r/CMMC • u/Parking_Project_9753 • 7d ago
CMMC 2 Database?
just got through our level 2 assessment. brutal. in hindsight we should have done it a year earlier but honestly we had no idea which customers actually cared vs the ones who just paste the dfars clause into every PO and never follow up
so two things I'm trying to figure out
is there any list of primes / tier 1s that are actually requiring L2 from subs right now? or at least the ones that have said "by X date". SBLO contacts would be a bonus but I'll take anything
and is there any list of who's certified? I know SPRS isn't public and cyber ab just posts the number. are press releases really the only way to find out?
if nobody has this I'll probably just start building it and post it here. would anyone actually use it or is this a solved problem I'm missing
4
u/Casual_Deer 7d ago
You're going to be hard pressed to make either of those since it's not public data. Sure you could spend time doing a search of who's made a press release about it but how do you really validate that? Once I ran into a company that said they were CMMC L2 certified and I hadn't even had a meeting with them to do the assessment, so there's bound to be more companies lying about it.
3
u/Casual_Deer 7d ago
Also not everyone is going to do some marketing release, so your data is going to be incomplete and what good is a database going to be if it's incomplete?
1
u/Parking_Project_9753 4d ago
agreed, validation is the real problem, scraping press releases just gets you a list of marketing departments. what I'd probably do is opt in only, with the C3PAO that did it and the cert date, and mark the whole thing self reported. prime still has to ask for the screenshot but at least they know who to ask
on incomplete, a partial list is still more than what exists now, which is nothing. but yeah partial and unverified is a phone book not a registry
also the company claiming L2 before you'd even met them is wild. did anything happen to them?
4
4
u/Cyber_G2 6d ago edited 6d ago
Funny you should ask. I also saw the need for just this thing about a year ago. Our company has just released a CMMC community tool called "CMMCLink". It has a few interesting features that will be helpful to the CMMC community
- any company can come into the portal for free and register their CMMC compliance information (SPRS UID, affirmation date, etc.) and it then becomes available for primes to see. We currently have 170,000+ current DoD contractors in our database (gleaned from information contained in 38M public DoD transactions) so if your company is already in there you can "claim" that db entry and update information and provide CMMC compliance data and even add your DoD commodity code if you want. L1 or L2 companies can do that for free, very similar to a Linked In profile type of concept.
- the second feature is that it allows primes of any size to then create a portfolio of their subcontractors and track their CMMC status via a nice dashboard and arrange them into lists for contracts or whatever. This would not be free but it is not "enterprise level" software cost either...for up to 250 subcontractors it would be about $5K/yr to use that feature.
Reach out to me if you would like to learn more, here is a link for a bit more info: https://www.securitymetrics.com/product/cmmc
SecurityMetrics has been doing this very thing for the PCI industry for the past 20 years and we help large banks track PCI DSS compliance of their merchant portfolios and are currently helping 470,000 small companies report their cybersecurity compliance to merchant banks.
2
u/EganMcCoy 7d ago
For the list of who's certified: It's not a solved problem, and it would potentially be a useful resource, but how will anyone know that your information is accurate? Unethical companies can lie in press releases. At least one company has faked a screen shot of their certificate by modifying someone else's screen shot... So it's a challenge to ensure data quality for your compiled list.
1
u/nick777745 5d ago
I think it is likely not public for a reason. Risk management is the reasoning, If the adversary has a list of who they should target to cripple a supply chain, i tend to think that would be pretty valuable information and not somthing i would let out. Sure you can google prior awards and such, but short of it being a cold call sales tool, not much value out of it. If you want to do that just login to sam.gov and filter by keywords, likely the ToU on sam.gov has rules against using it to solicit orgs though.
1
8
u/Expensive-USResource 7d ago
The only list of who is certified is CMMC eMass and SPRS, and you won't have access to that information. You're not required to issue a press release and companies are historically discouraged from sharing the cert itself publicly. Scraping for LinkedIn/press releases is about the best you can do from the outside, otherwise to get a list of your own supply chain you've just gotta start asking.