The Practical Matters of CMMC: Considerations & Common Challenges in Pursuing Level 2 Certification
With CMMC deadlines approaching and Level 2 certification becoming a requirement for many Department of Defense contracts, organizations are facing a difficult reality: achieving compliance is often far more operationally and technically complex than expected.
From underestimated preparation timelines and scoping challenges to FedRAMP requirements, documentation burdens, and costly remediation efforts, many contractors are discovering that CMMC readiness is not a quick checklist exercise. As of April 2026, only an estimated 1,300 organizations out of more than 104,000 in scope have successfully achieved Level 2 certification.
In this expert led discussion, Tevora’s Federal Compliance team, Jeremiah Sahlberg, Wayne Perry, and Alex Adams, moderated by Erin Badger, break down the practical realities organizations are encountering throughout the certification journey. The session explores how contractors should approach scoping, budgeting, technical remediation, operational planning, and long term compliance strategy before entering an official assessment.
Key Takeaways:
- What organizations should realistically expect during the certification process
- Why scoping mistakes can dramatically increase cost, effort, and timelines
- Common technical challenges involving FIPS validation, FedRAMP, encryption, and CUI handling
- How mature cybersecurity programs can accelerate certification readiness
- What assessors are actually looking for during a Level 2 evaluation
- Why CMMC should be treated as both a cybersecurity initiative and a business decision
Whether your organization is beginning its CMMC journey or preparing for a formal assessment, this session offers practical guidance on navigating one of the most significant compliance shifts facing the defense industrial base today.
Welcome everyone. Appreciate you all joining today. We’re really excited about the webinar that we’ve got for you all. We’re just going to give a couple of minutes for our participants to get in, and then we’ll get started. People are joining, so we were just having a little bit of a debate before everyone joined internally here, and I’ve got a little bit. Jeremiah really wanted me to ask this question, so just for our panelists, a little icebreaker before we get officially underway here. What do we prefer, apples or oranges? Jeremiah, do you want to go first, since you were so excited about this topic?
Let’s always kind of an icebreaker, and we’ve done different ones at different events here, so for I’ve been watching Stephen Colbert this last couple weeks as he’s going off the air, and it’s one of the questions that he includes in his questionnaire, so it’s like, that’s kind of an interesting one. For me, I’ve got a two-part answer here, I guess. If it’s earlier in the day, if it’s around lunchtime, is when I’d probably choose an apple. You can put peanut butter and apple. I don’t think you can put peanut butter on an orange. Well, I guess you could put peanut butter on an orange, but that sounds really gross. So, I would say apples for sure before dinner. I would say an after dinner treat for me, I would have to lean towards an orange, because I love a good old fashioned, and a properly made old fashioned has a little bit of an orange peel in it, so I’m going to go with both.
Wayne, how about you? Thanks for me, a lot simpler. I came from Florida. I love citrus, so I’m going with oranges, plus they give you a good healthy dose of vitamin C.
For my part, I’m also Florida born and raised, and we’ll also go with the orange eye for me. The peeling is a nice meditative exercise, and then I get to finish it off with a treat.
I guess I’ll throw my answer in there. I actually prefer Clementines, so nice curve ball.
Looks like we’ve got quite a few already joined here. I’ll get started here with introductions. My name is Erin Badger. I’m an account director here at Tevora, primarily supporting our clients across New England, and I’ve been lucky enough to be with Tevora for just over eight years now, and really looking forward to moderating the panel today. For those of you unfamiliar with Tovora, we’re a nationwide cybersecurity and compliance consultancy over 23 years in business. We are a registered practitioner organization designated by the Cyber AB and a C3PAO candidate. While Tevora provides a wide range of cybersecurity and compliance services, today obviously we’re going to be focusing on CME CMMC certification, many of you are likely here because you’re seeking CMMC certification to remain eligible for a DOD or a DOW contract. There are an estimated 104,000 companies that are in scope for CMMC certification, and as of last month, only 1198 just to be exact, CMMC level two certificates have actually been issued. If you haven’t yet earned your certification, you’re definitely not alone. We’re glad you’re here. Before you begin this long journey, I’m sure you’re looking for some practical advice on what to expect. How to plan for the certification project process, and that’s why we have our expert team here today. I’m just going to ask our panelists to give a brief introduction.
Thank you for joining this webinar today. My name is Jeremiah Sahlberg. I’m the principal consultant here at Tevora, which means I oversee a number of our consulting towers, including our federal services, like Aaron. We actually started on the same day, little over eight years ago. I’ve been a CSO in the past life, and certainly have some good stories that I’ll bring to the conversation today, as we’ve had these conversations and started to help our clients on this journey. But thank you for having me.
My name is Wayne Perry. I’m the newbie here, I’ve recently joined Tavora, going on a year. I come with 25 years of experience, mainly supporting the federal government and also Fortune 500 companies to obtain certification in areas such as FedRAMP. Definitely looking forward to talking and helping out the viewers to help them on their CMC journey.
I’m Alex Adams. I’m been with Tevora for just over three years now, I’m a CCA and RP, and I’ve been the one ear to the ground with CMMC for the past few years, attending the conferences and talking to ecosystem members to try and get the best idea of how things have been over the past few years as the rule has gone into effect, and we’re seeing organizations start to get over the finish line.
Thanks, everyone. Like I said, a team of experts, so we’re looking forward to a productive conversation today. Just one more housekeeping item before we fully get underway. If you have any questions for our panelists at any point, please throw those in the Q&A box. At the end of the session, we’ll do our best to respond to all of those. Let’s get started. First question, what are you hearing from clients that are embarking on the CMMC journey, Jeremiah. Do you want to start with this one?
This is a good place to start the conversation, is to understand, the psyche of the customer if they’re starting this journey, it really depends upon where they’re at, but a lot of them are feeling overwhelmed, like, this is something new that I should be doing. In reality, the base control lines that are underneath this is something that’s been around for over one or nine years at this point, but they’re overwhelmed because it’s not something they focused on before, and a lot of times, especially with some of the mid-market and smaller entities, they may not have dedicated cybersecurity team members, maybe they don’t even have a whole full cybersecurity team, and so you’ve got someone who’s maybe a director of IT that also wears the hat here, or maybe a contracts manager that’s trying to say, we’ve got all these things in place, it’s like, what’s this, CMMC requirement, and so there’s this sense of being overwhelmed that we’re seeing from our customers or potential customers. The other thing that we’re hearing a little bit on the news last year, I think there were three major settlements, and this really came from the False Claims Act, and some of the organizations that had previously attested within the Spurs system that we had all these controls in place. Turns out a breach event happened, or a whistleblower event happened, they went in there like, you actually did not have these controls in place, and some of these fines. I think last year there was a couple different cases spanning from $4 million fines all up to $12 million fines for organizations that falsely claimed that they were compliant with these controls, and so we’re kind of here that’s like there’s this, I’m overwhelmed, I hear that I’m not gonna get my contracts, I hear there’s fines. I’m hearing that from one CEO, where they didn’t have a well-developed cybersecurity team. He’s like, can I just buy my way out of this? Can I just write a check to someone to become compliant? The answer is not really. You can’t. I mean, yes, you can hire partners and buy tools that support your journey, but there’s this sense of how do I make this problem someone else’s, when in reality these organizations need to own their journey for becoming CMMC compliant. That’s kind of this like psyche that I’m seeing when I’m talking to different folks for the entities that are a little bit more mature and a little bit further in their journey, then they’ve got a plan, they’re working down that path. I wouldn’t say that’s a characteristic for everyone, but there is part of the spectrum in the ecosystem that’s trying to figure this out.
Thanks, Jeremiah. I think overwhelmed is definitely something that we’re all hearing a little bit when it comes to CMMC, so appreciate that. All right, so next question. The CMMC ruling has been evolving over the last several years. What is the status of the program today?
I can address this one, so recently 48 CFR was released, and that’s the final rule. There’s a lot of misconceptions about what that means in the industry. There’s, as I’m sure many on the line know, there’s several December 10 dates going out to 2028. Previously, there’s some misconceptions that was a deadline, but then recently, there’s been more and more talk about what exactly that means, so just understanding that the dates that contracts are become eligible according to the three phases to start receiving those DFAR clauses within them, so that’s one of the clarifications that some benefited the industry, and one of the things that we stress when we’re talking to our clients.
In addition to that, we’ve had about a year and a half now of certification assessments, so we’ve got a much better idea of the number of organizations that are already prepared to tackle certification and how the assessments are running, how the full ecosystem is supporting those, and also shaking out which vendors are able to enable what types of operations, what organizations in their CMMC journey, so there’s a real timeline, not a strict deadline, but some real time pressure for organizations to figure out when their contracts are going to come up for bid and how they can prepare for that, but we also have better resources now than yesterday, about what the assessment is going to look like, and what their tools are for preparation.
Thank you. Next question. Here, this is a good one. Many in our audience are probably asking themselves the same question. Is obtaining a CMMC certification really worth it? I would say both in terms of the overall investment and really the overall effort as well. Jeremiah, do you want to tackle that one first?
Is it worth it? Boy, that’s a business decision for every organization. If your sole revenues come in from the DOW, then absolutely, it’s something that you’re gonna have to invest in. If it’s something that’s a small percentage, your overall revenue, then it’s something that I’ve seen some organizations take a heart to take a moment and say, is the effort to go through and get these controls in place worth the revenue relative to their business portfolio. The one thing I would say is that when you look at CMMC 95, I’m picking the number 95, It’s an arbitrary number here, but a majority of the controls for achieving CMMC level 2, based upon the NIST 80171 framework, are just good standard practices to have in place within an organization. There are a couple of them that are a little bit nuanced and focused within the DoD space, but anyone who’s looking to build their cybersecurity program can. If you’re a cyber leader in your organization, or you’re maybe the IT manager that’s looking to mature your program, certainly adopting this as a minimum criteria for bolstering your security budget, it becomes really an opportunity in my mind for saying, we have to do this, we can help level up our posture as an organization. The big answer to the question there, is I’d say yes. Is it worth it? But, as all things, it does take investment, it takes time, it takes some energy to go through it. If your business is dependent upon government contracts, absolutely. If you’re just maybe flirting with the DOD contracts, and you don’t want to have a secure program, then maybe it doesn’t make sense. But by and large, I’d say, yeah, it does make sense to invest in this direction.
You’re saying really, at the end of the day, it comes down to sort of an ROI extra exercise, I’d say building on what Jeremiah pointed out, to properly embrace the CMC program, I think organizations should look at it more as a business development function to their or to their business, it’s going to be something that. Enables them to reach out and capture some exclusive contracts, and there’s also already evidence out there that shows that early adopters are already seeing that high ROI based on the fact that there’s a small number of DIB partners that are CMSC certified versus the demand pool for certified suppliers.
Then next question, kind of along those lines, where we’re talking about ROI, right? How much should the organization look to budget, and what are the ongoing costs to sustain a CMMC compliant program, you know, as a salesperson, Aaron, you’re always asking me, give pricing on in public, and we’re in a webinar here, I’m not giving actual pricing.
I tell the sales team, don’t share pricing until you’ve got all the business criteria, scope, and all that other stuff. I’m going to listen to my own words here, not actually give you $1 value answer, but rather talk about the components that go into it to help size out a budgetary effort that goes with this, and it really depends upon a couple things. What is the size and complexity of the organization? Some organizations, where you’ve already invested in a mature program, it can be a much easier uplift for organizations that maybe they have not invested in their cybersecurity program. Then there’s certainly going to be a larger lift, we always talk about it from what’s the assessment cost. People are coming to us, can you gap assessment? Let’s cost you a full assessment. What’s the remediation? But the total cost for going through this program is certainly understanding your current state. Typically, a gap assessment, the remediation can be a large effort of the budget. Sometimes you have to implement new technologies. I got to use FIPS 142 validated cryptographies. I may have to make some technical changes, may have to actually deploy some technology within the organization. Then I have to go through and maybe get a mock assessment coupled with a full compliance assessment as an organization. If you’re looking for the actual certification with level two, if we’re dealing with level one, then it’s just, I got these 15 controls in place, so I think the question has to really be broken in. Are we going after level one or level two certification, depending upon is it just federal contract information, or if there’s CUI within the environment? What’s the current state of the environment? How complex it is, and really, is there technical debt that the organization has? Or can you go to an enclave where you can just deploy a net new solution? That’s probably one of the biggest strategy discussions we get roped into. Do I need to uplift this environment, or can I create an enclave over here, wrap it in the enclave, and then it can be less expensive, but it really just depends. Does that model support your business? Can I keep the CUI in this enclave, or do I need to keep my CUI that’s a part of my machine shops that’s tied into these CNC devices, that’s now roping in this on-prem requirement. I hate to, in this moment, give you a ‘it depends’ answer, but..
I agree with Jeremiah, definitely it’s very hard to discern what the amount of time is for one client versus the next, highly variable, definitely depends on their maturity and scoping. I think scoping is paramount in this whole exercise, and getting that right really drives the rest of the effort.
Jeremiah, you said not to pick on you, but I want to kind of go back to a comment you made about sort of that remediation phase, and potentially implementing new technologies, so I’m just thinking about a conversation I had with a defense contractor the other day, going through this process, and it came around to some of the tools that they needed to implement, for example, if you outsource your SOC, are there certain considerations that you need to take when evaluating those tools that may or may not meet the requirements for CMMC.
100% I’ll probably kick the ball over here to Alex in a second to talk about some of the, we do have a cheat sheet internally of free solutions for different things for trainings and other considerations on what’s a lower cost impact but using AI. If you’re using a cloud service provider for something within your ecosystem that is going to hold the CUI, whether or not they are FedRAMP certified, and you’re extending your data into their environment becomes a costly investment for some organizations that maybe haven’t had the forethought to think about this and understand some of the criteria that’s been pushed out there over the last several years, I would kind of say, the investments that are needed, there’s your own tech for what you can manage, but looking at whether or not your third-party vendors are they a cloud service provider or are they an external service provider? I think there’s a nuanced difference there, maybe I’ll give Alex an opportunity to talk both through CSP versus ESP, as well as some other things that you have to consider in costs for when there’s remediation efforts that need to be done by an organization.
I think Jeremiah accurately covered it, but just to rehash it, any external party under the CMC 32 CFR rule is going to be considered a an external service provider in ESP, and then there are further broken up creatively into ESP CSPs and ESP, not CSPs, and the difference is that those ESPs handling CUI in a cloud environment do need to be FedRAMP authorized, but importantly, if they’re handling just security protection data, so maybe your, your SIM, or your, your vulnerability management data that does not have to be FedRAMP moderate authorized, it does still need to meet the applicable control requirements in terms of access control flow enforcement, but there’s not that additional cost increase in order to get into a FedRAMP authorized environment, and there are other important cost-saving measures, and this is stepping a bit into our to the later soaping discussion, but the DoD has laid out a very specific way that you can configure connections to cloud assets, where you only allow for a video stream, you don’t allow any type of copy paste, any type of screen capture or video recording, and that allows you to remove your enterprise assets from scope, which can reduce your mediation costs, your compliance and documentation burden. If you’re purely looking at a cloud system versus a hybrid cloud and enterprise system, but at the end of the day, the solution that you pick has to work with your operational requirements. There’s many companies that will sell you a nice compliant box, but if you can’t get the documents out of your box and remain compliant in order to actually do the work, then you know you can certify that box, but you can’t deliver on the contracts that you win.
That’s a really good point. Awesome. Let’s go to the next question. Then, what does the CMMC journey look like for a contractor, and how long does it take to go through that process?
Again, scoping is the theme here, as we’ve pointed out several times, the journey varies significantly by the client, and can be quite rigorous and daunting, depending on their scope, complexity, and maturity. With that said, it’s best not to approach CMC as a single project, but rather phases. I find it funny that they call it the Cybersecurity Maturity Model Certification, when really, it’s like an Organizational Maturity Model certification, so I’m sure many clients have discovered that the hard way. We typically see five phases: discovery and system boundary architecture design, implementation, mock assessment, and then finally the independent C3PO assessment, but again, discovery is the most critical phase, and where the journey really starts to take shape. On the recent engagement with a large AC construction firm, we spent significantly more time than we anticipated during that initial phase doing workflow walkthroughs, business unit by business unit, asking people to describe how they work today in plain language. Why that’s so important, you don’t want to make any assumptions when you walk in on these client engagements. We did not assume that any controls existed. The answers that were told to us where CUI fault flow, we really wanted to discover is where CUI flowed and what in that told us what to build, so this step can’t be fast tracked and it requires diligence as it sets the direction and tone for the subsequent activities, so with that said, a realistic timeline is typically 9 – 15 months. I’ve heard some cases of things some organizations getting through it in five months, but those are highly mature and very simple environments. For most mid-sized organizations, definitely 9 – 15 months is what I would bank on, and then that assumes that leadership is engaged in there’s reasonably contained CUI footprint. The variables that move the date left or right are definitely the scope size, how much of the environment touches CUI, and organizational readiness. Two things that compress or stretch that timeline more than anything else is first the scoping discipline up front, and then every asset you keep out of the boundary is remediation that you never have to do, so certainly looking for opportunities to descope where possible, and then second, the cloud tool inventory, if a tool has FedRAMP authorized, like Alex pointed out, then there’s a government variant. The migration can be very smooth, and sometimes often just switching licenses, so definitely looking for those opportunities as well.
You think you gave a very realistic for some of those mid but complicated environments, and someone who doesn’t know where their data always flows and hasn’t tackled this. I’m going to give a kind of a different end of the spectrum answer. I did work very closely with a firm who was fairly mature on their CMMC journey, or just their cybersecurity program journey. They were already ISO certified, and because they had a foundation that they had built upon, they had rigorous processes where their data flowed. We came in and within two months were able to identify the gaps of what they needed to add into there. They had to develop an SSP to go with it, but got them up and running, and they went out and got them through their certification assessment. 100% first try, no issues at all. I think it really comes back to the point of how long it takes. It really depends on how much you’ve already invested in your cybersecurity program. A good chunk of these controls are just table stakes for a mature program, and if you’ve already invested in those, you’re probably done a good chunk of the work, but if you haven’t, then you’ve got more work to do, and it’ll take a little bit longer.
Great, thank you. This goes back to what you all have touched on already a little bit in each of your responses, but really, the important question, How does an organization properly scope for CMMC? Where to start, and what are kind of the first steps?
I’ll give you the really the dumbed-down version that I think will turn into a little bit of more of a discussion. Is first off, so there’s level one, and I’m assuming everyone’s here because they’ve read something about CMMC, they understand level one, maybe level two, and if they don’t, where is your federal contract information following that in your environment, and then secondarily following where your CUI is within your environment, as Wayne had talked out that through that process, but knowing that those can have two distinct paths within your organization, and what your FCI scope is may be different than your CUI scope. Then think about those as two different approaches for certification. Where do I have to submit my Spurs score for my FCI? Where do I have to do my either annual or certified assessment for ICU. If anyone else wants to build on that, but I would say, follow those two things. How do they come into your organization? Who touches them, and where it goes? That’s kind of the cheap, easy answer. I’ll let the others kind of chime in with some more details about what does scoping really mean.
Build on that, so that’s there is often even a step zero before following the SCI and CUI, which is to figure out what your FCI and CUI are. The DoD is not consistent about identifying all of the CUI, so sometimes it is specified within the contract, there should be a CUI data sheet that describes what you are meant as an OSC to treat as CUI, and then ideally the CUI is also properly marked, but that can often be a discussion in and of itself that may involve the contracting officer to ensure that you’re clear on what that data is from there CMMC is a an asset based assessment scope so based on where the FCI and CUI flows, as well as the other assets that are on the same network or within the same system, even if they’re not involved in those processes. That all is going to contribute to your scope, and the CMC establishes a couple of different asset categories that all have different assessment requirements, so anything CUI has, the 110 missed 80171 requirements, but then if it’s not handling CUI but just protecting CUI, it has a smaller scope, and then devices that are connected to those, but not meant to handle CUI. Those have primarily documentation based, but a different scope. It’s important to ensure that you have the expertise to properly categorize, so that you’re fully aware of the obligate the requirements and the obligations for all of these assets, and then you can look at the process and see where can we remove some of these assets in order to reduce the time, effort, and budget required to achieve compliance.
As Alex pointed out, another important aspect of that is the flip side is understanding what isn’t CUI. Oftentimes, folks need to recognize that commercial off-the-shelf type of information is not considered CUI. In those circumstances, it’s very important that we look for opportunities to say, what we initially thought this was the UI, but you know what, it actually isn’t, so we can descope this whole information system or workflow or data flow, or whatever. Just recognizing that if something’s publicly available, if it’s something that you can go and buy, at your at the local Walmart, Target, whatever, or the equivalent, then that’s no longer considered CUI. CUI only applies to government-specific type of technical information that isn’t commercial or openly available to the public.
Great point. All right, let’s move on to the next question. From your perspective, what are the top three technical challenges with meeting CMMC criteria? Alex, why don’t we start with you on this one?
As a CCA, I’ve got a couple of pretty specific challenges, and maybe Wayne and Jeremiah will zoom out from there, but tips 140 is one of the top challenges that that I see organizations run into, the first is tips validated versus tips compliant, where they sound equivalent, but FIPS validated is what’s required. It means that all of the components have been evaluated together and given the green light, versus just the piece parts. What’s challenging about it is that each appliance or each system typically has a custom way to check for and then enforce tips mode to ensure compliance, so it can be a manual and an extended effort rather than slipping, flipping one switch, or adding one technology that’s going to cover you the way that some other controls can. A second challenge that organizations often work with is establishing system baselines where many stations will just apply the recommended defaults over the lifetime of their organization, and then they have a huge baseline that they’ve never specifically reviewed. It’s all additive, and slowly tackling the debt of reviewing everything that has been put in place, ensuring that it both addresses security requirements as well as operational requirements, is an extended compliance project, and the final one is system scanning, so a lot of modern malicious code scanners are focused on real-time file scanning, but there is still a specific CMMC requirement to have full or not full system scans, but to have periodic system scans. In addition to that, that requires configuration, it’s rarely a default, and ensuring that you are scanning strategically to still cover the handful of vulnerable areas where those periodic scans are really bringing some security to the equation, while not crippling the system with a full scan that is redundant with your real time efforts, requires some tuning and effort.
I’ll jump in here. Three challenges I say, you already gave three, so I think I should be off the hook here, but if you want me to give three more, I’ll add my own flavor to this. I think we talked about a little bit, but scoping is a challenge for organizations, we talked about that, but I think getting the head wrapped around that’s okay to have different boundaries for your FCI versus your CUI, it’s like, here’s my contract information. You don’t have to have all the CUI controls in place for your FCI if you’re willing to create different strategies for what’s how you’re handling FCI versus CUI. Another one, this is, I was at a conference talking to someone, and he was very new to it. He’s like, “Oh, I see that there’s this tool. They say if I buy this tool, I’ll be compliant”. It’s like, tools are an important part of the solution, but you can’t just buy a tool to be compliant and you’re done. There’s for the less mature, that’s definitely a challenge, but one that I think really came up in discussion is with these business owners that have not invested in having cybersecurity teams or cybersecurity leadership, they don’t have a governance program in place, and so there’s not someone to govern the process or govern the process, and that also understands the technology, so it’s one of those you need someone who gets both. I have to do these things, I have to have continuous monitoring capabilities, I have to have these activities go in place but understand how that affects the actual operations of the organization. Sometimes they’re just happy to get a contract and go build some stuff that actually can be plugged into some apparatus that gets attached to a tank or about whatever it is, so I think just that knowledge gap there becomes the technical challenge that I’ve seen recently.
I agree, but I’m going to flip flop again, and before I was talking about overscoping, now I’m going to talk about underscoping. Definitely one thing that I’ve discovered working with some of these more complex environments is that, in the manufacturing, construction, and in AEC space operational technology in those environments where you know oftentimes they’re overlooking where their CUI is flowing, particularly when it comes to CUI adjacent data flows, such as coordinates, technology, technical specs, diagnostics, telemetry, and engineering data, so making sure that we capture those is definitely one of the challenges addressing specialized assets. Alex touched on some of the asset categories. Specialized assets and CUI assets are particularly challenging because essentially those systems don’t lend well to traditional endpoint protection and things like that, so where those systems are maintained by OEMs and cannot be supported by the security tooling, they don’t integrate into the enterprise’s security stack. Those scenarios, IOS often require creative compensating controls, such as proxy access, jump boxes, segmented enclaves, or VDI-based access models. Bringing RPO like Tevora in to help with those unique use cases is certainly helpful for the clients. Finally, organizations also need to remember that the CMMC program isn’t just purely technical. I know we’re talking about technical challenges, but there’s a whole other aspects that need to be covered, such as the operational, managerial, physical, and personnel security safeguards that need to be put in place, and along with those safeguards, they need to be, there’s a documentation component to it, so those documents need to be well written, tested, and defensible for when they go through their independent assessment.
Good point, that it’s not just a purely technical exercise there. Let’s move on to the next question. Then we’ve got a couple left here. What are some of the biggest surprises that our clients are seeing during assessments? Alex, you want to tackle that one first?
It’s surprising for clients, but unsurprising for us is once again relates to scope, it 3.1 dot 22 which is control public information, while most of the controls are going to be scoped to those different asset categories, as we’ve talked about this one control, does reach outside of those scopes, and it’s going to look at all of the public systems controlled by an organization, so mostly websites, as well as any other hosted press releases, or other information, so now most for most organizations, their marketing team now has some involvement in the CMMC journey, in that they need to have a basic understanding of FCI and CUI to ensure that they’re not putting out the door, and then there is also a requirement for organizations to perform a look back, make sure that anything on the websites that they posted previously doesn’t have any FCI or CUI, and that that includes pictures, so you can have a nice video walkthrough of one of your one of your offices or workspaces, and if there’s something on a computer screen or on a desk that might be CUI, that’s a non-text-based way that there could be spillage of that information.
I love that. When in doubt, blame sales and marketing, right?
Is that what I said? Another, another surprise is encryption at rest. The relevant control simply says protect the confidentiality of a CUI at rest, and most people interpret that as using encryption, but that can also be done using physical protections, so a data center with proper physical protection access control does fulfill the requirements of to protect the CUI at rest, and where encryption becomes mandatory is going to be for devices that are out in the world, so laptops, mobile devices, and then whenever there’s encryption, that’s when your FIPS validation requirement comes in, and that that’s a surprise to many organizations who are really getting into the weeds trying to get that FIPS validated encryption into their network backup within their data center, that from CMMC revenue perspective, that’s not something that they need to invest time in from a compliance perspective.
One thing I’d like to also add to with Alex’s point out about encryption at rest and fit validation, and things like that, particularly when dealing with construction type environments and clients that have field operations. FIPS also has physical components to it, so some part of the physical or the VIP validation is also the assessment of the hardware in the cryptographic modules against specific tamper resistance and tamper evidence standards. That’s an important aspect that is often overlooked as look for that fifth validation when it comes to this physical security as well.
A big surprise for me, so there are a couple things. One, this is an open book compliance test out there, so the answers are within the CMC assessment guide that stipulate how you do it. Everyone talks about the 80171 as being the anchor on this surprise, and then people go, “Hey, go to the NIST website and go download that NIST 80171, knowing that there’s a NIST 80171 A, which is the assessor’s guide, and then more clearly specified in the CMC assessment guides that actually describe what it means, and there’s times it says, ‘Oh, well, this 80171 said this. Okay, read it all right. I could be interpreted this or this. Let’s go to the assessment guide and actually ask what they’re looking for. It’s amazing to me how many times things are misunderstood from just not understanding how to read the control, and as silly as it says, it’s like this must be documented, or this must be identified, or this must exist. It’s like sometimes people will take that sentence and just add a bunch of things to it’s like, no, it doesn’t say anything more than that. It just says this one little thing, so let’s not add complexity. Yes, you have to interpret what it means, but sometimes people just start layering in. I think that this is what this means, when reality, it’s no, read what it states, don’t make it bigger than it needs to be. Answer the question.
Thank you. I guess that leads perfectly into our next question, which CMMC control is most often misinterpreted. Who wants to take that one first?
One control, definitely with the case for being most interpreted is 3.12. to the operational plan of action control CMC does include a poem, but it’s the only framework that uses the poem in that way, for CMMC a poem is the all that it does is to bridge a conditional certification into a final certification, so if you have your certification, but you’ve you scored higher than an 80% and only missed some eligible controls, then you can get just those few controls reassessed and turn it into a final certification in, in other frameworks, your POAM is what you’re using to manage the ongoing improvement of your system, and for CMMC, that’s the operational plan of action, it is almost essentially the same as a poem for FedRAMP and other frameworks, so if you understand it, understand those, then you’ve got a pretty good idea of an operational plan of action. There’s one call out that I’ll bring up, which is enduring exceptions. When a vendor has to release a patch, or a technology is in the process of getting their FIPS once again, their FIPS 140 validation updated, and operationally you’re required to do something that puts you out of compliance, then you can document that on your operational plan of action as an enduring exception. Have a plan to check back every quarter or every six months to see if the solution is there, so that you can move it to completion, but that is an acceptable way to pass a level two certification as long as you’ve got that enduring exception in place, where applicable.
Great, thanks. Alex Jeremiah Wayne, did you have anything you wanted to add to that?
Have a little bit of a point on one thing, it’s kind of building on what Alex had mentioned before about the requirement around marketing in teams and checking websites and in talking with a company down in Texas, they had hired a fresh out of college person to be their social media liaison to talk about publishing content and stuff out there, and we’re talking about the marketing team. How do you scrub your content for CUI? I said I need to talk to everyone who puts that out there, and so we talked to, the VP of marketing. Well, the website’s maintained by this person. Our social media is actually maintained by this other individual. I said, well, we need to go talk to both of them to understand what’s the process to understand. Talk to the social media person. How do you make sure you don’t have CUI in any of your social media posts? What’s CUI? I’d say I don’t know if it’s a misrepresentation or just knowing that people have to be trained on what this stuff is, so it’s like, let’s go through what is CMMC, what is CUI, what are things that we’re putting out there to promote the company, and is there a way to make sure that the things that you push out there? I would say the social media aspect of marketing still needs to be thought through as a marketing channel when it’s used to publish stuff about the organization, specifically if you’re trying to reference contracts and other things that you’ve recently won. I think there’s this legacy idea of press releases and websites, but the misrepresentation in media is different now. Media goes through these other channels to that need to be considered as vehicles on how CUI could inadvertently get shared.
I’ll just bounce off of what Alex pointed out earlier about the enduring exception, one thing to remind clients is that CMMC is just another variant of a risk-managed framework. Essentially, when it comes to these type of situations, when in doubt, document and provide justification, that’s going to get you a long way when it comes to the assessment, so anytime you’re in question, what do we do with this? We can’t handle it. Definitely document it, provide that justification, present that to the assessor, because what they want to see is that you’ve actually addressed and acknowledged the risk, versus ignoring it, so that would be my takeaway from that.
Thanks, Wayne. Really great points, everyone. Appreciate that. We’re getting sort of towards the end here, so I want to pivot and make sure we have time for we’ve got a couple audience questions that came in, so I’m going to let me just take a quick look here. Our first audience question: What stringency should security protection assets be assessed against CMMC practices? Are they required to adhere to all practices, or only the practices they are related to? For example, a SIM solution against monitoring practices or data encryption practices. Who wants to tackle that one?
I can start. With respect to security protection assets, number one, it depends if the security protection asset is capable of decrypting or seeing. Let’s say, CUI in clear text, then all the controls apply. If it is just seeing security protection asset type of data, telemetry data, vulnerability data, things like that. Then only those controls that apply to the function that is providing or need to be evaluated.
Thanks, Wayne. Appreciate it. Let’s see, we’ve got another one here that came in. We are already doing slash maintaining SOC two and FISMA. What, if any are any deltas that you see in CMMC level two assessment?
I’ll speak to this a little bit, so there is definitely some difference, but there is some core components that will get you there. CMMC Nissan, here was everyone biased towards the control implementation end of the spectrum for these frameworks, whereas I would say FISMA, if you think about NIS 853 much more policy and procedure oriented in general for those frameworks, so while it can be a certainly a good foundation, and certainly there is some crosswalks and overlay between the two, there will get you a good chunk of the way there, more so on the FISMA side, SOC 2, it will depend upon what trust criteria that you’ve already invested in. You’ve got security, privacy, integrity, confidentiality. It really depends on which availability, which of those control trust principles you’ve looked at as part of your SOC 2, but there will probably be a bigger gap if with a SOC 2 attestation, but there’s some good foundational building that goes on with that, you’ll have a little bit more of an alignment with the FISMA, but just because you’re compliant with 853 doesn’t guarantee compliance with 80171 so still work that could be done within the organization.
Jeremiah kind of touched on this, but when you think about the traditional security triad of confidentiality, integrity, availability, that is covered under many of the other frameworks, we need to remind ourselves that with CMMC, it’s primarily just the confidentiality and the data flows, so there’s talk about this expanding out in the future, but currently that’s what the focus is.
I think we might have time for one or two more. Let’s see here. This is this is a good one. How can I use AI to expedite my certification process? For example, can I use Copilot to help me write my CMC SSP?
No, we get an argument about which AI platform is better and what? No, yes, I mean, no. The answer is, I don’t. Using AI to write the SSP it wouldn’t necessarily give SSP has to describe how your organization has implemented those security controls. There’s lots of different ways to implement the security controls, and so unless your model has all of the details about your platform. I’m a big proponent of, AI is moving in directions to help organizations as a tool, but it does not replace an understanding of what your what you do as an organization. I would say it might be good to coach you on what does it mean in some areas. It might give you an indicator, but it will give you a false answer if you let it write your controls, because it has to be how your organization’s written the controls. Alex or Wayne, do you have an opinion on AI?
Yeah, I guess it depends on is the application called AI Slop, in which case I’m sure it would produce a very good SSP. Like Jeremiah pointed out, there’s definitely an art and a science to developing SSPs, and definitely you have to have a good understanding of number one, what the control means, and then number two, your environment and how that control applies to your particular environment, and not in my experience, AI isn’t capable of discerning those things that well if, if it’s written by, if it’s Alex intelligence, I give it a thumbs up, the SSP, but otherwise I don’t know.
Fair, fair enough, fair enough. AI does not know all, I guess, is what that what it comes down to. We’re just about at the top of the hour here, so I think that just about includes our panel. I just want to say, thank you, Jeremiah, Alex, and Wayne, for your insight today. I think that was a really great, productive conversation. I just want to thank our audience for joining us today. Hopefully, you gain some valuable tactics and strategies to move forward with your CMMC journey. If you’re looking for more, we’re about to release our CMMC 101 guide, updated for 2026 and the clarified CMMC 2.0 requirements. So, for anyone who joined today, I did receive permission to send you sort of a sneak peek copy, so just feel free to reach out to me directly, and I’m happy to help you out with that. My contact info is here on the screen, and thanks again for participating and joining us. And I hope everyone has a fantastic rest of their day.




