I make a lot of jokes and post snark her eon the site, but I want to be deadly serious for this one. I am gravely concerned that the recent rug-pull by Dept. of War re: CMMC certification could result in risk of self-harm or suicide by those who have spent their savings to obtain the credentials needed to perform CMMC C3PAO assessments.

The costs to pursue the assessor credentials was high, and then required significant effort and time that went entirely unpaid. Some left their previous careers or training path to pursue CMMC assessment work based on false promises by grifters like Katie Arrington, Stacy Bostjanick, and the host of overnight CMMC “influencers” and Cyber AB Board Members who have been lying to the industry for years.

Now, as predicted, the bill comes due. The DoW was tolled the plan to require third-party CMMC assessments for two months, but is expected to drip it entirely, citing the costs to small business. That will leave both the C3PAOs and their entire auditor pools without any work. For those affected, it can mean the loss of their entire planned revenue stream and even career. The risks of self-harm or suicide from that loss are real.

Per the Cyber AB’s Marketplace, there are currently 1.061 CMMC Certified Assessors (CCA) and 618 Lead CMMC Certified Assessors (LCCAs), although many of the LCCAs also hold simultaneous CCA status. This means that just over 1,000 individuals are affected.

Those seeking emotional support in the USA are urged to dial 988 for help.

To offer a solution. Oxebridge is coordinating with a major accredited training organization to offer free transition “crosswalk” training so that CMMC Assessors holding either may transition to become an ISO 27001 Lead Auditor instead. With that credential in hand, the auditors would be qualified to apply for work with the established network of ISO 27001 Certification Bodies.

There is a shortage right now of ISO 27001 auditors, so this solves two problems at once.

As that deal progresses, I will keep you posted. Keep in mind, Oxebridge makes nothing off of this. We don’t do cybersecurity consulting and pass on all ISO 27001 consulting to our partners. We are doing this only out of a legitimate concern for the crisis created by this sudden rug-pull.

Yes, for years I was telling people this was a grift. But that doesn’t mean those duped by the grift don’t deserve help now that they are discovering they were victimized.

So don’t panic! Help is on the way.

Advertisements

Aerospace Exports Inc