By Vin DiPippo, Chief Technology Officer, Vertikal6
Vin leads CMMC Level 1 and Level 2 implementation for defense contractors and manufacturers across the DIB, working on the implementation side of the program rather than assessment.
No. Stay the course.
The Department of War’s July 13th suspension of phases two through four of the implementation of the CMMC program does not lift your obligation to implement the NIST 800-171 controls. For the vast majority of defense contractors, the situation is relatively unchanged.
We are now in the third week of our industry grappling with the effects and ramifications of that announcement. It has been quite a stretch of blogs and articles. I won’t hazard an estimate, but on this particular topic I have seen an extraordinary number of corrections and retractions, because the topic itself is fluid. I have written and revised this entry no fewer than six times as things changed underneath me. So, as I sit here attempting to actually publish something, the only message I can pull from these events is this: stay the course.
Why Is Unwinding CMMC Harder Than Building It Was?
Unwinding CMMC is confusing and uncertain because of the vast amount of legislative and regulatory infrastructure that had to have its gears meshed to get us to this point.
CMMC was codified in Title 32 of the Code of Federal Regulations. It has a statutory basis. It was run through the rulemaking process prescribed by the Administrative Procedure Act, which is also federal law. It then took us a while after Title 32 to get the Title 48 rule through that same process, prescribing that CMMC be included in contracts. Title 32 prescribed four phases of implementation, and the last three of those have now been suspended.
There is a 60-day period of review by a task force consisting of layers of participants, some who were involved in the initial creation and deployment of CMMC into the Code of Federal Regulations, some who were not. Their report is due in 60 days to the DoW CIO. Release to the public could come shortly thereafter. Or it could go the route of rulemaking and take another year to take effect.
What Was the Department Actually Saying by Suspending CMMC?
The Department was saying that the legislative and regulatory infrastructure around CMMC created a climate of overly complex and seemingly incomplete, out-of-date, and out-of-touch compliance that had become the thing, while the main thing — which is to ensure defense contractors and the information they handle are protected from cybersecurity threats as they conduct their business with the DoW — seemed out of reach. Whether you agree with it or not, in an attempt to secure the defense industrial base, we were poised to do it harm.
In light of this, the DoW decided to suspend implementation, take a step back, and see if they can create something more scalable that is still secure.
What Hasn’t Changed About Your Security Obligations?
Nothing about the underlying security problem has changed, which is why the obligation to implement the controls hasn’t either. It helps to remember what CMMC was built on.
CMMC is the validation mechanism for the implementation of NIST SP 800-171. Here is the stack it rests on:
- NIST SP 800-171 — 110 security controls, companioned by 320 assessment objectives that tell you how those controls are supposed to be implemented by way of how they are assessed.
- NIST SP 800-53 — the control set for federal systems, which 800-171 distills down for non-federal systems that interact with the federal government.
- The DoD scoring mechanism — the score, layered onto 800-171, that defense contractors enter into government systems.
- Controlled unclassified information — a government-wide, consistent standard for classifying information that needs special security or handling, created by an Executive Order and backed by federal regulations.
800-53 and the entire concept of controlled unclassified information both stem from failures within the federal government to protect its citizenry: disparate security postures, inconsistent standards, and an inability to communicate important information because of differing classification systems. The goal of fixing those problems has not changed. And if you look at the publication dates, these are turn-of-the-century problems, not problems from the past several years.
What Does Staying the Course on Cyber Hygiene Look Like?
Staying the course means implementing basic security controls across your whole environment, not just a scoped subset. One of the unique features of CMMC is its scoping exercise, where a company can legitimately reduce the number of employees and assets handling controlled unclassified information to reduce the scope of the control implementation.
But as an implementer, no one would find it reasonable to have a company implement basic security controls on only a subset of their systems and leave everything else unprotected. It just makes no sense. You wouldn’t install antivirus on only a subset of systems. You wouldn’t have only a few users using MFA. When it comes to some of the higher security measures, scoping certainly helps. But if the company does not have good cyber hygiene across the board, you will find that their ability to implement it for a scoped enclave is severely impaired.
How Much Does Assessor Variability Affect a CMMC Audit?
Assessor variability is real, even with strong training behind the program. For CMMC, the Cyber AB and the CAICO did an excellent job of providing training, scenarios, and an ISO-backed accreditation body to ensure that CMMC assessors were as consistent as possible. But you always have variability in how one auditor interprets whether a control meets the control objectives as implemented.
That points, again, to where CMMC became more about the process, the regulation, and the compliance than about the goal: protecting this information from foreign adversaries who will exploit the uncommon paths to get to it, well beyond what you could imagine. And with the advent of AI, every company is vulnerable to attacks from relatively low-cost technology. Imagine what foreign adversaries are doing with it.
If I could have only one meaningful change to CMMC — and indeed the entire cybersecurity industry — it would be to create an atmosphere where we wrestle with identifying real and realistic threats and then implement effective barriers (plural) to the exploitation of those threats as a continuous security program. If we can move to doing that far more than we wrestle with interpreting each and every word in a compliance framework, I believe the strides we will make will be strikingly different from the compliance burden perceived by so many today.
What Practical Conclusions Should Contractors Draw from the Suspension?
The practical conclusion is that customers under audit obligations that transcend the suspension are still required to implement the 800-171 controls (DFARS 7012, DIBCAC, etc.). Many were required to do so long before CMMC was ever scheduled to appear in contracts across the board. There are also very real consequences to glossing over security obligations in the performance of federal contracts, namely, crippling penalties under the False Claims Act.
So, people like me, who geek out over U.S. Code, the Code of Federal Regulations, rulemaking, and standards — and consume what may be an unhealthy amount of content on the subject — can see both sides. We can see what we were all trying to accomplish, and where it may have become a burden that lost the plot. I’ll leave that to the reader to decide.
Why Does Staying the Course Still Matter?
Cyber hygiene is not something you can put off, which is why the message is worth repeating: stay the course. The ramifications for the contracts you receive from the government and the certifications you are pursuing remain a case-by-case determination — and I will tell you that most cases are relatively unchanged.
I’ll be honest: I have been accused of flag waving in the past for saying it this way. But we do have adversaries who are not interested in encrypting our files in a very noisy way to get Bitcoin into their pockets. Nation-state actors also conduct those types of attacks, but those attacks are simply meant to line their coffers to fund their higher goals — to steal technology, match our capabilities, and threaten our way of life.
I will take the criticism of being a patriotic flag waver. But I can see the straight line connecting cyber hygiene and those adversaries who would seek to steal our secrets in an increasingly technological world that now includes AI threats we would never have imagined ten years ago.
So please, stay the course. Seek guidance on your cyber hygiene as the rubber-meets-the-road item, and — inexorably linked, but separately — on your regulatory obligations as they pertain to the defense work on which you rely.