00:00:14 --> 00:00:22
Today's story is about how pharmacies with DoD contracts must now meet CMMC Level Two requirements for controlled unclassified information.
00:00:22 --> 00:00:34
Exactly. If a pharmacy receives or generates controlled unclassified information, or CUI, for a Department of Defense contract, the CMMC program applies.
00:00:34 --> 00:00:36
So it’s not just about HIPAA compliance anymore?
00:00:37 --> 00:00:47
Right. HIPAA protects electronic protected health information, or ePHI, but the DoD’s CUI program is a separate, independent set of rules.
00:00:47 --> 00:00:50
And that distinction matters because the rules are different?
00:00:50 --> 00:01:04
Yes. CUI requires all 110 controls of NIST SP 800-171 Revision 2, while FCI, or federal contract information, only needs 15 basic safeguards.
00:01:05 --> 00:01:10
Which means a pharmacy that handles only basic contract documents might be okay with Level One?
00:01:10 --> 00:01:21
Correct. Level One covers the 15 FAR 52-21 requirements, an annual self-assessment, and a senior official affirmation.
00:01:21 --> 00:01:27
But if the pharmacy processes prescription data that the DoD designates as CUI, they need Level Two.
00:01:28 --> 00:01:38
Exactly. Level Two demands every system that stores, processes, or transmits CUI must meet all 110 practices across 14 domains.
00:01:39 --> 00:01:41
What’s the timeline for these rules to take effect?
00:01:42 --> 00:01:59
The CMMC Program rule, 32 CFR Part 170, took effect on 2024-12-16, and the acquisition rule, DFARS 252-7021, started on 2025-11-10.
00:01:59 --> 00:02:02
So pharmacies have been under pressure for a while.
00:02:02 --> 00:02:14
Yes, and the DoD’s Town Hall in March 2026 reported 103 Certified CMMC Professional Organizations, or C3PAOs, ready to conduct assessments.
00:02:14 --> 00:02:17
How many pharmacies are actually doing Level Two right now?
00:02:18 --> 00:02:30
Level Two certifications grew from 773 in January 2026 to 1 in May 2026, showing rapid adoption.
00:02:30 --> 00:02:32
That’s a big jump in a short time.
00:02:32 --> 00:02:41
It reflects the expanding scope of DoD contracts and the requirement that a valid CMMC certificate be in place before award.
00:02:41 --> 00:02:45
So if a pharmacy doesn’t have that certificate, they’re out of the bidding process?
00:02:45 --> 00:02:59
Precisely. DFARS 252-7021 states a contractor must hold a valid CMMC certificate at the required level before award if the clause appears.
00:02:59 --> 00:03:03
What about the complexity of the controls? 110 sounds daunting.
00:03:03 --> 00:03:14
It can be, but enclaving CUI into a narrowly scoped boundary like a GCC High tenant or a dedicated cloud landing zone can reduce the scope dramatically.
00:03:14 --> 00:03:15
How does enclaving help?
00:03:16 --> 00:03:25
By isolating the CUI to a single environment, the 110 controls apply only to that enclave, not the entire enterprise network.
00:03:25 --> 00:03:30
So a pharmacy with a large retail footprint can keep most of its systems out of scope.
00:03:30 --> 00:03:40
Exactly. That’s why many independent pharmacies are moving their pharmacy management systems and EHR interfaces into a dedicated landing zone.
00:03:40 --> 00:03:42
What about encryption requirements?
00:03:42 --> 00:03:55
NIST SP 800-171 requires FIPS-validated cryptography to protect CUI. Using strong encryption that isn’t FIPS-validated is a common gap.
00:03:55 --> 00:03:59
So legacy systems that use older encryption might fail the assessment?
00:03:59 --> 00:04:05
Yes, especially if they rely on non-FIPS algorithms or custom implementations.
00:04:05 --> 00:04:08
Does the DoD accept any cloud provider as long as it’s secure?
00:04:09 --> 00:04:21
Encrypted CUI in a cloud still requires a FedRAMP Moderate baseline or equivalency. The DoD CIO FAQ clarifies that encryption does not remove CUI status.
00:04:21 --> 00:04:22
What about incident reporting?
00:04:23 --> 00:04:33
A cyber incident affecting covered defense information must be reported to the DoD within 72 hours via the DoD reporting portal at dibnet.dod.mil.
00:04:34 --> 00:04:37
That portal needs a DoD-approved medium assurance certificate, right?
00:04:38 --> 00:04:42
Correct. Without that certificate, you can’t submit the incident report.
00:04:42 --> 00:04:45
And after reporting, what else must the pharmacy do?
00:04:46 --> 00:04:57
They must preserve images of affected systems and monitoring data for at least 90 days, submit isolated malicious software to the government, and hold cloud providers to FedRAMP Moderate.
00:04:58 --> 00:04:59
That’s a lot of documentation.
00:05:00 --> 00:05:06
It is, and it requires a mature incident response plan that covers those specific requirements.
00:05:06 --> 00:05:09
Who is responsible for ensuring all this is in place?
00:05:09 --> 00:05:19
Typically a compliance officer or security lead, but the System Security Plan, or SSP, identifies owners for each of the 110 controls.
00:05:20 --> 00:05:21
What does the SSP contain?
00:05:22 --> 00:05:32
It lists every control, its owner, evidence pointers, and a status indicator. The SSP is a living document that must be updated as the environment changes.
00:05:32 --> 00:05:36
And the Plan of Action and Milestones, or POA&M?
00:05:36 --> 00:05:49
The POA&M tracks any 'not met' requirements, with a 180-day closeout deadline under 32 CFR 170.21. It must be reviewed at least quarterly.
00:05:49 --> 00:05:53
So the pharmacy must continuously monitor and update these documents.
00:05:53 --> 00:05:59
Exactly. CMMC compliance is not a one-time project but a continuous process.
00:05:59 --> 00:06:00
What about the assessment itself?
00:06:01 --> 00:06:10
Only a Certified CMMC Professional Organization, or C3PAO, can conduct the Level Two assessment and issue the certificate.
00:06:10 --> 00:06:13
So the pharmacy needs to hire a C3PAO.
00:06:13 --> 00:06:20
Yes, but first it needs a Registered Provider Organization, or RPO, to prepare the pharmacy for the assessment.
00:06:21 --> 00:06:24
What’s the difference between a C3PAO and an RPO?
00:06:24 --> 00:06:32
An RPO prepares the organization, but cannot perform the assessment or issue the certificate. The C3PAO does that.
00:06:33 --> 00:06:38
So the pharmacy would work with an RPO to get ready, then bring in a C3PAO for the final audit.
00:06:38 --> 00:06:45
That’s the typical path. The RPO will help with scoping, gap analysis, remediation, and mock assessments.
00:06:46 --> 00:06:48
How long does the whole readiness process take?
00:06:48 --> 00:06:56
From gap assessment to C3PAO-ready, it usually takes 6 to 18 months, depending on starting posture and complexity.
00:06:56 --> 00:06:58
And the actual assessment?
00:06:58 --> 00:07:10
The formal assessment itself can take a few weeks, but the preparation phase-discovery, gap analysis, remediation sprint, and readiness handoff-runs 12 to 14 weeks for a mid-size contractor.
00:07:11 --> 00:07:12
What about the cost?
00:07:12 --> 00:07:21
Costs vary widely, but enclaving CUI into a dedicated boundary can significantly reduce the audit surface and lower ongoing costs.
00:07:21 --> 00:07:23
So the size of the network matters.
00:07:24 --> 00:07:32
Yes. A large enterprise network that includes many non-CUI systems will see a higher scope and higher cost if all are in scope.
00:07:32 --> 00:07:35
How do pharmacies determine if their data is CUI?
00:07:36 --> 00:07:49
The designation comes from the designating agency, usually the DoD. 32 CFR 2002.16 allows only the designating agency to apply limited dissemination controls.
00:07:49 --> 00:07:54
So the pharmacy needs to map its information to determine what’s CUI and what’s not.
00:07:54 --> 00:08:00
Exactly. Information mapping is the first step in any CMMC pharmacy engagement.
00:08:00 --> 00:08:06
That involves looking at pharmacy management systems, EHR interfaces, and supply chain platforms.
00:08:06 --> 00:08:12
Yes, those are common places where CUI can reside when interacting with defense contractors.
00:08:12 --> 00:08:15
What about the CUI banner marking requirement?
00:08:15 --> 00:08:27
32 CFR 2002.20 requires a CUI banner on every page that contains CUI, along with a designation indicator naming the designating agency.
00:08:27 --> 00:08:30
And that’s separate from distribution statements?
00:08:30 --> 00:08:43
Correct. DoD Instruction 5230.24 governs distribution statements on technical documents, but those do not satisfy CUI marking requirements.
00:08:43 --> 00:08:45
So pharmacies need to be careful with both.
00:08:45 --> 00:08:49
Absolutely, they must apply both sets of markings in parallel.
00:08:49 --> 00:08:52
How many pharmacies are currently certified at Level Two?
00:08:52 --> 00:09:04
The number grew from 773 in January 2026 to 1 in May 2026, indicating rapid adoption of the program.
00:09:05 --> 00:09:07
That’s a huge increase in a few months.
00:09:07 --> 00:09:12
It reflects the expanding scope of DoD contracts and the urgency for compliance.
00:09:12 --> 00:09:15
Do we know how many C3PAOs are available for assessment?
00:09:16 --> 00:09:23
As of the March 2026 Town Hall, there were 103 C3PAOs listed on the Cyber AB marketplace.
00:09:23 --> 00:09:26
So pharmacies have options for assessment.
00:09:26 --> 00:09:32
Yes, but they need to choose a C3PAO that aligns with their specific environment and scope.
00:09:32 --> 00:09:35
What about the ongoing maintenance after certification?
00:09:35 --> 00:09:45
After certification, the SSP remains a living document, and the POA&M must be reviewed at least quarterly. Re-assessment occurs every three years.
00:09:46 --> 00:09:47
And the senior official affirmation?
00:09:48 --> 00:09:55
An annual senior official affirmation is required for Level Two, confirming that the controls remain in place.
00:09:55 --> 00:09:57
So the pharmacy must keep a rigorous record.
00:09:57 --> 00:10:06
Yes, including evidence of controls, incident response plans, acceptable use policies, media protection policies, and more.
00:10:06 --> 00:10:09
What happens if a pharmacy has a 'not met' requirement?
00:10:09 --> 00:10:22
They must submit a Plan of Action and Milestones, or POA&M, to address the gap within 180 days, as allowed by 32 CFR 170.21.
00:10:22 --> 00:10:24
That’s a tight deadline.
00:10:24 --> 00:10:29
It is, but it ensures that gaps are closed promptly and the pharmacy remains compliant.
00:10:30 --> 00:10:31
What about the incident response capacity?
00:10:32 --> 00:10:41
The pharmacy must have an incident response plan that covers reporting to DoD, preserving evidence, and coordinating with cloud providers.
00:10:41 --> 00:10:42
It sounds like a lot of work.
00:10:42 --> 00:10:57
It is, but the risk of non-compliance can be high. Recent settlements like Verizon’s $4.09 million fine in 2023 and Raytheon’s $8.4 million in 2025 illustrate the stakes.
00:10:57 --> 00:11:00
Those are civil fraud settlements, not just security breaches.
00:11:01 --> 00:11:07
Correct. They show that the government is actively pursuing entities that misrepresent their security posture.
00:11:07 --> 00:11:10
So honesty in self-assessment is critical.
00:11:10 --> 00:11:14
Exactly. A false self-assessment can lead to penalties and loss of contracts.
00:11:15 --> 00:11:19
What about the DFARS 252-7012 clause?
00:11:19 --> 00:11:30
It requires adequate security-defined as the 110 controls-on every covered contractor information system, and it must be flowed down to subcontractors.
00:11:30 --> 00:11:32
So subcontractors must also comply.
00:11:32 --> 00:11:38
Yes, they must report incidents to DoD and provide the report number to the next higher tier.
00:11:38 --> 00:11:40
That creates a chain of responsibility.
00:11:40 --> 00:11:46
It does. The DoD expects a mature incident response plan that extends to the supply chain.
00:11:47 --> 00:11:49
What about the timeline for the DoD CIO announcement?
00:11:50 --> 00:12:03
On 2026-07-13, the DoD CIO announced the suspension of the 2026-11-10 Phase II deadline, giving organizations a window to build their program correctly.
00:12:03 --> 00:12:05
So the pause is an opportunity.
00:12:05 --> 00:12:10
Yes, it allows pharmacies to avoid rushing and ensure they’re fully prepared.
00:12:10 --> 00:12:13
What’s the next step for a pharmacy that wants to get ready?
00:12:13 --> 00:12:23
They should start with a gap assessment, mapping their CUI, and then engage a Registered Provider Organization to prepare them for a C3PAO assessment.
00:12:23 --> 00:12:28
But before we dive into the practical steps, let’s talk about what organizations should do next.
00:12:28 --> 00:12:38
The first concrete move is to conduct a thorough gap assessment that maps every system that handles or could handle Controlled Unclassified Information.
00:12:38 --> 00:12:41
That sounds intensive-how do they actually map the data?
00:12:41 --> 00:12:52
You start with an inventory of pharmacy management systems, electronic health record interfaces, and any supply-chain platforms that exchange data with defense contractors.
00:12:52 --> 00:12:56
So the focus is on the systems that actually hold or move the CUI?
00:12:56 --> 00:13:05
Exactly. Once you know which boxes are in scope, you can limit the 110 NIST controls to those boundaries instead of the whole enterprise.
00:13:05 --> 00:13:07
That’s the enclaving concept, right?
00:13:08 --> 00:13:19
Yes. Enclaving CUI into a GCC High tenant or a dedicated cloud landing zone creates a narrowly scoped boundary that reduces audit surface and shortens timelines.
00:13:20 --> 00:13:24
That sounds like a big architectural shift. Do most pharmacies have the resources for that?
00:13:25 --> 00:13:38
In many cases, the cost of enclaving is offset by the lower number of systems that need to meet the 110 controls, which translates into faster certification and lower ongoing maintenance.
00:13:38 --> 00:13:43
That makes sense. What about the documentation side-like the System Security Plan?
00:13:43 --> 00:13:57
The SSP is a living document that must cover all 110 controls, assign owners, and point to evidence. It’s required by NIST 800-171 and the CMMC program.
00:13:57 --> 00:14:00
Who typically writes the SSP in a pharmacy setting?
00:14:00 --> 00:14:11
Usually a compliance officer or a dedicated security lead works with IT to compile the SSP, ensuring each control has a documented implementation and evidence.
00:14:11 --> 00:14:14
And the Plan of Action and Milestones-how does that fit in?
00:14:15 --> 00:14:26
The POA&M tracks gaps that are “not met” and sets a 180-day closeout. It must be reviewed at least quarterly and feeds into the next assessment cycle.
00:14:26 --> 00:14:30
That’s a lot of ongoing effort. How do they keep it current?
00:14:30 --> 00:14:43
The SSP and POA&M are living documents. After each change-new software, a policy update, or a discovered vulnerability-you update the relevant sections and re-validate the evidence.
00:14:43 --> 00:14:46
What about the actual assessment? When should they schedule that?
00:14:47 --> 00:14:58
You schedule a C3PAO assessment only after you’re ready-meaning you’ve completed the gap assessment, remediated critical gaps, and have a mock assessment that shows you’re close to compliance.
00:14:59 --> 00:15:01
And the mock assessment-how is that conducted?
00:15:01 --> 00:15:12
The mock uses the Cyber AB CMMC Assessment Process, which simulates a C3PAO review. It helps you identify remaining gaps before the formal assessment.
00:15:12 --> 00:15:16
That seems prudent. Are there any common mistakes that pharmacies make?
00:15:17 --> 00:15:27
A few stand out: ignoring scope, using non-FIPS cryptography, assuming encrypted CUI is exempt, and overlooking incident reporting timelines.
00:15:27 --> 00:15:32
Let’s unpack those. First, scope-what are the pitfalls there?
00:15:33 --> 00:15:45
Many think every system is in scope, but for Level 2 only systems that process, store, or transmit CUI need the 110 controls. Enclaving reduces that number drastically.
00:15:46 --> 00:15:49
And non-FIPS cryptography-why is that a problem?
00:15:49 --> 00:16:04
NIST 800-171 mandates FIPS-validated cryptography to protect CUI confidentiality. Strong encryption that isn’t FIPS-validated doesn’t meet the requirement, exposing data to risk.
00:16:04 --> 00:16:11
That’s a technical detail that could slip through. What about the assumption that encryption removes CUI status?
00:16:12 --> 00:16:22
The DoD CIO FAQ clarifies that encrypted CUI is still CUI. Even in a cloud, you must maintain FedRAMP Moderate or equivalent controls.
00:16:22 --> 00:16:27
Got it. Incident reporting seems critical. What are the exact timelines?
00:16:28 --> 00:16:41
A cyber incident affecting covered defense information must be reported to DoD within 72 hours of discovery via the DoD reporting portal, which requires a DoD-approved medium assurance certificate.
00:16:41 --> 00:16:43
Then what happens after the report?
00:16:43 --> 00:16:56
You must preserve images of affected systems and monitoring data for at least 90 days, submit isolated malicious software to the government, and hold your cloud provider to a FedRAMP Moderate baseline.
00:16:56 --> 00:17:00
That’s a lot of work. Are there any tools that help streamline this?
00:17:00 --> 00:17:12
Many organizations use the Cyber AB CMMC Assessment Process for mock reviews, and eMASS for tracking assessment results and storing certificates in SPRS.
00:17:12 --> 00:17:16
Speaking of SPRS, how does the self-assessment score work?
00:17:17 --> 00:17:30
The SPRS self-assessment ranges from minus 203 to 110, with controls weighted at 1, 3, or 5 points. You submit the score annually for a senior official affirmation.
00:17:30 --> 00:17:33
And the senior official affirmation-what does that entail?
00:17:34 --> 00:17:44
It’s a formal statement confirming that the organization meets the required controls. It’s required annually for both Level 1 and Level 2 certifications.
00:17:44 --> 00:17:48
The timeline for the DoD acquisition rule-what’s the key date we should remember?
00:17:49 --> 00:18:05
The DFARS 252-7021 clause became enforceable on 2025-11-10, meaning a valid CMMC certificate at the required level is mandatory before contract award if the clause appears.
00:18:06 --> 00:18:08
And the program rule-when did that go into effect?
00:18:09 --> 00:18:21
The 32 CFR Part 170 program rule took effect on 2024-12-16, establishing the formal CMMC framework and assessment methodology.
00:18:21 --> 00:18:31
That gives us a clear timeline: program rule in December 2024, acquisition rule in November 2025, and the Phase II deadline pause in July 2026.
00:18:32 --> 00:18:39
Correct. The pause gives pharmacies a window to build a solid compliance foundation rather than rush into the assessment.
00:18:39 --> 00:18:45
Let’s talk about the role of the Registered Provider Organization. How does that differ from a C3PAO?
00:18:46 --> 00:18:57
An RPO prepares you for the assessment-it creates the SSP, policies, and POA&M, and does a mock assessment. But it cannot conduct the assessment or issue a certificate.
00:18:58 --> 00:19:02
So the RPO is a prep partner, but the C3PAO is the certifier.
00:19:02 --> 00:19:15
Exactly. After you’re ready, you hand off the SSP and supporting evidence to a C3PAO, who then performs the formal assessment and submits the results to eMASS and SPRS.
00:19:16 --> 00:19:19
What about the number of C3PAOs-how many can pharmacies choose from?
00:19:20 --> 00:19:37
As of the March 2026 Town Hall, there were 103 authorized C3PAOs, and Level 2 certifications grew from 773 in January 2026 to 1 in May 2026.
00:19:37 --> 00:19:43
That’s a lot of growth. Does the number of C3PAOs affect the assessment process?
00:19:43 --> 00:19:55
The main consideration is that you need a C3PAO that’s experienced with pharmacy or healthcare environments, so you can reduce the number of questions about industry-specific controls.
00:19:55 --> 00:19:58
Let’s shift to the practical steps a pharmacy should take right now.
00:19:59 --> 00:20:09
First, conduct a gap assessment and inventory all systems that could handle CUI. Map the data flows and identify the narrowest boundary for enclaving.
00:20:09 --> 00:20:12
Then you need to write the SSP and policies, right?
00:20:12 --> 00:20:27
Yes, the SSP must cover all 110 controls, assign owners, and link to evidence. The policies include incident response, acceptable use, media protection, and the 14 control-family policies.
00:20:27 --> 00:20:30
And the incident response plan-what should it contain?
00:20:30 --> 00:20:41
It should outline roles, communication channels, escalation procedures, evidence preservation steps, and reporting obligations to DoD within 72 hours.
00:20:41 --> 00:20:45
After that, you’re ready for the mock assessment. How long does that usually take?
00:20:46 --> 00:20:57
A typical mock assessment using the Cyber AB process can be completed in a few days to a week, depending on the complexity of your environment and the completeness of your documentation.
00:20:57 --> 00:21:04
Once the mock shows you’re close, you hand over to a C3PAO. What should you do between the mock and the formal assessment?
00:21:05 --> 00:21:17
You refine any remaining gaps, update the POA&M, and ensure all evidence is ready. You also schedule the assessment and secure any necessary cloud or on-prem infrastructure approvals.
00:21:18 --> 00:21:21
How do they handle the actual certificate once the assessment is complete?
00:21:22 --> 00:21:34
The C3PAO submits the assessment results to eMASS, which then pushes the certificate into SPRS. The certificate is valid for three years, after which you need a reassessment.
00:21:35 --> 00:21:39
And after certification, what ongoing activities must a pharmacy maintain?
00:21:39 --> 00:21:54
You must keep the SSP and POA&M updated, conduct quarterly reviews, perform annual senior official affirmations, and be ready for a triennial reassessment. Incident response plans must be tested regularly.
00:21:54 --> 00:21:59
That’s a lot of continuous work. How can pharmacies make it manageable?
00:21:59 --> 00:22:14
Automation helps-use policy-management tools, automated evidence collection, and scheduled POA&M reminders. Also, consider a managed security service provider that can monitor for anomalies and support incident response.
00:22:15 --> 00:22:18
Are there any quick wins pharmacies can implement before the full assessment?
00:22:19 --> 00:22:34
Strengthen network segmentation, enforce FIPS-validated encryption on all storage devices, ensure all user accounts have multi-factor authentication, and apply the CUI banner marking on every page that contains CUI.
00:22:34 --> 00:22:37
How do they handle the CUI banner marking-what’s required?
00:22:38 --> 00:22:52
32 CFR 2002.20 requires a CUI banner on every page containing CUI and a designation indicator naming the designating agency. It’s a simple but essential compliance step.
00:22:53 --> 00:22:55
That’s a small detail that could be overlooked.
00:22:55 --> 00:23:02
Exactly. Small details can lead to big gaps, especially when the C3PAO is reviewing evidence.
00:23:02 --> 00:23:10
Let’s cover some frequently asked questions. One common question is whether a pharmacy can use a single C3PAO for multiple contracts.
00:23:11 --> 00:23:26
Absolutely. A single C3PAO can certify multiple contracts as long as each contract’s scope is defined and the evidence is specific to that contract. However, you must maintain separate SSPs if the systems differ.
00:23:26 --> 00:23:31
Another question is about the cost-how do pharmacies budget for CMMC compliance?
00:23:31 --> 00:23:48
Costs vary widely, but you should budget for an RPO engagement, a mock assessment, cloud or on-prem enclaving, ongoing POA&M maintenance, and the eventual C3PAO assessment fee. A phased approach can spread the expense over 12 to 18 months.
00:23:49 --> 00:23:52
That gives us a roadmap. Any final advice before we wrap up?
00:23:53 --> 00:24:11
Treat CMMC as a continuous program, not a one-time checkbox. Keep your SSP alive, review your POA&M quarterly, test your incident response, and stay informed about rule changes. That disciplined approach will keep your pharmacy ready for any contract.
00:24:11 --> 00:24:14
Thank you for your insights and practical guidance.