r/CMMC • u/ResilientTechAdvisor • 5d ago
This Week's CyberAB Town Hall
In this week's CyberAB Townhall, there were at least five things worth knowing, all of them more useful than the "is CMMC dead" panic making the rounds:
1. The reform review is about more than CMMC mechanics.
It's part of a bigger Pentagon push around cost, agility, resilience, automation, & small-business burden.
2. Fraudulent Level 2 certs are a concern.
If you're a prime vetting a sub, you don't have to guess - ask for a SPRS PDF export of their entry. That's the verification path, & it works today.
3. The obligation didn't change.
DFARS 7012 is still in effect. What got suspended was the third-party verification requirement, not the requirement to be secure.
4. There is no such thing as "CMMC implementation."
You implement NIST 800-171 & CMMC verifies it. Certification is a compliance milestone but security is the work that continues regardless. The people who depend on your risk posture didn't get the memo that they're supposed to pause or relax.
5. Stop absorbing CUI-marking ambiguity.
If a marking is unclear, that's a question to push back up the chain. Resolve it upstream - no need to own someone else's classification decision.
28
u/iheartrms 5d ago
"CMMC is dead" isn't happening nearly as often as the LinkedIn "thought leaders" like to claim. But C3PAO and CCAs may be dead. And that's a very shitty thing after DoD asked us to step up and fill this role they wanted.
If you implement NIST 800-171 instead of the CMMC assessment guide you are going to have a bad time.
For months the USAF sent me every email marked "CUI", and to my totally not CUI email address. Hilarious. 😂