CMMC Updates and Panel Introductions
00:00:02 – Stephanie Hamrick
Hello, and thank you, everybody, for joining us for our live conversation today. We at Bluewave are partnering up with experts from Thrive and C3 to discuss CMMC’s latest updates and what smart organizations are doing during the suspension of phase two.
And we have a great discussion ahead, but before we start, I have some housekeeping items to cover. First, we are gonna aim for this session to run about sixty minutes today, but we are going to leave some time at the end of that hour for questions. The webinar is being recorded, and you will get a copy of the recording after the event. And lastly, there is a Q and A section on the webinar interface here if you’d like to submit questions as we go.
Again, we will be saving some time to get to those at the end.
So, with that out of the way, let’s introduce today’s panel. First, joining us from Bluewave, we have our cybersecurity and compliance practice lead, Michael Leggett.
Then from Thrive, we have VP of cyber consulting, Rolando Torres.
And from C3, we have chief growth officer and cofounder, Bill Wotton.
Thank you all for being here today.
And I will be your moderator along the way until we get into our main discussion. My name is Stephanie Hamrick, and I’m the director of demand gen at Bluewave.
So next, we’ll do brief introductions for those who don’t know us, and we’ll try to stick to sixty seconds or fewer each so we can get right into our discussion. First, about Bluewave. We are a technology advisory with the mission to bring confidence and clarity to technology decisions by partnering with IT leaders. We have expertise across a wide range of technology areas from security to CX to cloud and a whole host of others with both clients and advisers across the United States.
And I’ll hand it briefly over to Rolando to give us a short intro for Thrive.
00:02:13 – Rolando Torres
Hey. Good afternoon, everyone. My name is Rolando Torres. I’m VP of Cyber Consulting and GRC Services at Thrive. At Thrive, we’re a next gen managed services organization. We help you with your AI, cybersecurity, cloud, and managed services compliance needs.
We can do everything that the traditional MSP and MSSP can do for you or more. And we look to building partnership with our clients. It’s a pleasure to be here, and I look forward to this conversation.
00:02:47 – Stephanie Hamrick
Thanks, Rolando. And next, I’m gonna hand it over to Bill for a quick primer on C3.
00:02:54 – Bill Wootton
Great. Thank you, Stephanie. My name is Bill Wooten. I’m chief growth officer, one of the original founders here at C3, where we are a specialist service provider that is dedicated to designing, implementing, managing, and monitoring custom-built environments to support CMMC and, of course, DFARS 7012 and NIST 800-171.
We’ve been working in this industry, in this niche, for a little over ten years now. We have our own internal level two seats at CMMC, and we’ve now successfully shepherded dozens of clients through the assessment process.
00:03:29 – Stephanie Hamrick
Thanks, Bill. And with that, I am going to take down our slides here so we can focus on this panel discussion. And I’m gonna hand it over to Michael, my colleague from Bluewave, who is going to be leading the discussion among our experts here. Michael, over to you.
00:03:45 – Michael Leggett
Perfect. Thank you, Stephanie. So first and foremost, I wanna thank Rolando and Bill for being here, and thank you all for joining this. CMMC has obviously gone through some recent changes, and we’ve been getting a lot of asks from clients about what those changes really mean for them. So, to start things off here, I want to talk a little bit about what that recent suspension of phase two means, what it did and did not change.
And then as we get into it a little bit more, we can talk about what are some of the common mistakes that we see organizations make at the beginning of their journey and then provide some practical tips for folks that are kind of further down the path. So hopefully no matter where you are in your CMMC journey today, there will be something here that will be applicable to your organization.
Phase Two Suspension Implications
00:04:30 – Michael Leggett
To start it off, you know we can start with the ten-thousand-pound gorilla as it were, which is this suspension of phase two. The Department of War released a statement a few weeks back that said, hey, phase two is on pause. That did not state that CMMC level two was on pause nor did that impact the cyber security requirements that are needed for you to adhere to eight hundred one seventy-one of the DFARS clauses. It doesn’t impact what you’re going to need to do for your SSP or submission of an SPRS score.
None of the underlying cyber security and compliance requirements have been impacted by this announcement. It’s also important to note that this is a suspension as they are performing a review of the CMMC program. So, there is a task force that has been created to review the process to find areas that maybe are too burdensome for organizations going through this process and there was an RFI that was sent out to gather more information targeting certain areas hey what has been helpful what has been a challenge for you as they look to shape what they want phase two to look like moving forward.
So again, the key takeaways here are largely around phase two of the program, which predominantly focuses on C3PAO involvement and not the actual underlying cybersecurity and compliance controls. So, with that in mind, you know, I’ll start with you, Bill. Any additional color that you’d like to add to that and how have you seen clients responding to this recent announcement?
00:06:11 – Bill Wootton
Yeah. Absolutely. So, I think you outlined it really well in terms of the facts on the ground and the pause that was made with the program going into contracts to C3 certification on there. But to your point, you know, all of the other cyber requirements are still very much in place.
Those obligations are still there. Phase one is still very much showing up in contracts. We’re actually starting to see the DIBCACs still functioning and calling people up for assessments on there. From a client reaction, we’ve actually been really happy to see that a lot of our clients have understood the fact that this commitment isn’t just simply checking a box, it’s about a commitment to being compliant.
It’s a commitment to cybersecurity. Even those that are partway through the journey have come back and said, we’ve made this commitment, we wanna go finish the job, we wanna get it done.
00:07:00 – Michael Leggett
Right, and Rolando?
Protecting CUI and Defense Industrial Base
00:07:01 – Rolando Torres
Yeah, no, I would like to add, if you look at the announcement from the DOW, of the concern is being able to include innovation type of cutting-edge companies into the DIP, the defense industrial base, and the challenge that CMMC brings to that, right? Like there are maybe organizations that are working specifically with cutting edge technologies and advancements such as AI, drone technologies that might not become part of the DoD or DOW because of the CMMC compliance entry point. So, I think, I mean, that’s one thing. And the other thing is, we have been following CMMC for years, over years. So, it is not surprising that deadlines are pushed and things are changed. If you guys remember, we started with five levels and we end up with three. So, there are going to be changes along the line.
What hasn’t changed is the requirement to protect CUI, right? And I think that continues to be in place. The other part is, we are at war, right? And I think anything that could put at risk the integrity and the stability of the dip is gonna be reassessed and reconsidered. So, like having a deadline in November for CMMC compliance is maybe an unnecessary risk at this point.
So that probably leads to the pause. What I’m seeing with our clients is everyone is staying the course. I mean, like there’s requirements that haven’t changed, right? You have to still comply with NIST 800-171.
You still have supply chain requirements from prime companies that you might be serving contract with that are being cascaded down. And then there is the ability to hedge your risk in terms of compliance with getting a proper assessment and the certification, right? If you’re the one signing on the attestation, right? So, I think those things are very clear for our clients.
And I think, as of right now, I think we have only see a handful of clients that are not really part of the deep yet that are, you know, trying to become part of the deep that have really put a pause on or delayed, you know, getting the certification at this point.
00:09:19 – Michael Leggett
Yeah, I would say if that for organizations that have been a part of this for a while kind of to what you were speaking of this isn’t the first time we’ve seen a change to the program and a lot of those requirements and things that they have been saying they’ve been doing since twenty seventeen, those aren’t really impacted. So yeah. I think we can kind of split it into two camps about parties that are that are affected here. Folks that are trying to get into the space and trying to evaluate is this worth it to me still what will change if I want to do that and those that have been basically self-attesting for this a period of time for those that have been going through this and going through that self-attestation this shouldn’t really impact anything that you’re doing and I think that perhaps there is some hand wringing which we’ll get into a little bit about perceived costs or challenges that I would question if maybe they were being forthright with their initial assessments if these things are truly so daunting as some parties are making them out to be.
But I don’t really want to lead the witness. You can probably guess how I feel about those.
Guess we’ll go with this. So, there’s this pause. It’s under review.
Do we expect there to be major shifts on the heels of this? So, coming out of this review and the task force that’s being created, do we think there will be a radical shift to how CMMC will be implemented or what will be required? Or do we think there will be more of a slight edit in perspective? And I’ll start with you, Rolando, this time.
Future Shifts in CMMC Implementation
00:10:52 – Rolando Torres
Hard to say, right? I mean, think the one thing that in my mind is for sure is there is going to be a change. I mean, don’t think the DOW will push their pause button to say, Oh, I’m sorry, I didn’t mean to do that. Let’s just continue what we’re doing.
I do believe there are two tracks that will probably follow. One is the assistant DOD that is under contract and producing and part of the solutions and systems that are being developed right now. And then we, as I mentioned before, the innovation component part, which could be like PhD type of personnel that has LLC that might have like critical research data that is needed by the DoD, but it’s not really in a position to comply with CMMC, right? And I think that’s probably what I see as one of the major changes.
And it’s very difficult to know. I think to that, we should also add, as I mentioned before, the cascading effect of requirements from DOW prime companies like Raytheon and Lockheed Martin, those are not gonna change overnight. Those are bigger shifts that take time to change course. And they’ll continue to press their subcontracting firms to adhere to those standards.
So, I don’t see that as an issue. We have seen, you know, with regards to this 800-171, we have seen revision three being pushed, right? And this is before the pause. It seems to be more aligned with what the DOW was trying to do in terms of making the DIP more secure.
So maybe that’s part of the push, right? Which is, like now, in some time, we’ll be doing a revision three requirement, but it’s hard to say.
00:12:43 – Bill Wootton
Yeah, and I think you’re on the right track with a lot of those, absolutely agree with that. I think if you think about it, the DOW’s ability to maneuver is somewhat limited by the rulemaking process. We won’t go through this whole process of getting Title 32, Title 48 going through; those things are regulations that are in effect. So, it will take a pretty big event, for lack of a better word, to make a significant shift in kind of the program.
And I’m talking about kind of supporting CUI, cybersecurity priorities, those types of things. Areas that they can adjust and make some adjustments relatively easily are, you know, the way they were rolling out it in contracts to begin with, you know, the perception became that November 10th was a deadline, some sort of light switch, and it was being communicated at different levels of the government that all of a sudden, all contracts are gonna require CUI and CMMC. And that’s not what was intended by the rule; it was intended to add discretion, roll the contracts out in a way that didn’t disrupt the supply chain.
And that part got missed as it flowed down through the different chains of government. Correcting the priority programs that you’re gonna put this rule in first and then kind of maybe less important CUI come later on will give the industry the breathing room it needs to meet its adoption rates.
00:14:02 – Michael Leggett
Yeah, absolutely. And I think if we look at some of the questions that were asked in that RFI, it can kind of give you a sense of what potential changes might be made. So, you know, they’re asking about “what did you find to be the most administratively burdensome aspect of this?” “What were the areas that you thought were the least impactful but that required the most either money or change within your environment?”
And one that I found particularly interesting was: “Describe how your organization utilizes existing commercial cybersecurity capabilities and how could the DOW better recognize or accept those commercial solutions within a compliance of risk frameworks.” So, something to keep an eye on there to the point that’s being made here, and something that I would just like to double click on. There’s a reason why we have these regulations in place. There’s also a reason why there has been a need for a third-party audit of these things.
In 2017, a lot of this rulemaking was rolled out. In 2019, they did an audit of it and found that actually a lot of people who were self-attesting weren’t really living up to the standards they intended to, thus necessitating the need for a conversion within the program to have some sort of third-party oversight.
So, for those that were maybe hoping that well, this review will then do away with all of this oversight, I don’t foresee that happening, nor do I particularly think that would be a good thing for what we’re trying to accomplish and the intent of the compliance framework.
Let’s shift gears a little bit though and talk about folks that are maybe just entering the space. I’d be curious what you all would see as being a couple of the areas that they should focus on upfront as they’re beginning their journey, whether that’s because they repeatedly come up as mistakes later on, or you just found to be best practices.
So, Bill, I’ll start with you.
Defining Compliance Scope and Business Alignment
00:15:54 – Bill Wootton
You know, one of the things that we stress is this isn’t necessarily a technology problem. This is a business challenge.
And it really is like the absolute thing that is critical to get right is starting out by understanding your business, understanding your contracts, and understanding your data flows and knowing where those are and how they affect your ability. Is that first step, that first big milestone, is: what is your compliance scope going to be?
You’ve got to do that, and you’ve got to do that in a way that involves business operations, because they’re the ones that are gonna be impacted. They’re gonna have to, at some level, some way, change the way they work to accommodate compliance. You need to have them engaged in the beginning as very active participants. So, you know what you can maneuver with and what are hard lines that you can’t compromise.
00:16:38 – Rolando Torres
Yep. Yeah, I think that’s absolutely right. Think, I mean, like, historically, right, this has been, know, CMMC compliance, this has been assigned to technical leadership and technical teams to solve by enterprise leadership without understanding that the ultimate responsibility, it’s withheld by the CEO or the president of the company, right? So, I think, as Bill mentioned, having that good understanding of what that business process is, rely on CUI, who’s getting access to CUI, and understanding where CUI resides are fundamental and critical, right?
And before you say your path towards solutioning. And I think that’s one of the biggest mistakes we have seen is the technical guys and I’m a technical guy myself, you know, they want a solution immediately.
00:17:37 – Michael Leggett
Yep, yep. The three things that I had as talking points for this were lack of alignment, not understanding scope, and solutioning too quickly.
All those things are covered. We see that time and time again, and I understand the need and the desire to say, okay, we want to get this thing accomplished. Let’s put this in the hands of the professionals within our organization. This is an IT, this is a cybersecurity requirement.
But in practice this is just as much about the contracts that you’ve taken on and an understanding of who has access to the things that are called out within those contracts so you have to have that alignment top down that’ll probably be a recurring theme as we go through some of these other questions about like oh what should you try to avoid to do it really it comes down to that alignment and specifically I think it really step one should be understanding the scope and the impact to the business so to that note, what is the best way that you’ve seen organizations go about determining the scope of their environment?
And specifically, I get asked a lot from organizations that have maybe multiple subsidiaries, and they wanna know how that impacts it. So, any practical tips that you guys might give around determining scope and how that’s impacting the clients that you help service? Bill?
Data Flows and Enclave Strategies
00:18:52 – Bill Wootton
Yeah. I’ll kinda just continue to build off the idea of if you understand the business operations, the business flow, that will help give you an indication of where the data flows are. Those data flows then trigger down to what applications are going to see that CUI. Then you make a business decision on, do I need to have that operational flow the way it is? You know, for example, you may upload contracts that include the design attachments into your CRM system. Do you need to do that? Or could you put it in SharePoint?
One answer puts your CRM in scope, all of a sudden now you’re probably going to a FedRAMP version of Salesforce or some other version. The other answer says, I can eliminate Salesforce from my scope. I’ve just saved a boatload of money. And now I’m consolidating on what my scope and my tax service is gonna be, but go full circle and make sure the business can continue to operate and run with that change in process.
00:19:45 – Rolando Torres
Yeah, I think, I mean, the other part is the core business might be taken into consideration, right? If you’re a manufacturing operation, maybe you have that part down very well, because that’s what your technical team supports and operates. But you might be missing, like account receivables, account payables, the departments that actually get access to CUI documents specifically. So as far as the core functions, how do you support those functions, and how you’re going to be implementing the controls around those personnel?
And I think, as Bill mentioned, the FedRAMP component, I think that was one that surprised a lot of people when the rulemaking came down.
CMMC turned more into a FedRAMP conversation than what a lot of people expected.
But it’s something to consider. FedRAMP solutions and platforms are a lot more expensive than their commercial counterpart. And you have to take that into consideration when you design your solution. I think part of the cost creep, and we’re probably gonna go there a little bit later, is, you know, like, part of that is the design didn’t account for those costs to be higher. And this call wasn’t really focused on cost reduction from the compliance standpoint.
Managing CMMC Compliance Costs
00:21:00 – Michael Leggett
Yeah. Yeah. Let’s just dive right into it because one of the most common questions that I hear and I’m sure this is the same for you all. How much is this going to cost?
And part of that response is very dependent on where your organization is already at. So, my joke around that is: “How much is it going to cost? Well, how much does a bag of groceries cost?” Like it’s very dependent on the variables that are going on within your environment.
But even if you look at the most recent FAQ that was released from the Department of War, that is one of the specific questions they kind of basically say, well, it depends as well. So, I would be interested, know, Rolando, we’ll start with you to talk about what are some of the misconceptions around the costs involved for CMMC, and then what might be a couple of strategies to help keep that cost?
00:21:49 – Rolando Torres
Yeah, I think, you know, as we look into scoping of a solution for CUI and the CUI boundary analysis, it’s overseeing the ability to consolidate and control and make changes in business processes to reduce costs. I think that’s what it will be if resources were not an issue; most organizations will try to go enterprise-wide with CMMC compliance. They’ll spend everything they have on that. But the reality is, you have to be cognizant of cost control. And in many cases- not in all cases, but in many cases that leads to having that enclave, right?
With a cloud FedRAMP-compliant cloud solution that meets your requirements, right? You might have agile requirements; you might need GCC high.
You might not; you can probably go with GCC but looking into that option.
And then what are those business processes that currently exist, and how would they fit within that solution? For some organizations, they need to go enterprise-wide. And of course, that’s going to be the most expensive option. But it shouldn’t be overlooked, the ability to reduce the scope and try to reduce the cost that way.
00:23:09 – Bill Wootton
Yeah, it’s a great point, Rolando, in terms of the minimizing the scope, not only minimizes your attack service, it gives you a much, you know, it should be a better cost profile.
When we look at cost though, it’s like, you know, usually there’s a number that’s thrown out, and it’s just sort of a random number. You have to think about it in all of its piece parts. You’re going to have a certain amount of operational costs to run your IT shop. You’re going to need to keep the lights on, perform email, and manage your environment, and do all of the things that you would need to do to support the organization regardless of your security posture. The second layer of that is the security posture. What are you going to do to protect your environment? Whether that’s MFA or security monitoring or all those things, I hope at this point they can be considered all best practices in terms of how to simply protect the data, not only the government’s data, but your own intellectual property.
Once you get to the next layer of it, do you have a mature operation? Are you doing the things and cross-checking them with your documentation in the way you expect to do it? It should be an aspiration for most organizations to be able to run and operate effectively and efficiently. The last piece of that is the compliance, which, if you’re doing all those other pieces appropriately, is the cost of coming in and checking the work, being prepared for the test. There is some incremental cost that comes with it. But a lot of this is really mislabeled as things that you either need to do to simply function or should be doing in order to protect your environment.
00:24:36 – Michael Leggett
Couldn’t agree more. And the only thing I would add to that, kind of going back to what we were speaking to a few minutes ago, is looking at this as a business decision or as a business process. There’s a reason why you are adhering to these controls and to this compliance framework, and it has to do with potential dollars coming in the door of your organization through this through these contracts that you’ve signed. So, I think helping reframe it a little bit as a condition of possibility for the additional monies that will come in, I think helps lighten the load a little bit when you look at the overall impact it will make to the organization, and I couldn’t agree more, Bill with the last statement as well.
Being secure and being compliant are not always intersected. There are different layers to this, and many of the things that are required for your organization to adhere to CMMC also happen to be cybersecurity best practices. Just so happens that, in my experience, people don’t often do what they should do. They do what they have to do and thus look at this as the primary driver for them accomplishing what should be standard, sort of, table stakes for an organization.
There was something that you touched on a little bit, Rolando, that I’d like to just drill in a little bit more because this is another ask that we get a lot.
Hey, should I go Enclave?
Does it make sense for my organization? Just a couple of things from each of you that can help from a high level of saying, yes, it makes complete sense or no, you should go from an enterprise perspective. Couple things to think through.
00:25:59 – Rolando Torres
Yeah. I’ll start. You know, like, in many cases, what we see is, you know, companies that are already operating within the debt and have contracts that they’re fulfilling, they might have a misunderstanding of where their CUI really resides. And the conversation starts there, right? Where is my CUI? Is it really contained within the system that it should be contained, or is it spread throughout the organization? That’s almost like a starting point.
And if it is spread throughout multiple systems within the organization, is there a need for that? If there’s a business requirement that cannot be replaced with a more contained solution.
In many cases, what we have heard in the past is, I don’t know where my CUI really resides. It’s in email, it’s in systems, it’s in printers.
But if it has to be within the physical brick-and-mortar components of the organization, that brings a lot of systems in scope, including network infrastructure. And the cost is going to be a lot higher. Meaning, you might have network infrastructure that support fits 142. But if you don’t, you have to replace it. So, there’s an incremental cost to be able to bring some of those locations up to par with a requirement that you’ll be able to not have to invest in if you’re able to contain that.
But in some cases, like for example, if you’re an engineering firm that has to print blueprints and CUI of other form as part of a manufacturing process, you have no other choice but to bring those systems that handle CUI into scope. And that’s, you know, it’s gonna require you to have a wider scope on your CUI boundary than if it’s an organization that can actually continue to an enclave.
00:27:52 – Bill Wootton
Yeah, and we talked about enclaves to clients for almost every client has at least that question around it. And this is why that business process discovery is so important because it identifies the assets and identifies the individuals that are gonna be exposed CUI and not just necessarily directly, but indirectly. So, engineers, project managers, those types of folks may have access to CUI all the time, but maybe someone from sales or accounting or the executive level may not log in every day, but they are still going to want access to it. So then when we start talking about is what’s the choice between an Enclave or going all in, we generally start with what’s the percentage of the organization that’s going to have that access.
If it starts catching, if it’s below twenty percent, enclaves are generally a really strong starting point to evaluate and test to see if it works for them, because you’re going to be able to get a certain amount of cost savings to buy going enclave as opposed to bringing the whole organization up to the standard.
Once you get up to 25 or 30 percent, that inflection point starts to change because you’re double licensing and double paying for the cost of support of those individual users. Now we start thinking about do we go all in, or maybe even get to the point where you’re doing a reverse enclave, you’re leaving a small portion of the organization in commercial, but really the bulk of the organization is operating at that standard.
00:29:11 – Michael Leggett
Yeah, helpful insight there, guys. The other common question over and above Enclave or enterprise is, well, what about my MSP? What about my MSSP? What about these third parties? How does that play into my overall CMMC alignment, both from how they assist and then also how that impacts scope. So, I think if we could take a little bit to just give some pointers around that, that’d be super helpful. Bill, I’ll start with you.
Selecting Managed Service Providers
00:29:38 – Bill Wootton
Yeah, so if, you know, obviously we play that role. That’s the role that we play with our clients as that service provider. There’s a couple of different things that you really wanna consider.
You know, the final rule, rule thirty-two did not require service providers to be CMMC level two compliant. However, it strongly encouraged it, and it gave assessors the ability to go poke around in the MSP or MSSPs back office if they’re providing services and they have access to the client’s environment. So that’s a huge risk reduction for clients for working with a provider that has that internal CMMC level two certification. The other piece is that provider is gonna be acting on your behalf, and therefore they are required to have what’s called a customer responsibility matrix, which explicitly defines on each assessment objective, what are they doing for you? What is a shared responsibility or what is going to be the client’s responsibility? Those are two critical pieces when you look at service providers, how are they going to interact and how are they gonna impact your final assessment situation?
00:30:45 – Rolando Torres
Yeah, in addition to that, at Thrive, we provide these services for CMMC clients, right, from the MSSP side, providing 24/7 monitoring from the US based SOC. And then on the management and operations of, know, Enclave and other systems, is what are the, first of all, where’s the personnel, right? Is it US based, US citizen personnel that is being provided provision access to your systems?
What are the tools that are being used and are those FedRAMP compliant, right? I mean, data residency is a major component to this.
And then, do they have the policies and procedures documentation that support their CMMC level two compliance argument, if they’re self-attesting. And preferably, right, hopefully they’re CMMC level two certified. So those very important components when it comes to choosing an MSSP, an MSP, or like a GRC services company, which we do all three of them as part of your journey. At the end, you’re ultimately responsible for your compliance posture and the certification.
Especially if you’re self-attesting, you wanna make sure that you check all those boxes because you’ll be responsible for anything that happened, right, if one of those service providers actually gets breached or causes a breach in your organization.
Self-Assessment Versus C3PAO Audits
Michael Leggett
Yeah. And that’s a that’s a really good segue because with this recent pause on potential involvement from a C3PAO, can you guys talk a little bit about what the difference from a self-assessment versus a C3PAO assessment is and what that means for the client and how much responsibility is placed on them versus a third party?
Whoever would like to start.
00:32:36 – Bill Wootton
Yeah, I can jump in and, you know, if you follow the CAP and the acronyms escaping me right now, which is basically the instruction manual for doing assessments, the difference between a self-assessment and a C3PAO is essentially there’s not a C3PAO; everything else is you’re supposed to accomplish. You’re supposed to go through all the assessment objectives, collect evidence, and validate what you’re doing.
The requirements are essentially the same; you just don’t have that third party sitting there. And this starts to materialize itself in the SPRS scores now; that system has evolved so that when you go in and you put your SPRS score in, you’re no longer just putting a number and signing off. You’re putting a score in for every control, which really kind of elevates the commitment that you’re making as attesting to the fact that your self-assessment score is what it is.
00:33:25 – Rolando Torres
Yeah, I think, with that, comes also the responsibility, right? When you have a C-31 involved, they provide attestation and certification on your posture, right?
You’re hedging your risk, right? I mean, you now have a third party that actually went through your documentation and made sure that your controls were implemented in place using a sampling methodology and a well-established standard. When you’re doing the self-attestation, if you look at self-attestation, it’s not really new, right? The SBRS scores from many, many years ago were part of that self-attestation component.
Many organizations just say, oh, I’m one hundred and ten of one hundred and ten, high five, we’re good to go. But the reality was there was no level of scrutiny on the real implementation of controls and documentation. And what we see sometimes is the realization during the gap assessment that we performed at the beginning of our engagements that your SVR score, the one that you reported to DOW, is actually wrong. It’s not really where it needs to be.
Lacks documentation, lacks control implementation. There’s no evidence collection. There is no monitoring of the control. So, there’s a lot of things that you would think, you almost like said you had in place that you don’t.
And part of that is, just to be honest, just to add a little bit more is, these things are difficult, right? I mean, they are complex and your typical IT personnel, IT manager, he’s not a compliance expert. Hasn’t gone through an especially for the mid-market and small companies, right? He hasn’t gone through a whole process of readiness and audit before.
And they’re trying to make sense of what the requirements might be at some point.
To the best of their ability, they say, yeah, I comply with that. But the reality is there’s more that needs to be done to be in full compliance.
Common Control and Documentation Challenges
00:35:19 – Michael Leggett
Yeah, yeah. And to that note, you know, let’s spend a little bit of time on what are the objectives or controls that you guys see typically requiring more effort than organizations expected or the burden of proof is higher than perhaps what was expected? Let’s start with you, Bill.
00:35:37 – Bill Wootton
Yeah, so it’s not a specific control, but it’s a requirement and it’s the system security plan. It is the whole of documenting and mapping everything that you are doing into the documentation according to the various assessment objectives. The documentation is where it goes from practice to maturity. And that’s the spot that is always the hardest part for a lot of folks.
00:36:01 – Rolando Torres
Yeah, I think, I mean, like if you go to control families, right, there’s some that are a little bit more aligned with what most organizations do every day. And then there’s some that ask for more.
And specific to that, like configuration management is one area, right, that we see a lot of issues.
Organizations that have military leadership, former military leadership, they understand the stakes and configuration management better from their military careers.
But most commercial organizations that have a defense division sometimes struggle with some of those controls on the configuration management. And we have seen that quite a bit. Access control is also another one that, for whatever reason, brings additional challenges, right? It’s just the level of rigor required by the standard, which is actually aligned with best practices. But it’s typically one of the ones that we say.
The other one is identification authentication. That’s the last one that I will say is, you know, things that you would imagine, you know, like having a proper asset inventory, things, you know, documented and put in the proper place in terms of documentation. Most organizations don’t do that, right? They don’t have the time. So, I have to come back and keep up with that. So those three are, and I asked my team for that. It was interesting that we got that answer.
00:37:28 – Bill Wootton
Yeah, I even built up on the practice of change management and the discipline required to continually maintain that point of every time you make a change going through the process to review it before implementing it.
And unfortunately, the time that it takes for that is really the one thing that we see a lot of folks struggle with as well.
00:37:48 – Michael Leggett
Yeah, yeah. And to that note around that documentation and those changes and the evidence collection, in your experience, what’s made for a strong SSP versus one that creates issues during the assessment period? What are the commonalities between those?
00:38:07 – Bill Wootton
So, not staying up to date on your change management really starts to show when you start preparing for the assessment, you do your mock assessment and you start validating what was written maybe three, six, nine months ago to what the configurations look like today. All of a sudden, start seeing those deviations when you go through and you realize just how far you’ve drifted off there. So that’s probably one of the big areas that just kind of reinforcing that is being up to date and disciplined and really deliberative about your change management process.
00:38:42 – Rolando Torres
Yeah, I would add to that. I mean, I think we see SSPs, policies, and procedures that are coming out of templates that don’t apply to the actual configuration and controls that are in place.
And I get it. We want to find as many shortcuts as we can right in the process. But the reality is, during the audit process, your documentation will be reviewed and evaluated first for completeness. But then the fieldwork has to represent what is in your documentation.
I think we see some struggles there, right? Because you start with an SSB, which is pie in the sky of things, I think things will work at the end. But the reality is, once you start implementing the environment and you start to deal with the different areas, it’s a completely different environment. Right?
There’re different configurations and settings, and everything needs to be in sync in order for the, you know, the auditors to give you, you know, your 110/110.
00:39:45 – Michael Leggett
Yeah. Yeah. And the phrase that I like to use a lot for clients going through this is just remember that auditors are people too, you know, for the most part. So, if you can make their life easier, you have it well documented, you can show that that collection and it’s clean and it’s up to date and it’s well documented, your life will be a lot easier.
The process will not be as burdensome. It’s easier said than done but taking the shortcuts or making it more aspirational is not helpful in this process. That’s where I see a lot of people getting tripped up as well. Yep.
00:40:18 – Bill Wootton
So, for us, when we’re preparing a client for an assessment, we build an evidence playbook. We build a dedicated evidence playbook for them. We use it as part of our mock assessment. We go through all three twenty assessment objectives so that everyone knows what the answer is, what screenshot, link, paragraph we’re pointing to, and who’s responsible for giving that answer. And it really shows through when we get to the assessment, we have the look of an integrated, you know, well-rehearsed team because we really are.
00:40:50 – Michael Leggett
Yeah, I love that.
It really does just make all parties, makes everyone’s life easier when those things are going through, if you prepare properly and have those mock assessments done in the most reflective manner of what’s actually going to happen sometime for an audit. We’re getting close on time here, but I do want to just give some airtime to perhaps one piece of advice. One overarching piece of advice to folks that are going through CMMC, maybe they’re halfway through, maybe they’re just starting.
What is one piece of advice that you would give to organizations pursuing this that you think would be the most helpful for them?
00:41:29 – Rolando Torres
Yeah, no, I think I mean, we have covered a lot, right? I think in terms of advice, you know, looking at, you know, the business processes, the CUI data flows, you know, doing data analysis upfront before you jump into, you know, designing the solution that you’re gonna use.
For those organizations that are already part of the deep and are supposed to be compliant with the standard. Right? It’s looking at what are the things that they can do to improve and optimize their solution, consolidate so that they can eventually go through the CMC level to certification process.
But think, I mean, it all goes down, comes back to CUI, protecting CUI. I want to say the DoD is going in a better position right now in terms of cybersecurity posture than it was at the beginning of the program. So, everyone is trying, right? It’s doing the trying to do the right thing.
But I think having those conversations at the business level and spending the time upfront to get buy in from the business before you jump into designing is gonna save a lot of time.
00:42:44 – Bill Wootton
Yeah, it’s a great point. I’d echo that in terms of, you know, having the involvement and the active participation of the business side, it’s not a technical project, it’s a whole business effort. And then the other thing I’d probably talk to is, for all those organizations that haven’t started yet, there’s generally someone who’s a holdout on that process. It’s usually not the technical guys, usually not the cyber guy. There’s someone out there that’s in the, you know, executive team that is just not ready to make the quote investment or the cost of it. Are they getting past that point and recognizing this is coming? It’s just a matter of when and how.
And if you wait too long, you won’t have the time to react to your contract. And therefore, you’re going to either make a bad decision or a panicked decision that isn’t gonna serve your business well over the long term.
00:43:32 – Michael Leggett
Yep. Yep.
Understanding alignment of your business, understanding the scope of how this is going to impact you, always great starting points in the areas that if you have those things really dialed in, a lot of the other things will come with time, and you can work through those. Last question here, what are we looking at for current assessor capacity and how do we think that the suspension will impact that?
Bill?
00:43:58 – Bill Wootton
Yeah.
You know, a lot’s been talked about assessor capacity. Assessor capacity is not where the real bottleneck is. The real bottleneck at this point is companies being ready for assessment and going through. There are assessors out there that have open spots in their schedule over the next several months.
There are some plenty that are fully booked out in the next year, but there are those that have spots in there. It’s about folks recognizing that being ready takes time and just not being ready. We don’t have 10s of thousands of companies waiting for an assessment and that’s the bottleneck. It’s really about the organizations that are in that journey and not quite ready there to be ready there yet.
00:44:39 – Rolando Torres
Yeah, that’s, you know, we’re not a CFAPL, but we work with quite a few of them. And we’re hearing the same thing. I mean, like our clients, when we make introductions to CFAPLs because they’re ready for their audits, we’re not really looking at a very long onboarding period. I mean, it seems to be like there’s capacity in the market.
I think the pause is going to increase that capacity, right? As some of the organizations really didn’t need to be compliant immediately, they are probably going to take a little bit longer to jump back on. Plus, in addition, the CMMC AB continues to, you know, approve other C3PAO’s to come into the market. I don’t think that’s gonna be an issue or is not an issue at the moment.
00:45:20 – Michael Leggett
Perfect. Perfect.
That concludes the roundtable portion of this. I wanted to turn it back over to Stephanie, and there are couple other items we wanted to address and perhaps some questions from the audience if there were any.
00:45:36 – Stephanie Hamrick
Yeah. Thanks, Michael, and thank you to all of you. There was a lot of useful information in there for our audience.
We wanna end here with a few key takeaways. So first, the suspension paused just one requirement of the program, but it did not pause your obligations. So, phase one requirements still apply, and if you treat this like a break, you will fall behind.
Second, readiness work done now is never wasted. As our panel here said today, a self-assessment follows the same process as a C3 PAO assessment. So, any gaps, scoping decisions, and SSP quality issues need to be addressed either way, and right now is a great time to get ahead of it.
And lastly, slow down at the start to get the fundamentals right. As you heard here, you do need to put in the work upfront on scoping and being honest with yourself about where you really stand. If you get those wrong, then at the end of the day, no single control is going to save you.
And, of course, if you need help with any step in the process, whether that’s nailing that foundation or performing a self-assessment, we would like to remind you that at Bluewave, we can help you find clarity on what to do next. We can learn about your business, where you currently are, and where you need to go. And then we connect you with top-tier partners like Thrive or C3 when their solutions align with what you need and where you want to go. So, with that, I will thank everybody for joining us today.
Q&A Session Commencement
00:47:24 – Stephanie Hamrick
We do have a few minutes here, so I’m gonna hop into the Q and A and ask some questions. Some of these might be a bit of a repeat of some stuff we already covered, but wanna make sure we double tap on these and get those answered. So let me take down the slides here so we can see all of us well. Our first question here, how will this change evidence gathering?
Will NIST 800-171 revision 2 still be the benchmark, or will they update it to revision three?
00:47:59 – Michael Leggett
Well, short answer is how does the how does the suspension change it? The suspension doesn’t change it at all. What will come on the heels of it and any updates that may happen, you may see an update to rev three. We won’t really know until we know. But for now, the same as it has been. So, continue to align with rev. two.
00:48:18 – Bill Wootton
Yeah, and I think it’s important to understand that, you know, Rev 2 and Rev 3, there’s pretty significant differences between the two of them. It is not just like a kind of point-and-click upgrade and move on. There’s a significant amount of work, not just for the company going from one version to the other, but throughout the entire chain. All of the assessment guides will need to be updated. There was a lot of work already being done on that transition from Rev 2 to Rev 3. And the expectation is that there would be some overlap and it would take a period of time to be able to execute that transition.
Evidence Gathering and Audit Authority
00:48:56 – Rolando Torres
Yeah, I would add to that because the question also included the evidence gathering, right? I mean, I think that’s critical. Operating, maintaining, and monitoring the controls is critical. Let’s not forget that the CAC still has the authority to audit. So, at any given point, you might need to present that evidence that you are operating your controls.
00:49:18 – Bill Wootton
Great point.
00:49:24 – Stephanie Hamrick
That’s great advice. Alright. Another one here. What happens to the RFI comments after August 14th?
00:49:32 – Rolando Torres
Well, I mean, I I’ll jump in based on the CM and CAB town hall. So, the sixty-day pause with the RFI is gonna be collecting all that information.
And there is a fifteen-day period for a report to come out. So, whatever the decision is, that report will include some of those comments. And I will take into consideration some of the feedback. And then we’ll know exactly what has been adopted from the feedback provided by the DIP in during the RFI.
Starting the SSP Process
00:50:00 – Stephanie Hamrick
Awesome. And the last one here, where do I start with an SSP if I’ve never done one?
00:50:14 – Rolando Torres
Think it’s a great question.
You know, like I mean, like, understanding that compliance and cybersecurity are disciplines, right? I mean, it’s a question of whether or you have that background and the understanding.
If your organization requires to be CMMC compliant and you don’t have the understanding of what needs to be done, I think the answer is to partner with a company that will help you through that process, a consulting company that will help you through the readiness. I think going along, if you don’t have the proper knowledge and understand the process, it’s just not going to bear the results that you want. So, accounting for getting proper consultants to help you is the safest way to go.
00:51:01 – Bill Wootton
Yeah. And I’ll kinda build on that a little bit in terms of, you know, from our perspective, at least my personally, the SSP is the last step, not the first step. Yeah, we all the things that we talked about over the last hour around understanding your business, defining your scope, deploying your technology strategy, having your plan for map for how you’re going to operate the business, then you can build that SSP based on what you’ve designed and executed as your strategy for your unique situation.
All those pieces need to be in place because the SSP, at the end of the day, needs to be a reflection of what you are doing from an operational standpoint, and then it becomes the reference point to make sure you’re still on track.
Leveraging Third Party Services
00:51:42 – Michael Leggett
Correct. And where I’ve seen a lot of clients get benefit from leveraging services is that they have someone that can shepherd them through what a typical process looks like. I don’t even know where to start. How do I start?
How do I understand what my scope is? How do I understand contract language? How do I communicate the needs to upper management that thinks this is an IT project? And that’s where having a third party that can come in from an RPO perspective can be really helpful and impactful not just for the technical ends not just for the creation of the SSP but also helping organize and get alignment early on so that that SSP ends up being more impactful.
00:52:20 – Stephanie Hamrick
Yep. Fantastic. Yep. Great point.
Awesome. Alright.
That brings us to the end of our Q and A session for today.
I wanna finish up this session just by saying a thank you to all of our panelists for hopping on with us and sharing their knowledge. A ton of great insight was shared today, and I think we left our audience with a lot to think about.
Speaking of our audience, thank you to all of you as well. We hope you learned something new, and we hope to see you all on our next session. So, with that, one last thank you and a goodbye.
00:52:52 – Michael Leggett
Thank you.
00:52:52 – Rolando Torres
Thank you.
00:52:53 – Bill Wootton
Thank you, everyone.