, and uh and that's a whole nother absolutely is can of worms.
BrookeAnother whole bottle of wax. Yep.
What CMMC Actually Is
SPEAKER_01So the next thing I wanted to cover is uh the four-phase schedule of CMMC. So and this is go ahead. No, this is something that um I think uh you know a lot of people just tend not to realize or understand about CMMC and and what is paused and and that it's only on the beginning spectrum of of CMMC. So uh CMMC is made up of four phases, right? Um so can you kind of explain what the the phases are and where um we're at and what about the phases are paused? Because I think even people understanding the pause and seeing the headlines don't even understand um you know the phase piece of it, and that's kind of a missing piece of information for a lot of people.
BrookeSure. Uh so there's gonna be four phases to it. I say there was going to be uh until pause. So who the heck knows what's gonna come after this pause, right? Um you know they're they well anyway, they have limited things they can do legally right now, and there's a lot of the rest of the stuff is gonna require some sort of rulemaking or or something, right? So in any case, um right now phase two, three, and four are paused, but there were four phases. Uh essentially we're still in phase one. Phase one is essentially what everybody's been doing, except with uh maybe with a little more teeth, and it did have a definite timeline. Um, but uh phase one is self uh self-assessment or self-addestation, um and uh leading up to being ready to uh for uh level two certification. That's certification by a third party. So you get a see-through PAO to come in and uh do your assessment and uh get a perfect score. It's a if it's it's a perfect score, nothing, right? Um with a caveat it, you can have a POAM.
SPEAKER_01But um real quick, if I can pause you. One of the things I hear a lot whenever I'm talking to people is um people say you we've heard about the assessments, attestments, and certifications, and we've decided that we're gonna just stick to the the self-attestment for all two, because that seems easier. That's the route we're gonna go. Yeah, they can do that.
BrookeIf you want to, but if the if you were going for a uh uh contract that requires certification, then the answer is no. Well, actually, I guess you still can do self-assessment. You just won't get that contract.
SPEAKER_01So uh it's not you that is necessarily in control of what you're going to be asked to do unless you being control means you just decided you don't want that work. Correct. Okay. Yeah. And so that is how the phases connect, um, is what is being required on contracts.
BrookeThat is how they connect, but also the phases are just the phases for how uh what's going to be required on the contracts and the contracts from the federal government, not the contracts from Prime. Prime can do whatever they want to. Um it probably behooves them not to overmark CUI or um, you know, be too broad with it, because then that hurts them in the in the long run. But we see that all too often anyway. So um nevertheless, uh so phase one was self-assessment. Phase two was where uh it was gonna start on November 10th of no of 2026, this year, uh, where they were gonna require the government was gonna require um certifications on contracts starting then. And does and it didn't say all. It did not say all. It just said they were gonna start requiring them then. It was up to the program managers uh to decide what was required on that, right? Uh which gets into uh you know me having a problem with some of their statements they made for the pause, but we won't go there right now. That was on a previous one, if you want to go look at look and see what I had to think about it. Uh but uh so that those certifications were gonna come in, uh start coming into play on November 10th of this year, 2026. Uh so that's phase two. You go to phase three, and that's when uh the level three uh is gonna start being required on contracts, and uh that's gonna be a DIBCAC audit, so you have to have a level two first, and then uh then you do your level level three uh certification after that. Um but that level three was only gonna be a very few companies. And then uh by phase four, uh that's when it's supposed to be required on all contracts. So uh but because of the pause we're we're in phase one anyway, uh still uh but we're because of the pause, it's likely we're gonna stay in phase one uh for the foreseeable future.
SPEAKER_01So phase one is the government on their contracts requiring a self attestment to a certain level
The Dummy Curve Of Compliance
SPEAKER_01uh self assessment um excuse me, to a certain Certain level and it requires it on that contract. Yes. Um, and then that flows down with the contract through all of the subcontractors where it's deemed necessary, and what deems it necessary is their access to certain types of information, right?
BrookeYeah. And I might say it goes from the government to the first line, which is would be a prime contractor to their subcontractors, to their subcontractors, to their subcontractors. So it keeps on going. It doesn't stop at the first level of service subcontractors. Just so you know. Um that's another question we get all the time is you know, well, you know, we're like a sub to a sub to a sub. We don't have to do this. Oh, actually, you do. So depends on what information you get, of course. But yes.
SPEAKER_01So that's the phase we were already in before the pause, and we are still in today, and that is not pause. So and that is even you may not even see in a purchase order or a um or a contract yet with that included, because it may not have flowed down to you yet. That is, but that stuff is still happening and you're still seeing that piece being rolled out, you know, in its slow fashion and its trickle-down effect that that happens with, you know, top tier contract all the way down. So that is not gone away. That's where we live out today. So you still have to do a self-assessment for that. Um and then uh the phase two is the actual the third party certification that was going to start being required on some contracts in November this year. Correct. That's the piece that um they paused. And um, and then once it was included there, it would flow down in a similar way all the way down the supply chain. Um so I just wanted to reiterate that again, make sure kind of people understood that. Um and and before all that stuff, there was already NIST requirements and contracts prior and still some contract, a lot of contracts I should say, that are still have POs and uh, you know, payments and existing contracts today that um pre-exist all of these. So um that may, when they come up for renewal or something, be replaced by the existing phase one, right? So um my point with this is that even with a pause, you still may see some additional CMMC requirements that are attached to the phase one that you m you may not have heard of yet, because you are a subconscious tractor. So um there's still a lot of wheels and motions on that phase one piece, right? There is. Um and uh that's not even like fully done yet. It's it's implemented, but it may not even flow,
The Four Phases And Where We Are
SPEAKER_01you may not have heard about it yet, is what I'm trying to say.
BrookeYeah, they and you know, I can't tell you the number of uh clients that we've uh worked with that have, you know, we say, well, how do you know you have any CUI? You know, what kind of CUI do you have? How do you know what kind of CUI you have? Well, they told me we were supposed to be level two compliant. Okay, well again, what kind of CUI? And uh what are you what are you supposed to do? And and and uh they say, well, we don't know. They just told us, you know, and okay, well, is there a DFAR first of all, is there a DFARS 252.204-7012 on your on any of your contracts or POs? Well, I have no clue. Well, why don't you go look and and let me know. Lo and behold, oh hey, yeah, it does have 7012 on here. And uh so you know, we start finding those things after after they know what to look for, you know. And uh and then if they don't find them, they also say, hey, uh you know, you can also go back to your contract officer and say, hey, you told me I have to be level two compliant, but uh, you know, level two self-assessment. Uh but why is where's where's the defarce clause in here? What is what tells me in here that I have to have it? And sometimes they'll go, you know what? This one doesn't have CUI in it. Or yeah, it's in this document here.
SPEAKER_01We just sent you a supplier letter. I didn't actually look at your contracts that you have with us. That happens fair amount.
BrookeWe do have one client that uh they've told, you know, uh nope, you don't handle any CUI. You don't have to worry, you know, you you don't don't have to worry about CUI. And then they contact them and say, hey, we need you to be level two compliant. Well, I thought you said I don't have any CUI. I d you don't, but but we want we want you to be level two uh self-assessed, level two compliant. So back and forth, back and forth, and so you know, uh their ending point was we might as well do this so uh we can go ahead and keep the customer. Keep the customer and get get get more contracts, right? So uh but so it happens in all sorts of different ways all the time, right? Uh sometimes you actually do have that clause, sometimes you uh have you know some other clauses or you have uh ITAR data you think might be CUI, that they tell you C UI, but it's not marked as C UI. So yeah, there's uh the best thing to do is to go look at your contracts and see what deforest clauses are in there to figure that out. Talk to your contracting officers or you know, whoever or whoever you're working with, whether it's a prime or or the federal government, you can you can go back and ask.
SPEAKER_01Yeah, I can say I think we've saved a lot of people a lot of money on uh just our intake calls when someone reaches out to us and it's one of the first uh well, one of the first questions I ask. Um and some people have um taken a step back, did some homework, and then reached back out to me and said, Hey, you know what? I'm good. Thank you. And I was like, well, you know, bummer for us, I guess, but good for you, you know. So happy that uh you can avoid this for now, you know. So um that uh that is an exercise that if you've not done that, you should do that um if you're watching this channel, because uh you should always just challenge the assumption that you have this problem in the first place. Yes. Yeah, so worst thing you do is solve the wrong wrong problem.
BrookeExactly. Yeah.
SPEAKER_01You just mentioned um, you know, several things about you know, they told us to be level two or level two self-attest or assess or whatever. Um, so um, you know, that's kind of a fundamental question as to what level two actually even is. Sure. Um so if we could address that real quick, um, what is level two?
BrookeSo essentially the level CMMC level two, CMMC is the verification piece on top of uh the NIST 800171 controls. And CMMC right now is hard-coded or locked into uh revision two of NIST 800171. Uh revision two actually has been superseded by revision three, uh, but they're trying to give everybody time. They were trying to give everybody time. I don't know what the pause is gonna do, but they were trying to give everybody time uh to come up to speed on uh revision two and and be good before they uh went on to stay current and go to revision three, or if revision four is out by that time, who knows? But um so that's that's what they were trying to do. But uh uh NIST 800-171 revision two uh is uh are the controls you have to worry about, and really it's the assessment objectives in those controls. There's 110 controls uh in 14 families, and um uh there are 320 assessment objectives, which are the real uh where what you're actually graded on, really, is the assessment objectives, not the controls themselves, uh, but the assessment objectives. So the each of the controls can have one, three, five, six, or uh there's one that goes from A to O, however many however many that is, I can't remember off the top of my head. So uh a good amount. Yeah. But uh generally between one and one and six uh uh assessment objectives in each control. So it it equals out to 320. That's what you really want to cover. And then you gotta make sure that you understand the CMMC overlay on that. So, you know, if you m implement VDI virtual desktop infrastructure, for instance, you gotta make sure it meets the requirements that the DOD has set out. Uh, you know, no clipboard access, no map drives, no way for any data, uh, no screen capture, no, no way for any data to get out of that VDI. Um and you say, well, what about a cell phone picture? Well, it's they kind of draw the line there. You know, it's it's all the technical controls that you can put in place on a VDI session, right? Remote desktop will not work. Uh well, it'll work, but the endpoint that connects comes into scope. The reason somebody would use VDI and configure it appropriately is to keep that endpoint that connects by VDI uh out of scope, right? So uh so you have to understand all those CMMC overlay things. You know, what if I want to use a vendor, uh an ESP external service provider uh that is um uh for w for some COI. Well, you need to make sure that they're either FedRAMP uh uh authorized or FedRAMP equivalent. Well, what's FedRAMP equivalent? Well the DOD defined that. So you gotta go figure out what FedRAMP equivalent is. Um so those are the things you have to understand on top of NIST 800 171. Uh but it all starts with NIST 800 171 on all the controls and all the assessment objectives in there with that CMMC overlay. Overlay is not exactly a technically correct word, but that's the easiest way for me to describe it, I guess, and to think about it. Fair enough.
SPEAKER_01Thank you for that. So one of the things that we always hear about is a poem, plan of action and milestones. Um and uh oftentimes people can kind of misunderstand the utility of it or I guess um what the new utility of of it is. Um it used to be used in a much different way um than it is today. Um so if we could talk if you could speak to a POM and what the rules around that are, and what the hard limits for timelines and how a contractor can use that, if you just kind of dive in and broach the subject.
BrookeSo a POM, a plan of action and milestones is basically your to-do list of things that uh uh of controls that are not met, uh assessment objectives that are not met. Uh and so your plan of action and milestones is how to meet those, right? And so um in a GRC tool, you know, you could go market met, not met, and then if it's not met, you can click the little POAM. There's different ways of doing different GRC tools. Or if you're doing it in Word or something like that, then you just uh you know there's a template and you fill that out.
SPEAKER_01But a GRC tool is a software tool you'd use to run through and keep track of all your controls and assessment objectives and how you're doing on them and documentation.
BrookeYep, there's a ton of them out there. GRC stands for governance, risk, and compliance. Uh it's a software tool, like you said, that lets you keep track of everything. It'll calculate your score automatically, um, it'll step through an easy easy-to-view screens most of the time uh and generate your SSP for you. Um you can track uh changes, you can track authorizations and all that kind of fun stuff. It's they're really very handy. So a poem, uh, that's again your to-do list, plan of action and milestones. Uh you have, once you have your official poem, you have six months, 180 days, uh to close it out, right? And so uh you've got to start working through that uh to get that uh to get those closed. Um the other thing is on an assessment, uh you can't now if you're just starting and you're starting, you're building out, you may have, you know, a whole ton of stuff on your POAM, uh, and it may, you know, it may take you a year and a half to finally get through to through everything, right? So that's a little different than going through an assessment and having a having an official POAM. Uh so once you have your official POAM, um, you have six months to close it out, uh, or 180 days specifically. Uh, but you have 180 days to close that out. You can't have any three-pointers, any five-pointers, and some one-pointers you can't have on that POAM. So, um, which if you go look, well, what are the three-pointers and the five-pointers? Well, they're the hardest ones to meet, right? They're the more difficult ones. So you can't miss any of the difficult ones. Those those difficult ones are non-POAM. Uh, so and then there's some one-pointers, of course, that you like I said, that you you can't poam. So um, but if you if there are some of those one-pointers that can be poamed that you uh uh that you're that are not met, then yes, you can you can have a poam for those items. And your uh score has to be at least an 88. So 80% of 110. So 88. Um so you're you have to have uh a score of at least 88, and none of the five pointers, three-pointers, or those few one-pointers that can't be POAM'd uh can be on there. So that those are the requirements uh for an official POAM. Now, if you're just starting out, you go through, you do an assessment, and you figure out where you're at, you might be at a minus 163 or something like that. Or even maybe a minus 203. Minus 203 is the is the lowest score you can have. So um so it doesn't really I mean you have some time to work through that. You've got you're you're building your program. But once you get that built and you have an assessment, then uh you that 180-day clock starts. Hopefully, if you have an assessment by that point, then then you're um uh you're all clear and all good. You know. Uh a lot of times though, you have that assessment and you'll have a few things you got to go fix, a few little documentation things, because there is a lot to keep track of, and sometimes you might call, you know, might call out, uh might call a group one name here and another name there, or uh you might have one parameter in your SSP and you forgot to go change it in your policy, stuff like that. Those are the easy things to overlook. You think you go change them and you just don't. Um so uh you know, making sure all those things match is a is a really good thing to do. But as far as the POM goes, that's what that is. You have 180 days to fix it, it has to be at least an 88, and you can't POM on your official POM for the assessment, you can't POAM anything that's five or three points, and then some of those one-pointers.
SPEAKER_01Okay. So say a company has an SSP and a POM. Um are they basically ready compliant then, you know, or is there more on the table?
BrookeAaron Powell There's more on the table, and there's a lot more things uh that you have to do to actually be ready for an assessment. Um so you should, once you get everything in order and and you declare yourself ready in 110, right? Uh well that means that you have uh all your, you know, your authorized user list, authorized device list, remote users, um you have your boundary statement, you have your network diagram, uh your data flow diagram, stuff like that. So all those things should be in place when you say you have 110 and you're ready for you know an assessment. So but really ready for an assessment, you also have to have uh all your you have to have a bunch of proof uh ready to go. So you have to have uh you know screenshots of your users to prove to show that you know you have uh the users defined in intra ID or in uh Active Directory or Prevail or whatever it may be that you have them defined. Uh you know, you might it might be audit logs, you might have some shot, you know, some screenshots of audit logs, might even have a f uh uh an export of some audit logs or you know, something like that. So you need all that proof as well. Um and if you're getting ready, it's good to have that proof and then get another set of that proof uh later on when you're ready for your assessment, your third-party assessment. So um that way they you can say, look, here it is when we started, here it is quarterly, here it is right before this assessment, right? And so that's part of what we do right before an assessment. Uh we may have you know a bunch of that uh, you know, all the logs and everything else that have been uploaded, but right before that assessment, we go grab that evidence again and upload it and and have it ready to go and uh get all that ready. I mean there there's just so and you already know this, but just so everybody there knows, whenever we upload uh everything for an assessment, there's roughly somewhere over 400, 450 uh documents uh and artifacts that we upload. Uh that's your SSP, your uh policies, your diagrams, your procedures, uh, and all your screenshots and stuff like that. That's data can easily be 450 um documents or artifacts, whatever you want to call them. Uh so that it's just to explain, there's quite a lot. So there's a lot to it.
SPEAKER_01An absolute ton.
BrookeYes. One of the other things I just saw in my notes that I forgot to say uh is uh customer responsibility matrix or a CRM. We use that term interchangeably. Um uh when we say CRM, we also mean an SRM, which is shared responsibility matrix. Preferably. Uh that's one of the things you also have to have if you have a have an ESP uh uh external service provider that you're working with, you have to have that CRM or SRM. Preferably it's a SRM, because an SRM will show you what uh the vendor's responsibility is and what the customer's responsibility is. It lists both out there so it's a it's very clear. CRM technically it's his customer responsibility matrix, and it just shows just what the customer is responsible for, and that's what's required, but it's a lot better to have both to show what each does. So that that has to be part of that as well. Has to be part of every ESP that you use, you have to get that. If they're um if they deal with any SPA, uh uh SPD, SPA um security protection data or a security protection asset. Uh if they uh if they are a security protection asset or deal with any security protection data, you have to have one of those. Of course, if they deal with CUI, you have to have one of those, and they may have to be FedRAMP authorizer equivalent. Uh so but anyway, those CRMs are very important.
SPEAKER_01So I had a call with someone the other day um
Check Contracts For DFARS 7012
SPEAKER_01who said that they had already gotten um an assessment. Um and uh I was a little confused by it because um they didn't have a certification, um, but they had had an assessment, you know, done um from an assessor. Uh so um can you kind of clear up um what uh an actual assessment is and um you know what a C3PAO is and um you know who needs it, uh how many there actual are and and all that fun stuff?
BrookeSure. So there's two types of assessments. Um one is a self-assessment and one is a third-party assessment, or uh it's either level two, uh CMMC level two self-assessment or CMMC level two C three PAO. So C through PAO is a third-party organization that can come in and do that third party assessment and give you your certification. Um so any one of these um uses the basically uses the level two CMMC level two assessment guide, right? So uh if you if you do a self-assessment, you really, really need to the very, very least download that level two self-assessment uh um uh assessment guide. Um the level two assessment guide anyway, and go through that and do your self-assessment following that uh following that assessment guide, right?
SPEAKER_01So to clarify, if you do a self-attestment, a self-assessment or put in a Spurs or SPRS score, you don't just want to go off 110 questions. You should download the level two self assessment guide from the DOD and you should use that to perform your self assessment or to go through the questions. Is that right? DOW, but yes. On the link it still says DOD. It does do that.
BrookeD O D C I O, yeah. So uh yes, you do want to use that assessment guide. Uh you don't want to just look at the controls and go, yeah, we're good on that one. Yeah, we're good on that one. Um so you want to download that guide and go through it. Again, it's probably if you don't have a CMMC expert in-house, it's probably worth hiring somebody to come in and do that uh do that assessment for you.
SPEAKER_01Even if you have an IT guy.
BrookeEven if you ha especially if you have an IT guy, uh if they haven't gone through all the training, if they haven't gone uh to a bunch of conferences and and listened to a bunch of the uh Cyber A B town halls and all that kind of fun stuff.
SPEAKER_01Well I'll also tell you a little secret, secret, you know, um piece of information. So uh whenever if you're the CEO or management and you're not the IT guy, or even if you're the IT guy, um and you ask uh one of your people um to fill out this questionnaire, if they're in any way responsible for compliance or your IT, they often feel as if it's a reflection on them if they answer it poorly. Which is not the person that you want answering that, because you don't want a self-inflated score that misrepresents you. Like you you don't want someone's and hopefully this isn't taken the wrong way, but ego or something to come into it where they're like, oh well, we kind of do that, you know, or oh yeah, we you know, we're we do this, you know. If it feels in any way like a reflection on them or their job or how they're doing it, then you're not gonna get the right answer. It needs to be a black and white, because if you answer it in a way that uh is favorable when it's not necessarily the most true thing, you're introducing quite a bit of liability. Is that right? Fair to say?
BrookeThat is absolutely fair to say. And what I'll add to that is it goes uh also back to what I was saying is that uh it generally is because somebody is not trained and doesn't completely understand uh what the controls are asking for. Right. When it asks for an authorized user list, you know, an IT guy's like, heck yeah, I got that in Active Directory right here. Yeah, we've got an authorized list. I don't put them in there unless they're authorized, you know? Well, that's not exactly what they're talking about. So uh so you gotta know, you gotta understand what it's talking about and uh you know why it may or may not be met. Um you're right, no, it's not a reflection on you necessarily. Um there's just a a lot to know, so you gotta understand that. And and downloading that assessment guide is a very good first step that should at least tell you that there's more to it than you thought and that you may need some help. So yes, that's uh so that's what a self-assessment is, uh or self-addestation. Um the uh level two uh see-through PAO is with a C through PAO coming in and uh doing the same thing basically, uh except in a very formal manner, um and uh and in a manner where they can't give you any sort of advice or consulting. That's key to remember. Uh well, you know, why is why are you saying this is not met? Well, you know, uh your documentation doesn't match. Well, what do I need to fix? I can't tell you what you need to fix. Well, that sounds kind of dumb. What am I I don't know what I'm supposed to fix, you know? So um but anyways, when they when they come and do your certification, they can't do any sort of thing. Anything that even remotely looks like it might be some kind of consulting.
SPEAKER_01It's not because they're a jerk, it's because they are barred from doing it.
BrookeThey might be a jerk. I don't really know. But they might be bull. Uh so yes, they are barred from doing it. The the um um code of professional conduct, the ethics statement that uh you have to sign to be a CCP, a CCA, uh C through PO, anything else in the ecosystem, is they they stress and stress and stress all the stuff in that uh the COPC. And uh one of those things for assessors is that you can't uh give any uh consultation if you're doing the assessment. So they can give consultation, but then they can't do the certification assessment, right? There's a number of assessors that are out there, and this is this is one that the uh DOWCO Kirsten Davies got uh a little wrong. Uh she said there's uh only a hundred assessors out there, uh, and you j that's just not
What CMMC Level 2 Requires
Brookeenough for the demand and and all that. So uh there's not actually just a hundred assessors. There's at this point, there's there's probably even more now, but the last number I heard last month was 111 uh C through PAOs. The actual bottleneck for uh um assessments would be there's not a bottleneck right now because there's not enough demand, or before the pause, there wasn't enough uh enough demand to be a bottleneck, uh, but the actual bottleneck would be the number of assessors. Uh because it's really I mean you can have one C through PAO that has, you know, a hundred assessors working for them. Um so the actual bottleneck would be the um be the number of assessors, and we've got we've got over a thousand assessors. And so uh then when you add in CCPs that can also help with assessments, that that drives the number way, way up. So um so it's the so an assessor, a CCA, you have to have at least one lead CCA, and there's a certification for a lead CCA. Um uh you have to have at least one lead CCA and uh another CCA perform the assessment. CCPs can help with that assessment. Um then you have to have a quality uh assessor, uh also a CCA. So um you have to have those three uh at least those three do the uh do the assessment. Now the quality assessor isn't really involved in the assessment itself, but they're involved in making sure the quality of the documentation is is good and where it needs to be before it gets uploaded and all that kind of fun stuff. So that's the number of assessors we have. Uh there really was not a bottleneck. There was uh in fact, if you look at the the other uh proposed, there's uh a proposed rule. Um anyway, there's some some of the DFARS rules out there that um I think one was in the one of the proposed rules and even the final rules. Uh but the numbers they put out in those rules, the CMMC ecosystem was was far surpassing. Uh we were set to like 5x at the end of the year. 5x the um uh eclipsed the numbers that they thought we would need uh by five times uh at the end of the year. That's what that's the pace they were on. I mean, the ecosystem responded and was doing a good job of going through that. The problem is not the number of assessors, the problem was uh the number of companies who were ready for assessment. Uh so not to get too deep into the uh whole reason for the pause, but uh if you go back and look at the you know why companies weren't uh ready, the they just weren't they weren't compliant, so the problem was not the certifications really. The problem was they weren't compliant in the first place. And so if they were compliant in the first place and they just had to get a little documentation ready for, you know, for an assessment, then yeah, great. You know, but nobody ever expected to need one hundred thousand certifications as they as they pointed to for the pause. Nobody ever expected to need a hundred thousand certifications the first year. Uh and now that they've paused it and uh shot every C through PO and CCA in the foot, I don't see how they're gonna ramp up that much uh assessment um capacity uh quickly next time. I don't know who's gonna trust them, right? Uh but I digress. Uh please don't shoot the messenger. So uh but yeah, that's where we're at. That's who can perform assessments. You can perform your own self-assessment. You can get a uh you can get anybody to come in and help you. It doesn't have to be uh for a self-assessment. You don't nobody has to be certified or anything like that, but it is a good idea to have you know a somebody that's a CCP, somebody that's a CCA, uh, somebody that's level two certified to come in and do your assessment because they they know and they likely have been through uh this stuff before. So uh that sure helps.
SPEAKER_01So we'd already talked about what determines your assessment or certification requirement. But I don't think what we've addressed in this episode, at least thus far, is what determines your level of CMMC.
BrookeYeah, so uh there's three levels of CMMC, level one, level two, and level three. There you go. Uh level one uh is um you have to you have uh 15 controls, um and uh I can't remember exactly how many assessment objectives it were roughly 57. Um so uh but that level one covers just FCI. FCI is uh federal contract information, and
POA&M Rules And The 180 Day Clock
Brookefederal contract information uh is any of that contract information that is non-public. So in other words, think of it like this: if you have to log in to a place uh to somewhere to get that information about that contract, that information uh is is FCI. If that information on that contract, like uh the company name, you know, I don't know, or the the person's name or phone number, if that can be found publicly, then that's not FCI. Uh but there there is going to be stuff on that contract uh that is not uh public facing, uh that's not publicly available. Uh again, if you can if you have to log in to get to it, it's not publicly available. So um so that's FCI. COI is level two, and so if you have if you're uh will if if you're gonna store, process, or transmit uh any CUI, controlled unclassified information, then um then you have to be level two compliant, right? Or level level two self-assessed or level two uh C through PAO assessed. And uh CUI is gonna be information um typically like uh drawings or specs or uh something like that, right? Um there's uh all sorts of different types of uh CUI. Uh hopefully uh it's actually labeled, you know, what kind of CUI you have. It could be CTI, uh controlled technical information, and and a whole bunch of other stuff. So and it could be basic or it could be specified. Specified is if it has uh some dissemination instructions uh like um export controlled or uh no foreign or something like that. Uh so but if you if you have uh if you're gonna be processing, storing, or transmitting CUI, that's level two. Level three is gonna be more sensitive, uh more sensitive data, and uh you'll you'll know if you have level three. It's gonna that is a very small subset, uh at least from what they say. It's just a very small subset. Uh we've had some people call us and say, hey, we need to be level three certified. And so we talk to them about it and say, hey, uh tell me why you think that, and uh tell me what kind of information you have, uh, and we'll let's do let's determine if you really need level three because that's that's a whole nother bar. Uh level level one's reasonably easy down here, level two is up here, and level three is way up here, right? So uh let's determine if you actually need it. So uh most of those folks that have called us and said they need to be level three certified uh don't actually need that. And they've they go back and look at things and figure it out, and they're like, oh well, okay, it's really less level two, right? Um the other thing people get confused a little bit is that CMMC level one had five levels. And so uh level one mapped really to level one, I believe, if I recall. Level three actually mapped to level what now is level two, and level five mapped to essentially essentially what is level three now. So there's only three levels, level one, two, and three. Um, and level three is a very small subset. Um at least at this point, who knows if they'll change anything. Uh, but level two is where the majority of um majority of uh companies will need to be at.
SPEAKER_01Well, Brooke, thank you for your time today.
BrookeAbsolutely.
SPEAKER_01And uh hopefully here in a few days we will see uh w what the the DOD has for us and and what the results are gonna be.
BrookeI I'm I'm waiting. I I'm excited to hear.
SPEAKER_01It's happening one way or the other.
BrookeIt is happening one way or another. At least we think it's gonna happen. Who knows?
SPEAKER_01Supposedly. If you have questions about what we covered, please reach out to us. We're here to help fast track your compliance journey. Text, email, or call in your questions, and we'll answer them for free here on the podcast. You can find our contact information at cmc complianceguide.com. Stay tuned for our next episode. Until then, stay compliant, stay secure, and make sure to subscribe.

