Weekly CUI Hotline Q&A: 6.19.26

Summary

Jacob and Daniel discussed recent developments affecting the Defense Industrial Base, including CIRCIA reporting, a new False Claims Act settlement, international CMMC implementation challenges, and audience questions on remote work, MSPs, and assessment boundaries. They emphasized that organizations should focus on selecting qualified partners, understanding contractual obligations, and designing compliant architectures early to avoid costly rework. The episode also reinforced that many CMMC questions ultimately come down to scope, shared responsibility, and practical implementation rather than simply satisfying individual controls.

Key Takeaways

  1. Contracting officers still lack consistent CMMC training. While the CMMC Program Office has developed training, it is not yet mandatory for the acquisition workforce, creating unnecessary confusion during contract execution.
  2. The organization receiving the contract award must hold the required CMMC certification. Even if another affiliated entity performs the work or handles the CUI, the awardee is responsible for satisfying the contractual certification requirement.
  3. Remote employees using GCC High do not automatically bring their home networks into scope. Organizations should secure managed endpoints, enforce encryption, and implement alternate work site policies, but public internet traffic to compliant cloud services is generally treated differently than internal enterprise network traffic.
  4. Shared Responsibility Matrices should map to CMMC assessment objectives—not just NIST SP 800-171 requirements. Vendors and MSPs should clearly identify which assessment objectives they support and how they provide evidence during an assessment.
  5. CMMC certification is still uncommon among MSPs, making due diligence essential. Organizations should evaluate prospective providers based on their CMMC experience, certification status, and ability to produce assessment evidence rather than relying solely on marketing claims.

Transcript

[0:06] — Jacob
All right, everybody. It is Friday. It is Hotline time, like always.

We’re live on YouTube and LinkedIn. You can find us at cuihotline.org. You can call the number and leave a voicemail, fill out the form—especially if you have a longer question—or send us a DM.

Fun development: we now have Hotline Cat. Let us know in the chat if you can guess the cat’s name.

Daniel, I was in Huntsville at Summit 7 headquarters all last week filming a ton of content. Then this week we had four straight days of four-hour CIRCIA town halls.

There has been a lot going on:

  • CIRCIA
  • False Claims Act activity
  • Organizations beginning assessments
  • The normal day-to-day CMMC work

Let’s start with the weekend review.

[1:23] — Jacob
I spoke with an international organization today.

They wanted a gap assessment, so I asked the normal questions:

  • What does your environment look like?
  • What’s in scope?
  • What systems are you using?

They told me they had an on-premises data center.

Great.

Then I asked whether they had cloud services in scope.

They said they were using Microsoft Commercial for email and collaboration.

I asked whether that was part of their CMMC boundary.

It was.

Then I asked whether they were familiar with FedRAMP.

They weren’t.

At that point I explained that if we started a gap assessment immediately, we’d begin marking numerous controls as Not Met simply because they were implementing them on the wrong platform.

It wasn’t just Microsoft Commercial.

They also had cloud security products that weren’t FedRAMP authorized.

So I pulled up:

  • The FedRAMP Marketplace.
  • The CMMC Assessment Process.
  • The CMMC FAQs covering international organizations.

The reality is they now have to redesign much of their cloud infrastructure before they’re even ready for a meaningful gap assessment.

They initially assumed the sequence would be:

  1. Gap assessment.
  2. Certification.

Instead, they first need to redesign significant portions of their environment.

International companies often aren’t exposed to CMMC as frequently as U.S. contractors, so many simply aren’t aware of these requirements.

If you’re an international organization, spend time reviewing the CMMC Assessment Process and Level 2 Scoping Guide before paying for implementation services.

You may discover architectural issues that should be addressed first.

[4:44] — Daniel
I haven’t looked closely at the latest FedRAMP 20X documentation recently.

I don’t believe they’ve significantly changed the international guidance, but I’d need to double-check.

[5:03] — Jacob
FedRAMP Moderate is now classified as Class C, which creates another layer of explanation for organizations trying to understand the current guidance.

[5:21] — Jacob
We also spent four days attending the CIRCIA town halls.

We’ll dedicate an entire episode to everything we heard.

At the moment, I don’t see a realistic path for Defense Industrial Base contractors to avoid having both:

  • A reporting obligation to CISA under CIRCIA.
  • A reporting obligation to DoD under DFARS.

Unless something changes, I think both requirements will exist simultaneously.

[5:53] — Jacob
During the town hall I submitted comments strictly as a private citizen.

One major issue is reciprocity.

The proposed CIRCIA rule allows existing reporting obligations to satisfy CIRCIA only if they’re substantially similar.

The problem is DFARS 252.204-7012 incident reporting contains only a fraction of the information CIRCIA proposes requiring.

That creates a dilemma.

Either:

  • CISA accepts much less information than Congress instructed it to collect, or
  • DoD substantially revises DFARS 252.204-7012.

I don’t see either happening soon.

As a result, I think organizations should prepare for separate reporting obligations.

[7:34] — Daniel
Small businesses received exemptions in many areas.

Defense contractors handling CUI did not.

Because they handle CUI, they’re still included regardless of organizational size.

[8:03] — Jacob
Another major development this week:

After roughly six months without any DOJ announcements, we saw another False Claims Act settlement involving a Huntsville defense contractor.

The company had entered a perfect 110 SPRS score in 2021.

When DIBCAC conducted an assessment in 2024, the actual score was negative 170.

The Department of Justice ultimately recovered approximately $500,000 under the False Claims Act.

The underlying contracts totaled roughly $680,000, meaning approximately 75% of the contract value was returned to the government.

What’s notable is that this wasn’t a whistleblower case.

There was no relator.

The matter was referred directly by DIBCAC following the assessment.

For years we’ve heard DoD say DIBCAC frequently discovered enormous differences between reported SPRS scores and actual implementation.

This appears to be one of those cases.

I expect many future False Claims Act cases to begin the same way.

[10:26] — Daniel
A few years ago DIBCAC publicly stated it was actively coordinating with the Department of Justice.

This is exactly what they were referring to.

These cases simply take years to work through the system.

Half a million dollars is a significant penalty, especially for a relatively small contractor.

[11:17] — Jacob
Let’s move into the questions.

How much does CMMC Level 1 self-assestation prepare an organization for Level 2?

[11:31] — Daniel
It’s difficult to quantify.

Level 1 establishes good foundations, particularly around:

  • Identity.
  • Access control.
  • Basic physical protections.

Those concepts support many Level 2 requirements.

However, you’re comparing:

  • 15 Level 1 practices.
  • 110 Level 2 requirements.

That’s a significant jump.

If someone implements Level 1 today using cloud platforms already capable of supporting CUI, they may only need another two or three months to reach Level 2.

If they have to migrate platforms, purchase new hardware, implement FIPS-validated cryptography, or redesign infrastructure, the timeline grows considerably.

Level 1 itself can often be implemented within a few weeks.

Level 2 generally requires several months.

[13:03] — Jacob
Starting with Level 1 isn’t wrong.

The bigger mistake is implementing Level 1 on commercial cloud services, then later migrating everything to GCC High or another FedRAMP-authorized environment.

That migration is entirely avoidable with proper planning.

People often focus only on the controls.

They overlook everything else required by DFARS and the surrounding compliance ecosystem.

[14:03] — Jacob
True or false:

If I already have a valid Level 2 certification, do I still need a separate Level 1 affirmation in SPRS?

[14:23] — Daniel
Yes.

SPRS maintains separate entries because organizations may have:

  • An FCI-only Level 1 boundary.
  • A separate Level 2 CUI enclave.

Those are different assessment boundaries.

Many organizations will legitimately have both.

The challenge is making sure contracting officers actually check the correct tab within SPRS.

[15:46] — Jacob
Everyone focused on the recent GAO report discussing assessor capacity.

The more interesting observation was that the CMMC Program Office has already created extensive training for the contracting workforce so contracting officers understand how the program works.

[16:11] — Jacob
The GAO report pointed out that the CMMC Program Office created training for the contracting workforce.

The problem is that the Office of the Under Secretary of Defense for Acquisition and Sustainment—which oversees contracting officers—hasn’t made that training mandatory.

There’s no plan for when it will become mandatory.

That’s the real issue.

People aren’t talking about why contracting officers aren’t required to take the training that already exists.

The CMMC Program Office can’t force another organization to complete training.

Only the leadership over the contracting workforce can do that.

Instead of criticizing CMMC because there are supposedly not enough assessors—even though DoD says there are enough assessors and waivers exist—we should be asking why contracting officers aren’t receiving the training developed for them.

Organizations are spending time explaining basic CMMC concepts to contracting officers that would take only a few minutes to learn through the official training.

I’d much rather see that addressed in the next inspector general report.

[17:28] — Jacob
Next question.

Does an MSP need its own CMMC Level 2 certification to support a Level 2 customer?

[17:34] — Daniel
No.

I actually posted about this earlier today.

An MSP’s Level 2 certification isn’t required.

However, certification demonstrates they understand how to implement and support compliant environments.

I highly recommend checking mspcollective.org if you’re looking for MSPs that have already achieved Level 2 certification.

Here’s the real issue:

Your MSP becomes an extension of your infrastructure.

If your organization has implemented everything correctly, but your MSP cannot produce evidence or explain how they’re meeting the controls assigned to them under the Shared Responsibility Matrix, you fail—not the MSP.

Ultimately, it comes down to trust.

Has the MSP done this before?

Do they have compliant infrastructure?

Or are they relying on workarounds and policy language instead of proper implementation?

Certification doesn’t guarantee success, but it provides confidence that they know what they’re doing.

Without that experience, it’s difficult to know whether they’ll actually get you through an assessment successfully.

[19:15] — Jacob
I kind of want to take golf lessons from somebody who’s actually won a tournament.

Same idea.

[19:32] — Jacob
We received another question about international companies.

Will on-premises environments become the only practical option outside the United States?

[19:51] — Daniel
For many international organizations, on-premises infrastructure may become almost mandatory unless Microsoft expands eligibility for its Government Cloud.

There are many companies outside the United States performing defense work that simply can’t qualify because they lack a U.S. address.

I’d love to see Microsoft open that eligibility.

Otherwise, international contractors will need to rely heavily on on-premises infrastructure or find cloud providers with FedRAMP-authorized offerings that don’t impose the same eligibility requirements.

This isn’t necessarily a DoD limitation.

It’s primarily a Microsoft eligibility issue.

[21:01] — Jacob
Neil asks:

Two companies are independently certified.

Company A acquires Company B and migrates Company B onto Company A’s identical technology stack.

Does that constitute a significant change requiring reassessment?

[21:57] — Daniel
My first instinct is that this represents an operational change, not necessarily a significant change.

If the acquired company simply adopts:

  • The same technology stack.
  • The same policies.
  • The same procedures.
  • The same security controls.

Then it’s similar to hiring additional employees.

The assessment boundary has grown, but the implementation hasn’t fundamentally changed.

Now, if cage codes change or additional organizations must be added to the certified boundary inside EMASS, those administrative changes certainly matter.

The question becomes whether you’re still operating under the same SSP and assessment boundary.

Ultimately, these situations become judgment calls by the affirming official because the significant change language isn’t extensively codified beyond current FAQs.

[24:35] — Jacob
That’s one of the challenges.

The FAQ guidance isn’t part of regulation itself.

A lot of people don’t even know those FAQs exist.

[25:11] — Jacob
Next question.

If you use a SaaS-based Remote Monitoring and Management (RMM) platform to manage CUI endpoints—for script deployment, remote viewing, and policy enforcement—does the platform itself need to be FedRAMP authorized?

[25:24] — Daniel
It depends on what the platform actually does.

Script deployment alone generally doesn’t involve storing, processing, or transmitting CUI unless you’re transferring CUI through the platform itself.

Remote viewing is more complicated.

If the platform displays CUI that’s visible on a user’s screen, there’s a reasonable argument that it becomes a Security Protection Asset within the assessment boundary.

Some organizations avoid that by implementing strict policies requiring users to:

  • Close CUI before remote sessions begin.
  • Explicitly approve remote connections.
  • Disable screenshots.
  • Disable file transfer.
  • Limit remote capabilities.

Those restrictions can reduce the platform’s exposure to CUI and may allow it to remain outside FedRAMP requirements.

The tradeoff is operational efficiency.

If technicians have to remember six special steps for one customer out of a hundred, eventually someone forgets.

That’s why working with an MSP that specializes in CMMC matters.

These become standard operating procedures rather than exceptions.

[27:55] — Jacob
Next question.

We’re moving toward CMMC, but it feels like only a tiny portion of the Defense Industrial Base is actually doing anything.

Should we really be worried?

[28:13] — Jacob
I always compare this to poker.

You don’t know what cards your competitors are holding.

People point out that only a small percentage of the estimated 80,000 organizations needing Level 2 certification have achieved it.

But you don’t compete against 80,000 companies.

You compete against a handful.

If only a few competitors pursuing the same contract have certification, that’s enough for you to lose the work.

You’re essentially gambling because you don’t know your competitors’ status.

I’ve spoken with companies that already know two of their competitors are certified.

If they don’t pursue certification, they expect one of those competitors to win the contract.

It doesn’t take many certified competitors before certification becomes a competitive advantage.

From the government’s perspective, contract requirements don’t become optional simply because other companies haven’t complied yet.

Businesses make risk decisions every day.

Just understand that’s exactly what you’re doing when you decide to wait.

[31:40] — Jacob
Next question.

Two affiliated organizations have separate CAGE codes. One signs contracts for the other but doesn’t handle CUI.

Do both organizations need CMMC certification, or only the entity handling CUI?

[31:55] — Daniel
The organization receiving the contract award must be able to demonstrate compliance with the contractual CMMC requirement.

When the contracting officer checks EMASS or SPRS, they’re validating whether the awardee has the required certification.

If the organization accepting the contract cannot demonstrate compliance, it won’t receive the award.

Even if it’s simply acting as a pass-through and subcontracting all of the work downstream, it still must satisfy the certification requirement because it’s the entity accepting the contractual obligation.

That’s simply how the program works.

[33:29] — Jacob
Next question.

We have a large remote workforce using company-managed laptops that connect directly to Microsoft 365 GCC High.

A consultant told us that even if the laptops are fully compliant, employees’ home networks would still be in scope unless we use Azure Virtual Desktop or another VDI solution.

Is that true?

[34:15] — Daniel
This has been debated for years.

NIST SP 800-171 already includes requirements addressing alternate work sites.

Organizations should absolutely establish policies covering things like:

  • Physical access.
  • Preventing shoulder surfing.
  • Protecting conversations.
  • Locking office doors.

Those are all reasonable expectations.

The bigger question is the home network itself.

Here’s where it becomes important.

Traffic between the endpoint and GCC High is encrypted using FIPS-validated cryptography over HTTPS.

The DoD has also clarified that encrypted CUI is still CUI.

However, they also recognize that organizations cannot bring the entire public internet into scope.

There are really two different types of network traffic:

  • Public internet traffic that organizations don’t control.
  • Internal network traffic they do control.

When someone connects securely from home, a hotel, or another remote location directly into GCC High, that encrypted internet traffic has generally been treated as acceptable because neither the endpoint nor the public internet infrastructure is under the organization’s control.

If someone argues that all home networking equipment must be included in scope, that logic quickly falls apart.

You’d have to:

  • Put company-owned firewalls in every employee’s home.
  • Potentially require separate internet providers.
  • Bring every network hop into the assessment boundary.

That’s simply not how organizations operate today.

What is important is ensuring the managed endpoint:

  • Uses software firewalls.
  • Enforces encryption.
  • Maintains appropriate endpoint protections.

Internal traffic that the organization controls is a different discussion.

But standard encrypted internet traffic connecting to compliant cloud services has not generally been challenged during assessments we’ve seen.

[39:33] — Jacob
Next question.

Can someone without a cybersecurity background successfully lead a CMMC Level 2 program?

[39:46] — Daniel
I’ll answer it two different ways.

Can someone without a cybersecurity background lead an established CMMC program?

Yes.

Can they build one from scratch?

No.

Standing up GCC High, Azure Government, Intune policies, identity infrastructure, and everything else required takes technical expertise.

Once those systems are already established, someone with a quality management or ISO background can absolutely manage the program.

They can:

  • Collect evidence.
  • Follow established procedures.
  • Verify recurring activities.
  • Coordinate annual affirmations.

But building the environment from nothing requires technical knowledge.

[41:09] — Jacob
Defense Cyber Crime Center recently released another set of threat intelligence alerts.

If you’re not participating in the DIB CS Program, you should be.

The reports contain valuable information.

At the same time, they demonstrate how difficult cybersecurity really is.

Many organizations wouldn’t even know how to interpret the indicators of compromise or threat information without experienced cybersecurity staff.

That’s another reason building a CMMC program from scratch requires technical expertise.

[42:00] — Jacob
Next question.

We’re a foreign-owned company with a U.S. sales office.

Customers are asking about CMMC.

What’s the first step toward compliance, and does foreign ownership make the process more difficult?

[42:13] — Daniel
It does introduce some additional complexity.

Eligibility for Microsoft Government Cloud depends on having both:

  • A CAGE Code.
  • A U.S. address.

Assuming the organization isn’t performing classified work or dealing with FOCI requirements, the recommendation is usually to establish a separate enclave for U.S. operations.

That allows the organization to:

  • Isolate export-controlled information.
  • Keep the CMMC assessment boundary small.
  • Avoid bringing the foreign parent company’s infrastructure into scope.

Rather than attempting to make an entire multinational enterprise compliant, it’s generally much easier to build a dedicated compliant enclave supporting only the U.S. defense work.

[44:17] — Jacob
Next question.

Could devices like Alexa, Google Home, or similar voice assistants create problems by listening to conversations involving CUI or ITAR information?

[44:34] — Daniel
My instinct is yes.

They’re effectively collaborative communication devices.

You should have written policies prohibiting those devices from being present around CUI workspaces, particularly home offices.

The same conversation eventually extends to:

  • Smartphones.
  • Smart TVs.
  • Smart speakers.
  • Wearable devices.

Many of those systems are always listening to some degree.

Organizations should address that risk through alternate work site policies.

For example, some organizations already prohibit Alexa- or Google-style devices in home offices used for CUI work.

[46:22] — Jacob
Or maybe somebody should just build a FedRAMP version of a smart speaker.

[46:35] — Daniel
It’s actually a fascinating question because smart devices are everywhere now.

The challenge is that organizations don’t own most of those devices, so policy becomes the primary way to manage the risk.

[47:23] — Jacob
Absolutely.

There’s a 2006 Toyota Tundra down the road that I want to buy because it doesn’t have any of this technology in it.

Every time I walk the dog past it, I think I should just buy that truck.

Maybe the new Slate trucks will have a version without AI or connected features.

[47:49] — Jacob
Next question.

What should organizations consider when selecting DMARC monitoring tools for email security?

Do DMARC tools need to be FedRAMP authorized?

[47:54] — Daniel
DMARC validates ownership of your email domain.

You’re not transmitting CUI through the DMARC validation itself.

You’re simply proving that your domain is authorized to send email.

Likewise, DNS records are public information—they aren’t CUI.

For that reason, I wouldn’t consider a standalone DMARC service to require FedRAMP authorization.

Now, some email security platforms include many additional capabilities.

If you’re using something like Proofpoint, those other capabilities may introduce additional considerations.

DMARC by itself, though, generally wouldn’t require FedRAMP.

[49:16] — Jacob
Next question.

If an MSP only processes or stores Security Protection Data—not CUI—what controls apply to the MSP?

[49:28] — Daniel
Interesting question.

Security Protection Data environments are usually much smaller than environments processing CUI.

Think about systems like:

  • Microsoft Intune.
  • Device management platforms.
  • Zero-touch provisioning.
  • Certain Remote Monitoring and Management tools that have been configured appropriately.

Those systems may contain Security Protection Data without actually storing or processing CUI.

In those situations, you’re primarily evaluating the controls associated with protecting those management systems rather than the full set of controls associated with CUI processing.

Exactly which controls apply depends heavily on how the MSP and customer divide responsibilities, so it’s difficult to provide one universal answer.

[51:38] — Jacob
Here’s a great question about Shared Responsibility Matrices.

Someone asked:

“How many of the 320 CMMC Level 2 assessment objectives does your product address?”

That’s exactly the kind of question customers should be asking every vendor that claims to support CMMC.

Not just:

“Which requirements do you cover?”

But:

“Which assessment objectives do you help satisfy?”

The assessment objectives come from NIST SP 800-171A and ultimately become the verification procedures used during assessments.

You should expect a Shared Responsibility Matrix mapped all the way down to that level.

[52:37] — Jacob
For example, here’s Summit 7’s Shared Responsibility Matrix.

It identifies:

  • Fully customer-owned responsibilities.
  • Shared responsibilities.
  • Responsibilities owned by Summit 7.

Every one of the 320 assessment objectives is addressed at least at a shared-responsibility level.

Today we have more than 100 certified clients with a 100% pass rate.

More importantly, we haven’t had any clients receive conditional certifications requiring open items after assessment.

Any vendor claiming to satisfy CMMC requirements should be eager to show customers exactly how they support those assessment objectives.

If they can’t produce that information—or if it’s only mapped to high-level requirements instead of assessment objectives—that should raise concerns.

[55:25] — Daniel
Even though MSPs don’t have to be certified themselves, they still have to produce evidence supporting the controls they’re responsible for.

If an MSP offers extensive CMMC support and still hasn’t achieved Level 2 certification themselves—even this far into Phase 1—that may not automatically be a red flag, but it’s certainly something customers should ask about.

[55:51] — Jacob
A quick reminder:

Secure the DIB: CUI Hotline Edition is coming up soon.

Registration is free.

We’ll be taking many of the topics discussed on the Hotline and exploring them in much greater depth.

[56:38] — Jacob
Next question.

How common is it for MSPs supporting defense contractors to already have CMMC Level 2 certification?

[56:46] — Daniel
Not very common.

Roughly 50 MSPs currently hold Level 2 certification.

Compared to the total number of certified organizations, that’s a very small percentage.

Those MSPs may collectively support hundreds of defense contractors, but relative to the overall MSP market they’re still a tiny fraction.

Outside major defense regions like the Washington, D.C. area, it’s becoming increasingly common for organizations to work with fully remote CMMC-focused MSPs because there simply aren’t many certified providers in local markets.

[58:14] — Jacob
Final question.

Are System Security Plans (SSPs) and Plans of Action and Milestones (POA&Ms) considered Controlled Unclassified Information?

[58:21] — Daniel
Not for CMMC by themselves.

An SSP describing your own CMMC assessment boundary isn’t automatically CUI because there’s no law, regulation, or government-wide policy designating it as such.

However, if that documentation contains information associated with government systems—for example, documentation supporting an Authorization to Operate (ATO)—it may become CUI under those circumstances.

Even when SSPs aren’t CUI, they’re still highly sensitive documents and should be protected appropriately.

[59:17] — Jacob
That’s an hour.

Thanks for joining us.

We’ll be back next week at the same time.

Be sure to register for Secure the DIB: CUI Hotline Edition.

If you’re watching the recording afterward, leave your questions or comments and we’ll add them to the backlog.

You can also:

  • Visit cuihotline.org.
  • Submit the online form.
  • Leave us a voicemail.
  • Check out the podcast, where we’ll continue discussing CIRCIA, False Claims Act developments, and assessment capacity across the ecosystem.

There’s always something happening.

[1:00:14] — Daniel
Not a slow summer around here.

[1:00:16] — Jacob
Definitely not.

Thanks for joining us.

Like and subscribe.

We’ll see you next week.

Contact

Speak With Our Team

Scroll to Top