A CMMC Pause Deep‑Dive Review with Brett Cox | Boeing

Daniel Akridge and Boeing’s Brett Cox — who was one of five industry reps in the recent DoD CIO meeting — unpack what the Phase 2 suspension actually means. The core message: this is a pause to modernize CMMC, not to kill it, and contractors should keep implementing the underlying requirements.

Key takeaways:

  • Pause, not stop. Phase 2 C3PAO certification is suspended (and any early C3PAO requirements pulled back), but Phase 1 stands: self-attestation for Level 1 and Level 2. The CIO signaled openness to industry input, not a made-up mind.
  • Do NOT stop DFARS 7012. 7012 and 7021 are both in the contract — you still must implement all 110 requirements / 320 assessment objectives of NIST 800-171 Rev 2. CMMC is just the verification of that.
  • The real problem is understanding, not lying. Most failures come from people checking boxes without evidence (e.g., “we do MFA” while a single-factor side door exists). Brett wants more consistent assessor training so C3PAO A’s work can be trusted by C3PAO B.
  • Resiliency is coming. 800-171 only covers confidentiality; the CIO wants the full CIA triad (availability, integrity) plus modern controls — “brilliant at the basics” already reaches beyond Rev 3 (phishing-resistant MFA, backups). So expect more requirements long-term, not fewer.
  • FAR CUI is the sleeper. It puts DFARS-7012-style requirements (FedRAMP, 800-171 Rev 3, 72-hour reporting) on every federal agency, with ODPs setting the parameters for you — a huge wake-up call few are watching.
  • The new floor is real. Killing 7019 and reworking 7020→7997 removed the old “-203 to 110, post any score” era; conditional Level 2 now needs a minimum 88/110 (good for six months). That alone shrinks the eligible supply chain.
  • Certifying is still worth it. It gives primes assurance, can insulate you from False Claims Act exposure, and DIBCAC has reportedly de-prioritized companies with a C3PAO assessment already booked.
  • Two closing asks: respond to the RFI (only ~60 comments so far — not enough), and stay the course.

Transcript

Daniel: Hello everybody, and welcome back to That CMMC Show. Today we’re going to talk about the hot topic, and that’s the DoD CIO CMMC Level 2 suspension notice — dun dun dun. A lot of dramatic pause there. I know it’s been a while since the last podcast. I was actually out getting married a few months ago. And now we have an incredible guest with us — a returning guest, at that — Brett Cox, to talk about the latest and greatest CMMC news. Brett, how are you? For the people who don’t know you, give a little intro about yourself.

Brett: Hi, welcome back, guys. Glad to see everybody. So, I am Brett Cox. I’m the principal for our cybersecurity oversight office, and what we also call our DFARS/CMMC program management office, at the Boeing Company. So it’s my team who’s responsible for getting the entire Boeing enterprise and our subsidiaries ready for their CMMC requirements, so they can continue to compete in the marketplace and win contracts.

Daniel: I love it. And that brings us to the topic everybody wants to talk about right now. The DoW CIO released a CMMC memo suspending CMMC Phase 2 specifically. Phase 1 is still on the table, which requires self-attestation for Level 1 and Level 2 — Level 2 with minimum SPRS entries — but certifications for contract award are not currently a requirement during a review period. Now, I’ve talked to some people who happened to meet with the DoW CIO last week, and I would love to hear your take, Brett, on the memo itself: the general feedback and attitude of the meeting, how everything went. Give the people a little bit of an update here.

Brett: Yeah, absolutely. I’m not sure how many people were surprised by the memo that came out, or the suspension — the pause — in the CMMC Phase 2 requirements, because we were having trouble in the defense industrial base building compliant supply chains. When you get the Cyber AB’s numbers each month at the Cyber AB town hall, they update us on how many companies have their CMMC Level 2 C3PAO, and we are still estimated below 2,500 before November 10th, before Phase 2 would kick in. And that’s a very small part of the defense supply chain, especially within the defense industrial base, based on the Department of War’s estimation in the 48 CFR of how many companies would need CMMC Level 2 with a C3PAO requirement.

So that pause may not have been unexpected for everyone, but the timing on it was interesting. And it also came in conjunction with a memo by the Honorable Duffy, the OSD — the Under Secretary of Defense for Acquisition and Sustainment — that put some more parameters around it: that it wasn’t just a pause on the CMMC Level 2 requirement for a C3PAO that’s supposed to occur within Phase 2 going into effect November 10th of this year. He also addressed the fact that the CFR gave the department the ability to pull the requirements forward one year from the next phase. So we were, in the defense industrial base, seeing C3PAO requirements during Phase 1 — which was perfectly fine, it was an option that was allowed, completely understandable. But it wasn’t just a suspension of Phase 2 going into effect on 10 November; they also have to bring back and pull back any of the C3PAO requirements they’ve already been leveraging. So it did take a little bit of rework on the different customers within the Department of Defense — Department of War — to make sure they cleaned up their contracts and are meeting both the Honorable Davies’ requirements and OSD(A&S) — for Acquisition and Sustainment — going forward, to make sure everyone was on the same page. So what we saw was a pause, but no change in our CMMC Phase 1 requirements, which allow CMMC Level 1 — which is always a self-assessment — and the bifurcated requirement of CMMC Level 2, where the self-assessment requirements are still able to be leveraged under the 48 CFR Part 204.

Daniel: And with that, I think a lot of people see “suspension” and think, “Oh, CMMC’s dead,” because there have been a lot of false starts of CMMC, right? We’ve been in the industry and space long enough — we can count on probably two hands the number of times people really thought CMMC was dead. Now, I know that Corin and Fernando and other people got to meet with the CIO last week, and the general attitude is not “CMMC is dead.” It’s that the CIO is taking a really hard look at the CMMC program to figure out how to modernize it, where all that looks possible, to make it more digestible by the defense industrial base — not to forsake national security, but to provide some support when it comes to CMMC and even that certification process. Can you give us some highlight reels of how that conversation went, and even what the CIO might be thinking along these lines?

Brett: Yeah, I was honored to be included in the invite to be in that meeting, and it was a great meeting. There were five of us from outside of the department who were invited to come and speak with the CIO and the senior members of her staff — including the one performing the duties of the deputy CIO, the wonderful lady who’s leading the task force, the industry representative, and also her chief of staff. So it was a great meeting, with just five of us having a very good and candid conversation with her and her leadership team about what this is going to look like.

And you’re absolutely right — this is not the end of CMMC. And that was made very clear: the intention of the pause was not to kill CMMC. The intention of the pause was to look at it and ask, “Are we doing the right things? Have we addressed all of the things the department needs to enable the warfighter to extend power against the enemies of the United States and win without prejudice?” And one of the things the CIO brought up was resiliency. Of course, we all know that 800-171 is strictly focused on confidentiality. We accidentally pick up some integrity because of the encryption requirements, but it’s focused on confidentiality, not all three legs of the CIA triad. There are a few controls that involve integrity, but they’re not intended to address integrity directly, and availability is not addressed at all. When we talk about things like backups, it’s about protecting the confidentiality of the backup, not that we perform backups in the first place. You can pass that control by saying, “We don’t do backups. We’re good.” There’s nothing to prove there. So the addition of resiliency in the conversation, and, of course, the speed of acquisition — the speed of getting the component, the asset, the service to the warfighter — is where they are coming from. How can we modify CMMC to address all of the department’s requirements, not just address confidentiality?

So I think we will see changes to CMMC. The task force that has been put into place, and the different tiers of the task force, are going to be able to give them value-added feedback. And I think in some cases, some decisions have been thought through. But I picked up a very open opportunity for her and her staff to listen to what we had to say, and what others have to say, and take that into account. So I don’t think we’re in a situation where the mind’s been made up and no matter what you say is going to change anything. I think there is open and honest communication there. Now, we had the CPAC authority in the past, where we were able to form a consensus, and the new mechanism is similar but not exactly the same as CPAC. But I think it enables and empowers the government to extend invitations to industry and have those conversations again — even if we’re not forming a consensus, at least to get the opinion, and involve those of us who are in the trenches, who have been in the manufacturing environment, who have been in cybersecurity for years, to give our feedback of how things are really going out there and where the problems are: here’s what we know, here’s what you’re seeing, let’s make sure we’re all on the same page.

Daniel: And I love that. One of the most interesting stories I’ve had in talking to thousands of people in the DIB — one guy came to me at my door and he’s like, “I think I’m good with CMMC.” I said, “Fantastic, I’m amazed.” Small machine shop in Alabama. I was like, “Tell me how you’re doing it.” “Well, we took our server and put it in the attic and locked the door.” And I was like, “Oh, well, there’s a little bit more you’re going to have to do than that to meet the requirements.” But I love hearing the side of not only what it takes to protect national security — what do we have to do to protect the warfighter, which has to be a real consideration, and has been through DFARS 7012, now DFARS 7021 — but also, on the other side, what can we do, and how can we rely on industry to help those people meet the requirements they need to make? Whether that’s technical implementations, or appropriately scoping CUI before sending it downstream. Maybe not everyone needs access to CUI moving forward, where a lot of people might have had access to it previously. Maybe they don’t even need it anymore. Maybe they’re good with CMMC Level 1. So that’s really promising to hear — CMMC is not dead, and they’re open-table for the industry to communicate with the CIO and her office, which I think is amazing, to figure out how we can bring both of these worlds together to meet both needs.

CMMC is a good program. It’s been around for a long time, and it’s just a validation of the requirements. And I think that’s one of the interesting things we’ve already talked about a little bit, Brett — the CMMC pause, even in the memo the CIO published, said don’t stop DFARS 7012. CMMC Level 2, especially at a C3PAO level, which is a certification level, is just a validation of the implementation of DFARS 7012 — which was supposed to be in full effect December 31st of 2017. And so my question to you is: if I’m a small business now, or a medium or large business — somebody doing work with the DoD or DoW — should I stop implementing 7012 because CMMC’s paused now?

Brett: No, absolutely not. In fact, for those involved in the contracting aspect of things — the 7012 clause and the 7021 clause are both in the contract. There’s not a one-or-the-other. Both are included. So that means we have to, under the DFARS 252.204-7012 clause, meet all the requirements of NIST 800-171. We have a class deviation that says under Revision 2 is what we’re currently following, and CMMC says the same thing — CMMC says Revision 2 of NIST 800-171. So they’re both saying we need to make sure we implement all 110 requirements, all 320 assessment objectives, of NIST 800-171 Revision 2, to protect the confidentiality of controlled unclassified information. So no, we absolutely should not stop. We need to stay the course and ensure those requirements are still being met.

One of the things I brought up during our meeting was that I think one of the problems in industry is not so much that everyone is out to lie to the government. Of course, there will always be bad apples in the bunch. But more, I think the problem is that people don’t understand the requirements, and when they read NIST 800-171, they go, “Oh, of course we’re doing that. Check. Yeah, we’re doing that too. Check, check, check, check.” And they don’t know that they need to actually come up with evidence and prove it. They’re not being hard enough on themselves. They’re like, “Well, of course we’re doing multifactor authentication,” but then they’ve got a single-factor authentication something-or-other that is a side door into the network. So it’s important that we continue to train companies and make available what these requirements actually mean, how you meet them, and how you prove them. Because I think one of the things that’s missing is the consistency of that. When a C3PAO goes into a company — just like DCMA DIBCAC would do, and still does — they’re looking for the same things. And even though every implementation is going to be different — every assessment is a very unique and wonderful snowflake — the control is the control, the requirement is the requirement, but your safeguards and countermeasures may look different. It may be something the DCMA DIBCAC or the C3PAO has never heard of before. Doesn’t mean it’s wrong. So there has to be a little bit of give and take. But we also have to do better training in our community.

As part of that — I’m a lead CCA and I’m a CCI, so I’m teaching CMMC — I don’t treat my classes like a boot camp, even though that’s the great name everybody throws on the class. “It’s a boot camp!” Because “boot camp” sells classes. That’s what people want, they want a boot camp. I’ve been through boot camp in the Army, and — no, no, I don’t want that again. No, please. No, thank you. I made it through that, and we’re not going back. But that is what ATPs have right now, and what attracts people to them. But we’re not setting the stage for how to conduct the assessment. We’re not setting the stage, as a CCI community and in our classes, to know that we’re looking for equivalent things across the control, and that all C3PAOs are basically asking for the same kind of evidence. C3PAO A should be able to completely trust the work that C3PAO B did. And that’s not the case, and we need to get to that spot. We need a common understanding. We need more training resources out there — maybe even provided by the department — of what’s available for people to see. At NDISAC, we do a monthly class that everybody is invited to; there’s no cost. The cyber academy is what it’s called. But it doesn’t go into the details of “this is the type of evidence you should expect to present for control 3.1.6.” And that’s where we need to be. From the C3PAO standpoint and the DCMA DIBCAC standpoint, we should be looking for the same things. We shouldn’t be straying too far from the objective. It is an assessment, not an audit. But it’s also not cut and dry. It’s not going to be perfect. There is no sterile environment that exists out there in the real world. Everybody deals with different problems, has had different experiences, and the tools they have are the tools they have. We can’t mandate buying a particular program to accomplish something that can also be accomplished with administrative controls.

Now, that’s going to change a little bit in Revision 3, of course — which is our other hot-button topic from a couple weeks ago; we got a drop on that too. And is that even a more frightening aspect than CMMC Level 2 C3PAO? It could be, especially when those two things combine — you’re going to have C3PAOs looking for the Level 3 requirements and the ODPs, the organization-defined parameters, that the DoD/DoW has set.

Daniel: I might have strayed a little too far from your question, but I think this is great. To summarize the answer, at least the way I heard it: don’t stop doing DFARS 7012, which is the same framework as CMMC Level 2 — just verification of that. And guys, there’s something bigger coming down the line. One of the things before we get to that bigger thing — that fun FAR CUI conversation — one piece of feedback, if the DoW is listening (I don’t know if they’d listen to this or not): the DoD Assessment Methodology is out there. I know people who have gone there and filled out, to your point, Brett, the 110 controls — yes, no, yes, no, yes, no — and scored themselves, but they weren’t aware of assessment objectives. They weren’t aware of whether they were applicable or not, because they were on non-FedRAMP clouds. So you have this DoD CMMC FAQ, you have NIST Special Publication 800-171A, you have CMMC Level 2 scoping guidance — it’s several document sets. You really have to look through the lens of all of them to assess yourself correctly. And I agree — I don’t think people by nature are trying to be malicious and cover themselves. I think there are some organizations we found out through False Claims Act cases that have done not only a poor job but at points even a malicious one — look at Aerojet Rocketdyne, where they falsified an entry and intentionally knew that. But on the same side, a lot of the industry just wants to do the right thing. And to your point, education — especially for people below the cybersecurity poverty line, that terminology that loves being thrown around — it’s really important to have education for those people.

But I want to double-click on that FAR CUI thing. One of the things we talked about — you just mentioned NIST 800-171 Rev. Well, with FAR CUI pending, with the same FedRAMP requirements, and NIST 800-171 Rev 3, and 72-hour incident response — man, this sounds a lot like DFARS 7012, except for every federal agency, and just so happens to be on the latest version of NIST 800-171. So at some point we’re going to have CMMC collide with FAR CUI, because FAR CUI sits on top of DFARS, right? FAR is at the top, DFARS is right below it. And the DIB should be worried, but other federal contractors dealing with controlled unclassified information are about to get a huge wake-up call. This isn’t just going to be the DoD asking you to protect controlled unclassified information — it’s going to be every federal agency, potentially starting at the end of the year. I just saw the public comment period close, and now it’s back up for review for final publication. This thing’s a real thing in motion today, and not a lot of people are talking about it. Everyone’s focused on CMMC when FAR CUI is about to strike, and no one even knows it’s out there yet. So I hope this is a PSA for people unaware of that future contractual clause. Any commentary on that, Brett?

Brett: You know, I think the key here is that no matter what the government puts out — and it’s going to be part of the revolutionary FAR overhaul, the different aspects of trying to make sure everything within the defense industrial base is secure and resilient — that’s expanding now to the other executive branch agencies. Right now, we’ve had a mishmash of agencies that have adopted the CUI model. We even have an exception within the Department of War, where three of their bureaus are exempt from the CUI rule — they are still under FOUO, because of various reasons. But getting the entire government on the same page is going to be huge, because right now it’s a patchwork. We have rules that apply to the Department of War that do not apply to NASA, and NASA has rules that don’t apply to other agencies, etc. And in some cases we have people taking three different CUI trainings throughout the year, because they support multiple executive branch agencies who have adopted the CUI model.

Daniel: Yep.

Brett: But one of the things, going back a little bit and connecting to the question of “what should we do now, where should we be right now” — implementing NIST 800-171, even if its current state is basic cybersecurity hygiene, is not just going to protect the controlled unclassified information and the federal contract information. It’s also going to protect your proprietary information — the reason you’re in business, what discriminates you from your competitors, what makes you unique and able to provide a product or service to maybe not just the government but also the commercial sector. Both public and private sector. By following these basic tenets of cybersecurity hygiene, you’re going to protect your intellectual property from being stolen and used against you — for somebody to undercut you in the market with your own knowledge.

Daniel: Yep. And so, not only is it a contractual obligation so you can win more business, it’s also protection of your own IP that you don’t want out there. Nobody wants their secrets on the worldwide web, right? Nobody wants them on the darknet. Everybody wants to protect this. And it just so happens that managing and protecting CUI is a really good framework for managing your own proprietary data as well.

Brett: Yeah. Is it perfect? No, absolutely not. It is a basic set of requirements. Should we implement risk-based decisions in 800-171, or maybe as part of CMMC — a risk-based decision of, “Well, here I’m not meeting an assessment objective, but it’s four layers deep within my very, very tough outer shell of controls, and somebody would actually have to pull an Ocean’s 11 caper to get to this thing to compromise it in the first place.” Should that be a reason? Should one objective — if there are mitigations, if there are risk-management techniques — cause them to fail an assessment? And the answer today is yes, it does. If you can’t make this happen within 180 days, if it was POA&M-able in the first place — I turned it into a verb, everybody, it’s okay — if it’s POA&M-able in the first place, I still have to fix it within 180 days. Well, a risk-based decision — companies have those all the time. And right now, in 800-171 Revision 2, the risk-based decisions we can make involve timing. There’s nothing that stated, before CMMC, before 32 CFR Part 170 came out, that I needed to do my vulnerability assessments annually. I could have said I do mine every five years, whether it’s needed or not, and that would have been — well, you’d have gotten a cross-eye — but it would have been acceptable. It meets the requirement. But that’s all part of what risk is, and that’s what ODPs are as well: addressing that risk, and “this is our upper boundary for what’s acceptable within that risk.” So if we can address the upper boundary of what’s acceptable, why can’t we add other things to it and make it a more comprehensive look at the entire ecosystem, instead of saying NIST 800-171 cut and dry is it?

Daniel: Well, and that’s why I really like the understanding of NIST 800-171 as an add-on to an already-built cybersecurity program. It is not a standalone cybersecurity program. It’s a bolt-on — confidentiality is the goal, and it has overlaps with the CIA triangle. Not explicit overlaps, but maybe indirect overlaps, we’ll call it. And so that’s the interesting thing when we look at ODPs with FAR CUI. ODPs, for those who don’t know, are basically variables set — in this case by the DoW — on how they want you to, maybe, the frequency of things they want you to review. Maybe instead of you getting to decide “I do a risk assessment every five years,” maybe the DoW says you have to do it every year, or every six months. So because that’s coming out with FAR CUI, people used to play the guessing game of “I don’t know what’s enough, what’s too little, what’s too much, so I’m just going to throw a dart at it, or ask around.” Now those are actually going to be set for you. So it really should be easier, even for small businesses and even MSPs helping small businesses, because they actually have defined parameters.

Now, what’s interesting — I’m going to take a pivot upstream a little bit. In this world of CMMC, there have been a lot of certifications. Brett, you mentioned it before — I think we’re over a thousand CMMC Level 2 certifications at this point. And Cyber AB, I think, has a town hall here soon to update everybody on that. Depending on when you’re watching this — Tuesday, the 20th of September. Wow, it’s actually the evening of this recording. We’ll get an update on the count. And because of that, I’ve had a lot of subcontractors ask, “Do primes really see value in organizations still getting certified within the suspension? Is it still a worthy cause to validate your implementation of 171 to an independent assessor?”

Brett: So, a personal opinion on that: if I am a prime, or somewhere along the supply chain — but the key is that I have subcontractors — if I have somebody who has validated, using a third party, that they are meeting all the requirements, then I have a level of assurance that they can protect my information as well. So yes, I would still like to see that if I am a business. I’d like to see that they have an independent third party, just like we do with financials. We do the same thing with financials — if you’re a publicly traded company, why can’t I have that same level of assurance that you’re at least meeting a minimum set of requirements? Are you going to be perfect? No, nobody’s ever going to be perfect. But if I can at least set that floor, it’s going to be fantastic.

The other thing is that by continuing on and getting a C3PAO assessment, you’re also insulating yourself from a False Claims Act accusation. As we all know, the False Claims Act is typically a whistleblower who initiates an action, and then whether it’s a qui tam prosecution or is actually turned over to the Department of Justice — your ability to defend yourself against this accusation, whether it’s true or a false accusation just by a disgruntled employee, is that if you have a third party that has looked at it, then you can present that documentation and say, “See, I have an independent third party that does not have any conflicts of interest who has validated that I am meeting these requirements.” And hopefully it can stem the tide of any additional prosecution under the False Claims Act, because even if it is just a disgruntled employee, it’s still going to cost you as the company money to defend yourself.

Daniel: Yep. And the sooner you can make that end, the better off you’re going to be. I’ve even heard of DIBCAC saying, “Hey, if you’ve got an on-the-books scheduled C3PAO certification and DIBCAC calls you,” they’re actually taking that and saying, “Okay, now that we know you have it, we’re going to move on to somebody else.” They’re even using it almost as preemptive validation of “Oh, well, you must be confident enough to go through a certification. Guess what? That’s confident enough for us too. We’re going to move on to somebody else.” They made a risk-based decision.

Brett: That’s right. Medium or high assurance assessment. There you go, there’s my words there.

Daniel: All right, Brett, got one more for you, and then my favorite part, closing remarks. So, here’s an interesting little conundrum a lot of people, I don’t think, are realizing yet. DFARS 7012, right? That’s just “implement things” — have an SSP, have a POA&M, have policies, have procedures. DFARS 7019 rolls up on the scene and says, “Hey, we actually want you to do a score.” 7019, 7020 — “we want to see your posture of how many of these controls you’ve implemented.” Introduce the DoD Assessment Methodology, 5-, 3-, and 1-point controls, ranging from a total of negative 203 — which is the lowest you can go, because it’s a reductive scoring method — to a 110 perfect score. Well done. And what’s interesting is that they struck DFARS 7019 not too long ago and modified 7020. So now the requirement to enter your score into SPRS is not applicable on new contracts. But you know what is? DFARS 7021, the CMMC clause, and conditional CMMC Level 2 — even self-attestation — is a minimum 88 out of 110.

Brett: Mhm.

Daniel: So people went from being able to have basically any score they wanted — negative 203 to 110 — to now having to have a very, very high minimum score, and they can only have that for six months. So one of the things I always like to highlight: CMMC is not dead. It didn’t revert back to the old days of just posting whatever score you want in there. You actually have to do a lot of significant work in relation to implementing 171 from DFARS 7012, and show that you have that minimum baseline, as a sub or as a prime, to be able to get work through. So what’s your thought on the minimum score and the thresholds you’re seeing primes set? I’ve seen the CC form, I’ve seen other forms that primes have put out, and 88 out of 110 — that’s still going to be a really small supply chain that people have to work with, even if a certification never takes place.

Brett: Yeah. And I remember, when we first started talking about CMMC — I can’t recall the company, and these statistics are probably going to be off by percentages — but it was, out of 300 companies that were surveyed, the number that returned the survey… there were less than, I want to say, 30% — maybe 32% — that said they could get over a 70-point score on an assessment. So it was a very low percentage of the defense industrial base that replied and said, “Yeah, I could score more than 70 points on a self-assessment.” So I think we’ve always thought that someday there would be some kind of scoring tier. For this type of program — you look at uniforms. Uniforms that absorb infrared, or have radar-absorbing material, or are fire retardant, etc. — those could still be considered controlled unclassified information. Does that require a 110 out of 110 to protect the sanctity of how uniforms are made, versus a stealth bomber? Are they equivalent? Should there have always been tiers? I don’t know. But by having this minimum floor of 88 points — because I saw it the same way you did, that the removal of the 7019 and the change to 7020 becoming 7997 and removing the self-assessment requirement — the first thing that popped in my mind is, because you’re going to have to have a CMMC Level 2. Now, there’s a gap there, because they don’t have to put the clause in the contract until 2028. So, in 32 CFR Part 170.5, they have the ability at the program level to waive the CMMC requirement. So now there’s a three-year period where somebody might not have to self-disclose what their self-assessment is or was at the time — that was good for three years. So did they do that a little too early? Maybe. But I think the intention was to set that floor: to do business with the Department of War, you’re going to have to meet a minimum of 88 points, and it has to be at that conditional level.

So there are still going to be things that are not POA&M-able, and maybe that’s one of the issues we’re having — should there be more things that are POA&M-able at this point, and should we extend the 180 days? We need to make a risk-based decision on that and really look at what the risk is of extending it by another 30 days, another 60 days, or of extending it if I have mitigating circumstances — if I have something in place that protects my multifactor authentication requirement that I’m not meeting. And one of the examples I’ve enjoyed hearing is passkeys.

Daniel: Yep.

Brett: Passkeys are all the rage right now. Passkeys are considered to be very secure. Guess what passkeys aren’t? They’re not MFA. They’re not. So if you have 100% implementation of passkeys, how do you pass 3.5.3? It’s a fine question. But we had the ability with the 7012 clause to petition the DoD CIO’s office for alternate controls. We lost that in the 7021 clause. There’s no ability to petition the DoD CIO’s office for alternate controls. Could that be one of the risk-based decisions we bring back? A zero-trust architecture, completely, honestly — full ZTA — with passkeys, and it couldn’t pass NIST 800-171.

Daniel: That’s what’s interesting — addressed. I look at “brilliant at the basics,” right? The CIO published this the same day the memo was released about the suspension, and things like phishing-resistant MFA. So we’re looking at things like passkeys and other forms to have phishing resistance. That doesn’t exist in Rev 2. Phishing resistance is not a requirement in Rev 2. It’s a good idea to have it; it’s not a requirement. And so you start looking at, are there even enhancements to the current baseline — which some of what “brilliant at the basics” has, right? Do backups. Not a requirement under Rev 2. If you do it, you’ve got to protect it, though. And phishing-resistant MFA — not a requirement under Rev 2. But do we need to uplift it? And what I’m really seeing from the CIO’s office is almost a desire to merge 171 requirements with zero-trust-type capabilities, or more enhanced full CIA triangle requirements. So I’m starting to see things go a little bit up the ladder, and say you might actually end up with some more controls you have to implement.

And we saw this back with CMMC 1.0, right? The DoD at the time had some good ideas, had the Delta 20 controls. They lost that battle to NIST, and that’s how CMMC 2.0 was born. But when you start looking at this, and understand the goal is to have resiliency, to protect confidentiality, and to have integrity — we want all of this capability, availability being one of those things, but we want all of this in a package, and we also want to make it as accessible to the DIB as we can. Tiered scoring — maybe that’ll be a thing.

Brett: The problem I always run into is this: controlled unclassified information — and this is kind of the stance I’ve heard the DoW take before — wherever the data goes, the requirement goes. So I think it’s going to be so hard for the DoD to determine almost like subclassifications of CUI that would map to sub-requirements of what tier of CMMC within a Level 2 you can be — basically, how many allowable POA&Ms you could potentially have. And I think that’s the friction point a lot of people are trying to figure out. If CUI is the baseline, we’ve got to protect it based on what NIST 800-171 says, because that’s what the executive order said back years and years ago: NIST, build a standard. Then the DoD proactively said, “Hey, we want a contractual obligation that you’re going to do this,” and later said, “We want to know your score,” and then, when they kept getting IG reports saying everybody was failing — whether intentionally misrepresenting their cyber posture or actually maliciously doing so — “we want a verification mechanism,” which is where CMMC was born. So you’re seeing all these things pile up. And now, because that process has taken so long, we’ve lost some of the modern cybersecurity techniques that “brilliant at the basics” was bringing forward. So I, in a weird way, am seeing more requirements on the DIB long-term, rather than fewer requirements, because FAR CUI is Rev 3. So it’s not really going away. There is going to become an element of “you’re going to have to meet the contractual obligation to be in the defense industrial base.”

Daniel: And so, well — if we cannot meet the obligations, it’s becoming very clear that the feeling is: if you have a contractor that cannot meet the obligations or the compliance requirements, you’re going to have to find a new subcontractor. That message is going over loud and clear.

Brett: And maybe there’s a meet-in-the-middle. Based on what you were saying, do we go back to what Dr. Ron Ross said a couple of years ago — that Rev 4 of 800-171 is the planned obsolescence? That would be the last revision, and then it would go to NIST 800-53 with a CUI overlay. Now, within 800-53, and within RMF and 800-37, you have the concept of CIA. And right now, if you consider where CUI sits, it would be a moderate for confidentiality and a “no” for integrity and availability. Should that be notched up to be moderate-moderate-moderate? It shouldn’t be at the same level as secret, of course — maybe the whole thing needs to be adjusted. But are the mechanisms already there, and we just need to apply them and bring in that CUI overlay, which they published with Rev 3 of 800-53 — what their idea was for the CUI overlay — before Dr. Ross retired? And Vicki has done a great job of maintaining it as we go along and adding things. But is that the answer? I don’t know that that’s the ultimate answer either, because 800-53 also has to go through that same publishing cycle. And right now, technology is moving faster than the publications. How do we address that? How do we bring in passkeys? How do we bring in post-quantum cryptography? How do we bring in all these things we need to protect? And can we apply them retroactively?

Because — you may remember this, all of us who’ve been around since the good old days, “Pepperidge Farm remembers” — when CMMC came out, they said this is going to be for new programs. It wasn’t interpreted like that. It was being added to all new contracts, even from programs that have been around since the ’70s, where you have a supply chain that has been building the same airplane, or the same component for this airplane, since 1970-something.

Daniel: Yep.

Brett: And all of a sudden, now everything has to change, and all the cyber compliance needs to be there. Well, that’s going to raise cost. Nobody wants to pay for that cost. And because it’s a regulatory requirement rather than a contractual obligation, you can’t just tack that onto the bill. There’s a problem with the amount of money it would cost to bring these small-to-medium-sized suppliers up to compliance, where they’ve been producing the same part at a rate of one per month for the last 20 years.

Daniel: Mhm.

Brett: How do you all of a sudden turn them into a cybersecurity powerhouse, if they’re especially below the cyber poverty line — and that cyber poverty line keeps getting adjusted? If you’ve got a company, and I’m already in single-digit margins, and the defense side of the house is a small percentage of the work — why would I stay in business, when I can do the same thing commercially and not have all these requirements at this point in time? Is it a great idea to protect my intellectual property? Absolutely. It’s going to benefit them. But financially, it doesn’t make sense for them. Well, let’s say they hold a patent. What happens? Do you now force somebody to buy the patent, buy the company out, acquire the company? This is a very complex conversation — it’s like a choose-your-own-adventure book. There are so many different endings, and we just have to make sure that at the end of the day, we can still deliver the product to the warfighter, so that warfighter comes home to their family when they’re done with their mission.

Daniel: Yep. But I think the DoD has done a good job of turning up the validation requirements. I mean, DFARS 7012 is almost a decade old. It’s coming up on full implementation of the requirements at almost 10 years. And within that life cycle, pretty much everyone at this point has had a contract mod, or the inclusion of DFARS 7012 into their solicitations and contracts. And so now it’s just verification under CMMC. There are people making the same airplane part since the ’70s, and they were there when it was just ITAR regulations — that’s all they had to worry about, US people, US places. And then all of a sudden DFARS 7012 comes in, and people weren’t adhering to that, because they were still on lowest-price-technically-acceptable contracts. So honestly, a lot of them made the decision to not implement all the controls, or to POA&M everything. We saw a lot of the POA&M loophole in the past few years. And so now that there’s a validation mechanism — self-attestation, the Department of Justice has False Claims Act cases now, and the requirement, well, temporarily was the requirement, and potentially to be returned, for certification and validation of that — I think the DoD has given an incredible runway to companies to basically make the decision to stay in or stay out, sell the patent, don’t sell the patent. But these have been the requirements for a very, very long time. The first initial version of 7012 referenced, I think, 800-53 back in 2013. Very, very long time. So I’ve actually been impressed with the slow rollout, and then on top of that, CMMC is a five-year rollout on top of DFARS 7012 being around for so long. We’re looking at a total of 13, 14 years of NIST 800-171 requirements by the time this is all over. That’s a teenager — a teenager’s worth of requirements, right? That’s how long has passed.

So, okay — I know we’ve talked everyone’s ear off for a long time, but I always love giving closing remarks. If you were to say one thing to the supply chain right now about CMMC, about the pause — fill in the blank, whatever you’d like — give the industry some closing remarks based on your perspective here.

Brett: Two things, primarily. One: respond to the RFI. They need your input. Get out there. If you’re part of an industry association that is consolidating your comments — NDISAC, AIA, etc. — get with your industry association. If you’re not a member of an industry association, get your feedback out there at this point. They stated that they have about 60 comments. That’s not enough. Everybody has feedback. There’s nobody out here that thinks CMMC is perfect. Now, what needs to be improved? What needs to change? What needs to be added, or modified, to make it work in your mind? Please respond to the RFI. That’s going to help them make quality, informed decisions on what the future of CMMC looks like, because, like they said, the intention isn’t to kill CMMC — the intention is to improve CMMC.

Daniel: Yep.

Brett: My second takeaway, my second closing remark, is: stay the course. There is no downside, other than that you’re forcing yourself to look at yourself in a very hard way — “Am I actually compliant with all 320 assessment objectives?” Now, some of them don’t really apply anymore. Let’s be honest, there are outdated assessment objectives, we all know that. But at least you’re setting a minimum floor for where you should be. Even though it may not be 100% valid in 2026, it is still going to help you. If you’re not doing it, at least get to that point, and then look at elevating yourself above that — because it’s not only going to protect the information we need to provide goods and services to the Department of War and get into the warfighter’s hands, it’s also going to help you protect your intellectual property and partially insulate you from a False Claims Act situation. Should there be a safe harbor included in this — based on a C3PAO assessment automatically invoking a safe harbor clause? Possibly.

Daniel: Yeah. I mean, is that a good idea? That could bring value to the C3PAO that isn’t there today.

Brett: Yep. But I think the key is that right now, this is a pause. This is not a stop. This is not turning off the spigot. This is looking at it and kinking the hose and making sure that what you need to get done, you can get done. And the potential that C3PAO requirements will come back is absolutely out there. This is a pause, not a stop. We’re not stopping Phase 2. We’re not stopping Phase 3 or Phase 4. It’s just on a pause. Now, this review period of 60 days for the task force — could the implementation take a little bit longer? Sure, it absolutely could. I think we’d rather take it slow and do it right than try to rush it and possibly say that 60 days is it, and then we’ve got to make a go/no-go decision at that point. It could be that it’s a no-go right now, but we still need some more information to reach a green light. So keep doing what you’re doing, guys. Keep performing self-assessments, and if you find it advantageous to you, absolutely get a C3PAO. There are benefits to that.

Daniel: Absolutely. Do your best to protect your risk, your corporate risk, whatever that looks like — whether that’s contractual obligation through 7012, 7021, or protection from the DOJ, in case they do show up on your door through a whistleblower or a random DIBCAC assessment. It can go all over the place. So, thank you, Brett, so much. It’s been an incredible episode. Very, very informative. Thank you for taking the time, as always. We’re going to have to have you on after the pause is lifted, after the 60-day out-brief, and figure out what’s going on, what’s the latest update. Some are calling it CMMC 3.0 — whatever that new revision looks like. But thank you, everyone, for watching and tuning in. Get ready for some more content. We’re going to keep pumping out the podcast here, and hope you have a great rest of the day. Thank you.

Brett: My pleasure, everyone.

[End of recording]

Contact

Speak With Our Team

Scroll to Top