The Real Cost of CMMC Scoping Mistakes: Is "Six Figures" Real or Just Marketing?
CMMC Compliance GuideAugust 21, 2026
69
00:46:5832.27 MB

The Real Cost of CMMC Scoping Mistakes: Is "Six Figures" Real or Just Marketing?

Submit any questions you would like answered on the podcast! Is the "six-figure CMMC scoping mistake" a real number, or just something people throw around to sound scary? Stacey and Brooke break down where these numbers actually come from, what over-scoping really costs versus under-scoping, and what a defensible scope actually looks like. In this episode: Where the "six figures" scoping numbers actually come from (and why the DoW CIO and SBA's recent numbers conflated compliance cost with ce...

Submit any questions you would like answered on the podcast!

Is the "six-figure CMMC scoping mistake" a real number, or just something people throw around to sound scary? Stacey and Brooke break down where these numbers actually come from, what over-scoping really costs versus under-scoping, and what a defensible scope actually looks like.

In this episode:

  • Where the "six figures" scoping numbers actually come from (and why the DoW CIO and SBA's recent numbers conflated compliance cost with certification cost)
  • What over-scoping actually costs: pulling in unnecessary cloud systems, remote users, and locations
  • What under-scoping actually costs: a $30k-$40k assessment redo at best, a False Claims Act investigation at worst
  • The most commonly missed scoping items: downloaded CUI, cached files, backups, CNC-connected computers, and cloud file-sync tools like Prevail Drive
  • Why vendors and IT providers (MSPs, MSSPs) are an underscoping trap if their CRM/SRM documentation isn't in place
  • Why most over-scoping actually traces back to primes and the government not clearly marking what is and isn't CUI
  • 2026 scoping clarifications: encryption doesn't create a CUI boundary, paper-only CUI can limit flowdown, and why FedRAMP 20X won't satisfy DoW requirements
  • Real False Claims Act cases where scoping was the legal basis (including a Georgia Tech case)
  • What a defensible scope actually looks like in your SSP
  • NIST 800-171 Revision 3 on the horizon, and why you need to start planning for it now regardless of what happens with the CMMC pause
Stacey

Hey there, welcome to the CMMC Compliance Guide Podcast. I'm Stacy.

Brooke

And I'm Brooke.

Stacey

From Justice IT Consulting, where we help businesses like yours navigate CMMC and NIST 800-171 compliance. We're hard guns, getting companies fast track to compliance, but today we're here to give you all the secrets for free. So if you want to tackle it yourself, you're equipped to do so. Let's dive into today's episode and keep your business on track. Today we're talking about scoping. Specifically, what it actually costs when a contractor gets it wrong. People throw around the phrase six figures a lot. So let's get into these numbers and see if they're real or just marketing. So let's get started. Is six figures a fair number or is it a bit exaggerated, Brooke?

Brooke

Well, the problem from overscoping or underscoping can be all over the place depending on uh how big the contractor is, um, depending on how complex their setup is, um, all sorts of fun stuff. So uh yes, it definitely could be a six-figure uh mistake uh for over scoping. Um uh could be some other problems if you underscope. Uh and I guess those might lead into six-figure issues later on, but uh uh yeah, there definitely could be um, you know, a six-figure problem. So a lot of people like to throw around the the six-figure number, you know, you could you could be over-scoping and cost yourself, you know, $100,000, $300,000. Uh you know, the question is, you know, uh what size contractor is that? How complex is their system, uh, what time period does that cost, you know, all sorts of fun things. And uh so you could see over scoping costs you, you know, $30,000 or $40,000, you know, over a year or three years, or you could see it cost you $300,000, depending on how big of a or even more, I guess, but uh depending on what size contractor you are. For most small businesses, what we think of as small businesses, it won't be that high. Um but it still will cost money. And for small businesses, yes, that uh that still less than six figures uh means a lot. So uh yes, it could be definitely could be six figures, could be less, but there's a whole lot of factors there that that go into it.

Stacey

Aaron Powell So before we get into specific figures, where is this data actually coming from?

Brooke

Uh well part of it recently comes from the uh uh DOW CIO Kirsten Davies and the SBA uh Small Business Administration. They threw out some numbers that were wildly off. Uh but you know, um for what the government considers a quote small business, uh then those numbers could have been accurate for a 500-person company or or something like that, right? Um and that's if you way over over scope and have a big problem or or uh make your setup really complicated. And I guess really they were I think they were conflating compliance with uh certification in that case. And they were talking about certification costing half a million dollars and and um and so I don't I don't know of any certifications that have been for small business that have been even over a hundred thousand dollars. So um, you know, most of the certifications I know of, just for the certification assessment, you're talking uh thirty to forty thousand dollar range, you know, um even for a complicated one. Uh the simpler it is, simpler the environment is, the the easier it is to assess, and the the cost will be cheaper, right? Uh not necessarily the size, but the complexity. That's that's what drives a lot of it. Size does to some degree, uh, but the complexity does as well. So if you've got, you know, four different cloud systems involved and you know an on-prem server and a whole bunch of remote users and you know, this, that, and the other, and uh you have Macs and you have Windows computers and you know, that assessment uh um certificate that assessment cost is probably gonna go up, right? Uh however, if you have if it's all on premise, you know, you don't use any cloud tools uh or very few, uh at least not in scope or CUI, that then that brings down your uh your uh cost as well. Uh but we're talking about the assessment. So but as far as where those numbers come from, aside from the aside from the recent CMMC pause and the DOWCIO, uh they come from C through PAOs, uh RPOs like us, um you know, uh other people that have uh that are in the ecosystem that have said this is what we see, right? You generally don't have any context around that or not much context as to what exactly that entailed. So uh that's where those numbers come from, you know, Reddit, LinkedIn, you know, whatever, uh whatever else you may see out there, but um there there's nothing. Um there's no studies, there's no actual real data behind that other than what people have seen and what they what they talk about.

Stacey

So let's hop into over scoping.

Brooke

Sure.

Stacey

What does pulling too much into scope actually cost?

Brooke

Well, again, really. It's a it depends. That's that's the uh the biggest answer you'll really get. Uh so over scoping, it can increase cost. Uh it depends on what all you pull in, if you pull in cloud systems, if you you know, if it's just a pure number thing, number of employees, then it doesn't necessarily uh skyrocket the cost. It will increase it somewhat, uh, but it doesn't skyrocket it. When you start pulling in um, you know, uh different cloud providers and remote users and all this other stuff that you may or may not need to do, then that's when it starts really uh increasing the cost. Really that's it here. But the um you know, you can uh you can increase cost if you uh scope in the wrong systems, uh if you scope in too many people, uh remote users, um remote work locations, you know, that may or may not need to be included. Uh you know, they have to be protected just like uh just like your main locations. So if you have a you know two offices or you know, three offices or construction buildings or whatever it is, how they come into scope matters, right? Um so uh and they may come into scope only for physical CUI and not uh not electronic CUI, right? So um or logical, however you want to phrase that, but you know, depends on what they come in scope for and what where how they have to be covered. Uh so it can cause a big problem over scoping, it can cause a small problem, but generally if you overscope, it does increase the cost to some degree. And so, you know, the the one example I can I can throw out, and not a clear example with numbers and everything, but um if you have, for instance, a hundred-user company uh and you've got a mix of uh commercial and and DOW work, um, you know, does everybody do all 100 employees really have to access that CUI and process the CUI? You know? Uh if you have a mix of people, uh they may today, but you may not have to do that. If you change your workflow and say, all right, these 25 people are going to be considered in the quote enclave, you know, we've discussed enclave, that can mean a lot of different things. But enclave is basically something something separated, right? With a separate security boundary. So uh we can put for a 100-person company, if we put these 25 in this enclave and consider them in scope, uh, then that generally will lessen the burden on the rest of the network. A good rule of thumb if you create an enclave is to say, you know, here's the enclave, it's where my CUI is housed, and it has to be up to level two standards. The rest of my network, it may process FCI and it has to be up to level one standards. Level one, you can get that done, uh, especially if you have to have your enclave up to level two anyway. Your uh the rest of your network being at level one uh is a pretty simple step. Um it's not nothing. Uh and you're if you're starting out uh from the get-go trying to get to level one, again, it's not nothing. There are things you have to do, and there are things you have to make sure are in place, or else you can't um claim that you're level one compliant, right? But if you create that enclave, uh then absolutely it works and it can reduce the cost for you. Um and that's wonderful, but you have to make sure that enclave will actually work for you. For a small person, uh for a small company with, you know, maybe 20 users, and maybe there's an HR person and an accounting person, but everybody else, and uh, you know, 100% of your work or 75% of your work is uh Department of War, uh then you know it's very likely that most of your network's gonna have to be in scope. So you may be able to skip scope a few things out of it. Um but at that point, you know, you're scoping a few things out and not letting them have access to CUI, uh which is what you should do, uh, but you're not necessarily reducing the cost a lot.

Stacey

Aaron Ross Powell So if we pivot to the other direction, um underscoping and actually failing an assessment because of it, what does that kind of look like in terms of cost?

Brooke

Aaron Powell Well, if you fail an assessment because of that, you'll have to just do the assessment over again, right? Um hopefully if they catch it in phase one, you can tap the brakes and stop and reschedule, right? Uh if you pass phase one and get in phase two, and you fail during that phase two, they realize that, oh, hey, you said this was your enclave, but these computers over here are processing uh CUI from what you tell me. Uh you know, that that will be a that will be a giant red flag. Uh and you know, you'll fail that assessment. So um hopefully you discover that or the C3PAO discovers that uh, you know, in phase one, uh that would be helpful. Um but if you fail that it could be a $30,000 or $40,000 redo. Uh or if you're bigger, more complex, it could be more, you know, $50,000, $60,000, who knows? Um so that could be an expensive redo. The other problem is if you under scope and somehow you get through your assessment and it's not found out, and you have some sort of problem later on, uh some sort of whistleblower or some sort of breach or something like that, and it's found that you had COI outside of your enclave, that is not a good thing. You'll there may be a false claims act investigation that opens up. So that will be more than a $30,000 or $40,000 hit. That will be more like a, you know, uh we're talking about six figures. It could be, you know, six, seven figures uh for that hit depending on your contracts uh and the damages they they assess. But um those are the those are the dangers from underscoping.

Stacey

Is there one comparison that really captures this very cleanly for our listeners?

Brooke

Uh yeah. So if uh if you scope properly and uh so you make your enclave make it a little smaller, then you know, a lot of times, depending on your starting point, you know, uh you could get that done in less than a year. If you're if you're starting from zero, you could probably get that done in less than a year. Um if you overblow that scope, bring too many things in a scope, make it too complicated, that could push things out easily to 18 months or more, and could cost you a whole lot more to uh to to get everything covered in a scope and figure out how in the world you're gonna you know cover you know remote users with Macs or something like that. Uh so uh yes, if you if you uh if you scope properly, uh then uh that generally helps make sure that you uh keep that environment clean, simple, uh as clean as possible, and simple as possible. It may not be simple, but uh simple as possible. Uh so that'll help that'll help get things done a lot quicker as well.

Stacey

So diving into specifics, what are the actual items companies miss when they underscope?

Brooke

Aaron Powell Well, a couple of things really. Uh so one is uh not realizing that uh when you download CUI from uh a portal, a vendor portal, um, or a customer portal by you know Lockheed or the government or uh you know something like that. When you download that, guess what? That download is CUI, so wherever it goes, that that device is in scope now. It doesn't matter if you download it, transfer it into the quote enclave or or not, and then delete it, it it's still that computer is still in scope. You can't do that. It's you can't download it to an out-of-scope asset and then move it over to an in-scope asset. You have to do it from an in-scope asset. So if you download something, if you cache something, uh that brings that um into scope. There are some also uh cloud programs. Uh I'll just say uh Provel is one, Proveil's great, we love Prevel. Um, but uh, you know, if you're using Provel Drive, they do have a VDI solution now, virtual desktop infrastructure solution. But if you're using their um uh Prove Drive, uh that stuff lives on your computer. It may they may take care of a lot of the controls, uh, but that stuff lives on your computer. Um you open it up, it gets processed uh and transmitted uh from your computer. So your computer is in scope, and a lot of people don't realize that. So uh that's the biggest thing is that wherever anything that processes, stores, or transmits CUI is in scope, right? Um the other thing you have to think of, and I hope I'm not jumping ahead, but uh other things that are not in scope for CUI but in scope still are anything that processes uh anything that secures CUI is called security protection data or SPD, uh, which would make that an SPA, a security protection asset. So uh any of those security protection assets that don't really process CUI but uh process store transmit CUI, but they do secure it, uh those are in scope for SPA, and those will be uh reviewed for whatever controls, whatever controls they cover for that CUI, right? Uh so that's another thing you have to think about when scoping. You know, some other things that are in scope. Um another, you know, one thing is laptops, you know. Well, hey, I connect to my I connect to my Enclave with a remote desktop. So my laptop's out of scope, but not really. If you use VDI and you configure it properly, then yes, that laptop can be out of scope, or that whatever computer it is, but typically a traveling laptop, for instance, uh, you know, that can be out of scope. But uh if it's not secured properly or for its uh a remote desktop uh connection instead of a true VDI, instead of a true VDI, then uh that computer is in scope. So those are those are some typical things. Some other things are you know like uh computers that connect to CNC uh machines on the floor and control them. Uh those are in scope. You can actually those can actually be a uh you know a specialized asset, but you do have to treat them properly. You do have to secure them, you do have to show how you're you're taking care of that, right? Uh and another one is backup, uh backup of data. So uh it's not just that local backup, if it gets synchronized to, which is typical these days, gets synchronized to an off-site cloud, is that cloud is in scope for CUI, right? It doesn't matter that the data is encrypted. The government has said, has come out with their FAQs that, you know, encrypted CUI is still CUI, it's just encrypted. So um the uh those cloud systems uh have to meet extra or have to meet all the compliance requirements. So uh, you know, for instance, if it if you're backing up uh CUI to you know a cloud a commercial cloud, uh then it's not gonna it's not gonna work. It needs to be a FedRamp uh moderate authorized or uh equivalent cloud. Uh or you know, if it if you're using an MSP that backs your data up and they back it up to their data center um and it's not it doesn't classify as a cloud solution, uh then you know they need a level two certification, for instance. Uh so if they've got that and they back up data, they're all good as long as that was part of the scope when they were assessed. Um so that's all good. Um those are the kind of things you got to think about as far as uh scope goes, what actually gets missed in underscoping.

Stacey

Aaron Ross Powell So pivoting the conversation a bit to vendors and IT providers, how big of an underscoping trap are they?

Brooke

Good question. I just referenced some of it. Um, you know, but whatever typically, if they're not dealing with any CUI, they're not backing it up, they're not, they don't have some sort of cloud sync program, uh cloud file sync and share, right? Uh if they don't have that kind of program running or or manage it or uh anything like that, then that's out of scope. So CUI might be will probably likely be out of scope. Uh but they have to have their RMM configured correctly. They have to have all their services that do any kind of protection of the data. For instance, the the SIM, their security information and event monitor, um, the uh antivirus that they provide, you know, all that kind of fun stuff. They need to make sure those are configured properly. Uh and those will be assessed with uh with whatever uh CY they provide protection for, right? Um and they'll be assessed against the controls that that are applicable there. Um the other thing that they're they're gonna need is a uh CRM, a customer responsibility matrix, or a shared responsibility matrix, but everybody just refers to it as a CRM these days. Um we call ours a CRM, but technically really it's a SRM. Uh and we just call it a CRM because that's what everybody does now. Uh uh customer responsibility matrix is gonna be uh show you uh gonna go through all the different controls, hopefully all the assessment objectives. Um at least 110 controls, if not all the 320 assessment objectives. We do ours by assessment objective, and um but a CRM, uh a customer responsibility matrix is gonna say, here's all the controls or assessment objectives, and here's what the customer is responsible for. The SRM or the shared responsibility matrix uh is gonna be uh is gonna do the same thing with all the controls or assessment objectives, and it's gonna show you what the customer is responsible for, what you're responsible for. And it's also gonna show what the provider is responsible for. So on ours, we say this is what we do, and this is what you're supposed to do. And so uh that one arguably is a lot more helpful uh because it spells out what the uh provider does and it spells out what you're supposed to do. Uh so there's no question there. Uh but those CRMs, I'll just blanketly call them CRMs. So those CRMs are very important and uh they help assessors look through and you know verify that you're doing what you're supposed to be doing. Uh there they also are very, very helpful for the OSC or the person that's seeking the company seeking certification. Organization seeking certification, I guess I should use the right words, so OSC. Um organization seeking uh compliance, I guess, at this point. Uh but those uh CRMs uh will show, will explain to that uh company what that provider is providing to them and what their responsibilities are. Uh those are very important. Um if your provider has a uh MSP, for instance, has a level two certification uh and their uh CRM was assessed, um uh validated along with the assessment, uh whatever, you know, with the assessment scope, um then uh that that goes a long way to helping the assessment out and making the assessment a lot quicker.

Stacey

So on the flip side, why do companies overscope and what's the actual fix?

Brooke

Well, companies overscope uh for a few reasons, but the main one is they don't know what in the heck kind of CUI they have, and they don't know what in the heck is CUI. And most of that problem is the government's problem and the and the problems problem that they're causing. Uh and they're just saying, hey, here's your contract, and it has 7012 or whatever else in it, and uh there may be CUI in this in this uh contract, you know, in uh come in with this contract. So um you're like, great, that's wonderful. Well, now tell me what is a CUI, and they'll say, well, you know, any of it can be, and you push back and they say, Ah, all of it's C UI. So now you know you're stuck uh trying to treat everything they give you as C UI when that's not the case. If you push back politely and firmly, because I know you don't want to bite the hand that feeds you, um, you know, if you push back politely and firmly and say, hey, look, we we're really we're trying to reduce our scope here, and we're trying to save you money as well as us money. Uh can you tell me what is CUI on here? And uh and most of them I don't know about most of them, but uh they're so they should, they're supposed to. Two, some of them do uh come back and say, yes, this this is CUI, this is not, right? Uh some of them may even portion mark things, and that is awesome. Um so uh portion marking being here's a document, and this is CUI, this is not, this is C UI, this is not, right? Uh so uh you don't see that a whole lot. You do see it some. Um, but uh when they can tell you exactly what is CUI, that makes the picture a whole lot more clear. The unfortunate thing is that we we see it with all of our clients, not just one or two, not 75%, a hundred percent of our clients have this problem. And it is the DOD's problem, it is the Prime's problem that they cause. Um they don't know what exactly is CUI. They if it's not Mark C UI and they push back and they get some vague answers, then if they think it's C UI, they just have to treat it as C UI, right? And so that ends up leading to uh over scoping, saying, well, I don't know what is CUI and what's not, so we'll just include our whole network. Wonderful, but you don't necessarily need to do that, right? Um now sometimes that doesn't really matter if it's a small company and uh all you know they've got a significant portion of DOW work, then that's probably gonna be most of the employees working on it anyway. And it it may not reduce the cost, but that's what that's what helps lead to over overscoping. Um taking people's uh not involving the different parties at your uh at your organization that are actually involved in doing the work uh can also lead to overscoping, uh because the way I as an IT guy thinks things might it can also lead to underscoping, but uh the way I as an IT guy thinks things probably happen, or the way the general manager or CEO or whoever it may be thinks that things happen isn't really always the way it happens. So you bring in some of the workers, some of the supervisors, whatever it may be that actually deal with that work and do that work, they say, oh no, uh it doesn't go through this system, this system, just this system. This is what this is what happens, this is what we do. Or if they say, Yeah, it comes through all these, but really doesn't need to, you can say, Oh, you know what? In that case, why don't we change our process and we can we can reduce the scope here, right? Uh so not understanding the actual flow and what can be changed uh also leads to uh over scoping. And then uh, you know, if you're able to, sometimes you're not, sometimes enclaves work, sometimes they don't, but if you're able to uh design an enclave, whether it's a a VDI, virtual desktop infrastructure, or whether it's something else, uh, you know, an actual room where there's one or two computers or what, you know, whatever it may be, um if you can create an enclave and actually use that enclave, then that will help out a whole bunch. Uh that'll help out a whole bunch and keep you from over-scoping. If you can keep all the CUI in that enclave, in that room, on those computers, uh, then that helps out a bunch.

Stacey

Aaron Powell Are there specific 2026 clarifications contractors should have on their radar for scoping decisions?

Brooke

Yeah, there's a few things I talked about uh through the Cyber A B town halls and and uh and the FAQs, uh stuff like that, but they specifically uh and I don't know uh I didn't know anybody that actually believed this. Uh but in in they specifically stated encryption does not create a CUI boundary. Well Yeah. No, it doesn't. So that's that's understandable. Uh but uh they did make that clarification. So I guess there are some people I guess that's related to the uh once it's encrypted, it's not CUI any longer argument, which was always bogus, but a lot of people believe that and and fully and emphatically defended it. So uh but the si the DOW also came out in their FAQs and said it's if it's encrypted, it's still CUI, right? Um logical separation, VLANs, uh things like that, uh still uh they still require all the controls and all the explanations and all the diagrams and everything else, uh, but you you've got to show all that. One of the things that can reduce scope and reduce flowdown is paper-only CUI. Um and one of the things I can think this easily applies to is contractors. So if uh you still have to protect paper CUI, but if a subcontractor, uh say your concrete guy, maybe, I don't know, uh you know, needs some drawings or something to see where, you know, to pour the concrete, what kind, and all that kind of fun stuff, then um you can give him paper CUI or her, uh paper CUI, and uh it still needs to be protected. Uh DODI 5200.48 explains that. Uh but you don't necess the uh your CMMC level two uh requirements don't flow down to that contractor if it's paper CUI only. The very second that that contractor snaps a picture, scans it in, um, copies it, uh types it in, and draws a drawing of it and and you know makes it electronic somehow, they are now in scope. So if they can keep from doing anything that makes that CUI electronic uh or logical, then um as long as it stays physical and paper CUI, then they don't come in scope for all of the CMMC level two controls. Again, they still have to protect that paper CUI uh per DODI, DODI 5200.48, but they don't have to follow all the CMMC level two controls. That helps out uh a lot in in uh in some cases for contractors and whatnot, uh for construction companies especially. Uh the uh you know, some other things that were uh brought up are uh under the ESP umbrella, external service provider umbrella. So are you uh an ESP that's a CSP or are you an ESP that's not a CSP? That's the way they define that. So a CSP is a cloud service provider. That's gonna be like Microsoft 365, Google, AWS, um, and some others. Um anybody that um processes, stores, or transmits CUI in the cloud, uh, and that cloud is uh readily available, uh easily expandable, uh doesn't require interaction from the provider to expand it or purchase more or whatever. There's five requirements. Uh so if if you meet those requirements of a CSP, then you're gonna be a CSP. If you don't meet those requirements, you're just an ESP. So just an ESP. A uh ESP that's not a CSP includes we're gonna throw all sorts of TLAs at you, which is a TLA is a three-letter acronym. Uh so an ESP that's not a CSP uh could be things like a managed service provider or or an MSP or managed security services provider, uh SSP, um, things like that, right? Um any of those companies uh that provide service uh that may or may not typically don't process, store, or transmit COI, but could. Um and I just explained one of the caveats a minute ago with the backups. For instance, if you have an MSP, they're most likely going to be a security protection asset for you, and you'll need that CRM. Um the uh if they back up your CUI to their to their quote enclave, I'll just call it an enclave. Uh so if they back up your C their CUI to their enclave, that doesn't necessarily put them in scope as long as it's not in the cloud, as long as it doesn't fall under the CSP category, um, then they're still just uh an ASP, uh, but one that handles CUI. So if they do handle CUI in backups or anything like that, or a file sync and share program, then uh they're gonna have to have a level two certification. Uh if they don't have the uh if they don't handle CUI uh then if they don't process store transmit it, uh then they're they're they don't need a level two certification. It helps if they have one because that'll make a lot of things go a lot smoother. Uh but what you have to have from them uh is uh the CRMs we were talking about just a minute ago. You have to have a CRM that's based on NIST 800-171 uh and list out all the controls and who's responsible and uh preferably all of the assessment objectives. Because really, when you get assessed, an assessor will look at the assessment objectives to figure out if you meet that control. So there may be, you know, six assessment objectives that are part of one control. Might only be one assessment objective, but it could be could be six, could be even more. Uh and if you don't meet one of those assessment objectives, you fail a control. So if you list out per assessment objective and say who's responsible for what, that's the that's the best uh path forward there. Um but at the very least, you need to have a CRM uh based on the control NIST 800-171 controls, all 110, uh, that list out the customer responsibilities. So you have to have that. Um that's another thing uh that there uh that was worth some clarification. NIST 800-145 uh outlines the cloud computing criteria if you want to go look at it. And uh the also clarified that the DOW uh says that the FedRAMPS 20X uh will not work. So if you have a cloud program uh that was certified under the uh FedRAMP 20X and not uh previous program, it will not work. It has to be FedRAMP moderate authorized, uh FedRamp moderate or higher authorized or equivalency. And they did state that equivalency um is a DO uh is DOW uh there's a DOW definition for equivalency uh and that still holds. So ProVell, for instance, is uh is FedRamp uh equivalent, not authorized. Uh but they've been they've been thoroughly blessed by the uh by the DOD and and whoever did their uh whoever did their assessment. I can't remember who did their assessment off the top of my head. Um also worth noting uh that who knows what's going to happen with this CMMC pause. Uh but just before the CMMC pause, the DOW did say, hey, we're starting to plan for revision three. Which if things had gone along normally, I would say, you know, you're looking at probably two or three years uh before you have to worry about it, but you have to plan now. You have to start planning now because there are some changes, right? Right. It's gonna change your policies up, it's gonna change your SSP up, uh, it's gonna change how you do a few things, it's gonna bring some more things into scope. Um so there are fewer controls, but there are more assessment objectives. So it's arguably harder, arguably more uh intensive and more complex, I guess you should say. Um so there's more to it. Uh who knows where that's gonna go with this whole CMMC pause thing where they're trying to make things less complicated and less costly. Um, if you look at if you look at their brilliant at the basics program, you know, one, it doesn't really have any good definitions to it. It's just a marketing thing, really. Uh but if you look at that, uh one of the first things they one of the things they talk about is uh uh fishing resistant MFA. Well, in CMMC and NISTATERM 171, you have to have an MFA in place. It doesn't say fishing resistant. Now, I implore you to go ahead and please have some fishing resistant MFA in place. But that said, it is more complex. It is, you know, not as easy to put in as, you know, you may have to jump through some more hoops to make that work, or you may have to get rid of some old legacy program that meets all the controls, except it's not it doesn't have fishing resistant MFA, right? So, I mean they they list things out like that that arguably uh make it harder and more complex, and yet they're saying, you know, hey, uh, you know, we want to reduce uh cost and complexity, all right? And so uh it'll be very interesting to see what comes up. Uh I have waited and redone our uh response to the RFI. Uh and so I'll uh I think I'm gonna look over it one more time and then I'll probably probably submit it tonight. So um probably submit it before I leave work today, which is today is the 13th, so it's before the uh 14th deadline. Uh in any case, back to the questions, uh scoping clarifications to know. The only other thing worth noting that it doesn't really affect your scope right now, um, but uh the FARCUI rule, um they are uh the federal government is trying to standardize things. And uh so the FARCUI rule uh is uh a first stab at that. And so this whole CMMC pause may that may be part of it as well. Although I have a huge reservation about the numbers they use and the and the reason they use deposit. But could the CMMC program uh use some uh reworking? Yes, and we've said that from the get-go. There's several things in there. I would say the first thing that causes uh a lot of pain uh is uh the non-POAMable items. POAM is a plan of action of milestones. So you can't uh if you get assessed, uh you know, and you have some POAM items, great. You have six months to clear them up, wonderful. Uh except that there's five pointers and three-pointers, they can't be POAM'd. There's a few one-pointers that can't be POAM'd. So if you fail any of those, you just fail your assessment. It'd be nice if you could POAM any of those items and have six months or a year to clear them up. Um you know, there's there's several things that they could do to reduce the complexity cost and the and the burden on uh on companies. Although I will say that the DOD's been harping on this since 2017, before 2017, but the end of 2017, boom, you're supposed to be compliant with 80171 revision two, right? Or I guess revision one at the time. But anyway, you're supposed to be compliant with 800 171. They've talked about it and talked about it. The reason the certifications came along is because they realized companies were just not actually being compliant. They were going, yeah, we're good, you know, and uh not actually being good. So the change to revision three, um that could fall into this whole CMMC pause. Who knows? We'll see. But that'll be coming at some point.

Stacey

Aaron Ross Powell You kind of touched up on False Claims Act a little bit earlier, but has scoping specifically ever been the legal basis for a false claims act case?

Brooke

Aaron Powell Yes, it has for some. Uh so uh the most recent example, Log Zone, um, they didn't say anything about scoping really. Um uh although you know you could arguably say that it wasn't scoped properly and so they didn't implement all the controls, but that wasn't specifically said on that one. So again, we don't know all the gory details. Uh but I think it was a Georgia case, Georgia Tech case, uh, that they specifically said, I think they uh excluded uh lab uh the labs or something like that, uh, and said they weren't in scope when in fact they actually were in scope. So uh yes, scoping has been an issue in some of these uh some of these False Claims Act investigations and settlements. Um mind you all all of them that aren't actually in progress right now, all of them have been settled, not they haven't gone through to a court verdict or anything, so at least that I can think of. Um so uh which doesn't matter here or there, I guess, because if you settle it, you're still to some degree and yeah, and and spending m you know money on fines and whatnot. Uh so uh yes, scoping absolutely could lead to a false claims act, and so that's why you need to get it right. You know, if you over-scope, that's probably not going to get you a false claims act investigation. But if you underscope, it absolutely could lead to a false claims act, you know. Um, if you say, yeah, I've got this one little uh one little enclave here, and John Doe and Sally Joe, they they use it and they're the only ones in scope. There's two computers in there, uh, you know, there's a network in there that's all in scope, uh, you know, all that kind of fun stuff, and that's that's where our enclave is. But you continue to process information outside of that enclave and just not recognize it, you know, and somebody says, hey, we've got this problem here, you don't do anything about it, and that's when the whistleblower comes along. By the way, whistleblowers blowers are financially incentivized. They get 20% or something of the uh of the settlement. Uh so you know, if it's a million-dollar settlement, 200,000 bucks, boom, right in your pocket, right? Uh so that's an issue and something to be uh aware of. Um so uh you need to make sure you get scoping right. You don't need to underscope because it might get you in trouble, but you also don't need to over-scope and cost yourself more money. So you're walking that, you know, fine line.

Stacey

Yeah, that high line bar, that fine line.

Brooke

So uh so yes, that false claims act uh absolutely can uh can come about uh for underscoping.

Stacey

Aaron Ross Powell So you mentioned enclaves a bit earlier. Um for some it can be a fix for over scoping. Can that also cause some failures there too?

Brooke

Aaron Ross Powell Uh Yes, and I I kind of mentioned this a minute ago. Um, some people buy a CMMC in a box, you know, which is usually an enclave uh with you know their policy templates and SSP template and stuff like that. You just customize it and boom, you're good to go. Except that you're very well may not be good to go. So uh if you put one of those uh you know enclaves in place, you gotta make sure you're fully utilizing that enclave and that nothing is out uh happen no COI is being processed, stored, or transmitted outside of that enclave. You also have to make sure that um none of your S SPD is outside of that enclave unless you've documented it. If you've documented where your SPD comes from, like um maybe your Active Directory is on a domain controller outside your Enclave. You know, as long as you configure it properly, that can happen, you know. Uh but you've got to configure it properly, you've got to document it, and you've got to show what you do, right? Uh but all your CUI absolutely has to be in that enclave. If you're stating this is my enclave, that's where your CUI stays. It can't be processed, transmitted, or stored anywhere outside of that enclave. What we see uh with some uh clients that we have um um worked with is that they bought an enclave and uh weren't sure about it. And so we came into the picture and we looked and figured out that, oh, yeah, it's great that you got an enclave, but you've got all sorts of COI spillage outside this enclave. And so you're you're not gonna pass an assessment unless you lie. And uh I I would not suggest lying. So uh then we're talking about False Claims Act again, right? Um But yes, that's uh those enclaves can absolutely help, but you have to absolutely use them like they're supposed to be used.

Stacey

Aaron Powell So with all that being mentioned, um what does a defensible scope look like for a company that actually needs to do some protection there?

Brooke

Uh well, really the so your SSP is gonna uh tell your story, uh tell how you protect things, how you uh how you protect that CUI, um uh and where your SPA uh comes in, where your security protection assets come in. Uh and it's also gonna say, you know, what's out of scope, what's uh what's a specialized asset, um, you know, all that kind of fun stuff. What's a contractor risk managed asset? Uh so it's gonna define all of that. Your policies are gonna be, you know, thou shalt, thou shalt not, uh kind of thing. This is this is how we do things, this is what we require. Um uh you know, you're gonna have some procedures that go in there uh that shows how you do things step by step. Uh but without going that down that rabbit hole too much, your your uh SSP really is gonna tell your story. Uh your scope is gonna be included in there, whether it's an enclave or an enterprise-wide um uh setup, um, and how that how that boundary is defined, what's inside that boundary, what external systems connect to it, uh, all that kind of fun stuff. And that that defines your scope and your whole SSP is built around that. All those definitions, all those explanations of how all that works together, uh that's gonna that's gonna tell your story, and that's gonna be a defensible scope. That's very high level, there's a lot more to it than that. Uh, but yes, that SSP tells your story. Uh it defines your uh defines your boundaries, uh your external connections, uh, and everything else, right? Um and connects all your policies, procedures, your list, your configurations, all that kind of fun stuff. Connects all those. Uh so that's gonna be uh where all that is kind of defined at and where it's defensible.

Stacey

So, Brooke, if someone only remembers one thing from today's episode, what should it be?

Brooke

Scoping. I mean, I'm just we're talking about scoping. So uh, you know, uh I'd say the first thing always that's you can take it out of the scoping argument and say it's something on its own, which we kind of attack it as its own thing, but it's part of scoping uh anyway, is knowing what CUI you have, right? And what knowing where it's at. Uh so once you know what CUI you have and where it's at, then you can figure out how to scope properly. You know, where's all where is all of it uh, I was gonna say where does it live, but where is it processed, stored, and transmitted uh right now, and could you clean that up and and tighten up that scope, right? Could you create a uh an enclave and really tighten up that scope? So um determining uh where it is, determining uh determining what CUI you have, determining where it is or your data flow uh helps you draw a uh uh create a correct scope and um and decide whether you can uh you know tighten that down to an enclave or or what you need to do. So that is that's a that's the most critical thing is figuring out that scoping.

Stacey

If you have any questions about what we covered, reach out to us. We're here to help fast track your compliance journey. Text, email, or call in your questions, and we'll answer them for free here on the podcast. You can find our contact info at cmc compliance guide dot com. Stay tuned for our next episode. Until then, stay compliant, stay secure, and make sure to subscribe.