Ooey Cooey
Expert advice about Controlled Unclassified Information (CUI).
www.the-cyberadvisor.com
Ooey Cooey
CMMC RFI Response
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Why This RFI Response Matters
SPEAKER_01Hello and welcome back to UI Kui. I'm Leslie Weinstein. I really wanted to record an episode about my CMMC RFI response. And for the last week or so, I've been trying to come up with a good script. However, this morning, as I was finalizing my RFI response to send into the department, Adobe kindly offered to generate a deep dive podcast episode with two participants, which I will now play for you.
The Core Problem With CMMC
SPEAKER_00Welcome to the episode. Today we're breaking down a proposal to reform the Cybersecurity Maturity Model Certification, or CMMC. You know, that's the system the Department of Defense uses to make sure defense contractors protect sensitive info.
SPEAKER_02Right, and this comes from Leslie Weinstein, who's got over 20 years working in cybersecurity and national security. She's worked with more than 100 defense contractors on CMMC stuff.
SPEAKER_00What's interesting is Leslie wants to reduce the compliance burden, especially for small businesses, while still boosting overall security. That's a tricky balance.
SPEAKER_02Yeah, like recognizing equivalent assessments so companies don't have to jump through the same hoops twice. And expanding government support to help smaller contractors get up to speed.
SPEAKER_00Plus, she suggests moving away from a simple pass-or-fail certification to a more detailed cybersecurity assessment that could give a clearer picture of risks.
SPEAKER_02Makes sense. It's about making cybersecurity manageable without letting standards slip, a smart approach for the defense industrial base.
SPEAKER_00It turns out that the widely accepted model for CMMC certification, where contractors must obtain a binary pass or fail certification exclusively from a limited set of government-approved assessors actually inflates costs, restricts market competition, and provides little meaningful insight into actual cybersecurity risk.
SPEAKER_02Really? That sounds counterintuitive. I mean you'd think having a strict, centralized certification process would improve security, not make things worse.
SPEAKER_00Yeah, exactly. But the reality is quite different. This approach burdens small contractors with disproportionate costs, sometimes eating up most of their entire cybersecurity budget, and yet it fails to deliver a reliable measure of their cybersecurity posture. That's a big deal because it potentially leaves critical supply chains vulnerable.
SPEAKER_02Wow. So if I'm hearing you right, the current system might actually be undermining the very security it's supposed to enforce? That's wild. What can listeners expect to learn from this?
SPEAKER_00By the end of this episode, you'll understand the key systemic flaws in the current CMMC program and the nuanced policy reforms proposed to reduce compliance burdens while genuinely improving cybersecurity across the defense industrial
Small Business Cost Reality
SPEAKER_00base.
SPEAKER_02Okay, let's unpack that. Starting with the cost drivers and operational challenges for small businesses, what's really going on there?
SPEAKER_00Well, small defense contractors typically have annual cybersecurity budgets around $100,000. That has to cover everything. Technology, personnel, training, compliance, the whole nine yards.
SPEAKER_02And how much does a single CMMC assessment cost?
SPEAKER_00Anywhere from $20,000 to $75,000. So you're talking about a single assessment potentially consuming up to three-quarters of their entire cybersecurity budget.
SPEAKER_02That's staggering. No wonder small businesses struggle. But is it just about money?
SPEAKER_00Not entirely. Many small businesses also lack the internal expertise to interpret the NIST SP 800 to 171 requirements properly, define the right assessment boundaries, identify controlled unclassified information CUI, and prepare assessment ready evidence.
SPEAKER_02So it's not a lack of commitment, but a lack of resources and know-how?
SPEAKER_00Exactly. It's a resource constraint problem, not a willingness problem. And that makes compliance a heavy operational burden for these companies.
SPEAKER_02That makes sense. But what about the assessment market itself? I've heard there's some kind of monopoly going on.
The Assessor Monopoly Issue
SPEAKER_00Right. The Department of Defense currently requires assessments exclusively from cyber A B approved CMMC third-party assessment organizations or C3 PAOs.
SPEAKER_02So only these C three PAOs can perform the assessments?
SPEAKER_00Yes, and that exclusivity creates a government-created monopoly. It limits supply, reduces competition, and drives up prices.
SPEAKER_02That sounds like a textbook case of supply and demand gone wrong.
SPEAKER_00Exactly. The result is higher costs, longer wait times, and fewer choices for contractors.
SPEAKER_02But aren't there other qualified assessors out there?
SPEAKER_00Absolutely. CPA firms, law firms, Hitrust authorized external assessors, FedRAMP third-party assessment organizations all have decades of experience performing cybersecurity assessments with comparable rigor.
SPEAKER_02So restricting assessments to C3 PAOs hasn't actually improved cybersecurity outcomes?
SPEAKER_00That's right. There's no measurable improvement. Instead, it just increases costs and limits access.
SPEAKER_02That's a huge missed opportunity. Now, shifting gears a bit, what about the actual security controls?
Controls That Actually Reduce Risk
SPEAKER_02Are there specific ones that really move the needle?
SPEAKER_00Yes. From experience in a large financial institution, a small set of foundational controls serve as mandatory security gates before any system can enter production.
SPEAKER_02Which controls are those?
SPEAKER_00Multifactor authentication, encryption of data at rest and in transit, role-based access control with least privilege, and strong identity and access management processes.
SPEAKER_02Those are pretty well known, but it's interesting to hear they're considered foundational gates.
SPEAKER_00They directly reduce the likelihood and impact of unauthorized access to CUI. So they're critical.
SPEAKER_02Got it. Now I'm curious about the assessment scores themselves.
Why SPRS Scores Mislead
SPEAKER_02Do they really reflect the actual cybersecurity posture?
SPEAKER_00That's a big problem. Many organizations misunderstand how to perform self-assessments. They often evaluate only the 110 NIST 800 to 171 requirements without assessing all the associated objectives in NIST 800 to 171A.
SPEAKER_02So they're missing part of the picture?
SPEAKER_00Exactly. Plus, the DOD's Supplier Performance Risk System, or SPRS, scoring methodology is complex and can understate actual cybersecurity capabilities.
SPEAKER_02How so?
SPEAKER_00If even a single assessment objective under a requirement isn't met, the entire requirement is marked as not implemented. That can make the score look worse than the reality.
SPEAKER_02That seems overly harsh.
SPEAKER_00It is. And on the flip side, a perfect score only reflects a point-in-time snapshot of control implementation. It doesn't measure maturity, effectiveness, or resilience.
SPEAKER_02So the binary, score-focused approach gives limited insight into real operational risk.
SPEAKER_00Exactly.
SPEAKER_02Okay, so what are the key policy recommendations to fix these issues?
Policy Reforms And New Models
SPEAKER_00There are several, but let's start with recognizing equivalent independent assessment organizations.
SPEAKER_02Meaning?
SPEAKER_00Expanding the pool of authorized assessors beyond just C3 PAOs to include qualified CPA firms, law firms, HIT Rust assessors, FedRAMP 3 PAOs, and others.
SPEAKER_02That would increase competition and reduce costs?
SPEAKER_00Yes, without sacrificing rigor. The proposal includes requirements like U.S. ownership, assessor qualifications, independence policies, and quality assurance processes.
SPEAKER_02That sounds like a smart way to leverage existing expertise.
SPEAKER_00Definitely. Next, expanding government-sponsored cybersecurity assistance for small businesses and new entrants.
SPEAKER_02How would that work?
SPEAKER_00Small businesses could satisfy initial assessment requirements by actively participating in approved government-sponsored programs like the NSA Cybersecurity Collaboration Center or the DOD Defense Industrial Base Cybersecurity Program.
SPEAKER_02So instead of paying for a costly assessment up front, they get ongoing support?
SPEAKER_00Exactly. It reduces upfront costs and builds cybersecurity capabilities over time.
SPEAKER_02That's a more sustainable approach.
SPEAKER_00Agreed. Then, expanding the Defense Industrial Base Cybersecurity Assessment Center's capacity by contracting directly with C3 PAOs to perform no cost assessments on behalf of the government.
SPEAKER_02So the government would pay for assessments and prioritize based on mission criticality?
SPEAKER_00Yes, rather than leaving it to contractors? Ability to pay. They propose an open, multiple award contract vehicle, similar to the General Services Administration's multiple award schedule.
SPEAKER_02That's a clever analogy. It allows continuous expansion of qualified assessors.
SPEAKER_00Exactly. It increases capacity, reduces costs, shortens wait times, and better allocates resources.
SPEAKER_02What about controlling the spread of CUI in the supply chain?
SPEAKER_00That's where requiring CUI mitigation plans for prime contractors comes in.
SPEAKER_02What's involved in those plans?
SPEAKER_00Primes must identify anticipated CUI categories, define controlled distribution strategies to limit access only to necessary subcontractors, describe how they verify subcontractors, ability to protect CUI, and include strategies to reduce compliance burdens on small business subcontractors.
SPEAKER_02So it's about least privilege information sharing?
SPEAKER_00Exactly. It reduces the attack surface, lowers compliance costs, and improves supply chain security.
SPEAKER_02And the quality of these plans would be an evaluation factor in source selection?
SPEAKER_00Yes, incentivizing primes to minimize unnecessary CUI dissemination.
SPEAKER_02That's a practical, risk-based approach.
SPEAKER_00Definitely. Then expanding government-sponsored cybersecurity services beyond just information sharing.
SPEAKER_02Like what?
SPEAKER_00Services such as NIST 800 to 171 assessments, managed security services, secure enclave and fully managed operating environment solutions, continuous monitoring, vulnerability assessments, incident response, identity and access management, encryption and governance support.
SPEAKER_02And they'd establish open multiple award contract vehicles for commercial providers?
SPEAKER_00Yes, allowing continuous participation and competition.
SPEAKER_02Funding would prioritize services implementing foundational controls?
SPEAKER_00Exactly. Those that provide the greatest risk reduction impact.
SPEAKER_02That ties back nicely to the foundational controls we talked about earlier.
SPEAKER_00It does. Next, expanding government-sponsored secure CEI environments.
SPEAKER_02What are the key deployment models there?
SPEAKER_00Two main ones.
SPEAKER_02The Army's NCODE pilot is an example, right?
SPEAKER_00Yes, a successful pilot demonstrating secure enclave deployment.
SPEAKER_02Expanding these models to all small businesses would reduce compliance burdens and improve CUI protection.
SPEAKER_00Exactly. It leverages economies of scale and lets contractors focus on their mission.
SPEAKER_02Now, what about the certification model itself?
SPEAKER_00The recommendation is to replace the binary pass or fail CMMC certification with standardized independent cybersecurity assessment reports.
SPEAKER_02Like the reports used in SOC2 or ISO 27001 audits.
SPEAKER_00Exactly. These reports include assessor qualifications, assessment period and scope, environment type, narrative summaries by control family, independent assessor opinions, and lead assessor attestations.
SPEAKER_02And they exclude sensitive technical details?
SPEAKER_00Yes, to avoid aiding adversaries.
SPEAKER_02That provides richer, risk-based decision support and encourages continuous improvement.
SPEAKER_00Right. Plus, allowing any department recognized assessor to prepare these reports expands access and competition.
SPEAKER_02That's a big shift from a checkbox mentality to a more mature assurance approach.
SPEAKER_00Definitely. Then, adopting a risk-based assessment methodology.
SPEAKER_02What's wrong with the current SPRS scoring?
SPEAKER_00It weights governance and program management controls more heavily than foundational technical controls that directly protect CUI.
SPEAKER_02So it disincentivizes prioritizing the most impactful controls like MFA and encryption?
SPEAKER_00Exactly. A revised risk-based weighting would better reflect actual cybersecurity value and incentivize effective safeguards.
SPEAKER_02That makes sense. Finally, aligning DOD cybersecurity requirements with the current NIST SP 800 to 171 versions.
SPEAKER_00Right now, the DoD incorporates fixed versions into regulations, causing delays in adopting updated practices.
SPEAKER_02So the defense industrial base ends up behind the broader cybersecurity community?
SPEAKER_00Yes. The recommendation is to adopt a policy of aligning with the current NIST version per NIST's transition timelines.
SPEAKER_02That would give contractors predictable schedules and reduce uncertainty.
SPEAKER_00Exactly.
SPEAKER_02So putting it all together, these reforms aim to reduce the disproportionate burden on small businesses, improve supply chain security, and align DoD practices with mature industry standards.
SPEAKER_00Yes, expanding assessment capacity and eligibility, providing government-sponsored assistance and secure environments, shifting to risk-based narrative reports, and requiring CUI mitigation plans represent a paradigm shift.
SPEAKER_02From compliance as a checkbox to cybersecurity as a continuous, risk-informed process.
SPEAKER_00Exactly, and that could lower costs, increase competition, improve cybersecurity outcomes, and better protect national security.
SPEAKER_02It's a comprehensive roadmap for meaningful reform. Definitely food for thought for anyone involved in defense industrial-based cybersecurity.
SPEAKER_00Absolutely. Hopefully these recommendations gain traction and lead to real change.
SPEAKER_02Agreed. Thanks for breaking this down so thoroughly. Anytime.
Leslie’s Nine Recommendations Recap
SPEAKER_01But in all seriousness, I don't think this episode did a great job of identifying and clearly articulating each of my policy recommendations, so I want to briefly recap those now. Number one, I think the DoD should recognize equivalent independent assessment organizations outside of the C three PAOs. Number two, the DoD should expand government-sponsored cybersecurity assistance for small business and new DIB entrants. Number three, the DoD should expand DICAC assessment capacity through government contracting with C three PAOs. Number four, the DoD should require CUI mitigation plans for prime contractors. Number five, the DoD should expand government-sponsored cybersecurity services beyond small business and new entrants and provide more services in general. Number six, the DoD should expand government-sponsored secure CUI environments. Number seven, the DoD should replace binary CMMC certifications with a standardized, independent cybersecurity assessment report. Number eight, the DoD should adopt a risk-based assessment methodology. And my final recommendation, number nine, is that the DoD should align cybersecurity requirements with current versions of NIST 800-171. And as a reminder, each one of my recommendations are meant to be a standalone recommendation and not necessarily being dependent upon other of my recommendations being implemented.
Where To Read The Full RFI
SPEAKER_01I have posted my full RFI response on my website at www.thethe-cyberadvisor.com. Everything on my site related to CMMC can be found in the CMMC FAQ section. As always, thank you so much for listening. If you ever have any questions, please feel free to reach out to me through my website. And until next time, please don't say cooey because that would be very ooey.
Podcasts we love
Check out these other fine podcasts recommended by us, not an algorithm.
Main Justice
MS NOW, Andrew Weissmann, Mary McCord
Strict Scrutiny
Strict Scrutiny