Submit any questions you would like answered on the podcast!
Every CMMC vendor says the same thing: "we cover 80 out of 110 controls" or "90 out of 110." Austin and Brooke break down what that claim actually means, why "maps to," "satisfies," and "supports" are not interchangeable words, and why you almost always still have work to do even after buying the solution.
In this episode:
- What vendors actually mean when they claim to cover a specific number of the 110 controls
- Why "maps to," "satisfies," and "supports" are different claims with different implications for your compliance program
- Why you can't stack vendors (40 controls from Vendor A plus 50 from Vendor B does not equal 90 covered)
- The moment your computer enters scope even when you're using a fully FedRAMP-compliant vendor: downloading, caching, or transmitting CUI through it
- Why "I never saved it to my computer, I just passed it through" doesn't get you out of scope (process, store, or transmit is the bar)
- How to use a CRM (customer responsibility matrix) or SRM (shared responsibility matrix) to know exactly where a vendor's responsibility ends and yours begins
- Why your MSP or IT provider needs a CRM too, not just your cloud vendors
- The exact questions to ask any vendor before you buy: which control numbers, full satisfaction vs. contribution, which systems and assets it applies to, and what's still on you
- Why vendors can only speak to their own product, not your specific environment, and why you need someone (in-house or outsourced) who understands your full compliance picture
Welcome And Episode Setup
SPEAKER_01Hey there and welcome to the CMMC Compliance Guide Podcast. I'm Austin and I'm Brooke from Justice IT Consulting, where we help businesses like yours navigate CNN C and NISP 8100-171 compliance. We're hired guns getting companies fast track to compliance. But today, we're here to give you all the secrets for free. So if you want to tackle it yourself, you are equipped to do so. Let's dive into today's episode and keep your business on
What Vendor Coverage Claims Mean
SPEAKER_01track. Today we're talking about vendor marketing when it comes to CMMC, specifically the claim you see everywhere by every vendor, it seems. They'll say something like, We cover 80 or 90 or 60 out of the 110 requirements. Today we're going to talk about what that actually means and some of the nuances behind that. Okay, Brooke. So when a vendor says they cover a certain number out of the 110 requirements, what does that actually mean?
SPEAKER_00Well, it can mean a could mean a few different things, right? Um depends on what kind of solution it is. You you need to really look into it and see some of them, uh some of them cover the um control fully. Uh it also depends on how you've deployed whatever solution it might be, right? Um if uh that's the only solution you're using to cover uh a certain set of controls, then uh yeah, they very well might cover most of those controls they say they cover, but you also part of that is documentation. And while you might use some of their documentation, it's still got to be customized. So uh, you know, you've you know whether they support it, whether they, you know, it's an all-in-one environment, whether uh they cover some of the controls or whatever on a lot of these solutions. Uh yes, they may cover 90 out of 110 of the controls, uh, but you need to figure out how that what that really means and look down into the fine details. Uh, and I'm not saying they're a lion, really. Uh it's marketing, and that's how everybody tries to get you to buy their CMM sleeve, CMMC solution in a box. I just call it that. That's kind of a I don't mean it to be a derogatory term, uh, but that's uh, you know, their solution for CMMC, they try to get you uh to buy it by, or at least get you to come talk to them by saying that they cover 90 out of 110. And they're not lying. Uh but you've got to figure out what does that actually mean, right? Uh, do they fully cover it? Do you have to do your part? The answer there is almost always, yep. You do. You have a you have a you have a uh a part to play there. So you can't just depend on them and just not worry about it.
SPEAKER_01Well, that brings me uh to my next
Maps To Versus Satisfies Versus Supports
SPEAKER_01question. Your vendors use words like sports, maps to, and satisfies almost interchangeably. Are those actually different in what they mean and the implications of it?
SPEAKER_00They they are definitely different. Uh so uh maps to, if somebody says their controls map to this side or the other, it means they have some part in in those controls, and uh these are the controls they map to, right? Um if they say it satisfies those controls, uh then they that wording is still a little bit fuzzy sometimes because you really need to assess out the details, but that should mean that they cover that control completely, right? But I will tell you that there's a lot of those controls that are not that are the technical control and then the documentation part of it, and so you have to document, you have to write down what you're doing uh to satisfy that control, and you can't just lean on the vendor just to do their part and not worry about it, right? Um, so that's one you have to really look into. Uh and I support is uh is I know some people use that term and it's a pretty vague, really. Uh if they support the controls, uh you definitely need to just figure out what it is they have, right? And uh they're either gonna have a a FedRamp authorized solution, moderate or high. Uh they're gonna have a FedRAMP equivalent solution, or uh if it's I'm assuming we're talking about handling CUI, so it's gonna be one of those. Could be uh, you know, could be a uh if they're not a CSP, it could be a a level something that's level two certified as well. So um, but in it any of those cases, uh you should be able to get a CRM and SRM from them, they kind of suss that stuff out. And I hope I didn't jump jump ahead too far in what uh what we're talking about.
SPEAKER_01No, you're good. You're good.
Why You Cannot Stack Vendors
SPEAKER_01So uh the next question I have for you is um you know what if people stack a few vendors together? So if vendor A says we cover 40 out of the 110 controls, and another vendor says we cover 50 of those 110 controls, does that mean uh that you get to 90 out of 110?
SPEAKER_00That would be that would be awesome. I wish it was that wish it was that way. I wish you could stack vendors and that they all work that way. Uh in in the real world, it's not gonna work that way. I'm sure you could figure up some scenario where you could build on top and and make that work, uh, but uh I can't think of any off the top of my head. So um again, you just kind of need to figure out where they're at. I know on a lot of things, uh, when we're getting clients ready or going through assessments or or whatever it may be, um, you may have one control and you have uh you know uh project management or you know some sort of software like that that's part of the authentication, then you may have Microsoft 365 GCC that's part of it, then you may have uh Active Directory that's part of it, you know. So there may be different things there and they they they all overlap on that. They may take care of 40 here and 60 here, uh, or at least address those, right? Um, but if you have more than one of those solutions where you depend on authorization from them, um that's where it starts to get a little complicated. It's also where uh your assessments uh that's where where they start to get more expensive, right? If you layer on more of those solutions and uh an assessor has to go through and suss out all the different CSPs and ESPs and all that kind of fun stuff, um, it gets more complicated to figure out. If it's it's a if it's a very simple assessment and very simple boundary scope, uh, then you know it's much easier for them. But uh but no, unfortunately, they don't generally stack on top of each other.
SPEAKER_01And I would assume that would mean that two different vendors might even have to have the same control satisfied depending on what um you know the solution is. So if you have a ERP that's Fed ramp, and then you have a some CUI storage solution that's FedRAMP, then they might have to have both the same controls covered, and uh you're not double dipping there, but you're using both products and they both have to have the same controls. Anywhere CUI goes, all the 110
When Endpoints Quietly Enter Scope
SPEAKER_01controls have to be applied.
SPEAKER_00Absolutely. You know, even if you're even if you have something like uh Microsoft 365 GCC High and you're using it as your single uh point of authentication, uh where your maybe your ERP or MRP or whatever it is, uh, or whatever other solution uh authenticates against that. Uh that's great. Single sign-on is wonderful. Uh it simplifies some things. You you can act most ERP solutions won't uh allow you to manage uh at the device level, just the user level. So that's a really good thing to hint hint. That's a really good thing to uh implement single sign-on with 365, but uh you still are gonna have other other parts of that. Their permissions are likely still gonna be in not in 365, but in the other tool, you know. Uh so it's even if authentication is taken care of, uh, you know, the the roles and the functions and stuff like that uh won't necessarily be.
SPEAKER_01That makes sense. So um another question I have for you is if I have a vendor that's got you know whatever out of the 1210 controls covered, and I have CUI in there, and I download it, or it goes to my downloads folder, or I copy it into my clipboard and I put it in my CAM software, um, or you know, it goes from you know uh you know whatever CUI or FedRamp vendor that has my controls over here and it passes through my computer and then to go into another solution or software, does that mean the computer um has though it inherits those controls from the vendors, or do I have to do all the controls on my computer as well?
SPEAKER_00Actually, I I just knew what you're gonna say, and you said the other thing. So uh glad I didn't jump ahead. Um, so you're that does bring your computer into scope, and those controls do not flow down to it. So, you know, a typical one of those things is gonna be hey, I've got a VDI solution, all my stuff is in that VDI, and it stays there and and we're good. Except for this one computer, we have to download the stuff and get it over to these machines, you know, to to read the instructions, you know. That's fine, but that computer just came into scope. You just pierced that uh that BDI solution uh with that computer to download it, right? So those are the things you gotta think about. Uh you know, if it uh you know if you download it from a you know a compliant customer portal onto your computer, but immediately go put it in your uh in your CUI enclave, uh, that's great. And you delete the file, that's great. Except it doesn't really matter your computer's in scope. There's no time frame that says, you know, hey, if the download is only there for 20 seconds, then then it's okay. It's it's not in scope. It it no, it's it's in scope.
SPEAKER_01What if I never download it to my computer, but I I log on to a customer portal and then I go save it in the
Process Store Transmit Defines CUI Assets
SPEAKER_01you know drive or uh file storage solution or or whatever. And I never actually save it on my computer, but I'm downloading it from the customer portal right into the FedRAMP vendor that has all my controls covered. Does that mean my computer's out of scope? I think you've uh been sitting in some of our meetings.
SPEAKER_00X ray no. Uh I mean, so uh the the bar for CUI is whether uh whether a a device whether an asset is a CUI asset or not, is whether it processes, stores, or transmits. So at that point, you just transmitted it, right? And you you may have even processed it. So um depending on what you did with it. So um so yes, that is uh if you process store transmit CUI with an asset, then it's a COI asset.
SPEAKER_01So that means the computer is in scope. I can't get around that. Nope. Okay. That's uh yeah, it these are uh these are things that you know I hear all the time as we're bringing, you know, as people reach out to us and uh if they could store where where is it stored, you know.
SPEAKER_00Oh, that's good. That's one of the three legs of the stool, but not the other two, right?
SPEAKER_01Yep, absolutely. And it and it still traverses your network. I mean, um, you know, even if it's not stored. So it's it if you go to customer portal and you dump it into the Fed ramp vendor, then it's it's still going through your router, your firewall, your internet connection through that computer on the RAM or the paging file or whatever, and then it gets put into the um the vendor. So it's it's very much um it's not you're you're you're not it is you're not skipping it traversing your computer or your your network. Um it is very much handled through that. And um, you know, it's uh people should want to reduce their scope as much as possible and and um and put um you know, if you're paying for a vendor to do all the thing a bunch of things for you, then you should you know use that as much as possible, certainly. But there's just some realities of compliance that you just can't get around, and that's one uh that I comes up a lot. So I I wanted to talk about specifically this and ask it in the way that our customers and prospects ask.
SPEAKER_00So yeah, and our boot camps with clients, they uh uh that's that comes up a lot, you know. Well, we don't we don't download it to that computer. Okay, no, not exactly, but here's how it works. So uh, you know, your IT folks are gonna understand that as long as they understand process, store, and transmit. But you know, your your uh CEO or your general manager, they they just it it may not they just may not think of that right.
SPEAKER_01So uh yeah, we have well even the software developers may not think of it, you know. Um true coming from the solution, um, you know, or the the sales engineer, you know, um that with the vendor, they may not consider that that piece. So you really have to watch out for yourself or else you might find yourself putting uh um going down a road too far before you realize it was the wrong wrong turn that you took, you know. Right, exactly.
SPEAKER_00And what are we uh what are we supposed to do first? We're supposed to scope first, figure out the flow of information.
SPEAKER_01Absolutely, absolutely. So all right, on to our next
Use CRMs And SRMs To Draw Lines
SPEAKER_01question. So um how does a contractor, uh, an organization that's trying to get compliant or seeking certification or assessment, how do they actually figure out where the vendor's responsibility ends and theirs begins?
SPEAKER_00Uh well, typically, uh I mentioned it a minute ago, that's gonna happen with a CRM or an SRM. A CRM is a customer responsibility matrix, and just blanketly that's how everybody called what what do you call both of them, uh, just um uh you know in general, uh, but technically they're separate. A CRM shows what the customer responsibilities are, an SRM, a shared responsibility matrix, uh actually shows what the vendor's responsibility is and what the customer's responsibility is. Those are quite frankly, those are better to have because you know exactly what's covered and then exactly what you need to do. And that's that's the biggest thing. Anybody that provides any solution, whether as to a security uh for uh for CUI or whether you know as handling CUI itself, um, you know, they they should have those. They should have those uh CRMs for you. CRMs, SRMs, we'll just call one big happy family.
SPEAKER_01Yeah, and to that point, I mean, shouldn't uh MSP or your IT provider you know have one as well?
SPEAKER_00Any vendor and all, any ESP, right? An ESP is an external service provider, so that's any provider external to you that uh that helps you with uh that that has anything, any processing, storing, or or transmitting of uh CUI, right? They're gonna need to meet one bar. And then uh if they if there's services that if a provider that provides services to secure that CUI, that's a security protection asset or an SPA, and they definitely have to have a CRM as well. Helps with their level two uh certified, but uh they don't have to have that. They but they do need to have one of those CRMs. And I might say uh again, I hope I'm not jumping on the head too far, but uh uh the those CRMs or SRMs, it's best if they're broken out per assessment objective. So that's 320 of them, uh, but they at least be broken out into the controls, 110 controls uh of CMMC or NIST 171. So they have to be broken out like that before an assessor will accept it. They won't accept anything based on NIST CSF or ISO 27001 or um anything else, they won't they won't take those. They'll they'll take so they have to be based on uh CMMC controls. Preferably assessment objectives makes it easier.
SPEAKER_01Awesome. Makes sense. So um, you know, if you think if you're using um, you know, um a compliant vendor or a FedRAMP vendor that you know stores your COI somehow, or maybe it's an application or or whatever, they take care of some of the controls. Um, you use a customer portal, and then you know, you you obviously you're left with your computer and your network, and and you want to offload as much as possible. But as we just learned, you you can't fully offload everything unless unless you just um, you know, a lot of people can't, and at least the customers we're dealing with are typically, you know, uh construction or manufacturing or you know, um distribution or something where um you know they're dealing with you know real tangible things oftentimes. Um, and so if you can live in an enclave in a box or something, that's that's great. Um, and you know, if that's possible, then go for it. But a lot of people can't. Um and so you have to take care of, I kind of think about it as the last mile of compliance. So you have yeah, you know, you want to offload as much as possible as you can, um, but it's not generally possible to do offload, you know, the entire uh process, right? Um, or compliance. So um, you know, you want to scope that that last mile, whatever you have on your network, as tight as you can without um, you know, really hindering operations or efficiency. Um, but uh, you know, the the vendor that you know, if you're not gonna do it all internally, then you're probably gonna have an IT provider or an MSSP or MSP that that helps you at that last mile. And so it'd be real good to ask them uh, you know, ahead of time for that CRM or how they're gonna handle that that um you know the the you being the connection points, all of these vendors, right? So um, because they they really need to be able to understand that for you and um and help you uh with connecting all of these vendors and compliance solutions and your your endpoints and in computers and stuff all together where it's all in a compliant you know package. Um so uh it's um it's important to ask them as well. So I know we're talking uh a lot about cloud vendors and stuff here, so I just uh wanted to call that out because we didn't have it in our our show notes. So absolutely.
Vendor Questions That Prevent Surprises
SPEAKER_01Cool. So the next question I have for you is when someone is uh evaluating compliance product or solution um right now, uh or if they are evaluating a compliance product or solution right now, what should they actually ask the vendor? Can we give them the listeners some uh some good questions or tools to go to them and ask?
SPEAKER_00Yeah, sure. Uh so I mean it's nice to know somebody covers uh you know 90 out of the 110 controls or whatever it may be. Uh, but ask for that CRM, as for uh first really ask what specific requirements do you cover, right? Um and the actual control numbers, like I've just talked about a minute ago, how the CRMs have to kind of line up to the controls or the assessment objectives. Um and then secondly, uh, you know, do you fully satisfy those requirements? Uh do you contribute to them? Um, you know, what what else is involved in that control being fully covered? Uh uh, you know, next thing probably third is uh you know what systems and assets uh does your coverage actually apply to? You know? Um there's it could be workstations, it could be you know a whole uh VDI um solution, a CMMC in a box solution. Uh there's a you know could be uh file sync and share uh that's covered, and so everything's you know stored in their uh in their solution, uh, but it's processed and transmitted on your machine, uh or maybe processed on your your machine transmitted through theirs, uh, which still brings your machine into scope, for instance. Uh another one I'd uh I'd say is uh part of that uh part of that shared responsibility matrix or CRM uh customer responsibility matrix is what am I still responsible for on top of what you provide? Right? You do this, what do I still have to do uh to be compliant for this for these controls, right? Uh probably another one um is going to Be uh, you know, can you show me uh just what we just talked about? Uh can you show me a customer responsibility matrix or a shared responsibility matrix that lays it all out in writing? Um and is there look at it? Is there does it need to be explained? So you know, uh, you may you may look at it and go, This is this is all Greek to me. You know, I need somebody to help me figure out what this means. Um so really if they if they those are the kind of things you need to ask, uh, and they really can all be satisfied by an actual shared responsibility matrix, which lists their responsibility and your responsibility. Uh you may have to have some explanations on some of it. Um so the shared responsibility matrix should list uh what you have to do uh in relation to that to to finish that uh solution out. So and hint hint they uh they don't uh typically uh consider you having multiple solutions that uh that may uh address a certain uh control. Like we were talking, we'll just use authentication again, you know. Um how's authentication handled? Uh, you know, maybe their solution takes care of that, but if a computer comes in scope, what about authentication for that computer? How's that handled, right? So that's now you your documentation that you have has to has to bring that um uh bring that into the definition of that, right? So those are the kind of things you need to talk about, uh need to ask and make sure that you're very clear on uh with those vendors. And I'm again I'm not here to say that they're lying, they're not lying, they're just they're trying to explain to you that hey, we've got all these uh we've got all these controls that we cover and we make it a lot easier for you. And you know what, there's there's a lot that do. We use some of those vendors and and they do take care of some of those controls, but most of the time they don't fully satisfy those controls because there's more to the equation than just their product, right? Um kind of like uh, you know, when when I was still in the well, I guess I still do take exams for the CCP and all that kind of fun stuff, but uh when I was taking more uh certification exams, Microsoft, uh old Novell netware and um all that kind of fun stuff, uh, you know, um when you took their test, you don't think about the real world, you think about their little product, their little environment. Their questions are based on that. They're not based on the real world. So how if this is a Novell network or a uh uh Microsoft centric solution or a Cisco centric solution, how would I answer this question, right? And so that's the same um same mindset you need to uh bring with these uh shared responsibility make matrices, I guess is a plural. Um so uh that's the same mindset you need to bring with that. So they're coming at it from just their solution. That's all they're coming at it with. Typically that's that's all they're coming at it with. So you've got to understand again, first thing you need to do is scope before you ever even go talk to a vendor. You don't need to don't need to talk to a vendor until you've properly scoped, right? Figure out your data flow, figured out what it is, what it needs to be, um, and then figure out vendors to fill to fit a solution for you, right? So um but so anyway, that's that's what you need to do. And again, the real world is always gonna be a little bit different than a vendor's takeoff.
SPEAKER_01Yeah. So, you know, the vendor is gonna be thinking about it strictly from their context of their relationship with you within the context of the solution they're providing and nothing else, right?
SPEAKER_00Yeah, I mean, and that's understandable. They can't think about you know 500 million different kinds of ways it could be used and give you solutions for each one of
Training Needs And Wrap Up
SPEAKER_00them, you know, and it's uh it's a it's a tall ask.
SPEAKER_01Yeah, yeah. And so that, you know, you you either need someone on your team that can really, you know, take pick up the football and run with it from a compliance perspective, or that's you, um, or whether that's someone that you you go find and hire, that's a CCP or something that can um, you know, act, you know, watch out for numero uno, you know, um, and make sure that um they're taking ingesting all these vendors that you're looking at using or using, and then you know, look at you know what your business is actually doing and how you're actually handling CUI and and uh what you plan to be doing, and then be able to integrate it all um from your perspective, not from the vendor's perspective. So that's either someone that you need to you know build in-house, um, uh you know, within your own skill set, with you know, in someone else's skill set on the team, hire somebody um internally or or outsource it to uh you know a good um uh consultant or something that can figure all that out for you. So uh because you know, your your product offerings aren't gonna be able to do that for you.
SPEAKER_00Right. Another thing I'll add in there, uh, you know, using somebody internally, whether you hire or or tap somebody to do that, um, if they aren't already a CMMC expert, then they need to be trained up to be a CMMC expert, and they need to have a lot of exposure. And uh so that's gonna be, you know, exams, that's gonna be conferences, that's gonna be, that'll be their life for a while to try to figure all this stuff out. Uh they have to know what define means, what identify means. Um, you know, they'll have to understand what monitor means, they'll have to understand all these words and how uh what they really mean uh in an assessment, right? Uh for an assessor's mindset. Um, because what an IT guy thinks of as define or identify or list, you know, might be a lot different than than uh, well, not might, will be a lot different than what an assessor thinks it means and what it actually means for CMMC, right?
SPEAKER_01Yeah, yeah. And we hope you love our podcast um and that uh it's a great resource for you, but uh we are not a substitute for good old-fashioned book learning, you know, um when it comes to that stuff. So you're you're still gonna have to go source those. Uh, if you're gonna develop that skill set within yourself or someone in-house, and they still need to go get those um, you know, uh classes or training that is more formal in nature. Um, hopefully we're able to give you a good context and information around it, but it you still really need those resources, don't you? You do, you do.
SPEAKER_00I you know, I was gonna say that you know you might be able to go listen to uh you know hours upon hours upon hours of all our podcasts and listen to us rambling, uh, but it'd probably be uh a whole lot quicker to go get a certification and uh read some other material that get directly to the point rather than uh you know us rambling. But hopefully these are uh these are uh well I was gonna say entertaining. Hopefully these are uh instructional and informational for people, but which seems like it is. We get some good comments, so hope that helps. Hope they hit hope this helps.
SPEAKER_01Absolutely. So um where are you headed? I hear you're going on vacation. Tell us about it.
SPEAKER_00I am uh going on vacation. Uh so uh my wife and I have been to Scotland a couple of times, and we just really love Scotland. We also have Scottish roots, uh both her and I, uh different Scottish roots, just so you know. Uh and so uh clarify. Yeah, exactly. And so I've never wanted to go to Scotland in August because that's when everybody in the UK and all over Europe and in other parts of the world, that's when they take their vacation, and a bunch of them, a whole ton of them, go to uh Scotland, and it is busy, busy, busy. And so I've never really wanted to go, but there's a uh uh the Royal Edinburgh Military Tattoo uh that happens at the Edinburgh Castle. Uh and it's a whole bunch of bagpipes and drums, and then some other military bands from around the world that come and play. Uh, and it's a really, really cool thing. I've seen videos of it, whatnot. You can look it up on YouTube and see, and and if uh you know you have any inkling of liking uh bagpipes and drums, then you'll love it. But uh, we've always wanted to go to that, but I never wanted to deal with the crowds. I figured I had so many, so many airline miles from going to all these CMMC conferences uh that I would use them. And so we got we bought us airline tickets to go to uh the uh military uh Royal Edinburgh Military Tattoo. Uh and we're gonna dip in, be there for a couple days, see the show, and then and then come back home.
SPEAKER_01There you go, there you go. When you first told me about it, I thought you were getting a tattoo in Scotland. So now I understand.
SPEAKER_00You're getting a tattoo of Scotland? No, not this old boy.
SPEAKER_01Well, I'll tell you, we um me and my wife went to Dublin on St. Paddy's Day, and that was an absolute blast. So um I can I can only imagine what that'll be like. Hopefully it's just as fun as um our trip.
SPEAKER_00So I'm hoping uh fingers crossed, right?
SPEAKER_01Awesome. Absolutely. Well, we'll go ahead and finish it up here um so we don't bore the listeners. If you have questions about what we covered, please reach out to us. We're here to help fast track your compliance journey. Text, email, or call in your questions, and we'll answer them for free here on the podcast. You can find our contact information at cmc compliance guide dot com. Stay tuned for our next episode. Until then, stay compliant, stay secure, and make sure to subscribe.

