Go back

June 2026 CMMC Connect

46m 17s

June 2026 CMMC Connect

The June edition of CMMC Connect, hosted by Redspin, addressed key updates and common compliance questions. Jeremy clarified that November 10th is a milestone, not a hard deadline for CMMC certification; certification is needed at contract award, and many organizations will not be certified by then, so having a plan is sufficient. Dr. Graham discussed the re-released federal CUI rule, which foreshadows a shift to Rev3 by year-end, and a new strategy to enforce Post-Quantum Crypto by 2030 via CMMC, potentially leading to Rev4. The first Q&A focused on significant changes requiring reassessment, such as AI/ML tool adoption or M&A activity; the AO determines if scope changes trigger this, but clarity is still pending from the CyberAB. Another question covered defining periods of inactivity for user identifiers, with 5-10 minutes common and compensating controls allowed for operational needs. A final query about Microsoft MTO across multiple GCC High tenants for sister companies with shared users was addressed; this scenario is rare, and separate CAGE codes likely require individual tenants and assessments. The session emphasized proactive planning and engaging with primes or DOD agencies to demonstrate progress.

Transcription

7808 Words, 43652 Characters

English
CyberSpin, topics you care about by people you trust. This is CyberSpin, the podcast that helps you navigate CMMC. And now for the show. Well, hi everyone and thank you for joining us for our June edition of CMMC Connect. We're glad you could be here. It may still be June, but by the time we gather again next month, we'll have celebrated the 4th of July. And this year marks America's 250th birthday. So we hope you have a safe and enjoyable holiday and get the chance to celebrate this historic milestone with your friends and your family. I'm Anika Pastora, Senior Events Marketing Manager here at Redspin and I'll be hosting today's session. As we celebrate our nation's independence, it's also a reminder of the importance of protecting what matters, including the dib that supports our national security. So that's what CMMC Connect is all about bringing the community together each month to share practical insights, answer your questions and help you stay ahead of the latest CMMC developments. It's great to see so many familiar faces today. And if this is your first CMMC Connect, welcome. We're happy to have you and thanks for spending part of your day with us. So Jeremy, will you kick us off with introductions and then we'll go around the room? Sure, absolutely. Jeremy may as VP of federal accounts here at Redspin and kind of head up our sales efforts. If anyone I haven't had an opportunity to speak with in the past and with that, I will pass the torch to Dr. Graham. Dr. Thomas Graham, VPC. So here at Redspin, if you've been on, you know me. If you haven't been on, then I apologize upfront. Aaron. Well, thanks. Thanks, Thomas. My name is Aaron free tag. I'm a lead CCA, been with Redspin for a year and a half now. Deep in the trenches, performing assessments, a little bit of consulting, but we're quickly building our team and nice to see some fresh faces in today's CMMC Connect. Happy to 50 at the USA. Hey, everybody. It's Uncle Rob. If you notice Thomas is background, I tried to dress the same since it's the 250th. Welcome everybody. Glad you could take time out of your busy schedules to join us over to Pat. I see you, Darium. Pat. It's on you. I got this stuff coming to you. Thank you so much. The Pat Wicker recent addition to the Redspin team previously with DCMA, Dibkack and honored and happy to be here over to you, Monica. Well, I am the senior events marketing manager here at Redspin. Happy to help co-host the session and I'll put you in the hands of Lauren now. Hey, everyone. I'm Lauren Frickle, marketing marketing director here at Redspin. All right. Just a quick reminder that we are currently conducting our third annual CMMC survey. And we need you and your response if we don't have it yet. The survey takes five minutes. It asks you about your CMMC readiness. The challenges you're facing, how you're managing compliance over time, lots of things. Also as something to highlight, as a thank you, we donate $10 for every completed survey response to support veterans through the Gary Sinese. Yes. That is Lieutenant Dan, the Gary Sinese Foundation. Once the survey closes, here in another month or so, we'll analyze the results and publish our third annual CMMC report. And that'll go out later this year and share what we are seeing across the Dib. The survey link is in the chat. So if you have five minutes, even while you're listening to today's session, please take it. Awesome. Thanks, Lauren. Jeremy, over to you. Okay. So we are going to start off with what we call some field updates. And the first of these that we are going to touch on today is November 10th. And the date that everybody is talking about, some folks are climbing up on rooftops, please step back from the ledge. I'm going to do my best to debunk this a little bit for you. So there are a lot of people that are running around on social media and so on and so forth. Screaming about how November 10th is a deadline. November 10th is not a deadline. November 10th is a milestone that simply designates when the DOD will be moving from phase one to phase two of the CMMC rollup. That is the date that they will begin including CMMC requirements in contracts. You do not need to demonstrate CMMC certification until time of award. And typically that would mean that if November 11th, the Army Corps of Engineers issued a contract for bid that is likely not going to be awarded until sometime in early 2027. So there is some time and some flexibility there. I'm not saying anyone should take their foot off the gas and keep driving forward as quickly as they can, but November 10th isn't exactly the deadline it's being made out to be. Now Jeremy, what if we have a prime and they're requiring it? Okay, that's another scenario. The prime contractors can require whatever contractual obligations that they wish to include to their subs as private organizations. However, if you look at the graphic that we have here, this is based off of the last month's CyberAB Town Hall. We haven't had June CyberAB Town Hall yet. That will be taking place next week. And we'll obviously see these numbers increase a bit, but you can kind of see the pace at which they've been climbing over the last several months. As of, you know, the May Town Hall, it was 1391 certs that had been issued. If we map this out to November, the dirty little secret that nobody wants to talk about, but everybody recognizes is there will nowhere near be an entirely certified defense industrial based by November 10th. There are simply not enough individuals certified as assessors. There are not enough C3 P.A.Os to certify everyone by November 10th. And not everyone is ready either. And everybody's working towards it or hopefully working towards it, but not everybody is ready and at that point yet. We have seen across the board with clients of ours who have engaged with us and we have provided them an engagement letter or a test station letter kind of stating, "When their C3 P.A.O. dates are, some of those dates are, you know, after November 10th, you know, December, January, some of them are further out." Across the board, those letters have been universally accepted both by program managers and contracting officers within the DOD agencies, as well as the primes, as everybody recognizes not everyone is going to be able to be certified by November 10th. And this is going to spill over into next year. It's going to take time for everybody to get through this cycle the first time. And really, all everyone wants to see is that you have a plan. It's in action and you are moving towards certification. But Monica, I will throw in. There is a tremendous amount of pressure every year. It's in November 10th. So, as far as November 10th goes, we all recognize everybody is pressing on everyone about it, everyone's pushing hard saying that this is the date that you have to be certified by. But don't jump off of rooftops about this. There are ways to have conversations, you know, with the appropriate folks. And as long as they see that you've got a plan of action in place and are driving towards a date, like we said, we have not seen anyone not accept that. So, with that, I am going to step down from my soapbox and instead hand the soapbox over to Dr. Graham to talk to us about the federal CUI rule. Why? No, so if you're not aware last year, I know since then you've heard us mention periodically KeralC MNC Connect about the federal CUI rule that came out as a proposed rule last fall. So, I'm saying it's been questions whether or not it's going to happen, especially with new DOD CIO. Well, guess what? It's been re-released for public review. It's available now. So go take a look at it. And it's identifying the direction not only GSA, DOD, and NASA is going to go for the protections of CUI. It also has a lot of those elements in there that we've talked about, you know, previously such as still the standard form that identifies not only the types of CUI, but what is to be considered CUI in there. So, as long as it stays into the final version, it should provide some of that much needed clarification. A lot of you guys have been asking for. With it being re-released as a public inspection, this is kind of foreshadowing that more than likely, and none of us here are government, more than likely, it is going to be published as final by the end of the year. And that would be the first step in moving from Rev2 to Rev3 for the department. I say the first step because, of course, you know, there's other things that they'll have to do and go through the process on, but it is indicating where ultimately all of the federal government agencies are going to land, and it looks like Rev3 for right now. The other thing that come out here just in the last day or two is the strategy to move to Post-Quantum Crypto for the department. Now, normally here on CMMC Connect, we stick directly to things related to CMMC in the current ecosystem. The reason why we're mentioning this here is that one of the mechanisms that they're going to use to enforce the adoption of Post-Quantum Crypto is CMMC. It's actually identified in there. If you're not familiar with what Post-Quantum Crypto is, now is the time to start taking a look at it. It's because within the announcement they actually put a deadline of December 31st of 2030, where it either has to be implemented in transition or legacy retired. If it's in transition, you have an additional year, but want to be at least for the department, the enforcement mechanism. to make sure those systems are accounted for. The other part to keep aware of is that as many of you know in the current versions of 871, it mentions the FIPs requirements. Well, if there's gonna be a specific post quantum requirement, that's gonna probably require another revision to 871. So I wouldn't be surprised if we saw Rev4 on the horizon in the next couple of years. If you haven't taken a look at these two, please do, because they are gonna be very, very important in the very near future. And I think that's enough varies, Jeremy. - Excellent. Thank you as always, Dr. Graham, for your expert synopsis. Okay, so we are going to move on into the pre-submitted questions of RCMMC Connect. This first question that was submitted considering material changes, requiring a reassessment. And arrow in the Q&A, I think this ties into what you were actually known. It's later. So, but considering material changes, requiring a reassessment at what point do we cross the line? The implementation guard rails to the explosion of wildly, of widely available AI/ML-based tools, the use of AI agents, the implementation of vibe coding, et cetera. But this does tie to a question that arrow had in the Q&A, kind of asking also about scrolling back up to it. So I can grab it real quick. Arrow had asked, you know, as far as what qualifies as a quote unquote significant change that it's still not entirely clear, even with most recent FAQs. So Aaron, I'm going to let you touch on initially here, you know, where AI comes into play and potentially triggering a reassessment for a significant change. And then if anyone else wants to chime in on the larger significant change topic, that would be great. - Yeah, absolutely. I'll take the first bite at this apple. Anytime that you foresee some changes happening within your environment, that's something that you have to plan for, well in advance, execute your risk management procedures, and thoroughly investigate what that does to the changes within the scope of your system. I've seen a couple of assessments so far where they did utilize AI/ML tools, but you have to be cognizant of how it's processing, storing or transmitting CY within your system, is that AI/ML tool completely in the cloud, is it in a FedRAMP GCC-High Moderate Environment that should be if it's touching CY, or is it completely on-premise within your CY environment? Those are all big things to consider, and much like any other tool change outs within your system. The CMMC FAQ, I believe it's version five up to now, it touches on that in the responsibility of your high level organization, your AO, has to think about those changes within that system. There may be an explosion of some of those tools being used, but like any normal change out for, say, you're swapping one endpoint agent for your, from Windows Defender to something else, that has to be evaluated, and ultimately the responsibility goes on the AO to incorporate that into their system for a reassessment. Dr. Graham, did you want to jump in on that one too? Sure. At the end of the day folks understand, yes, the FAQ information is out there, did it provide more clarity? Yes, did it provide the clarity we wanted, no? But right now, the determination is based on the AO for your organization. I will tell you that the prevailing notion is a reassessment is required if there's any change to the scope of the environment. Now what that means is, well, if you switch from one NMSP to the other, would that necessitate potentially a reassessment? Possibly, because think of this situation, you're going from a CMMC certified MSP to one that isn't certified, or what if you switch your cloud storage from Microsoft to Amazon? Both of those organizations have FedRAMP offerings, but the FedRAMP inheritance or the implementation that shared responsibility matrix may be different. So these are all things that have to be taken into consideration. I can also tell you this is something that's being worked on at the Cybrae B level, and hopefully in the near future, and I was hoping, because I've said this last month, I think, too, hopefully that clarification will be coming soon. I can't tell you at a definitive date, though, but if it was me, if I want to do CYA, if it changes your scope, it's probably going to be something that wouldn't necessitate a reassessment right now. And I know on the same topic, something that comes up pretty often is M&A activity, and within the div, there's quite a bit of M&A, and acquiring a new, maybe multiple small orgs that you're incorporating into your organization. These are typically going to bring in additional sites, and that's going to expand your scope. So that's an area that we get a lot of questions about, is this a significant change if they're bringing in cage codes that typically means you're going to need a reassessment. So these are definitely conversations that we can have specific to your org, and have larger discussions around, and we'd be happy to schedule some time and talk, you know, your specifics, but yes, significant change in what it means, and when you need to get reassessed is definitely something we're all hoping for more clarity on. So next question, what constitutes significant change that could trigger a CMMC level two reassessment? I think we kind of blended into this one already. It kind of already covered this one, but any final thoughts on significant change for anybody before we move to the next? Just that you're affirming officials, the one that really makes that determination. So again, it's left up to interpretation. Apologize on coming out of this stuff. It's too hot. It's left up to interpretations so that you guys can determine it because you understand your networks better than the DOD does. So, you know, again, I don't know if they did that on purpose. I know the CyberAB has a committee that is working to kind of clean that up for us. So unfortunately, we're stuck with it until that happens. Okay, a period of inactivity after which an identifier is disabled is defined as the quote unquote statement there can compensating controls and procedures be used if a period of inactivity for regular users has not been defined. Dr. Graham, this one goes back to you. So since the terminology of regular users has been just being used in the question, I'm just gonna quantify this by saying, I'm taking the perspective of all your endpoints and I'm not flat out, say it. No, you have to define what that period of inactivity is and some matter of fact, when the transition to Rev3 happens, that ODP value I believe has already been defined by the department. Now, right now, is there a hard and fast number? No. For the most part, I've seen that a lot of organizations are kind of settling on 10 minutes, some are five to align with DOD requirements or DOW requirements, but understand that when you define that period, it doesn't necessarily mean it for your entire organization or even your entire scope. There could be operational necessity requirements that would honestly require part of your environment to be one thing and part of your environment to be the other. I'll give you a perfect example, let's say you're in a medical organization, let's say it's a medical center. They have contracts with the government. Well, if you said it to 10 minutes, you probably don't want the surgeon in that operating room, you know, taking his hand, let's say out of your chest every 10 minutes to move the mouse. So more than likely, you have an operational necessity to extend that and that's where those compensating controls and procedures would come in because if let's say it's 45 minutes or let's say it's 60 minutes, whatever case may be. Now to keep that threshold of risk low, you can put other compensating controls and procedures in place. So that way you have a justifiable position once you go through assessment or having for bid. Anything actually occurs such as an instant in your environment, but you still have to define it. Not even sure how to respond to that example you gave it was brilliant. That was really good time. So moving to the next question, multi-tenant organization, Microsoft MTL. I'm looking to maybe use this between my GCC high tenants since users are the same pretty much between all three tenants. I don't want to want to follow anything with CMMC if I were to pursue this, wanted to know if anyone else has successfully implemented something like this. I'm going to tackle this one. We have not seen someone use this before in a GovCloud space with multiple GCC high tenants. We just haven't encountered it. I'm not saying that there isn't anyone out there who has done it. But what we do see a lot of is folks leveraging either the Microsoft subscriptions and Azure DevOps and some of the other tools to segregate groups within one larger tenant into almost multiple sub-tenants within the same overall GCC high tenant. There are a lot of effective ways to do that. Whoever submitted this question, I would love if we could have a separate conversation to really dig a bit deeper into what prompted the path with the multiple GCC high tenants. how it's really just kind of the same users across all three tenants and what each tenants purpose kind of serves. And I might be able to kind of provide some better insight into it. It's just simply a scenario that we haven't run into yet. But there's obviously a good use case for it if you guys are doing that. So I love to learn more about it if we can set something up. So we can jump to the next one month. That was Katie. She dropped a note in the chat. I don't know if we want to unmute her. Maybe yeah. If you want to come on Mike and just chat about it a little bit. You know, Katie, when we first saw your question, if you can go back Monica, when we first saw your question, we were like, what is she doing with three cloud 10? Boy, that's a lot of money. I know. Can you guys hear me? Yes, ma'am. Okay. They're kind of sister companies to the same company, but they're separate cage codes. They're separate. They're separate. Right. But the fact is that we're sharing users between them right like like my CIO for this current company is CEO of that company. But they're all kind of the same. And so I don't know if I'm able to, I mean, they're separate. I don't have them purchased yet, but my intent was they're going to be separate GCCI tenants. They're most likely separate subscriptions for Azure government. I don't know if I need to though. Could they all run on one, but be separate tenants. And then in that case is MTO going to kind of save my vacant in licensing costs, right? Because they're the same people, but I want to make sure that our work is separate, right? Because they are separate cage codes. We are, you know, attesting separately insurers and all the things. And so I'm, I haven't committed to it. I did ask Microsoft directly on the current GCCI tenant I have is this even possible between GCCI tenants. And they said, yes, you can't go from GCCI to GCC moderate. Like, okay, that's fine. I guy, all right, just forget that I can go on. But I don't, I'm not saying I'm unique in this, in this endeavor. But like I said, we've got to say like the core same five people are from one to the next. It's just that they're separate cage code. So I need to separate those environments for any CUI that might come in. And that makes sense. And we were kind of wondering if it was, you know, something along like joint ventures or, you know, something cage code related. One is a joint venture for sure. Okay. The other one is just plain separate. We market to separate contracts, right? It's a, it's a veteran owned, you know, company. And so it's, it's a separate venture. It's not a joint venture. Where's the third one is a joint venture. And Katie, are you in Minnesota? Are you a Minnesotaian? South Dakota. South Dakota. Okay. Yeah. I think there's a rule out there in South Dakota. You can't have more than one cloud. So Jeremy, you want to talk about that? So before Jeremy, before Jeremy takes that over, Katie, I will let you know this. There is further guidance on how to properly handle joint ventures that's going to be forthcoming as well. I've seen the draft version of it. I think it's going to provide some of the clarity that that you're looking for is just, unfortunately, it's not out in the larger ecosystem yet. So at least for the joint venture component, I would say take a look at that before you make any hard and fast decisions. And also reach out to Jeremy, he can kind of, him and the cloud team can kind of work with you to help kind of get you in a right direction. You know, we've seen organizations out there that have multiple cage codes in one environment. Right. Hopefully what they do in that cloud environment is segment that cloud and then give each of those cage codes their own little piece of it, if you will. But then the management is, is, you know, centralized to just one team because you're managing just one cloud. So there's definitely many ways you can tackle this. Obviously cost savings has to be the number one thing in your mind, Katie, as you're starting to put this together. So yeah, definitely please reach out to Jeremy and have this conversation. Yeah, Adrian had dropped something in the chat just kind of mentioning that, you know, his team has two environments, one for prod, one for dev. We see that a lot where, you know, somebody may have an Azure Gov cloud for their CUI environment for prod, but they've got something in AWS for dev. We've seen a lot of folks with GCC high clouds beginning to move to Azure DevOps and leveraging Azure DevOps within our GCC high environment, you know, the dev guys get access to the Azure DevOps region, whereas, you know, the other users are in more of the traditional cloud portion of the tenant. And then it looks like Scott mentioned something about, you know, having multiple companies under a single tenant. We see that a lot, you know, where there's like a parent org or, you know, somebody has the primary on the tenant. And then as Rob said, you know, additional KH codes, additional entities, as long as everybody's essentially operating on a single system security plan and corporately defined policies and procedures that are the same across each, then you can essentially have everybody operating within the same cloud and just use, you know, subtenance and segmentation and such to kind of give each team its own space. Obviously, some users can be designated to have access to multiple, you know, portions or segments that catches if everybody's not operating on a single SSP and not, and everybody's not using all the same corporately defined policies and procedures and such to where there's variances between the orgs. Then I don't know how well the MTO component works in tandem with that, you know, that would take a little research on my part, but I'm definitely happy to have follow conversations on this Katie. Sounds good. Thank you. And I would offer just at a minimum, you hit a key point with the system security plan, the 320 requirement speaks specifically to connections to external systems. So at a minimum, you would just ensure that that external connection is reflected in the system security plan and addressed within the 3120 requirement. Thanks. And also to add on the pads, if there is any deviations between those 3 tenants, right? For example, physical security requirements may be different at each one of those locations. You just call out each location in that particular objective and describe what each one is doing, and that's how you kind of capture all that. Okay. I think we're ready Monica. Sorry. This was a great question. So thanks Katie for submitting that. Appreciate it. Yeah. Ready. Okay. What requirements and policy should you have in place for remote work? Do employees need to be on a separate Wi-Fi network from the rest of their household? What about connecting to hotel Wi-Fi while you're on business trips where Wi-Fi passwords are often just last name and room number? This question comes up a lot in sales discussion. So Pat, this one's going your way and I am eager to hear your answer and Greg on our team is very interested to hear it as well. Hey, thank you, Jeremy. I'll give it a good good swing. So specific to your question, no, you don't need to require segmented, segregated BLAN or separate SSID on your on your home network. Although I would say that if you do have that implemented, let me just say that you are certainly on point exceeding the standard. Similarly, there aren't any prohibitions with regards to public Wi-Fi or hotel Wi-Fi. So having said that, let me step back. I think you're question most closely relates to the 310-6 requirement. Actually shows up in physical environment, but it talks about safeguarding measures at remote or alternate work sites. So at a minimum, you would want to ensure that you've implemented telework or remote work agreements. That telework agreement is going to extend the acceptable use expectations for your organization out to the employee that's at the remote site and to the company-owned endpoint that's working from the remote site. You could potentially also include restrictions in this telework agreement like requirements for safe storage or requirements for minimum internet gateway standards or no printing or something like that. And keep in mind, actually, that this is under the assumption that you've implemented a bunch of other requirements, CMMC level 2 requirements, they kind of all work together in order to achieve adequate security. So you still want to make considerations as if you're using that company-owned endpoint. You have MFA enabled at the endpoint. Do you have, you know, do you have bitlock or enabled minimum encryption standards such as that? So consider all those things. The last thing that I'll mention is the NIST-871 makes a reference to another publication. It's the 846 guide to enterprise telework, remote access or BYOD security. That will probably answer questions that you did not even know you had with regards to remote access. Well, the other thing is, you know, when traveling, obviously many of the organizations are leveraging VPNs to provide that additional layer of security. So consider that. Remember that if you are going to leverage a VPN, you need to describe it in your documentation of when they are obligated to use it by requirements, whether it's optional for them or not, and then make sure you describe how they connect to it. Okay. So we are going to jump into live Q&A. So anyone is definitely welcome to raise their hand unless their name is Rob Teague or Thomas Graham, and then their raised hands will be ignored. There is a question from James Derrick. Jeremy, before we get into that, just for clarification, an earlier one when we were talking. about inactivity. Yes. Yeah, I had used an example of a session timeout. Yeah. The question was concerning disablement in Cyrus. I don't know if you saw my message, but I actually replied in the CMMC Connect chat for it. You still have to define what those parameters are. It could be 30 days, 60 days, 90 days, whatever, but just whatever it is, you have to justify what that threshold is. Understand also, this doesn't mean deleting the accounts, it's just disabling them. When you disable them, if it's a Windows environment, they sit in the dedicated OU for disabled accounts and honestly, they can stay there forever if you want them to. For example, I took a year hiatus for my DOD days. At one point, when I came back, all they did was reactivate my account and I still had email in there where people have been sending me email over that year I was gone thinking I was still there and wondering why I wasn't responding to it. But you still have to define what that threshold is. Yeah, and that's why. Thank you. Yeah, or Jeremy, if we can go to Patrick Cowling, he had a great question at the top of the hour. Yeah, there was a couple of questions in the Q&A that I didn't see get a dress. I just wanted to circle back on those. Aaron did respond a bit to Patrick, but it's definitely worth the conversation. He said, I am a Canadian RP. We are working with a USC 3PAO who insists that having a US-based cloud service provider that a CMMC level 2 and FedRAMP standard is not enough. They want us to have a US LLP org set up as well as Microsoft GCC high. And that is a great, great question. Tom, as you want to take a stab first for Pat? I haven't had enough to drink yet today. I'll throw it at you as because you've already assessed a couple of the Canadians. Yeah, I mean, at the end of the day, requirements are requirements. And Patrick, you know, there was a couple of things in your question. I guess I had questions on. I mean, is it to the FedRAMP standard or are they FedRAMP authorized? Are they FedRAMP equivalent? That's kind of maybe what that other C3PAO was getting at. And that's what calls under D47012 if it's a true cloud service provider, then it has to be FedRAMP moderate, authorized or equivalent. Now, being to a particular CMMC level as a cloud service provider, if it's a true cloud service provider at storing processing or transmitting CY, FedRAMP is the requirement. The CMMC level that would apply to any other types of external service providers. And there's no hard and fast requirement that they have to be CMMC certified. If they are, it may make it a little bit easier, but there's no hard and fast on that. So I'm not sure if you wanted to clarify a little bit more, but that's what the requirements are. There's no requirement for you to set up any kind of LLC or in the U.S. to get certified. You know, we've certified and assessed organizations in Canada. We've certified and assessed organizations in Europe. There's other contractors and other foreign nation states that are getting prepared to go through the requirements. So there's no hard and fast for a U.S. LLP. So I'm not sure if that answer helped Patrick dropped in the chat that they are not accepting a U.S. based cloud service provider who company is FedRAMP moderate. Patrick, you are a brave man to throw your number on that chip. We can reach out to you, brother. We'll definitely do that because, yeah, there's no requirement to have a U.S. LLP or specifically to get GCC high. The only requirement is that it's FedRAMP moderate or equivalent and that's under D47012. I see the recall, the philosophical debate that I had with you sometime in the past, Thomas with regards to this. So keeping in mind, there is certainly a difference between the D4s, even the D4s clause with regards to FedRAMP moderate and then C3G requirements for D47012 as well. You know, whereby the FedRAMP moderate is just going to require just that cloud service provider that's FedRAMP moderate authorized on the marketplace. Whereas the C3G requirements kind of encompass other duties as assigned to potentially include ITAR export controlled requirements that would necessitate a GCC high. And that's why the conversation and Pat, you're more than welcome to join us in the conversation if you want to come home mute. Yeah, so the mid thing is very, you know, there he is, Rob. Okay, hey Pat, welcome. Thank you. So like I told the way, it's like going to a restaurant and being told I got to buy everything. You know, set up an LL, LLP, you've got to get Microsoft GCC high. And I said like, we're Canadian company. We can't access GCC high. No, you've got to do all this. And then you've got to meet about nine other requirements. And I said like the cloud service provider that this company's working with, they're FedRAM moderate, they're CMMC level two registered. Don't know what more you're looking for. No, that's a great point. And that's why, you know, there's a lot of confusion and going back to the early days of joint surveillance when we did a lot of work with the DibCack. We ran into this not often because there wasn't too many overseas organizations really jumping in on the joint surveillance. I think it was focused on U.S. but there were some Canadian, I believe Canada was one of the first countries that the DibCack worked with on seeing if they could meet the requirements of CMMC. The main thing is is if you look at Microsoft's, you know, kind of blog forum page, it says in order to get a GCC high tenant, you must have a U.S. based presence. But there's other cloud service providers, as you mentioned, Patrick, that are already Fed ramp authorized. There's all kinds of Fed ramp equivalent clouds that organizations can choose. So you don't necessarily have to use that. And you certainly don't necessarily have to stand up a U.S. based presence in order to meet the requirements of CMMC. And that's why, you know, maybe a conversation with us on a one-on-one side. We can get a little deeper into what they kind of told you and see if we can't kind of steer you in the right direction. It is worth noting though that to obtain some of the quote unquote "gold clouds," Microsoft, Oracle's U.S. defense cloud, you do need to have a legal U.S. entity to put the cloud tenant under. So I don't know if that's maybe what they're talking about, but that is a factor there was some of the gulf clouds. So yeah. There are some other questions we want to try to touch on. Patrick, we'll reach out to you, buddy. Yeah, definitely. And like Rob said, "Brave man, for you're all me, Patrick, I see. Looks like you're trying to talk, but unfortunately you're all me." One question I do want to get in front of the group because this is probably going to be a greater and greater question as time goes by. James Darrell posted, "Will GSA take the CMMC certification done for the DOD?" My red is that they will use their own auditors and not DOD, meaning we would have to do another certification just for GSA. Have we heard anything about this? Well, what's wrong with doing another certification? You don't want to do like 10 of them, right? So right now there's still conversations being had. The initial release was, yes, there were differences in this, honestly, specifically, I think because GSA aligns with A2LA, that's a different accrediting body than the CyberAB is. And that could be part of the mindset currently. I do know that, like I said, there are conversations happening as far as where those conversations are going or anything of that nature. Unfortunately, again, none of us on this call are DOD anymore, so we're not a party to those discussions. It's something that we've actually asked the question on from time to time when we're in front of certain individuals. And we have no problems continuing to ask that question until we get a definitive answer. Unfortunately, we don't have one now. Unless Pat, you've heard something internal within, you know, before you departed DIPCA. Not necessarily, but it's worth it to know that the FARCUI rule has recently been released for comment. And if you consider that along with the fact that the GSA's recent IT security policy with regards to implementing security requirements, meeting those standards, seems to have been rescinded or disappeared from their website. But it's still early in consideration. I think about all we have to go on is the comment period for the FARCUI. But all we got for you now, I know that the PMO office was not happy about that release from GSA because it kind of went against everything that they had been working for and kind of putting them in place. And GSA just kind of leapfrogged them and went right to revision three. So I'm sure they'll get it cleared out. And I'm sure they'll get some information out to assume. I really don't know that they would leverage their own assessors and do something differently. That would just put a big, you know, kind of taxing the ecosystem we currently have because we don't even have enough assessors to get through CMMC ourselves. So. While we have a couple minutes, Caleb Blackburn had a question and hearing kind of, you know, addressed it to a degree. But if we could have a larger discussion, looking for that question. I was actually tired of every response to his follow right now Jeremy. Okay. Yeah, so Caleb, with regards to inbound and outbound, you have to define what's essential, what's not essential, and then provide evidence of how your control source and destination traffic flows, and especially when it's coming inside and outside your environment. Most of the major vendors, and I did drop a link in there for Microsoft, will identify what those ports protocols and services are. Now, if they don't, and if you contact them, and they still won't, there are ways to see what traffic's coming in and out. I mean, most modern firewalls can do it. You can use applications such as Wireshark if you have to. But at the end of the day, you as the organization have to define what is essential and what is non-essential for your organization. And I get what you're saying in the Q&A. But start with the major vendors for some of the things you use. Microsoft, I know I sent you the link for them. I know Adobe defines theirs, and good luck with Adobe. Once you account for all of those, if it's just someone off specific application, you may or may not get a concise answer back from the vendors. And then that's where seeing what is traversing your firewall comes into play. The word of caution I'll give you is that if you do this, you are presuming that your environment has not been compromised because that's the same way behavior-based threat detection, EDRs, XDRs, when they're trying to identify malicious behavior, they benchmark against what normal traffic is. And that benchmarking has you as the organization, or even the administrator, have to ensure what your benchmarking against 100% hasn't been compromised yet. So hopefully that provides a little bit of clarification for you. If not, definitely happy to talk with you about it some more. Just reach out to us and we'll get on a call, get on teams or something and kind of step through some of those scenarios. Thank you, Tom. The denial permit by exception requirement in pre-136 applies to both inbound and outbound communications. How you choose to implement that within the environment is up to you. Could be network-based protections for your firewall or endpoint protection or even EDR XDR. But the requirement applies to outbound communications as well. Hopefully that helped. We might have time for one last quick question, Jeremy. We have any uncertainties. We didn't see any in the Q and A that looked like they hadn't been tagged. Let me check the chat again. What's the over-under on Rev3 becoming a hard and fast requirement? Yeah. I mean, it's going to be the over. The federal CUI rule, the version that's out has it. The other federal agencies are lying into Rev3. So it's going to be a requirement. David posted something about this earlier. Yeah. If we're looking for an over-under on what month and year it becomes hard and fast, we could throw that out as a survey. Well, no, I actually have a better idea for a survey. Guys, girls, whoever's joining in on this call, he is Mr. Rob Teeck's anniversary. So tonight for dinner, should he take his wife out for steak or tacos? What do you guys think? Steak tacos. Yeah, there you go. Steak tacos. I'm not going to vote that. We have multiple votes for tacos. We have a chicken vote. We have steak tacos. We have steak tacos. And then the best answer, whatever she wants. That's right. Happy wife. Happy life, and I appreciate that, guys. Yes, we are hitting 38 years today. So, congratulations, sir. Appreciate it. No, but this was a great connect, everybody. Thank you for joining us. One thing I do want you to kind of take back his homework and circle back on our next connect is what is easier for you guys to do? White list or black list, right? Because we do get that question often. So think about that as you guys are mulling things over to the next CMMC connect, but we appreciate you joining us. So Monica, would you like to close us out for this session? Yes. Thank you, everyone, for all your questions. We appreciate them. And hopefully we answered all of them for today. I'm going to launch a quick poll right now to see if you'll be at any of these upcoming events that will be at. So on July 16th, we're teaming up with Zscaler for a webinar, answering, answering all of your CMMC questions and sharing practical strategies for strengthening your cybersecurity and compliance efforts. And then later in July, Jeremy will be speaking at the AFS Foundry Industry 4.0 conference. And we'll be discussing some different challenges facing advanced manufacturing. And then be sure to connect with us again on July 30th for our next CMMC connect session. We'll have some special guests from Microsoft. So we hope that you'll join us there. In August, you'll find us attending the NDIA Space and Missile Defense Symposium in Huntsville and Navy Gold Coast and seeing Yego where we'll have a booth. So please be sure to stop by if you'll be there. And then in September, Redspin is sponsoring and speaking at the CMMC in practice forum on September 22nd. It's a newer event put on by the Cyber EF and CyberBruze. So we'd love to see you there. And we'll also be exhibiting at the National Cyber Summit in Huntsville also that same week. And we'll also be hosting our fun networking event that we usually have. And this year's theme is celebrating America's 250th anniversary. So if you'll be there, we'd love to invite you. So let us know. And with that, our time has come to an end for today. Here at Redspin, we are here to help federal contractors move to a more secure, compliant and resilient state to help protect the defense industrial base. Thank you for joining us today. And we'll see you next month on July 30th for our next CMMC Connect session. Take care everybody and have a fun and safe Fourth of July. Sure everybody.

Podcast Summary

Key Points:

  1. November 10th is a milestone for including CMMC requirements in contracts, not a certification deadline; certification is needed at time of award, and many will not be certified by then.
  2. The federal CUI rule has been re-released for public review, indicating a likely final version by year-end and a shift from Rev2 to Rev
  3. A new strategy mandates Post-Quantum Crypto implementation by December 31, 2030, with CMMC as an enforcement mechanism, possibly leading to Rev
  4. Significant changes (e.g., AI/ML tools, M&A activity) may trigger reassessment, but clarity is lacking; the AO determines if scope changes necessitate it.
  5. Periods of inactivity for user identifiers must be defined (e.g., 5-10 minutes), with compensating controls allowed for operational needs.
  6. Using Microsoft MTO across multiple GCC High tenants for sister companies with shared users is uncommon; separate tenants with separate CAGE codes may require individual assessments.

Summary:

The June edition of CMMC Connect, hosted by Redspin, addressed key updates and common compliance questions. Jeremy clarified that November 10th is a milestone, not a hard deadline for CMMC certification; certification is needed at contract award, and many organizations will not be certified by then, so having a plan is sufficient. Dr.

Graham discussed the re-released federal CUI rule, which foreshadows a shift to Rev3 by year-end, and a new strategy to enforce Post-Quantum Crypto by 2030 via CMMC, potentially leading to Rev4. The first Q&A focused on significant changes requiring reassessment, such as AI/ML tool adoption or M&A activity; the AO determines if scope changes trigger this, but clarity is still pending from the CyberAB. Another question covered defining periods of inactivity for user identifiers, with 5-10 minutes common and compensating controls allowed for operational needs.

A final query about Microsoft MTO across multiple GCC High tenants for sister companies with shared users was addressed; this scenario is rare, and separate CAGE codes likely require individual tenants and assessments. The session emphasized proactive planning and engaging with primes or DOD agencies to demonstrate progress.

FAQs

November 10th is a milestone when the DOD moves from phase one to phase two of CMMC rollout, not a hard deadline. It marks when CMMC requirements begin appearing in contracts, but certification is needed at time of award, which could be months later.

The federal CUI rule, re-released for public review, outlines protections for CUI across GSA, DOD, and NASA. It is expected to be finalized by year-end and is a step toward moving from NIST SP 800-171 Rev 2 to Rev 3.

Post-quantum cryptography adoption will be enforced through CMMC, with a deadline of December 31, 2030. It may require a revision to NIST SP 800-171, potentially Rev 4.

A significant change is determined by your organization's Authorizing Official (AO) and typically involves changes to the system's scope, such as switching cloud providers or acquiring new sites. Clearer guidance is still pending.

Yes, compensating controls can justify extended inactivity periods for operational needs, like in medical settings. However, you must define the period and document the controls to maintain low risk during assessment.

This scenario is uncommon and hasn't been seen in practice. It's recommended to discuss specific use cases with experts, as segregating groups within one larger tenant is more typical.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.