Brief: The CUI Hotline — Jacob Horne with attorney Eric Crusius and assessment lead Max — on why the CMMC review report is late, the recurring assessor mistakes Max keeps seeing, and a long run of listener questions on CUI, contracts, and cost.
Key takeaways:
- No “60-day deadline” to publish. The clock’s start date is genuinely unclear (July 13 announcement vs. July 16 quote vs. July 20 convening memo), so realistically expect something late Sept–early Oct. Recent “class deviation” and DLA FAQ scares are old material people just re-discovered, not new policy.
- Assessor anti-hits (push back on these): asking for docs irrelevant to your system, objecting to SSPs that reference other documents (allowed), and asking OSCs to violate their own security policy by installing/uninstalling unauthorized apps mid-assessment.
- CUI determination is leverage. DFARS 7012(m) lets the contractor determine whether data retains its identity as CDI — a real (if caveated) opening to argue a drawing fragment isn’t CUI. Once you force the government to answer, they’ll say “CUI,” and the gray area is gone.
- Assessment cost reality: ~$40–50k for a simple all-virtual enclave, up past $100k for multi-facility — not the mythical hundreds of thousands. RFI responses reportedly confirmed this.
- A cert isn’t a get-out-of-jail-free card, but it moves you off the “soft target” list for DOJ/whistleblower False Claims Act cases, and clients report winning contracts on the strength of Level 2.
- Primes can still require CMMC even with third-party assessment suspended — prime/sub contracts are private commercial agreements. And there was never a real November 2026 deadline; primes invented that expectation.
Transcript
Jacob: All right, everybody. It’s Friday. It’s Hotline time. We don’t have nameplates up here — I forgot to put them up. Producer Dustin is not here, but we are. It’s a live show. Max is back — everybody’s favorite person who bullies assessors on a daily basis. And Eric Crusius is here. Everybody should know Eric from LinkedIn, from the DIB space, from podcasts, from all sorts of places. First time on the Hotline, right, Eric?
Eric: I think it is my first time. I saw that spinning red phone and I couldn’t resist.
Jacob: [laughter] Nice. So, we’re live on LinkedIn, we’re live on YouTube. You can add your questions in the chat like always. We’ve got questions in the queue that we didn’t get to last week that we’ll pull up. You can go to cuihotline.org and fill out the form — we’ve got some form questions in the queue as well. You can call the number and leave a message so we can hear everybody’s beautiful voices. There’s no time limit on the messages, so if you’ve got a really long question, feel free to leave the voicemail and we’ll play it. Daniel’s not here — he’s off doing fun stuff. Dustin’s not here — he’s off doing fun stuff. So we’re holding down the fort.
Let’s jump into it like always. “Where is the report?” We’re waiting. Remember that famous GIF? Well, we’re waiting. Everybody wants to know where the report from the CMMC review task force is. Daniel thinks we won’t hear anything until after the midterms. I think we’ll hear something before the midterms, but I think people are anchoring on the announcement of the suspension and then exactly 60 days later being the time when we’d hear stuff. And we don’t exactly know when the 60 days starts. The 60 days is not a deadline where it’s “pencils down, publish your report.”
If you go off the announcement of July 13th plus 60 days, that gives you one window. If you go off Davies’s quote on July 16th that said “we’re in the 60 days,” that could extend it a little. If you go off the actual internal memo that Davies signed that officially convenes the task force — that wasn’t signed until July 20th, but it doesn’t tell us when the task force was established. That memo also references a five-day spin-up window for the task force. And then she has another quote out there that says after the 60 days is over, they’re going to have 15 days to get everything together and report it up to the CIO with recommendations. So we don’t know when they’re supposed to report this out. If you take the whole realm of uncertainty around those dates, that’s late September, early October. I’d be surprised if we didn’t hear anything by the end of this month, but I wouldn’t be completely shocked if we didn’t hear anything until October. I would be surprised if we didn’t hear anything before the midterms. But ultimately, we don’t know. Nobody knows what the plan is. There is no 60-day deadline to publish. So if you’re wondering where the report is, join the club — we just have to wait and see. What do you think, Eric? Have you heard anything about official publications?
Eric: No. There are always a lot of rumors floating around as to when it’s going to come out. I don’t put a lot of stock in those rumors. I think we have to think of “math” and then “CMMC math.” CMMC math is: you add 2x to any time period you think something’s going to take. So I do think things always take longer with CMMC than we hope or expect.
Jacob: Boy, isn’t that the truth. Has there been one part of CMMC where it’s like, “Wow, that happened a lot quicker than I thought”?
Eric: October of last year was supposed to be the end of the original phased rollout from CMMC 1.0. So, you know, there you go. It’s another group of people from industry who don’t like government bureaucracy showing up in town to change the way things are done. There’s that quote — every dead climber on Mount Everest was highly motivated, trained, well-resourced, and ready to go. This isn’t the first time a group from industry has shown up saying, “All you’ve got to do is press the button nobody’s pressed before and that’ll fix everything.” And here we are, 60 days plus five, plus 10, plus 15 — still no report.
Jacob: Maybe they’ll come out and they’ll have done the exact right threading of the needle, and they’ll be like, “Why didn’t everybody just do this to begin with? You’re all idiots.” We’ll have to see what they say.
Everybody really wants to know what Max has to say — we’re just here to fill time. Max, we are 119 Level 2-certified Summit 7 clients. We’re going to be coming up into the 120s very soon, if not already. That was the number earlier today.
Max: [laughter] Yeah.
Jacob: Breaking news, everybody. Max, your favorite thing to do — my favorite thing to hear you talk about, everybody’s favorite thing to hear you talk about — is beating up on CMMC assessors. Put the fries in the bag and just verify what I’m telling you. What are you seeing out there after 120 assessments?
Max: Oh man, I have a whole list for you guys today. [laughter] I think there are like 13 or 14, but I’ll just read them off and go into a little bit of what we’ve been seeing. Obviously, we’ll leave out names and stuff like that. The first thing on the list: assessors asking for specific examples of things despite what a client’s documentation says — this is during the interview process. We have some assessors, maybe new, who are using some type of checklist that came from maybe the C3PAO, and they’re asking for documentation that’s not even relevant to the client’s system. So if you’re experiencing that, please say something — “We don’t have that in our environment. We don’t have an ISMS policy; we have a configuration management policy,” or whatever.
The next thing: an assessor’s opinion on what documentation should say versus what it currently says. It’s basically — the assessment objective is defined or identified. It’s defined in the SSP, it’s referenced. The authorized users are defined in the CMMC asset inventory. The fact that it’s not defined in the SSP throws some assessors off because they have to look in another document. There’s no rule or assessment objective that says you cannot reference other documents in your SSP. So that’s a big one.
Jacob: Makes you want to roll your SSP up and hit them on the nose. “Oh, stop it.” [laughter] You got a third one? Any other greatest hits?
Max: Oh yeah, I’ve got a whole list. This is a big one — I think this is the most important one. I’m not here talking the whole time for an hour, but: an assessor asking the OSC during interview and testing to violate their security policies by trying to install or uninstall an application that’s not authorized. That is a really big one. We see that a lot. If you’re seeing that out there, OSCs, push back and say, “That is against our acceptable use policy, because of X, and we cannot go any further.” So let’s try not to ask OSCs to break their security policy. [laughter]
Jacob: That’s crazy. It’s like, “Oh, the policy of your police department is to not carry one in the chamber. Why don’t you go ahead and pull the trigger real fast and prove it.” That’s crazy. Well, let us know in chat. Max, we’re going to have to have you on the podcast and do a whole episode on these — the greatest anti-hits of stuff that’s going on. Because listen, there’s still a lot of value in getting your assessment. This can happen whether you’re doing a self-assessment or not, depending on how ornery your internal people are. It doesn’t have to be an external third party that hits these snags. But whether it’s internal or external, ask for a trusted adult and call Max for her advice, because this is what she does and she’s very good at it.
Talking about trusted adults — Eric, help us out, buddy. Talk us off the ledge here, because I think people are anchored on this 60 days and everyone’s scouring the internet for any indication of what’s going to happen. It’s totally understandable, but a lot of people are grasping at straws. They’re seeing faces in the rocks on Mars, and really we’re just looking for patterns that aren’t there.
Eric: Absolutely. We saw that with the class deviation that came out recently — and somebody asked a question in the chat about the DLA FAQs about that. This is information that’s not necessarily that new, but somebody just happens to find it, bring it out into the open again, and all of a sudden we have a firestorm of, “Oh my gosh, what does this mean?” There’s a lot of that kind of stuff flowing out there. There’s not a lot of information out there, and people’s livelihoods are connected to what happens with this program.
Jacob: It’s also budget season.
Eric: It’s budget season. So these contractors are like, “Do I or don’t I have to do this before the end of the year?” I have to budget for what’s going on, and you guys just threw up a giant question mark and said “60 days later.” It isn’t just assessors — it’s everybody.
Jacob: Absolutely.
Eric: So it’s not surprising that every little thing somebody discovers creates a firestorm on LinkedIn and results in phone calls and meetings, even if it’s not something new or relevant to the CMMC program. I really think it’s important — as it says in the Weekend Review tagline — to take a breath before jumping to conclusions.
Jacob: That jumping-to-conclusions game — that was in that Christmas movie. But then you jump to conclusions. You shouldn’t do that. It’s not close enough to Christmas yet to do that. The thing I’d tell everybody: I don’t see this group of people currently in charge at DoD — after their July 13th ticker-tape parade, pyrotechnic main-stage parachuting smoke-streamer media blitz about the suspension — there are videos, press releases, news stories, stuff everywhere. They went crazy. I don’t think the output of the review is going to be a phantom update to some random buried thing that nobody saw. That’s not what they’d do, because they’re never going to pass up the opportunity to say, “Look at this thing we did.” So when the announcement comes out, everyone will hear it — you won’t be able to not hear it. I’m not even sure that DLA FAQ thing is an update. I’m 95% sure that this DLA FAQ people are talking about was always DLA’s policy. I’d have to go back in the Wayback Machine and look, and I’m going to try to do that while we’re on today.
Eric: Similarly, this class deviation issue — people found it in September because people were looking in September, because they felt that was the end of the 60 days. They didn’t realize that class deviation had been in place since July and actually contained wording from the final rule a year prior. So people were like, “Is this an update? Is this an extension?” But that’s why we do the show every week — to try to help out. So just realize that if you think you found a phantom update, there’s a good chance it’s probably not. But we’re all in this together.
Max: Real quick on the FAQ — I did see it a couple weeks ago. It was updated even before whatever report they’re doing was completed. So I don’t think it changed because the CIO told them something.
Jacob: This reminds me — on Acquisition.gov, in the def, at the top corner it’ll say “updated as of” and then a month and a year, and that’s whatever the newest version of the DFARS is, and it’s global across all the pages. So anytime there’s an update to the DFARS anywhere, all the pages for all the clauses say “as of this date.” So during rulemaking, when we were all waiting for the final rule, people would browse to the 7021 clause and it would say “updated as of last month,” and they’d go, “Oh my god, rulemaking’s done, this is the new thing” — not realizing that was this other archaic global artifact left over through some weird feature. So that’s what happens, DoD, when you make a big deal out of something and then just stop talking. When you stop talking, people are digging around, interpreting, hoping. You have to continuously update people. Otherwise people are like, “I never have to do any of it / I still have to do it / everything changed / nothing changed.” And that’s what ends up getting people to hesitate on doing anything at all, including their existing contractual obligations. So, pro tip, everybody at the DoD: you’ve got to keep everybody updated.
All right — very basic. “How do I know if my company actually needs CMMC Level 2?” What would your answer be, Eric?
Eric: It’s very appropriate for the name of this show, but — CUI. Do you have CUI? Do you expect to enter into contracts where CUI will be part of the contractual relationship — where you’ll be making it, receiving it, storing it — and is the kind of work you want to do next year work that will involve CUI? If any of those things are true, then making sure you’re compliant with 800-171 and getting Level 2 self-assessed or third-party assessed is the only answer. And you may need outside help to determine whether something is CUI. You shouldn’t just rely on the government saying it’s CUI, because they often mismark it — overmark, undermark. They do both. And I’m not blaming them — they’re not trained. They shouldn’t be expected to know it just by birth. They have to get some guidance as to what it is, how to mark it, and what not to mark. If this FAR CUI rule is issued this year with that form attached to it that requires contracting officers to identify the CUI, that would obviously be very helpful.
Jacob: I think there’s a chance that SF form could have some unintended consequences, because the default behavior is to just say it’s CUI, and now they have a form that would formally allow them to say “this is all CUI.” It isn’t hyper-detailed, and I have a feeling they’re going to default to checking the box that says it is CUI rather than the box that says it isn’t. So you’ll have a positive indicator in the contract that it’s CUI, but I don’t think it’ll actually change the underlying behavior. So it is good, it is an improvement, but I think it’ll cement bad behaviors rather than incentivize a change.
Eric: We’ll have to see. Calling up an attorney and interpreting what you’re allowed to do within the language of the contract clauses, interpreting the data flows, what your customer says or doesn’t say — that costs money, but it’s probably going to save you money in the long term if you can navigate those gray areas to say “we don’t have CUI,” or “we have very limited CUI,” or get these things taken out completely. If they just stamp the form and send it to you, that’s kind of it at that point. Let’s say you’re bidding on a contract you expect to be Level 1. You have a Level 1 self-assessment, and then the contracting officer in the solicitation puts that form in and says, “No, we’re going to have CUI in here,” and you as a contractor don’t actually think it’s CUI — one of the options you have is to file a pre-award protest and say, “This should be a Level 1, because this information is not CUI.” Obviously the government gets some discretion. On a 50-50 scenario, they’re going to win that battle. But if it’s clearly not CUI, you have a chance and an opportunity to take that out of the contract. If it means the opportunity to bid on a $100-million-or-more contract, it may be worth doing.
Jacob: This is what I tell people all the time. “Hey, DoD, you want to solve your problem? For most people out there, it was your decision to put DFARS 7012 into all contracts by default, even though the data that triggers it does not involve all contracts by default.” So you put all the pressure on the contractors to negotiate with you to take the clause out in order to mitigate your risk. So when you come out a decade later and say you’re really concerned about burden on small business — the call is coming from inside the house. Change the policy so you only include 7012 when the data is included. But that’s way too hard to do, because that would involve real reform. So instead we’re going to blame 800-171 like that’s the problem.
All right, Max — this is one we had last week. A question from the weeds. For requirement 3.4.6, assessment objective (a): “essential system capabilities are defined.” What capabilities are we talking about — only security capabilities, or whatever the system is supposed to do plus security capabilities?
Max: It’s whatever the system is supposed to do and security capabilities. I can go a little in depth here. The assessment objective states essential system capabilities are defined based on the principle of least functionality. What that means is organizations need to show disabled, unused, or unnecessary physical/logical ports and protocols to prevent unauthorized connection of devices, transfer of information, and tunneling. That also includes software. So we’re really looking at how your environment is set up — it’s supposed to be set up to the principle of least functionality. Only configure it to do what you need it to do and nothing more. A good statement — hopefully this helps — would be: “[Client name] configures the system to provide only the essential capabilities defined within the baseline configuration.” You do not need to list out every single port, protocol, and piece of software in your implementation statement — point to your baselines. That’s what those are for.
Jacob: “Give me all 65,000 ports and tell me which ones are on and which ones are off, please.” [laughter]
Max: Exactly. That’s 100% what they want.
Jacob: All right. Brad said: “Where would a CUI ombudsman need to be placed in the DoD to protect and advocate for prime contractors and subcontractors?” Eric, have you heard of a concept like this before?
Eric: No, but it’s not a bad idea. For instance, every agency has a labor advisor who has that role. If a contracting officer is unsure about what labor regulations to put in — they can be fairly extensive — the advisor is there to help them think through it. And they also act as a go-between between the contractor and the contracting officer sometimes, if there’s a dispute. No reason there shouldn’t be somebody like that for each agency regarding CUI as well. There’s Office of Small Business Programs, maybe. There is precedent for it. I could even think it could be in the program management office or somewhere in contracting — maybe not the CIO’s office, because they can’t really tell the contracting folks what to do.
Jacob: Wait, wait, wait — I thought we just had a big RFI with a bunch of questions about contracting specifics. What are you talking about?
Eric: They agreed to do it, but they didn’t have to do it.
Jacob: Ah, okay. [laughter] So how would that role work — conceptually? And Brad, if you have thoughts, let us know. From a lawyer’s perspective, in pre-award disputes, what would an ombudsman be empowered to do or not do? How would that throw a wrench in the gears?
Eric: Using the labor one as precedent, which I’ve seen work a lot: they do a few different things. One — the contracting officer is unsure what to do, so they voluntarily go to this person and say, “What do you think?” and they’ll take their advice, most likely. Then there’s a scenario where the contracting officer does something and the contractor disagrees, and if the contractor is right and they don’t get any relief from the contracting officer, they go to the ombudsman and try to make their case, and that person will go to the contracting officer. That’s a way to have a third party in the debate who the contracting officer would hopefully listen to. The problem is the contracting officer doesn’t necessarily have to listen to them, but 95% of the time they would, unless they have some reason not to. So “facilitator” is probably the best word to describe what they’d do — facilitate any dispute or questions.
Jacob: Gotcha. Hey — the nameplates came back up. We did it. All right. Question for you, Max, about VoIP, everybody’s favorite. “Can you please describe what OSCs are doing technically — not just in policy — to meet 3.13.14 objectives (a) and (b), specifically when dial-in needs to stay enabled?” Have you seen this one come up?
Max: Yeah, I’ve seen this one, and I can speak to both sides. If we’re talking about how it technically needs to be set up, that’s one thing; if we’re talking about how to keep it out of scope, that’s another. First one: dial-in. I’d ask a clarifying question — if you’re talking about Teams, because at this point technically Teams is not VoIP; VoIP technologies would really be PBX systems on-site or something along those lines. But we’d want to make sure those logs are being ingested and you can alert and view them in your Microsoft Sentinel or your SOC provider — make sure those connections are being monitored and controlled. However, if you wanted to keep it out of scope, you can logically segregate it by VNet. That’s what we usually do — we just segregate that SBC. So there you go.
Jacob: All right. Mike says, “Are there any manufacturers out here? We need drawings in order to build parts.” Dave says he’s a manufacturer. I’ve got a question for you, Mike, and for you, Dave. How are you feeling about the DoD CIO’s rhetoric over the last 60 days about how current requirements aren’t enough — that there needs to be manufacturing resiliency requirements, which would be an expansion of your existing security requirements? She’s also said security requirements focused just on CUI data are too narrow, so there’d be an expansion of scope, and your OT environment would presumably no longer be treated as a specialized asset — it’d be treated completely in scope. Have you heard this? What do you think? They don’t let anybody ask her any questions at these events, and you guys are busy doing stuff — you’re not going to Black Hat in Vegas. So what does the manufacturing community think of this really great idea the CIO has about making the requirements go up? Let us know in chat.
Part of the back-and-forth: Dave said, “Our issue is that we use small parts of the overall drawing, and it’s hard to control where those printouts go.” Classic data-flow problem. Dave says, “We get our stuff from Air Force, Navy, and DLA.” So this leads into some supplier questions. Eric, I don’t know how often you’ve seen this, but so much of the conversation around CMMC ignores the elephant in the room — that the impacts, costs, decisions, and data flow are filtered on the other side of the prime contractors. DoD’s policies could be pretty clear, pretty good, but what happens downstream starts to get really strange.
Eric: Yeah. I’ve worked with a number of manufacturers, and there’s not a one-size-fits-all answer on how to treat these things. You have stuff on the floor — so many manufacturing plants have open doors so people can go out and smoke. There are all these practical problems that don’t fit what the regulations or controls say. So I hate this answer, but it’s going to be highly dependent on the environment and what you’re trying to accomplish. It’s a one-on-one scenario. Generally speaking, can you potentially take a small piece of a CUI document and, if it’s not identifiable, maybe argue it’s not CUI? There are arguments in all different directions.
Jacob: Well — you’re an attorney, I have this question. I say this all the time and I’m not an attorney, so let me know if it’s completely off base. My favorite paragraph of DFARS 7012 is paragraph (m) at the bottom. In 2016 they added a line that said the contractor determines whether or not the data retains its identity as covered defense information. To me, that makes it sound like the contractor determines whether the data retains its identity as covered defense information. So if the contract clause says I get to make that determination, then who’s going to stop me from determining that this part of the drawing is not CUI? Because every time I go upstream, they’re going to tell me the whole drawing is CUI. If they’re never going to give me a clear answer, doesn’t that give me an opening to say it’s not CUI?
Eric: So I’ve used that opening a couple times with clients in the last couple years — with the proper disclaimer that “this is what it says; it doesn’t mean they’re going to interpret it this way down the road if push comes to shove and they’re unhappy about something.” But we have a cognizant argument that you could take this little piece over here that’s not identifiable and say, “This is not CUI.” So it’s something I’ve used before and expect to use again. It’s like that relationship status on Facebook — it’s complicated.
Jacob: Unfortunately — we talked about this last week — it seems to me the pattern in this little corner of the world is: every time there’s a gray-area, up-for-interpretation question, and people bug the government over and over for an answer, they get an answer back that they don’t like, and once they get that answer, it’s policy. “Is G-code CUI or not” is the classic one. Do you think that, gun to their head, “give me an answer, is G-code CUI or not,” they’re going to tell you it’s not — or do you think the ultimate risk-averse bureaucratic culture on planet Earth is going to be like, “Yeah, it’s probably CUI”? And then if they blanket-say G-code is CUI, you no longer have this gray area to interpret and maneuver in and make an argument that it’s not. Every time we get an answer from the government, it tightens stuff down and gets rid of your ability to maneuver. So it sucks, because it’s not certain, but that uncertainty is an advantage if you take the time to leverage it.
Eric: Absolutely. We live in a world of uncertainty. Every day we walk out of our house, we’re taking a risk of some kind. The question is how much risk you’re willing to tolerate, and what that risk looks like versus the benefit you receive. It’s all 3D chess all the time.
Jacob: Mike says, “We’re here for the long haul. I don’t think many small shops will be able to remain in defense. Not to mention, we’re also facing the silver tsunami — a lot of owners are looking to exit or wrap up or sell. A lot of people are going to be retiring.” This is a question I have. People keep talking about how the DIB has been shrinking dramatically since the end of the Cold War and continues to shrink, and they say CMMC is going to shrink the DIB. My question is: how many of those companies that would have left because of CMMC are about to leave anyway because the owner is retiring?
Eric: No one knows the answer to that one — but we all kind of know the answer to that one. You know what I’m saying? I’ll tell you this — we do a lot of M&A activity for defense contractors at the firm, and I have not come across any company exiting because of CMMC. They have other factors they’re considering for exit, but that has not come up as a material reason, at least that I’ve seen so far.
Jacob: We’re all friends here — this is a friendly environment, not casting blame or shaming anybody. But Dave has a great example of the nature of the problem. He says, “We have over 300 suppliers and we’re not sure how to control the CUI that we send to them. We either need to send them compliant devices or tell them to be compliant. Either way, it’s not feasible.” That’s 100% the reality a lot of companies are facing. They’re essentially primes in a smaller scenario. That problem gets bigger and bigger the higher up the supply chain you go.
Eric: However — from the perspective of an attorney, when you get to “it probably isn’t feasible” — how do I hear that statement? I have this contract requirement I have to flow down to everybody, and I have so many people I have to flow it down to that it’s not economically feasible. Is that an adequate defense if something were to go wrong? And this isn’t to say Dave is wrong — what I’m saying is there are bigger structural issues that require bigger structural answers than saying the contract clause is the problem, or that Dave is the problem, or that NIST is the problem. The question goes to how far you need to verify compliance. There’s a school of thought — some clients of mine use it — that you send down the clause with the CUI in your contract documents, and that’s it. That’s where your obligation ends. You set it and forget it — you tell them what their obligation is, you assume they’re doing it unless you know otherwise. There is a legal argument that says that’s all you have to do. That’s what the big primes do.
Jacob: What’s that famous lawyer saying? Never ask a question you don’t know the answer to.
Eric: That you don’t want the answer to. Both are applicable, sometimes at the same time. [laughter] So I think that’s a perfectly reasonable thing to do in a lot of circumstances. Now, if you’re a company flowing CUI down and you know for a fact or have a strong suspicion that they cannot protect it or are not protecting it, that changes the obligation — the Department of Justice or the Department of Defense/War may think of it a little differently, because that raises to the level of recklessness. But you can assume companies are doing the right thing if you have no reason to assume they’re not, and that just means flowing it down. Some companies take a more aggressive approach and try to verify compliance — send compliant devices they can read the CUI off of. Those lower the risk, of course. It’s a risk-balancing game — how much risk are you willing to take on yourself versus the benefit you get. It’s not a one-size-fits-all answer. Case by case, you have to determine what’s best for you.
Jacob: Here’s a specific question I have that’s probably relevant to Dave and Mike as manufacturers — this is not legal advice, maybe just your opinion. This has driven me nuts for years: the very large prime contractors have a list of approved processors that these manufacturers, who are in between the primes and the processors, must send data and parts down to. So you’re a precision machine shop — you’re machining the parts but not finishing them. You have to send those out to processing houses doing special processes: coating, painting, annealing, heat treating, all kinds of cool stuff. Those processing houses are very small, very specialized. You must send your data and parts only to those companies the primes tell you you’re allowed to. However, you know those processing houses are not compliant with the requirements they need to be. So what does a manufacturer caught in the middle do? On one hand the supply-chain people are telling them, “You must only send it to these companies,” and if they look at their contract clauses, they’re like, “I can’t send it to those companies.” It’s ridiculous that the primes are like, “Well, CMMC is the problem,” but you’re forcing people to send data to companies you know can’t handle the data.
Eric: A lot of this is going to be governed by the prime–sub relationship and what’s in that subcontract — what have you agreed to do and how have you agreed to do it. At that point, you know what I’d do? If I was king for a day and a client had unlimited funds, I’d say, “Let me send a letter — or write it for them to send — and say, ‘Which of these two clauses do you want me to not comply with?'” Make them make that choice for you. But a lot of times you can have a reasonable conversation with folks and just say, “Hey, this is the issue we’re having. How do you want to fix it?” And they’ll recognize that.
Jacob: All right. “How much should a small business actually expect to pay for a C3PAO assessment, and what determines the price?” I’ve heard through the grapevine that this mythical hundreds-of-thousands-of-dollars figure isn’t true. I’ve heard numbers much closer to an average of $40–$50,000 for an assessment, which matches what I’ve personally heard. And apparently that’s also what DoD heard through the RFI response — they weren’t finding out that assessments cost all that much money. Max, have you heard the ballpark? We’re talking price of the assessment, not implementation, migration, licensing — the actual “I decide to get a third party to do it rather than run it in-house.”
Max: I’d say if it’s a simple AVD enclave — all virtual, assessors don’t have to fly out to different facilities, no physical access controls to inspect — it’s around what you stated, 40 to 50, sometimes less. It really just depends. But some of the OSCs who are much larger and have multiple facilities, it’s going to be more. I’ve heard over $100k for several facilities.
Jacob: It’s highly variable. People are like, “Why doesn’t the government just do GFE enclaves for everybody?” It works in the use cases where it works. It doesn’t work in every use case. I’ve heard assessments as low as 25 to 30, getting up into 80 to 100 — it just isn’t a uniform price across the board.
Eric: And the great thing about that — if you can call spending money great — is that as your company is more successful and has more contracts and gets more complicated, that’s when the cost goes up. Companies that have less CUI, fewer contracts with CUI in them, are going to pay a lower cost. So it’s progressive — not politically progressive, but progressive in the non-political sense — where you pay more of a tax the more contracts and the more CUI you have.
Jacob: All right, this is an interesting one, because we saw last week text in an OTA that went out requiring 800-171 Rev 3, not 800-171 Rev 2. So somebody said: “I’ve been hearing that other transactions are not generally subject to the FAR and DFARS. Can 7021 be applied to an other transaction? I was thinking 800-171 can be applied — not sure if CMMC can be. What’s the deal, Eric?”
Eric: Great question. Other transactions are blank slates — well, let me say what they’re supposed to be. They’re supposed to be blank slates, where you start with a blank sheet of paper and the parties — the government and the contractor — agree what goes into that agreement. They don’t always turn out that way. Long story short, there’s no technical or legal requirement that 800-171 or any cybersecurity clauses are included in an OT. That being said, more often than not the contracting officer or agreements officer will seek to put CMMC — not CMMC necessarily, but some kind of cybersecurity requirement — in it, especially if there’s CUI being handled. So I wouldn’t expect a free ride, but there’s no legal requirement that it has to be in there. And there’s a difference, of course, between 800-171 and CMMC. 800-171 is the underlying security regime; CMMC is the verification program for that security regime. So it’s a two-step process. Maybe the OT would require compliance with 800-171 but not CMMC — but you can’t have CMMC without 800-171, of course.
Jacob: Right. Brad says, “I’ve asked this ad nauseam on the Cyber AB town hall: who has the supply-chain risk-prioritization responsibility between data-protection risk in CMMC and resilience/innovation-capacity risk?” Well, you’re never going to get an answer from the Cyber AB, because that’s way outside their wheelhouse. And you’re never going to get an answer from the DoD, because such a person doesn’t exist. There is no one person with a risk-prioritization responsibility to balance all those things. A lot of that decision-making is completely decentralized at the program-office level, and it’s highly variable. If you’re working on legacy programs, commodity parts, from one component of the DoD, or you’re working on super high-speed cutting-edge stuff, that could be a different risk decision. Like I said, we’ve seen OTAs as of last week requiring 171 Rev 3. We’ve seen stuff coming out that still requires CMMC verification. The language we heard from one program office was, “The DoD CIO suspended CMMC — we still want to know if you did it.” And everything in between.
I feel like this happens — people refer to the primes as monolithic. They see Lockheed as a monolith, when in reality it’s a huge conglomeration of multiple companies and corporations that have been acquired over time under the banner of Lockheed, and within those companies they all have their own program offices, cultures, customers, relationships, and tolerances. All the big primes are like that. All the program offices within the DoD are like that. So there isn’t a single person, which is part of the difficulty the DoD has had over the years — having a top-down policy while trying to have assurance the requirements are implemented. It’s tough to get everybody to move in the same direction within the department.
Eric: I’ll add a couple things. One, that discretion was built into the rulemaking from the start. That is not new — the contracting officer could decide they don’t want CMMC in right now, and they could do that for the next two years. That being said, if you go on SAM.gov today, you’ll see there are some contracting opportunities that have a Level 2 self-certification requirement. So CMMC is still happening, whether third-party is suspended temporarily or not.
Jacob: And to your point about the 2028 language in the final rule from 2025 — there was never, ever such a thing as a November 2026 deadline for everyone to achieve CMMC Level 2. Ever. That was never true in the history of the CMMC program — 1.0, 2.0, 10.0. It’s not real. The primes decided they wanted a bunch of their suppliers to be certified by November, so it didn’t really matter what the DoD policy was. Which is why I cannot wait to see what’s in the recommendation. I was just talking about this at Summit 7 Live in Boston earlier this week. They said, “We’re going to go back and review the program and the policy.” And I’m like — to say what? To say there’s no November deadline? It already says there’s no November deadline. What are you going to change it to say? There was already all discretion and optionality at the program-office level. So what are you going to do? Make a deadline that everybody’s going to accelerate? Say it’s all up to discretion? It already says that. So how do you change the policy to be more flexible than it already was, when there were no deadlines?
Eric: I don’t know.
Jacob: All right. Dave said, “Is anyone going to CS5?” Eric, you’re going to be there, right?
Eric: Yeah, I’ll be there with Ellison. I have a session there as well. Look forward to seeing everyone. Jacob, you are too, right?
Jacob: Yeah, I’ll be there. I’m presenting the morning of day one, talking about 800-172 versus 800-172 Revision 3. We’ll see if that’s relevant two weeks after I give the presentation, depending on what the department is doing. But CMMC Level 3 is designed to verify the selected requirements out of 800-172. The DoD originally only picked 24 of the requirements out of 800-172. 800-172 Revision 3 is way, way bigger in terms of the total set of requirements they could select from. And I’ve heard through the grapevine that a lot of the people on the CMMC task force were asking, “Why did you only select 24 requirements?” So — I don’t know. It doesn’t sound great, as far as “they’re going to come out of the review and there are going to be fewer requirements.” So maybe the presentation will be more relevant, because we can talk about a bunch of stuff that ironically was never relevant before the suspension but might suddenly become extremely relevant. But yeah, I’ll be there, presenting that first morning.
All right. Fun question, Eric: “Can my prime or customer require CMMC even if the DoD isn’t currently requiring a C3PAO assessment on my contract? Kirsten Davies said no more C3PAO requirements — why is Lockheed telling me to go get a cert?”
Eric: That’s a common misapprehension. Yes, they can. Contracts between prime contractors and subcontractors are commercial contracts — private parties can agree to whatever they want. So if you’re a subcontractor and a large prime is saying you have to get a third-party assessment, you could say, “No, I’m not going to,” and then it’s up to them to decide whether they want to still do business with you. If there’s a dispute over a contract like that, it’s usually meted out in state court. It’s not a special government-contracts court, even if there are FAR and DFARS clauses in it.
Jacob: Eric, that’s great. All your lawyer talk about contracts, that’s fine. There were many people who published their RFI responses or made posts about them, and they were like, “You know what would really fix this problem? If the DoD would just control what the primes are doing between the primes and their suppliers.” Can they do that?
Eric: Not without some kind of rulemaking. There has to be some kind of rule the prime would agree to that says they can’t do X. I haven’t seen that happen with this yet, and I don’t expect it to.
Jacob: Which is also a fun twist. I cannot wait to see what comes out of the review, because all we did for 60 days was demonize regulations and red tape and bureaucracy — and the only way you’re going to be able to change things up, down, sideways, expand, contract, is through — say it all together at home, everybody — rulemaking. The only way you can do it is through regulation. So I don’t know how you’re going to get anything done. What, we’re just going to write a bunch of memos that are going to get overturned? You’ve got to go through the rulemaking process. And 2028 isn’t that far away. So you’d better get that report out and get those proposed rules written pretty fast.
All right — somebody said, “We have a $1.4 million defense contract.” Congratulations. “Should we pay for a C3PAO assessment, or just do the required self-assessment for now?” First question to you, Eric: should people do something that’s not in their contract? Second question to you, Max: have you heard people talk about benefits they’ve acquired from getting their cert, whether it was something they had to do or not?
Eric: You can do something like that. I’ll leave the benefits to Max, but there are some benefits to getting a C3PAO assessment even if it’s not required. Part of that’s going to be: where do you think your business is going? Is it just a $1.4 million contract, or is this an area where you expect to expand and have more contracts and opportunities? Are your teaming partners going to expect that you have a third-party assessment and see benefit in that? There’s nothing that says you have to right now, but if I was a defense contractor and I could afford it, I would do it. There are also benefits from a compliance standpoint — False Claims Act risk goes way down.
Jacob: Let me pause you right there before we get to Max. A lot of LinkedIn lawyers out there really don’t like what we’ve said on the podcast. They’re like, “Getting a C3PAO cert means nothing in terms of protecting you from liability.” It seems odd to me that it wouldn’t count at all for anything. I’m not saying it’s a get-out-of-jail-free card, but the C3PAOs are taking on quite a bit of risk by being a C3PAO in the first place. If somebody comes after you for False Claims Act and you have a CMMC certification in hand, at the very least the C3PAO is going to get sued — that might not necessarily get you out of it completely, but what’s your take on this back-and-forth? There are a lot of non-lawyer people, myself included, going, “It helps / it doesn’t help / it helps.”
Eric: You said it perfectly — it’s not a get-out-of-jail-free card, but it certainly gets you a lot of the way there. A couple things: one, DOJ and whistleblowers are looking for soft targets. A company that has a third-party assessment is no longer a soft target — they’re going to look for easier cases to win. The second is, we all recognize a CMMC third-party assessment is a point-in-time assessment. On that very day you got assessed, you were compliant. You may not have been compliant the hour before or the hour after, but right then and there you were compliant. Then it’s up to that whistleblower or the DOJ to show what changed over that time to make you non-compliant with X, Y, and Z control — and that’s not necessarily an easy thing to do. So a third-party assessment is certainly very helpful in thwarting potential False Claims Act cases and complaints of non-compliance. It’s well worth the risk to get one versus the cost of having to deal with a False Claims Act case or an investigation — a third-party assessment is much cheaper than that.
Jacob: That’s a good point. Max, have you heard people talk about benefits from customers — perception, work won?
Max: Absolutely. We had a scenario — a very small manufacturing client — go through an assessment, achieve their Level 2 certification, and then send an email to Scott saying, “Thank you guys so much. We’ve just been awarded a million-dollar contract. This is amazing. We would have never done it without Summit 7, and we got this because of our certification.” We’ve heard many, many stories like that. I’d say paying for your C3PAO assessment and getting that Level 2 certification is an investment in your company. You’re going to look better and more appetizing to those prime contractors having it than you would just having a self-assessment.
Jacob: Honestly, we’ve got to talk to the team internally, because we get those emails and messages all the time. We need to have them auto-redacted and then just have a feed on the website of the success stories, because we get them all the time.
Something you mentioned, Eric — we’re getting up to an hour here — you talked about CMMC assessments being point-in-time. This is coming up more and more in the DoD CIO’s statements. We all know people are struggling with even a once-every-three-years point-in-time assessment. The DoD CIO has been very adamant about wanting continuous monitoring of these environments — “continuous and contiguous,” I believe she said at Billington. To me that sounds like some sort of active, constant monitoring of a company’s control environment. My question to you as an attorney: how excited are you to absolutely dunk on the idea of the government putting continuous-monitoring agents inside of non-federal systems? There’s no way that process would be allowed to work, even if they had the resources to deploy it. They can’t mandate that they put government — “You’re going to put cameras on my CUI system?” [laughter]
Eric: You’d have to agree to it in your contract. And guess what? A company that agrees to that is going to charge a lot more money than a company that’s not, because they’ll have to have the systems in place to ensure that continuous monitoring doesn’t show a control falling off just for a couple hours and coming back. It’s very similar to another initiative the department’s doing — they want a line into the financial systems that contractors have, in order to see what their profits are like, even in firm-fixed-price scenarios, which is kind of wild. So on one hand it’s “laissez-faire, we’re hands-off, we’re business-friendly,” and on the other hand it’s “we want lines into every part of your company to know exactly what’s going on at any moment.”
Jacob: The red part of red, white, and blue is getting real bright. You know what I’m saying, everybody? That’s all I’m going to say. That’s a topic for another day.
Last question, Eric, before we wrap up. The CIO, at the beginning of the suspension period, was talking — even in her video that came out in the media blitz — saying to the people who have already paid for C3PAO certifications during the suspension of the requirement, that “their efforts were not in vain,” sort of hinting there’s going to be preferential treatment for people with the cert, that they’ll somehow make them whole. Really, this is the only new policy wrinkle I see in the debate, outside of all the RFI topics — CUI marking, scoping, requirements, flow-down. Those are topics we’ve analyzed for years and years across multiple public comment periods. But what is the CIO talking about? What would the DoD be able to do that wouldn’t cause a flurry of lawsuits — rewarding people with the cert who weren’t required to get it, but got it because they thought they were required? What’s your crystal ball say about how that plays out?
Eric: If they actually did that — rewarded people for getting a C3PAO assessment — one way is in a best-value scenario: give additional points. DHS did something similar a few years ago where they said, for best-value scenarios, “We’re going to evaluate your cybersecurity, and if you have good, neutral, or bad cybersecurity, it’s going to go into the best-value calculation.” So they could do something like that — maybe not make a C3PAO assessment the ultimate requirement, maybe a self-assessment too, but something like that is helpful in a best-value scenario. Now, there’s also lowest-price-technically-acceptable, which they say is on the best-value continuum — I don’t like that they came up that way, but that’s going to be harder with LPTA unless you make the C3PAO assessment a prerequisite, which I imagine they’ll never do.
Jacob: It’ll be interesting. They said a lot of stuff at the beginning of the suspension, and I’m not sure how they’re going to get all those points to line up in a way that’s coherent. I’m here with my popcorn like everybody else, because it’s quite the puzzle they’ve set for themselves — with the announcement that, like we said at the beginning of the show, probably late September, early October, depending on when you start counting the 60 days and how much you believe they’re even interested in publishing a lot of their findings before the midterms.
All right, everybody — that was an hour. Max, thanks for stopping by. Eric, thanks for stopping by — feel free to stop by anytime. It’s always fascinating to hear what you guys are thinking and seeing out there. If you’re finding this after the stream is over, you can still add your questions and comments down in the chat and we’ll add them to the queue for next week. Go to cuihotline.org, leave a message at the number — no time limit — or leave a question through the form. Find us on LinkedIn. Make sure you’re following Eric, make sure you’re following Max. Send us DMs. You can find us at summit7.us. Find us at CS5. And for all these legal questions that come up, because we’re talking about contract requirements — make sure you reach out to Eric, because he’s easy to get a hold of, he’s a really nice guy, and he knows what he’s talking about. We’ll see you guys next week. Thanks, everybody.
Contact
Speak With Our Team
Our team of compliance and cybersecurity experts are on standby and ready to help. We’ll walk you through what you need and what to expect.
