Episode 151
Listen to this episode on
Episode Transcript
Speaker 1 00:02
This is CyberSound, your simplified and fundamentals-focused source for all things cybersecurity.
Jason Pufahl 00:11
Welcome to CyberSound. I’m your host, Jason Pufahl, today joined by Mark Jennings, part of the Vancord team, and one of our resident experts on CMMC, which is our topic today.
Welcome, Mark.
Mark Jennings 00:24
Thank you. Welcome.
Jason Pufahl 00:25
So this feels a little bit like here we are again, July 13th. We had basically a rollback of CMMC requirements where that looming assessment date was put on pause. And so everybody who had been planning for assessments with the C3PAOs that are out there, I guess the positives, I will say, h…
Speaker 1 00:02
This is CyberSound, your simplified and fundamentals-focused source for all things cybersecurity.
Jason Pufahl 00:11
Welcome to CyberSound. I’m your host, Jason Pufahl, today joined by Mark Jennings, part of the Vancord team, and one of our resident experts on CMMC, which is our topic today.
Welcome, Mark.
Mark Jennings 00:24
Thank you. Welcome.
Jason Pufahl 00:25
So this feels a little bit like here we are again, July 13th. We had basically a rollback of CMMC requirements where that looming assessment date was put on pause. And so everybody who had been planning for assessments with the C3PAOs that are out there, I guess the positives, I will say, have a reprieve because they have an opportunity maybe to make sure they’re more fully prepared. But I’d love, if you wouldn’t mind, to spend a minute on what are the obligations for CMMC? And really, what does this assessment mean to people a little bit?
Mark Jennings 01:05
Sure, sure. Yeah. And just to level set, what is being paused is the requirement to be fully CMMC Level 2 certified by November 10th, if it shows up in your contract.
So that’s the key thing, is that the November 10th date was the date that supposedly all new DOD contracts were going to require full Level 2 certification in order to date on the contract or accept the contract. That’s the thing that’s been paused, and it’s been paused for 60 days so that they can review the program and does it make sense. A lot of the concerns that have been thrown out there have been that for the SMB market, it’s very difficult that they’re seeing manufacturers pull out of the market completely saying, look, we just don’t even want to play this game.
There’s not enough money in it, etc. So that’s really the landscape that we have today, is it’s been paused. So what do we do now?
Jason Pufahl 02:06
But not necessarily stopped, right? Because their language is, we know that things are going to move forward, but how does it look? I think is a little bit a question.
Mark Jennings 02:15
Correct. So there’s nothing that’s changed at this point. Everything still stays in place. They’re just pausing everything, which really we don’t even know what that means.
What’s going to come out at the end of this? What we do know, though, is that the underlying requirements that CMMC is there to certify are still there. If you do business with the DOD, more than likely, there is a clause, the DFARS clause 252.204-7012, that has been around for 10 years. It’s in there. That is the requirement that you meet the NIST 800-71 controls. There’s a lot of acronyms and numbers in there, but that’s the meat and potatoes of this, is that you have to meet these controls if you accept these contracts.
Originally, it was on your word. Then it became, you had to post a score. It specifically said which ones you met, which ones you didn’t. And now this certification is a third party comes in and assesses you. That’s the big change. That’s what CMMC is all about. CMMC has nothing to do other than the fact that it’s a certification of the fact that you’re meeting the controls.
Jason Pufahl 03:29
Right. That you previously have self-assessed against.
Mark Jennings 03:32
Correct. And phase one is already in place where if your contract says that you have to self-assess and attest to the fact that you are meeting CMMC or level 800-171 controls, that’s already in place.
Jason Pufahl 03:51
None of that’s changing, ultimately.
Mark Jennings 03:53
Exactly. That’s still in place. The underlying controls are still in place. You still have all these obligations. The DIBCAC, which is the DOD assessment organization itself, can knock on your door any time and say, I want to review your practices to make sure that you’re following NIST 800-171. And if you’re not, and if you posted a score in SPRS, which is how you’ve assessed how well you’re doing, that is incorrect, you’re in violation of the False Claims Act, which can have penalties up to three times the amount of the contract that you’ve been awarded. So all of these things still are there. Don’t take any comfort in the fact that this program has been paused.
Jason Pufahl 04:36
Well, and I think the positive, right, so they released an RFI where they’re actually now seeking feedback from the defense industrial base on what’s worked, what would they like to see changed. And I think they’re looking at how do we actually make this work a little bit better maybe for that SMB market that you referred to. At least that’s my interpretation of it. I don’t know if you have a different line of thinking or if your outtake from that is different than mine.
Mark Jennings 05:01
Yeah, I mean, they absolutely in their announcement said the reason they’re pausing this is because of the SMB market. The Small Business Administration had a lot to do. They were pushing hard against this because in reality, there are some small manufacturers that have pulled out of the market. They’ve said, look, we just don’t want to be in this business anymore. There’s not enough money in it, whatever happens to be the case. And I’ve done some assessments for some like micro businesses that they don’t make sense.
I mean, it’s almost embarrassing to be asking them, do you do this? It’s like, why would a company that small put all these things? There’s independents out there, sole proprietors that have to meet these and they just go too far. So I don’t argue the fact that there needs to be some sort of accommodation for, I’d say the micro small business. If you’re 20, 25 employees or more, you should be doing this stuff. I mean, it makes sense.
So there’s a segment of the population, yes, needs to be simplified. But overall, it’s not a heavy lift for most organizations of, again, 20 employees or whatever.
Jason Pufahl 06:13
And honestly, the conversation I’ve had with the sort of companies in general, especially as some of the questions have arisen now as a result of this pause, has been most of these controls are controls that you would want to implement regardless of whether or not you had regulatory obligations. So you want MFA, you want better password practices, you want to train your employees. There are some really high outcome, reasonable controls that every business should do no matter what. And if you haven’t put those in place already, then that’s a great place, frankly, for anybody who hasn’t put the effort in yet to focus on. And then as the obligations become a little bit more clear, I think that maybe you can invest a little bit more. But these were laid out pretty practically for most businesses. And I think they’re just trying to make it a little bit more practical, even for all businesses.
Mark Jennings 07:09
Yeah. And as I said, I don’t argue the fact that there is a segment of the business community that needs probably some relief from some of this stuff. But the way that they’ve gone about it just by, we’re going to do a pause for 60 days, just leaves everybody in the scratching their head mode of, what do I do now?
My recommendation is full steam ahead. You may decide to pause your assessment dates or push your assessment dates. I probably would be looking at that if I were an organization, but I would not pause at all my preparation for these controls. Make sure that whether you do a self-assessment or have a third party do a gap assessment, keep going because you’re not going to buy yourself any time through this if you just pause everything.
Jason Pufahl 08:02
Yeah. I mean, honestly, this is an opportunity for any organization that wasn’t prepared for November to get prepared. And I think that’s how people should be looking at it. And for me to speculate a little bit, I could envision a slightly reduced set of requirements, maybe for the SMB market, but they’re certainly not going to remove CMMC as an obligation.
Mark Jennings 08:27
No. I mean, it’s in law. I mean, CMMC is a law. So I don’t think, I’m not a lawyer and I’m not a lawmaker. However, I don’t think the Pentagon can just say, we’re doing away with CMMC.
Jason Pufahl 08:42
We’re done with this.
Mark Jennings 08:43
It’s going to take literally an act of Congress to do that. So I think there’s comfort in that in the sense that whatever investments you’ve made so far are not just going to go up in smoke. But I agree. I think they did release this thing they called a brilliant at the basics campaign, which is a quasi framework, kind of vague. These are the top 10 things you want to do in IT. These are the top 10 things you want to do in OT.
But it’s nothing you can follow, nothing you can draw any kind of a conclusion as to whether or not you’re meeting that standard, because it’s not really much of a standard. And a lot of those things are going to be just as cumbersome to a small business as NIST 800-171 is. And that, again, just throws more confusion. It’s like, well, where are you going with this? So like I said, the bottom line is I don’t think this changes really anything other than do you go forward with a C3PAO audit next week or whatever.
Jason Pufahl 09:51
Yeah. It just changes that timeline.
Mark Jennings 09:53
Yeah. So we’ll be keeping an eye on it and making sure that whatever does come out of it makes sense.
Jason Pufahl 10:01
Yeah. Yeah. I mean, I think that feels like we’re about to end, frankly, this little podcast, right? Because the reality is we’re in the same boat as everybody, which is we know where we are today. We know what the obligations are to date for everybody. We’ll see what the RFI produces in 60 days.
We’ll hopefully get some more information at which time we’ll come back on and probably talk about that a little bit more. But it really is, it’s business as usual in a lot of ways, maybe with a little bit of a buffer now in terms of that assessment obligation and nothing else really changes.
Mark Jennings 10:35
Yeah. I mean, the good news is I haven’t had any clients cancel, say we’re just going to drop on the whole thing. I mean, everybody, there might have been, okay, we might want to slow down a little bit just because it’s a lot of pressure, but nobody’s stopping, which is good.
Jason Pufahl 10:50
Yeah. And frankly, when this was first announced, I was concerned that might be a reaction, but largely that hasn’t been the case.
Mark Jennings 10:58
Yeah. Yeah.
Jason Pufahl 10:58
Good. Well, on that note, I think the good spot to stop, we’ll come back when we know more information and depending on what it is, we’ll try to add some, hopefully some clarity and perspective to it. In the interim, if anybody does have questions, we do a lot of CMMC work. We are RPOs. We generally do a lot of the assessments, sort of the pre-assessments and all that remediation work. Happy to have a conversation and add whatever clarity we can.
And if you’ve got questions, just reach out because we’re happy to chat. And Mark, thanks for taking a few minutes and sharing your perspective on this.
Mark Jennings 11:32
Happy anytime Jason. Thanks.
Jason Pufahl 11:34
All right. Thanks. Bye.
Mark Jennings 11:35
Great. Thank you.
Speaker 1 11:37
We’d love to hear your feedback. Feel free to get in touch at Vancord on LinkedIn, and remember, stay vigilant, stay resilient. This has been CyberSound.


































































































