Event
August 7, 2025
A Good Example…or a Cautionary Tale? Avoiding CMMC Preparation Pitfalls
Overview
Join Future Feed’s Stuart Itkin as he moderates a webinar featuring Fathom Cyber CEO Jim Goepel and C3’s VP of Compliance Scott Whitehouse. They will discuss the most common mistakes organizations make when preparing for CMMC and offer strategies to avoid them. Using real-world examples and expert advice, this session aims to help you spot potential issues, make timely adjustments, and guide your organization toward a smoother certification process.
Here’s what you will learn:
- The most common pitfalls in CMMC preparation—and how to steer clear of them
- Misunderstandings around scoping, documentation, and evidence
- Lessons learned from organizations that got it wrong (and right)
- How to build a readiness plan that’s efficient, realistic, and assessment-ready
- Tips for engaging leadership and building a culture of compliance
Transcript
Good afternoon, everybody. Thanks so much for joining us today.
Today we’re going to be talking about Avoiding CMMC Preparation Pitfalls. My name is Karen Vasquez. I’m the marketing director at C3 Integrated Solutions.
I’m your host for today’s webinar. We have a panel of terrific people, experts in their fields. I’ll allow them to introduce themselves in just a second. Stuart Itkin, who is our moderator, will kick things off. Before we get started, though, I just wanted to cover a couple of housekeeping items. First off, we’ll be recording the webinar and distributing it to all of our registrants by the close of business today, so be sure to look for that in your email.
It will come from me, Karen Vasquez, kvasquez[@]c3isit.com. Once in a while, those emails wind up in junk. So double check, but you will get it before the close of business today. Next, we’ve got a lot of great stuff to cover in today’s one-hour session. We are definitely going to leave some time at the end for Q&A.
So, if you do have a question, please enter it in the questions module on the right-hand side of your screen. We’ll do our best to get to everybody’s questions before the hour is up. But if we don’t, we’ll do our best to answer it via email following the conclusion. Lastly, included in that email will be a registration link for our next webinar that we have scheduled for September 23rd, also on CMMC.
If there are resources that our speakers mention today during the course of the webinar, we’ll be sure to include those as well. Just as a heads up from a presentation standpoint, we are looking forward to a terrific discussion. As such, we won’t have a bunch of slides to share, but that will allow you to remain engaged in the presentation.
Like I said, we’ll have the recording. So, if you miss something or you want to go back and clarify a little bit of information, you’ll have that recording to reference. With all that said, why don’t we get started? Stuart, why don’t you kick us off?
Okay, let me introduce myself. My name is Stuart Itkin. I’m the CRO and the Chief Security Evangelist at Future Feed. Future Feed is the leading GRC and compliance management platform created for the defense industrial base. Much of my career has centered on supply chain and vendor risk management and regulatory compliance. I previously served as a member of the CMMC Standards Working Group and participated in the establishment of the CMMC accreditation body.
I’m a founding member of the MSPs for the Protection of Critical Infrastructure and a director of the CMMC Industry Standards Council.
Scott, want to introduce yourself?
Sure. Scott Whitehouse, I’m the VP of Compliance at C3 Integrated Solutions. I’ve been in the industry about 20 years. Kind of an interesting side, I’ve worked in the defense industrial base where I ran IT departments in classified space. I’ve also now been on the service provider side, helping organizations get ready for CMMC compliance.
It’s a fun place to be, having sat on both sides of the table.
And I’m Jim Goepel. I’m the CEO of Fathom Cyber. We’re a CMMC compliance organization. We help you get ready. We’re not an MSP or MSSP. We are partners with C3 and point you to them for a lot of the work when you need help with some of the less technical and more business-oriented things—especially getting ready for that CMMC certification. That’s us.
I’m a CMMC provisional instructor and lead assessor. I helped create the CMMC accreditation body, and I’m a lawyer and all sorts of other fun stuff. Which, by the way, means that I need to put in the disclaimer that none of this is legal advice. Everything we’re going to talk about is really at a high level.
So, make sure that you’re getting good legal advice. I am not in private practice, so I can’t help you, but I can point you to people if you want to reach out to me. Our contact info is in the slides, so if you need help, I can point you to a couple of lawyers.
Okay, and we’ve got a lot to cover with respect to common pitfalls that we’ve seen organizations make in the course of preparing for CMMC. Again, we want to share helpful hints to avoid those pitfalls that others have made. Two weeks ago, the CMMC program reached an important milestone when the 48 CFR rule was passed on to the Office of Management and Budget for its final review.
This is a signal that the final rule could be published in the Federal Register as soon as 15 days, and not likely more than 45 days from now. The rule will become effective 60 days after publication, meaning its effective date could be as early as October or November of this year. Now, the importance of 48 CFR is that it enables contracting officers to add CMMC requirements in the form of what will be a new and improved 7021 clause to solicitations and contracts as of that effective date.
If we look at 32 CFR part 170, this is the CMMC rule, which became effective last December and established the CMMC program. It says, in quote, “On the effective date of the complementary 48 CFR part 204 CMMC acquisition Final Rule, DoD intends to include for CMMC status at level one or level two for all applicable DoD solicitations and contracts as a condition of contract award.”
It goes on to state that 12 months after the effective date, a C3PAO assessment will be a condition of award for Level 2. Twenty-four months after that effective date, a DIBCAC assessment will be required for Level 3.
What this means is that if you’re expecting or hoping to receive an award after that effective date—potentially as early as October or November, or you’re expecting to exercise an option period, then you must have met the CMMC requirements to receive that award.
If you haven’t, you’re not. If you’re not award ready, no award. It’s that simple. And so, make no mistake, CMMC is coming to a contract near you, and to be awarded that contract, you need to be ready. And so that’s what today’s discussion is about. It’s about being ready. Collectively, we’ve probably seen hundreds of companies that have gone through the process of going ready, and we’ve observed them preparing for CMMC and preparing for their assessment.
In the course of that, we’ve seen a series of common mistakes companies have made. Today we want to explore some of those common mistakes with you and share some best practices to help you avoid them. So, let’s get started.
The process of getting ready itself is pretty involved. Unmet requirements need to be addressed, an SSP needs to be created, policies and procedures need to be established and institutionalized, evidence needs to be gathered, and the organization needs to prepare for its assessment. This all takes time.
When going through the process of being ready, do organizations typically allocate enough time? Are there steps they miss when planning, or things that they don’t account for? Let me start this with Jim.
There are actually several things that people don’t account for. If you’re going to try to do this yourself, you can count on this being at least a 12-to-18-month process. Quite frankly, most organizations think that they can push the easy button and just build an enclave, and tomorrow they’ll be done and ready. That’s definitely not the case. There are some good solutions out there, and good solution providers like C3 that will help accelerate that process for you, but it is still something that takes time to get done. Even if we get involved, it’s still a 6-to-9-month process at a minimum. There are just fundamental business things that need to be addressed.
One of the things I want to point out, as Stuart was talking about that timeline, is that there are two factors here. The first year is self-assessment, which everybody kind of thinks is still that get-out-of-jail-free card. That’s not actually true. You need to have either that perfect 110 score or pretty close. You need to have a minimum of an 88 to get what’s called a conditional assessment. That starts a clock, and you’ve got six months to get to done. So even though you have this extra year of self-assessment, it doesn’t mean things are going to continue to be status quo.
You need to be prepared to go back to Stuart’s fundamental question about timing. You need to make sure that you understand when you expect that next good contract you want to be included on. You need to understand when that’s likely to happen and work backward from there. You also need to look at the backlogs that the C3PAOs have. One of the companies I’m involved in is a C3PAO. They’re all backed up. They all have a lot of companies in queue. One of my good friends runs another C3PAO. His company is backed up until March or April of next year at least. If you think you’re going to have that contract coming up, you really need to get on that C3PAO waitlist now. You need to start working backward and make sure that you have the time and resources allocated to it.
Scott, I don’t know if you disagree with anything I said.
No, I actually think you’re hitting the nail right on the head. As you’re thinking about the timeline, the most important thing you can do is leave yourself breathing room. There will be hiccups along the way, and you can probably predict some of them. And then there will be two or three that you don’t predict. If you’re working backwards from when you need to apply on a contract to today, plan on having some hiccups along the way and give yourself some breathing room.
Also, keep in mind your process should not just be: I get all my documentation, I do all my configuration settings, and then I’m ready to go. You need to include readiness and preparation for the actual assessment. Having your policies, having your plans, having your SSP together—fantastic. However, that does not mean you’re ready to walk in day one with an assessor. You need to make sure that you’ve prepped stakeholders, talked to business partners, and ensured that they’re ready. Do you have external service providers? They need to be prepared to support you and provide you with the necessary documentation in order to walk into that assessment.
Those things take time. Leave that in your schedule. And if you’re going to hire somebody—sorry, Stuart—if you’re going to hire somebody, that’s one of the big things to look for. Make sure that you are working with an MSP, MSSP, or cloud service provider that understands 800-171, understands the CMMC program, and is prepared to make the commitments necessary to do all the things that need to be done.
We see a lot of folks who are bringing their MSPs or MSSPs with them. To Scott’s point, they think they’re ready. They’ve written up what looks like an SSP—a system security plan—but it’s not, and there are a lot of holes. There winds up being arguments back and forth between the MSP and the company that’s trying to get assessed because the company thought the MSP was doing things and vice versa. It just becomes a whole big mess. Finding a good, sophisticated company that knows what they’re doing is going to be really important. And if this is your first entry into hiring an MSP or MSSP, you really want to make sure you’re doing some diligence in selecting them.
With respect to timing, it’s not just, “Okay, we’ve finished everything, we’ve put everything in place, here’s our documentation, let’s get assessed.” You actually need to demonstrate that you’ve institutionalized these things, that you’ve been doing them, and that they’re achieving the objective you expect them to achieve. So yes—plan, leave enough time, and anticipate that something is likely going to go wrong so you have a little bit of wiggle room.
Let’s move on. The first step to getting ready is scoping. Scoping involves identifying the CUI boundary, inventorying and categorizing the assets within that boundary, and establishing the scope of it. Scoping establishes the foundation for the rest of the process and for your assessment.
Presumably, a mistake when scoping can affect everything else and ultimately jeopardize passing an assessment. What have you seen organizations get wrong when it comes to scoping? More importantly, what would you recommend they do to get scoping right?
Let me start with Scott. Two big things. One is identifying your assets. You have to know what you have and apply proper classification to them. CMMC established different asset classifications: security protection assets, CUI assets, and specialized assets. As you’re going through those, the requirements for each individual asset type vary. If you have a CUI asset, all 110 controls are going to apply. If you have a specialized asset, that’s not going to be the case. That may be the difference between documenting, identifying, and having risk management and structure around it versus making significant investments to bring something up to meeting 110 controls.
Most of your assessment is going to be won and lost on your scope. Included in that is what assets actually come into your scope. Is your physical premise going to be in scope? What about your network, your endpoints, people, or alternative workspaces? Those are all super important. The smaller your boundary, the smaller your scope, the fewer things you have to prove through your assessment. Concurrently, you have to be able to prove that is actually your scope.
If the assessor walks in and they’re looking at a diagram and it says your boundary does not include a physical office space, but you have no logical separation, yet people are working there and processing CUI, it’s not going to pass the smell test. You have to have a justification. Yes, I have somebody there, but this is why it’s no longer in scope. Be prepared. Write that down in advance so you have your talking points ready. We’re big advocates for starting at the very beginning.
So, we’ve published a 12-step program. And the first step is actually to understand what CUI you have and what government information CUI and FCI you have. How does it come into your organization? How does it flow? Because to Scott’s point, you need that inventory. Well, first you need to understand what touches that information. And so I first thing you know, where the information is what kind of information do I bring in.
And there’s a whole bunch of other things that you need to know too. One of the requirements talks about popping up a display banner when people go to log into your computers. That banner needs to be consistent with the requirements associated with the kind of CUI that you have. Well, if you don’t know what kinds of CUI you have, you’re going to fail that.
So, we always tell people, start with that FCI or start with the FCI and CUI. Understand how does it come into our organization? Does it come in by email? Do we get it through Dropbox? Do we get it from DoD SAFE or from some other source? All of those different options—how does that come in?
And then, what flavors of CUI do we have? How much of it is CUI specified versus CUI basic? Get that basic information inventory in, start looking at that, and see how it flows through the organization and who touches it. Because there are requirements right up front. The very first requirement 311A, as you go through the 800-171 alpha assessment guide, states that authorized users are identified.
Well, in order to be an authorized user, you have to know what kind of information they’re handling, whether they are authorized to handle that particular piece of information on that contract versus another contract. There are all sorts of subtleties, and we see people jump right into, “Oh, well, we’re just going to do an enterprise-wide assessment.”
So they assume that everything is in scope, but they fail to do some of the basic fundamental data inventories and asset inventories that Scott was alluding to. As a result, they wind up just creating all sorts of problems for themselves. They think they’re ready for the assessment, but they fundamentally can’t do some of the things they need to do.
One of the biggest challenges I see organizations face is identifying their external connections, and they become sticky. As Jim’s talking about identifying your CUI—where it is, where it’s going to live, how it’s moved—the best way to do that is by talking to the people on the front lines who are actually interacting with the CUI.
I can’t tell you how many times we’ve come across this. We have a CUI flow in place, and then you talk to someone, and they say, “I don’t do that. No, it comes from this other place, or Jimmy does that.” It’s always Jimmy. So, go talk to the people at the ground floor and find out how they’re actually interacting with your CUI.
What you may end up finding is that there are other tentacles that exist. It’s that shadow IT—“Oh yeah, we shared this folder with this external organization,” or, “Yeah, we’ve got this B2B connection,” or other mechanisms that allow access to the environment that may not have been documented. It went through a service ticket, was set up, and somebody forgot to tell somebody else.
Those are the things in requirement 3120 about identifying your external connections that will trip you up. As you’re going through the assessment and the assessor says, “Great, can you show me that?” you’ll stumble across something undocumented, and they’ll say, “Wait a minute, I don’t remember seeing that before. Can we circle back to this?” Suddenly, all these green checkmarks go from green to red, and now you have users you haven’t authorized, connections you haven’t identified, and probably no monitoring or logging because you didn’t know it was there.
I’ll add the extra wrinkle of security protection assets and security protection data. I saw this in a gap assessment we just did where the client gave us a list of all the assets. We start going through it, and then I ask them, “Well, how does this happen?” They reply, “Oh, well, that’s this tool over here.” That tool was not in the asset list.
I asked, “Does it actually handle CUI?” and suddenly it opened a whole can of worms. Thankfully, it was a mock assessment—even earlier, it was just a gap assessment. But had it been a formal certification assessment, they would not have passed.
So yes, identifying CUI, as you mentioned, can be confusing. Jim, you wrote the book—actually, I think you wrote three of them—on CUI, and presumably they’ll be referenced in the materials that Karen sends out afterwards.
Scoping can be confusing, identifying CUI can be confusing, and there are partners available to help organizations through this journey. C3, for example, is one of those partners that has helped a number of organizations go through this process and supplement those that don’t have the compliance expertise or the IT or information security expertise needed to implement, operate, monitor, and maintain their CMMC program.
While there are many good managed service providers and managed security service providers out there, and most of them are capable and qualified, some do misrepresent themselves. They say they’re qualified when they’re not, and choosing the wrong partner can be a mistake.
So how do you ensure that you’re choosing somebody who truly is capable and qualified, and ideally the right one for you? Let me start with Jim on that.
For that, there’s a lot of basic diligence that needs to happen. Asking upfront whether they can actually spell CMMC and know what the acronym means is a good start. I’m partly joking, but you’d be surprised. Getting good answers out of them and asking for an SRM—a service responsibility matrix—helps. That breaks down what the vendor is committing to do at the 800-171 level, ideally at the assessment objective level, but at least at the requirements level. Walking through exactly what they do and what’s still on your plate to do.
If they have that at the ready, even if they require you to sign an NDA, that’s a fantastic sign. You can better manage your expectations, really understand what they’re committing to, and it shows diligence on their part that they’re at least reasonably mature in this process.
If they don’t understand some of the basics, another point is to look for somebody who has a CMMC Certified Professional (CCP) on staff, or at minimum, a Registered Practitioner (RP) on staff. Those are people who have gone through basic training on CMMC and passed a quiz or exam. It’s a sign of competence.
MSPs that have gone through and passed their own CMMC Level 2 certification provide further assurance—they understand the requirements of NIST 800-171 and have demonstrated their ability to address them satisfactorily. There is even a directory of organizations that have voluntarily completed their own Level 2 CMMC certification on the MSSP Collective website, mspcollective.org.
Some companies also work with multiple partners—more than one MSP or compliance advisor—to prepare and maintain their CMMC program.
Scott, what do companies need to be cautious about when they have more than one service provider supporting their environment?
It’s important to maintain communication with your vendors. The last thing you want is everyone working in a black box. When it comes time for an assessment, nobody is prepared, or they’re on different pages. Also, keep in mind there may be overlaps in services.
For example, if you have a SoC monitoring your system with vendor A, and you have an MSP handling your IT and break-fix work with vendor B, there may be overlap. The SoC may end up sending some tickets and support requests to vendor A to fix.
Hey, we just saw this. We need to run this scan or this computer needs to be removed and rebuilt—those types of things. When you’re thinking about incident response, there are going to be overlapping priorities and overlapping services. So keep that in mind. Make sure that their SRMs are aligned. Make sure that your plans and your documentation keep that in line.
Or if you say it’s only performed by one vendor and in actuality it’s performed by both, that will come out within your assessment. As you start to prep for the assessment itself, it’s worthwhile to get everybody in the same room, get on a Teams call, get on a Webex, and talk through it. “All right, here’s where I see the potential overlaps. Who’s going to speak first? Who’s going to speak second? How are you going to hand this from one entity to the next?”
We’ve done that before where we had a customer using another SoC and we walked through it. “Cool, you’re doing the monitoring. You’re doing the analysis and the triage, and then you’re handing off to us for containment.” Those types of things need to be worked out so that when it comes time to show evidence, you have consistent evidence. Someone should be able to show: “Well, in alert one we did A, B, and C, and then we handed it off.” But if another vendor got a ticket for alert seven and there’s no continuity, the assessor may ask, “Wait a minute, how do I know you’re actually following this through from start to finish?”
If I can circle back for just a minute—when you’re going through and selecting vendors, making sure that they have certifications obviously goes to their credibility and capability. It will also de-risk your assessment, and that’s a huge key.
In the 32 CFR Part 170, your external service providers are open for assessment. If they are already certified, those assessments are performed to a greater degree. So now you’re a little less concerned about whether your ESP is doing the needful to keep your environment secure, or if they’re going to be the risk that causes you to fail.
If they have that certification, they can provide the evidence. Sometimes assessors will still ask to see things, but if they’ve gone through the due diligence of creating the assessment, investing in it, and completing it, you have a much greater likelihood that they’re doing the right things than somebody who’s just saying, “You’re my one CMMC customer.” That makes a lot of sense.
We’ve seen some companies that within their SSP, for each individual control, they’ll identify the RACI—who’s responsible, who’s accountable, who needs to be consulted, and who needs to be informed. That way it’s clear that when you’re working with multiple service partners, or even within your own organization, you know who has the ball and how coordination occurs.
Talking about the system security plan—we mentioned it a little before—it really is the core document that describes how an organization addresses each of the 320 NIST 800-171 assessment objectives. The CMMC program is built around the concept of “trust but verify.” During the assessment, a C3PAO will walk through each assessment objective in the SSP with the OSC. They’ll ask the OSC to describe what they’re doing, how they’re doing it, and how that meets the objective.
We touched on SSPs, but where else have organizations made mistakes in preparing them? For me, a lot of times it’s evidence. They’ll write up what they’re doing, and that’s great—but you have to be ready to prove you’re actually doing it. If you have a procedure that’s supposed to happen monthly and your system has been up for six months, I should at least see a couple of pieces of evidence showing it was done.
Same thing with onboarding and offboarding procedures. As you bring people in and out of your organization, you should have evidence. Now, as an assessor, if you’ve got an onboarding process created three weeks ago and nobody’s been hired since, I’m not going to ding you. We’re not unreasonable, but we are diligent. We will ask you to show those things.
The part I see people messing up on most is not being thorough with documentation. Stuart used two good verbs: adequate and sufficient. Adequacy is whether it meets requirements. Sufficiency is whether you have it for all relevant assets in scope. People often forget that a requirement may apply to multiple assets, and you need evidence for all of them.
Scott, do you have anything to add?
Yes. When you’re going through the SSP, pay attention to the verbs. Every assessment objective uses a specific verb, and that verb tells you what you need to do. For example, if you see “define, describe, develop, identify”—write it down. Maybe it’s a paragraph, maybe it’s a spreadsheet, but it needs to be documented.
If you see “controlled,” it may be documentation-related or a technical configuration depending on the objective. “Monitored, implemented, performed” generally means someone is actively doing something. If you see “protected,” it’s likely a technical configuration. Break down those verbs and make sure you have evidence to prove you’re doing what’s required.
If something says you’ve defined it, it’s going to be difficult to prove with just an alert. And if you’re working with a service partner who has helped other organizations with their SSPs and gotten them through certification, that’s a good sign you’ve got someone qualified who can help you avoid mistakes.
We often forget that for most organizations, getting ready for CMMC and satisfying NIST 800-171 is a first-time event. Getting it right the first time without help can be very difficult.
We’ve talked about some of the big rocks—timing, scoping, service providers, and the SSP—but there are other requirements organizations regularly struggle with. Jim, can you share more about CUI and how organizations stumble there?
I think the biggest thing you can do is get educated. DoD and NARA have some good training on how to mark CUI. That’s all well and good, but bigger-picture issues often trip people up.
I run a nonprofit, the CMMC Information Institute. We give away training—you just need a $25 membership. We also run webinars that cover the same material. Go learn about CUI, get familiar with it. Fundamentally, it’s sensitive information. It’s data that a law, regulation, or government policy requires you to protect.
Under CMMC, the government is now verifying that you are protecting it the way the law requires. The single biggest mistake I see is confusion. People pull up the NARA registry—the CUI registry that lists all relevant laws and regulations—and see that privacy information is listed. They panic, thinking every employee record is CUI.
That’s not the case. There’s a wrinkle in the definition that says it must be the government’s information or information the government is handling on someone else’s behalf.
And so the government ultimately, is the entity that has to determine whether that piece of information is CUI. And the only time that it can be CUI is, again, when it’s their information, when it’s yours and it’s in your environment, it’s not CUI. So, there are some basic things that can really simplify the analysis to go back to that inventory conversation from the very beginning.
There are some fundamental things that if you are aware of them, as you start down this process, life gets a whole lot easier. Matter of fact I’m going to chime in on that a little bit. You know, circling back to our conversation earlier about scoping and boundaries and preparation, if you’re unsure where your CUI is or what it is or how you receive it and when it becomes CUI.
In some instances, those are things you really need to understand before your preparation begins. That is your step one, because it is a cornerstone of identifying what you need to do. If you don’t know what your key is or where it is, or how it becomes quiet when it becomes C why? What makes it key? You will not understand what to protect and you will have dollars wasted on investments either through technology enhancements or, personnel and policies and procedures that are unnecessary.
If you’re in that boat, reach out to Fathom Cyber. Talk to Jim. He really is an excellent, excellent resource on identifying CUI. And I think with respect to, I mean, any of these requirements, I mean, certainly with respect to CUI in scoping, but, you know, but any of the controls, I think, you know, maybe the best advice is, you know, that if you if you’re not sure, if you don’t know, don’t guess if you think that, well, this would probably satisfy something you need to make sure you need to ask the right expert who can tell you exactly what the requirement is, how it’s going to be assessed, what it is you need to do to be able to ensure that you satisfy that requirement.
And, you know, it kind of goes on to not just the technical things we’ve talked about. You know, not all of the NIST 800-171 controls are technical. About 45 of them are non-technical. They include such things as physical security, and within security, physical security, such things as a requirement for escorting visitors just, you know, Scott, where do you see organizations making common mistakes with respect to some of these non-technical controls and things like physical security?
Yeah, I’m going to continue to hammer on scoping. I’m going to sound a little bit like a broken record because this is your left and right term. Right. If you have physical premises or premises that are in scope now, you need to get into more tech and more non-technical things. How do you identify visitors? Do they need to be walked?
How do they are they monitored? How do you monitor it? Is it through video? Do they need to be with an employee? Is it any employee? You know, can they go to restricted areas? Are they allowed throughout the entire premises? There’s a lot of questions that go into just how do you control your visitors? That’s your scoping comes in.
The smaller your scope, the easier things are going to be. If you have printing involved, be prepared. It will open up a lot of questions about your non-technical controls. Where do you print? Do you print CUI? What devices do you use to print CUI? Once you’ve printed it, where do you store it? Does it have to be locked?
Does it go into a specific area? Can it be anybody printing? Is it any space within your facility that’s printing? Does that print go over the network? There’s a lot of questions that go into that. So, your non-technical controls, we can’t we can’t ignore those. Those are just as important. And you’re just the greatest. You’re just as much of a degree of being able to fail an assessment from saying, I don’t know where my paper goes or I don’t know how I dispose of it.
I just put it in the recycle bin and the cleaning crew comes through at night and it’s gone the next morning. Like that’s not going to fly. Right? Right. There are regulations about how to destroy physical CUI. Right? There’s a whole NIST 800-88. So you have those things in mind. But it’s not limited to just paper.
Keep in mind, you know, removable storage or SD cards, USBs, external flash drives, controlling of those are all non-technical controls. Right? So, we can take a thumb drive, stick in their pocket, walk out the door. That’s a problem. So, how do you control it? Be prepared for this. Have a process and be able to prove it. I’ve been told many times say what you do.
Do what you say, right? You say that you’re doing something. If you say that somebody has to sign out of an external, storage device in order to use it, or it’s only going to be assigned to specific people. Do that, show that you do that, have that log? Yep. I assigned them all. They went to these people.
And these people have them in their possession. And at night they’re required to lock them up. Here’s the policy. It’s in our acceptable use policy. They’re required to do that. They’ve signed it. Here’s a desk drawer. You can see they have a lock. And on their keychain they’re showing they have their key. Right? You are saying what you do.
You do what you say. Be prepared for this. For the non-technical controls, sometimes it can be harder to prove. I want to just emphasize one thing Stuart. And, then I promise I will let you talk. But, remember that we’re talking about visitors. People tend to forget about certain categories of visitors. Say your family. Like for small businesses, you get used to having family come in to your place of business, and it makes it a nice place to be, right?
Well, when it comes to CUI you can’t have them just walking around the facility, same thing with the copier repair person or the vending machine person or any of that stuff if they are in your controlled environment, if, they have to be escorted the whole time. They are visitors, no matter what they are. And you have you have to make sure that they don’t have access to CUI that whole time.
So, what we often find is, we, our clients need to do some. It is advantageous to the way that they do business. And we put it that way. They don’t need to do it. But because of the way that they do business, they set aside rooms for CUI or they set aside entire sections of a facility for CUI.
And that’s where everything gets done. Same thing with your manufacturing floor, with other areas. You really need to be thoughtful about how you are handling those visitors and making sure that they’re in there. Again, maintenance staff, all sorts of people. You’re cleaning crew. To Scott’s point before, there are lots of people who are not really authorized to be in that environment on a regular basis, but who do need access to it for various reasons.
But they are not what are called authorized holders for that CUI. So, therefore they you have to make sure that they don’t get access to it. And, you know, I think that you see some organizations that, you know, that, you know, feel that, gee, I bought Microsoft GCC High or I’ve got virtual or PreVeil. Yeah, I’m pretty much covered.
And don’t give as much diligence or consideration to the non-technical requirements. And, you know, if you read the title of NIST 800-171, it’s about protecting controlled unclassified information (CUI) in nonfederal organizations, which is people and places and systems. It’s not just the systems part of it. You’re kind of moving on, you know, maybe back a little bit to the to the technical side, you know, encryption, you know, is something that is particularly easy for companies to get wrong or, or conversely, it’s hard for companies to get right.
You know, somebody else who is the scripts guy that needs to validate all this stuff? You know what? What are some of the common mistakes that, you know, Scott, that you see with implementing encryption and, and just kind of understanding what encryption is and what are exceptions is that may be allowed. Yeah. FIPS, we all love it.
Right? It’s fantastic. It never pauses anything to break. Everything goes smoothly and all applications are always using it consistently. For those who don’t know, that’s definitely a joke, right? It’s been the bane of many people’s existence for many years. Yet we have to do that to a certain degree. So, this goes back to my broken record on scoping and identifying your assets.
CUI must be protected with FIPS 140-2 validated encryption. That’s clear, right? In the making of CMMC and the assessment guys, like they have been abundantly clear. CUI must be protected with FIPS validate encryption. What if the assets are not touching CUI? Right? What if I have an SPA or a specialized asset?
Well, now you don’t have to use FIPS. You can, nothing wrong with it. That’s great. But if you’ve got an asset that is not a CUI asset, it’s not going to store, process or transmit CUI. You don’t have to use FIPS. So, that becomes really important because that can save you from having to invest or migrate to new technologies in order to meet that FIPS requirement.
So going back right, identifying those assets, identifying your CUI flow. And then you can determine where you have to have FIPS. If you have FIPS be prepared to prove it right. Say what you do. Do what you say I say that this is protective of the FIPS encryption. How do I prove it right? Certificate numbers, proof of encryption,
be prepared to show it as you’re walking into your assessment. And you know I’m sorry. Go ahead. There’s a there’s a lot of confusion around FIPS. I agree with everything Scott said. One of the biggest is to understand that it’s the encryption module that you need to make sure is validated. And, you’ll see people talking about how entire devices have to be and all this other stuff.
At the end of the day, the requirement in 800-171 says that it’s a FIPS validated encryption module. And so, there are there are some shortcuts that you can take that actually simplifies things. There’s also this idea of what are called enduring exceptions. In 32 CFR 170, the CMMC Program Rule that allows you there’s a recognition that, FIPS validation takes a ridiculously long time.
It’s like a year and a half process. And technology changes way faster than that. So there’s this idea of an enduring encryption, enduring exception that once you have, you’re working with a FIPS validated encryption module. It can go out of compliance. We’d rather see you patch the encryption module, make sure that you’re staying up to date, not having a new vulnerabilities in your system, and you’re just tracking the fact that, hey, this is actually out of compliance, but it’s kind of got an asterisk next to it because we’re actually doing the right thing and making sure that we’re properly patched.
But it’s fundamentally Scott’s absolutely right. Like the FIPS program because it takes so long and because there are so many subtleties in the language and everything else. It can it is a real pain for most people. And, there’s also, I think, a configuration issue that needs to be considered. There are some devices, some services, that have been FIPS validated but aren’t necessarily required to operate in FIPS mode.
And so when the when the environment is set up, certainly FIPS validated encryption needs to be enabled. Either in those services or in those devices. And, you know, we’ve seen sometimes people just kind of say, well, I bought the device and it’s FIPS validated. You actually need to turn it on sometimes. And we’ve seen, you know, we’ve seen that that missed, we move on.
You talk about incident response and within the incident response, family, that there are requirements for incident response plan testing. You know, things like incident response tabletop exercises. I kind of see them like the fire drills we participated in when we were in school. You know, the intent is to rehearse, you know, so that in the event of an actual fire or an actual incident, you know, people know exactly what to do.
Now, Jim, where are people falling short here? And how do they avoid the common mistakes you’re seeing with respect to response planning? And response plan testing. So the requirement is that the plan has to be tested. We’re seeing some vendors who are saying, well, we handle it’s our system that you’re coming into, so therefore you can simply inherit from us all of the testing that we’re doing, we run tests on an annual basis.
So therefore you’re good. And that is actually not true. So the requirement says that you have to be involved in that incident response plan. And in that incident test. Otherwise what’s the point? Fundamentally, the idea of an incident response plan is that now everybody that’s involved in an incident and your end users are the people that are typically you’re the ones that are triggering these incidents.
Everybody that’s involved in that incident knows what to do. They’ve been trained in how to how to deal with it. Again, you can’t just the service provider can’t do all of that for you. Your teams have to be involved. And there’s a whole host of things that that need to play out as part of that process.
There are notifications that have to happen. There are other things that, again, if you’re not testing this properly, you just you’re going to create lots of issues for yourself, not just from a CMMC certification perspective, but from a true compliance perspective. There are requirements in DFARS 7012 that you have to alert DoD whenever there’s, an incident and all of these other things.
And if you don’t know how to do that, if you’re not testing it, making sure you have the right the keys that are necessary to, to, sign into the systems to to issue that notification and all this other stuff. When the inevitable breach happens or incident happens, you’re going to be really sorry. Yeah, okay. I know we’ve got three other things we wanted to touch on briefly.
So let me try to get to them before you, try to answer some questions. You know, alternate work sites. You know, many people are working from satellite offices or other company controlled locations, and still others are working from remote sites like home offices. You know, if those individuals are handling CUI, well then, as we’ve described before, they are in scope, you know, the companies that you’re working with understand how NIST 800-171 controls apply to alternate work sites.
And, you know, what do we see people making some mistakes here? All over the place. Right? The alternative work sites become difficult because they’re not organizationally owned. So it’s really hard to tell your employees, you need to have this firewall. You need to have a certain network configuration, or certain network protections. That becomes a really difficult thing.
It’s completely impractical. And, NIST was aware of that. And that’s where they came into alternative work sites. And they said, look, we understand that people may not always be sitting inside of their office working. So how do you protect them? A lot of this is going to be policy based, right? We talked I talked before about your assessment objective verbs.
And you’ll notice for 3106 alternative workplaces that there the assessment objectives are primarily non-technical. And you’ll still need to be able to show how you control CUI at those. So keep in mind I go back to printing. If your folks are able to print, how do you safeguard the print job so that when, let’s say your child runs into your room, grabs a piece of paper to make a paper airplane, is playing out with their friends on the street?
That piece of paper doesn’t say CUI across the top of it. Those things can happen. So be prepared to have a plan about you. When people can print, how do they handle CUI? If they are allowed to handle CUI at an alternative workspace. Maybe it all exists in the cloud and you’ve prevented downloading and printing, and so you’ve been able to control it that way.
But document that you have and have a plan to explain how your CUI is protected in those locations. And, and we wanted to talk a little bit about background checks. So the personal security domain 3.9.1 requires organizations to conduct background screening before granting any individual access to systems that store or process CUI. This seems like a pretty simple requirement, but then many organizations seem to be getting this wrong.
In your experience. Why is that, Scott? And again, what is it that they can do here? It’s kind of subjective, right? Like what constitutes a background check. And there’s a rabbit hole to go down there about who needs to have it, what it is. What I would say is don’t overthink this. Most organizations are likely doing some sort of criminal history investigation.
Maybe it’s an education verification. Something along those lines when they’re trying to hire that will likely suffice for what you need. Now, obviously, if you have, some organizations will also have folks that are going for a clearance and there’s a separate process there. That’s great. But keep in mind, as you’re documenting what your onboarding process is, define what’s required.
You can do additional. So if your minimum requirement is running criminal history, national, local, state, and an education verification, great. Do those things and be prepared to show it. Assessors will tell you you can obfuscate any PII. You don’t care about what the person’s social is. They don’t care about what their address is or anything like that.
Right? They just want to know that you’re actually performing your background checks. So be prepared. You know, maybe do a printout, screengrab, obfuscate any protected information, but be ready to prove that you’re actually doing this background checks and that they align with what you said you’re going to do. Yeah, yeah. Make it make sense. So again one last question.
And this is really for both of you. And it involves what I believe can be the biggest mistake a company can make. You know, I’ve seen companies delegate responsibility for their CMMC compliance programs. Sometimes I’ve seen it delegated to IT. I’ve even seen it in one case, delegated to accounting. You know, where does the responsibility for a company CMMC program belong? And,
Jim you want to start. Yeah, it’s really senior management. Usually it’s either the CEO or a director report of the CEO. It’s somebody there. It’s not three levels down, five levels down on the org chart. This is a fundamental business issue. This is the kind of thing that’s going to keep your business from being able to win more business.
And so if you don’t have the responsibility and, somebody who has decision making authority, actually running this, you’re not going to win. Even we see tension between the CIO, the chief information officer, whose job it is to keep the systems up and running and make sure that this, that the, compute systems are available for clients and all of that good stuff, when you get security involved, security slows all of those things down.
It creates hurdles, it makes things harder, and that’s intentional. That’s how we keep the bad guys out. But, so the when somebody’s job is to make it as easy as possible to buy from your company, have resources that are always available, well, security is going to get in the way of that. And now you have competing incentives.
So you need to make sure that you’re elevating that, security discussion to a level where those competing, priorities are articulated to the CEO or to somebody else who has decision making authority and that you’re pushing through. Because otherwise, if you don’t do this, it’s going to fail. And fundamentally, you have this requirement to do a self-assessment and then affirmation on an annual basis of continued compliance.
And again, that has to be a senior official. There’s no description yet from DoD of exactly what that means. But senior generally is going to mean, CEO somebody one of their direct reports, and that’s about as far down as the food chain is, they’re probably going to accept. Yeah. Scott, anything to add there?
Yeah, great summary. Right? And getting them involved early. You’re explaining the existential risk that comes with failing an assessment of, hey, 70% of our business is done on DoD contracts which have CUI. We don’t do this, we’re losing 70% of our revenue becomes a really good starting point. Get their buy-in early because you will need it along the way.
When you need to flex a little political capital to institute new policies, plans, procedures. To getting them involved early and explaining the impact of the organization, not just from a security standpoint, but from a business standpoint is imperative. And I think organizations need to, you know, recognize this isn’t about compliance. CMMC isn’t a checkbox exercise. It’s about ensuring that they can meet their obligation to secure the sensitive information with which they’re entrusted by the government, by their customers, and the sensitive information that, you know, that that they have created in a security culture.
Thinking security first really does need to come from the top down. It almost needs to become again, part of the religion, part of the culture, of a company, for CMMC to really achieve what it’s intended, you know, to achieve. So, yeah, just one last thing there. If the carrot doesn’t work, the DoD also has the stick, right?
False Claims Act is always there. So if you get through your CMMC assessment a year later, you have to do that annual attestation that you was talking about, right. Falsifying that attestation and saying, oh yeah, we’re doing everything we said we were doing a year ago when it wasn’t actually the truth can leave them open to significant penalties.
And that affirming official you referred to could end up becoming an orange jumpsuit model if they’re, if they’re not careful. So. Right, right. So, hey, Jim Scott, thank you for, I think what’s been a really informative and I think an important discussion and I think as we’ve indicated, you know, CMMC is a case of if you fail to plan, that’s planning to fail.
And, you know, even when organizations have had good plans in place, there are some common mistakes. And one piece of advice is said before when addressing the requirements. If you don’t know if you’re not sure, don’t guess. If you don’t have the compliance expertise, the technical expertise, the security expertise in-house. Find a capable and qualified partner who can help and make sure that you budget sufficient time.
There’s a lot at stake for your business. But there’s also a lot of stake for our national security. Karen, let me throw this back to you, and we can try to get to some questions. Great. Thank you guys. Really appreciate it. That was some fabulous information. So, you know, as you all heard, in addition to being experts in their fields, and really adept at all of this information, they all can talk and chew gum at the same walk and chew gum at the same time, because there were a number of questions that, they got to in the, in the, chat.
So, hopefully all of our attendees have had a chance to kind of keep an eye on that and see those questions like I’ve answered. There are a couple more. One of them is I it’s a good one. It’s really about supply chain. And so the question is about, you know, how CMMC extends to suppliers.
For example, if the person you know needs CMMC documentation from a supplier, for instance, a POA&M, and that supplier won’t provide it, what’s the recourse for that? Are there penalties? Are you just left with, I guess we can’t do business anymore. You really want to be thoughtful about what you’re asking for? So asking for POA&M is asking for problems.
There’s it’s one thing to ask for their score, their supplier performance risk score, or to ask for at a high level, which, which requirements are not met? But as soon as you start getting into even which requirements aren’t met, there’s, you’re getting a lot of very sensitive information. You’re going to have to safeguard it.
I have advised people, my clients that don’t give the client that if they don’t give the prime contractor that information, ask them for their score, ask them for their, system security plan. Because before I give you my sensitive information, I can make sure that I’m doing my corresponding diligence to. And usually when you do that and I say a little bit tongue in cheek, but usually when you start pushing back like that, because I know enough to know that this is sensitive and I shouldn’t just give it to you.
Oftentimes the primes will back off. There is really no reason for a prime contractor or mid-tier for any of that to have any of that kind of information about their subcontractors, other than the really high-level metadata type of do you have, a CMMC certification? Great. Can I see a copy of that certification? Do you have a score?
Can you show me a screen capture from SPRS of that score? Great. But again, as you start getting down into technical implementations or POA&M or other details, you really shouldn’t be asking for it. Now you notice I’ve said should every time, that there’s nothing that says that you can’t ask for that. And to the point in the chat that some in the question, the person said, do I just basically say, I’m not going to work with you anymore?
The answer is yes. Right? If you can’t get the answers that you need to get you to a level of confidence that you feel you need, then yeah, it’s time to move on. Find another supplier. Yeah. And DFARS 7012 and in the 32 CFR part 170 and emphasize as know the requirement to flow down requirements to anybody with whom CUI is exchanged and the DFARS specifically states that you are responsible for ensuring those you exchange CUI with are capable of receiving it and, protecting it.
So that’s, you know, that obligation is one that organized actions need to be very mindful of, I’ll just share on that one. One thing that I’ve seen for our customers when they’re asked by their primes is they’ll ask, do you have, have you implemented a POA&M? And that becomes the catch all of do you have it and are you running with it, or did you just kind of run it that, you know, write it down and it’s sitting off to the side growing dust?
I haven’t seen many asking for the POA&M itself. Just want to know that it’s a it exists and that it’s being followed. And so that there’s a note in the chat. Sorry, Karen, I keep cutting people off, but, there’s a follow up in the chat that says that their MSP or MSSP and honestly, if they’re if the MSP is not willing to give you POA&Ms about the environment that they are managing for you, runaway. Call C3. Thank you for saying that Jim.
I saw the follow up as well. Yeah, yeah yeah. Scott the that yeah it probably be a signal that they’re probably not prepared for CMMC. I’m assuming that they’re not certified, which is why they have a POA&M. And now that goes back to the they may be a risk to your certification is that they will the assessors will ask, about how they’re safeguarding your information.
So, if they’re not prepared to share a POA&M, they are probably not assessment ready. And if you are at that point, it might be time to make some tough decisions. If you want, call us. We will, we do. We give away a lot of time. So we will sit with your MSP. We will sit with you and talk through what to expect during an assessment.
Again, I’m a lead assessor. I’m a part owner in a C3PAO like we will have those conversations with both sides and hopefully that may twist their arm enough to push them. But then yeah, it’s time to move on. Yeah. And Jim’s correct. He, he does a lot of work. In this area, he has provided even, you know, training to some of our staff members as well.
And, you know, on his time and everything. So I just second the fact that Jim’s a terrific, terrific resource on some of these questions. For sure. Let’s see, where are we at? We are at 2:02. I think maybe there was one question we didn’t get to. Do you all have a couple of minutes or should we try to answer that later?
I need to actually jump for another webinar that I’m doing in minutes. So, but I’d be happy to. I’ve been trying to answer some of the questions. Happy to try to do that between the three of us. We’ll get back to everybody with the questions that weren’t answered. That’s great. We will definitely do that. So, before everyone heads out, just wanted to give you all, everyone’s contact information one more time.
I will send all of this information, in the email that’s going out, as I mentioned by COB today. Also, be looking for the next webinar that we’re going to be doing. And I think everyone touched on this towards the end, Maintaining Your CMMC Compliance After the Assessment. Right? The assessment is the thing. But there are, you know, the necessity of maintaining the thing.
Well after. So, thank you again, everyone, for, your time today. All the preparation, we really appreciate it. It was just tremendous information that you all shared. And we can’t thank you enough. So without further ado, we’ll wrap things up. Thank you to our audience members. And be on the lookout for, that email which will be coming for me, with today’s webinar.
So all the best. Goodbye, everyone. Great. Thank you everyone. Thanks, everyone