The GIST of Govt IT

A Pause, Not a Pass on CMMC

Season 1 Episode 14

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 23:43

On July 13, the Department of War hit pause on one of the most consequential compliance regimes in the defense industrial base. In Episode 14 of The GIST of Govt IT, Brian and Sean break down the suspension of CMMC Phase II — the third-party assessment requirement that was set to take effect November 10 — and what it actually means for the thousands of contractors caught in the middle. Sean's message is blunt: this is a pause, not a repeal. The requirement to protect controlled unclassified information isn't going anywhere, and the smart move is to keep marching toward NIST SP 800-171 compliance regardless of what the 60-day CMMC Reform Task Force recommends. The conversation digs into the real economics that triggered the review, the False Claims Act lawsuits already settling in the six-to-eight-figure range for contractors who attested to compliance they didn't have, why ISO 27001 is the closest on-ramp for commercial companies new to the space, and a clear Monday-morning playbook. Plus, CISA Director Nick Andersen's hacker name (hint: he's a Matrix fan).

Resources Mentioned in This Episode

The Core Story

Legal & Advisory Analysis

Standards & Frameworks Referenced

Compliance & Assessment Concepts

The False Claims Act Angle

The Hosts & Show

CONNECT WITH US

Got an idea for a future episode? Want to be a guest? Let us know.

Brian Lake - blake@swishdata.com

Sean Applegate - sapplegate@swishdata.com

Subscribe wherever you get your podcasts: Apple Podcasts, Spotify, or gist360.com.


CMMC Phase II Gets Paused

Brian Lake

On July 13th, the Department of War hit the brakes on the rollout of CMMC Phase II, which included the third-party cybersecurity assessment that thousands of defense contractors were scrambling to meet by November. And if you're a small business owner, your first reaction was probably relief. But before you celebrate, Sean's got a message. This is a pause, not a repeal. The requirement to protect sensitive defense information isn't going anywhere, and the companies that keep marching towards compliance are probably the ones who will come out ahead. So what should you actually do over the next 60 days? To break it all down, you know what we gotta do. Let's get down to the gist of it.

Quick Catch-Up

Brian Lake

Hey, I so it's I we apologize to all our listeners. Today's Tuesday. We uh Sean and I had two customer events, quarterly business reviews, and a 20th anniversary party on top of a wedding, I think you were at this weekend. So we uh we're a little late in getting the podcast out this week. Uh better late than never, as they say, right, Sean? Absolutely. All right, Sean, before we get into the program, uh today we're not going to be talking about those actual events, those just events that we were asked last week with CISIS director Nick Anderson, as well as some folks from Department of Transportation, Department Award. That'll be next week's show. But I have to ask you, you know, tell the folks, we we talked about it last week. What did Nick Anderson say when you asked him what a cyber hacker name would be?

Sean Applegate

Well, hey, Nick was a good sport because we dropped him on him last minute in a room full of probably 200 people. And he he said, Hey, give me a hot second and I'll be prepared. So Nick came back with uh you know something related to Neo, as in The Matrix. He's uh obviously a nice sci-fi fan, like many engineers, and he thought something related to Neo would be his hacker name. So he's got to do a little bit of work to refine that, but we're in the ballpark.

What The Suspension Actually Means

Brian Lake

Nice. Well, we'll make sure that next time we talk to him, we'll give him a little more heads up. So uh, Sean, listen, uh big not only was a big week for us last week, there was a lot of news happening in the space, and that's to what we're gonna talk about today. So just over a week ago on July 13th, the Department of War announced that they are suspending plans to introduce phase two of the Cybersecurity Maturity Model Certification Program, uh, which the CMCC uh requirements for phase two was those third-party assessments. Um, and those were gonna be due on November 10th of this year. And they announced that they're going to do a sweeping review of the program. So talk to us a little bit about what does this actually mean. Uh, give us the straight, the straight read on this. Tell tell us about kind of the ins and outs of what they said, what they didn't say, and let's start talking a little bit today about the how do we read into what the next steps are going to be.

Sean Applegate

Certainly. Yeah. So first step, it is not dead. As many of us might prefer it to be. It is not. It is suspended. That's the key point. Okay. There have a they have a group pulled together. They posted an RFI on Sam.gov. So feel free to go there, provide your input and responses back. They're looking for input on what works, what doesn't work, and why. But really, the whole spirit was in streamlining acquisitions, getting new innovative companies to work with Department of War. I think some of the pushback was, hey, if I'm an innovative startup in the valley or if I'm a young startup, you know, I don't have $100,000 or $115,000 in a year to go work this program to become compliant. I need to be able to work with you today or next week. Right. Right. And this creates a really big hurdle for a lot of small innovative companies to just work and engage with the Department of War. So they go, hey, I'm not going to go do it. I'm going to go focus on where there's real money and I can engage a market that's ready to work with me and meet me where I'm at, not make me jump over this very high hurdle.

Brian Lake

Right. So just walk us back though. Phase one, what was required under phase one? And then what was required under phase two?

Phase One Versus Phase Two Requirements

Brian Lake

Yeah.

Sean Applegate

Effectively under phase one, you had to do a level one self-assessment to get ready. And in phase two, you you in many cases need to do a level two self-assessment or get a third-party certification. That third-party cert could be required in many acquisitions that are coming up this quarter by the Department of War. We've certainly seen some of those with our organization where they required at least self-certification. So there's a lot of people asking in acquisition documents right now around getting that done. So, you know, a lot of companies leaned in early to try to get their third-party certification for level two completed. So they're ready if it does pop on an acquisition. There are a lot of companies that are have done their self-assessment, are kind of waiting to see what actually comes out on acquisition requests to see kind of whether they need to make that further investment or not.

Brian Lake

Right. And I mean, when we talk about um third-party assessors and the self- and the self-assessments, uh, I think I read the statistic was we're talking about thousands of contractors who needed to do these assessments, but there's only about a hundred third-party assessors. So the calculus doesn't seem to add up at this stage. Is that is that an accurate statement? Yeah, I think I think that's pretty accurate. Yeah. Okay. Well, but realistically, this is the second review of this CMCC program in five years. The Biden administration did one in 2021, and it was the same rationale. We have to look at the impact for small businesses. You know, why this whiplash? Do you buy the reasoning? Um, I mean, truly, we're a small business. We were going through it. I mean, I think you were pretty excited last week when you heard about depositing the program. Uh, so I mean, is this I mean, this is actual reasoning, right? I mean, this is this is something that's really affecting uh small businesses from a financial standpoint, from a manpower and a resource standpoint. Yeah, absolutely.

Why CMMC Costs Hit Startups Hard

Sean Applegate

So let's so let's step back, right? You have about 110 controls that have to be met. They can't be partially met, they have to be fully met to be compliant. So it's a pretty high bar. You're you're effectively fully compliant with NIST uh SP 800-171 Rev2. And so it's been out for a number of years. There's a lot in that. If you're if you've been around federal and you only do federal business, that's not a uh an impossible bar to pass. You should have most of that done or be skating towards having it done. The challenge normally is if you're an earlier stage startup in a tech company, you have to now accept flowdowns in many of those contracts. Those flowdowns might mandate CMMC requirements to the OEM tech vendor, not just the prime contractor. And so that creates a lot of fallout when you think of all of these other small tech companies that want to work with the Department of War, but now because of contractual flowdowns, that they must accept because of secure supply chain risk management reasons. You have to, you have, you can't not accept it. And that creates challenges. And it's and it takes them a long time to do that. In most cases, they're also not operating and often not directly handling controlled unclassified information or controlled technical information. They may be in time, but initially they've never done that before. So this feels very alien to them. So if you go to a small startup like that and you say, hey, look, to work with Department of War, you got to get this level two CNMC cert. It's gonna take you, I don't know, three months to a year because your CISO has to audit and they go, well, we don't have a CISO. We have this guy that runs IT. We have a guy that's a part-time IT guy, but he really writes code all day long, right? Or he's our CTO and he has some part-time guys working for us. So that's where it gets challenging. Not that you shouldn't be doing that stuff, but that's the reality of a startup. And so that cost to do a level two C3 PAO audited environment is typically about $105,000. When you think of maybe some increased software costs on your side, some third-party audit costs, which could easily be in the $50,000 to $80,000 range just for the third-party audit, which you have to do every three years. And then any other small changes. Good example, you might be running your favorite ubiquity SOHO firewall, you know, wireless gear at home, but you may need to make sure you can encrypt C UI CTI end in with a FIPS compliant algorithm. And you may go, well, if I have a small office, we have a shared password. Well, you can't, when somebody leaves that office and they leave the company, they have the password. Now somebody outside the organization has your Wi-Fi password. And that may be in scope. You may want to go make sure you're doing certificate-based auth auth for your Wi-Fi. You have to go set that up, configure it. It's uh most small end Wi-Fi doesn't support that. So host stuff doesn't. So you could go by like a real Wi-Fi, you know, like Aruba AP or a Cisco AP, and then some certificate-based auth server integrate with your certificate authority, which again, if you're a small startup just using some third-party Google workspace, you probably don't have a certificate authority set up to do certificate-based auth. So you can start seeing there's this a lot of work that you have to do to be fully compliant in many cases. And so if you're doing, you know, get up gotta go past the assessment, there's a bit of consulting work up front too. So if you're a small company new to this space or a new tech startup, you might have another hundred or two hundred thousand dollars of consulting time and other IT costs and just personnel resource time internally, right? On overhead to go get that all done before you do your audit. I mean, that's the bottom line. But at the end of the day, right, you still have to do yourself a testation. You need to make sure it's accurate and it's and you meet it. So you still have to go do the work. If you can save on the third-party audit and still be just as secure, that that's a great place to be.

Brian Lake

Right. But this is also the reason the program exists is is an absolute necessity in the space, right? You just mentioned if you just rely on um administrative passwords, you you're you're opening yourself up to vulnerabilities. Uh there the the program exists for very important reasons overall, right?

The Real Threat Model Behind CMMC

Sean Applegate

Absolutely. Yeah. So the program exists to handle controlled, unclassified information and controlled technical information appropriately. And and in large tech companies where they have international presence, you might want to make sure you can isolate that off to U.S. citizens only that are working the actual program. So it's least privileged user access and isolated and controlled. Um, and you get to think about how does that CTI come into my environment? Do I capture that on just emails? Does it get recorded on Zoom meetings or team calls? Are those recordings transcribed by some AI system? Where does that information go? Um, and so you do need to think about how you absorb that and how you protect that information. The intent of the program is to control that information that's sensitive to design things like weapons platforms or um sensitive application architectures and other information on top of that, or a what's when you might consider critical infrastructure as part of an organization. Think of building out arsenals and depots, and you're a civil engineer and you have a lot of um engineering drawings for what is on a base. That's all extremely sensitive stuff that an adversary would like to get their hands on to. And the weak underbelly of our cybersecurity systems are being attacked. So when you think of uh an adversary, you don't need to attack the Department of War directly. You might go attack the integrator doing the HVAC work at a base of interest or on an island in the Pacific, or maybe their electricity provider or somebody that delivers, you know, handles other things like uh fixes the buildings on the base and has access to the diagrams that you want to get access to. And as an Intel guy, this is the kind of stuff I did in the Marine Corps for deployed and we did for training exercises. You would be shocked with what you can find if you just dig around a good bit and know where to go to get blueprints. Um, and if they don't check your identity, you can get amazingly good access to information as somebody that's done this firsthand.

What To Do During The 60 Days

Brian Lake

Right. So the Department of Wars, again, this is a pause and a reevaluation about the path forward. Uh, for organizations that are looking at this a week a little later, talk to us a little bit about what if you're a small business or a startup or and or you're a uh a CISO or a IT a cybersecurity IT director for a large prime. What are you doing now? What what's the next steps for you? Do you keep moving forward? Do you keep uh planning for what you expect will happen? How do you read the tea leaves and what you what you should be doing um now, or do you just sit back and wait for further guidance for the Department of War?

Sean Applegate

Yeah. So so again, this is a pause, a 60-day pause. They're gonna come back with some guidance that'll be more specific. That guidance will not be, hey, don't worry about security, we're all good. Right. Right. It's going to be, hey, you probably need to do a self-assessment. There may be some third, some more industrial standards that they may reference and respect that you could work work through those. We'll talk about that in a minute. But if you're a small business owner and you're or you haven't done your level two self-attestation in the SPRSS system, you should probably knock knock out at least level one if you're not done with level one, knocked it out first, get fully compliant, and then work through your level two compliancy and be tough on yourself. Um, there are lawsuits in play now, and some that have been settled for anywhere between six and eight figures for the False Claims Act. So don't put yourself in an uh awkward position to claim compliance on paper, but not actually have it in place. The Department of Justice has definitely sued contractors because they claimed they had compliance on a contract and they didn't. This is, and this is before CMMC was fully in place. So don't claim something you don't have. So be truthful, have a high degree of integrity, go put those security controls in place to your best of your ability, get some third-party help if you need it. You're not in this room, you know, go pay for third-party CMMC consulting firm or good cybersecurity firm or some managed security services, if it makes sense for you to do that, if you don't have those skills in-house. So work towards your level two self-assessment. That'd be my near-term recommendation. Um, there are if you're a technology company and you haven't started the process yet, and you're a new start, you know, new tech startup, or you're a company that wants to work with DOD but hasn't done that in the past, you know, consider getting your ISO 27,000 one. That's probably your your closest comparable. That's an industry standard that's accepted globally, that you'll probably see industry recommending the Department of War to align with from an industry standard. So we don't create duplicative cybersecurity compliance requirements for commercial entities that want to work with the Department of War. You'll still need to eventually comply with the NIST SP 800-171, Rev2, or potentially Rev3, which is is already out. It's slightly different, but most of the controls map. Um, so work on that. You're gonna need it for the federal civilian executive branches, anyways, and you're gonna accept that on your contracts, anyways. So get compliant with that. You could have a plan of action milestones. If you don't really have anything met, you can you can say, hey, I've got 109 of 110, but one is not done, for example. So there's a little more leniency on the federal civilian executive branch and what we report from that perspective to our primes versus the CMMC, which is black and white. You either have it or you don't.

Brian Lake

So if you haven't gotten level one done, keep moving towards that, absolutely, right? And the Department of War said, give us feedback. We have an open period of comments. We're looking for you to provide us information on how we should continue to evolve program, right? So actually go and provide that feedback while also continuing to move towards that level two compliance, is what I'm hearing from you.

Sean Applegate

Yeah, absolutely. So so again, the level two compliance for CMFC is nothing more than the NIST 800-171, which if you're working with civilian branches they want you to meet anyways, they just don't require a third-party audit. And so keep in mind you you've got DFARS compliance that you have to be aligned with, and the DibCAC, who is the auditor for the defense community, could show up at your door and complete an audit and want to see all the proof for 800-171, anyways. And so you need to have that ready to go if you're a contractor. Again, if you've been around doing this a long time, you're probably good. You're comfortable with it, you've been doing it a while. If you're new, those are things just to be aware of. Go work with your trusted, you know, cybersecurity consultants or your legal firm. If you have a lawyer that you want to leverage for some of the stuff on a GovCon level, they're just much more expensive. But they'll give you the right advice and they'll get you to where you need to be.

Brian Lake

This falls uh, and just help me and excuse my ignorance for a second here. So this you know, this period will fall right around the end of the fiscal year. Is there any concern that um they will revert to say the current program is valid and then there will be requirements for acquisitions that you know you need to have this level two compliance? I mean, is that something that may be real or something that you should be concerned about?

Avoid False Claims

Sean Applegate

Uh I mean, I we are seeing solicitations live come out, certainly querying your CMMC level and what level you're at. There are competitors that are in the space that have completed their level two third-party certification already. We may not see the third-party cert requirement on solicitations since they've walked this back a little bit or paused it potentially, you know, paused it primarily. I expect you will see a CMMC level two self-assessment requirement on a number of solicitations. So again, if you don't have that done, I'd say that's your target you want to hit. That's pretty obvious and likely to hit real solicitations. Um again, if the program goes away completely, that could change. But I think if you're if you're if you've if you're you know you're tracking stuff right now, that's the easiest target to plan for and to shoot for in the next 60 days and feel very safe about being able to do business in the Department of War. Right.

Brian Lake

So it can't hurt you to have that competitive uh advantage here by being compliant with level two or I mean having it done by uh you know, your your audit done by a third party assessment.

When Third-Party Audits Still Make Sense

Sean Applegate

Yeah, well that and that's probably the real question is if you if you have not paid for your third party assessment yet, you probably don't want to start it. That's gonna cost you 50 to 80 grand. You you probably don't do that unless you have a giant solicitation you're confident is gonna require a third party assessment, which which they may not. If you if you've started it and you're part you know you're you're well down the path, you may want to just see that through and get it done. You've already sunk the cash on it, you probably sunk most of the work. Just work through it and punch it, punch it home would be my recommendation. Um we've got a sister company we know pretty well, and they're they're 75% of the way through, and they're like, yeah, we're just gonna wrap it up, get it, have it, and we're good to go. And it's good for three years based on the current uh program. So they won't need to do it down the road if they if if it goes away. If they keep it around, they're just that much further ahead.

Brian Lake

Right, right. Well, I mean, it it it sounds like to me that this this is this is in alignment with the administration's priority to really rapidly bring new technologies in into the ecosystem to be on a, for lack of better words, a wartime footing uh in that we want to get the best technology into the ecosystem as quickly as possible, and we want to remove those roadblocks uh that could be potentially delaying or inhibiting those technologies and those companies into the space. Um is there anything that you that if if you were to look at it, is there anything that strikes you that could catch the industry uh community off guard uh about this review, or something that you would be surprised if they took a different pivot or a path around this?

Sean Applegate

I mean, there there's nothing obvious jumping out at me, but again, the the the reasons behind why we need to secure the organizations aren't going away. The why still exists. The attack vectors and the verocity of those attacks are only going to increase. And so the bottom line is keep doing good cybersecurity practices. If you're a young startup, go build those things within your organization and protect your intellectual property. If for no other reason than Department of War, do it for protecting your own intellectual property so you don't lose your source code. That certainly has happened to a lot of technology vendors over the years. Some of that was was nation-state actors, many of it were just hackers that wanted to grab your code and reuse it and steal it or ransomware you. So those reasons aren't going to go away, they'll just get worse. Um, you're still gonna need to maintain 800 171. So again, work towards level two and 80171. That that's a no-brainer. And then probably if you've got cycles and a desire, respond to the RFI or join a listing session if they have those. But I mean, maybe make sure you that you walk a fine line and you're you're ethical in what you do and you report what you actually have in place. Don't put yourself at risk from a false claims act perspective. That's gonna be something you don't want to do, that certainly has a history, at least more recently, of being held accountable for.

Brian Lake

Right. So just to just to recap here, realistically, if you're already down the path, keep down that path. If you've sunk those resources and those costs into this assessment or to the third-party assessment, just see it through. Um, keep driving towards NIST 800-171 as a guidepost for what good looks like and what you should be getting your organization into compliance with. If you haven't uh submitted comments, join the RFI, submit and participate in the listening sessions. And as you mentioned, I think the manager exposure. So make sure that you can back up that score, that back up that compliance. Don't just say you're compliant and and not actually be in compliance. Anything that I missed or that that that I missed on the recap there?

Supply Chain Security And Final Takeaways

Sean Applegate

No, I think you know, I think the the the other maybe uh hidden thing in a room that's not in the Department of War statement, but you've seen in other executive orders more recently would be make sure you have a secure supply chain. So manage your supply chain risk that can look very different to different types of organizations. Um but you know, if you're sourcing software from places that aren't maybe TA compliant, make sure you're inspecting the code, protecting it, hardening it after you get it. Um, but be careful where you're sourcing your materials from, whether that's chips, software, hardware, minerals, um, or other components you use to build weapon systems. Right.

Brian Lake

Well, I mean, listen, this is a fast-moving story. A lot of things happening in this space right now. Of course, the end of the fiscal year is rapidly approaching. I know this is top of mind for a lot of folks. So we'll obviously be talking about this further over the next couple of weeks. I'm glad we were able to jump on uh and talk about this a little bit today. So a lot of the both the memos, the uh the notices, the uh RFI information will be in the show notes. For any other information, go to gist360.com. John, I'm excited for next week's show to talk a little bit about those panel sessions with government speakers that we had last week. So stay tuned next week for those shows. And obviously, keep trucking forward, keep moving forward, don't slow down, don't just wait for new guidance. So uh more to come in this space. And obviously, Sean, always good to talk to you, my friend. We'll catch you next week. Talk to you soon, sir. Hey, take care, have a great time.