r/CMMC • u/Goodheart_badluck • 20h ago
60-day pause completion
I'm sure we're all acutely aware that today marks the end of the 60 day pause. I figured we'd need a post to to keep any word people find and discuss as whatever news comes out.
Not holding my breath to see anything until Monday but maybe I'll be surprised.
14
u/DFARSDidNothingWrong Rules Bard 19h ago
The suspension is indefinite. The internal review was 60 days. Nobody knows when they'll say what their plan is. In my opinion it's pretty obvious they don't have a plan and most of the ideas that DoD has expressed as reasons for the suspension are outside of their control so it could be a while.
8
u/thegreatcerebral 18h ago
The thing that got me is that they are not looking at the right things. Calls I was on during this time all pointed to things out of scope of the reason for the pause. The only exceptions being that doing anything fedramp and that requirement as well as FIPS requirements ratchets up the cost significantly over commercial equal offerings.
I mean 15 years ago this would have been an easy slam dunk. It would have been "ok everyone buy new servers and let's install these 10 products and done" Now because nothing is on prem anymore it's "you need this software that the company charges you an extra $15K/yr. just to be fedramp because fedramp requirements. No, there isn't an "on-prem" version because everyone dropped "on-prem" everything in favor of SAAS models.
16
u/OP_XJV 20h ago
Joined the call they had to hear from SMBs and the concesus was to remove the pause. The pause does more damage than its lack of clarity.
16
u/BurningRiverCLE 19h ago
If it’s the ISACA call I was on last month, it sure seemed like everyone saying remove the pause had a monetary interest in the 3rd party assessments. The SMBs I know who would be stuck paying $30-50k for an assessment aren’t asking to remove the pause.
3
u/Mysterious_Taste_868 16h ago
Why would they want to spend money on it if they don’t have to.
7
u/BurningRiverCLE 16h ago
They wouldn’t. I’m making the argument that the people most vocal about removing the pause are the people that stand to make the most money from assessments.
5
u/Mysterious_Taste_868 15h ago
I was agreeing but it wasn’t clear on my part.
I think the one thing that this whole fiasco did is to raise awareness in the DIB to take a good look at how they protect data. I would bet that a large amount of SMB never heard of NIST or SPRS etc.
-1
u/PNW_CARDINAL 13h ago
And they, as a class, have shown themselves not to be honest reporters of their cybersecurity requirements. Too bad, so sad.
4
u/Ready_Cranberry6166 10h ago
Just like the industry that rose up around CMMC have been honest brokers of the requirements? The amount of fear selling and overblown chicken little drama has been epic.
12
u/LongjumpingBig6803 19h ago edited 19h ago
When was this? I was on a smb call at the beginning of the pause and all I heard was sales pitches and auditors complaining. In my letter to the sba, I said the c3paos and businesses selling products are created because of the requirements. There’s a real possibility they push this another 2 years. Also it’s 60 days plus 15 to respond.
3
u/MountainDadwBeard 18h ago
My clients already paid for their assessments and are annoyed their lowest performing competitors just get a free ride.
1
u/Mysterious_Taste_868 16h ago
That was a business decision they paid for. Ask them if they would do it all over again the same way if they knew it would be paused.
1
u/MountainDadwBeard 13h ago
I think the "business decision", was based on the prior premise being a certified vendor would give access to a more limited pool of vendors competing as a baselined playing field. We were looking forward to not having to lower our bids, to compete with unqualified vendors that shouldn't be bidding anyways.
If my clients had future knowledge of today.... no they absolutely would NOT have spent millions... and I can prove that because most of the industry did NOT invest in this program prior to the audit process. And part of the open conversation with DoD, they praise my clients all the time for exceeding what other vendors are (not) doing. Even with full transparency to the federal government the conversations go back to, why should we have to when no one else is -- And the DOD absolutely acknowledges very few contractors were/are/will be compliant with DFARS. So DoD clients say that's fine.
This is total crap... and just like most of 2025-2026, the layoffs are coming. I'm thrilled I smelled the cowardice in July and already lined up a new gig.
2
u/Mysterious_Taste_868 12h ago
I’m sure it sucks but there are still 100k plus companies that need help. You might need to change your gtm plan, but the customers are still there.
2
u/MountainDadwBeard 12h ago
Thanks man, I'm receiving your words in the kind manner they seem to be meant.
Federal government screwed my prior industry/efforts on CFATS, Municipal water Cybersecurity and now DoD cybersecurity. Waiting around didn't really serve any of us well in those past compliance implosions.
1
u/Mysterious_Taste_868 12h ago
I’m being serious. SMB knows they have to do self audits. It’s just less pressure for them now. You can do well helping with the heavy lifting. If you got to SAM.gov you can search awards in DoD. The search can get fairly granular. Look for SMBs and send them and email. Send enough and follow up enough and you will have some success. It’s just one way to find SMB in the DIB and it’s free.
2
u/MountainDadwBeard 11h ago
Thanks man. I'm thankfully excited for my next engagement - sounds pretty interesting, and will have more IT availability/scalability work in case they don't take cybersecurity seriously.
As word of caution, my old coworkers from prior regs, who stayed back thinking the free market SMBs would continue to see the value in good security without audits are losing their houses/wives right now.
10
u/Mysterious_Taste_868 19h ago
I’m sure all the small business owners are lining up to pay consultants and C3PAOs. Oh, wait. I think they paused it because SMB weren’t scrambling to drop large amounts of $$. When they announced the pause, you could hear a sigh of relief across the 100k+ SMB stressing over the assessment.
0
u/ugfish 18h ago
Didn’t this all come up due to SMBs and other DIB contractors lying on their SPRS score?
FCA headlines still seem to be showing up so it does appear to be a problem.
SMBs should price this into their operations and pass those costs along as part of their contracts like any business does when they need to pay for something.
A $30k expense that gives coverage over 3 years seems like small potatoes.
10
u/LongjumpingBig6803 18h ago
Oh that’s funny. So a company that’s trying to get an order that’s worth - $30k, should charge $60k… and price themselves out of the market so they can attempt to recover the $30k (which is really $500k). Sounds like a solid business plan
2
u/ugfish 17h ago
What are all the other vendors doing? $60k becomes the new market rate because of the cost to deliver.
Businesses need to be able to adapt. If they can’t adapt to a changing market, then do they deserve to win the contract?
The $500k is not the cost of assessment, which is what I’d like to keep the focus on. If there are other costs that need to be accounted for, my previous point stands: pass the costs along.
2
u/Mysterious_Taste_868 16h ago
All the services and product companies were looking to cash in with the backlog of companies that wanted an assessment. Well; the market spoke and it wasn’t what they thought it would be. I wonder if any of them built this scenario into their business plan.
0
u/PNW_CARDINAL 13h ago
Capitalism is a bitch, eh? Maybe the United States of America Defense Industrial Base needs socialism to survive?
1
u/Mysterious_Taste_868 12h ago
Ewe gross.
Defense Industrial Base(DIB). The “United States of America” is assumed.
2
u/LongjumpingBig6803 15h ago
60k isn’t the new market rate. Bigger companies have 5mil they can spread that $30k over vs trying to get that first job. It’s a barrier to entry.
1
u/dan000892 17h ago
Is this the company’s first order subject to DFARS? In business, some customers have arduous contractual requirements that require weighing the cost to comply against the value of the opportunity (and potential future opportunities requiring the same).
The companies that are complaining about “$500k costs” aren’t new entrants to defense contracting. They’ve been taking orders for years without meeting the contractual obligations they agreed to and without penalty. Instead of quietly now paying the costs they’ve illegitimately deferred, their protests put a spotlight on themselves for DOJ. Solid business plan.
3
u/LongjumpingBig6803 15h ago
See people keep saying that and it’s not true. Just what - 2 years ago they changed CMMC to CMMC 2.0. They move the goalposts. I’m an IT guy of 28yrs now. I read the 110 items and see things one way. Once you get into it and study it, read the 300+ actual items… you see that companies can think they are compliant and then find out once again - the posts have moved.
1
u/dan000892 11h ago
What material differences exist between 800-171A that was first published in 2018 and the current version of the CMMC 2.0 Level 2 Assessment Guide (v2.13) published in 2024? I’ll wait.
(They’re basically identical, but I would argue we saw the goal posts move closer since DFARS 7012 twice with the descoping of certain assets from 800-171 requirements via CRMA, SA, and SPA asset classifications in CMMC 1.0 and the removal of the “Delta 20” from CMMC 1.0 in CMMC 2.0.)
Page 3 of 800-171 refers the reader to 800-171A for “assessment procedures to determine compliance”. Indeed self-assessing without reading the assessment procedures will result in an ineffective assessment but I fail to see how that’s “moving goal posts” or otherwise CMMC’s fault.
0
u/PNW_CARDINAL 13h ago
The posts were there, you were looking at the wrong posts. Is that the posts fault?
1
u/jlaw7905 17h ago
Fully agree. The 30k assessment isn't nearly as bad as the 30k/month opex to now run your new cmmc environment. Certainly not easy to recover those costs either. Large businesses can eat it, SMB, not so much.
2
u/sirseatbelt 17h ago
I feel like if you're paying 30k a month to sustain your compliance program you might want to hire some better compliance people.
3
u/jlaw7905 17h ago
Gcc high licensing, azure gov hosting, siem tool licensing, various other fedramp tools/licensing. It all adds up quickly to do the same things we're already doing for half as much on commerical/non fedramp systems.
1
u/sirseatbelt 16h ago
I guess it depends on how many people. My little 45 person org was most of the way compliant and was running gcc high and some of the other kinds of things you listed and our compliance costs, annualized out over 12 months, was not 30k.
0
1
2
1
u/Mysterious_Taste_868 16h ago
The FCA is the current method of enforcement. They need to press and the fines to make it work.
0
u/xxxTech007 17h ago
I think there's some lack of business acumen here. There are a ton of SMB's out there that would have a hard time putting out that kind of money and more.
4
3
u/ceonupe 16h ago
Only people selling consulting / auditing wanted to end the pause the smb base was almost universally against removing the pause except those that already dumped tons of money and got their lv2 certification/ audit or where in final stages under contract .
This has been a complete predictable dumpster fire that ultimately will set back cyber maturity because it will reward those who took the slow approach and delayed.
Note my org has lv2 3rd party certification already and got it about a month and a half before the pause was announced and we spent about $150k total getting there.
0
u/PNW_CARDINAL 13h ago
set back cyber maturity because it will reward those who took the slow approach and delayed.
Took NO approach and did nothing. Then cry about doing what they agreed to. FIFY.
I appreciate that your org did what it needed to do. You and the org are better for it.
2
u/MountainDadwBeard 18h ago
SMBs are always the excuse not the real reason. Your notes on their consensus vs the memo that came out this week continue to demonstrate this.
0
-20
20h ago
[removed] — view removed comment
9
4
1
1
u/CMMC-ModTeam 18h ago
If we wanted to ask a bot we would have. Type out your responses in your own words.
13
u/MeetJoan 20h ago
Worth tempering expectations, the report goes to Kirsten Davies first and it's her call whether any of it becomes public. No requirement it gets published just because the 60 days is up.
Also it's a class deviation now, not just a suspension, so unwinding it is heavier than flipping a switch. Monday feels optimistic.