Jacob and Ryan Bonner discuss how contractors can use long-range acquisition forecasts and Procurement Administrative Lead Time (PALT) data to identify their actual certification timelines rather than relying on generalized CMMC rollout dates. They also examined lessons learned from CS5, including ongoing confusion around CUI identification, the growing importance of supplier readiness, and the challenges organizations face when balancing implementation speed with proper scoping decisions. The episode concluded with audience questions covering prime contractor deadlines, assessment readiness, reassessments, external service providers, and the importance of focusing on cybersecurity fundamentals rather than searching for shortcuts.
Key Takeaways
- Long-range acquisition forecasts can help organizations identify their real certification deadlines. PALT data provides a more accurate picture of when certification will be needed than relying solely on broad rollout timelines.
- Many organizations continue to struggle with determining what qualifies as CUI in their specific environment. Proper scoping and understanding applicable source authorities can significantly reduce implementation costs and complexity.
- Prime contractors are increasingly establishing their own compliance deadlines. Customer-driven timelines may be more important than government rollout dates when determining how quickly an organization needs to achieve certification.
- Supplier readiness may become one of the biggest challenges facing the Defense Industrial Base. Many organizations are focused on their own compliance efforts without considering whether their suppliers will be able to meet the same requirements.
- Successful assessments depend on people and processes as much as technology. Organizations that understand their requirements, document their environments effectively, and prepare personnel for assessment interviews tend to achieve better outcomes.
We’re back from CS5 so this week we’ll be stepping through a ton of questions we got from the event and, like always, anything that comes up during the livestream.
Transcript
[0:14] Jacob
All right, everybody. It is Friday, so it is Hotline time like it is every Friday.
We’re live on LinkedIn. We’re live on YouTube.
You can go to cuihotline.org and you can fill out the form. You can call the number and leave a voicemail.
We’ve got a bunch of stuff in the backlog. We’ll get to questions in chat. If we don’t get to your questions in chat, we’ll add them to the backlog and then the cycle will repeat forever and ever every Friday.
This week we are joined by the great and powerful Ryan Bonner because Mr. and Mrs. Daniel Akridge are on their honeymoon right now.
So they are out doing their thing.
And I hope Daniel, if you’re tuned in, you’re wrong, buddy. I hope you’re not here.
You’ve got other things to be focused on right now.
Ryan, how the heck are you? What’s going on?
[1:06] Ryan
Good, good.
I’m just playing a little game of is it a head cold or is it an allergy?
[1:12] Jacob
Well, you’re a road warrior these days, dude.
So it could just be generic travel crud.
You never know.
[1:18] Ryan
That is true.
I’ve been breathing a lot of jetliner air.
[1:37] Jacob
Okay, we’ve got a bunch of stuff to get to.
We’re coming off the heels of CS5.
You’ve been to a bunch of conferences out there.
Everything is ripping and roaring.
Heads are exploding in the L3Harris supply chain.
Tons of stuff to get to.
We’ll start off the way we always do: Week in Review.
Okay, so this is actually what I talked about at CS5.
Everybody’s worried about CMMC deadlines.
Is it November?
Is it 2027?
Is it 2028?
Is it two months ago?
Remember everybody, there are no deadlines baked into the CMMC phased rollout.
Period.
November 2028 is not the deadline for all Level 2 certs for everybody who will eventually need a Level 2 cert.
Your deadline is based off of your contract or your customer’s contract that you are a subcontractor to.
A lot of people have already seen their deadlines come and go.
Some people have been notified their deadline is March of 2027.
If you’re in the high-speed world of SOCOM work under Special Operations Command, they say that you could get a Level 2 self-assessment six months after award because they get to do that, I guess.
So it’s highly variable.
[2:50] Jacob
One way of pulling a signal out of the noise is through long-range acquisition forecasts.
These are available on the small business office websites of basically every DoD component.
The Navy ones are especially easy to find.
If you go on the NAVWAR website, NAVSEA, NAVSUP, NAVFAC—who said recently that they have their deadline coming up for November—you can see all of the anticipated awards they’re planning to put out by contract value, contract type, acquisition method, incumbent contractor, and a bunch of other data.
Most importantly, those long-range acquisition forecasts contain Procurement Administrative Lead Time data.
We’ve talked about PALT on the podcast now for many years.
That’s the period of time between solicitation and award.
Since your CMMC status is a condition of award, if you’re waiting until you see the requirement in the solicitation, you’re hoping that you have enough time between solicitation and award to do your implementation, get through your assessment, and go from zero to status in hand so you can do the work.
The bad news is those PALT windows are getting very short on purpose.
They are getting shorter and shorter as time goes on.
[4:17] Jacob
You can go to these long-range acquisition forecasts and look up the specific opportunity you want to work on or win directly.
Then you can say:
“Hey, how long is this PALT window?”
Three months?
Six months?
Twelve months?
Eighteen months?
That tells you how much time you have.
You don’t have to call up an MSP and get sold to.
You don’t have to go on Reddit and get random DMs from people trying to sell you stuff.
You know whether you’ve got eighteen months or eight weeks.
Which can be very, very different.
Long-range acquisition forecasts are a deadline hack in my opinion because you can find out what your specific timeframe is.
[5:02] Ryan
I don’t want to go all Six Sigma here, but you have more information than you realize.
You can understand which programs you’ve performed on in the past if you’re a subcontractor.
You can go back through old contract performance and purchase orders and stitch together which program that was under, which contract that was on, and start to reverse-build that timeline.
That was a huge takeaway for me at CS5.
You can wind the clock forward and understand, at least for contracts where your customers are incumbents, what renewal or rebid opportunities are coming.
Then figure out what is the most bleeding-edge thing that’s going to hit first with one of the primes you’re working with.
That can help drive the conversation.
[6:01] Ryan
I think you had great advice.
Take that data and ask your customer:
“Can we talk here?”
“I know you’ve got this form letter that says I need to be done by X date.”
“However, I can’t help but notice that the soonest I need this for all of our current programs is this later date.”
“Can we do some horse trading here?”
“Can we haggle?”
I think that will generally be well received because buyers and suppliers are usually working at the program level.
They just want to know that they’re covered.
[6:37] Jacob
This is that phenomenon of:
“Company commander says we’re having formation at noon.”
Then everybody at division level says be outside at 11.
Everybody below them says be outside at 10.
Before you know it, you’re standing in the parking lot at 6 a.m. for a formation that doesn’t start until noon.
You’re not actually late if you show up at 9.
It’s a long shot, but it is a handhold you can use.
If L3Harris Missile Solutions announces they won a major Army contract and sends out a letter saying suppliers need to be compliant by July, but the award doesn’t happen until November, maybe you can go back and say:
“Listen, I can’t make July, but I can make September.”
“You’re getting awarded in November.”
“We’re still within the window.”
“Can we work here?”
That’s better than asking if you can just not do CMMC at all.
Because they’re definitely not going to let you do that.
[8:08] Jacob
There’s a lot of really good data in those acquisition forecasts.
People are trying to reverse engineer their specific situation from phased rollout policy, and that’s just too high-level and too obscure.
Instead, use the actual acquisition data that’s available.
All right.
Let’s talk about your CS5 recap.
You were saying industry is getting smarter on some things, still struggling on some things, and maybe has a few blind spots.
[8:27] Jacob
Let’s talk about your CS5 recap.
Ryan, you were saying you’re seeing industry get smarter on some things, people are still struggling on some of the same things, and there are maybe some blind spots people aren’t talking about enough.
[8:40] Ryan
Right.
I think we had a lot of conversations at CS5, and I’m really encouraged to see organizations engaging with C3PAOs a lot earlier.
They understand there are lead times, so they’re getting on assessor schedules before it’s absolutely necessary.
Instead of saying:
“Boss says I need it.”
“Let me go get it.”
And then scheduling whenever they feel like it, they’re recognizing that there can be significant lead times.
That’s been great to see.
[9:16] Ryan
I also think there’s been much better cross-talk between organizations.
People are trying to get face time with companies that have already been certified.
They’re asking:
“Hey, what worked?”
“We’re looking at doing this. How does that compare to what you did?”
People are trading notes and being very collegial about it.
They want to help each other succeed.
It’s been cool seeing organizations swap war stories about what worked, what created assessment risk, and what went well.
There’s a lot more cross-pollination happening in the industry.
[9:51] Ryan
Where people are still struggling is definitely:
“What the heck is CUI in my context?”
That continues to be an issue.
You have organizations that know they need to implement 800-171, but where they’ve started is either too broad or not broad enough.
Neither is a good thing.
You’re either going to build too small of an implementation and immediately need to pursue a reassessment, or you’re going to overspend.
A lot of organizations are still struggling with that.
[10:25] Ryan
We did a CUI roundtable at CS5.
Everybody was dealing with so much pent-up frustration, ambiguity, and exasperation over low-effort answers they’ve been given by customers or the lack of public documentation.
That continues to be a struggle.
[10:50] Jacob
It’s really frustrating because I see this all the time.
The culture of the department and components lazily overmarking everything ends up being baggage that the CMMC program has to carry.
And it isn’t the responsibility of the CMMC program.
It drives me up the wall.
I totally understand why there’s frustration.
But it’s the ultimate punching-down situation.
[11:16] Jacob
Stacy Bostjanick used to explain this really well.
CMMC comes at the end of a process.
Whether or not you have CUI.
Whether or not 7012 applies.
Whether or not you asked for deviations from the 800-171 baseline from the DoD CIO.
All of that has been settled before the CMMC assessment ever begins.
The CMMC program only governs how assessments run.
They don’t control 7012 applicability.
They don’t control CUI determinations.
They don’t control waivers.
None of that.
[11:59] Jacob
But by the time everything rolls downhill, nobody is talking to the acquisition people.
Nobody is talking to the policy people.
The CMMC PMO is the only office around.
So they’re the ones who get yelled at.
The program ends up carrying water for all these cultural issues.
[12:16] Ryan
You and I have talked about the idea of an accountability sink.
I didn’t create that piece of policy.
Therefore I can’t affect change in how it’s enforced or rolled out.
It creates a situation where the person available to hear your frustration is not the same person overseeing the authorities that created the problem.
People feel like they’re getting spun around and pointed in no particular direction.
That gets in the way of agreeing on scope and moving forward with a good system design.
[13:01] Ryan
We’ve had to do a lot of work going back into the old magic.
We have the CUI Registry.
If we’re better students of the laws and regulations, we can start determining:
“This category is this.”
“This category is not that.”
We can build those lists.
Industry can do that work.
But you can’t bootstrap it overnight.
It takes a lot of reading.
[13:41] Jacob
I remember the other day you were helping a client with a scoping issue.
I think you said they reduced either their scope or their cost by around 75 percent just by going through that process.
[13:54] Ryan
Absolutely.
It seems like getting clarity slows you down.
But if that clarity affects how you spend money, the ROI is there many times over.
That’s why it’s important to know what your PALT window is.
If somebody shows up and says:
“We have to be done in eight weeks.”
You don’t have time to go through that process.
Your scope is probably going to be larger than necessary.
You’re probably going to spend more money than necessary.
If you’ve got eight months instead, that’s a much easier project to execute.
[14:41] Ryan
If you gave me eight weeks, I don’t know that I could take a completely hardened environment with all the documentation and policies already written and be prepared to answer assessment questions.
I couldn’t even read enough to understand everything about the environment, much less live under the policies and procedures.
[15:05] Jacob
What are people maybe not talking about enough?
What are the blind spots you saw from the conversations at CS5?
[15:18] Ryan
A lot of it goes back to timelines.
People are either very unbothered by impending revenue risk, or they have unrealistic expectations about how long implementation is going to take.
They’re not moving with a sense of urgency.
[15:47] Jacob
You know, your father and I support the comet because it’s going to bring jobs.
Just don’t look up.
[15:52] Ryan
Exactly.
Motivated blindness is probably the correct term.
People think:
“This is unpleasant to think about.”
So they mentally move it several layers away from their day-to-day reality.
Nobody is screaming loud enough until they start receiving form letters from customers.
[16:11] Ryan
I don’t think enough people are talking about timelines, how to respond to prime contractors, or how to shape expectations.
And then there’s what I think is the biggest existential threat:
What are you going to do about your suppliers?
If all the problems you’re having with your customers are true and valid, then you have to realize you’re probably passing those same problems down to your suppliers.
Unless something changes, you’re just becoming the next stop on the train.
[16:48] Ryan
The lower you go in the supply chain, the less revenue there is and the lower organizational maturity tends to be.
Those companies are not magically better positioned to become compliant.
Someone has to find ways to eliminate sensitive or regulated data from supply chains while preserving those supply chains.
And honestly, nobody is talking about that enough.
[17:08] Jacob
I see that all the time.
People say:
“The prime needs to limit the flow of CUI down to me.”
Then you ask:
“What are you doing to limit the flow of CUI to your suppliers?”
And the answer is:
“Nothing.”
It’s the same problem.
Second verse, same as the first.
[17:24] Jacob
Speaking of supply chains, let’s talk about L3Harris.
Because everybody’s heads exploded this week.
For anybody who missed it, L3Harris sent notifications to portions of its supply chain establishing certification expectations and timelines.
The internet reacted exactly the way the internet always reacts.
[17:48] Ryan
Yeah, and honestly I think some of the reaction was predictable.
People see a letter.
They see a date.
And they immediately assume that date came from the government.
A lot of the time that’s not what’s happening.
What’s happening is a prime contractor is evaluating risk and making decisions about how it wants to manage that risk.
[18:19] Jacob
That’s an important distinction.
Because everybody keeps asking:
“When is the government deadline?”
Sometimes the more important question is:
“When is my customer’s deadline?”
Those aren’t necessarily the same thing.
[18:36] Ryan
Exactly.
Your customer may decide they need certainty before they bid a contract.
Or before they renew a contract.
Or before they award subcontract work.
That’s a business decision.
Whether people like it or not, that’s the reality of how supply chains work.
[19:04] Jacob
I think that’s where some of the confusion comes from.
People look at phased rollout timelines and assume those timelines protect them.
They don’t.
Your customer is free to establish business requirements that are more aggressive than the government’s minimum timeline.
[19:29] Ryan
And frankly, we’ve seen that happen for years.
This isn’t unique to CMMC.
Prime contractors have always flowed requirements down their supply chains.
Cybersecurity is just the latest example.
[19:51] Jacob
Let’s pivot into some audience questions.
We’ve got a good one.
How should organizations think about assessment readiness if they’re still uncertain about parts of their scope?
[20:08] Ryan
I would separate uncertainty into categories.
There are things you know.
There are things you don’t know.
And there are things you can reasonably determine.
You don’t want to use uncertainty as an excuse to stop moving forward.
At the same time, you don’t want to sprint in the wrong direction.
[20:35] Ryan
For example, if you’re waiting on one narrow CUI determination, that probably shouldn’t stop you from implementing identity management, logging, configuration management, training, incident response, and all the other foundational pieces.
A lot of compliance work is useful regardless of the final scope decision.
[21:02] Jacob
That’s one of the reasons we talk about parallel paths.
There are some decisions that are gating decisions.
There are other activities that can proceed while those decisions are being worked.
People sometimes treat every unknown as a complete stop sign.
[21:23] Ryan
Exactly.
And that can create unnecessary delays.
If you wait until every question is perfectly answered, you may never start.
[21:40] Jacob
Here’s another one.
What are organizations consistently underestimating when they prepare for assessments?
[21:52] Ryan
The human element.
Without question.
Everybody focuses on technology.
Everybody focuses on controls.
Everybody focuses on documentation.
Then assessment week arrives and people realize they actually have to explain how everything works.
[22:20] Ryan
The assessor is going to ask questions.
They’re going to talk to administrators.
They’re going to talk to users.
They’re going to ask why things are done a certain way.
Organizations that prepare people tend to perform much better than organizations that only prepare technology.
[22:49] Jacob
That reminds me of something we’ve talked about for years.
You don’t rise to the occasion.
You fall back on your training.
If assessment week is the first time someone has ever heard about a policy, that’s not ideal.
[23:08] Ryan
Exactly.
People need familiarity.
They don’t need scripts.
They don’t need memorized answers.
They need understanding.
There’s a huge difference.
[23:29] Jacob
Let’s talk about reassessments for a second.
Because I think people hear the word and immediately panic.
[23:38] Ryan
I think part of that is because people imagine reassessment means starting over from scratch.
In many cases that’s not what we’re talking about.
The bigger issue is understanding what changes could trigger reassessment and planning accordingly.
[24:00] Ryan
If you know your environment is likely to evolve in a certain direction, then those future changes should be part of your planning process today.
That doesn’t eliminate risk, but it does reduce surprises.
[24:25] Jacob
Which is why architecture matters so much.
People want to think only about today’s requirements.
The organizations that do best are usually thinking about where they’ll be a year from now, two years from now, three years from now.
[24:49] Ryan
Exactly.
A little strategic planning can save an enormous amount of pain later.
[25:02] Jacob
All right.
Here’s a fun one.
What’s your favorite misconception that still exists in the industry?
[25:13] Ryan
Only one?
That’s hard.
I think one of the biggest is the belief that there is some magical shortcut.
Some secret product.
Some hidden architecture.
Some special assessment trick.
People desperately want there to be a shortcut.
[25:40] Ryan
The reality is much less exciting.
Successful organizations usually do the fundamentals well.
They understand their requirements.
They understand their environment.
They implement controls.
They document what they’ve done.
Then they maintain it.
It’s not glamorous.
But it works.
[26:07] Jacob
That’s one of the least marketable truths in cybersecurity.
The fundamentals are undefeated.
People want a silver bullet.
Most of the time the answer is disciplined execution.
[26:28] Ryan
Exactly.
Nobody wants to hear that.
Everybody wants a life hack.
But the fundamentals still matter.
[26:42] Jacob
Well, unfortunately for the internet, that’s probably the correct answer.
Let’s keep rolling because we’ve got a few more questions before we wrap up.
[26:55] Jacob
Let’s hit a few final questions.
This one comes up a lot.
What should organizations do if they genuinely disagree with a customer’s CUI determination?
[27:09] Ryan
The first thing I’d say is document your reasoning.
Too many organizations immediately jump to one of two extremes.
Either:
“Everything is CUI.”
Or:
“Nothing is CUI.”
Neither position is particularly helpful.
[27:31] Ryan
If you believe something has been marked incorrectly, go back to the source authorities.
Go back to the regulations.
Go back to the laws.
Go back to the CUI Registry.
Build an evidence-based position.
That gives you a much stronger foundation for having a productive conversation.
[27:57] Jacob
That’s one of the reasons I get frustrated when people act like CUI is completely unknowable.
It’s difficult.
It’s messy.
It’s sometimes ambiguous.
But there are source authorities.
There are references.
There are rules.
You can do the work.
[28:18] Ryan
Exactly.
It may not always produce the answer you want.
But there is usually a path toward a defensible answer.
[28:35] Jacob
Here’s another one.
How should organizations think about external service providers?
Because that’s another area where people seem to create confusion for themselves.
[28:48] Ryan
I think the key is understanding function.
People tend to focus on labels.
Cloud provider.
MSP.
MSSP.
Consultant.
Whatever.
What matters is what the organization is actually doing.
What data are they touching?
What security functions are they performing?
What responsibilities do they have?
[29:21] Ryan
Once you understand those relationships, the compliance conversation becomes much easier.
The label attached to the company matters a lot less than the role they’re performing.
[29:42] Jacob
That’s one of the recurring themes in compliance.
People want taxonomy.
They want categories.
But the implementation details are usually what drive the answer.
[29:59] Ryan
Exactly.
The details matter.
The data flows matter.
The responsibilities matter.
That’s where the real analysis happens.
[30:20] Jacob
Let’s talk about something that came up repeatedly at CS5.
Organizations wanting certainty.
Everybody wants certainty.
Everybody wants somebody to tell them exactly what will happen three years from now.
[30:37] Ryan
And unfortunately, that’s not how any of this works.
Cybersecurity changes.
Threats change.
Technology changes.
Policy changes.
The organizations that succeed are usually the organizations that can adapt.
[30:58] Ryan
I think people sometimes spend too much energy trying to predict every future requirement and not enough energy building resilient programs.
If your program is fundamentally sound, adapting becomes much easier.
[31:22] Jacob
That’s one of the reasons I always push back on hypothetical future scenarios.
People ask:
“What if Revision 3 does this?”
“What if the rule changes that?”
“What if this agency does something different?”
Maybe.
But today’s requirements still exist.
[31:45] Ryan
Exactly.
There’s no value in perfectly preparing for a hypothetical future if you’re unprepared for the requirements that already exist.
[32:04] Jacob
All right.
Last question.
What gives you optimism?
Because we spend a lot of time talking about problems.
What makes you optimistic about where things are headed?
[32:17] Ryan
Honestly, the collaboration.
Five years ago, organizations were much more isolated.
Today they’re sharing lessons learned.
They’re talking to each other.
They’re comparing approaches.
They’re helping each other avoid mistakes.
That’s healthy.
[32:44] Ryan
I also think there’s a much deeper understanding of cybersecurity risk now than there was a few years ago.
Not perfect.
Not even close.
But better.
And progress matters.
[33:06] Jacob
I agree.
I think we’re finally seeing the conversation shift from:
“Is this real?”
To:
“How do we do this well?”
That’s a much more productive conversation.
[33:27] Ryan
Exactly.
The questions are getting better.
And better questions usually lead to better outcomes.
[33:43] Jacob
Well said.
All right everybody, that’s going to do it for this week’s Hotline.
Thanks to Ryan for joining us.
Thanks to everybody who submitted questions.
Keep sending them in through the website, LinkedIn, YouTube, voicemail, smoke signals, carrier pigeons, whatever works.
We’ll be back next week with more questions and more compliance fun.
[34:07] Ryan
Thanks everybody.
Have a great weekend.
[34:10] Jacob
See you all next time.
Contact
Speak With Our Team
Our team of compliance and cybersecurity experts are on standby and ready to help. We’ll walk you through what you need and what to expect.
