The podcast discusses the Department of Defense's suspension of CMMC Phase 2 and its implications. Host Eric Crucius and guest Jacob Horn argue that the suspension, while citing cost and bureaucracy, ignores that most expenses stem from implementing underlying NIST 800-171 security controls, not certification. Self-assessments have historically failed, rewarding non-compliance and penalizing companies that invest in security. The suspension risks undermining trust in the program, as previous pauses under CMMC 1.0 and 2.0 eroded stakeholder confidence. Despite the DOD exceeding certification targets in Phase 1, the review delays progress. Horn traces the decade-long policy gap since 2011, noting that repeated reviews follow preventable cybersecurity breaches. Eliminating third-party certifications would violate the statutory mandate for proof of compliance, as self-assessments have proven ineffective. The DOD could rely on whistleblowers and False Claims Act cases for enforcement, but this is messier than third-party assessments. Ultimately, contractors must continue complying with security controls to avoid liability, and the suspension may weaken future cybersecurity initiatives.
Hello and welcome to Regulatory Fishing, a podcast focused on the intersection of government contracts and cybersecurity. I'm your host Eric Crucius, chair of the government contracts practice at the Law from Hunting and Drus. Curth, and we bring you the latest industry news and some of the most important newsmakers so they can share their perspectives with you. I appreciate you joining us today and hope you find this informative. Hello everyone out there and welcome to another edition of Regulatory Fishing. We have a somewhat special episode today as you probably have heard by now and seen in the show title, the Department of Defense/War suspended phase two of the cybersecurity maturity model certification program. To discuss that we have a special guest coming on shortly Jacob Horn over at Summit 7. He calls himself at times a CMMC town cryer and other things but he's very plugged into this space and I think has a lot of interesting thoughts on CMMC in general. Certainly this action by the department and cybersecurity protection of assets that are necessary to support our warfighter. Before he comes on though I wanted to share just some thoughts on this suspension. So they're going to do a 60 day review of the CMMC program and whether they want to continue on with third party certifications. That's the background of what is being proposed. So during that time they issued an RFI to get feedback from industry about this proposed step. They've also are taking feedback in other ways. So if you have a position on this one way or the other I urge you the time is now to say something and I will have a link to the RFI in the description of this podcast. We also have issued a blog on our blog about this as well with some thoughts and some guidance for contractors moving forward. There's a link to that as well in the description of this podcast. So a few things I wanted to run through though before Jacob joins us because he's going to have a lot of really interesting things to say and some of them will be kind of complimentary to what I'm saying here. First the department cited to the cost and the bureaucracy of CMMC as a justification for kind of suspending the implementation of phase two and specifically getting that third party certification. It is true there is a cost to that and it is true for some companies that cost is fairly substantial. But the vast majority of the time that costs is substantial because the CMMC third party certification process requires those companies to come to the realization that they have not been compliant with the underlying security controls. So for the vast majority of companies complaining about cost that is rooted in the fact that those security controls have not been in place. And if you look at kind of the department's own estimates of cost to get a C3PO certification versus the cost of instituting the security controls, it's not a close call. The security control implementation is much more expensive, much more burdens and much more time consuming than getting a CMMC certification. You could actually just kind of call this CMMC certification kind of like the cherry on top. But what it does is kind of create an obligation to institute those security controls and that is where the cost is. Now the department has said, look, we are assuming that everyone is doing that when we're talking about the cost of CMMC, but the reality is any government contracts lawyer or any professional in this space will tell you the vast majority of companies have not instituted these controls and the only reason they're doing it is because of the pressure of a third party certification. So I wanted folks to keep that in mind that this is not necessarily going to help lower the cost by very much in order to be compliant with the underlying security controls, which is still vital. So the second thing is what we saw before third party certifications began to become required is that self-assessments were not working and they still don't work as a whole. We're seeing pressure releases over and over again from the Department of Justice about contractors that are not implementing the security controls required in their contracts. Self-assessments as a rule, as the department has acknowledged many times, just don't work because they reward companies that don't take the time and money and effort to institute these controls. Because you have this kind of compliance, reverse compliance dichotomy almost that punishes compliant companies. Because if you have two companies going to contract performance in those two companies, one has been taken the time and money to institute the security controls and the other one hasn't. Well, the overhead for that one that hasn't is going to be much lower and that's not particularly helpful. So for that company that has taken the time and money and they become uncompetitive and then they maybe don't institute the cybersecurity controls in the future. So it really creates an incentive, a reverse incentive to not institute these controls. The fact of the matter is that the dipkack is too small to do regular CMMC assessments or compliance assessments of a lot of contractors. Where the risk will be is in whistleblower lawsuits. If there are a lot of, if there is an active whistleblower kind of community out there and folks who are looking out for this and plaintiffs firms that are taking on these cases, all those things I would not be surprised to see, then you may see self-assessments at least work a little bit. But nothing will substitute the fact that third party assessments are the gold standard. Third observation, there were folks who went out of a limb for CMMC 1.0 within their organizations. I know a few of them. And they really kind of pushed it within their own internal organizations, their companies urged those companies to get on board with the promise that CMMC 1.0 was going to happen. And then a pause was announced and it didn't happen. And those folks had the rug pulled out from under them. And it was very hard to get them back to the table to push them to understand that CMMC 2.0 was going to be a different story. And that is still equally important to institute these controls. Because remember, the motivation for a lot of companies is not the compliance. It is the checking of the compliance. And now we have the same thing happening again. It's like Charlie Brown in the football. We have so many folks who went on on a limb, invested a lot, had their companies invest a lot of money in a program that may not exist in the future. And that will weaken our cyber security. And the next time the Department of War or any other Department of the government tries to institute a program like this, it's just not going to happen. They've lost their chance to institute something like this in the future. And then the last point about innovation, whether it's stopped or because of CMMC, I haven't seen any evidence of that. If there is innovation that's being stopped, it's because of the underlying security controls. The Department always has the option almost always when it's something that's innovative to go the route of another transaction agreement. And they don't have to have CMMC in OTAs. Also waivers are available. So I don't think a lack of innovation is a reason to suspend CMMC. In all, contractors still have the underlying compliance obligations that has not changed. It's really important for contractors to continue to be vigilant about their NIST-800171 compliance. If they are not, they are still subject to false claims act claims. They are still certifying to the government the so-of-an-obligation to affirm to the government under oath. They are compliant with these. And I would urge those who are listening who have the budget to do so to still get a third-party assessment done. And not in a third-party assessor or not a C-3PO, I get nothing out of it. But I do think it can save you a lot of money in the long run because those whistleblowers who are very expensive, whether or not or false claims act cases are very expensive, whether justified or not. But getting a third-party assessment will oftentimes not guarantee, but oftentimes stop those in the tracks. So with that, we're going to move on to our guest, Jacob Horn. And as promised with me is Jacob Horn. Jacob is the Chief Cybersecurity Evangelist at Summit 7, Huntsville, Alabama, Basemanage, Security firm. He hosts a really successful podcast, watched by thousands or listened to or and/or watched by thousands of people each episode, the Summit Up podcast, which is focused on cybersecurity policy and the defense industrial base. He was, before this, a US Navy cryptology technician and has developed numerous cybersecurity training programs for the NSA, National Cryptography School, UCLA, and UC Irvine. Jacob, I can think of no one else better to have on this podcast on a day like today when this has come out, so really appreciate it.
you joining today. Yeah, no, thanks for having me. It's so funny because after the two CMMC final rules went into effect, I was bombarded with messages where people were like, "What are you going to talk about now?" And now here we are. It's funny to talk about. And I think when you think about what's happened over the years, this has been a long and winding road. And a little inside baseball before we hit record on this thing today, Jacob was walking through everything that's happened over the last more than 10 years at this point between the CMMC program, the underlying security requirements, NIST-171, NIST-153. I think it'd be really helpful if the audience heard the long and winding road we've been facing here so far. Yeah, well, I'd say that this is a long story. And the pattern that I've noticed over the years having been very, very tightly focused on just this space is that almost every complaint about the program, the requirements, their enforcement, and so on typically stems from people not having zoomed out far enough on the full story. And that's really how I would kind of distill probably 95% of the critiques of CMMC. There are still legitimate critiques to the program, but most of it comes from just not as sufficient understanding of the last and why would anybody have this 10 years of DOD cyber policy. But in its essence, for anybody not familiar, the CMMC program is designed to fix a single policy gap in the DOD cyber security policy that has existed since 2011 is as far back as I've been able to trace it. And the DOD's guidance essentially has been when contractors handle our sensitive controlled information. We have requirements for them to meet, but we're going to stop short of making them prove that they are meeting those requirements. And that decision has haunted the department for G's, I mean, over 15 years going on 20 years now in one form or another. And almost every time that the DOD has revised requirements, gone through rulemaking, gone through changes, gone through programs, gone through reviews, has almost always been on the heels of a horrible, preventable cyber security catastrophe. That's like the last 15 years of this space as I could sum it up. So, you know, fast forwarding to the modern era, you know, the defense contractors have had cyber requirements in their contracts since 2013. Those contract requirements were revised in 2016 to the form that they basically are today. They basically been unchanged for a decade. What's fun though is that a lot of people think that the deadline to have complied with those requirements was December of 2017. That's actually not true. The deadline to comply with the current set of requirements was originally supposed to be August of 2016. However, even though the current requirements are actually a smaller set of things to do than the original 2013 baseline of requirements back in 2016 industry said we need more time to implement our requirements red flag, right? So the DOD actually gave a smaller set of things to do. People said they need more time to implement. This is the equivalent of telling your boss that you've been working on documents and then you access it and it says you need to request permission to see it and then you're busted. Yeah, everybody knows. Everybody knows what you were doing. So, the DOD gave contractors an extra 14 months to implement the requirements in NIST SP 80171. That was supposed to be done by December of 2017. And then three years went by and massive cyber security catastrophes happened where major DOD weapon systems were compromised. I won't bore anybody with the details, but it was really bad. So bad that it got Secretary of Defense Mattis' attention. He formed the protecting critical technology task force, the DOD IG ran audits against contractors found widespread systemic noncompliance with those requirements that were due in 2017. This got the attention of the armed services committees who then added a provision in the FY20 NDAA that said plug that gap in your policy, create a framework for holding contractors accountable and make them prove that they are implementing these cyber requirements that they've had all along. Then in 2020 the DOD created what was then called CMMC 1.0. We now know at that time that contractors weren't compliant with their requirements. And yet there was still a phased rollout to give people time to implement the requirements and then prove it, massive concession to the industry. And the moment that contracts started to be threatened, they paused the entire program at that time and said we're going to do a programmatic review. Sound familiar for anybody listening these days? Took them nine months through 2021 and they announced CMMC 2.0. Sure enough, all the changes under 2.0 were basically superficial because DFR 712 and NIST SPA 10171 are still the underlying layer of requirements verified by the CMMC program. So you can change it from five levels to three levels. You can change the colors on the logo. You can change the you can do whatever you want to at the surface level. It doesn't change the underlying requirements that it had to go through rule-making, which everybody knows takes a really long time. Even more time for companies to comply with DFR 712 fast forward to November of 2025, all the rule-making is done. And then the new phased rollout starts giving people more time to implement 1.71 and comply with those requirements that were due in 2017. And now here we are about eight months into that phased rollout. The DOD has absolutely smashed the number of level two certifications that they expected to get in the first 12 months. Fun fact for everybody listening at home, the DOD originally estimated that in the first phase of the rollout, they would achieve 517 level two certifications. In November of 2025, the first month of the rollout, there were 575 level two certifications. Since then, we are now adding more certifications per month than the DOD really expected to get in the first 12 months of the program. Massive, massive over achievement. Nobody was really talking about it. And now here we are. Here we are, you know, 10 years later. Finally, starting to turn the ship slowly, accelerating the number of companies that are proving that they're complying. And the current DOD CIO has said, actually, we're going to stay in phase one for a while. And we're going to conduct yet another program review. So throw this on the pile with the extension in 2016, the IG report in 2019, the various NDA reports that have been issued since then, multiple GAO reports, multiple industry analyses, plus the CMMC 1.0 to 2.0 program review. And we're going to review it again. And I'm not sure what they're expecting to find because there's not much more left to review at this point. Yeah, this has gone through, this is probably, and I, for a living look at regulations and the history of regulations and go back, obviously, CMMC is a central part of that, but other regulatory schemes as well. Doing the far overhaul, which has changed the entire far as a much quicker and painless process than changing this one thing. You know, what kind of strikes me about how drastic this was is, the unified agenda, regulatory agenda was just released. We talked to CMMC 3.0 essentially by updating the standards to NIST-800171 revision 3. So it just seems like this is very sudden, because just recently the department kind of again. Yeah. So, according to that unified agenda, at some point prior to Ms. Davies taking over is the CIO, because the unified agenda data call happens many months before the unified agenda is published. Right. The DOD had a 10 for 1 executive order exemption. They have an interim final rule written and ready to go that outlines a plan for the transition from 800 171 revision 2 to 8171 revision 3. 8171 revision 3 came out in 2024. And so now they are coming up at the plan for the slow transition over to the new standard finally. And through something, some sort of math and accounting, they figured out a way for the program to affect 20% fewer companies at level 2. So you're moving on to a better standard. You are reducing the number of companies that are affected by the program, which is going to reduce cost. You have your exemptions and you have an interim final rule status, which anybody who knows about rulemaking knows that that is quite the anomaly, especially these days. And yet that's not seemingly good enough. We're going to review the program again. I would love to know what is it 25% fewer companies? Is it a super interim rule? What other iteration are we planning to have on top of the rule that is clearly ready to go?
Do you think that there's a possibility coming out of this review period that they'll just eliminate third party certification requirements altogether? Well, I don't know how that would work because the statute that's not what the statute asks for. Right. I mean, the policy problem is that self assessment doesn't work. Right. And so if you, yeah, so if you rely on self assessment to fix the fact that self assessment doesn't work, then you're fired. Because it's not what the statute says. Like the entire reason that we're here is because that's a failed policy. Now, one of the reasons why they went with the idea of the CMSE program as it exists today is because they said they couldn't scale the duty workforce to meet the number of assessors, which thank God they didn't go with that plan because two years ago, everybody got fired. We doged everybody and said we don't need your services as a government employee. So if they had tried to scale all the DibCack assessors, that wouldn't have worked. We have plenty of assessors on the outside. So, you know, basically, are they going to say, well, DibCack is going to do all of the assessments after the fact. So we know that everybody's non-compliant and we're going to let them be non-compliant. And then we're just going to catch a few of them years later whenever DibCack is able to show up in their limited capacity. Is that what is that what the armed services committees want? I would love to know. Yeah, that that doesn't seem like a solid policy goal. And I do wonder if they're going to rely on whistleblowers to fill in some of the void as well. I'm not saying that's the right policy, but I wonder if that's part of the thought also. Yeah, it's certainly messier, but it's one of those things where it's like, okay, they're saying you're going to stay in phase one. Eventually, the decision has to be made, right? Are you going to prefer to award contracts to people who can demonstrate that they've implemented these requirements or not? Right. And one of the criticisms that has been downed about about the CMMC program is there's just not enough capacity on the C3PO side. Right. And it seems like there are some C3PO's that are booked out kind of far three, six months out, which isn't a huge roadblock, but there are a lot of C3PO's that seem to have readily available capacity. Yep, that's your sense. Yeah, we know we know anecdotally, you know, speaking with C3PO's, you can go on LinkedIn right now and some of them have been basically like standing on the sidewalk, flipping a giant arrow sign being like, we have open slots available to schedule some of them are booked up, but nobody who would want an assessment right now is unable to get one. It's simply not true that there aren't enough assessors available for the assessment demand. What is true is that not enough people are ready to go through the assessment. I mean, I've been telling people this for years about the assessment capacity argument is based on the premise that everybody out there is ready for an assessment. That isn't true because that's why the program was created. If everybody was ready for an assessment, that means everybody had implemented their requirements, which means the DODIG wouldn't have found what they found. And we wouldn't need CMMC in the first place. The other misconception that that adds to that bad case is that people for some reason think all 80 to 100,000 companies that are estimated to need a level to Sir would have needed it by November 10th, which is not what the phased rollout says. The phased rollout says that starting in November 10th, there was going to be an uptick in the number of new contracts and solicitations that would require third party verification rather than self assessment verification. But for some reason that still confuses me, people say that all of the companies would have needed to be assessed by November. And it's just not true. It's just not true. Like Miss Davies in one of her interviews today was saying the math doesn't math. What math? What math doesn't math? There's some math I would love to know. And I hope that there are hearings from the Armed Services committees because the pressure relief valve in the program, in the regulation for there not being enough assessors and not enough assessment capacity is waivers. Like that's what the regulation says is that if you as the program determine that you're not going to have enough certified suppliers, then you get a waiver at the program level for the entire procurement. And then you obviously come up with a workaround for making sure that the data is still protected. But the CMMC verification requirement does not apply to the contract at the contract level. How many waivers have been requested? Nobody knows. We know there's enough assessors. So it's not that there's a lack of assessors. So how many waivers were requested? Another question I would love for Miss Davies to answer. She is the single person in the Department of Defense that is able to approve control by control variances for contractors under DFR-712. If you look at 800-171 and you think this requirement doesn't work for me for whatever reason, she is the one that you ask. She's the one that approves. You don't have to do this. You have to do this instead. You don't have to do anything. She gets to make that decision as the DOD-CIO. How many control variances has she approved since she's been the DOD-CIO? How many requests for variances has she even received? Are people struggling with the same control over and over again? Have they even asked that they need to vary? These are the kinds of amplifying details that are not present in any of the statements that came out with this pause. That would paint a very different picture than the rhetoric that's being used. I would love to know those answers. The messaging that I've tried to get it across, I know you have two, is that it's a verification program. The underlying requirements have been changed. We've had and we will have a discussion on companies' commitments to those. I'm talking about controlling those controls. Whether that's going to still be there if there's no third party verification. I think a lot of this confusion stems from the fact that there's a lack of understanding in some corners that the much heavier costs in this is not the CMMC program itself. It's the underlying, getting compliant with the underlying controls and people complaining about CMMC are complaining about the fact that they have not kept up with the underlying controls because they're dealing with that cost. Essentially what we were looking at was a K-shaped CMMC ecosystem if you will, where the companies that were ready to go that had complied with their requirements were having zero problems passing their assessments. The companies that had not complied with DFR-712 were not able to complete assessments. There are many more companies than the DOD thought that are ready for and achieving their assessments while there is a very loud and vocal group of companies that cannot achieve their assessment. In the crossfire, the program is being blamed as the problem when it's doing what it was supposed to do. It's executed as designed. To put some actual numbers on this, I know you've talked about this before, Jacob, too, is when the FAR Council initially released rulemaking on implementation of NIST-8171 for the civilian agencies, they estimated the cost of instituting NIST-8171 for small businesses was 148,000 for the first year and for other than small businesses, 543,000. That juxtaposes the cost of a CMMC assessment to be under $100,000 and a self-assessment to be something like 35 to 100. That's a great point. Let's just assume everybody is going to self-assess. So there's no cost now, because that's essentially what they're saying is, in order to get rid of this cost problem that's preventing companies from participating in the DIB, we're going to eliminate the third-party verification. And this ignores the thing that you and I have been telling people for literally years at this point. CMMC is not the requirements. DFR-712 is the requirements. ITAR is the requirements. There's all these other things that have existed and continue to exist, whether you're doing your assessment or whether a third-party is doing your assessment, it just turns out that when you assess your own work, the department doesn't have a lot of assurance that you're telling the truth. Does just how self-assessments work? So extending phase one and allowing self-assessments to continue under the guise of saving assessment costs isn't going to save anybody extra money. If anything, this decision is going to cost people more money and more time and more confusion, because if we were only talking about DOD policy on this timeline, that would be one thing. But we now have the FARCUI rule and the Cirquecia final rule, both scheduled to go into effect before the end of the year. Now we've got a real problem on our
hands because DOD had a plan for getting us to 171 or Vision 3. If the DOD takes this 60-day review and they change it from three levels to two levels or three levels back to five or who knows what they're going to do, right? The requirements are still going to be 8171 or Vision 2, right? Are they going to go through rulemaking at the end of this year and say you got to implement 8171 or Vision 2 or 8171 or Vision 3? Does that defeat the benefit of the pause? Is that going to be different than the interim final rule that you already had ready to go? Basically, what they've done at this point is basically guaranteed that moving into next year, contractors with federal contracts will be on one baseline. Defense contractors with a defense contract will have a different baseline. And if you're in both of those worlds, you're going to have to juggle two different baselines, which is ironically exactly what the DOD opted to avoid back in 2024 when they issued their class deviation, which I don't know, but it doesn't seem like the people who are giving statements and interviews about this pause who work for the DOD are aware of what that class deviation is or why it was created or the problem that they have now as far as I can tell cemented for defense contractors in the name of saving them time and money. Right. The cost is going to be driven up because they will have to comply with two regimes at the same time whereas before it was just one. So any kind of cost savings from not having to get a C-3PO assessment? To say nothing of the fact that all these poor people who work inside of these companies who have been fighting tooth and nail to convince their leadership teams to give them the budget and the authority and the decision making to be able to implement these requirements are now they just they now just had the rug pulled out from under them. Yep. So you can say all you want to, but that 7, 12 is still the set of requirements as they do. But anybody who was around in the 1.0 to 2.0 transition day knows exactly what people will interpret this news to be. Their confirmation bias will make them say, well, it doesn't sound like they're going to make us prove it. So it's not a priority and that's not the correct thing to do. That's a fraudulent thing to do, but that's what people will do. And I don't think that the current leadership team was around back then. So I don't think they realize that that's what they have catalyzed here. Yeah. I mean, I remember back when 1.0 happened and that that pause happened back then and how so many people were just left out hanging out out to dry in those companies who had really advocated for the Department of Defense. Oh, yeah. I remember standing on the vendor floor of Navy Gold Coast in the San Diego Convention Center and multiple people would walk by and they'd say, Hey, what do you guys do? I'd say we help with CMMC and people laughed in my face. They had stray of laughed in my face being like, that's not happening. They paused it. And I was like, are you a defense contractor? They're like, Oh, yeah. It's like, how long you've been a defense contractor for? They're like 20 years. I'm like, well, you have had those requirements and they're like, anyways, see you later, loser. That's that's kind of the strange thing. One of the strange things about this pause to me is that you know, we've had kind of we've gone down this road before the Department realized it didn't work and it didn't work spectacular in spectacular fashion actually. Yeah. And we're going possibly back to the thing that we all know didn't work. And what do we expect to happen if that happens? Here's my question. We're in. So the thing about phase one, I know it's a subtle detail, but it's an important one. The DOD regulation for CMMC says that during phase one, the department can require third party verification at their discretion if the data warrants that you're required to have third party verification. Just like in phase two, they can determine that you get level two self assessment if the data requires it. There's no magic at the original phase rollout where everyone's on self assessment. And then the next day, everybody's on level two third party assessment. So if we're extending phase one indefinitely until they're done with their review, will the department still exercise discretion to require level two third party assessment when the data requires it? Or is the DUDCIO saying we have assessment capacity to spare? We have data that would otherwise require verification in order for us to have assurance that you're implementing it. And we're still not going to require that verification because some other people were able to get their certification. Is that what the ARM service is wanted when they wrote the statute? I don't think so. Yeah, I mean, and it's really interesting because you have kind of companies out there. And I have not heard from any companies that they were trying to get assessed and they missed an opportunity because of a capacity issue. It was like you said Jacob, it was always an issue of we haven't gotten compliant yet. So we're just not ready to get assessed. Which is just, you know, there's a couple other like there's two other things that jump to my mind here that just give me the feeling that this was at it's hard to say but it's moving at the speed of government. This was a little hasty on their part. The first one is the DUDCIO a couple weeks ago just published their post quantum cryptography strategy. And unlike page 20 of that strategy, they talk about how they want to change CMMC to deal with post quantum crypto threats and requirements. Which is funny to me because as we talked about, CMMC is a verification program. CMMC doesn't establish its own set of requirements unless you're talking about CMMC level three. So are you saying that you want NIST to include post quantum crypto requirements? Why would that require a CMMC change? Are you saying you want to change CMMC level three? CMMC level three wasn't supposed to kick in for a couple years. So why are we pausing things for that? Currently, maybe that's a good idea but that feels like something that you wouldn't have to pause phase one to phase two for. That feels very disjointed to me and it's not clearly explained because they just put that out prior to this. On top of that, when the CIOs on their new CMMC page, they list these items on their brilliant at the basics campaign with their attempt to summarize complicated cybersecurity requirements in a way that would make them easier to implement. Although I thought the problem was assessment, not requirements. On that list of 10 IT requirements is resilient backup and data recovery architecture. We're going to reach way back in the past, everybody. If you remember CMMC 1.0, the DOD opted to add additional requirements on top of 871 to augment NIST's tailoring decisions that left out very good security requirements. One of those requirements that the DOD opted to add in 2020 was backups, secure backup architecture. After the 1.0 to 2.0 review, they removed it because they said it was going to be to burden some on industry. Now we're pausing the review program for another review and then the recommendation from the CIO is the thing that we removed five years ago. What are we doing? I call this the duality or dichotomy of compliance where compliant companies are getting punished now. With the CMMC program did it, is it put everyone on a level playing field? The companies that were not compliant had to spend the money to get compliant. So when those two companies were bidding on contracts, the compliant and the previously non-compliant company, they are on a level playing field with overhead and costs and things like that. Now companies that have been proactive in our compliance are at a competitive disadvantage because their costs are just going to be higher than their competitor and there's no way for the department to reach out if they take away third party verification, to reach out and verify that competitor has done what they're supposed to do. They don't have the staff to verify it. Maybe they're relying on whistleblowers. The craziest part about that is I remember in the previous administration, Dr. Kelly Fletcher, deputy DUDCIO was on the industry event rounds and she would get on stage and she would say very convincingly that one of the arguments for CMMC as a policy was fairness because companies that are not complying with their security baseline have arbitrarily lower rates and therefore are viewed as better deals as more competitive for winning work and so it's unfair to the companies who are complying with the same requirements because they'll lose out on work and so you have to have this mechanism to level the playing field otherwise you're punishing the people who are doing what they're supposed to do and now here we are with way more companies than the DUDC thought doing what they're supposed to do and you're punishing them. Kind of backwards. It
It certainly seems that way. - Another criticism, I think, you know, I've heard of the CMMC program that they're trying to address with the press releases kind of how innovation is being stopped because of CMMC. And I think for all the reasons we talked about already, that doesn't seem to be the case. But I mean, DOD does have other avenues to do business with innovative companies. They can use other trends that there are other transaction authority to do so. And OTAs don't have specific starting points and for our D-FARS clauses that go in them. So it's up to the parties, it's to those agreements to do whatever they want. Like you said, Jacob, before waivers. - Right. It brings me back to that point. If we're losing these innovative companies because they can't comply with the requirements, how many waivers have been requested? And how many waivers have been approved? Have any waivers been requested? Are we just punting on phase two? How do you know? How do you know? Like they keep saying the math doesn't matter. What math? Because we know that since, geez, what was it the 1980s after the end of the Cold War that we have hemorrhaged companies out of the Dib almost on purpose as national policy for literally decades. Like my entire life the Dib has lost companies every year. And then now we've got a separate and parallel problem where we're sending data for innovation into an unsecure supply chain and losing it at a dramatic rate. But we won't pull the trigger on making people prove that they can secure it because they might leave even though they're leaving already. So it just has always been interesting to me that the humble little CMMC verification program to plug a 20 year old hole in DOD policy gets blamed for the failings of national industrial policy since the '80s. Like if it weren't for CMMC, these companies would stay or these companies are leaving anyways and we're not going to ask the ones that are staying to do security. Like does that make sense? - Yeah, and then very few contracts as it is now I've had a CMMC requirement in it. So there's nothing that anybody's been doing. - Where are these companies that are leaving and how many of them are leaving because CMMC because they probably haven't had the requirement yet. And then this comes down to the policy question. What does Congress want? What should the policy, and I know this isn't a question that we can really answer. But what is the policy going to be, right? Are we going to say you can't have access to control data if you can't prove that you can protect it or not? Because you're going to lose some number of companies as a result of that policy. If your goal is we want people to secure the data and we can lose zero companies while we do it, then you better back up the Brink's truck and write a new authority to dump a bunch of cash for a thing that you already paid for, right? I mean, this was a thing that Katie Earrington said towards the end of her time that I wished that she had said more was she would get on stage and she would say, I wish I could pay you to do this. But I've technically already paid you to do it when you submitted your invoices pursuant to D4R712. I literally couldn't give you the money even if I wanted to. 'Cause it's not the right color. So, ah, you know, I don't know. If this is so important, where's the money? We know that the policy doesn't fix itself, so where's the cash? I think that there's in the FY27 NDAA Senate version, there's a draft provision in there for grant programs to assist with CMMC assessment costs. And I think the initial number on the authorization was like, I think it was like $100 million or something like that. It was $50 million. I remember looking it up. It was 5,000th of 1% of the $1.2 trillion proposed defense budget, right? Like, I'm trying to think of what a real world measurement of 5 1,000th of a percent might be, it might be how much hair I have left on my head. It is such a tiny, infinitimally small amount of money. It's like, Congress doesn't seem to be funding this problem because contractor rates are supposed to be funding this problem. And so to be fair, the CIO's office has to wrestle with this problem. They're inheriting decades of bad national industrial policy. They're inheriting bad DOD policy with allowing people to self-assess their compliance. And so they're stuck in the middle. So yeah, I mean, it's not really all that surprising that they would extend it, but at this point in the game, we've now, how long has enough time to implement the requirements allegedly? 10 years? Is that enough time? 15 years? How long should somebody have to implement 171 before you're like, we can't give you the contract? Right. And it's interesting that because I think we talked about this a little bit but this conflation between the underlying compliance, the underlying requirements and those costs and the separate costs of the CMMC assessment. According to the press release, they're not doing anything to relieve people, companies of the obligation to be compliant with NIST Day 1171. But let's imagine, yeah, let's imagine that the DOD overnight has enough assessors for everybody that would need an assessment tomorrow. Like the entire Dib could go get a third party assessment tomorrow for free. Is that going to reduce these six figure costs? Not even close. Because if you haven't implemented DFR 712, like you said, the FAR council says it's going to cost you $140,000 to $500,000. So if the assessments are free, it doesn't fix the problem. And if the assessments don't happen, it doesn't fix the assurance problem. Absolutely. Well, Jacob, any last thoughts I've already taken up enough of your time and I really appreciated it, especially on such short notice. But yeah, I mean, any suggestions on how do we move through the next 60 days and navigate this uncertainty? Well, I would tell people the same thing now that I told him back in 2021, do not look at an extension of phase one self assessments as an excuse to not be compliant with DFR 712 if you are making attestations to the government and submitting invoices because either an insider in your organization or a random DibCAC assessment in the future is a great way to end up in a DOJ press release for having paid out $500,000,000,000,000 $4 million in false claims accettlements. You are still liable for those existing requirements. Doesn't matter who the CIO is, doesn't matter which review we're in, those requirements are still the same and they haven't changed. I think it's kind of a bummer that they decided to do this review so long into Davies 10 year at this point. I just don't think they're going to find very much to change when they get done with it. And yeah, so I would not take your eye off the ball on DFR 712 because the DOJ certainly isn't. - I think it's a great point and it's a great way to end and I'll just add too. We have something this time that we didn't have the last time, this affirmation requirement, which is an explicit promise to the department that you actually have implemented these controls before you can maybe argue some ignorance to that fact whether that argument would be successful or not is another story, but you don't have that argument anymore. - Yeah. Now, I mean, maybe they pull a rabbit out of their hat and they figure out some AI infused magical easy button that makes the assessments free and fast and scalable for everybody who wants one tomorrow doesn't fix the cost problem of implementing the requirements. So I think that they might make some progress after the review, but they're not going to solve the problem that they think they're going to solve. - Let me ask, I promise I bet you go, but one last question. After this review is over, what do you think the outcome will be if you had a guess? - Well, of history is any guide. They're going to reach the exact same conclusion. I'll tell you what I would love to see happen. I wrote an email to Miss Davies after I met her in person in January after she became the DOD CIO and I said, you want to reduce the cost of the program? You want to dramatically reduce the number of companies that are affected by CMMC? Delete CMMC level one. There you go. Because with the FAR CIOI rule, the standard form on the FAR CIOI rule now positively indicates whether or not you have CIOI and exactly what kind of CIOI that it is. This is the holy grail that we've been missing for the last 10 years. So if you eliminate CMMC level one, two thirds of the cost and two thirds of the companies affected by the program are no longer a problem. And with the standard form under the FAR CIOI rule, the problem of mystery data artificially inflating scope and cost is also solved. So now all of a sudden, your 20% reduction in affected companies might be 30 or 40%. And I don't know, because it depends on the data flow. But you have to lean into the regulation to solve the problem rather than just pretending like you can ignore the regulation and magic your way out of the situation. So there are ways forward that would be wonderful. I just wish they would have done it day one instead of six months into return or whatever, 'cause now we're gonna run the FAR CIOI rule.
into the holidays and all that other stuff. Absolutely. Well, Jacob, thank you so much for joining us. Really appreciate it and we'll talk again soon. Yeah, absolutely.
Podcast Summary
Key Points:
The Department of Defense suspended Phase 2 of the CMMC program for a 60-day review, citing cost and bureaucracy, but the underlying security control compliance remains mandatory.
Self-assessments have historically failed to ensure compliance, creating a reverse incentive that penalizes compliant companies and rewards non-compliant ones.
The suspension undermines trust in the program, as stakeholders who invested in CMMC 1.0 and 2.0 now face uncertainty, weakening future cybersecurity initiatives.
Innovation concerns are unfounded, as waivers and other transaction agreements exist for innovative projects; the main cost is implementing security controls, not certification.
The DOD exceeded certification expectations in Phase 1, with 575 Level 2 certifications in November 2025 alone, yet the review threatens to delay progress.
Eliminating third-party certifications would contradict the statutory mandate requiring proof of compliance, as self-assessments have proven ineffective.
Whistleblowers and False Claims Act lawsuits may fill enforcement gaps if self-assessments are revived, but third-party assessments remain the gold standard for accountability.
Summary:
The podcast discusses the Department of Defense's suspension of CMMC Phase 2 and its implications. Host Eric Crucius and guest Jacob Horn argue that the suspension, while citing cost and bureaucracy, ignores that most expenses stem from implementing underlying NIST 800-171 security controls, not certification. Self-assessments have historically failed, rewarding non-compliance and penalizing companies that invest in security.
0 eroded stakeholder confidence. Despite the DOD exceeding certification targets in Phase 1, the review delays progress. Horn traces the decade-long policy gap since 2011, noting that repeated reviews follow preventable cybersecurity breaches.
Eliminating third-party certifications would violate the statutory mandate for proof of compliance, as self-assessments have proven ineffective. The DOD could rely on whistleblowers and False Claims Act cases for enforcement, but this is messier than third-party assessments. Ultimately, contractors must continue complying with security controls to avoid liability, and the suspension may weaken future cybersecurity initiatives.
FAQs
The CMMC program is designed to fix a policy gap in DOD cybersecurity policy since 2011, requiring contractors to prove they meet security requirements for handling sensitive controlled information. It was created after widespread noncompliance and cybersecurity catastrophes, as mandated by the FY20 NDAA.
The DOD suspended phase two to conduct a 60-day review, citing cost and bureaucracy of CMMC, particularly the third-party certification process. They also issued an RFI to gather industry feedback during this period.
Self-assessments are not effective because they reward companies that don't implement security controls, creating a reverse incentive that punishes compliant companies. The DOD has acknowledged this, and third-party assessments are considered the gold standard.
Contractors must still comply with NIST-800171 requirements, as they are subject to false claims act claims if not. They must continue to be vigilant and certify compliance under oath to the government.
The DOD has repeatedly revised requirements after preventable cybersecurity catastrophes, including extensions, program reviews, and changes from CMMC 1.0 to 2.0. The latest review pauses phase two despite ongoing rulemaking for CMMC 3.0.
The review could eliminate third-party certification requirements, but this would conflict with the statute mandating proof of compliance. It may also rely on whistleblowers or DiBCAC assessments, though these options are less effective.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.