Listen to this episode

CMMC, DFARS and NIST 800-171 Webinar and Podcast: The DOD is done playing around!

0:0036:27

Recorded March 2021. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.

The episode in brief

What this episode covers

In this webinar style episode, Erin, one of Petronella Technology Group's six certified registered practitioners, explains the origins of NIST, DFARS, and CMMC and how they fit together for Department of Defense contractors. She describes how DFARS 252.204-7012 directs contractors to NIST SP 800-171 for protecting controlled unclassified information, and argues that self-attestation has failed, citing an assessment in which no company was fully compliant.

At the time of recording, she says CMMC requirements were starting to appear in RFPs, with all contractors expected to hold certification by 2025. The episode covers the interim rule that, at the time of recording, required SPRS self-assessments and DoDAM scores, along with basic, medium, and high audits and penalties including False Claims Act cases. Erin debunks common misconceptions, recommends starting with a system security plan, policies, and consulting, and shares a discount code for resources on compliancearmor.com. Craig Petronella describes an end-to-end encrypted email and data solution built on Preval, and attendee Todd Weed asks how it handles exchanges between commercial and DoD environments.

Worth remembering

Key takeaways

  1. Complete the SPRS self-assessment of NIST SP 800-171; at the time of recording, contractors without an entry would not be awarded new DoD contracts.
    “if you do not enter your self-assessment into SPURS. You will not be rewarded any new contracts.”
  2. Erin explains that, at the time of recording, lacking a system security plan left even a company with all 110 controls with a negative score.
    “If you do not have an SSP, even if you have all 110 controls, In place, it doesn't matter.”
  3. Erin stresses that, at the time of recording, CMMC audits allowed no POAMs, so every security control had to be in place to pass.
    “for CMMC, you will not be allowed any POAMs. It's you have to have every single security control in place or you fail.”
  4. Erin says plain Office 365 will not pass an audit; at the time of recording she called Microsoft 365 GCC High DoD the minimum.
    “at a very minimum, you need Microsoft 365 GCC High DOD to pass an audit.”
  5. Erin argues that certification delivers a competitive advantage, since almost no business is currently eligible for contracts requiring CMMC certification.
    “once you've put in the time, energy, and money it requires to get compliant and certified, you actually gain a competitive advantage over other businesses who are not certified.”
  6. Erin warns against the harmful misconception that the DFARS interim rule did not, at the time of recording, apply to companies that never touch CUI.
    “if you do not touch CUI, the D FAR's interim rule does not apply to you.”
  7. Craig recommends an end-to-end encrypted email and data storage solution that bolts onto commercial Microsoft 365 because GCC High costs three times as much.
    “We use what's called an end-to-end encrypted email data storage solution that bolts on top of Microsoft Office three hundred and sixty five commercial or Google or really most email applications.”

The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.

From the show notes

About this episode

| Get the latest facts on the CMMC, DFARS and NIST 800-171 from CMMC-AB Certified RPO Petronellatech.com - Listen to CMMC-AB RP Erin Dotsey and CMMC-AB RP Craig Petronella discuss CMMC, DFARS 252.204-7012 - Watch the recording on our youtube channel at - Please be sure to hit the subscribe button to stay updated! The DOD is done playing around. Get compliant with CMMC, DFARS and NIST 800-171 with products at

Full text

Episode transcript

Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.

Encrypted Ambition

Never miss an episode

New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.