
Cyberspin · 2026-06-25 · 46 min
Key moments - from our scoring
Substance score
49 / 100
Five dimensions, 20 points each
CMMC Connect's June 2026 session addresses three critical topics for defense contractors navigating maturity model compliance. Jeremy Mares clarifies the November 10th Phase Two transition date - not a certification deadline but rather when DoD begins including CMMC in contracts, with actual demonstrations required at award (typically early 2027). As of May, only 1,391 certifications had been issued; the ecosystem lacks sufficient C3PAOs and assessors to certify the entire DIB by November, making attestation letters with documented assessment schedules universally accepted by program managers and contracting officers. Dr. Thomas Graham previews the federal CUI rule's re-release for public review, signaling potential NIST 800-171 Rev 3 adoption by year-end, and introduces the department's post-quantum cryptography strategy, which uses CMMC as an enforcement mechanism with a December 31, 2030 deadline - likely triggering Rev 4 revisions. Aaron Freetag and the team tackle significant change definitions, emphasizing that AI/ML tool implementations require thorough risk assessment, particularly regarding CUI handling, cloud environments (FedRAMP compliance), and scope expansion. Dr. Graham confirms that the Authorizing Official ultimately determines whether changes require reassessment, though clarification from the Cyber AB is pending. Katie's question about multi-tenant Microsoft configurations across separate GCC High tenants for sister companies with shared users but distinct CAGE codes receives guidance on potential segmentation within unified cloud environments to manage costs while maintaining separation.
No. November 10th is when DoD transitions to Phase Two and begins including CMMC in contracts, but companies don't need to demonstrate certification until contract award, typically early 2027. Engagement letters showing planned assessment dates after November 10th are currently accepted by DoD program managers and primes.
Changes that alter system scope typically require reassessment, including switching between different CMMC-certified and non-certified vendors, changing cloud providers (e.g., Microsoft to Amazon), expanding to new CAGE codes via M&A, or deploying AI/ML tools that process CUI. The Authorizing Official makes the final determination, though the Cyber AB is working on clearer guidance.
No - organizations must define a specific inactivity period (commonly 5-10 minutes). Compensating controls may justify operational necessity deviations (e.g., 60 minutes for surgical staff), but a baseline threshold must be established and documented.
Microsoft confirmed multi-tenant configurations are possible between GCC High tenants but not between GCC High and GCC Moderate. Organizations with multiple CAGE codes typically segment a single cloud environment rather than maintain separate tenants, centralizing management while maintaining logical separation.
The DoD's post-quantum crypto strategy names CMMC as an enforcement mechanism, with a December 31, 2030 deadline for systems to either transition or retire legacy cryptography. This will likely require updates to NIST 800-171, potentially triggering Rev 4 revisions within the next couple of years.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode contains a handful of useful regulatory updates - the November 10th reframing, the CUI rule re-release foreshadowing Rev3, and post-quantum crypto enforcement via CMMC - but the majority of answers are hedged with 'clarification is coming' or 'reach out to us,' and substantial airtime is consumed by holiday pleasantries, anniversary banter, and taco polls.
November 10th is not a deadline. November 10th is a milestone that simply designates when the DoD will be moving from phase one to phase two
one of the mechanisms that they're going to use to enforce the adoption of post quantum crypto is cmmc. It's actually identified in there
Most content is reactive regulatory narration rather than original analysis; the post-quantum-to-CMMC enforcement link is a genuinely forward-looking connection, and reframing November 10th as a milestone rather than a deadline shows some independent framing, but the bulk of the episode is 'it depends on your AO' and 'we hope clarification comes soon.'
one of the mechanisms that they're going to use to enforce the adoption of post quantum crypto is cmmc
I wouldn't be surprised if we saw Rev 4 on the horizon in the next couple of years
The panel includes a former DCMA DIBCAC practitioner and a working lead CCA performing live assessments, giving it genuine practitioner credibility; however, all speakers are employees of the same vendor running a marketing webinar, which limits independent perspective and introduces promotional bias.
Pat Wicker, recent addition to the Redskin team, previously with DCMA dibcac
I'm a lead cca. Been with Redspin for a year and a half now. Deep in the trenches, performing assessments
There are credible specific data points - 1,391 certifications issued, the December 31 2030 post-quantum deadline, DFARS 7012 citations, and specific NIST requirement numbers - but many answers dissolve into vague assurances or referrals to future clarification rather than named examples, real timelines, or documented outcomes.
As of, you know, the May town hall, it was 1391 certs that had been issued
within the the announcement they actually put a deadline of December 31st of 2030 to where it either has to be imp in transition or legacy retired
The webinar format produces some genuine follow-through - letting Katie unmute to clarify her multi-tenant scenario was productive - but there is no meaningful pushback on any claim, multiple questions are deflected to offline conversations, and a notable portion of the runtime is consumed by social filler rather than substantive questioning.
Yeah, if you want to, if you want to come uh, on Mike and just chat about it a little bit.
should he take his wife out for steak or tacos? What do you guys think?
Computed from the transcript - who did the talking, and the words that came up most.
In this June edition of CMMC Connect, Redspin's assessors and consultants cut through the noise on the questions defense contractors are asking right now: Why November 10, 2026 is a phase milestone (not a drop dead deadline) What the re-released federal CUI rule signals about the shift to NIST 800 171 Rev 3 The new post quantum cryptography (PQC) strategy and its December 31, 2030 enforcement date What actually triggers a reassessment when AI/ML tools, M&A, or cloud changes hit your environment Multi-tenant organization (MTO) considerations across GCC High tenants The real rules for remote work and telework agreements. Plus a Canadian compliance scenario that exposes a lot of FedRAMP confusion. Hit play for real questions, real answers, zero LinkedIn doom scrolling required. CMMC Connect happens on the last Thursday of every month at 1 PM ET. Register for the series and submit questions here:
Transcribed and scored by The B2B Podcast Index.
Speaker A: Cyberspin.
Speaker B: Topics you care about by people you trust.
Speaker A: This is Cyberspin, the podcast that helps you navigate cmmc. And now for the show.
Speaker C: Well, hi, everyone, and thank you for joining us for our June edition of CMMC Connect. We're glad you could be here. It may still be June, but by the time we gather again next month, we'll have celebrated the Fourth of July. And this year marks America's 250th birthday. So we hope you have a safe and enjoyable holiday and get the chance to celebrate this historic milestone with your friends and your family. I'm, um, Monica Pastor, Senior Events Marketing Manager here at Redspin, and I'll be hosting today's session as we celebrate our nation's independence. It's also a reminder of the importance of protecting what matters, including the dib that supports our national security. So that's what CMMC Connect is all about. Bringing the community together each month to share practical insights, answer your questions, and help you stay ahead of the latest CMMC developments. It's. It's great to see so many familiar faces today. And if this is your first CMMC Connect, welcome, we're happy to have you. And thanks for spending part of your day with us. So, Jeremy, will you kick us off with introductions and then we'll go around the room?
Speaker A: Sure, absolutely. Uh, Jeremy Mares, VP of Federal Accounts here at Redspin and kind of head up our sales efforts for anyone I haven't had an opportunity to speak with in the past. And with that, I will pass the torch to Dr. Graham.
Speaker B: Dr. Thomas Graham, VP, CISO here at Radio Redspin. If you've been on, you know me. If you haven't been on, then I apologize up front, Aaron.
Speaker D: Well, thanks. Thanks, Thomas. My name is Aaron Freetag. I'm a lead cca. Been with Redspin for a year and a half now. Deep in the trenches, performing assessments, a little bit of consulting. But, uh, we're quickly building our team. And nice, uh, to see some fresh faces in today's CMMC Connect. Happy 250th USA.
Speaker E: Hey, everybody, it's Uncle Rob. If you notice Thomas's background, I tried to dress the same since, uh, it's the 2 50th. Welcome, everybody. Glad you could take time out of your busy schedules to join us. Over to Pat. I see you, Darium.
Speaker A: Pat, it's on you.
Speaker F: I got this stuff coming. Hey, thank you so much. Uh, Pat Wicker, recent addition to the Redskin team, previously with DCMA dibcac and honored and happy to be Here, over to you, Monica.
Speaker G: I'm.
Speaker C: Well, I am the senior Events Marketing Manager here at Redspin. Happy to help co host this session and I'll put you in the hands of Lauren now. Hey everyone, I'm Lauren Friggle, Marketing Marketing Director here at Redspin. All right, just a quick reminder that we are currently conducting our third annual CMMC survey and we need you and your response if we don't have it yet. The survey takes five minutes. It asks you about your CMMC readiness, the challenges you're facing, how you're managing compliance over time, lots of things. Also as, ah, something to highlight as a thank you, we donate $10 for every completed survey response to support veterans through the Gary Sinise. Yes, uh, that is Lieutenant Dan, the Gary Sinise Foundation. Once the survey closes here in another month or so, we'll analyze the results and publish our third annual CMMC report that'll go out later this year and share what we are seeing across the dib. Um, the survey link is in the chat, so if you have five minutes even while you're listening to today's session, please take it. Awesome. Thanks Lauren. Jeremy, over to you.
Speaker A: Okay, so we are going to start off with what we call some field updates. And uh, the first of these that we are going to touch on today is November 10th and the date that everybody is talking about. Some folks are, you know, climbing up on rooftops. Please step back from the ledge. I'm, um, going to do my best to debunk this a little bit for you. So there are a lot of people that are running around on social media and so on and so forth screaming about how November 10th is a deadline. November 10th is not a deadline. November 10th is a milestone that simply designates when the DoD will be moving from phase one to phase two of uh, the CMMC rollout. That is the date that they will begin. Including CMMC requirements in contracts, you do not need to demonstrate CMMC certification until time of award. And typically that would mean that if November 11, the Army Corps of Engineers issued a contract for bid that is likely not going to be awarded until sometime in early 2027. So there is some time and some flexibility there. I'm not saying anyone should take their foot off the gas and keep driving forward as quickly as they, but November 10 isn't exactly the deadline it's being made out to be. Now Jeremy, what if we have a prime and they're requiring it? Okay, that's another scenario. The prime contractors can require whatever contractual obligations that they wish to include. To their subs as private organizations. However, if you look at the graphic that we have here, this is based off of last month's cyber AB Town Hall. Uh, we haven't had June Cyber AB town Hall yet. That'll be taking place next week. And we'll obviously see these numbers increase a bit, but you can kind of see the pace at which they've been climbing over the last several months. As of, you know, the May town hall, it was 1391 certs that had been issued. If we map this out to November, the dirty little secret that nobody wants to talk about, but everybody recognizes is there will nowhere near be an entirely certified defense industrial base by November 10th. There are simply not enough individuals certified as assessors. There are not enough C3PAOs to certify everyone by November 10th. And not everyone is ready either. And everybody's working towards it, or hopefully working towards it, but not everybody is ready. And at that point yet, we have seen across the board with clients of ours who, who have engaged with us, and we have provided them an engagement letter or attestation letter kind of stating when their C3PAO dates are. Some of those dates are, you know, after November 10th, you know, December, January. Some of them are further out, uh, across the board. Those letters have been universally accepted both by program managers and contracting officers within the DoD agencies, as well as the primes. As everybody recognizes, not everyone is going to be able to be certified by November 10th. And this is going to spill over into next year. It's going to take time for everybody to get through this cycle the first time. And really all everyone wants to see is that you have a plan, it's in action, and you are moving towards certification. But, Monica, I will throw in. There is a tremendous amount of pressure everywhere, uh, within M. November 10th. So as far as November 10th goes, we all recognize everybody's pressing on everyone about it, everyone's pushing hard, saying that this is the date that you have to be certified by. But don't jump off of rooftops about this. There are ways to have conversations, you know, with the appropriate folks, and just as long as they see that you've got a plan of action in place and are driving towards a date, like we said, we have not seen anyone not accept that. So with that, I am going to step down from my soapbox and instead hand the soapbox over to Dr. Graham to talk to us about the federal CUI rule.
Speaker B: Why, no. So if, if you're not aware last year, I know since then you've heard Us mention periodically here on CMMC Connect about the federal CUI rule that come out as a proposed rule last fall. Since that time it's been questions of whether or not it's going to happen, especially with new DOD cio. We well guess what, it's been re released for public review. It's available now. So go take a look at it. And it's identifying the direction not only GSA, DoD and NASA is going to go for the protections of cui. It also has a lot of those elements in there that we've talked about, you know previously, such as still the standard form that identifies not only the types of cui but what is to be considered CUI in there. So it's. As long as it stays into the final version, it should provide some of that much needed clarification a lot of you guys have been asking for. With it being rereleased as uh, for public inspection, this is kind of foreshadowing that more than likely, and none of us here are government more than likely, it is going to be published as final by the end of the year. And that would be the first step in moving from Rev 2 to Rev 3 for the department. I uh, say the first step because of course you know there's other things that they'll have to do and go through the process on, but it is indicating where ultimately all of the federal government agencies are going to land and it looks like Rev3 for right now. The other thing that come out here just in the last day or two is the strategy to move to post quantum crypto for the department. Now normally here on CMMC Connect we stick directly to, to things related to CMMC and in the current ecosystem. The reason why we're mentioning this here is that one of the mechanisms that they're going to use to enforce the adoption of post quantum crypto is cmmc. It's actually identified in there. If you're not familiar with what post quantum crypto is, now is the time to start taking a look at it. Because within the the announcement they actually put a deadline of December 31st of 2030 to where it either has to be imp in transition or legacy retired. If it's in transition you have an additional year but want to be at least for the department the enforcement mechanism to make sure those systems are accounted for. The part. The other part to uh, to keep aware of is that as many of you know in the current version of 800171 it mentions the FIPS requirements. Well if there's going to be A specific post quantum requirement that's going to probably require another revision to 800171 so. So I wouldn't be surprised if we saw Rev 4 on the horizon in the next couple of years. If you haven't taken a look at these two, please do because they are going to be very very important in the very near future and I think that's enough. Varies Jeremy, Excellent.
Speaker A: Thank you as always Dr. Graham for your expert synopsis. Okay, so we are going to move on into the pre submitted questions of our cmmc. Connect this first question that was submitted considering material changes requiring a reassess and Arrow in the Q and A. I think this ties into what you were actually no, it's later so. But uh, considering material changes requiring a reassessment, at what point do we cross the line? The implementation guardrails to the explosion of wildly widely available AI slash ML based tools, the use of AI, uh agents, the implementation of vibe coding, etc. But this does tie to a question that Arrow had in the Q and A. Um, kind of asking also about. I'm um, scrolling back up to it so I can grab it real quick. Arrowhead asked, uh, you know, as far as what qualifies as a quote unquote significant change that it's still not entirely clear even with the most recent FAQs. So Aaron, I'm going to let you touch on initially here. Uh, you know, where AI comes into play and potentially triggering a reassessment for a significant change. And then if anyone else wants to chime in on the larger significant change topic, that would be great.
Speaker B: Yeah, absolutely.
Speaker D: So I'll, I'll take the first bite at this apple. Uh, anytime that you foresee some changes happening within your environment, that's something that you have to plan for well in advance, execute your risk management procedures and thoroughly investigate what this, what that does to the changes within the scope of your system. I've seen a couple of assessments so far where they did utilize AI ML tools, but you have to be cognizant of how it's processing, storing or transmitting CUI within your system. Is that AI ML tool completely in the cloud? Is it in a fedramp GCC high moderate environment? It should be if it's touching CUI or is it completely on premise within your CUI environment? Those are all big things to consider and uh, much like any other tool change outs within your system, the CMMC faq, I believe it's version five up to now it touches on that and the responsiveness ability of your, your high level organization. Your AO has to, has to think about those changes within that system. There, there may be an explosion of, of some of those tools being used. But like any normal change out for say you're, you're swapping one Endpoint agent for your from Windows Defender to something else, you know, that has to be evaluated and ultimately the, the responsibility goes on the incorporate that into their system for a reassessment. Dr. Graham, did you want to jump in on that one too? Sure.
Speaker B: At the end of the day folks understand. Yes. The FAQ information is out there. Did it provide more clarity? Yes. Did it provide the clarity we wanted? No. But right now the determination is based on the AO for your organization. I will tell you that the prevailing notion is a reassessment is required if there's any change to the scope of, of the environment. Now what that means is, well, if you switch from one NMSP to the other, would that necessitate potentially a reassessment? Possibly. Because think of this situation. You're going from a CMMC certified MSP to one that isn't certified. Or what if you switch your cloud storage from Microsoft to Amazon? Both of the, both of those organizations have Fedramp offerings but the Fedramp Inheritance or the implementation that shared Responsibility matrix may be different. So these are all things that have to be taken into consideration. I can also tell you this is something that's being worked on at the cyber AB level and hopefully in the near future. And I was hoping, because I've said this last month, I think too hopefully that clarification will be coming soon. I can't tell you a definitive date though, but if it was me, if I want to do cya, if it changes your scope, it's probably going to be something that would necessitate a reassessment right now.
Speaker A: And I know on this same topic, something that comes up pretty often is M and A activity and um, you know, within the div there's quite a bit of M and A and acquiring, you know, a new, maybe multiple small orgs that you're incorporating into your organization. These are typically going to bring in additional sites and that's going to expand your scope. So that's an area that we get a lot of questions about. Is this a significant change? If they're bringing in cage codes, that typically means you're going to need a reassessment. So these are definitely conversations that we can have specific to your org, um, and have larger discussions around and we'd be happy to schedule some time and talk, you know, your specifics. But, yes, significant change in what it means and when you need to get reassessed is definitely something we're all hoping for more clarity on. So, next question. What constitutes significant change, uh, that could trigger CMMC level two reassessment? I think we kind of blended into this one already and kind of already covered this one. But, uh, any final thoughts on significant change from anybody before we move to the next?
Speaker E: Just that you're affirming official is the one that really makes that determination. So, uh, again, it's left up to interpretation. Apologize. I'm coming out of this stuff. It's too hot. It's left up to interpretations so that you guys can determine it because you understand your networks better than the DoD does. So, you know, again, I don't know if they did that on purpose. I know the Cyber AB has a committee that is working to kind of clean that up for us. So unfortunately, we're stuck with it until that happens.
Speaker D: Okay.
Speaker A: A period of inactivity after which an identifier is disabled is defined as the quote, unquote statement there. Can compensating controls and procedures be used if a period of inactivity for regular users has not been defined? Dr. Graham, this one goes back to you.
Speaker B: So since the terminology of regular users has been. Is being used in the question, I'm just going to quantify this by saying I'm taking the perspective of. On your endpoints, and I'm going to flat out say it. No, you have to define what that period of inactivity is. And as a matter of fact, uh, when the transition to Rev3 happens, that ODP value, I believe, has already been defined by the department. Now, right now, is there a hard and fast number? No. Uh, for the most part, I've seen that a lot of organizations are kind of settling on 10 minutes. Some are five to align with DoD requirements or DoW requirements. But understand that when you define that period, it doesn't necessarily mean it for your entire organization or even your entire scope. There could be operational necessity requirements that would honestly require part of your environment to be one thing and part of your environment to be the other. I'll give you a perfect example. Let's say you're in a medical organization. Let's say it's a medical center. They have contracts with the government. Well, if you set it to 10 minutes, you probably don't want the surgeon in that operating room, you know, taking his hand, let's say, out of your chest every 10 minutes to move the mouse. So more than likely you have an operational necessity to, to extend that. And that's where those compensating controls and procedures would come in. Because if, let's say it's uh, 45 minutes, or let's say it's 60 minutes, whatever the case may be now keep that threshold of risk low. You can put other compensating controls and procedures in place. So that way you have a justifiable position once you go through assessment or heaven forbid anything actually occurs, such as an incident in your environment. But you still have to define it.
Speaker A: Not even sure how to respond to that example you gave. It was brilliant. That was really good, Thomas. Uh, so moving to the next question. Multi tenant organization, Microsoft mto. I'm looking to maybe use this between my GCC High tenants since users are the same pretty much between all three tenants. I don't want to run a follow of anything with CMMC if I were to pursue this. Wanted to know if anyone else has successfully implemented something like this. I'm going to tackle this one. We have not seen someone use this before in a gov cloud space with multiple GCC High tenants. We just haven't encountered it. I'm not saying that there isn't anyone out there who has done it, we just have a encountered it. But what we do see a lot of is folks leveraging either the Microsoft subscriptions and Azure DevOps and some of the other tools to segregate groups within one larger tenant into almost multiple sub tenants within the same overall GCC High tenant. There are a lot of effective ways to do that. Whoever submitted this question, I would love if we could have a separate conversation to really kind of dig a bit deeper into, you know, what prompted the path with the multiple GCC High tenants. Uh, you know, how it's really just kind of the same users across all three tenants and what each tenant's purpose kind of serves and I might be able to kind of, you know, provide some, some better insight into it. It's just simply a scenario that we haven't run into yet. But there's obviously a good use case for it if you guys are doing that. So I'd love to learn more about it if we can set something up so we can jump to the next one.
Speaker E: Monica, that was Katie. She dropped a note in the chat. I don't know if we want to unmute her and maybe.
Speaker A: Yeah, if you want to, if you want to come uh, on Mike and just chat about it a little bit.
Speaker E: You know Katie, when we first saw your question. If you can go back, Monica, when we first saw your question, we were like, what is she doing with 3 Cloud 10? That's a lot of money.
Speaker G: I know. Can you guys hear me?
Speaker E: Yes, ma'. Am.
Speaker G: Okay. They're. They're kind of sister companies to the same company, but they're separate cage codes. They're separate. They're separate. Right. But the fact is that we're sharing users between them. Um, right. Like. Like my CIO for this current company is CEO of, uh, that company. But they're all kind of the same. And so I don't know if I'm able to. I mean, they're separate. I don't have them purchased yet, but my intent was they're going to be separate GCCI tenants. They're most likely separate subscriptions for Azure Government. I don't know if I need to, though. Could they all run on one, but be separate tenants? And then in that case, is MTO going to kind of save my bacon in licensing costs? Right. Because they're the same people, but I want to make sure that our work is separate. Right. Because they are separate cage codes. We are separate, you know, uh, a. Testing separately in spurs and all the things. And so I'm, I'm, I haven't committed to it. I did ask Microsoft directly on the current GCC High tenant I have. Is this even possible between GCCI High tenants? And they said yes. You can't go from GCC High to GCC Moderate. Like, okay, that's fine. Like, I. All right, just forget that and go on. But, uh, I, I don't. I'm not saying I'm unique in, in this, in this endeavor, but like I said, we've got the same, like the core, same. Five people are from one to the next. It's just that they're separate cage codes. So I need to separate those, those environments for any CUI that might come in.
Speaker A: And that makes sense. And, uh, we were kind of wondering if it was, you know, something along, like joint ventures or, you know, something cage code related.
Speaker G: One is a joint venture for sure.
Speaker A: Okay.
Speaker G: And the other one is just plain separate. We market to separate contracts. Right. It's, uh, a, it's a veteran owned, you know, company. And so it's, it's a separate venture, it's not a joint venture, whereas the third one is a joint venture.
Speaker B: And.
Speaker E: Katie, are you in Minnesota? Are you a Minnesotan?
Speaker G: South Dakota.
Speaker E: South Dakota. Okay.
Speaker B: Yeah.
Speaker E: I think there's a rule out there in South Dakota. You can't have more than one cloud. So, Jeremy, you want to talk about that?
Speaker B: So, uh, but before Jeremy, Before Jeremy takes back over, Katie, I will let you know this. There is further guidance on how to properly handle joint ventures that's going to be forthcoming as well. I've seen the draft version of it. I think it's going to provide some of the clarity that, that you're looking for. It's just, unfortunately, it's not out in the larger ecosystem yet. So at least for the joint venture component, I would say take a look at that before you make any hard and fast decisions.
Speaker E: And also reach out to Jeremy. He can kind of, him and the cloud team can kind of work with you to help kind of get you in a right direction. You know, we've seen organizations out there that have multiple CAGE codes in one environment. Typically what they do in that cloud environment is segment that cloud and then give each of those CAGE codes their own little piece of it, if you will. But then the management is, you know, centralized to just one team because you're managing just one cloud. So there's definitely many ways you can tackle this. Obviously, cost savings has to be the number one thing in your mind, Katie, as you're starting to put this together. So, yeah, definitely, please reach out to Jeremy and have this conversation.
Speaker A: Yeah, Adrian. Adrian had dropped, uh, something in the chat, just kind of mentioning that, you know, his team has two environments, one for prod, one for dev. We see that a lot where, you know, somebody may have an Azure Gov cloud for their CUI environment for prod, but they've got something in AWS for dev. We've seen a lot of folks with GCC high clouds beginning to move to Azure DevOps and leveraging Azure DevOps within their GCC high environment. You know, the dev guys get access to the Azure DevOps region, whereas the other users are in more of the traditional cloud portion of the tenant. And then it looks like Scott mentioned something about, uh, having multiple companies under a single tenant. We see that a lot where there's like a parent. Org or somebody as the primary on the tenant. And then as Rob said, additional CAGE codes, additional entities. As long as everybody's essentially operating on, um, a single system, security, security plan and corporately defined policies and procedures that are the same across each, then you can essentially have everybody operating within the same cloud and just use, you know, sub tenants and seg and segmentation and such to kind of give each team its own space. Obviously, some users can be designated to have access to multiple, you know, portions or Segments. The catch is if everybody's not operating on a single SSP and, and everybody's not using all of the same corporately defined policies and procedures and such to where there's variances between the orgs, then I don't know how well the MTO component works in tandem with that. You know, that would take a little research on my part, uh, but I'm definitely happy to have follow up conversations on this, Katie.
Speaker G: Sounds good. Thank you.
Speaker F: Ah, I would offer just at a minimum, uh, you hit a key point with the system security plan. The 3.120 requirement speaks specifically to connections to external systems. So at a minimum you would just ensure that that external connection is reflected in the system security plan and addressed within the 3.120 requirement. Thanks.
Speaker E: And also to add on to Pats, uh, if there is any deviations between those three tenants. Right. For example, physical security requirements may be different at each one of those locations. You just call out each location in that particular objective and describe what each one is doing and that's how you kind of capture all that. Okay, I think we're ready. Monica. Sorry. This was a great question though, so thanks Katie, for submitting that. Appreciate it.
Speaker B: Yeah.
Speaker C: Ready.
Speaker A: Okay. What requirements and policies should you have in place for remote work? Do employees need to be on a separate WI FI network from the rest of their household? What about connecting to hotel WI fi while you're on business trips where WI fi passwords are often just last name and room number? This question comes up a lot in sales discussions. So Pat, this one's going your way and I am eager to hear your answer. And Greg on our team is very interested to hear it as well.
Speaker F: Hey, thank you, Jeremy. Uh, I'll give it a good, a good swing. So specific to your question, no, you don't need to require segregated VLAN or separate SSID on your home network. Although I, I would say that if you do have that implemented, let me just say that you are certainly on point exceeding the standard. Similarly, there aren't any prohibitions with regards to public WI FI or hotel wifi. Um, so having said that, let me step back, I think, and say, um, I think your question most, uh, closely relates to the 3106 requirement actually shows up in physical environment, but it talks about safeguarding measures at remote or alternate work sites. So at a minimum, you would want to ensure that you've implemented telework or remote work agreements. That telework agreement is going to extend the acceptable use expectations for your organization out to the employee that's at the remote site and to the company owned endpoint that's working from the remote site. You could potentially also include restrictions in this telework agreement like requirements for safe storage or requirements for minimum Internet gateway standards or no printing or something like that. And keep in mind actually that this is under the assumption that you've implemented a bunch of other requirements, CMMC Level 2 requirements that kind of all work together in order to achieve adequate security. So you still want to make considerations as if you're using that company owned endpoint. Do you have MFA enabled at the endpoint? Do you have, you know, do you have BitLocker enabled minimum encryption standards such as that? So consider all those things. The last thing that I'll mention is this. The NIST 800171 makes a reference to another publication. It's the 846, uh, Guide to Enterprise Telework Remote Access or BYOD Security. That will probably answer, uh, questions that you did not even know you had with regards to remote access.
Speaker E: Yeah, the other thing is, you know, when traveling, obviously many of the organizations are leveraging VPNs to provide that additional layer of security. So consider that. Remember that if you are going to leverage a vpn, you need to describe it in your documentation of when they are obligated to use it by requirement, whether it's optional for them or not. And then make sure you describe how they connect to it.
Speaker A: Okay, so we are going to jump into live Q and A. So anyone is definitely welcome to raise their hand unless their name is Rob Teague or Thomas Graham and then their raised hands will be ignored. But there is, there is a question from James, Derrick, Jeremy.
Speaker B: Before we get into that, just for clarification, earlier when we were talking about inactivity.
Speaker E: Yes.
Speaker B: Yeah. I had used an example of a session timeout. Yeah, uh, the question was concerning disablement. And Cyrus, I don't know if you saw my message, but I actually received replied in the CMMC connect chat for it. You still have to define what those parameters are. It could be 30 days, 60 days, 90 days, whatever. But just whatever it is, you have to justify what that threshold is. Understand Also, this doesn't mean deleting the accounts, it's just disabling them. And when you disable them, if it's a Windows environment, they sit in the dedicated OU for disabled accounts. And honestly they can stay there forever if you want them to. For example, you know, I took a year hiatus for my DOD days. You know, at one point. And when I came, all they did was reactivate my account and I still had email in there where people had been sending me email over that that year. I was gone, thinking I was still there and wondering why I wasn't responding to it. But you, you still have to define what that threshold is.
Speaker A: Yeah.
Speaker E: And that's why.
Speaker A: Thank you for the answer.
Speaker E: Yeah. Uh, Jeremy, if we can go to Patrick, uh, Cowling, he had a great question at the top of the hour.
Speaker A: Yeah. Uh, there was a couple of questions in the Q and A that I didn't see get addressed. So I just wanted to circle back on those. Uh, Aaron did respond a bit to Patrick, but it's definitely worth the conversation. He said, I am a Canadian RP. We are working with a USC 3 PAO who insists that having a US based cloud service provider that a CMMC level 2 and FedRamp standard is not enough. They want us to have a US llp. Org set up as well as Microsoft GCC high.
Speaker E: And that is a great, great question. Thomas, you want to take a stab first for Pat?
Speaker B: I haven't had enough to Dr. Yet today.
Speaker E: The only reason I threw it at you is because you've already assessed a uh, couple of the Canadian.
Speaker B: Yeah, I mean at the end of the day, requirements are requirements and Patrick, you know there was, there was, you know, a couple of things in, in your question. I guess I had questions on, I mean is it to the Fedramp standard or are they Fedramp authorized? Are they Fedramp equivalent? That's kind of maybe what that other C3PO was getting at. And that's because under DFARS 7012 if it's a true cloud service provider, then it has to be Fedramp moderate authorized or equivalent. Now being to a particular CMMC level as a cloud service provider, if it's a true cloud service provider, it's storing, processing or transmitting CUI FedRAMP is the requirement the CMMC level that would apply to any other types of external service providers. And there's no hard and fast requirement that they have to be CMMC certified. If they are work, it may make it a little bit easier, but there's no hard and fast on that. So I'm not sure if you wanted to clarify a little bit more, but that's what the requirements are. There's no, there's no requirement for you to set up any kind of llc Org in the US to get certified. You know, we've certified and assessed organizations in Canada. We've certified and assessed organizations in Europe. There's other, you know, contractors in other foreign nation states that are getting prepared to go through the requirements. So there, there's no hard and fast for a US llp. So I'm not sure if that answer helped.
Speaker A: Patrick dropped in the chat that uh, they are not accepting a US based cloud service provider. Who company is Fedramp Moderate?
Speaker E: Patrick, you are a brave man to throw your number on that chip.
Speaker G: Yeah,
Speaker E: we can reach out to you, brother.
Speaker B: Yeah, we'll, we'll definitely do that because yeah, there, there's no requirement to have a US LLP or specifically to get GCC High. The only requirement is that it's Fedramp Moderate or equivalent and that's under DFAR 7012.
Speaker F: I seem m to recall the philosophical debate I had had with you sometime in the past, Thomas, with regards to this. So, so keep in mind there is certainly, uh, a difference between the dfars, even the DFARS clause with regards to Fedramp Moderate and then C through g requirements for DFARS 7012 as well. You know, whereby the Fedramp Moderate is just going to require just that cloud service provider that's Fedramp Moderate authorized, uh, on the marketplace. Whereas the C through G requirement kind of encompass other duties as assigned to potentially include itar export controlled requirements that would necessitate a GCC High.
Speaker E: And that's why that, you know the conversation. And Pat, you're more than welcome to join us in the conversation if you want to come off mute. Yeah, so the main thing is that, you know.
Speaker B: There he is, Rob.
Speaker E: Okay. Hey, Pat, welcome.
Speaker A: Thank you. So I like, I told him, I said it's like going to a restaurant and being told I got to buy everything.
Speaker E: Yeah, you mean you don't, you don't
Speaker A: um, set up an LL stuff llp. You've got to uh, get Microsoft GCC High. And I said like, we're a Canadian company, we can't access GCC High. Oh, well, you've got to do all this and then you've got to meet about nine other requirements. And I said like the cloud service provider this company's working with, they're Fedramp Moderate. They're uh, CMMC level two registered. Don't know what more you're looking for.
Speaker E: No, that's a great point. And that's why, you know, there's a lot of confusion. And going back to the early days of joint surveillance when we did a lot of work with the dibcat, we ran into this not often because There wasn't too many overseas organizations really jumping in on the joint surveillance. I think it was focused on us. But there were some Canadian. I believe Canada was one of the first countries that the DIBCAC worked with on seeing if they could meet the requirements of cmmc. The main thing is, is if you look at Microsoft's, you know, kind of blog forum page, it says in order to get a GCC High tenant you must have a US based presence. But there's other cloud service providers, as you mentioned Patric, that are already Fedramp authorized. There's all kinds of Fedramp equivalent clouds that organizations can choose. So you don't necessarily have to use that and you certainly don't necessarily have to stand up a US based presence in order to uh, meet the requirements of cmmc. And that's why, you know, maybe a conversation with uh, with us on an, on, on a one, on one side we can get a little deeper into what they kind of told you and see if we can't kind of steer you in the right direction.
Speaker A: It is worth noting though that to obtain some of the quote unquote Gov clouds, Microsoft Oracle's US Defense cloud, you do need to have a legal US entity to put the cloud tenant under. So I don't know if that's maybe what they're talking about, but that is a factor. There was some of the govclouds, so yeah. And that there are some other questions we want to try to touch on.
Speaker E: Um, Patrick, we'll reach out to you buddy.
Speaker A: Yeah, definitely. And like Rob's a brave uh, man for.
Speaker B: You're on mute, Patrick. I see. Looks like you're trying to talk, but unfortunately you're on mute.
Speaker A: One question I do want to get in front of the group because this is probably going to be a greater and greater question as time goes by. James Darrell posted. Will GSA take the CMMC certification done for the dod last I read is that they will use their own auditors and not DoD. Meaning we would have to do another certification just for gsa. Have we heard anything about this?
Speaker B: Well, what's wrong with doing another certification? You want to do like 10 of them, right? So right now there's still conversations being had. The, the initial release was yes, there, there were differences in us honestly, specifically I think because GSA aligns with A2LA, that's a different accrediting body than the Cyber AB is and that could be part of the, the mindset currently. I do know that like I said there, there are conversations happening as far as where those conversations are going or anything of that nature. Unfortunately, again, none of us on this call are DoD anymore, so we are not a, uh, party to those discussions. It is something that we've actually asked the question on, um, from time to time when we're in front of certain individuals and we have no problems continuing to ask that question until we get a definitive answer.
Speaker E: Unfortunately, we don't have one now. Un pat, you've heard something internal within, you know, before you departed dibcac?
Speaker F: Not necessarily, but it's worthy to note that the FAR CUI rule has recently been released for comment. Uh, GSA is a, you know, I guess a co sponsor for that rule and if you consider that along with the fact that the GSA's recent IT security policy with regards to implementing security requirements, meeting those uh, standards seems to have been rescinded or disappeared from their website. But it's still early in consideration. I think about all we have to go on is the comment period for the FAR CUI report.
Speaker E: About all we got for you. Now I know that the PMO office was not happy about that release from GSA because it kind of went against everything that they had been working for and kind of putting in place. And uh, GSA just kind of of leapfrogged them and went right to a revision 3. So I'm sure they'll get it cleared out and I'm sure they'll, they'll get some information out to assume, I really don't know, that they would leverage their own assessors and do something differently that would just put a big, you know, kind of taxing the ecosystem we currently have because we don't even have enough assessors to get through CMMC ourselves.
Speaker A: So while we have a couple minutes, Caleb Blackburn had a question and, and Aaron kind of, you know, addressed it to a degree, but if we could have a larger discussion looking for that question as well.
Speaker B: I was actually typing in response to his follow up right now. Jeremy.
Speaker A: Okay,
Speaker B: yeah, so Caleb, with regards to inbound and outbound, you have to define what's essential, what's non essential and then provide evidence of how your control source and destination traffic flows and especially when it's coming inside and outside your environment. Most of the major VEN vendors, and I did drop a link in there for Microsoft, will identify what those ports, protocols and services are. Now if they don't, and if you contact them and they still won't, there are ways to see what, what traffic's coming in and out. I mean most modern firewalls can do it. You can use applications such as wireshark if you have to, but at the end of the day you as the organization have to define what is essential and what is non essential for your organization. And I uh, get you know what you're saying in, in the Q and A, but start with you know the, the major vendors for the, you know, some of the things you use like you know, Microsoft, I know I sent you the link for them. I know Adobe defines theirs and good luck with Adobe. But once you account for all of those, if it's just you know, some one off specific application, you may or may not get a concise answer back from the vendors and then that's where you know, seeing what is traversing your firewall comes into play. The word of caution I'll give you is that if you do this you are presuming that your environment has not been compromised because that's the same way behavior based, you know, threat, threat detection, EDRs, XDRs, when they're, when they're trying to identify malicious behavior, they benchmark against what normal traffic is. And that uh, benchmarking has you as the organization or even the administrator have to ensure or what you're benchmarking against 100% hasn't been compromised yet. So hopefully that provides a little bit of clarification for you. If not definitely happy to talk with you about it some more. Just you know, reach out to us and uh, we'll get on a call, get on teams or something and kind of step through some of those scenarios.
Speaker A: Thank you. Tom.
Speaker F: The deny all permit by exception requirement in 313.6 applies to both inbound and outbound communications. How you choose to implement that within the environment is up to you. Could be network, network based protections or your firewall or endpoint protection or even edr, xdr. But, but the requirement requirement applies to outbound communications as well.
Speaker E: So hopefully that helped.
Speaker C: We might have time for one last quick question. Jeremy, we have any, I didn't see
Speaker A: any in the Q and A that looked like they hadn't been tagged. Let me check the chat again.
Speaker D: What's the over under on uh, Rev 3 becoming a hard and fast requirement Over.
Speaker B: Yeah, well I mean the, yeah the, it's going to be over the federal CUI rule, the version that's out has it the other federal agencies are aligned into to Rev3 so it's, it's going to, you know, it's going to be a requirement.
Speaker E: David posted something about this earlier.
Speaker A: Yeah, if we're looking for an over under on um, like what month and year it becomes hard and fast. We could throw that out as a survey, but well, well, no, I actually
Speaker B: have a better idea for a survey. Guys, girls, whoever's joining in on this call you Mr. Rob T's anniversary. So tonight for dinner, should he take his wife out for steak or tacos? What do you guys think?
Speaker D: Steak tacos.
Speaker A: Yeah, there you go.
Speaker E: Steak tacos.
Speaker A: I'm not going vote. Uh, that we have multiple votes for tacos. We have a chicken vote, we have steak vote and we have steak tacos. And then the best answer. Whatever she wants.
Speaker E: That's right, Andrew. Happy wife, happy life, Andrew.
Speaker A: Um, damn right.
Speaker E: Uh, no, I appreciate that, guys.
Speaker D: Yes.
Speaker E: We are hitting 38 years today, so congratulations, sir. Thank you. Appreciate it. No, but this was a great connect, everybody. Thank you for joining us. One thing I do want you to, to kind of take back his homework for and, and circle back on our next connect is what is easier for you guys to do. White list or black list? Right, because we do get that question often. So think about that as you guys guys are muling things over onto the next CMFC connect. But we appreciate you joining us. So Monica, would you like to close us out for this session?
Speaker C: Yes. Thank you everyone for all your questions. We appreciate them and hopefully we answered all of them for today. I'm going to launch a quick poll right now to see if you'll be at, uh, any of these upcoming events that we'll be at. So, uh, on July 16th, we're teaming up with ZSCALER for a webinar answering, answering all of your CMMC questions and sharing practical strategies for strengthening your cybersecurity and compliance efforts. Efforts. And then later in July, Jeremy will be speaking at the AFS Foundry Industry 4.0 conference where he'll be discussing some different challenges facing advanced manufacturing. And then be sure to connect with us again on July 30th for our next CMMC Connect session. We'll have some special guests from Microsoft, so we hope that you'll join us there. In August, you'll find us attending the NDIA Space and Missile Defense Symposium in Huntsville and Navy Gold coast in San Diego where we'll have a booth. So please be sure to stop by if you'll be there. And then in September, Redspin is sponsoring and speaking at the CMMC in Practice forum on September 22nd. It's a newer event put on by the Cyber EF and Cyberbruise, so we'd love to see you there. And we'll also be exhibiting at the National Cyber Summit in Huntsville also that same week. And we'll also be hosting our fun networking event that we usually have. And this year's theme is celebrating America's 250 anniversary. So if you'll be there, we'd love to invite you. Um, so let us know. And with that, our time has come to an end. For today here at Redspin, we are here to help federal contractors move to a more secure, compliant, and resilient state to help protect the defense industrial base. Thank you for joining us today, and we'll see you next month on July 30th for our next CMMC Connect session. Take care, everybody, and have a Fun and Safe 4th of July.
Speaker A: Thanks for everybody.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.