CMMC, DFARS and NIST 800-171 Webinar and Podcast: The DOD is done playing around!
Recorded March 2021. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.
What this episode covers
In this webinar style episode, Erin, one of Petronella Technology Group's six certified registered practitioners, explains the origins of NIST, DFARS, and CMMC and how they fit together for Department of Defense contractors. She describes how DFARS 252.204-7012 directs contractors to NIST SP 800-171 for protecting controlled unclassified information, and argues that self-attestation has failed, citing an assessment in which no company was fully compliant.
At the time of recording, she says CMMC requirements were starting to appear in RFPs, with all contractors expected to hold certification by 2025. The episode covers the interim rule that, at the time of recording, required SPRS self-assessments and DoDAM scores, along with basic, medium, and high audits and penalties including False Claims Act cases. Erin debunks common misconceptions, recommends starting with a system security plan, policies, and consulting, and shares a discount code for resources on compliancearmor.com. Craig Petronella describes an end-to-end encrypted email and data solution built on Preval, and attendee Todd Weed asks how it handles exchanges between commercial and DoD environments.
Worth rememberingKey takeaways
- Complete the SPRS self-assessment of NIST SP 800-171; at the time of recording, contractors without an entry would not be awarded new DoD contracts.
“if you do not enter your self-assessment into SPURS. You will not be rewarded any new contracts.”
- Erin explains that, at the time of recording, lacking a system security plan left even a company with all 110 controls with a negative score.
“If you do not have an SSP, even if you have all 110 controls, In place, it doesn't matter.”
- Erin stresses that, at the time of recording, CMMC audits allowed no POAMs, so every security control had to be in place to pass.
“for CMMC, you will not be allowed any POAMs. It's you have to have every single security control in place or you fail.”
- Erin says plain Office 365 will not pass an audit; at the time of recording she called Microsoft 365 GCC High DoD the minimum.
“at a very minimum, you need Microsoft 365 GCC High DOD to pass an audit.”
- Erin argues that certification delivers a competitive advantage, since almost no business is currently eligible for contracts requiring CMMC certification.
“once you've put in the time, energy, and money it requires to get compliant and certified, you actually gain a competitive advantage over other businesses who are not certified.”
- Erin warns against the harmful misconception that the DFARS interim rule did not, at the time of recording, apply to companies that never touch CUI.
“if you do not touch CUI, the D FAR's interim rule does not apply to you.”
- Craig recommends an end-to-end encrypted email and data storage solution that bolts onto commercial Microsoft 365 because GCC High costs three times as much.
“We use what's called an end-to-end encrypted email data storage solution that bolts on top of Microsoft Office three hundred and sixty five commercial or Google or really most email applications.”
The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.
From the show notesAbout this episode
| Get the latest facts on the CMMC, DFARS and NIST 800-171 from CMMC-AB Certified RPO Petronellatech.com - Listen to CMMC-AB RP Erin Dotsey and CMMC-AB RP Craig Petronella discuss CMMC, DFARS 252.204-7012 - Watch the recording on our youtube channel at - Please be sure to hit the subscribe button to stay updated! The DOD is done playing around. Get compliant with CMMC, DFARS and NIST 800-171 with products at
Episode transcript
Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.
This is Encrypted Ambition, a podcast about the builders rewriting the rules. Join Petronella Technology Group as we decode the ideas, challenges, and momentum behind tomorrow's business, technology, and leadership breakthroughs. You're listening to Cybersecurity and Compliance with Craig Petronella. Visit us online at petronellatech.com.
This webinar is the first in a series of webinars that we are going to be doing. It's kind of just an introduction to CMMC, NIST DFARS, how they're all related, the interim rule, things of that nature, and really how the DoD is using all of this, all their tools, to signal that they are done playing around with cybersecurity. So.
Give you a brief overview on our objectives. By the end of this webinar, you will hopefully be more familiar with the origins of CMMC, also NIST and DFARS. Also, understand why it is that the DoD is done messing around. And then we are also going to go over the.
The next steps that your business needs to take to achieve CMMC certification, regardless of the level. All right, so just a brief background on Petronella Tech. Petronella Tech is a top cybersecurity and IT firm that's been doing business for 30 plus years.
We currently are a certified CMCCAB registered practitioner organization, or RPO, and we do have six certified CMCCAB registered practitioners, or RPs. I am one of those. I've actually been working for Craig for.
Going on eight years now, and I kind of specialize in writing about regulations, including CMMC. So throughout the years, I've become really familiar with it, which is one of the reasons why I decided to become a registered practitioner.
All right. So first, let's do an overview on NIST, DFARS, and CMMC. Oh my, because there's a lot to go over. And what I found is just that a lot of people don't really know the origins. They don't know how everything is related to each other, and it's understandable because there's not a lot of information out there. I had to do a lot of research to really understand.
How it all came together, but let's go ahead and start with NIST. It stands for the National Institute of Standards and Technology. It was actually established way back in one thousand, nine hundred and one by Congress to promote the U.S. economy through technical leadership for the country's measurements and standards infrastructure.
They develop and issue standards and guidelines that help to protect the sensitive information within federal agencies. And protecting federal contractors as well as the supply chain has become a major focus of NIST recently. They create publications, including the Special Publications (SPs), which I'm sure you've heard of, NIST SP, which are guidelines and technical specs. So NIST.
SP 800 series actually covers computer security, and SP 800 171 specifically outlines cybersecurity for contractors who handled control unclassified information, also known as CUI or CUI. And that is information that's created by or for the government, and it's sensitive but not technically classified.
All right. So DFARS, it's under the Federal Acquisition Regulation, or FAR, and it stands for the Defense Federal Acquisition Regulation Supplement. The FAR system was created from the Office of Federal Procurement Policy Act of 1974 to standardize the executive branch's acquisition process.
D FARs is a set of supplements. It's divided into chapters based on the department that it governs. So, D FARs 252.204-7012, which I'm sure we've also all heard of, is the second chapter of the supplement, and it regulates the Department of Defense acquisitions.
It's called safeguarding covered defense information and cyber incident reporting. Most of the supplement focuses on what to do if you're breached and the proper steps in notifying customers and government. But subset B particularly covers adequate security, and what it does is it tells the DoD contractors.
That they have to be NIST SP 800-171 compliant. So, who can tell the difference between NIST SP 800-171 and DFARS 252.204-7012? Well, first of all, DFARS explains to the DoD contractors what they need to do to protect covered defense information.
Which is CDI, and it is grouped into either CUI or covered technical information (CTI). But for the purposes, it's mostly CUI. And the vast majority of DFARS 252, 204, 701-2 explains to contractors what they have to do and who they have to notify if their CDI is breached.
There's only one subsection B that directs contractors to eight hundred one seventy one. So, what does this all mean? Basically, it means that even though they're not technically the same thing, all DOD contractors who handle CDI or CUI in any way have to be NIST eight hundred one seventy one compliant.
So, just an illustration. So, under NIST, we have the publications and the special publications here. Their guidelines and technical specifications. We have NIST SP 800, which is computer security. It addresses and supports the security and privacy needs of contractors who handle CUI. Oops, sorry about that. So that's NIST SP 800-171.
And then with FAR, the Federal Acquisition Regulation, we have the FAR system, and then under the FAR system, we have DFARS, which is the supplement, and they have different chapters. Chapter two, in particular, is for the Department of Defense, and we have the DFARS 2522047012 that directly instructs their contractors to take a look at NIST SP 80171 to make sure that that's how they are securing.
Their data. All right, and the reason that they're doing this, the reason for CMMC, is because even with NIST and DFARS, cyber espionage costs the U.S. six hundred billion dollars every single year. Still, so an example of this is China's counterfeit air force. They actually were able to steal.
Plans through Lockheed Martin, and even though Sue Bin, who was the guy that stole it, was sentenced to 46 months in prison, the repercussions of this are going to live on for decades. And that's just one example. Now, also another thing that kind of shows that NIS and defars aren't working.
There's a company called Sarah Bren that assessed a number of companies, and what they found is that zero companies were 100% compliant, not a single one. Okay, so that, as you can imagine, leaves big gaping holes in national security. On average, companies implemented only 39% of the controls.
61% of the controls, if you boil it down, were either not implemented or only partially implemented. What they found is kind of makes sense. Large companies, on average, successfully implemented a little bit more than the smaller companies at nearly 60%. But that's still not nearly enough. Small to mid-sized companies, however, only successfully implemented 34% of the controls.
And over 80% of the companies that were assessed failed to implement 16 specific controls. And what's really troubling is that there are three specific controls that could have prevented or significantly reduced data breaches. This includes 3.53, 3.5.3. Sorry about that. Multi-factor authentication.
3.2.1 awareness or training, and 3.11.3, which is vulnerability remediation or fixing your problems once you figure out that you have one. All right, so some further proof that NIST and DFARS are not working. First of all, so CMMC is basically spearheaded by Katie Arrington. She's the Office of Undersecretary Defense for Acquisition and Sustainment.
Now, the thing about NIST and DFARS, if you follow the advice that's listed there, they're fantastic, and if followed, it does work. But our data keeps getting stolen. Why is that? First of all, self attestation is not working. It's also too complicated, and companies don't know what they don't know, and a lot of times they don't even know where to start.
So, Katie Arrington likened cybersecurity to the advent, sorry, of automobiles. CMMC certification is your driver's license on the information superhighway. When cars were first invented, there were no rules and no infrastructure. But as time went on, people were hurt, even killed. They realized they needed more than just an honor system. And as Katie Arrington likes to say, "Trust but verify." We haven't - they haven't been verifying that these.
Been followed, so it just hasn't been working. So why now? Why is CMMC now? Well, RFPs and RFPs are going to include the CMMC requirements beginning later this year. There's a five-year acquisition process, which means that all contractors will require CMMC by 2025. Why 2025? Well, in 2025.
5G is going to be pretty much everywhere, and it's so fast that it's going to make protecting unsecured networks from outside threats practically impossible. Also, quantum computing is going to be very widespread, and it will enable bad actors to easily crack basic encryption.
So the goal with CMMC is to try and create a unified global cybersecurity standard. You can almost look at it like a U.S. license that will allow you to drive your vehicle anywhere in the world. So it's similar to ISO standards, but for cybersecurity. Now, what does this new regulation mean for your business?
Well, eventually, one thing that I see as a positive is that there will no longer be separate NIST or DFARS requirements. The CMMC combines various cybersecurity standards and best practices, and then maps these controls and processes across five different maturity levels. The maturity levels actually build on top of each other, so.
You can't reach level five unless you've already completed level one, two, three, and four, and they range from basic cyber hygiene to advanced cyber hygiene. Now, for a given CMMC level, the associated controls and processes, when implemented, will reduce risk against a specific set of cyber threats.
Now, this is really important, and you're going to see me reiterating this throughout the presentation. Contractors and subcontractors must be CMMC certified before they will be granted contracts. That means every single security control has to be in place. There, there's no room for error. It's go or no go.
It's imperative for you to be compliant by the time audits begin, because you will not be awarded a contract until you have become CMMC certified. Now, one thing I've noticed too is that contractors - they look at CMMC and NIST and DFARS, and it just seems overwhelming. It seems like it's going to be a sunk cost. It's hard to see the positive in it.
But there are actually some major benefits of being NIST, DFARS, and CMMC compliant. First of all, you have increased security. It also gives you a competitive advantage, peace of mind, and it gets you to the different CMMC levels. Now, for increased security, being compliant and certified will significantly reduce the likelihood of a breach.
And if you are breached, it will actually decrease the impact of the breach. So, looks really good for you to do this with your client's security. With a competitive advantage, once you've put in the time, energy, and money it requires to get compliant and certified, you actually gain a competitive advantage over other businesses who are not certified. If you have to be CMMC certified to get a contract.
And almost no business right now is eligible for that. But you work really hard, you get that done. There's going to be a lot of contracts left out on the table that you could actually pick up because you are CMMC certified.
It also gives you peace of mind. You're not going to lose sleep wondering if you're going to lose your contract and your reputation because you fail to comply. Now, with the CMMC levels, once you become NIST compliant with the 110 controls, and everybody has to do that before.
Before CMMS takes place, and we'll get into that a little bit further, but you are that much closer to being certified in all five CMMS maturity levels. So, taking just a few extra steps is actually going to give you that much more of a competitive advantage. So, who must comply with DFARS, NIST, and CMMS guidelines?
All entities who are in contact with CUI and/or CFI must be compliant. This includes storing, processing, transmitting, and/or creating data. It applies to any subcontractor that sells anything to a government supplier or wishes to do business with a government supplier or contractor in the future. It's not confined to manufacturers, and it also does not include commercial off-the-shelf items as long as there were no.
Modifications when sold to the government. Okay, now how do you know if you need to be compliant? First of all, you're going to get direct. You could possibly get direct notifications from the DoD. There's also contract stipulations, especially with CMMC. When you get your contract, it'll tell you what level you have to be in order to.
Even be eligible to win the contract. You can also ask your subcontractors or service providers. And it's really important to note that even if you're not notified that you need to be compliant, it does not excuse you from being compliant. Okay, so ignorance is not is not acceptable. Okay, so what will happen to my business if we are not compliant?
Well, there is no NIST certification, so NIST compliance, as we mentioned, has been an honor system. But if you're found out of compliance, it actually can cost you dearly. You can lose your contract. With the DfARS interim rule, you'll no longer be eligible for a contract if you haven't entered your information into the SPURS system, which we'll talk about also, and you have a positive DODAM score.
CMMC, it's a go/no-go. As I mentioned before, if you don't pass the CMMC audit, you will not be eligible for a contract. It also opens you up to fraud. So, if you lie about being compliant when you know that you aren't, you're breaking the law, and you can be held criminally and civilly responsible. There are actually several companies who have lost cases under the False Claims Act for lying about their compliance.
And there's also the breach of contract lawsuits. You can be sued for damages by your prime contractor or subcontractor for negligence if you fail to maintain a specific NIS code. All right, so let's talk about really getting real here. Why is the DoD?
Not paying their contractors for CNC compliance - it's a question a lot of people have asked. But the reason is because they already have. Every contractor that's a current that has a current contract has signed that contract, and it says that they are NIST DFARS compliant. The government has also already compensated you for such. So.
They've given you the money. They've paid for you to be compliant, so they expect you to be compliant. Now, previously, due to self-ass attestation, it seemed to be a little bit more of a wink, wink, nudge, nudge, as far as contractors getting away with not implementing the security controls. It's like, "Do you have this? Yeah, we have it, but you don't really."
It there haven't really been any repercussions from that anymore, but that's they're doing away with that. Now, will they help with any of the costs? Yes, they actually are. They don't want this to be completely cost prohibitive for small businesses. As of today, we don't know exactly how much they're going to be compensating contractors, but from what they've stated, you will be able to add.
To the contract, the additional cost of any extra security controls that are needed to get you from eight hundred one seventy one with the one hundred and ten security controls to CMMC maturity level three or more. So, for example, with CMMC maturity level three, it's a hundred and thirty security controls. So, whatever costs you incurred going from the one hundred and ten to the one hundred and thirty.
They will compensate you for that, but they don't. We don't necessarily know how much at this point. They also said they will compensate for the audit. Okay, so we talked about CMMC, DFARS, NIST. How those are all related? When those are all going to start? Especially with the CMMC.
So that was all going well until this past fall, the DOD introduced a interim rule, and we're going to take a look at that because there's a lot of confusion with that. Now, with CMMC rolling out this year, why the interim rule and why now? Well, hackers are not going to wait.
For contractors, subcontractors, or vendors to get their cybersecurity whipped into shape to start a cyber attack. In fact, they don't want you to be ready. They the less prepared you are, the better for them. Exfiltration of sensitive data by malicious actors around the globe is a threat to both national and economic security, and the DoD is working with the Defense Industrial Base DIB.
To enhance protection of controlled unclassified information along the supply chain. So let's take a look at the new rule. If CMMC certification is your driver's license on the information superhighway, then you can think of the new interim rule as your driver's permit. It has three new provisions: seven zero one nine.
Advises contractors that they must maintain and report their NIST 800-171 compliance and the Supplier Performance Risk System, or SPRS. It also explains the three types of assessments or audits that they will be now conducting: basic, medium, and high.
Seven seven zero two zero outlines requirements of contractors to provide the government access to its facilities if the DoD is renewing a contract or conducting a medium or high assessment. This just means that, so with the medium and high, they're actually going to visit your place of business to see that you are telling them what.
Or you're doing what you're telling them that they're doing that you're doing, and so this is requiring that you allow the government officials in. And then seven zero two one is a discussion of integrating Steam MC maturity levels one through five with the DFARS interim rule. All right, so let's take a look at the Spurs and DODM scores. Okay, so Spurs self assessment.
Effectively ends self-attestation of NIST SP 801-71. It will be included in all RFPs after December 1st, 2020, which, as we all know, has passed. It is not recommended that contractors wait. The DoD wanted all the subs and primes to self-assess by the due date. So, if you haven't done that, it's something you definitely need to start working on.
Now, the CMCC will take its place as it rolls out, but until then, you must complete the assessment. So, even if you don't think you're going to have maturity level three, you think you're only going to have to have maturity level one, you still have to implement these 110 security controls before CMCC, or you open yourself up to a lot of liability.
Okay, so for each of the one hundred and ten NIST eight hundred one seventy one security controls, you must submit two pieces of evidence to prove that you have, in fact, implemented the control. You must also provide a plan of action and milestone or POAM for each missing control.
Stating first of all how you're working towards correcting this issue, and also how you when you expect it to be completed. So I think it's important to note that for CMMC, you will not be allowed any POAMs. It's you have to have every single security control in place or you fail. With the interim rule, they're giving you a little bit more wiggle room. So if you don't have everything implemented yet, that's okay.
For the most part. All right. So, with this new system, the contractor will is directed to fill out the assessment, and then the contracting officer reviews the DOTAM scores before giving the award, and then it's a go or no go. So, if you have a negative score, you're not going to get your contract renewed.
Also, it's important to note that your DoDAM score is valid for three years, but you are allowed to update it as you implement new controls. All right, so what does this new interim rule have to do with you? Well, every contractor who works with the DoD is expected to have an assessment uploaded by December first, twenty twenty, because if you do not enter your self-assessment into SPURS.
You will not be rewarded any new contracts. Okay, that is really important to note. There's no exceptions to this, except for the commercial off the shelf. All right. Now, what happens if you don't enter this into Spurs? So, if you don't upload your assessment, it puts you at risk for loss of contract.
And then also potential fines and penalties under the False Claims Act, and also with the audits. As I mentioned, they're doing the high, medium, and low-level audits. So if you are found to be lying, you get into some real trouble. Again, note it does not matter which CMMC maturity level that you are expected to have in the future. Every DoD prime and sub must follow this new rule and implement NIST SP 800-171.
Security controls. If you would like to continue working with the DoD, all right. So the next question is, where do we go from here? These are going to be actionable steps that you can take. However, I do first want to clear up a few common misconceptions that we have heard. Now, one thing that we've heard is that only certain
NAICS codes have to follow the new DFARS interim rule. That is untrue. While there are certain codes that are going to be impacted more than others, if you are a contractor, you will not be awarded another contract unless you have your information entered into SPURS.
I've also heard people say that since they have Office 365 or some other type of software, that they're fine. But at a very minimum, you need Microsoft 365 GCC High DOD to pass an audit. It can take months and thousands of dollars to set this up. So it's it's very very secure. It's a lot more secure than just Office 365, which will not pass an audit.
We've also heard that you only have to have, or only maturity level three and higher, have to have a C3PAO audit, which is the third-party audit from CMMC. That's not true at all. Every single CMMC maturity level requires an audit before you can get your contract. Additionally, the level that you need to obtain will be in your contract. No CMMC is going to be a self-assessment.
That only applies to the interim rule. All right, we've also heard that if you do not touch CUI, the D FAR's interim rule does not apply to you. As I've gone over, that is false. It's just it's untrue, and it might even be the most harmful misconception that we've seen floating out there. If you listen to Katie Arrington, even if you only need maturity level one, you are still required per your current contract.
To be compliant. Now, by signing your current contract, you've already attested that you're following these guidelines, and you've already been paid to do so. So, if you're audited, you're opening yourself up to fines and penalties, and it's just not something that you can ignore anymore. All right, and then we've heard that no practitioners are CMMC A B certified. That might have been true a couple months ago, but.
The CMMCAB has begun certifying registered practitioners (RPs) as well as registered practitioner organizations. Last quarter, you don't need to choose a cybersecurity specialist who is a registered practitioner or working for an RPO, but it does make sense to choose someone who has been trained in CMMC because, as you can see, it's pretty complicated.
All right. So, where do you go from here? Well, really, the next step in your journey depends on you and your business, and where your business is currently. So, first of all, a good question to ask is: Do you have a system security plan or an SSP? If you do not have an SSP, even if you have all 110 controls,
In place, it doesn't matter. You have you'll have a negative score of two hundred and three. Now, if you do have a system security plan, what is your SPURS score? Your DODAM score, Petronella Technology Group can actually help raise your DODAM score as efficiently as possible. The next question to ask is: Do you have all seventeen policies and procedures, which one for each domain?
If you do, then it sounds like you're probably ready for the mini gap assessment. If you don't, then you probably want to start with the DFARS NIST policies and procedures pack. Now, if you don't have anything, meaning you have a negative score in place, and you want to move as quickly as possible, there's no need to buy a gap assessment now because you are not ready. We've seen that a lot where.
If a business, a contractor has nothing in place, you know, people will tell them to go ahead and get a GAP assessment. But you're not ready for that. You you need to have some things in place before a GAP assessment. Okay, so what we recommend is our policies as a good starting point. Our policies and procedures bundle, encrypted email and data solution, and then consulting. And we recommend consulting because it buys you blocks of time. It can be tailored to fit your needs.
So it's not something that's just a template for anybody. It can really help you and help answer the questions and things like that. So, at the end of all this work, when you no longer need poems and when you think that you're ready for a CMMC audit, that's the best time to conduct a gap assessment.
All right, and Craig has offered our participants of the webinar a discount. If you use the code free zero two two one, anything on the compliancearmor.com website that's under a hundred dollars can be free or is free for you. This includes our CMMC one-page checklist, which is also a good starting point.
The Ultimate Guide to CMMC, which is a book by Craig Petronella, and there are several guides on there, including guides with Deforest NIST CMMC and the Deforest interim rule. Okay, so that concludes that portion of the webinar.
If you guys have any questions, please feel free to ask. Also, we do have Craig here, so if you have technical questions that I may not have answers to, then he can answer those for you. Great job, Aaron.
Thanks. So, it looks like there's not too many questions right now. No questions. So everybody's got all this figured out. This is Todd Weed. I have a quick question. Yeah. Can you talk a little bit about your data and email encryption solution? Yes, we can do that. Craig, do you want to tell him about that? Yeah, sure. So.
We have we ourselves. We use what's called an end-to-end encrypted email data storage solution that bolts on top of Microsoft Office three hundred and sixty five commercial or Google or really most email applications. It's a solution made by a company called Preval, which we have.
Chosen to work with because it's cheaper than the Microsoft GCC High from DOD, which is offered by only about six or seven authorized resellers in the country. That actually is three times the cost of commercial Microsoft Office 365. So we chose the PreVeil solution, and then we added on top of that solution our security control layers.
And it's just really easy to use. Doesn't need any passwords to remember. Nobody can get tricked by a phishing email. And it's also ITAR compliant. Well, does that work with like your data exchange between compliant environments? For example, from a commercial environment to a DoD environment. So.
You you have a couple choices. So if you're a sub to a prime, the prime most likely has a solution in place, and they may want to use their solution. But you can, with this solution, you can invite them into the ecosystem. So after you secure licenses, you can invite people outside of the organization to become.
A part of the encrypted channel, but in the relationship of a prime and a smaller sub, typically the prime already has a solution in place that they may want you to use theirs. But obviously, when in doubt, you would use your own. It just depends on the certain situation. There's also other methods that they may want to choose to communicate with. Understood. Thanks.
Sure. Well, Craig, is there anything that you would like to go over or reiterate from the webinar? I was just going to add on the solution for end-to-end encrypted email and secure data. That's one of the largest gaps that we find that most companies don't have a good solution for.
Which is why we chose the the PreVeil solution, and then worked with them, and together have helped accelerate the cadence of getting folks compliant and filling that gap with our consulting and our policies and layers that we've added. We've been able to bring companies from that minus two hundred three, all the way up to a positive sixty five very rapidly.
So a lot of folks fall into that area, so that's a good a good spot for you know filling that gap for a lot of people. Okay, that makes sense. Anybody else? All right.
Well, that will conclude our webinar. If you have any additional questions, you can go to our website or email myself, Erin at petroliotech.com, or Craig. And thank you for joining. Any last words, Craig?
No, I think that's it. I think you know, folks. Obviously, take advantage of the special offer that we posted there. We thank you for joining the webinar, and if you know anybody that could benefit from this factual information, please pass this link around. Be sure to sign up for our newsletter on our website at petronella tech dot com.
I'll also put that in a link there on our YouTube channel, where where you can follow us as well, and other you know LinkedIn and other social channels as well. We're very active on LinkedIn. That's probably the most active social channel that we use because most of our clients are B two B. But yeah, be sure to stay tuned. You know, we'll we'll be updating this regularly as new information is released from the DoD.
And we hope you you found value in this. And I think Aaron, you did a great job. And take advantage of of the offer. Go to complianceharmer dot com and get started today. All right. Don't wait. Thank you guys so much. Thank you. Bye.
Thanks for listening to yet another episode of Cybersecurity and Compliance with Craig Petronella. Listen to all of our podcasts on Apple, Google, and Spotify. Visit us online at petronellatech dot com to book a meeting with Craig about your business. That's a wrap on this episode of Encrypted Ambition. Subscribe wherever you listen, and if today's guest inspired you,
Leave us a review or share the show with someone in your circle. To learn more about how we support innovators with AI, cybersecurity, and compliance, head to petronella.tech.com. Thanks for listening, and remember: the future favors the bold.
Never miss an episode
New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.