The CUI Hotline Episode 100!

In their 100th episode, the CUI Hotline hosts argue that the DoD’s silence on its CMMC review is why their show has to exist. The big news is that CISA’s CIRCIA final rule went to interagency review and will likely publish between Q4 2026 and Q1 2027. With no sign of a deal letting DFARS 7012 reporting substitute for CIRCIA reporting, defense contractors will probably face two incident-reporting regimes, and potentially a third under FAR CUI. The hosts also answer audience questions on CUI marking, cloud options, and whether third-party assessments will return.

Key Takeaways

  • CIRCIA is the rule to watch. It requires 72-hour incident reports and 24-hour ransom payment reports, and applies organization-wide with no CUI scoping.
  • Expect duplicate reporting. Contractors will likely report under both DFARS 7012 and CIRCIA, plus FAR CUI for non-DoD work.
  • No tool decides what is CUI. Software can apply markings, but a human must determine what is CUI first.
  • The November 2028 “Phase 4” date is in limbo. Level 2 certification was never universal, and the November 2026 deadline came from primes, not DoD policy.
  • Third-party assessments will likely return, but changing the rules requires rulemaking. The hosts say assessor capacity isn’t the problem, and RFI data puts average assessment costs near $45,000, far below the SBA’s $600,000 claim.
  • FAR CUI has no built-in certification. Signing the clause is itself an attestation, which creates False Claims Act risk.
  • DoD’s silence is hurting the ecosystem, with providers already pivoting away from CMMC work.

Transcript

Jacob: All right, everybody, it’s Friday, and it is episode 100 of the CUI Hotline. Can you believe it? I can’t. We’re streaming live on LinkedIn and YouTube. You can find us at cuihotline.org, where you can fill out the form or leave a voicemail, and you can DM us on all the social media platforms. You can also find us at summit7.us, and occasionally live and in person at Summit 7 events. We were just in Denver, which was a great time, and before that in Boston. There are more coming toward the end of the year, so check summit7.us and we’ll tell you about them well ahead of time.

Daniel, happy hundred episodes. We did it. First of all, thanks to everybody who makes the show happen. The only reason it works is that people show up and ask questions. It’s a back-and-forth, so thanks to everyone who participates, tunes in every week, and submits thoughts and questions. Thanks also to Dustin, Will, and the whole production crew.

Daniel: Absolutely. You guys set us up for success, and so does the audience. Even if you think a question is dumb, or that it’s been answered before, keep them coming. We’re here to help in any capacity we can. Thank you for being part of the ecosystem.

Jacob: Any quick takeaway after a hundred of these?

Daniel: More and more people want to do the right thing, and I appreciate the momentum I’ve been able to ride because of that. You hear all the negative stories about False Claims Act cases and so on, but then there’s the single IT person trying to do this the right way. Hearing those success stories keeps us going. Thank you for staying diligent, trying to do the right thing, and not giving up.

Jacob: The main thing doing this show has reinforced for me is something I’ve thought for years: the DoD needs to keep talking. I don’t know if you guys are listening this week. I love you, but I can’t say this enough. Saying something once doesn’t mean you can stop talking until you have another update. You have to keep talking about the same things day in and day out, week in and week out, forever, until the heat death of the universe. And even then, people won’t hear you.

The reason this show works is that every week we answer “What is DFARS 7012?” and “What is CMMC?” I’m happy to answer, no judgment, but we’re answering because the DoD isn’t. This is really a show the DoD should be doing. Culturally, they’re just very bad at this, and the CMMC review and report is a nice microcosm. They’re not in rulemaking. Their hands aren’t tied. There’s no gag order. The DoD could come out at any moment, live-streaming from the car or the house, posting on LinkedIn, tweeting, whatever, and tell everybody what they’re thinking and which way things are going. Nothing. The more things change in leadership, the more they stay the same. I’m sure we’ll do another hundred episodes, because the DoD doesn’t look like it’s coming out to answer anybody’s questions anytime soon. And with FAR CUI, we’ll be talking about every agency, because there may be certification requirements all over the place.

Let’s get into thoughts of the week. You’ve been in Denver all week talking to higher education, Daniel. What’s on your mind?

Thought of the Week: The Dam Sensor Story

Daniel: I’m in a hotel room in Denver for our hundredth episode. I heard a story from a university that I had to share. I won’t say which one. They saw suspicious activity from a server on their research network and reached out to the researcher to say, “This is going on, we need to figure out what’s happening.” No response. So the security team did what any security team should do and isolated the device until they got an answer.

It turned out this piece of research equipment was monitoring dam levels. It was the single appliance that would report a dam breakage and trigger notifications through FEMA and other warning systems. That’s pretty relevant given the weather over about a third of the country right now. A few hours after they cut it off, they got a call: turn it back on immediately, because people thought a dam was breaking.

I share it because we were talking about CUI and NIST 800-171 and protecting regulated research. The security team was doing the right thing. But because the researcher didn’t lean into the appropriate compliance process, they suspended a system that should never have been suspended and could have triggered a statewide or multi-state alert about dams breaking when nothing was happening. So resiliency and redundancy matter. If you’re a principal investigator at a university, tell your security team what’s actually on your network and how critical those systems are.

Jacob: That’s wild, especially with actual dams getting overrun. It reminds me of the Hawaii missile alert, where people woke up to an alert on their phones about incoming missiles because someone spilled a Gatorade on a keyboard or something.

Daniel: I presented this morning at the conference. People don’t want to engage with compliance content because they don’t want to admit they’re not compliant, so it’s a pretty dry audience. But you can always tell what they care about most by when they take out their phones to photograph slides. Someone even said it out loud: export control. They’re having a hard time identifying the nationality of the people who have access to systems doing export-controlled research. We were talking about CMMC and FAR CUI and student records, and the one thing everyone was up in arms about was export control and “U.S. person” status, which we see all the time in regulated research.

Jacob: If you want an entertaining read over the weekend, look up the website of the House Select Committee on the Chinese Communist Party. They put out research reports every few months that are terrifying to read, and they’re always up in the university and research ecosystem’s business. Terrifying titles, terrifying intros. It’s not fun, but it’s bracing. If you want to see how bad the situation is in regulated research, look them up.

Big News: CIRCIA Final Rule Heads to Interagency Review

Jacob: Now for some big news. If you’ve been listening, you know there’s a confluence of rulemaking happening in Q4 and Q1 that’s going to make defense contractors’ lives harder. Despite all the talk about harmonization, none of these rules are being harmonized, and that means more work for you.

CIRCIA is the Cyber Incident Reporting for Critical Infrastructure Act. We’ve done many podcasts on it. After the Colonial Pipeline attack, everybody asked how there could be no obligation to report cyber incidents. Congress created a statute telling CISA to make critical infrastructure report cyber incidents to it. There are 16 critical infrastructure sectors, and the DIB is one of them. CISA wrote an almost 500-page proposed rule addressing each sector. It requires incident reporting within 72 hours and ransom payment reporting within 24 hours. There are data retention requirements, update reports, combined reporting, and different triggers. CISA gets subpoena power to verify you’re doing it.

In that proposed rule, CISA says it knows the DIB already has a cyber incident reporting requirement and that this creates a second one, and it doesn’t care. Unless an agency reaches an agreement with CISA that substitute reporting is “substantially similar” to what the statute requires, you’ll have multiple obligations: one under CIRCIA and one under DFARS 7012. Over the last couple of years there have been zero indications that the DoD and CISA are working on an agreement to use 7012 reporting as a substitute. There’s also zero evidence CISA believes 7012 reports would be substantially similar.

The current update is that as of yesterday, the CIRCIA final rule was sent for interagency review. OIRA, the Office of Information and Regulatory Affairs, runs that process. On paper it can take up to 90 days, extendable to 120, though it typically doesn’t take that long. So the ballpark is that we’ll see the final rule published sometime between Q4 of this year and Q1 of next year. We won’t know the fate of defense contractor incident reporting burdens until it’s published. Once it is, we’ll see the effective date for the brave new era of cyber incident reporting, and at that point it’s codified in black and white.

So everybody go ask Kirsten Davies, since she’s nowhere to be found: what’s the plan? The DoD will have seen this rule during the current interagency review, and they don’t have a good answer. I’ve told this story on the show before. Back in January, I flew to DC when a bunch of DoD cyber people were there, right after Davies got confirmed. Katie Sutton, who handles cyber policy and whose wheelhouse this is, was on stage talking about harmonization. I asked her about the status of the CIRCIA agreement and what the DoD was doing to keep this from becoming a secondary obligation. She didn’t know what I was talking about. She had never heard of the issue. That doesn’t give me a lot of confidence that progress has been made.

So tell your friends, tell your parents, have your go-bag ready, and keep some extra water and canned goods. This isn’t a DoD rule. It’s a CISA rule, with a statutory obligation behind it. Once it’s out, there’s no changing it.

Daniel: This is as much authority as CISA has ever had. It’s the big stick they get to carry around. Subpoena power is amazing.

Jacob: Congress straight up wrote a statute and said, “Do it.” CISA’s proposed rule is one of the most thorough cybersecurity proposed rules I’ve ever read, including all the supplemental materials. They got more feedback from the authors of the statute through public comments from the congressional reps, then held town halls that became part of the public record. You can go to the docket right now and read the transcripts of all the town hall sessions.

Daniel: Sean says CISA received significant public comments, many emphasizing the need to reduce scope and burden, improve harmonization, and clarify terms, and CISA is considering them. That’s from the Unified Agenda. Standard boilerplate.

Jacob: All of the DIB’s comments said, “We already have to do cyber incident reporting under 7012, don’t make us do a second one.” That ignores the fact that you’d need to convince CISA, through the terms of the rule, that 7012 reporting is substantially similar to CIRCIA reporting. When you compare the two, as we have in previous podcasts, they’re not. So unless CISA is willing to accept a vastly smaller amount of reporting data that the DoD can’t even prove anybody is submitting, why would it? CISA has a statute. It has the speaking stick, the conch shell, the golden ticket. Why would it concede to a ten-year-old DoD regulation that the DoD hasn’t bothered updating, can’t prove anyone follows, and clearly doesn’t care about? It doesn’t make sense.

There’s no indication the DoD will update 7012 anytime soon to match CIRCIA. My gut says that by the end of this year, or before the end of Q1, defense contractors will have double the incident reporting requirements. And there’s no scoping under CIRCIA. It’s everything in your organization by virtue of being a DIB contractor. No CUI data-flow scoping, no CMMC scoping guide, none of that.

Daniel: FAR CUI also has incident reporting at 72 hours, and CIRCIA is the first of these to make it this far through rulemaking. Do you think FAR CUI will remove its incident reporting in favor of defaulting to CIRCIA, or is it yet another requirement layered on?

Jacob: FAR CUI wouldn’t remove it, because it applies to all federal contractors, and not all federal contractors are critical infrastructure. So there’s no reason to.

Daniel: So potentially three levels of reporting.

Jacob: Correct. By virtue of being a defense contractor, you’d have incident reporting under DFARS 7012 and CIRCIA. If you also have other federal contracts, you’d have reporting under FAR CUI, which wouldn’t go to the DoD. Penalties vary. CISA has subpoena power to go after you, and the penalties depend on its decision to refer you to the Department of Justice after a massive breach you didn’t report.

Daniel: And the SEC has its own reporting for publicly traded companies. It’ll be interesting to see all of this blended together. It sounds like somebody’s full-time job, an incident-reporting regulatory response team.

Jacob: All we’ve talked about for years is harmonization, and this is the rule that’s supposed to harmonize. The vibe from CISA is basically, “By harmonization we mean you harmonize to us, not the other way around. If you have a problem, go talk to Congress, because they wrote the law.”

[A viewer asked for a link in chat.] If producer Dustin is looking, he can drop it in. Otherwise, find the most recent CIRCIA podcast, where the links are in the show notes. If you hear news about something, we almost certainly did a podcast on it, and the show notes usually have direct links to rules, publications, and reports. I’ll also update my LinkedIn post later today with links to the rule in the comments. For the proposed rule, you can just Google “CIRCIA proposed rule” and it’s the first result.

Audience Q&A

Are Amazon and Microsoft making CMMC and CUI labeling easier?

Daniel: I’m having this conversation this week at EDUCAUSE, here in Denver. People keep asking whether there’s a magic wand from a technology perspective for CUI marking. Microsoft has Purview, which lets you label data types with supported file extensions, such as Office documents and PDFs. Some third-party integrations go as far as engineering documents. Titus and Varonis are other examples. I’m not sure Amazon has anything native. But the tool has to know what counts as CUI. If you’re generating the CUI yourself, you’re the one who has to mark it, because your technology isn’t smart enough to put those 37 pieces together and realize something is CUI. No AI agent has been able to take all the different publications, mix them with your IP and public information, and identify what’s controlled unclassified information. Maybe one day, in the magical land of Oz when Anthropic IPOs, they’ll come out with a specific CUI model. I don’t see that happening anytime soon.

Jacob: I hate to split hairs, but CMMC is a verification of DFARS 7012 requirements. The requirements for protecting CUI in cloud environments like Amazon’s and Microsoft’s aren’t NIST SP 800-171 requirements. They’re FedRAMP requirements. So the real question is whether Amazon and Microsoft are making FedRAMP-compliant environments more accessible to small and medium defense contractors. Microsoft recently released a different licensing structure for smaller businesses. Daniel, tell us about that.

Daniel: They released Business Premium inside GCC High, which is a good bit cheaper than the full E5/G5 license. It’ll be interesting if AWS, Microsoft, or GCP go further, because we now have defined ODPs (organization-defined parameters) for Rev 3, whenever that comes about. Allegedly. They took it off the CIO’s website, but you can still find it. With the ODPs prescribed, you could do better automation and orchestration, pre-filling those variables and building a more preconfigured landing zone. Rev 2 was almost a choose-your-own-adventure, where you picked the variables and parameters yourself. In Rev 3 they’re prescribed. It’ll be interesting to see whether a big cloud provider ships a landing zone that supports all the Rev 3 ODPs, especially when FAR CUI comes out. Right now there’s no real enclave-in-a-box from these providers. They don’t know what parameters you want to fill in. And a large portion of the burden isn’t technical. It’s writing the compliance documentation about how your organization uses the environment and which PaaS, SaaS, and IaaS tools you use. They’re FedRAMP authorized at moderate and high, which is great, and cheaper licensing is coming, but from a “just take my money and do it for me” perspective, none of them are at that level.

Jacob: Microsoft and Amazon don’t do the work themselves. Their partner networks do. So you’d work with a company like ours, and the degree to which we hand you the keys versus build the car and drive it for you depends on the level of service you want. CMMC is obviously the big issue, but you’re also asking whether they have cloud offerings compliant with export control, or ones that reciprocate DFARS 7012 obligations. It goes far beyond NIST 800-171.

Daniel: To John’s comment in chat: Egnyte, a widely used file-sharing tool, especially in construction, meets the compliance obligations for a CSP. It does data marking, but just like Microsoft’s tools, it can recognize CUI only if the data has been marked. So some human effort is required. I wish it weren’t so, because humans are error-prone, but the technology isn’t any better.

Is Google Workspace a viable alternative to GCC High for ITAR and export-controlled CUI?

Daniel: Yes. Google can be configured to meet the requirements. It meets the FedRAMP requirement, but you have to buy extra licenses for Assured Workloads to meet the export control component, so there’s extra cost. We’re a big Microsoft partner, but we talk about every vendor. The problem we see is that when people come to us with Google Workspace, they have to bolt on a bunch of third-party tools to fill gaps in the security stack. Workspace is a great collaboration platform, but for end-to-end device management and similar functions, you typically need one or more third parties. So yes, you can use it with Assured Workloads for export control and CUI. The question is how much more you have to buy to meet the full CMMC, really DFARS 7012, obligations.

Jacob: Someone in chat noted that GCP and Workspace currently maintain FedRAMP High status. Good info to know.

What does the November 2028 Phase 4 deadline mean? Does Level 2 certification become absolute?

Jacob: Mr. Palmer asked what the November 2028 Phase 4 deadline means for the CMMC ecosystem, short of rulemaking, and whether third-party Level 2 certification becomes the absolute requirement. Before the suspension, during it, and theoretically after it, Level 2 certification has never been an absolute requirement. There will always be some people doing Level 2 self-assessments and some doing Level 2 certification assessments. There was no certification cliff, no drop-off, and no deadline for everybody to receive a cert. November 2028 was the beginning of Phase 4 of the original phased rollout, and that rollout is suspended for all intents and purposes. We don’t know whether November 2028 will be the end of an updated rollout. We don’t know their plan. We were supposed to know it almost 30 days ago, but the DoD CIO is making videos about Cybersecurity Awareness Month instead of telling people the results of the massive review of the program.

Daniel: I pulled up what I’d call a legacy document that’s still on the DoD procurement toolbox website, which you’d think they would have taken down with the suspension. The DoD actually had a framework for which types of CUI call for certification versus self-assessment at Level 2. There wasn’t a mandated certification at the end of Phase 4 for everything that’s CUI. That implementation policy is still out there. It’ll be interesting to see whether, post-suspension, they still follow that guidance for the different CUI categories.

Jacob: I’ve been saying this to everybody who will listen. When Kirsten Davies justified suspending Phase 2 of the CMMC rollout, every reason she gave was demonstrably false. Not enough assessors? Not true. Not enough assessment capacity? Not true. Not scaling fast enough? Not true. You can look at the DoD’s own numbers and do the math. She also said CMMC is required to bid, which isn’t true, and that November was a Level 2 deadline, which also isn’t true. There is no DoD policy, and there never was, that said CMMC Level 2 is required by November 2026. The primes created November 2026 as their own deadline, in spite of what DoD policy said. So if you come out with an update to CMMC policy, what will it say? That there’s no deadline? It already says that. Are you going to underline it, bold it, put asterisks around it? Once you set the policy, you can’t prevent the primes from acting of their own volition.

Daniel: I keep every slide I’ve ever made at Summit 7, because you never know when you’ll need one again. Here’s a supplier notice slide: “effective November 10th, in alignment with Phase 2 implementation, we require all applicable suppliers to achieve Level 2 certification.” That’s not in alignment with 32 CFR Part 170, which doesn’t impose a November 10th deadline. It’s confusing, because primes were telling their supply chains to go get certified because that’s “what the rule says,” and it isn’t. The rule says you might need certification as part of Phase 2. I’m assuming Leonardo DRS and others were thinking, “Let’s get our supply chain certified so our BD team can go after any and all work with any and all requirements,” which I can’t blame them for. It’s a good business move. But primes in general never took 7012 that seriously, so they have a very archaic, under-secured cyber supply chain. This was whiplash to most suppliers in their ecosystem, which in my opinion is why the suspension happened in the first place and why the SBA got involved.

Jacob: Even so, what’s the plan? What will you update the policy to say to stop primes from setting their own artificial deadlines and telling everybody to go get Level 2? You can’t. When the behavior happens even though DoD policy doesn’t say it, you have a management problem, an education problem, a communications problem, a governance problem. You don’t have a red-tape bureaucracy problem within the policy. They suspended everything to fix the red tape, and you won’t get different behavior on the other side.

Daniel: And these supplier notices started five or six months ago, tops. Where were they during the whole rulemaking, when the final rule was published?

Jacob: That’s a whole other conversation. Hoping the DIB and the primes will do this of their own volition without a regulation is like hoping the AI companies will police themselves. Am I right, everybody?

Does Summit 7 offer virtual app publishing (e.g., a secure browser) instead of full VDI for GCC High clients?

Daniel: I love the question. The last time I looked at RemoteApp through AVD, there was an issue with screen protection controls for copying and pasting out of the remote app window. We’d definitely be open to doing it. I need to verify that the out-of-scope asset classification can be met explicitly by RemoteApp versus a full VDI session. Smith, great question. I’ll investigate after this call to see whether those capabilities are now available, because for a while they weren’t.

FedRAMP reauthorization

Jacob: Thomas says Congress has 363 days to reauthorize the FedRAMP Authorization Act of 2023 or FedRAMP rides off into the sunset. I highly doubt that happens. It’s something to keep an eye on, but I think it will be like the CISA reauthorization and all the others, where they wait until the last minute.

Will third-party assessment ever be required again?

Jacob: Jason asked whether third-party assessment will ever be required again. I can’t imagine it won’t be required in some fashion. The rhetoric the DoD has used during the suspension is strange. We just did a podcast on the Cyber Security for Small Business Act of 2026. Between the DoD and SBA statements at the suspension announcement, their LinkedIn posts afterward, and the press release language around that bill, they really hate the idea that companies have to spend money on consultants to understand and comply with the requirements. They see it as ridiculous and unnecessary, a function of bad bureaucratic requirements. Little do they know the reason you have to hire people is that you don’t have the people internally. NDIA’s response to the RFI said that when they surveyed the DIB, 30 to 40 percent of companies have zero FTEs working on IT and security at all.

So the idea is that you could write the requirements so self-evidently that the DIB wouldn’t need to hire anybody. That’s the same assumption trap the original authors of 800-171 fell into when they took the 800-53 moderate baseline and chopped it into little pieces. They assumed you knew all the other stuff and were already doing it, which clearly wasn’t true, and they’ve been backing off that decision ever since. Era after era and leadership group after leadership group keeps stumbling into this bear trap: an assumption of pre-existing maturity that doesn’t match the DIB. It won’t fix the problem.

Congress told them: we know contractors aren’t meeting these requirements, we know primes are letting it happen, we want contractors held accountable, fix it. That’s what CMMC was designed to do, plug the hole in DFARS 7012. The DoD’s policy had been: we’ll give you controlled data, we’ll require you to protect it, and we’ll never ask you to prove it. Every few years a national security crisis results from people not doing basic things, so eventually they had to act. CMMC 1.0 came out on the heels of a disaster, so the DoD overreacted, went way too high, over-scoped and over-specified everything, and got in everybody’s face. They dialed it back. Now we’re at 2.0, with many more caveats, many more concessions, and a much longer timeline. And it turned out everybody just hadn’t implemented the DFARS 7012 requirements yet. By their own admission at events and in the RFI responses, everybody in the room with the DoD was effectively saying, “Don’t put me in jail, I haven’t done this.”

Daniel: It’s a scene out of The Big Short.

Jacob: So will third-party assessment be required again, as a condition of contract award? It would surprise me if the DoD changed that policy. Even if they wanted to, they’d have to go through rulemaking, because CMMC is a codified rule. Meanwhile, DIBCAC is still being sent out to run third-party assessments on people after the DoD gives them the data, knowing many contractors can’t protect it, which seems like an insanely stupid policy to me. It doesn’t match what Congress asked for or the logic the DoD maintained through years of rulemaking. So I’m sure it will be required in some manner. But back to the earlier point: what will they say? DoD policy already says third-party assessment is required only when very specific data is involved. The primes then said, “Okay, everyone go get it, because we don’t know if or when you’ll get that data and we don’t want to wait.” So even when the DoD releases its updated plan, whenever Davies gets around to it, the primes’ reaction to that policy will determine how many people need a third-party assessment, not the policy itself. The DoD didn’t anticipate asking a lot of people to get third-party assessments. The primes did.

Daniel: Which, ironically, is why CMMC was created in the first place.

Our SIEM/SOC supplier is getting out of the SOC business because of the CMMC pause

Jacob: A viewer says their SIEM supplier is getting out of the SOC business, so they have to change everything related to SOC incident response evidence. Maybe clarify: are the people you partnered with for logging and monitoring getting out of that work?

Daniel: I’d bet it was a SOC that served CMMC-specific clients. Because of the pause, they’re pivoting away from CMMC. Smith, tell me if I’m right. That’s how I read it.

Jacob: Here’s the thing: there was no net increase in C3PAO applicants. People still got certified last month. The town hall just happened, and people still got their CCAs and CCPs. But at some point a delay in an announcement starts slowly killing an ecosystem that was built to support what the DoD told it to support. Silence from the CIO’s office is causing damage, and a shortage of people who will likely need to be put back to work once this is done, because rulemaking takes so long. I get it if you don’t like the program the way it’s written, or if the SBA thinks CMMC costs a jillion dollars. But every little piece of that has been debunked, whether it’s the forecast of how many assessments are needed, the assessment capacity, or the average cost, with multiple C3PAOs submitting receipts showing the average is around $40 to $50,000.

Daniel: Based on the RFI responses submitted to the task force, the average C3PAO assessment cost was about $45,000. So what was all that about $600,000, SBA?

Jacob: This is ultimately why I think they’re hiding. Kirsten Davies isn’t going to CS5, and no one from the DoD CIO’s office is, which leads me to believe they won’t announce anything before CS5. They’re too scared to get on stage and tell people what’s going on, because they don’t have to. All the things they said were problems weren’t the problems they made them out to be, and now they’re becoming problems through your own inaction after the review was finished.

It also points out that the requirements for SIEM, monitoring, auditing, analysis, and incident reporting exist outside CMMC. Whether CMMC is suspended or not, nothing changes about the requirements DFARS 7012 imposes through NIST SP 800-171. Without a program like CMMC, people don’t comply with 7012, and the proof is that providers of services 7012 requires are leaving the space because the DoD backed off CMMC. We saw the same thing with the pause and review of CMMC 1.0. CMMC 1.0 included a requirement in what was called the “Delta 20” for secure backups, which isn’t in NIST 800-171. When CMMC 2.0 was announced and that requirement was removed, people called us and said, “Turn off the backups.”

Daniel: News flash.

Jacob: If you don’t require it, 99 percent of people out there won’t do it, and if you don’t ask for proof, they definitely won’t. I know you don’t like it because it’s not popular, but it’s the only thing you have to make sure people are doing it. So tell me more about how compliance doesn’t equal security next time you’re on stage at Black Hat.

Daniel: She’s not talking to the same people I talk to every day.

Jacob: Definitely not. She’s not going to CS5, not on any of the calls we’re on. Go talk to other CISOs at giant security conferences, I guess.

Should CPAs or CISAs be allowed to do targeted audits of key controls in 800-171A?

Jacob: By regulation they can’t, because they don’t meet the requirements. You’d have to change the requirements for qualified assessors through regulation, which would take a significant period of time. It was through the public comment process that the assessor requirements went through the roof, because people don’t want inexperienced people showing up to assess them. When the DoD said any random person who meets a minimum qualification could do the assessment, people said no, and the requirements went to 20 years of experience, extensive training, and so on.

This question also insinuates that we need more assessors. We have plenty of assessment capacity. We’re sitting on excess. The growth rate of assessment capacity in the ecosystem was dramatically outpacing the rate at which companies were ready for assessment, because nobody is complying with DFARS 7012 in the first place. We didn’t have an assessor-number problem or a capacity problem. If you quintupled the assessors, or built 100,000 free autonomous assessor agents to verify all these requirements, you’d still have the problem that no one passes, because they aren’t complying, and in many cases can’t because they don’t have the money. If a company has nobody doing IT or security work, no money, no skills, no knowledge, and no ability to acquire them, it doesn’t matter how small the baseline is. They can’t meet it. We keep blaming the requirements, and they’re not the problem. In Cybersecurity Awareness Month they’re talking about being brilliant at the basics and phishing-resistant MFA, but the number two most commonly failed requirement is MFA at all, just vanilla MFA. They’re missing the point.

So would that be a good idea? Maybe. Would it get through rulemaking? Almost certainly not. And I don’t think it solves a problem we have. Instead of more people, automate it. DISA has been able to automate 800-53 control assessments to a massive degree forever. Assessment capacity is not, and never has been, the problem.

Daniel: At this EDUCAUSE event I brought up Brilliant at the Basics during a round table. I was talking about the OT piece and asked if they’d looked at it. They hadn’t, so we pulled up the list and they said it would kill them. It would kill regulated research and consolidate defense research into a small handful of universities, the big boys like Johns Hopkins, MIT, and Georgia Tech. It’s fascinating being in the room. People over-rotate on things like Brilliant at the Basics for OT, or phishing-resistant MFA on the IT side. Those are all good things, and I’m a big fan of security, but if you don’t do them in a scoped and progressive way, which is what the CMMC plan was, you’ll break everything immediately.

Jacob: That’s the fundamental contradiction in what Davies has said over the last 60 days of this review. The last 20 days don’t count, because she’s nowhere to be found. She came out guns blazing on July 13th saying this is bureaucratic nonsense, red tape, getting in the way of innovation, ridiculous, costs too much. The next day she was out talking about doing OT, doing IoT, replacing legacy systems, and saying 171 isn’t good enough, it’s the bare minimum. And I’m thinking, lady, what are you talking about? I don’t disagree that you need more requirements. But the problem isn’t how 171 is written. The problem is that it’s already too much of a burden for many of them. That’s why I think they’re not saying anything. They painted themselves into a corner, and there’s no way out without upsetting everybody.

Daniel: If they haven’t done 171 in ten years, how long will it take them to adopt Brilliant at the Basics? Twenty years?

Jacob: You’re not addressing the uncomfortable tradeoff. You have a group of people who, no matter what the requirements are, cannot meet them, or in many cases will not meet them unless you make them. Your decision is whether to keep conceding to those people or to go to Congress, hat in hand, as you’re supposed to, and say, “We’re doing what you asked. They need help. Where’s the money?” But they’re not doing that. They’re blaming the NIST requirements as if they’re the problem. It’s ridiculous.

How long after the FAR CUI rule will we have to become certified?

Jacob: There is no certification requirement in the FAR CUI rule. It’s like DFARS 7012 for everybody. By accepting the terms of the contract clause, you’re attesting to the government that you comply with its requirements. Just by signing the contract, you’re saying, “We are doing this.” That’s what gets everybody hemmed up in these DOJ settlements. It has nothing to do with CMMC or with waiting on CMMC. It’s that you signed a contract saying “we do this,” submitted an invoice, and got paid, and it turns out you didn’t do it, so they want their money back plus a little extra.

There’s no certification requirement written into the FAR CUI rule. Whether you need to prove compliance, and to what degree, up to third-party proof, is left to each agency’s discretion. NASA might decide one thing, the Department of Energy another, the Department of Education another. CMMC is a very convenient way to do it, but nobody is required to use it. We might have six different approaches. Maybe it’ll all be harmonized. Technically, CMMC solves the harmonization problem, because it makes people prove through a standardized method that they meet 800-171, which is the FAR CUI requirement for everybody. But CMMC doesn’t have a great brand, so maybe they’ll use it and maybe they’ll make their own. We don’t know.

Just as people have gotten in trouble for signing and accepting 7012 and then not doing it, magnify that by a bajillion. Now you’ve got federal contractors who have no idea what’s been going on in defense contracting for the last decade walking into the same trap. There’s no phased rollout. They’ll get the clause in their contract, sign it, keep going about their business, and then maybe DOJ calls.

Daniel: Here’s what I think, too. ISACA, which handles the CCA and CCP certifications, is supposedly working on a Rev 3 uplift. Say CMMC goes away. I still think the role of someone who can assess Rev 2 and Rev 3 will exist as an accreditation and certification for an individual, and companies will still want to be independently assessed by someone certified. Even if agencies don’t require it out of the gate, I think primes would be very interested in proof of a third-party audit. And Rev 3 has an annual requirement, though they may use the word “assessment” rather than “audit.” I’d have to look up the exact control, but from a Rev 3 perspective in general, you’ll have to do some kind of validation yourself.

What’s the difference between “tier one and tier two” or Rev 2 versus Rev 3?

Jacob: Maybe they mean CMMC Level 1 and Level 2 versus 800-171 Rev 2 and Rev 3. Daniel, do you want to take this one?

Daniel: I thought they were talking about Tier 3 eligibility for a second. CMMC Level 1 is for federal contract information. Level 2 is for controlled unclassified information. Level 1 points back to FAR 52.204-21, the basic safeguarding requirements, and you have to meet 100 percent of them, with no POA&Ms allowed in the world of the DoD. Level 2 currently maps to NIST 800-171 Rev 2 as the assessment framework, which points back to the DFARS 7012 obligation already in your contracts. You won’t have the CMMC clause, DFARS 7021, without 7012. They have to coexist, because one is the requirement to implement the controls and the other is the requirement to be assessed.

Jacob: A quick note: FAR 52.204-21 is a FAR clause, not a defense-contractor-specific one. All federal contractors, whether they know it or not, have been attesting to the government since 2016 that they meet these requirements by virtue of being federal contractors. Fun fact: in the FAR CUI rule, they estimate the cost of complying with NIST SP 800-171 partly by excluding the 15 requirements in the basic FAR clause, because technically you’re already doing them. Sound familiar? It’s exactly the issue that has plagued defense contractors, and it’s going to repeat across every other agency’s supply chain pretty soon. We expect the FAR CUI rule to start making progress by the end of the year. CIRCIA was the first out of the gate, but there will be more to deal with by this time next year.

Daniel: We’re going to have to make this a two-hour show every Friday. The number of requirements coming from different agencies simultaneously is going to be the most confusing thing. It’s the It’s Always Sunny in Philadelphia meme, the guy pointing at the board with all the yarn.

Jacob: That’s going to be the new show: this ties to that, and that ties to this.

My customer can’t tell me what is CUI. How do I know what to protect?

Daniel: A quick caveat first: unless there’s a pleasant surprise in it, the CIRCIA rule doesn’t care about CUI. In the near term you’ll have cyber incident reporting requirements that don’t care about CUI scoping or CUI data flow at all. Now, to the question. Hopefully if your customer can’t tell you what CUI is, they shouldn’t be marking things as CUI. And if they’re marking everything CUI but can’t tell you what it is, we have a bigger problem.

If they say, “Listen, we don’t actually know, but we have to flow this contract clause down to you,” I’d sit down with them and break apart the information they’re going to send you. Identify IP, public information, and so on, and then use the CUI Registry, looking at things like controlled technical information, to see which specifications fit into a fourth bucket. Then agree with them that the fourth bucket is what requires CMMC Level 2 protection. The other three shouldn’t be marked CUI. That’s my recommendation if you have a good working relationship with your customer. If not, and I see this all the time, people end up over-scoping their CUI boundary because they have to receive everything the customer sends to avoid rocking the boat. They say, “Okay, we’ll treat it all as CUI,” which isn’t the way it should be, but people typically still do it.

Jacob: And this is a bit speculative, but the DoD said CUI marking and over-marking is the number one problem it blames on CMMC. Through the RFI and review process, the current leadership has found out that CUI marking and governance doesn’t belong to the DoD CIO or the CMMC program. It’s a cultural problem inside the building: training, awareness, governance, management, all the hard things we’d rather not do. We’d rather blame requirements. There’s no easy fix, certainly no near-term one. With the FAR CUI rule, it would be very convenient for them to say, “The FAR CUI rule in its magical form will fix this problem. That’s now a FAR CUI issue. We’ll go focus on Brilliant at the Basics and resilience and post-quantum crypto and all this other stuff.” They’d wash their hands of the CUI problem, much like DHS did with its CUI rule. DHS didn’t even address requirements for non-federal systems, saying it would wait to see what the FAR CUI rule says. What a move that would be. “We’re definitely going to fix it.” “Actually, this isn’t our problem. Go talk to them.”

Wrap-Up

Jacob: It’s been an hour. We’ll definitely have to make the show longer by this time next year, because there’s no way we’ll fit everything in. By then we’ll be at 200 episodes: 200 episodes, two hours each, then 300 episodes, three hours each, and so on until it’s the only thing we do all day. But I’m happy to do it. Thanks, everybody, for watching, participating, and submitting questions. That’s what makes the show happen, and it’s always cool to see everybody in chat and to hear from people who find the show and say it’s super useful. We take questions of all forms. Go to cuihotline.org, leave a voicemail, submit the form, or DM us. If you find the recording after this is over, you can add your question or comment and we’ll add it to the queue. Catch us live every Friday if you want to participate in the chat.

Daniel: It’s always humbling that anybody would stop scrolling to pay attention to what we have to say. We try to joke around as much as possible because, let’s be honest, a lot of this stuff is pretty boring.

Jacob: It is. Cyber Ninja, I didn’t know you were in Denver. I’m about to fly home, but next time I’m in Denver, we’ll grab some beers.

Daniel: Absolutely.

Jacob: We’ll be back next week. Watch for updates on the CIRCIA final rule, and see my LinkedIn post today for a brief update. What do you think? Will the government reach an agreement so the DIB has only one reporting requirement, or does the government not know what the rest of the government is doing, so we’ll have two? Let us know in chat. Thanks for watching, and we’ll see you next week.

Daniel: See y’all.

Contact

Speak With Our Team

Scroll to Top