An hour of live Q&A recapping the DoD’s post-RFI CMMC listening sessions and answering listener questions. The recurring theme: CMMC keeps taking the blame for costs and obligations that actually come from DFARS 7012, NIST 800-171, and export-control rules — and scoping, not lowering the bar, is what actually saves money.
Key takeaways:
- CMMC is the scapegoat. At the listening sessions, contractors blamed CMMC for ERP costs, cloud costs, even a 10-person shop openly admitting “I haven’t done any of this” (10-year-old requirements) — while the DoD didn’t correct the record. If CMMC vanished, those 7012/171 obligations and costs remain.
- “Not a cost of CMMC.” With Phase 2 suspended, nobody pays for a third-party assessment — so where are the costs coming from? Implementation, not verification.
- The cloud-cost complaint is already answered. The DoD did push providers; Microsoft’s GCC High Business Premium (~$50/user/month, capped at 300 users) is the result.
- FedRAMP 20x is unresolved. The DoD hasn’t recognized it as sufficient (reportedly an internal “civil war”), so you can’t rely on it yet. And FAR CUI pointing to 171 Rev 3 + FedRAMP could blow a hole in the harmonization/cost narrative.
- Push back on unmarked CUI — it works. A listener (Justin) got his prime to confirm in writing the data wasn’t CUI by asking for the exact required markings. If it’s not CUI, 7012 (and therefore CMMC) doesn’t apply. Distribution Statement D, by contrast, does signal CTI + export control.
- The DoD can’t stop primes. “November 2026” was never DoD policy — primes set it. Primes can require certification regardless, so the fix isn’t a DoD memo; it’s contractors pushing back.
- “Same as Lockheed” is a myth. 800-171 is the minimum floor, but it’s regressive — the smaller you are, the relatively bigger the lift. Still, there must be some minimum, and endlessly lowering it just relocates the problem; the real answer is funding (ENCODE, subsidies, tax breaks).
- Quick-start guides won’t fix it. The problem isn’t missing “IKEA instructions” — even contractors with an IT person and a full click-path refuse the work. Most of the DIB lacks a security program at all (the “paradox of burden”).
- CUI marking is the #1 pain point. With unreliable markings, you must comb the CUI Registry and sort your data into IP vs. COTS vs. custom/contract-specific (usually CTI). Enclaves (VDI, ENCODE) help knowledge-work/SETA shops but don’t fit manufacturers or range/test data — and data still lands on non-federal systems, which is exactly why scoping matters.
Transcript
Jacob: All right, everybody. It is Friday, so it’s hotline time. We’re live on YouTube, we’re live on LinkedIn, so you can chat with us down there. You can find us at cuihotline.org. You can call the number, you can fill out the form, you can send us DMs, you can find us on summit7.us, you can shoot us emails, you can send messenger pigeons or a raven. Lots and lots of ways to get hold of us, lots and lots of stuff to talk about. We’re live just like we are every Friday. And Scott’s here. Everybody likes it whenever Scott is able to take some time out of his schedule. We’ll get the names back up on the screen if you don’t know who Scott is. He’s the one in red, if you aren’t familiar.
Scott: Hey, red, white, and blue. Look at us today. Didn’t even plan that.
Jacob: There you go, Scott. You’ve been traveling a bunch, as you always do. You’ve been talking to a lot of people. We’re now at 118 Level 2 certifications, which is crazy, despite the Phase 2 suspension.
Daniel: The types of companies that like to work with us are the types of companies that aren’t phased by phased rollouts, if you will. Just thought of that, folks, off the top of my head.
Scott: But you wanted to talk about something a little bit different this time. So this is a real quote, everybody. Real quote. Yeah. So this morning, news broke that the Ninth Circuit, out of California, has basically said that the supply chain risk ban for Anthropic systems is unconstitutional, and has put a stay on that. So, if you were using Anthropic systems, this has been an issue that we’ve been working through for the past — I don’t know, two, three months now, I think — since they came out with Anthropic as a supply chain risk. Now, that doesn’t mean we’re completely out of the woods here with Anthropic. There is still a second ongoing court case in the DC Circuit — I believe the Circuit Court of Appeals — in DC, and we’ll have to wait to see how that one rolls out. But clearly, the administration is likely going to appeal the Ninth Circuit decision, so it continues to go on. But good news for Anthropic today. They’re probably getting a little bit of a stock bump, if I had to guess — haven’t looked it up, but maybe so. There’s still more to go, but looking good for Anthropic — they’re certainly not out of the woods yet with this whole situation.
Jacob: Yeah, it’ll be a fun one to watch. I wonder what internal counsel at Anthropic pulls down per year whenever they’re out here telling everybody that. Are they the ones that were going to tell everybody their market cap was $30 trillion coming out? I think I saw that in the headline. So, anybody that’s going to try to slow them down or get in their way is definitely going to get the full lawyer treatment. So we’ll have to keep an eye on it, but that definitely ain’t stopping at the circuit court — that’s probably going all the way up.
Scott: Probably. But yeah, that has come up in the past, in questions where people are like, “Can I use this if I’m a defense contractor?” So right now, what I would say is: if you are doing direct work and direct deliverables on a government contract, I would still probably look at not using it. But if it is on ancillary work or non-DoD work, then you’re probably in good shape at the moment on using Anthropic for other things — just not direct deliverables or systems doing DoD contract work.
Jacob: Yeah. It depends on your zip code, if you got a California. However, I am not a lawyer.
Scott: I am not a lawyer. Talk to yours.
Jacob: That’s right. Hey, Dave — yeah, it said “leave a message,” sorry. If you’ve got a question and you want us to do it right now, you can just leave it in chat, it’s probably a faster way for us to get a hold of it. If you have a longer one, you can leave the message on there and we can play it. Wild times. All right, Daniel — this is actually a real quote that you heard at the listening session.
Daniel: Man, what a time to be alive. So, I attended the Philadelphia DIBEX — the DIB accelerator conference — to hear the CIO speak, which is a whole other fun takeaway. But then a few hours later, they had the CMMC listening session. Now, this is post-RFI, and we’re sitting in a room of about 50-ish people, give or take, maybe upwards of 70. And around the room we have a mix of C3PAOs, a mix of MSPs, a mix of small businesses, and people just servicing the DIB — I’m sorry, the DoD. And we’re talking about questions five, six, and seven from the RFI. And they have a very strict “this is the only thing we’re talking about, you don’t get to ask any other questions.” And one of the questions was like, “Hey, what control has actually helped your security posture — that wasn’t just compliance, but the compliance led you to implement that security control, and you’ve seen real earnings from that, security protection, etc.?” And so this woman — and God bless her soul, she states her name, I’m not going to say it here — a 10-person company, she raises her hand and she says, “Hey, don’t throw me in jail. I haven’t done any of this.” And I’m sitting back in my chair, and I’m like, what is happening, where we can blatantly talk about not implementing the requirements that are 10 years old — and the DoD just nods their head in the room. Cynthia and the facilitator are both like [nodding], and I’m just sitting there bewildered, because I honest to God don’t understand. Was DOJ sitting in the corner just writing it down?
Jacob: Dude — I’d be at every listening session if I could, because I’ve either commented, or listened to recordings, or been present for almost all the listening sessions, and this is the first time I’ve heard anything like that — a small business admitting, “I haven’t done any of this stuff.” And the other side of it is, we hear it all the time on our calls.
Daniel: Absolutely. We hear it all the time.
Jacob: Right. But that’s why we require NDAs, everybody, so you don’t tell us stuff. You know that.
Daniel: Yeah.
Jacob: But to have somebody stand up in front of the DoD and say, “Hey, I haven’t done any of this, don’t put me in jail” — that’s pretty wild. That’s bold.
Daniel: That was the craziest thing. And anyways, people go across the room and they’re asking questions and saying, really, just, “CMMC costs too much, Microsoft licenses are too expensive, the DoD should subsidize that in some way” — all these random things being said, and I’m like, “Guys, you have export control data. You’re going to have to have GCC High, ITAR-type required clouds anyway. And the implementation and the controls, as we all know on this live stream, that’s 10 years old and you haven’t done any of it.” And you’re here admitting it openly without any shame, and it’s just like, guys, I don’t know what point you’re trying to make, but you’re doing it the wrong way.
Jacob: Well, it’s funny that you say that, because I’ve seen some of the RFI responses and heard some of the things from the listening sessions where people are like, “The DoD should just make the cloud providers charge less for access to their services.” One, that’s not how it works. Two — if you remember, a couple years ago, Stacy used to get up on stage and say she went to Microsoft and Amazon and Google and said, “You need to charge less money.” And according to that — we’ll have to find the clip, it’s out there — she was like, “I went to the cloud providers and said, ‘You need to charge less money for this.'” And they said, “How much do you want us to charge?” And she said, “50 bucks.” And they laughed her out of the room.
Scott: Well, you know what, Jacob? I’ve been in these meetings, literally, where they’re asking Microsoft to do this, and I’ve talked to people that have been in lots more meetings than I was in. And that is absolutely correct. The DoD — the DoW — has gone to the providers to ask that. That is literally 100% the entire reason that Business Premium licensing was released in GCC High. 100% the reason. And guess how much that is? Right at 50 bucks a user a month. I mean, they did it. The DoD went and did their work, they pushed on the providers, and the providers responded. Now, is that everything? Is that all the capabilities? No. But you can get there for small business. Microsoft has limits on the number of users you can have in a tenant — it’s limited to 300 users maximum with Business Premium. So you can’t have a large enterprise come in and buy 3,000 users of Business Premium — you’re going to have to move to the enterprise-level SKUs, which are more expensive. But the providers have responded to that message. They really did. So they’ve kind of already done that work.
Jacob: Yeah. Well, this is similar to what you were talking about, Daniel, about the listening sessions. So these are not recorded, they’re taking official public statements. I just posted on the DoD CIO’s LinkedIn page, where they talked about these listening sessions, “Guys, you’re recording these, right? Because then, when you come out in September with your recommendations and your report and you claim that people said XYZ, you have a record to point to.” Not a lawyer, certainly not their lawyer, but whatever you say — “we’re doing this because of what was said” — you have a record of that, right? Because from what I’ve heard, these sessions aren’t recorded. People — I wasn’t even in Philadelphia — but people have sent me what they overheard from some of these sessions. And similar to you, Daniel, somebody stood up from a 10-, 20-person defense company. Apparently this company has been a defense contractor for 30 years. They do some pretty high-speed stuff — they’re not out there putting up chain-link fence around the base, they’re doing real stuff on real systems. And the quote is: “We’re trying to get an ERP system, but because of CMMC implementation, when you ask for CMMC compliance, the cost was so much higher for the ERP system. Then they ask you, ‘Where are you going to put your CUI?’ So I felt like we needed an approach that will make this more reasonable, because it’s really increasing the cost on everything. If we want to be CMMC Level 2, then the ERP choices get narrower.” Quick chat pop quiz — what’s wrong with what this person just said? It’s completely true that the ERP system will cost money. It is completely, 100% not true that it is CMMC’s fault that your ERP system would cost more money. You’ve been a defense contractor for 30 years. If you want to put the CUI into a cloud-based ERP, you have a bunch of other stuff to worry about outside of CMMC. You had stuff to worry about before CMMC was a thing. You still have stuff to worry about now that CMMC Phase 2 is suspended. If CMMC disappeared overnight, you would still have issues. And so the question I put on LinkedIn today was: “If it weren’t for CMMC, this company could just use any ERP system they want to — true or false?” And there are people voting true. There are people voting true. And it’s like, guys, I don’t know if the DoD is hearing what people are saying in these listening sessions, but this is a quintessential example of CMMC taking the blame for everything else that involves DoD cybersecurity requirements.
Daniel: Yeah. It’s just stunning to me — people just attributing the cost of everything that is in their contract to CMMC. And it’s not true. Not true. And the DoW — I’m sitting in the room, the DoD is not correcting people and saying, “This was your requirement, has been your requirement for 10 years. CMMC didn’t do this to you.” No one is saying that to the room, which feeds this narrative that CMMC is the problem. And it’s like, it’s not the problem. There was another — two people in the room, a two-person drone-motor manufacturer based out of our lovely Huntsville, Alabama. Great guys, super genuine. They’re like, “If I have $30,000 to spend, I’m buying a CNC machine, I’m not buying cybersecurity.” And then you have the CIO at her keynote fireside chat saying, “CMMC — we’re hearing numbers between 200 to 500,000 for small businesses over three years.” And I’m like, there’s a small business that won’t even pay $30,000 to do it. Like, if CMMC Phase 2 was suspended and nobody’s paying for a third-party assessment, then everybody’s paying zero dollars, right?
Jacob: Right.
Daniel: Where are all the costs coming from if nobody has to pay for an assessment anymore? Absolutely crazy. I don’t know. All righty, let’s see here. Got a bunch of people in chat, which is always fun to see. All right, Dave put his question in the chat, so thanks for doing that, Dave. He said, “I’m new at this organization, and we are working on CMMC Level 2. We are an aircraft engine parts manufacturer. Some parts are for the military and some are for commercial, since this is for the C-130 aircraft. The contracts we get spell out DFARS 7012 and RD00004 CMMC Level 2 self-assessment, but none of the data we have has any CUI markings. They do have Statement D, which reads more like ITAR requires.” I assume you mean Distribution Statement D, so that means the data is not public. “But then the owner said they registered with the JCP for DD Form 2345, and that calls out Level 2. So I’m lost on what we’re really needing to do.”
Jacob: Man, we see this JCP thing coming up more and more, in parallel with CMMC, calling out Level 2. The contract says they have DFARS 7012, and they have data that’s marked Distribution Statement D, even though it doesn’t have a CUI marking on it. So, Daniel, what do you think here?
Daniel: So here’s a little bit of the conundrum. JCP, at least when we were looking through it, wasn’t going to require certification for Level 2 until the end of the phased roll-in, which was like 2028, I think, is when they had put on their website. So here’s a little bit of the conundrum — because you’re not wrong. DoD Distribution Statement D — and I have a pretty picture, because I’m a pretty-picture guy here — DoD Distribution Statement D does include both CTI and export control. So ITAR. So not only just in the distribution statement itself, it’s actually saying you have CUI, because controlled technical information is part of the CUI umbrella, if you will — and you have export control simultaneously. So you have a DFARS 7012 requirement, which is “go implement these things to protect this data,” and then you have CMMC Level 2 self, saying the thing you did to implement, you have to have implemented to a score of 88 out of 110 in a very specific way. And so, long story short, you have CUI, you have export control, you have to meet a minimum requirement of 88 out of 110 — but from what I can see, you don’t actually have to be certified, unless your prime is requiring that for the sake of the contract. Certified meaning C3PAO certification.
Jacob: C3PAO certified. That’s right. You have to self-assess.
Daniel: You have to self-assess. Yeah. And so make sure that, as you’re looking at deploying this with that ITAR requirement, the Distribution Statement D, make sure you are on the correct cloud when you implement — not in a commercial cloud, because that would be a problem.
Jacob: Yeah. And if you look at DFARS 7012 — it doesn’t use the acronym CUI in it. It specifically says the data that is relevant is the data that’s marked with those distribution statements. So if you were to completely ignore CMMC — suspensions, Level 2, Level 1, whatever — and just look at the applicability of that 7012 clause in your contract, it says this applies when you have these distribution statements. You have one of those distribution statements. So, 7012 and then the corresponding requirements are the ones I’m interested in. Do — are the other clauses in that contract, the 7021 clause, or anything else in that contract, Dave? Let us know, Dave, if you’re still around. Do you see DFARS 7021 in there that indicates [certification], or is it just 7012 and then your JCP stuff in parallel with that? All righty, let’s see here. “You’ve mentioned a number of times that FedRAMP 20x certification does not satisfy the requirement for cloud service providers who store, process, or transfer CUI to be FedRAMP certified. Could you explain why?”
The easy answer is the DoD hasn’t recognized FedRAMP 20x statuses as being sufficient. The word on the street is that there is a civil war going on inside of the Pentagon, where a bunch of people think that FedRAMP 20x is the greatest thing since sliced bread, and a bunch of other people think that it is completely misguided and completely out of line with what FISMA says — and they haven’t made a decision. This has been complicated by the fact that, apparently, when DIBCAC showed up, one team thought that FedRAMP 20x was fine, another team thought FedRAMP 20x wasn’t fine, and so now they have a real problem on their hands. So nobody really knows what the answer is going to be from an official policy standpoint. And until they tell you that 20x is going to be sufficient, you can’t rely on it for being sufficient. So we don’t know.
Beyond that, if you go into the details of 20x — this is a policy question the DoD will end up having to answer. Because back in 2016, when they were revising the DFARS 7012 clause, they used FedRAMP Moderate authorizations as a stand-in. They basically said, when we put data in the cloud, or we use cloud services, it has to be FedRAMP. “When you put our data in the cloud, what should the requirements be? It has to be more than 171, but what’s the answer?” So they just pointed to the FedRAMP Moderate baseline and said, “Make it equivalent to that,” because that’s what we would have to do. And that seemed like a reasonable workaround. Now that FedRAMP 20x is changing the idea of what Moderate looks like, does that still satisfy what the DoD thought of 10 years ago? Is the FedRAMP 20x Key Security Indicators baseline enough for them to say, “If you’re equivalent to this idea, that’s enough for us,” or not? They haven’t decided. Doesn’t appear that they’re going to decide anytime soon. When they do decide, that would have to be put out through a memo, put out through 7012 rulemaking. I don’t know. So as of right now, they haven’t given us an official answer.
Daniel: I mean, the other problem at play here is FAR CUI calls out FedRAMP Moderate authorized, or FedRAMP Moderate baseline — not equivalency. So even with a newer proposed rule, which went through public comment and is making its way to final publication, they’re still hanging their hat on FedRAMP Moderate language as well. And so it’s not the full equivalency memo that the DoD stated, which is far and above just having a FedRAMP Moderate baseline, but it’s still hanging the hat on the Key Security Indicators, right? So, man, Scott, we were talking about this — it’s like the FAR CUI rule comes out and points to 171 Rev 3 and FedRAMP, and it’ll rip a hole right in this DoD narrative about harmonization and burden and cost.
Scott: Yep. It will blow a hole in the side of this whole effort. And the DoD doesn’t seem to be aware —
Daniel: Yeah.
Scott: — of the threat here, of getting their narrative derailed. I don’t know what their answer is going to be here. But the FedRAMP — to answer your point — they haven’t given us an official answer. So until they say that it’s acceptable, you can’t rely on that as being a stand-in.
Jacob: All righty. Justin says — oh, he was responding to Dave. He said, “We work for a big prime. I’m pretty sure the information they’re sending us would be considered CUI, but they did not mark it as CUI. We asked them if it was CUI. When we persisted and asked and asked and asked, the contracting officer asked their security officer, and they reneged, stating that the information they sent us wasn’t CUI. I don’t think the primes know either.” Well, Justin, congratulations. You have done it. It’s a miracle. You pushed back on the prime, and they said, “Actually, none of this data is CUI.” Please keep that in writing, keep that in records. I would suggest to you that the next step is get them to say that if it’s not CUI, they’ll remove DFARS 7012 from any of your contract language or paperwork, because the only thing that would trigger the applicability of DFARS 7012 is if you have the data. And if 7012 doesn’t apply to you, CMMC doesn’t apply to you either. You have the golden ticket in your hand here — a prime saying, “We are not sending you controlled data.” All of this other stuff triggers if you have that data. So I can’t tell you how valuable it is that you have that in your hands. Honestly, shoot us a DM, because if you would like to come on the podcast and explain to us anonymously how this back-and-forth went, that would be a journey that many people would be like, “How do I get out from underneath these burdens?” That’s how you do it.
Scott: I may be reading too much into the comment, but they said the security officer said that. That doesn’t mean the contracting officer is going to accept that as the answer and contractually put that in writing. And we’ve also seen this happen — not to rain on your parade, Justin, I mean, it’s Friday — but we’ve also seen this happen all the time, where people get their primes to say, “Yeah, we don’t send you any CUI,” and they go, “Hooray!” And then they go, “Still do CMMC.”
Jacob: Yep. They don’t care.
Scott: Speaking of — we need a happier background, Jacob. We’ve been — you know, it’s been raining for like three years. We need a more happy background.
Jacob: A happier background. Okay. Let us know in chat, everybody — what would a happier background look like for you? No, not any of the rain — I like to have the rainy background. Blowing trees from in the mountains. Something with 60% humidity, you know.
Scott: Oh my gosh.
Jacob: Fun fact, everybody: Long Beach, California is the most humid place in the United States today. So pray for your friends in California. All right, Dave responded. Okay, they’re just going back and forth talking a bit about what was going on. We love when people make friends on our show. Look at this — “they just put it on all contracts as a blanket statement.” And this is actually very interesting that they’re talking about this, because this has come up in the RFI responses and in the listening sessions, where people are telling the DoD, “Just keep the primes from blanket-requiring CMMC status and 7012 and 800-171. Just tell them to stop.” And what we’ve talked about in the past is that the DoD can’t do that. Which — I’ve brought this up many times, much to the chagrin of people on LinkedIn and Reddit — there is no DoD policy, you will not find it, because it does not exist, that says that November of 2026 was the deadline for everyone to achieve CMMC Level 2. That was never the DoD’s policy. The primes made November of 2026 the deadline for their suppliers, of their own volition. So when people go to the DoD, and when the DoD says “November deadline was a problem” — what is the answer after the review? Make a policy that says November is not the deadline? That’s what the policy already said. So what will we say the deadline is? “We’re going to phase in the requirement and not have a deadline”? That’s what you already did. Are you going to have a policy that says you should mark CUI accurately, and then you shouldn’t flow this down to people who don’t need it, and that 7012 only applies when they have the data? That’s what the policies already say. So you have this behavior at the prime contractor level of them being able to mitigate their own risk, manage the risk of their suppliers, and do whatever. It doesn’t really matter what the DoD policy says — they’re going to accelerate and increase the requirement across the board. And there’s really not much the DoD can do about it, unless brave folks like Justin push back on their customer.
Scott: Yep.
Jacob: All righty. Justin said, “What worked for us was asking them for the exact markings that would be required.” Nice. “Once they were on the hook to provide solid information is when they admitted the data wasn’t CUI.” This is incredible. Shoot us a message, because I definitely want to know some more details. This is a story that needs to be told. We don’t have to say who your company is or who you are, in reality, unless you’d like to. But this is a great success story that alleviates the CMMC problem by using things that exist outside of CMMC. This is exactly what we’ve recommended to people over the years. A lot of people have always told us they don’t want to push back on their customer because they don’t want to be a problem. But man, it’s always great to hear when this actually worked. All righty, let’s see here. “Should micro businesses really be held to the same requirement as a 5,000-person defense contractor?” Hear this one a lot.
So, a lot of times this comes up in the context of 800-171, and people go, “It’s ridiculous that a five-person drone-motor manufacturer would be required to achieve the same security requirements as a Lockheed Martin.” I want to hold everybody’s hand when I say this: you are not required to meet the same requirements as Lockheed Martin. I don’t know how to tell you this, but you don’t have the same requirements at all. The agreements between the government and their mega-prime contractors at the program level are a different universe of security requirements than 800-171. 800-171 was originally designed to be the minimum baseline for the protection of federal data on non-federal systems — the floor, the minimum that is acceptable. The problem is that, like a flat tax, this is regressive as it occurs for smaller and smaller companies, which means the minimum standard is a relatively larger standard the smaller you get. So it’s very small for Lockheed, it’s very large for a five-person company. So then the debate that ends up happening is, people go, “Well, the minimum standard needs to be lowered so it’s achievable for a five-person company.” And then you get stuck in this loop where the government says, “Well, we aren’t willing to allow for a lesser standard.” And so when a program like CMMC comes along and holds people to that standard, CMMC takes the bullet, because then people blame the accountability mechanism for all these other issues that stem from these long-standing policies. So, what do you think here, Scott — the requirement?
Scott: Well, the first thing I think is we’re going to have to up that 5,000-person defense contractor size, because under the new SBA size considerations, that 5,000-person company is probably still a small business. Anyway. I think Shadow Sig there has a great comment that goes right along with this: “Should a small kitchen be as clean as a large kitchen?”
Jacob: That’s cool. Pretty well put. Dang, well done, Shadow.
Scott: Shadow’s out here with the bars today.
Jacob: That’s excellent. I actually haven’t heard that metaphor lately. That’s pretty good, man. So good. All right. “If my contract contains DFARS 7012, but I don’t actually receive or create CUI, do I need to implement NIST SP 800-171 or obtain CMMC Level 2?” Daniel, what do you think?
Daniel: I get this question all the time. People are like, “But I don’t get it [CUI].” I was like, “Well, then get it out of your contracts.” And it’s like, “But if you have it in your contracts” — I tell people, you need to create the equivalent of a guest room, so that when the crazy aunt shows up, she has a place to sleep. Now, she might only come once every year, and she might show up on your doorstep suddenly, which is typically how CUI gets delivered to you. But it’s one of those things where — push back like Justin did on your contractual obligation, if you really don’t have it. If not, you have to be able to receive it, so prepare to have a place for it to be, with 7012 requirements, NIST 800-171, FedRAMP, all the fun things. Even going back to the previous question, around “should a small business and a large business have the same CUI requirements” — it’s protection of the data. Smaller businesses also don’t have the enterprise technology stack that a very large business has, and it’s a lot more expensive to do that for a large business than a small business. There are small-business licenses and smaller things you have to do, because you don’t have as many assets. So the cost doesn’t scale dramatically for a small business — and I’m trying to be sensitive here, because you have so many fewer things. Some of the oversight and management to compile documentation, sure, but overall, you can’t go apples to apples to what Scott was saying. So anyways, all I say is: get 7012 out, or follow the requirements.
Scott: It’s expensive to be small, is what I tell people all the time. That’s just what it comes down to. And so you get into this position where — this is what’s in vogue right now, as it was a couple years ago — people say, “Well, it’s too expensive for smalls, so the requirements need to be lowered.” And then the question at that point is, okay, well, where is the bottom? I don’t disagree — I think there are things in 800-171 that shouldn’t be in there, I think there are things in 171 that are redundant, there are some things that should be in 171 that aren’t. I agree with people, there are things in 171 that make it not the perfect minimum standard, lots of room for improvement. We talked about this for over a year when they were doing the 171 Rev 2 to Rev 3 revision request for comments — we were doing podcasts every week being like, “change this, change that.” The philosophical question is: there must be a theoretical minimum for protecting the data. What that is, I don’t know. But must there be a minimum? One requirement, 10 requirements, 12 requirements, 100 requirements — what is the minimum standard? Once you figure out what that minimum standard is, then the question is: will you award contracts to people who cannot meet whatever that minimum standard is? Because no matter what you say, no matter what the minimum standard is, as long as there is a minimum bar to cross, there will be thousands and thousands of DIB companies that cannot meet it, for various reasons. So you’re going to end up in the same position, no matter how low you make that bar. And if you never establish a bar for what the minimum standard is, you’ve got to go to Congress and tell them why you just ignored what they told you to do 10 years ago. So you just go around and around and around. This isn’t to say it’s wrong to say the minimum bar needs to be lower, but clearly the answer is: where’s the money? You’ve got to help people in other ways. You’ve got to do ENCODE, you’ve got to do tax breaks, you’ve got to do subsidies, you’ve got to do all this other stuff. Whittling away the minimum standard is not going to fix this problem. Not to say it can’t or shouldn’t change — but that isn’t going to solve the issue for everybody.
Jacob: Okay. “Do you need a system security plan for CMMC Level 1?”
Daniel: Yes. You have to document the controls somehow. How else are you going to score yourself? And maybe the formal terminology of “SSP” — there’s not an SSP required by FAR 52.204-21, right?
Scott: Yeah, there is no actual requirement to have a document labeled “System Security Plan.” However, this is part of the problem with FAR 52.204-21 and 800-171 — and I think I said this last time I was on the Hotline — 171 is not built to be a security program. Neither is FAR 52.204-21. All of this is supposed to be an overlay. You’re supposed to already have a security program with all of these things done, and then these are just the minimum standards the government says you need to meet. You need to uplift whatever doesn’t meet it in your security program, so that you can hold CUI — or, in this case, FCI. That’s the biggest problem we have: we have tens of thousands of companies who literally do not have a security program. Period. End of story. They just simply do not have one. And so when they start looking at all of these controls, they have no frame of reference for how these plug in and actually function as a security program, because they don’t have a security program to plug it into. That’s the problem. So, no — FAR 52.204-21, CMMC Level 1, doesn’t say you have to have an SSP. But just because you are a business, you should have a security program, and that security program should have something documented, and then you should document what you’re doing for FAR 52.204-21 in whatever that document is that you have for your security program.
Jacob: Yeah, that’s a soapbox I can get on all day long. And this is the thing that has haunted the NIST requirements since they were written. They went through and said, “Well, if you were going to do a security program from scratch, then there would be 250 requirements in your contracts to go from zero to full program.” That, obviously — we’ve done videos on this, this was not that long ago — and the DoD said, “Well, we have to assume they have something in place already. It would be ridiculous to assume that a business isn’t doing any security.” That was obviously a very naive assumption. And so what they did was they tailored all that stuff out of that 250-control baseline, on the assumption that there was a security program in place. So then when they threw that baseline over the wall, in an attempt to not be bureaucratic — their own words — they said, “Here’s the things we need you to achieve through your own security program.” And everybody said, “We don’t know what to do here.” So nobody did it. And now here we are. In the famous history-of-CMMC video that came out in 2021, I called this the paradox of burden. We keep talking about the burden placed on the industry. Well, if nobody has a security program, nobody has a budget, and nobody has the staff or the skills to run a security program, then the only way to alleviate the burden is to give people more information about how to start and run a security program — which ironically increases the burden, because the requirements have to expand. And so it’s just a huge mess. That’s why this generation of DoD CIO leadership is going to wrestle with the same issue that the last 15 years of DoD CIO leadership has. And that really feels like — I really want to give them the benefit of the doubt, because I feel like a lot of the things they’re saying are correct. Yes, phishing-resistant MFA is a really fantastic idea, it would be great to get to that. Doing backups — absolutely, you should be doing that. But I don’t think they understand the level at which the majority of the companies in the defense industrial base are, when it comes to security maturity. We’re literally asking — phishing-resistant MFA, post-quantum cryptography — those are college-level courses, and we are literally trying to get some of these small businesses through kindergarten. And they just don’t have a frame of reference for what any of this stuff even is. Now — not every business, but a lot of businesses. The businesses primarily here listening today, those are not the businesses I’m talking about. It’s the ones that just simply aren’t paying attention and don’t have this as a frame of reference, but they still are in the defense industrial base, and they still are providing very important stuff to the warfighter, and we have to get them upleveled, because the warfighters need their stuff.
Scott: Right.
Jacob: And the answer — we want as many companies in the DIB as possible, and you want the security baseline to be as high as possible. The answer cannot be “constantly increase the requirements and never ask anybody to prove it.” That can’t be the policy answer. But the answer to that problem also cannot be “constantly lower the baseline and never ask for proof.” I laughed so hard — this reminded me, Scott. So if you guys didn’t see the podcast this week, go check it out. I gave some statements to National Defense Magazine about the “brilliant at the basics” and how it contradicts what the DoD has been saying about the suspension — they say they want to reduce cost and burden, but then the “brilliant at the basics” they published is a massive increase in cost and burden, were those to become the requirements. We’ve done a couple episodes on this. The Reddit reaction to the article was hilarious, because somebody said that my statements were “out of touch,” and that doing this MFA solution “just really isn’t that hard.” They were talking about replay-resistant MFA, and the quote on the Reddit thread said, “Here’s all it takes to implement replay-resistant MFA in Entra: enable FIDO2 and TAP authentication methods, deploy Windows Hello via Intune, then one conditional access policy requiring the built-in phishing-resistant MFA authentication strength, block legacy authentication for all but your break-glass Azure accounts. If you’re also using AD, do the same three Entra steps, plus Entra hybrid join, Server 2016+ domain controller, set Azure AD Kerberos server once per domain, then set up a GPO enabling Windows Hello with a cloud Kerberos trust. If you don’t like Windows Hello, you can use YubiKeys or all sorts of other choices.” Who are you talking to? Who are you talking to right now? Are you talking to the person who stood up at the listening session and said, “We don’t have an IT person, we don’t have a security person”? Who is that information for? That makes sense to all of us. That makes sense to the people that you’re talking to. If that were the guide that they published and said “do this” — oh, they would be great.
Scott: But that’s the quick-start guide. That’s the quick-start guide they’re talking about doing, right? I said this to you the other day in chat — you know, Jason Sproesser and I, we partnered with Microsoft back, I don’t know, four or five years ago. We literally wrote a step-by-step guide that you can download for free — call it a quick-start guide if you want to. A literal step-by-step guide to implement CMMC Level 1 in Office 365 commercial. I bet it hasn’t been used 25 times in five years, but it literally tells you everything you have to do for CMMC Level 1 in Office 365. Quick-start guides are not going to get it done.
Jacob: And this isn’t a dig at the defense contractors — there’s a reason why they don’t have this staff. But the idea that the only thing preventing them from doing OT security is that they don’t have IKEA instructions for how to do OT security is just insane. It’s completely out of touch with reality. I’m sure those quick-start guides would help some people, but it’s not going to fix your problem of the reason why it doesn’t get done. This reminds me of a story, back when I worked at DEFCERT with the great and powerful Ryan Bonner. We were on a call with a company that does awesome helicopter stuff, really cool helicopter stuff. They have an IT guy. We got on the phone with the IT guy, and we’re like, “Listen, we have mapped every single 800-171 requirement to the corresponding 800-53 control and its description of how to implement that 800-53 control in the DISA STIGs.” So the way the DoD explains how to implement 800-53 controls — if you go into the DISA STIGs, it literally gives you a click path. Click on this, enable this, click this. If you whittle those down to the 800-171 requirements, you could literally go step by step for 90% of the requirements for how to configure them in Windows, in Adobe, in all these technologies, because that’s how the DoD standardizes their implementations. We said, “Listen, here are 2,200 things that you have to do in order to implement all of this stuff.” And he immediately — I still remember this — he was like, “I’m not doing that. There’s — that’s too many steps.” And we’re like, “No, no, no, this is exactly what you would have to do, top to bottom, and you’d be good to go.” He’s like, “I’m not doing it. I’m not doing it. It’s too much stuff to do.” So you could literally hand people a click path — who have an IT guy — and they still are like, “not going to do it.” So, you should do the click paths, you should give them the quick-start guides, tell them all these things that Reddit was telling them. How hard could it be? Anyways. All right, let’s get back to it. I just don’t know what they’re going to do in 60 days. Are they going to come out and say, “Oh, the only thing we needed was guides on how to do it”?
Scott: Well, we’re only like 20 days out now, right?
Jacob: Yeah, I know. So crazy. All right. “Could the CMMC review actually change NIST 800-171 requirements, or is the DoD only reconsidering how compliance is verified?” That’s a great question.
Daniel: Great question. And this is what I struggle with, sitting in that room for the listening session. It’s like, all right, the DoD doesn’t own the requirements to safeguard CUI. NIST does, via executive order. They don’t actually have the ability, once FAR CUI comes out, to change the incident response timing of 72 hours, or the FedRAMP Moderate requirement. And so I was like, really, the DoD only has the power to validate. Now, here’s the interesting thing — and I actually put this question as a banner as well, Jacob, as a follow-up: let’s say something crazy happens and the CIO wants to go do rulemaking and change a bunch of stuff. DFARS 7021 is likely going to live well past into rulemaking, because it’s the only mechanism now for self-reporting your cyber posture. And they’re not going to get rid of that during rulemaking, if something were to even happen. So I’m looking at this and I’m like, guys, I don’t think you understand — CMMC is going to be around for a long time, even if the CIO wanted to change something. It just doesn’t happen overnight like that.
Jacob: So — let’s do an even crazier situation. Let’s say the DoD comes out, whether they can or not, and they just say, “We don’t want to require 800-171. We want to require the ‘brilliant at the basics.’ Do these 20 things as a condition of your contract.” What happens when the FAR CUI rule points to — not just 171 Rev 3 — literally any other set of requirements? Wasn’t the whole point here to harmonize the requirements across [the government]? I get that you want this extra higher level of security, but the way they’re talking — they’re like, “We want OT, we want this, we want that, we want phishing-resistant MFA, we want dynamically updated asset inventories across your entire company regardless of the scope of where CUI is.” How are you going to jive that with all this talk about harmonization and cost and burden?
Daniel: So here’s an interesting question. NIST 800-171 — safeguarding of CUI. Let’s say they wanted to add “brilliant at the basics” on top of that. They couldn’t add it as a CUI protective measure, because it’s not in the NIST publication. It would be added as probably a separate contractual line item, and it would just be a blanket of, “Hey, if you’re doing defense work, you’ve got to do these 20 things. Oh, and by the way, you’ve got to do these other things.”
Jacob: Yeah, it’d probably be a new clause. I would guess — it’s honestly the Delta 20, 2.0. I mean, we’re back to 2021. That’s my thing. If they wanted to change 171 requirements to something else, wouldn’t that require a change to DFARS 7012? Because CMMC isn’t the thing that’s causing you to have to implement the requirements. So the DoD CIO is going to get a different Under Secretary’s office to write rulemaking. Are you sure about that? Has the Under Secretary for A&S figured out what they’re going to do about the FedRAMP problem that we talked about earlier in the show? Because you’re not going to get an answer for a DFARS 7012 revision to what the requirements are until that gets figured out. And they’ve been talking about changing DFARS 7012 for three years, and that rule hasn’t made any progress. So they’re talking about CUI, 7012, all these other things, and it’s like — there’s at least three different Under Secretary offices, and possibly more than one agency, involved here. How much rulemaking are you planning on doing?
Scott: Yeah. And I haven’t done the crosswalk on this, but how many of the “brilliant at the basics” are in 800-53 Revision 5? So, I don’t know — I’d have to go do the crosswalk. But we would essentially have to wait on 800-53 Revision 6 to get the new requirements in there, and then 800-171 Revision 4, which would be the derivation from Revision 6, to get these new controls into an 800-171 requirement set.
Daniel: Also, the CIO, at her fireside chat this week, said, “I only have 877 days left of my employment here as the CIO.” Is that a long enough time to even do rulemaking to make the changes that someone would want to make?
Jacob: Right. The last time the DoD was hyper-motivated to get this done, it took them five years. And wasn’t that — an individual rule took five years to get through the process. There were a lot of reasons it took five years. But maybe they know something about the rulemaking process that we don’t. I just don’t know what the answer is going to be here.
Daniel: It’s going to be fascinating when we find [out].
Jacob: It will be absolutely fascinating to watch. “How should contractors determine what is actually CUI when contract documents and government markings are unclear?”
Daniel: Yeah, this is probably the number one comment in all of the RFI responses that I’ve read — CUI marking is the number one problem.
Jacob: 100%. Daniel, you’ve had Ryan on the show many times, we’ve done presentations at conferences many times about — I mean, we have people, when we’re working with them, literally run a script that rips through their environment to try to find some of this data. What do they actually need to do here, if they can’t rely on the markings?
Daniel: Yeah. So it’s really, really hard, and this is a very difficult problem. As everyone on this live stream probably knows, NARA holds the responsibility of the classification of CUI, sources it from agencies and government-wide policies and all sorts of good stuff, and the DoD has their own copy of that with a little bit more information and detail. So the DoD CUI Registry is actually more insightful than the NARA registry when you’re looking at it, but the CUI categories are the same. And so when you’re looking at this, it’s like, okay, I need to dive in and understand this a little bit more. We’ve built all sorts of keyword searches via regex to search — M365 content searches, eDiscovery, etc. — to try and surface the CUI that is marked. For the CUI that’s not marked — and this is where it gets a little hairy — you have to understand: what is your IP, what is COTS, and then what is custom? And by “custom,” I mean, what is specific information given to you on behalf of the contract that is private information that maps to one of the CUI categories? The most common is controlled technical information — space and military application is kind of the broad-stroke covering of that. But it can be inclusive of a lot of different things. Controlled technical information can [apply], but it doesn’t include COTS or your specific IP — it’s that unique information that you’re either receiving or creating on behalf of that contract. And so it takes a lot. You have to comb the registry, you have to know what your own data set is, how much you own, what’s new information to you from the prime or from the DoD directly. And it just takes a long time. And Justin, who did it earlier — the easiest way to do it is to push back on your prime and say, “What’s going to be CUI as part of this?” There’s a new form coming out with FAR CUI, called the SF-XXX form, which will have a numeric sequence to it — but that will be given to the prime. I wish they would have included contractual requirements for that to also flow down to the subs, for the primes to fill that out for all the subs, to say, “This is the CUI you’re going to be dealing with specifically.” But that’s not looking like it’s going to be inside the FAR CUI clause. So, I say all that to say: it is not easy. DEFCERT and Ryan Bonner have built an incredible business that only does this one thing, and they’re slammed, because people don’t understand how exposed they are. So, we’re happy to walk people through how to do this at a very basic level, and try and decouple or descope things. But I do not envy people that have to go through this process. We’ve seen hundreds of thousands of companies have to do it, though.
Jacob: Yeah. All right. “If employees access CUI only through a prime contractor’s devices and environment” — lucky you — “what is actually in the subcontractor’s CMMC scope?”
Scott: Yeah, if you literally — yeah, go ahead, D.
Daniel: No, no, go ahead. I’m pulling up something real quick.
Scott: So, if you are on a prime contract and you’re using nothing but prime-contractor-owned devices, cloud environments, what have you — you’re going to have to make sure you’re meeting the personnel requirements and getting background checks and those kinds of things, I would assume, by the prime. But if you are not getting CUI flowed into your systems, then you likely do not have a CMMC requirement set there. That is all going to be on the primes. And this is what we’ve actually recommended to many micro companies — seeing if you can get your prime contractor to host you in this manner, so that you actually don’t ever get CUI on your environment, and you work with it completely within the scope of your prime’s infrastructure. That is a really good solution for micros, and especially micros that only work with a single prime contractor.
Daniel: And I’ve seen this a lot. So this became more prevalent when the paper-copy FAQ language came out. This is the CMMC FAQ document, where it basically says — to summarize — hey, if you don’t have any CUI on a technology asset, you’re not taking a picture of it, you’re not digitizing it, not sticking it in other cloud systems or on-prem systems, then guess what? All you have to do is meet the applicable DFARS 7012 requirements for handling physical media. That’s the extent. You don’t have to have a self-assessment score, you don’t have to have a certification, you don’t have to do that stuff. So people took this and ran the clock back a little bit and said, “You know what, this could also apply.” Meaning, if technology systems are out of scope, I could have my subs access my enclave, or a separate enclave that I’m hosting for subcontractors, and follow the same pattern of behavior — because, again, no technology in their possession is actually going to process, store, or transmit CUI. So yeah, I would highly recommend, if you’re trying to help your subs — and it would take a lot of primes to get behind this — to build their own enclaves for their subcontracting network. Here’s the gotcha, though. A lot of subs — and this question got brought up at the listening session — people are asking, “Why can’t the government just host me a VDI enclave?”
Jacob: I see this all the time. I see this in comments. So many comments on the LinkedIn posts are like, “This is so easy to solve. Just create a government-hosted enclave for everyone in the DIB to operate out of.” And it’s like, hey guys, we would love that, if that were true. Because you know who does that work on the back end? Companies like ours. You want to have a government-run enclave for every single company in the DIB? Wonderful. We’re just going to turn the lights off after that’s done, because we won’t have time to do anything else. Daniel, why isn’t that an answer? Why can’t they just create an enclave for everybody, and then all this nonsense can end?
Daniel: Well, it’s all use-case based. If you have companies that can work solely in a VDI environment with basic applications — Office apps, things like that — then guess what, that is the easiest, most turnkey, “put them in an enclave.” SETA contractors, companies that just do basically information management — they’re knowledge managers, they just deal with information — all of that, SETA contractors, they’re great, they can use those kinds of environments, it works really well for them. 100%. And there are thousands of those companies out there, it’s a good fit for them.
Scott: Well, and what’s funny is — oh, keep going.
Daniel: Well, the problem I see all the time is really twofold. One, people have to have physical CUI, or CUI on physical hardware assets that they own, for the sake of the work they’re doing — a lot in manufacturing. But the second thing is, there are organizations that don’t want to put their IP in a government-run enclave environment, to mix it with the CUI, to get the documents that they actually need to do the work. And so, again, it’s just this tension of — it could fill a big need for contractors that can do VDI only and maybe aren’t putting IP in there, but a lot of them don’t really want to do that.
Scott: Well, also, you have — we have this a lot in Huntsville here — companies that are literally out on ranges doing testing and evaluation of systems. They’re getting ballistics data off of a missile launch or a rocket launch, or what have you. That data, that performance data, is CUI — or in some cases classified, but it’s one of the two — and then that data has to get uploaded to the government. That VDI environment does not work for that situation, if that CUI is either created outside the VDI and has to get somewhere, or if the CUI has to come out of that enclave environment to go onto a system somewhere. It doesn’t work at all, and that’s a very large number of contractors.
Jacob: Yeah. And it gets to this, where it’s like, okay, great, the government should provide as many of these government-furnished, subsidized enclave environments as possible — that’s wonderful, they should do things like ENCODE, they should do programs like that to the greatest extent possible. No matter what, the situation will still exist: that data will flow onto a non-federal system. It doesn’t matter if every company in the DIB has access to one of these types of environments — that data will flow onto a non-federal system in some cases. When those cases happen, what are the minimum requirements, and how do you know that people are doing them? So, slice off 20% of the companies out there needing to wrestle with this, because they could operate in this environment — what do you do about the rest? It doesn’t solve the problem. I see a lot of technologists and IT and security people go, “Just use technology to solve this problem.” And it’s just not that easy. We wish it was.
Scott: Mr. Flunky said, “That would be great.”
Jacob: Mr. Flunky says, “Can you touch on QuickBooks Online, and what the data from contracts can and cannot be placed into a platform like that, which is not FedRAMP?” This comes up relatively often, Daniel.
Daniel: It does. Yeah. So it’s kind of interesting. CMMC Level 1 is federal contract information, and that’s very nondescript. Basically what that says is private information between you and the government, or on behalf of the contract, that isn’t related to transactional information — like invoicing, for example. And so a lot of the data put into QuickBooks is probably not even applicable as FCI. But then the next level up, with that being contract information that’s non-CUI, has FCI requirements, which is the FAR 52.204-21 requirements — but there is no FedRAMP requirement for that. So, unless you’re putting controlled unclassified information — CTI is very common if you’re manufacturing in space and military applications, like engineering drawings, quality reports, very in-the-weeds type data that you likely wouldn’t attach to QuickBooks unless you have to provide evidence that you’ve done the work — and I would not stick that in QuickBooks. You don’t actually have to be FedRAMP for QuickBooks at all to meet CMMC Level 1, or to meet sending just invoices to the government or to your prime.
Jacob: Yeah, it’s all about the data. It’s always “follow the data,” and as long as CUI is not going to be there, you’re good to go. Keep CUI out of QuickBooks — unless the DoD statements around “brilliant at the basics” are to be believed, and then scoping goes out the window, and everything inside your network, just by virtue of being a defense contractor, is suddenly in scope.
Daniel: That’s going to be CISA’s approach with CIRCIA. I mean, it doesn’t matter, there is no scope. You’re only a defense contractor with relevant systems because you have the data. But because you are a defense contractor, now everything, regardless of the data, is in scope. That’s what’s going to happen with CIRCIA.
Jacob: It’s just so funny — we are, ironically, despite some of the accusations online, trying to encourage people that the CMMC scoping guidance is the thing you need, because it prevents you from spending more money. We will sell you fewer licenses if they narrow the scoping guidance down, rather than expanding it to everything in your organization.
Daniel: Yeah. Scoping is the number one way to save money with all of these requirements. And if that goes away, it’s going to potentially be a challenge.
Jacob: There you go, everybody. Well, it’s been an hour — it always flies by, especially when you’re here, Scott. It’s always great to hear your perspective. If you find this broadcast recording afterwards, you can add your questions and comments in the chat, we’ll add them to the queue. We’re live every Friday, so you can save your questions for the live chat next week whenever we see everybody. You can find us at cuihotline.org, you can fill out the form, you can leave a message over there at the real phone number that actually works. You go to summit7.us, keep up with our blogs. You can find us at events — we’re going to be at Summit 7 Live in Boston coming up here pretty soon, so make sure you guys register for that. We were just at Summit 7 Live in DC, which was a great event. We got to watch the Rockies lose, which is always a fun time for everybody.
Scott: They didn’t lose, they got destroyed. Yeah, it’s very different.
Jacob: Fourth consecutive season where they’re on track for 100 losses. Literally, if you’re not watching Rockies games, folks, you’re missing out on witnessing baseball history. They are terrible. There you go. So, yeah, thanks for joining, everybody. Lots of exciting stuff coming up. We’re headed into September, so we’re going to see what the DoD’s grand plan is going to be. So make sure that you like and subscribe, because we’re going to be covering all of the ups and downs of their next set of good ideas. And yeah, thanks for hanging out. We’ll see you next week. Have a great weekend.
Scott: See you.
Contact
Speak With Our Team
Our team of compliance and cybersecurity experts are on standby and ready to help. We’ll walk you through what you need and what to expect.
