Submit any questions you would like answered on the podcast!
This is the all-in-one CMMC checklist episode. Austin and Brooke pull together everything into one place: what the 60-day Phase 2 pause actually changed (and didn't), what CMMC Level 1 really requires, what Level 2 really requires, why scoping is the foundation everything else depends on, and where most assessments actually fall apart.
In this episode:
- What CIO Kirsten Davies' memo suspended, and what it left completely alone (spoiler: almost everything)
- Why the government's stated reasoning for the pause (cost, assessor shortage) doesn't hold up against real assessment pricing
- The RFI and task force timeline: what happens on August 14th, and what to expect around September 14th
- What happens to contracts that already have Phase 2 certification language written in
- Where to actually focus your compliance budget and effort during the pause
- CMMC Level 1: the checklist most people gloss over, and why it's not "nothing"
- CMMC Level 2: the 110 controls and 320 assessment objectives, POA&M rules, and the controls that most commonly get missed
- Why scoping has to come first, and what happens when you skip it (including a mole infestation analogy that actually makes sense)
- Whether your G-code, derivative drawings, and CAD pull-outs are CUI
- ESPs, CSPs, MSPs, and MSSPs: what each one means for your documentation and your assessment
- The two most common reasons assessments fail: documentation gaps and vendor/CRM gaps
- Justice IT Consulting's own path to CMMC Level 2 certification, completed right after the pause was announced
Welcome And The Checklist Goal
AustinHey there, and welcome to the CMMC Compliance Guide Podcast. I'm Austin. And I'm Brooke. From Justice IT Consulting, where we help businesses like yours navigate CMMC and NIST 800-171 compliance. We're hired guns getting companies fast-tracked to compliance. But today, we're here to give you all the secrets for free. So if you want to tackle it yourself, you're equipped to do so. Let's dive into today's episode and keep your business on track. So, Brooke, today we're doing something a little different. Normally, uh, we try and cover little pieces or segments of CMMC uh and compliance uh and in its portions and pieces. But today we're gonna try and do uh an all-inclusive uh checklist episode of uh kind of where we're at with the pause and and uh all the different components of CMMC put together and how they relate to each other today.
BrookeSounds great. Let's do it.
AustinSo talking about July 13th, let's get specific on what CIO Kirsten Davies memo actually suspended uh and what
What The 60-Day Pause Actually Means
Austinit uh what it left alone.
BrookeSure, sure. What do you think? Sorry, sorry, I'm laughing. This is the the first thing that always comes to mind is uh what they did was throw the whole CMMC ecosystem into chaos. That's what happened.
AustinOther than that.
BrookeOther than that. Um so really uh what that what the pause did, what that memo did that they released uh is it put a pause. Uh and interestingly, it's a 60-day pause on the implementation of uh phase two, which would have required uh that certifications when they're acquired when they are required on a contract, that they uh uh anyway, that those get required on the contract in no on November 10th. I don't know if I said that exactly. That was kind of confusing. So November 10th was when the certification, uh level two certifications were going to start being required on contracts. That is what's paused. So maybe that's a better way to say that. Uh so everything else is the same. We're essentially still in um, not essentially we are still in phase one. Phase one continues. Um DFAR 7012 uh continues. Um the uh you're still supposed to protect FCI and CUI. Um if you uh assess your uh self-attest your score, uh the POM uh restrictions may still apply, not necessarily, but may still apply. Uh so uh all that stays in place. There's of course there's always caveats to everything, but all that stays in place. The certifications that were going to go into effect on November 10th uh are paused. Interestingly enough, it was a 60-day pause, and when they announced it, the uh November 10th was a little over 120 days away. So which leads you to believe that there's they're gonna continue that pause in in some manner, probably be by an interim final rule, or maybe maybe I should not say probably. I have no idea. I don't know what the uh, you know, I'm sure they have more than one, uh I know they have more than one uh trick up their sleeve or more uh avenues to follow, however you want to phrase it. Um so they could release an interim final rule that says this is what we're gonna do until um until we decide what we're gonna do, uh until they revamp the program or the you know, it's it's also possible that they'll come back in 60 days and say, hey, you know what? We were just joking, you know. Uh we found out that there's a mechanism where we can delay this anyway already in uh uh the DFARS rules, and we can go ahead and delay it through those mechanisms through telling the uh PMOs to not include it, you know, uh not include it on uh the year one or something like that. Have no clue what exactly they're gonna do. Um there's not they didn't let any of this leak about what about the pause. So uh that was I'm pretty impressed. Uh but I there's been nothing that leaked out or nothing that's no scuttle butt or anything about what's gonna go on in 60 days. So but there is an RFI out, uh request for information, and we're gonna respond to it. Um and I encourage y'all to respond to it as well.
AustinYep. So uh just a couple days after July 13th, um I had uh you know, I do a lot of our intake meetings and everything, and I received uh email from uh one of the people we were doing intake meeting on, and he said, Don't worry about it, you know, don't need a meeting anymore. They canceled CMMC. So uh uh so it's not canceled.
BrookeIt's not canceled, absolutely not. Um they made absolutely clear. If you read the whole statement or listen to the whole statement, they made absolutely clear that is not the case, that phase one is still in effect, and you still have to protect that FCI and C UI.
AustinYeah. So the only thing that's in question is the certification portion. So if you think of a um you know a CMMC as like a four or five-step process to get to certification, all the stuff before you still have to do, right? Absolutely. Oh, yeah, absolutely. All the documentation, all the implementation, all the evidence, all the stuff.
BrookeWhich if you really study it, that's the more costly part instead of the certification. But hey. So you know, what do I know, right?
AustinCertainly uh the certifications are expensive, and I still I hope they do get um less expensive.
SPEAKER_03There are ways to do that. Mm-hmm.
AustinYeah, there's there's also some other things they could couldn't could have looked at um downstream or or before that that uh could have made things uh you know a little more. Yeah.
BrookeI mean uh you know, some you know, the whole uh FedRAMP thing, the the the Phips thing, the um requiring three assessors. I mean uh there's uh the length and depth of the cap, you know, the there's all sorts of things that they could do to lessen the burden on uh small b truly small business, not the small business they referred to in their statement. You know, I don't know of anybody that's actually been quoted $600,000 for their assessment. Um that number gets thrown around by uh a couple people sometimes, but there's no uh there's no proof of that. All the assessments that we've seen for small business, you know, 50 employees and under, have all for the mock and the and the uh uh C through PAO assessment combined have all been under under or around $50,000. If you're talking about just uh just the certification assessment by itself, you know, yeah, that's definitely, you know, that's in the you know, 30 to 40 range, you know. Now, I wouldn't necessarily depend on that, but uh it is in a better pri a lot better price range than everybody estimated when this first kicked off. Everybody said, you know, it's gonna be around fifty thousand for the floor. And then when the uh government said, you know, when they or when they made the rule that uh they had to add an extra assessor, uh two CCAs plus a uh quality assessor, a QAP, I think is what the QAP is what they called it. I guess what it was, but anyway, they uh you know when they did that, that raised the cost because that's more labor involved when two people have to sit through the assessment, you know, rather than one. You don't necessarily need two people on an assessment for a for a simple uh you know, for a simple enclave or a a small environment, you know, one that's all on-prem or one that only has one solution, not a bunch of different uh integrated things, you know. Uh so by digress, I'm chasing rabbit, and that's uh you know, that's one of those things that raids uh raised that cost that was uh self-inflicted from the government.
AustinSo you kind of alluded to this, uh but why did they state the reasoning was uh behind the decision for the pause?
BrookeUh high level they said it's it's too costly. Right. Uh but what they actually said was the
The Cost And Assessor Shortage Claims
Brookecertification assessments are too expensive, um, that small business is just such a big burden on small business. The certification assessments are such a burden on small business that they uh they're five and six hundred thousand dollars. And um and they also said that there is a uh shortage of assessors, uh which also leads to um higher prices and and uh you know not enough capacity to do all of them. And they you know state the number that there's a hundred uh a hundred thousand uh dip companies that need to be assessed, uh which you go back and look at numbers, they're all over the place. But even if they use that number, the the government never intended. You look at their uh you look at the government's own numbers and their uh and the final uh proposed and final rules that they released. Uh you know, they're they never intended for a hundred thousand assessments to be done in the first year. Never, never, never intended that. I don't know who got that from where, but you have to stand up the capacity to do that if you want a hundred thousand to be done the first year. And they did they certainly didn't do anything to stand up that capacity to do a hundred thousand in the first year. Uh and now they've shot themselves in the foot if they want a hundred thousand to be done in any year, because you know how how many assessors are going to trust them that they're actually gonna follow through.
AustinI was looking on LinkedIn and uh a lot of assessors in my network, and uh I've seen quite a few of them just announced that they had gotten uh certified to do other assessments for other compliance regimes just a couple days after the pause, and I was like, well, that tells you um the at least immediate effect um on the assessment capacity is that um you know uh you as to your point, you may have just undermined the assessment capacity because we're gonna scare off all the assessors that were um because we were above projections for the number of assessors. We absolutely were above the projections. That we may be in a worse off spot now because of the pause, because you may have these people that um were doing assessments go elsewhere um and and because we've scared them off now.
BrookeYeah. So that those are the reasons they gave as to as to why they paused it. Uh all the all the numbers they float, every single one of the numbers they floated out there was wrong. Uh they said there's only um a hundred assessors. Sorry, that's not accurate. There is there was a hundred and seven or a hundred and ten C3 PAOs at that point, but that's not where bottlenecks come in. Bottleneck for this comes in. The bottleneck comes in with a number of assessors that can perform assessments. And so if you somebody had a great chart, and I referenced this on one of our other podcasts, uh, I wish I could go back and find it and uh and ask them if I could show it or use it or something, because it was it was a really good chart. Uh but if you use, you know, if you say there's only gonna be 50% of the assessors that are gonna assess, and then uh they only do two assessments a month. Uh you know, this is how much the capacity was, and the capacity was, you know, pretty high. The uh if you're depends on if you're watching or listening. So I was gonna say this eye, but if you're listening, you can't see anyway. The the assessment um the assessment level is pretty high. Then the uh the actual number of assessments that are being requested and scheduled is quite a f quite a bit below that. So there was so there was extra capacity left. And the government, when they're in their uh proposed rules and final rules, uh, you know, they only expected a few hundred uh to be done uh the first year. I think the the C through PAOs were on track to d complete over two thousand of them. Uh so there's somewhere in the number of uh uh range of four or five times uh the amount uh initially thought. So I would say that's a pretty dang good track record. Uh so you combine that with what they said, you know, we have a capacity problem that's a thousand percent inaccurate. Uh and then the the numbers that they threw out there, the numbers that they threw out are inaccurate. I don't know where they get the number of, you know, the the amount that it costs for a small business to go through it. Um then again, the small business administration was where they got those numbers from. And the small business administration, to them, a small business is 500 people in some cases, 1,500 in another in some other cases. Uh that may be right for the government, but it's not what you and I think of as a small business, you know. A small business is typically going to be maybe 50 uh full-time employees and under, you know, something like that. Um, you know, so if you go, if you consider that, the cost for those assessments were way, way cheaper than 600,000. They were, like I said a minute ago, they were in the you know $30,000, $40,000 range, which is still high. I'm not saying it's not, it is high. That cost could still come down, but it's the government's own fault it's that high to begin with.
AustinSo it's um certainly compliance is expensive, but I think they're uh looking at the wrong expensive pieces of it. So unfortunately.
BrookeSo everybody is conflating the cost for uh compliance and the cost of certification. The two different things. Of course. Two different sides of the same of the same corner, however you want to phrase that. They're related, but not exactly the same.
AustinAll right. So we talked about the pause, we talked about the 60 days, um, they're essentially pausing the certification piece, potentially, you know, 60 days. Um all that fun stuff. Um let's pivot to the task force that was referenced in the memo. Um, and then they've tasked the task force um with um what what are they doing? Um, what date are we gonna hear from them? What's gonna happen?
BrookeUh well there's uh you have 30 days to submit
Task Force, RFI, And Next Steps
Brookea the uh response to the RFI, so which I have a feeling they're gonna get an absolute ton of responses. Uh so there'll be a lot of responses there. Um uh the task force is gonna be convened uh to uh to take those into account and uh I guess also other you know things they come up with on ways to improve the program, uh lessen the cost uh while still uh providing security uh in the whole nine yards. So that's what the task force is is uh tasked with doing. Uh so uh and then they have uh from uh they have another 30 days uh to respond and um and say what the next steps are, right? Which is not really enough time to really take everything under and decide what's gonna happen. So for the government to actually take all the responses, their thoughts, and uh and say concretely, this is what's gonna happen on November 14th or 13th or whatever, uh, the uh there's not enough time to do that. So that's you're gonna see another some sort of pause through an interim final rule. I don't I'm not a government policy wonk, so I can't tell you what all the tools available to them are. Um I have a couple in my head, and one is an interim final rule, and one is the fact that they already had a lever that they could pull, uh, and that lever was the fact that they left themselves wiggle room uh where the uh uh program officers could, uh program managers could um could delay uh the certification required on a contract uh to option year one, two, three, or four, or whatever. So uh they have a couple of levers that I know of that they could pull, uh and probably even more than that. So um nevertheless, 60 days, uh 30 days to respond to the uh RFI, which would be uh August 14th or 13th or 14th, uh and then September 14th, uh we should hear something uh from uh the DOW about what's gonna be happening moving forward, which will be here's just other temporary measures, so so we so we come up with something, right?
AustinYeah, I was gonna say I'd uh I've tried to stay away from publicly speculating on what I think is gonna happen, but I think I have two outcomes that I really think are gonna happen. And I'll um I'm not gonna share them in the podcast. I don't think it's fruitful. I don't think it's fruitful, but um I was just thinking if I was a betting man, and then I thought, have you heard of polymarket? No, I wonder if there's a polymarket for um for the CMMC result of the task force.
BrookeOh, you mean like a place in Vegas or something?
AustinNo, a polymarket. So there'll be like like I think uh like the I'm sheltered.
BrookeI'm sorry.
AustinSo the uh Trump's teleprompter guy, if this is an example, um just got in trouble for betting on the words that Trump would say in speeches and indicted on it or something. So like there'll be things like that. I'm just using it as an example, or there'll be like um a chance that uh some public broadcast, some uh celebrity says this or um whether um and people can go bet on that stuff. Yeah, it's just random things, like things that could happen, right? And so I'm wondering if there's a CMMC polymarket. Because it could be politics or it could be sports or it could be um it's political candidates for like uh like who's gonna win races. Um so you'll see like they pull those numbers now when they're doing analysis of um like who's gonna win or not. Uh so are you blowing it up, Stacey?
BrookeSo if you you know, if there wasn't before, maybe uh maybe there will be now since you mentioned it.
AustinYeah, maybe maybe someone will go submit it as a repetition for. But my question is, can we bet on that or are we gonna get in trouble? I don't want getting indicted. Do we know too much? Maybe maybe I shouldn't bet. Right. We'll we'll we'll check in with uh Stacey in a second.
BrookeReally, we have no inside information, so you know. I mean that shouldn't matter.
AustinYeah. I'm joking. Of course. No polymarket? Bummer. This is a quotation to get it out. There we go. Maybe yeah. Uh go go request polymarket CNMC chances because uh if my my um opinions of what's gonna happen are pop up there, I might put some money down. We'll see. Because I'm I feel pretty confident about it.
BrookeUh you know, on that, uh not exactly related to that, but you know, we're talking about what's gonna happen, and and we just got finished talking about a lot of the numbers that uh the Honorable Christian Davies used were were inaccurate. Uh we'll just say they were inaccurate. Um and they were because that's what the SBA fed her. That's what the SBA said, here, use this. We're trustworthy, you know. Uh and so um anyway, there's there was a group of uh folks from the CMMC ecosystem that uh actually went to talk to her. They posted on LinkedIn, uh, so it's not hidden, it's not a secret, but they went to talk to her and some senators and congressmen, and so they said, Hey, look, this is what the DOD asked for. This is what people stepped up to the plate and were helping y'all build out or building out on behalf of the DOW, however you want to phrase it. And so this is what this means, this is what this is there for. So they at least got that information out there because if you listen to the if you listened to it or read anything out that came afterwards, it was like they had no clue what CMMC was. So uh, but there was folks there were folks that went to talk to them and and um and so maybe you know I know there's a lot of folks that think that uh there's people that are getting rich off all this, and and uh I you know, is it a business opportunity? It absolutely is, you know. Uh but I don't know very many people that are actually getting rich. A lot rich is subjective, you know, but I don't know a lot of people that are uh getting rich off of this because there was a lot of requirements from the government as far as the amount of time you put in and everything else. Uh the hoops that all those C3PAOs had to jump through to be able to be a C three PAO and assess. Uh it is not a small ask.
AustinSo we'll see if that polymarket comes out. I might change that. Uh I'm kidding, of course. So um All right. So next question for you is Um There is already potentially some phase two language, phase two meaning certification requirements on contracts that have trickled down from the government or however you want to phrase that. Um I'm just trying to use uh You talking about
Contract Flowdowns And Prime Requirements
Austinthe old trickle-down theory of of contract flowdown requirements. Um so uh anyway, uh if there is existing phase two language on a contract, um what happens to that?
BrookeSo first of all, we'll tell you what is supposed to happen and what probably will happen, but you absolutely have to go check your contracts and you have to talk to uh whoever you have that contract with, right? Uh but all the uh certification requirements on contracts and solicitations was supposed to be pulled back by amendments and uh some other mechanism. But anyway, they're supposed to be pulled off those uh contracts and solicitations. But don't assume it is Do not assume that is the case because it is a contract. If it's on the contract, doesn't get pulled out, you're still liable for it. It doesn't matter what the government uh did. If your contract is with the other thing is if if your contract is with a prime, uh I have not seen it and I haven't had any of our clients tell me this, uh, but I've seen that uh at least people are saying out there that uh uh some primes are telling uh their subs that they still want them to have a certification. Um I know uh I know a couple people that work uh for some some of the bigger primes.
AustinSome of those letters have been shared publicly that they've asked them to just keep on with what they've already requested. Trevor Burrus, Jr.
BrookeOkay. I've not seen those publicly shared letters.
AustinYeah, I've seen one or two on on LinkedIn, and I'll I'll uh I'll stay away from mentioning the prime to make sure I don't get the prime wrong, but I know I've seen it.
BrookeSo I know I've talked to a couple people at other primes, uh I'm assume other primes anyway, that they they have uh they're not requiring that at this point. They're uh keeping pace with what the government is requiring. So the short of it is uh it should be coming out of all those contracts, uh, but the primes don't have to pull it out because that's their own requirement. Um and they can require more out of you than the government wants if they want to. That's up to them. Um uh so you need to need to check on your contract, check with your contract officer, uh, see if that can be pulled out if it's already in there. Solicitations that were out there, that should be coming out as well. But again, check and make sure. Uh and ask if you don't know or if you can't tell.
AustinYep. So it's um, you know, it's important to note that um phase there's there's not a ton of contracts that already had the phase two on there to begin with. So like if you already had a contractual clause or your prime asking you to do something, the pause from the DOW or DOD does not change what like you've already been requested and unless you explicitly hear otherwise, which you probably won't. Um right. Um and so now now you may have some primes or you know, uh obviously, or if you have direct contracts, you may have that certification requirement, you know, extended or pushed or or whatever, who knows after the the 60 days, or or if you have a direct contract, they may have removed already that phase two language from it. Um but it's important to note that especially like with a lot of our customers, they're subcontractors to the primes or further down the supply chain, and these primes and uh you know other people are managing at scale. And so um if if you've already been asked to have you know a Spurs or SPRS score or an attestation in or something like that, none of that's changed. That's um that is all that is all the same.
BrookeYeah. That's the phase one requirement, yes.
AustinRight. So everything you've been asked to to do to this date for for most most people, broadly speaking, I'm generalizing here, which is not always useful, but I think in this sense, you know, for most people sitting out there at home or you know, at work wherever they're at, um what they've been asked to do today is still like what they have to do pause or not, right? Um unless there has been a specific certification requirement um on them that has just been lifted. And that's not most people. Right. Yeah. So I just want to make that clear because that a lot of people don't realize that. Yeah. Most people I talk to don't realize that. So I think it would be helpful to share publicly. So great. In terms of the 60-day pause, which you know is pausing that phase two, the phase two is the certification requirement on contracts. Um, you know, the the question, you know, uh is I'm posing the question to you, and a lot of people have been asking the question about like, so um
Where To Focus Effort Right Now
Austinwhere do we put our resources in terms of uh CMMC compliance, right? So um it's canceled, don't worry about it. Yeah, right.
BrookeJust joking, just joking.
AustinRight. So is uh, you know, I think the obvious implication is is maybe the certification piece, which is the goalpost uh for a lot of people. Um not everyone. Some people are just looking to get uh a level two attestation or an accurate spurs score or to get to a point where what they said their spurs score was is actually true. Right, right. Not to call anybody out here. But um so uh you know, considering this the 60-day pause on the certification requirement, um you know, where uh you know should people be focusing their efforts on in terms of like spend and resources for compliance.
BrookeI mean it you're in phase one, so really just keep chewing through those poem items. It depends on where you're at in the journey, also. Uh depends heavily on where you're at in the journey, but uh the overall thing is just keep chewing through those poem items, getting them done, and uh getting compliant. You need to be compliant. Um there is teeth in that, and uh you don't want to be caught not being compliant. Um, you know, you don't want any kind of whistleblower thing going on, you don't want kind of breach or anything that causes people to come look and say, oh, you know, you didn't uh you know, you said you were 107, but you're really a negative 163. Um so by the way, you can have a minus 203, just so you know. Uh and it goes up to 110 from there.
AustinSo um, someone told me one time they had a 220. I was like, I don't know if I told the government 220.
BrookeI guess they started the scale down at uh minus 203 and just start at zero there. Why they did the you know, it's uh anyway. Uh whoever came up with the scoring on that, it's it's uh creative. So um then there's five pointers and three-pointers and you know all that kind of fun stuff. But really, I would say that you need to chew through that uh poem and get it done. Um if you've already got uh like a mock assessment and or a certification assessment scheduled, now this is a business decision, of course, but I would say go ahead and go through with that mock, at the very least, the mock, uh, and go uh I would encourage you to go ahead and go through the certification assessment, uh, get it done, get it out of the way, because at that point you have a third-party validation on your security security controls, and if anything ever happens, you've got that third-party validation backing you up saying, here it is, they validated us, they everything is everything was good when they looked. We we kept uh you know current and uh you know, here's the proof of all of our uh upkept logs and and everything else, change requests, everything else, uh that puts you in a really, really good spot and lowers your risk a lot. Uh beyond that certainly makes you less likely to look at, you know, for uh makes you less likely to look at and it makes uh primes uh know that your your risk level is is very low. Um so you know beyond that, uh if you don't already have a certification uh uh mock or a certification assessment scheduled, uh then um you know you need to go ahead and uh you need to be compliant is a short of it. So um and depending on whether you've self-assessed and reported a score or not, you know, uh depends on uh what I tell you next. But if you've already reported a score, I would be very, very try to be very, very sure that score score is accurate, right? And defensible. And defense defensible, exactly.
AustinAnd the most common we s thing we see um just whenever we start working with somebody and they say they're N80, um we come in and they may have a lot of the technical controls like implemented to support an eighty, but what they're missing is the documentation, the SSP, and the actual program behind it, um so which is not scorable, right? Uh and so you really can't report N80 if if you don't have all the other stuff, right? Right, exactly.
BrookeBut documentation is part of what makes that score. So call that out.
AustinYeah.
BrookeYeah, absolutely. The the two most common things are one, uh things aren't documented properly. You know, when it says you need to have an authorized user list, that's not Active Directory. It can you can pull stuff out of Active Directory and use that as a basis to make an authorized user list, but that in itself is absolutely not an uh an authorized user list, uh is where your all your authorized users may live, you know, their accounts may live. But uh the the second not so that's documentation. The second one is people just misunderstanding the controls. You know, what does identify mean? What does define mean? What does authorize mean? What does, you know, what do these different things mean? What do they really mean? And what is what is an assessor looking for, or what does the uh uh NIST 800 and 171 Alpha, the assessment guide, what does it uh tell you to look for? So uh misunderstanding of the controls is uh another big one of those things. So you know if you don't have an assessment scheduled, um uh depending on if you've uh at some point I would say schedule some sort of uh validation. Have a it doesn't have to be a C through PAO necessarily, but a third party to come in and uh do a readiness assessment or a gaps analysis or uh something like that uh to verify you are where you think you are.
AustinYeah. So I think uh just you know uh bringing that out into dummy language for me, uh how how I hear that is um you know, you want to spend all the money, effort, and resources to get ready for a certification assessment. And then whether whether you want to get a certification or set assessment or not is like the optional piece, right? Like you can decide to spend money on that if there's a business use case for it, if you think it's worth the money, you know, et cetera. Luckily for us, um we we didn't have to make that decision because we had got our formal certification two days after uh the pause.
SPEAKER_00So, you know, we're that was the we passed a few days before and got the actual certificate a couple days after in hand.
AustinWe could actually say it. Um key celebration. Yeah. Yeah. We don't have to um we don't have the you know, we don't we don't have to make that decision. So we don't. It was made for us. That's right. Um so you know, I mean we're not uh in the exact boat, everyone else is. Um I guess, you know. Um so yeah, I mean it's the but the boat we're in with everybody else's.
BrookeWe did spend a lot of money to get certified.
AustinYeah. So yeah.
BrookeIt is expensive. We can verify that.
AustinIn that sense, we're very much in the same boat. We've done everything else um that everyone else has, you know, uh done, you know, all the way up to getting certified, and and here we are. So um, but you know, uh we're good. Um, you know, from the perspective of we've gone through the paces and just like you mentioned, and we have that third party to have validated it. So that does feel good. Um, you know, so uh but we didn't have to make the decision whether to do it or not. So we've been talking about phase one uh and the self-attestation requirement, right? And we talked about phase two and how that's been paused, but there's a four-phase rollout, right? What? Yes, yes, there is. Where do we stand at there um if we're paused on two?
BrookeWe're just gonna skip right to three and four. Uh just kidding. Uh so really uh essentially the the whole thing is paused.
Rollout Phases And Procrastination Traps
BrookeUh so um they're pausing phase two. Uh phase three isn't gonna be till um uh November wasn't gonna be until November of 2027. Uh and then that would make four uh November of 2028. Did I do my math right? I think I did. Um so uh those are phase two is is paused for right now. Uh so those whatever comes out in 60 days, we'll find out. Uh but I would imagine that those get paused as well. Phase three was gonna be the DIPCAC assessments. Uh and really uh how the DIPCAC assessments were gonna work is you had to have a level two certification, and then uh DIPCAC uh, if I remember right, was gonna come in and just um uh assess your level three uh controls. Uh so you had to get that level two anyway, uh for the level three to to go in place. Uh that's that's paused. Uh the level four, of course, or excuse me, phase four, not level four. Uh I guess level four of uh CMMC would probably be not unclassified, but classified information, but uh just joking. So the uh phase four was gonna be when uh when CMMC certification or CMMC is going to some CMMC status was gonna be required on all contracts. Okay.
AustinAwesome. So we'll see where that ultimately ends up in a few days. You know.
BrookeUh so I guess at this point it's uh 40 days away or so, something like that. So we'll see what the you know, I was gonna say I have no doubt, but I always have a doubt with government. Uh there's it's a high likelihood that it'll be some another temporary measure put out that says we're gonna hold what we got until uh you know, until we can come up with a revamp of the program somehow. Which I expect probably to still and we've talked all about this, I expect to still have some sort of third-party validation because it is well documented that people were just companies were just not being compliant. There were some that were, uh, but large majority of companies were just not being compliant. Uh some of them were just not worried about it and checking the box. Uh there was no risk to them uh that they could that they could see at least, and uh, and others yet uh like we talked about a minute ago, um didn't understand it and uh said, yeah, we've got antivirus and a firewall, and you know, we've got whatever else it might be, uh we've got a sim in place and we're good to go. We've implemented our technical controls, you know. Um so some misunderstood it, but there was a lot of companies that were uh that were proven to be not nowhere near compliant, a very low percentage were were compliant, actually compliant.
AustinI'm just thinking back to one of my calls I had somebody uh uh cool guy, and um he's we had just had a call right after uh the the pauses happened. And so uh the way I've been running my calls is just you know uh talk about that first in case they weren't aware, just update everybody, right? Um anyway, uh and so his his uh verbatim um uh take on this was boy, this is a procrastinator's dream.
BrookeYeah, he's right. He's right. A lot of people are using it for that. So and some people are you know in the process of uh realizing, you know, I know some that we worked with to develop a poem uh that didn't necessarily hire us to implement or manage. Uh they're struggling through the implementation and they were glad for a pause. You know, uh there's uh two or three of them like that. So, you know, they're they're glad for the pause and glad to have more time to work on it. And uh but truthfully, everybody that we've talked to, with the exception of the one person that you said thought CMMC was canceled, everybody that we've talked to has, you know, has their head screwed on straight and knows that they need to be compliant and they know they need to get there and they don't want to slow down.
AustinWell that's what I was uh gonna say is he said that and uh he was like uh it it almost um moved the needle for him even further. He was like, Well, now that I got the chance, like I'm on a strike while the iron's hot and he wants to start like getting stuff implemented, which I thought was interesting because you know um that's uh you know uh just because you see how different people react and and everything. So even even the people that even self-admittedly have uh you know been procrastinating to their own admission, you know, or whatever, um uh I have still been very much um you know moving forward, more or less. Um it's uh very rare that we ran across anyone, just one person that um thought that the whole thing had been cancelled.
BrookeSo I tell you what, Monday night the thirteenth, when it was cancelled, uh that is not the way I thought it was gonna go.
AustinNo. No. Uh yeah, it's uh yeah, I was expecting um quite a bit different. Um so it's uh especially with the way it was announced. Yeah. You know. Um read the memos to understand what they actually did versus the announcement, you know, because it the announcement reads a lot more um like a lot more of a gift to uh the business community than it is. She still said all the right things, but it was yeah. It has that, you know, feel to it, right? And then you go read the memo and you go, that's a bit different than the way it was, you know, it's presented.
BrookeIt's politics and and they were just trying to play to the people that uh uh you know, I I'm throwing these accusations out, and I probably shouldn't, but you know, it's they were trying to play to the people that were complaining. That's him, not me. The right people, the right groups got in there and uh complained and uh and got this pause uh implemented. Not that the program can't use some uh some help to do to reduce cost because they've been criticizing it for years. We have, absolutely. There's a lot of things that are uh it's a good program at a high level. You know, it's it's got uh a lot of the right stuff in it. Intention's good. Intentions Good intentions pave the road to hell, didn't they? Uh but you know it's got a lot of great things in there, but there was there's certainly a lot of uh overbearing, unnecessary, unnecessary to my thought, uh things. Uh things that r raised the cost and didn't uh raise the security bar very much.
AustinYeah. There's certainly Yeah, we'll just leave it there.
BrookeWe could go off on Chase Nut Rabbit all day long.
AustinI got a lot of opinions. So we'll next thing I want to pivot to, which is uh redheaded stepchild of CMMC, which is level one, CMMC level one. Yeah.
BrookeYou know, everybody says, oh yeah, we've got level one covered. It's okay.
AustinYeah.
BrookeYou know, level one's not nothing. Just so you know, you you are on the hook. If you say you're a level one compliant, then uh you know, and you've assessed
CMMC Level One Requirements That Matter
Brookeyourself that way, there's some things you better make sure that you're doing. So it's not nothing. It's it's nothing compared to uh level two, but it's it's not nothing.
AustinNo, it's not. Yeah, and it's it's all in what? Documentation. Yeah.
BrookeYes, uh all in documentation, right.
AustinIt all leads back to paperwork, you know. Um so uh you know, this funny enough, uh comes up way more than I thought it would um in in my conversations. Um and I'm glad I'm glad that it does because uh like I said it's the Red Hat Step Child of CMMC and people just gloss over it. Um and that's a problem for all the reasons you just said and more. Um but without getting into that, um, you know, can you just dive in a little bit to um what you know a contractor actually needs to do for level one?
BrookeYeah, sure. I'm gonna cheat a little bit. I got my phone here in case you're watching and seeing me. Uh but um authorized access control, you've got to have a list of users, devices, and and processes, which are service accounts, uh, that type of thing. Uh you gotta have an authorized list. And again, that's not the list that you can't point to intra or um intra ID or uh or active directory. You've that's gotta be an actual list that somebody has authorized. Uh transaction function and control, um, external connections. You've got to know where your external connections are and who they go to. Uh you got to control public information, make sure none of that FCI is being posted on your website or social media. There's media disposal, you got to limit physical access, boundary protection, uh talked about public access, system separation, so like a DMZ. If you have any, hopefully you don't have any uh you know exchange servers or email servers in your uh environment, but you might have some something else, you know, uh a VPN uh endpoint termination, right? Um update malicious code, system file scanning, flaw remediation, you have those are the things that have to be addressed, right? And so you have to have policy, uh a policy or policies to um which would be one long policy uh or you know policies to address all that. Um you have to have proof, you have to have your authorized user list and and everything else. So you have to have all that is not nothing. The other thing is uh with level two, you get the chance of a poam, right? With level one, you either meet all the controls or you don't. It's a it's a 100% or zero, kind of like level two certification is, but uh with level two self-assessment or even certification, you can have conditional and have some POM items and you have six months to get those done. Uh but with level one, there's no chance for a POM. You either meet it or you don't.
AustinYep. And so and uh we actually get a gener what our episode on CMMC level one, during its. A lot of uh uh uh calls into us um because I think a lot of people are not talking about it. Um and so um anyway, on on there I'm I mentioned we've got a a guide that uh kind of explains the gotchas in level one and I don't have it ready for rather busy, so I don't have it like published on our website because it's not gone through all the editing phases that uh I feel comfortable enough to get it out there. But if you do call or email us or text us and ask for it explicitly, I will get it to you um with uh caveat that it is not ready for prime time. Um so feel free to request that. But um just uh uh want to preface that with this is uh so the 32 CFR uh tells you what isn't what you're doing when you self a test or what you're supposed to have done when you self a test. Um and that uh attestment for level one all revolves around evidence and documentation, right? Um and retaining it for six years. So what you're supposed to do is um get all your documentation put together, get all your evidence put together, and then file it away in a little wax stamp, you know, time-dated digital file or whatever. Um and so should the government ever come knocking, you have that point-in-time attestation file and folder um that you can point to and uh because because when you attest, you are literally saying that you have that and you are retaining it, so you have to have it. And then to have that, you have to do all the things, right, uh, first and have the implementation done. So um CMMC level one is at the core of it, like some good side just cybersecurity and physical security practices. Um but you have to do it it's it is very basic, but it is very, you know, prescriptive as CMMC is. It is and you have to do it the CMMC way. And you have to write the documentation the CMMC way, right? And so it's uh that is uh so a lot of people may have um some of the core practices, you know, um in place and and at least uh or or the technologies capable to be configured in a way that you can be compliant. Um but what 90% or more people don't have um is all that other stuff I talked about. Documentation to back it up, yeah. And and making sure it's set up the proper way that they want you to have it set up, right?
BrookeYeah, there is a level one assessment guide. Yes, yep. You know, so it that would be handy to go look at as well. Yep, it is, it is. Which if there's an assessment guide that also tells you it's not nothing.
AustinYeah, yeah, exactly. And it's the guide that the government would use when they go to double check you, you know. So absolutely. Yeah. Anyway. All right, so uh that is level one. So let's move on to level two. So kind of talked about what's required and and level one, um, but uh when people talk about CMC, almost always are talking about level two. Right. So broadly speaking, um, what are the requirements of of level two with or without certification?
Level Two, POA&M Rules, And DFARS
AustinBecause level two still exists with or without certification. A lot of people don't understand. I know we've said that a lot of times, but the pause um does not affect level two existing. It already has existed in phase one of self-attestation, right? Right. So um with or without certification, it it prevails, right? Um so what are the requirements to to meet level two?
BrookeWell, there's a I mean, just at a high level, there's 110 controls and 320 assessment objectives, and um you you have to uh be compliant with all those, although you can have a POAM at level two. Um and uh there's another thing I'll talk about in just a minute that determines how the POM is treated. Uh, but you can have a POM at least with level two and get that and uh be able to chew through those things and get them done, right? And have a conditional uh assessment, um uh a conditional score. So it depends on uh what's in your contract, really. Um 7012 by itself, uh that's the basic you have to be uh compliant with uh all three 320 assessment objectives. You can't have a POM at that point. Uh 7021, if that's in the contract or your PO or whatever, uh then that's what uh governs the uh limitations on the POAM. Uh um the POAM, you can only have a POAM for 180 days. It can't include any three-pointers or five-pointers, and then there's a few one-pointers it can't include, uh, which means that uh you can't miss anything hard. Because guess what the three-pointers and five-pointers are? They're the hard ones. So uh if you miss one assessment objectives on those har hard ones, then you you don't meet that control, right? Uh so uh part of that is gonna be on our uh response to the RFI, but um get rid of the poem limitations, you know. That's what that's what made people feel like they had to have a um that's what made people feel like they had to have a mock assessment because if you've failed one of the hard ones, you just you were just done, you know. Uh so but aside from that, um so the if you have the 7021 in your contract or your PO or something like that, uh that's where you get those POAM limitations. Now what I will say, if you don't have that, the there's not technically any poem limitations, but they're not gonna accept an open-ended poem. And they're not gonna accept a 10-year poem or a five-year poem. Um and I'm talking about the government of the primes, you know, when they see that and they you try to put that, you know, this is 18 months out from getting this done, there they'll you'll probably get some pushback on that. And if, you know, so um but that's uh that's where everything stands. That's where uh what you have to do, you have to meet all 110 controls and 320 assessment objectives with those POAM um uh caveats to it. So, you know, I I don't really have time. We don't have time, I guess, to go through uh we talk too much about the pause. We talk too much about the pause. We don't have time to go through all of the uh uh controls, um, but all we'd do would be doing anyway is mentioning them, not telling you how to do every single one of them.
AustinWe do have a couple episodes that go through the broad categories. Uh we do, yes. You know, category by category.
BrookeSo Yeah. So I mean just to highlight a few uh, you know, uh you're gonna have to worry about the the same uh authorized user device and process list. Uh you're gonna have to worry about that same thing, except now you're gonna have to call out um whether they have access to CUI or not, all that kind of fun stuff. Uh same external um connections uh list. Uh here you do also have to worry about encryption and FIPS. Uh so you gotta that's gotta be addressed. Uh you gotta worry about um uh application whitelisting. Gotta have to worry about application whitelisting or blacklisting, whichever one you want to do. Personally, I think uh I think blacklisting is a excuse me. I think whitelisting is a better, a better way to better uh direction to go, especially with the solutions that are out there now that have done a really good job. Um you know, uh you have to worry about uh putting a sim in place. They don't actually say you have to have a sim, but if you go read the uh all the controls, it says you gotta have a sim. There's no way that you could a person can sit down and review uh the cheaper way to accomplish it is to buy a sim. The cheaper way to actually really meet the control is to put a sim in, yes. You know, and uh a big one, um uh access control always takes a long time to get through, but another big one that ends up being uh taking a lot of time uh is configuration management, having essential capabilities uh and functions and um and uh listing out your you know all your all your approved software, all your approved uh functions and and everything ports protocols, all that kind of fun stuff for your servers, for your uh for everything in your environment that is uh that is related, right? Uh that is in scope. Uh so that one, that one's a big one. Uh media protection, uh, you know, do you use USBs? Do you have paper CUI? Uh you know, those kind of things you have to address. Uh so there's there's quite a few things to address uh that um uh this is by no means an exhaustive list, but those are some of the some of the top things that uh need to be addressed in there. The one of the other things, I mean, uh is onboarding and offboarding of employees. You know, uh how do you bring that employee on? Uh how do they get assigned um uh access to systems? Um do they go through training? Uh training is part of this too, right? Uh you have to prove training. Um, what policies do they have to read? Uh and they're supposed to go through that training before they have access to the system. A lot of times uh when you're provisioning accounts, you provision everything, get them all ready, and you say, here you go, log in, and you can do the training, and then it may take them uh if they're diligent about it, you know, they may finish that training day one, which is what we make everybody do, but uh they may finish that training day one, but sometimes that lags on and they've already got access to other systems, right? Well, this CMMC specifically calls out you're you're supposed to do that before they they get access to other systems. Uh so that has to be part of your process. Background checks. Uh screening, excuse me. Screening. Uh you define the screening, but you have to have a defensible definition of that screen screening, and uh and so you just gotta have proof that you did that and that all the employees that have access to the data have been screened. Uh so those are the those are a lot of things that uh that are included. Again, that's by no means an exhaustive list, uh, but we've already been talking for for a little while, and uh that would take quite a while to go through all of them.
AustinSo stay tuned for our eight-hour episode. At least. At least. So let's talk about another core component, or I actually don't think it's a core component. I think it is a foundational component to um not even just level uh level two compliance, but level one compliance or anything CMMC, and that is scoping.
Scoping CUI With Real Data Flows
AustinUm and uh so I want to talk about that for a second and give it a few minutes um because it is one of the if not the most important piece. So can you give us a little guidance on um you know, and we'll just we'll talk about level two and CUI here for the sake of not you know confusing everybody, right? Um so what guidance would you give to a contractor um that uh you know handles CUI and and caveat, you know, what CUI they may create, can they create, if any?
BrookeSure. Uh so the first thing is uh you've gotta scope your environment properly, but the first part of that is understanding what kind of protected data, what kind of CUI you have. If you're a manufacturer uh or a construction company, it's you know very likely it's CTI. But what data, what comes in that is actually uh that CTI? What comes in that's that's CUI, right? Uh where does it come from? And are there any dissemination requirements on it? Is it uh is it export control, is it no is it no foreign? Is it uh you know, what is is are there any dissemination restrictions on that? And uh a lot of the times uh everybody's like, well, I don't know, I don't know, I don't know, you know, and and it's like well we gotta figure this out first. We we really can't move on and uh and scope your systems properly with unless we know what kind of data you have and all that. And so one of the things you look at is do you do ITAR work? And a lot of people say, oh, well, yeah, we do ITAR work. Not all ITAR is CUI, and of course not all CUI is ITAR. So it's not a one-to-one it's not a not if you have some consultants. Right. Right, right. But there's a high likelihood that if you're doing ITAR work that that you're gonna have that CUI is gonna be export controlled. If so, then uh that puts some more restrictions on what type of solutions you can use. For instance, uh we'll just talk about Microsoft 365, and I know I'm kind of getting off on a little rabbit here, but uh Microsoft 365. So if you uh don't have any export controlled or any other um any other reason, uh any other dissemination restrictions uh that apply, uh if you don't have any of that, then you can probably use Microsoft 365 GCC. If you do have any of those uh dissemination restrictions like export controlled, like the ITAR data, uh then you have to use uh Microsoft 365 GCC high. So it's GCC and GCC high, right? Uh that said, just because you have Microsoft 365 and you have CUI, that doesn't mean you have to use GCC or GCC high. That's all part of the scoping question, right? So you figure out what kind of data you have. That is critical, you got to do that first. Where does it come from? Uh and this is all your data flow. Where does it go to, right? Um likely, you know, it goes uh you download it from a protected portal uh to a computer and you take, and from that computer you copy it over to a map network drive, and from there you may put it in your uh MRP or something like that. Uh, and then from there, other people get to it from uh MRP installed on their computers or maybe from the map drive. Um maybe they open it up in CAD and do some work on it and make some smaller drawings, which is part of what you were getting at here in just a second. Uh, or you know, pull-outs of that and make some drawings uh on certain pieces in there. Um so you gotta figure out where that data flow, where that data flows right now. And then you gotta look and go, does it does all the CUI need to flow through all those points? Or can we take and shrink that down a little bit? You know. Well, the accounting person, she opens up the drawings because she just wants to look at them, you know. Uh the uh the HR person, well, you know, that they have access to them. And do those people really need access to the CUI? You know? Um do all your uh production people really need access, or is it just these two or three people? Uh so you got to figure out what you really need and scope your environment properly and scope it down to where you think it can go, but you need to do that full data flow diagram so you really understand it. And you need to involve other people, not just not just the IT guy, because as IT people we're like, yeah, it goes here, here, here. That's you know, but whoever uh whoever does the work will go, oh, you know what? I actually do this and this with it too. And the IT guys are gonna be going, really? So uh point is, or the C CEO may, you know, president or whoever may not understand all that. And so the point is, bring some of the people in that actually do the work, the the the owners of that work or the supervisors that know the process and uh get that data flow drawn out properly. And so once you have all those people in the room that can help you uh develop that, you know your CUI data flow, right? So the part part of the uh and that helps you scope all your systems appropriately, right? So maybe you can scope email out. Maybe you don't need uh access to anything, uh any CUI on on phones or tablets. Uh maybe, you know, maybe they're only out of fifty people in the office, maybe only eight people need access to it. You know, I whatever it may be. Um or maybe truly it is you have a 10-person office and everybody but the everybody but the uh office manager have to have access to it. Maybe that really is the case. Uh but you need to scope appropriately. Uh and so that will help drive the rest of the conversation from then out. Do you need Microsoft 365 GCC or GCC high? Maybe, maybe not. Maybe you can do commercial, uh, maybe another solution. Anyway, those will drive a lot of decisions. The one other thing you were talking about is, you know, you've got that data that I know always comes in marked. Right. Uh and I I laugh because it's that's that's the exception rather than the rule, right? Uh but if you've got that data that's C UI, that drawing, we'll just use a drawing. We've got that drawing that's C UI, and then one of your engineers takes and breaks part of that out uh and makes a drawing off of that and makes then makes some um uh some G code off of it to go uh build a build a part, you know, uh then depending there are some caveats, but uh uh depending on whether it's a COTS, uh, an off-the-shelf product or not, um so uh that likely is CUI, right? That piece that you pull out of it that comes from that government drawing, it's produced on uh uh on behalf of the government on behalf of the uh for that contract, so that's gonna be CUI. Uh the uh the G code that results out of that. Now there's a big debate about it this online, and we may even get some hate mail for this, but uh that G-code uh I already do. That G code is likely uh CUI as well. That doesn't mean uh that doesn't necessarily mean your life is over and you know you gotta your C and C is a good thing.
AustinIt's so much easier uh than people think it is.
BrookeIt is a lot easier than people make it out to be. But that doesn't necessarily mean that C and C machine uh has to be has to meet all 110 controls. That's that's not the case. Um you do have to protect it. But so you do have to have to show how you do some things, but doesn't necessarily mean um what a lot of people think it means. So that G code is likely going to be in scope. Possibly it it might not be, but it doesn't matter if you strip all the uh original part numbers off or the names off or anything like that. What really matters is that it says it's uh the that was or that it's produced on uh or on behalf of uh the govern uh on behalf of the government on and the performance of that contract. Uh so that's what really matters. Uh again, if you can show and prove that uh what you have, uh the the piece that you're pulling off there is just a commercial off-the-shelf product, uh document it and and you're good. But I would say you you definitely want to make sure that you can defend that, you know. Uh so I think that's where you were getting at with all that. Um but uh you gotta you gotta know what kind of data it is data you have and where it comes from and where it goes in your systems, and then you can scope properly and figure out what has to be in scope and what doesn't.
AustinSo to dummify it. That's my that's my job on the podcast. That's my job on the podcast. So I don't know if you if you're a longtime listener, you might have you might know that I've recently taken over my own lawn care again uh because I got frustrated with my lawn company. Um so uh just preface what I'm saying. No, not at all. Uh not at all. So in fact, my lawn's looking better uh than uh them doing it, so which is why I uh got rid of them. Anyway, so uh the problem with um not doing scoping or starting there um is that you typically solve the wrong pro wrong problems. Absolutely. Um what happens is when people get into uh um the compliance stuff, they like to skip to the feel goods. And the feel goods is buy a tool, do an implementation, do X, Y, or Z, and oftentimes you end up solving the wrong problem because you didn't scope correctly. Absolutely. And so to use my lawn care analogy, because I'm you know uh been doing that a lot lately, is um I've recently had a mole problem, mole infestation. Oh no. Yeah. And so um what I did uh scoped incorrectly um is I immediately just bought um uh a mole trap. And I tried that for a couple weeks to no success as uh the little jerk. I'll uh watch my PC language, was rolling around destroying my roots and my my lawn and everything else. Um and then um anyway, long story short, uh I get to like uh because that felt good, buy a trap, kill them all, right? Yep. Um and so uh but didn't work. Uh and so I got to diving into it a little deeper, understand more about the moles, and you know, a little more legwork, the the work I wasn't wanting to do. I just wanted to solve the problem, but I ended up delaying the problem and making it worse. Um and so long story short, I learned to kill the grubs first, lay down some of that, um, and then basically. Like starve him out to make him go away. Um then I didn't have to kill him. Uh anyway, but also and then I laid down You should chase him over to a neighbor's house. I hope my neighbor doesn't watch podcasts because he has a mole now. Um but and then I laid down mole deterrent and and phases, and that seems to have worked for now at least. You know, we'll see. Maybe I'll talk here in a couple weeks about how I was wrong about Was your mole in your front yard? Uh it was in the front, and I got pocket gophers in the back.
BrookeSo I'd say you have a defective dog if they're in the back.
AustinSo right. Well they're under the ground. So um but anyway, so uh just using the analogy is that you know, um skipping scoping, you're you're sh you're skipping to the feel goods, which make you feel good in the moment, but delay your problem and make your problem bigger and worse down the line. So pause and do the painful, boring work of scoping to build a good foundation, and then you can actually solve the correct problem because like a lot of times people just go buy GCC high and they don't ever realize they didn't need it in the first place. Right. Not saying GCCI is a bad tool. It's a great tool if you need it, and if it solves a problem, oftentimes not needed.
BrookeOftentimes not needed, oftentimes overkill, yeah.
AustinRight. And so my mole problem, I didn't use the trap to get rid of them. Right. So uh anyway, that's uh dummifying it. That is why scoping is important, is because you've not done, you solve the wrong problem and you don't actually get compliant.
BrookeAaron Powell The other thing I'll add to that is that uh you the reason you start there with figuring out what kind of data you have is because of of what everybody everybody's answer when whenever we say, you know, what kind of uh what kind of CUI do you have? Oh, you know, well, how do you know you have CUI? They told us we had to be compliant. Okay. But but beyond that, you know, uh so it's it's a it's not the easiest thing to solve. And it's an unknown. And it's an unknown partly because of the uh government uh or at least the primes not marking things as they come down uh to contractors and subcontractors. They're they're not marked well. So uh that's understandable, but you do have to do that homework and figure that out at first and uh and figure out where that's coming from.
AustinThat is um I you you'll you'll hate to hear this, but I do more unselling than selling in our our company because a lot of times I'll get um someone calling in and say we need TMMC compliance, we need level two or whatever. And uh more often than not, just through frankly, the sales process, um, you know, I'll ask them, you know, like, well, let's look at contract clauses, let's, you know, what did your buyer say? What's you know, letter did you get, let's dive into this. And oftentimes I'm able to just have them go back to their buyer or their prime and they'll go, oh, you know what, you actually don't need to be level two, um, you need to be level one. Or you know what, this actually doesn't even apply to you, you're fine for now. Um, you know, uh, and you don't have this requirement at the moment. Yeah, so absolutely uh that it is very worth doing that because you might solve you might save a couple hundred thousand dollars.
BrookeI would rather do that than get somebody in the solution they don't need and be upset that they spend all that money uh you know down the road.
AustinYeah. So that and and if you do scoping, you'll figure that out. Right. And that's why that that is also important. So um you may find that you don't have to do compliance at all.
BrookeRight.
AustinUh maybe not. Maybe you're maybe you'll find how um how much you do have to do, and that's not gonna be fun either, but at least you know. So I know we're running out of time here. Um again, took too much time on our uh on the 60-day pause. Um, but uh I think we can wrap it up um simply by saying uh and addressing where assessments go wrong, right? Um so where do we see you know assessments uh typically going wrong or where um uh the the problems that when someone comes to us that they're experiencing where they haven't been able to get a compliance program off the ground or an assessment being successful?
BrookeYeah, uh but one of the things we said earlier, you know, uh it's documentation.
Why Assessments Fail: Docs And Vendors
BrookeThat's the biggest thing uh that stops most people. Um not all the controls, but uh most of the controls have a documentation piece to it. Uh so um, you know, if you don't have that documentation piece figured out and then done properly, uh then you just miss that control, right? Um if you don't list out all your authorized users, which ones are uh privileged or admin, which ones have access to CUI, um, where do they have access to it? Do they have an access through Active Directory or on a file server? Do they have access an intra ID and SharePoint? Do they have, you know, where do they have access to it? Uh an on-prem MRP solution, uh, you know, there's users in there, you gotta take that, uh take that into account. So um but point is documentation is where most assessments go wrong. Uh and even when you go through an assessment, you might think you have something documented properly. Uh and an assessor might say, we need some more documentation on this, you know, needs to be fleshed out a little better. Or you said you didn't deal with it this way, but you know, I don't understand what that means. You know, and so uh so you may need to go back and flesh some of that out. Now, you may not be going through an assessment anytime soon, but um the point is you need to have that documentation fleshed out so that other people understand, not just not just the people in the know, right? Um so that's the biggest thing that uh that we see. Another one is um uh ESPs uh and and other vendors, I guess. Uh well, all those would be ESPs. So ESP is an external service provider. Uh they come in two different flavors. Uh ESPs that are a CSP, and ESPs not a CSP. That's how they define them. So Which could be an MSP. Exactly, which could be an MSP or an MSP or a anyway. Uh so uh the CSP is a cloud service provider. Uh and the NIST 800 uh 145, I believe it is. Um one of those. Uh has like uh a five-character test uh to uh and I don't have it pulled up here in front of me. So those five uh those five characteristics are gonna be things like uh uh can you self-provision? Uh is it provisioned automatically, uh quickly? Um uh is is it based on usage, you know? So those are the things that that make uh make a service a CSP. Like and that's gonna be like Microsoft 365, Google, um, you know, Amazon, stuff like that. Those are the easy ones I can throw out there. Um ESPs not a CSP uh are gonna be uh most of the time uh an MSP, a my uh managed service provider, uh an IT services company, whatever you want to call it, people like us, uh most of the time we're gonna be a MSP, not a CSP. So um if you have any cloud services uh that you serve clients, uh then you might be a CSP. So uh we were very careful to make sure that we didn't that we didn't fall into that category because when you become a CSP, there's a whole nother level of compliance you have to worry about, uh, which is FedRAMP uh author authorizer equivalency. So um so uh MSP will be a ESP, not a CSP, right? Um MSSP, so uh MS M SSP is a uh managed security services provider, and typically their focus is a little narrower than a MSP. Used to be that a MSP was your j general IT department, and MSSP did the security, but there's a lot of intermingling now, and and there's more a lot more MSPs uh that do the MSSP work uh than than used used to. So um and meaningful real MSSP work, you know, not playing around the edges. So um so you might have uh MSSP that provides you a SIM, might provide you application whitelisting, might provide you uh you know something else like that. So uh some of these cloud managed tools that are um security protection assets, so a security protection asset, SPA, uh and uh will handle security protection data, SPD. Uh so any of those are uh if they're cloud managed, um like uh EDR solution, uh endpoint detection response, uh managed EDR, MDR solution, um a SIM that's cloud managed, any of those things that are cloud managed, deal with those things in the cloud. Unless they handle CUI, they're just an SPA, right? And in that case, uh they're an ESP, not a CSP, because they're securing that CUI, they're not handling it. So um but those uh for any of those providers, uh ESP's not a CSP, uh you have to worry about documentation from them as well, right? You have to worry about their um CRM. We just we just shorten it to CRM, you know, uh customer responsibility matrix. Um technically what we provide is a SRM uh shared responsibility matrix. So on a CRM, technically that says here's all the controls, CMMC controls, and here's the things that you're responsible for, Mr. Customer or Mrs. Customer, or Miss Customer, or just customer. So uh and then for a shared responsibility matrix, it says what the provider does and what the customer does. That has two columns, right? Uh frankly, assessors like to see the SRM uh much more. Uh we provide SRM to say these are the things so you can see concretely, these are the things we do, uh, what we we provide for you, and here's the things that you're responsible for. Um so you some of these things you'll probably just get a customer responsibility matrix out of it. Uh that's the the bar. Um so you need to have that documentation uh from your ESP. If you're a C if you have a CSP uh cloud service provider that falls in that category, then you need to worry about uh FedRAM. Uh so you need to worry about whether they're FedRAMP authorized, um, FedRamp moderate authorized or higher or uh equivalent. And equivalent has a specific meaning from the DOD or DOW. Uh so you have to read that and make sure uh that they uh have actually achieved actual equivalency. And there are a few out there. The first one was prevail. Um so uh there are a few out there that have equivalency, and you can use those, uh, but they also provide uh uh CRM or SRM. Uh if they're FedRAMP authorized, they have a FedRAMP package. You have to include that in your documentation. Um some assessors are okay if you're again we're we keep bringing assessors into this because there are still assessments going on. It's likely assessments will happen after this. We just don't know what exactly they'll look like. Um so the uh the assessors are gonna want to see um uh gonna want to at least know the FedRAMP package number, right? Um a lot of them already they've done enough assessments, they they either have or know the Microsoft GCC one, uh GCC High one, you know, AWS, the, you know, they've seen all of them. So if you if you've got the at least have that package number, you know, they have it. But what I can tell you is uh they don't just hand that out to everybody. You have to request it. You have to be a customer, usually you have to be a customer uh to request that package. And so you gotta request that. It doesn't always come quick, so you gotta uh request that in plenty of time uh before assessment or before you need it, uh, you know, uh before you declare that you're uh you meet all the controls, if you've if if that's part of the documentation you have to have, then you need to get that. So um so your ESPs that you use or vendors that you use for your environment, uh they matter uh a lot as well. Not just the documentation you have, but their documentation matters uh as well. If you use an MSP, um again, they need to have, at the very least, they need to have a CRM for you uh mapped to at least all 110 controls, preferably all 320 assessment objectives, uh, and preferably really you want to have a shared responsibility matrix that lists their responsibility and uh your responsibility. Um if they're level two certified, even better. Uh so uh if they are level two certified, they'll probably uh no, it's not uh a definite 100%, but if they are level two certified, there is a high likelihood that um your uh they won't dive in as much to uh to your vendor, to your MSP. Uh they will, uh your MSP will sit in on those assessments, uh some MSPs have taken the uh route of trying to be uh have a SRM or CRM that takes them out of scope as as much as humanly possible, and they're just kind of like a uh an antivirus or a sim. And you know, you just read it and you put your stuff in place and you're good. Um But you know, if you're if you have an MSP that really helps you with all this and is not just a you know commodity product, then then uh they're likely gonna have to sit through that assessment with you. Those are the things that we see where people are lacking. And that documentation, uh knowing what vendors they have and what documentation they have from their vendors, uh and where they even those vendors even meet the requirements. A lot of times they don't.
AustinAwesome. Well, thank you for that, Brooke. And I think we'll probably end the episode here. We'd lost our video, we've been having technical difficulties.
BrookeOur camera bit the dust. So those of you that were watching online, you know, you'll probably see uh uh something else other than video at this part.
AustinSo Right, yeah. An apology. That's what you'll get. So um anyway, so uh appreciate you guys hanging out there with us and and uh I
Key Takeaways And How To Reach Us
Austinthink the the main thing um you know take away from this episode if uh if you don't take away uh anything else is that um just know that uh you know the the mechanism of of phase two um has has been paused for the 60 days. Um but just keep in mind please that your um your all the requirements for the contracts um still exist um and you you uh still have those liabilities out there. So um make sure that you're uh taking care of yourself on that front and you've got all your documentation, you're uh you're still being compliant and you're you're still doing your implementations and everything else. So don't don't get caught get caught in a scenario where you're uh not staying compliant anymore. So that's still that's still the goal. So CMMC is not dead at this point. Not not yet, anyway. So um if you have any questions about what we covered, please reach out to us. We're here to help fast track your compliance journey. Text, email, or call in your questions, and we'll answer them for free here on the podcast. You can find our contact information at cmccomplianceguide.com. Stay tuned for our next episode. Until then, stay compliant, stay secure, and make sure to subscribe.

