Daniel Akridge and Jacob Horne bring in a government-contracts attorney to stress-test what the DoW CIO can and can’t legally do during the CMMC suspension. The recurring theme: the CIO has real but limited power, the moves create harmonization and legal traps, and primes β not the DoD β actually drive a lot of contractor behavior.
Key takeaways:
- Class deviations are “donut tires.” The May 2024 deviation hardcoded NIST 800-171 Rev 2 as a temporary fix; this administration is using deviations far more aggressively (the whole FAR overhaul runs on one). They can undo it anytime β either via rulemaking to Rev 3, or by reverting to “latest version at award.”
- The CIO can sidestep, but can’t just press-release a rule away. A likely play: leave the 32 CFR program intact but keep the requirement out of contracts via a 48 CFR class deviation. Something regulatory had to happen before November 10th β hence the July timing.
- The RFI is not real rulemaking. No obligation to adjudicate or publish comments β Eric’s disappointment eases only if they release the feedback. And most comments (CUI marking especially) concern things the CIO doesn’t even own (that’s the Under Secretary for Intelligence & Security) or DFARS 7012, not the CMMC program.
- Only NIST owns the controls. Another agency rewriting/adding controls (Γ la CMMC 1.0’s Delta 20) invites a court challenge β and diverging baselines across agencies would cost small businesses far more than any assessment, while making security worse.
- The Rev 2 vs. Rev 3 collision is real. FAR CUI is expected by year-end on Rev 3 (folded into the must-pass FAR overhaul), while DFARS sits on Rev 2 β every escape route (shred the deviation, keep it, or announce a new baseline) lands the DoD in hot water, including a 2020 statute requiring proof of compliance.
- Primes can require CMMC regardless. Prime-sub agreements are commercial contracts (disputes go to state court); parties can require whatever they want. And DoD policy generally can’t stop a prime from demanding certification β “November” was a prime-made deadline, not a DoD one. The optics of the government telling primes “don’t verify” are terrible.
- The FAQs aren’t legally binding β but act like it. “Encrypted CUI is still CUI,” significant-change guidance, etc. aren’t in 32/48 CFR, so technically optional; but the DoD can weaponize them in False Claims/litigation. Post-Loper Bright, agencies no longer get automatic deference on interpreting their own rules. Eric’s advice: follow the FAQs anyway, but know you don’t have to.
- Third-party certification is still worth it β cheaper than one incident or a whistleblower suit β even from an attorney who’d profit from the False Claims cases if nobody certified.
- “Small business” is shifting β SBA rulemaking may move thresholds toward ~$500M, so a $300M “small” business and a $10M shop face very different burdens (a whole separate episode).
Transcript
Daniel: Hello everybody, and welcome back to That CMMC Show. Today we are joined by a prestigious lawyer and partner to discuss government contract law, and how in the world that applies to CMMC during the suspension. What can a CIO do? What can’t a CIO do? What can primes do? What can primes not do? So we’re going to go through all of this with my good friend Eric. And we also have my favorite co-host in the world, Jacob Horne, joining us as well. Eric, I’m going to introduce you first. Tell us a little about yourself β how you came into law and what your expertise is.
Eric: Gosh. Well, first the dinosaurs came, and then the earth grew. No β I think I got that backwards, actually. So I’ve been practicing law for about 25-plus years now, and I came into the government contract space about 15, 16 years ago. Before that I was at an internet law firm. So the mix of cybersecurity and government contracts has always been a passion of mine, and I picked up that passion and kept it going in 2010 when I joined a government contracts law firm, and I’ve been doing it ever since. I’ve been following this rulemaking since that time. I was giving presentations when there were two or three people in the room, because nobody cared. It’s still hard to get people to care, but it was even harder back then. The presentations were hard to fill for an hour β like, “What’s going on in federal government contracting related to cybersecurity? Not much. End of presentation.” But we always had something to talk about, and now it’s a completely different story. We could do a full day and not even touch on all the highlights that are around. So, I’m at a large firm, I chair the government contracts group, I interact a lot with our privacy and cyber group, and it’s a whole lot of interesting stuff every day, and it’s actually fun. It’s really great to solve these problems and help the DIB out and figure out a way to make everyone secure.
Daniel: Yeah, I love it. Jacob Horne, for those who don’t know you β who are you?
Jacob: Yeah, well, longtime listener, first-time caller for this show. I also host podcasts on this channel, so like and subscribe. You can find us on the Hotline every Friday that Daniel and I do live, and on LinkedIn almost every hour of the day, trying to navigate and explain the regulatory gobbledygook that’s been going on. Hopefully one day when I grow up, I can be more like Eric. Every time I hear Eric talk about this stuff, I learn something new. So when I heard he was going to be on the show, I tried to weasel my way in here so I could hang out and learn some stuff.
Daniel: Well, here we are. And the first thing we’re going to talk about is going to be something a little bit spicy β and the title’s a little clickbait, I’ll give you that. Can the DoW CIO actually change CMMC? Now, Eric, I wanted to walk through this at a high level so we can understand what can and can’t happen. And the best way to do that is start back in October of 2016 with the birth of DFARS 7012, which we all know and love. Now, the first thing we get all the time: CMMC is not DFARS 7012, but rather a validation of DFARS 7012 at CMMC Level 2. So a lot of people conflate the two. The SBA just had this big memo β or press release β saying it’s $600,000 for an assessment, and in reality it’s like, “No, that’s actually DFARS 7012.” And that’s kind of the way it’s been for almost a decade now.
Eric: Yeah. It’s been a long time. And even before they used 800-171 as the marker, they used a subset of 800-53. So in some way, shape, or form, this requirement has been around for a very long time, like you said, around 2016. And then they transitioned over to 171, which is a subset of 53. And when you have a business come out and say, “I’ve been doing federal contracting for a number of years now, and getting a CMMC assessment is really expensive, it’s going to cost me a few hundred thousand” β that’s a tell that they’re not compliant with the underlying security controls that have been around for a long time. So this rulemaking has obviously been critical for the advancement of CMMC, because it’s the underlying security metric that CMMC is testing. So, agree with your point there.
Daniel: Now, here’s the interesting thing. May 2nd of 2024 comes along, a bit more recent, and there was a class deviation that basically said, “Hey, instead of the most current version of NIST 800-171 at time of award, we’re going to hardcode it to NIST 800-171 Rev 2,” because during all of this time, CMMC was well underway. So I guess my first question to you is: what is a class deviation? How could they do this without formal rulemaking?
Eric: Yeah. So, class deviations β in previous administrations, they’ve been used pretty sparingly, but I liken them to a donut tire you put on your car. You’re driving down the highway going 70 miles an hour, you hit a rock, boom, your tire goes out, and you’re like, “Oh, I’m stuck.” But I have this little donut in my trunk, I’m going to use that to get to the gas station, until I can get a full-size tire. So class deviations are kind of like those temporary donut tires you put on your car to get us to the point we need to go eventually, when we go through a formal rulemaking process. It’s a temporary allowance for an agency to say, “We’re going to do this temporarily a little bit differently.” But it really can’t contrast something in the FAR β there are limitations to class deviations themselves. And this class deviation in particular was not surprising and not altogether controversial, because of the way the DFARS 7012 clause was written, where you’d have to be responsible for a new version of NIST 800-171 without a lot of formal notice. Rev 3 has been around for a little while now, but wasn’t much around at that time. It would be hard to ask contractors to comply with those new security controls when Rev 3 had just come out weeks earlier, or was about to come out. So it was understandable they’d issue this class deviation, and that’s what they did. And it gave everyone time. We’ve had nothing but time to get compliant with NIST 800-171.
Daniel: It’s true. It’s crazy, right?
Eric: Yeah. It gave everyone more time to get compliant with Rev 2 before moving on to Rev 3. And it was seen as a temporary measure to get us to that point. I know we’re going to talk more about the other rulemaking that followed, but it set up a spot where the government could be aligned with the same sheet of music. So if you’re bidding on contracts at the Department of Defense, if you’re bidding on contracts at Health and Human Services or NASA, you’re going to have the same security control requirements eventually. That was kind of the hope with this. Now, that being said β they’ve used class deviations in this administration a lot more aggressively. They’re reforming the entire Federal Acquisition Regulation, and they’re using a class deviation to do that. So it’s like all four tires on your car are now donut tires.
Daniel: And the gas station is 500 miles away. We’ll see if we get there or not. Man, I love this so much. That should be the thumbnail β just four donut tires on a car in the middle of the desert. Don’t try this at home. Don’t try to eat the donut tires. All four of them, at least, anyway.
Eric: Well, thankfully nobody usually has four of them in their trunk. But yeah, that’s what the class deviation did, and I think it helped align with the CMMC rulemaking as well, which was important.
Daniel: So, since that got us aligned to Rev 2, and that’s just a temporary measure β at any point they can undo that class deviation, right?
Eric: Right. Now, they can wait to do rulemaking and maybe modernize it to a specific version like Rev 3, or they can just lift it up and say, “Hey, guess what, guys, now it’s back to whatever the most current version is at time of award.” So they can go either way there if they want. And one thing happening in the background is there’s a revision of DFARS 252.204-7012 happening. They want to modernize it. We haven’t seen a draft yet, but I imagine they want to get the more current definition of CUI in there. And I’m sure they want to revise it to use the cadence of the different revisions of NIST 171 being required. And there were also things indicating they were going to work 800-172 into it β which is, you know, CMMC Level 3. So all those things were supposed to happen in this upcoming revision of the 7012 clause. We’ll see what happens now after this announcement, but that was the plan, at least, and they’ve been working on it for some time.
Daniel: I would love to see it. A lot of alignment β we’ll talk a little bit later about FAR CUI, I’m assuming β the standardized set of requirements, trying to get everybody on the same sheet of music. Which brings us to the largest question of why we’re here. So CMMC was basically split into two parts. 32 CFR was the CMMC program β this outlined how to be assessed, what the assessment was, all the nuance on minimum SPRS entries, a very large and significant document. And the CIO led the charge to the CMMC PMO to get that rulemaking to happen. Boom, we’ve got the program established. I’m going to get back to the class deviation thing in a second. And then 48 CFR comes along, which is the contractual obligation β this is our DFARS 7021 clause that everybody knows and loves. And class deviations are allowed on that. So, question number one: because 7021 is really just the contractual obligation to do CMMC, and a lot of what would be considered the burden of getting certified β how to get certified, how to meet the requirements β is under 32 CFR changes… Can the CIO even make changes to 32 CFR through any means outside of rulemaking?
Eric: So that’s a very important question. And then you kind of think, “Can they, or will they?” β just because they cannot… And I don’t want to seem like I’m taking a political position, because I’m not, but this administration has been very aggressive about how it works on rulemaking. We recently saw standards for SBA size status come out that are wildly different than the ones before, that probably under any previous administration would not have seen the light of day. But here we are. And I’m not saying that’s good or bad β I’m just saying it is what it is. And here, with the 32 CFR, one thing they could do is just leave 32 CFR as it is and attack the contractual obligation. Because without the contractual obligation, arguably it doesn’t attach to contracts, and it’s a contractual obligation in the first place. So if they can find a way to keep it out of contracts, 32 CFR can live on, assessments can go on, all the underlying program requirements can happen β it just won’t be in any contracts. That’s a potential option they have if they issue a class deviation under the 48 CFR.
Daniel: So here’s the conundrum that Jacob and I were talking about a little earlier. So, they took away DFARS 7020, as we know and love β specifically the requirement to self-attest to any kind of score in SPRS. And the reason they did that was, why duplicate the effort? DFARS 7021, through self-attestation, says you’ve got to not only report a score but a minimum score of 88 out of 110. So if they were to implement a class deviation, would they just do it against certification, that way they can leave self-attestation there? What could you imagine they could even do with that?
Eric: Yeah, I’ve tried to look at the rulemaking and see what they could do. They could push Phase 2 back like two years, maybe, through a class deviation, and that would hold us where we are right now for a long period. And if they want to do rulemaking while that happens, they could do that. They do have optionality on how they want to handle this β and that’s aside from whether it’s a good idea or not, right? We all have our opinions on that, and I think, sure, probably our three opinions are fairly closely aligned. But if they’re smart about it and creative, they could probably think of ways to not require third-party certifications for some period of time. But they’ve really painted themselves in a corner, because Phase 2 is starting in November, just a couple months from now, and you have to do something before then. You can’t just issue a press release and stop a regulation from happening β there has to be some kind of regulatory action to change the previous regulatory action, as the saga of CMMC continues to evolve. So I think that’s one of the reasons why they announced it when they did. They really couldn’t announce, in like October, a 60-day pause, because they’d then completely run afoul of the rules already in place. So the only way to do this is to get some kind of regulatory action on the books before November 10th, as I see it. But this is all unprecedented, so who knows.
Daniel: That was the interesting thing. So I was looking and searching around, and in 32 CFR it says, as part of Phase 2, the DoD intends to include C3PAO assessments or certification requirements. Why did they issue a suspension at all on July 13th, if they already had the leeway to just not do it? The CIO could have just said, “Hey guys, you know what, just don’t do it this year, we’ll come back and revisit it November 10th of 2027.”
Eric: The cynical part of me says they wanted some good press. They wanted to show they were helping small businesses. They wanted to show they were listening. The CIO’s office probably wanted to show the greater department they were taking action to further the department’s goals. Because it’s not a regulatory reason why they had to do it this way. If we’re giving them the benefit of the doubt, they wanted feedback β so this is a way to get feedback. We’ll see how they take that feedback, and if they actually use it and address it. If you go through a regular rulemaking process, one thing you’re supposed to do is take the comments and adjudicate them, address them in future rulemaking, and address them on the record β essentially say, “We got a comment that says X, here’s why we agree with X, or here’s why we don’t.”
Daniel: Yep.
Eric: This process doesn’t have any of that. It doesn’t have an obligation to address any of the comments they got. And we don’t know whether any of the comments will see the light of day. There’s no obligation, as of now, to disclose it, unless somebody asks for it through a legal process.
Daniel: I peaked Jacob’s interest, I know, because he’s like, “Give it all to me. Right now, for your request.”
Jacob: I have no idea what you’re talking about.
Eric: So, I am disappointed, I guess is the right word, that it went through this process. But my disappointment will be blunted if they actually release β anonymized, if they want β the feedback that they got. A lot of people are sharing their feedback on LinkedIn, good or bad, constructive or not constructive, about the CMMC program. Everyone has an opinion of it. Unfortunately, a lot of them are not well informed. That’s the problem I have even with the RFI.
Daniel: I am happy the industry is providing yet another channel of feedback, even though formal rulemaking was done β there were public comments, they were adjudicated, at least to what the DoW thought was sufficient. But a lot of them have nothing to do with the CMMC program. They have to do with DFARS 7012. And so, again, people are fueling this flywheel of “CMMC is the problem,” and they’re completely ignoring 7012, which is where pretty much the majority of the RFI questions were trying to address β FedRAMP requirements, what controls are important. The number one thing on a lot of those published RFI responses, from NDIA and the SBA and all the ones floating around out there, is CUI marking.
Jacob: This DoD CIO does not own the DoD CUI program. The Under Secretary for Intelligence and Security owns the CUI program. They’re in charge of marking, training, all that other stuff. So we suspended the CMMC third-party assessment because, allegedly, according to the DoD, there weren’t enough assessors β although the numbers disprove that. And then everybody’s feedback is about a thing the DoD CIO doesn’t control, that’s totally outside the scope of the program, and has nothing to do with assessment capacity. It just doesn’t make any sense to me.
Eric: No, it doesn’t. And I think all these comments demonstrate the conflation that’s been going on, like you said, between the underlying security controls and the CMMC program itself. I don’t know if I’ve seen any comments β maybe one or two β that were true to just keeping to the CMMC program itself, commenting on the burdens established by the program because of the program, or the benefits of the program. And that was partly because the CIO’s office was not actually seeking comments on the CMMC program very much. They were mostly seeking comments on the underlying security controls. So they, in part, added to this confusion and conflation of the underlying security controls and the assessment of those controls, which obviously is what CMMC is doing. You see these incorrect statements about cost and burden. And there are some people who are just misinformed because they haven’t gotten into knowing what to know β in some respects that’s understandable if they’re a small business owner doing a million things at the same time. Granted, they should have been paying attention to the underlying security controls, but they view CMMC as the underlying security controls. But there are a lot of people who should be better informed who are conflating the two also, and that’s been the most disappointing thing coming out of this.
Daniel: So, let’s look at NIST for just a second. Via an executive order, NIST was basically given the right and authority to build the controls to safeguard controlled unclassified information. So even with the feedback the RFI might be given around what controls work and don’t work, does another agency outside of NIST have the ability to dictate what controls should actually be implemented, or even define new controls on top of NIST, for the safeguarding of CUI? It sounds like they’re fighting each other a little bit, because CMMC 1.0 had the Delta 20, and then the DoD at the time got their hands slapped and told, “Uh-uh, you don’t have the power to do that.” And I’m seeing things play back out again where people are trying to modify NIST 800-171, cherry-pick things β not from a validation requirement of what controls to validate, but actually rewrite or add on top of the existing control set. Do they have the power to do that, another agency?
Eric: With enough rulemaking, they could probably figure out a way to do it. It’s not obvious how they would do it, because, like you mentioned, CMMC 1.0 β that was the biggest problem with it, and that’s what mostly changed moving from 1.0 to 2.0. But I never underestimate the ability of folks to make rules that are not necessarily inside the bounds of what they’re supposed to do, and put the rule out there and let somebody challenge it in court. Just do what we want to do, and let somebody come back and tell us we can’t. And that’s not just this administration β previous administrations have done the same. “Let’s just do it and let somebody come back and tell us we can’t.” But I think it creates a larger problem, where we were finally getting to a uniform standard across the government after all these years, after everyone asking for a uniform standard. And now, with this RFI, we have the potential prospect of changing the underlying security controls again at one agency, where the rest of the government is going to be under a separate security regime. And you talk about costing small businesses money β that cost will far exceed any cost of a CMMC assessment. Let’s just say we took away CMMC third-party assessments, but we had a new security regime for these contractors to follow. That’s going to cost a lot more. That scenario costs a lot more than the current scenario we’re in, if those contractors also do business with other agencies β which the vast majority do. So it’s not necessarily about saving money. I don’t know what the motivation is, but it’s not saving money, because that does not save money. And it makes security worse β I’m sure Jacob could talk to this for hours. When you have multiple different security requirements, it makes security worse for each of those requirements. One company, multiple security regimes, is never a good answer.
Jacob: It’s one of those things where it’s just so crazy to me that now, after people have been yelling about harmonizing, harmonizing, harmonizing, the DoD would be out here signaling they want to go in a different direction with the security requirements, right as the FAR CUI rule is coming online to get everybody onto the same baseline for this data. And like you said, it flies in the face of saving people money, because now they have different baselines. And the “brilliant at the basics” that the DoD CIO is signaling they believe in β as far as we can tell, the direction they’d like people to move in β is a dramatic expansion of the requirements, the scope, all those things that were put in place to help save people money. So the rhetoric doesn’t line up with the things they’re signaling in their actions.
Daniel: Well, and so β go ahead, Eric.
Eric: No, just going to agree with that. It’s very true.
Daniel: So, the DoD/DoW was usually just operating at their own pace, right? They kind of decided when they wanted to do CMMC, and they were early adopters to adopt NIST 171 with DFARS 7012. But to your point, there’s now a pretty short timeline in front of us, because as FAR CUI comes out β the public comments just ended, I think I counted them, they were like 86 or 87 public comments on that part of the FAR overhaul, which was nothing. No one even knows this thing exists. But the problem is, this is going to be the new baseline the DoD would actually sit under as well. And so this is a bit of the friction point, because no decisions have been made and now we’re in a suspension time period. Jacob’s brought this up multiple times β there’s likely going to be a point where people have to follow DFARS 7012 and FAR CUI simultaneously, because of their multiple contracts, multiple agencies they’re cooperating with. Do you foresee FAR CUI changing the perspective of CMMC in any form or fashion? Outside of Rev 3 adoption, do you think anything’s going to happen? Do you think they’re going to try to move faster with CMMC to adopt Rev 3 for unification? Because we’re getting both sides of it β “brilliant at the basics,” we want to rewrite and have harder controls, but also, out of the CIO’s CMMC listening session at Black Hat, she says we actually want to unify everything with CIRCIA and FAR CUI. So what’s your take on this, and the timeline to hit it within final-rule status, and CMMC continuing on past the suspension?
Eric: I mean, this could be a three-hour conversation in itself, because if you look at that decision tree on all the directions this can go, it’s really infinite. So we know certain things. We know that the Department of Defense β I heard a good… because it’s confusing what to call it, because it’s technically the Department of Defense, but they’re calling it the Department of War. So somebody at a conference came up to me β I apologize, I don’t remember his name β and he said, “I take it as Department of Defense doing business as the Department of War.”
Daniel: DBA action. I like that.
Eric: DBA. And I think it’s perfect, because it’s not minimizing the DoD as a name, it’s just the reality of the situation. I actually hope in the next National Defense Authorization Act they just change it to one name, so we can all talk to one name. Anyway β the FAR CUI rule has been bouncing around, I know Jacob’s talked about this a lot, has been bouncing around for a long time. And with this latest version of the FAR overhaul, which has another interesting twist β the administration official in charge of shepherding the FAR overhaul left a couple days ago.
Daniel: Oh, wow. Didn’t know that.
Eric: Yes. Kevin Rhodes resigned. So we don’t know what that will mean for the FAR overhaul. But what they did is β I wouldn’t say they snuck this rule into it, because there’s no sneaking in regulations, everyone sees it β but they took out all the dusty rules that were in the cupboard, that had been neglected for a long time, like the Chinese tech ban, like the TikTok rule, like other security-related ones, like the FAR CUI rule, and just put it as part of the FAR overhaul. Which was brilliant, I think, because that’s a must-pass thing. This is a high priority for the administration. They want the FAR overhaul completed by the end of the year.
Daniel: Revolutionary.
Eric: It’s revolutionary, right. And you stick the FAR CUI rule in it β you’re not stopping the FAR CUI rule in the FAR overhaul, most likely. Famous last words. So we’re expecting to see, like by the end of the year, this revised version of FAR Part 40, which includes the FAR CUI rule. And the nice thing about it is they went to NIST 171 Revision 3, which is where the Department of Defense/War has been going, because they’ve had a rule they’ve been working on for a long time to move from Revision 2 to Revision 3 as well. So before this announcement, you kind of all saw it coming together, right? Where everyone was going to get to Revision 3, probably with some additional runway of time, maybe six months, a year, but we would all get there at the same time. Didn’t matter what agency you did business as β this was the security regime you had to comply with. And now we have a couple monkey wrenches in it. One, Kevin Rhodes has departed the government. Two, you have the CIO putting out this new security baseline they may want to look at, and asking questions about what security controls under NIST 171 are very difficult for you β “multifactor authentication, let’s get rid of that.” So it’s like, we were so close to accomplishing what we all wanted, that took seven to 10 years to accomplish, and we kind of are seemingly stepping away from it. So I really hope we get back on track and have a Revision 3 as the baseline, or at least Revision 2 β whatever revision it is, the same baseline across the government, because we were going there and now we seemingly have stepped away from it. And an example of that: the last proposed version of the CUI FAR rule had an 8-hour incident response time, and it moved to 72 hours, so it was uniform across the government, because CIRCIA is also 72 hours. So they were really looking to make everything uniform and standard across the government, which I really appreciate, and I think companies would appreciate β it would cut down on their costs, it would help small businesses quite a bit.
Jacob: So, I guess this is probably the question that Daniel and I both have, that a lot of people have. Okay, we’ve got this class deviation in the DFARS that keeps everybody on Rev 2. The DoD had a plan and a rule, as of the unified agenda, to move everybody to Rev 3. So there can be a conflict.
Eric: Yep.
Jacob: They seemingly have abandoned that idea in lieu of this review and whatever they’re doing. So the FAR CUI rule is still expected. So when the FAR CUI rule comes out and says Rev 3, and DFARS 7012 class deviation says Rev 2 β what then?
Eric: You’ll have companies that have to do both. That’s going to be the reality of the situation, unless they update the class deviation to say it’s Rev 2, but if you’re doing Rev 3 you’re okay also.
Jacob: Well, and that’s also the problem. So let’s get a little crazy with rulemaking here. Let’s say the FAR CUI rule comes out, points to Rev 3. DoD says fine, they shred the class deviation and make defense contractors move to Rev 3 for DFARS 7012, and they just don’t put CMMC in contracts. That solves the Rev 3 harmonization problem. But then they’ve got a congressional problem on their hands, because there’s a statute from 2020 that said you need proof that they’re doing the requirements. Doesn’t matter what revision you’re talking about β we still need proof. So they rescind the class deviation but they don’t do CMMC β they’re in hot water. They keep the class deviation, companies are juggling multiple baselines β they’re in hot water. They announce a different baseline β now multiple baselines, Rev 2, whatever the heck they’re going to be working on, FAR CUI Rev 3, plus, like you said, it could go in all these different directions. This is way worse for small businesses than the plan that was in place beforehand.
Eric: Yes. And part of that plan that was in place was to establish β I know you all are familiar with this β enclaves they could work out of, that would save them a lot of money as well. So the marketplace, whether government-driven or industry-driven, was catching up with these concerns. And all those concerns being addressed, and relief for small businesses that was coming, are being thrown out the window. And I’ll just add too β third-party certifications, the cost in most circumstances, no matter how small you are, is worth the cost. And I don’t sell third-party certifications. In fact, if nobody gets certified by a third party, I will financially benefit from that, because of all the False Claims Act cases I’ll be handling. So I have a financial incentive to say “no more third-party certifications.” But every client I talk to, I tell them: if you can get a third-party certification, you should get a third-party certification, because it eliminates your risks of a whistleblower suit, a False Claims Act suit, or even an issue happening with a cybersecurity incident β and one cybersecurity incident is way more expensive, no matter how small, than a third-party certification. Third-party certifications, even for the very smallest companies, are probably at least… And there’s no third-party certification for a small business that costs $100,000, despite what the SBA is saying.
Daniel: Yeah β the incidents cost that much, you mean?
Eric: Yeah, the incidents cost more than that, but the certification that may help prevent the incident costs way less than that.
Daniel: Well, and I think that’s the interesting transition here, one of the questions we get asked all the time: can a prime still require CMMC even during a suspension? Well, primes are all about mitigating their risk. They want to validate and make sure you’ve done the thing you were supposed to do. So, contractually, can a prime issue a CMMC certification requirement to their sub, even though there’s no DFARS 7021 obligation for it?
Eric: Absolutely. And I imagine there are quite a few that will β some have come out and said they’re going to continue to require it no matter what. I think a lot of people mistake the fact that prime-sub agreements, or higher-tier to lower-tier sub agreements, are not government contracts. They are commercial contracts. They happen to have FAR and DFARS clauses in them because they just get flowed down. But if you have a dispute under that contract, you’re going to state court β you’re not going to the Court of Federal Claims, you’re not going to the Board of Contract Appeals, you’re going to your local state court usually, unless there’s diversity where the parties are from different states, to resolve those disputes. And I’ve done this quite a few times, for better or worse β you’re before a state court judge who maybe doesn’t know a lot about government contracts, and you have to explain it. But the larger point is that parties can agree to whatever they want in a subcontract. It doesn’t matter whether there’s a government requirement or not. They could require compliance with 800-53 if you’re handling CUI, right? They could do whatever they want, as long as they find a contracting partner willing to sign that contract. And if I’m a large prime contractor, and I have supplier A that has a third-party cert and supplier B that does not, even if supplier A is a bit more expensive, I’ll go with supplier A, because I’ll have the confidence that the information I’m sending down is going to be protected. And in the end, I’ll probably save money, because I won’t have to worry about the security controls supplier B has and the leakage they have with the information β because all those largest cybersecurity incidents we’ve seen in the government contracting industry have really come from those contracts.
Daniel: Yeah. Downstream. Now, Jacob, you have this interesting question: can the DoD control primes’ one-size-fits-all behavior? Do you want to elaborate on that?
Jacob: Yeah. So this gets back to what you were just talking about, Eric. People talk about, “Well, the majority of the DIB are small businesses.” The other part is that the majority of the DIB aren’t prime contractors β the majority of the DIB are on the other side of the prime contractors, on the other side of the federal contract, with this prime-sub relationship. And so β not a lawyer, but there’s this term that gets thrown around called privity of contract. And I keep thinking about this, because some of the RFI responses I’ve seen, people go, “Well, delay the timing for when the certification is required.” And it’s like, okay, let’s say you don’t need the certification at time of award, and the DoD presses a magic rulemaking button and says, “You need certification six months after award,” in order to make this easier to achieve β and Lockheed and RTX and Northrop come out and they go get Level 2 right now. There’s nothing DoD policy can do to stop that. Give you a perfect example: November is not a deadline in DoD CMMC rollout policy. The primes made November their own deadline because of what they wanted to do. And now we’re going back and revisiting DoD’s policy that says nothing about November being a deadline, as if changing it to still say November is not a deadline will change prime behavior. So what does pulling the levers of DoD policy do to control the behavior of the prime? Because I think a lot of people think the DoD can control the behavior of the prime, and as far as I understand, that’s not true.
Eric: That’s generally not true. And in fact, they’d have to come up with some bespoke DFARS clause they could put into prime contracts. They can’t do it unless a prime contract requires it. So they’d first need to issue a solicitation that says “you can’t require this” somewhere in the solicitation, and then the contract award would have to say that. We haven’t seen any indication that (a) that’s going to happen, and (b) they have the authority to do that β because, I know you all have talked about this before, the CIO does not sit with contracting. They have to agree on this also. And that clause would require rulemaking. So, as it stands now, that’s not something they can do, at least on a widespread basis. Maybe a bespoke basis β a contracting officer drafts their own thing to put in a solicitation. But if the contractor doesn’t like it, they could file a pre-award protest saying, “Hey, this is not a proper clause to put in the contract.” So β “because we want to have security requirements in our contractors”… And boy, how bad does that look? You have a prime contractor that wants to verify their subcontractors are protecting the government’s information, and the government says, “No, don’t verify it.”
Daniel: Oh, man. That’s hilarious. “Please don’t tell us if the companies are [compliant].”
Eric: And I do wonder β just to go back to something we were talking about earlier β if that 7020 clause comes back to life, if there’s some kind of delay on third-party certifications, because that was in the rule that was kind of taken away, with the expectation that CMMC would be here. And for self-certifications, it still is, but not for third-party certifications.
Daniel: Nope. And to have this kind of open window of people not having to attest β like, what is happening? We’re going backwards. We’re going back to just the 7012 days.
Eric: So, the good news is, the lack of the 7020 clause, I don’t think, will impact that many companies, because for companies that have existing contracts, they still have the 7020 in their contracts, they still have to comply with it. So it’s only really impacting companies that have not previously, or do not currently, have a contract, and have been awarded one, and don’t have the CMMC Level 1 or Level 2 self-certification requirement in it. So the delta on that is probably not that many companies. But we also have to talk about one last thing β they’re helping small businesses, that’s the angle here. What is a small business is probably changing drastically, with the SBA recently releasing new rulemaking to quantify small businesses. It’s not necessarily $40 million under popular NAICS codes β it’s more like $500 million. And you have a small business that is a $300 million business. Their ability to comply with this is a lot different than a $10 million business.
Daniel: Yeah, that’s a whole other podcast.
Eric: Yeah.
Daniel: We’ll have to have you on for that one. One last legal question we have β Jacob and I have tossed this around for a long time β then we’ll wrap up. The DoD, on their website, has a FAQ section around CMMC. Now, this states things like “encrypted CUI is still CUI.” It says what significant changes are, and more clarity outside of the scoping guidance, which is mandated by the rule set. So Jacob and I are like, okay β if it’s not in 32 CFR, referenced in it, if it’s not in 48 CFR, can the DoW have a supplemental set of guidance that directly impacts how people could interpret CMMC controls and/or be assessed, or need to be reassessed? Is that legally binding in any form or fashion? Because it sounds like just good advice, but doesn’t sound like I actually have to follow it if it’s not in 32 or 48 CFR.
Eric: So the answer is kind of complicated, but I’ll just say the answer is no, it’s not legally binding. But (a) it is how they’re thinking, and (b) if there’s ever a False Claims case or other litigation or contract cancellation, they’ll say, “This is how we interpret the rule to be, to include these things that are in the FAQs.” So in a way, they can make it legally binding β because it’s not in your contract, right? So I always argue, if it’s not in your contract, it’s not legally mandated. Obviously there are some exceptions β you can’t commit fraud even though there’s not an anti-fraud requirement in your contract, and stuff like that. So I do think there’s a good argument that it’s not legally binding, but they could make it legally binding if pressed to do so, through court cases. That being said, I always tell clients: you should follow what they say in the FAQs if you can, because that’s how they’re thinking, and that’s how they interpret their own requirements. I’ll take the counterpoint now and say we had a Supreme Court case recently, called Loper Bright, that stopped giving agencies discretion when interpreting their own regulations. So companies and agencies are now operating on the same playing field when interpreting the agency’s own regulations, whereas before, the agency was getting discretion on how they interpreted their own regulations. So there’s not a case that discusses this β we have a soup of noodles and pasta and vegetables all interacting with each other, and we don’t know how it’s going to come out. But my best advice would be that you should follow it, but you don’t have to.
Daniel: Yeah. Because I peel it open sometimes, I just take a look. And listen β to everyone who’s contributed on the CMMC PMO side, it is appreciated. This is not a Debbie Downer. Clarity is kindness, so the more clarity the better. But there are certain things, like “encrypted CUI is still CUI.” I’m like, they’re not just talking about the CUI that they possess, the controlled technical information β they’re making this broad sweeping terminology, which DFARS 7012 is inclusive of anything in the CUI Registry. But NARA is the one with the authority to define the CUI and to source all of that. And so if the DoD or DoW doesn’t have any other precedent outside of an FAQ document stating things like this, it’s really hard to defend that, because part of them doesn’t even have the right to say that. Anyways, I won’t go into all that fun stuff, but it’s interesting to follow all the pasta news, right? We got macaroni, we got some spaghetti β it’s all over the place right now.
Eric: You’re making me very hungry right now, I can tell you that.
Daniel: Oh, me too. I have not eaten lunch, so I’m very excited. Well, we’re going to wrap up the show. I’m in Central time, it’s terrible β it’s 2:40 now.
Eric: I know.
Daniel: Well, with that being said, we’re going to wrap the show. We’ve got closing remarks, which is one of my favorite things to do. Eric, you can tell the people whatever the heck you want β your favorite pasta, your favorite regulation, your crystal-ball predictions, whatever you want. The last few seconds of this show are all yours.
Eric: Well, I’ll just say this. It’s not just in cybersecurity land, it’s everywhere across government contracting: this administration is paying more attention to procurement than any other administration previously. So it’s really important to stay up to date β watch shows like this, watch LinkedIn, subscribe to blogs to stay informed. Because if you think you know what’s going on in government contracting, just wait till the next day and that will all be upended. We’re just seeing drastic change after drastic change. When you don’t think something could change, and you think they’ve run out of things to change, they have not run out of things to change. There is more to change. So I’d just say to folks, keep watching and listening and taking it all in, going into conferences, all that good stuff, because it’ll help you stay informed in this very complicated area.
Daniel: I love it. Well, Eric, thank you for joining. We’ll likely have you on again to discuss the SBA thing, because I think that’s pretty interesting. Everyone’s β small businesses might be a weird nomenclature to use if they’re making $500 million a year, right?
Eric: That’s a little bit hard to reconcile, but β scrappy startup, $500 million.
Daniel: That’s right. Make half a million. Eric, thank you, sir. Jacob, pleasure as always. And with that, the show is over. Make sure to like and subscribe, and have a good rest of the day, everybody. See y’all. Thank you all.
[End of recording]
Contact
Speak With Our Team
Our team of compliance and cybersecurity experts are on standby and ready to help. We’ll walk you through what you need and what to expect.
