We are seven years into this CMMC mess and the confusion is still rampant. The problem is that the CMMC folks thought they understood everything and then “winged it” while ignoring the decades of prior certification and accreditation rules that they now have to comply with. When guys like me came in to correct them, we were tossed out on our assess while uninformed “Town Criers” sucked up all the airtime.

Recently, a C3PAO rep — and I’m not gonna name the guy because I think he’s trying to do the right thing — thought he’d tackle the issue of CMMC costs by suggesting a radical idea: a $20,000 flat rate CMMC assessment fee for everyone, with the only additional fees being for travel. It sounds great on paper, and people are loving it.

But it can’t happen, and once again it’s my job to rain on everyone’s parade.

Now, remember, this guy’s heart was in the right place. He just doesn’t know the basics (which is scary, since he’s running a C3PAO.)

I asked him a simple question that should have put the matter to rest. I asked him if he would perform the $20,000 flat rate assessment for a 10-employee machine shop and then again for a 10,000-employee company like Raytheon.

I thought that would end it. It didn’t. He said, “yes.”

Again, he just doesn’t know what he doesn’t know.

Let’s play this out. A CMMC assessment has to verify the controls defined in the NIST 800-171 document. There are 110 controls broken into 14 families. (I am ignoring the Rev 3 version for now.) Those controls include things like “Access Control,” “Awareness and Training,” and “Maintenance.”

Next, understand that a CMMC assessment requires three types of evidence gathering:

  • Interview – talking with folks to verify implementation of the controls through verbal testimony
  • Examine – reviewing records to verify the controls
  • Test – literally testing the controls through penetration testing, phishing tests, etc.

As I spoke about here, no C3PAO will ever use “Test” because they are not qualified for it, and we are all just ignoring that part. So essentially that only leaves Interview and Examine.

Now imagine the C3PAO is assessing that 10-man machine shop. Using Interview, they will sample a handful of employees — maybe five? — and obtain evidence. Then, they will use Examine to verify records of various systems and controls. To do that, they might walk through a single building and/or check a single enclave. Easy-peasey.

Now what about that 10,000-employee gargantua? Here, the C3PAO has to increase its sampling. It cannot simply interview five people out of 10,000. The sample rate is wildly off-kilter. (That would be 50% of the staff for the machine shop, and only 0.05% of the staff for the gargantua.) That is not anywhere near fair and, of course, the giants are the main targets of hacks, not the tiny machine shops. So the machine shops would get far more comprehensive assessments than the actual targets of hackers.

And now you have very bad national security.

No, instead, the C3PAO would have to interview hundreds of employees and examine thousands of records, examine multiple systems, see how various enclaves interact with each other and how the system interacts with the gargantua’s ERP system, its HR system, its learning management system (LMS), its security systems and more. The assessment team would need to look at dozens of facilities, perhaps scattered all over the world.

To do this, the C3PAO needs to bring a far larger assessment team and perform the assessment over a far longer period of time.  Perhaps the machine shop can be assessed by the minimum team of three people over a week or two. The gargantua? A team of 25 assessors working for a month.

Think it’s crazy? Ask an aerospace auditor. Right now, a guy I know is doing a full month of auditing at a single Boeing site, alongside his teammates, and that’s for AS9100… not exactly national security-level stuff.

Now you see how the gargantua cannot be assessed at a flat rate of $20,000.

These “flat rate” audit scams are common in India, where they just get a bank deposit and issue a fake cert without any audit. That can’t be done under CMMC. Unless the CMMC scheme is just an Indian-style scam after all, but one run by white people near the Beltway?

So, dude, I know you meant well. I know you were trying to crack the case on CMMC costs. But your idea is not going to work. The problem is that as a C3PAO, you should know this. To already be issuing Level 2 CMMC certs and not realize that an assessment of Raytheon is going to take more people and time than Joe’s Machine Shop is… well, incredible.

But it’s on brand for CMMC.

Advertisements

Free ISO 9001 Template Kit