Weekly CUI Hotline Q&A: 6.12.26

Wanna know why the CMMC program persisted despite it’s unpopularity? After almost 2 years and 2,000+ questions on the livestream […]

Summary

Jacob and Daniel answered audience questions covering CMMC implementation timelines, scoping, contract requirements, MSPs, CUI handling, and the transition to Phase 2 of the CMMC program. Throughout the discussion, they emphasized that organizations should focus on understanding their scope, selecting experienced implementation partners, and engaging leadership early rather than waiting for contract deadlines. They also highlighted the growing role of prime contractors in driving compliance and the continued distinction between CMMC certification requirements and existing DFARS cybersecurity obligations.

Key Takeaways

  1. Leadership buy-in remains the biggest barrier to CMMC success. A month-long community poll found executive support outweighed cost, timelines, and technical challenges as the industry’s top obstacle.
  2. Implementation timelines are driven primarily by scope. Small, well-defined enclaves may be completed in a matter of months, while large enterprise transformations involving multiple sites, systems, or ERP migrations can take a year or longer.
  3. Choose implementation partners based on proven experience. Organizations should evaluate prospective MSPs and consultants by asking about their own CMMC certification status, customer success, and experience with Level 2 assessments.
  4. CMMC and DFARS 252.204-7012 are related but distinct requirements. Current False Claims Act enforcement continues to focus on DFARS cybersecurity obligations rather than CMMC certification itself.
  5. Prime contractors are increasingly enforcing CMMC readiness. Even when certification isn’t immediately required by regulation, many primes are establishing their own deadlines and may limit future opportunities for suppliers that are not progressing toward compliance.

Wanna know why the CMMC program persisted despite it’s unpopularity?

After almost 2 years and 2,000+ questions on the livestream two of the most common topics we get are about requirements outside of CMMC:

FedRAMP & ITAR.

Without CMMC few people would have discovered they had been operating in violation of existing obligations.

Of course, we answer questions about all the acronyms people love to hate.

Come hang out!


Transcript

[0:06] — Jacob
All right, everybody. It is Friday.

First time ever—first time on the show all alone here in Headquarters Studios. Normally I’m joined by somebody, so I’m flying solo in headquarters today. Daniel’s here from two hours up the road.

[0:28] — Daniel
Straight up north, baby.

[0:30] — Jacob
That’s right.

It’s Friday. It’s Hotline time.

Like usual, we’re live on YouTube and LinkedIn. You can find us at cuihotline.org. You can call the number and leave your question, fill out the form on the website, send us DMs, visit our website directly, or send us an email.

Lots of ways to get ahold of us, lots to talk about, and a big backlog of questions to dig through. We’ll get to questions from chat as we move forward.

Daniel, the temperature has definitely been rising. There are companies with former senior military leaders on their boards who spent a long time telling everyone CMMC was never going to affect them. Now it suddenly does, and they’re left holding the bag.

[1:40] — Daniel
I had a call this week with a company that had two very senior retired military leaders on its board.

Their message was, “CMMC is nothing to worry about.”

Most of their contracts are with the Navy, and they believed they had inside information that CMMC would never apply to them.

Then I got a call from their lead IT director.

He said, “They told us we didn’t have to do this because it would never affect us. Now we have until August 1 to become compliant and produce certification.”

I told him, “I’m so sorry.”

I don’t know how they’re going to accomplish that in the amount of time they have.

No competent implementation partner is going to be able to get an organization assessment-ready that quickly.

It’s already June.

School is out, people are taking vacations, the holiday is coming up, and summer slows decision-making.

August is a good time to prepare for November, but if you’re just getting started during the summer, it can be difficult to get everyone moving in the same direction.

I feel terrible for these people because they drew the short straw.

[3:29] — Jacob
The IT director called you.

The board members who insisted it wasn’t happening weren’t the ones on the phone.

[3:34] — Daniel
Of course not.

They’re saying, “Go fix this problem.”

This isn’t just an IT problem.

It’s a rapidly growing company that probably needed more infrastructure in place already.

This has become an enterprise transformation effort.

The people who said CMMC would never affect them aren’t the ones being held accountable when the company misses an important contract opportunity.

They have an August 1 contract that requires certification before award.

I don’t think they’re going to make that window.

I have a lot of confidence in the IT director. He’s incredibly smart.

But this takes time.

And he still has a full-time job.

Stories like this are sad to hear.

Take our advice.

Send this to any executive who’s still a CMMC naysayer. It may actually apply to them.

[4:56] — Jacob
That leads into what I wanted to talk about.

For those of you who missed it, check out LinkedIn.

Over the last month we’ve been running a tournament of LinkedIn polls, loosely inspired by playoff brackets.

Marketing asked me what the biggest issues were in the CMMC ecosystem before one of our webinars.

I immediately said:

  • Cost
  • Timeline
  • The same issues we hear every day

They asked me to validate that with a poll.

That turned into a tournament.

I gathered every topic people mentioned in the comments, created a seeded bracket, and let people vote through each matchup.

The championship poll is live right now.

The final matchup is between:

  • Leadership buy-in
  • Bad guidance and snake oil

Not cost.

Not CUI marking and identification.

Not timeline.

Not flow-down.

Not technical knowledge or training gaps.

Not even scoping.

Right now, leadership buy-in is winning by a wide margin.

That’s interesting because LinkedIn shows each poll to different groups of people over time.

Different audiences independently reached the same conclusion.

The biggest issue isn’t technical.

It isn’t budget.

It isn’t implementation.

It’s whether contractor leadership gives their teams permission to move forward.

If you agree—or disagree—go vote.

We’ll do a complete wrap-up after the tournament ends.

[8:11] — Daniel
It’s true.

Without leadership buy-in, organizations can’t move forward.

Eventually that friction either creates whistleblowers or causes good employees to leave before leadership finally realizes it needs them.

[8:36] — Jacob
Let’s get into the backlog.

First question:

Do I have to achieve CMMC Level 1 before pursuing Level 2?

[8:45] — Daniel
Great question.

You don’t have to achieve Level 1 before Level 2.

You can go directly to Level 2 because Level 2 includes the Level 1 practices.

That said, starting with Level 1 isn’t a bad strategy if your contracts allow it.

The important decision is to implement Level 1 on FedRAMP Moderate cloud services from the beginning.

Level 1 doesn’t require FedRAMP.

Level 2 does.

If you start on commercial cloud services, you’ll end up migrating later.

Starting on FedRAMP positions you much better for Level 2.

[9:56] — Jacob
It’s probably not a bad place to start from a controls perspective.

We’ve asked our assessment engineers where they would start from an assessment standpoint and from an implementation standpoint, and there are lots of opinions.

There’s no single right answer.

Starting with the subset of controls that carry into Level 2 is fine.

Just remember that many of the biggest challenges come from requirements outside the 110 controls, like FedRAMP.

That’s where organizations often get caught.

[10:40] — Jacob
Next question.

If I don’t have CMMC Level 2 by November, am I immediately ineligible for my contracts?

[10:46] — Daniel
No.

You’re not immediately disqualified.

You’re only disqualified when you can’t produce the required certification.

You may submit proposals for solicitations that require CMMC.

Many solicitations require your assessment boundary and CMMC Unique Identifier at proposal submission.

Even though certification may not be required until award, you’ll still need to show evidence that you’re progressing through the CMMC process.

Your business development team can keep pursuing opportunities.

The bigger problem is getting to the end of the procurement process and losing the award because certification isn’t complete.

[12:03] — Jacob
November is relative.

Some companies are being told August.

Others October.

Others sometime in 2027 or later.

Read your customer’s requirements carefully.

The general rule is that November doesn’t automatically make you ineligible, but individual primes may have earlier deadlines.

[12:40] — Daniel
For most companies, your prime contractor—not the DoD—will dictate your timeline and determine when certification becomes necessary for future work.

[12:53] — Jacob
Next question.

How are companies determining what qualifies as CUI when there’s no guidance in the contract?

[13:13] — Daniel
Great question.

Contracts don’t typically identify every CUI category you’ll receive.

DFARS 252.204-7012 references Covered Defense Information and CUI generally.

Not every CUI category applies to contractors.

Some categories exist only for government agencies.

For example, budget information submitted to the Office of Management and Budget is CUI for agencies, but that category would never apply to Lockheed or another defense contractor.

The best place to start is:

  • Ask your prime contractor what CUI categories they’re using.
  • Review the DoD CUI Registry.
  • Compare it with the National Archives CUI Registry.

Most contractors ultimately deal with Controlled Technical Information (CTI).

The DoD registry generally provides more practical explanation than the National Archives registry.

[14:48] — Jacob
The National Archives CUI Office has been missing in action for the last few years.

We haven’t seen much activity from that office.

Go with the DoD guidance until we hear otherwise.

[15:13] — Jacob
Mr. Julian asks:

“Subcontractor here. Why am I seeing so much Controlled Technical Information coming in from customers without Distribution Statements B through F? Did something change?”

I’m not sure why you’re receiving CTI that isn’t marked with those distribution statements.

As far as I know, nothing has changed with DoD marking policy.

The general rule of thumb—and Ryan Bonner has talked about this many times—is that when you see Distribution Statements B through F, that’s a strong indicator the information is Controlled Technical Information and therefore Controlled Unclassified Information.

[16:00] — Daniel
Exactly.

Distribution Statements B through E generally indicate Controlled Technical Information and export-controlled information, so it’s a one-two punch.

I’m not aware of any changes to DoD marking policy.

It may simply be that the prime contractor created the information and marked it as CUI before sending it to you.

The DoD isn’t responsible for marking every piece of CUI.

The information owner—whether that’s the government or the prime contractor—can apply CUI markings when appropriate.

That’s a common misconception.

People think only the federal government can mark CUI.

That’s simply not the case.

[16:50] — Jacob
Nicholas asks:

“Did anyone learn anything new about when the Joint Certification Program is required? The DLA website says it’s needed for military technical data, but is there a federal requirement or law written anywhere?”

I remember you asking this before, Nicholas, and I never followed up.

I’ve been living out of a hotel the past week, so this one slipped through the cracks.

I’ll dig into it more because I don’t have anything new to add today.

[17:23] — Daniel
The DLA website explains who can apply.

Generally, you must:

  • Complete a NIST SP 800-171 assessment in SPRS.
  • Comply with DFARS 252.204-7012.
  • Have a SAM registration.
  • Have a CAGE Code.
  • Be located in the United States or Canada.

They also discuss CMMC implementation timelines, though I believe those requirements don’t become effective for the program until 2027 or 2028.

We’ll verify that.

[17:53] — Jacob
Herman asks the most important question of the day:

“Where did Banana finish in the CMMC challenge rankings?”

Fun fact:

The championship poll is the first LinkedIn poll I’ve posted in three or four years that doesn’t include Banana as a voting option.

People actually have to pick a side.

Leadership buy-in or snake oil.

No Banana.

There was a semifinal where Banana actually received enough votes that it almost changed the outcome.

Can’t have that happen in the championship.

The Banana option will return after the finals.

[19:17] — Jacob
Joe Smith asks:

“We haven’t heard much about False Claims Act activity around CMMC. What’s going on?”

A couple of things.

First, we released a podcast on Thursday covering our mid-year prediction review.

Back in January I predicted we’d see at least a dozen False Claims Act settlements related to defense contractor cybersecurity.

So far…

Zero.

We’ve seen none.

That doesn’t mean nothing is happening.

Everyone familiar with these cases says there are well over 100 investigations working their way through the process.

These cases simply take a long time.

At the same time, white-collar enforcement activity at DOJ has slowed generally, and staffing challenges may also be contributing.

The important distinction is this:

The False Claims Act cases we’ve seen involve DFARS 252.204-7012, not CMMC certification.

They’re based on failing to meet existing cybersecurity obligations—not certification failures.

That’s why I continue telling people there’s an important distinction between CMMC and DFARS 252.204-7012.

If organizations ignore DFARS because they believe CMMC will never apply to them, they still expose themselves to False Claims Act risk if employees become whistleblowers.

Go watch Thursday’s podcast.

We cover all of our predictions in detail.

[22:29] — Jacob
Next question.

How strict should the separation between administrative and standard user accounts be?

Should administrators be restricted from routine activities like opening files or browsing the web?

[22:48] — Daniel
You first define what constitutes privileged activity within your organization.

NIST SP 800-171 allows organizations to define privileged functions.

Typical privileged activities include:

  • Installing software.
  • Making system-level configuration changes.
  • Editing the registry.
  • Performing administrative tasks.

Once you’ve defined those activities, build your role-based access controls around them.

Technologies like Just-in-Time administration allow users to temporarily elevate privileges, complete the task, and immediately return to standard permissions.

Build your governance and security model around your organization’s definition of privileged activity.

[23:46] — Jacob
Easy question.

Can someone go from zero to CMMC Level 2 certification in three weeks?

Asking for a friend.

[23:52] — Daniel
Hard no.

We had a conversation this week with a company asking how quickly they could become compliant.

They were comparing us against much cheaper providers with little CMMC experience.

Leadership naturally wanted the cheaper option.

The question became:

“How fast can you do it?”

My answer was:

About six months.

I recently prepared material for our Secure the DIB event comparing VDI enclave offerings against more traditional implementations.

People often believe buying a VDI seat means they’re compliant within a few weeks.

That’s simply not true.

Many of these offerings advertise:

  • Buy a seat.
  • Receive policy templates.
  • You’re done.

There’s far more to CMMC than that.

That’s exactly why snake oil ended up in the championship round of the LinkedIn tournament.

Leadership delays decisions, then imposes unrealistic deadlines, making organizations much more susceptible to promises that compliance can be delivered quickly, cheaply, and easily.

It’s a chicken-and-egg problem.

[26:41] — Jacob
Pridewin asks:

“If SPRS were a sports team, what would it be?”

Let us know in chat.

Would it be unpopular?

Would it constantly come up short?

Would it even be a major league team?

[27:21] — Jacob
Here’s another fun one.

By definition, CUI is information.

Can a physical manufactured part or component itself ever be considered CUI?

If so, what governs that determination when there isn’t a Security Classification Guide or contracting officer guidance?

[27:47] — Daniel
Ryan Bonner and I have talked about this several times.

Information is information.

Engineering drawings and technical documentation contain enough information to reproduce a part.

The physical part itself generally does not.

A physical component may still require protection under ITAR.

But simply possessing the component doesn’t necessarily mean you’ve received CUI.

Unless someone can reverse engineer the design from the physical object itself, the component isn’t automatically CUI in the same way the drawings are.

[28:40] — Jacob
Anybody watch Disclosure?

It raises a similar question.

You’ve got:

  • digital information,
  • documents,
  • physical devices.

Is the physical device itself CUI?

It’s certainly export controlled in many cases.

Interesting discussion.

No spoilers.

[29:15] — Jacob
Next question.

“We’re an electrical contractor pursuing CMMC Level 2. We work from Navy job-site trailers using CUI drawings, but we don’t control the physical security of those trailers. How are we supposed to handle that?”

The trailer probably belongs to NAVFAC.

They’re simply occupying it temporarily.

What do they do?

[29:46] — Daniel
Interesting question.

NIST SP 800-53 discusses inheritance and specifically uses examples involving physical security on military installations.

Real-world situations aren’t always that clean.

Specialized Assets include government-furnished property.

When operating inside government facilities or using government-furnished spaces, I think there’s a reasonable argument that the trailer itself could be treated as a Specialized Asset.

You would still protect your own CUI assets appropriately while relying on the government’s physical security controls for the facility itself.

I’d be interested in hearing how assessors would approach that scenario.

PART 3 (30:16–45:02)

[30:16] — Daniel
Specialized Assets include government-furnished property.

When this guidance was written, it was probably intended more for government-furnished technology, like a government laptop or device.

But if you’re working on a military installation using a government-provided trailer, I think you could reasonably consider that trailer a Specialized Asset because your CUI assets are inside it.

You would protect your own CUI assets appropriately while following the government’s physical security policies and procedures for the facility itself.

If there are any assessors listening, I’d be interested in their opinion, but I don’t see why you couldn’t treat that as Government-Furnished Property.

[31:15] — Jacob
Someone asked whether there’s a registration link yet for Secure the DIB 2026.

If there is, we’ll drop it in the chat.

If not, you’ll definitely see the marketing announcements soon.

Be on the lookout—the content should be really good.

[31:44] — Jacob
Next question.

“We failed our mock assessment because we didn’t document in the SSP how every requirement applied to every Security Protection Asset in our environment. Is that standard?”

[32:04] — Daniel
No.

You should not have failed your mock assessment for that reason.

Security Protection Assets are evaluated based on the controls that are applicable to the capabilities they provide.

For example, when evaluating something like Active Directory or Microsoft Entra ID, you look at the controls that are relevant to those systems.

If someone expected you to document all 110 controls against every Security Protection Asset, they weren’t following the guidance correctly.

Quite honestly, I’d question whether that’s the right organization to perform your certification assessment.

[32:46] — Jacob
At least it was only a mock assessment.

I’d have a conversation with them before moving forward.

[33:11] — Jacob
Next question.

How restrictive should software controls be?

Should users be prevented from installing any unauthorized software, or is blocking commonly abused applications sufficient?

[33:24] — Daniel
Under NIST SP 800-171 Rev. 2—the current CMMC baseline—you have two options:

  • Allow list (whitelist)
  • Deny list (blacklist)

You can maintain a deny list that blocks specific applications.

However, Rev. 3 removes that flexibility.

Going forward, the expectation is an allow-list approach where approved applications are explicitly defined.

If you’re preparing for Rev. 3 now, I’d recommend gradually moving toward an allow-list model.

Build your catalog of approved software.

Use technologies like:

  • Microsoft Windows Defender Application Control (WDAC)
  • ThreatLocker
  • Similar application control solutions

[34:37] — Jacob
Regardless of Rev. 2 or Rev. 3…

Users downloading whatever they want isn’t a great idea.

Maintain your baseline.

That’s why people have personal phones.

Do whatever you want there.

Leave corporate systems alone.

[35:16] — Jacob
Next question.

Will NIST SP 800-171—or even CMMC—spread beyond the Department of Defense to other federal agencies?

[35:29] — Daniel
Yes.

NIST SP 800-171 already exists for all federal agencies whenever contractors handle Controlled Unclassified Information.

Every agency has CUI that eventually leaves government systems and enters contractor environments.

NIST SP 800-171 is the minimum baseline for protecting that information.

The reason it feels like a DoD-only issue is because we’ve never received the FAR CUI Rule.

That rule would create a government-wide contract requirement.

We’ve been waiting roughly ten years.

The DoD couldn’t wait because of the cybersecurity threats it was facing.

So it created DFARS 252.204-7012 instead.

When the DoD updated that clause in 2016, it said the rule was intended as a temporary placeholder until the FAR Council finalized the government-wide rule.

Ten years later, that FAR rule still hasn’t arrived.

Ironically, the proposed FAR CUI Rule now looks a lot like DFARS 252.204-7012 instead of the other way around.

NIST SP 800-171 absolutely applies government-wide.

Whether agencies require third-party verification like CMMC remains an open question.

The proposed FAR CUI Rule doesn’t mandate third-party certification.

Instead, it allows agencies to decide.

Some agencies probably will.

Others probably won’t.

The CMMC model itself is agency-agnostic, so nothing prevents other agencies from adopting it.

[38:30] — Jacob
Next question.

Can I achieve CMMC Level 2 while using Google Workspace or Microsoft 365 Commercial?

[38:42] — Daniel
Only if those environments are out of scope.

The challenge is FedRAMP.

Both Google and Microsoft offer FedRAMP-authorized versions of their platforms.

That usually means:

  • Google Workspace with Assured Workloads.
  • Microsoft GCC or GCC High.

Standard commercial licenses aren’t sufficient.

Some organizations attempt bolt-on solutions like Prevail or Virtru.

The challenge is scope.

Encrypted CUI is still CUI.

If that data moves through a non-FedRAMP cloud service, you’re still creating compliance problems.

[40:03] — Jacob
We get questions about Prevail all the time.

People ask:

“What happens when CUI leaves the Prevail environment?”

At that point, do those endpoints become in scope?

It’s like that Simpsons episode where Mr. Burns has layer after layer of security protecting his vault, only to discover the back door standing open.

[40:37] — Jacob
Next question.

Do you have guidance for High Performance Computing environments?

[40:56] — Daniel
NIST has publications addressing HPC environments, just as it does for quantum computing.

Those are situations where organizations sometimes consider enduring exceptions.

Examples include:

  • Systems that must replicate operational environments.
  • Medical devices.
  • Test equipment.
  • Operational Technology (OT).
  • Internet of Things (IoT).

Those situations require documentation in the System Security Plan.

High Performance Computing is a unique case because fully implementing every security control may significantly reduce the system’s intended performance.

That doesn’t automatically justify an enduring exception.

You should use that concept very conservatively.

But if applying every security requirement fundamentally prevents the system from performing its intended mission, there may be a reasonable path forward.

[42:15] — Jacob
Charlie Snyder’s in the chat.

Charlie and I served together in the Navy.

Charlie—

Who did you vote for in the CMMC tournament?

Leadership buy-in or snake oil?

I trust Charlie’s judgment.

[42:39] — Jacob
Next question.

Can an organization achieve CMMC Level 2 while using an MSP that isn’t CMMC Level 2 certified?

[42:45] — Daniel
Absolutely.

It’s possible.

The better question is whether they’re capable of getting you certified.

Ask about their past performance.

How many organizations have they successfully taken through certification?

This isn’t 2019 anymore.

During the early days of CMMC, lots of organizations claimed they’d solved the problem.

There wasn’t a good way to evaluate those claims.

Now there is.

We’re more than halfway through the first year of implementation.

If a provider still hasn’t demonstrated successful outcomes, that’s a significant question.

Organizations like those participating in the MSP Collective have proven they can do it because they’ve completed certification themselves.

If you’re trusting someone with your certification, make sure they’ve demonstrated success.

If not, make sure your contracts include strong protections in case their implementation failures prevent you from achieving certification.

[44:48] — Jacob
Perfect example.

We spoke with a really interesting space startup this week.

Their advisor had been telling them for a long time that CMMC would never apply to them.

[45:07] — Jacob
Now they’ve won the work, and the consultant who had been telling them CMMC wouldn’t apply suddenly has a CMMC offering.

Maybe that’s true.

But when they called us, we asked some simple questions:

  • Are they Level 2 certified themselves?
  • They don’t have to be, but it certainly helps.
  • Do they have any other Level 2 clients?
  • Are you their first customer going through this process?
  • Do they have an SRM?
  • Do they know what an SRM is?
  • Do they know NIST SP 800-171A?
  • Have they been assessed themselves?

You don’t have to know the requirements to ask those questions.

This isn’t 2019 anymore.

We’re well into the rollout now.

[46:13] — Jacob
Charlie Snyder voted for Leadership Buy-In.

That’s where most people landed.

After a month of polling, the overwhelming conclusion is that the biggest challenge is simply getting contractor leadership to give people the green light.

That’s poetic because it’s exactly why this program exists.

[46:41] — Jacob
Next question.

Can a contract include DFARS 252.204-7025 without including 252.204-7021?

[46:53] — Jacob
First, I’m not a contracts attorney.

Talk to Eric Crusius or another attorney who specializes in this area.

That said, we’ve discussed this issue for years.

DFARS 252.204-7025 is a contract provision.

DFARS 252.204-7021 is a contract clause.

The provision belongs in the solicitation to notify offerors that the resulting contract will contain the clause.

The contract itself should contain 7021.

If it doesn’t, the contract isn’t actually telling you which CMMC level applies.

That’s my understanding, but consult a contracts attorney if you’re dealing with that situation.

[49:12] — Jacob
Next question.

After Phase 2 begins, will primes continue accepting valid Level 2 self-assessments, or will they require third-party certification?

[49:28] — Jacob
First, remember:

A Level 2 self-assessment remains valid for three years, just like a certification assessment.

There isn’t a 12-month expiration.

Beyond that…

It depends on the prime.

We’ve seen supplier notices from Leonardo DRS, RTX, Leidos, Boeing, Lockheed, and others that essentially say:

“If you don’t meet our requirements by this date, we’ll reevaluate our relationship.”

Talk to your prime.

Some suppliers may continue receiving work.

Others may quietly stop receiving solicitations because their supplier profile isn’t updated.

Sometimes organizations aren’t explicitly rejected.

They’re simply no longer invited.

[51:22] — Jacob
People ask whether everything changes on November 10.

No.

Nothing magical happens that day.

If your prime gave you a specific deadline, that’s different.

But simply because the calendar reaches November doesn’t automatically invalidate a properly completed Level 2 self-assessment.

Again…

Primes are going to make their own business decisions.

[52:29] — Jacob
Daniel…

Why does it take anywhere from three months to eighteen months to become Level 2 certified?

How can there be such a huge range?

[52:44] — Daniel
Scope.

Everything comes back to scope.

Consider everything that can expand an assessment boundary:

  • Multiple locations.
  • Multiple countries.
  • Multiple SSPs.
  • Enterprise applications.
  • ERP migrations.

An ERP migration alone can easily take one or two years.

That’s why timelines vary so dramatically.

A brand-new enclave supporting only a handful of applications might be completed in six months.

A large enterprise transformation may require twelve to eighteen months.

Define your scope carefully.

It saves both time and money.

[53:55] — Jacob
We talked to a startup this week with around thirty employees.

Single customer.

Single contract.

Series A funding.

Everything brand new.

They thought they could make a decision in two weeks.

Even that surprised me.

We’ve seen organizations call us saying they’re ready to start immediately…

…and then disappear for three months because leadership couldn’t reach a decision.

Leadership buy-in wins again.

[54:57] — Daniel
Even after leadership approves the project, there’s still the Master Services Agreement.

Lawyers negotiate it.

Contract officers negotiate it.

Sometimes that takes:

  • Two to four weeks.
  • Sometimes three months.

Only after the MSA is complete can Statements of Work be executed.

That’s before implementation even begins.

[55:31] — Jacob
When we tell people CMMC takes twelve months, we’re talking about the entire lifecycle.

From the first phone call…

…through planning…

…contract negotiations…

…implementation…

…assessment…

…and certification.

Not just the technical migration.

Even very small organizations typically spend months moving through that entire process.

[56:23] — Jacob
Can I purchase only a gap assessment or documentation support from Summit 7?

[56:30] — Daniel
Absolutely.

We offer:

  • Gap assessments.
  • Policy and procedure development.
  • Documentation support.
  • Combined compliance engagements.

Those services are led by our compliance team of Lead CCAs, CCAs, and CCPs.

[57:07] — Jacob
Next question.

Are the primes themselves CMMC certified, or are they simply enforcing DoD requirements?

[57:18] — Daniel
A while ago, some primes were sending supplier notices before receiving certification themselves.

That’s changed.

Today, most supplier notices I’m seeing come from organizations I know have already achieved Level 2 certification.

Six months ago I would’ve called it a toss-up.

Today I think it’s fair to assume most primes issuing supplier notices are certified.

[58:06] — Jacob
It’s also more complicated than people think.

There isn’t one giant “Lockheed system.”

Many prime systems ultimately become government systems through RMF authorization processes.

So the question isn’t always as simple as asking whether a particular company has one Level 2 certification.

Regardless…

If your customer requires CMMC, arguing about whether they have certification probably won’t change anything.

[59:14] — Jacob
Last question.

What controls prevent MSP administrators from granting themselves access to CUI?

[59:21] — Daniel
Realistically…

None.

You can implement very granular role-based permissions.

You can separate responsibilities.

You can limit administrative access wherever possible.

But it’s extremely difficult to guarantee administrators will never have access.

That’s particularly important because much of the Defense Industrial Base also handles export-controlled information.

If an administrator can view unencrypted ITAR-controlled technical data, that’s already a problem.

Use privileged access management wherever possible.

Reduce exposure.

Work with an MSP that’s competent and demonstrates responsible handling of customer data.

[1:00:33] — Jacob
This is another reason many of us believed the final CMMC rule should have required MSPs supporting Level 2 contractors to obtain Level 2 certification themselves.

The root issue goes all the way back to DFARS 252.204-7012.

The rule talks about:

  • Storing.
  • Processing.
  • Transmitting CUI.

It doesn’t explicitly include accessing CUI.

If “access” had been included from the beginning, this entire discussion would be much simpler.

Instead, organizations now have third parties with administrative access into their environments who aren’t necessarily treated the same way under the regulation.

Maybe that’s something future revisions address.

[1:01:39] — Jacob
That’s an hour.

Thanks for joining us.

If we didn’t answer your question today, we’ll add it to the backlog.

You can:

  • Send us a DM.
  • Leave a voicemail.
  • Visit cuihotline.org and submit the form.
  • Find us at Summit 7.

Watch for registration for Secure the DIB 2026.

Like and subscribe.

We’re adding about a thousand new subscribers every day.

Thanks for your support, and we’ll see you next week.

[1:02:25] — Daniel
See you all.

Contact

Speak With Our Team

    Scroll to Top