A live Friday Q&A recapping Navy Gold Coast and fielding audience questions about what the CMMC Phase 2 suspension actually changed. The recurring theme: the requirements never went away — the suspension mostly created confusion, new loopholes, and future harmonization headaches.
Key takeaways:
- The field thinks CMMC is still on. At Gold Coast, Army, Navy, MDA, and NDIA all treated it as “temporarily paused, still in our contracts.” The SBA was the outlier (“we want it to die”) — but the hosts note SBA conflates CMMC with DFARS 7012 and has no plan for the costs that exist independent of CMMC.
- “Not a cost of CMMC.” A self-assessment costs ~$0 in third-party fees, yet the real expenses (implementation, tooling, cloud) come from DFARS 7012 / 800-171 — so blaming CMMC misses where the burden actually lives.
- The assessor “shortage” doesn’t hold up. Even at a conservative half-capacity model, the ecosystem has never come close to maxing out; ~1,500 Level 2 certs are “missing” vs. what capacity allowed, and growth was on track to hit DoD’s own peak estimate (~end of 2028) before the suspension likely chills it.
- A new loophole: without DFARS 7021 in solicitations, some CUI-handling contractors now have to report no cyber posture at all — “we went back 10 years.”
- The Rev 2 vs. Rev 3 collision is coming. DoD had an interim final rule (on the CIO’s desk) that would’ve moved everyone to 800-171 Rev 3 together; suspending it means FAR CUI likely lands on Rev 3 while DFARS stays on Rev 2 — plus “brilliant at the basics” reaches beyond Rev 3. So much for harmonization.
- Enclaves aren’t a silver bullet. The Army’s ENCODE program (+ ~$50M assessment subsidy) could make an enclave nearly free, but CMMC’s documentation/assessment burden stays on the business, and cloud-only doesn’t work for many manufacturers — and data still flows to non-federal systems.
- Quick answers: Level 1 vs. 2 is dictated by the contract/data; you don’t need GCC High (just FedRAMP Moderate or equivalent) — it’s a de facto norm born from DFARS 7012 incident-reporting reciprocity; and “significant change” (M&A, boundary/architecture changes, making an N/A control applicable) can trigger reassessment, though the FAQ guidance sits in a legal gray area.
Transcript
Jacob: Hey everybody, it is Friday. It is hotline time. We’re live on YouTube, we’re live on LinkedIn. You can find us at cuihotline.org. You can fill out the form, you can call the number, you can put your questions in chat, you can send us DMs — or you can just go outside and yell, and we will hear you. Just scream your questions into the ether, and we will answer it on live. Just keep yelling. So, anyways, here we are. It’s Friday. Less than 80 days till Halloween, everybody. So make sure you’re planning — this will be the only Saturday Halloween for the next 11 years, so plan accordingly. Halloween is our Super Bowl around here. But anyways, Daniel, you are looking great. Beard is looking outstanding.
Daniel: I’m trying. I’m trying. I feel nice about it. I’ve started an oil-and-cream routine. Apparently you got to do some self-care.
Jacob: Applause in chat for the mountain man. Yeah, it’s looking great. And so, you were just at Navy Gold Coast.
Daniel: I was. And despite the fact that the DoD CIO and everyone who works for the DoD CIO opted not to show up for the first time since at least 2018, everyone was asking about CMMC.
So I think this is the most fascinating thing. Gold Coast of years prior — Jacob, I know you can attest to this — you’d walk up and say the word CMMC and they’re like, “Why are you cussing me out?” They didn’t even know what it meant. “What is this word? This is crazy talk. We’re here to sell things to the Navy. Get out of our way.” This year was fascinating. We saw vendors with little PowerPoint slides above their booth showing CMMC certs — “Hey, we’re CMMC L2 certified.” What do you know? Talk to a construction company, they’re like, “We’re CMMC certified.” The buzz was around. And what I thought was crazy was, most people said, “Yeah, CMMC is still a thing.” So I went to the Army booth for small business, the Navy booth, and I was like, “Hey guys, just checking in, CMMC’s still a thing.” MDA — they’re like, “Yep, Phase 1’s still a thing. Do the thing. It’s still in our contracts. Move forward.” “Temporarily paused” is the language they’d use. And I will say this — I walked over to the SBA booth because I just had to talk to them and figure out what they want to do. I said, “Are you guys going to offer grants or loans or anything to small businesses to help lift the burden of CMMC?” Now, I use that language because they think CMMC and 7012 are the same thing, so it’s a very difficult concept to break those apart. And they’re like, “No, it’s suspended, and our goal is to make sure that it dies, basically.” So you have the Army and the Navy saying, “Nope, still a thing,” and then the SBA — who really doesn’t have any ability to change anything — is like, “No, we just want it to die.” And it’s like, you don’t even understand what you’re saying.
Jacob: This has been my question to the SBA all along. They’ve never been a fan of CMMC, ever. So when they had their listening sessions pre-suspension, unrecorded, I’d get on there and be like, “Okay, fine. Let’s say CMMC gets nuked from orbit. What’s your plan to help small businesses with DFARS 7012?” Because right now, nobody is required to get a C3PAO assessment in order to win a contract. They only have to do a self-assessment. So the cost of an assessment, theoretically, is zero. You are not forced to pay a C3PAO to run a third-party assessment. And yet everyone still has all of these costs — because it’s not a cost of CMMC.
Daniel: I need a light-up sign in the background: “Not a cost of CMMC.” And then the applause sign goes off, right?
Jacob: So what’s the plan, SBA? You guys got a plan for offsetting those costs? You don’t have a plan, because you can’t think past the idea of CMMC. You cannot imagine something outside of what this program is. It’s just insane that they’re holding this whole thing hostage because of their own lack of understanding.
Daniel: Well, I think what was crazy was, we had businesses coming up to our booth and they were like, “We need to get CMMC certified.” And we’d probe a little bit, or we’d walk around asking questions, and they’re like, “Yeah, our prime is still requiring it.” And Navy said it’s a go. I even talked to NDIA, Army — everyone’s like, “It’s still a thing.”
Jacob: Well, this is something we talked about — circa 2019, most people didn’t know there were cyber requirements in these contracts, for various reasons. But over the course of six years, there’s just more understanding now that the requirements are independent of CMMC, and that there’s no proof that they’re implemented. So it might just be the case that people’s understanding has changed, and that they still want some sort of assurance over the requirements, that gets lost in the rhetoric around what’s going on.
Shout out to Gails here. Gails’ first time watching the hotline was last week, reached out via DM, watching videos, doing some reading. Gails is back this week. Everybody say hi to Gails. Gails has been learning about this space for a couple weeks — probably, in total, like many days. And this person is already like, “Am I taking crazy pills, or is the SBA just not understanding what’s going on here?” You are not taking crazy pills, Gails. You understand exactly what’s going on. Welcome to the circus.
Daniel: Yeah, you pretty much get the entire story. But I just love it because they’re brand new. They’re like, “Am I understanding this right?” You’re like, “Yep, you understand it.” They’re like, “Well, why is it so hard for this to get across?” And you’re like, “Good question. Good question.” And it’s nice to have some fresh eyes on things, make sure we’re not crazy. It feels nice to feel that way a little bit.
Jacob: I mean, it is easy to feel crazy in this space. Many, many times I wake up in the morning like, do I understand what’s going on in this space? Am I the one that’s not understanding? But, you know, we’ll see what happens with the RFI review. All righty. So there you go. That was Gold Coast.
I got some fun charts for everybody. Gather around, everybody, because this data we’re looking at is going to be very important as we move into August, September, October, because the main justification for the suspension was that there aren’t enough assessors, there isn’t enough assessment capacity, and that the ecosystem’s assessment capacity isn’t scaling fast enough. So let’s look at that first piece — “there aren’t enough assessors.” That is not true. It has never been true during the phased rollout, even once. So the bars here are the number of new Level 2 certifications per month since November of 2025, when the DoD started their phased rollout. The black line is the theoretical capacity the ecosystem can support if you put together all of the possible assessment teams based on the number of certified assessors available — and then cut that number in half. Take the total number of assessments you could potentially run, based on the total number of assessment teams you could potentially put together, based off the Cyber AB’s reporting of how many certified assessors there are, and then assume half of them don’t exist because they work for companies and aren’t running assessments — just cut it in half. And there has never been a month during the CMMC phased rollout where the ecosystem has maxed out or come close to maxing out the number of potential Level 2 certifications that could have been run, even if you assume half of the ecosystem isn’t running. Not even close.
And so when you add up how many we could have run over the last nine months — if everyone had fully utilized half of the potential capacity of the ecosystem — we should be at 3,371 Level 2 certifications, which is a ton. As of July, we have 1,924. There are 1,500 missing Level 2 certifications that would have been there if we had been utilizing half of the ecosystem’s capacity over the last nine months. If you want to look at that a different way, you can look at it as the percentage per month that was utilized of this half-capacity. And on average, the ecosystem has only used half of the capacity available per month, assuming that only half of the teams are actually operating. Never once has the ecosystem over Phase 1 come anywhere close to maxing out the potential assessment capacity. So you should be asking yourself, why then is the DoD saying they need to suspend third-party assessments because there aren’t enough assessors, when their own data — reported out of eMASS and out of the AB’s certified assessor numbers — disproves that claim very obviously? I mean, these aren’t our numbers. We just added up the numbers on the Cyber AB town hall every month. Those numbers come out of eMASS. Anybody got a guess? Anybody want to know? Because it isn’t true.
Now, I haven’t finished the chart yet, but if you get to the second point, where the DoD says the ecosystem isn’t scaling — well, we’ve already established there are enough assessors. So they go, “Well, maybe there won’t be enough assessors for the increase in demand.” Well, how much demand are we talking about? When are we talking about it? November is not a DoD deadline. You don’t have to have 80,000 or 100,000 Level 2 certs by November. That’s not what the DoD estimated. The DoD estimated that at the peak demand in year four, there would be somewhere around 32,000 Level 2 assessments required — for all the new Level 2 assessments you’d need, plus all the year-one renewal assessments. It ends up somewhere around that number. The ecosystem is currently — and I’ll make a slide for this next week — on track, at pre-suspension growth per month, if you extrapolate it forward, to meet the DoD’s maximum annual estimate by the end of 2028, which is Phase 4. Exactly the phased rollout they came up with.
Daniel: Yep.
Jacob: So when the DoD says it’s not scaling in accordance with their estimates — what estimates are you talking about? Because the only estimates you’ve ever published line up directly with the numbers you guys put out there. So I’ll make a fun chart that shows it, but I want everybody to pay attention, because we’re going to have to look at the numbers post-suspension. These July numbers don’t reflect the chilling effect the suspension will have, because not as many people will sign up to be an assessor. You’ll have fewer assessment teams available. The growth rate will slow down. So what’s the plan? Are they going to somehow reinvigorate the growth of the ecosystem in order to renew the number of assessment teams? Are they going to be able to do that, and have it happen faster than before?
Daniel: Yeah. What’s the plan?
Jacob: Because the line goes up exactly as fast as it needed to before the suspension. The line will go up not as much after the suspension. So what’s the plan? Gap. And I don’t think they have a good answer. And I’m pretty sure that’s what the armed services committees are going to ask about when they come back after their August recess and the CMMC review is done — because they’re all going to get a copy of these slides, because these are public numbers. So just tell your friends, pay attention. We’re going to track those numbers moving forward on this show, on the podcast, and everything. These are all public numbers. Estimates are in the rules. DoD has new estimates, maybe. I don’t know where they got the numbers from, but nobody has seen them.
Daniel: So my only thought is: how many people were in that false-start number? How many assessment teams were consumed by false starts? And honestly, in my mind, a false start should probably equal a failure. If you can’t deliver the appropriate information within a given amount of time, you likely don’t have it at all, and therefore you probably just should have failed. I think that would be a wonderful number for them to publish.
Jacob: Can you imagine if the DoD came out and said, “We had to suspend third-party assessments because so many people were failing — it was taking up assessment capacity for the people who could pass”? That’s very, very different than saying that CMMC is peacetime paperwork, bureaucratic red tape, waste-of-time compliance checkbox exercise. That is a very different story, and that’s not the story the SBA is going to tell you. And everybody knows why. But we got the numbers, folks. You can go do the math yourself. You can go to the Cyber AB town hall, look at all their town halls. You can go to the rule, check it out. We’re going to keep track of these numbers — blogs, shows, all that stuff. But just so you know: everything was tracking just fine. DoD said the opposite.
I tell people this all the time. Back in 2021, when they announced the program review, they just said, “We’re reviewing it, we’ll get back to you.” We didn’t hear anything for nine months. Here, they shot themselves in the foot, because they said, “We’re only doing a review for 60 days.” I’m like, yep, we can wait 60 days.
Daniel: Oh yeah. 60 days is nothing.
Jacob: So I don’t know what your plan is in 61 days and counting, but you’re going to see a dip in that growth rate, and you’re going to have to answer for it, because it’s your fault.
Daniel: Yep.
Jacob: All righty. Nothing specific on the charts. If you guys got questions, let us know — we’re going to have some additional ones coming out soon. Now, here’s the fun part. Let’s say the DoD came out and said, “No one’s ready, so we’re going to be nice to everybody and extend Phase 1.” I was half expecting them to do that, because most people aren’t ready. And the DoD has granted extensions. But they didn’t extend Phase 1. They suspended Phase 2, because they said there wasn’t enough. That’s just not the case. It’s crazy.
Daniel: I don’t know. I don’t know.
Jacob: Gails is the newest person watching the show and she’s already made two jokes about needing to be medicated to understand the environment. It’s hilarious. Okay, let’s get into some questions here. Classic: “What is the difference between CMMC Level 1 and CMMC Level 2, and how do I know which one I need?”
Daniel: The contract will tell you. Whether that’s the private contract between you and a prime, or, if you are the prime, inside the solicitation with DFARS 7021 — it’s going to state the level you have to be at. Level 1 is for federal contract information, which is private information between you and the government that’s not CUI, meant for transactions like invoicing and things of that nature. Level 2 deals with CUI — controlled unclassified information — and there’s a whole CUI registry that defines what law, regulation, and government-wide policies govern that specific type of data. So those are the two different levels, two different data types. Now, if you’re just dealing with COTS products, or your own IP, or things that are not CUI or even FCI, that likely won’t even have a CMMC level associated with it — probably a Level 1, just because there might be some private information exchange, but you could just be a COTS consumer out there.
Jacob: Yeah. So CMMC Phase 2 is suspended, and really the only thing that means is that the DFARS clause 252.204-7021 should not indicate that you need to achieve CMMC Level 2 C3PAO status in order to take award of that contract. The only thing that clause can say is that you need either CMMC Level 1 self-assessment status or CMMC Level 2 self-assessment status. You still have to complete either of those two statuses and everything that comes with them. And you still have to comply with DFARS 252.204-7012, implement NIST SP 800-171, FedRAMP equivalency, all those sorts of things. Nothing about the suspension changes any of those other requirements. The only thing it theoretically does — but we’ve heard the opposite recently — is that the DoD will not require you to achieve C3PAO status to take a contract. But we’re hearing that A&S didn’t do a very good job of instructing its contracting workforce. Shocker. And there are 7021 clauses going out right now with Level 2 C3PAO status in them. So people have to deal with that, and then walk it back and talk to their customer, and this and that. It’s a giant mess.
Daniel: It is a giant mess.
Jacob: It’s a giant mess. The mess you had beforehand was people weren’t requiring Level 2 C3PAO when they ought to have. Now they’re requiring it when they shouldn’t. So, you know, 60 days just isn’t a lot of time to turn a ship around the size of the DoD, especially the contract workforce. All righty. Nicholas says, “How often are small and medium businesses attempting to sanitize their ITAR CUI work for other subcontractors so it’s no longer considered ITAR or CUI? Is there an official course a person can go to to learn how to do this properly?”
Daniel: No. No official course. But here’s how people are doing it. They’re taking, let’s say, an engineering file — a CAD file — and looking at who in their supply chain will obviously need certain parts of that information. And here’s the beautiful part: if it’s a COTS product, just send that information down — not CUI. If it’s their IP, that you already know they own and it’s not customized — guess what, just send that data down. So people almost become a dispatcher and say, “Okay, I need these for that bill of materials. I’ve got 50 things. 10 of these include the secret-recipe CUI from the DoD or the prime. 40 of these are just COTS products or suppliers’ IP we need to purchase, that are not CUI. We’re not asking them to modify anything existing.” It’s really when you drift into the modification, or potentially the assembly of that data together, where CUI really becomes manifest — where it’s really, really there. So it’s simple: hire the equivalent of a CUI program manager, figure out which parts are your secret sauce, and then ship out the rest as COTS, IP, or maybe just FCI data — because it has no law, regulation, or government-wide policy behind it. So, you just have to look at the data and determine what’s yours, what’s the government’s, and what’s public information, and dice it up accordingly.
Jacob: Yeah, it’s always a fun conversation, because people go, “Well, my prime is requiring me to get this level. I wish they would just not mark the data, or send me the data I don’t need.” And then inevitably you’re like, “Well, are you going to take the time to dissect the information so that your suppliers don’t need to?” “We don’t have time to do that.” And you’re like, well, that’s exactly the same situation the primes are in. Just because they’re a massive company doesn’t mean the individual program offices have the resources you think they do. They win those bids because they’re low cost and they don’t have enough people — not necessarily because… Northrop is not a monolith, you know what I mean? All righty. Eigor’s here. Been a long time, man, good to see you. He says, “How are you convincing reluctant vendors to ignore the pause and keep investing in their compliance and security program?”
Jacob: Well, you can’t convince somebody who doesn’t want to be convinced. We’ve garnered enough authority in the ecosystem, and people recognize us for what we do, that the people who seek us out are the people who know what’s up. They generally understand they have requirements in their contracts, and that one way or another, inevitably, somebody is going to ask them to prove it — and even if that day is a long time from now, you still have the requirements in your contracts, so you’ve got to deal with them. So we typically work with companies that understand that fact. We put out a lot of content to help companies understand it. But it just turns out some people want to take the risk. That’s not what I’d do, not what I recommend, although I understand why people make that decision. I’ve seen this on some LinkedIn discussions — which is only one channel — but a lot of the people celebrating the pause in the same breath will be like, “I’m so tired of hearing that these requirements have been in contracts all along.” And I’m like, right, okay, but it’s true. It’s true. I don’t know what to tell you. So, convincing — we just tell them what’s in their contracts, what’s been going on, and why the first brush against the most recent headlines isn’t always going to serve you for determining your strategy. Because if you took just the news since July, it would sound like you don’t have to do anything. And that’s not true.
All righty. Mr. 11944 said, “Can you explain how DFARS 252.204-7997 allows Army to forego DFARS 7012 and not require CMMC Level 2, even though the RFP contains CUI? The minimum level of CMMC Level 1 is all that’s required, yet we still have to handle CUI.”
Daniel: So, RFPs shouldn’t contain CUI, just pretty much period. If it’s on SAM.gov and you can get to that information without validation, that’s a problem. Now, DFARS 7012, DFARS 7020 — which has been renamed as 7997, which we’ll talk about in a second — all of those are once you’ve won the contract. Prior, you’re likely going to see a provision, or basically a notice, saying, “Hey, FYI, protection of CUI is coming through other contractual obligations.” But here’s a weird loophole. CMMC requirements for self-assessment at Level 1 and Level 2 are out as part of Phase 1. You probably noticed not every solicitation has DFARS 7021 requirements with self-attestation. DFARS 7020, which is now 7997, took away the requirement for minimum SPRS scoring. This is when you could have a score ranging from -203 to a perfect 110. So here’s a terrible loophole the suspension caused: without the inclusion of DFARS 7021 in solicitations — even at a self level — there are organizations handling CUI that have to do no reporting of their current cybersecurity posture at all. So not only did we suspend CMMC because people basically weren’t ready — and if you boil all the numbers down that Jacob just presented — but we also said, “You know what, we might suspend you having to report your cybersecurity posture at all for a myriad of contracts.” And so we went back to just DFARS 7012 days of handling CUI. We went back 10 years in one tiny little suspension. So this is a little bit of the frustration here — it’s hard to say you care about cybersecurity when you’ve actually inadvertently removed the requirement to even self-attest for certain solicitations, once you’re awarded that contract. Because if they don’t include 7021 — which, again, we’re talking about a phased roll-in of CMMC requirements — you’ve got a big problem on your hands.
Jacob: You know, this is the current crop of leadership out there — DoD, OMB, all these folks currently in the seats — apparently have very short memories. This is an unrelated topic, we’re going to do a deeper podcast dive on this, so like and subscribe. But I don’t know if anybody paid attention to the recent announcement around federal system logging requirements and how those have been reformed. So, if you go way back — everybody remember SolarWinds, and how it was the worst compromise of the federal government and multiple federal agencies ever? Take the OPM hack and all that stuff — way worse. I mean, you’re talking Defcon Ultra Platinum, Rune King, Thor Emergency. And one of the reasons it was so bad was that the dwell time of the advanced actors in the system was really, really long, and they were using legitimate credentials to move around. So if you didn’t have sufficient logging, and long enough amounts of logging backwards, you can’t figure out what they were doing, because they’re not just going in and smashing up the china cabinet everywhere they go. That’s not how they operate. So GAO did the report, there’s congressional hearings, all this stuff. And they said every agency was logging things differently, if at all, keeping things at different lengths, if at all. There was zero ability to retrace what was going on. It was a complete disaster. Fix it. So an executive order got written, federal logging requirements came out, and they said you’ve got to keep like 12 months of active logs, 18 months of cold logs, log these types of activities, because this is how SolarWinds operated, and if we’d had this data, we could have mitigated the damage even if we couldn’t have prevented the compromise to begin with. Well, OMB issued a memo a couple months ago that was like, “That’s just compliance, that’s not security. This is ridiculous. Get rid of these overly prescriptive requirements and rewrite them.” So then CISA, following orders, just published their new federal system logging requirements, and it has a very minimal amount of required logging, and all of the logging requirements are up to agency-based risk decisions — which is exactly the situation that didn’t let you deal with the SolarWinds deal. Fascinating story, we’re going to talk about it on the podcast, like and subscribe. I think it’s a fascinating story, because it’s exactly what we’re watching in the CMMC space.
Daniel: It’s coming all the way back. Exactly the same situation, and it’s a total farce where they go, “This is security outcomes versus compliance.” You don’t want to spend the money, you don’t like being told what to do, even though it came from a place of a legitimate intrusion. So you relaxed the requirements, and now we’re going to be back in the same position in a couple years. It’s a fun story, everybody. The water sector, federal logging, CMMC — same cycle over and over again.
All righty. Mr. 11944 says, “As a prime, we’re in a huge pickle to distribute what is clearly marked CUI to bidding contractors who are not compliant. Level 1 CMMC is inefficient, in my opinion, but competitors are sending out CUI freely.”
Daniel: Yep. It’s hard. It’s hard doing the right thing.
Jacob: Doesn’t it make you want to feel like, man, I wish there was something that would filter out non-compliant organizations from winning this work, to then be able to distribute that CUI out? It goes back to — some people look at DFARS 7021 and C3PAO certification requirements as a burden, which, by the way, it is. It’s a lot to get to 7012 and then go through a certification, like all regulations, by definition.
Daniel: You’re right.
Jacob: And so you look at this and you’re like, man, in reality, having people prove that they’ve actually done the thing is going to inadvertently shrink the supply chain — not for the sake of shrinking the supply chain, but for the sake of being good stewards of the data they’re in receipt of. And at the end of the day, if you tell people to go do this, and they’ve done it, and now you’re not going to reward that, and you’re going to allow these false 110 scores to continue to populate in your system — which the CIO at Black Hat even addressed, and said the average score from an incident reported to DIBNet is a 109.5.
Daniel: Yeah, that’s their average SPRS score. That’s crazy.
Jacob: Yeah, they know the SPRS scores aren’t accurate. They’ve known it since 2020.
Daniel: Yeah. Yeah.
Jacob: So, to your point, when you look at the RFI responses — which is a whole other story about why those are RFI responses and not public comments — it’s the same policy issues brought up in every public comment period on every DFARS cyber rule since 2011. It’s CUI marking. It’s minimum requirements. It’s small business cost impacts. The same policy over and over and over again, brought up again and again. The only new policy question really around as a result of the suspension is: now you have a humongous number of companies that did do the right thing. Now what are you going to do? Because back in 2019, everybody was in the same boat — pretty much nobody could prove, for one reason or another, that they had complied. Now, years later, you’ve got a massive group of people who, as a result of the suspension, are put in a worse competitive position, because you reversed the policy position you told them to get into.
Daniel: Yep. How are you going to handle that one? How are you going to handle that class-action lawsuit?
Jacob: Right. I just don’t understand how the DoD is going to get themselves out of this corner they painted themselves into, because the only new policy position they haven’t covered six or seven times so far is what to do when you put the people who did what you told them to do into a bad position. I’m not envious of the DoD right now. Okay. Somebody said, “I have a feeling they will announce that Rev 3 will be the new assessment standard.”
It’s funny you mention that, because the unified agenda was published a couple weeks ago. When the CMMC program rule was finalized and went into effect at the end of 2024, the DoD team at that time started working on the next version of the regulation — what we might call CMMC 3.0: how to transition to 800-171 Rev 3, how to deal with FedRAMP equivalency, how to deal with the organizationally defined parameters. All these things that had come up in the rulemaking to CMMC 2.0 were going to be in the CMMC 3.0 revision, update, overhaul of that regulation. That rule was so close to being done, it was on the unified agenda. So for all intents and purposes, that rule was on the DoD CIO’s desk when she got confirmed last year, and it’s been on her desk for seven, eight months. And that rule was designed to go to 800-171 Rev 3. In fact, the unified agenda indicated it was an interim final rule — you wouldn’t have to go get public comments first, adjudicate the comments, republish the rule, a process that typically takes 12 to 18 months. The rule would go into effect as soon as it was published, and then you could keep going. Interim final rules are very difficult to get. The last time the DoD had an interim final rule and paused the program to do a lengthy review, they went back to OMB and said, “Okay, now we have a plan, we’d like our interim final rule.” And OMB was like, “Go get in line. It’s clearly not a national security emergency, because we gave you the waiver and then you took nine months to get back to us.” Here, OMB said, “Okay, here’s your waiver.” And what did they do? They waited seven months, then paused the program, and then went into a review. So what are they going to do? Come back and say, “Rev 3 ODPs, FedRAMP equivalency changes to the program — we’d like an interim final rule now.” Ain’t gonna happen. It’s exactly what happened in 2021. So everybody’s going to be stuck on Rev 2 for an extended period of time. And that’s a big problem, because the FAR CUI rule is going to put everybody on 800-171 Rev 3.
Daniel: I don’t know. I mean, we emailed them in January. We flew out to DC to meet the new CIO leadership team, sent them an email the same day: “Hey, we’ve been looking at this ecosystem for a long time. Here’s some things you can do, some things you can tweak in your upcoming rule, some ways you can eliminate CMMC Level 1, cut the cost of the program, save a bunch of confusion, make that the FAR Council’s problem,” blah blah blah. Just tons of recommendations. They never responded. Now here we are.
Jacob: So here we are. I don’t want to say I told you so, but you should have checked your email, guys, because now you’re really screwed. I have no idea. When the FAR CUI rule says 800-171 Rev 3, and the DoD comes out of this review and says, “What? We’re going to go into rulemaking to move to 800-171 Rev 3?” — that’s what the rule on your desk was for last year. Crazy.
Daniel: I don’t know. Crazy world. Lots of smells. I don’t know. All righty. “Will the government ever provide a shared CUI enclave for small businesses? Would it satisfy CMMC requirements?”
Funny that you mention that. So here’s what’s pretty fascinating about ENCODE. ENCODE — the Army program — they took some funding away from it this year, but it’ll be back October, supposedly, of this year, where they’ll start onboarding people and doing all of that. They picked a handful of organizations — Summit 7 being one of them — to provision these enclaves. Now, these enclaves are not on a government M365 cloud, and I mean that in the sense that it’s not the DoD M365 cloud. They’re still in a GovCloud, but one that contractors can procure. So here’s what’s interesting: the burden of CMMC will still be on the small business to achieve. The Army, through its partners like Summit 7, will be providing basically funding for you to have an enclave environment that’s stood up and licensed with virtual desktops, and nothing on-prem — a cloud-only native environment. Here’s a little bit of the conundrum: most organizations today can’t only work in the cloud. It just isn’t functional, from manufacturers, to only have that data sit inside a VDI that they don’t directly control or are able to exfil in a compliant way, because their on-prem systems are likely out of scope. So Army’s going to provide ENCODE — again, that’s imminently going to happen once funding is restored — and that’s great for the thousands of businesses. I think like 10,000 organizations have signed up so far. Who wouldn’t sign up for something that’s free? However, the burden of still fulfilling CMMC through the contractual obligation is still on the small business. You still have to have documentation. You still have to potentially go through an assessment, if certifications are reinstated. Now, the DoD was working on some additional subsidies to pay for CMMC, and basically, when you look at that, it’s really just the assessment costs — which have been suspended, ironically enough. But they’ve earmarked $50 million for it, is what they’ve requested. And so, in reality, ENCODE plus that could equal a 100%, or very close to it, 95%-free solution from a technology and assessment perspective. Then it’s just the labor it takes to check in all the boxes, do the policies and procedures, and things like that. It’s kind of crazy out there when you start looking at it all. And providing an enclave doesn’t mean it provides you the solution that you need. That’s really the gist of it: if you can work in just VDI, this is for you. If you can’t, you’ve got a bigger problem on your hands.
Jacob: Yeah, absolutely. Besides the fact — I’ve heard this a lot on LinkedIn since the suspension. People go, “They should just stand up these enclave systems and everybody should work out of there.” Like you said, that’s not the use case that works for everybody. So my whole point is, okay, fine, they should do that, they should have been doing that, let’s go do that. The problem is, when the data ends up on a non-federal system, what then? Because it’s going to flow onto non-federal systems. The guy at Gold Coast who represents NDIA’s training to small businesses told me on a LinkedIn comment that if the CUI data flows onto a non-federal system, it would be considered a spillage of CUI. And I’m like, brother, you’re out there teaching businesses about how this works. I think there’s just a lot of technologists out there who say we can just solve this problem with cloud enclaves and then everything will be fine. “Why, what’s wrong with everybody? Are they just stupid? Just stand up some cloud enclaves and everything’s going to be totally fine.” That’s going to fix the problem for a lot of people. It is not going to fix the problem for everybody. It’s not a panacea. Even if it were funded — which it should be — it’s not going to fix all the situations. So the question to ask then is: yes, and what do we do then? What do we do in addition to those things?
All righty. Somebody said, “I wonder how the long-awaited FAR CUI rule will impact CMMC. Can you imagine the spicy meatball of a FAR requiring Rev 3 and DFARS stuck on Rev 2?”
I can’t imagine it, because at this point that’s going to happen. That is going to happen at this point, because nobody seems to have a good answer for making it not happen. The answer the DoD had for avoiding this problem was the rule that was on the DoD CIO’s desk whenever she was confirmed and went into her office. Since it was an interim final rule, the DoD was going to move its contractors to Rev 3 while the FAR was going to move federal contractors to Rev 3. But because somebody decided that rule wasn’t good enough, and that we were going to suspend the program to do God knows what, the FAR CUI rule is continuing to chug along, and it’s going to be on Rev 3. So now, if you restart the rulemaking process and you don’t get an interim final rule — which you probably will not — defense contractors will be on Rev 2 for some period of time. Well, every other federal contract is on Rev 3. What’s the plan? You’re not going to issue a class deviation to the FAR to put them on Rev 2. What’s the plan? Based off what I’ve heard from the listening session, there is no plan. In fact, if you look at what the DoD CIO’s office put out with their “brilliant at the basics,” not only are those not 800-171 Rev 2 or Rev 3 in many circumstances — they’re beyond the requirements of Rev 3. They’re beyond the scoping requirements written for Rev 2 and Rev 3, because they want operational technology security to be in scope. So you’re going to have a DFARS clause that says do 800-171 Rev 2, rulemaking that’s going to tell people to move to “brilliant at the basics,” and FAR clauses that tell people to move to 800-171 Rev 3. Hey, DoD CIO — I thought the whole point here was to harmonize everything and get everybody on the same page. What are we doing?
Daniel: What are we doing? What are we doing?
Jacob: Yeah. So I don’t know what the answer is. They had a plan. They had a rule. They had a path to success to move everybody to 800-171 Rev 3 at the same time. And she decided that wasn’t good enough. So I don’t know. Stay tuned, because the previous leadership teams at the DoD avoided this exact problem. They issued a class deviation in 2024 that said, “Whoa, whoa, whoa. CMMC is going to be on 171 Rev 3, DFARS is going to be on 171 Rev 2 — everybody stay on Rev 2. We don’t want you having to juggle two different baselines. When the next CMMC revision comes out and moves to Rev 3, we’ll move everybody together.” Well, now, ironically, they’re going to be in that exact situation the previous team thought forward to avoiding — and it’s the current team’s fault.
Daniel: I’m going to put this out here. There are obviously crosswalks up to Rev 3 from Rev 2. There are more controls in Rev 3, if you look at the actual assessment objectives and all of that. But the one thing people are overlooking: FAR CUI has a FedRAMP Moderate baseline. DFARS 7012 has FedRAMP Moderate authorized, or FedRAMP Moderate equivalency. So when you start looking at some of these things, you might have a cloud provider under FAR CUI that meets a FedRAMP Moderate baseline but does not meet equivalency and is not authorized. So now you have potentially disparate cloud providers to meet FAR CUI that can’t meet DFARS 7012 and equivalency.
Jacob: Right. Because the FAR CUI final rule is going to come out, and as far as we know, there’s no plan on behalf of the department for how to deal with the fact that defense contractors, by virtue of being defense contractors, have incident reporting requirements that are completely beyond the scope of CMMC scoping guidance. As of right now, under DFARS 7012, your scoping guidance pertains only to where the data goes and incidents pertaining to the data on those covered systems. CIRCIA says nothing about system scope. It just says you’re in the DIB, therefore you’re critical infrastructure, therefore any incident that occurs anywhere in your infrastructure is reportable.
Daniel: Yep. What’s the plan? Anybody talked to CISA lately?
Jacob: Should have read your email. Should have read your email. Because — this is the joke I always make — there is more rulemaking and disparate, unharmonized requirements now, six years after everybody’s been talking about harmonizing requirements, than we had in 2020.
Daniel: It’s crazy.
Jacob: Yep. It’s crazy. All righty. Somebody says, “What is proper handling of the situation when CUI is shared from enclave to commercial environment within the same company?”
Daniel: See, here’s the problem. The way CMMC is written, it’s all about data flow. Where the data goes, those assets are in scope in some capacity — CUI assets, security protection assets, specialized assets, etc. So if you have something inside your CMMC enclave reach out to your commercial environment — uh-oh, your commercial environment is now in scope of handling CUI. You’ve basically just immediately extended your boundary. And you have two different plays here. You can remediate and purge that information, document it, make sure it’s tracked appropriately, and potentially report it as an unauthorized disclosure — because it’s not a spillage, but CUI got into an environment where it shouldn’t have. Or you now have the decision to immediately make that asset in scope. Now, significant change language could potentially bring that in, where you’d need to do a reassessment — either self or third-party certification, depending on what you’ve done. So long story short, the goal is: don’t have that sneak out of your CUI environment, or else you’re bringing a lot more in scope, or a heck of a lot more remediation and reporting.
Jacob: “Do you think that when Rev 3 is required, will certified Rev 2 be able to do incremental assessments that would increase the revision, or will they need a full reassessment?” Don’t know. We don’t know the policy for how the DoD is going to handle that, because the rule the DoD CIO opted not to go forward with would have explained how that process was going to work. What is the plan for transitioning to 800-171 Rev 3? Because nobody ever saw that rule, we don’t know what the plan was for the transition. Now, during the suspension, the RFI is talking about what requirements are good, what requirements are bad, CUI marking, all this stuff that’s completely outside the scope of the CMMC program at all, and sometimes even outside the scope of the DoD CIO office itself. What’s the plan to go from Rev 2 to Rev 3? Are you going to, in the name of harmonization, tell DoD contractors that their future requirements won’t be either Rev 2 or Rev 3? The DoD CIO got on stage at Black Hat — unrecorded, wouldn’t allow anybody to record — and told everybody 800-171 Rev 2 doesn’t go far enough. Published “brilliant at the basics,” which is a baseline beyond 800-171 Rev 3, beyond what could technically even be in 800-171 Rev 4, if you know how they’re derived. So what was all that stuff about costs? What was all that stuff about saving people money? What was all that stuff about reducing burden? “Doesn’t go far enough.” You want availability and integrity and operational technology and AI and this and that. Are you going to deviate from the FAR CUI rule? We’ll have to see what the report says.
Daniel: Well, and that’s kind of another little saving grace of getting certified: FAR CUI is going to happen. CMMC is the mechanism to assess 7012, at least at a Level 2 perspective. So what’s interesting to me is, if you get certified now, prior to Rev 3 happening, likely you’re not going to need a delta assessment until your three-year period is up. So take advantage of the suspension.
Jacob: Yeah. The CIO has said that companies that go get their CMMC certification will be rewarded, and it will not have been in vain, and they’re going to make it worth your while. Are they going to grandfather CMMC assessments against Rev 2 for some period of time, while they’re out here talking about doing OT and AI and phishing-resistant MFA? It’s going to be way cheaper to get your CMMC cert against Rev 2 than against what the DoD CIO is signaling she thinks the requirement should be, if they can even get the rule done.
Okay. “Do you actually need GCC High for CMMC Level 2, or is that something the ecosystem has turned into a de facto requirement?”
Daniel: I love this question, because we specialize in getting people into GCC High, and we will be the first people to tell you: you don’t need GCC High to achieve CMMC Level 2.
Jacob: Nope.
Daniel: You need something that’s FedRAMP Moderate or equivalent, and if you have export control data, active support contracts that make sure the data stays in the US and that the support personnel who have the ability to decrypt the data are US persons — those are your checkboxes when looking at a CSP. So no, you can use other platforms, 100%. GCC High became the de facto because it’s built on the back of DoD M365. The reason primes jump to it is because that’s what the DoD was using. The reason subs jump on it is because that’s what their primes are using, and they want little to no friction between each other when communicating on Teams, email, documents, SharePoint. So it’s been largely adopted just because the DoD did it first, when DISA did their move, and then all of a sudden the primes are like, “Oh, we want to get in on that, make sure we can collaborate easily.” And then boom, subs are like, “Well, we want to collaborate with the primes easily, so we’re going to go ahead and jump on the GovCloud too.”
Jacob: Well, and prior to CMMC ever being a thing, when there was just DFARS 7012, Microsoft was the only cloud service provider that stood up a cloud enclave that would reciprocate the incident reporting and data retention requirements in DFARS 7012. That’s why they created GCC and GCC High — because when you experience a CUI incident, DFARS 7012 says you need to retain the data and make it accessible to the DoD when they conduct their investigations, like in a SolarWinds, an OPM hack, Sea Dragon, or any of the various catastrophes that have happened over the years. They won’t do that in commercial. They will not reciprocate that requirement in commercial. So they stood up these environments. So it has nothing to do with CMMC. DFARS 7012 incident reporting requirements aren’t in CMMC — they’re in DFARS 7012. So you still have them right now, even if CMMC didn’t exist. And so if you are trying to use a cloud environment, and that cloud environment will not reciprocate DFARS 7012, you can’t use it. Nothing to do with CMMC. Turns out it was the only thing that would really do that for years. And so people then associated “I need GCC High for CMMC.” That’s not really what happened, but people have sort of conflated the two. That’s just what we do in this space. And these days, commercial doesn’t support FedRAMP. So you double can’t use it.
Daniel: Can’t triple-stamp a double-stamp there, Jacob.
Jacob: “Once you pass your official CMMC assessment, is there a list of items that will trigger the need to have a reassessment? What is the official guidance?” Daniel, your favorite question.
Daniel: I love some PowerPoints, let me tell you, guys. So here’s a little bit of a conundrum. Now, I’m not a lawyer — Jacob and I will be speaking to a lawyer in like half an hour — but we are not lawyers. Like and subscribe. Inside the actual CMMC program, 32 CFR, where it points out specific guidance, basically through the scoping guidance it references: if there’s any kind of significant architectural or boundary change — like expansions of networks, mergers and acquisitions — guess what, you need to get recertified, or you need to do a reassessment if you’ve done a self-assessment. However, the DoD CMMC FAQs, which as far as I can tell are not legally binding guidance — there’s no contractual obligation to follow the FAQs, but C3PAOs do follow them, and there’s no mechanism here — this is where it gets a little bit of gray area. Maybe our buddy that Jacob and I are talking to can clarify this legally. But if you look at the additional oversight given — this was in May of 2026 — they basically said things like moving from a control that was non-applicable… so think paper copies of CUI, because you had a VDI enclave, and now all of a sudden you’ve extended the boundary, so now you have to meet physical media requirements — you have to meet that control because you actually have to meet it, not because it wasn’t applicable anymore. They’re saying that is a triggering of a recertification/reassessment, depending on what you’ve done so far. Things like upgrading from FIPS 140-2 to 140-3 — not a problem. Run it in your operational POA&M, get it updated, call it a day, not a significant change. And then they basically added this: a careful evaluation by the affirming official, where it’s like, hey, if you’re adding a bunch of new types of systems to your boundary, you need to figure out if there’s enough of an overlay or not to trigger that certification or reassessment requirement — whether that’s self or third-party certification, depending on what you’ve done. So here again is the conundrum: the CMMC program says there’s scoping guidance; scoping guidance says significant architectural or boundary changes; and then the DoD FAQ, which is not part of the CMMC rule or even supporting documentation, provides some extra clarity. The question is, do you actually have to follow this as a filter set to look through, legally? Now, everyone pretty much is, by the way. But it’s an interesting little issue that I could foresee having to be contested at some point in the future — around whether someone had to get reassessed or not based on guidance. So there you go.
Jacob: Antonio says, “Maybe there will be a phased step-up to Rev 3.” I assume that’s what the interim final rule that they opted not to keep pursuing after it was written was going to say. What is the plan for the transition to 800-171 Rev 3? So if they do this — I’m telling you right now, I will stream it live on camera, my hair might grow back — if we get through this review and they come out the other end and go, “We’re going to transition to 800-171 Rev 3 and do all this stuff,” and the description of their plan is literally what was in the unified agenda for the rule they had before the pause — my hair is going to grow back just so I can tear it out again. Fun fact about Rev 3: you know who doesn’t have a phased rollout for Rev 3? The FAR CUI rule. There is zero requirement to have phased-in scheduling. That is a courtesy the Department of Defense gave to contractors. Remember, the entire reason they had the program is because they knew contractors weren’t actually complying. And they said, “We’re going to come and make people prove it, but we’re going to slowly phase in the amount of time we give you in order to make you prove it, because we know you haven’t done it.” The FAR Council doesn’t have to deal with that, because they’re like, “Yeah, defense contractors are already doing it, because they said they’re doing it, and this is a new requirement for federal contractors, and if you can’t do it, don’t bid on the contract.” They are under no obligation to give a phased rollout. So I don’t know what the DoD’s plan is here. Let’s just say they say, “Okay, we’re moving to Rev 3 with a phased rollout,” and the FAR CUI rule comes out with no phased rollout. How do you deal with that?
Daniel: Yep. That was supposed to be taken care of with the interim final rule that you put in the shredder.
Jacob: Yep. All righty, last question here, we’ll wrap up. Cyber Ninja says, “Europe has projects that require similar controls of CMMC. Any thoughts with having these users in our GCC High, as long as there’s logical separation between CUI and European projects and people?”
Daniel: So there’s no issue with having non-US persons interact with CUI, assuming it’s not export control data — and this is the big gotcha. We have a ton of large international companies that have non-US persons in their GCC High instance. And the data they can access is basic CUI, or really just CUI without export control requirements. And then they have logical separation — security groups, site containers, etc. — for the export control data, and they do all of that through attribute-based access control. So inside their HR systems, they check a box saying “not a US person,” which provisions the Entra ID or AD and replicates appropriately, and then they have dynamic security groups filtering these people out on what they can and can’t access. So, not a problem at all — as long as there are no European sovereignty requirements. And this is where the big gotcha happens all the time. Certain European countries also have data sovereignty requirements. GCC High is only sovereign inside the US. So you’d have to have an appropriate export control license from that European nation in order to put that data inside GCC High. That’s why, a lot of times, we see a GCC High instance for US sovereign data, and then CMMC requirements bound around that, and then people having to go on-prem if the same 7021 obligation is following overseas contracts that have been awarded with CMMC requirements — because FedRAMP doesn’t really exist outside the United States. So that’s the conundrum and friction, and with Microsoft commercial dropping their FedRAMP authorization, it becomes a little problematic. So there you go.
Jacob: All right, everybody, clear as mud. There are more questions now than we’ve ever had before. Everybody’s waiting with bated breath through the summer doldrums to figure out what the DoD’s plan is. So if you want to keep up with all the news and all the speculation about what’s going on, make sure you like and subscribe. We do this livestream every Friday at the same time. So if you find this afterwards, you can add your comments and questions to the chat, and we’ll add them to the queue. You can tune in live and give us your questions in the chat. You can go to cuihotline.org, fill out the form — especially if you have a longer question — call the number and speak your question into the phone, and we’ll play it on the air. You can DM us. You can find us at summit7.us. We’ve got other podcasts on the channel that go into other topics as well, so make sure you like and subscribe to that. Thanks for participating and being on this wild and crazy cyber regulatory adventure with us. And we’ll see you next week.
Daniel: See y’all.
Contact
Speak With Our Team
Our team of compliance and cybersecurity experts are on standby and ready to help. We’ll walk you through what you need and what to expect.
