The final Cyber AB TH of 2025 took place this week which means it’s time for the team to unpack all the important information you need to know. On this week’s show, Jason and Joy sit down for one one last time in 2025 as we discuss things like: •The final ecosystem update of 2025 •The biggest highlights of 2025 •DO I have to affirm my C3PAO assessment score? •What the AB expects for 2026 Tune in as we close out this year of Cyber AB Town Halls with a little fun!
The final Cyber AB TH of 2025 took place this week which means it’s time for the team to unpack all the important information you need to know. On this week’s show, Jason and Joy sit down for one one last time in 2025 as we discuss things like: •The final ecosystem update of 2025 •The biggest highlights of 2025 •DO I have to affirm my C3PAO assessment score? •What the AB expects for 2026 Tune in as we close out this year of Cyber AB Town Halls with a little fun!
Transcript
[Music]
Joy, we’re here and we’re here for one last time in 2025. We’re saying goodbye to the year of CMMC. I think it it’s safe to say that we can label it that, right? The year that it became a thing. And the way that we are saying goodbye to it is with our last CyberA town hall recap of 2025. Don’t be sad. I I understand. I’m sad. But I will say 2025 feels like a year of champions to me. It was exciting to see all these numbers and and and I’m excited to dig into it.
Yeah, I think it was a year of growth and like I said, I think we could amply name it the the year of CMMC and confidently say that that it kind of fits there that the program came to life. um organizations got assessed and certified growth of an ecosystem and then a plan moving forward and they talked about all that in the town hall and that plan starts with obviously CMMC Phase 1 is here!
title 48 now being in enforce right in effect November 10th was the big day it’s finally here and uh it means just a couple of things and these things were relayed to us uh most importantly right year one of the CMMC phased implementation is underway way. And some people may think of that to be uh most expected to be self attestation of level one or level two is the only thing that’s going to be required of them.
Um between now and the 9th of November of next year, 9th November 2026, that’s the date for phase one. But Joy, we’re already seeing and they kind of alluded to it that the DO has discretion, DO, Department of War, has discretion to apply these requirements to CMMC contracts and solicitations well before the intended phased period.
So, uh, while I say it’s in force and while they say, you know, this is what the DO says to expect, um, I think we’re seeing differently. What do you think?
Absolutely. I think the word discretion has a lot of power in it. Um I I think that it’s been made clear from the start that they’re really taking this seriously and the CTI category um of CUI is something that people are not understanding the sensitivity that the Department of War places on that.
So, we’ll we’ll see how it actually pans out, but we are seeing the early indicators for sure that a C3PIO certification is going to be out there in 2026.
And not to argue your point at all, right? Like I I think I I 100% agree with you like that that’s one of the the driving factors, right? That the CTI data and what data is attached to it and the evaluation of risk uh as far as the contract goes.
But I think there’s another little evaluation of risk that’s there and it’s in the supply chain, right? The evaluation of risk of saying that this is going to take a long time to get there and we’re expecting this to happen within that time period.
We kind of want to jump start it now, right? We’ve seen that this has been neglected for a long time or we’ve seen that people really haven’t been aware as aware of this as they probably should have been for a long time and this is now what’s going to happen.
you’re going to see more proactivity and I think that that is going to be the word for the first phase of uh the CMMC implementation is proactivity and I think it’s going to be on part of primes and on the part of the DoD and I don’t think there’s very many people that can argue that.
I totally agree. Uh, I just wish the primes hadn’t waited so long to indicate what their position is going to be because they had years years to start laying that on to their supply chain. And the fact that they, you know, in the last 12 months, maybe six months is when we’ve really seen it. It’s like, what were you waiting for?
Yeah. I don’t understand the motivation behind that. Um, you know, obviously there’s been conversations and I know I’ve said it on the air. and Jacob said it on the air and many people have alluded to that the conversations are happening and or just because we can’t see them doesn’t mean the conversations are not happening.
I just think that they’re publicly happening now and I think that that’s one of those things that you get that sent out in the air and everybody’s now sniffing it and they want they want a piece of it. So that’s a good point.
Um another thing uh that we were brought up to speed on is uh there’s been a change New Cyber AB Board Appointments in the board of directors or because of the elections, right? board of directors only sit for a certain amount of time and either they need to come up for reelection or whatever and the cyber is no different.
Um this year’s elections happened and there are new board of directors and these are the people that basically tell Matt Travis and all the other people at the AB what they should be doing to carry out the mission of the cyber AB, right?
And so Paul Michaels who was elected the chair of the cyber AB board last year reelected uh for a second year in a row. So congratulations to you.
Um Debbie Taylor Moore was last year’s secretary and has now moved into the vice chair position. So elevation, congratulations for the hard work. And then Kathy Hennessy joins and takes over as the secretary.
And then a name that is a little familiar to us. We’re huge fans. Wayne Boline uh has been named the exam at large.
Yeah. Mr. Yes. No. And that’s it. And I think that’s what his job is, right? The all the yes and nos, right? When it comes down to it, he’s the atlarge member of the board that’s going to come in and provide the input.
Um, so congratulations to all of them. Starting a new year, new cycle of the cybby program and realistically the first board of directors of the active uh CMMC program. Active. Yeah, it’s a big responsibility.
Well, let’s talk about some more big responsibilities. There were some Work plans for C3PAO Advisory Council subcommittees and committees that were named, right? The C3PO Advisory Council.
Um, one of the things that we were brought up to speed on on last night’s town hall or this week’s town hall, um, is that, uh, essentially, uh, there is a work plan for each of these committees because these committees serve at the discretion of, uh, the cyber AB, right?
And so the cyber AB then says, hey, you’re here to advise us, but these are the specific topics, so you can focus on those. And we got a list of some of the immediate topics that these newly formed committees are going to address.
Um and so just covering them kind of like in and quick and maybe touching on some of the things that we feel like okay about time we’re we’re going to get on that. Right.
So um the accreditation committee is is one of the first committees and uh this committee is focused on the accreditation process and how things go through that.
Um and so the two things that they are immediately going to be focusing on joy are the C3PO accreditation scheme how we’re doing that. I don’t know if you remember but uh just last year there was an audit uh that was conducted uh on the cyber B as to this uh accreditation scheme.
So now that there’s a committee that’s going to make sure that we are going through we’re evaluating it we’re improving it and making sure things are good. I I think two thumbs up for that.
And then another not necessarily I think it’s urgent for people wanting to display their pride of being certified but the OSC certification emblems now fall under the accreditation committee. So, coming soon from the accreditation committee near you, maybe an emblem for you to represent your CMMC level too, right?
Finally. That’s going to be great. I I I know I I kind of played it down like it wasn’t that big of a deal, but like I I can tell you that when in reading the Q&As’s for for the monthly town halls, you see the emblem mentioned quite a few times, almost as much as tier three screening. So, uh they’re they’re trending both upward. Right.
One of the other committees that that serves at the discretion of the AB is the assessment guidance committee. So this committee uh as the name formulates or as the name indicates uh is uh designed to help with assessment guidance to to clear out any issues of uh interpretations and things like that.
And so what they’re going to be focusing on here in this initial uh onset joy is on premise assessment requirements, sampling of controls, pauses and assessments. I think these are called false starts. It it might be I I don’t know though.
Significant change to information systems guys. I know a close friend of mine who may have recently posted something uh in relation to significant change and I know a very loudmouth podcast hype man for a couple of months who on his wish list was just like some clarification on some significant change from the cyber AB.
Looks like that clarification is coming and it’s just not coming from one point of contact. It’s coming from the committee that’s going to advise the AB. So that’s interesting.
We we know that there’s a FAQ that the DOW will be issuing um on an FAQ on from the DO. I’m losing track of all of my acronyms.
Um but yeah on significant change guidance and then what will be interesting to me is what the assessment guidance committee comes up in what their take on it is and how much of that will influence the DOW to maybe update or modify their FAQ.
So I’m they really listen and hear the input that that I think that’s very vital because you formulated this committee and this committee is supposed to provide that input to you and whether you act on that input and that recommendation is still at the discretion of the DO at the discretion of the library how it carries forward.
So it would be interesting to see if any of those uh significant change FAQ information that comes out uh is disputed by this committee and recommendations are sent upward for change and if that significantly changes that FAQ. My guess is it will be yeah that they’re not going to match up really closely at all but we’ll see. We’ll see.
Another thing is and maybe you can help me with this. The assessment guidance committee is going to be uh providing more guidance on uh the interview examination and test methodology that when it comes to assessments.
I I uh because you can’t find that information in the assessment guide, Jason. But but what I I I don’t know if is there things that necessarily need update. I’m not I’m not I I can’t even say it. I’m I’m at a loss for words here, right?
like I I can’t even begin to think and maybe that’s why I’m not on the assessment guidance committee, right?
Um I can’t even begin to think of things that are needed to update the the interview examination and test methodology unless there are errors like or there are issues where maybe uh interpretation can be affected or maybe there are elements within the assessment guidance that list things that necessarily aren’t relevant for that particular control or or something like that. I I don’t know. I don’t know.
I really It did surprise me to see that on there and then I thought to myself, I wonder if they’re experiencing a lot of push back from like consultants or OSC’s on things that are being presented, whether it’s a document or spoken to in an interview where they really are challenging the assessor point of view on it.
And so they want to get some more, you know, um some guidelines out there for what does or doesn’t qualify. I I imagine that’s it.
But there’s a lot of um examples in the actual assessment guide and all of the assessors in the CCP and CCA classes are talked through examples of all of it. So it was interesting to see it.
Yeah. I what we see here just by the list that we’ve been given of the priorities and we still have two more committees to go is that um from my perspective and obviously I get to see a lot of what industry and ecosystem says right like on social media whatever it may be these are all things with the ex exception of the interview examination and test I don’t think I’ve ever seen anybody say hey we need to reevaluate the interview examination and test.
But as far as sampling as far as on-prem assessment requirements these are all talking trouble points points. So it’s nice and it’s refreshing to see that the immediate things that they are addressing are all things that the ecosystem are buzzing about as to hey help us figure this out a little bit better.
So from my totally totally agree with something else and uh figuring out and understanding something else something better a CSP not an ESP MSP op whatever it may be right the external services subcommittee is now uh tasked with addressing that.
So the external services um subcommittee is going to be not only tasked with CSP versus MSP determination guidance, right? What is that line of delineation? What can we put as a hard line in the sand and recommend up uh the Fed ramp moderate equivalency which is buzzing?
Um obviously with new fed ramp requirements coming and some conflict with that I I think that there’s going to be some conversation there.
And then this one um which I I do agree with there not all customer responsibility matrix are created equal and if one of them is hasn’t been created well it’s going to be very troublesome on your assessment outcome right.
And so uh the external service providers are going to go with assessment guidance um what necessarily needs to be in the CRM and what the assessors need to look for and the subcommittee is going to recommend that up.
What does a good SRM look like? what needs to be included in that and how should you evaluate to tell if this is telling the truth or not.
So critical that that is squared away. Um I think that many of the C3PAOs and MSPs, MSSPS um have very different versions of what qualifies as a shared responsibility matrix.
I’m sure if I was a contractor out there shopping for a new MSP, I would have no idea what is a good or a bad SRM that I would be looking at by, you know, if I’m the prospect out there.
So, I think it’s going to be great and that that kind of information is really going to help inform the CAP committee, which is the next one.
Um, and because I think that’s crucial, a crucial part of the CAP document is, you know, we have one paragraph right now about a lower level of effort or a lower burden of effort if the MSP MSSP already has their own CMMC level two certification.
um the quality of that customer responsibility matrix is also going to inform the depth that you go into I would imagine when you’re doing the assessment of the OSC who’s using that MSP.
So the CAP is going to need to give a lot more guidance and I think that those two committees are going to have to work together a bit to make sure they’re coming to a common language for the CAP.
Yeah. And that’s the the first cat crafted cap. Remember that right? CAT crafted crap. It’s and it’s going to have a cover to cover review from the from the CAP committee and uh yeah, perspective annexes or appendixes into the cap.
I listen um the CAP came out the new version of the CAP came out three years ago now. Three, maybe. Maybe. No, I thought that it was updated with the final rule with 32. You’re I believe cap 2.0. Yeah, cap 2.0. and C CPC 2.0.
So two years from CFR uh from title 32 part 170 the cap. Well so now there obviously are changes to the program. There obviously are changes to FAQs. There obviously are a lot of things that have evolved since that cap has been updated the last time.
And then it’s one of those documents I think that needs to be in a constant uh you know revision re cycle.
So, um, it’s good to see that there’s a committee that that now is going to cover that and kind of kind of press on the gas and make sure that keeps happening.
I I don’t think I would let that happen, but what do I know, right?
Um, so that was the work plan. So, that’s the work plan moving forward for next year just for the advisory council.
2025 CMMC Year in Review: Cyber AB edition
Um, but we don’t want to get too far ahead into next year without reflecting back on kind of where we’ve come in 2025, which at the top of the show, the year of CMMC, I think is it’s safe to say that um there was a lot accomplished here that really formed the program within this year, a lot of changes.
And uh I’m just going to go through a couple that I think people don’t realize. Like when they were reading them off, I was like, man, that felt like so long ago. But no, that that actually was this year, you know, that was in December of this year, like when 32 CFR entered force, right?
Like it entered into effect December 10th of of No, last year, right? And then January 1st is when assessment started, remember, because they paused it for like three weeks. So within a full year.
So yeah, within a full year. And then had I known that this uh slide contained this, maybe if I did a little read ahead, we would have avoided some of the conversation because within this year they published the cap and the COPC updates.
So it hasn’t been two years. It hasn’t been three years happened this year. Like like I said, like I didn’t even realize it happened this year. I thought it happened so long ago. You know, time flies when you’re having fun.
So here we are. Another big thing that happened and that was a part of one of the audits and one of the you know um the investigations that took place was the reertification of all CCAs and CCPs because of 32 CFR going into force and new requirements being attached to them.
They had to go through and make sure that all of the uh CCAs and CCPs that were certified at that point in time when the rule went into force now meet all of these new requirements that are laid out within that rule.
So uh they did all of that and as you know that’s a lot of people joy.
Um they also reauthorized all the C3PAOS going through that process commenced we started issuing at the first of the year CMMC level two certifications we want to talk about the FARC UI rule coming out of dormcy right like it exists it’s there but realistically like it’s there and it exists we don’t know when it’s coming but we should be cognizant of it.
um CS5 uh launched as the the conference series that contains multiple elements of uh cloud conformity, compliance, uh frameworks.
I I don’t even know all of the acronyms, but it’s everything that encompasses this industry and this ecosystem, right?
Everything that the ecosystem stands for now all fits into one conference that is uh obviously headlined by the cyber AB.
And then last but not least, we just came out of this joy. And I don’t know um if I have any complaints about how prepared the program was because the program thrived and we’re going to talk about it in the numbers uh later on, but we endured the government shutdown, right?
The CMC program had the government shutdown from it. Not only did it endure it, as we go into um the reflection of the CMC year in review and the numbers, which is what we’re going to talk about now.
Yeah. um you’ll see that it it it thrived. The ecosystem is there. It’s in a good spot. This is all before the program even started.
Um but let’s talk about it, Joy.
Yeah, it was impressive that they kept on rolling. We kept on rolling during the government shutdown and we have some big numbers in one year.
Really happy to see this one-year growth of assessors 100%. Right.
that like no matter what the number is the growth there we ended in November 25 and I doubt we’ll get any of these ecosystem updates until our next show in 2026 right so I’m excited to see how far they grow just between now and then because the ecosystem is kind of humming.
uh the shutdown did delay some of those certified professionals and certified assessors getting their final stamp of approvals some authorized C3POs going through the process the final stages of the process so these numbers are going to grow between now and then but in 2025 alone loan, 1006 uh% growth in CCAs, uh 52% growth in the amount of authorized C3PAOs we have, and then uh 21% growth in certified professionals.
Right? Doesn’t sound like a lot, but when you get into the numbers that we were already at, right? We were at a thousand in the beginning of November 2024. Now we’re a little bit over 1,200.
Um and then the biggest growth, 384% not listed here of lead CCAs because lead CCAs were implemented. We didn’t have any last year. We have 384 of them now.
That’s 384 people that are capable of leading assessment teams. That means if there were three people that wanted to go along with them, that’s 384 assessments that could happen a week. Sounds good to me. Very powerful. Very exciting.
It’s over 1,200 a month. That’s a good start. Program just started. Yeah. In case you forgot.
So now one number that we didn’t get in the year and review is because that number was um reserved for the special guest Dana Mason who joined from the CMC PMO.
We’re going to get into that um right before we uh right after we talk about the look ahead what the AB looks to do in 2026 or what they expect to happen in 2026.
Right. So, we talked about the biggest growth in 2025 being the assessors.
What to expect from the AB in 2026
and we talked about what they want to happen in 2026. And essentially, this is their goals, new leadership in the KO.
Mike Snder was commended for filling in um on short-term and interim basis, but as Matt Travis stated, they have larger plans for Mike Snyder and Mike Snder will be doing bigger and greater things eventually as new KO leadership has emerged or emerges, right?
um they intend to expand. So, we talked about on last month’s show how some people join the AB team and they’re going to grow some more.
The program’s running, assessments are happening. Now, it makes sense to staff out this program to have people dedicated in certain spots.
I I think people overlook the fact the little amount of people that were staffing the CyberA through the onset uh of the program getting off of its feet and stuff like that, how many hats those people had to wear.
It’s almost poetic because it’s kind of like a DB contractor, right? A small DIB contractor trying to wear all of these hats for their CMMC compliance.
Well, they’re wearing all these hats so that we can have CMC compliance. Kind of crazy. Hats off to them. I’m glad they’re getting some help and they’re expanding. Me, too.
Practitioner programs going to be overhauled and now I know that we’ve made complaints about the RPOS’s, maybe the level, the length of the training, maybe uh clarity as into exactly what role they’re supposed to play or what they can do.
Um so we’re expecting an overhaul of that in 2026.
Um I ISO um 17,01 um recognition and their C3PO accreditation program. Obviously that’s one of the necessary steps that they have to take. Rules finalized. The clock’s ticking. That needs to happen.
Um some more engagement initiatives that they are going to announce in the upcoming months.
Uh survey to improve the quality of town hall ecosystem.
Uh so so a survey of the ecosystem to improve town hall quality.
Um, and then, uh, the expansion, we talked about CS5, uh, finally turning into this event that encompasses everything the ecosystem represents.
And so, the only thing that you can do is once you get to that point is to grow it and make it better. And they have intentions of doing that in 2026.
And then 2026 is going to introduce to us uh on November 10th, 2026 to be exact. Just a guess. I don’t know, maybe there’s something there.
But uh phase two of the implementation which is where organizations realistically should expect from do or sorry not realistically should expect but where the DoD states within documentation that organizations should expect C3PO assessments to be the normaly right.
so um we know that that’s going to happen way before then.
what on this list most excites you July overhauled practitioner program
why did I you saw a reflection of that in the Q&A some of the well comments more than questions I guess about the quality of consulting that’s happening and um you know it was it’s kind of sad to know that there are I hear of many organizations seeking some kind of you know like can we capture some of our money back is there any liability that this consultant is facing and giving us really bad guidance.
so I think that it’s um it’s something that should have been done in tandem with standing up the assessor ecosystem to make sure that the the quality of the consultant was equally as valuable and robust and even tested, right?
Not just, oh, uh, I took a six-hour pre-recorded course. I won’t go on about it anymore than I already have multiple times.
I’m very happy to know that they are going to focus on it. The sooner the better. I think it’s desperately important.
these companies, many of these small contractors, you know, uh they already are spending so much money trying to get ready just with the technical part of it.
And so when they’re hiring anybody to help them with it and they’re given the wrong advice, spending, you know, good money after bad, um we just don’t want to see it anymore.
Yeah, I think improved training is important for the reasons in which you mentioned, but let’s talk about the numbers, right?
We always say strengthen numbers and stuff like that. Right now, registered practitioners outnumber the total number of certified assessors and certified professionals in the or in the ecosystem. Right?
So, if they’re not going to take that next step and be the CCA or the CCP, let’s make sure that at whatever stage that they’re at, they’re trained to at least contribute to the effort because we just talked about being able to uh complete uh you know, multiple number of assessments in a week in order to meet the mission.
We just talked about staffing those teams that of those 384 lead assessors.
Well, if you can search down in the depths and find an RP at 198 or a CCCP at, you know, one of the 198 RPs or one of the,53 CCPs that can come in and serve on those assessments, then those lead assessors can staff more assessment teams.
but the training has to be there because if the training is not adequate, then what purpose and what help are they, you know, actually doing?
So that’s just my personal opinion, but I think um because they represent such a large number in the ecosystem of the positions that are recognized um let’s put them to work and let’s make sure that the work that they’re doing is quality.
And the only way that you do that is you train them up so they can perform both, right? Yep.
All right. So we talked about the numbers. We talked about what’s coming in 26. We talked about what happened in 25.
uh Dana Mason uh they they didn’t give us some numbers that we particularly look for Joy uh those CMMC certification assessment numbers because those were delivered by Dana Mason an IT specialist with the CMMC PMO’s office.
Program Update from PMO
she joined the town hall sand slides let’s try not to make that a habit um and speed read through all the statistics that are really really important to us.
so it’s basically you took my favorite part of the town hall AB and you put it in 2x so I had to like shorting and type to keep up. Thanks for the help.
But let’s let’s get here.
Um, all right. So, we are going to talk about uh in particular, first thing, the number of uh CMMC uh level one selfassessments that are in SPS as of reported by Dana Mason as of this week’s AV town hall.
7,047 companies have level one self- assessment.
While I commend that number, um I don’t think that that’s all the dip. It’s a teeny drop in the bucket. A teeny tiny drop in the bucket. That’s crazy.
Yeah. Now, the crazier part of it is during that government shutdown that we just endured, a thousand of those were completed.
So, they a thousand SPS level one self assessments were uploaded in SPS during the government shutdown.
People were busier during the go. We’re going to talk some more. people didn’t take the government shutdown off like we thought. Mhm.
Like and two, um I’m also remembering now that the SPRS system wasn’t adjusted to accommodate a level one self assessment until just what, like two or three months ago.
So, it could be that that’s contributing to the loan number that all of a sudden ramped up during the shutdown.
Oh, no. I I’m just saying that like that’s crazy. no matter what 7,000 is crazy progress in that short time period.
Maybe leading with that would have kind of helped uh put in context like kind of that that number being as as good as it is, but it’s still a long way to go, right? Like still a very very long way to go.
Um during the government shutdown, additionally 72 level two self assessments were completed.
Now systems been set up for those for a while. So no excuse there like absolutely none but there are 72 done there.
Um during the government shutdown there were a total of 76 level 2 C3POA certifications recorded.
that means completed done and recorded within that what is it 41day shutdown.
Yeah that’s fascinating to me that we had more C3PIO assessments than we did self assessments in one month.
Yeah, maybe maybe because they already had the score in maybe I don’t know that was just during the shutdown.
So let’s talk about the total numbers. This is the last CMMC level two certification.
So these are the last statistics. Drum roll please.
What have we completed in the first I don’t know we’ll say the year of CMMC including C3PO and DIP CAX which have been converted over there are a total of 575 I think I typed quick enough and caught the right number maybe off like one or two there’s a margin for error there that are listed within SPS as being completed now Joy one thing that I learned last night that troubled me about this is that there are 15 of those pending affirmation.
and me being naive as I am thought that that was pending like okay it’s done and we just need to go through check the te you know cross the te’s dot the eyes uh the C3PAO needs to make sure that they upload it or maybe there were some issues we were talking about cage code issues before preventing the affirmation that’s not the case.
we learned last night that there are 115 companies of these 575 total that technically can’t say that they’re C level two C3PAO certified on any contract they wanted to bid on because they’re not because they haven’t affirmed with an SPRS, right?
Yeah. Um that’s how I understood it. And that means that the organization went and celebrated after they got their certificate and thought, “Okay, we’re done.”
I mean, they might be still celebrating. It’s a big accomplishment. Who knows?
What’s the purpose of the affirmation, Jason?
So, are you asking me or I’m asking you? I don’t know what the purpose of the affirmation.
I thought the affirmation was the the company official is going to log in themselves and say I am attesting that everything that has been you know presented as evidence is true and correct. That’s the purpose of the affirmation.
So the C3PAO may have validated it and issued the cert certificate right certification.
The company official though for that contracting firm is the one that needs to get on there and say it’s my name on the line. I attest to this.
for some reason I thought that like in this one scenario right where you’re going through the C3PO is doing it in lie of the affirming official doing that right that the C3PO did that uploaded it you were good to go and then every year after the affirming official would have to come in and do that right the trienal understanding.
yeah and so now this is a wrinkle that apparently is catching a bunch of other people uh more so than me and look I I’ll be vulnerable.
Look, I thought 100% honestly thought that when my C3PAO evaluated my organization and they pumped it up in the EMAS that it just did this double population workflow, whatever it was that in both places because it made sense.
Yeah, it made sense.
I just paid somebody 30 to $50,000 to come in and assess my environment and now I got to do extra work on top of that because you know now here’s the other question that’s good for three years.
Is it good for three years from the time that it’s been uploaded in EMass by my C3PAO or good for three years from the time that I affirm it? And then what if there’s an overlap in that time frame?
Okay. I I think it’s when it’s entered in the SP system by the C3PAO.
Okay. Um that’s how long you have the clock starts ticking now for your 12 months before you have to do your annual self assessment whether or not you’ve gone in and done the affirmation.
I think that’s crazy.
And then the last thing, Joy, that I want to talk about from Dana Mason’s update from the town hall.
This is it’s so crazy to me, but um a bit of progress and a look of of what’s to come.
Before the government shutdown happened, uh we were told that there were two organizations that completed the CMMC level three process walkthroughs, right?
So these are what’s going to happen during a CMC level three assessment done by DACA, right? How is this going to take place? How are we going to document this? blah blah blah.
All of that’s happening now so that those could start happening uh when the DO thinks it’s going to happen in the phase roll out.
I I feel like if they’re doing it now, it’s probably be int anticipation um that’s probably going to happen before that phase roll out implementation like everything else that’s happened thus far.
I would feel like that too.
Um I I wish that I could have participated in that some way or somehow. I mean, how fascinating.
I love the whole thought of level three um with the enhanced cyber security control.
So I’m excited about that. And then the way the assets are managed within level three and stuff like that. It’s going to be very fascinating.
All right. So like I mentioned, Joy, there’s no town hall until January 27th of 2026, which See you next week!
leaves us in this lull period, right?
And I know that the AB put out some stuff that they want to work for in 2026. And usually we say next month on the town hall, we’d like you to put this up there and it’s our wish list.
So we’re going to just substitute for this month and real quick go through our way too early predictions for the year 2026.
I want Joyy’s can’t miss prediction for 2026 for the CMC program. What is one thing that you are certain that I should go and create a parlay around?
Level three assessments will take place by the end of Q3.
By the end of Q3. So your early prediction is by the end of I’m going there. I’m saying that.
How about you?
I like that. Um I think that we will be above 135 authorized C3PAOs uh by the end of Q1.
By the end of Q1.
Okay. Because remember we talked about how like there’s almost a hundred. This is I shouldn’t explain the logic to my guests.
Um almost a hundred and then they keep hinting at the the shutdown holding up the process of so many and they listed so many there and then so many that are about to go through the Dipk assessments and from what I hear Dipk’s kind of hard charging right now through assessments.
Anybody and everybody we just assess it, right? Like a little baby sliding across the table. Let’s assess it real quick.
And so like that’s basically the way things are going. So I could see it happening quicker than that.
That that analogy was very interesting.
Um but Um, from 88 to 135 by the end of Q1. By the end of Q1. So, it’s four months.
All right. Like a baby sliding across the table. The table. I got to assess everything. I just logic.
All right. So, um, as far as the show goes, like and subscribe and we’ll see you next week.
[Music]
Contact
Speak With Our Team
Our team of compliance and cybersecurity experts are on standby and ready to help. We’ll walk you through what you need and what to expect.



