Brief: The CUI Hotline — Jacob Horne & Daniel Akridge (plus guest Brad) recap the Billington Cybersecurity conference and DoD CIO Kirsten Davies’s remarks, then work through the “suspension readiness gap” and clear up the class-deviation confusion before taking listener questions.
Key takeaways:
- The Phase 2 suspension is a pause on the third-party certification requirement, not on the underlying controls — contractors who stop working toward 800-171 are creating a readiness gap they’ll pay for later.
- The “new class deviation” everyone panicked about is Revision 3 of unrelated Chinese-tech/supply-chain guidance — not new CMMC guidance. Don’t conflate them.
- Davies’s Billington messaging leaned on speed and DIB expansion, consistent with the suspension framing but light on a concrete path forward.
- Listener Q&A hit the usual practical ground: FIPS/BitLocker validation, ODPs, cage codes vs. SSPs, other transaction authority, and export control / GCC High.
Transcript
Jacob: Everybody, it is Friday. It is hotline time. We are live on YouTube, we are live on LinkedIn. You can find us at cuihotline.org. You can call the number, you can send us DMs, you can send smoke signals, you can interpretive dance and then live-stream it — let us know. We’ve got a bunch of questions in the backlog, a bunch of questions in the chat. I’m sure everybody has lots and lots of questions.
Daniel: I have lots and lots of questions. It seems that every day that goes by, I have more and more questions about a codified regulation, which is not how that’s supposed to work.
Jacob: Gosh. But anyways, Brad’s here, so everybody can celebrate. We love it when Brad joins us. So, yeah, I guess we’ll just jump right into it. Daniel — Billington Cybersecurity happened. It’s the premier federal cybersecurity conference that happens after the summer every year, and the DoD CIO got up on stage and gave everybody updates.
Daniel: She sure did. And here’s what’s interesting. So, we perused the video and the content and the transcripts and all sorts of other good things — we had people actually in attendance as well. And I compiled a little bit of a cheat sheet based on the quotes of the CIO. And I put them in two buckets: the bucket that would require you to do more work, or insinuate more work, and then the bucket that said “help SMB.” Now, listen, if you’re an SMB out there, I understand the burden it takes. I am not minimizing your position in any stretch. But when we look at what she’s saying, it almost slightly contradicts itself.
So, first thing out of the gate: cybersecurity is not only important, it’s critical, it’s vital. So there’s some urgency there. Next up: continuous assessments, dynamic cybersecurity to keep up with the threats. Continuous — to keep at the pace of the threat itself. Okay, that’s more real-time monitoring, more requirements, more validation. At this point, operational technology is so critical right now, and nowhere in CMMC was there even a mention of how to build cyber resilience for a manufacturing line — not the intent of CMMC, but let’s say we want to add that in, in a rulemaking change. So now manufacturing’s in scope in ways that it wasn’t in scope for CMMC Level 2. That’s more effort. Last up on the more-work side: how are we going to prove — how do we prove that the defense industrial base is following federal policies? This is still something we need to resolve for. Not to account for there being hundreds of CCAs and CCPs and C3PAOs out there able to perform a validation of that. So I don’t know what we’re still trying to solve for on that side. And then the one major walkaway quote about SMB was: “CMMC was hitting small-to-medium businesses really, really hard, and inappropriately hard. So we have some work to do. It’s coming, though. It’s coming.”
And I’m reading this and I’m like — question out of the gate: how do I say this in a nice way? I don’t think the program was meant to care about the size of an organization. It was really meant to care about where the data went and protecting the data. And so we’re changing the whole mindset and methodology between protecting controlled unclassified information, which is problematic. Now, listen, if they want to modify some POA&M requirements for certain thresholds of business size, maybe that’s a good path forward. But at the end of the day, it’s less about the size of the org, more about protecting national security — which was the intent of DFARS 7012. It’s now the intent of FAR CUI when it comes out. It was the intent to validate people did the right thing with CMMC. And I’m just confused by these takeaways and these comments. I don’t understand how, out of one side of your mouth, you can preach five times more requirements and more things to do, in alignment with mostly what CMMC’s already built, and then in just one takeaway phrase say, “Well, we know it’s hard for small business, we’re going to do something about that.”
Jacob: I’m right there with you. I’m right there with you. The thing — if you guys didn’t watch it, from the Sum IT Up podcast two weeks ago, we talk about this exact thing. And the line I’ve been using is: everyone is clapping so loudly for the CMMC suspension, you’re not hearing what she’s saying. Since February, as far back as I can find quotes from her, she has said that the 800-171 baseline isn’t enough, that there is too narrow a focus, that the controls don’t go far enough. Everything she’s saying is that the controls need to expand, that the baselines need to go up, that people need to do more, that we need to expand into other domains of technologies — that there’s just more and more and more stuff that we have to do. And I don’t disagree with her, but like you said, in the next breath she’ll say cost, burden, impact, small business, and it’s like — how are you going to square those things?
To your point, the review of the CMMC program should be a review of the program. But because they overscoped the RFI, we’re talking about all kinds of stuff that’s outside the scope of the program. So instead of focusing on additional POA&M items that could be allowable, POA&Ms that could be different based on company size, the nature of the assessments, what’s done in an assessment, when assessments happen, when assessments are required, how the assessments are run, evidence types, sufficient amounts of evidence — everything within the scope of the assessment program is what the review should be focused on. We’re out here talking about OT and CUI and all these things, resiliency.
Daniel: Yeah, which are great.
Jacob: But a lot of that stuff is stuff she doesn’t even have any control over. And two — what does that have to do with the program? Because when she says CMMC was having an effect on small businesses, is she talking about the actual program itself, or is she talking about DFARS 7012? Are we talking about CUI? There are no questions that get asked during these presentations. No one asks her a question from the audience. There’s no more CS2 out there anymore, sadly — because CS2’s thing was, we would get DoD people on stage and just let it rip. People could just ask questions. So I want somebody at the current DoD leadership team to explain to everyone, in their own words, what is the CMMC program? What, in your mind, is the program? Because the CMMC program was designed to solve a very specific issue. DFARS 7012 has a policy hole in it that you could drive a truck through. It imposes requirements to protect data, and it never asks anybody to prove that they did it. So the program plugs that hole. If you’ve got a problem with how it plugs that hole, fine. If you have a problem with the requirements that it’s verifying, that’s a different set of problems in a different Under Secretary’s office.
So — I’ll get off my soapbox here in a second — we say this all the time: stop asking the government for answers, because now that they overscoped the RFI and we just said everything is CMMC, everything is up for grabs, and now once the dust clears, your requirements are going to go up. That’s not the way it’s supposed to work, but that’s what’s going to happen. Just look at what she’s been saying.
Daniel: Yeah, it’s crazy.
Jacob: Two weeks ago, in that podcast — back in February, she said, “It’s so critical, in the world of technology and risk resilience initiatives, that we don’t just look at the confidentiality of data.” And that brings us to the podcast we did this week, where the suspension has made this way worse for people, because all of these ideas can’t be turned into requirements without rulemaking. And that rulemaking takes time, even if you got the waivers to go fast. And in the interim, people are going to have other agency rulemaking come down on top of them because of the vacuum formed by the CMMC suspension. And the DoD apparently has no plan for how they’re going to insulate contractors from wrestling with those things. And it’s all their fault. Like and subscribe, everybody, because we have way more stuff to deal with as a result of this suspension than we did before this suspension. Like, way more stuff.
Daniel: But anyway, at a high level, it feels like this whole RFI and everything they’re doing right now is like they didn’t actually read what CMMC was. They didn’t understand that it was verification — assessment of the requirements being implemented. They didn’t understand that it’s the same no matter what size the company is. They didn’t understand any of that. And then they put this RFI out there, and then everybody is up in arms, and the scale of the damage that was done to the industry is just crazy. Because you’ve got different people — you’ve got people that are doing the right thing, and you’ve got people that are like, “Yay, I don’t have to do this anymore.” You still have to do it. It’s still in your contract.
Jacob: Yeah. You could just rip up the statements she’s made on stage for the last two months, because it doesn’t line up with the stated intention or the justification for the suspension. And as a result, I don’t know how the task force is going to get out of this corner they’ve painted themselves into. So we’ll just have to see.
Anyways, Brad — we were talking before we went on about what I’m informally calling the CMMC suspension readiness gap, because we’re seeing a distinct split where companies took the news about the suspension and just stopped working. Not just that they stopped preparing for assessment — they just stopped everything. And then we’re also seeing companies that saw the suspension and it didn’t really faze them. Like, they’re still moving forward, because they still have the obligations. I think, in my analysis, this is a split between companies that understand how liability works and companies that don’t. Typically that line generally is split between small, and medium-plus size businesses — but not always. What are you seeing? What do you think?
Brad: Yeah, I think we’re seeing that split across all of our existing clients and new clients that are coming in — and, Daniel, clients that you’re talking to. We had a lot of clients that were in process, had just signed, and then the pause is announced, and then you go and talk to them, and they’re like, “No, we still have to do this. We’re still contractually required to do this. We want to do this the right way. We want to make sure we’re meeting these requirements. We’re not stopping. It’s all ahead full.” And then you’re always going to have those small — especially the very, very small ones, the micro businesses — that are like, “This is a huge cost for me, and I don’t know if this is the way I need to go,” and there’s timelines involved with when they think they’re going to have to meet the requirements. It’s very complicated the smaller you get. But a lot of our clients — new clients especially — have been wanting to do the right thing and making sure they’re meeting those requirements. So we’re not stopping. We’re keeping going. We’re implementing their requirements and helping them get ready.
Jacob: Yeah. I’m glad to see the difference now between 2021. Back in 2021, people were made aware of their existing obligations for the first time as a result of CMMC. Over the years, people conflated CMMC with those requirements. But I think, in some small part, thanks to our content and outreach and a lot of other people, it started to sink into folks that CMMC is a separate program from the clause imposing requirements on you. And so while we were waiting for rulemaking, people still had the obligation. After we had the rulemaking, and we earned a phased rollout, you still had the obligation. Now that we’re in whatever this is, you still have the obligation in your contracts. So it doesn’t really matter if they rename it to something else or change it. 7012 and how that works is still in there — which is so funny when she’s like, “Oh, CMMC was affecting small businesses.” It’s like, does DIBCAC decide who to audit based on business size? They decide to audit people based on the data that they have.
Brad: Yep. Yep.
Jacob: So if DIBCAC is running a third-party audit, or a C3PAO is running a third-party audit, then it’s not CMMC that’s having an effect on people.
Brad: Right. Right.
Jacob: Everybody — but we don’t get to ask questions at these events, so I don’t know what they’re going to say.
Daniel: Here’s the part that gets me every time. Let’s take the terminology “CUI” off the table. Brad put this in chat just a second ago — the amount of export control data that has been grossly mishandled, and I’m talking like true negligence, is shocking. I was saying, if you blew up the CUI program and just said “just protect export control data, or ITAR,” which they’re already supposed to do — that might even end up being the exact same thing for the sake of the DIB in most cases. Not every case, don’t get me wrong, but I have to imagine somewhere north of like 70% of the CUI is probably also in part export control.
Jacob: 60, 70%. It’s not a trivial amount.
Daniel: Right. And so, when you’re looking at this — the amount of people that are dropping CMMC, and “dropping” is the wrong word, reconsidering it — this is mostly small businesses, because they don’t want to sink the cost in for something that might go away, even though they don’t realize this has been a contractual obligation for a decade. But what they don’t realize is that they’re usually in gross negligence of mishandling export control data. So even if they chose not to abide by DFARS 7012 because they didn’t believe in this “CUI fairy,” you know who really cares about export control? The Department of State — who’s a very different beast than the Department of War. So you just start going through this and I’m like, for the love of God, people — you have to understand what data you have. I don’t care if you don’t want to protect your own IP, that’s on you. But this is not your IP in most cases.
Jacob: Yeah. You’re a steward. You’re a steward of controlled data.
Daniel: Yeah. This is information that you’re either being paid to deliver, or paid to create, or you have to receive to perform the work — so protect it as such. I get so hung up, because I see so much of this in the ecosystem, that I’m like, the Department of Justice should be making trillions of dollars.
Jacob: If taxpayers heard what we hear on phone calls every week, people would be a lot more upset. And people are reaching out to us in good faith, but it’s a systemic problem. So the status quo does not work — without some sort of forcing function, whether it was inadvertent or tangential or whatever. Without some sort of forcing function, the status quo of what we were doing is an absolute failure. So they’ve got to do something, and the rhetoric around the CMMC suspension is not helping.
Okay. So there’s some good stuff in chat here. Everybody, please listen to me. This kerfuffle about the class deviation this week — please listen to what I’m saying. The class deviation that people were talking about this week, that came out last week, is not any different than the class deviation that was issued in July in order to implement the suspension. So if we rewind to July 13th, Monday, Kirsten Davies comes out with her video and the announcement, with the PR blitz, and says, “We’re suspending CMMC. We’re going to do a review. I’m directing that we suspend this program.” The Under Secretary for Acquisition and Sustainment, Michael Duffy, writes a memo and says, “We’re going to implement the DoD CIO’s suspension of this program to do the following things. The only thing that anybody needs in order to win a contract is Level 1 or Level 2 self-assessment. Do not put Level 2 C3PAO or Level 3 as a condition of contract award. If there are existing solicitations, change them. If there are things coming up for award, change them. If you’re going to issue a solicitation, make sure it’s in line with this guidance.”
Now, here’s the question: how does Duffy’s memo get into the hands of the contract workforce to do what he’s telling them? They don’t look at the memo and then do the work. How do you get that memo guidance into their hands? You have to have a class deviation that gives them new guidance, because if they don’t have a deviation, they’re going with the guidance that’s on the books pre-suspension. So July 16th, that Thursday, the DoD issued a class deviation that said, “Do these things that Duffy just told you to do. Only put in Level 1 or Level 2 self-assessment. Everything else is the same, including the language around 2028.” Because if you remember, just a year ago when the 48 CFR final rule came out, that 2028 language is in there. The only thing the class deviation changes is the statuses that can be put into the blank form for the condition of contract award. No one talked about this class deviation, because everybody was just so overwhelmed by the news of the suspension. I didn’t post about the class deviation because it’s a dusty old class deviation that’s doing what’s in the memo. I literally didn’t even think twice about it.
I think that people started looking around, because they’re expecting to get news 60 days later, and they see Revision 3 of this class deviation. Revision 3 of that class deviation is completely unrelated to the CMMC program. It includes new guidance around Chinese companies and supply chain security and so on. You can find this for yourself — if you go to my LinkedIn post from like Tuesday, I have the links in the comments. You can go to the revolutionary FAR overhaul class deviation page, you can search for 0025, which will take you to the current class deviation, Revision 3. Click on the word document format, and at the top of the header it says, “changes are indicated by a line in the right-hand margin.” And if you scroll down, none of the CMMC text has a line next to it, because it was the text from July. There is no new class deviation. There is no new guidance. People discovered that it was new. People are writing news articles in industry publications like this is new guidance. It is amazing to me that people picked this up and ran with it. It’s understandable — who knows how class deviations work? Why would anybody know that? I’m just letting you know that’s not a new development. That’s how they implemented the suspension. All the text around 2028.
Daniel: Let me put it to you this way. I’m going to hold everybody’s hand while we say this, because it’s going to be kind of a snarky LinkedIn post. A lot of this audience is going to understand what I’m saying. We cannot get onto social media and tell people that if they are talking about the cost of implementation, they are telling on themselves for not complying with DFARS 7012 — and then the next day talk about text in a final rule as if it’s new, because you are telling everybody you don’t know what the policy says of the program you’re shaming people about. If you’re going to call people out on being non-compliant, at least understand what the heck you’re even talking about in the first place, please. My DMs are open. Do you think this is a new class deviation? Just message me. I’ll tell you it’s not new.
Jacob: Anyways, off my soapbox.
Daniel: We’re going to have to do a whole podcast about this. But Jacob — I thought the task force was supposed to release something today. Where are we with that? That’s the piece. There’s blood in the water right now. Everybody, understandably so, is waiting for something to drop.
Jacob: Yeah. So let’s talk about this. Ian brought this up. Everybody’s thinking about it. The suspension of Phase 2 is indefinite. The suspension is not 60 days. That’s why they issued a class deviation in July, not in September. Until they do something different with that class deviation, the suspension is in effect. The only thing that can happen is self-assessment requirements. 60 days is what the DoD CIO gave the task force to do their review. The task force did not begin their review on July 13th. They had to form the task force, which took several days. I don’t even know what the exact date was, but it wasn’t July 13th. As far as I have heard, the task force is done with their analysis and their report, but there was no requirement for them to publish the report. And there certainly wasn’t a requirement for them to publish the report within 60 days. Now, somebody’s going to say something eventually, but like Ian said, Davies was like, “Well, we’re going to have the task force, and then they have two weeks to report it to me,” and this and that. But they never say when the task force was formed, or what that means. So nobody knows. Nobody knows what they’re going to say or when they’re going to say it.
I would imagine — we’re all adults here — I would imagine we’re going to get something before the midterm, for obvious reasons. Read between the lines about why they did the suspension in the first place. I would be shocked if we didn’t hear something before the midterms. Do you think that’s going to help? I don’t know, that’s a separate podcast. I would be surprised if we don’t hear about it before the end of this month. But based off the situation they’ve put themselves in, I don’t know what they’re going to be able to say. And so I’m increasingly thinking maybe it’ll be October — because what are you going to do? You’re going to come out and say, “We’re not going to do third-party assessments”? Okay, well, that’s going to trigger a hearing in the armed services committees. That’s a huge problem. You’ve admitted on stage that you know self-assessments don’t work. So that’s not an easy answer to the solution. You’ve talked about increasing everybody’s requirements. So if you all remember, back in 2021 in November, they got done with their review, they had a press release, and they had an advance notice of proposed rulemaking, an ANPR. They said, “Here’s our plan. We’re going to do rulemaking. We’re giving you notice that we’re going to do rulemaking. We’re going to publish a proposed rule in a year or two.” So none of the policy positions the DoD has suggested they’re entertaining are possible without rulemaking. So, is there going to be an ANPR? Is there going to be less than an ANPR? This is my whole thing — sure, you got 60 days, but I don’t know how they’re going to explain the answer. So I would be surprised if it’s not by the end of this month, I would be stunned if it’s not before the midterm, but it doesn’t have to be today.
Daniel: I wouldn’t be surprised if it’s after the midterm, because I don’t think they can provide good enough news that would trump pausing it for SMB and using that wave to ride through the midterms — and then a week or so after, be like, “Oh, hey guys, we can help you a little bit, but we’re not going to be able to help you as much as we maybe thought.” And they would never say it like that, right? They’d come out with some banner and say, “We’re saving small business, because you can have 10 fewer things on your POA&M,” or whatever. This is going to be either a Thanksgiving Day or a Christmas Day release. I guarantee it’ll be on a holiday, and it’ll ruin Jacob’s whole vacation.
Jacob: I think it’d be a wonderful Christmas, because I can’t wait to see the answer to the riddle they’ve created for themselves.
Jacob: Brad has a good point. There’s also drawing out the difficulty non-practitioners have making the distinction between a data protection program, which is what CUI needs, and an information security program. So this gets back to a philosophical question I’ve asked people on LinkedIn before. Should the government assume that people who are bidding on contracts with data protection requirements have an information security program or not? And if they assume you don’t have the information security program, is it the government’s job to teach you how to have one? Like, if I bid on a contract to machine precision aerospace parts, but I don’t have the skills or the machinery or the team internally to do it — well, the government should teach me how to do it, because I bid on the contract, right? Like, why? That’s not how it works.
Daniel: That’s not how it works.
Jacob: And so it’s like we’ve got Kirsten Davies out here saying we need CMMC to teach manufacturers how to have an OT resiliency program. That is completely outside of what the program was designed to do, what Congress asked you to do, what the problem posed by DFARS 7012 is, how contracts work. Sure, have resources, outreach, environments, all that other stuff — absolutely, if you can find the money, because the authorization bill is already written, so unless there’s going to be a new appropriation, I don’t know where you’re going to get the money from. The fundamental idea is the assumption that defense contractors have an information security program. And if the DoD wants to come to grips with the fact that — per RFI responses submitted to them that were made public — a lot of defense contractors don’t even have a single full-time employee in charge of IT or security… So is the answer, we’re going to constantly go back and blame the requirements for being too burdensome? Any requirement will be too burdensome for a company that has zero people doing IT and security.
Daniel: The math doesn’t math, if you will, Jake. That math definitely doesn’t math.
Jacob: And so you’re going to get stuck in this nonsense loop of, “Okay, if no one has an information security program, you can’t have information security requirements” — which you clearly must have. You’re talking about increasing security requirements and resiliency and continuous monitoring. They still don’t have a body in their company to do the work. And which gets back to the report they’re going to have out. They know all this. They know they don’t have the people. The DoD knows they don’t have the right color of money. So, what are you going to do? The answer, in my mind, was: extend Phase 1, and then wag your finger at everybody, because that was enough to motivate the people who can get there to get there, and then go to the Hill and be like, “People can’t meet these requirements.” Instead, we’re acting like we can change the requirements and also make them go up, in a way that your HR person is going to be able to [handle]. It just — yeah.
All righty, let’s see here. “What is needed to prove the FIPS validation, proper implementation of BitLocker? Only the dump filter has the 140-3 CMVP certificate, but that doesn’t seem adequate for all of BitLocker for satisfying an assessment.” I’ll have to look up which FIPS modules that would be dependent on. Nicholas, come back in just a few minutes — I’m going to go do a little research while I move on to the next one.
Alrighty. Brad says, “There’s an interesting concept that the velocity of changes in the external environment may now be outstripping the speed of the tools the federal government has to adapt.” I mean, the requirements can be updated to meet the threat. They have ways of doing that. They had a rule ready to go that moved everybody to 800-171 Revision 3, that had regulatory waivers for making new regulations. They had all the tools in place, and then they opted to do the suspension. So it might be true that the process for keeping up is slow, but in this case they had all the things they needed on the desk, and then they decided to go backwards. So you can only blame the regulatory process so much when the current group of leadership opted to not take advantage of waivers to that process to go faster. They opted to just admire the problem again, rather than building off the waivers that were already sitting there ready for them to use, by the last team.
All righty. “The 60-day CMMC review is over — what happens now, and when will contractors actually know what DoD is changing?” So, the 60-day review, as far as we know, is done, and the review task force has completed their work. What happens now? They come up with how they’re going to explain the recommendations. Davies didn’t give us any details about what the plan is after the review is done, other than that something’s coming. When will contractors actually know what DoD is changing? Nobody knows. I would imagine the pressure is going to build and build, because — it was summertime, so Congress is in recess. But this is hearing season, September-October timeframe. And if the Armed Services Committees had a hearing while the review was going on, the DoD is just going to get in there and be like, “We’re reviewing, we’re reviewing, we’ll get back to you.” Well, now the review is done. So is the hearing going to catch up? The DoD can make lots of announcements and pronouncements about changes and plans, but all the mechanisms for dealing with those things take a lot longer to kick in — hearings, analyses, GAO reports. So people are looking for an immediate thing where they’re going to say “X, Y is going to happen.” I just don’t think that’s how it’s going to play out. I think they’re going to come out with a mixed bag of statements, probably without a lot of substance, because there’s only so much they can do without actual rulemaking, that’s going to trigger longer-term issues like GAO analyses, CRS analyses, armed services committee investigations and hearings. So we might not know what is actually changing for real for some time, other than rhetoric out of the department. And like we talked about in the podcast on Thursday, that’s a really big problem, because now you’ve got FAR CUI rule issues, you’ve got CIRCIA incident reporting issues.
One thing — this is another thing — if anybody goes to one of these events and you get the opportunity to ask Davies a question: she wrote in her post-quantum crypto strategy in April that they were going to be updating CMMC requirements to include post-quantum cryptography in the CMMC program. They’re reviewing the CMMC program. They’re talking about changing requirements. Is that going to include post-quantum crypto? Can someone help everybody out here and let us know — do contractors need to start learning about post-quantum crypto solutions or not? Because the deadline the federal government has set is the end of 2030, and that’s not very far away.
Daniel: The other thing I don’t understand is that in FAR CUI, they reference the DoD’s ODPs for Rev 3. That doesn’t exist on their website anymore — at least from a direct clickable link. You can still find the PDF if you’re doing a deep, deep search, but when you look at their list of resources, it doesn’t exist anymore. So whatever rulemaking or whatever she wants to do, I have to imagine she’s having to work with the FAR Council, because either they have to reference a new set of ODPs that don’t exist, or create a brand new set from scratch.
Jacob: I emailed the folks at NARA and I&S, and I was like, “This is why you need to define the ODPs for 800-171 and not let agencies do it, because when agencies do it, you end up with nonsense like this. Are you guys the executive agent in charge of this program or not? If an agency wants to define higher ODPs, more to them — that’s what CUI Specified is for. But until you define the ODPs, you have actually not fixed the problem you were designed to fix, where everyone has the same minimum floor.” They didn’t get back to me. They never get back to me.
All righty. “Does the CMMC suspension change anything if DFARS 7012 is already in my contract?” Brad, this is right up your wheelhouse.
Brad: Nope, doesn’t change anything. Still got to do it.
Jacob: There you go.
Brad: I mean, it’s pretty straightforward. CMMC is for assessing and proving that you actually did it, but you still got to do it. And if DIBCAC comes calling, I hope you did it.
Daniel: Here’s the fun bit of it. DFARS 7012 — if you look at the scoring methodology from DoD, negative 203 to 110 perfect score — DFARS 7012 doesn’t mandate a minimum score at all. It just says, “Hey, implement and do all this stuff by December 31st of 2017, and if not, pick up the phone, call the CIO, shoot them an email, and say, ‘Hey, I haven’t done this, here’s why.'” So, fast forward a few years, we’ve got the SPRS system, we’ve got reporting your SPRS score for the sake of your cyber posture specifically added in there. And then that goes away from being able to have a score as low as -203 to 110. And here’s what I tell people all the time: 7012 is still there. 7021 is actually still an active thing that can be put in your solicitation. Here’s the conundrum: the minimum bar just raised from -203 to 88 of 110, through a specific combination of things. Davies did not suspend the minimum SPRS entry for CMMC Level 2 self-attestation, and there is no other mechanism contractually anymore, moving forward, to include self-attesting outside of CMMC. So yes, you have to do 7012, but if you see 7021 coming down the pipe, you have to have a minimum score of your implementation of 7012 at an 88 out of 110.
Jacob: Right. The CMMC suspension didn’t suspend the inclusion of 7021. It limited the options for what could be filled in the blank in 7021. The only thing that can go in the blank is Level 1, Level 2 self-assessment. That’s it — rather than Level 1, Level 2 self, Level 2 C3PAO, Level 3. It took those other two out. That’s what the suspension did. So everyone will get a 7021 Level 2 self-assessment requirement in their contract, and when you go into SPRS, the only way to get the green light is to put in an 88 or better. So what’s everybody going to do?
Daniel: 88 of 110, as Fernando said. No one’s going to purposely self-assess and say, “We didn’t pass.”
Jacob: That’s the whole point. That’s why it doesn’t work.
Brad: Yep. Roll the dice and hope they don’t call.
Jacob: All righty. “Should I keep preparing for CMMC Level 2 during the Phase 2 suspension, or wait until DoD tells us what comes next?” Here’s my thing. If by “preparing for CMMC Level 2” you mean complying with the requirements in DFARS 7012, then yes, you should still be preparing for Level 2, because that’s a requirement completely independent of CMMC. I know that seems like splitting hairs, pedantic vernacular, but it does matter. Imagine Davies comes out today and she just Men-in-Black deletes CMMC from everybody’s memory. You still got 7012 that you have to comply with. And like you were saying, Daniel, there’s no self-assessment, there’s no scoring. By virtue of accepting the terms in the contract, you are making the attestation to the government that you have complied with the requirements in 7012. That was the whole problem that led to the creation of CMMC — to verify, because that policy doesn’t work. So should you keep preparing for that? Yes, because that definitely isn’t going to change. Should you be preparing for the intricacies of a C3PAO assessment? That’s more of a judgment call. You still have to do a self-assessment, like you said, Daniel — and 90% of everything you’re going to do under a self-assessment, under proper conditions, is going to be exactly the same as a C3PAO assessment: evidence collection, what type of evidence, assessment objectives, all that other stuff. So it just depends on what you mean by “CMMC Level 2.” A lot of people point to the requirements when they point to CMMC. You should still comply with your existing requirements.
Daniel: Well, and let’s add another wrench in here with FAR CUI. Let’s say 7012 and 7021 were deleted. FAR CUI comes up over top with an updated version of the requirements that — if you haven’t already started with Rev 2 — is going to be a significant motion, and there’s no phased rollout of it.
Jacob: Nope. And this is a deep pull, and I don’t expect people to know this — I certainly don’t think the leadership team at DoD understands this, because it was too many years ago and nobody remembers. The DFARS 7012 revision in 2016 was originally intended to be a placeholder while they waited for the FAR CUI rule. The DoD was on stage in 2018 and said, “We’re waiting for the FAR CUI rule, because we’re just going to default to the FAR. But we can’t keep waiting for the FAR, because we’re out here getting spanked and everyone’s stealing the data. So we’re creating this DFARS stand-in while we wait for the FAR CUI rule.” Turns out it’s 10 years later and we still don’t have the FAR CUI rule, and everybody thinks this is a DoD-specific thing, and it’s not. This is a huge conspiracy — so everybody strap in. If you remember the DHS CUI rule — the DHS CUI rule said, “Here are the requirements for CUI on federal systems. As far as non-federal systems, we are going to wait for the FAR CUI rule.” They just completely backed out and said, “We don’t have any requirements for non-federal system CUI. The FAR CUI rule is going to take care of that.” So I could see a world where the current DoD leadership team realizes that the number one issue everyone’s dealing with is CUI that doesn’t belong to them — that belongs to the Under Secretary for I&S. They realize that 7012 is a placeholder for the FAR CUI rule, and they want to go over here and talk about OT and resiliency and all this other stuff. So they’ll just say, “FAR CUI rule is out — shred DFARS 7012.”
Daniel: Yep. And so then all of a sudden you have even less recourse about what to do, because now you just have a general FAR clause, immediately go to Rev 3. CUI problems aren’t the CIO’s problems, and then you’ve got whatever other good ideas the CIO comes up with. And this is what’s interesting about FAR CUI: there’s no scoping guidance. There’s not a term called “specialized assets” in the sense of how CMMC scopes that. So it’s things that process, store, transmit CUI in the entirety of the organization. And so when you start looking at Rev 3 without an overlay of additional scoping guidance, and it’s like “CUI assets or bust,” there are elements again of ESAs and SPAs just from a language perspective, but not direct scoping guidance. Then you’re looking at potentially way more in-scope assets than you even had with CMMC Level 2. And by “in scope” in this case, I’m referring to technical application of technical controls. So you start looking at all this stuff, and the DoW CIO could end up getting more OT lean-in with Rev 3 — even though Rev 3 doesn’t explicitly have OT controls per se, but because it follows CUI. You just start looking at this and you’re like, man, they’re just going to wait till FAR CUI, say, “Sorry guys, the DoD tried to make it easier on small business,” and go “bling, bar.”
Jacob: Yep. That’s what DHS did. DHS didn’t even get into the game of trying to do an interim set of guidance — which ironically means that CUI on their federal systems has no requirements to be protected, which is insane. But yeah, it would allow them to say, “We’re following the way the system was supposed to work. We’re back in line with what our original plan was 10 years ago. We’re going to go over here and do real security, while you guys are over here worried about confidentiality. If you’ve got problems with CUI, talk to the Under Secretary for I&S — good luck. And if you’ve got problems with your requirements for confidentiality, go talk to the FAR Council and NIST. Anyways, who wants to do OT security?” That would let them wipe their hands clean of the controversy and the issue. It would let them kick out of the idea of CMMC entirely. It would let them say, “We’re doing real security requirements over here.” And it would ultimately just screw contractors over, because now they have no obligation to explain any of that stuff to people.
Daniel: Yep. Simplify things. The more I say that out loud, the more — maybe that’s what they’re going to do.
Jacob: It’s the perfect out, because they tried, but then they were overruled by the FAR clause.
Daniel: Yeah. And ultimately it’s like, CUI is the problem, I don’t control CUI, and it’s too hard to fix, so I’ll just blame somebody else. “I don’t control this, I don’t control CUI.” So put them back in their rightful place and say, “Go point at them.” What a story.
Jacob: All right. Sean says, “Back in my RMF days, organizationally defined parameters were defined by the organization. Seems like the agency is defining them now. Seems to go against how 800-53 is implemented.” Okay. So, ODPs — organization-defined parameters — are defined by the organization. In this case, for the 800-171 baseline, the organization is not you. The organization, in this case, would be NARA, because they are the executive agent in charge of protecting this data. They are the ones who would define the values to go into those parameters. The whole idea of creating the 800-171 derivative baseline — which is essentially, for the RMF people, a CUI overlay — is that everyone was defining different sets of requirements for the same data, so there was no minimum floor. In many cases there were no defined requirements at all. In some cases there were very specific defined requirements. So when that data — that’s all considered to be the same confidentiality level — flows between these organizations, nothing happens: it gets protected, unprotected, or doesn’t get shared at all. And so they said, “We need to define a floor.” They defined that as 800-171. But they didn’t define ODPs, because they took those variable fields out of 171, even though they still technically exist in 171A. Well, now we’re on 171 Rev 3, and those variable fields are back. So do you let everybody define their own parameters for the incomplete baseline? If you let everybody define their own parameters, you’re back to the same problem the CUI program was supposed to fix back in 2016, by getting everybody on the same baseline. So if the “organization” is the contractors, you have no baseline, because everybody’s got their own. If the “organizations” are the individual agencies, you’re right back into the same problem. There has to be one organization that defines the minimum parameters. That should be I&S — the office inside of NARA that’s in charge of the federal CUI program, in my opinion. But that’s bureaucracy, and people don’t like it, so who knows?
Can you imagine if the FAR CUI rule comes out and they’re just like, “We’re going to let everybody define their own ODPs”? That would probably be the worst-case scenario, because you’re going to have every agency with the same set of requirements but a different set of organization-defined parameters — which means every agency has their own set of requirements.
Daniel: Yep. So much for harmonization.
Jacob: Listen, I would love 37 enclaves. Who wouldn’t love — we’re going to have to make the podcast three times a week.
Daniel: That’s it. You got your FAR CUI version with these ODPs, you got the CMMC version, you got — just change the color of the banner across the bottom.
Jacob: Oh, shout out to Jody — Jody just sent me an email. Thanks, Jody. Nicholas, she typed up a beautiful recap of the FIPS validation piece for you. So feel free to hit me up on LinkedIn, but Jody, thanks for sending that.
Daniel: Nice.
Jacob: All right. “If we’re already building GCC High for ITAR and EAR or other export control data, does waiting on CMMC Level 2 actually save us anything?”
Daniel: Yes and no. So if you’re dealing with ITAR and EAR outside of a federal contract — and in this case, outside of a federal contract that is a defense contract — then you don’t have the overlay of the 171 requirements to implement to protect export control, because Department of State — because there’s no FAR CUI clause, and it’s not ITAR — can exist outside of a federal contract. You wouldn’t have those obligations of the 110 controls. So if you’re implementing GCC High for the sake of export control solely, explicitly not a defense contract, and you’re not obligated contractually to implement the 110 controls, you would still have to do a lot more to catch up to CMMC. So GCC High is a big first step for sovereignty and US-personship — two big things, obviously, for export control. But if you have no means of doing this work on behalf of a defense contract, you’re not obligated to implement the 110 technical controls. So if you are doing export control on behalf of a defense contract, then you’re obligated with DFARS 7012 to also implement the 110. And so that’s the fun little dance with it.
Jacob: All right, let’s see here. “Question from the weeds: for 3.4.6a, ‘essential system capabilities are defined’ — which capabilities are we talking about? Only security, or whatever the system is supposed to do, and security?” I don’t have this one off the top of my head. I’ll tell you what my normal process would be, and what I’ll do after this. I always go to the 171 requirement, and then look in 171A for what the assessment objective is. And when it’s not clear, I go to the 800-53 control that it was derived from, because the 800-53 control it’s derived from typically has more guidance in its explanation, and the 800-53A verification procedures are typically much more detailed than what’s in 171A. That can provide a good clue. If that isn’t enough, you can even go to previous revisions of 800-53, because as the years have gone on, they have taken more and more detail out of 800-53. So sometimes the Revision 3 version of an 800-53 control is more clear than a Revision 5 version. That’s the process I go through whenever questions like this come up, but I don’t have this one off the top of my head.
Daniel: Yeah, that one talks about the principle of least privilege. So that would be applying security trimming to whatever capabilities are there.
Jacob: There you go. Mr. Levy says, “What are the required conditions for two separate organizations with two separate cage codes to be able to use the same system security plan for the same CMMC Level 2 self-assessment?”
Daniel: Yeah, you can have one SSP for two different cage codes.
Jacob: Yeah. I mean, I think RTX probably has 10,000 cage codes, but they don’t have 10,000 SSPs. So there’s no requirement of segmentation of SSPs based on cage codes. Maybe that’s the better answer for you. If we misunderstood your question, let us know and rephrase it.
All righty. “If information is publicly available, decades old, or shouldn’t be CUI, does a CUI marking automatically make it CUI?”
Daniel: Well, CUI should never be public in any form or fashion — which is always fun, but it’s out there all the time on SAM.gov if you’re just looking for a good time to click around.
Jacob: Or YouTube. The SAM.gov back pages.
Daniel: That’s exactly it. So CUI has to have a law, regulation, or government-wide policy. Period, hard stop. And it is not available for public consumption if it is marked controlled unclassified information — also hard stop. So just because something is marked CUI does not always mean it is CUI, because if there’s no law, regulation, or government-wide policy, it’s just not appropriately marked — it’s inappropriately marked CUI. And so you would challenge that with the information holder and say, “Hey, I see that you put grandma’s chocolate chip cookie recipe out on the internet marked CUI, and you threw a distribution statement on it just for good measure. I think you should reassess that, because A, it’s public, and B, I just have a feeling there’s no law governing grandma’s chocolate chip cookie recipe.” And so, hopefully, they would take it back, take it offline, reassess, and either republish unmarked because it’s likely not CUI, or not publish at all publicly because it actually is CUI. That’s how things should work. They don’t work that way. People overmark things all the time because they think it’s the equivalent of legacy FOUO. They think the same type of rules would apply, and that’s just not the case. And now that we’ve switched CUI training in the DoD to every two years, I don’t anticipate that getting any better anytime soon. Which also shocked me — I could not believe they changed it to every two years. They don’t even understand it with every one year of the training, and the training is not that great. So, we’ll see.
Jacob: All righty. Somebody says people submitted questions on the CUI Hotline form on the website — go to cuihotline.org if you’d like to submit your question on the form, and we’ll check it out from there. Also, higher number of people watching than usual. I feel like a lot of people are tuning in because they’re expecting us to be talking about announcements from the DoD. Just to remind everybody, there’s no obligation for them to put out anything at the end of 60 days. That’s the obligation for their internal review to be done. The suspension is indefinite. So I think they’re going to put something out before the midterms. Daniel thinks they’re going to put something out after the midterms. Let us know in chat when you think they’re going to put it out — but there’s no deadline for them to put it out at any given time. I don’t think there’s going to be enough good news that they can actually action without rulemaking and significant delays. I think they’re better to ride the wave until after the midterms, because they’ve got the good small-business voodoo right now where they’re like, “Oh, DoD cares about us.”
Daniel: Hey, listen — not a political show, but I’ll put it to you this way. I would not want to be an appointee after these midterms, because every committee is going to be looking for any wrinkle or seam or excuse to get some camera time. And boy, did you make a big wrinkle with this one. Not saying it’s political, but that’s just how the politics works. So after the midterm, this is going to be crazy.
Jacob: Okay. We got a follow-up from Dan. “So in the case of Rev 2 to 800-53, that mapping is down to Revision 4 of 800-53?” Yeah. So 800-171 Revision 2 is derived from 800-53 Revision 4. 800-171 Rev 3 is derived from 800-53 Revision 5. But compare and contrast 800-53 versions of controls — what’s very fascinating, I personally think, is watching certain 800-53 requirements change not at all in 20 years. So when some people are like, “Oh, these requirements are outdated because they’re from 2016” — you’re like, the idea of least privilege has been the same for 25 years. That evergreen requirement and control and idea has not changed at all. So there’s only so much you can do when people are like, “These requirements are out of date, we need more updated requirements.” That’s true, but it can be very interesting and illuminating to go further and further back into the geological record of where the requirements we’re dealing with today came from.
Okay, form question: “Hi, I’m relatively new to the CMMC space. I’ve been hearing that other transactions are not generally subject to FAR and DFARS. Can 7021 be applied to an other transaction? I was thinking 800-171 can be applied, but not sure if CMMC SPRS scores and all of that could be applied to an OT [other transaction].” Any thoughts on other transaction requirements? Have you guys seen this come up on calls, where people are —
Daniel: It’s funny. I don’t think I’ve ever had anyone ask that. The threshold of buying, which I think is what, $10,000 — the micro contracts, or whatever they call it — being excluded, but I’ve not heard OT [other transactions] being excluded from CMMC. But I’m pulling up the clause right now.
Jacob: Yeah, I’ve heard that one. Let’s see. Somebody put in a longer question about the FAR revolutionary overhaul, including Part 40, Part G. I’ll have to look at that one in more detail, because it’s a question about the proposed rule, so we’ll add that to the backlog for next week. I’m still digging into it though. “Couldn’t we add the fact that the CDI block is to facilitate a reversal of the determination?” — this is in regards to a determination that something is or isn’t CUI. “The block in the lower right has a point of contact in case you want to alter access.” Yeah, the designation block on a document saying something is or isn’t CUI is supposed to say what’s the category of CUI and who do I call about it. That isn’t always the case. It doesn’t always exist. So your mileage may vary.
The language of the rule is: “CMMC program requirements apply to all DoD solicitations and contracts pursuant to which a defense contractor or subcontractor will process, store, or transmit FCI or CUI on unclassified contractor information systems, including those for the acquisition of commercial items, except those exclusively for COTS items, valued at greater than the micro-purchase threshold, except under the following circumstances: the procurement occurs during implementation Phase 1, 2, and 3 described in the paragraph; and application of CMMC program requirements to a procurement or class of procurements may be waived in advance of the solicitation.” So the waiver process — I’m not seeing anything here about OT [other transactions] not having to abide by CMMC.
Daniel: Well — and this is, sorry everybody, this is other transactions, not operational technology. So, everybody — that’s a fun one too.
Jacob: I can’t remember exactly — somebody would have to go check the CMMC FAQs, but I’m pretty sure this came up in there. And from what I remember, the DoD’s answer was that the FAR and the DFARS don’t apply to other transactions, but that CUI needs to be protected regardless of where it ends up — and no explanation as to how data protection requirements end up in other transactions that don’t include FAR and DFARS clauses. So it’s kind of an open question. Maybe they’ll answer that with our review.
Okay, last question here. “We’re just a supplier to a defense contractor. How do we know whether we actually need CMMC?”
Daniel: Well, first off — do you have DFARS 7012? It’s a good leading indicator that you might, although you could just have that clause because no one tried to fight back on the fact that you don’t have CUI. The next question is, raise your hand to your prime and say, “Hey, do you send me CUI these days? When’s the last time you sent me CUI?” Or review what you have internally — this is the better position. Figure out what you’re delivering to these primes, and then figure out if any of it is CUI — meaning it’s not your IP, it’s not milspec, public information, COTS; it falls outside all of those scopes and falls into scope as being CUI. Then you could also know if you actually need to pursue CMMC. The minimum impact is going to be CMMC Level 1 for federal contract information, which you’re going to have that flow down likely at a minimum, for FCI data — again, unless you just have full COTS and that’s all you have. Anyways, you hate to say the word “it depends,” but the question is: do you have FCI or do you have CUI? And if you don’t know, you can either ask the prime, which will tell you you have both even if you don’t, or you can find out for yourself based on what you’re delivering on behalf of that contract vehicle, and then make a case — fingers crossed — to your prime to remove those contractual clauses and obligations to you.
Jacob: Yeah. This reminds me — one of the soundbites people are using out there is, “CMMC is ridiculous, because every moving company with a government contract suddenly has to have all these cybersecurity requirements.” And you’re like, one of two things is happening: either people are arbitrarily flowing down a level of requirements that shouldn’t be there, because those people aren’t dealing with the data that would trigger those requirements — which is not CMMC policy, it explicitly says you shouldn’t be doing that, so I don’t know why you’re mad at the program for people misusing their applicability of requirements — or those people actually are dealing with the data that would need protection, and we’ve got a serious problem on our hands, and blaming the program designed to protect that data isn’t addressing a bigger-picture issue. It’s one of the two. And those are both difficult questions that a review of the program won’t fix, because people, if they have the data, still have to do the requirements, and you’re distracting from that; or people are misusing the program, and overscoping, elevating, accelerating requirements — and it doesn’t really matter what the requirements turn into after the review, they’re still going to do that. So it’s just not that simple. I think there’s a lot of people that have the data that don’t realize they had the data all along.
So there you go. All righty, everybody. Parting thoughts. Brad, what do you think, man? Think we’re going to hear anything at the 11th hour here, before the weekend?
Brad: Nope. I think we’re going to hear something on the next holiday, and everybody’s going to go crazy, and it’s going to be a lot of fun.
Jacob: Brad thinks holidays. Daniel thinks after midterms. I think before midterms. What do you guys think? When are we going to hear the update for the future of whatever the heck they’re going to call this thing? Let us know in the chat. If you find this afterwards, you can leave your comments and questions and we’ll add them to the backlog. You can always go to cuihotline.org and fill out the form — we had some come in, some of the longer ones we’ll have to add to the backlog. You can call the number and leave a message. We always love hearing from everybody. You can find us on LinkedIn, shoot us DMs, find us at summit7.us. We’re going to be at Summit 7 Live Boston next week — actually, Cambridge, it’s not Boston, I know, I know. Come hang out over there. We’re also going to be in Denver next month, which should be wonderful. Check that out, you can register, it’s free — check us out over at summit7.us for the registration link. And yeah, there you go. We’ll see you next week.
Daniel: See y’all.
Contact
Speak With Our Team
Our team of compliance and cybersecurity experts are on standby and ready to help. We’ll walk you through what you need and what to expect.
