
That CMMC Show · 2026-02-10 · 32 min
Key moments - from our scoring
Substance score
61 / 100
Five dimensions, 20 points each
This episode bridges technical and legal perspectives on CMMC implementation, featuring Dawn Stern from DLA Piper's government contracts practice. The discussion unpacks real-world contractual dilemmas facing defense contractors: whether organizations can claim perfect CMMC Level 2 compliance when they lack FedRAMP-authorized cloud environments, what penalties apply to incorrect SPRs scores (whether from ignorance or intent), and how deep prime contractors must enforce CMMC requirements down their supply chains. Stern, who spent 15 years at DLA Piper advising both government and contractors and previously worked as a trial attorney at the Department of Justice on government contracts cases, explains that the False Claims Act now serves as the government's primary enforcement mechanism - a significant shift from CMMC's original collaborative intent. She emphasizes that "knowingly" misrepresenting compliance includes reckless disregard and deliberate ignorance, meaning cursory self-assessment without proper documentation creates legal exposure. The episode also addresses how primes are increasingly mandating Level 2 certification as a condition of continued subcontract work, even for small businesses and set-asides, and explores whether workarounds exist for suppliers who provide non-CUI widgets or components.
Not without risk. You must be transparent with the government about the FedRAMP limitation in your proposals. Options include submitting a slightly lower score (109) to flag the issue, adding contractual language disclosing the limitation, or documenting internally why you cannot meet that requirement - simply submitting 110 while knowing you lack FedRAMP compliance exposes you to False Claims Act liability.
Liability depends on your diligence. The False Claims Act covers "knowing" misrepresentation, including reckless disregard and deliberate ignorance. If you spent minimal time scoring without proper documentation, you cannot easily claim ignorance. However, if you conducted reasonable diligence, documented your process, and can show good-faith effort, that provides a stronger legal defense if an error is discovered later.
No. CMMC compliance requirements flow down regardless of set-aside status - the clause is agnostic of company size or designation. Prime contractors are increasingly making Level 2 certification a condition of continued subcontract work, though some primes may work with smaller suppliers making genuine progress toward certification if their product is essential and no alternative source exists.
It should be someone one level removed from the day-to-day assessment - typically a CISO, VP, or president depending on company structure - rather than the person who conducted the assessment. This creates objective oversight and provides a stronger legal position if questions arise later about how the score was determined.
The False Claims Act, which comes with significant monetary penalties and potential criminal liability. This represents a shift from CMMC's original collaborative intent and means misrepresenting compliance carries serious legal consequences beyond contract termination.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode delivers substantive insights on real contractual ambiguities operators face (SPR scoring, FedRAMP gaps, False Claims Act enforcement, supply chain flowdown), but padded significantly with context-setting, personal introductions, and repeated restatement of questions. The core legal substance is concentrated in roughly half the runtime.
the False Claims act standard is a knowing standard. Um, so you do have to knowingly misrepresent. However, that knowingly category includes reckless disregard and deliberate ignorance
the CMMC puts in the prime's ambit of responsibility, the need for the prime to say, you know, it's like the Oprah, like, you get a car and you get a car, you're going to get cui
The framing of CMMC contractual issues is topical and addresses real practitioner pain points, but the underlying legal frameworks (False Claims Act, documentation standards, senior official sign-off) are standard government contracting practice. The originality lies in application to CMMC rather than novel legal theory or contrarian thinking.
document, document, document
CMMC is not an IT problem. CMMC is a company problem
Dawn Stern is a qualified, relevant guest with 15+ years in government contracts, prior DOJ litigation experience, and active CMMC advisory work at a major law firm. However, she is primarily a legal expert, not an operator who has built or scaled a defense business or navigated CMMC implementation at the ground level. Her perspective is institutional and counsel-focused rather than hands-on practitioner.
I co chair the government contracts practice at DLA Piper
prior to that um, was a trial attorney at the Department of Justice where I handle government uh, contracts cases on behalf of the government
The episode references concrete examples (Microsoft FedRAMP removal, 60,000-person contractor impact, Leidos/Elbit enforcement timelines, 800+ certifications) but most are mentioned in passing without deep detail. Legal guidance is largely principles-based (document well, be transparent, get legal counsel) rather than specific thresholds, case citations, or precise regulatory language. The SPR scoring problem is well-articulated but solutions remain vague.
Microsoft back in, I think it was October of 2024, ripped their FedRAMP authorization off their M365 commercial cloud
Leidos told them, if you're not certified by October, we're taking you off our list
Host Daniel asks pointed, well-framed questions that surface real dilemmas (SPR scoring paradoxes, FedRAMP timing gaps, significant change ambiguity) and gives the guest room to answer. However, follow-ups are often soft; when Guest gives non-answers or hedges ('it depends on company structure,' 'it's yet to be seen'), Host rarely pushes back. The conversation is collegial but not sufficiently adversarial to stress-test claims.
So when we're talking to organizations like either, a couple things will happen
what happens to imminent contract awards in between that? There's so many question marks there, right
Computed from the transcript - who did the talking, and the words that came up most.
Sit down with Daniel Akridge, CMMC CCP, Summit 7, while he talks with Dawn Stern, Global Co-Chair, Government Contracts Practice at DLA Piper. In episode 16 of That CMMC Show Daniel & Dawn discuss SPRS scores, CMMC & DFARS risks, supply chain flowdown, and more, be sure to listen in!
Transcribed and scored by The B2B Podcast Index.
Speaker A: Foreign
Speaker B: and welcome back to that CMMC show. Today we have another follow up to people's favorite topics and that is contracts and legal as it relates to cmmc. Now I have somebody who's been in the CMMC space even before it was CMMC is the DFAR space, the DFAR 7000, 7012 space. Dawn Stern is with me today. And Don, I'm so excited to get into some very pointed questions that I get asked all the time. I slept at a Holiday Inn Express, but I am not sadly a lawyer. So I'm going to pass things over to you to see if we can get some clarity around some of the contractual obligations of CMMC both as the prime receiving it and then what kind of flow down stuff we have to work with today work with as well. So dawn, first tell us a little about yourself.
Speaker A: Thanks so much for having me. I think it is super important to um, have the dialogue between the technical side and the legal side. So really appreciate you all having me today. Um, so, um, I co chair the government contracts practice at DLA Piper. DLA Piper is a large global law firm. We have 90 offices in over 40 countries around the world. Um, and our government contracts team, um, is also global. Um, our US government contracts team advises companies that does that do business with federal, state and local governments. Um, and so that is across all aspects of that relationship, whether it's negotiating contracts, negotiating teaming agreements, thinking about what your compliance obligations are all the way through government facing litigation and supply chain litigation. So um, really thinks about, look at looks. We look at things from all aspects and really help clients um, throughout the industry be thinking about what they need to do um, in order to be successful in their government contracts. You know, and government facing work. Um, me personally, I've been at the firm um about 15 years now. Um, and prior to that um, was a trial attorney at the Department of Justice where I handle government uh, contracts cases on behalf of the government. So I tell folks I've been on the dark side, you can pick which one that is. But I've advised companies and advised the government um, on all legal issues involving government contracts. My practice now is um, a lot of litigation against the government and also um, with respect to investigations, supply chain issues, um, and then have a, just a real personal interest and niche in advising clients on um, CMMC and cybersecurity. So hence our connection and really look forward to the discussion today.
Speaker B: And that that's. You say the dark side jokingly tell people all the time. It's like I was in it for 17 years I did the thing and then I switched the sales. But they already know what the dark side is there, right? It's like, oh, well, the sales is obviously the dark side. Right? But what's interesting is that you've seen it from every aspect, right? You're on both, both sides of the fence when it comes to contracts. And now because you've been in the CMMC and DFAR space for so long, like you've seen probably just about everything. Which leads me to, to some very pointed questions, Don, and I'm so happy you're here. Uh, preface. I am not a lawyer. She's not representing you. So these are just a conversation and questions that we're going to answer today to the best of our ability. So first up out of the gate, Don, this is a fun one. And this was one that somebody posed me a few weeks ago. I think you and I briefly talked about this before. So if I'm an organization and I meet all 110 controls and I have a perfect one 10 in SPRs based on the DoD assessment um, methodology, but I don't meet the Fedramp requirements as required by CMMC and I go to SPRs to enter my score for my CMMC level 2 self attestment. What score do I put in? Can I put a perfect 110? Because I'm technically meeting the control framework, but I'm not meeting the cloud. And there's no checkbox in spurs saying I have CUI only in FedRamp moderate or moderate equivalent clouds. I've had people wrestle with this because they're like, we don't want to lie, but we're not lying. We're, we're submitting all the options that we have in the system. So first question, I know it's, it's, it's a hard one in my opinion, but you probably can just cut through this immediately. So I'm going to turn the mic over to you.
Speaker A: Yeah, I, I agree with you. I mean, I think it is a hard question. Um, interestingly we had never heard this and then maybe like you in the last, I'd say six months or so we have gotten this question in a, a few different, um, iterations of it from different companies at different sizes. Some of it I, I think I can attribute to maybe some of the Fedramp cloud providers kind of changing, um, uh, their, what they are providing or how they deem their, um, you know, you know, the cloud. Um, and I think folks are just now realizing as they're getting closer to their CMMC assessments that this is kind of a separate requirement. So I don't really know what to attribute that uptick to. But I do find it interesting that you're hearing it and we've heard it a couple of times as well. Um, the best I can say is I think there's not a one size fits all answer. And I hate to kind of give that lawyer answer, but I think that's true. Um, what is important is that you are transparent with whatever representation it is. So where I think the problem comes in is if you tell the government we have 110 and you're submitting proposals that represent that you are fully compliant with 7012, um, that's where that misrepresentation can come in. So I've had some clients say, while not necessarily covered by one of the 110 controls, we are going to give ourselves 109, um, simply to give the government a heads up that there is something and if the government has questions they can ask. Um, I'd had other Companies take the 110 but put some type of representation in proposals when they think that makes sense. Just, um, can language that an attorney can help draft to put something in again to put the government on notice that this is something you're aware of, you're not misrepresenting it, um, you're working to fix it, whatever steps you're taking. Um, I've had others do poems, so it's internally documented that they're not meeting it and what they plan to do to fix it. So again, I don't think there's a one size fits all answer as to how you deal with it, but I think burying your head in the sand and pretending that everything is okay, even if you know that you're not meeting the Fedramp requirements, um, is where the problems can happen.
Speaker B: Yeah, I know Microsoft back in, I think it was October of 2024, ripped their FedRAMP authorization off their M365 commercial cloud. And I can't tell you the amount of people that were like, wait, we were compliant? Like, well, for Fedramp, sure. But there's also an incident response requirement in DFAR 7012 and. But that doesn't actually carry over to CMMC certifications, which is fascinating. That's the one part of 7012 that didn't make the jump over. And I asked the Cyber AB and they're like, yeah, that was intentional. It's like, oh, okay, that's interesting. Right. So, um, but then People are like, oh, I've been in commercial. I talked to a, uh, company not too long ago that was like, we're ready. We just want a gap assessment to figure out and just make sure that we're good to go. Like we have all the 110 controls. Like, oh, what cloud did you do it in? Like M365 commercial. And I was like, I'm so sorry. Like, I've got to be the bearer of bad news because they ripped that away about a year and a half ago and they're like, oh, no, I, one of the, the companies I talked to was about a 60,000 person defense contractor. And it uh, was just insane, right? I mean, tens of thousands of people and they were like, we've got to do this and fix this like immediately.
Speaker A: Right?
Speaker B: And so it's so interesting when people bring this up because it's not like Microsoft or any other cloud vendor just has, huh, sends you a text and say, oh, by the way, no more FedRamp.
Speaker A: Right?
Speaker B: And so people get caught off guard a little bit, which leads to, oh, I don't want to misrepresent myself. Now there's the other side of this, which is also a fun conversation, which is my next question that we get all the time, which is the penalty for posting an incorrect SPR score, even if you didn't know.
Speaker A: Right.
Speaker B: And the didn't know part is, is the interesting part. So when we're talking to organizations like either, a couple things will happen. One, the IT guy that submitted the SPR score is no longer there and they're wrestling to figure out how to update it. Right? Um, and so that's the other kind of big piece of it. Um, the outside of that, it's, oh, I just put a score because I just went down the 110 and checked yes, no, yes, no, yes, no. And that's how I got my score. Because when you look at scoring it, it doesn't actually, how do I say this? It doesn't do a good job of showing the assessment objectives. So unless you know something is happening, it's, you don't really know if you're scoring yourself correctly. Right? And so that's where the kind of, the confusion comes with a lot of people, they're like, oh, I went down the 110. It's like, yeah, but there's this thing called 171A and know you actually, you know, you didn't, you got four out of the five assessment objectives, but you fail the whole thing if you don't get all of them.
Speaker A: Right.
Speaker B: And so I think that was kind of the interesting part is like people just ignorance and didn't do the research on how to score. And then you have people that submitted an incorrect score, maybe intentionally. We've seen that with, you know, other cases previously where they were basically strong armed into posting a score that was perfect even though they knew it wasn't. So now that I'm done talking and explaining the question in, uh, more detail, Don, what happens if my organization submits an SPRs score that's incorrect? Either by me not knowing how to score myself appropriately or someone just intentionally did it wrong?
Speaker A: Yeah, I think, you know, those are two really different, um, different standards. Right. So because at the end of the day, and what we're seeing is the government has made no secret of the fact that they are using, um, the False Claims act to, um, review cybersecurity compliance and as a potential enforcement mechanism for failure to comply with the cybersecurity requirements. That's a shift. Right. Because when this all started, if we all remember when Katie Arrington first rolled out the idea of CMMC and we sat in conference rooms and we were all talking about what it was going to look like, it was a very kumbaya feeling. It was a, this is the government and us working together to protect the government's information and the stuff that really needs to be out of the hands of our adversaries. And I think that's right. And I think that feeling, um, that that goal is still there. I think everybody is still pulling in the same direction and recognizes that's why we need to do this. I mean, I, I don't think anybody's going to dispute we don't want this information, um, you know, in the hands of the wrong people. Um, but that kumbaya feeling isn't there anymore because now the government is using, um, the False Claims act as an enforcement mechanism and that comes with significant, um, monetary penalties. It can get into the criminal side. Right. So it's something now I think companies are more focused on and thinking about. Well, where is that line? The False Claims act standard is a knowing standard. Um, so you do have to knowingly misrepresent. However, that knowingly category includes reckless disregard and deliberate ignorance. So I buried my hand in my head in the sand. I didn't think about, um, what the standard really was. I spent five minutes and went down the 110 and went check, check, check, check, check. I meet them all and didn't actually take my time as either the legal side, the business side, or the IT side, to really think about what this is and what the scope is and what I'm doing generally, that's where, you know, you could, maybe there's plausible deniability, right? Maybe you could say, well, but I did it and I didn't know that it was wrong. Um, but, you know, at that point, that doesn't really work if you're not doing sufficient diligence in order to be able to say, here's why I didn't know it was wrong, or here's why I had a good faith reason for making the representation I did. That's where the risk can come. So if you are diligent, if you document the basis for your decision, if you go through and spend time, right, and you do it from a standard of somebody who is reasonable in that, with your knowledge and with your IT expertise and with the support that you have, that's generally an okay defense to. Well, I said we complied with this, but when I brought in Summit 7 or somebody else to do a gap assessment, um, we realized that we had just missed the mark a little bit. And because of X, Y and Z, um, that story makes a whole lot more sense than I spent five minutes and did. Check, check, check the box. And, um, and I, you know, then I quote, unquote, didn't know, obviously, if we're deliberately misrepresenting a score. Um, that certainly comes with False Claims act risk, breach, um, of contract, risk, I mean, you name it. Um, but the sort of closer to the line is where I tried to do my job and I just, you know, miffed on a control or whatever that's, um. Usually, um, with the help of counsel, you know, you can then figure out what happened. Um, the one thing I'll say in the narrative that you gave that I think is really important to highlight is the documentation part. Because, uh, as we all know, is not uncommon for your IT person to do the assessment. And then the, you know, you're looking at it two years later and saying, oh, goodness, Jim left. And we don't know why Jim marked us as compliant or not compliant. And we have no idea. So what's critical in all of that is really making sure that whoever is doing it is fully documenting why and what the rationale is. So that whether it's one year, two years, you know, somebody leaves, somebody gets sick, whatever the case is, um, we can be able to figure out what happened.
Speaker B: Now, I have a follow up to that, actually, because you just sparked something in my. In my brain DFAR 7012 and 7019. They don't really call out a senior official or who should submit the SPRs score. Uh, but CMMC has this thing, the senior official language in it where it's like, hey, we actually want somebody that has responsibility in the organization at a higher level to actually post and validate that. Yes. This is a score. From your experience, is that a specific type of role that you typically see? Is this a C suite? Is this a vp? What's a good maybe line to walk there from how you would deem what a senior official is?
Speaker A: Um, it depends on the company structure and I think companies are handling it differently. Smaller companies, um, we've seen are going up to the, you know, president level because that, who, that's who makes the most sense. Um, other companies are, you know, your CISO type, um, or perhaps somebody directly below the ciso, depending on the size of the company, who would have oversight and sort of personal knowledge of the assessment that was done. So I really think it depends. But it does need to be generally not the person who was responsible for the assessment. So it really does help to have that additional, you know, uh, the day to day management of it. Right. It really helps to have it sort of one person removed who can say, this isn't my baby. And so I was able to look at it objectively and m. Meet with them and understand what was done and why it was done. And so I feel really comfortable making that representation. Um, that additional letter layer of objectivity is just helpful if, you know, any of the things we talked about go south. And so, um, it, it again gives you a little bit more of a story. But that's not a, you know, one size fits all. You must do that. It's just good practice if it's possible.
Speaker B: Okay, now, now, now that we've kind of isolated the company level of SPR scores, this is a question that people didn't really honestly pay attention to in the DFAR. 7012 days at least didn't pay attention. Well, and that is our good friend Mr. M. Flowdown. So one of the things that CMMC has really, I'll say, agitated a lot of primes right now and a lot of them are taking good steps. So like we just had elbit on one of our other podcasts with Jacob and Jason and basically the interview was, hey, if you guys aren't certified, like, we're not going to use you, right? At some point in time. Um, I just got off the phone call with a small business, a 50 person small subcontractor. That said Leidos told them, if you're not certified by October, we're taking you off our list. Right. And so we're starting to see this narrative start coming out where it's like, oh, like not only do I have to be compliant, but I've got to look downstream, potentially multiple different tiers of suppliers and figure out how do I manage and enforce CMMC there or do I even have to do that? So the two questions I get all the time are, Daniel, what exactly is my requirement for CMMC and flowing down? How far am I responsible for? And the other question is, is there a world in which I don't have to flow this down to them? Right. So first question being, what's my level of responsibility and for how deep in the supply chain? Second one being, is there any way to get around? It basically is the summarized version of that. So what's your take on the CMMC contractual flow down language as it applies to both of those things?
Speaker A: Yeah, this is certainly an area. I think you're hearing it and we hear the same thing on the legal side. It is tough. Um, and cmmc, while in a lot of instances has taken a little bit of the, um, the risk from contractors because now you've got the C3PAO who's doing your assessment and there's a little bit of that, you know, the issue we were talking about, well, what if I put in a 110 and I didn't know that that risk goes down now because somebody else is going to tell you whether you have a 110. Right. Provided you give them the right information to put into the assessment. Um, but the supply chain risk is there and it's, and it's big and it's significant. And the reason is because of the dynamic down the supply chain, because the CMMC puts in the prime's ambit of responsibility, the need for the prime to say, you know, it's like the Oprah, like, you get a car and you get a car, you're going to get cui. You're going to get cui and you're going to get cui, right? And so all of you need to be level level two. And then you have that tension between the prime and the sub, because the sub over here says, wait a minute, all I make is widgets. It doesn't matter what you're putting it on, I don't need cui, I'm going to give you my widget and you're going to Put it in your little whatever you're building. And, and I don't need cui, so why am I level two and that tension starts and the government wants to look at you and say, not my problem. Right. That is, that is your prime problem. That is further complicated by the fact that as we have all experienced, the government doesn't really want, uh, to tell you what cui you are going to get. So it's a little bit of a whack, a mole. And at the very beginning of a contract, when oftentimes companies don't know where the contract performance is going to lead or what kind of information they're going to get and they're in a position then to decide who gets the cui, um, it becomes very complicated. Um, and so I think you're right. What we are seeing more and more are companies taking the position that they just want to get everybody in their supply chain to a level two. And if you're not willing to spend the money and effort and time that is needed, then perhaps they're going to look elsewhere. Yeah, um, in other instances there are primes that realize that they have a mom and pop widget maker and nobody else in the country makes this widget. And so they have to figure out a workaround with that company. Whether that is finding a way to keep that company at a level one or finding a way to share cui with that company only on the Primes level two system. Um, uh, you know, you've seen people, probably not the best practice, but moving toward paper documents. I mean, I've heard all kinds of stories of people finding, trying to find a way when that sub, um, is indispensable. Um, and so, you know, but, but as a business, if you are a smaller business and you are down the supply chain, the best thing you can do is start moving towards your level two. I think if you are doing that and you're making reasonable efforts and you are moving the needle, a lot of the primes, uh, still have patience for that. They understand that the line to get a certification is long and the wait is long. And so they're, they're able to work with you to find workarounds until you can get the certification. But if your answer is I'm not doing it, that's not for me, I don't want the Oprah car, then I think that those primes are starting like you said, more and more to say then, then we're going to find somebody else.
Speaker B: And that's what's interesting is like these you know, people are always like, daniel, but I'm a small business, I'm a set aside. I've got all of these. I'm veteran owned, I'm disabled, I'm minority, I'm. Women like you name the, the set aside list, right? And they're like, surely CMMC is not going to impact that because the DoD is obligated to fund a certain amount or that's their goals, to fund a certain amount of sba. And it's like, no, CMMC trumps set asides, right? And it's like, even as a blowdown requirement, if the data goes, the clause goes, right? And it's like, it's one of those things where it's like, it's agnostic of size, right? And that's hard because the burden of implementation and paying for a certification, I mean, some organizations could look even on the small side of hundreds of thousands of dollars over a multi year implementation and certification process. And so, um, it's always interesting to see that tension, right, of like, oh, can I get a get away with, you know, getting it on my system or give them a paper copy or something like that. Because everyone's trying to crack that code. Because I personally think, I mean we're looking at a pretty large consolidation of the supply chain in the defense space if, if it holds true the way that it's written. I could, I could imagine somewhere north of 40% deciding to exit maybe, maybe a little bit lower just because of the cost to do it. They're like, we'd rather go do our commercial work until of course, you know, far cui comes out and then they can't do any federal work at all. And we'll talk about that on another podcast episode because that's uh, an emerging thing all on its own. But so we've hit a few. Definitely Hot topics. I'm going to throw a more generic one out out at you. And we talked a little bit about False Claims Act. Are there any other contract contract risk people should be aware of as it relates to DFAR7012 and 7, 19 and 20 and CMMC, or is FCA kind of the really big one in the room?
Speaker A: Um, look, I mean, I think the threshold one is losing your contracts. So, you know, either because your, your primes don't want you if you're not level two, or you're not eligible for contracts if they're issued, you know, at a certain level. So that's the, the biggest risk and that's the one, you know, we all want to Avoid. So hopefully if we're listening to this, that's not where we are. Um, other than that, certainly false claims act like we've talked about, um, supply chain like we've talked about, I think. Um, you know, and then more M and more granular. When you're actually talking about the assessment, be really thinking about your scoping issues. So like I said before, right, it's, it's that that assessment is only as good as the information that you provide. And so if you are not scoping your system correctly for your CMMC assessment, if you're not thinking about what cui you get or how it flows through your system, um, all of those are risks. Um, we see a lot on the M and A context. So how do I identify risk if I am looking to acquire a new company? Or what do I need to do if I am going to be looking to sell my company in the near future? So all of those are things to be thinking about. Um, as you're thinking through your cyber compliance. Compliance.
Speaker B: I've got one follow up to that and it's uh, it's related to the M and A stuff.
Speaker A: So.
Speaker B: One of the most loosely defined terms in CMMC is significant change. The DoD threw out this significant change language where it's like significant architectural or boundary changes, expansions of networks and mergers and acquisitions. And that's the, that's the entirety of it. And they're like, hey, one of these things happens as a significant change, you got to go get recertified, right? Uh, what, what have you seen on the interpretation of like that, on the significant change or might be too early on in the process to really have seen that really come to light a lot because of, I think we're over 800 certifications, I think now. But, um. But what, what's your take on that from an M and A approach?
Speaker A: Yeah, it's a tough one. I, I think, you know, if you, in the near term, where we've seen clients going, is thinking about when your closing date is going to be, um, vis a vis your assessment, right? So if, you know, and this is, you know, all the more reason, yet another reason for why I get on my soapbox and say CMMC is not an IT problem. CMMC is a company problem and we, or company initiative, right? So we really need to be thinking about it with business folks in the room, legal in the room, management in the room, it. Everybody's gotta be on the same page. So, because your IT folks, huh, may not know that your leadership is contemplating some, you know, acquisition of another company. And your IT folks are now scheduling your CMMC assessment a month before the closing of that new acquisition. Well, maybe now we want to push that assessment out three months to allow the integration. So then we don't have the significant change question pop up within two months after we get, um, you know, our level two. Um, so I think that all needs to be thought of together. I do think you're right. It's yet to be seen. It seems a bit unmanageable to, um, for the AB to take the position that anytime there's an acquisition you need a new CMMC certification or CMMC assessment. Um, it seems, particularly with the waiting list they've got now, that's going to not be manageable in the long term. But I just don't think we know yet.
Speaker B: Yeah, it's going to be interesting to see what, what shakes out because you have to have a C3 PAO tie the cage code in EMASS in the background. So it's like if you have a new cage code, do you just wait? Like, what happens to performance of those contracts? What happens to imminent contract awards in between that? There's so many question marks there, right. That people are like, what do we do? And it's like, honestly, we don't quite have the playbook yet.
Speaker A: Right.
Speaker B: We don't really know. And I hope DoD has been issuing a lot of FAQ updates. I really hope that they clarify significant change a little bit more to maybe give a little bit more flexibility there. I have a feeling they'll probably over rotate and be more prescriptive in maybe a more negative light, uh, causing more harm than good. But, you know, we'll kind of wait and see there. But. All right, I got my last one. And ask everybody this. Yeah, I think we're going to have to really. And, and that's what our second episode will be about. Don. So, um, closing remarks. I ask everybody question. This is going to be the fun thing. This is the what's your favorite food all the way up to how do I stay out of jail? Right. So anything that you have in regards to something you like to share with the audience and the thousands of viewers that we get. Um, anything that just really strikes you as something you want to share with the audience here.
Speaker A: Yeah. Stay out of jail now or have wine and dark chocolate until we figure this all out. Um, I think those are all fair. And I'd say the last thing right. And we touched on this is document, document, document. Really make sure that you are writing down um, and accounting for the decisions you make, the representations you make, the assessment scope that you do, um, that documentation becomes critical. If there ever are questions from the government, it really is what we look to are those contemporaneous documentations, not some post hoc thing that you can then develop once you talk to a lawyer and you're under investigation. So make sure to document now and make sure to read your contracts now because there are still agency specific requirements, there are still command specific requirements, there are varying reporting requirements. So make sure you're, you're looking at those, you know what they are. Um, and, and that'll hopefully keep everybody on the right track.
Speaker B: I love it. Well Don, thank you so much for your time. This was an incredible episode. You answered a lot of the burning questions that I get asked all the time. And I just say go talk to Dawn. Right. So, um, Don, we'll hide your contact and LinkedIn in the, in the YouTube video here so people can reach out to you, um, if they have any actual contract questions and you obviously can, can have conversations and move forward from there. But thank you so much for joining. Uh, this was such a pleasure. I'm so happy to bring kind of the IT cyber world back in with legal right. And so I wish they would talk to each other more. I've been in so many calls where I feel like just a mediator just trying to build a bridge between those two teams because they don't understand what, what's a corporate risk there. Um, but you've just been such a breath of fresh air. Thank you for joining and uh, we'll look forward to the next episode.
Speaker A: Thanks Daniel. Appreciate you. And the whole team. Look forward to it.
Speaker B: Absolutely. All right, everybody, thanks for watching and make uh, sure to tune in the next one.
Speaker A: Mhm. It.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.