Submit any questions you would like answered on the podcast!
We're recapping the Cyber AB's June 2026 Town Hall, five topics every DoD contractor needs to hear, plus what's changed since (including the CMMC Phase 2 pause that landed after this town hall happened). Stacey and Brooke break down the real enforcement numbers, the paper CUI rules everyone gets wrong, how to actually vet a C3PAO, and the FAR CUI rule updates working their way through public comment.
In this episode:
- False Claims Act enforcement: why almost every case comes from whistleblowers, not breaches, and why the discrepancies are massive (think negative scores, not "110 vs. 107")
- Paper-only CUI: when you're exempt from CMMC Level 2 controls, and the exact moment that exemption disappears (scanning, photographing, emailing it)
- How the town hall's November 10th "full steam ahead" messaging got overtaken by the Phase 2 pause memo weeks later
- What to actually ask when interviewing C3PAOs (assessor headcount, 1099 vs. employee, on-site requirements, SOCI screening status)
- FAR CUI rule updates: the incident reporting window moving to 72 hours, and the mislabeled/unlabeled CUI reporting requirement getting struck
- Why NIST 800-171 and CMMC were built for ongoing management, not a one-time snapshot, and what that means for your evidence and documentation
- Justice IT Consulting's own path through certification, and why that certification still matters even during the pause
Welcome And Town Hall Setup
StaceyHey there. Welcome to the CMMC Compliance Guide podcast. I'm Stacy.
BrookeAnd I'm Brooke.
StaceyFrom Justice IT Consulting, where we help businesses like yours navigate CMMC and NIST 800-171 compliance. We're hard guns getting companies fast tracked to compliance, but today we're here to give you all the secrets for free. So if you want to tackle it yourself, you're equipped to do so. Let's dive into today's episode and keep your business on track. Today we're recapping the Cyber A B's June 2026 Town Hall. So Brooke pulled over five topics out of that update that every contractor listening needs to hear. So let's start with the one that should scare people a little, enforcement. So starting off with enforcement, Brooke, what came out of the town hall
False Claims Act And Whistleblowers
Staceyon that front?
BrookeWhat came out of that really is that uh false claims act enforcement. Uh those uh the litigations cases, however, whatever you want to call them, however far down the road they get, uh they've all been settled uh as as opposed to they some of them did go through a court process, but they're settled before final verdict. I don't I don't think there were any that were settled by verdict. So but anyway, of all those falc false claims acts, they've they're they're continuing to march through those and and um and address those. Um and I will tell you, most of them are from whistleblowers. The the vast majority are from whistleblowers. Uh not very many are from uh from other other arenas, other notices, I guess, or you know, a breach or or things like that. So but the uh the largest majority of those, huge majority is is a whistleblower. So uh but we haven't seen any uh false claims act uh settlements that were for somebody that said they scored 110 and and uh you know somebody turned them in or maybe they had something happen or whatever and and uh they got assessed. You know, Dibcat came in or whoever comes in and and assesses them looks at it and says, uh, you know, you didn't really make 110, you made 107. So we're you know, we're gonna we're gonna take you to court over this. They they don't do that. Well, I guess they might do that, but but uh, you know, these uh almost all these are huge discrepancies, you know. Instead of 110, you've got a minus 163 or whatever it is, you know. It's it's uh they're huge discrepancies. Uh people that uh said that they were doing everything and basically just check the boxes, you know. Uh, you know, Kirsten Davies is uh uh the honorable Kirsten Davies is all worried about uh people checking the boxes, you know, for CMMC and the certification. I hate to tell you this, but the certification part is not checking boxes. That's actually validating it. The checking the boxes part is what people do when they go, yeah, we're good. I promise, you know, and just uh self-assess and upload their own scores, right? Uh not everybody. There are a lot of people that do it right. There are a lot of people that have wanted to do it right, and a lot of companies that have wanted to do it right from the beginning. We have clients that, you know, have been doing this for a while, and uh, you know, they want to get this done and they want to do everything right. Uh they do lament how much it costs, but you know, they say, hey, Joe Blow down the road, you know, uh I know they're not meeting all these controls and and uh they're they can offer their services for less, you know, and that really bothers me. It really pisses me off. I'm like, well, I I don't know what to tell you, you know, other than maybe be a whistleblower, but uh not really. I wouldn't necessarily suggest that. I wouldn't want any bad juju to come from that, right? Uh but point is uh that enforcement is real. Um most of it is from whistleblowers, people that say, you know, that go to the uh Department of Justice or whoever they uh report it to and say these people say that they're compliant and they're not, they're not anywhere close.
StaceyAaron Powell So it looks like there were talks about paper CUI. So if a company only handles hard copy, are they in the clear?
BrookeAaron Powell Yes. Uh so if they only handle paper CUI, they're in the clear as far as a CMMC level two assessment goes. They still have to uh protect that paper CUI. It's not like they don't have to protect it. They can't just leave it, you know, open in their truck as
Paper CUI Rules And Traps
Brookethey're, you know, as they're doing their job, just leave it in there all alone. They they can't do that kind of stuff, right? They've got to actually protect uh that paper CUI uh and they gotta protect it according to DODI, uh DOD instruction, I think, uh 5200.48, I believe is what it is. Um but the uh as long as you don't, as long as that stays paper CUI, it's beholden to that and not CMMC level two, uh all 110 controls. Um the moment you take a picture or scan it or or something else like that, uh, that becomes uh electronic, then yes, at that point CMMC level two uh controls do apply. So watch out for that.
StaceySo in the town hall, there had been a lot of confusion around November 10th, 2026. But as we now know, a memo came out and kind of turned everything on its head. So can you elaborate on that?
BrookeI can. And so we uh uh we are obviously recording this uh a little bit after the uh I know this is a June town hall, we're just now getting around to it, but
November 2026 Pause And What It Means
Brookeuh uh the uh they said the enforcement was coming. Uh, you know, everything's full steam ahead. And then on the uh 14th, uh the uh July 14th, the uh um Department of War CIO Kirsten Davies announced that uh, you know what? Just joking, we're gonna put this on pause. So uh they're just joking as a paraphrase and you know inaccurate. But um anyway, they said we're gonna put the uh certification, uh the the requirement for certifications on contracts that was supposed to hit on November 10th, they're gonna put that on pause. Interestingly enough, the pause is a 60-day pause. And so November 10th was roughly 120, 116 days away or so. I didn't do all the math, but you know, almost four months away. So um the uh so it'll be paused. There's no question. Uh well, I guess there is a question. They might come back and say, you know, uh no, we're moving forward anyway. I kind of doubt it. Uh if you read the memo that came out, um, I think we talked about this on uh the last episode. Um if that has that been uploaded yet? Yes. Yes. So there's a there's a link on that episode. Can you put a link on this episode to that memo? Okay. Uh good. Stacey will take care of that for us. Uh so uh anyway, if you read the memo, it's pretty clear that they want to do something about it. I don't know why they waited till now. Uh and I do have a problem. Uh a lot of people have a problem with the facts and figures that they gave gave. I should say uh I don't know if I should say facts because they weren't facts. They were facts from somewhere, but not accurate. So um, you know, they they way overblue the uh cost of a certification. You know, they said they could be $600,000, $500,000. I I've not seen any for all of our small business uh customers that we we take care of uh that we've helped get quotes for their uh CMMC level two assessments and and the mock, even even with the mocks included, um I don't know that any of those has been have been over $50,000 with the with the mock included. Uh you take the mock out of that, and some of those are in the 30s, you know, uh which is still expensive. I'm not saying that's not. So we went through it, we ate our own dog food. It is expensive, uh, it stinks, but um, but in any case, uh it is not the numbers that they posted. But when you go back and think about it, they she got the numbers from the SBA, the Small Business Administration, and the Small Business Administration and the government call small businesses, in this case, probably 500 people or less. So a 500-person company is a little bit different than a 20-person company or a 50-person company. You know, and uh 20 to 50 is uh a large majority of what we serve. Uh we serve some larger and some smaller, but uh that's uh by a large majority, 20 to 50 uh people is how many or uh 20 to 50 computer users is the size of the companies that we serve. Uh I can tell you their estimates, uh their quotes and what they paid for their assessments is nowhere near that. That is not 500,000, 600,000. Even the cost of uh all the implementation doesn't even get that close. So uh SBA and Department of War, you gotta do better than that. So uh they also said uh that there were uh a short of age assessors, there was a uh capacity problem, and there's not. The DOD never intended a hundred thousand uh dib contractors to be uh certified the first year. That was never the intent. Uh we are, and I say we because we're part of the ecosystem, we we don't do any certification, so I guess I shouldn't say we. Uh they, all the C three PAOs. Um they uh all the C through PAOs have uh have done a great job doing the assessments, getting them through, bringing the cost down. I know whenever uh uh you know the cost first came out, you know, they were they they were here, they went up, and now that we've gone through this, the cost will come down. Uh so they're more reasonable now. They're they're more they're closer to what a SOC2 type 2 and that kind of audit would be. Um the uh but they have extra capacity left. There's a number of assessments here, and you know, the capacity is up here. So do they have enough capacity to do 100,000 assessments the first year? No. But guess what? There's not there's not that many companies that are ready and want wanting to pull the trigger right now. Um what this really did, what this whole certification thing, certification push really did was make people realize, oh crap, I actually have to get compliant now. That's the problem. They're in a time crunch to actually get compliant where they've supposed they're supposed to have been there for the last nine years or more, but we'll just say nine years. Uh so uh, you know, up until now the DOD said, you know, uh you're already supposed to be compliant. Uh and I'm sorry that you're not compliant. Um, you know, this for nine years we've required this, you know, and now this is just the assessment on top of that, right? Again, it is expensive. I'm not saying it's not. It is expensive. Uh but they they used inaccurate numbers. Not that's fear mongering, that's politics, that's whatever you want to call it. It's inaccurate. So uh they also had a way to address this already, uh already baked in. Uh they were able to uh the program managers were able to say, you know, hey, instead of requiring the certification in uh in the first year, we're gonna require it in option year one or two or three or whatever it may be. Uh and they could have delayed it that way. Would they have had would that have had the same effect? Would have been hard to manage. It would have probably not had it would would likely have had close to the same effect. And yes, it would probably have been hard to manage for the primes and for anybody that needed to flow down, right? Because, you know, at this point, I need to be, you know, certified for this contract, but not for this contract. And, you know, primes are just telling everybody you just all have to be level two certified. That's that's what they're telling people. So um so yes, it was paused. I don't necessarily agree, uh, and a lot of people don't agree with some of the facts and figures they used. But the fact is it's paused. It's paused for 60 days. Uh I get it, it is expensive. There are problems with it. There, you know, anything the government does, I hate to tell you this, folks, is gonna have problems. You know, whatever they come up with to quote fix this is gonna have some more problems. There's gonna be more people that don't agree with it, you know. So it's you know, there's a bunch of CMMC naysayers out there that said, see, I told you so. Uh but you know, it's uh there needs to be some sort of third-party validation. Uh personally, what I think if they want to reduce the cost, and they're talking all about uh they're talking all about certification and how much certification costs, when really, really what people are upset about, but they're not saying or they're getting the two uh intermixed is that uh is that certif uh the compliance part is is the expensive part. And it is. Uh there's several things that they could do, you know. Um get rid of the the Fed ramp, uh, the need for FedRAMP. Uh there that's there's a that limits the amount of products that you can use and increases the cost two to four times for those products. Get rid of FIPS because if they can't keep up and get things get those modules approved quick, then you know, just get rid of it. Um you can have some other requirement in there. It's gotta be uh FIPS quality or higher, it's gotta be FIPS compliant or better, you know, whatever it is. FIPS does not mean FIPS validated cryptography does not mean that it's the best encryption out there and it has the best performance. It does not mean that. It just means it's been blessed by the government. And they're not old old algorithms, right? So you know, if you can prove that you've turned off uh you know all of the um deprecated algorithms and and stuff like that, then then you ought to be fine, you know. Um everybody wants to be secure, everybody well, I know everybody wants to be, not everybody wants to do the work, but uh there you can accomplish what FIPS is meant to accomplish without having to go with FIPS validated cryptography. Part of some of you might argue that there's another caveat to that. We won't even go there, but uh so that may be what they're getting at. But you know, if they're you're talking about reducing cost, get rid of the FIPS requirement. Get rid of the uh the FedRAMP requirement, you know, get rid of the requirement to have two assessors on every assessment. Um you know, you want to go even further, then uh you want to reduce the cost, you're gonna have to go to frameworks where it's risk-based and and it's the it's a judgment call for the uh for the C through PAOs, you know, for the assess for the one doing the assessment. Um, you know, SOC2 type two, ISO 27001, those are still you know expensive uh assessments or audits to go through. Um people will can argue that they're better, you know. I yes and no. Uh so I mean there's a whole argument to be made there. But there's several things they can do to reduce the cost. Um who knows what they're gonna do. We've got 60 days till they come out and say what they're gonna move forward doing. Uh likely, uh you know at the end of 60 days, they'll say, you know, we need to go back and revamp and we're gonna issue a interim final rule, you know, to amend this until you know we get through the process. You know, uh something like that. I don't really know. I'm not the smartest when it comes to uh all the federal rules and everything else. I just read them. Uh I kind of know how it works. Um, there's other people that are off the deep end in in and uh understanding all that, but I'm pretty sure in our final rule, uh, which is the you know, they've done that before, it it becomes effective immediately. Uh so maybe that's the route they'll go at the end of 60 days to say, hey, we're gonna we're gonna push this off uh until we get finished revamping the program. Uh I would bet though that there is gonna be some sort of uh third-party validation still. I can't imagine them going back to letting people say, Yeah, I promise. You know, I mean, just look at all the just look at all the companies that have been caught with the False Claims Act, you know, uh, and not just a little difference, a big difference. So you look at all that, look at all the DIPCAC assessments that they did, you know, how many companies actually passed and how many didn't, you know, it's it's those are the reasons that they put the certification, third party validation, the ster certification in place in the anyway. So um because you gotta have if you don't have somebody coming in, a third party coming in and validating all the controls, uh you're gonna get a lot of noncompliance. And that's just the unfortunate fact of the matter, you know. And it could be inadvertent, you know, could be uh, you know, some IT guys reading, you know, going, yeah, we have uh we have that defined, we have it, you know, uh we tell people to do that. Or we have, you know, sure, we get everything authorized, you know, and uh Bob told me, you know, while I was drinking a cup of coffee that he wanted a new user, you know. And well, it's everything's gotta be documented, right? If if it's not documented, it didn't happen. You can't prove it. You can't prove it legally, you can't prove it through an assessment, you can't, you know. So uh there's a the requirement is a lot of a document a lot of documentation, and I don't see how they're gonna get around that and still have a good program.
StaceyYeah, I agree.
BrookeI went way I went way over and uh explaining that, but uh yeah, that uh that's the announcement. Uh that's how I feel about the inaccurate faction figures they used and you know what's what's coming. So we don't really know what's coming, we just kind of got to wait and see. But I can't see them getting rid of a third-party validation.
StaceyAaron Powell Yeah, we can only hope that after the 60 days it's for the improvement of the program in a way that um you know benefits everybody, not just the government, but even the manufacturers we service, like the barrier of entry for cost. Hopefully we get to see that go down for them and really assist with that. Because if the problem is really cost, then we can only just hope and pray, I suppose, that they stick to that and really help us out in that way. Um, because not everyone has government big funds. Right, right.
BrookeNot everybody does. Uh the one thing I didn't add that uh so I'll keep on talking now, sorry. Uh one thing I didn't add that I'm I should have a second ago is that the one thing uh Kirsten Davies did say was that uh phase one is still in effect. Uh DFAR's uh 252.204-7012 is still in effect. You still have to protect CUI, you still have to protect FCI. So none of that has changed. And I would argue that the third party validation, the the certification assessments, uh gave you some cover and and somebody else saying that you had everything implemented correctly. So if something happens, you can say, hey, I had a third party come in and uh you know they were trained, they were certified, everything else, and everything was good. So you have that to fall back on. Now you don't have that. Well, if you already were certified like us, uh then you still have that to fall back on. But uh, you know, at this point, if you're if you're not certified and you don't get certified, then it's your your word, your CEO's word, your CF, whoever whoever's in charge of this program there, uh it's their word uh that uh they're doing everything. It's not gonna fall on your IT guys, it's not gonna fall on the company you had helping you. Uh you're accountable, you have to make sure it's done. Uh so are you does this put you in a worse place uh than you were before? No, not at all. Some people say it does, and I kind of get what they're saying, but not really. Uh it puts you in the same place you've been since November 10th of last year, right? You've had to self-test, self-assess, and uh enter your scores and say that I promise, you know. Uh that was a poor cross thing. Sorry. Uh that was uh anyways, the uh I I promise that we're 110 or 75 or whatever score you put in, right? Um so uh and now um I believe I haven't I haven't entered any scores. We don't enter the scores, our clients do. So I'm hearing that uh to enter scores now, uh they have to be 88 or better, is what I've heard. Don't really know that. There may be some caveat or or some new contract or something like that. I don't know what that's for. Um but uh anyway, you have to enter your own score. You've had to do that from the get-go. Uh so keep on keeping on, keep on implementing the program, keep on managing it, keep on fulfilling all the documentation. Those are all the things you have to do. This NIST 800 171 and CMC uh were written for ongoing management. They were not written for a for a for a one picture and you're done, right? Um so yes, the assessment is a picture in time. They were they were assessed at this at this period, but you're supposed to be able to prove that at any point. And so you should have all that evidence uh hopefully uploaded to your GRC tool, saved on a file share, whatever it may be. Um but uh this is built for ongoing management. They said you do have to do it. If you've got an assessment on the books, I would keep that assessment uh scheduled. Go ahead and go through it. Um there's uh there's every likelihood that that um certification is still gonna mean something after after all this is over. Um and uh there's I would seriously doubt, like I said, that there's not gonna be any third-party validation. So that certification will mean something. If you don't have an assessment scheduled, then yeah, it it may be right to go ahead and uh maybe a right business good business call to s just tap the brakes and wait to see in another whatever it is, 50 days or whatever from now, uh, you know what happens. Um but keep on keeping on, keep on managing. Keep on working towards full compliance. You got a little bit of a breathing room. Who knows how long it'll actually be? But you've got a little bit of breathing room to make sure that you are fully compliant.
StaceyOn the topic of assessments, it seems like in the town hall there was some talk about choosing the right C through PAO for you. Now, with the pause for the 60 days, you know, like you mentioned earlier, you may want to kind of wait before scheduling out your assessment, but it's still good to know these tips on who to choose, what type of pricing, or you know, just general
How To Pick A C3PAO
Staceytips on choosing the right C through Pao for your business.
BrookeAbsolutely. Uh we've we've talked to a whole lot of C through POs, and we have uh a few that we uh work with and that we uh that we that we ourselves trust and know. Uh you know, if you're if you don't have somebody to help you find them, then um, you know, do your homework, talk to a bunch, have a list of questions. Uh prepare a list of questions that you want to ask and and ask those questions and how would you how would you handle this? Um I can tell you that if the question gets too much into what they think might be consulting, they'll they'll not answer it or answer it very vaguely. Um so they'll stay away from consulting on that kind of uh that kind of meeting, but uh ask them all sorts of questions. You know, that's that's you're going to hire somebody that you're gonna pay a lot of money to uh to tell you whether you're compliant or not. Ask them what the pro what their process is. Uh ask them whether they need to come on site for the on for the physical portion. Ask them how many assessors do you have? How many teams? Are they 1099s? Are they employees? Whatever you want to ask. Uh, you know, you can ask them all that. Uh they talked about asking about their SOCI uh screening status and um, you know, all sorts of other things. But really what it boils down to is uh interview some uh a few see-through PAOs beyond just the assessment uh cost and scheduling, you know, uh write down questions you have. You know, uh a good thing would be to engage someone for um readiness, for a readiness assessment uh who's been through this uh and either taken part in assessments or uh been around the ecosystem for a while, and they can they can help you ask those questions and they can help you interview uh those C3 PAOs. Of course, that's on hold for now as far as well, I take that back. They will still do assessments, the assessment the assessments still do matter. Um so that's not on hold. Uh I was about to say that's all on hold now, but it that part is not on hold. They will still do assessments. Uh so if you want to hire somebody to do an assessment or you want to get ready, uh whatever, they'd be happy to talk to you. Um again, what's on hold is just the certification requirement on contracts. It's not gonna not necessarily going to be it's on a 60-day pause, which is before November 10th, but um uh that uh that requirement, certification requirement on contracts is on pause for right now. 60-day pause, which ends before November 10th. But you know, make your call.
StaceyAll right. So it seems like there was some FAR CUI rule updates. Um what changed and why does it matter?
BrookeUh yeah, sorry, I gotta refer to my notes here to remember what I wrote. Uh so uh yeah, there were some uh updates to that FARCUI rule. One of them uh that people like me were kind of uh I was gonna say worried
FAR CUI Rule Reporting Updates
Brookeabout. I don't know if I was worried more than uh perturbed about it. Uh there was an eight-hour reporting requirement, you know. And I was like, you know, sometimes you can't even get everything figured out, you know, enough figured out to report in eight hours, you know, depending on what it is, you know. Uh anyway, uh but uh that's it's 72 hours. It matches what you're supposed to do for CMMC uh at this point anyway. The other thing that they uh struck was the uh potential CUI thing. They um I think you had to report uh potentially mislabeled or unlabeled CUI uh within eight hours, and they've they've struck that. So that's good because that's a that's a big burden on on folks that you know. I mean I can tell you right now uh you'd be reporting things all day, every day. There is there is a lot of stuff that's not labeled. There's also a lot of stuff that's over labeled. So um but I would say in our experience, what we've seen is far more in the direction that uh and we don't we don't get the CUI, but from what our clients, what we talk to, and our clients tell us it it's uh by far, it's uh no labeling on the CUI is what they see. And it looks like uh public comments are open until July 23rd, which uh may or may not be after you see this uh town hall update. Uh but um anyway, so it's coming up. They're uh that FARCUI rule, uh that's all coming out. I have no doubt that that probably played some role in uh the I say I have no doubt, uh I do have doubt, I guess, but uh it this probably played some role somewhere in uh the pause for CMMC level two certifications on contracts. So it makes sense. You know, you want to align the two programs. One is based on uh NIST 800-171 Rev3, and one's based on Rev2. So I you know whether they do something with that or not, I don't really know, uh, but we'll see.
StaceySo wrapping today's episode up, if our lovely listeners remember only one thing from this town hall recap, what should it be?
BrookeAaron Powell Accuracy, documentation, make it keep on keeping on. Uh you know, this is you still have to protect CUI. Uh you know, part of the town hall was that it's actually going into effect on November 10th, which you know now phase
Keep Protecting CUI And Document Everything
Brookephase two. Uh now phase two is not going into effect, but they made abundantly clear that you still have to protect FCI, CUI. Uh DFAR-7012 is still in place. Um CMMC is still in place. NISTAR171, uh R2 is still the guiding document. So um did I say R2? I said if I didn't say R2, I meant R2 for the NIST 800171. Um so all that is still in place. You still have to protect everything. You're still liable, uh still responsible, uh still contractually obligated to uh to be compliant. So um like I said a minute ago, just keep on keeping on, keep on moving towards being fully compliant. Um this doesn't mean that you can drag it out for another year. Uh you know, I wouldn't want to get caught uh not having everything implemented, uh especially if I reported a good SPRS score. Uh but the other thing is you want to be able to report that good SPRS score. If you've already been uh certified, kudos to you, kudos to us because we got certified. So the joke around his office is, you know, uh, doesn't matter now. And I'm just joking it. That does matter now. It is a joke around the office, not true. Um, but the uh, you know, those certifications do matter. Uh, you know, if you're a prime uh looking for somebody uh to do a contract to uh for a contract, um, then you've got somebody that's been assessed and somebody that hasn't. They both report 110, both of them are fully capable. You know, which one you're gonna choose? You know, uh there's there are some primes that have been on LinkedIn talking about, you know, uh choosing capable partners and choosing ones that are uh certified and you know the how you look at them and all that kind of fun stuff. So you just want to put yourself in the best uh position possible to be able to do that. To be able to be the one they choose, I guess. That's what I'm saying.
StaceyAll right. If you have any questions about what we covered, reach out to us. We're here to help fast track your compliance journey. Text, email, or call in your questions, and we'll answer them for free here on the podcast. You can find our contact info at cmc compliance guide dot com. Stay tuned for our next episode. Until then, stay compliant, stay
Reach Out With Questions And Subscribe
Staceysecure, and make sure to subscribe.

