- Home >
- Resources >
- SecureTalk >
- CMMC Phase 2 SUSPENDED: What DOD Just Did, What It Really Means, and Why Little Changed
CMMC Phase 2 SUSPENDED: What DOD Just Did, What It Really Means, and Why Little Changed
The Pentagon paused CMMC Phase 2 with zero warning — and half the defense industrial base is celebrating for the wrong reason.
The Pentagon paused CMMC Phase 2 with zero warning — and half the defense industrial base is celebrating for the wrong reason.
Description:
When the Department of War suspended CMMC Phase 2 rollout with no notice, panic spread fast across the defense contractor community — but the requirement to secure CUI never went away. In this special roundtable, host Justin Beals brings together three CMMC insiders — Logan Therrien (C3PAO Chief Strategy Officer, retired Navy submariner), Lance Arnold (30-year industry veteran, just completed his own CMMC Level 2 journey), and Brian Hubbard (President, Evolved Cyber Solutions, CMMC assessor since 2015) — to separate what actually changed from what didn't.
They break down the difference between the assessment requirement (paused) and the security implementation requirement (still very much alive under NIST 800-171), why "self-assessment" doesn't mean "no requirement," and what small businesses and primes should do right now instead of waiting for clarity that may not come for months.
Sources referenced
DFARS 252.204-7021 (CMMC assessment clause)
DFARS 252.204-7012 (NIST 800-171 compliance clause)
DFARS 252.204-7019 (SPRS scoring requirement)
32 CFR Part 170 (CMMC Program Rule)
32 CFR Part 48
NIST SP 800-171 / NIST SP 800-172
#CMMCPhase2, #CMMCsuspended, #DFARS7021, #CMMC2025update, #CMMCcompliance, #defense #contractor #cybersecurity #NIST800-171 #C3PAO, #CMMC #self-assessment #DIB #cybersecurity
View full transcript
Justin Beals: Hello everyone and welcome to SecureTalk. I'm your host, Justin Beals. I'm really glad to have you joining us today. This is a special episode of SecureTalk.
We're joined today by some incredible experts and luminaries in the field of CMMC compliance. And the reason that we brought this incredible team together is that there's been a recent announcement by the Department of War regarding the phase two rollout of the CMMC program.
We wanted to get ahead of what I like to call folklore in this industry with some science, and that's why we brought some experts with us today. And so this will be a little bit different format where we're going to kind of dive in with folks and go ahead and generate a discussion fairly quickly. And I'm just going to start off by doing a little roundtable and helping to introduce our panelists today that are joining us. Logan.
Would you be willing to kick us off with an introduction?
Logan Therrien: Yes, sir. Hey, thanks, Justin, for having me here. This is a good topic to be a part of, and I appreciate being part of this team here. So my name is Logan Therrien, and I'm the Chief Strategy Officer for Keri Solutions. We are a CMMC third-party assessment organization, and we also provide CMMC consulting services.
My history is retired Navy submarine force with a history of all the pillars of security and then the education masters. I'm currently working on my PhD in cyber defense and it's really focused on CMMC. So I love this field, and again, good to be a part of the conversation.
Justin Beals: Thanks, Logan. And I loved our prior episode regarding some of your academic work. It was really fun. Lance, thanks for joining us today. Maybe a little bit about your background and expertise.
Lance Arnold: Sure, my name is Lance Arnold. I also work with Keri Solutions. I've been there for about three months. Prior to that, I've got 30 years in the industry supporting everything from very large Fortune 500 companies to chemical to spent the last 20 years doing direct consulting and building enclaves, and you name it, anything you can think of, I've done it for some Navy, COCOM along the lines. So, I'm happy to be here and add some feedback and perspective, especially from the other side of the fence, to those that are dealing with this, having just spent the last year taking my own previous organization through CMC Level 2 and now being on the other side.
Justin Beals: Thanks, Lance, for joining us today. We really appreciate that operator perspective as we dig into these issues. Then Brian, thanks for joining us today.
Brian Hubbard: Sure thing. So yeah, I'm Brian Hubbard. I'm president of Evolved Cyber Solutions, or Cyber LLC is actually we shortened it. But anyway, so I've been in the cybersecurity business for over 43 years now, I guess it is 30 of that was in the DOD Intel community, doing cybersecurity-related things for several companies and agencies. But I have been involved with CMMC from the very beginning. I did my first eight hundred and one seventy-one assessment for a company back in twenty fifteen, way before CMMC.
When the requirement first came on board. I have become a lead CCA, and my company is an authorized training provider. So we teach the CCP and the CCA classes. And also have some other training around CMMC to help people understand how to get ready for assessments. So we are, and we are an aspiring authorized C3PAO. We're a candidate, and we're going through our process right now, which is making this even more fretful. But that's a little bit about me. So been doing lots and lots of assessments and having lots of fun doing them. But.
Justin Beals: That's great. And thank you all for joining us today. You know, I have this: I've worked in business for a long time, but of course the business will operate inside, you know, the culture community, including the government structure, the laws that we need to abide by and things like that. And the thing I always ask for is kind of like a steady even path, you know, chaos is what makes it hard to operate a business and be successful at it.
And so when I heard the news yesterday, and it rippled through our team, I was of course floored. I was like, this is not the chaos I need. I'm go back around the, excuse me, horn here. Brian, I'm curious what went through your head as you read the announcement yesterday, yeah.
Brian Hubbard: Well, at first it was a criminy here we go again kind of kind of dote and then done trying to figure out because actually I got a call from a a good a colleague and he says, Hey, have you heard that CMMC has been paused? I'm like, I say, Yeah, that's funny. what are you talking about? And then he forwarded me the announcement and that was the first I'd heard of it. So it was, you know, a heck moment to say the least. And just trying to scramble. And since then it's just been trying to figure out, okay, how do how do what do we need to do? How do we pivot? You know, what are the things that the companies out there that are gonna be calling me need to understand about this, that it's not a cancellation, that kind of thing. So I had to wrap my head around it, and then I did a lot of research to find out what this really meant.
Justin Beals:
Lance, how about you?
Lance Arnold: Similar, think I was already wrapped up for the day, and I saw a news alert come in, I saw text, and then I saw a third, and then I saw a fourth, and then I saw a fifth. It's like, okay, something big has happened. And I think we went through the five phases of, hey, what's actually happening? And then, okay, I got to acceptance pretty quick. Obviously it's a pretty significant change, but the core requirements are still there, and I'm sure we'll get into that a little bit.
And once I understood that and I could understand the small business, very small business perspective, it certainly creates challenges for the ecosystem. But you know, this is just another chapter versus the end of the book. So I kind of came to that pretty quickly and then started focusing on the calls at hand or the task at hand and talking to a lot of people. A very quick succession.
Justin Beals: How about you, Logan?
Logan Therrien: You know, not much different. You know, all the stages and the shock. And so at 6.13 PM, I felt a little shock. I remember that time very well. And so I think probably most of that was because it was just the day before we were discussing the next steps that were being advertised by the same team. Right. So just to have this completely dropped on us with zero notification and any method is it's kind of an odd way of doing business. And so I was just surprised and like, is this real?
And then the video started showing up in the memos, and it's just, nope, this is real. So what do we do next? I'm constantly, not anything unlike my peers here, is that I'm constantly in a way of how can I do things better? Where do I need to go next? And so that's where my head went to is what do we do next?
Justin Beals: Yeah, I found there was a lot of internal communication all of a sudden. I had a lot of our sales folks and customer success reps, like what do we say, what do we do? And that was our first thing that we needed to do was sit down and figure out what happened. So let's crack that open. And I might ask you, Logan, to help us kick off with this question. So what would phase two have required that phase one didn't, essentially?
Logan Therrien: So really expansion of the phase two requirements and contracts. So that's the primary one. It was supposed to be a phased implementation for contracting officers to include further contracts that have the DFARS 252.2047021 clause that says do CMMC, which is again just an assessment of all the other clauses, same 252.2047012, which it says, do NIST 800.171, be compliant. And it just shifted over from doing a self-assessment reporting through Spurs to now follow 70 to one and either do a self-assessment. So just an expansion. And it was allowed to be able to give the contractors throughout the dib more time for their teams to prepare and implement. Again, shouldn't be much of a change because all it's adding is the
formal assessment process, not the implementation requirement that's been there for nearly a decade. Right. So, just that contractual delivery vehicle method, the expansion of that, in addition to DIPCAC. So that's the government's assessment team ability to come in and perform level three assessments, which is NIST 800 172. Additions to provide more security requirements for the higher level or more at-risk projects that were accomplished within the DIB. So it's just, again, expansion and addition for level 3.
Justin Beals: Yeah. Brian, was that your take as well?
Brian Hubbard:Yeah, pretty much. And so, you know, I just say, you know, this is not the first time in CMMC history that this has happened, right? So we had something called CMC one that is has been termed CMMC one point right? And I was involved in developing a curriculum for a previous company, come another company has run their CMMC program, and we developed the curriculum for CMC 1.0 and right as we taught our first class, the DOD, out of the blue, dropped CMMC 2.0 on us and stopped everything for what, two, three years, and we had to completely redevelop our curriculum and and everything else along with that.
So this is not the first time this has happened in the history of CMMC. And so I, you know, from that perspective, it's not that much different. But the the Logan was spot on on what what the contract was going to require, what the what the con what the what the program requirements in the in the CFR were. Phase two is just that additional requirements and contracts basically.
Justin Beals: Yeah, Lance, I imagine where you're working directly with companies on implementation, you know, you know, considering that this requirement didn't go away, but it sounds like the rollout did, is your recommendation to continue to roll out program internally?
Lance Arnold: Yeah, I think especially working both on the other side of the fence last year and now working with people that are going through that process, the biggest headline is it didn't change. And the analogy I like to use is hey, you're going to college, and the SAT is good judging how well that you're going to do in college. You don't have to take the SAT to go to Harvard. If you take the SAT and/or you don't take the SAT and you go to Harvard and you know you get like a 20 score, you're gonna have a tough time. And I think that's the point that needs to really be heard and driven across is this CMMC was a great mechanism to understand it. I've been in this industry a long time.
Justin Beals (12:18.119)
think we lost you there for a second, Lance.
Justin Beals (12:24.477)
There we go, you're back with us, yeah. You said you've been this, it's okay, I'll take you back to where you started, we can fix it in post, it's not a problem. You said you've been in this industry a long time.
Lance (12:27.635)
Sorry about that.
I've been in this industry for 30 years and I'll say understanding the contractual subtext. This is what this NIST standard means. This is where it's not really clear or understood to those that are actually doing the IT work. It's not fully understood to most of the people that are going after the contracts.
Now the contracts people understand it. And they assume that the IT people understand it, but the CMMC ecosystem did a good job of tying those things together. So I would say keep using it, keep pressing forward. Don't stop what you're doing because this is the best framework that we know of, maybe next year or maybe 60 days down the line. Something will be clearer and smoother and more streamlined, but for now, this is the best that we have. Keep pressing forward.
Logan Therrien: Can I add something to that?
Justin Beals: Please, Logan
Logan Therrien: So the requirements really aren't gone. This is where I think a lot of confusion is about to just spread. DFAR 721 was not repealed. What's been suspended is phase two of the rollout plan. Right? So, and how the contractors implement that. when we say, or when I read that the self-assessment requirement will now be in place, it was just the lowest level of DFARs 252.204.7021. And again, that has nothing to do with actually implementing security requirements. It's just the assessment of them.
And so 7012, the farce 252, 2047012 is what says do NIST 800171. And I think that's where a lot of the confusion, I see folks celebrating, hey, we don't have a requirement anymore. And good, because that was expensive. All right, but here's the truth. It's going to sting a little bit. The expensive part is implementing security. That part has been around for eight years. That part did not go away.
The part about implementing security is that CMC and it's write up, NIST 800 171 is difficult to read because it's designed for 120,000 organizations to implement at the best that they can, but the requirements are still there. And it causes confusion.
And that's what one of the benefits of having a third party come in, accept the risk. So they're accepting the risk of evaluating and making a determination for the C3PO. But they're also accepting the risk of, we are accepting the risk of standing by that answer and providing it to the government and saying, this is what we saw. So we are absorbing that risk. And so what we saw under the self-assessment method was that organizations were not doing it correctly.
And it's actually on record that organizations were not doing it correctly. So if we go back to just a year and a half ago, the requirement was actually not even a year and a half ago. The requirement is to report your score is under DFARS 252-204-7019, which says you have to have a score in the SPRS system to be eligible to bid for contracts. However, you could have the high scores of 110.
The low score I think, is negative 205, 203. You could put negative 53 in there, basically saying, I am not secure at all. I am not even doing half of what you're asking me to do. Have that score in there for the last eight years and still win the contract with zero protection and confidentiality of the data that the taxpayers are paying for. That was acceptable. It wasn't until the 32 CFR 170 came on and said, this is the CMC program. This is what the requirements are.
And then 48, DFARs, or sorry, 32 CFR 48 came out and with the DFAR 7021 that says, now this is how it's going to be rolled out into contracts, that companies are actually getting the truth of what that is. And it's been hard. There's been a lot of false starts of companies that cannot start their assessments because they can't even identify what their assets are categorized or where their data is flowing or not identity, they don't know still what devices are using the data or who is using the data, right? Now that's not all of them, but there's a large percentage that cannot start assessments because of these milestones that they haven't overcome. These are companies that are still receiving contracts with negative scores implemented in defaults and they have been since the beginning. What we're doing to see C3PO is going there identifying who is and who is not doing it right.
And then again, taking that risk and promoting it too. So the requirements to do the security protections have not changed. What has been removed is the lowest cost part of this entire process, lowest cost to come in and validate, absorb the risk of that validation and the report to school.
Justin Beals: The risk still stands. mean, in some ways this reminds me of like HIPAA. Every doctor's office I ever went to, you know, does HIPAA pretty rigorously or as best they can. Why would they even decide to do that? Because there's no third party assessment requirement. It's because if Health and Human Services figures out that you're not doing it, the fines are gigantic. And now I think that we are set up in this risk situation. It's even riskier for the company to not get a good quality assurance measure on what they're doing.
Logan Therrien: This is disgusting.
Brian Hubbard: Yeah.
Justin Beals: Because it could come and bite them severely on the backside.
Brian Hubbard: Yeah, and we've seen that recently, right? With the the Department of Justice going after companies that did have an SPRS score. but then they went and did an audit and discovered that they lied. They they put a hundred and ten up there and they aren't even close. And they're, you know, getting hit with massive fines. So it's not just the companies that, you know, back in the D for seventy twelve requirements where they, you know, they're supposed to be compliant, but compliance was a weird sort of, well, if you're if you're doing something, you're compliant. Well, that's not the case anymore. You have to post that score. That score has to be accurate. And you have somebody in your company too that is putting their neck on the line now, the affirming official, right? That has to go up an SPRS and affirm that, hey, yeah, this is really our score. And I'm I'm attesting to that legally. And now they're going after those people.
Logan Therrien: That's the changes now that we don't do that negative score that's acceptable. The requirement is that it's perfect or it's still above a certain requirement, and it will be perfect in less than 180 days. I promise.
Brian Hubbard: Yes.
Lance Arnold: And Justin, you said, like that analogy. I want to go back a little bit further because the reason that every doctor's office, if I go in and they say, Hey, text me my lab results, the receptionist, the doctor, or the surgeon is going to say, no, log into our portal, download it in a secure way. And they will not bury from that. Well, why is that so sustainable? Because if they did that, I could sue them directly. You know, there's a civil and liabilities for it there here is what's happening here. The difference is there's so many things, and people are very litigious. So they've seen that time and time and time again, as been referenced by both everyone on this call; the government is now dealing with that. The days of oops, my bad, I lost some data and oops, my bad, it wasn't protected. There's, especially in a public setting, I'll say there's real consequences to not dealing with this data, and it's no more conceptual.
Justin Beals: Yeah.
Lance Arnold: Look at what's happening in the world. Look at what's going on in your company that you're looking at. As you guys are watching this video, think about what data you had and what could the U S's adversaries do if they had access to it. And also what if you were the reason that that sailor soldier war fighter died because your data was leaked and it was easier to hack your network than trying to go after a major DOD system that has layers and layers and assessments on there. So I think this is one of those. It sounded good. Hey, Mom, I want a gallon of ice cream for dinner. It feels really good at that moment, but it's going to be a lot of pain in the morning and through the night, especially if you're lactose intolerant and you're going to just be dealing with it for quite some time. think that's the watershed moment we're at at this point.
Justin Beals: I like how you say about litigiousness because any disgruntled employee, any competitor, any flow down requirement, I mean you're so much more exposed than what you mentioned Logan where if I got an assessment from a third party auditor, I have some defensible position when these things come together.
Lance Arnold: Yeah, and I'll be the first one to say as an IT guy that's done a ton of this stuff, there were things that I did not see and think of going through my third party assessment. We spent all this time, energy on it, we're good. what do you mean that? well, that actually makes perfect sense. And now that we're crawling through it, painfully, slowly walking through that process, I guess on the other side, painfully dealing with it, because I thought my SSP was perfect. I thought I covered everything as we learned, and adapted and did that process. just I encourage everyone to continue to go forward during this time period so you know your data, your contracts are safe and secure.
Brian Hubbard: Yeah, if I if I could just for briefly pull on that thread of the HIPAA thing, think about HIPAA. You cannot be HIPAA compliant if your people in your organization don't understand the requirements, right?
Same with CMMC. You cannot be compliant with CMMC if your people in the organization don't understand their part of the requirement. Didn't say the entire requirement, because they don't, you know, your HR people don't need to understand all the how your firewalls are configured or what they need to how do they need to block. But they do need to understand what their role is, right? And even down to the janitorial staff walking through your shop floor as a manufacturer.
Your gen though they need to understand if I see CUI laying around, do I just pick it up and throw it in the trash can? Right? The answer is no, right? And they need to understand that. Even those people need some some portion of the education about what the requirements are.
Justin Beals: Logan, I'm, I'm a little curious as, as, you know, leading an assessments team, we hear a lot about the technical aspects of these implementations and someone that was an ex CTO. understand how obscure those can feel and difficult, but I often tell customers the biggest lift is actually on your internal governance and how people operate. and, you know, it's, there will be a challenge around the technical side of encryption or tracking data effectively, but the bigger and, and maybe more visceral changes how you're going to operate as a company.
Logan Therrien: Yeah, you're absolutely right on with this. so the easy part is I'm going to flip the switch off, right? But the operations is, well, what does that affect? Well, then half the department say, can't do my business like that. Why can't I? Well, because I don't like to. Well, can you do it another way? So I mean, if you just think about programmatic solutions, processes being implemented across an organization. And by the way, that's after you get everybody to talk. You have large organizations where the physical security teams in a different part of the country than the IT folks, than they've never met the contracting team. So this is after you get everybody on board, figure out how to even coordinate this program, and then being able to determine, well, we can't do this. How would we like to operate? Let's start a working group. That sounds like a lot of work, and it is. And by the way, none of that's an assessment cost. That is actually the bigger picture that didn't disappear. But that's a lot of work. I worked with a company between my military time and my working with Cary time for about a half a year and it was a beast. It was a little bit, not much different than the military, not as slow moving as the military for process change, but still just having everybody on the same mission focus with the same priorities, it's difficult.
Justin Beals: Before we move off of this, what is still required conversation? What is the change around phase two, which I think is really the meat of what folks need to understand. Anything else that anyone on the panel would like to add to, this is still something you need to do. This is why that we may not cover.
Logan Therrien: I think I mean, please back me up, Brian and Lance, but the still need to do you still need to enforce one 70 missed 800 171 compliance at the 800 171 alpha assessment objective level, right? You still need to validate you're doing all these things. You still need to assess those results and report them via SPRS method and then affirm that they're accurate in accordance with the scoring methodology that is accepted by your organization with DFAR 7021. So again, all the same rules apply. The only thing is that at this point, if the change in the requirement, not the DFARs, so you're still gonna receive DFAR 7021, but it may be the wording and having a level two self-assessment versus a C3PO third party assessment. And so everything else is the same.
Logan Therrien:
So really how this impacts again is you just you got to make sure you're just really knowledgeable and you've lost a layer of backup between yourself and the government itself. Now what has not changed? We have many customers that are on board, right? They are doing the right thing. We have had no cancellations, right?
Primarily, I think it's a couple different reasons because of exactly what I mentioned, you know, we are absorbing that risk. We've come in and we validated and they understand because they've done, they're not the beginning stages. These folks, these corporatists have worked hard, did their due diligence, due care and paid the price of whatever that costs, manpower, monetary value, and then made it happen. They're at the final steps and they understand the cost is minimal at this point the price tag on an assessment versus compliance. And they're just going to move forward and move and take it. However, there's another part is this is a suspension, not a cancellation of the process. And it's a 60 day review. They may come back and say, actually, we're going to continue. But these are some minor changes. We're actually going to delay the implementation to reduce. Here's the number. Here's actually what we found out is we're moving too fast. Maybe we'll slow it down. We don't know. It's all speculation. But it's a suspension. And anything can happen.
So to just stop saying, don't want an assessment, there's risk in that itself. Because we are also, we have a six month backup. We are doing four assessments plus a week. our schedules fill into December, right? So if they come back in 60 days and say, actually, we need to get back on the schedule, sorry about that. Okay, we'll see you in January. I hope that doesn't affect your contracts.
Brian Hubbard:
Yeah. Yeah, I think that's about the that's the other thing that hasn't changed is it may maybe the DOD contract isn't gonna have the clause in it that you thought was gonna come. But your primes, if you're a subcontractor.
They still need assurance that you are doing the right thing. How are you going to provide that assurance? They may still require you to go get a C3PAO assessment. You know, it's up really, it's up to the prime. It's not a government thing. They they can flow down the requirement exactly how it comes through the contract, or they might add to it. You know, it's you need to have those conversations, right, with your with your primes and and your and certainly your government contracting officer say, okay.
Okay, well, this is a suspension. What are you planning after that time frame? Because if you're looking at a contract that's not gonna be awarded for another six months, 60 days extension doesn't that means nothing. If it gets turned on right before that contract award, you better be compliant or you're not gonna get the award, right?
Logan Therrien: I guess just one more thing I want to nail home here is that C3PAO's are still acting and operating functionally in accordance with 32 CFR port 170. Cyber AB is still operating. EMAS PMO team is still operating. We're doing business as usual.
Justin Beals: Yeah, excellent. Okay, Lance, let me just carve out some space. Anything you want to add to that? Otherwise, I may move on to chat a little bit about how this messaging was received. Yeah.
Lance Arnold: God, think I'm good. think Logan and Brian covered it.
Justin Beals: Excellent. Okay, so there were some very interesting things in the communication and I think it's fair to ask about them and what was said and how you guys feel about that. One is the CIO pointed to 100,000 plus companies needing assessment against only 100 assessors. And that doesn't jive with any data I've seen before. I'm curious.
Who might like to dive in on how valid, thanks Logan, you think that particular statement is? Yeah.
Logan Therrien: You know, so I'm all about efficiencies. If we can find a way to do things better, let's do it. But it has to be based on informed and accurate information. And that's not what this is going on. Right. So what I this is Logan's perspective on one point, and then I'll follow up with some accurate data. I think from what I've seen from the GO report and also some videos of a congressman asking questions about CMMC recently, is that he is receiving constituent complaints. And that is from small business administration who are, of course, they're defending their folks, they're doing their job, saying that CMC is hard and costs a of money. Well, let's go back to it. The requirement is that they do compliance. That costs a lot of money. The assessment is a small portion of that value, right? So what I really hear when I hear that is becoming compliant is expensive, right?
So I am not sure that what those folks in charge are receiving is accurate information on what exactly the costs are. Is it protecting the data or being validated of protection requirements? The other part is this assessor, right? So let's just look at a website. That information is incorrect, right? There are over 100,000 organizations that still need to be assessed. That is true, but there was seven years to do it.
There's a four phase rollout, but there's seven years of that implementing happening. And that is spelled out in the rule, right? That phase implementation is there. Now let's go back to the 100 assessors. If I were to look up today, and when was that memo generated? How many days ago? Three, right? So I looked at Cyber AB today. There are 1,035 CMC certified assessors.
Justin Beals: It was like two days ago, yeah, yeah.
Logan Therrien: There are 2,073 CMC certified professionals who can assess. And then out of them, there are 617 lead assessors. And if companies are doing right, they can lead multiple assessments a week. And so we're looking at potentially four to six assessments per week for an average C3PAO. We're not limited by assessors. Also, let's talk about full informed information.
There are assessors that we have sitting on the bench that are salaried. And why are they sitting on the bench? Because they're waiting for a T3, which is the background investigation that is in the rule as a requirement to be able to do this job as an assessor. What is the holdup for a T3? It's the government. So, you know, now what I would love to see out of this whole process is that they go, all right, now we have informed accurate information. Let's take a look at our internal processes.
And then let's start getting where are we missing data? Let's now talk to the folks that are actually doing the job and seeing what they're seeing on the deck plate and gather their information.
Justin Beals: Yeah, Brian, you're working in this assessment space. You're getting ready to become a C3PAO. How do you feel about this claim that there's just not enough capacity to run the assessments that are being asked for?
Brian Hubbard: Well, on on one hand, I I like that claim because it means more people should come take my CCP C C A classes. but on the other hand, they're wrong. and that is to Logan's point. You know, there's there's one, you got X you got it untapped capacity that has not gotten their clearances yet, their tier three, which everybody in the community has maintained that that's completely unnecessary wicket to go through. It's it's basically like going it's going through the same process as getting a secret clearance, except that you don't need it get a secret clearance. You do not need that for C th for CUI. So it it is complete overkill for this program. So that's one thing. But the other thing is organizations are not ready to be assessed.
So organizations haven't gotten themselves ready. So even if we were at w working at full capacity and they say, well that's not gonna be enough to get all those those companies are not ready.
So a company will show up to our door as assessors and we have to say, no, we can't if we do your assessment right now, you're failed. I mean, we can we can tell you that like in the first discussion often is like you are not ready for an assessment. You need to go back and do the work to actually become eight hundred one seventy one compliant and then come to us. Right?
Justin Beals: Yeah. Lance, think, yeah.
Logan Therrien: Yep, actually, can I come back to this? So I think this is important. You know, this is not a knock on OSCs. CMC is complicated. We do this 40 to 60 hours a week. and are both instructors. We understand what the requirements are and we try to teach and we give up our time to make sure folks understand. I love doing this and I love I'm an instructor by nature. I want to see folks succeed. We also have we're stirred to the community also just in our in our nature.
Right. And we we don't we this we make revenue off of good stories, you know. And so if folks come to us and we can see that they're not going to pass, it would not be in our interest or theirs to say, come on in, let's let's take care of this. Right. That is almost evil. Right. So it's unfortunately there's not we can't catch all cases, but we do have a screening and a scoping or framing process to validate that they are least meet simple objectives before moving in.
So I just wanted to make sure we understand this, that we don't, we're not saying you're not ready to go away because it's just fun to do, or we're just making up our own objectives. There are actually screening requirements to get into that assessment process, and we try to make the most of it so we're not wasting their money, again, in that minor expenditure of what the compliance and assessment process is.
Justin Beals: Yeah, everybody wants to pass an assessment. They don't want to fail a test.
Brian Hubbard: Exactly. Well, I may I maybe jump into a completely different topic, but but the but I think it's related.
When you have a C3PAO independent assessment, okay, the way the whole system is designed is not perfect, but the way the the CMMC assessment process is laid out and every C3PAO has to follow that process. every assessor is trained with the same, well, not exactly the same, but the, you know, the same, they pass the same test. They are all going through the same curriculum. they though so there should be some standardization there.
So when you're talking about a C3PO validated assessment, you know, you have consistency. So what does that do for procurement? It makes it a balanced playing field, right? You don't have one that just buys an assessment and another that does all the work and they are competing on the same contract. Self-assessment, all bets are off, right? You got anybody's interpretation going on, and well I'm false claims act may not hit me. You know
Logan Therrien: And that goes back to the risk. The prime is now taking that self-assessment. What are they getting? How are they? What is the risk at that? Sorry, Lance, go ahead.
Lance Arnold: Yeah, I guess I'll go back to Justin's original question or two parts. One, as we've said a few times here, the process, and I'll back up even further. I'm probably the one person in this call that doesn't have all the NIST controls memorized backwards and forwards. It's like my kid's birthday. So I don't have that same level of engagement with the years and years and years of focusing on this.
So for those who are listening to this podcast and they found it, would say, pull back a level. You're going to go buy a house. Do you, and there's all these standards where we are in the country and these be flood resistant. It needs to be fire resistant. It needs to be hurricane resistance wherever you at in the country. Well, if there is an issue and they're reviewing their permitting process and they say, Hey, we're going to pause on permitting. can self permit.
Do you wanna buy a house from the company that self-checked that has never had an assessment or has never been permitted to build your house that you're gonna be in? Are you gonna go with the one that's been certified, third-party, validated, and they know what they're doing, they can speak to it? Second point I'll make is with a self-assessment, I think it's less about someone trying to make the wrong decision or trying to take the cheap way or not wanting to do it. And even that $40,000 or whatever the price is for C3PAL seems like a big number. But as Logan as others mentioned, that big number, big number is actually a small number when you look at the level of effort of what you should be doing to be assessed. If you're at a point where that's your C3PAL bill, then you should have spent three to four times of time and level of effort and resources and software to be ready for it.
So if you self-assess, you're really taking a very high amount of risk saying that, Hey, I'm doing what I should do. And ultimately those government CEOs, which are not one unified person in one unified error, all across doing the business with you're asking them to take that risk and say, Hey, you know, you've never been permitted. You've never, but you can trust this house and you can trust that your data is secure. In this real world environment where at least in Florida or somewhere else, you may never get hit with a hurricane. So you can take that risk. In this world of cyber, we're all being attacked. We're all being hit. So there is, it's not a matter of if, I would say when, how will your network, how will your company, how will you respond? And how much risk are you asking that government contracting officer to take on your company?
Justin Beals: Yeah, Lance, I have one other question for you before we move to final thoughts a little bit. The other thing that came out was just the description of the cost of becoming NIST 800.171 compliant. It is not a one-size-fits-all. The folks in NIST in designing the framework, CyberAB in designing the assessment methodology has really tried to make it flexible. That is where some of this interpretation comes into place for different companies of different sizes with different types of data and different types of infrastructure. And I find oftentimes that people come in terrified until we sit down with them a second and say, hey, look, you're doing most of this. We just need to refine it a little bit. And then, yeah, there's some lift here, but it's good for you too. Is your experience similar?
Lance Arnold: Yeah, I think if you look at the smallest one, they're on a GCC high and you know, they're ready to go in and they're looking at the level of effort. going, my gosh, it's going to be so much. Well, do you need to print? Do you need to have a local enclave? Okay, well, no, you can keep it all simple. You can keep it all small. Microsoft and the GCC high is going to take care of a big chunk for you. If you're a large organization, you've got manufacturing things, you've got huge drawings, you got cameras, you got physical stuff that needs to be, no, that's a completely different scenario. So even though on that smaller scenario, I'll still say take that time because the difference between how you manage printing and how you manage your local laptops means a very secure network versus something that is easily hacked and accessible.
And I don't think there's one person, at least me,I would not, with even all my knowledge, all my expertise, I would not go into a network and build it all myself and say, I'm good to go self-assessment without someone else coming in and check my work. And somebody like a Logan who hasn't memorized and can cite exactly the moment in time when it came out, because they're going to give me that higher level. If Logan missed it, I don't know that anybody else would have caught it.
Justin Beals: Yeah, someone has pushed a lot of code to production. Quality assurance saved my butt many, many, times. Lance, any final thoughts? I'll then come to Brian and Logan as we wrap up our call today.
Lance Arnold: Yeah, I'll just say to everybody listening and watching is it is it is confusing. It is a little scary as a little back and forth. And especially if you're a very small business or actually it doesn't even matter or you're a very large business and you're looking at how much time and energy you're doing. This is the right thing to do. Is it the right perfect framework? Is it the right perfect rollout? Is the right perfect timeout? Could there be more? Could there be less?
There's always, there can be improvement, but I think that this is good enough to fundamentally improve your cybersecurity posture, which means you're improving the DODs or DOWs cybersecurity posture, which means you're improving everybody's, the nation, everybody on this call. It's important for everybody here that anybody supporting the Department of War is more secure and is more effective. So please take a moment. Think long, think hard, figure out a way of becoming more secure for the sake of everybody.
Brian Hubbard: Yeah, so I guess I would say that, you know, the key takeaway I think for OSCs or companies that need to be compliant. Let's call it that now, since it's not always organizations seeking certification now. But it is confidence. So they need to have confidence in w their implementation, and how do they get that compliment, you know, that confidence. They maybe get that confidence by hiring a a C3PAO to come in and do a do an independent validation, or they may get confidence from having their own people doing it, right? But how you're how are you getting that confidence? How are you making sure that those people in-house know what they're doing? And if you're hiring a third party, whether it be a C3PO or a RPO or you know other acronyms in CMMC LAN, you know, or just somebody off the street to say, hey, come in and do a do a gap assessment. What is your confidence in that person? Do you have people in-house that are actually trained enough to understand whether they're being led astray, right? Are they being told the right things? Does it make sense what they're what how their how what their the assessment is saying to them, right? So you know to me it's how do you build that confidence, and then you need to really get people in-house that are at least know enough to to make that make that judgment.
Justin Beals: Logan.
Logan Therrien: I don't want to stack on everything Brian and Lance just said, but I'm definitely in line with what they're saying. So the C3PO's also, a lot of them provide consulting, not all of them too. So if this is a shift, and again, the requirements haven't changed, who are you using to validate? So we've talked about the level of knowledge of your internal team versus the external, the folks that have been doing this for quite some time. How are you going to get through that? And if there is that risk that you identify and how you're managing it in one of that ways, you know, use those folks that have been doing this for quite some time, have all the certifications, have the assessment experience, have that network of folks when they have questions to be able to get you through this process. So what I do want to add is there's a request for information out from the DOD-CIOS office right now. I said I'm proponent of efficiency as long as it's informed and accurate, right? So. without the cost, I think they've already heard that enough, right? What are your concerns? What are your questions? And get that in front of the DOD-CIO's office so they can, again, make informed decisions on how they want to do this. Because the ultimate outcome after the suspension may not be, let's put it back in place, let's just get rid of it. It may be, let's do it better, and this is what it looks like. So that input from the ecosystem is going to be really important.
Justin Beals: Yeah. My thoughts about this are as someone who has loved ones that are employed or participate in the national defense, our military and our community, and someone that has now taken his company into a space of supporting companies that are supporting that mission as security matters. Since World War II, our nation's defense has been a private public partnership. It was required for us to be able to be successful in those engagements and succeed in defending the nation, to be able to produce and manufacture and bring intelligence to the battlefield in a term. And if you're operating in this industry and you don't have a passion for supporting that mission, I think you're in the wrong industry.
Lance Arnold: Yeah, can I have one say Brown? I just I love your analogy Justin and in World War two the adversaries were not sitting at all around the table with all of our public private people. We're all connected to the internet. If you don't have good cybersecurity available, you're basically doing all of your you're not using some other type of certification to verify it.
You're everything you're doing. You're doing with all of our nation's adversaries. And right now it's a very complex world. There's a lot that's going on and we have a lot of people that are relying on you to do it well. So do not take lightly with your responsibilities.
Justin Beals: Thank you, Lance.
Logan Therrien: Oh, one more thing. just, you know, so, you know, we talked about, I think this was mentioned a couple of times was, the arsenal of freedom, pay attention to that, you know, and being able to rapidly put capabilities. So if we're removing a step in validation, validating the confidentiality of that data, just so we can produce things faster, you know, that's, that's kind of a shift in priorities that may not make sense. And if you look at one of our largest adversaries, China, they have proven that they can reverse engineer everything.
And what they typically do is either buy or steal intellectual property and create something just as cool. Maybe not as good, but just as cool. But that's only one side of it. Now, if they have that data, exactly what you mentioned, they may know the vulnerabilities. And so it doesn't matter how fast we produce things or how many things we produce. If they know how to take it out within before we can even defend ourselves, that is not valid.
Justin Beals: Yeah, I know all of you served on some level and you sat in those seats that took the brunt of, you know, a difficult adversary. I'm very grateful to get to have this conversation with you all today. Thank you so much for bringing expertise in science to a very confusing scenario. We're really glad to get this podcast out quickly to our audience.
So just my heartfelt thanks from myself, the listeners at SecureTalk, and broadly our community for the work that you do.
Lance Arnold: All right, thank you out there.
Logan Therrien: Thanks, Justin.
Brian Hubbard: Thanks for having us.
About our guests
Lance Arnold is a global cybersecurity and engineering leader with 29+ years building and delivering secure enterprise solutions for the Department of Defense and Fortune 500 organizations — spanning CENTCOM, EUCOM, AFRICOM, SOCOM, and DISA. As Director of Kieri Solutions, he helps defense contractors achieve CMMC certification, and as a former enterprise CISO he personally led a company to a perfect 110 CMMC Level 2 score with a full Zero Trust transformation. He is a CMMC Certified Professional and Certified Assessor (CCP/CCA) and pioneered the DoD's first virtualized data center and private cloud under the Mission Partner Environment (MPE).
Brian Hubbard is President of Evolved Cyber and a cybersecurity leader with more than 40 years of experience. As a Lead Certified CMMC Assessor and CMMC Credentialed Instructor, he helps defense contractors and cybersecurity professionals navigate CMMC assessments, readiness, training, and compliance. Brian has led major cybersecurity programs, supported NIST cybersecurity initiatives, and spent two decades with Booz Allen Hamilton supporting national security and information assurance efforts.
Logan Therrien is Chief Strategy Officer and Lead CMMC Assessor (LCCA) at Kieri Solutions, one of the original C3PAOs in the U.S. Defense Industrial Base. A retired Navy Lieutenant Commander with 24 years of active duty, he managed information security for over 7,000 personnel and oversaw physical security for assets valued at more than $20 billion. Since transitioning to the private sector, he's become one of the most recognized names in CMMC implementation, conducting assessments, training the next generation of assessors as a CMMC Provisional Instructor, and co-authoring research on standardized evidence sampling in CMMC assessments. He holds a M.S. in Information Assurance, the CISSP certification, and is actively pursuing a Ph.D. in Cyber Defense.
Justin Beals is a serial entrepreneur with expertise in AI, cybersecurity, and governance who is passionate about making arcane cybersecurity standards plain and simple to achieve. He founded Strike Graph in 2020 to eliminate confusion surrounding cybersecurity audit and certification processes by offering an innovative, right-sized solution at a fraction of the time and cost of traditional methods.
Now, as Strike Graph CEO, Justin drives strategic innovation within the company. Based in Seattle, he previously served as the CTO of NextStep and Koru, which won the 2018 Most Impactful Startup award from Wharton People Analytics.
Justin is a board member for the Ada Developers Academy, VALID8 Financial, and Edify Software Consulting. He is the creator of the patented Training, Tracking & Placement System and the author of “Aligning curriculum and evidencing learning effectiveness using semantic mapping of learning assets,” which was published in the International Journal of Emerging Technologies in Learning (iJet). Justin earned a BA from Fort Lewis College.
Other recent episodes
Keep up to date with Strike Graph.
The security landscape is ever changing. Sign up for our newsletter to make sure you stay abreast of the latest regulations and requirements.
.jpg?width=1448&height=726&name=Screen%20Shot%202023-02-09%20at%202.57.5-min%20(1).jpg)
%20(5).png?width=500&height=300&name=Untitled%20(350%20x%20200%20px)%20(5).png)