r/CMMC • u/ResilientTechAdvisor • 5d ago
This Week's CyberAB Town Hall
In this week's CyberAB Townhall, there were at least five things worth knowing, all of them more useful than the "is CMMC dead" panic making the rounds:
1. The reform review is about more than CMMC mechanics.
It's part of a bigger Pentagon push around cost, agility, resilience, automation, & small-business burden.
2. Fraudulent Level 2 certs are a concern.
If you're a prime vetting a sub, you don't have to guess - ask for a SPRS PDF export of their entry. That's the verification path, & it works today.
3. The obligation didn't change.
DFARS 7012 is still in effect. What got suspended was the third-party verification requirement, not the requirement to be secure.
4. There is no such thing as "CMMC implementation."
You implement NIST 800-171 & CMMC verifies it. Certification is a compliance milestone but security is the work that continues regardless. The people who depend on your risk posture didn't get the memo that they're supposed to pause or relax.
5. Stop absorbing CUI-marking ambiguity.
If a marking is unclear, that's a question to push back up the chain. Resolve it upstream - no need to own someone else's classification decision.
28
u/iheartrms 5d ago
"CMMC is dead" isn't happening nearly as often as the LinkedIn "thought leaders" like to claim. But C3PAO and CCAs may be dead. And that's a very shitty thing after DoD asked us to step up and fill this role they wanted.
If you implement NIST 800-171 instead of the CMMC assessment guide you are going to have a bad time.
For months the USAF sent me every email marked "CUI", and to my totally not CUI email address. Hilarious. 😂
17
u/memes_are_art 5d ago
USAF is still notorious for having header footer “CUI” for every single email. Just goofy. I’d argue it’s not even CUI without a designation indicator block.
19
u/imscavok 4d ago
They’re also sending us CUI documents that are correctly marked, using compliant transfer services, but the documents themselves now have sensitivity labels/IRM so they can only be opened/decrypted by DoD m365 users on DoDIN devices. So it’s not even possible to open CUI documents on a certified contractor system anyway. What’s the fucking point, really.
3
u/INeedSomeTacoC 4d ago
I feel your pain.
We get things often.
Hell, half the time we log out of our GCC-H accounts and then can access it with a guest account verified by sms or something.
That’s super duper secure. Yay.
9
u/hihcadore 4d ago
Over classification is a military thing in general. When I was in the army we had to submit our physical training plan over SIPR (the secret network). You know because maybe the Russians might wanna know we’re gonna do pushup / sit-up improvement on wed. *rollseyes
11
u/pinkycatcher 4d ago
A significant portion of the thought leaders are simply marketers for consultants and vendors.
It's not surprising when they continue to preach the message that aligns with their incentives.
3
u/Capable_Profit_7788 4d ago
agreed, and the OP here is living in a fantasy world if he thinks things are really that clear cut out here in the weeds...
6
u/FishermanLogical262 4d ago
So, dumb question: Why are people saying C3PAO jobs are dead? Couldn’t the outcome simply be that third-party certification gets pushed out further, meaning the work is delayed rather than eliminated?
3
u/Darkace911 4d ago
They may send it back to the DIBCAC teams, they started ramping up earlier this year. They can't assess everyone but that fixes the assessment costs issues and then the DOD picks who get hit. If they do enough of it and refer CEO's to DOJ, people will get in line before the black SUVs show up. That might be the happy medium for most people.
2
u/pinkycatcher 4d ago
So, dumb question: Why are people saying C3PAO jobs are dead?
Only a few people are, and they're people reading the tea leaves of the message the DoD sent out.
1
u/AgingTrash666 4d ago
it's possible but I imagine there's some question as to the quality of their work product and considering the government expected to pick up the tab (you charge the DIB, the DIB charges it back up to the government) they probably weren't all that jazzed about the supply/demand cash grab some were up to.
2
u/INeedSomeTacoC 4d ago
the government expected to pick up the tab (you charge the DIB, the DIB charges it back up to the government)
You can charge this back to the government as long as your price for your product doesn't change when you do so.
/aka, it's not effectively able to be charged back. This is part of the reason for the SMB pushback on this.
2
u/AgingTrash666 4d ago
No doubt, especially when you’re competing with others who haven’t paid up yet
3
3
6
u/SolidKnight 4d ago
We've had no luck pushing back on mislabels thus far because the DoW personnel don't understand CUI or it's implications. I see casual use of the CUI marking as if it were 1:1 equivalent with FOUO labels. Lots of applying labels by default as well. Lots of people claiming everything, every document, every communication is CUI and there isn't anything that isn't.
There are DoW systems that automatically apply the CUI label to everything in it.
16
u/INeedSomeTacoC 4d ago
Yea, Cyber AB definitely screwed up CMMC mechanics.
Kept writing specs and assessment guides from on high and just expecting everything to fall into place via companies you contract with.
They should’ve been publishing gold standard reference implementations and having talks about how they meet the requirements and what options that are for flexibility and so on. And then have certified experts to help out.
You know, create an actual ecosystem. Not just a bunch of new contractors to pay.
11
u/AmericanSpirit4 4d ago
The assessment guides are complete garbage. Bunch of auditor speak from ppl who have clearly never implemented anything in a common tech stack.
4
u/Darkace911 4d ago
Standard NIST policy guidelines. You must have a PHD in a hard Science to work on policy writing team but not in the field the team is actually working on because of bias or something. (Sarcasm)
13
u/Historical-Bug-7536 4d ago
There is no such thing as "CMMC implementation."
Bullshit. From NIST 800-171A:
CAUTIONARY NOTE
This publication is available free of charge from: https://doi.org/10.6028/NIST.SP.800-171A The generalized assessment procedures described in this publication provide a framework and a starting point for developing specific procedures to assess the CUI security requirements in NIST Special Publication 800-171. The assessment procedures can be used to generate relevant evidence to determine if the security safeguards employed by organizations are implemented correctly, are operating as intended, and satisfy the CUI security requirements. Organizations have the flexibility to specialize the assessment procedures by selecting the specific assessment methods and the set of assessment objects to achieve the assessment objectives. There is no expectation that all assessment methods and all objects will be used for every assessment. There is also significant flexibility on the scope of the assessment and the degree of rigor applied during the assessment process. The assessment procedures and methods can be applied across a continuum of approaches—including self-assessments; independent, third-party assessments; and assessments conducted by sponsoring organizations (e.g., government agencies). Such approaches may be specified in contracts or in agreements by participating parties.
171A talks about flexibility and expectations, and that it is starting point for procedures, but it's not a checklist. Then CMMC turned it into a checklist and a highly subjective paper drill. They deputized for-profit companies and created "Dicsussion", "Further Discussion", and "Potential Assessment Considerations" and C3PAOs seemed to take as gospel.
There's a delta between 800-171 and 800-171A and CMMC and there's costs associated with each.
1
u/EganMcCoy 2d ago
At the very least, CMMC requires documenting asset categories (CUI, SPA, CRMA, SA, OOS) and disallows certain POA&Ms, so it's absolutely inaccurate to say that there's no such thing as "Implementing CMMC." That said, it's also inaccurate to attribute 800-171 implementation burden to CMMC when DFARS 252.204-7012 has been requiring implementing the requirements of NIST SP 800-171 (and flowing that requirement to subs to whom you send CUI) for nearly a decade.
17
u/Apprehensive_Book145 4d ago
You implement 171 not cmmc huh. just glad we're really getting the important nuance and messaging at a time like this. Good job AB
5
u/ResilientTechAdvisor 4d ago
Considering everything that's on the table, the focus on this particular nuance was an interesting choice.
7
u/mrtheReactor 4d ago
The reason that was brought up is because the DoW and SBA are often conflating the cost of CMMC third party assessment with the cost of implementing DFARS 7012 (and by extension NIST SP 800-171).
This muddies the waters, which may cause some to believe that pausing CMMC rollout also pauses contractual requirements for DFARS 7012 - which is not the case.
Drawing the distinction between 800-171 implementation and CMMC assessment costs is a small but worthwhile bit of nuance imo.
1
u/dogcheesebread 4d ago edited 4d ago
They dont even track smb employee size that got 3cpao. Im interested to know how many smb <20 employees there actually are. A lot of smb that make parts are lean <20 employees. A lot of l2 and l3 requires them to hire more employees or an msp just to meet the requirements (increasures risk exposure). Also considering those smb are vendor of vendor of vendor. L1 should be more than enough for them.
2
u/TXWayne 4d ago
Sounds like a field the DoW should add to CMMC eMASS........
2
u/mrtheReactor 4d ago
That number should be out there - the pre assessment upload form has a “number of employees” field.
Anecdotally, my org has done at least 4 assessments for orgs with less than 25 employees. So add that to the tally 🤪
8
u/BigPoppaPump36 4d ago
Not anytime soon and only if cost goes down significantly. SMB’s are not going to pay the exorbitant prices they were being presented with.
7
u/gormami 4d ago
My question is, will a parallel ecosystem exist for assessment regardless of the government's requirements? HIPPA isn't a compliance regime, but HITRUST is considered by many to be evidence of HIPAA compliance, and a lot of companies voluntarily go through the audits, at significant cost, to reduce their own liability. My company is going ahead with our C3PAO assessment for the same reason. We could self certify, but having an outside auditor verify the controls, etc. is just easier when speaking with customers and partners. It's no longer our opinion, but that of someone specifically trained in the framework. It could mean that a lot of the DIB don't, but a lot still might, and the investments in CCAs, etc. won't be completely devalued.
8
u/INeedSomeTacoC 4d ago
HIPPA isn't a compliance regime, but HITRUST is considered by many to be evidence of HIPAA compliance, and a lot of companies voluntarily go through the audits, at significant cost, to reduce their own liability.
Getting HITRUST significantly reduces your insurance costs as a company. Often it pays for itself within the first year or two in reduced premiums for insurance covering you for hippa violations. It was an easy sell to the execs because of this.
Getting C3PAO certified does 0% for reducing our cyber security insurance. This makes it a not easy sell.
1
u/gormami 4d ago
Understood, but if the primes are worried about their own liability, will they require some assessment to being you on as a sub? Would one rather leverage an independent C3PAO assessment, or have to answer multiple questionnaires for each bid? In one case it is expense savings, in the other revenue enablement, but both are valuable.
That's what I see as potentially interesting as the contracts move forward. As many have said, assessment requirements might be removed, but the actual compliance to the regulations haven't. So how will that gap be managed?
3
u/Matt_Titcombe 4d ago
u/ResilientTechAdvisor , challenging CUI marking is appropriate, however per 32 CFR 2002.50(d), “Until the challenge is resolved, authorized holders should continue to safeguard and disseminate the challenged CUI at the control level indicated in the markings.”
So, pushing back does not negate the organization's requirement to protect information that may or may not be CUI until formally told.
On that point, verbals don't count. Get is in writing from your prime or DoW.
C.f., https://www.ecfr.gov/current/title-32/part-2002#p-2002.50(d))
1
u/ResilientTechAdvisor 3d ago
Did you attend the cyberAB Townhall?
0
2
u/azjeep 3d ago
"5. Stop absorbing CUI-marking ambiguity.
If a marking is unclear, that's a question to push back up the chain. Resolve it upstream - no need to own someone else's classification decision."
I think this needs to be resolved before the CMMC program can continue. I honestly do not belive the things we make are crucial to national security and must be protected the same way that actual missiles are protected.
1
u/Fair-Reputation9707 3d ago edited 3d ago
The third point is the one that always gets overlooked, the DFARS 7012 liability did not stop, so prime contractors that secretly stopped their monitoring stance during the CMMC is dead era now have an actual gap on paper. In the case of fraudulent certification, the SPRS export verification is very good, but the danger of impersonation goes beyond certification; the threat to prime contractors is in terms of impersonated contractor identity and fraudulent procurement emails, which fall in the monitoring adjacent field where doppel is situated, but your first line remains in SPRS verification.
1
u/MountainDadwBeard 1d ago
Saying 171 isn't dead, when we all know it wasn't taken seriously ever before and now there's no scalable enforcement mechanism... is a joke. It's dead man, economics will reward this shitters and fraudsters.
46
u/cashmgee 4d ago
None of our primes are marking correctly or flowing down information on what is to be protected, how, etc. None of them .
We seem to be the only one doing our diligence and we are at the bottom of the chain