Summary
Jacob and Daniel answered audience questions covering CMMC implementation timelines, scoping, contract requirements, MSPs, CUI handling, and the transition to Phase 2 of the CMMC program. Throughout the discussion, they emphasized that organizations should focus on understanding their scope, selecting experienced implementation partners, and engaging leadership early rather than waiting for contract deadlines. They also highlighted the growing role of prime contractors in driving compliance and the continued distinction between CMMC certification requirements and existing DFARS cybersecurity obligations.
Key Takeaways
- Leadership buy-in remains the biggest barrier to CMMC success. A month-long community poll found executive support outweighed cost, timelines, and technical challenges as the industry’s top obstacle.
- Implementation timelines are driven primarily by scope. Small, well-defined enclaves may be completed in a matter of months, while large enterprise transformations involving multiple sites, systems, or ERP migrations can take a year or longer.
- Choose implementation partners based on proven experience. Organizations should evaluate prospective MSPs and consultants by asking about their own CMMC certification status, customer success, and experience with Level 2 assessments.
- CMMC and DFARS 252.204-7012 are related but distinct requirements. Current False Claims Act enforcement continues to focus on DFARS cybersecurity obligations rather than CMMC certification itself.
- Prime contractors are increasingly enforcing CMMC readiness. Even when certification isn’t immediately required by regulation, many primes are establishing their own deadlines and may limit future opportunities for suppliers that are not progressing toward compliance.
Wanna know why the CMMC program persisted despite it’s unpopularity?
After almost 2 years and 2,000+ questions on the livestream two of the most common topics we get are about requirements outside of CMMC:
FedRAMP & ITAR.
Without CMMC few people would have discovered they had been operating in violation of existing obligations.
Of course, we answer questions about all the acronyms people love to hate.
Come hang out!
Transcript
[0:06] — Jacob
All right, everybody. It is Friday.
First time ever—first time on the show all alone here in Headquarters Studios. Normally I’m joined by somebody, so I’m flying solo in headquarters today. Daniel’s here from two hours up the road.
[0:28] — Daniel
Straight up north, baby.
[0:30] — Jacob
That’s right.
It’s Friday. It’s Hotline time.
Like usual, we’re live on YouTube and LinkedIn. You can find us at cuihotline.org. You can call the number and leave your question, fill out the form on the website, send us DMs, visit our website directly, or send us an email.
Lots of ways to get ahold of us, lots to talk about, and a big backlog of questions to dig through. We’ll get to questions from chat as we move forward.
Daniel, the temperature has definitely been rising. There are companies with former senior military leaders on their boards who spent a long time telling everyone CMMC was never going to affect them. Now it suddenly does, and they’re left holding the bag.
[1:40] — Daniel
I had a call this week with a company that had two very senior retired military leaders on its board.
Their message was, “CMMC is nothing to worry about.”
Most of their contracts are with the Navy, and they believed they had inside information that CMMC would never apply to them.
Then I got a call from their lead IT director.
He said, “They told us we didn’t have to do this because it would never affect us. Now we have until August 1 to become compliant and produce certification.”
I told him, “I’m so sorry.”
I don’t know how they’re going to accomplish that in the amount of time they have.
No competent implementation partner is going to be able to get an organization assessment-ready that quickly.
It’s already June.
School is out, people are taking vacations, the holiday is coming up, and summer slows decision-making.
August is a good time to prepare for November, but if you’re just getting started during the summer, it can be difficult to get everyone moving in the same direction.
I feel terrible for these people because they drew the short straw.
[3:29] — Jacob
The IT director called you.
The board members who insisted it wasn’t happening weren’t the ones on the phone.
[3:34] — Daniel
Of course not.
They’re saying, “Go fix this problem.”
This isn’t just an IT problem.
It’s a rapidly growing company that probably needed more infrastructure in place already.
This has become an enterprise transformation effort.
The people who said CMMC would never affect them aren’t the ones being held accountable when the company misses an important contract opportunity.
They have an August 1 contract that requires certification before award.
I don’t think they’re going to make that window.
I have a lot of confidence in the IT director. He’s incredibly smart.
But this takes time.
And he still has a full-time job.
Stories like this are sad to hear.
Take our advice.
Send this to any executive who’s still a CMMC naysayer. It may actually apply to them.
[4:56] — Jacob
That leads into what I wanted to talk about.
For those of you who missed it, check out LinkedIn.
Over the last month we’ve been running a tournament of LinkedIn polls, loosely inspired by playoff brackets.
Marketing asked me what the biggest issues were in the CMMC ecosystem before one of our webinars.
I immediately said:
- Cost
- Timeline
- The same issues we hear every day
They asked me to validate that with a poll.
That turned into a tournament.
I gathered every topic people mentioned in the comments, created a seeded bracket, and let people vote through each matchup.
The championship poll is live right now.
The final matchup is between:
- Leadership buy-in
- Bad guidance and snake oil
Not cost.
Not CUI marking and identification.
Not timeline.
Not flow-down.
Not technical knowledge or training gaps.
Not even scoping.
Right now, leadership buy-in is winning by a wide margin.
That’s interesting because LinkedIn shows each poll to different groups of people over time.
Different audiences independently reached the same conclusion.
The biggest issue isn’t technical.
It isn’t budget.
It isn’t implementation.
It’s whether contractor leadership gives their teams permission to move forward.
If you agree—or disagree—go vote.
We’ll do a complete wrap-up after the tournament ends.
[8:11] — Daniel
It’s true.
Without leadership buy-in, organizations can’t move forward.
Eventually that friction either creates whistleblowers or causes good employees to leave before leadership finally realizes it needs them.
[8:36] — Jacob
Let’s get into the backlog.
First question:
Do I have to achieve CMMC Level 1 before pursuing Level 2?
[8:45] — Daniel
Great question.
You don’t have to achieve Level 1 before Level 2.
You can go directly to Level 2 because Level 2 includes the Level 1 practices.
That said, starting with Level 1 isn’t a bad strategy if your contracts allow it.
The important decision is to implement Level 1 on FedRAMP Moderate cloud services from the beginning.
Level 1 doesn’t require FedRAMP.
Level 2 does.
If you start on commercial cloud services, you’ll end up migrating later.
Starting on FedRAMP positions you much better for Level 2.
[9:56] — Jacob
It’s probably not a bad place to start from a controls perspective.
We’ve asked our assessment engineers where they would start from an assessment standpoint and from an implementation standpoint, and there are lots of opinions.
There’s no single right answer.
Starting with the subset of controls that carry into Level 2 is fine.
Just remember that many of the biggest challenges come from requirements outside the 110 controls, like FedRAMP.
That’s where organizations often get caught.
[10:40] — Jacob
Next question.
If I don’t have CMMC Level 2 by November, am I immediately ineligible for my contracts?
[10:46] — Daniel
No.
You’re not immediately disqualified.
You’re only disqualified when you can’t produce the required certification.
You may submit proposals for solicitations that require CMMC.
Many solicitations require your assessment boundary and CMMC Unique Identifier at proposal submission.
Even though certification may not be required until award, you’ll still need to show evidence that you’re progressing through the CMMC process.
Your business development team can keep pursuing opportunities.
The bigger problem is getting to the end of the procurement process and losing the award because certification isn’t complete.
[12:03] — Jacob
November is relative.
Some companies are being told August.
Others October.
Others sometime in 2027 or later.
Read your customer’s requirements carefully.
The general rule is that November doesn’t automatically make you ineligible, but individual primes may have earlier deadlines.
[12:40] — Daniel
For most companies, your prime contractor—not the DoD—will dictate your timeline and determine when certification becomes necessary for future work.
[12:53] — Jacob
Next question.
How are companies determining what qualifies as CUI when there’s no guidance in the contract?
[13:13] — Daniel
Great question.
Contracts don’t typically identify every CUI category you’ll receive.
DFARS 252.204-7012 references Covered Defense Information and CUI generally.
Not every CUI category applies to contractors.
Some categories exist only for government agencies.
For example, budget information submitted to the Office of Management and Budget is CUI for agencies, but that category would never apply to Lockheed or another defense contractor.
The best place to start is:
- Ask your prime contractor what CUI categories they’re using.
- Review the DoD CUI Registry.
- Compare it with the National Archives CUI Registry.
Most contractors ultimately deal with Controlled Technical Information (CTI).
The DoD registry generally provides more practical explanation than the National Archives registry.
[14:48] — Jacob
The National Archives CUI Office has been missing in action for the last few years.
We haven’t seen much activity from that office.
Go with the DoD guidance until we hear otherwise.
[15:13] — Jacob
Mr. Julian asks:
“Subcontractor here. Why am I seeing so much Controlled Technical Information coming in from customers without Distribution Statements B through F? Did something change?”
I’m not sure why you’re receiving CTI that isn’t marked with those distribution statements.
As far as I know, nothing has changed with DoD marking policy.
The general rule of thumb—and Ryan Bonner has talked about this many times—is that when you see Distribution Statements B through F, that’s a strong indicator the information is Controlled Technical Information and therefore Controlled Unclassified Information.
[16:00] — Daniel
Exactly.
Distribution Statements B through E generally indicate Controlled Technical Information and export-controlled information, so it’s a one-two punch.
I’m not aware of any changes to DoD marking policy.
It may simply be that the prime contractor created the information and marked it as CUI before sending it to you.
The DoD isn’t responsible for marking every piece of CUI.
The information owner—whether that’s the government or the prime contractor—can apply CUI markings when appropriate.
That’s a common misconception.
People think only the federal government can mark CUI.
That’s simply not the case.
[16:50] — Jacob
Nicholas asks:
“Did anyone learn anything new about when the Joint Certification Program is required? The DLA website says it’s needed for military technical data, but is there a federal requirement or law written anywhere?”
I remember you asking this before, Nicholas, and I never followed up.
I’ve been living out of a hotel the past week, so this one slipped through the cracks.
I’ll dig into it more because I don’t have anything new to add today.
[17:23] — Daniel
The DLA website explains who can apply.
Generally, you must:
- Complete a NIST SP 800-171 assessment in SPRS.
- Comply with DFARS 252.204-7012.
- Have a SAM registration.
- Have a CAGE Code.
- Be located in the United States or Canada.
They also discuss CMMC implementation timelines, though I believe those requirements don’t become effective for the program until 2027 or 2028.
We’ll verify that.
[17:53] — Jacob
Herman asks the most important question of the day:
“Where did Banana finish in the CMMC challenge rankings?”
Fun fact:
The championship poll is the first LinkedIn poll I’ve posted in three or four years that doesn’t include Banana as a voting option.
People actually have to pick a side.
Leadership buy-in or snake oil.
No Banana.
There was a semifinal where Banana actually received enough votes that it almost changed the outcome.
Can’t have that happen in the championship.
The Banana option will return after the finals.
[19:17] — Jacob
Joe Smith asks:
“We haven’t heard much about False Claims Act activity around CMMC. What’s going on?”
A couple of things.
First, we released a podcast on Thursday covering our mid-year prediction review.
Back in January I predicted we’d see at least a dozen False Claims Act settlements related to defense contractor cybersecurity.
So far…
Zero.
We’ve seen none.
That doesn’t mean nothing is happening.
Everyone familiar with these cases says there are well over 100 investigations working their way through the process.
These cases simply take a long time.
At the same time, white-collar enforcement activity at DOJ has slowed generally, and staffing challenges may also be contributing.
The important distinction is this:
The False Claims Act cases we’ve seen involve DFARS 252.204-7012, not CMMC certification.
They’re based on failing to meet existing cybersecurity obligations—not certification failures.
That’s why I continue telling people there’s an important distinction between CMMC and DFARS 252.204-7012.
If organizations ignore DFARS because they believe CMMC will never apply to them, they still expose themselves to False Claims Act risk if employees become whistleblowers.
Go watch Thursday’s podcast.
We cover all of our predictions in detail.
[22:29] — Jacob
Next question.
How strict should the separation between administrative and standard user accounts be?
Should administrators be restricted from routine activities like opening files or browsing the web?
[22:48] — Daniel
You first define what constitutes privileged activity within your organization.
NIST SP 800-171 allows organizations to define privileged functions.
Typical privileged activities include:
- Installing software.
- Making system-level configuration changes.
- Editing the registry.
- Performing administrative tasks.
Once you’ve defined those activities, build your role-based access controls around them.
Technologies like Just-in-Time administration allow users to temporarily elevate privileges, complete the task, and immediately return to standard permissions.
Build your governance and security model around your organization’s definition of privileged activity.
[23:46] — Jacob
Easy question.
Can someone go from zero to CMMC Level 2 certification in three weeks?
Asking for a friend.
[23:52] — Daniel
Hard no.
We had a conversation this week with a company asking how quickly they could become compliant.
They were comparing us against much cheaper providers with little CMMC experience.
Leadership naturally wanted the cheaper option.
The question became:
“How fast can you do it?”
My answer was:
About six months.
I recently prepared material for our Secure the DIB event comparing VDI enclave offerings against more traditional implementations.
People often believe buying a VDI seat means they’re compliant within a few weeks.
That’s simply not true.
Many of these offerings advertise:
- Buy a seat.
- Receive policy templates.
- You’re done.
There’s far more to CMMC than that.
That’s exactly why snake oil ended up in the championship round of the LinkedIn tournament.
Leadership delays decisions, then imposes unrealistic deadlines, making organizations much more susceptible to promises that compliance can be delivered quickly, cheaply, and easily.
It’s a chicken-and-egg problem.
[26:41] — Jacob
Pridewin asks:
“If SPRS were a sports team, what would it be?”
Let us know in chat.
Would it be unpopular?
Would it constantly come up short?
Would it even be a major league team?
[27:21] — Jacob
Here’s another fun one.
By definition, CUI is information.
Can a physical manufactured part or component itself ever be considered CUI?
If so, what governs that determination when there isn’t a Security Classification Guide or contracting officer guidance?
[27:47] — Daniel
Ryan Bonner and I have talked about this several times.
Information is information.
Engineering drawings and technical documentation contain enough information to reproduce a part.
The physical part itself generally does not.
A physical component may still require protection under ITAR.
But simply possessing the component doesn’t necessarily mean you’ve received CUI.
Unless someone can reverse engineer the design from the physical object itself, the component isn’t automatically CUI in the same way the drawings are.
[28:40] — Jacob
Anybody watch Disclosure?
It raises a similar question.
You’ve got:
- digital information,
- documents,
- physical devices.
Is the physical device itself CUI?
It’s certainly export controlled in many cases.
Interesting discussion.
No spoilers.
[29:15] — Jacob
Next question.
“We’re an electrical contractor pursuing CMMC Level 2. We work from Navy job-site trailers using CUI drawings, but we don’t control the physical security of those trailers. How are we supposed to handle that?”
The trailer probably belongs to NAVFAC.
They’re simply occupying it temporarily.
What do they do?
[29:46] — Daniel
Interesting question.
NIST SP 800-53 discusses inheritance and specifically uses examples involving physical security on military installations.
Real-world situations aren’t always that clean.
Specialized Assets include government-furnished property.
When operating inside government facilities or using government-furnished spaces, I think there’s a reasonable argument that the trailer itself could be treated as a Specialized Asset.
You would still protect your own CUI assets appropriately while relying on the government’s physical security controls for the facility itself.
I’d be interested in hearing how assessors would approach that scenario.
Contact
Speak With Our Team
Our team of compliance and cybersecurity experts are on standby and ready to help. We’ll walk you through what you need and what to expect.
