CMMC After the 60-Day Review: What DOD Decided, What It Didn’t, and What to Do Now

October 6, 2026
  • copy-link-icon
  • facebook-icon
  • linkedin-icon
  • copy-link-icon

    Copy URL

  • facebook-icon
  • linkedin-icon

CMMC wasn't suspended. Only one piece of it was, and the defense contractors acting like the whole program went away are the ones taking on the most risk.Eighty days after the DoD CIO paused CMMC Phase 2, the 60-day review has closed, a class deviation has written the pause into contracts, and the Reform Task Force's recommendations are still not public. Contracting officers and primes aren't waiting. Some solicitations now require a posted SPRS score before you can even open the RFP.

In this SecureTalk panel, host Justin Beals sits down with three NIST SP 800-171 practitioners (a C3PAO strategist, a lead CCA and instructor, and a former Navy cryptologist turned enclave provider) to separate what DoD actually decided from what the internet decided for it.

WHO THIS IS FOR
Defense contractors and subcontractors, compliance and IT leaders preparing Level 1 or Level 2 self-assessments, MSPs and MSSPs serving the DIB, and anyone trying to make sense of CMMC after the Phase 2 pause.

TIMESTAMPS
00:00 Why this episode is a panel
00:39 Meet the guests
04:11 "We're NIST 800-171 experts, not CMMC experts"
05:16 80 days after the pause: where things stand
07:21 What hasn't changed: Level 1 and Level 2 self-assessments
08:26 Myth: "CMMC was suspended"
11:33 No SPRS score, no RFP documents
14:08 CMMC is a floor, not a ceiling
14:26 The FAR overhaul and retired clauses still in contracts
18:29 Myth: "CMMC got pushed to November 2028"
22:02 The class deviation most people misread
24:14 What a defensible self-assessment looks like
29:06 Reddit, Discord and the misinformation problem
33:30 Myth: "My MSSP handles CMMC for me"
36:40 Myth: "Our policies prove we're compliant"
40:32 Myth: "We bought an enclave, so we're done"
44:07 Where the real risk lies now
51:13 How to choose outside help

SOURCES REFERENCED
- DoD CIO memo suspending CMMC Phase 2 (July 13, 2026), via Federal News Network: https://federalnewsnetwork.com/cybersecurity/2026/07/pentagon-suspends-cmmc-phase-two-requirements-launches-review-of-program/
- Sept. 3 acquisition memo codifying the pause, via MeriTalk: https://www.meritalk.com/articles/dod-codifies-pause-of-cmmc-phase-2-dod-cio-says-more-work-needed-on-cmmc/
- 32 CFR Part 170, the CMMC Program rule (phased rollout in §170.3): https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-G/part-170
- NIST SP 800-171 Rev. 2: https://csrc.nist.gov/pubs/sp/800/171/r2/upd1/final
- NIST SP 800-171A, the assessment methodology: https://csrc.nist.gov/pubs/sp/800/171/a/final
- CMMC Program Final Rule: https://www.federalregister.gov/d/2024-22905/p-1876-

- Free executive level class: https://www.evolvedcyberacademy.com/courses/Rev3LeadershipWHAT

- CMMC Level 2 Self- Assessment: Step-by-step with Templates: https://www.strikegraph.com/blog/conduct-cmmc-level-2-self-assessment

YOU'LL LEARN
The requirement never moved. The pause hit third-party C3PAO assessments, not NIST SP 800-171 compliance and not Level 1 or Level 2 self-assessments. Brian Hubbard sets the bar at a self-assessment you could defend "if the DIBCAC walked in the next day after you posted your score."

November 2028 is not a new deadline. Logan Therrien explains it has always been the end of CMMC's four-year phased rollout. Reading it as a two-year reprieve is one of the costliest misreadings in the market.

The market is moving faster than the policy. Vince Scott compares it to oil moving through the Strait of Hormuz: there are months of supply in the system before anyone feels the change. Primes are already asking to see SSPs and SPRS scores.

GUESTS
Logan Therrien, Chief Strategy Officer, Kieri Solutions (C3PAO); 24-year military veteran
Brian Hubbard, President, Evolve Cyber; Lead CCA and CMMC instructor; 40+ years in cybersecurity
Vince Scott, CEO, Defense Cybersecurity Group; retired Navy cryptologist

HOST
Justin Beals, founder of Strike Graph and host of SecureTalk, a podcast focused on security news, innovation, and excellence.

🔔 Subscribe for conversations where cybersecurity, compliance and national security meet.

#CMMC #NIST800171 #DefenseIndustrialBase

View full transcript

Justin Beals:  Hello everyone, and welcome to Secure Talk. I'm your host, Justin Beals. This is a little bit of a different format from our normal Secure Talk podcast. The reason being we're having a bit of a panel discussion today around CMMC and the current state of CMMC. And so since we're bringing in a lot of folks today and we're moving very quickly, that seems counterintuitive to what we know about compliance, but it's been a little bit of a roller coaster.

I'm gonna start off by letting my guests provide an introduction of their background. And why don't we kick off with you, Logan? Give us a little bit of your background and how you came to join us today.

Logan Therrien:  Sure. Thanks, Justin. So my name is Logan Therrien, and I'm the Chief Strategy Officer with Kieri Solutions. We are a CMMC third-party assessment organization that also provides CMMC consulting, this 800-171 consulting for the Dib. My background, twenty four years of military experience, and I converted it over into the CMMC spectrum and haven't looked back since then. It's been a blast, if not a challenge, every single day. And then I'm also working on my PhD, and I focused a lot on supporting the DIB and trying to understand compliance obstacles and help them get through that as well.

Justin Beals: Excellent Logan. And Brian.

Brian Hubbard: Sure. So I'm Brian Hubbard. I'm the president of Evolve Cyber. We are a CMMC, totally CMMC-focused company. and I should I should expand from that, I guess. Now we're actually working with all of the federal government on even on  800-171 Rev3. But we are an authorized training provider for CMMC.

And by the time this airs, we will be an authorised C3PAO. So we're running down that path. And me personally, I've been in the cybersecurity business for over 40 years, doing assessments and evaluations and all kinds of other related things. I'm a lead CCA for CMMC and a credentialed instructor as well.

Justin Beals: Excellent. And congrats, Brian. Well done. Vince.

Vince Scott:  Yeah, I'm Vince Scott. I'm the CEO of Defense Cybersecurity Group. We're a company that is focused on the CMMC space, but not exclusively in that space. we have two sides to our company: a consulting and preparation help side to the company and an MSP side to the company. So we are an external service provider with aspirations to be a cloud service provider, I guess, at this point. We've completed our FedRAMP moderate equivalency package and gone through the whole 3PAO process. We're on the FedRAMP marketplace, all that good stuff. That's been exciting. And then me personally, I like Logan; I'm a retired Navy officer. I was a cryptologist, so I think I used to play offense. So I had nothing to do with defense in my Navy career or training track or anything. We're really exclusively focused on offense. So the whole CMMC world, looking at this through the defensive lens, is a little different than for me. And I also think I look at it differently. I look at cybersecurity differently than a lot of people in the community, most people either grew up in IT or they grew up in sort of the GRC space, right? I didn't grow up in either one of those spaces. I grew up breaking into other people's stuff. And so that's a that's a very different mindset. Where I come from sometimes impacts what I think is important in the cybersecurity world. I just see it differently. So.

Justin Beals: Yeah, thanks, Vince. 

Logan Therrien: Thanks, Justin, can I add something real quick?

Justin Beals:  Please, Logan, yeah.

Logan Therrien:  Just because I  think it's imperative and we're probably gonna bring it up later on the conversation anyway, so we can get it out of way. I think we all just said we're CMMC something. And  I wanna just work around this because it's so embedded in all the titles. You know, I'm a I'm a CMMC certified CMMC instructor, so is Brian, right? And you know, we're all lead CMMC certified assessors. However, just let's step it back. What we are are NIST 800-171 in whatever revision.

Vince Scott: All three of us.

Logan Therrien: Subject matter experts. And and that we'll we'll talk about that more, I'm sure.

Justin Beals:  Yeah, but I do think it's a it's a critical discussion because the words conflate and it makes for confusion. I talk about all the time, actually, in our own software, we don't have a CMMC framework. We have a NIST 800-171 Rev. 2; we have a NIST 800-171 Rev. 3. When I talk with someone about becoming compliant, really our conversation wraps around that. And I describe CMMC as an assessment methodology broadly. You would agree with that, Logan?

Logan Therrien: Exactly. One hundred per cent.

Justin Beals: Yeah. So, and actually that probably brings us to our first good topic to begin with. And maybe I'll pick on you, Logan, to start off with. It's been 80 days since we received the prior memo; I believe it was back in July, then, if I'm counting back, right?, that put a pause on a future November phase change in the rollout of the the DOD's securitization of their vendors.
what you know, maybe Logan, you can just take us today. What's the current state of affairs from your perspective?

Logan Therrien: We're in a pool of assorted opinions, surrounded by a mist of speculation. And and I don't think what I think has changed is just Logan's view, is the readiness progression has slowed down due to the ecosystem not understanding what the next steps are and getting to that end so abruptly.

So I think I think we're kind of taking a back turn in readiness across the dib. And that has been the only change. There's been no level of understanding of what's going forward at this point. And anything that we hear is speculation from a social media post or something that was misinterpreted and then gained tremendous s velocity in the wrong direction.

Vince Scott: Well, we do know some things, right, Logan? Right. So, I think one of the things you're hitting on is the misinformation aspect of myth, rumor, I once heard on a podcast, sort of information that goes around, but you know, from your perspective, what are the things that we do know that Department of War has written some things down, and I'm sure you're familiar with those.

Logan Therrien: Well,  so what I do know, what I do know is that the requirements have not changed. That is that is a solid, steady, it's still written down, right? The requirements to be compliant with NIST 800171 across the DIB. if it's if it's in that contract, whether it was written you know, well, if it's a seven D470 12, it's still a requirement. Whether or not it's gonna be self-assessed, assessed by somebody else. and then there's other levels, right? There's that level one requirement that hasn't changed, right?

Vince Scott:  Well and there's even CMMC requirements beyond seventy s twelve requirements that still exist in contracts, right?

Logan Therrien: Absolutely. Absolutely. In fact, there's, you know, the the suspension only affected partial of that CMC requirement. Just that third-party assessment and then the the level three for the dip to step in. And so, again, the self-assessment for level two has not gone away. The self-assessment for level one has not gone away. And so again, the the lot of the things that those were and I and I guess the how I got to the things that have changed, right? The things that we haven't really seen much change because those were still in effect day one of the suspension memo being published.

Vince Scott:  I still think there's a lot of confusion around that though. There's there's a lot of people who are thinking, well, CMMC was suspended. Well, no, that's not really what happened, right? I just did a I I tried to look back the last 30 days of RFPs, right? And we do see, we still see CMMC level one and level two self-assessment requirements in contracts.

I did see a couple of contracts modded to move from certification requirements to self-assessment requirements, which is in accordance with the pause and the DODCIO's memo on the subject. So I am seeing some adjustments. I'm also continuing to see a lot of variation in what people are actually seeing come down the pike in p contracts. And I think that adds to this confusion and challenge that we have explaining to everyone accurately what's going on with CMMC is that the actual wording, the contract clauses, the requirements in the contracts are changing, right? And varied across individual contracting authorities in the government. So I was looking at US SOCOM contracts and US SpaceCOM contracts and NAV spec warcom contracts and blah. And what I saw was very different approaches to the cybersecurity requirements in those different contracting activities.
 One of the big things I saw, though, and I'm interested if you guys are seeing it, is a movement of the cybersecurity requirements having to be met at contract award to at proposal and even to
You've gotta have a one ten score in SPRS in order to be able to see the RFP documents at all. Are you guys seeing that in your work too?

Brian Hubbard:  Well, I haven't paid much attention to to that because I'm not in the in the not doing answering the mail on government contracts, but but it doesn't surprise me, right? It's it's it's when a when a government contract analyser gets a set of proposals and they're saying, Yeah, we'll be we'll be compliant at contract award. Well, that's a risk, right? So now they're gonna say, Well, when you submit your proposal, you should be compliant already.

And already have you know have all your things in order, and that makes sense, right? From a from a contracting officer evaluating a set of proposals, that makes a lot of sense. And likewise, it makes a lot of sense for primes when they're talking to their subcontractors. They can't talk to their subcontractors and hope that they're gonna get ready by the time they get or get an award. They have to make sure their subcontractors are assessed and ready and compliant now, before they ever put their proposal into the government. You know.

Vince Scott: Well, and increasingly I'm seeing you need something, a one ten score, a UID, an eighty-eight score, something, in order to be able to receive the CY documents that are the request for proposal. So the request for proposal itself is CY. They're not releasing that document unless you already have proof in the system that you're able to handle and properly process, store, and transmit that information as required, which is an interesting twist from CMMC: it's suspended; you can't see the RFP unless you actually have already reported your compliance.

Logan Therrien:  And Vince, I think I'll need to go back and look, but I I just I believe that was a change between the Spurs reporting requirements under DFARS 225 224 7019 to the CMMC requirement in 7021. And I think that's where that wording shift happened is one had you had to have the Spurs scores in there that was no later than three years old, and then the next one was you have to have a CMMC assessment score. And

Vince Scott: Yeah, well, from a regulation perspective, the 7025 clause actually brought some pre you know at at proposal instead of at award language in. But really what I'm seeing is it's being written into, not using the clauses per se, but the contracting activity is actually writing it into their process for the RFP, and saying, hey, I'm not going to give you those RFP documents unless you already have a one-tenth score, which is fascinating.

Logan Therrien: Yeah. Again, a risk if you weren't prepared.

Justin Beals:  Do you think that the, you know, Vince, the things that you're bringing up, and I'm trying to read into what's happening with the contract officers. But considering the amount of confusion we've had on the, you know, the private sector side, I have to imagine there's an equal, if not larger, amount of confusion on the public sector, you know, government buying side, and that contracting officers are navigating a a legal decision in a way of what to put in these RFPs and probably a little bit of CYA work on what they write down, which is probably more rigorous than if we had left the process in place, or at least I would be. I would be inclined; it wouldn't hurt anything to be more rigorous as a contract officer than in a space where I don't quite know where to put my feet on the ground.

Brian Hubbard: Well I think we should also bear in mind that, you know, CMMC and any other you know, Code of Federal Regulations program is a floor, right? A contracting activity can decide what they want to put in a contract for requirements based on their program needs.

Vince Scott: Yep. Yeah, so but one thing I would add, Justin, is there's a a lot of ignorance, unfortunately, even across the contracting officers. So there's a certain amount of bureaucratic momentum I see in how this moves, right? . Having watched this now, when I retired in 2010. I went to work for Oklahoma State University, but I was a director in the multi-spectral lab. We did a lot of government contracts, right? So I've sort for the last sixteen years I've been watching that government dip contracting space sort of on and off. And these changes don't don't necessarily instantaneously happen across all of the contracting activities, right? And we do get a lot of contracting officers who will tell me I've always done it this way? Well, I've been doing this for 10 years, and I've always done it this way. And in cybersecurity, that probably means you're wrong. Because let me tell you, this area of regulation has been maturing quite a bit over the last 10 years. So if you're still doing it the same way you were, that's probably not in accordance with the regulations.

And so you mentioned, Logan. We have DFARS overhaul going on, right? So where there's a lot of changes to the federal acquisition regulations. One of those is that the DFARS 252-204-7019 clause, which actually is the one that said you have to have a DFARS score in and sort of started this off, came out six years ago, right? That was sort of the initial I gotta report how I'm doing this to the DOD, has gone away. That was taken out.  Now, di  I still in this last 30-day review? Did I see a lot of 7019 clauses still, you know, listed by reference? Absolutely. Right? That hasn't caught up. Now that change was made in February. Here we are in October. We've still got this appearing in contracts. And so that will probably go forward for years, honestly. We will continue to see a clause that's technically been retired appearing in our contracts. And we will continue to see people saying, hey, you have to have your basic self-assessment score, which is a little different than your CMMC score, put into SPRS. Even though technically that was retired in favor of CMMC self-assessment. Those were wisely viewed as redundant, right?. And saying don't have to do a 171 score and a CMMC level 2 self-assessment. And by the way, the 171 score process didn't allow for a real level one company. There that was a hard, you know, if I'm really not handling CUI, but I've got FCI and I'm supposed to be level one, how do I report that accurately to the government? Was a problem in that process. 

Now we have CMMC level two and level one. Let's just use that. But that's going to take time to change, and that's an additional level of complexity on the top of changes, reform task force, all of that. And that translates differently in all these different contract activities and what they're looking for. In general, though, in that review, I saw a trend to ask for more scores or something that shows me you're doing this, not just blind trust.

So that's a change. That's not the way we were three or four years ago. And those requirements are coming at the RFP stage or the pre RFP pay stage, even to get the RFP documents, and they're not waiting until contract awards before you've got a cybersecurity requirement, you gotta meet.

Justin Beals: I think and Logan, I'll ask you to speak to this a little bit. And I think it builds on what Vince is communicating here because a lot of contractors have said, they've moved it to November of 2028, right? It's kind of deadline sort of the next phase. And you know, Vince is talking about this transition from the first D FARS to what was then updated and now a pause to that particular rollout, which has made it very confusing. yeah. So Logan, let's put a fine point on the November 2028 interpretation that a lot of government contractors have had. Yeah.

Logan Therrien: Yeah, certainly. So if you go back and you look at the timeline, the phased rollout for CMMC, and I believe it was in the preamble of thirty two CFR one seventy, the Federal Register version, it had a four-year phased rollout for CMMC because the government, you know, the way I understand it is that the government di figured it might be difficult for 120,000 companies to get a third-party assessment within, you know, a very short amount of time. So they said, let's roll this out, contracting officers, use your judgment in a in a way that doesn't shut down the defense industry, and make it last four years, right? So, you know, starting with the first year, we're going to see level one self-assessments in there. We're gonna start seeing level two self-assessments, you know, with I think, them it was we're roughly around 12 12 to 14000 level two third-party assessments, and then start increasing those by volume over the next four years, which, if you do the math, was November of 2028. And so there was a memo that came out a few weeks ago. And in it was very, if you read it, at the top it said, you know, the I think the italicized notes are the new additions. Everything else is just kind of being pulled from multiple memos, and it's a way for the DOD to say, all we've said a lot. 

Let's get it into one document and get in front of but that date of November of 2028 stuck out to a lot of folks, and we got and talked about the misinformation. And so a lot of people who read it said, Hey, this is getting pushed out until two or couple of more years from now. So we don't have anything to worry about. And that is untrue. That date has always been there for the full implementation of the CMC rollout into the contracts, with that four-year phase rollout. Again, this is phase two that was supposed to happen here in about 30 days. And then there was a phase three, and then phase four was everybody's covered. Right. So, you know, there's some risk with this delay of achieving the November 28 or the November 2028.  And that risk being, you know, there some C3PAOs  may not make it without having business for a few months, right? Some assessors that had, you know, been ready to support may choose a different line of work.

And so there's a risk, but ultimately that date is it's still the same. And so that's that's something that we I I've seen a lot of folks get in front of it and try to clarify that information.

Vince Scott: So I did drop into the chat, Justin, and you may want to include it in the show notes, a direct link to the phase rollout in the 32 CFR 170 that Logan brought up. It's actually in in 170.3 . It's in the role itself, Logan. So I put the direct link in that for you for the show notes, Justin.

Justin Beals: Yeah, thanks, Vince. We'll include it. And I did read that. It felt like it came out at a very strange moment. We were all keyed up for this 60-day kind of research project. And quietly in the middle, this summary memo that was very legalese. It took me a couple of reads to try and figure out what it was trying to describe. But in a way, it's like if I were thinking about a software development project plan, and I'm sorry, that's my background, and we were like, we're gonna start at A, we're gonna get to B, and then we're gonna result in C. We just took B and said, no, we're gonna make it disappear and still believe that C will happen somewhere down the road, you know.

Vince Scott: Which which work memo are you talking about, Logan?

Logan Therrien: I forgot the exact title. It came out about three weeks ago, and it was an acquisition. Yeah, that's right, acquisition.

Brian Hubbard: From acquisition d from acquisition. Yeah.

Vince Scott: Was it the class D you're talking about, the class deviation memo update? Yeah, okay.

Logan Therrien:
Yeah, it talked about not being able to purchase some parts from, I think it was Huawei, some Chinese manufacturer.

Vince Scott: Yeah, right. So right. So that is it I I guess in my view that has a little bit more weight than just a memo. It's actually a modification to the class deviation that is a part of the far overhaul. Right?. And so it has a number of other things in it besides CMMC, but one section of that is the incorporation of the language out of the DODCIO's pause memo into the class deviation.

Logan Therrien: Yeah, yeah, absolutely. And and I I I speak specifically of the memo because it referenced that memo with no changes, but you're absolutely right. And fo a lot of folks didn't focus on hell, we can't get all these parts from this manufacturer that we may have been using. They focused on, hey, we don't need to do this other thing any any for the next few years. So.

Justin Beals: Yes, which was a strange amalgamation of information, right? It's like okay. And I'm not used to reading these things, so it did take me a couple of turns of the crank.

Logan Therrien: Yeah.

Vince Scott: If like you said, Justin, yeah, that's and it had various parts. we're gonna modify this part over here and that part over here and blah.

Justin Beals: Yeah. Brian, what is your current advice to your customers? Especially if you're thinking about the preparation side or the assessor community and what to think about.

Brian Hubbard: Yeah, well, I yeah, I mean the first piece of advice is the requirement hasn't gone away, right? So the requirement to be compliant with NIST 800-171 Rev.2  for the DOD is still in force. And and the memos are very clear on that. It is still in force, in full force. And so contractors need to be getting themselves prepared; they need to be doing some kind of assessment, at least a self-assessment, and a self-assessment they can defend. So,  from you know, just you know, taking off my sales guy hat, right? And and saying, okay, what do you need to do? You need to do a self-assessment that if the DIBCAC walked in the next day after you posted your score, you could defend it. Or if they walked in six months after you posted your score, you could defend it, right?

And a defensible self-assessment is something completely different than what people think they are doing. What people are not thinking they're doing, what people are currently doing, right? Because a defensible self-assessment is basically being able to defend against a C3PAO type assessment, right? So what you know you know, of course, my advice then, of course, with the sales guys hat on is what better way to do that than get a C3PAO assessment? Treat it as a self-assessment if you want to, but it's still a validated self-assessment.

Vince Scott: Yeah, it's important to do that with integrity, right? And good knowledge and understanding of what that means. I do think for me it's made a little difference in how we advise our clients in that in working up towards certification assessments, I honestly worried about the puritanical assessor, right? Somebody who would come in and be over the top on in
perhaps add to the body of regulatory requirements, which I hate to see happen. But but some you know somebody who is very, very precise about this. I like to say I think I could fail anybody in the DIB on CMMC if I wanted to follow the regulations exactly puritanically in every case. It it it's really hard standard, right?

But now in the more self-assessments going on than certification assessments, I think it's it's important for us to have a good story about why what we're doing is compliant. And I'm less worried about somebody else coming back with a little different interpretation, or I see it this way, etcetera. But as long as we have a good defensible story about, hey, here there's 110 security requirements, there are 320 assessment objectives.

Here's how all I'm looking at those, etcetera. And then if DIBCAC rolls in and if DIBCAC wants to disagree, they they can, but they're not gonna be mad at you, right? Okay, you missed one. They interpreted it differently. They didn't like something about FIPS-validated cryptography that you had and you thought was good, and you know, they just said, No, we don't like that. Okay.

I so I have moved my philosophy a little bit in advising our clients on that. But like you said, Brian, we still have to have a process, right? Self-assessment isn't just I tick the box in SPRS. For one thing, I gotta tick a box for every one of the 110 security requirements. But for another, I'm expected in doing a self-assessment. To do it like you, Brian, or you, Logan, we're doing it as a C3PAO right? we're supposed to collect evidence. We're supposed to save that evidence for six years. So we have to have some rigor in that self-assessment process in order to actually be meeting the requirement and reduce the risk for our organization.

Brian Hubbard: Yeah, and that's kind of what I've been spending my my my downtime because of the pause on doing is is is trying to develop I've been developing some classes and you know won't turn this into a sales pitch but I've been developing some classes on how to do a proper level two self-assessment, how to do a proper Rev3 assessment, right? And start to gear towards Rev 3. So.

Vince Scott:  We can't talk about Rev. 3here 'cause we'll we'll leave another podcast for that.

Brian Hubbard: Well no, but but but people do need to start gearing up for it. I mean, it is coming, so yeah.

Vince Scott: For sure.

Logan Therrien: Yeah, so it and so one thing I do we you know, we talk about misinformation and there's some really good sources of information and misinformation and they're usually the same source. And for for this community, it's it's Reddit and Discord, right? And and I will see some questions pop up and I will see ridiculous answers. Such as, you know, since we don't have a third party assessment, we don't have to worry about the assessment methodology as much. And going back to, you know, both Brian and Vince's statements here, that is inaccurate.

Right. And and so even if you were to go back to NIST 800 171, there's again footnote number 11, type four font. It's an expectation that you would use 171 alpha as your assessment methodology. Now, there it's still codified, even if you don't go with there's you may use this. The DOD assessment guide actually has broken down what you should be looking at. Right. And so there's the expectation we put pull up this game plan and we're gonna look at it from the same perspective. Now again, there's variations.

Vince Scott:  I think that's in the regulation as well; that 171 A is the basis for the assessment methodology. That's mandated. it's also mandated in the DOD assessment methodology for the old 171 SBRS score. And you know, 171 A is incorporated by reference into the regulation. A lot of people miss the significance of that. That means it's like it's a part of the regulation.


Right?. It's it's completely incorporated. You gotta use 171 A, and not paying attention to that is a major mistake.

Logan Therrien: Right. And and so the the the problem with this ecosystem in general is that there's so many things that even Vince just called out. Right. Most people were told IT manager, go get us in in line with 171, Right?. And then they have to pull the string and become subject matter experts and do this for forty hours a week, right? At a minimum, to understand every reference that we just called out.

There's again that's the danger of doing it by yourself, right? Without reaching, or even just going to those misinformation channels. But something that's important is whether you're doing a self-assessment or a third-party assessment, the records have to be maintained by that OSC, the organization seeking certification, for six years, right? So let's say you didn't do it how the the DOD expected. Well, it will be discovered if there's ever an incident, and that has to be pulled.. So I see you set this at you 15 minutes, right? Show me that you did exactly what you said. There should be some record of evidence that that occurred, not just a personal statement that we did it. And that's the again, the danger is not understanding what the requirements are and getting reference at misinformation levels.

Vince Scott: Well in the requirements, there's a lot. One of my favorite quotes, right, is I made a spreadsheet of all the documents 171, 171, A, 32 C F 170, D470, 21, etcetera, etcetera. Right. Three times the New Testament was my summary, right? If I if you line all those up, I actually had AI do a word count, and then we did a word count of the King James version of the New Testament, right at 3x. That's a lot to know. And it's even an I think all three of us probably see this in the assessor community and in teaching assessors. That's a lot to know, right? And to say, no, really, you've got to dig into this, Mr. Assessor, and you've really got to know what you're talking about. You cannot go off of just what you knew, what you heard, what you think you remember of my PowerPoint slides.

You've got to be focused on those real regulatory documents that are the real mandates. And there's a lot of that to understand. And it's particularly a lot for like Logan or Brian said, that IT manager, right, who's got this as a collateral duty. Wow.

Justin Beals: There is an old business story people love telling, where there was a real estate agent that wrote a book about how to sell your own house, and that was his number one Legion instrument because people would read the book and decide that they did not want to try and sell their own house, and they would call the real estate agent to come help them sell their house. I love that trope because I do think we're in that era, Brian Logan and Vince, that you guys are talking about, where people are like, I can do this on my own, but severely, you know, misunderstanding, maybe ignorantly, the level of requirements, the level of rigor, and the risks as they're outweighing. So maybe I might throw some myths that I hear in the market oftentimes. You can tell me whether fact or fiction; for example, one myth I hear very often is my my MSSP, my managed security services provider, is handling CMMC for me. Is that valid?

Brian Hubbard: . No. No. Yeah, the the OSC owns the owns the requirement, right? So they can certainly get help from an MSP or an MSSP and and they can help them with lots of things, and maybe hand off all their technical controls to them to to do for them, but they still own that requirement. It's still their responsibility. And there's a lot in CMMC that is not IT driven.Right. That an MSP doesn't have anything to do with.

Vince Scott: Yeah, in my MSP business, we talk about doing eighty or ninety per cent, depending on how much physical CUI you have. And, you know, there's some pieces. If you're not doing that, then you know, that's not something the OSC has to worry about. But it's impossible for us, in my view, as an MSP, to do 100% of the things that are required in the standard for exactly the reason Brian brought up: there are things that aren't technical. 
In things like evaluating the risk to your company because you process, store or transmit CUI. I can't do that for you. You gotta do that for you. Now I can set you up to have a process and understand how to do that in a compliant fashion and make sure you got records and documentation, but you still gotta do that. I can't make that evaluation for you. And that's a critical piece that's missed when we hand CMMC to IT and say, "It's got cyber in the name; it must be just an IT thing." That is a misconception.

Logan Therrien: Yeah, I've seen I've seen MSPs that were pretty close. They were very much tailored to the CMMC needs, but it's not just there. 

Vince Scott: You can't do a hundred per cent. And and I actually advise clients and say “if anybody tells you they can do a hundred percent of this, don't hire them. 'Cause it's not true”. Yeah. It's a that's a that's a risk indicator.

Logan Therrien: It's danger, danger close. And then yeah, and then we we talk about you know, I we won't talk about Rev. 3, but it's almost it's pretty impossible to get there with Rev.3 and have everything supply chain management, risk management, all of that stuff outsourced to the same company. I mean it could be outsourced to other individuals with ten-ninety-nine support; a whole bunch of, you know, the spectrum is endless, but

Brian Hubbard:
Yeah. You can't even get past the first control on Rev.3. There are 28 assessment objectives, and about six different roles have to do those 28 assessment objectives.



Logan Therrien: And and so Justin, I mean basically to answer that too, there may be some MSPs that are very close to it, but if you look in the future, we know Rev3 will be here. It's it's you need to look at where before you start putting everything in place, will this be a sustainable model?

Justin Beals: Yeah. And then the the other kind of fiction that seems to be roaming around is, and I think you guys point this out, is that, well, I'm pretty much am doing the paper like the policy side, or I'm agr I'm running through this checklist and making sure we handle these objectives. But you had to collect the receipts, right? So the myth that I can state my way into CMMC compliance, you know, without actually, you know, taking the receipts of the work, that feels like another myth that happens a lot.

Brian Hubbard: Yep. Yeah, the policies and procedures and things that you might write down, that tells you what you're supposed to do, right? And that's why we have examine, interview, and test in the assessment methodology, right? Because you interview the people that are supposed to do it to see if they're actually doing it the way you wrote down. And then you look at the evidence, the test, to see if the evidence shows that you actually did it. Right? So all of those things combined make the compliant environment, not just writing it down.

Logan Therrien:  Yeah, actually, the writing it down is a smaller portion in Rev.2  in my opinion. And if there's a requirement for an SSP and you have to I you'd have to talk about how you do things in the SSP, for Rev. 2, and and most of it is show me that you do it like you said. Rev. 3 is a lot of Rev. 3is the first time it says you have to have policies, procedures, and and you have to keep them updated. All right, so there's a lot more incorporation to that.

Vince Scott:  I don't I don't know that I'm aligned with that, Logan, from a looking through the individual's assessments objectives and looking at things, although the policy and procedure explicit requirements aren't there in Rev2. Give it, agree. But if I look at R identified, R defined, R specified assessment objectives, I count that up to be a little bit over 50% of all the assessment objectives. And one of the things I was going to say, Justin, I see I I think a lot of is we give it to IT, because it's got cyber in the name. IT comes up with technical solutions and, in some cases, pretty good technical solutions. They're smart technical guys. They want to do the right thing. 

But they're like, someday, I will do documentation. When I lived in, I was the fleet cryptologist for Sick US Sixth Fleet, I lived in Naples, Italy, and the Neapolitans had this saying that was Domani, Domani, Dope, Domani, which is tomorrow, tomorrow, always tomorrow, right? And it meant they were never going to do it. Right? When you went to a Neapolitan and said, Hey, I'd like to have my trans trash picked up, Domani, Domani, Dope, Domani.

A lot of people are doing that with documentation and CMMC. That's not working. That's not compliant. That doesn't produce evidence. That's not meeting the requirements. Yes, there are technical controls, and I have to do those well, but I have to do the documentation piece. And there's a lot a a fair amount of that documentation piece that is business process or outside of IT, HR, other other parts of the enterprise that have to do this.

And so if we don't have those parts, then then really we're not meeting the 171 requirements as assessed by CMMC.

Logan Therrien: Yeah, and you'll see spectrum too. A smaller company, very technical related, you're gonna see very small written down, a lot of I do. And then you'll get to larger companies that are very much into ISO standards, and you're a lot of written down and then a lot of do as well.

Justin Beals:  Yeah. The thing that I find really intriguing sometimes, Vince, to your point, and this was one of my complaints about the SOC two marketplace when I was a chief technology officer. They'd be like, you know, there talks about security, Justin, you're the CTO, go get a SOC 2 compliant. And when I read the trust services criteria, I was like, you know, this is only thirty percent cybersecurity. The rest of it comes from the rest of the organization.

And this is the other myth and I've I've written a fairly long white paper on it: we adopted an enclave; we are CMMC compliant now. And I that is a real struggle for me because even in some of the the shared services analyses that have come up, they might take the major objectives like, we're we're hitting a hundred of the hundred and ten major objectives, but when you break down the sub-objectives, it was fifty-fifty that the enclave was solving for. And there were a lot of sub-objectives with no solution because the customer was expected to manage and operate the enclave themselves. And so I'm curious if you guys see this similar kind of challenge with the enclave providers, perhaps.

Vince Scott: Well, and I am an enclave provider. So we like I said, we advertise eighty to ninety percent, but we do that at the assessment objective level. And that variation depends on okay, I'm not going to use thumb drives at all. Okay, we've disabled that capability in the system. You don't have to do any work on that. We can just simply document that in the SSP that that's closed off and we we meet that requirement, right? That kind of stuff. So I do think it is possible to do this with a properly configured enclave built by people who know what they're actually doing. And really the critical aspect of that, in my view, is the virtual desktop infrastructure. So, right, the virtual desktop has a carve-out in the regulation that says an endpoint accessing assets via a virtual desktop is out of scope. So what that does is that keeps you from infecting the rest of your network with CUI because you have logical separation as defined by the regulation when you access things via that virtual desktop. And that gives you a capability to do that.

 I had a conversation last week with you know a little MSP that was helping a little manufacturer and they were gonna do an enclave by putting building them server in, you know Azure Cloud.


Okay, full stop. All right, wait a minute. No. You haven't solved the problem, right? You there there's no logical separation there. we just I started pulling the string and there were just a ton of problems with it, right? So that is the problem I think that you get to you see a lot of people making enclaves, but they don't have the depth of expertise on what the requirements really are, in order to be able to have that correctly configured enclave so that when somebody like Logan comes in to pull the string and Logan is really good or a really smart assessor on this stuff, that becomes problematic rather quickly.

Justin Beals:  Yeah. I realize we are starting to run a little low on time, so I'm gonna give us a round a couple of questions here. Maybe we'll go Brian, Vince, and then Logan to close us out. And really two thoughts that I have. The first thought is: where does the current risk lie? You know, what what is what is the risk as a defense contractor, and what should you be nervous about? And then any if you have any thoughts about the next six months and how you think things will play out? 

Brian Hubbard: Well, okay, so so risk risk is a loaded question, of course, right? Because is it the what is the risk I am really trying to mitigate? And that's the risk that the bad guys are gonna come after you for the data that they want from your government client. And and that is what we're trying to mitigate with against, right? The risk from them, from a legal perspective, is that they're signing a contract that says that they're compliant with these things.

These controls in 800-171 revision two that are geared towards protecting the confidentiality of CUI. And yet, if they're, you know, leaking data like a sieve, still after they've signed a contract that says they're compliant, they are putting themselves at risk for the False Claims Act. Is there a high probability that the fickle finger of the DIBCAC is going to point to them? No, not a high probability, but there is a probability, right? And do the and do they want to be doing business that way, right? And somebody so somebody's might maybe coming along and saying, well, this is a major risk to our business, regardless of that. Yeah, we can put off the cost for another two years. Great, we just won't do it. Well, you're already signing contracts that say you are. So the risk is you already have the requirement and you're not doing it, right? So the road ahead is to go ahead and get prepared, get ready.

Even if the contract doesn't call for a third-party assessment right away, it is not a bad idea to have a third-party assessment done, right? So so continue on with that on in that in that in with that in mind that you should be ready to stand up, even if it's not a C3PAO coming in, maybe it's going to be the DIBCAC coming in as a government auditor to find out that you've not done it correctly. All right, that's the risk.

Justin Beals:  Vince?

Vince Scott: Same questions?

Justin Beals: Same questions.

Vince Scott:  Where the risk is a loaded question. To mirror what Brian said. I'll look at this from a risk to the company, the Dib company that's working in this space. I think risk number one is I'm gonna miss out on contract opportunities because I don't have this put together yet. I don't have my scores in, I haven't looked at this program, etc.

As you know, as I look at the contracts and I see this moving towards not even being able to get access to RFB documents, that increases that risk, right? That I won't even be able to bid on the projects that maybe I would be well qualified for. And that also goes by subcontractor. We talked about the momentum in the regulatory space.

Right?. So even though we put a pause on at the top, this is like the price of oil coming through the Straits of Hormuz. Right? There's a six-month supply in the system before you actually start to see reactions to it. So what I'm seeing today is prime contractors, contracting activities, etc., continuing to really scroll ramp up on cybersecurity requirements and contracts, and that you show me in some fashion that you are prepared, and that goes beyond, I assume you're good because you signed the contract. We're now into show me your SBRS score. I want to be able to see it. I'm increasingly starting to see some prime contractors and government ask for their system security plan. I actually want to see it, Right?.   

I want to be able to go through it with you, etcetera. Particularly if you look at like Ingalls shipbuilding and some of these other, you know, big prime contractors, they're getting they're clamping down more because they're anticipating still that even though we have a pause, that this is it it's not going to stop. Cybersecurity has continued to be a priority. We're going to continue to see more requirements from the government, and we've got to get a better handle on our supply chain. And that takes time.

And so it really hasn't impacted that much. So from a risk perspective, I think taking your foot off the gas isn't the wrong move. because this is going to be increasingly a risk to the viability of your company in the Department of War contracting space. and if you look at it through the lens of I do commercial and government stuff, and do I really want to do this DOD stuff? I think global economics leads us to perhaps a pessimistic outlook on how this is gonna go. There's just so many challenges right now, economically, globally, in the US, outside the US, etc., and oftentimes those Department of War contracts are really good because they continue to pay even in economic downturns. So I think this slice of the business for a company that does both commercial and DOW business is becoming even more important. I as a CEO would look at it, i you know, if it's thirty percent of my business, but maybe it's a really important thirty percent, because there's volatility on the commercial side. so that's where I think the risk is.

Justin Beals:  Thank you, Vince. Logan, final thoughts for us, yeah.

Logan Therrien: So you know, it's everything Vince just mentioned that he has seen, I believe we brought this up about sixty days ago with you in the in on on the podcast of this is our expectation is that primes are gonna have already been through this, they're gonna feel that there's a vacuum in validating compliance, and they're gonna start implementing it on our on their own. And I and I think that's exactly what we're seeing. You know, so big risk, in absolutely adding on is misinformation and misunderstanding, right? So organizations, there's a there's a lot of far clauses, a lot of defares clauses, and you know, there's quick information, again, maybe wrong. You know, so as an organization, do you have the internal people and tools that you need to validate that you're actually meeting the compliance requirements? If not, bring somebody in, bring somebody external, whether it's a long term, short term, and just make sure you're meeting the intent and that your organization is safe to move forward.

Vince Scott: And make sure you bring in real expertise, right? there I went to a conference and every other booth had a CMMC expert sign hanging out. if they did IT, I would go up to them, and I would ask them a couple of questions, and they wouldn't know very much, and you know, I would move on. Back to the three times the New Testament. Boy, there's a lot to know here. And if you're gonna seek outside help.

I think that's Logan's point about, hey, seek outside help, and we're all kind of conflicted because we all do outside help. But no, really. I don't want to see a company spend a lot of money on what they think is the solution. And then six months later, after that's gone wrong, then we come in and go, you know, really, that was a waste of time and that that wasn't the right way to allocate your funds. Some of the most important work we do is telling people what they don't have to buy.

And  that com our ability to do that comes from having real expertise. Today I was describing what I did with another manufacturer where they had the CUI packages move around the manufacturing floor, and they had a process where those got set in inboxes. What we did was we bought an old-timey mailbox that goes in and locks. So now that CUI is secured. And I didn't

I didn't, you know, come up with a real that was a hundred buck solution, right?  to their problem of how do they secure those packages in transit. And we didn't come up with a very expensive, you know, I have to have a badge reader for the building or something else, right? In order to be able to do that. So I hire a real expert. And Brian and Logan are both great examples of that, right? With companies that have been working in this space for a long time. Make sure that you you choose wisely if you choose an outside.

Justin Beals: Thanks, Vince. Appreciate it. Logan, again, we just really appreciate your ability to translate this changing landscape, and Brian, your support broadly the community. And we'll include in the show notes some of the recommended classes and materials that we talked about today. And you know, I think sadly, not by design, but I think this actual podcast, this actual event where we talk about CMMC. We may have to revisit it in another three months. I told everyone when I got into compliance it would be a really calm space and not a lot of drama. And I am so wrong. So, gentlemen, it is with gratitude for myself and our listeners that you came today and shared your expertise and helped give us some guidance on what to expect next. Thank you.

Brian Hubbard:  Probably. Thanks for having us.

Logan Therrien: Thanks, Justin. Thanks, team.

Vince Scott:  Thanks for the invite. Cheers.


About our guest

Logan Therrien, Brian Hubbard and Vincent Scott

Logan Therrien is Chief Strategy Officer and Lead CMMC Assessor (LCCA) at Kieri Solutions, one of the original C3PAOs in the U.S. Defense Industrial Base. A retired Navy Lieutenant Commander with 24 years of active duty, he managed information security for over 7,000 personnel and oversaw physical security for assets valued at more than $20 billion. Since transitioning to the private sector, he's become one of the most recognized names in CMMC implementation, conducting assessments, training the next generation of assessors as a CMMC Provisional Instructor, and co-authoring research on standardized evidence sampling in CMMC assessments. He holds a M.S. in Information Assurance, the CISSP certification, and is actively pursuing a Ph.D. in Cyber Defense.

Brian Hubbard is President of Evolved Cyber and a cybersecurity leader with more than 40 years of experience. As a Lead Certified CMMC Assessor and CMMC Credentialed Instructor, he helps defense contractors and cybersecurity professionals navigate CMMC assessments, readiness, training, and compliance. Brian has led major cybersecurity programs, supported NIST cybersecurity initiatives, and spent two decades with Booz Allen Hamilton supporting national security and information assurance efforts.

Vincent Scott: Vince is a retired Navy Cryptologist/Information Warfare Officer and serial entrepreneur who has started two companies, two not for profits, and is passionate about cyber defense. He has lead a number of cybersecurity programs since retiring in various roles including CISO, and CSO. He is a CMMC certified professional (CCP), CMMC Certified Lead Assessor (LCCA), CMMC Provisional Instructor, CNSS
Certified Incident Handling Engineer (CIHE), CNNS Certified Information Security Professional, CNSS Certified Senior Systems Manager, ISACA Certified Information Security Manager (CISM), and US Navy
certified expert in Cryptology and Information Warfare. He currently serves as the FBI Infragard Subject Matter Expert on Cyberwarfare, and the Deputy Chief of the FBI Infragard Defense Industrial Base critical infrastructure sector. He is a graduate of the United States Naval Academy with a BS in computer science, holds a Masters Degree in Management Information Systems (MIS), and holds a graduate certificate in Cybersecurity. He is a prior editor of the Journal of Law and Cyber Warfare.

Justin BealsFounder & CEO Strike Graph

Justin Beals is a serial entrepreneur with expertise in AI, cybersecurity, and governance who is passionate about making arcane cybersecurity standards plain and simple to achieve. He founded Strike Graph in 2020 to eliminate confusion surrounding cybersecurity audit and certification processes by offering an innovative, right-sized solution at a fraction of the time and cost of traditional methods.

Now, as Strike Graph CEO, Justin drives strategic innovation within the company. Based in Seattle, he previously served as the CTO of NextStep and Koru, which won the 2018 Most Impactful Startup award from Wharton People Analytics.

Justin is a board member for the Ada Developers Academy, VALID8 Financial, and Edify Software Consulting. He is the creator of the patented Training, Tracking & Placement System and the author of “Aligning curriculum and evidencing learning effectiveness using semantic mapping of learning assets,” which was published in the International Journal of Emerging Technologies in Learning (iJet). Justin earned a BA from Fort Lewis College.

Keep up to date with Strike Graph.

The security landscape is ever changing. Sign up for our newsletter to make sure you stay abreast of the latest regulations and requirements.