Event
July 23, 2025
What to Expect When You’re Expecting…a CMMC Assessment
Overview
In this on-demand webinar, industry experts break down what it really takes to navigate a Cybersecurity Maturity Model Certification (CMMC) assessment—from both sides of the table.
Watch Ryan Heidorn, CTO, and Bill Wootton, CRO of C3 Integrated Solutions, alongside Fernando Machado, Managing Principal & CISO of Cybersec Investments, as they share hard-earned insights to help your organization succeed.
What you will learn:
-
How to prepare your team and environment for a CMMC assessment
-
What C3PAOs are really looking for
-
Common pitfalls—and how to avoid them
-
Firsthand lessons from both sides of the assessment process
Whether you’re just starting your CMMC journey or preparing for your official assessment, this session offers practical, actionable advice to move you forward with confidence.
Meet the Experts:
- Fernando Machado: Managing Principal & CISO, Cybersec Investments. C3PAO, author of The Assessor’s Playbook, and a trusted advisor to organizations navigating CMMC readiness.
- Ryan Heidorn: CTO, C3 Integrated Solutions. Recently led C3 through a successful CMMC assessment and has supported multiple client certifications.
- Bill Wootton: CRO and Co-Founder, C3 Integrated Solutions. A driving force behind one of the original AOSG partners and a leader in the CMMC ecosystem.
Video Transcript:
Karen
Good afternoon, everyone. This is Karen Vasquez. I am the marketing director at C3 Integrated Solutions, and I’m so pleased to welcome you to today’s seminar. Webinar. Excuse me on, What to Expect When You’re Expecting…a CMMC Assessment. We are joined today by some incredible speakers. I’m really excited, for us to introduce them.
Before we do, I did want to go through just a few housekeeping items. First off, we are recording the webinar today, and so what that means is, we’ll have a copy of, the webinar, the recording sent out to you by close of business today via email. So be sure to look for that, in your inbox, like again before COB today.
In that email, there will also be a few links, to some upcoming webinars that we have scheduled for, July, August and September. The next one actually being tomorrow. On How to Fast Track Your CMMC Assessment. And Bill Wootton will be presenting that particular webinar. So again, look for that in your email. Second piece is, we have about an hour today for our session.
That said, we will be sure to leave some time at the end for Q&A. So, as we go along, if you do have any questions, please be sure to put them in the question module. You’ll find that on the right hand side of your screen. And we will try to get to everything. So we have, as I noted, a number of different items that we’re going to review, in the webinar.
You all have seen these before in our registration materials. And, at this point, I’m going to kick things over to Bill Wootton. And, he will make introductions and get us started. Bill, take us away.
Bill
Great. Thank you. Karen. And, you know, we do this on a regular basis, but I got to tell you today, I’m super excited. Especially excited about what we’re our topic is today is incredibly timely. And we’ve got two just absolute rock stars of the industry with us today. Fernando Machado who’s Managing Principal of Cyber Investments. And, our own Ryan Heidorn our CTO here at C3 Integrated Solutions. I’ll let each of them make an intro for, themselves, just to say hi to a little bit about themselves. And, Fernando, lead us off.
Fernando
Yeah. Fernando Machado, Managing Principal and CISO at Cyber Investments. I’m a lead CMMC Certified Assessor, and our organization is an authorized CMMC Third Party Assessment Organization (C3PAO).
Bill
Great. Ryan?
Ryan
Ryan Heidorn Chief Technology Officer and Chief Compliance Officer here at C3, where I lead not only our internal compliance practice, but also the compliance services team assisting our clients through assessment.
Bill
Fantastic. And my name is Bill Wootton, Chief Revenue Officer here at C3. I am also, in addition to running sales and marketing, get to be emcee today and kind of shepherd us through this conversation. So let’s kind of get started. While like, this is not really about a full CMMC conversation, I do want a just a quick, ask on this, you know, what’s the latest that we’re hearing out in the industry on 48 CFR? Is there any news, any updates on maybe timelines that sort of thing? Fernando, what do you think?
Fernando
Yeah. So the comment period for the 48 Rule closed on October 15th of last year, and that was, ironically enough, was the same exact day that the 32 Rule was published. Interestingly enough, it’s funny that you mentioned that DoD has completed adjudicating those comments and sent the 48 Rule over to the Office of Information and Regulatory Affairs earlier today.
So I think we can expect that completed 48 Rule, sometime later this fall if no issues come up. Another thing that I want to add to that, though, you know, we’re starting to see prime contractors pressuring their supply chain to contact C3PAOs and get in line for an assessment, because that 48 Rule applies to the prime contractors, not the subs, because the subs work for the primes.
So when that 48 Rule goes into effect, we can expect that DoD is going to begin the phase one that’s outlined in the 32 CFR Rule.
Bill
Wow. That’s great. So a little bit of late breaking news that I even got some info that they passed that on the OMB, today. And we even saw recently with the, the Lockheed Martin putting a, a blog out, basically saying they’re going to start pushing their supply chain even a little more aggressively with complying and getting ready for CMMC.
Ryan
Yeah, I would add to that to Bill and Fernando, you know, like six months ago, as the CMMC kind of ecosystem was coming online, there were still a lot of questions about whether this administration represented a delay or a change to CMMC. I just saw, this morning there was a memo from, Secretary of Defense Hegseth that was talking about not CMMC specifically, but about enhancing security protocols to protect the supply chain from, nation state adversaries like China and Russia.
And in the memo, the first thing that he cited in terms of ways that the department, is trying to address those issues was CMMC. So I think at this point, you know, we have enough precedent, not only in the strength of the, demand for assessments even prior to the rulemaking in 48 CFR going live, but also from the administration as well.
So it’s really interesting to be on this call today after I don’t know how many webinars we’ve all participated in over the years leading up to it. It really feels like, it’s go time.
Bill
Yeah, it’s super exciting. You know, I think we’ve eliminated any doubts of ‘when,’ I mean, ‘if’ it’s a matter of ‘when’ and when is getting closer and closer or literally by the day at this point. So, you know while we’re waiting on CMMC to actually go into contracts, you know, 32 CFR is in effect now the program is up and running.
We had assessments that started as of this January. Let’s talk a little bit about, you know, how’s it going? How many, do we have any idea how many assessments have been completed so far from an industry perspective of and what kind of the industry perspective is on that?
Fernando
Yeah. So, I’ll, I’ll take that question. So I think the Cyber AB had stated, a couple town halls back, that 115 assessments had been conducted, at that time, which is probably a couple months back. And Cybersec at this time has, at the time had completed 25 CMMC Level 2 assessments. And to date, we have completed, a total of 35 CMMC Level 2 assessments.
And, you know, we’re going to continue to keep, pressing forward in helping the defense industrial base.
Bill
Yeah.
Ryan
Yeah. From the C3 perspective, one of the things I’m excited to share today is kind of our experience as a managed service provider or an external service provider, going through assessment ourselves earlier this year. Back in January, we stood up a new dedicated team within C3 that’s just about helping our clients get through assessment. And after achieving our own certification in February, I think our first client sat for certification, maybe in April, but at this point, we’re now doing 1 or 2 per week now and definitely booked through the winter.
So in terms of demand, I mean, I personally have spoken to dozens of clients that have indicated they’re trying to schedule and sit for a certification assessment in the next 12 months, and most of those are well into kind of the initial stages of preparing for the assessment process, reaching out to a C3PAO. Many of them have, a scheduled assessment at this point.
So even ahead of the contractual requirement coming online, I think most defense contractors now kind of understand that CMMC certification will be a hard requirement for them in the near future. To continue working in the defense supply chain.
Bill
Yeah. And it’s really been interesting to see our clients reaching out and almost aggressively wanting to schedule those assessments. What’s interesting for me is seeing how some are starting to talk about it as a true differentiation for their business. And when they talk to larger primes that they’ve got this box checked and they’re ready to go.
So let’s dig a little bit into kind of what an assessment looks like. Fernando kind of walk me through a little bit real quick as an overview. What does that assessment process look like.
Fernando
Yeah. So the CMMC Assessment Process (CAP) document or the CAP is located on the Cyber AB website. And you can go over there and download that document so that you as a contractor can see the phases. And the CAP breaks down the assessment process into four phases. So phase one is conducting the pre assessment. This is where the assessment team will review your system security plan and see if there’s enough evidence to even begin an assessment.
So things are that we’re going to want to see are things like, you know your customer shared responsibility matrix, policies and procedures. And at this time we’re not even evaluating if it’s good enough. We’re just trying to determine, do you even have enough evidence here to even begin an assessment? After that’s done, then one of the things that we do is we complete the pre-assessment form.
And so this form gets uploaded into eMASS regardless of whether the assessment is postponed or canceled. Then that leads into phase two, which is conducting the, conformity of the requirements. And the lead assessor here will conduct an in-brief meeting with the contractor. And the assessment is going to be conducted in accordance with NIST 800-171 and 171A and then after the assessment is completed, that leads to phase three, the completion and reporting of those assessment results.C3PAOs can utilize the assessment results template as part of like their eMASS submission. And then the lead assessor will convene an out-brief and then discuss the assessment results with the contractor. And then lastly as part of that phase three is the contractor will have to provide us a return value of the hashing algorithm of all of their assessment evidence and documents, and they’re going to need to retain that for six years.
And then last but not least, right, phase four issuing the certificate and closing out the POAM. So if the contractor met all 110 controls, they’re going to be provided a final CMMC Level 2 certificate of status. If the contractor had controls that were eligible for POAM items, per the 32 CFR part 170. The contractor will be then be providing a conditional CMMC Level 2 certificate of Status, and they will have 180 days to remediate those items and have those closed out.
And that pretty much concludes the CMMC assessment process in a nutshell.
Bill
There’s definitely a lot going on there. It’s a pretty intensive process. Ryan, can you talk a little bit about what we do here at C3 to make sure our clients are ready when our clients are going through each one of those phases?
Ryan
Yeah. I mean, our goal is to engage with our clients on preparing for the assessment before any of those phases start. Right. So, we’d love to be engaged really heavily on assessment prep before they reach out to C3PAO. So before, you know, the CAP really kicks in. And there are a number of reasons that, you know, we as an external service provider have to be aligned on timing.
And really it’s kind of a make or break, I think, because timing is going to impact not only kind of some of the current throughput issues in the C3PAO ecosystem, as well as our own scheduling constraints, but primarily readiness, right? So we want to have mutual agreement with the client on a self assessment score of 110 before they even reach out to schedule anything.
Right? So, we try not to let a client get to scheduling with C3PAO if they’re not ready, because kind of fundamentally as a, advisor, as a participant in the assessment, our goal is to pass that assessment as I use air quotes here in phase one. So before we’ve even started to look at the conformity to the requirements, I want to make sure that we have kind of fully and thoughtfully described both the assessment scope and the classification of all the assets and scope, so that when we engage with a C3PAO like Cybersec, we’re able to provide a very fulsome list of the evidence we intend to provide for examination.
And we have a lot of confidence that when we get to phase two, we’re not going to be kind of grasping at, oh, shoot, you know, what am I what do I need to say here? Who’s speaking? Do I have the right types of assessment? We want to make the assessors job really as easy as possible to have, you know, maximum confidence in a positive outcome there.
Bill
It’s fantastic. It’s certainly a lot to go through, but it’s so important. Fernando, I know you’ve gone through obviously, 35 assessments now, at least that that you’ve gone through. You know, what separates those who kind of pass and go through fairly smoothly and then, you know, the folks who may struggle through that process or maybe even not make it.
Fernando
Yeah. So a couple of items, right? One, it still astonishes me today that contractors don’t know that there is a second part to NIST 800-171 and that’s 800-171A. Now, on paper it looks like you have 110 controls, but in reality you have 320 separate assessment objectives that you must address. And failing to implement the requirements at the assessment objective level will almost guarantee you an automatic failure.
And two, contractors processing, storing or transmitting CUI in a non FedRAMP authorized or equivalent cloud service provider environment, is going to cause you to fail. Microsoft 365 Commercial as an example, is one of those cloud service providers that is not FedRAMP authorized. So if you’re using Microsoft 365 Commercial today, the processor, store, or transmit CUI that would almost be an automatic failure right out of the gate.
So those are the two primary issues that we see during our discovery calls with our clients.
Bill
That’s pretty amazing. Ryan?
Ryan
Yeah. I mean, I think I can probably end the webinar here by just saying the word preparation ten times. So I’ll just keep hitting that point. You know, thankfully, we have not had a client fail an assessment yet because we’ve been very, insistent on kind of a prescriptive approach to preparation. But certainly some of our clients have struggled in the lead up there.
And I think kind of the common thread there is those that have some level of urgency, whether you know, real or kind of self-inflicted, that spurs them to try to push past our recommendations for best practices, preparation, which I’ll kind of go through here. You know, scoping I mentioned is critical. You kind of can’t proceed until you have confidence in your understanding around your CMMC assessment scope.
We are strong advocates for mock assessments, essentially like going through a dress rehearsal before we get to the actual show with the assessor. That definitely is a best practice. And then evidence collection, which I’ll talk about here. Later in the webinar, too. But one thing that I’ve seen now working with a number of C3PAOs out in the community is, I’ve noticed, kind of a pretty wide delta on the quality of the individual assessors.
And the reason that’s important is, you know, what evidence may have been, very positively received by one lead, CCA might cause another to have a very different reaction. We’ve seen some assessors that take a default tone of, like, collaboration and are pretty consistent in their approach and others who are perhaps more rigid or even a little erratic.
So we try to emphasize to our clients that they’re it’s important the decision of which C3PAO to work with. And, you know, I have never been an assessor, but I can observe that it is both a science and an art. And my personal opinion, having been through a number of these now, is that, if I’m sitting across from an assessor that perhaps used to be an engineer on the other side of the table, sometimes there’s a tendency to bring their own personal history and kind of an implementation bias to the conversation where, you know, they implemented a control themselves in one way and made believe that’s the way to do it, regardless of whether the OSC took a different approach, even if it meets all aspects of the assessment objective.
And one of the things that I’ve observed, too, again, I’m not in the assessor community directly, but, we don’t have an overwhelming quantity of certified lead CCAs. And so we see some C3PAOs that are kind of sharing resources through, 1099s and others that, have a consistent staff with W-2 employees and I’ve noticed a difference there, too.
So, all that to say, you know, part of the preparation is thinking through, you know, the assessor that you want to work with and making sure that they have a good reputation in the community. Obviously, you know, that doesn’t guarantee an outcome of any sort. And it’s not a substitute for full preparation and doing everything that’s required.
But, you know, it’s one of the things that we consider.
Bill
Yeah, it’s great points across the board there. And I think what the thing that stands out to me there is the preparation piece of it in that you don’t just show up on Monday and kind of run through it kind of and ad lib it. There is a level of effort to get ready for that assessment. Any, anything, any good stories, any good juicy gossip or anything. You know, any standout stories from clients that you’ve seen, maybe something that surprised you?
Ryan
I’ll take the first step there. So, let’s see seen both positive and negative. Right. Start with the positive. I had one client that I’m very excited about their recent success achieving their CMMC certification. They were an early adopter of C3’s CMMC reference architecture obviously won’t mention a name, but they’re a large kind of household brand.
True partnership with us as a managed service provider over the years, which if you are an OSC that works with an external service provider, you probably understand intuitively that alignment with your ESP is going to be critical through the assessment process and probably a huge part of the outcome. Right? So, you know, we’ve been in this space for a number of years.
And as the rulemaking, kind of came online and we had experiences with DIBCAC, our recommendations have changed as we’ve kind of learned lessons there. But this client, was a true partner through the whole thing. And I would say what differentiated them was that they took their DFARS contractual obligations seriously, not in 2025 or 2024 or 2023, but like going back to when they were included in their contract.
Obviously we had to wait for the CMMC final rule. And, you know, at the end of 2024, they were still kind of putting some finishing touches on their compliance program to ensure alignment with the CMMC assessment process and other aspects of the final rule. But all of that kind of like taking those requirements seriously led them to be extremely well prepared for the assessment.
And so they were able to demonstrate an early win, kind of to your point, Bill, in terms of a competitive differentiator, earlier than their peers and their competitors. And so I was really happy for them to achieve that. On the other side of the table and not to speak ill of anyone, I have seen a certain profile of clients that we work with as well that, perhaps is not similarly invested in their contractual requirements and as a result has struggled.
And some of the characteristics there, have been kind of like pushing aggressively on timeline. And in my view, again, as an outsider, a timeline that’s not really tethered to reality. So both in the sense that, like the deadline for them to be certified was artificial, right? There was no contractual requirement yet or a real deadline from a customer, but it was also unrealistic based on like where they were in terms of preparation.
So the client I have in mind, I’ve really just started implementing security requirements a few months ago, and we’re just pressing like, we’ve got to get certified, we got to get certified, we got to get certified. Along with that, and I’d be curious to see if Fernando has observed this too, an attitude of kind of like, hey, we’ve been through SoC audits, so we know how this works, and you’re probably overcomplicating it by wanting to do all this preparation, not seeing the value in preparing for the conformity assessment that is CMMC Level 2, there’s kind of an attitude of like, hey, we paid you to do our IT.
That should be enough, right? And they weren’t quite sold on the idea that robust preparation really does not only de-risk the assessment, but especially if you’re trying to hit an aggressive timeline, like you have to invest in preparation for the assessment itself. And that occurs after you finish the implementation of the security requirements. Otherwise it can be a pretty high risk activity. No doubt.
Bill
Fernando, about you, any, any good stories to share in?
Fernando
Yeah. I mean, so the biggest thing is like to Ryan’s point is the better prepared the client is, the quicker the assessment typically goes. And so what ends up happening is instead of having to sit on average on an assessment for five business days, you can actually cut that down to about 2 to 3 business days, depending on how well the client is prepared.
And Ryan, to the point that you were mentioning earlier of an organization stating that are ISO 27001 or SoC 2 or whatever it may be. I kind of liken that to, you know, the five stages of grief when it comes to CMMC. They’re in the bargaining stage at that point where they think that they can bargain their way out of it.
And. Right. Nothing is going to be able to prepare them for a CMMC Level 2 assessment outside of actually implementing the NIST 800-171 security requirements themselves.
Bill
Yeah, I can tell you about those five stages. On the revenue side, we typically deal with a lot of anger and avoidance in those stages. But, you know, people work their way to their own pace, I guess, you know, it’s okay if you’re not comfortable saying. But have you failed anyone yet?
Fernando
No, I’m comfortable saying that. No, we haven’t had to fail anyone yet. However, we what we have had to do what’s called an adverse determination, meaning the OSC was not prepared to go through the assessment. And we’ve had to do this, in two separate occasions with two contractors. First contractor, when we received their, their documentation, we discovered that they had no established evidence or artifacts to address the incident response control family.
When we asked about that, they said that their answer to us was, well, in the event of an incident, we’re going to open a ticket. I’m like, great, but like, where’s that incident? That operational incident handling capability? And all we received was crickets, which told me right there that they didn’t have that. So, we did the an adverse determination on them, meaning they were non voluntarily rescheduled.
And then for the other contractor when they, when we received their documentation, they sent us their plan of action, a milestone document. And it had a bunch of controls that were listed as open that had not been implemented. We asked them about that. They said they sent us the wrong document. We waited for about a week, and when we saw that, we haven’t received anything that kind of told us right then and there that what we received was actually the correct document, if items were still open.
So we not voluntarily rescheduled them as well.
Bill
It’s interesting, like there’s a couple of signals that very quickly tell you that there’s a larger, probably challenge or problem behind the scenes and would have been interesting to be in a conference room when they got that POAM back.
Ryan
So I love the term non-voluntary rescheduling. That’s quite nice. I mean like, clearly no one’s going to put out a press release that they failed an assessment. But, you know, kind of reading between the lines on some of these Cyber AB town halls, it definitely seems like there is a not insignificant number of contractors that are bumping up against the non-voluntary rescheduling, which I think is actually nice and that it speaks to, the effectiveness of the process in the CAP to gauge readiness for the assessment before you actually like a go on site or start having those all day, you know, assessment sessions.
Fernando
Yep. Agreed.
Bill
I agree with you on that, Ryan. No doubt. So if you know, obviously we on any audience, we have companies who are in that, you know, OSC type of place and they’re, you know, trying to determine are they ready? You know, what are some of those indicators as an organization, as you start thinking about, should I use schedule my assessment, you know, is there things that that are good signals are great things that are red flags? What would you, how would you kind of talk to that. And in terms of preparation and understanding, do you feel like you’re ready to go make that phone call for a C3PAO?
Ryan
I would say if you haven’t at least thought through what evidence you plan to present for every single assessment objective, all 320 at CMMC Level 2. That’s a red flag, right? So I’ll keep emphasizing the value of doing the evidence collection and having an internal validation process of that evidence, which occurs after you’ve implemented the security requirements.
But before you schedule the assessment. I also think mock assessments are an effective way to, to kind of work through that. I will say my opinion is it is too risky to go into an assessment, kind of hedging, thinking like, I’m going to get the right people on the call, whether that’s my internal resources or I’ve got an external service provider.
And since they do it, they’ll be able to tell the assessor how we’ve done it correctly. I think relying on demonstrations and interviews, as opposed to evidence that can be examined by the assessor is risky. And the reason for that is, look, you’ve got three options to basically demonstrate how you’re meeting an assessment objective. It’s, examine, interview and test.
I used to be a sales engineer for a living, so I’d give demos. Right? And anyone who’s ever done a live demo knows what can go wrong on those live demos, even if your product works the rest of the time. Right? The same is true for security controls. So I try not to give live demos if I don’t need to.
And you know, we’re all human and we know that humans can behave irrationally and unpredictably, especially when they’re under pressure. So I don’t necessarily want to take my very gifted engineers, for whom maybe, you know, clear, polished presentation to an assessor is not their strong suit and just rely on them to save the day. Right?
I basically want to create objective evidence that can be examined by the assessor in as many cases as possible. Of course, the assessor can always dig. Right? So if they don’t feel like you’ve provided enough or the right evidence, they can pivot to an interview or a test, or ask for more evidence to examine. But, again, kind of tie that back to your question, Bill.
It’s a red flag for me personally if you have not thought through and had a game plan for the objective evidence you intend to present for every one of the 320 assessment objectives?
Bill
Yeah, I was amazed, Fernando, when you said earlier, some folks don’t know there’s a 171A it’s literally the questions on the test. So like, you know, like it’s kind of it’s not quite an open book test, but it’s pretty darn close at that point. So, Fernando, how about how about you? What, what would you suggest or what advice would you give to a company trying to, you know, get a feel for am I ready to go pick up that call, that phone and call?
Fernando
Yeah. I mean, in my opinion, right. It’s best to work with an external service provider that has been in the space for a long time and actually, has hands on experience of helping clients through an assessment. Because that kind of experience is invaluable and it can really save you, precious time and money.
Bill
It’s a great point. Great point. Ryan, you lead our internal CMMC Level 2 assessment. You know, without obviously getting too far in the weeds, you know, what was that experience like? How did how did you approach it and preparing our team to be ready for our own internal assessment?
Ryan
Yeah, I’ll say honestly, and I put this on LinkedIn in the context of this webinar, probably the most fulfilling professional accomplishment of my career to date was getting through those assessments. And the reason for that was C3 is an external service provider that focuses solely on the DIB. So we saw CMMC coming obviously many years in advance. And, you know, I use this analogy from airplane safety, which is basically, you know, please secure your own mask before attempting to help others.
So that was definitely the mindset. And because it’s our entire business helping contractors, we knew we had to be first out of the gates and the kind of acceptable margin for having findings, you know, to delay our, our final certification was basically zero. So the stakes were high. Compounding that challenge, C3 had gone through two mergers or, you know, in the years leading up to our assessments.
So there’s some complexity introduced by, you know, integration of systems and, new kind of processes for working with our clients, which I think many organizations in the DIB can relate to that process of mergers and acquisitions. So, for me, the important part was getting the boundary right and the CMMC final rule in title 32 give us a lot of clarity, more than I was expecting, honestly.
But still, there were gray areas because C3 doesn’t process, store, transmit CUI, but we definitely handle security protection data on behalf of our clients. We absolutely host and manage security protection assets for our clients, and we have access into our clients CMMC assessment scopes. So, we ultimately landed on to kind of different scopes, and we made the choice to go through two assessments, one for each scope.
Without kind of belaboring the point and going into the why, we are both an MSP and an MSSP. So we have a 24/7 SoC. Our VP of Security Operations comes from the Defense Cybercrime Center. We take separation of duties very seriously. So one of the scopes that we kind of put together was every single asset that’s going to touch a client’s CMMC assessment scope.
So that’s every single security protection asset, both technology and people who are going to interact with the client environment. They’re in that scope. And from there we mapped all of the data flows. So like all of the ingress egress out of that system, all of the external connections, whether they’re directly connected to a client environment or cloud service providers that we’re operating with on behalf of our clients or our other internal C3 scopes, and made sure that not only are they documented, but we have kind of a written justification for those data flows.
The other scope was specific to our SoC. And so, that included their data pipeline and the tooling that they use for things like, detection, analysis and response. And the reason or one of the reasons we did that was to draw the boundary very clearly, thinking about the future state of our clients going through assessment so that we could say to an assessor, hey, it’s easy for us to demonstrate how we’re implementing segregation of duties between our system administrators over here and the security analysts over here who are managing things like audit logging and, detection infrastructure.
And the other, but all said and done, like even after, you know, preparing for years of implementing NIST 800-171 internally, it was still nine months of dedicated effort, at least preparing for that assessment event. But by the time that the assessment did come, I personally had, you know, 99 plus percent certainty that we had a strong defense and thankfully, we were able to get through our assessments really quickly.
In fact, it shocked me, shocked our lead assessor how fast we went. Our lead assessor told us it was the fastest and smoothest assessment they had gone through. It was the first CMMC assessment I’d ever been through. Right? Because it just came online. But, after that experience, I knew that was a good approach, basically being maximally prepared.
We probably prepared more than our clients need to because we had, you know, zero tolerance for findings. But taking a similar approach for our clients has been kind of core to getting our clients through assessment today.
Bill
Wow. Even with all of that and the very limited insight I had into that process, I think you’re still underselling the level of effort that was required for us to get there really was a tremendous amount of work, and obviously the whole organization, we’re super proud about that. Kind of open for both of you, you guys know, is what’s the difference in the approach when you’re looking at an assessment as a service provider as opposed to maybe an actual government contractor themselves?
Is there anything that shifts a little bit, in a way, you focus on it or where you prepare?
Ryan
Well, from my perspective, I think kind of just echoing what I said, like understanding how the service provider scope overlaps with and is part of the client’s assessment scope is critical because then you’re able to answer questions around, the CRM, the customer responsibility matrix. It’s still fuzzy to me, kind of how assessors are thinking about again air quotes, ‘inheritance’ from a service provider.
We don’t have inheritance in the same way that, you know, the FedRAMP program has. Right? So, you know, from the service provider side, making sure that we have the body of evidence, in addition to our own certification to show an assessor. Hey, you know, this asset over here that was included in our scope is directly one for one applicable to our clients satisfaction of that requirement.
Because we operate it on their behalf. So I think that’s critical. It’s definitely different in the sense that the service provider, at least in our case, is an MSP. It’s not necessarily handling CUI. So the scoping for the service provider is a different kind of thought process than a scoping for a contractor, which really should be focused on what are my CUI data flows, what are my FCI data flows and how do I protect those.
Bill
Sounds great. Fernando?
Fernando
Yeah, I mean, everything that Ryan said, don’t want to, you know, continue to keep beating a dead horse. Everything he said was spot on.
Bill
No worries. That’s all good. You guys have talked extensively about preparing evidence effectively in a in a playbook type of style. You know, can you talk a little bit about, like what do you do in terms of building that, that evidence playbook and kind of how should someone think about that a little bit?
Ryan
I could spend the rest of the webinar talking about that, but I kind of stole the idea, at least in part from Fernando. So I don’t know if you want to take the first swing on. Like, what do you like to see from OSCs in terms of how they present their evidence?
Fernando
Yeah. So one of the things that we’ve done is we created, what’s called the assessor’s playbook, and it’s simply a one note document that allows organizations to organize their artifacts in one central location. That way when the assessor is reviewing your evidence and documentation, they can see at a high level that you’re meeting the intent of the requirements.
And you can download it for free on our website. And it’s literally just, you know, populating screenshot shots into each of the different assessment objectives on how you’re meeting that intent. So it allows us to basically look at a high level and say, okay, we have this artifact and they’re meeting the intent of these requirements. We potentially would just have to see it in real time during a live screen share, and that should be enough.
But it gives us a lot of confidence going into the assessment early on that things are being met as they’re supposed to.
Bill
Sounds great. Fernando, kind of adding on to that a little bit. You mentioned a little bit earlier on one of the answer is that it’s really important that your ESP has experience with CMMC. How important is it that ESP actually has their level two assessment certificate or certified and how does that impact the actual assessment process itself?
Fernando
Yeah. So one of the biggest things that like we’ll see in the 32 Rule is that external service providers are not required to get level two certified. However, if they do intend to get level two certified, then what ends up happening is it lessens the burden for the contractor during the time of their assessment. And so while even though it’s not a requirement, it’s highly suggested that level to our level or excuse me, service providers be level two certified to help reduce the level of effort for some of the contractors, because otherwise what ends up happening is you’re going to end up being on assessments the entire time and you’re never going to do your primary job, which is right, management managed services. So having that CMMC Level 2 certification will definitely help in the long run with supporting some in the defense industrial base.
Bill
Sounds great. So we wanted, as we plan this webinar to really make sure we left a little bit of time for, questions, expecting a fair amount from the audience, hopefully, we got a great, great crew, great audience here today. But before I kind of turn it back over to Karen, I want to give you guys first, both kind of like a little bit of a final takeaway in terms of what’s the single best piece of advice that you would give for companies looking to get through, especially the first time around on the assessment process?
Fernando
Yeah. I can take that one first if you want. Ryan. So one of the biggest things that we’re, that we’re constantly when we start talking to contractors that are starting their journey now, versus, you know, when they should have started it months ago. If you’re starting your journey now and you’re going to hire a external service provider to help you, please ensure and understand that their timeline on helping you to reach preparation is going to be completely separate from our timeline to certify you.
So it’s best that if you’re going to talk to an external service provider or C3PAO, that you’re talking to them in tandem to find out that, you know, maybe your external services provider is booked out for ten months and your C3PAO is booked out for 12 months. So you’ll have to kind of like make sure that you’re kind of putting those two timelines in mind when you start strategizing on how you’re going to go through your implementation and certification process.
Ryan
Yeah, building on that, because I see it from just a slightly different angle based on the work that we do, is, you know, we’ll tell an organization that let’s just say, you know, they’re part of that cohort of defense contractors who are coming online now, kind of like just waking up to, oh, I was supposed to have been doing this. I had no idea. Right. And so they’re very focused on, timeline and cost. Right. I need to be certified as soon as possible. Right. And they want to know, bottom line, what’s it going to take? It’s actually somewhat difficult to get the message across that, look, it’s going to take you a certain amount of time to implement the technical controls.
It’s also going to take you a certain amount of time to implement the non-technical controls. The sum of that time doesn’t necessarily mean that you’re ready for assessment either, because preparing for the assessment event is itself some level of effort too, so one of my kind of key takeaways for, contractors who are either in that boat or even if they have been preparing for a while, is like, look, you can’t just build it.
You also have to prove it. Right. We know that. And you’ve invested so much time and effort into the implementation. Like don’t skimp on the preparation for the assessment, right. Because you need to know all the evidence that you’re going to present before you even show up for that scoping call. And my best advice is basically, I want to show up for this scoping call, basically the phase one activities of the CAP and provide the assessors with the path that I want them to walk. Right?
There is one school of thought that says bury the assessor in evidence. I don’t I don’t think that’s it. I don’t correct me if I’m wrong. Fernando, you don’t want a firehose, you want traceability. So I want to build a path, lay it out for the assessor so they can walk through and determine ‘met’ or ‘not met’ for each assessment objectives at a rapid clip.
I will trust that you will come back and say, this is not quite what I was looking for. Give me more. But otherwise I think you are optimizing the assessment process for speed, efficiency and reduced risk again by investing in preparation for the assessment event, which happens after you’ve reached a self-assessment of 110.
Yeah, tying that back together. Like, you know we you mentioned earlier and we see this a lot in, you know, in the prospective conversations we have with potential clients of the goals being somewhat arbitrary. And, you know, we’ll ask someone, you know, when do you think you want to sit for an assessment. They’ll say third quarter 2025. And we’ll kind of remind them that we’re in third quarter 2025. And you align well. There’s a lot of work to do to get ready. And even at that point, there’s a preparation exercise that needs to go through, even as you’re thinking about when you can schedule it and those things, you know, you might get a little bit of overlap on the scheduling.
But, you know, there’s a lot of demand for the C3PAOs that are out there. Fernando, I imagine you’re pretty well backed up at this point as well from a scheduling standpoint.
Fernando
Yeah. Like right now I think our first availability is, mid-March. And we’re already starting to schedule some clients into April of next year. We have no availability for calendar year 2025 anymore.
Bill
Wow. That’s amazing. That’s absolutely amazing. So we’re at a really great spot now to kind of shift things a little bit. I want to bring Karen back in here a little bit. And she can kind of emcee any questions we might have from the from the audience.
Karen
Great. Thanks, guys. And thank you, Bill. We do have a handful of questions. The first one, I think I’ll tee up is, question about the score. And the question is, do companies get a score for level one certification, or is that only for level two certification?
Fernando
Yeah. So to my knowledge, level one is self assessed, where that organization will have to and I think more information will come out on that in the 48 rule on how that’s going to be done. But when it comes to level two, if you’re doing a level two self assessment, right, you’ll have to input that SPRS score. Right?
And that already exists today for the DFARS 7019 you have to submit a basic self assessment in there. And if it is going to be a level two third party assessment then this is where achieving that final level two CMMC Certificate of Status, meaning you’ve implemented all 110 controls, or you get a conditional level two, certificate of CMMC status.
If you’ve implemented most, at least 80% of the controls or 88 out of 110 controls, and you have some items that are POAM-able and you’ll have 180 days to remediate and close those out to basically graduate from a conditional level two to a final level two certification.
Ryan
It’s one of those like peculiarities of kind of the layered rules, right? Which is like if I go directly to get my CMMC certification assessment, that doesn’t mean I don’t have to also put in my self assessment score into SPRS. In fact, like you have to do that, you have to get the assessment and they have to affirm the assessment results in SPRS, which is a few different steps that like for contractors who are just coming online to CMMC, might not make intuitive sense.
Bill
Right.
Karen
Right, thank you guys. Appreciate that. Next question is, about some next steps. It is if a company is working to become CMMC compliant and they’re using M365, what would you suggest the next steps be to begin a path to compliance. So this is really about, how do I get started?
Ryan
I guess I’ll share a heavily biased implementers view of that. I am a Microsoft fanboy. I’m not fully drinking the Kool-Aid. I, you know, want the best technology for the purpose. Right? But Microsoft Cloud, and especially their government cloud is a great solution for contractors. I believe that obviously it’s core to C3’s business model too. What I learned when I started this in 2017 was that it makes more sense to start from, you know, your desired outcome and then work backwards through your tech stack than it does to get a tech stack and work forwards towards the implementation security requirements.
So to make that a little bit more concrete, I have worked in M365 environments and even in, you know, on-prem environments, other cloud environments too, where I was never able to get to fully, implemented for one reason or the other. And so the C3 approach is basically like, look, we have a technical blueprint for meeting all of these security requirements in CMMC Level 2, we leverage the Microsoft Government Cloud for a lot of those technical requirements as well.
You basically, if you are getting started and it makes sense for you to work with a service provider, sign up to say, hey, that approach makes sense to me. I’m going to adopt this kind of vetted system configuration and all of the benefits that come along with it in terms of like, hey, we already have these things mapped to, you know, control outcomes. We have documentation to support it. We’ve got the evidence that we plan to capture as a result. So that’s one approach.
If you are not taking that approach and you’re working in the Microsoft cloud, you know, without a service provider, without a reference architecture, Microsoft still does maintain what they call their product placement for CMMC, which you can just Google. I think the last update might have been a year ago, but it’s still fairly relevant. It’ll help you map from Microsoft’s perspective, which, Microsoft Cloud Services, which licenses that enable those services, can map to given CMMC requirements and assessment objectives as well.
That can be a sanity check for saying, do I have, for example, the right licensing for coverage for CMMC. It doesn’t mean that obviously turning on or even starting to configure some of those services de facto puts you into a implemented state. There’s still a lot of thoughtfulness, required in terms of like how the various controls in CMMC are interrelated.
And that’s where a lot of people trip up at the end of the day. And so again, for that reason, I recommend, working from kind of a vetted system, baseline configuration.
Bill
Great. I’ll, Karen, I’ll add in that that question was almost a plug for tomorrow’s webinar as well. That will take a little bit of a different, you know, a similar approach. Very much so. But in the in the way we’ll outline tomorrow’s webinar is kind of breaking down different phases of going through that journey from understanding your business to how you set your boundaries to some of the things that you’re going to require.
I think Ryan made a great point there with 365 and a placemat, but then also understanding that a lot of those controls are performative. You’ve got to be doing something. It’s not a configuration where you set it and forget it. So, it’s critical, it’s a great starting point. But that placemat is a starting point in that area.
So Fernando or if you want to move on to the next question and where are we going to go next?
Fernando
Let’s go to the next one. You guys you guys hit that one.
Karen
Great. Okay. That sounds good. And Bill, thanks for the plug about, tomorrow’s webinar as well. I agree. It’s a definitely, must see TV. For folks who are just getting started, next question, is about, primes and subs, right? So, as you know, everyone knows that federal contractors, they’ve got the flow down clause to subcontractors and suppliers. And the question is if subs and suppliers cannot or will not get compliant, what are our contractors options and does a sub noncompliance affect Prime’s assessment?
Bill
Wow!
Fernando
That’s a loaded question. All right I’ll try to tackle as much as I can. So the reality of it is, critical suppliers, if you’re a critical supplier to a prime as a subcontractor, you probably would have already been hearing by that prime contractor by now on helping you get compliant. If you haven’t heard from them, then chances are good you’re probably not as important to them as you know you think you are.
I mean, I hate to be blunt about it that way, but it’s just the reality. And, you know, the only thing that I think a lot of people tend to misunderstand is that CMMC is nothing new. The only thing CMMC is that a third party verification program of your existing DFARS 7012 requirements, specifically your implementation of NIST 800-171, which you’ve been attesting to the government that you’ve implemented and self attested, right, per the DFARS 7019 and 7020 clauses.
That’s pretty much all I have to say about that. You know, I think that the if you want to play in the DoD space, this is going to be what is going to be required going forward. And I think it’s just a matter of time before the other agencies start to pick this stuff up. When we starting to see things like the FAR CUI rule currently going through the rulemaking process as well.
So if you want to play in the federal government space, I think that this is the way that things are going to be going from here on out.
Ryan
Yeah, I would add pure speculation because I am not, an expert on federal contracting by any means. So huge caveat here. Just my two cents, right? Having spoken to some contracting officers and some, supply chain folks at some of the large primes, I think what you said is spot on in terms of like, these are critical suppliers.
And clearly, there has been already an enormous amount of pressure from the large primes to their supply chains in terms of ratcheting up the messaging. First, it was like, you know, give us some general, stats or demographics about, NIST 800-171 without any sort of like, teeth to it. Now it’s become much more tactical. Like, at what date do you expect to be certified?
Are among the questions that I have seen. However, we were talking about at the beginning of this webinar about the, the rulemaking in 48 CFR moving forward. I think it’s reasonable to expect that to come online this year. I think it’s probably a tone change from the prime contractors, like especially the large primes. They’re not going to take chances on winning new contracts that do have a CMMC Level 2 requirement by saying like, oh yeah, you know, we’ve got self attestations or worse from our supply chain, they’re going to need to validate, to some extent that the folks that are going to be performing on those contracts meet the requirement.
Otherwise it’s a massive risk and liability. The large primes simply cannot, you know, tolerate that type of risk. And so I think we’ll continue to see more and more urgency, among the suppliers and subcontractors that gets generated from the primes in the coming months.
Fernando
Yeah. And, Ryan. So I’m sorry, Bill. And, Ryan, to your point, I mean, you know, just late last month when Lockheed put out that memo, that last line that they made sure like they actually made 100% sure that they bolded it where it said all DIB companies managing CUI should have fully implemented and be confidently meeting the NIST 800-171 requirements.
So this right? The only thing that is different with the CMMC program is just a third party validation of it. That is what the eyes of the DoD is going to be looking at.
Bill
Yeah, I was that was exactly what I was going to mention, Fernando. And kind of also highlight the significance of that. They, like the primes, have been talking, for lack of a better word, behind the scenes with their suppliers for so long, coming out and publicly putting out a blog I think was a an important key change a little bit.
In a way, they’re going to be pushing and really being firm on those requirements. And also kind of mentioned that like, you know, having it is a condition of awarding contract doesn’t necessarily mean you need it then. When primes are putting teaming partners together, they need to have confidence when they put that proposal in that you’re going to be ready at award.
So things are much sooner than maybe a lot of people think when they look at the CMMC timelines for implementation. So.
Ryan
I think we’ll see some broken hearts for, you know, some of the smaller primes and the subcontractors supplier base that have not taken the seriously thinking that they have more time, or maybe just not understanding the amount of time that it takes to be ready for an assessment, which is, unfortunate one regard, I think the more, harsh reality is a message that you just put forward, Fernando.
And it’s echoed a lot, which is like, guys, if you didn’t see this coming, kind of like question your powers of observation because this was a very slow moving train with a pretty consistent message.
Bill
Yeah. And then we do that. There’s a big difference between having something planned, having an urgent need to do something. And when we get that phone call where someone is panicked and we’ve gotten a few of those already at this point, it’s a completely different conversation with that client. And, you know, it’s because it’s already like they’re starting to realize that they should have been doing this a while ago.
And, and it’s already hitting them in terms of a real requirement, probably a prime or some other organization. So.
Karen
Right. Thank you, guys. Hey, I want to be, respectful of everybody’s time. I know Fernando is kind of hard, hard stop at 2 p.m. So, I think probably now is a good time to wrap up and, just, give a quick closing message. Again, look for your webinar recording in your email by close-of-business today.
It’ll be coming from me, Karen Vasquez. And my email address, kvasquez at c3isit.com. So definitely check your spam folder. Sometimes it goes there. I’ll also include the, registration links to those three upcoming webinars that you see on your screen. Definitely encourage you to, plan to attend those if you are able.
Guys, any last thoughts? Any final, suggestions, tips, marching orders, what have you?
Fernando
Yeah. I mean, I think the biggest thing is if you’re going to play in this space, you know, quit dibble-dabbling with CMMC, embrace it 100% and use it as a competitive advantage, because as a lot of companies decide they don’t want to do this, you stand primed to win a lot of contracts. And, you know, in most cases you can even become a prime contractor yourselves, depending on how well you set yourself apart from your competitors.
Ryan
I’d say go grab that free assessor’s playbook from Fernando’s website. A great place to start, and if you’re not fully confident and filling it out, give Bill a call.
Bill
There you go. I’ll wrap it up. Don’t be one of those companies that has a broken heart or has to make that panicked phone call. It’s already very late in the game. Get started today. Echoing Fernando’s comment like, just get started, get moving. Start figuring out a plan even if you’re not opening up, you know, the budget at the moment.
Make sure you know what that pathway, that timeline and that budget looks like so you can pivot as quickly as you can when you finally make that choice. I also wrap up by thanking both of you guys. Ryan, Fernando, as I said in the beginning of this, total rockstars in this industry, you guys totally deliver today in terms of being able to provide amazing information for our folks out there as an audience. I really appreciate your time and your insights today.
Fernando
Thank you, Bill. Thanks for having me.
Bill
Yep. All right.
Karen
Thanks, all. Well.
Bill
Thank you everyone. Everyone.
Fernando
Thank you