The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Marketing/Trust Issues
Trust Issues artwork

The CUI Scoping Mistake Blows Up CMMC Budgets

Trust Issues · 2026-08-26 · 45 min

0:00--:--

Key moments - from our scoring

Substance score

60 / 100

Five dimensions, 20 points each

Insight Density13 / 20
Originality11 / 20
Guest Caliber13 / 20
Specificity & Evidence14 / 20
Conversational Craft9 / 20

This episode tackles the pervasive 'CMMC cost fallacy' that conflates certification expenses with implementation costs. Speaker A, a registered practitioner with 30 years in defense contracting and prior work on tactical communications for the Missile Defense Agency and drone systems, breaks down the actual cost structure. CMMC certification itself runs $30-50k on average - comparable to ISO 27001 - but implementation under DFARS 7012 varies wildly depending on scoping decisions. The critical mistake contractors make is assuming CUI exists everywhere in their environment and therefore needs protection everywhere, when the real question should be: where *should* CUI be present? Common budget-exploding decisions include migrating to non-FedRamp systems (like Microsoft 365 Commercial), deploying CAD systems in unsecured clouds, and mishandling ITAR on endpoints. The episode unpacks why false self-attestations fail under third-party C3PO assessment, and contrasts NIST 800-171 (the implementation guide referenced by DFARS 7012) with NIST 800-171A (the assessor's guide CMMC uses). For SMBs and defense contractors navigating Phase 2 rollout and rumors of NIST 800-171 Revision 3 adoption, this explains where real costs hide and how proper scoping can reduce budgets from $1M+ to $100k.

Key takeaways

  • →The $300k - 600k CMMC cost myth conflates DFARS 7012 implementation expenses with CMMC certification, which averages only $30 - 50k - on par with ISO 27001 per year.
  • →Poor CUI scoping is the primary cost driver; contractors incorrectly assume CUI is omnipresent and protect everything rather than identifying where it actually should reside.
  • →Non-FedRamp systems like Microsoft 365 Commercial are instant package failures because one non-compliant system fails the entire CUI protection package.
  • →ITAR handling on uncontrolled endpoints (e.g., laptops abroad, exposed to foreign nationals) creates $1.2M-per-violation liability; virtual desktop deployment on FedRamp GovCloud mitigates this risk.
  • →CMMC certification uses NIST 800-171A (assessor's guide), not NIST 800-171 (implementation guide) - contractors confuse guidance on how assessors grade them with how to build compliance.

Topics in this episode

CUI (Controlled Unclassified Information)DFARS 7012CMMC (Cybersecurity Maturity Model Certification)ITAR (International Traffic in Arms Regulations)C3PAO (Certified Third-Party Assessment Organizations)NIST 800-171 and NIST 800-171AFedRamp and FedRamp GovCloudMicrosoft 365 CommercialCAD systems and PLM softwareScope Small Win Big (book)

Questions this episode answers

Why do contractors claim 100% CMMC readiness but fail C3PO assessment?

Self-grading inflates scores; the first red flags are usually non-FedRamp systems like Microsoft 365 Commercial or ITAR on uncontrolled endpoints, which contractors often overlook during self-assessment.

What's the difference between NIST 800-171 and NIST 800-171A?

NIST 800-171 is the implementation guide (what DFARS 7012 requires); NIST 800-171A is the assessor's guide (what CMMC uses to grade you). Contractors mistake the assessor's guide for implementation guidance.

How much does CMMC certification actually cost?

Third-party C3PO assessments average $30 - 50k per certification cycle, comparable to ISO 27001 (~$7 - 10k annually). Implementation costs under DFARS 7012 vary wildly based on scoping and system architecture.

What makes CAD systems and ERP a CMMC cost problem?

CAD systems storing ITAR or CUI in cloud environments (non-FedRamp) force either costly migrations to compliant infrastructure or system redesigns to isolate CUI, often adding six figures to budgets.

Does the DoD care if my systems are down or unavailable?

No. CMMC and DFARS 7012 focus on confidentiality of CUI only (the 'C' in CIA triad), not availability or integrity; system resiliency is the contractor's business problem, not DoD's.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

13 / 20

The episode delivers a solid cluster of actionable insights - the DFARS 7012 vs. CMMC cost distinction, SPRS submission mechanics, FedRamp 20x timelines, and the 7025 solicitation provision teeth - but loses density to a lengthy biographical intro, repeated book plugs, and the cost-fallacy theme being restated several times rather than developed further.

just 1 minus 3 disabled the button. Just 1 negative 5 being marked open, disabled the submit button. Being under a score of 88, disabled the submit button. I tested all of those features out
CMMC 5k to 17k, ISO 7k to 10k, are they right on par with each other? Yes. So is this a CMMC cost fallacy? Yes

Originality

11 / 20

The central reframe - that the $300K - $600K CMMC cost figure conflates DFARS 7012 implementation with actual CMMC certification - is a genuinely clarifying distinction that circulates less widely than it should. Most supporting points (CIA triad basics, scoping advice, self-attestation gaming) are conventional compliance guidance repeated in many CMMC discussions.

this cost fallacy of CMMC costs between 300k to 600k for the average defense contractor is ignoring the fact that the implementation costs, uh, are where the costs lie
what they are worried about on the CIA triad is not integrity, is not availability. It's purely confidentiality.

Guest Caliber

13 / 20

Speaker A is a credible working practitioner with 22+ years in defense contracting, Missile Defense Agency and UAS program experience, and active RPO client work - not a career podcast guest or abstract thought leader. She stops short of the senior-DoD-official or prime-contractor-executive tier that would push the score higher.

I actually worked on tactical communication systems for the US Government. I was a tactical communications engineer. I led teams of professionals for working with the Missile Defense Agency, working with pm, uas
I've seen the lowest B9K. I threw it out as an aberration because it's really hard to find a lot of people at charge 9k. But 16k is kind of the next quotation I've seen. Average is 30 to 50k.

Specificity & Evidence

14 / 20

The episode is notably concrete for compliance content: exact SPRS thresholds (88 minimum, no negative fives or threes) verified by personal testing, C3PAO cost ranges ($9K - $50K, host-confirmed ~$40K average), ITAR per-violation costs ($1.2M, RTX case starting at $1B), a named $1M PLM migration failure, and FedRamp 20x approval timelines (30 - 90 days vs. two years under JAB). Named primes (L3Harris, Elbit) and specific clauses (7021, 7025) further anchor the discussion.

just 1 minus 3 disabled the button. Just 1 negative 5 being marked open, disabled the submit button. Being under a score of 88, disabled the submit button.
they probably spent a million dollars migrating to this new PLM um software and it will cause their entire package to fail

Conversational Craft

9 / 20

The host rarely probes or challenges - frequently affirming rather than pushing - which reduces the episode to a largely uninterrupted guest monologue with occasional co-sign commentary. The opening question is serviceable but generic, and the closing ask is a soft invitation for a prepared summary rather than any attempt to surface tension or test a claim.

I second and triple. Second your.
What would be your final word? What would you want our listener to get? If there's one fee you would like them to do, what would it be?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker A85%
  • Speaker B15%

Most-used words

cmmc42cost31first24clients21implementation21system20systems19defense18back16costs15security14fedramp13industry13phase13score13government11

Episode notes

A lot of contractors hear “CMMC” and immediately think of a six-figure bill. According to Christina Reynolds, that’s the wrong place to start. In this episode of Trust Issues, Bruno Lecoq speaks with Christina Reynolds, Registered Practitioner Organization leader and author of Scope Small, Win Big, about where CMMC costs really come from. Her point is clear: certification is not usually the cost problem. Bad implementation decisions are.

Full transcript

45 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: I had one client that invested in a brand new PLM software, interfaces with their CAD systems, stores their designs. Well, the salesman told them it was compliant and they are not Fedramp. So I had to give them the bad news. They probably spent a million dollars migrating to this new PLM software and it will cause their entire package to fail. And there's no way to extricate CUI out of that environment. So is a failure point.

Speaker B: Welcome to Trust Issue by Demo, the podcast where we go beyond checkbox compliance and all about security. In every episode, we will break down what's happening in the world of cmmc, cybersecurity and grc. Straight from the people building auditing and living it. Real conversation about real security,

Speaker A: defense contracting. I remember, you know, it was my mother who was the original CEO of the company, and she would show me a list of things she had to do just to maintain her status with the US Government in a favorable state. Right? And it was a list of easily 15 things between registering on SAM, uh, having an approved accounting system, making sure that you could qualify for your bids, making sure that you had a cage code, making sure that for, uh, entities like gsa, you were reporting accurately your costs and paying your fees. You know, there was always one more step in the ladder that as a small business, you had to undertake just to do business with the federal government and in particular the Department of Defense. And for those of us who have served and of most of those 30 years that you mentioned. I know, I know I don't look like it. I actually worked on tactical communication systems for the US Government. I was a tactical communications engineer. I led teams of professionals for working with the Missile Defense Agency, working with pm, uas, and working with basically all of the drone systems we see fly in the sky today. Uh, we had teams of engineers working on each one of them. So, you know, looking at how our defense system needs to operate and understanding that large businesses and small businesses alike are the backbone of supporting this really brought about an understanding of who we were supporting. And that's the war fighter. And, you know, understanding that our mission above all else is to support the warfighter in their mission. I have a husband who served in the Air Force. My father served in the Air Force. I served as a contractor for 22 years, supporting, uh, U.S. army, U.S. navy. So when you see the real impact of the work we do, you understand the ultimate cost and what it is we are protecting.

Speaker B: Based on that, from your perspective, what is, do you think, a misconception about CMMC cost Today.

Speaker A: And I'd like to bring up some slides, if you'd let me, because I think I'm always, uh, a person. I always say I like to talk with pictures, and I like to have a lot of pictures when I talk. First and foremost, when we start talking about the CMMC cost fallacy, what we know there's been a new transition, new DOD cio. We know previously Katie Arrington had led the charge, um, for almost 10 years of really building the program and understanding the pain points of our defense systems and watching as our nation's defense secrets were exfiltrated to foreign nation states. And when we see duplicates of our own planes and our own drones flying in China's airspace, we kind of get an impression of what it is we are securing. Now, cui, from its initial conception, is not necessarily classified information. Right? But when I talk to my clients, I say, let's say you have a sheet of paper that's marked secret and it's classified, but you fed that through the shredder and you just handed everybody in this room a shred of that paper. That shred in and of itself isn't going to reveal much about the classified picture it could form. But if everybody in the room got back together and tape their shreds together, what would have been a strip of cui, class, uh, controlled, unclassified information now becomes a secret picture because you aggregated the information. And that's the best way, I like to convey the dangers that improperly handled CUI poses to our classified information as a whole. Because enough CUI aggregated can become classified information. Um, in and of itself, a lot of our defense, um, uh, products and services that we support, um, can be labeled itar. ITAR is a subcategory of cui. So first and foremost, understanding where this all came from is top secret, number one. Right? So what we heard with the transition to the latest DOD CIO was a lot of older misconceptions that need to be busted, which was cmmc. Now let's go back and define what CMMC is. Cybersecurity Maturity Model. What is that last C? It's certification. CMMC doesn't tell you to do it. All CMMC tells you is you've got to go seek an independent party that's been properly trained to certify you. And Those are the C3PAOs. Let's take on, you know, kind of the first slide. What does CMMC actually cover? So we see on the right here, implementation and readiness is not what it covers. It actually covers everything that comes beyond that, which is assessment and validation. And so this cost fallacy of CMMC costs between 300k to 600k for the average defense contractor is ignoring the fact that the implementation costs, uh, are where the costs lie. Where do the implementation costs actually derive from? Well, everybody's conflated the word CMMC because it's so easy to say with our original requirement that dates all the way back to 2014 was as early as I started really working with it, which is DFARS 7012. Now the biggest question we have, especially in what the DoD has recently issued, which by the way, is the third time we have asked industry questions about how CMMC is affecting them. And, and the first two times are well documented, by the way. So the 32 CFR, when it was posted, I think they had over 800, um, comments from industry and they very diligently went through each one and have a very thorough explanation. One of the biggest things was the economic cost analysis of cmmc. And one of the very first things they addressed in that is we will not address the implementation costs because that is already addressed under a whole different clause because it is DFAR 7012 that tells you to do it. So I like to refer to it as the implementation clause. That's the thou shalt implement NIST 800 171A, uh, class deviation locked it into revision two because they had already locked in CMMC the assessment requirement into revision two. So they made the match. Right. So now that we've got both, you need to understand where the costs lie. So let's look at those costs. Where does the money actually go? We advise our clients as a registered practitioner organization and we love sitting on the RPO side. By the way, could we have gone down the C3PO route? Yes, but everybody on my team, what we do really well is we advise our clients everything on the left and everything on the right, so we work through with them. We what are your actual costs for implementation? And it varies widely. Right, so this like we're going to reach out of thin air and grab a cost for implementation. Well, first of all, that's going to be under your DFAR7012. So are we questioning that in the current CMMC phase two. Pause. No, we are not. They're questioning the costs of cmmc. So that's what I want to address first and foremost. So on the left, cost of security, and look at all these things you have to do under DFAR 7012. It's implement the security measures. Now, I want to give you a little primer on how the DoD works because we also heard through some meetings, uh, that were occurring at the top levels of the DoD CIO's office that again, misconstruing what it is the DoD is trying to protect. Now, when the DoD issues you a contract, what they are saying when they put DFARS 7012 in your contract is there's three things we worry about in cybersecurity and specifically in the DOD when we handle classified information and unclassified information. That is the CIA triad. But they aren't concerned about your particular like resiliency. Right? Those are your systems. Unless you operate a system on behalf of the DoD, only then are they concerned about resiliency. If it's a system M that needs to be up all the time. So we heard a misconception that they weren't really interested in resiliency. Well, the DoD is saying we are providing you controlled, unclassified information. This is unclassified information that needs to be controlled. Otherwise it wouldn't have the word controlled in front of it. That being said, what they are worried about on the CIA triad is not integrity, is not availability. It's purely confidentiality. And so what you see applied, that kind of goes down this chain of the cost of security is how do we enforce you as the defense contractor to protect that very first thing, which is the C on the CIA triad, which is our data is flowing through your system. So show us that that data is protected to protect its c. Its confidentiality. So, you know, another myth we had to bust is we heard, well, why aren't you, as the defense industrial base, worried about system resiliency? Well, that's the company's problem. Sorry. The DoD doesn't care if your systems are up or down. What they do care about is that your systems are secured. So. So resiliency is the organization's problem, not the DoD's problem. The DoD is strictly stating where does our sensitive data flow and how are you protecting that. Now, what they don't tell you, which is very interesting, is how are you going to protect that data? And what parts of your architecture is that data flowing through? They leave that for you to decide. So when we look at the cost of security, parentheses the implementation on the left under DFARS 7012, that depends on you. So I always think about city slickers when they say, what's the secret to life? And Curly lifts one finger up and he said this and he goes, what your Finger. And he goes, no, one thing. And they say, well, what is it? And he goes, that's what you have to figure out. Same thing applies here. Where do you need to protect cui? That's what you need to figure out. But don't assume, and this is the first thing I have to bust with my clients, that it is everything everywhere and omnipresent on every system in your environment. First you ask where is it present? But the second question you need to ask is should it be present on that system? And that's the question people don't really ask when they first engage with us. They assume because CUI is currently present in every system in their environment, or they assume it is, that they need to bring every system up to that level. This is where the cost can get overblown. I recently wrote a whole book, you can look it up on Amazon. It's Scope Small, Win big. And it's just about this whole cost of not CMMC, but implementation and making the right decision so that you're not in the $1 million category, maybe you're in the 100k and you can keep it cost reasonable for implementation. So let's bust the second side of that cost of certification. So I have worked with many C3POs. It's the tail end of our job is to write our clients documentation package, help them with their strategy and their implementation side, write that package and then we walk them across the finish line to the C3PO. We have seen C3POs charge anything. I've seen the lowest B9K. I threw it out as an aberration because it's really hard to find a lot of people at charge 9k. But 16k is kind of the next quotation I've seen. Average is 30 to 50k.

Speaker B: And it's because I would say it's what we see about 40k on average from the people we work with.

Speaker A: Yes, yes. And it's because the people who do these assessments, like ourselves, you have to be an expert in nearly everything to assess these systems. You have no idea the type of people that we definitely have to recruit, that the C3POs have to recruit, that have to know not only on premise systems and everything under the sun, cloud systems and everything under the sun to be able to properly assess it. Their time, their expertise is really honed and really developed. These people aren't coming from nothing. They're coming generally from M people like me, from working in the DoD and doing assessments. And those are my people. So when we look at this, let's look at comparisons. Right? Let's just take ISO 27001. What are the requirements for ISO? Okay, every three years you get your certificate, do some manual surveillance. Right? Right on par with CMMC level 2. So the certification, if you average it out per year, CMMC 5k to 17k, ISO 7k to 10k, are they right on par with each other? Yes. So is this a CMMC cost fallacy? Yes, it's a cost fallacy because everybody's conflating having to secure their systems to whatever level they have decided to secure CUI residing within their systems. And that is a decision point with actually getting the endpoint attestation certification by a third party who has said we have verified your claims of security and found them to either be truthful or maybe not as perfect as you thought they were and they get kickback. Right? Try again. Try, try again. We're not discouraging you. You can do this a second time, but you have to do it right.

Speaker B: What's interesting for Jeremy and Ian, we talked to, you know, from our perspective again, we secure environment before C3PO will go check and very often we'll talk. Customer will come to us and say hey, uh, I self attested 110 out of 110. Oh great, well, okay, should be a piece of cake. And then uh, of course you open the hood and you're like no, uh, way, no way. You are minus something. And I think for me this is kind of on one side the biggest disappointment. What I never know is because I think you have some people that are truly doing an honest mistake, okay? They will swear they do it and they truly believe they are ready and you're the one that they know they cheat the system. And I think this is the one I have less patient about it because I think it goes back to what you said at the beginning. At the end, they are not here for the mission. They are just here to put, you know, I would say money in their pocket. They don't see that they must have been hacked 20 times over.

Speaker A: You know, and I think for me,

Speaker B: I uh, love CMMC M for that. That it at least now someone is shaking their work.

Speaker A: And that's the whole premise here and much to your point, and you make a great point because it leads into something I tell my clients all the time is I say it's very interesting that when you let grade school students grade their own test, they all achieve 100 somehow. But when you have the teacher grade their test, usually there's a different story to be told. And some of this is really not to be blamed on the defense contractor. There's a lot behind the scenes they're just not aware of. So, for example, the first question I ask when a client tells me they're 110, the first question I'm going to ask them is, are you on Microsoft Commercial Office 365? Because that's my litmus test, right? It's not compliant. Right. So when we look at Microsoft Office 365, and this is per Microsoft, by the way, like I always say, you know, don't blame the messenger. This is not my product. We look at what is approved in the Microsoft cloud and we all reference the famous Richard Wakeman chart that he provides us. I've just summarized it here. But the minute you say we're in Microsoft Office 365 commercial, it's an instant package failure. And why? Because non Fedramp systems cause your whole package to fail. So that's usually the first piece of bad news I have to give my clients is we have customers.

Speaker B: Same thing. We ask the first question that there is, oh, I have ita. And you're like, itar commercial. That's it.

Speaker A: That's usually the second question I ask is if you're aerospace and defense manufacturer. I always say ITAR and ERP Systems are the bane of my existence right now. Because first of all, itar, you register with the ddtc, there are fines involved if you have exposure to foreign nationals or that data gets on foreign soil. There are a few pretty famous ITAR violations cases. There's a Boeing one, there's an rtr. I do like to use the RTX one because it really exemplifies where things can go wrong to my clients. For instance, in that case, one of their employees went to visit his good friend in Russia with his work laptop, which had defense articles on it. And so one can assume that once he took just the laptop because the defense articles weren't on a virtual machine. Right. They were residing on the endpoint device. The minute he walked that endpoint device off the plane, every single file on there that was marked as ITAR was a violation because now it was on foreign soil just by the sheer fact that he stepped off a plane, Right. If he'd opened it in front of his girlfriend who's, uh, a foreign national. Right. Additional violations, and Every violation is $1.2 million. And it adds up pretty quickly. That case alone started at a 1 billion with a B dollar fine. It got whittled down because I assume Raytheon has really good lawyers. So. But it was a lesson to my clients and why we typically put their deployment in a virtual desktop because then the data is always residing on US soil and we can make sure that it is residing on a FedRamp govcloud US soil and the rest is up to you. I always say if you're going to open that window in front of a foreign national, train your personnel better. But itar, as you can see from the ITAR nuclear, you see that the first two under the Azure commercial, Microsoft 365 commercial, Microsoft GCC, those are flat out no's. So if we have a client where they are a uh, defense and especially a manufacturer, we already know inherently they probably are rife with itar. I've had discussions with clients who swore up and down they had no ITAR on their foreign operations side. By the time we start asking lawyers to come on the call, we already know what the truth is. And that is really, really important, is that you start with the highest level of data aggregation because that's what you're securing to, that's what you're assuming is throughout your systems and that's what you have to build to. And that, that's what brings us back to that cost fallacy is no two contractors are alike. No two contractors have the same data sets, the same requirements. And so what I always tell my clients is for that implementation cost, you need to scope and you need to scope first. And like I bring it back to scope small, win big, right. Title of my book, make sure that when they are looking at their costs, they can choose how small they want to make their enclave with some choices being unavoidable for them. Right. The second question I'll ask them is, do you have CAD systems in scope? Because that's usually where, you know, you make a lot of decisions very quick.

Speaker B: And CAD systems, which CAD system are you using?

Speaker A: Which CAD system, um, are you using it in the cloud? Because now we're talking about, you know, are we handling CUI within a system that's going to be a CUI asset or a uh, system that could be a crma, right? And these discussions in scoping become the first touch point for all of our clients. So when we talk about the cost for cmmc, your cost for certification is going to be pretty much like you said, an average price point.

Speaker B: But to your point we go back to the same conversation, the customer, wow, CMMC is going to cost me a lot. And it's Always. This has nothing to do with cmmc. This is your default first.

Speaker A: Exactly. And none of that, by the way, with this RFI, this request for industry comment DFAR7012, while there is references to implementation costs, again, this is the CMMC cost fallacy that they're confusing. And uh, let's go back. What did the 32 CFR that instantiated the CMMC program do? If you actually read through it, and I sincerely hope that Everybody in the DOD CIO's office right now actually reads through the 32 CFR, it puts together the rules for assessments for the assessors, right? Look through it, read it, read the industry comments, read the DOD's initial, very thorough, very thoughtful answers to that. Because implementation is never really mentioned. It's about how do you perform an assessment. Right? And so it's the difference from what we see behind the scenes. NIST does a great job in outlying their frameworks. And there's two things you need to read, right? Whether you're in a classified system and you're handling NIST853 or you're in an unclassified system, the implementation guide is your set. You know, 800171 revision two, revision three. Right? Then there's an A version. When you take the same number NIST 800171 and you put the A behind it, what is that? That's the Assessor's Guide. CMMC references the Assessor's Guide because it's all about how do the assessments work, how do the assessors grade you? What scoring metric do they use to grade you? That's the secondary NIST 800171 revision 2A. The actual implementation guide, which is what DFARS 7012 refers to, is NIST 800 171, the standard revision 2 version, right? That tells you how to implement it. And so what people get confused is they read the guidance for CMMC which tells you what are we looking for to grade you? And they think it's an implementation guide. It is not. It's an assessor's guide. Read the COVID sheet. It's an assessor's guide and it really is. Do we let you grade your own test? Well, we know from the sheer number of false claims acts, people who grade their own tests don't do a great job grading their own tests. Right? So CMMC is all about let the teacher do it.

Speaker B: Yes. So I have a question for you because I feel like for me right now they're almost like a double message because you can see Red 3 is on its way. Okay. Which means more control and, um, you know, at when the computing is coming, you will have to protect against that. So if I look at, from a business perspective, if I want my IT system being secure, the costs are going to go up. Yep. You can avoid it. And on the other side, we are kind of saying it's starting to be too expensive for SMB. And so I just feel like there is kind of. I, uh, am on the other side. I am a small business. Okay. Which direction are we going?

Speaker A: Right. And you know, at this point we can see the trends. We know that GSA put out some security guidance at the beginning of this year. Quite frankly, that was all over the map. If you could tell me what it looked like when I read through it, it looked like a mixture of 800, 171, 853, maybe some RMF thrown in for good measure. It really felt much more like what we do for classified systems. So knowing that there's three stakeholders for the FAR proposed rule means that we know that one of those stakeholders is gsa. So because what they wrote in their security guidance was a NIST 800171 Rev 3, we actually know who's pushing this. And, and I in m my glass crystal ball prognostication, it's GSA pushing the revision 3. So this gives industry pause, right? Hey, I'm a DoD contractor too, not just the federal contractor. I've been working hard. Because you said you were going to lock in revision two, four phase rollout four years, you locked it in. Right. So now what we're seeing is a, uh, shift in a movement to what if the federal government comes along and instead of knowing that DoD was one of the three stakeholders, DoD, GSA, NASA, of this new far proposed rule, why didn't they just say, hey, let's stick with Rev 2 through the end of the DoD rollout? Well, a few things can happen. Number one, and this is what I hope really happens, reciprocity. And so I hope they acknowledge that the DOD at being one of the stakeholders has been on this road longer than any they made this road, right? They've paid their dues, they've done their research, they've listened to industry. We've been on this road a long time. So I would love to see the federal government come in and say, and hopefully industry, if you're listening, when they put out a proposed rule, that is your time to comment and to say, this is what we want to see. They listen, right? That's what they put it out for comment for is to say, we've been on this road, we got our certification under the DoD allow reciprocity so that if we have a federal contract with this new FAR clause come out and say you have to be revision three, that you will allow us reciprocity with an existing CMMC certification to revision two until our certification runs out. So I would love to see that if you're an industry, ask for it. You know, you don't get anything you don't ask for. Be bold, go out and ask for it. Say we've done the hard work. Don't make us have two SSPs with the second one having a 30% higher level of controls added to the baseline. Let us proceed forward with your four phase rollout. DoD and federal government acknowledge we've done the work. Right. Those who have not been on it. Sure, okay, I get it. Right. They were going to inevitably roll to Rev 3. We all knew this. The fact that they made it a class deviation into the DFAR 7012 to hold it at revision 2 to match up with the rulemaking for CMMC. We all appreciated, both as defense contractors, as the assessors, because every time they have to change something, they have to do a class deviation to existing rulemaking. Right. And that's as much for us assessors is to say, we got to go back and retrain you all with new guidance on how to properly assess Rev3, which we don't have right now. We have none of that, so we can't do it. Our industry is not positioned to just start doing Rev3 assessments tomorrow. Right. Last thing is Katie Arrington. Before, like about a year before she was gone from her office, she said, we are looking at federalizing CMMC now. What does that mean? That means bringing CMMC as a certification standard up from the overall ownership under the DoD all the way up to the federal government level. So my question is, and I'm sorry if I'm extremely opinionated on these matters, but what will it matter for the DoD to go back and assess whether this program is cost effective if essentially CMMC as a certification standard will be adopted at the federal level, it will no longer matter what the DoD does or does not do. The federal government's going to require it. And a FAR clause, a, uh, DFAR supplement is a supplement to the far. You have to obey the far.

Speaker B: So again, it's. I cannot wait to be mid October to kind of find out what's, what's the next step, you know?

Speaker A: Right, right. And I, you know, I don't think. And I attended the Small Business Advocacy center and there was a lot of people on that call. I swear there was at least 500 attendees on that call, some from small business, some of US who are RPOs and C3PAOs all weighing in at the same time to bring that reflection back to the DOD CIO's office. With this RFI, I'm going to really give it up to the defense industry. Those who were dibs, small contractors. While there were some like we don't understand why we're doing this. There was a lot many that said we have put the cost, we have put the time in, we know what we're protecting, we have protected it, we've proven it, we've gotten certified. Could you just make this a little less onerous on us now? Where can the government make this less onerous in terms of cost? Is really going back to looking at the implementation standards. And two things I recommended, and I think others were chiming in are the Fedramp requirement is really difficult and it really throws our clients packages off almost immediately. I had one client that they just invested in a brand new PLM software, right? Interfaces with their CAD systems, stores their designs. Well the salesman told them it was compliant and they are not Fedramp. I had to give them the bad news that you know, they probably spent a million dollars migrating to this new PLM um software and it will cause their entire package to fail and there's no way to extricate CUI out of that environment.

Speaker B: So m the issue that for customers is as soon as you know, I find the cost of software for when you're on GCC high very expensive, you know and you don't got that many options very often it's this or this.

Speaker A: Yes. And to be quite honest I also have a part of my practice that works with Fedramp and the new FedRamp 20x I think will really mobilize a lot of these software vendors to get their Fedramp. They're just rolling it out this month. I think they have like a phase A and B. I can talk to my, my SME expert on it that my, my Fedramp guy will um. But in that rollout they're looking at low to moderate packages. By the time you submit the package to the new FedRamp 20x portal they can get approval in as little as between 30 and 90 days. Now before, before with the JAB authorization process, basically you could stand in line as commercial industry to get your Product approved. But top secret packages could always slip in ahead of you. And so it kept pushing people back. Uh, and that's why it would take about two years to get through jab authorization. With the new 20x portal, they've really revolutionized how we get approved government products through this system and to get them approved faster. So I think that's going to change the landscape for a lot of our defense contractors to have more Fedramp approved products. But right now it's still a bottleneck for all of our clients because we literally have to do an authorization boundary scoping where we say list all your cloud services because just one can make you fail.

Speaker B: Exactly. And the problem is, you know, the cost. So again goes back with the cost is on the implementation bucket side. But again the I say when you have to look at all your software and make sure they are compliant, then this is where I think if I see our customer base when they are the most surprised, you are saying, oh, you cannot use this package. You have to go with this. You have to. Well, but it's three times the price. What extra value do I get? None. From the, from that, from that perspective, yeah.

Speaker A: So I think FedRamp is one cost driver, the other cost driver. And I don't know if you agree with this, but uh, I've certainly seen it is fips because it takes so long and so much expense to get that FIPS validation. It's kind of in line with the Fed ramp and a lot of these companies just aren't there. And sometimes they actually have higher levels of encryption that just aren't yet FIPS validated. So you're actually protecting your data more. You just don't have that validation. So those two alone, I think if we loosened up the requirements for commercial DoD industry, I think we could see much lower costs for implementation because then they could use existing solutions they have in their environment, enforce strict security controls as they need to. I have no arguments against MFA and I don't think you should unravel MFA in any way, shape or form. But FIPS and FedRamp seem to be the enormous cost drivers for a lot of our clients.

Speaker B: So I second and triple. Second your.

Speaker A: We all agree?

Speaker B: Yes. I think, you know, I was in Jim. I just came back from the CMMC Pacific Northwest conference and for me, the first time that I saw in a conference you had everything. You had the US government, you have prime, you had the whole food chain. And I was, I think I felt pretty good leaving it because I felt like everyone was kind of aligned. I wish I was not expecting that. I was expecting a lot more. You know, again, it was a lot more people together than people having a different opinion or so at least. You know, I was worrying when I saw the again the polls on cmmc, but coming out of that, I came back kind of pumped up a little bit, kind of okay. I think people are thinking of the mission first and it was, it felt good. Maybe the people that went there are because they also believe in the same story.

Speaker A: I've seen people on both sides of the fence. I've seen those in industry, and I hate to overgeneralize here, but the people who I've seen who understand and get it and are abiding by their contract requirements are the ones that have already gotten CMMC certified. They understood it. They took on the task. I usually tell my clients it can take nine to 12 months to get from beginning to end, especially if you end up building a new environment. The ones that I'm seeing push hardest, when I have a truthful conversation with them, they generally admit to me they aren't certified yet. And obviously we see the same thing.

Speaker B: So us, again, we call them good and bad students. The people that today again have been working hard to get their cmmc, they are continuing, they are not stopping. And all the ones that are trying everything to not be go there, they're like, oh, great, uh, let's stop our talk. Let's talk again in three months. You know, and they're just waiting and praying that same MC will go away. And it's just. Yeah. So.

Speaker A: Yeah, yeah. And, and, and of that, obviously I've, I've put up my slides for the phase two rollout. Um, because I also with my clients, I want to dispel myths there because what everybody is missing is just because they have put on hold temporarily the phase two, which says we're not right now going to enforce a rollout of certification requirements. What they did not put on hold was the phase one requirements. So what we see is a massive push of the primes to say, hey, listen, subcontractors, our contract requirements didn't go away because you think phase two is on hold. We already have 7,021 in our contracts. And what does that state? Well, it states that you still have to go to SPRs, the Supplier Performance Risk System. You still have to report your CMMC Level 2 score. Now, what everybody seems to miss in this is that to submit your score. And I do this on behalf of my clients. I will register with my clients as the assessor, I will fill in their score and you get to the final stage where you send it to their ao, their affirming official. And it's really funny because it has metrics attached to this button to submit. And if you don't meet the metrics, it grays out. So what are those metrics? Well, first and foremost, you have to have a score of 88. And so the first thing I usually address is, you know, you can't even qualify for your contract unless you can post a score of 88 or above. And you must have no negative fives open. So none of your controls that are negative fives, none of your controls that are negative 3. I played around when posting a score one time just to see what would disable the button. Just 1 minus 3 disabled the button. Just 1 negative 5 being marked open, disabled the submit button. Being under a score of 88, disabled the submit button. I tested all of those features out and only when you are above an 88 and you only have a handful of the negative one controls were you allowed to submit.

Speaker B: Also, uh, people need to think you have an ABA great, but you have six months to go fix it.

Speaker A: Yes. Right. And, and so, like you, basically what they don't understand in this phase two suspension where everybody's saying, oh, phew, we don't have to do anything, your primes are still passing down these requirements. Phase one didn't go away. It didn't magically go away overnight. It's still already in awarded contracts from last November 10th and beyond. And you, as a subcontractor, inherit this flow down. Right? Your primes, they don't know if you are or are not handling cui, they are flowing down the requirements, uh, as they are instructed to do. So when you see those instructions, I usually tell my clients, you're posting in two places. If you have DFAR 7012, you're posting in that NIST 800, 171 tab. If you are posting for CMMC, you're going to be posting in that CMMC Level 2 tab. But those metrics are required. So if you are thinking, I'm going to get away with posting a bad score and nobody's going to know the one on the left will let you post any score because per DFARS7012, it says, Post your summary level score. Summary level score is wherever you are right now, Tell us where you are. But the one on the right does not work that way. And the minute you have a 7021 clause in your contract. Worse yet, the minute you have the Solicitation Provision 7025, and this is where everybody misses it, the Solicitation Provision 7025, what that actually says is if you are a prime and you are applying to win a contract, right. 7025 is on the lower left here. This is the CMMC solicitation provision that has teeth to it. And those teeth are. We go up to SPRs, and under this phase one rollout, if we do not see your score successfully, they don't see a score in process, right? They only see what you have successfully been allowed to submit. So you have to be an 88 or above. No negative fives, no negative threes. Only then do you qualify for the award. You don't get 7,021 until you get the contract clause. You get 7,021 because you won the award. But if you never get through the solicitation provision 7025, you'll never get 7021. And you know why? Because you didn't win. That is the teeth of all of this, and that is the relation to SPRs and some of the fallacies we're seeing in the phase two suspension right now that need to be addressed and need to be corrected. Because the primes we saw, uh, L3Harris put out two letters this past year. We saw elbit reinforce that their subcontractors, uh, we see all these letters going out from prime saying, we are still obligated. You are still obligated. None of this went away Good.

Speaker B: So, Christina, because, uh, we are, uh, reaching out. What would be your final word? What would you want our listener to get? If there's one fee you would like them to do, what would it be?

Speaker A: It really is. When we talk about the cost fallacies, the choice is yours. Under the implementation reduce your scope. That's what the RPOs and the C3POs are here to help you with. We're really not the bad guys. We actually are the good guys. To help you get these costs reined in, to advise you how to do this successfully, to stop any bad assumptions you might be making that your whole environment is in scope, when it might cause package failure. We're here to help. Let's teach you how to scope small so that you can win big. To title of my book again, uh, to make sure that you know what's at stake here. You have already signed your contracts, right? This is what's in them. You need to know that abide by your contracts. Abide by what Your primes are flowing down to you. Don't stop if you have momentum. This phase two pause is not the time to stop what you have already begun. If you haven't begun, you need to start Now. It takes nine to 12 months for the majority of our clients to get from beginning to end. And that's not because we move slow. It's because they have to implement all of these programs. All CMMC is, is show me what you've written for your security program and now prove you've done it. If those two things don't match up line for line, we wrote that we do this, we show you we do it and it matches up identical. That's a not met. Our job is to get you to the finish line.

Speaker B: Again, I want to thank you for joining us today. I think I hope our listener will get a lot of amazing advice and uh, thank you.

Speaker A: Thank you so much for inviting me.

Speaker B: That is another episode of Trust Issue in this conversation. Help you think differently about compliance, security, Security or trust. Share it to help someone who is still stuck in a checkbox mode. Each week we will keep bringing you more episodes resource and real world insight from the BMO team. Wherever you are listening from. Don't forget to rate the podcast and follow us to stay up uh, to date on the latest development in the GRC space. Remember, compliance gets you certified but real security that earns um, trust. Thank you for your this thing.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • July 2026 CMMC ConnectCyberspin · on DFARS 701280 / 100
  • The CMMC Reality Check: Gap Assessments, Documentation Overload & Why 30-Day Compliance Claims Are a Red FlagCMMC Compliance Guide · on CUI (Controlled Unclassified Information)80 / 100
  • What Every MSP Needs to Know About CMMC (feat. Matt Travis, CEO of Cyber AB)Climbing Mount CMMC · on CUI (Controlled Unclassified Information)79 / 100
  • CMMC Readiness Can’t Pause Just Because Phase 2 of the Program DidThe Government Technology Insider Podcast · on CMMC (Cybersecurity Maturity Model Certification)78 / 100
  • The Bad Guy's Different Set of RulesSecurity Breach · on CMMC (Cybersecurity Maturity Model Certification)78 / 100
  • The Evolving World of Cybersecurity Compliance, with Nathanael DickIT Matters · on CMMC (Cybersecurity Maturity Model Certification)76 / 100

More from Trust Issues

All episodes →
  • How to Build a Cross-Functional CMMC Readiness Team74 / 100
  • Why CMMC became necessary in the first place.88 / 100
  • Has CMMC Changed Cybersecurity Culture Forever?65 / 100
  • The four phases of a CMMC assessment84 / 100
  • Treat AI agents like human employees80 / 100
Explore the best B2B Marketing podcasts →
All Trust Issues episodes →