Listen to this episode

CMMC Cybersecurity and Compliance - October 2020

0:0035:14

Recorded October 2020. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.

The episode in brief

What this episode covers

Craig Petronella of Petronella Technology Group hosts an open question and answer session on the Cybersecurity Maturity Model Certification, joined by Jamal, Elisa, and Whitney. Craig announces passing the accreditation body test the previous Friday, describing himself as the first registered practitioner to pass all 12 tests, and weighs consulting versus assessing, since the ethics and code of conduct prevent doing both.

He tells Jamal that Gatekeeper, Jamal's password and access solution, could help satisfy CMMC controls, and suggests watching CMMCAB.org for a licensed software providers list. Craig explains that the DoD released the CMMC on the 31st of January, that defense contractors were already supposed to be compliant with NIST 800-171 at the time of recording, and that an interim rule announced on the 1st of October caused confusion about self-assessment submissions. He outlines a slow rollout of contracts requiring CMMC levels, describes False Claims Act penalties, and expects the CMMC to bleed into areas like payment cards and HIPAA, while Whitney anticipates pressure from insurers. The group also discusses security awareness training and cyber insurance limits.

Worth remembering

Key takeaways

  1. Craig Petronella announces passing the CMMC accreditation body tests, describing himself as the first registered practitioner to pass all 12 tests.
    “We did the registered practitioner organization, and I'm the first registered practitioner who passed all 12 tests.”
  2. Craig explains that, under the ethics and code of conduct, a firm cannot both consult for CMMC clients and assess them, and he sees more opportunity in consulting.
    “Once you perform one side of the other, you can't go to the other side.”
  3. Craig observes that many defense contractors should already be compliant with NIST 800-171 at the time of recording, but those he talks to are not close.
    “A lot of these defense contractors are supposed to be already compliant with NIST 800-171. At least the folks I talked to are not even close.”
  4. Craig warns that, at the time of recording, the False Claims Act allows three times the contract award plus other fines against non-compliant contractors.
    “So if you take money from the government, and you're awarded that $10 million, and they find that they're not compliant, they can enact the False Claims Act.”
  5. Craig says CMMC, at the time of recording, replaces self-attestation with on-site third-party assessment; contractors must show compliance rather than buy it.
    “You have to go through a third-party certified auditor. An assessor comes on-site to your location and watches over your shoulder to ensure that you have all this stuff you're attesting to at the maturity level you're after.”
  6. Craig explains that, at the time of recording, CMMC maturity level three adds 20 controls on top of the 110 NIST 800-171 controls.
    “Maturity level three has all of the 110 controls for NIST 800-171. But you need an additional 20 controls to get to maturity.”
  7. Craig argues the CMMC will bleed into other industries, pointing to payment cards and HIPAA as areas he expects it to affect.
    “That's kind of what I'm getting at and why I think that the CMMC will bleed into other industries.”

The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.

From the show notes

About this episode

Your host, Craig Petronella, #1 Best-Selling Amazon Author of multiple books, including Ultimate Guide to CMMC: How To Access Millions In Government Contracts, How HIPAA Can Crush Your Medical Practice and more. Craig is MIT Certified in AI, Blockchain and an IT Cyber Security Expert that founded Petronella Cybersecurity and Digital Forensics is frequently on ABC, CBS, and FOX news discusses the Cybersecurity Maturity Model Certification (CMMC) and how it may affect other regulations like HIPAA, SOC 2 Type II and others.

Full text

Episode transcript

Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.

Encrypted Ambition

Never miss an episode

New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.