Event

September 29, 2025

The Final Rule Is Here: What the 48 CFR CMMC Rule Means for the Defense Industrial Base

Overview

Join C3 Integrated Solutions’ authorities—Bill Wootton, Scott Whitehouse, and Jon Bierer—for a practical, forward-looking discussion on what the final rule means for your organization and how to prepare.

Here’s what you will learn:

  • What’s Changed (and What Hasn’t): A clear breakdown of the updates in the final rule versus earlier drafts.
  • Timeline & Milestones: Key dates and the phased rollout of enforcement so you know what’s coming and when.
  • Implications for the DIB: How these changes impact contractors and subcontractors across the defense supply chain.
  • Actionable Next Steps: Practical guidance you can apply now to prepare your organization for compliance.

Transcript:

Good afternoon, everybody. Hello. Welcome to our webinar. “The Final Rule is Here: What the 48 CFR CMMC Rule Means for the DIB. My name is Karen Vasquez. I’m the marketing director at C3 Integrated Solutions and your host for today’s webinar. We’re joined today by three members of our C3 team, each experts on CMMC. Bill Wootton is a co-founder of C3 and the current Chief Revenue Officer.

Jon Bierer is C3’s Compliance Services Manager and he works with Scott Whitehouse, who is our VP of Compliance. All our frequent speakers on all things CMMC. Before we get started, I’ll just cover a few housekeeping items very briefly. First we’ll be recording the webinar and distributing it to all of our registrants by the close of business today, so be sure to look for that in your email.

An email will be coming from me, kvasquez@c3isit.com. So if you don’t get it every once in a while it winds up in junk. So double check there. Next, while we’ve got a lot to cover in today’s one hour session, we definitely want to hear from our audience members. So if you have a question, please enter it into the questions module.

You’ll see that on the right side of your screen. And we’ll do our best to get to everyone’s question before the hour is up. If we don’t, we’ll do our best to answer those via email following the conclusion. And then lastly, included in that email that I’m sending, will be a registration link for our next webinar.

We have that one scheduled for October 7th. Bill Wootton will be leading that one, and it will be a deep dive into C3’s CMMC solutions suite. So be sure to look for that email in your inbox today. I think that’s about it. So, why don’t we get started? Bill, I’m going to turn things over to you.

You can kick us off. Sounds great. Thanks, Karen. Thanks, everyone, for joining today. We’ve got a packed schedule. We’ve got a long list of things to kind of cover. So, want to make sure that we jump right into things. So let’s get started. As we kind of lead into CMMC, the CFR 48 roll is here.

Jon, kick it off. Help me understand what the CFR 48 is and how does it fit into the overall CMMC program?

Sure. So CFR 32, as, most of our audience may know, went to effect last December. It basically creates the foundation for CMMC. And then CFR 48 is the, final step that makes it real, right? So it puts the requirements directly into contracts. Basically implements the program. Fantastic. So basically, things are real now.

Things are actually happening. Scott, put that in the context in terms of like this is obviously a big milestone, but in the overall journey within the CMMC program. Yeah. You know, over the last several years, CMMC’s been one of the things is full of fits and starts. You’ll hear ramp up and then it hits a road bump and then it ramps up and it hits a speed bump again.

It’s now official. Right? What started years ago underneath Donald Trump’s first administration was endorsed by the Biden administration is now coming live again underneath Trump’s administration. So there’s been a lot of questions about with a changing administration and different perspectives, would there be a change to CMMC? It’s not. It’s here. It’s there. 48 CFR is what puts it into contracts.

So we went from knowing what we need to do to now the Department of Defense has the ability to put that into live, everyday, contracts. It’s great to see as much as we see things pivot back and forth in today’s world. That commitment to protecting our national security information has stayed consistent across the multiple administrations.

You know, when we looked at CFR for 32, that’s really where the bulk of the program is. And we kind of expected 48 to be somewhat of an administrative last step. But I think as we went through it, we found that there were some things that were interesting, some things that were clarified on there. Let’s talk a little bit about what’s changed in CMMC and maybe what didn’t change in terms of CFR 48 coming out.

One of the items, it was a little bit of a new term was, a CMMC UID. What is that? And can you, Jon, can you explain that? Yeah, CMMC UID is an unique identifier. It’s like, a license plate on your vehicle. You get your, your vehicle registered. It’s now authorized to operate on the roadway.

Think of that with your system, and CMMC. It’s the license plate for that system. And, once you get, assessed and certified, it identifies the system that’s now authorized to, store and process CUI. Sounds great. And if contractors using multiple systems, how does it how does that work? Yeah. So, systems is a good way to think about it.

Unique environments, unique systems, need, unique identifiers.

Cool. Awesome. And then, you know, as you read through the rule, there was a connection between kind of the individual contractors being awarded and individual contractor IT systems. Scott, how did they draw the connection between the two of those? Yeah. So the idea being is as Jon was just kind of alluding to, if you have system A and it has UID A, then that system has to be specified within the contract.

So, if you are an organization that manages multiple systems, it makes it harder to say, I’m going to apply for a contract or bid on a contract for system A and then deliver off of system B. Government wants to know what systems are being used in order to deliver on a contract, to ensure that they have the proper cybersecurity and in this case, CMMC level, to fulfill the contractual needs.

So, I think key there is you also have to make sure you’re including all of the systems that are going to store, process or transmit data on behalf of that contract. Right? Yeah, that’s exactly it. And, it’s kind of interesting because in the Q&A section in the 48 CFR, that was published, the DoD specified that, when a proposal is submitted, the government’s got a three step process that accumulates a total of 15 minutes of time to validate.

So, they’re not doing a lot of digging. They’re looking to see alright I entered in UID one two, three, four. Is that CMMC Certified yes or no? It’s just a “boolean check.” It’s not a we will be or we’re getting close. It’s is it in eMASS or is it not? I think that’s the important piece is that you’re in or you’re out.

There’s no gray area. There’s no nothing like that. So that’s a really important part there. As we one of the other things that was discussed a little bit was commercial work in the context of CMMC. Jon, can you comment on that? Yeah. So, commercial work has long been the question, for ten years now.

How does that how does that play into this? I would say that if, you’re touching CUI or FCI, the commercial services or products could potentially be in scope. The only exception would be COTS, commercial off the shelf products, are completely out of scope. Yeah, that was an interesting clarification there. And then was also a little bit of discussion around, reporting certain things within 72 hours.

How did that land on the final rule? So, good news. No changes there. So the same reporting requirements you’ve had for many years of 72 hours, as defined in DFARS 7012 remain the same. Right. So there’s a bunch of rumors. Are we going to have to do different filing requirements, different reporting requirements in this that the other they all stay the same.

So little bit of a win there. We get to remain and continue to do what we’ve all been used to for quite a while. It’s good news. A little less paperwork for a change on there. It was interesting. Is reading through the rule that they went through great lengths to define the word current. And, you know, from a practical standpoint, you know, what is what is current mean.

And at least in the context of the CMMC rule of itself. So, it’s actually something, touched on in the last webinar. So you want to, to maintain a current environment. You want to avoid drift essentially. It’s a snapshot every day. Is your environment compliant as of right now?

And are you maintaining that day-to-day? Drift, for those that didn’t catch the last webinar. It can happen when you, you add users, subtract users, add functionality, add privilege, add hardware, add software, change your network diagram, but you’re not documenting any of it. Right? So, your practice no longer aligns with your documentation and you’re drifting from what you’ve stated is the case.

To keep current, you need to make sure that your practices and your documentation align and that you maintain compliance every day going forward so that you can stay current. It’s an interesting point there because a lot of folks just think of IT or an IT system as a static thing where it is in a lot of ways, a living, breathing thing is there’s always a little bit of an adjustment, whether that’s as simple as adding users or making major changes, as you kind of alluded to on there.

Go ahead, Scott. If I could reply to that. When we think about CMMC maturities in the name. Right? And so, one of the things that differentiates this from other compliance standards that are out there is the expectation that it remains mature and remains active. It’s not a point-in-time event. It’s not a hey, we did an assessment let’s high-five, we’ll be back in three years. The expectation is that you’re maintaining that certification. You’re maintaining the processes that you said you were going to follow and that when you go to apply or bid on a contract and perform on a contract, you’re continuing to do the things you said you were doing. Yeah. Makes a ton of sense. And, those annual affirmations we’ll get to in a minute

are also another point of stating the fact that I’m maintaining that compliant environment and a compliant posture throughout that three year life cycle. So, this sort of sounds like, for the most part, 48, you know, they are some smoothing out some edges that didn’t necessarily, you know, any nothing major shifted. Everything’s still on schedule and on course with all that.

Would you guys agree with that? Yeah, absolutely. You know, it was one of those things of what are they going to do next? Right? We had 32 CFR now part 170. A lot of information in there. Some of it we expected, some of it we knew was going to happen. A couple fun little, little bumps along the way there.

And then 48 was kind of sitting out there and we were waiting and waiting and waiting. And, you know, one of the big questions being out there of like, when this comes into contracts, how soon is it coming to a contract near you? And, one of the nice things is they reiterated the DoD’s timeline of a phased rollout.

So, not every new solicitation will have a CMMC requirement day one. Yeah. Good stuff, good stuff. You know, some of the principles, it’s kind of stayed the same that we were looking for. Like, obviously, you know, you guys want to comment on that a little bit. You know, some of the foundational pieces of CMMC seem to stay pretty solid.

Yeah. You know, the foundation being NIST 800-171 Revision 2 remains the same, which is good. So, all the contractors that are out there that have been implementing or preparing to implement 800-171 Rev. 2 there’s no change there. Right? So, that’s fantastic. And for the organizations who have already gone through the CMMC certification, you’re still good.

You don’t have to change anything. You’re now prepared. You have your certificate, you’ve got your high fives. And you’re ready. Not a whole lot of changes. Some definition changes. You know, they’re pretty in the weeds, right? They define current, which is great, but for day-to-day life isn’t going to be a big shift. Yeah.

Good stuff, good stuff. Jon, one of the unique things about CMMC is it’s essentially a pass-fail. There’s, you know, it’s you’re either good or you’re not. But there’s also this little bit of a conditional status that in certain scenarios might apply. Can you talk a little bit about what a conditional status is relative to CMMC? Yeah.

There are potentially some scenarios during an assessment where, you’re, you know, you’re practicing the thing that you say you’re practicing. But maybe you didn’t capture it down very clearly in your documentation. Or, you know, just as an example, but the conditional status is, a temporary bridge, right? Where you get up to 180 days, to make a quick correction or fix, so that you’ve got a real path to certification.

And it doesn’t become, an outright failure or roadblock to your future there with CMMC. I actually like to throw that back over to Scott. He’s probably got some unique perspectives here as well. Yeah. There’s a couple key things to those. All of your all of your controls are weighted, right? 1, 3, or 5 point controls.

And your conditional status can only have not meant items that are one point control. Right? So, the government is using those points in order to weight risk. And the greater the risk, the higher the points. And they’re kind of saying, look, if this is a lower risk item, meaning a one point control, then you can have a conditional status.

You’re doing most what you need to do. You got a thing or two that you need to clean up. However, if you have a three point or a five point control that is missed, or even worse, you have an incomplete SSP, that’s a full-stop altogether. None of those will allow you to have a conditional status. That conditional status is also only good for 180 days.

So you’re not able to, indefinitely extend it. You’re limited to those 180 days. It’s a cleanup period. It’s not the full high-fives of “your certified.” So, if you end up in that situation where you have the conditional. Yeah. Don’t wait, get to work on it, get your things resolved, and then you go back to your C3PAO to get a Delta.

And they’re going to they’re going to look back at those items that you missed and evaluate them. They have the right to go back and audit other things. So if there’s something else that it was a 3 or 5 that the market met, but they maybe were, not super confident you were doing it, they could go back and ask it.

So if, you know, you scrape by a couple by the skin of your teeth, make sure you’ve got your ducks in a row because they, they have the right to go back and ask you any one of those other 110 controls. So, if I say maybe get the hook up monitoring it in my environment, I can’t count on a POA&M to save me?

And, you know, skate by for a couple months. Negative. But that would not be what we refer to as a successful strategy. No, not at all. Not at all. And you know that that 180 day window that’s played out through the construct of a POA&M right?

Yeah. And, so once, you know, let’s say you wound up with a conditional award, you have your POA&M, you’re on your track for 180 days. If you clean up the stuff you have there. Can you still actually win something? Can you still move forward and get contracts with the government? You know, obviously once CMMC is fully implemented and all of that.

So. Jon can you grab that or. Yeah. So if you’re not certified in the in the contract to require certification, you’re not going to win that contract. You’ve got to have that at time of award going forward. Yeah. And if they’re on a POA&M and they have a conditional status. Is there any window for them to continue to receive awards?

But they still need to prove that they’ve cleaned everything up.

You know, I’m not sure, actually, it’s a good question. All right. We’ll take that for action. Yeah. If you’re on that, conditional status, you can still get the award. But this goes back to the condition of current. Right? So, while you’re on that award, you have to close those things out. Because you are required annually, to affirm your status.

So, if you have that 180 days and you get your contract award at day 50 out of 180. Great. But no, you still have to get those things, cleaned up. You cannot operate indefinitely on the POA&M and on the conditional status. And that’s the key point, I guess, is it’s not a free-pass to be able to go continue doing business.

So, you do have to close out, there’s a structure there. Scott, talk a little more about that annual affirmation on CMMC. You know, what is you know, what is that about and what are the risks that are kind of tied to that as well for a contractor? Yeah. So this is huge, right? Because the DoD, believe it or not, took some cost saving measures into account here.

Right? So, good news is, as folks in the chat are probably ready to throw pencils at me for saying that, we don’t have to get assessed annually. Right? So, the actual assessment by C3PAO is every three years. But, the DoD is also aware that if they only require an assessment every three years, people are probably only going to operate their program every three years.

And so, the way to get around that is to require an annual affirmation. This is having the quote affirming official, which has to be a senior official within the organization if they don’t specify an exact title. But it has to be somebody who has responsibility over the cybersecurity program, goes in and affirms that they’re still performing their CMMC program, their cybersecurity program, as stated, or, within their SSP.

And, it’s kind of a big deal because the DoD has sitting in their back pocket the False Claims Act. So organizations that may say, all right, I’m going to get certified in year one, year two and year three, I’m going to do some hand-waving, and then I’ll prepare for my assessment in year four. If you walk in to the in year four and you’re no longer that C3PAO finds, you’re no longer to 110, you’re at a five.

Well, then there’s going to be questions about oh, wait a minute, you just told me you’re at a 110 the last two years. What happened? Right? And so, it’s really important that, when you do these affirmations that you have a degree of confidence if the DoD will hold organizations accountable, if they turn out to be grossly inaccurate.

Appreciate that. And, you know, and we talked a minute ago about, you know, systems are living, breathing things. Businesses change and evolve. You know, different things either expand or contract within the business and therefore IT systems. What would trigger like a refresh during the overall performance or during that three year cycle? Yeah. So they called a material change to the system.

And this is what’s fun because what constitutes a material change. Right? And that is a, you know, the million dollar question. Right? One can easily say if you have a service provider that’s doing a large percentage of your services and change service providers and likely your services, and the actions that are being performed behind the scenes are going to change. That becomes easy. If you’re to move from, you know, a Google Cloud to a Microsoft cloud, that’s a material system change.

 

Well, what about if you say I’m adding five new servers? Maybe, right? Were servers in your scope originally? Maybe, maybe not. Right? And so that’s where you need to take a little bit of a risk based, approach there and identify, how your system was originally documented. And if the additions to your system fall within the original plan.

So, for example, adding or removing users does not constitute a change, right? That is not a material system change. And so, you have to be careful there. Because there are situations where you will have a material system change. Let’s say you have a new CUI flow that is materially different, right? This isn’t just, I added some new users.

I have a new partner. This is I’m doing new mechanisms, new enforcements, new monitoring, and nothing that was originally assessed against at all is still plays. Yeah, that might be a good time to go do a reassessment. The key on this is this is not going to be a delta, right. The C3PAO will not say okay, the only control the change is 313 or go, no, no, no, we’re doing all 110.

So, if you’re in that situation where you have a material scope change and you’re going to sit back for your assessment, this will be a full assessment. So, make sure you’re prepared and ready. It’s a great point. And it’s like one of the things we think about and we get talked to a lot on the sell-side is M&A activity.

You know, if you’re just buying an organization and absorbing those users, probably not necessarily a big change. But if you’re, purchasing a company and it comes with four more manufacturing shops and a whole ERP system and a different line of business, and that would be a whole different kind of consideration there, you know? Yeah, that’s exactly right.

Because if you’re if you’re buying an organization and that organization is going to continue to operate as-is. Right? We go back to the top of the conversation. We talk about the CMMC UIDs. Right? So, if your case codes and your UIDs are not changing and you have the same processes, the same technologies, maybe even the same personnel doing the same things that were assessed.

That doesn’t constitute a material change to system scope. However, if you were to take all those users and processes and move them into a completely different environment, well, now that’s a that is going to be a different UID. So, now you’ve got some reporting elements that you need to do, and you need to ensure that that UID that folks have moved into is CMMC certified to the minimal level of the contract.

Okay. And they put some mechanisms in there and some conversation in the role about how you go ahead and update that and at what point you do, if I remember right. So, it was really interesting the way they thought through some of that. But, I think to your point, that judgment of like those gray areas, have I done enough that I now need to kind of trigger that reassessment will be interesting to see how the industry evolves and kind of starts to figure out what’s the right trigger points for that.

Yeah, yeah, it’ll be fun to see for sure. Because there’s a lot of, consternation in the marketplace about that and justifiably so. You know, the it’s easy to point out the left or right boundaries. It’s like you said that that gray area that’s that gets spicy. 100%, 100%. So let’s talk a little bit about timelines.

So, like the big thing that we were waiting for a CFR 48 was when’s the starting gun going to be one? How are we going to roll this out? When will we actually start seeing CMMC in contracts? Good news. We have 42 days. So, CMMC will be coming to a contract near you as soon as 42 days. Also known as November 10th.

So, like I said, that’s not every contract. So if you’re applying on a contract or you’re bidding on a contract and it’s November 11th, you know it, it’s likely not going to have CMMC in it. Okay? There’s a three year phase-in process through year one is going to be a lighter weight. And then, as we move into year two and three, that’s what we’re seeing more. I’m going to throw in a little word of caution though.

While the DoD is going to has their own timeline as to when they’re going to require CMMC in contracts, what we also see is primes pushing the CMMC readiness sooner than DoD. They’re doing their own risk evaluation of their supply chain and going back and saying, all right, contractor, you are working on this contract. We think that this is going to, we know that this has CUI and we think it’s going to have a CMMC requirement.

Provide me your CMMC status. Yeah. And, for those reasons timelines will accelerate for a lot of contractors that act as subs. So, if you’re in that situation and you are a subcontractor, be prepared. Right? The last thing you want to have happen is somebody else is have a prime shift to another provider because they’ve been through that process.

Yeah. So, let’s scroll into that a little bit. You know there is that three year phase-in period. What are we going to see in phase one? When this phase two kick in? That sort of thing? Either Scott or Jon, whichever one of you guys want to jump in on that.

Yeah. So, phase one is November 10th, right? Remember, remember the 10th of November? So, I think it’s, what, 5% of contracts? It’s not going to be a whole lot. I don’t I don’t know the dates. I think it’s, what, one year for the phase two and another year for phase three? Right? So, you’ve got time, a little bit, if you’re concerned about, the re-ups on those contracts. But, I would also maybe put an asterisk with that and say you’ve got, if you haven’t started yet, you don’t have as much time as you think.

It takes approximately 6 to 9 months, to go from scratch to compliance. And then you’ve got another six months with your C3PAO. A lot of the C3PAOs, right now, are booked-out six months. So, even if you’re ready, you may not be able to get lined up for a certification assessment, for another six months.

Yeah. And I’ll point out, that’s your absolute best case scenario. Like, if the more complexity in your environment, the more on-prem assets or more you know, complexity around the CUI in your systems, that’s your best case in terms of preparation cycles, you know, with can easily stretch. And we still see industry numbers in the 12 to 18 month range a lot a lot of the time as well.

On there. So you know, and I think C3PAO requirements don’t start to that phase two one year out. Is that right?

Yeah, that’s right. And, we’ll put the asterisk whenever DoD has had some options to be able include a C3PAO requirement in phase one. But, generally speaking, phase one is a self-assessment. There’s so you don’t have to be actually certified. However, as Jon mentioned, that line to be assessed is long and getting longer. Right?

The number of contractors out there that need to be assessed compared to the number of billable assessors is not a great ratio. So, if you know that you’re that used store, process or transmit CUI. You know you’re going to have to be CUI or CMMC Level 2, at a minimum, start making your preparations and get in line today.

Hey, this is not, this is not a good time to wait. Yeah. So, I would also, if I could, just, like, you know, self-attestation or self-assessment. Not quite the same thing. The bars are the same. You’re expected to assess your environment just as a C3PAO would and so you can’t pass off or point fingers, you know, any of that responsibility for, the accuracy.

Right? So, you’re holding all of that responsibility if you do that self-assessment and say that you’re at 110 and you’re good to go. And you didn’t have the help of an outside perspective. If you’re not confident in your ability to perform that yourself, you probably need to reach out, to a third-party for assistance.

So, I want to kind of tap into that a little bit. The way it was described to me by a couple of different folks is if you’re, you know, you should be doing your self-assessment with the same rigor as if you had a third-party assessing organization. You’re just almost just simply saving the money of a third-party coming in.

But that rigor should still be there in the way you evaluate yourself. Is that is that accurate? Absolutely. Awesome. I want to get myself back on track for a second here. One of the things around CMMC is it’s a condition of award and so when we start thinking about these timelines, you know, okay, great. I’m going to see, you know, it is a condition of award a year from now.

But that doesn’t mean we won’t see it in the solicitation beforehand. Right? Yeah, that’s exactly right. You know, it’s a it’s key to note the it’s condition of reward. However, you’ll see it in the solicitation. So, when they say we want, DoD wants to procure X and you’re going to provide X. You’ll know upfront that you need to be CMMC Level 2.

And you have to do that by the date of award. However, when they’re making their evaluations, I go back to that 15 minute check. Contracting officer is not taking time to repeat that evaluation. Right? At the time of the award, they take their 15 minutes and you’re boolean. You’re certified or you’re not.

It’s also key to note that within the process to get certified, there are a lot of opportunities for delays. Right? C3PAO availability, general readiness, preparations, if you’re in that situation where you’re like, I’ve got some things, but I don’t have some things. Start getting your house in order. Right? Because that line is not going to get shorter to get assessed.

Yeah. And I think the other piece I want to point out is, you know, if we’re looking at phase 2 starting in November 10, 2026, government has full discretion to put it, you know, solicitation if the award is going to be after that date. But you may see CMMC in that solicitation in September, May, June, next year, kind of pushing ahead with the anticipation that there will be a, you know, multi-month, you know, bid and review cycle on there.

So, you will start seeing it in solicitations much sooner than that phase impact impacting. Yeah. And you, the other thing I want to note when we say contract award, this isn’t just new contracts. This applies to task orders as well as period of performance. So, if you have a contract where you’re either working on task orders or if you have like a three year contract with two one-year extensions, that that time of extension, there’s a potential for you to have a CMMC requirement.

That’s a good point. It’s a great point, Scott. Awesome. So, let’s talk a little bit about what does this mean. What are the implications for the defense industry or how these changes are going to impact the way kind of contractors are going to kind of live their lives and do their things every day? You know, if you’re a prime contractor out there, how does this change how CFR 48 now impact your perspective on the way you’re looking at your supply chain?

Scott, lead us off. Yeah, so, the key here is to know what contracts you have, when they renew, and if you have any extensions tied to them. That now drives how soon your supply chain needs to be certified. You should be following up with your supply chain. I mentioned earlier ago that how we’re seeing primes coming to their subs saying, hey, where are you in your CMMC readiness, right? Start those conversations now. And unfortunately, if you have subs that are woefully unprepared and you have a contract that’s going to be coming up in the next year, it might be time to start having some discussions. Know, what are your plans? How are you going to do this? When’s you expected readiness date?

All right, start asking those questions now because the last thing you want to happen is have your contract be jeopardized because of a subcontractor who’s unable to perform. Yeah, and we’ve certainly seen some public displays of that. Lockheed Martin in particular, put a blog out at the end of June. It basically called out, we’re going to be pushing our supply chains to be moving faster and evaluating where they are.

Jon, I want to get you back into the conversation here and talk a little bit about kind of that flow down process from a prime contractor into their subs. What’s required, what are prime contractor is supposed to do? Yeah, we’ve seen for years now that they’re pushing out questionnaires and surveys asking for a status update.

It’s no longer sufficient to say that, we will comply. You have to be compliant. If you’re a sub to a prime or a sub to sub. There’s a potential for you to be replaced. The Prime can’t afford to miss out on that contract because one of their subs was not compliant. And, so, you’re potentially, replaceable, right?

So I would say, move fast, reach out, ask questions, get help, and work towards compliance so that you can, you know, remain a part of that team. Absolutely. And, you know, talk a little bit about, will this change the bid or no bid decisions for a, prime contractor is you’re evaluating not only who or what business they’re chasing, but who they go to go to that, bid with.

Well, yeah, I mean, status is still, an eligibility gate. So, if you don’t have a status, then you’re not eligible. So, like I said, you’ve got to, work towards that certification. Having that, you know, quote unquote piece of paper and, you know, being able to wave that around and show the world I am certified and ready to go, could mean the difference and hundreds of thousands of dollars of revenue for you.

Absolutely, no doubt. So, Scott, as a prime contractor is looking at, you know, that evaluation process and kind of acknowledging maybe not everyone’s got I’ve got my certification in place. There’s still a fairly small number. What should they be asking their subs to help them ascertain, are they actually make any investments? Are they on the pathway to get there when they need them to be?

Yeah. So, there’s some standard questions to ask. Right? What is your SPRS score? Do you operate off of a POA&M? What’s your anticipate readiness date? Those are all kind of standards within the industry. However, if you’re in a boat where you have a sub that comes back to you and they’re like, what’s an SPRS score, right? Or, perhaps they come back with a very low number or a timetable that is, maybe, incongruent with what you had hoped or desired.

It’s time to have some conversations. Right? And, this becomes going back to your contractor and or your subcontractor and saying to them, hey, your contract is up in 18 months. Will you be certified by then? Or do we need to find somebody else to perform on this when we bid for renewal? In some cases, you know, some of the especially within the smaller subs, there may just be an awareness issue.

They may not realize that they need to have CMMC in order to get a period of performance extension, or to get task orders or something to that effect. And just having that conversation and bringing their awareness will be enough to help them prioritize CMMC beyond where they are now. Sounds great. You know, obviously contractors have their own approach for doing things to build on their proposals.

I imagine most of them have a template that they would kind of build as part of that readiness. You know, Jon, how should they think about that and which would go into those templates to make sure that they understand upfront what subcontractors are, where they are and what they’re able to provide. Yeah, I would say my recommendation would be to, state the system that you got built out.

If you’ve got one, describe your system, the level, that it meets, describe, the date that you met, that compliance requirement. If you’ve got any conditional items like we talked about earlier, conditional status that you’re working on include that as well. It doesn’t need to be overly complicated. Just, you know, you’re communicating pertinent information.

You know what? What is your system as a compliant? What remains? When were you certified? And just keep it, short and sweet. Sounds great. Awesome. So it’s a little bit. So sorry. I’d like to add to that a little bit. I think, one of the things you hear from subs is, you know, hey, I don’t actually perform with any CUI on this contract.

Do I need to be CMMC Level 2 certified as well? And, it’s a great question. And the answer is no. If you are performing actions on a service and, you are not going to store, process, or transmit CUI or none of your employees store, process, or transmits CUI, you may not have to have CMMC flow down to you.

So, the engagement type between you and your prime will dictate a little bit as to whether or not you have to implement CMMC Level 2. I will say that even if you are not required to do CMMC Level 2, it would be highly recommended to be CMMC Level 1, right? You don’t have to be C3PAO certified for that.

You can do the self-assessment, but you’re likely going to have federal contact information. Right? Somebody is going to tell you what you’re supposed to do. And that’s likely going to include FCI that is covered under CMMC Level 1. So, you know as you’re having these discussions with your with your prime, or if you’re a prime having with your sub, scope it around the content that’s going to be provided or delivered by your sub.

If they’re interacting with CUI, it makes it easy. Right? Prepare for CMMC Level 2 as a minimum. If they don’t then you know, maybe CMMC Level 1 is sufficient. Yeah, it’s a great point. We sometimes forget about level one occasionally. We’re so focused on level two. It’s such a higher bar. And level one is. But pretty much anyone doing any work will more than likely need that level one.

And unfortunately it’s a little bit of a lower standards, a little bit easier to achieve. But you can’t forget about it. You still got to do the work on it. So, I want to pivot now a little bit and talk about, you know, for a practical standpoint, what are those next steps the contractor should be taking?

Kind of start off, Jon, with, you know, when should a contractor be ready for that third-party assessment as opposed to a self-attestation? Is there is there any difference in that? What would you recommend? Yeah. You know, it touches on a couple of things that we’ve talked about already. One is you know, looking at, you know, some sort of deadline, out in the future, when do you want to be able to bid on contracts or, you know, and then working that backwards because you’ve got to also give yourself time for the C3PAO schedule, right?

They’re busy assessing other contractors. So, you’ve got to give yourself six months to a year, as you alluded to, 12 to 18 months total time. Right? On top of that, you want to be I would think you’d want to be an early mover, right? So that, if the primes are looking at suppliers and you can say, hey, I’m already level one, certified or, hey, I’m already in process for level two.

It may, potentially increase your odds for, some teaming arrangements. I think the answer is always as soon as possible. You don’t want to delay, especially if, you know, defense work is a good portion of your revenue. So, I would say start now with the backwards plan. You got to give yourself time to, to get a, get compliant and then get assessed.

It’s certainly a great point. If you know, you have a contract that’s coming up for renewal or for an option year, in the next couple of years, you can start to use that as some of your planning, in addition to what you’re doing for your new business and your new capture strategy on it. Jon, I will stay with you.

One of the one of the things that some of our folks, when we talk to clients and we talk to like to an IT manager or something, is struggling with this conversation around CMMC as a cost center as opposed to something that can deliver an ROI? And how do you have that conversation with executives around what’s the ROI around this whole program and process?

Yeah, I mean, that’s also long been a topic in this conversation. Security should be a line item in the budget. Compliance now needs to be a line item in your budget. The ROI is your ability to compete on contracts, right? If you’re not compliant, if you’re not certified, you’re not playing in the same sandbox as everyone else.

And so, you’re now outside that picture, watching, everyone else have fun. So, the ROI is your ability to state to the government that you can protect their data. And, so now they can feel confident in awarding you work. That’s the ROI. Yeah, it’ll be interesting. You know, today, right now, organizations can differentiate by being ahead of the curve and being an early adopter.

Pretty soon that will shift. And instead of being something unique or advanced, maybe a little ahead of the curve into something you just need to maintain to stay in the game itself and you know it’ll change that posture, but that ROI starts to become the risk of lost business, not just what’s incremental there. Scott, you know, from like proposals, whether it’s today or as CMMC starts kind of coming into play you know, what should contractors be thinking about, what they include in their proposals when they’re responding to a bid? Yeah, so, this takes a little bit of planning. One of the things that you should include in there is your UID for the system that’s going to be used. If you have one UID, you, you have one system.

It’s an easy conversation. When you have multiple systems in multiple UIDs that becomes a little different. And so, you need a mechanism not only to identify which system you’re going to use and which UID, but to track it. If it’s going to be several months into a contract award, you don’t want to try to rely on memory of like, oh, I put in my UID for system A and accidentally deliver on system B, even if it’s still certified.

It’s not the same UID that was implemented. And you’re going to have some heartburn to deal with. So, you plan to identify your systems, plan to identify those UIDs and then have a mechanism to track which ones you’ve applied to, which contracts. Sounds great. And Jon, what’s some of the best practices about keeping current between, you know, various awards or options and certainly in between assessments and stuff?

Well, you know, as part of your, assessment, as part of your 110 controls and requirements, you’ve got to have, a change management and continuous monitoring, process. Right? So, as you have changes that will be implemented over time, naturally. You’ve got to document those properly. So, you want to, stay curious by following the processes that got you certified to begin with.

Right. If you passed your CMMC certification an assessor found your change management process and your continuous monitoring process to be sufficient, you just need to make sure that you follow it, document the changes, keep everything up to date so that you can stay current, stay compliant, and avoid that drift. And when that time comes for that next award or option, you’re not going to, you know, be found, drastically short of the standard.

Make sense? Awesome. As we kind of wrap up, you know, one last question for both of you guys in terms of, you know, what’s the quickest way for contractors to think about, you know, what am I going to be doing in those near term bids? Is there anything else you kind of recommend that they be thinking about or focused on as we kind of move forward, we start to, you know, start to get CMMC implemented.

Yeah. So, I’ll start off and then Jon would love to hear your thoughts as well. Talking with executives and ensuring you have top end organizational support is certainly necessary. There will be costs, there will be things that you need to do differently, and you want to make sure that you have alignment from the top and support from the top to help push those things through.

Put together a timetable, understand when your contracts are going to expire, when you want to be certified. And to Jon’s point a moment ago, work backwards. Have a plan, right? Especially if you’re an organization where, you know, you’ve got a lot of work to do, you don’t want to delay that because there will be bottlenecks in the ecosystem to get to your certification.

I think you stated it. Well, I think the only thing I would add is I’ve been doing this for years, and I’ve never seen an organization, do this successfully without, the support, leadership and direction, from the top down or the leadership has to get behind this. It’s not that they’re in the in the weeds in the day to day.

But if you’re not asking questions or following up or ensuring that this reaches its end state, then you’re just you’re drifting along or floating, you’re not reaching CMMC compliance because there is no motivation. You lose momentum, in that project and it starts to flounder. Right? So, I would say leadership, involvement is going to be key.

It’s so critical we see it even in the sales process with prospects and stuff is, you know, until that organization at the C-level with the C-suite makes an organizational commitment, makes, the recognition and the understanding that, you know, this is not only a worthwhile endeavor. There’s a lot of value in CMMC, but in some ways, it’s also an existential threat to that revenue.

It’s only at that point do we see organizations pivot and become ready to move forward. So, I absolutely agree with you is such a critical component of it. Karen, if you’re still with us, I want to bring you back in and see if you have any questions for us. Yep, I am here. So, yeah, let’s, transition over into the Q&A portion of our webinar.

We’ve got a handful of questions. I think you guys can see them. I’m going to start at the top here. The first question is, was about, is there a negative impact, for a company to have a, failing audit on their record? Have you guys come across kind of the, any of those instances?

Yeah. So it’s a great question. And I suppose the answer is that it depends. Right? If you self-certified last year or for multiple years that you’re out of 110 and you go through an assessment and you get dinged and it gets reported at a 109 and you’re conditional or even, you know, a 105 and conditional, you know, I wouldn’t be too concerned, if you self-reported at a 110 for the last couple of years, you come in at a -50.

I probably contact my attorneys, and that’s bad, bad. Right? So, you know, it’s an inexact science as to where that line is in between. Right? What I would say is, if you go in and fail, get it right quickly, and you get your delta or get reassessed, depending on the particular controls that you failed, and get that corrected, the last thing you want to do is leave it as a fail for extended period of time and say, well, we tried.

We’ll try again next year or something to that effect. And leave that fail there for an extended period of time.

Great. Thanks, Scott. Our next question, is about timing, actually. And, it’s a, you know, we’ve all heard this. There’s been lots of chatter about a level two assessments being the majority requirement that you’ll see in contracts beginning November 10th. With the third-party assessment requirements existing, you know, in only a handful of contracts, is does this jive with, with what you guys are aware of?

You know, what would you say to somebody who’s planning to wait to do a third-party assessment? You know, later in 2026? So, I’ll kind of jump on it. You know, if you keep using Jon’s reference, which was great of, you know, if you plan to be ready a year and a half from now or a year from now, and you start backing out the time available for, you know, scheduling a C3PAO the time it takes to do your documentation, the time it takes to make sure that you’re either doing a remediation or doing the technical deployment of it of a greenfield environment.

You’re already behind. It’s already too late. And it’s not just C3PAOs who are seeing a rush of, business and getting their kind of their schedules filled up. Service providers are as well. There may very well be a time, three, six months from now when you show up and you say, by the way, you do this next week, right?

And the thing is, there’s going to be no, there’s a lag, there’s a backlog. We’ll get to you as soon as we can. And then you’re starting from even a slower standpoint. So, it’s you know, if you haven’t started already, you’re already behind. And then we haven’t even layered in that timeline of not just condition of award, but when you will see CMMC as part of a contract, part of a solicitation.

And if you’re doing that as a group, maybe as a sub to another prime or as a teaming agreement, those timelines get compressed even further there. So, the I can’t stress more than enough that it’s you’re a year late, you need to get up. You need to make some effort to get caught up. Jon, Scott, I’ll let you jump in on that as well.

You know, I couldn’t agree more. You know, DoD likes point back to a three-year rollout period. But, you know, we talked a little bit ago that’s going to be accelerated. Right? We we’re already starting to see it come down from the primes. And understanding that the DoD has the opportunity to add it into task orders as well as extension periods.

You may not have the five year waiting period that you once thought for a contract that started last year or perhaps started earlier this year. So, given the timelines that it takes to get in, get assessed and get through the other side of things and the bottlenecks that we already start to see, it’s you’re better off getting started now, and getting on that, getting on that schedule.

Yeah. Thanks, guys. I know that we’ve covered that in a few other webinars, especially related to, you know, availability of C3PAOs. Right? And being, you know, having to get in line, with them as well. And then as we move further into 2026, that that bottleneck will just start to get bigger and bigger, basically, or smaller and smaller, as it were.

In terms of the bottleneck itself. Yes. That’s okay. Another question about, level one certification. And whether a C3PAO is needed to issue a level one certification and then whether that certificate, that certification is required for an RFP submission. So, I think a little bit in terms of not only, the level one certification process, but then also like, what are the, what at what stage do you need to have that certification, you know, before you’re able to, to bid on a contract or, or submit an RFP?

So, for all of CMMC, it’s required at the time of contract award. So your bids do not require although you will have to specify the UID or the system that you’re using. The actual status is not required until the time of award. So, I hope that helps clarify on the question.

Yeah. And, I think the other part of it is whether or not you need a C3PAO and if you don’t, level one is a self-assessment, self-attestation. But you still need to make those annual affirmations. You know, it’s just like you would for level two. Right, thank you guys for the clarification on that for sure.

Next question is about subcontractors. And a type that’s, a staffing partner. So, contractors that are working on site with the Prime, do they need to be CMMC certified as well? It’s a definite maybe. So, the this is where it kind of depends on how the work is being performed and whose system is being used.

So if, if you’re staffing folks are using your customer’s equipment and your customer’s systems, then you likely don’t have a need to be level two yourself. That would be an asset to that other organization. And it should be listed and documented accordingly. If they’re using your systems in fulfillment of a contract at the customer’s location, then you’re likely need to be CMMC certified.

And, the only other thing I’d probably add to that is looking, making sure you’re really being diligent if you’re going to come to a position of I’m not storing, processing or transmitting CUI data, you’re making that determination organization wide. So, on an individual contract or even most of your contracts, you may not have that, that status or that situation, but you only need one.

So you know, that factors into maybe some of your longer term business decisions or some of the work you may want to pursue over a long period of time. If it will require it. Also, teaming partners, primes have a lot of discretion on what they’re going to require to continue working with you, even though an individual contract or set of contracts may not have that.

So, it’s a it’s a really hard choice for those organizations with that business model of where they want to be and what that investment, in CMMC is going to yield to them. Let me just add real quick to that it’s not the organization getting certified. It’s the system that’s being assessed and certified. So, when you say things like, what level do they need?

They don’t need any level right, at that system. And so who owns that system? That’s the organization that’s responsible for getting that system certified. That’s great point, Jon. So that might that might be a good lead in then to this next question, he said, we’re a hybrid system cloud and on prem right. And so what does that what’s the implication so of that, of those requirements?

So, it depends on how you define your system. If you define your system as being your on prem and your, your cloud environment, then that would be one system scope and one UID. If you are defining it as two separate systems that have an external connection and this is getting way into the weeds, then you may end up having, more than one system scope and more than one UID.

So, it really depends on how you are documenting, presenting and using your system. Usually what I see in this situation is you have one system scope and you’re documenting it as a single system and a single UID. However, there are opportunities to buy for key, environments. But if you, if you go down that route of bifurcating an environment, you’d be very prepared to defend how part of it is out of scope.

Yeah, I was, I was just going to. Yeah. Yeah, yeah. If you’re, if you elect for whatever reason that you want to pursue a strategy where you’re going to say some portions or sections are not within your compliance. So you do need to prove that separation. Right, Scott? Yeah. That’s it’s going to happen in your scoping call. And, you will win or lose

right then. So, you won’t even be in, you know, your phase two or actual assessment. And, you’ll know if you have a go, no go. You know, in that phase one, when you’re doing your scoping call, you’re going to sit down with your assessors. You’re going to say, here’s my system, this is what I have.

This is how it works. This is how my system flows. These are my connections. And this is where a lot of assessments stop. Right? If you talk to C3PAOs who are in the environment and there and, you’re performing assessments. That’s the killer. Right? If you get to that point, you’re like, my SSP is missing significant pieces or I’ve put together a strategy for my environment in scoping, but it doesn’t pass muster. Either it’s undocumented or perhaps the justifications lack merit. The assessor has the ability to call it and stop the assessment there. So, you know, if you’re in that situation, be very prepared. Yeah. And we’ve heard some stories from our friends in the industry who, you know, some C3PAOs who’ve taken that action because it’s just been clear that even at that early stage, it’s not going to land well.

And so. Okay. All right. Great. Thank you all. We’re right at about the, yes, 2:30 mark. Pretty on the nose there. So, thank you all for your time. Thanks to our audience today for spending their hour with us. Very much appreciate your guys’ time and expertise as we, you know, dig into this process.

So, for everyone in our audience, just a reminder that, you’ll be getting a link to the webinar recording in your email, by COB today. And then also, definitely encourage you all to join us for our next webinar. On October 7th. There’ll be a link for registration in there. Bill, do you want to just give a quick little commercial for that webinar in particular?

You’ve done it. I’ve done it a few times. And so, you’re kind of the expert here. You know, so, one of the things that we do with our, with our content and whenever we produce these webinars is very much what we did today, which is try to use educational, explain kind of what’s going on, either with the rule or with different strategies to kind of get there.

On this one, we pivot a little bit and we kind of talk a little bit about why CMMC is such a challenge, what’s required to get there. But we will talk a little bit about our approach as C3 approach and how we work with our clients to be able to achieve CMMC. It’s really informative and it kind of lays out the different steps along the way that kind of ensure that the audience understands not only how we approach it, but some of the things that and the complexities that come with solving for CMMC.

Awesome. Great. Thank you very much. I think that does it for today. Hope everyone has a great rest of your Monday. And, we hope to see you on another webinar soon. Thanks again. Thanks everyone. Take care. Bye.