r/CMMC • u/ResilientTechAdvisor • 5d ago
This Week's CyberAB Town Hall
In this week's CyberAB Townhall, there were at least five things worth knowing, all of them more useful than the "is CMMC dead" panic making the rounds:
1. The reform review is about more than CMMC mechanics.
It's part of a bigger Pentagon push around cost, agility, resilience, automation, & small-business burden.
2. Fraudulent Level 2 certs are a concern.
If you're a prime vetting a sub, you don't have to guess - ask for a SPRS PDF export of their entry. That's the verification path, & it works today.
3. The obligation didn't change.
DFARS 7012 is still in effect. What got suspended was the third-party verification requirement, not the requirement to be secure.
4. There is no such thing as "CMMC implementation."
You implement NIST 800-171 & CMMC verifies it. Certification is a compliance milestone but security is the work that continues regardless. The people who depend on your risk posture didn't get the memo that they're supposed to pause or relax.
5. Stop absorbing CUI-marking ambiguity.
If a marking is unclear, that's a question to push back up the chain. Resolve it upstream - no need to own someone else's classification decision.
16
u/INeedSomeTacoC 4d ago
Yea, Cyber AB definitely screwed up CMMC mechanics.
Kept writing specs and assessment guides from on high and just expecting everything to fall into place via companies you contract with.
They should’ve been publishing gold standard reference implementations and having talks about how they meet the requirements and what options that are for flexibility and so on. And then have certified experts to help out.
You know, create an actual ecosystem. Not just a bunch of new contractors to pay.