Fernando Machado — CISO of the first accredited C3PAO, with 150+ assessments done — recaps his meeting with the DoW CIO and dismantles the “assessments cost $600,000” narrative driving the suspension. The core message: keep implementing, keep certifying, and expect more requirements coming, not fewer.
Key takeaways:
- The $600K number is bogus. It came from the SBA taking the single largest figure in the regulatory impact analysis and applying it to every small business. Real assessments are under $100,000 for most small businesses — Fernando showed the CIO five redacted contracts (companies under 50 employees) to prove it, as did peers from other C3PAOs.
- Two costs get conflated. Implementation/readiness (DFARS 7012 compliance) is separate from the assessment. People who quote “$300K–$600K assessments” are really lumping in years of deferred implementation — “saying the quiet part out loud” that they never did 7012.
- Short-term relief ideas he pitched: expand the ENCODE enclave program (~13,000 companies applied); restructure the FY27 NDAA §1626 grant from $50M/$100K-per-company to $500M/$50K-per-company (~10,000 companies certified); tax incentives for those already certified; and wartime waivers. Note: grants cover the assessment, not implementation — so an ENCODE enclave + grant could make Level 2 nearly free.
- FAR CUI is coming for everyone. It extends DFARS-7012-style requirements to all federal agencies handling CUI. It doesn’t yet require a score or certification, but each agency gets discretion to validate — and GSA (STARS III, Polaris) has already signaled CMMC-style language ahead.
- 88 is the new 110. Under the suspension, self-attestation still requires a minimum SPRS score of 88/110 (you can’t POA&M the heavy hitters), and SPRS literally won’t accept less. Fernando warns against fudging to 88 — DIBCAC is actively running involuntary assessments and reviewing SPRS.
- DIBCAC gives a pass for booked assessments — showing a scheduled C3PAO assessment usually gets them to move on (one holdout aside, which smells whistleblower-adjacent).
- ~95% keep going. Only a handful of Cybersec’s clients backed out; eMASS is live and certificates are still being issued. Get in before the post-suspension rush.
- The suspension likely means more requirements. The CIO’s office thinks 800-171 isn’t enough — expect operational resiliency, OT (NIST 800-82), and continuous monitoring (vs. point-in-time) on the horizon. And OT hardening is far costlier than IT.
Transcript
Daniel: Hello everybody, and welcome back to That CMMC Show. We are on a roll. We just talked to Brett Cox from Boeing. We have my wonderful friend Fernando joining the call today, who also was able to attend the recent DoD CIO meeting. But not only that, he’s been making the rounds and having conversations with primes and subs and the government, and he has years of experience — he’s been through the hurdles of CMMC delays for the years and years they’ve been going on. So we’re going to hear today from not only a C3PAO, somebody who’s been in the ecosystem a long time, but someone who actually got facetime to talk with the CIO about issues and concerns around the CMMC program. So, Fernando, welcome to the show, my friend. Why don’t you give the people a little intro? Tell them who you are.
Fernando: Yeah, so I’m Fernando Machado, the managing principal and CISO here at Cybersec Investments. I’m happy to announce that we were the first accredited CMMC third-party assessment organization. And we have conducted over 150 assessments to date since the CMMC program went into effect, and we’re still churning forward. So, looking forward to seeing what the future brings.
Daniel: I love it. So, right around 10% of all assessments your team has been a part of.
Fernando: Yeah, and that’s not including the JSVAs. This is strictly the CMMC assessments, when they began back in January of 2025.
Daniel: Man, I love it. We need to have another episode around scoping and assets — let me tell you, your experience would go very far. I’ve had so many conversations recently where they’re like, “Wait, if a web browser processes CUI, is the computer in scope?” Anyways, that’s just one of 10,000 questions we get, but we’ll save that for another episode.
I do want to start off strong here. You were able to attend a meeting with the DoW CIO, and there’s this murmur around a $600,000 assessment. Now, I didn’t see you pulling up in a Lamborghini to this podcast episode, so I am very curious of not only your take on what the CIO had to say and how that conversation went, but where in the world did the Small Business Administration get this $600,000 number?
Fernando: So, I heard that this number — this $593,800 number — came from the Small Business Administration reading the regulatory impact analysis. And what they had done was they had taken the largest number they could find, and then applied it to all the small businesses below, which is not accurate at all. So one of the first things I did with the CIO was ask her, “Do you need me to level-set with you and give you a history as to how we got to where we are?” She said no — she was very well read into the program. So I told her there were a couple of things I wanted to dispel, some of this misinformation. The first one, obviously, is that the cost of these assessments is $600,000. I said these assessments aren’t even $100,000 for most small businesses. And I said there’s a huge difference between the cost of the implementation, readiness, and compliance, and the cost of the assessment — those are two separate costs. Per the procurement toolbox, any costs associated with compliance with DFARS 7012 are allowable. But I think what we’re starting to see now is that a lot of organizations have been kicking the can down the road, haven’t made those investments, and now they’re coming out to an organization like Summit 7 and saying, “How much does it cost me to get compliant?” Then they contact me for how much an assessment costs. They’re grouping it all together, and going back to the SBA and the DoW CIO and saying, “My assessment’s costing 300,000, 500,000, $600,000,” which is not the case.
Daniel: Nope. Not the case at all. I think that’s the struggle we’re seeing — there’s this overly inflated number, but in reality, in their mind, it’s a number. It’s not two different contractual obligations. It’s “CMMC is making me do this.” I mean, DFARS 7012 is almost a decade old. It’s been around forever. And by people stating the cost of a CMMC assessment being so high, they’re kind of outing themselves — saying they haven’t done DFARS 7012 in the same breath.
Fernando: As we like to say, they’re saying the quiet part out loud. And what I did with the DoW CIO — I said, “Just to prove to you that these assessments don’t cost even $100,000.” We had brought in five contracts of small businesses that had signed with us in the last month and a half. We redacted the names of the companies, and we said, “Here are five contracts we signed in the last month and a half, of companies of less than 50 employees.” And her eyes kind of got wide, and she’s like, “Can I keep this?” And I said, “Absolutely. Don’t share it outside your office, but you can take this information to do your analysis. This proves to you that these assessments don’t even cost $100,000.” And my colleagues — Karen Wise, Rob Teague from Redspin, and Mike Dempsey from CISA — all provided similar contractual agreements between them and their companies to the DoW CIO, to prove that there’s almost a baseline they could see, of what the range of an assessment would cost.
Daniel: I love that, because so many people are like — I really hope the narrative is getting out that these are two completely different buckets of things. If anything, people need to reform 7012 from a cost-burden perspective, if that’s the case. But then there’s the friction of: how much power do you have to change the standard, 171? How much or how little should you validate? Should we enhance controls, like “brilliant at the basics” does — it’s kind of an additional overlay on top of 171 if you look at what it covers? And it’s just so many moving parts at the same time. Because the ecosystem for a long time has been very head-in-the-sand — I don’t mean the CMMC ecosystem, I mean the broader DIB, because this has been a significant cost, and for a long time primes and the DoD have really leaned into lowest-price-technically-acceptable, and there’s been no validation mechanism of 7012. I remember when 7019 got on the scene, people were freaking out, and then they realized, “Oh, I can still win a contract with a negative 203 score.” They’re like, “Oh, okay, the DoD really isn’t looking at this, so I can just kind of do whatever I want.” And obviously that opened up things like the False Claims Act with people posting perfect scores — a whole different segment we’ll talk about a little bit later.
Now, I don’t have a crystal ball in front of me — I wish I would have brought one to the recording — but you posted some stuff on LinkedIn which I thought was very interesting, about recommendations that you provided the CIO on how to enhance the program, make it better, if it were to go through some level of reform. What do you anticipate changing with CMMC after the 60-day review period, after the 15-day out-brief? What do we think we might see?
Fernando: I think one of the things we might see — anything that’s going to make substantial changes to the program obviously is going to go through rulemaking, and as we all know, we’ve lived through rulemaking not once but twice, and it does take a long time to get through that. So maybe some of the short-term wins the DoW CIO can use in her arsenal: the first one we talked about was the ENCODE project — how there were a thousand companies that signed up for the pilot program, and the rumor was that when the Army opened up that portal to ask how many companies wanted one of these enclaves, about 13,000 companies had applied. Wow. So that’s one solution we could do in the short term.
The other one was in the National Defense Authorization Act for fiscal year 2027, Section 1626. It talked about establishing a $50 million grant specifically for the purposes of offsetting the cost of the assessment, with a maximum award of $100,000 per company. And so what I did was I said, “Well, since we know most of these organizations’ assessments aren’t going to cost $100,000, my proposal would be: increase that amount from 50 million to 500 million, but decrease the per-company award from 100,000 to 50,000. Now you can get about 10,000 companies to get certified.” And I told her, “Ma’am, I just want to reiterate — that is the cost of the assessment, not the cost of the implementation, which most of the contractors are having problems with.”
And then the other recommendation would be that, for the organizations that leaned forward and actually got CMMC Level 2 certified by a C3PAO, maybe potentially offering them tax incentives. Probably the other thing I could see her doing in the short term — she keeps talking about the arsenal of freedom, and how we are currently in a war with Iran and involved in Ukraine. So probably one of the things she could leverage would be the waivers within the program rule, basically saying anything that’s involved with the war, maybe give them a little bit more time to get involved, since they’re actively engaged during wartime. And that way you can kind of get the program going from that standpoint.
Daniel: See, I love all of that, because it’s not changing the burden of NIST 171 — which, by the way, the burden was set in 2010, right? The executive order for NIST to create “what does it take to protect the confidentiality of CUI.” So I love that it’s like, “Hey, reward the people who have done the right thing and been validated,” but also let’s see what kind of funding mechanisms we can come up with. The bottleneck problem I see the whole time, to your point: this does not cover the costs of implementation. The DoW offering a grant system for CMMC is great, and I’m happy you made that recommendation, because we don’t want another student-loan situation — where, you know, if I can borrow $100,000, all assessments immediately become $100,000. We don’t want that type of behavior in the ecosystem. But on the other side, I feel like the SBA should maybe get involved and look at some kind of loan program, some long-term way to help assist with the implementation arm under DFARS 7012. And man, if I was the Department of Justice right now, I would just be licking my lips over everything that’s going on. But in the spirit of being helpful: SBA pitching in, maybe looking at implementation or cybersecurity long-term loans with low interest rates, and then the DoD/DoW looking at maybe offering grants to small businesses to actually get certified. But to your point, ENCODE is free — the Army is subsidizing the ENCODE project. You just have to pay for an assessment. So if the DoW covers that and you’re in ENCODE, you could have a near-zero cost. And that is amazing. That’s the first time I think I’ve ever verbalized that there could be this almost-free CMMC Level 2 roadmap for small businesses, which is incredible.
Well, the news doesn’t stop with CMMC. As you know — as I know — federal rulemaking lives on in many different capacities, as our good friend Jacob Horne would attest to. There’s this magical thing out there that we’ve talked about a little bit with Brett, talked around on the podcast and the CUI Hotline: FAR CUI. So FAR CUI, if we were to play back the tape, is DFARS 7012 — with NIST obligations, and FedRAMP obligations, and incident reporting obligations — except to all federal contractors that work with CUI.
Fernando: FAR CUI?
Daniel: Yeah. Now, what it doesn’t do — it doesn’t require you to attest to a score. It doesn’t require you to be certified. But I say all that meaning it doesn’t require that yet, because the FAR CUI clause gives discretion to each agency to figure out how, and if, they want to validate implementation. And I have a feeling — I’m just going to shoot in the dark here — a lot of people saw DFARS 7012 fail with validation, and where that led us: to major cyber exploits in the supply chain. I have a feeling they’re going to see that canary in the coal mine and be rather quick to say, “We want to validate elements of this.” Do you foresee C3PAOs — yourself and others — getting geared up to assess for Rev 3 and FAR CUI requirements, even though right now there’s no direct contractual obligation? Do you foresee that on the horizon?
Fernando: I really do. Especially when you’re looking at organizations like GSA, with their STARS III and Polaris contracts, where they said that once CMMC is done, they’re going to adopt CMMC-type language in their contracts moving forward. And then, of course, it’s just a matter of time before this thing starts to grow legs, before people say, “We want third-party verification like what the Department of War has done.”
Daniel: Yep. And that’s what’s tricky — you can run but can’t hide. I talk to a lot of construction companies right now, and they’re starting to see stuff out of the DOE and DOT. This is all pre-FAR CUI, which — at the time of this recording, August of 2026 — we’re anticipating at the end of the year. It just finished public comments. I think there were only 86 or 87 public comments, which is crazy, right?
Fernando: Which is crazy.
Daniel: Nobody knows this was happening, and like 10 of them were asking for extensions on the comment period. So it’s really like 70, 75 actual active comments on the rule, which is crazy, Fernando.
Fernando: Yeah.
Daniel: But we’ll see. I know a lot of the conversations around FedRAMP 20x were in there. The request by Allison from Winvale — I saw her public comment, which was like, “Hey, with this new CUI identification form, don’t just have a checkbox saying all CUI applies to this form and push it down,” right? Because everybody wants clarity on what kind of CUI they have. That would help a lot.
So, all right — another interesting question I’m getting a lot: people call and they’re like, “Daniel, what’s everybody else doing?” Everybody always wants to know what in the world everybody else is doing. And I’m going to give you the lay of the land as I see it — I want you to chime in here. I see medium and large companies, and small segments of small business, continuing the journey to meet the requirements, either because they’ve been around long enough to see CMMC stop and start so many times that they’re just figuring it’s going to start back the same way it already was, and they’re like, “Thank God I just bought two or three months of time here.” But I’m also seeing some micro and small businesses say, “We’re going to wait out the pause, just like the other two, three, four times CMMC was paused.” What are you seeing? Are people still getting certified? Is it still a good idea? Is there still value to that? Walk me through that a little bit.
Fernando: Yeah. So as far as Cybersec is concerned, we’ve only had five customers completely back out and just say, “Wow, CMMC is going away, we want nothing to do with this, good luck,” and then they leave. Then we’ve had probably about another five customers who are like, “Hey, we want to push our assessment date back a little bit to give us more time to prep.” But the vast majority — I would probably say 95% — are still pushing forward with their assessment. eMASS is still up and active. We’re still submitting assessment results up into eMASS. We’re still issuing certificates. From that standpoint, nothing has changed.
Daniel: Man. So, get in now before the line gets crazy long once CMMC — I don’t even want to call it 3.0, maybe CMMC 2.5, you know, a 2.5 version coming out post-suspension. Once that gets back on the rails, people better really, really start dialing up. So now’s your time. This might be a pause or a suspension in review of what’s going on, but this does not pause or suspend your implementation of 7012 to get you ready to go through a third-party assessment. And I’ve heard primes really want to see that — even though it’s not a mandated requirement, it shows and validates that you’ve done this, and it mitigates their risk. So whether it’s Boeing or Lockheed or Leidos or fill in the prime’s name, I’m sure all of them would be very interested — if you haven’t already told them — if you’re certified.
Now, we know certifications themselves, for award of a solicitation, are suspended during this review. However — I’ve brought this up a few times, talked about this with Brett — with the way DFARS 7021 is written, CMMC Phase 1 is still alive and well. Self-attesting is still a requirement. Well, a lot of people don’t know: you can’t just self-attest to a negative 203 and be awarded a contract under the suspension. Doesn’t work anymore. In SPRS, you have to put a minimum score of 88 out of 110. Not only that, there’s only a certain combination of controls you can do to meet that 88 out of 110, right? All the heavy hitters, all the hard ones, you can’t put on your POA&M. It’s all the easier one-point controls along the way. So what are you seeing on that side? Are people still saying, “Hey, Fernando, I want you to do a gap assessment, because I just want to see if I’m even self-attesting correctly”? Do you have any words of advice or wisdom from what you’re seeing out there, from people just ratcheting up their self-attestation trying to get that right?
Fernando: Yeah. Well, I was jokingly saying — in the past, we already know, under DFARS compliance, CMMC 1.0 and then 2.0, in the past you could submit a negative 203 and still win an assessment. Or, on the opposite end of the spectrum, we were seeing what people were doing — they were just submitting 110s without doing anything. So I’m now jokingly saying that 88 is the new 110. People are going in and submitting 88s, even though they’re not a true 88. And what they don’t realize is, when you do that, DIBCAC is out there still doing assessments, and they’re still reviewing SPRS, and they’re very, very active. I’ve heard this past week alone, we’ve had a couple of contractors reach out to us and say, “DIBCAC reached out to us for an assessment, can you help us?” And I said, “We can try to help you, let’s see what we can do — maybe bring you in for a CMMC third-party assessment.” But I can tell you right now, DIBCAC is very active. And to your point, Daniel — one of the things I’ve noticed, because I also have access to SPRS for our own organization, is I tried playing with the numbers in there, and if you try submitting something less than an 88, or without any of the three- or five-point controls, or the subset of what it needs, it just won’t allow you to submit. It’s stuck. It will not allow you to submit anything. So now, if you try to submit something less than an 88 — you’re at, I don’t know, an 83, and you have that one five-point control — it’s very tempting to just say, “Ah, I’ve got an 88,” and just move it up. That’s why I jokingly say 88 is the new 110. So, be very careful with that, because DIBCAC is actively doing these involuntary assessments.
Daniel: I’ve gotten two calls over the last, I guess, three and a half weeks. People like, “DIBCAC just showed up on my door. What the heck do I do?” I was like, “Well, what’s your score?” They’re like, “Well, it’s perfect.” I said, “Well, is it really perfect?” And you do this conversation under an NDA, everybody. And so then they’re like, “Well, we’ve had some issues, and long story short, the guy who uploaded it isn’t here anymore, and we don’t know where any of the documentation was that he was using.” And I’m like, “Okay, we need to revisit this a little bit.”
A fascinating thing — I don’t know if you’ve seen this. I’ve seen DIBCAC say, “Hey, if you can produce evidence that you have a scheduled C3PAO assessment, and you can show that to us within some sort of time span — it can’t be two years from now — then we’ll just go ahead and think that’s good enough, and we’ll move on to somebody else.”
Fernando: That’s right.
Daniel: And so that’s the other interesting thing — DIBCAC is seemingly just validating: “Hey, if you’re already on track to have a certification, we’re just going to trust that you’re good enough, and that’s all the evidence we need. We’re going to go move on and bother somebody else who isn’t ready.” So I thought that was very interesting too.
Fernando: More often than not, that’s what I’ve seen too. We’ve had a few DIBCAC involuntary assessments where they reached out, and when we proved they were on our schedule, they’ve left them alone — all with the exception of one company, where DIBCAC was like, “We don’t care that you have a C3PAO assessment, we’re coming to see you anyway.” And I said, “Well, good luck to you.”
Daniel: That’s got some whistleblower fringe around it, potentially — like someone really knows something’s going on in that one. So, yeah. Man, do the right thing. Produce the correct score. And if you can’t meet the requirement, do the thing to meet the requirement. This is what people don’t really understand: we need to reward the people who have done the actual work to implement and protect controlled unclassified information. We all know there’s overmarking out there — everywhere there’s overmarking around CUI. But at the end of the day, if a gizmo costs $6 and they’re not CMMC compliant or meeting DFARS 7012 in reality, then guess what? I might still go buy their gizmo if I don’t know the difference between them and a $7 widget or gizmo who has done all the right things with cybersecurity. And if you look at the history of the federal government, they love lowest-price-technically-acceptable. So as that talk track continues, there has to be some sort of verification mechanism to validate that people have actually done the thing they’re supposed to do — or else they’re going to keep awarding contracts to companies and subs and suppliers that aren’t protecting the national security interest. And that’s the friction point of everything. It’s like, “Man, I want to do the right thing, but I also don’t want to lose business.” It’s like — well, you can actually gain business if you do the right thing. And so that’s the narrative I wish people would talk about a little bit more. It’s kind of lost in the narrative of “everything’s so expensive.”
All right, with that, we’re going to round out the podcast episode. Fernando, you can tell me what your favorite lunch spot is, you can tell me your thoughts on CMMC 3.0, whatever it’s going to be — give me some closing remarks. Address the audience of — I think we average about 10,000 viewers an episode. So, 10,000 interested organizations.
Fernando: So, I can tell you, based on the conversation I had with the DoW CIO: their office does not believe 800-171 is enough. Because they’re interested not only in confidentiality but in operational resiliency. So they’re looking at potentially tacking on controls to the 800-171 framework — that’s why you’re seeing things like “brilliant at the basics.” And continuously, she keeps talking about operational technology, and it’s just a matter of time before that NIST 800-82 might make its way onto the CMMC framework and get tacked on to make sure operational resiliency gets added. So that’s the feeling I got, speaking to her and the deputy CIO — that they don’t think 800-171 is enough, and they’re looking at potentially adding more requirements in the future. That’s the mindset they had.
Daniel: Wow. And listen, people think it is really expensive and costly. If anyone’s ever had to price out hardening an OT environment — God bless them. It is a walk in the park compared to OT infrastructure, because of how critical it actually is. Not only critical, but it’s very hard to remediate and patch, because you’ve got systems that are 20, 30-plus years old. My favorite story is somebody buying SCSI drives off of eBay because they need to keep this one system alive. And so, man, that’s really good insight — the fact that we could see an overlay on top of the requirements of 171, like that. The burden just went up, not down.
Fernando: Yeah. And the other thing they brought up too was, they were not a fan of the snapshot-in-time assessments. They wanted something along the lines of continuous monitoring of some sorts. So again, all of this is leading to potentially more requirements later on down the road. At least, those were the conversations they both had with us.
Daniel: Amazing. I mean, I say “amazing” in the sense of — everyone thinks they hear the word “suspension,” they think “canceled.” The opposite of what they’re thinking is: there’s going to be more requirements potentially showing up on my doorstep. Or, crazy enough, the DoD might require me to plug into a huge enterprise SIEM solution to make sure I’m staying compliant, that I’m responding to incidents appropriately. Obviously, it’s a large, dramatic response to that — but some sort of continuous requirement on top of that. I know FedRAMP 20x is obviously all in the news right now, continuous compliance is a big topic. You think point-in-time compliance is expensive — continuous compliance is a whole other level. So, Fernando, we always appreciate you being on. You can always speak so concisely to the issues at hand. We truly do appreciate you and your team. We are big fans of Cybersec. If you guys need a gap assessment, C3PAO certification, advisory services — these are your people to go to. Absolutely incredible. So, thank you. And hey, for all those watching, stay tuned — we’re going to have some more guests on here shortly. And with that, we will both bid you adieu.
Fernando: Farewell.
Contact
Speak With Our Team
Our team of compliance and cybersecurity experts are on standby and ready to help. We’ll walk you through what you need and what to expect.
