Weekly CUI Hotline Q&A: 6.26.26

By the end of this year there will be at least two final rules with direct impacts on defense contractor […]

Summary

This episode focused on major FAR CUI and CMMC policy developments, including the FAR CUI rule’s transition to NIST SP 800-171 Rev. 3, uncertainty around future CMMC rulemaking, and the DoD’s post-quantum cryptography strategy. Jacob and Daniel also answered a wide range of practical implementation questions covering CUI identification, MSP scoping, ITAR, BYOD, shared responsibility matrices, reassessments, and consultant access. Throughout the discussion, they emphasized understanding the underlying regulations—not just CMMC itself—to make sound compliance and architectural decisions.

Key Takeaways

  • The finalized FAR CUI rule introduces NIST SP 800-171 Rev. 3, potentially creating dual compliance baselines for organizations that also support DoD contracts until CMMC is updated.
  • CUI must be supported by a law, regulation, or government-wide policy; documents like SSPs and POA&Ms are sensitive but are not legally designated as CUI.
  • ITAR and export control requirements—not CMMC itself—are often what drive organizations toward GCC High and impose data sovereignty restrictions.
  • Changes that make previously “Not Applicable” CMMC controls applicable after certification (such as adding software development or new technologies) can trigger a reassessment.
  • Organizations should carefully scope MSPs, consultants, BYOD devices, and cloud services based on actual responsibilities and data flows, rather than assuming blanket inclusion or exclusion.

By the end of this year there will be at least two final rules with direct impacts on defense contractor cybersecurity requirements: 1) CIRCIA – potentially creating a second incident reporting obligation beyond DFARS clause 252.204-7012. 2) The FAR CUI rule – potentially pressuring DoD to move to SP 800-171 revision 3 requirements faster than anticipated. Got questions? Stop by the Hotline live every Friday at 10am PST.


Transcript

[00:14] — Jacob
All right, everybody. It’s Friday. It’s CUI Hotline day. It’s your favorite day of the week. It’s your favorite show of the week. It’s the day where we answer everybody’s questions about literally anything and everything related to cyber policy that has even the mildest connection to the defense industrial base.

We are streaming on YouTube. We are streaming on LinkedIn. You can find us at cuihotline.org. You can call the number and leave a message. We have many messages to go through today, so thanks for calling the number, everybody. You can fill out the form if you’ve got a longer question. We got one of those on the form. You can send us DMs. You can ask questions in chat. You can find us at Summit 7 and send us an email. You can call us over there, too.

There’s a ton of ways to get a hold of us. There’s a ton of questions to get through.

Daniel, it’s supposed to be summertime. It’s supposed to be the summer doldrums. We’re supposed to be doing countdown lists. We’re supposed to be doing top 10 content reuse videos, scraping the bottom of the barrel. Instead, I’ve got people who want to come on the podcast, and I’m telling them we’re not going to be able to fit them in for two months because there are just too many policy updates happening.

I thought we were going to have to do some BuzzFeed content. “What CMMC asset type am I?” I feel like a Security Protection Asset personally. That’s what I identify as. But this is crazy—what’s happened in just one week’s time.

[01:45] — Daniel
It is. It’s crazy, but it’s nice to see. It’s a good problem to have.

John, fun fact: we will not be on the Hotline next Friday either. It’ll be a special edition on Thursday. If you’re around Thursday, you’ll be able to check it out. We’re off work on the 3rd because it’s Fourth of July weekend. The World Cup is going on, too.

[02:11] — Jacob
The European mind cannot comprehend the Fourth of July weekend.

The World Cup game is right down the road at SoFi Stadium for me, so it’s going to be awesome to see. The U.S. won their group, so we’re moving on to the round of 32. Get your jersey, get your face paint, get ready, and we’ll get into the weekend review.

Daniel, here we are yet again.

[02:42] — Daniel
It’s funny to say this because this was already in a proposed state back in February or March of last year. We were expecting it to launch into final status until the President wanted a FAR overhaul.

They just released the updated package, and buried inside many, many pages was the FAR CUI clause. We looked at it and said, “It’s back in action.”

This thing isn’t going away. Democrats can’t kill it. Republicans can’t kill it. Everybody loves cybersecurity. Let’s just extend it to all federal contractors—at least the ones dealing with CUI.

A couple of interesting updates from the proposed rule:

  • It’s now based on NIST SP 800-171 Rev. 3, which makes sense.
  • FAR CUI moved to a 72-hour incident reporting requirement instead of eight hours. Thank goodness we have alignment on that.
  • They no longer state FedRAMP Moderate Equivalency specifically. Instead, they reference the FedRAMP Moderate baseline template.
  • FedRAMP Moderate still includes an independent assessment component, but FAR CUI does not require third-party certification the way FedRAMP Moderate Equivalency does. That decision is still left to the agency.
  • They added language stating that endpoints accessing VDI are out of scope if configured appropriately, matching DoD guidance.
  • They’re looking to adopt the DoD ODPs under FAR CUI while staying under 171.
  • NIST SP 800-172 is also called out at the discretion of the contract if the data is sensitive enough.

Overall, there’s a lot of alignment with CMMC.

The downside is that CMMC is still hardcoded to Rev. 2. Jacob, I want to pick your brain on that.

Can the DoD issue a class deviation and bypass the Rev. 2 requirement? Do they have to go through rulemaking? Am I going to have two enclaves now? A FAR CUI enclave?

[05:56] — Jacob
The great irony here is that the DAR 7012 class deviation was intended to avoid the exact problem of DAR 7012 pointing to 171 Rev. 3 while CMMC pointed to Rev. 2.

Since then, the DoD hasn’t done anything to move CMMC to Rev. 3, which is fine if they want to stay on Rev. 2.

Except the FAR CUI rule points to Rev. 3.

That means if you’re a defense contractor with other federal contracts—and there are many companies in that situation—you’ll have the 171 Rev. 2 baseline for DoD and the 171 Rev. 3 baseline for everybody else.

The exact situation the original class deviation was intended to prevent is now the situation it will create because the DoD hasn’t updated CMMC in 18 months.

What is taking so long?

We know the rule has been ready. The new CIO has been there for more than six months. We don’t know what’s happening.

Now, because they’ve taken so long, they’re going to reintroduce the very problem they successfully avoided two years ago.

People are going to end up holding the bag with two baselines, two enclaves, and multiple assessments.

God forbid another agency adopts a CMMC assessment against the Rev. 3 baseline while DoD requires Rev. 2. Then you could have two enclaves, two baselines, two contracts, and two different assessments from the same C3PAO.

It’s completely avoidable.

I don’t see any way they can get the 3.0 rulemaking done before the FAR CUI rule because the FAR CUI rule is riding the wave of the FAR overhaul.

We successfully predicted that, by the way. Like and subscribe.

It’s a mess, and I don’t know how they get out of it without moving immediately.

Enough with whatever has been happening for the last six months. Get the rulemaking moving, or the contractors you supposedly care about are going to get screwed.

[09:07] — Daniel
Washington, D.C. is a mess, Jacob.

Speaking of CMMC updates, we haven’t heard much about rulemaking, except we recently got the DoD CIO’s post-quantum cryptography strategy.

It’s a nice-looking strategy. There are vision statements, lines of effort, 36 objectives, and complicated graphics.

Buried on page 20 is a statement saying CMMC will be updated to require post-quantum cryptography standards as part of the department-wide strategy by December 31, 2031.

[10:09] — Jacob
That raises a lot of questions.

What does “update CMMC” actually mean?

Does it mean updating the CMMC program? That’s a 32 CFR rule and requires rulemaking, like CMMC 3.0.

Were you waiting for CMMC 3.0 to integrate post-quantum cryptography requirements? The problem is the rest of the strategy isn’t finished. What are you going to update it to?

Are you going to delay 3.0 until the post-quantum strategy is complete? That could take years.

Meanwhile, the FAR CUI rule goes into effect, bringing us back to the issue of two different baselines and potentially two different assessments.

Or do you mean NIST will update the baseline that CMMC assesses? That would require another revision to 800-171. Are we going straight from Rev. 2 to Rev. 4? What’s NIST’s timeline?

Or do you simply mean updating the organizationally defined parameter for the encryption requirements in Rev. 3? That wouldn’t require rulemaking. You could just update the ODP.

Maybe that’s what you meant. I don’t know.

What does “update CMMC” mean?

Who knows?

I certainly hope we weren’t waiting the last six months just to sign this document.

It specifically says they’re going to update it, but it gives no details about what that means or how it’s going to happen.

Like and subscribe, everybody, because it’s not very apparent.

[12:39] — Daniel
My favorite line in that document is, “Costs will be incurred.”

Every new CIO comes in talking about cutting costs, then eventually releases a strategy saying, “We actually have a serious problem, and it’s going to cost money.”

At least they’re being honest about it.

Here’s a question.

FAR CUI is leveraging the DoD ODPs. If they want to change those ODPs, do they need FAR Council approval? Is the FAR Council going to have its own FAR CUI FAQ?

[13:38] — Jacob
Good question.

Are we going to have dueling FAQs?

Are there asset types under FAR CUI? I think it’s just CUI assets.

Are they going to adopt CMMC scoping? That’s a DoD program.

How does any of that work?

Like and subscribe for more rulemaking facts.

These things are clearly moving forward, but it’s another example of the left hand not knowing what the right hand is doing.

I remember when CMMC went final and people said, “What are you guys going to talk about now? This is the end of CMMC history.”

I have more policy questions now than ever before.

[14:23] — Daniel
Someone said if you’re not doing post-quantum cryptography with a rating of seven on the Shannon scale and rotating certificates every 24 hours, you’re already behind.

Everyone’s behind.

The DoD CIO wasn’t that long ago saying compliance isn’t security.

Now we’re saying people need to comply with these requirements in order to achieve security.

Crazy.

[14:59] — Jacob
Enough with the sarcasm.

Let’s get to some of these phone calls.

Caller:
I’ve got a client who has a machine product that they customize for the government.

Even though the product is commercially available, the customization is specific to the government entity they’re working with.

Everything tells me this should involve CUI and likely CTI, but their program manager keeps saying there’s no CUI involved.

Clearly this isn’t a COTS product anymore.

How would you recommend advising this client, who doesn’t really want to prepare for a CMMC Level 2 assessment or self-assessment?

Thanks.

[15:52] — Daniel
My initial thought—and I’m not sure what occupation the caller has—is that you need to talk to a lawyer.

You’re modifying a COTS product to a specific government standard, probably involving controlled technical information.

Meanwhile, your current program manager is saying, “Don’t worry about it.”

How many times have we heard customers tell people, “Don’t worry about it,” only for them to wake up one day to an email saying,

[16:32] — Daniel
…and then one day they wake up to an email saying, “Go get Level 2 certified right now, or we’re never talking to you again.”

Talk to an attorney. Get it in writing if they believe it is not CUI and that CMMC Level 2 certification will never be required. Get that commitment in writing because they can very easily change their position and say, “You’re modifying this according to controlled specifications. We’ve changed our understanding, and now these are the rules.”

Now, one caveat. A lot of organizations assume that because the DoD is providing something that appears customized, it must be controlled technical information. It might actually be something like a military specification or other public information.

Even though the inputs are coming from the DoD, that doesn’t necessarily make them CTI. That’s the fine line Jacob was talking about. They could simply be asking you to customize the product to publicly available specifications.

Back to Jacob’s point, though, we’re entering the pay-to-play phase of CMMC. Many primes and Tier 1 suppliers are telling their supply chains, “Either you become CMMC certified or you can’t work with us anymore.”

So, regardless of whether the data is actually CUI today—and again, talk to an attorney, someone like Defert Ryan Bonner, a friend of the show, to understand the legal side—you also need to ask your prime contractors what their deadline is for requiring CMMC compliance.

They’re probably going to require it because they don’t necessarily know what information is flowing down to subcontractors. Their contracting officers don’t know exactly what Engineer Joe is sending you. They’re going to protect themselves, and you need to be on the right side of that if you want to continue working with them.

So there are really two questions:

  • Do you actually have CUI?
  • Even if you don’t today, will your prime require you to become CMMC certified anyway?

[18:52] — Jacob
On a related note, here’s another question.

“On existing DoD contracts, is the DoD allowed to add DFARS 252.204-7021 with a CMMC Level 2 requirement on the fly, or do they need to wait until the contract is renegotiated?”

I’m not an attorney, so talk to a lawyer for specifics.

But if you’ve negotiated the terms of a contract, they generally can’t just wake up one day and change those terms because they feel like it. They can include new requirements during an option year or another negotiated modification, but they shouldn’t simply impose them mid-contract.

That said, are people seeing this happen?

Yes.

Can they?

Probably not.

Are they?

Quite often.

Defend yourself accordingly.

[20:00] — Daniel
What we’ve mostly seen is this happening through IDIQs.

For example, NAVFAC has indicated that certain construction IDIQs may require CMMC certification.

I haven’t really heard much about existing contracts being modified mid-performance. Most of what we’ve seen involves renewals, option years, or renegotiated contracts.

So right now it’s probably more common for the requirement to appear there, though agencies may find other creative ways to introduce it before the contract ends.

[20:39] — Jacob
There’s also another dimension here.

Even if the DoD isn’t changing the contract directly, primes can change requirements flowing down to subcontractors.

A lot of companies actually have the standing to push back and tell their prime, “You can’t require this.”

The problem is they don’t want to rock the boat.

Even when they’re justified, they accept requirements they probably shouldn’t because they don’t want to be viewed as difficult.

That’s not a feature of CMMC. That’s simply the dynamic that often exists between primes and subcontractors.

All right.

Nick, your question got cut off. If you want to finish it in chat, we’ll take another look.

Here’s another question:

“With the September 2026 FIPS 140-2 sunset approaching, Windows 11 and BitLocker still rely on FIPS 140-2 certificates. Microsoft has FIPS 140-3 modules in the NIST queue, but final approval might not happen before the deadline.”

Daniel, what are you seeing regarding the transition from 140-2 to 140-3?

[22:06] — Daniel
We’ve definitely seen this come up.

Assessors have been accepting FIPS 140-3 because many appliances no longer even provide firmware supporting 140-2. It’s already being sunset.

What’s interesting is that the first time the DoD mentioned FIPS 140-3 was in the significant change clarification added to the DoD FAQs.

They specifically said that upgrading a firewall from FIPS 140-2 to 140-3 is considered a routine change to maintain security posture. It is not considered a significant change requiring reassessment.

So the DoD clearly recognizes that 140-2 is being retired and that moving to 140-3 is simply part of normal operations.

Even though Rev. 2 technically references 140-2, assessors and the DoD have been accepting 140-3 in practice.

It’s one of those situations where understanding how assessments are actually being performed is important.

[23:32] — Jacob
It’s interesting because FIPS 140-2 and 140-3 are cryptographic module validation standards.

The post-quantum cryptography standards from NIST are algorithm standards, not validation standards.

That makes me wonder what the DoD actually means when it says it’s going to update CMMC for post-quantum cryptography.

Are they saying they’ll require post-quantum algorithms in addition to validated modules?

Or only the algorithms?

The validation process itself doesn’t really depend on which algorithm is being used.

I don’t know.

It also reminds me that when the Defense Industrial Base Cybersecurity Assessment Center used to publish its top “Other Than Satisfied” findings every year, the number one finding was FIPS validation.

The thing people struggle with most is cryptography.

And now we’re talking about updating CMMC with entirely new cryptographic requirements.

Wonderful.

Excellent.

[laughter]

[25:20] — Daniel
John asks:

“What is the criteria for requiring a Shared Responsibility Matrix? We use an MSP and have an SRM, but we’ve been told we also need one from vendors such as Sophos for endpoint protection.”

I generally haven’t seen vendor-specific SRMs.

Using Sophos as an example, the assessor wants evidence that all applicable Security Protection Asset controls are implemented, but that’s typically documented within your MSP’s SRM because the MSP is responsible for how that tool is configured and managed.

One thing they may ask for is proof of FedRAMP authorization, especially if the product can process, store, or transmit CUI.

Products like spam filters, EDR platforms, and Sophos certainly have that capability.

So the MSP should document how the product is configured as a Security Protection Asset.

You shouldn’t need an SRM directly from Sophos because Sophos doesn’t know how the product is deployed in your environment.

Instead, make sure your MSP accounts for it within its own documentation.

If FedRAMP Moderate authorization needs to be demonstrated, use the FedRAMP Marketplace or provide the appropriate evidence.

Going to every individual vendor for an SRM generally doesn’t make sense.

Some organizations previously needed Microsoft’s Shared Responsibility Matrix because GCC High remained in-process for FedRAMP authorization for such a long time.

Now that GCC High is FedRAMP High Authorized, we haven’t seen assessors requiring Microsoft’s SRM because they can verify that directly through the marketplace.

[28:04] — Jacob
Mr. Burstrom asks:

“Have you seen organizations successfully run Mobile Application Management on BYOD phones and have it hold up during an assessment? If not, what’s the typical assessor pushback?”

I’ll check with our assessment engineering team, although they’re currently in assessments and may not respond before the stream ends.

Daniel, what have you seen?

[28:27] — Daniel
Yes.

We’ve seen BYOD devices pass assessments using Mobile Application Management, but there still has to be a light layer of Mobile Device Management.

The application has to be containerized, and the device itself still has to meet compliance requirements, such as encryption being enabled.

So it’s really a combination of light MDM plus MAM.

Your corporate protections—preventing copy-and-paste from Outlook into Apple Notes, for example—are handled through MAM.

That approach has passed CMMC assessments.

For CMMC Level 3, however, you introduce another issue because devices must be organizationally owned.

If you’re planning for Level 3, it may make sense to issue corporate devices now.

Some states, like California, may even require employers to provide them.

There are also technologies like Hypori that provide virtual mobile infrastructure by streaming a compliant Android image to an iPhone or Android device, keeping the personal device completely out of scope.

There are quite a few ways to solve that problem today.

[29:47] — Jacob
Absolutely.

Reminder, everyone: visit cuihotline.org.

There’s a submission form if your question is too long for YouTube or LinkedIn chat.

Here’s one submitted through the form:

“We have DFARS 252.204-7012 in many of our contracts and are working toward CMMC Level 2. We have a Prevail enclave for CUI. However, I’ve never received anything actually marked CUI, nor any Security Classification Guide identifying CUI.

I received a DD254 with the CUI block checked, so I asked the customer for guidance on what would actually be CUI. They removed the CUI designation from the DD254 and revised it, saying they would never send CUI.

How are we, as a small business, supposed to know what to protect if we’ve never actually seen CUI?

The only reason I have Prevail is because DD Form 5512s are marked CUI when completed.

I need to train employees on what to look for besides obvious markings, and I’m still confused about what to tell them.

We work exclusively with the government. Any guidance would be appreciated.”

[31:16] — Daniel
The difficult answer is that it depends.

What I show organizations all the time is the types of information that could be CUI for their business.

Remember:

  • CUI must be backed by a law, regulation, or government-wide policy.
  • Not every CUI category applies to every organization.

For example, when you look through the CUI Registry and see “Budget,” that doesn’t mean your company’s budget is CUI.

It’s referring to a government agency’s budget submitted to the Office of Management and Budget.

[32:00] — Daniel
So those are two immediate points.

When you start breaking it down, one of the most common CUI categories in the Defense Industrial Base is Controlled Technical Information (CTI). That’s generally private, non-public technical information.

It’s not military specifications, it’s not your intellectual property, it’s not publicly available information, and it’s not COTS products.

The problem everyone runs into is asking, “How am I supposed to know?”

Honestly, your prime contractor or whoever is providing the information should be telling you what qualifies as CUI because you shouldn’t have to assume. You’re receiving documents that should already be marked so you know how to handle them.

Now, if you’re being instructed to create CUI on behalf of the government, that’s possible. But you should be explicitly informed of that as well.

At the end of the day, all you can really do is ask questions. If you’re not getting answers, looking for proper CUI markings is probably the best thing you can do.

The interesting part about CMMC is that ideally you establish your protected environment before you ever receive CUI.

The best way to do that is understand your existing data flow and ask, “If we receive a defense contract, how does that change the information flowing through our business?” Then build your enclave boundary around that.

I know that’s not the most satisfying answer, but outside of working with someone like Defert to perform a detailed review of your existing files, it’s probably the best guidance we can offer.

[33:45] — Jacob
Something else caught my attention.

They mentioned having forms that become CUI once they’re completed.

Typically that’s true for the government.

When you fill out a government form and send it to them, the government has to protect it as CUI.

That doesn’t necessarily mean the information was CUI while it was sitting in your possession.

That creates confusion because people think, “This form says it’s CUI once it’s filled out, so my copy must be CUI too.”

Not necessarily.

It sounds like they may have invested in an enclave and all this infrastructure, but they may never actually handle CUI because the only protected information involved is their own information being submitted to the government.

Take personal health information as an example.

Should you protect your own health information?

Absolutely.

Are you legally required to protect your own health information under CUI rules?

No.

When you send that information to the government, however, they have to protect it as CUI. They’ll mark it as CUI. If they send it back to you, it will still be marked as CUI.

That doesn’t automatically mean your original copy suddenly becomes subject to all of those requirements.

The direction the data flows matters.

Speaking of that, here’s another question:

“Are System Security Plans and POA&Ms considered Controlled Unclassified Information?”

No.

Absolutely not.

There is no law, regulation, or government-wide policy that says SSPs or POA&Ms are CUI.

There are plenty of suggestions and recommendations from the DoD saying you would probably be better off protecting those documents, but the 32 CFR Part 170 regulation never actually says they must be protected.

That’s the line that has to be crossed for something to become CUI.

Ironically, the DoD could have made them CUI simply by writing that requirement into the regulation.

Instead, they refer to things like security protection data and strongly encourage protecting it.

You’d definitely be cooler if you did.

But that doesn’t make it CUI.

Pop quiz for everyone:

How many legal authorities are listed across the 126 categories in the National Archives CUI Registry?

There are 435.

Not one of them says System Security Plans must be protected as CUI.

Daniel, do you hear this question often?

[37:05] — Daniel
All the time.

We’ve seen this with programs like UNMPI and higher-level Navy certifications, but not CMMC.

People ask whether they need a FedRAMP-authorized GRC tool.

If you’re collecting screenshots that contain CUI, then yes, you need to protect those appropriately.

The easier answer is: don’t collect evidence containing CUI. Put it somewhere separate if necessary.

It’s a pretty common misconception.

[37:40] — Jacob
Obviously the DoD thinks this information should be protected.

C3PAOs themselves have to achieve CMMC Level 2 because they handle large collections of information that technically isn’t CUI but probably should be treated that way.

They’re protecting aggregated assessment data that isn’t actually CUI by regulation.

For whatever reason, the DoD stopped short of saying the words necessary to officially designate it as CUI.

It really doesn’t take much.

A regulation simply has to say the information must be protected.

That’s the magic phrase.

[38:27] — Jacob
Mr. Bird asks another follow-up.

“When talking about light MDM for BYOD phones, does that mean using Defender to check device threat level or things like MAM checking operating system versions and whether devices are rooted or jailbroken?”

[38:52] — Daniel
The real question is what Conditional Access policies can enforce, especially in Microsoft 365.

For control 3.1.1, you have to authorize the device connecting to your CUI asset, which is typically Microsoft Government Cloud.

To do that, the device has to enroll in some form of MDM through Intune so the device state can be validated.

When I say “light MDM,” I mean validating things like:

  • Operating system version
  • Encryption status
  • Device compliance
  • Other Conditional Access requirements

Some organizations even use custom Conditional Access policies to block apps like TikTok on Android devices because of separate government requirements.

So yes, even in a BYOD environment, you still enroll the device in MDM.

Then MAM protects the corporate applications and CUI itself.

MAM alone can’t authorize the device.

You still need enough MDM to validate the device’s security posture before Conditional Access allows it to connect.

[40:09] — Jacob
Here’s another interesting question we received this week.

“Do companies need facility clearances or personnel clearances to handle CUI or achieve CMMC?”

[40:22] — Daniel
No.

You don’t need a facility clearance.

You don’t need security-cleared personnel.

What you do need is to authorize users who will handle CUI.

That means things like CUI training and probably some level of background screening.

The discussion sections of the controls provide several good recommendations.

Where this changes is when the CUI also falls under export control.

Then you have to verify citizenship, where employees are working, and whether additional restrictions under ITAR or EAR apply.

I know it’s confusing because there are so many regulations and acronyms.

CMMC itself isn’t what forces you into GCC High or prevents you from using Microsoft Commercial.

Export control regulations create those requirements independently.

Those obligations already existed before CMMC.

[41:47] — Jacob
That’s exactly right.

Many organizations ignored their export control obligations until CMMC exposed years of accumulated regulatory and engineering debt.

Then they blamed the messenger.

People say, “CMMC is forcing me into GCC High.”

I spent months debating someone on LinkedIn—a smart business owner who now works inside the DoD—and I couldn’t convince him that CMMC isn’t what requires GCC High.

ITAR is.

Long before a CMMC assessment ever happens, the restrictions attached to your data determine what engineering solutions you’re allowed to use.

Those aren’t security clearances, but data sovereignty requirements absolutely limit your options.

[43:06] — Daniel
Here’s another important point.

ITAR is not automatically CUI.

ITAR can stand completely on its own.

Sometimes it overlaps with CUI during performance of a federal contract, but it doesn’t have to.

I’ve spoken with some of the world’s largest weapons manufacturers who are handling ITAR technical data entirely within commercial environments.

The issue isn’t just data sovereignty.

One of the key ITAR clauses prohibits causing or enabling a foreign person to access, view, or possess unencrypted technical data.

Notice the wording.

CUI is concerned with processing, storing, and transmitting information.

ITAR focuses on access, viewing, or possession.

Here’s the problem.

Even if you configure Microsoft Commercial so your data resides in the United States, Microsoft doesn’t guarantee it will always stay there. During a service event, your data could fail over to another country.

You might think GCC solves that because it guarantees U.S. data residency.

However, GCC still uses follow-the-sun support.

There’s an interesting middle ground with Customer Key.

If Microsoft can’t decrypt your ITAR data and it remains in the United States, you may have a path forward.

But Customer Key breaks a lot of functionality.

If Microsoft can access your encryption keys and therefore decrypt the protected files during support, then you’ve enabled that possibility.

That’s why Microsoft only contractually satisfies ITAR requirements in GCC High.

Support personnel are U.S. persons, and the data remains within the United States.

That’s where most of the friction comes from.

People think, ‘I’ll just go to GCC and then, if I ever need ITAR, I’ll upgrade to GCC High.'”

[45:25] — Daniel
“Another common problem is that there is no upgrade path from GCC to GCC High. It’s a full implementation and migration all over again.

Out of our 1,400 clients, I would say 95–98% are in GCC High—not because all of them actively handle ITAR or export-controlled data, but because they don’t want to box themselves into being unable to pursue that type of work in the future.

[45:19] — Daniel
…need ITAR, I’ll upgrade to GCC High.”

Another common problem is that there is no upgrade path from GCC to GCC High. It’s a full implementation and migration all over again.

Out of our 1,400 clients, I would say 95–98% are in GCC High—not because all of them actively handle ITAR or export-controlled data, but because they don’t want to box themselves into being unable to pursue that work in the future.

[45:48] — Jacob
We tell people the same thing when they talk about moving from CMMC Level 1 to Level 2.

None of these requirements exist at Level 1 because they aren’t part of the FAR Basic Safeguarding Clause.

They don’t appear until you’re dealing with things like ITAR, DFARS 7012, or FedRAMP Moderate equivalency—requirements that have existed for a long time outside the CMMC program.

It’s a bit of a head fake.

The assessment program has Level 1, Level 2, and Level 3, but the underlying implementation requirements were never designed to be stepping stones between those levels.

It makes sense from an assessment perspective, but not from an implementation perspective.

[46:34] — Daniel
The maturity language in CMMC probably needs to be revisited.

Maybe in future rulemaking we’ll get a rebrand.

Maybe it’ll be “Crystal CMMC.”

Who knows?

If you could rename the CMMC program, what would you call it?

Serious answers only.

[47:14] — Jacob
Someone commented:

“Depending on how the SSP is filled out, you can reverse engineer the environment and launch a social engineering campaign. I recommend treating it like a FedRAMP SSP.”

I completely agree these are sensitive documents.

They absolutely should be protected.

The point is simply that the DoD stopped short of making them CUI by regulation.

Because they didn’t cross that line, they remain in this strange gray area.

They’re highly sensitive, they’re directly related to your CUI environment, and you should absolutely protect them as though they were CUI.

But that doesn’t legally make them CUI.

There’s a difference between something you should do and something you’re contractually required to do.

[48:30] — Jacob
Here’s another question from the form.

Regarding Access Control Policy and control 3.1.22:

Do public job postings on LinkedIn or other recruiting sites need to be included in the public-facing media policy?

We’ve discussed 3.1.22 several times.

Publicly accessible systems are not the same thing as social media.

Just because LinkedIn is public doesn’t mean it’s a publicly accessible information system that you control.

If you really want to make the technical argument, Appendix E of NIST SP 800-171 Rev. 2 points back to NIST SP 800-53 PL-4 enhancements concerning social media.

Those controls are not part of the 800-171 baseline.

They’re informational.

Revision 3 goes even further by explicitly classifying the social media requirements as non-confidentiality objectives.

NIST has twice indicated that social media isn’t what 3.1.22 is addressing.

So yes, you can safely remove LinkedIn job postings from that policy.

Just understand that some assessors may not interpret the requirements that carefully, and you may have to explain your reasoning.

[50:57] — Daniel
Here’s a related question.

If I post a job listing on my own website—which I control—that’s different than posting to social media.

Honestly, I’m struggling to think of a situation where a job posting would contain CUI in the first place.

The important thing is having a review process before content is published to systems you control.

Whether that’s your website or another platform, someone should verify that no CUI is included before anything goes live.

[51:50] — Jacob
Exactly.

We don’t put CUI into job postings regardless of where they’re published.

Have someone review everything before it’s posted.

Job postings don’t contain CUI.

Review complete.

This is also one of my favorite examples of NIST’s tailoring process.

The original NIST SP 800-53 control includes both reviewing information before posting and periodically reviewing information after it’s been posted.

Only the first requirement made it into 800-171.

There is no requirement to periodically review existing public content.

You absolutely should do that.

You’re just not technically required to.

[53:00] — Jacob
Another question:

“Can an MSP manage infrastructure and security tooling without becoming part of the assessment scope?”

[53:07] — Daniel
No.

There’s an important distinction between hosting and managing.

If an MSP is managing infrastructure inside your CMMC boundary, they’re performing functions that map to NIST SP 800-171 controls.

They’re interacting with Security Protection Assets, Security Protection Data, and potentially CUI.

The one scenario we’ve seen stay outside normal MSP scoping is staff augmentation.

In that case:

  • The contractor uses company-owned equipment.
  • They use company-issued credentials.
  • They follow your policies and procedures.
  • They’re essentially functioning like temporary employees.

But if the MSP is providing its own tooling and its own personnel are operating that tooling in your environment, that’s where they become part of the assessment scope.

There’s a narrow edge case where staff augmentation works, but most organizations hire MSPs specifically because they want the MSP’s tools and operational capabilities.

[54:48] — Jacob
Here’s an interesting Reddit question.

A company successfully passed CMMC Level 2.

Now they want to begin software development inside the enclave.

That means introducing IDEs, Java, Node.js, Windows Subsystem for Linux, package repositories, and software development workflows.

The security team is worried this will trigger a reassessment.

Does adding software development after certification require a reassessment?

My first reaction is yes, potentially.

Software development controls were probably marked “Not Applicable” during the original assessment.

The DoD specifically uses that scenario as an example of something that can trigger reassessment.

[56:04] — Daniel
Exactly.

You have to review every control that was marked Not Applicable and determine whether it has now become applicable.

The DoD gives wireless networking as one example.

We often use another example.

Suppose you build a fully virtual desktop enclave and certify it.

Then, a month later, you realize you need to print documents.

Now you’ve brought printers, networks, or physical devices into scope.

Controls that were previously Not Applicable now have to be implemented.

That’s what triggers reassessment.

This is why getting scoping right from the beginning is so important.

I’m not saying bring every asset into scope.

I’m saying bring in representative examples so your baseline already accounts for future growth.

Then your SSP can describe how those capabilities will scale later.

[57:52] — Jacob
We’ll finish with one more Reddit question.

“How do you keep consultants compliant in a CMMC Level 2 environment? They’re consultants rather than employees, so we can’t perform our own personnel screening. They only need email and shouldn’t access CUI. Is sensitivity labeling plus DLP enough?”

[58:25] — Daniel
If they don’t need CUI, keep them outside your boundary entirely.

Why bring them in?

If they absolutely require access, you need very strict onboarding requirements.

We see this frequently with guest users.

You’re responsible for anyone accessing your environment.

Your intake process should verify that they’ve completed the required personnel screening and will follow your acceptable use requirements.

You really have two choices:

  • Treat them like employees and require them to comply with your policies.
  • Treat them like visitors and digitally escort them through everything they do.

Nobody wants to do the second option because it’s extremely cumbersome.

Either way, you’re responsible.

[59:41] — Jacob
There are also a lot of standard account management controls that apply here.

This is exactly how attackers operate.

They create new accounts or compromise stale accounts.

Good governance over identities and accounts is a fundamental part of the security model.

All right, everybody.

It’s been an hour.

The hour always flies by.

Thanks to everyone who called the hotline, left a voicemail, or submitted questions through the form at cuihotline.org.

Thanks to everyone who sends us DMs on LinkedIn.

You can also find us at Summit 7. The new website overhaul is live, so check it out.

The blog has new content every few days.

Secure the DIB is coming up, so be sure to register.

One last reminder:

There won’t be a Friday show next week because of the Fourth of July holiday.

We’ll be doing the Hotline on Thursday instead.

Thanks for all the great questions.

We’ll see you next week.

Contact

Speak With Our Team

Scroll to Top