We’ve been making content about DoD cyber regulations for years. Here’s one of the most common critiques we get: Distinguishing between CMMC and other DFARS cyber requirements is just nitpicking semantics. You know who doesn’t agree with that statement?
- The Department of Justice, who regularly drops the False Claims Act hammer on contractors misrepresenting their DFARS 7012 compliance.
- Congress, who have a plan for providing grant funding for CMMC assessments, not the cost of complying with DFARS 7012.
- The Department of Defense, who spent years repeating that CMMC verification is different from the requirements in DFARS clause 252.204-7012.
Just to name a few. Curious about why? We help answer questions about CMMC vs DFARS live every week, come check it out.
Transcript
[0:11] — Jacob
All right, everybody. We are live.
Apparently there was an issue going live on LinkedIn, so if you’re watching on both LinkedIn and YouTube, good luck.
It’s Friday. It’s almost the Fourth of July.
For only the second time, we’ve got the full four-person “Brady Bunch” setup.
As always, we’re streaming on YouTube and LinkedIn.
You can ask questions in chat, send us a DM, visit cuihotline.org, call the hotline, fill out the form, or visit the new Summit 7 website.
There are plenty of ways to get in touch.
We’ve only got an hour, so let’s jump right into the weekend review.
Scott, you wanted to talk about the Verizon DBIR.
[1:09] — Scott
Before we get there…
Was it a red card?
VAR reviews are supposed to be viewed at normal speed—not slow motion and freeze frames to decide something like that.
I don’t think it was a red card.
[1:32] — Jacob
You missed the perfect opportunity to say that point-in-time snapshots aren’t the best way to judge a situation—you need continuous monitoring.
[1:38] — Scott
I’m sticking with no red card.
We’ll miss Flo, but I still like our chances.
I’ve got the U.S. making the quarterfinals.
If we beat Belgium, great.
France is going to be tough.
If we somehow make the final eight, that would be incredible.
[2:52] — Jacob
If the United States somehow wins the World Cup, I will never stop talking about it.
I’ll bring it up on every show until I’m in a nursing home.
Europe better hope that never happens.
Now…
Back to the DBIR.
[3:09] — Scott
One of the biggest takeaways from this year’s Verizon Data Breach Investigations Report is that exploitation of vulnerabilities has officially surpassed credential theft as the leading cause of breaches.
Historically, stolen credentials were the biggest attack vector.
I’d like to think increased MFA adoption is helping reduce credential-based attacks.
Unfortunately, we’re now seeing:
- More vulnerabilities being discovered.
- Organizations taking longer to remediate them.
Average remediation time increased from roughly 33 days to 43 days.
That combination has made vulnerability exploitation the primary attack method.
Whether you manage security internally or outsource it, make sure you understand your remediation SLAs and patch management process.
Go read the DBIR.
There’s a lot of valuable information in it.
[4:53] — Jacob
It’s definitely a significant shift.
Exploitation wasn’t always the biggest issue.
Now it is.
[5:16] — Daniel
Knock, knock.
It’s DIBCAC.
One of the conversations I had this week involved a company receiving notice that DIBCAC wanted to assess them.
That’s great…
Unless you’ve submitted a perfect 110 SPRS score that isn’t actually accurate.
In this case, the organization scored itself using only the DoD Assessment Methodology checklist.
They weren’t evaluating themselves against the assessment objectives.
They also hadn’t brought several non-FedRAMP cloud services containing CUI into scope.
When DIBCAC asked for their System Security Plan within 30 days, panic set in.
If your score is legitimate, 30 days is plenty of time.
You simply send the documentation.
If it isn’t, now you’re trying to remediate everything in a month.
For a mid-sized company, that’s extremely difficult.
Making major changes after DIBCAC contacts you also creates awkward timing because all of your documentation suddenly changes after the assessment notice.
I’m not an attorney.
I recommended they immediately speak with legal counsel.
[7:34] — Jacob
That sounds almost identical to the recent LogZone case.
If DIBCAC identifies significant discrepancies, I think we’re going to continue seeing Department of Justice False Claims Act actions.
[7:58] — Daniel
Exactly.
Call us before DIBCAC calls you.
[8:15] — Jacob
Brad, you mentioned something interesting earlier.
Companies allowing their IT departments to lead CMMC programs seem to struggle more than organizations with strong governance and management.
[8:33] — Brad
That’s exactly what we’re seeing.
There are certainly technical problems to solve.
But CMMC isn’t simply an IT project.
It’s a business transformation.
Leadership has to be involved.
Governance, Risk, and Compliance personnel need to participate.
Documentation, business processes, assessment boundaries, policies, and organizational decisions all extend well beyond IT.
If the IT department owns everything by itself, organizations often miss major pieces of the program.
Leadership needs to drive the effort across the business.
[9:33] — Jacob
Daniel, when that company called you…
Was it leadership?
[9:39] — Daniel
No.
It was the IT director.
Halfway through our conversation, he stopped me and pulled the CEO into the meeting because he wanted leadership to hear exactly what I was explaining.
The IT director was also the person who had originally submitted the 110 SPRS score.
[10:36] — Jacob
We also released a short podcast this week discussing assessment capacity.
The idea that there aren’t enough CMMC assessors simply isn’t true.
We’ve analyzed the Cyber AB numbers month after month.
Even if only half of the available assessment teams are actively performing assessments, current capacity still exceeds demand.
More organizations have already achieved Level 2 certification than the DoD projected for the entire first year.
Assessment capacity isn’t the bottleneck.
Preparation is.
Organizations are showing up far too late in the process.
[13:18] — Daniel
That’s exactly what we’re seeing.
Companies call and say they need certification by November.
Many haven’t even started.
One misconception is treating all existing CUI the same.
One strategy is standing up a brand-new compliant enclave for new CUI while gradually bringing legacy CUI into scope over time.
Even building a greenfield environment still takes months.
It isn’t something you can accomplish overnight.
[14:44] — Jacob
Next question.
Epicor offers a cloud ERP hosted in Microsoft Government Cloud but without a FedRAMP authorization.
Epicor says that’s acceptable because it’s running in GovCloud.
Is Government Cloud the same thing as FedRAMP?
[15:18] — Daniel
No.
Being hosted inside a FedRAMP-authorized cloud environment does not automatically make the application FedRAMP authorized.
The FedRAMP website explicitly says that.
Applications can inherit certain infrastructure protections, but they do not inherit FedRAMP authorization itself.
We see this misunderstanding all the time.
Someone buys the Government version of an application hosted in Azure Government or AWS GovCloud and assumes it’s compliant.
Unless the application itself has completed the necessary authorization—or otherwise satisfies applicable requirements—you cannot simply assume it’s appropriate for processing CUI.
[16:40] — Scott
That creates another challenge.
Most organizations don’t even know exactly where all of their CUI resides.
If they don’t know where the CUI is, they can’t confidently say it isn’t being placed into unsupported systems.
The same issue applies to AI.
If you don’t know where your CUI is, how do you prevent it from being submitted to AI platforms?
[17:16] — Jacob
Speaking of AI…
We’ve received quite a few questions this week.
First one:
Do you eventually see AI replacing C3PAO assessments?
[17:31] — Scott
Maybe AI can handle Dollar General C3PAO audits.
But no—I don’t see AI replacing assessments.
These models are impressive, but they’re not going to replace the human element.
What I do see is AI improving efficiency.
It will:
- Speed up assessments.
- Reduce assessment costs.
- Improve evidence gathering.
- Improve documentation.
I absolutely think AI will make assessments faster and more affordable.
I just don’t see it replacing C3PAOs anytime soon.
[18:33] — Daniel
I agree.
The current CMMC Assessment Process (CAP) doesn’t support a fully AI-driven certification process.
It explicitly requires human participation through interviews with your internal staff and service providers.
Could AI help conduct interviews?
Maybe someday.
For now, I see AI making assessments more efficient and somewhat commoditizing the process by reducing cost and effort.
FedRAMP 20X is a good example.
They’re trying to accelerate authorization using automation—not eliminate human oversight entirely.
I think we’ll see a similar “fast-track” approach emerge for CMMC, where AI helps C3PAOs work faster while people remain responsible for the assessment.
[19:51] — Jacob
I don’t see AI replacing C3PAOs anytime soon.
If anything, the AI hype cycle will probably cool off long before the DoD changes its culture or regulations enough to allow that.
Automation, though, should happen as quickly as possible.
DISA has automated huge portions of STIG compliance for years.
Those aren’t AI capabilities—they’re simply automated technical checks.
There’s no reason many of those concepts can’t be applied to NIST SP 800-171.
[20:46] — Scott
Every cybersecurity tool vendor is racing to add AI features.
Evidence collection, documentation, and reporting are all going to improve dramatically.
Replacement?
No.
Automation?
Absolutely.
[21:06] — Jacob
Be careful what you wish for.
Today we estimate the average C3PAO team completes about two assessments each month.
If AI allows those teams to perform four, six, or even eight assessments each month, suddenly we need fewer assessment teams overall.
That means the argument that “there aren’t enough assessors” disappears even faster.
Let’s automate it.
[21:38] — Scott
I already know C3PAOs developing methodologies that could eventually perform eight to twelve assessments each week with a single team.
Assessment capacity won’t be the limiting factor.
Large programs like the Army’s Enterprise Next Generation Commercial Enclave (ENCODE) require thousands of organizations to be assessed in relatively short timeframes.
The assessment process has to become more efficient to support that scale.
[22:42] — Brad
Efficiency improves on both sides.
C3PAOs become faster at evaluating evidence.
Customers become faster at collecting and organizing evidence in formats assessors can consume.
Both sides benefit from better tooling.
[23:07] — Jacob
People often say continuous compliance is better than point-in-time assessments.
That’s true.
But are organizations actually prepared to demonstrate compliance continuously?
If they are, DIBCAC doesn’t even need to call anymore.
They can just review your continuous compliance dashboard.
[23:39] — Jacob
Next question.
Is vulnerability information about a contractor’s own systems considered Controlled Unclassified Information under the Information Systems Vulnerability Information (ISVI) category?
[23:56] — Jacob
No.
The statutory authority behind that category applies to federal systems—not contractor systems.
People frequently overextend that authority.
Personally, I think vulnerability information should receive stronger protection.
The same applies to Security Protection Data.
But under today’s authorities, vulnerability information for non-federal systems is not automatically CUI.
[24:47] — Jacob
Next question.
Is there guidance on using AI during the readiness phase of a Level 2 assessment?
[24:55] — Scott
Use it.
Just verify everything it produces.
AI is designed to provide helpful answers, and sometimes that means giving you the answer you want rather than the answer you need.
Don’t blindly trust the output.
Review everything before handing it to an assessor.
Organizations should also establish AI governance policies before employees begin experimenting with public AI tools.
Define:
- Which AI systems are approved.
- What information may be submitted.
- What data must never leave the organization.
[25:50] — Jacob
And don’t put your CUI into random AI platforms.
It’s still just data moving across the internet.
Treat it accordingly.
[26:10] — Jacob
Next question.
Is there any data showing how many organizations fail CMMC Level 2 assessments?
[26:17] — Jacob
No.
The industry doesn’t collect failed assessment statistics.
What I’d much rather see tracked is false starts.
Most organizations don’t actually fail assessments.
They never reach the assessment because they aren’t ready.
C3PAOs have told us anecdotally that roughly 25–40% of organizations scheduled for assessments ultimately never begin because they:
- Can’t produce a System Security Plan.
- Don’t have sufficient documentation.
- Can’t get required participation from their MSP.
- Aren’t actually assessment-ready.
Those organizations don’t fail.
They simply never start.
[27:45] — Daniel
I’ve had three false-start conversations in just the last three weeks.
One organization defined such an enormous assessment boundary that the assessor encouraged them to revisit their scoping before proceeding.
The other two couldn’t move forward because their MSPs refused to participate during the assessment.
They’re now stuck addressing those issues before assessments can continue.
Some of those remediation efforts could easily take several months.
[29:05] — Jacob
This reminds me of the Manufacturing Extension Partnership study from last year.
Researchers interviewed hundreds of defense contractors and concluded that organizations were dramatically overconfident about their cybersecurity readiness.
Now we’re seeing exactly what they predicted.
Companies believe they’re ready until they begin preparing for an actual assessment.
[29:50] — Jacob
Next question.
What controls prevent MSP administrators from granting themselves access to CUI?
[30:05] — Scott
Realistically…
Not many.
If your MSP fully administers your environment, administrative privileges naturally provide the ability to access CUI.
You can implement:
- Privileged Identity Management (PIM).
- Approval workflows.
- Role-based permissions.
- Just-in-Time administrative access.
Those controls improve accountability.
They don’t eliminate administrative capability.
That’s why selecting the right MSP is so important.
[31:00] — Brad
Exactly.
Administrative access inherently means elevated access.
You can scope responsibilities, but if you’re asking an MSP to manage the entire environment, someone on that team will inevitably have access to CUI.
[31:26] — Daniel
This is one of the biggest concerns I have.
How does your MSP hire people?
What background checks do they perform?
How do they vet remote employees?
If they’re supporting export-controlled environments, are those administrators U.S. Persons?
If not, you could create a deemed export issue under ITAR simply by granting administrative access.
Customers should evaluate not only an MSP’s technical capabilities but also:
- Hiring practices.
- Personnel vetting.
- Insider threat controls.
- Export compliance processes.
Those factors become just as important as the technical implementation itself.
[32:49] — Daniel
Sorry—this is a bit of a soapbox for me.
It’s one of the things I emphasize constantly with our HR team because it’s incredibly important.
I’m not going to stop talking about it.
[33:00] — Jacob
None of those were the answer I was looking for.
The real answer is:
“They told us they wouldn’t.”
We’ve outsourced administrative access to a third party, and they promised not to access our CUI.
What’s the problem?
Apparently, that’s the security control.
[33:17] — Jacob
Weekly reminder:
ITAR is not CMMC.
Export control requirements and national data sovereignty requirements are completely separate from CMMC.
Whether you end up in GCC High to satisfy export control requirements is an export control decision—not a CMMC decision.
Don’t blame the DoD for ITAR.
ITAR dates back to the 1970s.
Different agencies.
Different statutes.
Different regulations.
They’re separate compliance programs.
[34:10] — Scott
When I was an IT Director for a defense contractor, our foreign parent company wanted IBM to administer our environment.
They refused to create a U.S.-only administrative team.
Because of ITAR restrictions, we couldn’t allow that.
We ultimately had to separate the environment, move into GCC High, and find a completely different administrative model.
We had to escalate the issue all the way to the legal leadership of the parent company before they finally understood why U.S.-person restrictions mattered.
[34:59] — Jacob
We’ve even seen False Claims Act settlements involving actions taken by outside service providers that ultimately resulted in liability for the contractor.
Don’t underestimate export control requirements.
[35:35] — Jacob
Next question.
Can a distributor simply rely on a manufacturer’s Level 2 certification, or does every company in the supply chain need its own certification?
[36:17] — Scott
The first question is:
What information is flowing to you?
Are you receiving:
- CUI?
- Only Federal Contract Information (FCI)?
- Commercial information?
- Intellectual property that isn’t CUI?
That determines everything.
[36:41] — Daniel
I actually have a whiteboard for this.
Let’s say we have:
- A prime contractor.
- A subcontractor.
If the prime only provides:
- Public information.
- Military specifications.
- Intellectual property that isn’t CUI.
Then the subcontractor likely only receives Level 1 flow-down requirements because they’re handling FCI.
However…
If the prime sends digital CUI, then the contractual Level 2 requirements generally flow down with that information.
There is one important exception.
The DoD allows CUI to be transmitted solely as paper.
If the subcontractor never digitizes those paper documents, then only the physical handling requirements from DFARS 252.204-7012 apply.
So…
As Caleb likes to say:
“It depends.”
Unfortunately, many primes simply apply Level 2 requirements to every supplier because it’s the safest legal position for them.
That’s why so many subcontractors end up needing Level 2 certification even when it may not have been strictly necessary.
[40:36] — Jacob
Follow-up question.
Does using a VPN create a compliant environment for transferring or storing CUI?
[40:48] — Daniel
Security and compliance are different things.
Suppose I have:
- A laptop.
- A VPN tunnel.
- CUI flowing through that encrypted tunnel to a server.
The DoD has clarified that encrypted CUI is still CUI.
That means encryption alone doesn’t remove systems from scope.
A VPN absolutely improves security.
It does not exclude the VPN path or connected assets from your CMMC assessment boundary.
The endpoints remain CUI Assets.
[42:16] — Scott
The VPN itself doesn’t store the data.
The systems on either end of the VPN do.
Those endpoints remain in scope.
[42:34] — Jacob
If another company tells you:
“Don’t worry. You’re covered because we have a VPN.”
Verify that independently.
Don’t simply accept someone else’s interpretation of the requirements.
[43:02] — Daniel
One more example.
Suppose the prime hosts an SFTP server.
The subcontractor downloads CUI onto a workstation.
That workstation sends the files to an internal server.
The server backs them up to cloud storage.
Every system you control along that data flow becomes part of your assessment boundary.
The SFTP server belongs to the prime.
That’s their responsibility.
Everything after the download becomes your responsibility.
Organizations often think only about the transfer mechanism.
They forget to map everything that happens after the file arrives.
[44:41] — Scott
And once you begin sending that same CUI downstream to your own suppliers…
The exact same flow-down requirements continue.
The requirement follows the information.
[45:20] — Daniel
That’s why I encourage subcontractors to push back when appropriate.
If you don’t actually need the CUI to perform your work, ask your prime not to send it.
Tell them:
“Send me only the information necessary to manufacture the part.”
Reducing unnecessary CUI distribution benefits everyone.
[46:11] — Jacob
Exactly.
Sometimes primes say:
“Our suppliers aren’t ready.”
My response is:
“They would be if you stopped sending them unnecessary CUI.”
[46:24] — Scott
The challenge is organizational.
Contracting officers can’t control every engineer throughout a massive company.
Different departments often don’t communicate well enough to prevent unnecessary CUI from flowing downstream.
That’s one of the biggest practical challenges in the Defense Industrial Base.
[47:07] — Jacob
Speaking of the NIST SP 800-171 baseline…
Here’s our next question.
“We’re a 60-person company. How much is CMMC going to cost?”
[47:30] — Daniel
It depends.
Are you implementing a full enterprise architecture or an enclave?
That’s the first question.
For nearly a decade, we’ve said CMMC is generally a six-figure problem, regardless of company size.
When you include:
- Internal labor
- Hardware
- Software
- Consulting
- Assessment costs
A typical organization with around 100 employees will often spend $200,000–$400,000 to go from zero to Level 2 certification.
Your architecture makes a difference.
An enclave is generally less expensive than an enterprise implementation.
But even before purchasing technology, you’re already paying for:
- A dedicated internal resource.
- The assessment.
- Planning and implementation.
Those costs add up quickly.
[48:43] — Daniel
For Secure the DIB, I looked at what it would cost to build everything in-house.
For a 100-person company, the staffing alone approaches $1 million annually.
That’s before:
- Government licensing.
- Assessments.
- Network upgrades.
- Cloud migrations.
You’re talking about:
- Compliance personnel.
- Help desk.
- Cloud administration.
- Security operations.
It’s a significant investment.
[49:43] — Daniel
I know discussions about cost discourage people.
But there are some positive developments.
The Army’s ENCODE initiative is intended to help very small defense contractors by providing a government-funded enclave.
Organizations would still pay for their own assessments, but the operational environment itself would be funded by the government.
There’s also proposed language in the FY2027 National Defense Authorization Act that would create grants of up to $100,000 for companies completing certification.
We’re actively engaging with lawmakers because we believe that language should be expanded to support implementation—not just assessment costs.
[52:33] — Jacob
That’s my concern.
The proposal currently focuses on assessment costs, but assessments aren’t the biggest expense.
The expensive part is complying with DFARS 252.204-7012:
- Migrating to compliant cloud environments.
- Meeting FedRAMP requirements.
- Implementing NIST SP 800-171.
- Building the actual compliant environment.
If Congress only subsidizes assessments, it risks artificially driving assessment prices higher instead of solving the real problem.
The funding should support implementation activities, not just certification.
[54:57] — Jacob
Next question.
Has the DoD published target numbers for:
- CCAs?
- CCPs?
- C3PAOs?
[55:08] — Jacob
Not officially.
However, 32 CFR Part 170 estimates approximately 16,610 Level 2 assessments per year once the program reaches full operational capacity.
Based on that estimate:
- About 693 active assessment teams would be needed if each team completes two assessments per month.
- Assuming only half the available teams are active, the ecosystem would need roughly 1,400 potential assessment teams.
- That translates to approximately 3,400–3,500 certified assessors.
We’re already about one-third of the way there.
Those aren’t official DoD staffing targets.
They’re our calculations based on the assumptions in the final rule.
[57:22] — Jacob
Next question.
Does 32 CFR Part 170 require Security Protection Data (SPD) to be safeguarded?
[57:30] — Jacob
No.
The regulation doesn’t explicitly identify SPD as information protected by a law, regulation, or government-wide policy.
Ironically, that’s all it would take.
If the regulation simply said:
“Protect Security Protection Data.”
Then SPD would immediately satisfy the authority required to become a form of CUI.
That language appeared in the proposed rule.
It didn’t make it into the final rule.
The DoD clearly encourages organizations to protect SPD as though it were CUI.
But the legal authority isn’t currently there.
[58:39] — Jacob
Another question.
Are there grants available today to help small businesses with CMMC?
[58:46] — Jacob
Not yet.
The NDAA language is only a proposal.
Even if it’s included in the final bill later this year, Congress still has to appropriate the funding afterward.
That means organizations shouldn’t expect grant money anytime soon.
There are some state-level programs, but they vary significantly by state and many have already ended.
[59:29] — Jacob
Final question.
How will the DoD transition from NIST SP 800-171 Revision 2 to Revision 3?
[59:43] — Jacob
There are several possibilities.
One option is simply issuing a new class deviation updating DFARS 252.204-7012 to reference Revision 3 instead of Revision 2.
If that language appears in your contract, you’d immediately be required to comply with Revision 3.
Whether the DoD provides another phased rollout is unknown.
Another possibility is that the forthcoming government-wide FAR CUI Rule effectively drives everyone toward Revision 3 regardless of what DFARS says.
Unlike CMMC, the FAR Council has not proposed a phased implementation approach.
That phased rollout was a DoD decision.
Other federal agencies may take different approaches.
[1:01:05] — Daniel
That raises another interesting question.
The DoD explicitly states that encrypted CUI remains CUI.
The proposed FAR CUI Rule doesn’t currently include that same clarification.
Will every federal agency eventually publish its own FAQ document explaining these nuances?
Or will there be one government-wide interpretation?
We simply don’t know yet.
[1:01:36] — Jacob
Once every agency begins implementing the FAR CUI Rule, there could be:
- Different FAQs.
- Different guidance.
- Different verification approaches.
- Different implementation timelines.
We’ll have to wait and see how consistent those agencies remain.
[1:02:03] — Jacob
On that note…
Happy Fourth of July.
Thanks for spending part of your holiday weekend with us.
We’re here every Friday.
You can:
- Visit cuihotline.org.
- Check out the new Summit 7 website.
- Register for Secure the DIB.
- Leave questions in the comments after the stream.
Like and subscribe.
We’ll see you next week.
[1:02:32] — Daniel
See you all.
[1:02:34] — Scott
Keep all your fingers.
Happy Fourth.
Contact
Speak With Our Team
Our team of compliance and cybersecurity experts are on standby and ready to help. We’ll walk you through what you need and what to expect.
