CUI Hotline: 09.04.26

In this episode of CUI Hotline, Jacob and Daniel break down what defense contractors should be doing while the CMMC program is under review—and why a pause or future policy change does not eliminate existing cybersecurity obligations. They discuss DFARS 7012 compliance, CUI identification challenges, C3PAO assessment readiness, False Claims Act risk, supply-chain accountability, and the broader question of how the DoD should balance cybersecurity requirements with the realities facing small businesses.

Key Takeaways

  • CMMC changes don’t erase existing requirements. Contractors handling CUI still have obligations under DFARS 7012, NIST SP 800-171, export control requirements, and other existing contractual requirements regardless of what comes out of the DoD’s CMMC review.
  • Many contractors are discovering compliance obligations years after signing contracts. The hosts discuss organizations realizing they have carried DFARS 7012 requirements for years without properly implementing or budgeting for them—creating both compliance and financial risk.
  • CMMC has exposed broader cybersecurity gaps across the DIB. Even where CMMC itself is not the underlying requirement, the program has forced organizations to examine existing obligations around CUI, ITAR, cloud environments, and cybersecurity practices that may previously have been overlooked.
  • Preparing for a C3PAO assessment can still provide value during the pause. A strong self-assessment should rely on much of the same evidence required for a third-party assessment. Certification may also help contractors demonstrate assurance to primes, reduce compliance risk, and potentially differentiate themselves in future contract awards.
  • CUI identification and marking remain major weaknesses. A central challenge is that contractors and primes often do not receive clear guidance on what information is actually CUI. Responsibility is also distributed across different DoD offices, contributing to what the hosts describe as an “accountability sink.”
  • Fixing CUI marking alone will not solve the problem. Even with perfectly identified CUI, primes may continue imposing CMMC requirements on suppliers based on their own risk management and procurement decisions. Better policy, training, governance, and supply-chain practices are still needed.
  • NIST 800-171 compliance and CMMC readiness are related, but not identical. DFARS 7012 includes obligations beyond the core CMMC assessment, including cloud requirements, incident reporting, flowdowns, SSPs, POA&Ms, and implementation of NIST 800-171 requirements. CMMC primarily provides an assurance mechanism for validating portions of those obligations.
  • Small businesses face a structural challenge—not simply a CMMC problem. The same minimum security baseline applies to sensitive data regardless of company size, yet smaller contractors often lack dedicated cybersecurity personnel, budgets, and expertise. The larger policy question is whether requirements should change, companies should receive more assistance, or contractors unable to meet the baseline should ultimately be excluded from certain work.

Bottom Line

Until official policy changes actually take effect, contractors should continue implementing their existing requirements, conducting accurate self-assessments, maintaining evidence of compliance, and preparing as though those obligations remain enforceable—because they do.


Transcript

Jacob: Alrighty, folks. It is Friday. I have the distinct feeling I’m forgetting something, and I have no idea what it is. So if something’s wrong, let us know in chat, because I have this sinking feeling. Is the stove on? I don’t know.

Daniel: Your LinkedIn’s connected, your YouTube’s connected, we’re streaming.

Jacob: I just had this overwhelming feeling like I was forgetting something. And everybody’s at school. Anyways, it’s Friday, it’s hotline time. Thanks for remembering to come and hang out. We’re live on LinkedIn, we’re live on YouTube. The website is still working at cuihotline.org — you can call us there, you can leave a message, you can DM us, you can email us, you can find us at summit7.us. Let’s see what else. Housekeeping: we have Summit 7 Live coming up in Boston in two weeks — well, technically it’s Cambridge, the Boston people were very upset. If you check out our events page, we’ll link it down in chat, you can see what’s going on live. Daniel and I will be there. We always talk about fun stuff that we don’t always talk about in our videos, if you know what I’m saying — things we’re hearing through the rumor mill — so it can be somewhat insightful and valuable to come hang out in person and ask us questions. And we’re in task force review watch here. Nobody knows what’s going to come out, or what they’re going to say, or when, but I would be surprised if it were next week. I would also be surprised if it were not by the end of this month. So we might find out live in Cambridge whenever we’re hanging out with everybody. Who knows?

Daniel: I feel like, at a large moment of the CMMC rulemaking process, we’ve been at a company offsite for like a Christmas thing, or we’ve been at an event. Crazy things happening.

Jacob: So, I’ve been on stage when NIST updates have happened. I’ve been on stage when CMMC rulemaking updates have happened. Yeah, so maybe we should just do that instead of planning for when vacation is supposed to happen — we should just plan events, because that seems to trigger updates. So we’re all going to find out together what the big plan is going to be moving forward.

In the meantime — like the DoD has emphasized — if you look at the DoD CIO’s CMMC website, it says you still have these requirements. If you’ve gone to any of the listening sessions, the DoD CIO has said the requirements to protect CUI are non-negotiable. She also describes them as the table stakes for being a contractor. Those have not changed in any way whatsoever. And yet, Daniel, as we’ve talked to people throughout the week — throughout the last several weeks since the suspension — people are sometimes surprised to learn this.

Daniel: Yeah, so it’s so funny. I was talking to an organization this week in the construction space, and they come to me — wicked-smart IT guy. He’s like, “This contracting person came to me the other day, and the sales team came to me the other day, and they were like, ‘We need to prepare for this CMMC thing.'” It’s like, “Oh cool, great, no problems, let’s talk about it. We’ll talk about self-assessment, we’ll talk about the pause and all that stuff.” He’s like, “Actually — I need to pivot for just a second. It turns out — that was the initial intent of this call — turns out we’ve actually been executing contracts with DFARS 7012 for years, and they just told me. So, we have two contracts of these existing requirements, and we’re very, very afraid of a phone call for non-compliance.” And so I don’t know if that was prime-related, if that was DoD-related, if they had hinted at something, or if I was talking to a potential whistleblower — who knows? But they were like, “We have to do something.” And so literally, he’s in full motion, because he’s like, “We have signed a document saying that we’ve been doing this.” And I was originally approached because of CMMC, and “it’s going to allow us to enable revenue.” And then, when I asked one additional question, it turns out they had obligated themselves to this contractual implementation and protection of CUI for like six years, on these two or three contract vehicles. And so it was just one of those things where the IT guy’s like, “Listen, I didn’t know. No one told me. Sure, of course I know now — but now that I know, what do I have to do with it? I have to go fix the problem.”

Jacob: Right. Guess what wasn’t built into any of the rates of those contracts? The cost of implementation of DFARS 7012.

Daniel: Yeah. So now they’re going to have to eat that as overhead for the organization, with no real payback from those defense contracts they’re supporting.

Jacob: Yeah. Because what do you do? You go back to your customer and say, “Actually, I need to get paid more on this contract from a while ago”? That’s a good way to get a phone call.

Daniel: Exactly. “Whoopsies” doesn’t really go too far in the private or federal contracting space. So anyways, it’s just interesting — people, even now, as of this week, are having conversations or bringing up things, saying, “We’ve had this for years, we’re scared to death right now.”

Jacob: Yeah. I mean, listen, they’re going to come out with recommendations around their program review. I have no idea what the scope of those recommendations is. But one thing you cannot argue with — and this is a hill we will both die on, from the last six years — the number one thing that has raised awareness around other cybersecurity and export control requirements was the CMMC program. Even though the program has nothing to do with those requirements — nothing to do with them. You just have to contextualize a lot of the RFI responses, the rhetoric around CMMC, how much people don’t like it. Like we’ve said, almost all the critiques of the program are the things exposed by the program, rather than the nature of it itself. Now, there are plenty of things to fix within the scope of the program, sure. But it’s just been an invaluable thing — I mean, how many people have we talked to who call us up and say, “We need to migrate into a sovereign cloud, because all our ITAR and export control data is in commercial cloud,” and the only reason they started looking at it was because of CMMC — which is technically not requiring you to do that? And these are billion-dollar companies, and companies that maybe make $100,000 a year off defense work. The span of this is insane.

Daniel: CMMC is the best fraud-prevention thing that could ever have happened to the supply chain. Because there are so many people now doing the right thing — by which “the right thing” is just meeting your contractual obligation. And there are a crap-ton of people at this point who are so far off base, and they’re still winning contracts. I had a conversation this week with somebody — they’ve won contracts historically with a negative 203 and didn’t have any issues, and they’re like, “This is the problem.” The DoD groomed the ecosystem for everything to be okay, which is why, in my opinion, everyone’s feeling this massive whiplash around meeting these requirements — because it never prohibited, in any way, their ability to win work.

Jacob: Right. From the 30,000-foot view of how the DoD’s policy has evolved over the last — gosh, 15 years — this is a very interesting chapter. And we’ll just all have to see what the answer is. But like we said, any superficial changes to the program don’t change your existing obligations to ITAR, export control, DFARS 7012, CUI — all of those things. And whatever they announce coming out of the review isn’t going to change those things either.

Daniel: Well, and the thing is, the self-reporting mechanism — I can’t imagine the CIO changing that in the midst of rulemaking, if she wanted to make a dramatic change. So I foresee self-reporting at an 88 of 110, because you can’t change 32 CFR, and the only self-reporting mechanism is in 7021, the CMMC clause. I can’t foresee her getting rid of that for a good long while, even if she wanted to change it.

Jacob: Yeah. Even if they say, “We were going to relax what can go on a POA&M, because we’re willing to accept more risk” — which is totally fine — and they say, “We want to allow additional controls, or allow three-point or some five-point controls to go on POA&Ms,” you have to go through rulemaking to make that change. And that’s a lengthy process, especially if you can’t get an interim final rule waiver. So I have a feeling what’s going to happen is they’re going to come out banging the drum, press releases, just like they did in July. Lots of talk. And then shortly thereafter, people are going to be like, “Oh, so changes are like two years away. I still have to self-assess. I’m still on the hook for all this stuff.” So I have a feeling they’re going to talk a big game, but immediate changes are probably going to be hard to come by. But we’re going to have to see.

Because — speaking of which — listen, not just False Claims Act, but white-collar crime enforcement is at a 40-year low. It’s a stunning drop-off in how fast this process moves. I had predicted that by the end of this year we would see a dozen cybersecurity-related False Claims Act settlements. This is the second one so far this year, which is kind of crazy, because we know of — from what we’ve heard — hundreds of these things working through the system. But this is a good example. You guys didn’t see: Honeywell Aerospace settled — $2 million. The whistleblower who blew the whistle and pursued the suit against Honeywell, that the government joined, got paid $375,000. Her lawyers separately got paid $350,000, so the lawyers’ fees are covered. This took, I think, four years to go through the process until it was finally unsealed. Some of that is probably related to how good Honeywell’s lawyers are — there’s probably something there that’s real. If you’re a smaller business that doesn’t have in-house counsel and the budget to deal with these things for two, three, four years, then you’re probably going to end up settling faster. But these can take a long time, in addition to the fact that white-collar crime enforcement is down. However, the quotes from the DOJ’s settlement press release were not mincing any words about how much they care about the issue.

Little bit of breaking news here for everybody, Daniel — you haven’t even heard about this. In fact, no one at Summit 7 has heard this. If you guys have not liked and subscribed to the YouTube channel, please do so, because the episode of the podcast Sum IT Up that comes out two weeks from now will have the Honeywell Aerospace whistleblower on the podcast.

Daniel: Amazing.

Jacob: On the podcast. We can’t wait to see you, Rachel — Miss Rachel Tenny. As far as I know, the first podcast — certainly our first podcast — that has an actual cybersecurity False Claims Act whistleblower talking about what happened, telling the story. We’ve heard from lots of attorneys about how it works, what they do to represent their clients, but we haven’t actually heard from a whistleblower directly. But that’s all about to change. So if you guys have questions you’d like to ask a cybersecurity False Claims Act whistleblower who went all the way through to settlement, let us know in the chat below, and I’ll try to work them into the show. We can take an hour, an hour and a half, we can take 20 minutes — however much time we need. I’ve talked to Rachel so far, she’s awesome, and I’m fascinated to learn what it’s actually like. And, again, another in the long list of whistleblowers that are gainfully employed after the whistleblower thing is done. There’s not a reason not to. So, we’ll see what happens. All it takes is the winds to change at the Department of Justice slightly, for more and more of these things to come out. But $2 million ain’t much for Honeywell Aerospace.

Daniel: No. $2 million is an existential problem for smaller businesses.

Jacob: Yeah. According to the SBA’s proposed rule, Honeywell Aerospace is going to be a small business here pretty soon.

Daniel: I’ve heard murmurs of what the new thresholds plan to be, and I’m like, “You’ve got to be kidding me.” I think it’s like a billion dollars in [revenue].

Jacob: It’s like a 15x increase in the definition of some small businesses. So if you guys don’t know what we’re talking about — I don’t think we have a banner for it — there is a Small Business Administration proposed rule. I think there’s a little over two weeks left on the comment period. They want to adjust upward the definition of small businesses to the point where $500 million a year — a billion dollars a year in some situations — would be considered a small business. That’s great for the SBA, because they get to say, “Look at all these small businesses we have fostered in the country,” right? They get to take credit for an increase in small businesses. It’s really bad for actual small businesses, because now you’re competing against a billion-dollar company for small-business awards. So it’s good for some people, really bad for some other people. We haven’t done a show on it yet, but if you don’t know what’s going on, it’s going to be some fun Labor Day reading, because it’s not great for actual small businesses.

Daniel: No.

Jacob: All right. Hey, we did a podcast not too long ago — Jason and I — if you guys scroll through the YouTube page down just a little bit, it’s “Your Last Chance to Influence the FAR CUI Rule,” that outlines best practices for formatting public comments. So if you’d like a guide for formatting public comments, check out that podcast. Dump the transcript into your LLM of choice and generate some comments. People don’t know if it’s an error or not, but sometimes when you go to that proposed rule, the Federal Register says there are 65,000 comment submissions. I don’t know if that’s actually correct, but I wouldn’t be surprised, because — you know, one John Oliver segment on a proposed rule, like they did with the FCC, and they end up with tens of thousands of public comments. So, dang.

Let’s see here. Okay. So — we’ll add this in for the show — but like I said before, we’re going to have the Honeywell Aerospace whistleblower on the podcast. So if you guys have questions you’d like us to work in, put them in chat below. For example, Nicholas said, “What type of official or unofficial repercussions have you experienced that you reported?” Yeah, I saw some people on LinkedIn commenting on the story, and they were like, “Another disgruntled employee.” Uh, she seems like a nice lady to me. So, I don’t know — would she describe herself as a disgruntled, super-pissed-off [employee], or was it just sort of, “This is just business at the end of the day, and I’m not going to be on the hook for it”? I don’t know.

Alrighty, let’s see. Brad says, “The contract issue is extremely common — the assumption that just putting the 7012 clause into contracts will cause compliance to flow through the organization, where that’s not the case.” Yeah, listen — the DoD never reached out to me individually, why would they? But something we’ve talked about on the show before: if you go back far enough into the rulemaking, in the 2016 revision to the DFARS 7012 clause, the DoD’s original idea was that they would only put DFARS 7012 into contracts when they positively indicated the contract involved CUI. Can you imagine?

Daniel: Can you imagine?

Jacob: Instead, public comments said, “Isn’t that a risk to the department, that they might miss something and not put in the protective clause when they send out the data? That’s bad.” And the government said, “You know what? You’re right. That’s a great idea.” So instead, they adopted the policy they have maintained for the last decade, of putting DFARS 7012 into all contracts and solicitations by default.

Daniel: Yep.

Jacob: And it’s up to you to tell them whether or not that clause should be there, based on whether or not you have CUI. And what ends up happening? People don’t push back, for various reasons — they don’t know if they have CUI, or they know they don’t have CUI, and then the customer still won’t take the clause out of the contract. The fundamental issue is: it’s in contracts by default. So if you wanted to really help this problem, you would change that guidance to say, “Don’t put it in by default; only put it in when there is CUI.”

Daniel: That’s right. As in situations where the upcoming SF — yeah, the FAR CUI SF form — you cannot include DFARS 7012 unless the box is checked that there is CUI.

Jacob: Right. Now, that would have been something they could have said in 2016, had the FAR CUI rule come out. But the FAR CUI rule never happened, so they were sort of left to their own devices. And this has created a situation where every defense contractor has 7012, but nobody knows whether they have the CUI or not. And then by the time CMMC comes along to fix a problem with 7012 — when you have the CUI, you must prove you are complying with 7012 — everybody then says, “Well, I don’t know if I have CUI, so CMMC is the problem.” And around and around we go. But I agree with you, Brad — just putting it in by default, not the right call.

Daniel: Nope. And it’s caused massive issues, to the point where everyone, including now even people in the DoD, are recoiling against the idea of getting people to prove they’re doing a thing they know they’re not doing, because of the fact that this decision 10 years ago put us on this path.

Jacob: Yep. “And properly mark that CUI.” Yeah. This would be nice, wouldn’t it? This is the number one issue in the RFI responses. This is the number one issue we hear on the phone. This is the number one issue on Reddit and Discord and LinkedIn and everywhere, and everybody knows it. Everybody knows that the identification and marking of the CUI is the problem. And I know this is not popular. I know people don’t like hearing this. I’m agreeing with you that this is the problem. What I’m saying to people is: the person in charge of that problem is the Under Secretary of Defense for Intelligence and Security. OSD(I&S). Not Michael Duffy, not the Under Secretary for Acquisition and Sustainment. OSD(I&S). Not Kirsten Davies, the DoD CIO, who is basically on par with those Under Secretaries. The Under Secretary for I&S. Quick chat pop quiz — does anybody know who that is? Does anybody know their name? Don’t look it up. What’s their name? Who is it?

Daniel: Steve.

Jacob: How long — freaking Steve over there. When’s the last time he got on stage? When’s the last time he was on a town hall? When’s the last time he was out there explaining what was going on? The last thing they did was say that the DoD’s training for CUI, instead of being annually, needs to be every two years.

Daniel: They’re not doing anything. Seems like we’re going the wrong direction on the training for CUI marking appropriately, doesn’t it?

Jacob: It sure does seem like a problem, right? And so it’s like — I’m agreeing with you that this is the problem. What I’m saying is, it’s not that CMMC doesn’t have issues, it’s that if you go and tell the DoD CIO that CUI marking is the problem — yep, that everything else comes after that problem — the DoD CIO isn’t the Under Secretary for I&S. So we don’t know if the DoD CIO will be able to make the Under Secretary for I&S do anything. What would be better is if we all got together and found out where the Under Secretary for I&S parks their car, and go ask them politely, “Hey man, what are you doing to fix this problem?”

All of the feedback is perfectly legitimate. But this reminds me of a fun story — little sidetrack before we get into the chat comments. When I was a junior sailor, bright-eyed and bushy-tailed, I was a young E-4. I changed duty stations, and on the way to changing duty stations, I stopped for additional training. I went from Monterey, California, to Pensacola, Florida, on my way to San Antonio, Texas. My final duty station was not Pensacola, Florida — my final duty station was San Antonio. When I left Monterey, my leadership let me down. They said, “Listen, if you do a permanent change of duty station move and you use the automatic system, they’ll move all your stuff, everything’s fine. However, if you do what’s called a DITY move — where you do the move yourself — you could potentially make some extra money on the side, because that’s just the way the process works.” And I was like, “More money? I’m broke, I’m an E-4, I don’t make any money. This sounds great.” So I did the DITY move — did all the paperwork, packed my own stuff, weighed my own vehicle, did all the things. Get to Pensacola, I go to the admin office, I turn in all my change-of-duty-station paperwork, go to training, go to San Antonio — and never get paid. And I’m like, “Hey man, I did my change of duty station, what’s going on?” And the admin office in San Antonio was like, “Cool, give us all your paperwork.” And I was like, “Well, I turned it in in Pensacola.” And they’re like, “Why’d you do that? You don’t work in Pensacola, your station is here.” Oh — not Pensacola. And this is when I learned you’ve got to keep copies of everything, which is why I go back and read all the rules, probably because of this trauma. They call Pensacola, and they’re like, “What are you talking about? You got copies of what was going on?” Because I turned in the paperwork to the wrong office. They were like, “I don’t know what this is — shredder.” Nobody stopped to tell me. I should have known. Somebody should have helped me out. Whatever. I turned the paperwork in to the wrong people — even though it was the right paperwork. Had Pensacola been my final duty station, everything would have been fine. Had I kept the paperwork, turned it in at San Antonio, everything would have been fine. Things get mixed up. Everybody’s got a story like this on active duty.

My point is: you’re turning in the right comments, but you’re turning them in to Pensacola. We need to be turning them in to San Antonio. You’re turning them in to the CIO. They need to be going to I&S. So, the DoD CIO clearly knows now that this is a problem. What do you all think — do you think the DoD CIO will be able to change what I&S does? Maybe. Maybe she’s the chosen one, maybe she’s the one that’ll be able to fix it. I don’t think so — not because of any problem with her as a person, but just because of the way the system works. So, we’ll have to see. Yeah, Gills — it was DLI, I was trained as a Mandarin linguist at DLI. So there you go, fun fact, everybody.

Alrighty. Brad says, “And then we have a compliance program owner with distributed responsibility for the overall program.” I mean — over here in the land of the… blessed here, you have a compliance program owner. We were just talking about an IT guy that’s responsible for everything, and they get this thrown over the wall. Most companies don’t have that at all. The NDIA RFI response paperwork, if you guys haven’t read it, is very interesting. They talk about their cyber survey to lots of DIB companies, where they asked for the estimated cost of compliance with DFARS 7012, entirely outside the cost of CMMC — very insightful numbers. But they also said that 30% of all the people they’re responsible for representing don’t have a single full-time employee in charge of IT or security. A compliance program owner? Gosh, most of the DIB doesn’t have anybody working on this stuff at all.

Let’s see here. Alrighty. This is probably the biggest question of the last 60 days, I would say — besides people asking if they still have to do anything: “Should I keep preparing for a C3PAO assessment while Phase 2 is suspended?” It’s easy enough to say people should still comply with the requirements they have, because obviously not complying is not a good option — see Honeywell Aerospace. But should you still be preparing for a C3PAO assessment? I would contend that if you are properly conducting your self-assessment, the types of evidence you would need to show yourself, if you will, are the same types of evidence you’d need to show a third-party auditor, a DIBCAC auditor, an internal auditor. You still have to show yourself the evidence like you’d have to show anybody else who came in. And so, in many ways, preparing for a C3PAO assessment isn’t going to be any different. Now, I know some people are going to say there’s variance in terms of interpretation — that’s why it’s important to choose a third-party auditor that isn’t crazy. But when you get down to brass tacks, there’s not all that much of a difference if you’re going through the same assessment process. On paper, the only difference between a self-assessment and a third-party assessment, regardless of who runs it, is who runs it. Everything else is exactly the same. What do you think, Daniel?

Daniel: I am seeing so many people come to me recently. A couple things. One, DIBCAC’s on their tail to assess them, and they’re like, “What if I have a CMMC assessment scheduled?” For a while, they were giving passes for people who had that, so it’s a little good CYA coverage. I’m seeing a lot of people still leaning into CMMC certification. Number one, because they don’t believe the DoD is actually going to pull anything back, because of the FAR CUI clause mandating control implementation, mandating FedRAMP requirements, mandating fill-in-the-blank. So I see a lot of people wanting to minimize their risk, and also show their prime, “Hey, I’ve actually done this thing, just so you have proof, I’ve done this thing, it’s validated, you can trust me” — as a differentiator. Now, I’m really hoping — and the CIO said she would do this — that for people who get certified, or that are certified, she would allow for basically bonus points during the contract review or award cycle, and be like, “Hey, you did the right thing, we’re going to give you 10 extra points on your proposal.” And so, I don’t know, it could be an actual differentiator in winning work whenever that does happen. And then the other side is people wanting to minimize their risk, because the organizations I talk to now, we’re talking sometimes hundreds of thousands of users. I had a phone call from outside counsel a couple weeks ago from a separate company, and they said, “Hey, the company I’m working with, they did this thing two years ago. Now someone popped the hood, and they don’t even understand how they got the score they got — and it’s a perfect score. And we don’t think that’s real.” And so now C-suites are starting to freak out — especially with CIRCIA coming along, around reporting incidents for the whole organization regardless of an enclave separation of defense work, and if you’re publicly traded, you have to do reporting on that side of the house, on the SEC side. So there are so many different things where they’re like, “I just need proof that we actually did something we were supposed to do, in case one of these things falls” — which, it’s only a matter of time if you have a very large enterprise landscape. “We just have to have some sort of insurance policy,” is what they’re saying to us.

Jacob: Yeah. And we had heard this before too, that there were people getting C3PAO assessments that weren’t even in the defense industrial base. I think it was like a Fortune 500 company, and the CISO was like, “There is no third-party certification I can get against a NIST baseline.” Because there’s no NIST CSF — there’s no NIST CSF verification criteria. So it’s like, if I use NIST as the gold standard and I say I can keep your data confidential, how do you tell anybody? How do you tell the board? How do you do all these things? I’ve got to find that guy’s information and see if maybe they’ll talk about why they thought it was valuable — and they’re not even in the DIB. How do you know? That’s the whole point — it’s something I’ve been saying all along. It doesn’t really matter what the requirements are. We can debate what the requirements ought to be every day, and they might be a different case for different things — different threats, different technologies. The same evergreen controls are always going to be the same evergreen controls, but there’s a million different ways you could specify a minimum baseline or a recommended whatever. The point is: whatever requirements you pick, whatever number of requirements you pick, how do you know that anyone is doing them? That’s the gajillion-dollar question — how do you have any assurance that they’re doing it? Anyways, that was quite a question. That’s a fun one.

All right. Gil says, “Why are you saying the CIO is not the responsible party?” Okay. So, the DoD CIO owns the CMMC program — it’s part of her portfolio of programs. The Under Secretary for Intelligence and Security owns the DoD CUI program. They are the SAO — I can’t remember what that stands for, but they are the agency’s responsible party for the agency’s CUI program: the Under Secretary for I&S. So the DoD CIO — this is part of how the bureaucracy works — the DoD CIO isn’t in charge of the oversight of the CUI program. So if you go to the DoD CIO and say, “The CUI program is all jacked up and it’s not working correctly,” the DoD CIO is going to say, “That’s not my program, it’s the I&S Under Secretary’s program.” Now, they might make recommendations, they might go over there and beat them up, they might go over there and take their lunch out of the refrigerator in the break room, because they work down the hallway from each other — I don’t know. But ultimately, they aren’t the decision-maker in charge of that program. Similarly, the Under Secretary for Acquisition and Sustainment is in charge of other things. We actually had a question come in that’s related to this exact question, based off what Gil said: “Who actually decides whether something like CNC G-code is CUI?” Ultimately, if you want to go all the way up into the reactor itself of the bureaucracy, to the headwaters of the policy — the Under Secretary for Research and Engineering, OSD(R&E), are the ones who would make a call about what kind of data is or isn’t going to be controlled, classified, unclassified, all of those things. Now, how that guidance trickles down into policy, into training, into decisions at the program level, into decisions at the prime level, as it filters through the system, is another problem. But you can imagine how that would work. Take CMMC policy: the DoD CIO’s office set CMMC policy in the 32 CFR 170 regulation. There is no November deadline. There is no requirement to get a certification to bid. There is specific guidance that says you only need to require a CMMC Level 2 C3PAO status when specific types of data are involved. And what ended up happening? Nine months into the rollout, people are like, “November is a deadline, I need the certification to bid, and everybody needs Level 2 regardless of what kind of CUI they have.” That literally is not what the policy says. But as it trickles through the ecosystem, those are the interpretations that happen.

Daniel: Not only that — primes are articulating that. That’s the devil.

Jacob: Exactly. So R&E has to, like all the other Under Secretaries, give constant care and feeding and training and oversight and governance. That’s literally their job — over making sure the CUI program works, over what are called program protection requirements: what data is classified or not, what data is controlled or not, is G-code CUI or not? These are positive decisions they have to make and train and maintain and monitor and govern constantly — and they don’t. Which is why, out here, nobody freaking knows if G-code is CUI or not. There are very convincing cases on both sides of the debate about whether or not it’s CUI. I remember a couple years ago, I was in the room at the AIA headquarters — I don’t even remember how I ended up in there, it was definitely an accident, because I haven’t been invited back since — where all of the Under Secretaries were on one side of a comically long meeting-room table, and all of the CISOs from the primes were on the other side, and I was in the corner, literally in the corner. And the question came up: is G-code CUI? I cannot remember her name, but I’ll look it up — the then-Under Secretary of R&E said, “We don’t know. We have to make a decision.” And they’ve never made a decision. So this is what Brad was saying in the chat earlier, where he was referring to the fact the department doesn’t have a single accountable leader. This is a concept — we’re getting a little cerebral here today — this is a concept known as an accountability sink. Very interesting idea, check it out. Because the department can do this and say, “Well, that Under Secretary is in charge of that, and that Under Secretary is in charge of that, and I’m in charge of this.” Nobody ends up having to actually do anything to fix this problem. And the real problem is that they’re all correct. It is true that the CIO doesn’t own it, and that those people own it, and within their realm of what they’re responsible for in their stovepipe, they think they’re making all the correct decisions.

Daniel: Yep. And this is a little frustrating when new leadership shows up into these roles and they talk about fixing the bureaucracy like they’re just going to press a button and fix what is ultimately a cultural problem.

Jacob: Yep. They are not the first person to come in — from inside the government, from outside the government — who hates this stovepipe system. I always say that railing against the bureaucracy hasn’t really given us any progress. You really need somebody in there who’s going to leverage the way the bureaucracy works against itself — like, “I know who’s in charge of this part, and I know who’s in charge of that part, I know what belly button to press, I know how the game works.” But we keep putting people into these positions who hate the bureaucracy, so they reject the bureaucracy, and then they’re gone in a year or two, and nothing actually happens. And we still don’t know if G-code is CUI after all this.

Daniel: We still don’t know.

Jacob: But ultimately, when you get down to who decides whether something like G-code is CUI, there is always the get-out-of-jail-free — well, not technically, if you ask Honeywell. DFARS 7012, paragraph M, at the very bottom, has been the same for 10 years: it says the contractor decides whether data retains its identity as controlled defense information. So, what do you think, Mr. and Mrs. Contractor? Do you think that G-code is CUI? Because the DoD is not going to tell you, your prime is not going to tell you, your contracting officer is not going to tell you. You can find a case that it is, and you can find a case that it isn’t. And DFARS 7012 has — to use a term of art from today — unleashed your flexible decision-making to decide whether it is or is not CUI.

Daniel: Ryan Bonner was on the show, I think for the CUI Hotline, a few months ago, and we went through that same thing, and it was like — yeah, a lot of times detailed CAD would fall into scope, but G-code doesn’t have all of the capability to be able to reproduce the actual thing. Right? To create or reproduce a military or space application, for controlled technical information — if it only has a single part of it to be able to perform that reproduction, no. Ryan Bonner’s pretty firm in the “G-code isn’t CUI” [camp]. But the problem is, to your point, Jacob — if the DoD can’t even articulate it, how can we expect anyone else to be able to articulate it, when they own that particular CUI category, I guess I’ll call it?

Jacob: Yeah. Ryan makes a very convincing [case] — he’s primarily the one I’m talking about whenever you look at the case that says it’s not CUI. And here’s the thing: if something happens and it gets compromised, who’s going to tell you that it is or isn’t? Are you willing to accept the ambiguity? And this is a thing I’ve seen come up in the Discord and some other conversations. People are really, really adamant that this CUI issue is the problem, and they use the G-code example as the example.

Daniel: Yep.

Jacob: And I’m not saying they’re going to do this, but — we have said many, many times on all of our content, every time people ask the government for a decision, they don’t like the answer they get. If you had to bet, just based off what you know and what you think about the nature of the government — do you think, gun to their head, G-code is CUI, yes or no? That they’re going to say no?

Daniel: They’re going to say yes every time.

Jacob: They’re going to say yes. They always are going to default to risk aversion. That’s just culturally what they do. I mean, I hope they wouldn’t, and they’d come up with a reason — but if you forced their hand, what do you think they’re going to say? They’re going to give you the government answer, and then all of a sudden all the G-code is CUI — whereas right now, you have the freedom to say that it’s not, and you have the ambiguity to make the case: “Shut up, leave me alone, go worry about the actual CUI, this isn’t the CUI you’re looking for.” The second they come out with a policy that says it is CUI, that’s a wrap.

Daniel: That’s a wrap.

Jacob: So I’m not saying don’t bring it up as an issue. I’m just saying it’s making me really uneasy about how much of an issue this is. The pattern we’ve seen from history is that they’re going to say it’s CUI every time — and then Ryan’s going to have an aneurysm, and we’re not going to be able to have him on the show anymore.

Daniel: That’s true. RIP.

Jacob: All right. “What happens if the DoD’s 60-day CMMC review ends without any new guidance?” Nothing happens. Keep self-attesting 88 of 110 appropriately.

Daniel: Yeah. Implement the controls you’re supposed to. Your requirements are still the same. You still have to comply with DFARS 7012 if you have the data.

Jacob: The government is still going to be bad at telling you if you have the data. The primes are still going to tell you to do it anyways. And you shouldn’t have to achieve a C3PAO CMMC Level 2 status in order to win a contract award. They could take 60 days, 90 days, 600 days — those are still the requirements that are on the books. I don’t think we’re going to go very long without hearing something out of the CIO’s office, for various reasons — political, reputational, whatever. I would be very surprised if we don’t hear something by the end of the month. I don’t think it’s going to be next week, because of the holiday. But we’re definitely going to hear something by the end of the month, is my bet.

Daniel: I think if it’s something that shows them as friendly toward small business, we’ll know before November 3rd. I think they’ll delay if they decide they can’t actually do anything about the rule and it’s still going to impact small business — we’ll hear that November 4th, probably.

Jacob: Yeah. So we’ll see. I mean, listen — not a political show, but depending on how November goes, the government might just stay shut down. So even if they come out with a rip-roaring plan to change everything in a hurry, it might get frozen like everything else because of a shutdown. So, I don’t know. I can’t wait to see what they say.

All right. Mr. Levy says, “Other than the urge to do the right thing, what other incentive would a defense contractor have to decide that certain data they produce is CUI? Seems to me that if a contractor is not required to identify a certain type of data as CUI, they wouldn’t.” Yeah, they probably wouldn’t. This is — whether you’re a glass-half-full or glass-half-empty type of person. The original authors at NIST for the 800-171 CUI baseline, and at NARA, and the original DoD collaborators on that document, had the fundamental assumption that companies were — to borrow a term from economics — rational, self-interested actors. They are already self-motivated to protect their own intellectual property and confidential data, therefore it should not be a big bridge to cross for them to also be protecting government information. And they used that assumption to absolutely rip apart 800-53 controls. They were like, “We don’t need to specify details, we don’t need to tell anybody how to do anything, we don’t need to do anything except specify very high-level, broad ideas, because they’re clearly already doing stuff like this. There’s no way companies wouldn’t be doing these basic things — that would be an unbelievable level of risk they’d be taking with their own data.” Turns out — talk to the people that I talk to. I’ll tell them it’s like — honestly, they really might say they care on paper, but most organizations I’ve seen, by their actions, don’t really care.

Daniel: Well, yeah. There’s lots of reasons. In conversation, they probably actually do care — they’re like, “Yeah, I would love to have better cybersecurity.” It costs money, it costs time, it costs skills, it costs expertise. “I don’t have those things, so it doesn’t get done.” It’s just another priority that isn’t a high enough priority to actually get finished. That doesn’t mean they’re bad people or bad companies — it’s just how the economics works. And so there isn’t going to be that incentive.

Jacob: Had there been that incentive — as we’ve talked about before — had, during CMMC rulemaking, in that long five-year purgatory, DIBCAC gone out and run assessments and been like, “Actually, everybody’s doing all this stuff, they’re doing stuff beyond what the baseline says, stuff we don’t even require,” you would never have had the case for an accountability mechanism. If the DoD report had not found that contractors were not compliant, none of this would have ever happened — they could have just put in this self-attestation and taken everybody’s word for it. Not so long ago, the people in charge of DoD rulemaking were like, “We hope we don’t have to keep specifying minimums, that companies just sort of start doing security and exceed the baseline, so we don’t have to keep doing this.” Not how it works. Sadly, not how it works.

Alrighty. Rachel says, “Yeah, they’ll point to OPSEC.” Yeah. So, the OPSEC thing is kind of the catchall they’re going to use in terms of saying everything is going to be CUI — liability issues at the prime, OPSEC from the prime. The common thing I’ve heard from program managers at major prime contractors talking to their government customer: they’ll go to their government customer and say, “Is this data CUI?” and the government will say, “Everything we sent you is CUI.” Now the decision is on the prime. And they don’t — contrary to popular belief — have the budget and the people and the time to dissect the information when it goes from the program office over to supply chain, over to their supply chain questionnaires, into the flow, all that other stuff. And so it just sort of evaporates. So even though that mechanism exists in DFARS 7012, nobody uses it, and around and around we go.

Which — not to rain on everybody’s parade — I have a magic button for you. Press this button, and we’re all going to wake up, come back to work on Tuesday, and every single shred of CUI is going to be properly marked and identified by the Department of Defense. Hallelujah, everybody, we solved the problem. Is that going to prevent the primes from telling all their suppliers they need CMMC Level 2? No. I’m not saying they don’t need to fix that problem — but I cannot stress this enough. I saw a company out there on LinkedIn hyping up their RFI response, and they were like, “The DoD needs to put the mega-primes in their place. They need to slap these companies around and tell them to stop requiring Level 2 where it’s not needed, and to stop overmarking the CUI, or requiring things when they don’t even flow the CUI down to them. We told the DoD they need to do this, because somebody had to.” Brother, I don’t know how to tell you this — that’s not how it works. The DoD can urge and tell the primes to do whatever they want. The prime’s behavior is its own problem. So even if you were to fix the marking — I hope they fix the marking — we’re not going to be out of the woods if you press that magic button. We still are going to have structural issues that we have to address through training and guidance and governance from R&E and A&S and the CIO. So there you go.

All right, let’s see. “If a subcontractor never receives CUI into its own systems, does it need its own CMMC Level 2 status?”

Daniel: I mean, the question comes back to: what does your prime say? Because primes are going to work with people who are able to meet the requirements, theoretically. Now, I talked to some supply chain managers about DFARS 7012 back in the day. I was like, “Why don’t any of you do a better job of verification, or actually use tooling that goes down to the assessment-objective level to actually know if your supply chain’s genuinely meeting these requirements? Why don’t you include FedRAMP requirements? Why don’t you include whether they’re flowing it down to their subs?” And they’re like, “The more we know, the more we’re liable for. Period. Hard stop. Our legal team will not allow us to obtain more than the minimally viable information.” Yep — that is the lawyer answer. And so, in the case of CMMC, that’s the minimum viable for them to collect. So they’re going to collect your cert, they’re going to collect your self-assessment, your conditional status, whatever it is, and they’re not going to ask a lot of questions. And the reason the primes didn’t ask questions of subs, in my opinion, is one of the major reasons the CMMC program exists in the first place. Because if the primes would have moderated the larger supply chain and only actually worked with people who were preserving the cybersecurity and confidentiality of CUI, then we would have a way smaller supply chain — number one — but we would have one that was actually meeting and adhering to the requirement. So I look back across this whole thing and I’m like, if the primes would have just done a better job of enforcing and moderating the cybersecurity hygiene of their supply chain — even at just the tiers they can see — a lot of this would have gone a lot better.

Jacob: Oh yeah, absolutely. Alrighty, let’s see. “What is the difference between being NIST SP 800-171 compliant and being CMMC assessment-ready?”

Daniel: That’s such a good question, and we get that question a lot. If you look at the False Claims document, it refers to NIST 171 a lot, and people are like, “Oh, Honeywell wasn’t doing NIST 171.” It’s like, well, they really weren’t abiding by the contractual obligation, which is DFARS 7012. You have to do FedRAMP Moderate or equivalent clouds for CUI, whether that CUI is encrypted or not. You have to implement all the controls of 171. You have to do the assessment objectives, policies and procedures, SSP, POA&M. You have to flow down incident response as part of DFARS 7012, and respond to incidents within 72 hours. Now, those last two aren’t in the CMMC program. CMMC is just validating a couple of major things: have you implemented the controls, on the appropriate clouds if you have them? That’s really the main gist. And so you have to do those two major parts of DFARS 7012 to be able to adhere to the CMMC requirements to go through an assessment. Because you can go buy an assessment today — I know a bunch of salespeople who would love to sell you an assessment at some of our partners — but at the end of the day, if you don’t have and can’t meet those requirements, you’re going to fail that assessment. So: FedRAMP Moderate or equivalent implementation of the controls, meeting either the minimum requirements for conditional status (which is called out by 32 CFR) or meeting all of the controls for the ability to receive a final status or final certification. Those are the main differences.

And I agree with some of what the CIO has been saying — which I know is a crazy thought — simply because a lot of the feedback is like, there’s not a good, easy-to-digest version of this. “What do I have to meet in 7012?” is one thing. “What do I have to meet in CMMC?” is the same, yet a little bit different — it’s reduced just a little bit. And the question I have — and maybe you’d be a good person to ask, Jacob — is: what is the federal government’s obligation to make sure that contractors understand the flowdowns they’re given? Is it even in their wheelhouse to have to do this, or should that burden truly rest on the primes and the subs?

Jacob: I mean — this isn’t a philosophical show, but I’ve had poll questions about this on LinkedIn before. People have said GAO found this all the way back in 2021 — GAO was like, “Companies don’t know how to do any of this stuff.” NDIA’s cyber survey in 2024 — companies don’t have the in-house understanding of how to even understand what the requirements are. It doesn’t even matter how you write them; they don’t even have a full-time person in their company who could possibly understand them. And with the unemployment rate — or the employment rate — in cybersecurity even to this day, even if you wanted to find those people, it’s very difficult to find.

Daniel: It’s negative unemployment. It’s crazy.

Jacob: And so it gets to this question of: okay, is the government responsible for teaching you how to do any of the other things that DFARS requires you to do to win the contract? Like, can you bid on a contract to machine precision parts without having the ability to machine the parts? Can you bid? Sure. But then, if you win the contract, is it then the government’s problem that you don’t have the equipment or the people or the know-how or the budget in order to do it? That would be absurd. And so it comes down to this: do you think the government is responsible for teaching everybody how to do these things, or are they going to go with a market solution and say, “We want to work with the people who can do these things”? Which then gets into the problem when 75% or more of the market can’t do those things. Do you either remove the requirements, remove the requirement to prove you’re doing them (which is effectively the same thing), or do you help them in some way? The biggest issue I’ve heard from the inside is that people in the various administrations, on both sides of the aisle over the years, have basically been like, “We have to have these requirements. We have to have them prove it.” And they go, “Okay, well, now it’s time to pony up the money and the help and the resources.” And they go, “We can’t do that.” And you’re like, “So, what are you going to do? What is the answer?” And for all I can tell, based off what’s going to come out of this review in September, it might just continue to be a mixed bag.

Daniel: Yeah, that’s probably the most likely situation.

Jacob: They’re going to come out and say, “We’re going to do assessments in some cases, we’re going to do self-assessments in other cases, we’re going to seek to increase requirements in certain cases, we’re going to seek to do all these other things, these minimums are still the case.” There isn’t going to be a clear-cut answer, there isn’t going to be a magic button they can press. They’re going to say some things that are just words, they’re going to do some things that are actual actions, and we’re just going to have to continue going forward, having to juggle all this stuff, because it just isn’t that straightforward. And — a personal question — what do you think? Do you think the government is responsible for teaching contractors how to do the things specified in the solicitation or not? Because if they do it for one thing, they should probably have to do it for all things. It’s also a bit of a question where a lot of people are like, “Cybersecurity is fundamental, it’s fundamental to the business.” And then you go, “Okay, well, if it’s fundamental to your business, then it’s reasonable for us to expect that you do these minimum things in order to do business with us.” And they go, “No, no, no, that’s a bridge too far.” And you’re like, “So it’s not fundamental to your business” — which is fine. But can the government choose to work with people based off their preference, or are they obligated to give contracts to people who can’t meet the requirements? Can the requirements change? Should they change? Yeah. But eventually you’re going to have to draw a line somewhere. Is CMMC in its current form the line? Maybe, maybe not. But you’ve got to draw the line somewhere. So, that’s a bigger philosophical question.

Speaking of which — “Will the DoD ever create different compliance paths based on company size or CUI exposure?”

Jacob: Based off their policy that they’ve maintained since 2011, no. What will they say this month? Nobody knows. The rule and the regulation and the policy of the federal government — not just the DoD — is that the size of the company does not determine the sensitivity of the data. The data retains its own sensitivity, regardless of whether one person is handling it or a 10,000-person company is handling it. And 800-171 is the federal minimum baseline for that data, regardless.

Daniel: Yeah.

Jacob: People then say, “I shouldn’t be responsible for doing the same thing as a 10,000-person company.” You’re misinterpreting the floor as the ceiling. That’s because, for a one-person company, 800-171 is a lot; for a 10,000-person company, 800-171 is trivial — because that’s how minimum baselines work. It’s harder and harder as you get smaller and smaller. So, NIST has not made guidance based on company size. NARA has not made guidance based on company size. The DoD has maintained for 15 years that company size doesn’t influence it. Similarly, they have not made different policy guidance based off the amount of CUI you have. They do have policy that says the type of CUI you handle is what determines the type of assurance they need — only the defense categories of CUI would trigger the requirement for a third-party assessment, according to their last iteration of their policy. So, do small businesses get a different baseline? Not according to what’s on the books. Should the baseline be different? Sure. How will that be different? I don’t know.

Daniel: What I hear people murmur in the hallways, if you will, is like, “What if we did a tiered POA&M requirement, where enterprises — based on NAICS codes, whatever you want to do — can POA&M 10%, and small business can do 20%, here are the controls they can and can’t [POA&M]?” And I was thinking about that the other day, and I’m like, if they did a tiered POA&M allowed-list based on size of company, they’re literally just showing our adversaries who the weakest link in the chain is — if it’s not all the requirements applied to where the data sits.

Jacob: I’ll give you a different angle. I’ve said this a million times: if the government says, “We’re willing to accept self-attestation for some of these requirements” — just get rid of them. You know that self-attestation doesn’t work. So if you’re willing to accept the risk of knowing that if you don’t require proof, it won’t get done, then just don’t require it. Period. And so — I don’t say that 800-171 in its current form is the final form it should take. I’ve given entire conference presentations on how that baseline should change and the ways they could change it. But eventually you’re going to have a minimum baseline. And the problem you’ll run into is, if you set that minimum baseline to 20 requirements, there’s still going to be thousands of companies out there without a single FTE in charge of doing any of this. It doesn’t matter if you require them to do one thing — they don’t know how to do it. And so, do you cut them out of the supply chain, do you just require nothing, or do we go on a third path here and say they need money and assistance and all these other things that Congress and the government and the agencies are very reluctant to do at all? What we’re currently trapped in is this circular thing, where we’re pointing at the assurance mechanism and the requirements like they’re the problem — and if we just fix that, it’s going to fix this other broader issue. And I’m not sure that’s going to be the case. But we’ve got to wait and see what they’re going to end up saying at the end of the month.

All right, last question here, and then we’ll wrap up. “What if a subcontractor is a single person working under 1099 — complete implementation of 800-171?”

Daniel: So, this is what’s fun. As a 1099, you could actually fall under the boundary of your prime, if that’s the work you’re doing. The problem is, you couldn’t use any of your personal assets or your company’s assets as part of your CMMC scope or the CUI scope, because the scope would follow that of the prime. So we know 1099 people that are supporting a prime, using all of the prime’s systems as part of their boundary. So the question comes back to: if you’re a 1099 and you’ve got to use your own assets to do the work, that’s the conundrum — because you can’t process, store, transmit CUI, because they’re not part of the prime’s boundary. So long story short, you can dance around that a little bit as a 1099, but you’re going to sacrifice being able to use your systems in performance of that. But if you’re collectively using all of their systems, following their authorized user policy, fill in the blank, yada yada, then you can continue to work for them as a 1099.

Jacob: Yeah, there you go. So, what are they going to say? What’s the rule going to be? I don’t think we’re going to hear next week. Maybe we’ll find out live on the Hotline on a Friday. Are they going to drop the update on a Friday? I have no idea. But we’re going to have to see what the decision is going to be. It’s going to be sometime soon. Either way, we have a lot to ponder over the Labor Day weekend, as I hope the DoD is pondering what they’re going to do here. And then we’ll go from there. So, yeah, we got a little off into left field here today on some of the broader questions, but this is probably the time to think about them, because soon enough we’re going to have some actual policy to sink our teeth into, and that’s going to be the direction everybody’s going to have to move in. Hopefully we have some real policy decisions and not just more talk. So, we’ll go from there. We’ll be back live next Friday. We’ll be in Cambridge at Summit 7 Live coming up here soon, in two weeks. So if you want to join us for the midnight-release live watch party of the DoD’s new policy, then maybe we can all do it together out there on the East Coast — hopefully I’m not on an airplane whenever it drops. Like and subscribe. We’re going to have the Honeywell Aerospace whistleblower coming up here soon, check that out. You can find us at summit7.us, you can find us on LinkedIn, you can shoot us DMs. There were a ton of awesome questions in the chat, we didn’t get to all of them, so we’ll add them to the queue for next week, pick up where we left off, and we’ll see you then. Happy Labor Day.

Daniel: Yep. Happy Labor Day. See you guys.

Contact

Speak With Our Team

Scroll to Top