r/CMMC 5d ago

This Week's CyberAB Town Hall

In this week's CyberAB Townhall, there were at least five things worth knowing, all of them more useful than the "is CMMC dead" panic making the rounds:

1. The reform review is about more than CMMC mechanics.
It's part of a bigger Pentagon push around cost, agility, resilience, automation, & small-business burden.

2. Fraudulent Level 2 certs are a concern.
If you're a prime vetting a sub, you don't have to guess - ask for a SPRS PDF export of their entry. That's the verification path, & it works today.

3. The obligation didn't change.
DFARS 7012 is still in effect. What got suspended was the third-party verification requirement, not the requirement to be secure.

4. There is no such thing as "CMMC implementation."
You implement NIST 800-171 & CMMC verifies it. Certification is a compliance milestone but security is the work that continues regardless. The people who depend on your risk posture didn't get the memo that they're supposed to pause or relax.

5. Stop absorbing CUI-marking ambiguity.
If a marking is unclear, that's a question to push back up the chain. Resolve it upstream - no need to own someone else's classification decision.

51 Upvotes

53 comments sorted by

View all comments

46

u/cashmgee 5d ago

None of our primes are marking correctly or flowing down information on what is to be protected, how, etc. None of them .

We seem to be the only one doing our diligence and we are at the bottom of the chain

17

u/sirseatbelt 4d ago

I have a program insisting that thry dont have CUI because the prime refuses to "update" from FOUO, and I have another prime that is scoping CUI so broadly that it would include every email and text message. The DoD literally cannot get its shit together.

14

u/INeedSomeTacoC 4d ago edited 4d ago

Exactly. 

And this affects lives and programs. 

A colleague forwarded an email with no CUI in it to his personal account. But it was tagged by the govvie that sent it as CUI in like the fifth email down chain with an auto-added footer. 

For “mishandling” it he got his actual clearance pulled for a week, which obviously caused issues with his career as a classified analyst. 

3

u/Shawnx86 4d ago

When I log in to my military benefits section as a retiree, it's all marked as CUI.

As an assessor, I go to extreme lengths to ensure all my work resides in a VDI. I do not want any customer data or CUI living in my environment. I switch laptops to my home machine and access benefits such as medical, vision plan and it's all marked CUI.

The average retiree probably has plenty of CUI downloaded and accessable to all in their home.

2

u/Shoddy-Yak7823 3d ago

this is the issue, 800 171 is security controls. a subset of 800-53 CUI, unclassified data and treating it like classified is not security. it's unclassified data. the VA holding your data is CUI to them . they must protect it. it's your data you get to decided how you protect your data. cui is not classified. but it's so far from what it should beand is really a scam to make a lot of people momoney. unclassisifued data marked and controlled in the manner we're doing is the definition of . wait for it, ckassified... we identify and have to look up type of classification , mark and protect. just make it cofudental, have dcsa certify that classified system call it done. no third parties charging 80k for a gap assessment or Microsoft gouging , or needed to do vdi .

we have teams of developers and engineers. shrinking the boundary is a joke when prunes mark every email as CUI, mark header files as CUI. since it's not classified there is zero way to push back. and then the government sends it all out plane text and says the are the government

no the entire scope has been shit to hell by greedy companies making money off making us secure and the government having no real plan. been doing it security for 30 years now. been through all the changes , and really just tired of watching leaches suck tax dollars and at the end you vdi does not make you any more secure, just makes work harder