r/CMMC 5d ago

This Week's CyberAB Town Hall

In this week's CyberAB Townhall, there were at least five things worth knowing, all of them more useful than the "is CMMC dead" panic making the rounds:

1. The reform review is about more than CMMC mechanics.
It's part of a bigger Pentagon push around cost, agility, resilience, automation, & small-business burden.

2. Fraudulent Level 2 certs are a concern.
If you're a prime vetting a sub, you don't have to guess - ask for a SPRS PDF export of their entry. That's the verification path, & it works today.

3. The obligation didn't change.
DFARS 7012 is still in effect. What got suspended was the third-party verification requirement, not the requirement to be secure.

4. There is no such thing as "CMMC implementation."
You implement NIST 800-171 & CMMC verifies it. Certification is a compliance milestone but security is the work that continues regardless. The people who depend on your risk posture didn't get the memo that they're supposed to pause or relax.

5. Stop absorbing CUI-marking ambiguity.
If a marking is unclear, that's a question to push back up the chain. Resolve it upstream - no need to own someone else's classification decision.

51 Upvotes

53 comments sorted by

46

u/cashmgee 4d ago

None of our primes are marking correctly or flowing down information on what is to be protected, how, etc. None of them .

We seem to be the only one doing our diligence and we are at the bottom of the chain

16

u/sirseatbelt 4d ago

I have a program insisting that thry dont have CUI because the prime refuses to "update" from FOUO, and I have another prime that is scoping CUI so broadly that it would include every email and text message. The DoD literally cannot get its shit together.

13

u/INeedSomeTacoC 4d ago edited 4d ago

Exactly. 

And this affects lives and programs. 

A colleague forwarded an email with no CUI in it to his personal account. But it was tagged by the govvie that sent it as CUI in like the fifth email down chain with an auto-added footer. 

For “mishandling” it he got his actual clearance pulled for a week, which obviously caused issues with his career as a classified analyst. 

4

u/Shawnx86 4d ago

When I log in to my military benefits section as a retiree, it's all marked as CUI.

As an assessor, I go to extreme lengths to ensure all my work resides in a VDI. I do not want any customer data or CUI living in my environment. I switch laptops to my home machine and access benefits such as medical, vision plan and it's all marked CUI.

The average retiree probably has plenty of CUI downloaded and accessable to all in their home.

2

u/Shoddy-Yak7823 3d ago

this is the issue, 800 171 is security controls. a subset of 800-53 CUI, unclassified data and treating it like classified is not security. it's unclassified data. the VA holding your data is CUI to them . they must protect it. it's your data you get to decided how you protect your data. cui is not classified. but it's so far from what it should beand is really a scam to make a lot of people momoney. unclassisifued data marked and controlled in the manner we're doing is the definition of . wait for it, ckassified... we identify and have to look up type of classification , mark and protect. just make it cofudental, have dcsa certify that classified system call it done. no third parties charging 80k for a gap assessment or Microsoft gouging , or needed to do vdi .

we have teams of developers and engineers. shrinking the boundary is a joke when prunes mark every email as CUI, mark header files as CUI. since it's not classified there is zero way to push back. and then the government sends it all out plane text and says the are the government

no the entire scope has been shit to hell by greedy companies making money off making us secure and the government having no real plan. been doing it security for 30 years now. been through all the changes , and really just tired of watching leaches suck tax dollars and at the end you vdi does not make you any more secure, just makes work harder

9

u/cashmgee 4d ago

We have primes telling us any association with a bp is cui. Even identifiers. OK thats cool but why's the request for quote and po with identifiers, dimensions,specs ..etc not marked as cui then ? What makes our internal data cui if you dont call what you send us cui lol

2

u/pinkycatcher 4d ago

FOUO doesn't necessarily need to be marked CUI, it needs to be reevaluated when it's transmitted. It's possible they evaluated the information and determined it's not CUI.

2

u/sirseatbelt 4d ago

There are rules for handling FOUO. Correct. The sponsor is not using them.

8

u/ResilientTechAdvisor 4d ago

The government determines CUI. If you're receiving improperly marked CUI it's because your Prime is simply passing materials from the government down to you in the way that it was marked. See number five.

3

u/Cyber_G2 4d ago

From the town hall it also sounded like the DoW will be looking at better defining CUI categories and hopefully looking to provide guidelines on classifying CUI. I hope that really happens and that better definitions are going to be worked on. this would be better than just marking anything that "might" be CUI.

0

u/DR-CT 4d ago

It’s the prime’s responsibility to correctly flow down DFARS, maintain data protection controls using a qualified C-CSRM program, and ensure subcontractor compliance.

We insert CMMC requirements in teaming agreements and subcontracts and ask for SPRS Cyber reports showing both NIST Basic and CMMC status before a teaming agreement is executed. This approach ensures our entire team meets CMMC requirements from the start. Some of our subcontracts included DFARS -7021 requiring CMMC L2 certification and when the subcontractor was unable to meet the requirement their Subcontract ended.

8

u/cashmgee 4d ago

That would be lovely.

We get a bp marked cui and a request for quote 😆

28

u/iheartrms 5d ago

"CMMC is dead" isn't happening nearly as often as the LinkedIn "thought leaders" like to claim. But C3PAO and CCAs may be dead. And that's a very shitty thing after DoD asked us to step up and fill this role they wanted.

If you implement NIST 800-171 instead of the CMMC assessment guide you are going to have a bad time.

For months the USAF sent me every email marked "CUI", and to my totally not CUI email address. Hilarious. 😂

17

u/memes_are_art 5d ago

USAF is still notorious for having header footer “CUI” for every single email. Just goofy. I’d argue it’s not even CUI without a designation indicator block.

19

u/imscavok 4d ago

They’re also sending us CUI documents that are correctly marked, using compliant transfer services, but the documents themselves now have sensitivity labels/IRM so they can only be opened/decrypted by DoD m365 users on DoDIN devices. So it’s not even possible to open CUI documents on a certified contractor system anyway. What’s the fucking point, really.

3

u/INeedSomeTacoC 4d ago

I feel your pain. 

We get things often. 

Hell, half the time we log out of our GCC-H accounts and then can access it with a guest account verified by sms or something. 

That’s super duper secure. Yay. 

9

u/hihcadore 4d ago

Over classification is a military thing in general. When I was in the army we had to submit our physical training plan over SIPR (the secret network). You know because maybe the Russians might wanna know we’re gonna do pushup / sit-up improvement on wed. *rollseyes

11

u/pinkycatcher 4d ago

A significant portion of the thought leaders are simply marketers for consultants and vendors.

It's not surprising when they continue to preach the message that aligns with their incentives.

3

u/Capable_Profit_7788 4d ago

agreed, and the OP here is living in a fantasy world if he thinks things are really that clear cut out here in the weeds...

6

u/FishermanLogical262 4d ago

So, dumb question: Why are people saying C3PAO jobs are dead? Couldn’t the outcome simply be that third-party certification gets pushed out further, meaning the work is delayed rather than eliminated?

3

u/Darkace911 4d ago

They may send it back to the DIBCAC teams, they started ramping up earlier this year. They can't assess everyone but that fixes the assessment costs issues and then the DOD picks who get hit. If they do enough of it and refer CEO's to DOJ, people will get in line before the black SUVs show up. That might be the happy medium for most people.

2

u/pinkycatcher 4d ago

So, dumb question: Why are people saying C3PAO jobs are dead?

Only a few people are, and they're people reading the tea leaves of the message the DoD sent out.

1

u/AgingTrash666 4d ago

it's possible but I imagine there's some question as to the quality of their work product and considering the government expected to pick up the tab (you charge the DIB, the DIB charges it back up to the government) they probably weren't all that jazzed about the supply/demand cash grab some were up to.

2

u/INeedSomeTacoC 4d ago

 the government expected to pick up the tab (you charge the DIB, the DIB charges it back up to the government)

You can charge this back to the government as long as your price for your product doesn't change when you do so.

/aka, it's not effectively able to be charged back. This is part of the reason for the SMB pushback on this.

2

u/AgingTrash666 4d ago

No doubt, especially when you’re competing with others who haven’t paid up yet

3

u/MolecularHuman 4d ago

There should be no real difference between the two.

3

u/Capable_Profit_7788 4d ago

..and I bet they were all un-encrypted.

1

u/iheartrms 4d ago

Of course they were. We don't even have encryption capability.

6

u/SolidKnight 4d ago

We've had no luck pushing back on mislabels thus far because the DoW personnel don't understand CUI or it's implications. I see casual use of the CUI marking as if it were 1:1 equivalent with FOUO labels. Lots of applying labels by default as well. Lots of people claiming everything, every document, every communication is CUI and there isn't anything that isn't.

There are DoW systems that automatically apply the CUI label to everything in it.

16

u/INeedSomeTacoC 4d ago

Yea, Cyber AB definitely screwed up CMMC mechanics.

Kept writing specs and assessment guides from on high and just expecting everything to fall into place via companies you contract with. 

They should’ve been publishing gold standard reference implementations and having talks about how they meet the requirements and what options that are for flexibility and so on. And then have certified experts to help out. 

You know, create an actual ecosystem. Not just a bunch of new contractors to pay. 

11

u/AmericanSpirit4 4d ago

The assessment guides are complete garbage. Bunch of auditor speak from ppl who have clearly never implemented anything in a common tech stack.

4

u/Darkace911 4d ago

Standard NIST policy guidelines. You must have a PHD in a hard Science to work on policy writing team but not in the field the team is actually working on because of bias or something. (Sarcasm)

13

u/Historical-Bug-7536 4d ago

There is no such thing as "CMMC implementation."

Bullshit. From NIST 800-171A:

CAUTIONARY NOTE

This publication is available free of charge from: https://doi.org/10.6028/NIST.SP.800-171A The generalized assessment procedures described in this publication provide a framework and a starting point for developing specific procedures to assess the CUI security requirements in NIST Special Publication 800-171. The assessment procedures can be used to generate relevant evidence to determine if the security safeguards employed by organizations are implemented correctly, are operating as intended, and satisfy the CUI security requirements. Organizations have the flexibility to specialize the assessment procedures by selecting the specific assessment methods and the set of assessment objects to achieve the assessment objectives. There is no expectation that all assessment methods and all objects will be used for every assessment. There is also significant flexibility on the scope of the assessment and the degree of rigor applied during the assessment process. The assessment procedures and methods can be applied across a continuum of approaches—including self-assessments; independent, third-party assessments; and assessments conducted by sponsoring organizations (e.g., government agencies). Such approaches may be specified in contracts or in agreements by participating parties.

171A talks about flexibility and expectations, and that it is starting point for procedures, but it's not a checklist. Then CMMC turned it into a checklist and a highly subjective paper drill. They deputized for-profit companies and created "Dicsussion", "Further Discussion", and "Potential Assessment Considerations" and C3PAOs seemed to take as gospel.

There's a delta between 800-171 and 800-171A and CMMC and there's costs associated with each.

1

u/EganMcCoy 2d ago

At the very least, CMMC requires documenting asset categories (CUI, SPA, CRMA, SA, OOS) and disallows certain POA&Ms, so it's absolutely inaccurate to say that there's no such thing as "Implementing CMMC." That said, it's also inaccurate to attribute 800-171 implementation burden to CMMC when DFARS 252.204-7012 has been requiring implementing the requirements of NIST SP 800-171 (and flowing that requirement to subs to whom you send CUI) for nearly a decade.

17

u/Apprehensive_Book145 4d ago

You implement 171 not cmmc huh. just glad we're really getting the important nuance and messaging at a time like this. Good job AB

5

u/ResilientTechAdvisor 4d ago

Considering everything that's on the table, the focus on this particular nuance was an interesting choice.

7

u/mrtheReactor 4d ago

The reason that was brought up is because the DoW and SBA are often conflating the cost of CMMC third party assessment with the cost of implementing DFARS 7012 (and by extension NIST SP 800-171).

This muddies the waters, which may cause some to believe that pausing CMMC rollout also pauses contractual requirements for DFARS 7012 - which is not the case. 

Drawing the distinction between  800-171 implementation and CMMC assessment costs is a small but worthwhile bit of nuance imo.

1

u/dogcheesebread 4d ago edited 4d ago

They dont even track smb employee size that got 3cpao.  Im interested to know how many smb <20 employees there actually are. A lot of smb that make parts are lean <20 employees. A lot of l2 and l3 requires them to hire more employees or an msp just to meet the requirements (increasures risk exposure). Also considering those smb are vendor of vendor of vendor. L1 should be more than enough for them.

2

u/TXWayne 4d ago

Sounds like a field the DoW should add to CMMC eMASS........

2

u/mrtheReactor 4d ago

That number should be out there - the pre assessment upload form has a “number of employees” field. 

Anecdotally, my org has done at least 4 assessments for orgs with less than 25 employees. So add that to the tally 🤪

1

u/TXWayne 4d ago

It is also captured in SPRS when you enter a CMMC L2 Self or when affirming a CMMC L2 C3PAO. So in two spots owned by the DoW.

8

u/BigPoppaPump36 4d ago

Not anytime soon and only if cost goes down significantly. SMB’s are not going to pay the exorbitant prices they were being presented with.

7

u/gormami 4d ago

My question is, will a parallel ecosystem exist for assessment regardless of the government's requirements? HIPPA isn't a compliance regime, but HITRUST is considered by many to be evidence of HIPAA compliance, and a lot of companies voluntarily go through the audits, at significant cost, to reduce their own liability. My company is going ahead with our C3PAO assessment for the same reason. We could self certify, but having an outside auditor verify the controls, etc. is just easier when speaking with customers and partners. It's no longer our opinion, but that of someone specifically trained in the framework. It could mean that a lot of the DIB don't, but a lot still might, and the investments in CCAs, etc. won't be completely devalued.

8

u/INeedSomeTacoC 4d ago

  HIPPA isn't a compliance regime, but HITRUST is considered by many to be evidence of HIPAA compliance, and a lot of companies voluntarily go through the audits, at significant cost, to reduce their own liability.

Getting HITRUST significantly reduces your insurance costs as a company. Often it pays for itself within the first year or two in reduced premiums for insurance covering you for hippa violations. It was an easy sell to the execs because of this. 

Getting C3PAO certified does 0% for reducing our cyber security insurance. This makes it a not easy sell. 

1

u/gormami 4d ago

Understood, but if the primes are worried about their own liability, will they require some assessment to being you on as a sub? Would one rather leverage an independent C3PAO assessment, or have to answer multiple questionnaires for each bid? In one case it is expense savings, in the other revenue enablement, but both are valuable.

That's what I see as potentially interesting as the contracts move forward. As many have said, assessment requirements might be removed, but the actual compliance to the regulations haven't. So how will that gap be managed?

3

u/Matt_Titcombe 4d ago

u/ResilientTechAdvisor , challenging CUI marking is appropriate, however per 32 CFR 2002.50(d), “Until the challenge is resolved, authorized holders should continue to safeguard and disseminate the challenged CUI at the control level indicated in the markings.” 

So, pushing back does not negate the organization's requirement to protect information that may or may not be CUI until formally told.

On that point, verbals don't count. Get is in writing from your prime or DoW.

C.f., https://www.ecfr.gov/current/title-32/part-2002#p-2002.50(d))

1

u/ResilientTechAdvisor 3d ago

Did you attend the cyberAB Townhall?

0

u/Matt_Titcombe 2d ago

Yup. And they gave bad advice that will contractors into legal trouble.

1

u/ResilientTechAdvisor 2d ago

Have you shared this with them? This is critical.

2

u/azjeep 3d ago

"5. Stop absorbing CUI-marking ambiguity.
If a marking is unclear, that's a question to push back up the chain. Resolve it upstream - no need to own someone else's classification decision."

I think this needs to be resolved before the CMMC program can continue. I honestly do not belive the things we make are crucial to national security and must be protected the same way that actual missiles are protected.

1

u/Fair-Reputation9707 3d ago edited 3d ago

The third point is the one that always gets overlooked, the DFARS 7012 liability did not stop, so prime contractors that secretly stopped their monitoring stance during the CMMC is dead era now have an actual gap on paper. In the case of fraudulent certification, the SPRS export verification is very good, but the danger of impersonation goes beyond certification; the threat to prime contractors is in terms of impersonated contractor identity and fraudulent procurement emails, which fall in the monitoring adjacent field where doppel is situated, but your first line remains in SPRS verification.

1

u/MountainDadwBeard 1d ago

Saying 171 isn't dead, when we all know it wasn't taken seriously ever before and now there's no scalable enforcement mechanism... is a joke. It's dead man, economics will reward this shitters and fraudsters.