Webinar Replay | 60 minutes

CMMC has entered a period of change. With the Department of War's suspension of Phase Two, many organizations across the Defense Industrial Base are asking what the pause actually means for their obligations and their spend.

Here we dig into how smart organizations are using this window to get their scope, documentation, and fundamentals right.

 

Join Experts from Bluewave, Thrive & C3 as They Discuss CMMC Lessons From the Field

  • The suspension paused one requirement, not your obligations. Phase Two's pause affects C3PAO involvement. Phase One requirements and underlying controls still apply; NIST 800-171 and DFARS 7012 obligations remain in force, and the DoW still has the authority to audit. Treat this as a break, and you'll fall behind.
  • Readiness work done now is never wasted. A self-assessment follows the same process as a C3PAO assessment. Every gap, scoping decision, and SSP quality issue has to be addressed either way, so the pause is a great time to get ahead of it.
  • Slow down at the start to get the fundamentals right. Put in the work upfront on scoping and be honest about where you really stand. Get scope wrong, and no single control will save you at the end of the day.
  • CMMC boils down to a business challenge. Ultimate responsibility sits with the CEO or president, and business operations must be active participants from day one. Lack of alignment, unclear scope, and solutioning too quickly are the most common early mistakes.
  • Scope drives cost; map where your CUI lives. Understanding your CUI data flows lets you decide between an enclave and going enterprise-wide. Minimizing scope reduces both your attack surface and your cost profile.
  • The SSP is the last step. Your System Security Plan should reflect what you actually do operationally after you've defined scope and executed your strategy. Then it becomes the reference point that keeps you on track.