Trust Issues · 2026-06-30 · 56 min
Key moments - from our scoring
Substance score
68 / 100
Five dimensions, 20 points each
Stacy Boston Janik, VP of Government Services Strategy at CyberSec Investments and former Director of CMMC Policy at the Office of the Undersecretary of Defense for Acquisition and Sustainment, reveals how CMMC emerged from systemic failures in the defense industrial base. The episode traces the origin story: a 2018 DoD IG investigation and Navy Cyber Readiness Review exposed that contractors claiming compliance with NIST 800-171 requirements under the 2252.204.7012 clause were actually gaming the system - downloading boilerplate system security plans and filing plans of action and milestones (POAMs) with closure dates like 2099. Companies hadn't genuinely invested in cybersecurity; they'd simply attested compliance while maintaining minimal protections. Secretary Shanahan's mandate to "validate that these companies are actually doing what they're supposed to" sparked the Protecting Critical Technologies Task Force, which developed the DoD scoring methodology and established DCMA's Defense Industrial Based Cyber Assessment Center. Janik explains why CMMC became necessary and unpacks the rulemaking gauntlet - interim vs. final rules, OMB OIRA desk officers, interagency coordination, and the two-year, 400-page documentation process. She addresses cost concerns (companies had already been charging for "security" they weren't delivering), discusses small manufacturer challenges, and contextualizes the threat: CISA reports adversaries are actively in U.S. water infrastructure and hitting daily, yet many companies don't know they've been breached until the FBI arrives.
A 2018 DoD IG investigation and Navy Cyber Readiness Review found that contractors were gaming the 2252.204.7012 clause - submitting generic system security plans downloaded from the internet and filing plans of action and milestones (POAMs) with closure dates decades away. The compliance wasn't real, so the DoD needed a way to actually validate and assess whether companies were genuinely protecting controlled unclassified information (CUI) rather than just attesting to it on paper.
NIST developed the 800-171 standard specifically for defense contractors because industry pushed back against the more comprehensive 800-53, saying it was too difficult to implement. The 800-171 standard was agreed upon through rulemaking in 2015-2016 and became the baseline requirement for contractors handling CUI under the 2252.204.7012 clause.
Costs vary dramatically based on network complexity - from as low as $5,000 to hundreds of thousands of dollars for large prime contractors. However, Janik argues that contractors were already charging for compliance over the past decade through higher rates; they were just not actually doing the work. Companies have already been attesting to 800-171 compliance for years, so the compliance cost is not new - only the verification through CMMC assessments is.
According to Janik, the 800-171 baseline may stop amateur hackers but won't prevent determined state actors from breaching networks. The goal of CMMC is not to achieve perfect security, but to raise baseline cyber hygiene across the industrial base so companies understand their vulnerabilities and make conscious decisions to defend critical innovation and military technology.
CMMC required a 32 CFR programmatic rule with strict federal procedures: documenting 400+ pages of requirements, intra-agency review and coordination, addressing every public comment, OMB OIRA desk officer review, and 90-day interagency comment periods (with possible 30-day extensions). The process took two to two-and-a-half years and required careful coordination to avoid exceeding the 120-day deadline, which would have forced the entire process to restart from the beginning.
Our reviewer’s read on each dimension, with quotes from the episode.
Contains genuinely non-obvious insider detail on CMMC's origins, the 800-53-to-171 downgrade, gaming of SSPs, and the cost-accounting rationale for not directly paying for compliance, but is diluted by lengthy tangents (polygraphs, seatbelts, family stories).
they still gamed it because they went out to the Internet and they downloaded a system security plan that had a line that said, insert company name here
you'll pay for it, but you're not going to directly pay for it
The rulemaking-process narrative and the taxpayer/cost-accounting framing are fresh insider angles rarely heard publicly, though the broader security arguments are somewhat familiar.
had you begun in 2013, 14, 15, when this started, then you could have incrementally done it
the money that they would have spent to develop, they can now apply to manufacturing and they outmaneuver us
The guest was the Director of CMMC policy at OUSD A&S and CIO, former head of contracting at DIA, with 37 years directly building and shepherding the rule through government - an exceptionally relevant practitioner.
you were the Director of cmmc, uh, uh, policy, uh, prior to this
before I was at the Pentagon, I worked for the Defense Intelligence Agency as their head of contracting
Rich with named clauses, revisions, agencies, timelines, CFR sections, real companies, and cost ranges, though some claims remain anecdotal.
There was the 252, 204, 7012 clause
We've seen costs where companies have gotten compliant with all 110 for $5,000
The host largely affirms and cheerleads the guest rather than probing or challenging, offering supportive prompts and his own MSSP endorsements with no pushback on any claims.
I thoroughly believe in, like, what, what you've done for sure
it truly does make, uh, the United States safer, like, hundred percent
Computed from the transcript - who did the talking, and the words that came up most.
CMMC did not appear overnight. It followed more than a decade of contractors failing to do the work they were supposed to. In this episode of Trust Issues, Brandon and Bruno Lecoq welcome Stacy Bostjanick, VP of Government Services Strategy at Cybersec Investments and former Director of CMMC Policy at the Pentagon, to unpack the long road from DFARS and NIST 800-171 to enforceable CMMC assessments. Stacy explains how contractors gamed self-attestation, why the cost of stolen innovation extends far beyond a single compromised company, and how attackers deliberately target small businesses within critical defense supply chains. She also takes listeners inside the federal rulemaking process and explains why today’s CMMC requirements are only the beginning of a much larger shift toward stronger, more automated security.
Transcribed and scored by The B2B Podcast Index.
Speaker A: The thing that is also worrisome with this current conflict that we're in, we've been told by CISA they're in our water, they're in our infrastructure, they are hitting us every day. And I talked to the guys up at DC3 and I'm like, are you getting an influx, an increase in your reporting about incidents now? Is that because they're not hitting or
Speaker B: they're not reporting it? They don't even know.
Speaker A: A lot of times what you hear is they don't know until the FBI knocks on their door and says, oh, by the way, you were hacked weeks ago.
Speaker C: Welcome to Trust Issue by Demo, the podcast where we go beyond checkbox compliance and get real about security. In every episode, we will break down what's happening in the world of cmmc, cybersecurity and grc, straight from the people building, auditing and living it. Real conversation about real security.
Speaker B: Welcome to Trust Issues. On today's episode, we're joined by Stacy Boston Janik, VP of Government Services Strategy at CyberSec, uh, Investments. Stacy brings a decade of experience across defense intelligence contracting and cybersecurity strategy, working on some of the government's most complex acquisition and national security programs. Uh, currently she helps organizations navigate CMMC readiness, DFARS requirements, and the evolving realities of cybersecurity compliance inside the defense industrial base. Welcome to the show. Uh, Stacy, um, I kind of wanted to just started off with, uh, you were the Director of cmmc, uh, uh, policy, uh, prior to this, um, at the office of the Undersecretary of Defense for Acquisition and Sustainment, which is another mouthful. Uh, for people who don't know, this was basically the body that was drafting CMMC before, uh, the DoD went into enforcement phase. Um, so tell me more about what your time was like over there. How did you get into the CMMC policy? Why did you want to get into this? What was it like?
Speaker A: So, you know, it's interesting. Um, so before I was at the Pentagon, I worked for the Defense Intelligence Agency as their head of contracting. And at one point they, uh, made a rule that all sess had to rotate out of their jobs into different jobs. Well, at the Defense Intelligence Agency as a contracting and acquisition person, I wasn't a humanter or, you know, any of the ents to be able to go into that side of the house. So they were like, okay, it's time for you to rotate. You need to go find a job in the acquisition world. And it was really funny because I talked at that point in time. Shea Assad was in, uh, defense pricing and contracting over at the Pentagon. And so I reached out and I said, hey, do you guys need any help over there? Because I'm going to have to go do a joint duty assignment is what the intelligence, uh, world calls that. And I'm looking for possibilities. So he said, yeah, I think we could use some people. And they started the process, but they were taking, uh, an extraordinarily long time. So at the same time, NGA reached out to me and they said, hey, we would like you to come work with us. I said, well, I've already started something with, uh, the Pentagon, so whoever gets their paperwork done first is where I'll go. And so ended up that they called me and said, okay, we've got the paperwork done at nga. Right after I got the call that said the Pentagon finished theirs. So I'm like, sorry, Pentagon finished theirs first. I got to go to the Pentagon. So while I was over at the Pentagon, I worked for. They called it DPAP at the time, right? So I worked for them for a while, and then they started the Protecting Critical Technologies Task Force. So, uh, the second year I was on my assignment, I moved into that, and I worked with General Tom Murphy was in charge. There was the 252, 204, 7012 clause, right? That issue effort was started in, like, 2013. And so the DPAP was working on that, and they were the ones that were helping educate people about what that clause meant and what it was. They came up with the DoD scoring methodology for the compliance with the 110. So what happened was there was a, uh, DoD IG investigation and the Navy Cyber Readiness Review. And that year went out and said, okay, you guys are supposed to be compliant with the 110 requirements. If you handle our CUI. How are they doing? And so they went out and they basically said, not right. That people are, ah. And unfortunately, you know, when they started the work on the 7012 clause, they originally said, hey, man, we want you to do the 853, which is confidentiality, availability, and integrity. And industry went, are you kidding? No way. We can't do that. That's way too hard. So NIST formulated the 800, 171 specifically for industry because they said it was too hard to do the 53. So it had to go through rulemaking, which we'll talk a little bit about my experience with rulemaking, but that ain't a fun or easy process to get through, Right. So I started in 2013. It took them 2015, 2016 for them to settle on 800, 171, for industry to say, okay, we'll do the 171. We can do that, and that's what we'll comply with. So Fast forward to 2018. They go out and they're like, all right, how are they doing? Well, that clause said you have to have a system security, uh, plan. You have to have a plan of action and milestones to close out the requirements that you don't currently meet. But we're not going to say you got to have it all done day one. So what they found was companies had gone out to the ones that even tried to meet the letter of the law. They still gamed it because they went out to the Internet and they downloaded a system security plan that had a line that said, insert company name here. So, you know, it had no bearing on their actual system. And they had plans of actions and milestones for all 110 requirements that the DIP CAC saw some, that they weren't going to close any until 2099. Right. We'll be dead. Yeah. By the time that they would do anything. So didn't particularly help protect our data. So Secretary Shanahan at that point in time was like, you know, we've got to validate that these companies are protecting our data. They're doing what they've signed up to. And so that's when the Protecting Critical Technologies Task Force stood up and the Defense acquisition, um, started looking into, okay, what can we do to validate that these companies are actually doing what they're supposed to. So that's when, uh, a lady by the name of Vicki Machete and a group of other people came together and developed the DoD scoring methodology for these 110 requirements. So we could go out and do an assessment and say, okay, how many of the 110 do you actually meet? You know, that was another funny story. You had companies that they said, okay, you go into the supplier performance risk system and you put in your evaluation of yourself, right? And they said, 110. And then the, the DIBCAC said, okay, we're going to come look at you. And all of a sudden that score went to a negative 200. And. And then the DIBCAC was like, now we really want to come talk to you. Because what changed? Were you lying up front? You know, were you just gaming the system and telling us what we wanted to hear? So the. What happened was they started talking about, how are we going to do this? What are we going to look at and um, that's when they said, okay, we need to develop this DCMA Defense Industrial Based Cyber Assessment Center. So that's what stood that up was this whole recognition from that IG report and the cyber Readiness Review that these people weren't doing what they were supposed to and they were kind of gaming the system, right? They met the letter of the clause, but they really weren't complying, which was kind of disingenuous because we fought for this. 171. Because you said you couldn't do the other one. You agreed to do it. And nobody's checking. Nobody's checking, right? Nobody's checking my homework so I can get away without having to do it. And uh, I have to tell a story. So Shanahan at the time said, we are not going to pay more for security, right? Well, the general that was in charge of the pictif, he took that charge and he was running around saying, we're not going to pay more. But we were like, but sir, it's an allowable cost for overhead in G and A. It always has been. It's documented that way. So you'll pay for it, but you're not going to directly pay for it. There's not going to be a contract line item that's going to give you an upfront chunk of money to go do this, right? And through this is where I put on my geeky acquisition hat, right? Through the cost accounting standards that's applicable, right? Because if one program pays all the costs for your enclave or your enterprise to be CMMC ready, right? Well, you're going to use that multiple times. You can use the same enclave for more than one program. You can use that enterprise for more than one program. So it does it from a uh, cost accounting standards and audit perspective. You can't just pay for. Give a company a chunk of money to pay for it. The other thing is, is you can't standardize, right? Because each network, uh, in each company is set up and developed differently. So the intricacies of getting uh, compliant are going to have variable cost, right? You have some people that are like, we've seen costs where companies have gotten compliant with all 110 for $5,000. We've seen others where it's way more expensive, right? Hundreds of thousands of dollars. But that's because they have a very complex network. It's usually the primes that are that expensive, you know, I mean it really depends, you know. So I guess, ah, it's a testament for keep it simple stupid, right? You know.
Speaker B: Yeah, well, we're seeing a lot of people, they say that, oh, it's actually really expensive, um, but they've had to be ITAR compliant for years and they've done nothing about it. Uh, they're on all non fedramp high technologies. And so they've been saying, wow, it's a surprise to us, it's CMMC M that's so expensive. But they've been attesting that they've been complying with 7012 for years now. So you've been saving?
Speaker A: Well. And they've, they've accepted higher rates. Mhm.
Speaker B: Yes.
Speaker A: Because they were supposedly doing this, right? And, and that's the other thing. We don't want to raise our rates because we'll be less, uh, competitive. Well, you've already done it. You've already been, uh, you know, it said that you were doing it. So that's what. And I will tell you, the one probably thorn in the program office's side is the fact that people like CMMC is too expensive. It's driving me out. No, the assessment's not that expensive. It's the compliance that you were supposed to have done. And so that's where. And you know, and of course, unfortunately, people in the more political perspectives, uh, are impacted by those conversations because they're like, oh my God, we've got to be nicer to the small businesses, we can't put them out of business, blah blah, blah, blah, blah. And it's like, but had you begun in 2013, 14, 15, when this started, then you could have incrementally done it, right? And had we gone out and evaluated and found companies were doing what we asked them to do, we'd never have a cmmc. Right. The whole impetus behind this is because people were gaming the system. Now it's human nature, right? If I can get away with it and I can save myself a little bit of money and I get to have my swimming pool in my backyard.
Speaker B: If I can be a doctor, not go to med school and not pass all these tests, well, why not? I'll get paid the same as a doctor. Right.
Speaker A: And that's my argument too, right? Because uh, I've heard several perspectives, right? But it's like, well, um, what do we care about the confidentiality of our data? We just need to out manufacture them, the adversary. And it's like, no, wait a minute, as a taxpayer, you should be pissed, right? Because the data and information that these people are able to garner and steal because we don't have good cyber hygiene is the data and information that took millions of billions of dollars of innovation and development to put together, right? Like the F35. How much money did we spend to be able to design that aircraft to do what we need it to do, right? And I remember this is how old I am, right? I worked at Navair when they had the problem with the thing couldn't, uh, take off of the carrier because the wings were too heavy, right? So they had to go redesign it to make sure that it could do that. So that's billions of dollars that we as taxpayers spent to develop this premier aircraft that was able to be replicated. Now, you know, some of the systems that are on there are classified, so they didn't get all that information, but they damn sure got the same body, right? So the amount that they had to put into development was this much as opposed to this much, right? And so, you know, there are people like, well, we just need to manufacture faster and make more and we'll win. Well, two things, right? We had to come up with the money to develop it. Now they don't. So the money that they would have spent to develop, they can now apply to manufacturing and they outmaneuver us and can, uh, manufacture faster because they already didn't have to spend that upfront money. I got to go back to taxpayer to say, hey, give me some more money so I can go manufacture faster. Right? Whereas if had you kept your information secure, you wouldn't be in that situation, right? That's one and two, okay? Even if we have more than they do, I don't want my kid to be in that number one and two, that they have equivalent that gets killed before he can come home to take care of his mama, right? I want him to be able to have the, the kick ass piece of equipment that comes in and says, you're out of here. Right? And there's no question, hands down, we go in, we take over, we have military superiority, we, we bring our men and women home, there's no issues, we're done. So. So, you know, uh, those are the perspectives that people don't really get. Now, I also have to give a shout out because I, uh, there was a lady that works for wintech. They're a manufacturer in Atlanta. Awesome people. And the lady, that's their president, Allison Giddens, right? Because when we started our whole roadshow on cmmc, we're like, well, y' all have already been telling us you're doing it. You're not telling me you've been lying, are You. And she. She finally told me, she said, that's not helpful. You're not helping us. And I think one of the things that we've got to figure out is how to get the message and the information down to those small manufacturers. And when you talk to those guys, uh, they say, look, it's all I can do to keep the wheels on the bus, get my payroll paid, and get everything done. I don't have time to go out and take a day class or go to all these different conferences where y' all decide to come speak. Right? And so I just had a conversation with her the other day because, you know, they're like, you guys aren't thinking about the small manufacturer's perspective on how we get there and what we do. And I will say, the current administration that's in the CIO today, a lot of their focus is moving to availability and integrity, which are the last two pieces of that 853we really actually asked you to start with, but we cut off, um, and stuck with confidentiality because they had a heart attack over it. Right. And if you think about it, it is a smart way to go because, um, think about all the weapons that we are expending now in the conflict with Iran. Right. And our acquisition process, because acquisition people and contractors are rewarded by the fact that they save the government money. Right. That they protect the taxpayer's dollar and that we, uh, don't gold plate things and have requirements. Creepy. But that also doesn't engender multiple vendors. Right. That really kind of, uh, embraces, uh, having partnerships, having one. One sole source in the supply chain because we get our best discipline, price and. But now we move into the age of cyber, right? Where we've got vulnerabilities. Think about those one company that's supplying all of the bolts, or all of this or all of that. And, uh, they're the only suppliers. Right? Right. And our friends hack them, they take them down, they ransomware them. They can't get to their data and information. You've just stopped that entire production line. The thing that, that, that is also worrisome with this current conflict that we're in. We've been told by CISA they're in our water, they're in our infrastructure. They are hitting us every day. And I talked to the guys up at DC3, and I'm like, are you getting an influx, an increase in your, um, reporting about incidents? No. No. Now, is that because they're not hitting the defense industrial base or they don't even know Right. Because a lot of times what you hear is they don't know until the FBI knocks on their door and says, oh by the way, you were hacked a couple weeks ago, right? Ah, and you know, so the sad part about the 800171 in compliance with that is that if you're a cyber geek, what I'm told is that really it's not going to stop much. It may stop the 11 year old in the basement from hacking and playing, you know, thermal global, uh, nuclear war with the game, but it won't stop the state actors. What it will do is maybe make it more visible to you that you can, you know, see right now where the industry will hopefully at one point get to with AI and what have you is that it'll make it easier for companies to be able to buy tools that will help them understand where they are and up the game. And the whole idea behind CMMC was to get the industrial base and industry right as it, as ah, a country, a United States country, whether you are in the defense industrial base or any other thing, we should be trying to keep our data and information ours. Right. And so CMMC was really started to help companies start thinking about cybersecurity, right. And to be able to understand the avenues of which they are going to attack you and be able to start making conscious decisions to stay out in front of it right now. Because when we started with the first round of CMMC we had a lot of maturity things, well, 20 maturity things extra over and above the 171 built into it. The Biden administration came in, they said we need to make sure this thing isn't too hard. It's not, you know, so instead of having five levels we dropped to three. You know, we did some things to make it easier. We only standardized on the 171 because that was what they were already saying they were doing. So we didn't introduce anything new. Right. And so we kicked it back and we simplified it even more. So we took that maturity part out of it. Right. Which was really what we were hoping to get people to start getting ahead of and allowing them to think. So where we are today is the next revision for CMMC. Uh, the 800171 is rev 3. Now one of the things you were talking about is uh, the rule making process and what it entails. And it's very interesting because the rulemaking, the rules would impact everybody in industry. They treat that data and information like it is more secret than the cop secret stuff at CIA, right? Because they don't want anybody to get information before somebody else and be unfairly advantaged or disadvantaged because of, uh, that. So when you're in rulemaking, you can't talk to anybody about anything. And they get very like, you can't give that information. So the way the process works, though, I'll give you insight in that. Right? So you have to. There is a 32 CFR, which is the programmatic rule, and the 48 CFR, which is the federal acquisition side of the House, the defense federal acquisition side of the House, to have a clause. So when we started cmmc, before we did the Biden era reset and simplification, we put together a 48 CFR clause for CMMC. The powers that be in the building at that point in time felt that we could just do a 48 CFR rule and implement CMMC because we had put the model out for people to comment on on our website and stuff like that. When we did the reset and after we put that out and we were, uh, okay, another part that I forgot to bring in, first part, with these rules, you can do an interim rule or a final rule. An interim rule. If you are granted that blessing, you can make it effective after you receive the public comments, right? You don't have to answer the public comments, you just have to get them and then you can make it, uh, enforce it then while you finish the rest of the rulemaking process. Okay, so we did that. CMMC was due to go into effect November 30th of 2020. Right. And that was an election year. So what happened was by November 30, the Biden administration had won the election. They knew they were coming in. Uh, and of course, everybody goes on hold until the new administration comes in. New administration comes in, and they're like, we want to look at this. We want to make sure we're not being overly punitive, we're not being difficult. So I actually moved at that point in time from ANS over to the cio. So when I retired, I was in the cio, and so we did the rulemaking from there. But what, uh, OMB OIRA came back with, after the comments came in from the first interim rule, they said, you actually kind of need to do a program rule, the 32 CFR. So we had this blessing of an interim rule. The Biden administration decided they wanted to change things and manipulate it. It was determined we needed to do a 32 CFR rulemaking. So the journey began. Right? So the, the 48 interim rule kind of did Nothing. It was kind of just um. Suspended. Right. It was a 400 page rule. Took us two to two and a half years to get it documented and put together. Once you have your documentation together then you have to socialize it within the building. So intra agency review and coordination. You have to address every comment and concern, show how you addressed every comment and concern, what changes you made to the original documentation, how you answered it. And once you do that and you're assigned an OMB OIRA desk officer. Right. And the lady we had, she was one tough cookie. She's probably the most powerful GS15 in all of federal government. So Ann, so when we started that process with her on the 32 CFR, she had been the desk officer on the 48 CFR for that interim rule. Now remember I told you it was a blessing. They don't give those out willy nilly. Right. It is, it is a huge deal if they give you an enormous. And her perspective was. And then we went and squandered it and sat on it for two years and didn't move out. And if it was really that urgent then how could you take that long m to look at it? And you can't really fight that because we did. Right. So when we started with her on the 32 CFR she was not a fan, she was insulted, she was angry and it took us probably that entire time to get her back on our side. So do your intra agency. Then you give it to OMBO aira, they review all the documentation, they ask you questions, you have to answer their questions. Then they will send it out interagency to all the other agencies. They have 90 days for them to submit their comments. Now it can go longer and they can give it a 30 day extension. If it goes longer than the 120 days they can say sorry for your luck, you got to go back to the beginning and start all over. So first round of interagency went 120 days. And I will tell you my team, we work nights, we work weekends, we did everything because there was a mantra that we weren't going to let them say we dragged our feet and we didn't. It wasn't important to us. So uh, and that was the only way we got back in that desk officers good graces is we were turning things in two to three days. I mean we were working weekends and we were, we were hitting it. Right. So do that. Then there were a lot of like oh um, didn't we tell you as we went through. Right. So we get through the, the 120 day interagency. We answer all their comments, we come to closure on that, and we said, okay, now we can also, we need is a memo from the cio, we can put it out for public comment and we can get to the next phase. And then they went, oh, did we forget to tell you? It has to go to the federal registry and they have to do a review of all of your, um, like, uh, if you reference anything, any other rule in there, they have to go like, check your references, right? And that's a week to 10 days. But then their lawyers get to review it for another 30 days, right? And you're like, who knew that the lawyers that There was another 40 days in the process that we weren't tracking, right? We're like, what? So whoever watches this? Because industry was pissed because when we put it out for public comment, it was the 26th of December, and they're like, yeah, great way to ruin my Christmas holiday by putting this, dropping this thing. Because then when you drop it for public comment, they have 60 days to respond and give their public comment, right? So at the end of 60 days, you get to close public comment. Now, there are other, um, I'm going to get the number wrong, but there is like 18, 26, uh, meetings that, uh, industry can, during that process, say, I want to have a meeting with the, uh, program office. I want to talk this through with them. So we got through all that. We had over 2,000 comments. Some were just editorializing, some of them we laughed because I always said I wanted to be back in the old Saturday Night Live where they were like, jane, you. And that would be my response, right? You know, it's like, are you kidding me? Come on. That's just right. But we answered every single one of their comments, right? Then what you do is you take all of those comments and you bucket them into categories and then you have to summarize all of the questions and responses in a bucket response for the category, right? And they all have to track and align and be. You know, so somebody can draw a, draw a direct line that, oh, my comment landed in the administrative bucket and it's covered in this. And so we got that done in two months because we were kicking butt and taking names, uh, like crazy. So get those done, send those back. Then it goes back based on your comments and any changes that you make in the rule goes back into another intra agency review and comment, right? Which in the Pentagon is another couple months. Then, uh, we did push, like, we got it done Faster because uh, my kids say I'm the best nag in the world, second only to my mother claim to fame. So um, we get that done and then it goes back into another 90 day uh, interagency review. But only after your OMB OIRA desk officer reviews it. Right. And there were a couple of things they forced us to do. Like we were forced to tie CMMC to a specific revision of the NIST 800 171. Whereas the 7012 clause, it just says the current version. So they pushed us to do that. So now when we go to Update to the Rev3, we go through this process again. We have to go in, update the clause verbiage and then it goes through again. Right. So 90 days goes. And then of course we get back to the Federal Register again, which is another 30 uh day review before it can go out for, for publication. So uh, yeah, it was a fun time. Right. And it took us a lot. We were, we have been revered as ah, developing the most complex rule in Dow history. Um, uh, Jacob Horn is so Ombora publishes a uh, guidance on rulemaking is like a four. It's a 400, uh, 300, 400 page book. Right. And there are very few people in this world. Our lady. That was our lead uh, for rulemaking. Diane Knight probably read it and Jacob Horne read it cover to cover.
Speaker B: Yeah. From summer seven.
Speaker A: Yes. And if you, if you see him, he was like, they got this through in record time, is the fastest anybody's ever done one of these. So to that effect we did probably uh, meet a lot of records.
Speaker B: I feel like it's extremely effective now because now everybody in industry now is actually doing it. Right. Um, a lot slower than I would have maybe anticipated. But um, there's several years to go do this depending on who your prime is, what your contract says. But it seems really crazy that in explaining this history of, you know, all this sort of started in 2013 and it, and basically started off with 53 and saying oh no, that industry said oh that's too hard. Okay, we're going to bring it down to 171. Oh, that's too hard. People are still not doing it. And now even now talking to companies today, you know, people are coming to me as an MSSP to um, do implementations of their technology and cybersecurity for the first time. They're still not doing anything. It seems like at what point do we just say too bad. So sad. You had all the time. All these people did so much work to make it easier for you to make it comprehensive, for you to answer all your questions and comments, and you're still not doing anything.
Speaker A: Well. And, you know, the hard part is, uh, if I put on my government political hat, right? We want to be kind to the small businesses. We need their innovation, we need their, their stuff. But, you know, if I put on my taxpayer hat, it's like, yeah, but what good is it if it's already stolen before we ever get to do anything with it, right? How is it really furthering us? And if the depart. You know, the hard part is the damage assessment process is also slow. Now, hopefully with AI and new technology, it will expedite and we'll be able to figure out faster than we did before. But we haven't gotten to the point where, uh, they've said, you know what? Y' all didn't do what you're supposed to. You're m. Yeah, well, or we're canceling the contract because it's no longer viable, right? It's not a worthy contract anymore because, you know, uh, that, that, that technology's, uh, gone. We need to pivot somewhere else, right? And we find, uh, two things, right? They, they lay in wait for the small businesses because they know their cyber is not as advanced as some of the bigs, right? And, you know, um, these small businesses are also thinking, well, nobody cares about me. Nobody wants my stuff. But they, but they do, right? They. They definitely do. And what the fence contractors don't see, right, because you can guarantee if Pepsi had China, uh, allowed China to steal their recipe and started manufacturing Pepsi over there, they would be like, oh, I need to protect this a little bit more for the defense industrial base, The Department of Defense or war is never going to go well, Hell, we'll go buy it cheaper over in China, right? They've got a lock on the industry, so. So they don't feel the impact of their innovation being taken. But as a national U.S. uh, citizen, I should be insulted and concerned that I came up with this whiz bang, uh, innovation and now somebody else is utilizing it, right? And that's where we find ourselves in a position where all of a sudden one day we wake up and they're using drones. That we probably were the first ones who came up with that innovation against us, right?
Speaker C: I think the worst is that small business. Told you.
Speaker B: Oh, um, I'm one.
Speaker C: I have 110 out of 110.
Speaker B: Yeah. I am compliant.
Speaker A: Trust me, Right? I think that's. Yeah, yeah, that's the ticket, you know, you know, we don't want to be punitive, we don't want to be negative to these companies. We want to embrace them and bring them in. And one of the good things, um, was it Fields of Dreams, right? If you build it, they will come. Uh, so we've got the Army ENCODE capability, uh, that is providing an environment for companies to operate in. And we've come up and developed through our, um, discussions with the cloud service providers and the MSPs with ways that companies can kind of hit the easy button and inherit all of the capabilities that the MSP or the cloud service provides them and they just have a virtual desktop. Uh, you know, there are mechanisms and ways that we can get these small businesses to do it. Now, when I had my federal government hat on, I can't as a federal employee go out and say, well, just go use ABC Company, right? And you'll be fine. Because GHJ is going to go like, what the hell? Why aren't you using my company? That's not fair. You know, you're, you're. So we have to try to give everybody fair opportunity to participate. But we also as a nation need to recognize that our innovation and our superiority is getting eroded because we're not careful and what happens. And you know, I also have to take some blame for it from by days when I was in contracting because we negotiated out extra, uh, hours, uh, back in the day from contracts as being superfluous when they used to have CAD Cam, people go in and dissect the statements, um, of work and the tech data packages to only give those companies what they need, right? We need to get back to where we only give a company what they need to do their job. Right? I think Katie's, uh, I've told this story a million times. I'm sure people are like, seriously? Again? But there was, she went out to Transcom, uh, and there was a guy who was a welder and he was like, hey, I want to talk to this woman, right? Because he's like, I'm a welder. I don't need no stinking cybersecurity. I just need my acetylene torch and I'm good to go. And she said, you know, it was interesting because she went out there and they made sure she had her, you know, safety glasses, steel toed boots, you know, you know, all that stuff. All our OSHA requirements were met, right? And so she said to the guy, she said, well, how do you know what to weld? He says, oh, they send it to me. And he had a laptop sitting up on the, the, you know, the side of the thing. And she said she could see his, uh, Facebook Instant messenger and his Amazon delivery notifications, right? And he had a CAD program. And she said, hey, can you zoom out on so I can see what that was? It was the entire structural design of the F22. And she said to him, she said, you think our adversaries might want to get a copy of that? And he's like, oh, I guess. Or even more nefarious. What if they get in and they change the tolerances on the welds that you were sent, right? And now you have low, uh, uh, confidence and we don't use you anymore. So they've eroded my industrial base because now I have one less participant in good standing, right? Or if that eroded, uh, or bad, well, gets through, right? Somebody's flying and their, their plane starts falling apart, you know, I mean, you know, there are multiple ways. And I think where we are naive as citizens, uh, in a nation is there are so many different vectors that supply chain security, security can hammer us, right. If they intercede. And they were seeing this some, um, with the Ukraine conflict, right, where they can intercede a delivery and mess with stuff before it gets to you, right. They can get in and change, uh, stuff on your online. Like those tolerances of those welds that can impact the way, the quality of the product, right. There's so many different ways and avenues that we can be attacked and we are sitting here fat, dumb and happy just like Will. Nobody cared about little old me, right?
Speaker B: So when, when contractors come to you, now that you're on the assessor side of, you know, you're in industry now, are you bringing that perspective into your engagements with these contractors?
Speaker A: So I, I have not directly engaged with, uh, customers from, uh, people coming to get assessed. I'm my vantage point here is more working with the other federal agencies and helping further the CMMC from industry, right. So, you know, it's funny because we get the rules done everything. And then of course we had another administration back to the Trump administration who started this, but a whole new set of political appointees, right. And of course this is a Stacy opinion and nobody else's, right. I don't want. But it's difficult for the political appointees because they always want to bring somebody in from industry that is innovative and going to revolutionize the department. But what they don't have is that familiarity and understanding with the rules and the authorities and the budget process and everything, you know, Everything you have to go through, right. A lot of them are like, well, you know, let's just standardize on one kind of computer system across all departments. And that'll, that'll bring efficiencies and interconnectivity. And it's like, yeah. Did you pay attention to the JEDI contract? Because they were gave. Went to JWCC and gave everybody a chunk of the pie. Because what. Because if one didn't get it, they protested, right. And then they changed to another one and everybody else protested. And so. And we have a responsibility to provide an, uh, an opportunity for anyone. Anyone, right. Uh, people who set up a company, uh, out of their garage. And when I worked at nswc, way back in the day, right, NSWC White Oak, before they blew themselves up, we had small business innovative research contracts where guys were in their garage with three computers linked together with cables, right. We have one guy, he got, uh, a travel trailer to do his research as part of the contract, and he drove away. We never heard from him. So things like that. We don't understand when you come from industry, what the rules and regulations are and what we have to go through to award contracts and do things. And so there is a lag of bringing them up to speed. And sometimes they perceive or get the feeling like the federal employees are against them and don't want them to succeed. And that's not the case at all. Right. I think, um, most all federal employees, we park our political perspective, uh, at the door when we walk into the building. And, you know, if I get a new political that comes in and says, hey, I want you to stand on your head for 20 hours and if it's possible, okay, we'll do it right? Because you're the boss, you've been put in this position for a reason, and we're going to follow what you ask us to do. Right? We pray at the end of the day that, you know, the war fighter is still protected and that we're still doing things to make sure that these men and women get to come home to their families at the end of the day. Because that's really all we care about, right, Is doing right by them. And, you know, we have been blessed and fortunate enough to be able to interact with these people through our careers, to hear some of the things that they go through when they're in the field, to try to help them. Right? But, you know, uh, so it's been, it's been a journey. Um, when I retired, it was funny because one of the politicals came in and they said, you know, we've been hearing some people, uh, are going to retire and we just want to let them know they don't have to retire. And I started laughing. I said, did somebody tell you that I felt like I had to retire? He's like, well, I just wanted to let you know I don't want you to retire. And I said, unfortunately, it's my time, right? If I hadn't retired, the people below me will never have an opportunity to fleet up and spread their wings and do their leadership skills. Um, two, I'm old, right? I mean, I am at the peak age. My husband's five years older than me. And you know what? It's time for me to get out and be able to have 100% remote work, uh, position, right? Because, um, I don't know if you guys. Katie made a. Katie Arrington made a post. My husband had open heart surgery back, um, in April, right. It was funny because she made this post, you know, let's pray for Stacy and her husband. And, uh, General Murphy obviously just hit whatever the AI generated response was because she said, let's come together and pray for them because her husband is having open heart surgery today. And his comment was, congrats to Stacy. Well done. I responded. I was like, I don't think my husband would feel the same way, Tom. And I don't know if that's a badge of honor. I put my husband in open heart surgery. You know, it's like, I don't know that's a wife's benefit or not, but, but anyway, so, you know, it's time for me to be able, you know, I'm still thoroughly invested in cmmc. I am thoroughly, uh, believe in the program. Uh, do I think that there are going to be things that as we roll this out, that we're going to go, ooh, yeah, we need to change that.
Speaker B: I thoroughly believe in, like, what, what you've done for sure. Like, I see, like, you know, we're on the, obviously the implementation side, being an MSSP. And I can tell you that, you know, NIST 800171 is extremely comprehensive and what CMMC is asking for it truly does make, uh, the United States safer, like, hundred percent. Um, I am very gung ho about three years down the line when everybody has to go do this. We truly will be a much safer place for sure.
Speaker A: And the sad part is, right when people ask me about this is the roll before the crawl, before the walk, before the run, right? I mean, this is just the very Nascent stages and where CMMC will go now, hopefully we'll be able to prove out automation and it'll be the easy button because, you know, a lot of these companies, they know mechanical engineering, they know how to make their bolt, but they don't understand it. They're waiting for their nephew to come home from college to fix that laptop over there. It's doing something funky. I mean, you know, we see that we're hoping that we can move the nation further ahead and, you know, zero trust, theoretically is where we've got to get to. Right. What was, uh, Katie always refers to the phenomenon, the movie. Right. The bunnies are in the farm right there. Uh, people are already in our networks, they're already monitoring what we're doing. And I think the thing that frustrates me that I don't understand what message needs to get out there is what's it going to take for us as a nation to sit up and say, hey, this is serious. Right. They've already mess with our gas, with the Columbia pipeline thing. They've already been in our water, they've already been in our electrical.
Speaker C: We are waiting to have a shutdown
Speaker B: and this will wake up everyone. Yeah, no, I think CMMC is the right way to go about this. I do think that obviously it's, let's call it taken 10, 13 years, uh, in the meanwhile, but it's going to happen over the next three years. Right. Like, uh, enough people are going to get it where it's going to make the nation a lot safer. And it's also like, on the MSSP side, I see that we're doing like 10 years worth of digital transformation in like 12 months. But once things like Revision 3 come out, or let's say you need to make them go to 53 at one point, that part will be a walk in the park compared to what's happening right now. I think the hardest part right now is just that they're going from 0 to 100 in 12 months. Um, they have put off 13 to 15 years worth of digital transformation. And so it's really, really hard on the entire organization to do this all at once. But to go then from revision two to revision three, like rmr, like, my technology's already up to date. It's like, it's not going to be like that crazy of a thing, right?
Speaker A: Yeah, yeah, They've already done the dance, so it's just a new step. And it's funny because I have a very good friend that, um, works for one of the contractors for the base that near where we live. And she was like, oh, it's such a pain in the ass. I just want to do my job. But now I got to go over here because I'm using cui and, you know, and it's muscle memory, right? Because, I mean, uh, when I worked at Navair back in the day, right, we had to go into a teeny, tiny closet to do anything on supernet, right? Secret stuff. It was a huge change in culture, a huge thing to get used to, right? And then I leave there and I go to the odni, right, where I had to be polygraphed and, you know, the whole nine yards. Uh, that. That was another funny story. So my first time I go in there, uh, it was back in 2006, 7. I worked for the ODNI, right? So you go into the polygraph room, and you're sitting there, and there's this chair, and there's this. There's this pad on the seat. And I said to the guy, I said, what's that pad for? He says, we find people clench their butt cheeks when they lie. And I said, but you didn't tell me not to eat beans the night before, because if I have gas, I'm going to be doing the same thing, right? You know, if you have to pass gas, you're going to. Or. You know what I mean? So, uh, so everybody used to laugh at me, and they used to make fun of me because they were like, oh, we didn't have that in our polygraph. I don't know what they were doing to you. And I was like, that's not fair. So, you know, uh, but it's a culture change, right? It's all in what you get used to. It's all in knowing the steps and what you have to do. So I think once we get over the hump, then, yes, but I'm afraid there's going to be something catastrophic that's going to happen to our nation in the meantime, while we're dragging our feet, right? And I, uh, don't know why that surprises me, because I think, you know, we got OSHA requirements because what kids were dying, uh, in plants back in the day, right? I mean, every regulation that we have is born out of somebody messing something up.
Speaker B: It's like the insurance.
Speaker C: Yeah.
Speaker B: He's like, yeah, it's why you have to wear seatbelts. It's why. It's why you have to do all these things, right?
Speaker A: Uh, it's exactly right. Right. And, you know, I mean, we Our kids don't know a world. Uh, before seat belts, while the rest of us were walking around on the back seat of the car as we, you know. Right, right. You know, we were going to Florida for vacation. My sister and I were both laid down across the back seat, but, you know, bitching who got more of the space than the other. But no seat belts. Right. And, and of course, uh, you know, probably mothers today don't feel the need to stick their arm out in front of you when they slam on brakes where I had that arm come m across my middle a couple times. And both my kids have. Right. Because I remember those days where you reached your arm out to stop the kids from.
Speaker B: Well, in, in, in a few years, I think people will have the same reaction where they'll be telling stories of, before cmmc, we could just do all this stuff and, and, and all that.
Speaker A: Your Uncle Bobby came home from school and took care of it, you know,
Speaker B: uh, and I think all the like, entry level people who start getting into this industry now, they'll be like, wow, like, I can't imagine ever not, not doing this type of thing. Right. It's just gonna take, you know, another five years for, for everybody to get used to it. But then it'll become the new normal and everybody will be kicking themselves thinking, wow, I can't believe we never did
Speaker A: this sooner, you know, and by then I hopefully will be sitting on a beach somewhere sipping on a mica full time with my rottweilers hanging out around me.
Speaker B: Well, I appreciate you so much for coming on here and explaining the whole history of it all. Um, you've really been amazing here today, Stacy, so I really appreciate your time.
Speaker A: Anytime. This stuff is fun stuff. While we were going through it, it didn't feel quite so fun. But now today it's a good stuff
Speaker C: story and yeah, I guess thank you for your service.
Speaker B: Amazing. What you really, uh, yeah.
Speaker A: 37 years. Can you believe it? I mean, I'm like, I gotta go get facelift or something.
Speaker B: Well, appreciate your time. Um, I hope you have a great rest of your week and um, we'll talk to you soon.
Speaker C: That is another episode of Trust issue in this conversation. Help you think differently about compliance, security or trust. Share it to help someone who is still stuck in a checkbox mode. Each week we will keep bringing you more episodes, resources and real world insight from the BMO team. Wherever you are listening from, don't forget to rate the podcast and follow us to stay up to date on the latest development in the GRC space. Remember, compliance gets you certified. But remember, security that earn trust. Thank you for listening.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.