CHPS of Insight: Policy to Practice

CHPS of Insight Episode 10: Cybersecurity and the Defense Industry

Clark Hill Season 1 Episode 10

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 50:54

In this episode of CHPS of Insight, host Ron Sullivan speaks with David Fraley of Secure IT Service Management to discuss the Cybersecurity Maturity Model Certification (CMMC), ongoing compliance obligations for Department of Defense contractors, and The Department of Defense pausing the Phase 2 requirement tying contract eligibility to C3PAO certifications. 

Together, they explore industry concerns about cost, limited assessment capacity, low compliance across the defense industrial base, and increased legal risk from misrepresenting SPRS submissions under the updated CMMC reporting tab.

This podcast is intended for general informational purposes only and does not constitute legal or financial advice or a solicitation to provide legal services. The information in this podcast is not intended to create, and receipt of it does not constitute, a lawyer-client relationship. Listeners should not act upon this information without seeking professional legal counsel. The views and opinions expressed in the podcast represent those of the individual speaker only and are not necessarily the views of Clark Hill PLC.

SPEAKER_00

This podcast is intended for general informational purposes only and does not constitute legal advice or a solicitation to provide legal services. The information in this podcast is not intended to create, and receipt of it does not constitute a lawyer-client relationship. Listeners should not act upon this information without seeking professional legal counsel. The views and opinions expressed in the podcast represent those of the individual speaker only and are not necessarily the views of Clark Hill PLC.

SPEAKER_02

Hello everyone, and welcome back to Chips of Insight, where we bring policy into practice. I am your host, Ron Sullivan, Senior Counsel here at Clark Hill PLC, and Senior Director in Clark Hill Public Strategies. I am very happy today to have an expert in the field, a government contractor himself, and a CMMC advisor to many. CMMMC. Four letters that means something very important to every government contractor and to the federal government, especially the Department of War, Department of Defense. I will let our guest introduce himself and explain what each of those four letters mean.

SPEAKER_01

Hi, Ron. Thank you for welcoming me to your podcast. My name is David Fraley. Um, I run a company called Secure IT Service Management, which is a division of a company that my wife and I own called Paragon Solutions Inc. Secure ITSM is a CMMC managed service provider. And so we go in and we help people through the entire process. We maintain their IT, we help them through the assessment, we provide a full service. A little bit of background about me. I'm 25 years in the Army, a retired signal officer. I have several certifications, including CISSP, and have been doing IT and cybersecurity long before it was cool to do cybersecurity. It's now quite cool to do cybersecurity. So thank you, Ron. And tell us what CMMC stands for. Cybersecurity Maturity Model Certification. It's the DOD's attempt to enforce cybersecurity hygiene focused on the NIST 800-171 standard. Right.

SPEAKER_02

Well, folks, like I said, we have an expert at Secure IT service management company who's one of the best in the business, and we've been working together for quite a while. Let me start by asking if you're a CMMC certified certifying company, is Secure IT SM certified?

SPEAKER_01

Yes, we are. We have been through a CMMC assessment via a C3PAO. We passed with a score of 110 out of 110. Our certification number is 216.

SPEAKER_02

So when we talk about CMMC and the Department of War order, tell me where that starts. When did the Department of War and the Department of Defense direct or order something special in the CMMC arena?

SPEAKER_01

CMMC is nothing new. In December 30th, 2015, the Department of Defense issued and propagated a DFARS Clause 252-204-712 that said that any vendor doing business with the Department of Defense must implement NIST SP 80171 Rev 2. Right. And there's some other requirements, but so for more than 10 years, every DOD contract, now Department of War contract, has required their vendors to be compliant with the SP 80171.

SPEAKER_02

Right. Now many companies over the last since of course 2015, and especially with a very heavy emphasis in this area in the last three or five years, were working toward CMMC certification. Of course, there are some self-certification opportunities built into the directives and the regulations, but there's been the C3PAO assessor requirement that had a November 10th, 2026 deadline in order to handle controlled unclassified information and higher information. And this week, the Department of War, Department of Defense issued a statement saying it was suspending that November 10th, 2026 requirement. Tell us about that and what that actually means with respect to handling controlled unclassified information and higher classified information.

SPEAKER_01

So just a little bit of background first. In November of 2025, they published an update to the DFARS that required it was a four-stage implementation process. Phase one required basically self-adestation that was for a one-year process. And in November of 26, the plan was to implement the first third of all DOD contracts to require a C3PAO certification before you could bid on contracts. The phase three, which would be a year later, would have been November of 27. The second third of all contracts were going to require it. And then finally, the November of 28, the final year of implementation. And so by the plan was for over the next three years, they're going to phase in where all contracts by the end of the plan, you could not be bidding on a CUI type contract unless you've been through a third-party assessment. So what the DOW did when they were really looking at this, they sit back and said, okay, where are we? Are we ready to go? And so they came in and on Tuesday they issued an order that really put everything on hold, right? Specifically, it put CMMC phase two third-party certification requirements on hold. You still have to be compliant, you still have to mint the 712s, all the NIST 80171, you still need to go into SPRS and file your reports, you're still required to implement all of the security. None of that changed. But the third-party certification requirement, and particularly the limitation that if you hadn't been through a certification, that you could not been on work, that was put on hold. And that has caused a lot of commotion and emotions, uncertainty in the whole contracting, the DOD contracting world right now. Certifications are not required. Compliance with the DFARS and NIST is required.

SPEAKER_02

Does someone have to go out and get a certification the way it was required before? Is compliance required with the NIST standard and the DFAR standard? Yes. So contractors, of course, must still comply with their contract requirements. They must still read their contract clauses and comply with them. And of course, the NIST 800-171 requirement is still out there in Lumen. All right, let's get real for a second. How compliant is the defense industrial base with 800-171 and CMMC?

SPEAKER_01

So I'm going to take that in uh two phases, right? First off, I'm going to say what was wrong with CMMC, and I'm going to look to an authoritative order for that, right? And the SBA on the 13th, also, same day as the Department of War, issued a press release and they came out and stated that one of their biggest concerns with CMMC was the cost and administrative burden on small businesses. The SBA estimated that a self-assessed, the time frame was not given, but they estimated a self-assessment was $389,000. I'm assuming that was over a several-year implementation window. I don't know if it's a three-year, a five-year, a 10-year, that I don't really understand yet. But $389,000, that's a lot of money for a small business. Further, they said that if you have to go through a 3PAO assessment, C3PAO assessment, it was going to be about $594,000. That's an incredible amount of money, right? And that is significantly differs what the DOD initially published in the Federal Register. The DOD initially said that to comply with, this is level two, to comply with a the requirement, they were saying about $37,000 for a self-assessment. If you had to go through a C3PAO assessment, it was $105,000, which is hugely different, right? Now these numbers aren't really apples and oranges. The DOD's position when they publish this information in the Federal Register, one of their assumptions says that since 2025, you've already had a contractual requirement to comply with NIST 800-171. Therefore, we're not going to put any cost assumptions into the model saying that you have to get compliant because you already have contracts, so you must be compliant. Very few organizations are compliant. I will say the SBA is correct. It's significantly more expensive than what the DOD has made in the Federal Register. The SBA's press release also said that it would restrict defense industrial base growth. And they are 100% correct on that. I've got several customers that are DLA and the DLA supply chain provides parts and goods to DLA. And one of them, which we're taking through a C3PAO assessment in the next month, they were looking at their business as it was going to skyrocket. They were estimating at least 50% of their competition would go out of the defense business because they hadn't been through an assessment. They weren't ready. And honestly, I think that's probably correct. Now, if you're a business wanting to get a competitive advantage, that's great. If you're the Department of War and you need to maintain a capability and grow it, that's not so good if half your industrial base leaves. So I definitely agree with the SBA, it would cause a downward growth. They said that they talked about the assessment capacity. They've estimated that 120,000 small businesses need a three C3 PAO assessment. And there's they said in the press release about 100. Uh the next day, the Cyber AB came out and said 110, so I'm going to say those numbers are really close. They also came out and said cybersecurity remains a priority. The implementation model is under review, and they're not saying, neither SBA or the Department of War suggesting that cybersecurity requirements will disappear. Nobody thinks they should. If you go and look at an F-35, and then you look at the Chinese version of an F-35, if you paint them the right colors, you think they're the same aircraft, right? You look at networking equipment. There have been incredible amounts of intellectual property theft from the United States and the defense industrial base that's been taken overseas. So nobody's saying that we need to reduce cybersecurity or not make the DIB secure. And they also talked about alignment with the Department of War's acquisition transformation system, ATS, that they want to replace compliance-heavy processes, deliver stronger cybersecurity, and faster acquisition defense capabilities. The SBA has come out and they really said it's very expensive. They've also said there's not enough C3 PAOs. Right now there's about a thousand CCA certified assessors and a hundred, 110 something like that, C3 PAOs, and 100,000 plus organizations that need to get certified. A little bit of ballmark math says that's probably a 20-year journey to get 100,000 businesses through that process. The Department of War can't wait 20 years to get, they can't wait 20 years to have a defense industrial base to meet their requirements. They've got huge requirements with all the recent conflicts and requirements have been placed upon them.

SPEAKER_02

That is very that what you just said was very enlightening. So one thing I want to recount is there's about a hundred C3PAO assessors out of the thousand companies out of the thousand assessors, and there are a hundred thousand companies estimated that need to be certified yet. So when we do the math, even if we did those one a week, that takes a long time to do.

SPEAKER_01

So there's about 10 assessors per C3 PAO on average, right? I'm sure the averages don't work at the highs and the lows, but about 10 per organization, which means they could do maybe two assessments simultaneously. The Cyber A B also pointed out that 2,000 certified defense contractors, there's 2,000 CMMC certified professionals. These are advisors and others that have gone through Cyber A B training to ensure a level of quality and knowledge across the certified professionals. There are uh 2,000 registered practitioners and 4,000 or 400 practitioner organizations, right? And 52 training providers. Well, the cyber B came out and said, hey, we've made a lot of progress. Not saying there's nothing more to do, but they did say that there's been a lot of progress made and they're correct. They also clarified that voluntary C3PO level two assessments are still ongoing. The Cyber A B also reinforced existing obligations to SP800, SP 800-171 and the DFAR 712 clause. And the SBA said the same thing, the Department of Awards did the same thing. So we're all all the authoritative comments are saying exactly that, right? And in general, the the Cyber A B is supportive of the CMMC framework. They suggested that the third-party assessment environment has reached a meaningful scale, and they emphasize the importance of independent third-party verifications. Finally, they encourage organizations to continue pursuing certification and to ensure that they're compliant with the NIST SB 800 171 despite the pause.

SPEAKER_02

How compliant is the DIB with 800-171 and CMMC?

SPEAKER_01

Ron, that's a great question. And unfortunately, my answer is not going to bring a lot of confidence to anybody listening to this podcast. I will acknowledge there are organizations that are compliant. There's 2,000 plus, at least 2160, because they give the number sequentially. There are companies that are very compliant, and there are companies that are partially compliant. Let's talk first about the technology implementation, right? There's some really hard items to comply with the 800-171 log file collection. That's a tough one, right? You got a firewall in your organization, and you need to collect transactional logs, security logs from your firewall. That's that is not an insignificant undertaking. Collecting all the logs, having a change management system so you track when you do changes. There are some really tough items to implement here. When I go through and sign up a new customer, so they come into our service. We have a very standardized model that we use. We're a Microsoft shop, we use Sentinel, we use Azure, we use Defender, and we have some enterprise grade MSP tools that we use to do some of the back end, some of the patch update, and all of that. But when I go through and say, okay, how compliant is this organization? I've not seen an organization that we signed up yet that would probably that would have a SPRS score that was positive. SPR scores range from 110 at the high to almost 200 as negative as you can get. And I would imagine that the average organization that I have looked at, that I have been into their environment, they were probably somewhere in a negative 100, 110. They've almost done none of the work, right? Most of them did not have a system security plan, which is an automated fail. No MFA, they turn on the base defender and say we're compliant. That's not even close. It's so bad. And if I haven't even seen 1% of the DIB, far below that, right? But if I had to guess, I would say 75 to 90 percent of the people reporting the SBRS score of at least 80 or 90, probably are actually at a minus 100 or so. So it's the department cannot relent on making people secure. And I'm not saying they are, they've already committed to pushing and continuing, but it's really bad out there. So what is a correct SPRS filing today? The SPRS filing has changed with the last year, right? Let me go back a little bit. The 712 clause has been in effect, it's still in effect, and I have no belief that there's going to be any back away from the 712 clause. That's what requires NIST SP8171 Rev2. In particular, the DFARS 252-204-712, which was back in November 30th, 2020, required to have a current SPR score before award, right? I can still run into companies that don't have a SPURS score and are still doing business with the Department of Defense, right? Contracting staff needs a little bit better training to make sure they go in and check that one. When you would go into SPRS and you're going to make a Spurs submission, you go in, you go to Cyber Reports, which is on the left-hand side, it's just right on compliance reports. And then you go to the tab that says NIST SP 800-171 assessments, right? And you go in, you click add a new assessment. A screen pops up, it asks for the assessment date, it asks for the score. You can put in any number, right? Doesn't matter. You can write in anything. You have to select a scope. Is it enclave, is it enterprise, or is it a geographic location based? If you have a plan of action completion date, you have to put it in. According to the rules, if you don't have a 110 score, you have to have poems. You need to have it, you need to identify your SSP, both the title of it, the version of it, and the date, and you identify your cage codes and you hit save. What was unique about this as opposed to the current, and I'll get to that in a minute, there was no when you go into enter your assessment details, there's no screen that pops up that says the warning banners misrepresentation may result in criminal prosecution or some variant of that. There's lots of variants of that. But we all click on warning screens and/or we're agreeing to the terms and conditions of a software license or something. There was nothing like that for the NIST SP 800 171 SS SPRS submission. You went in, you put your dates, you hit save, and then you would go in and you'd have your nice little scores, right? And I know that there are many companies out there that they didn't know what they were doing. They were just guessing.

SPEAKER_02

Self-assessments and getting assisted with a self-assessment, there's some level of rigor that a company should have to have someone assist them with the self-assessment if they're not going all the way to the certified C3 PAO provider. Is that what you're saying?

SPEAKER_01

That's correct. I would guess to make this just a guess, but I would bet you that 15 or 20% of all of the defense industrial base, the people that are responsible for making decisions about CMMC, don't realize that NIST 8171 is not assessed at the 110 controls, it's assessed at the 320 assessment objectives. You know, 3.1.1 has six AOs. If you fail any one of those AOs, you fail the control. And I'll bet you 20% of the DIB doesn't know that.

SPEAKER_02

Understood. Understood.

SPEAKER_01

On November 10th, an update to 252 uh 204 or a new one, 252.204.721 was publicized. This was the effective date of the 48 CFR, the final rule, right? And this one talks about a CMMC status. And I'm going to read the actual statement. This is out of 252-204.721. Uh, it is uh uh E.2, right? Enter into SPRS the results of a current self-assessment for each CMMC UID, not covered by a C3PAO assessment, and then it goes on to provide some additional information. And in order to do that, you do not go to the NIST SP 800-171 assessment tab in Spurs, you go to the CMMC assessment tab, and that's a new tab. You go back two years, that didn't exist. That was part of the rollout with the 48 CFR update.

SPEAKER_02

Tell us about that tablet.

SPEAKER_01

So you go to that tab and it use CMMC assessments, you click on it, and you have four different sub-screens under that tab. A CMC level one self-assessment, a CMMC level two self-assessment, a CMMC level two C3 PAO. So if you've been through and passed a C3 PAO assessment, it'll show up in there. Or a DIBCAC CMC level three assessment, right? And so you have to choose one of those if you to comply with the new clause. And so to do that, uh you click on the little box that says add new CMC level two self-assessment. Right. When you click on that, a new screen comes up. And I'm gonna read this verbatim. Warning misrepresentation of a CMMC compliance status to the government may result in criminal prosecution, including actions under section 1001, Title 18 of the United States Code, Civil Liability under the False Claims Act. And you have to acknowledge it. If you don't acknowledge, you can't go forward. Wow.

SPEAKER_02

So once you finish that, uh like you do when you fill out your taxes, I submit this under penalty of perjury. You've basically know that you could be in trouble, your company could be in trouble if there's false information presented here.

SPEAKER_01

That's correct. So if you say that you're 110 score and you click acknowledge, you go in, you fill out the form, say 110. And it's actually more complex than that, but you go through the acknowledge and you go through the submission process, and then the government comes back to you, and they have gone back to several companies and take them. They recently did one, and I'll talk more about this later, where they took a half million dollars from the company under the False Claims Act. This is gonna get serious. So when I'm gonna fill out the new SPRS, under the 800 171 tab, I go in and put a code, a score, right? 95, 110, minus 100, whatever it was, right? I just put a number in, hit submit, and was done. But when you do it now, they actually take you through 14 screens, one for each control family. Start at AC1, and you have to go through and you say MET. And then you go down to 1.2, 3.1.2, and you say met, you often say not met or not applicable. And so you go through this for all of the controls in each family. And when you're doing this, when you say I have met 3.1.1, that means you're also compliant with 3.1.1a through F, all six of the AOs, right? And so you're now certifying that you comply with all of those AOs. And so many companies don't even know that there are AOs, right? And in some cases, you can go in and say, give you an example, in IA 3.5.3, which is multi-factor authentication, you can meet some of the AOs and not others and get a partial, right? So they have partial credit, right? And you get a partial score. And so it's a much more complex system. And then when you get it all done and you submit, you can actually download a self-assessment report. And I have customers that are now getting requests from their contracting officers saying, I need that report, I can't give you an award until I get it. And then they have to go back and certify they're compliant. This is creating, this is why the entire CMC industry is saying, don't stop getting compliant. There are legal liabilities here. And the liabilities are real and they're not going to go away.

SPEAKER_02

Has DOJ gone after any of the bibs for falsifying their SPRS report?

SPEAKER_01

They they have, it's not a big number of organizations, right? The most recent was a logs.io government services, and they got 507,000 in fines from them. This is a pretty small business. I can tell you, if 507K came out of my bank account because I falsified a report, I I'd be working a few more years to help make that money up. And Georgia Tech paid $875,000. Uh Aero Turbine paid $1.75 million, Raytheon, $8.4 million, Health Net Federal Services, $11.25. They're the biggest. There's not a lot of examples. And if you're a gambling man and you're saying, I don't think the DOD is going to come after me and check me, you're probably correct. But is that really the way to run a business? Is that are we being good partners in the Department of War?

unknown

Right?

SPEAKER_02

That's a poor crafts bet, and you never know when that shadow is going to come over your shoulder. And that half a million to more could easily shut down a small business overnight. And they're still responsible, of course, for whatever the requirement is.

SPEAKER_01

Well, yeah, and I'm sure they go after we certify personally, so I don't think I don't think it's something that you can walk away from. I think that that's a judgment that even if you file bankruptcy at the business level, you're still liable. I'm not an attorney, but I'll bet you that the DOJ is going after both the person that certified it and the business.

SPEAKER_02

Understood. This has been very informative. I want to make sure I get some recommendations directly from you for both sides. Both if you are talking to CEOs and CTOs and owners of the DIB, what you tell them. And then why don't you you've been in this space now for quite a while and a career in this IT organization, as well as across the spectrum, what you would say to Department of War, Department of Defense officials. So let's first go with what would you tell Dib companies now?

SPEAKER_01

So the first thing I tell a DIB company, and I say this to a lot of organizations, you know, you gotta get compliant, right? You don't know what you don't know. How to capture a log file off your system and put that into a reporting system that can aggregate all the logs across all of your computers and your firewalls and whatever you might have, that's beyond the realm of 99% of all small businesses, right? But you got to get compliant, right? Submit a correct SPRS scores via the CMMC tab. Be honest. I was talking to a one of my customers, and he goes that their prior business, their CIO was a real honest guy. And when they started their path, they're not quite certified yet, but they're in queue to be certified. The CIO went through and did an honest score, and he said he submitted scores that it was hugely negative. I don't know exactly how negative, maybe a negative 100 or something. And every few months you go in and do another submission and it'd go up a little bit because we got another chunk done, right? Honestly, I think a contracting officer would rather see that than some fallacy that I'm 110 and I use AOL as my email, right? So submit a correct spur score in the CMMC tab. And when you hit that certify, be honest with yourself, you don't want to run the risk of them coming after you. Select a partner to assist you. I will tell you that I am biased. When we were going through and getting ready for our assessment due to some family issues and the loss of several family members, I had to bring in some CMFC consultants to help me, right? And to the one, I would say 90% of every CMFC consultant dollar I paid was a waste of money. Right? It just it was not worth that. None of them had actually been through, I didn't lead an organization that have been through an assessment. There are organizations out there that do that and that have been assessed and they know exactly what it's about, and I commend those. But all of these people that send out emails and say, I can help you. I've assisted a hundred people, right? 100 organizations get compliant. I if they don't have some real money in the skin in the game and have done their own assessment, I'd be very wary of them. For a small business, my belief is you need to select a CMMC managed service provider, somebody that's been assessed, that will support you not only in achieving your authorization, but to support you on the longer run. That that's my opinion. There's lots of good CMMC RPOs out there that that do a good job. Where I see the problems is on the back end. So you have a consultant, you come in, you pay them a lot of money, and you get get ready, right? As soon as you go through the assessment, you're everything changes. New employees are hired, new employees, employees leave. You have other actions that occur, right? You have continuous monitoring that needs to go on, right? Unless you have somebody that has built all of that into a model, like we did, it's really hard to be compliant. I would say be patient. 800-171 is not going away. I'm 100% convinced on that. So be patient. Is there a lot of emotion and turmoil and people saying, I just spent $100,000 getting ready for an assessment? It was a waste of money. I don't think it's a waste of money, right? But the number one thing that we tell all of our customers is make sure your environment's secure. I have talked to companies that have been through a ransomware attack, and you want to talk about something that's traumatic. Not only are you going to pay tens or hundreds of thousands or even into the millions of dollars just to get through it. You have your ransomware, but you're going to probably bring in a mitigation team. You probably have to bring in public affairs, people that can help you with messaging. You're going to have to call all of your customers and tell them that I just got hacked. You're supposed to report it, not everybody does, but you're supposed to report it to the Department of Defense. You they want to know you have 72 hours, right? You need a partner, but the be patient. Get yourself compliant. It's not going away. But in general, it's great business practice to be secure. The final thing I would tell them is don't wait, act now. This is not the time to stop.

SPEAKER_02

So that's for the I hope they're listening and take your advice to heart. If you were talking to Department of Award, Department of Defense officials, uh, what two or three tips would you offer to them?

SPEAKER_01

I probably got more than two or three. And I will be writing a response and submitting them as part of the process that they have established to receive industry feedback. But the first thing I would say about the CMMC model, it's basically a no-fail test, right? It's either pass or fail. It's not quite true, but only about one-third of your 320 AOs allow a POAM, right? So if you don't do something right and the assessor catches it, one out of three AOs cannot you fail. You very small number, right? And the ones that they do allow you to get a POAM on are the easiest to pass that almost no one fails. It's the hardest. What's a POAM? Sure, a plan of action milestone. Essentially, it's a get well plan. That means two-thirds of your AOs you cannot fail, right? You'll get a score, but you won't fail. If you don't have a system security plan, or your system security plan doesn't meet the requirements, and that case the assessment's over, you get no score, and you're you just failed, right? On the government side, both in uniform and as a contractor, I have done a lot of RMF and both DIBCAC, not DIPCAC, RMF, authority to operate processes, right? Where you would go in and essentially go through an assessment using 853, which is what 8171 is based on. But you would go in and do an authority to operate. So you go through exactly the same thing. You have third-party assessor assessors, there's security control assessor-validator, SCABE's. And the SCABE's come in, they're third party, they come in and they review all of your documentation and they provide the background. Yeah, it's a lot more flexible environment for the government systems than it is under CMMC. CMMC, you get a very small window to pass, right? Maybe make only the most important controls and AOs, what I call a no-fail, because if you fail them, you flunk, right? So the first thing I would say is loosen the assessment constraints. The next one is a technical recommendation, right? I have two. When we're going through and getting ready for our assessment, we were using a non-FIPS compliant, it was partially FIPS compliant, remote management tool. You go in, you can do bug patch updates. It's a really good tool. We like it a lot. So we were using one that was only partially compliant. We turn on the FIPS mode onto all of our computers, and we can no longer patch our computers. We thought patching was pretty important. Technically, it is, right? That's one of the controls. You need to patch them. And so we had to go out and the vendor actually had another product and we had to go through, and luckily, they actually gave it to us on a trial for about a year until the other product gets FIPS compliant. The PIPS one, I think that one could be waived indefinitely. The second one, they really need to put a permanent hold on implementing 800-171 Rev 3. Revision 3 significant it goes from it, it adds about a hundred new assessment objectives over 800-171 Rev2. It's way more complex. It has the Department of War specified certain values that need to be looked at. That one, Rev3, that would be a hugely more complex undertaking. I think 817 Rev3 needs to be permanently put on hold. The next item that I would say for the Department of War limits the FedRAMPI implementations. So I was talking to a potential customer this week, and they are a small organization. They do business with Defense DLA, Defense Logistics Agency. And they provide their small gears, they're just little cogs in the great big system. Honestly, the organization almost knows, never knows where these parts that they provide to DLA, what they go into, what they're associated with, right? But I was going through the contracts with them this week, and they had a no foreign ITAR requirement in the contract, right? In order to meet a no foreign, which is a FedRamp requirement, you go into FedRamp High. So in Microsoft's world, that's the government community cloud high. GCH has a much different pricing model than the government community cloud or the commercial cloud. GCC and commercial, you can pay monthly, right? So you don't you only pay it's $30, $40, $50 a month, depending on what kind of license you have. When you go to GCCH, you have to pay it once at one time. And so for this little company, they're looking at a license that was about $800 a user. And for that $800, they had 10 users just by the licensing. It was $800, right? If this were a weapon system, put them in FedRamp High, lock it down, right? Even if the weapon system data itself is not there. I that truly sensitive. Top secret contracts, put them in FedRamp High. I get that, right? This little company that was making little widgets, and for them to have to write a check for $8,000, that was just the licensing. We had our own cost to implement them. And then on top of that, you had the C3PAO, and that was a huge amount of cash going out. So limit the FedRamp High implementation. We could be smarter about that. Going on, my recommendation is to keep the third party assessment model, right? But I think you should allow self assessation forever, right? So I could self attest no matter what for as long as I want it. But since under ATS and acquisition reform, I would put at least a 10% weight in every solicitation that goes out. That if you have a C3PAO certification, you get an auto-immediate 10% of the total score given to you.

SPEAKER_02

Incentive for those who did the third-party assessment. And that would, of course, encourage those self-assessors to let someone else assess them so they would have a greater chance at uh contract award.

SPEAKER_01

And that could be baked into the next three years implementation model really easy, right? So instead of on year one, only a small number of contracts were designed. These are more critical contracts. But for those contracts, you say, okay. Now, some of them, again, a weapons system, a TS contract, they get a CMC cert requirement, the get-go. But for other contracts that were going to go in, just put in the selection criteria, the evaluation model, that CMC certification, that's 10% of the total weight. That'll get industry interested, right? That really will.

SPEAKER_02

So let me see if I can restate this. A company that has the maps of a military installation, because they're putting the roofs on a building or painting a building or doing landscaping or some basic IT wiring and they have no locations or whatever basic controlled unclassified information, you would say, hey, this is a risk that we could limit, as opposed to the difference of building an aircraft or where our drones are being shipped, or something like that's very sensitive. Those already require a higher level of certification. So a little different there. So here you're saying on the less sensitive, less important when I and I'm using that loosely, for the lower threat controlled and classified information contracts, your recommendation would be throw it into the contractor ward and let contractors push themselves up higher that one.

SPEAKER_01

Entirely. Yes. And then for truly sensitive ones, okay, if it's truly sensitive, we got to do it. That's just part of the deal. I have one final recommendation, right? So I think we need to make SPRS smart. Let's make Spurs smart, right? The current administration loves AI, right? It's been used all over and has made, in some cases, some truly beneficial gains for the country, right? So let's think about this for a second. When uploading SPRS to that warning banner, I would add a phrase that first says that this SSP complies or documents all 320 assessment objectives. That's going to shock people because again, they don't realize a lot of people don't realize that there's not just 110 controls, right? I would also require an SSP to have pictures in the document as evidentiary artifacts, right? Show me a picture of how you're doing Sentinel, right? And the coolest thing is I would require that when you submit your under CMMC and you get through all of your controls, go to the last screen and have to upload your system security plan, right? And then back to the AI, it would not be that hard. I'll bet you 60, 90 days. They could have an AI engine on the back end of SPRS that would look at SSPs. The AI could tell, okay, you just did a check mark on that NIST form that's 12 pages long. Okay, fail. That'd be uh you could email out automated compliance questions to submitters. If it's egregious, the AI can afford that to people for review and maybe even to the DIPCAC for a formal assessment. I think that would also, because right now you it's still basically just waiting for somebody to come and knock on your door and say, tell me about your SSP. Are you really compliant? We had to upload them into Spurs, and that'd be one screen and an AI engine on the back end. I don't see that as a big lift.

SPEAKER_02

Dave, I want to thank you so much today. All the information that you just shared was truly invaluable. You, the secure ITSM team, for letting us have your time here today and sharing that with the Dib, with government officials, with other folks out there trying to navigate this very sensitive and complex topic that some people think is really simple and easy. It's not just pressing a button and keep going. It's not just clicking yes or entering 110. You really gave us some valuable tips there. One last parting shot for everyone. If you had to wrap anything up, there's one thing that you want everyone to know about things that you said today. What would that thing be?

SPEAKER_01

Get compliant one 800-171. You gotta do that. Get compliant, do something, do it yourself. Bring a MSP, bring in a consultant, do something. Doing nothing is a great big risk.

SPEAKER_02

Dave Fraley, thank you so much and the secure ITSM team. Everyone, my name is Ron Sullivan, senior counsel here at Clark Hill PLC and senior director of Clock Hill Public Strategies.

SPEAKER_00

This podcast is intended for general informational purposes only and does not constitute legal advice or a solicitation to provide legal services. The information in this podcast is not intended to create, and receipt of it does not constitute a lawyer client relationship. Listeners should not act upon this information without seeking professional legal counsel. The views and opinions expressed in the podcast represent those of the individual speaker only and are not necessarily the views of Clark Hill PLC.