Ooey Cooey

CMMC RFI Response

The Cyber Advisor

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 16:37

Why This RFI Response Matters

SPEAKER_01

Hello and welcome back to UI Kui. I'm Leslie Weinstein. I really wanted to record an episode about my CMMC RFI response. And for the last week or so, I've been trying to come up with a good script. However, this morning, as I was finalizing my RFI response to send into the department, Adobe kindly offered to generate a deep dive podcast episode with two participants, which I will now play for you.

The Core Problem With CMMC

SPEAKER_00

Welcome to the episode. Today we're breaking down a proposal to reform the Cybersecurity Maturity Model Certification, or CMMC. You know, that's the system the Department of Defense uses to make sure defense contractors protect sensitive info.

SPEAKER_02

Right, and this comes from Leslie Weinstein, who's got over 20 years working in cybersecurity and national security. She's worked with more than 100 defense contractors on CMMC stuff.

SPEAKER_00

What's interesting is Leslie wants to reduce the compliance burden, especially for small businesses, while still boosting overall security. That's a tricky balance.

SPEAKER_02

Yeah, like recognizing equivalent assessments so companies don't have to jump through the same hoops twice. And expanding government support to help smaller contractors get up to speed.

SPEAKER_00

Plus, she suggests moving away from a simple pass-or-fail certification to a more detailed cybersecurity assessment that could give a clearer picture of risks.

SPEAKER_02

Makes sense. It's about making cybersecurity manageable without letting standards slip, a smart approach for the defense industrial base.

SPEAKER_00

It turns out that the widely accepted model for CMMC certification, where contractors must obtain a binary pass or fail certification exclusively from a limited set of government-approved assessors actually inflates costs, restricts market competition, and provides little meaningful insight into actual cybersecurity risk.

SPEAKER_02

Really? That sounds counterintuitive. I mean you'd think having a strict, centralized certification process would improve security, not make things worse.

SPEAKER_00

Yeah, exactly. But the reality is quite different. This approach burdens small contractors with disproportionate costs, sometimes eating up most of their entire cybersecurity budget, and yet it fails to deliver a reliable measure of their cybersecurity posture. That's a big deal because it potentially leaves critical supply chains vulnerable.

SPEAKER_02

Wow. So if I'm hearing you right, the current system might actually be undermining the very security it's supposed to enforce? That's wild. What can listeners expect to learn from this?

SPEAKER_00

By the end of this episode, you'll understand the key systemic flaws in the current CMMC program and the nuanced policy reforms proposed to reduce compliance burdens while genuinely improving cybersecurity across the defense industrial

Small Business Cost Reality

SPEAKER_00

base.

SPEAKER_02

Okay, let's unpack that. Starting with the cost drivers and operational challenges for small businesses, what's really going on there?

SPEAKER_00

Well, small defense contractors typically have annual cybersecurity budgets around $100,000. That has to cover everything. Technology, personnel, training, compliance, the whole nine yards.

SPEAKER_02

And how much does a single CMMC assessment cost?

SPEAKER_00

Anywhere from $20,000 to $75,000. So you're talking about a single assessment potentially consuming up to three-quarters of their entire cybersecurity budget.

SPEAKER_02

That's staggering. No wonder small businesses struggle. But is it just about money?

SPEAKER_00

Not entirely. Many small businesses also lack the internal expertise to interpret the NIST SP 800 to 171 requirements properly, define the right assessment boundaries, identify controlled unclassified information CUI, and prepare assessment ready evidence.

SPEAKER_02

So it's not a lack of commitment, but a lack of resources and know-how?

SPEAKER_00

Exactly. It's a resource constraint problem, not a willingness problem. And that makes compliance a heavy operational burden for these companies.

SPEAKER_02

That makes sense. But what about the assessment market itself? I've heard there's some kind of monopoly going on.

The Assessor Monopoly Issue

SPEAKER_00

Right. The Department of Defense currently requires assessments exclusively from cyber A B approved CMMC third-party assessment organizations or C3 PAOs.

SPEAKER_02

So only these C three PAOs can perform the assessments?

SPEAKER_00

Yes, and that exclusivity creates a government-created monopoly. It limits supply, reduces competition, and drives up prices.

SPEAKER_02

That sounds like a textbook case of supply and demand gone wrong.

SPEAKER_00

Exactly. The result is higher costs, longer wait times, and fewer choices for contractors.

SPEAKER_02

But aren't there other qualified assessors out there?

SPEAKER_00

Absolutely. CPA firms, law firms, Hitrust authorized external assessors, FedRAMP third-party assessment organizations all have decades of experience performing cybersecurity assessments with comparable rigor.

SPEAKER_02

So restricting assessments to C3 PAOs hasn't actually improved cybersecurity outcomes?

SPEAKER_00

That's right. There's no measurable improvement. Instead, it just increases costs and limits access.

SPEAKER_02

That's a huge missed opportunity. Now, shifting gears a bit, what about the actual security controls?

Controls That Actually Reduce Risk

SPEAKER_02

Are there specific ones that really move the needle?

SPEAKER_00

Yes. From experience in a large financial institution, a small set of foundational controls serve as mandatory security gates before any system can enter production.

SPEAKER_02

Which controls are those?

SPEAKER_00

Multifactor authentication, encryption of data at rest and in transit, role-based access control with least privilege, and strong identity and access management processes.

SPEAKER_02

Those are pretty well known, but it's interesting to hear they're considered foundational gates.

SPEAKER_00

They directly reduce the likelihood and impact of unauthorized access to CUI. So they're critical.

SPEAKER_02

Got it. Now I'm curious about the assessment scores themselves.

Why SPRS Scores Mislead

SPEAKER_02

Do they really reflect the actual cybersecurity posture?

SPEAKER_00

That's a big problem. Many organizations misunderstand how to perform self-assessments. They often evaluate only the 110 NIST 800 to 171 requirements without assessing all the associated objectives in NIST 800 to 171A.

SPEAKER_02

So they're missing part of the picture?

SPEAKER_00

Exactly. Plus, the DOD's Supplier Performance Risk System, or SPRS, scoring methodology is complex and can understate actual cybersecurity capabilities.

SPEAKER_02

How so?

SPEAKER_00

If even a single assessment objective under a requirement isn't met, the entire requirement is marked as not implemented. That can make the score look worse than the reality.

SPEAKER_02

That seems overly harsh.

SPEAKER_00

It is. And on the flip side, a perfect score only reflects a point-in-time snapshot of control implementation. It doesn't measure maturity, effectiveness, or resilience.

SPEAKER_02

So the binary, score-focused approach gives limited insight into real operational risk.

SPEAKER_00

Exactly.

SPEAKER_02

Okay, so what are the key policy recommendations to fix these issues?

Policy Reforms And New Models

SPEAKER_00

There are several, but let's start with recognizing equivalent independent assessment organizations.

SPEAKER_02

Meaning?

SPEAKER_00

Expanding the pool of authorized assessors beyond just C3 PAOs to include qualified CPA firms, law firms, HIT Rust assessors, FedRAMP 3 PAOs, and others.

SPEAKER_02

That would increase competition and reduce costs?

SPEAKER_00

Yes, without sacrificing rigor. The proposal includes requirements like U.S. ownership, assessor qualifications, independence policies, and quality assurance processes.

SPEAKER_02

That sounds like a smart way to leverage existing expertise.

SPEAKER_00

Definitely. Next, expanding government-sponsored cybersecurity assistance for small businesses and new entrants.

SPEAKER_02

How would that work?

SPEAKER_00

Small businesses could satisfy initial assessment requirements by actively participating in approved government-sponsored programs like the NSA Cybersecurity Collaboration Center or the DOD Defense Industrial Base Cybersecurity Program.

SPEAKER_02

So instead of paying for a costly assessment up front, they get ongoing support?

SPEAKER_00

Exactly. It reduces upfront costs and builds cybersecurity capabilities over time.

SPEAKER_02

That's a more sustainable approach.

SPEAKER_00

Agreed. Then, expanding the Defense Industrial Base Cybersecurity Assessment Center's capacity by contracting directly with C3 PAOs to perform no cost assessments on behalf of the government.

SPEAKER_02

So the government would pay for assessments and prioritize based on mission criticality?

SPEAKER_00

Yes, rather than leaving it to contractors? Ability to pay. They propose an open, multiple award contract vehicle, similar to the General Services Administration's multiple award schedule.

SPEAKER_02

That's a clever analogy. It allows continuous expansion of qualified assessors.

SPEAKER_00

Exactly. It increases capacity, reduces costs, shortens wait times, and better allocates resources.

SPEAKER_02

What about controlling the spread of CUI in the supply chain?

SPEAKER_00

That's where requiring CUI mitigation plans for prime contractors comes in.

SPEAKER_02

What's involved in those plans?

SPEAKER_00

Primes must identify anticipated CUI categories, define controlled distribution strategies to limit access only to necessary subcontractors, describe how they verify subcontractors, ability to protect CUI, and include strategies to reduce compliance burdens on small business subcontractors.

SPEAKER_02

So it's about least privilege information sharing?

SPEAKER_00

Exactly. It reduces the attack surface, lowers compliance costs, and improves supply chain security.

SPEAKER_02

And the quality of these plans would be an evaluation factor in source selection?

SPEAKER_00

Yes, incentivizing primes to minimize unnecessary CUI dissemination.

SPEAKER_02

That's a practical, risk-based approach.

SPEAKER_00

Definitely. Then expanding government-sponsored cybersecurity services beyond just information sharing.

SPEAKER_02

Like what?

SPEAKER_00

Services such as NIST 800 to 171 assessments, managed security services, secure enclave and fully managed operating environment solutions, continuous monitoring, vulnerability assessments, incident response, identity and access management, encryption and governance support.

SPEAKER_02

And they'd establish open multiple award contract vehicles for commercial providers?

SPEAKER_00

Yes, allowing continuous participation and competition.

SPEAKER_02

Funding would prioritize services implementing foundational controls?

SPEAKER_00

Exactly. Those that provide the greatest risk reduction impact.

SPEAKER_02

That ties back nicely to the foundational controls we talked about earlier.

SPEAKER_00

It does. Next, expanding government-sponsored secure CEI environments.

SPEAKER_02

What are the key deployment models there?

SPEAKER_00

Two main ones.

SPEAKER_02

The Army's NCODE pilot is an example, right?

SPEAKER_00

Yes, a successful pilot demonstrating secure enclave deployment.

SPEAKER_02

Expanding these models to all small businesses would reduce compliance burdens and improve CUI protection.

SPEAKER_00

Exactly. It leverages economies of scale and lets contractors focus on their mission.

SPEAKER_02

Now, what about the certification model itself?

SPEAKER_00

The recommendation is to replace the binary pass or fail CMMC certification with standardized independent cybersecurity assessment reports.

SPEAKER_02

Like the reports used in SOC2 or ISO 27001 audits.

SPEAKER_00

Exactly. These reports include assessor qualifications, assessment period and scope, environment type, narrative summaries by control family, independent assessor opinions, and lead assessor attestations.

SPEAKER_02

And they exclude sensitive technical details?

SPEAKER_00

Yes, to avoid aiding adversaries.

SPEAKER_02

That provides richer, risk-based decision support and encourages continuous improvement.

SPEAKER_00

Right. Plus, allowing any department recognized assessor to prepare these reports expands access and competition.

SPEAKER_02

That's a big shift from a checkbox mentality to a more mature assurance approach.

SPEAKER_00

Definitely. Then, adopting a risk-based assessment methodology.

SPEAKER_02

What's wrong with the current SPRS scoring?

SPEAKER_00

It weights governance and program management controls more heavily than foundational technical controls that directly protect CUI.

SPEAKER_02

So it disincentivizes prioritizing the most impactful controls like MFA and encryption?

SPEAKER_00

Exactly. A revised risk-based weighting would better reflect actual cybersecurity value and incentivize effective safeguards.

SPEAKER_02

That makes sense. Finally, aligning DOD cybersecurity requirements with the current NIST SP 800 to 171 versions.

SPEAKER_00

Right now, the DoD incorporates fixed versions into regulations, causing delays in adopting updated practices.

SPEAKER_02

So the defense industrial base ends up behind the broader cybersecurity community?

SPEAKER_00

Yes. The recommendation is to adopt a policy of aligning with the current NIST version per NIST's transition timelines.

SPEAKER_02

That would give contractors predictable schedules and reduce uncertainty.

SPEAKER_00

Exactly.

SPEAKER_02

So putting it all together, these reforms aim to reduce the disproportionate burden on small businesses, improve supply chain security, and align DoD practices with mature industry standards.

SPEAKER_00

Yes, expanding assessment capacity and eligibility, providing government-sponsored assistance and secure environments, shifting to risk-based narrative reports, and requiring CUI mitigation plans represent a paradigm shift.

SPEAKER_02

From compliance as a checkbox to cybersecurity as a continuous, risk-informed process.

SPEAKER_00

Exactly, and that could lower costs, increase competition, improve cybersecurity outcomes, and better protect national security.

SPEAKER_02

It's a comprehensive roadmap for meaningful reform. Definitely food for thought for anyone involved in defense industrial-based cybersecurity.

SPEAKER_00

Absolutely. Hopefully these recommendations gain traction and lead to real change.

SPEAKER_02

Agreed. Thanks for breaking this down so thoroughly. Anytime.

Leslie’s Nine Recommendations Recap

SPEAKER_01

But in all seriousness, I don't think this episode did a great job of identifying and clearly articulating each of my policy recommendations, so I want to briefly recap those now. Number one, I think the DoD should recognize equivalent independent assessment organizations outside of the C three PAOs. Number two, the DoD should expand government-sponsored cybersecurity assistance for small business and new DIB entrants. Number three, the DoD should expand DICAC assessment capacity through government contracting with C three PAOs. Number four, the DoD should require CUI mitigation plans for prime contractors. Number five, the DoD should expand government-sponsored cybersecurity services beyond small business and new entrants and provide more services in general. Number six, the DoD should expand government-sponsored secure CUI environments. Number seven, the DoD should replace binary CMMC certifications with a standardized, independent cybersecurity assessment report. Number eight, the DoD should adopt a risk-based assessment methodology. And my final recommendation, number nine, is that the DoD should align cybersecurity requirements with current versions of NIST 800-171. And as a reminder, each one of my recommendations are meant to be a standalone recommendation and not necessarily being dependent upon other of my recommendations being implemented.

Where To Read The Full RFI

SPEAKER_01

I have posted my full RFI response on my website at www.thethe-cyberadvisor.com. Everything on my site related to CMMC can be found in the CMMC FAQ section. As always, thank you so much for listening. If you ever have any questions, please feel free to reach out to me through my website. And until next time, please don't say cooey because that would be very ooey.

Podcasts we love

Check out these other fine podcasts recommended by us, not an algorithm.

Main Justice Artwork

Main Justice

MS NOW, Andrew Weissmann, Mary McCord
Strict Scrutiny Artwork

Strict Scrutiny

Strict Scrutiny
Law and Chaos Artwork

Law and Chaos

Liz Dye; Andrew Torrez