Transcript
In this episode of Beyond the Horizon, enable head security nerd Lewis Pope is joined by Mark Pardee, president of Prescott, to take a deep dive into CMMC. Part of the reason this is so important is it pushes a standard framework across all federal agencies. Now we're starting with the DOD, so this doesn't apply to any of the other agencies yet, but it pushes the standard framework to protect what eventually became known as controlled unclassified information. Welcome everybody to this episode of Beyond the Horizon. I'm Lewis Pope, one of the head nerds at enable focused on security. Today we have with us Mark Pardee from Prescott. They are our partner in our journey on CMMC, and we're going to be having a conversation today about CMMC. We're going to be getting pretty deep into it. So Mark, welcome to Beyond the Horizon. Yeah, thank you. Glad to be here. I'm Mark Pardee, president of Prescott, and we are a RPO, a registered practitioner organization. We'll get into more of that later, but we help MSPs get ready for CMMC, the Cybersecurity Maturity Model Certification, and we work with their clients as well to help their clients get ready, kind of working with them in partnership. And CMMC is a hot topic in the MSP channel at the moment, but not even the MSP channel. Really anywhere that it kind of reaches out to, which can be a very, very broad set of businesses that you may not expect would be included in scope of it. So let's get everybody up to speed real quick. What is CMMC in the first place? And I think we should also kind of, while we're doing that, kind of talking about why we have it and where it kind of came from in the first place. Yeah. So we'll go back and start with this 15-year long journey so far. In 2010, President Obama signed an executive order that said the federal government shares information with all of these different contractors across all the agencies. And some of that information, while it's not secret or top secret or classified, they want to control it. They don't want it disseminated out to just anybody. And these include things, especially when it comes to Department of Defense and aerospace, it's things like drawings of weapons and planes, tanks, those types of things. So obviously, we don't want those out to our adversarial nation states, other ones. And they saw an increasing attack from nation states, whether it was Russia, China, North Korea, even Israel, with different malware that even 15 years ago was attacking. And it's a lot easier to, part of the reason this is so important is it pushes a standard framework across all federal agencies. Now, we're starting with the DOD, so this doesn't apply to any of the other agencies yet. But it pushes the standard framework to protect what eventually became known as controlled and classified information, this information that's not secret, but the government wants to protect it. And that's kind of how we got to where we are today. The other federal agencies are going to come into scope, but it could be another two years, five years. We'll have to see. This isn't moving very rapidly, as you can tell. And that it has not been moving very rapidly. That's something I do want to spend just like one minute kind of getting into of the mindset that has put a lot of people in that have known about CMMC for a while, but haven't dug into it. But now all of a sudden, everybody is saying, well, no, there's an actual deadline associated with it. So do you feel like that has caught some people on the back foot? Yeah, absolutely. We still hear it all the time. Well, the DOD is not really going to do this. They shot themselves in the foot, unfortunately, because 2017, December 31st of 2017, every contract with the DOD that's been signed since then, that contains either federal contract information or control, unclassified information, is when you sign that contract, you're affirming that you meet NIS 800-171. In 2019, there was a meeting with Kitty Arrington, who was at the time the CISO for the Undersecretary of Defense. And she asked, all these companies are saying they're doing this, are they doing it? And basically all the industry experts said, no, they're not doing it. So later that year, she announced CMMC version one. They pushed it out, started with assessments right away. They got so much pushback from the industry that they pulled it, said, okay, we're going back to self-assessments. So that was one flip. And then a few months later in 2020, they flipped again, introduced CMMC 2.0, and said, now we're going to have assessments again. But they simplified the program. We'll talk about the different layers later on, but they simplified it. But this back and forth has been unsettling. And then the other really big thing is once they announced 2.0, they had to go into formal rulemaking. And once they were in formal rulemaking, the rulemaking laws or regulations forbid them to say anything about it. And while they said it could be 18 to 24 months, it ended up being almost four years in rulemaking. But it finally came out. It was published last October 15th. It went live December 16th for the actual CMMC rule. So that's now in effect. And we are the assessing companies, the auditing companies, since the beginning of January have been doing formal CMMC audits. And companies are either passing and getting their certificates, or they're not passing and not getting them. And there's a fairly high percentage that aren't passing. But it's going to happen. We're waiting on one more thing to really make it formal, and that's what's called CFR 48, Code of Federal Regulations, number 48, which is the contract clause that technically allows the DOD to put the requirement for CMMC and the certifications in the contracts. There's at least some of them right now that that's not stopping them. They're starting to put it in contracts already. But officially, they can't start doing that until that final rule is published. And that's been something that I've seen myself a few times over the past few years is there wasn't the explicit you must, but there was variations of are you implementing, are you working towards a language that I've seen here and there too, because like you said, there weren't teeth, but we're coming up to teeth soon. So there's the question of, well, in the grander scope of, well, why does this matter specifically for, well, who we're usually going to be talking to, MSP. So for the MSP that just everybody to the same level of understanding that's listening, what does it represent for MSPs as an opportunity slash challenge? Sure, that's a great question. And I'm going to back up just a little bit as to why it matters, because the mission of this is really important. We are trying to protect our warfighters. This information, when you look at the F-35, China put out an identical aircraft almost as quickly as we did. If you look at the drones, the ships, the aircraft, ground vehicles, they have identical vehicles to ours, and they've done that by sealing our designs. And it's a whole lot easier for them to seal the designs from Joe's machine shop than it is from Raytheon or from Northrop Grumman or one of the primes, because they have a lot of resources to do good cybersecurity. Not that they still can't get in sometimes, but it's much easier for them to go after those same drawings that are passed down to these small contractors. And that's where the DoD is very serious about getting these smaller contractors all the way through the supply chain to protect this data. So how that really, why it matters to the MSP is because when you look at NIST 800-171, especially when you look at 171A, the assessment guide, there's 320 assessment objectives. And if you're an MSP providing a full stack of cybersecurity tools and services, you're responsible at least partially, if not completely, for about 50% to 60% of those controls. So if you don't do what you need to do to document, to have those controls in place with policies and procedures, train your staff, and collect the evidence showing you're doing that, unfortunately, you'll be the reason your client fails their assessment. Because when they have their assessment, you're going to have to sit in and show how you meet the controls that you're saying you're responsible for or even partially responsible for. And that is the biggest challenge for a lot of MSPs that I've been talking to is that initial, well, it's not even the hurdle for CMMC, it's the hurdle of compliance in general. You're dealing with clients you've been supporting for five years, 10 years, 15 years, that you may have had a passing conversation with them about higher-end security controls or your better security packages, and they brushed it off. And now coming up with something that's going to mandate they must do these things, but you've got no practice in it. You've got no practice in actually setting up proper controls, monitoring those controls, having the ability to audit those controls, having your documentation of SSPs, system security plan. And that's one of the chunkier things, isn't it, to fill out? Yeah, for the client, if their system security plan isn't hundreds of pages, it's not enough. Because they have to detail how they meet all 320 assessment objectives. So you take that, and even if it's a quarter of a page each or half a page each, you're over 150, 200 pages already. And a lot of them take more than that to really detail how you meet that assessment objective. So that's a big burden. It's actually, to get compliant, it's about 70%, 80% documentation. Because not only do you have to have an SSP, you have to have change management, risk management, all of these other things. You have to have policies, and you have to have documented procedures of how you implement and how you train your staff. You have to have training records for your staff. So it's a lot. And it gets overwhelming really quick if you don't have somebody that sees the big picture. I want to go back to one of the things you said is it's not a checkbox exercise. You get it done, and it's done. It is implementing a compliance program. So once you've done this or started to do it, what we recommend is when you start making your changes, like configuration changes, firewall changes and stuff to meet the controls, make sure you're raising change requests, you're documenting approvals, you're doing a risk assessment on those, because that all becomes evidence that you actually are implementing and have a mature cybersecurity compliance program. Right. And that is a scary word for a lot of MSPs, evidence. That's connotations of, oh, wait, I'm on the line here. I'm attesting to something. I'm saying something was done, and I need to have my CYAs in place to be able to prove that, not only for your client who may be assisting with it, but also for yourself. So there, of course, this represents opportunity for MSPs, tons of challenges, but opportunities as well. For me, I've always kind of seen, well, there's kind of two broad paths. Either you go through a lot of work and you yourself become CMMC2 assessed and certified by a C3PAO, which is a big endeavor, or you include yourself on the scope, within the scope of your client's pursuit. And, you know, being included in your client's scope is definitely a lot easier, because it's only going to be limited to, well, what are you doing inside of their environment and what you're doing for them there, and not you as a whole entire business entity. Is that a, you know, how do you go about, you know, sitting down with someone and telling them, you know, either this is a good idea for you to pursue this path or this is a good idea for you to go this way? Yeah, that's, it's a big question we get asked all the time. A lot of the smaller, even to the lower end of the mid-tier MSPs, we finally only have one or two defense contractor clients that right now are going to be in scope for this. And it depends on how their staff is and what, you know, what kind of security stack they have, what type of clauses they have in their MSSA, their Master Services Agreement, and how mature they are. Now, one of the things I always say is MSPs that go down this road will become better, because you will have documented procedures, documented policies. You will have to train your staff to follow those. You have to do things the same way every time as far as documenting and collecting that evidence. And it just makes you more consistent in how you approach things and staying on top of it. Because like you said, if there is a lapse, if there is a lapse, if the control doesn't work, you need to raise a POAM, a plan of action milestone, you need to document that it happened and what happened, you have to have incident response, and then you have to fix it, of course, and make sure it's not going to happen in the future, and that's all part of the idea of a maturity model, that you have to be getting better all the time at it, so the client has to be recertified every three years, if you're going with the I'll support them type of approach, you have to create a customer responsibility matrix, so you list all 320 of those objectives, and you say am I responsible for this, is it shared responsibility, there's part of it the client has to do, or is the client entirely responsible, and because typically there's about 50 to 60 percent of those that the MSP is going to be either fully or partially responsible for, it is a lot less work, the opportunity comes once you've done that, and you're mature enough to treat every client the same with, you know, the security stack is the same, you mandate that for each client you work with, especially in the my customer responsibility matrix to the next client you work with, and they're, you know, somewhere fairly far down the road, they're, you know, they're 30, 40, 50 percent down the road, because they can say they've inherited these controls from their MSP, the shared ones, you're going to tell them what they have to do to coordinate those controls, so that your controls are effective, so it helps them a great deal, now they'll still have HR controls for background checks and physical security controls for their buildings and places where CUI is stored, but a lot of the other technical controls you'll already have in place, so that makes you very attractive to other defense contractors, and our recommendations are that you're charging a premium as much as two, two and a half times as much for your regular per seat price for these, because it is a lot more work, and there's more liability to it as well, typically you have a bigger tool set, a more advanced tool set with SimSoc, and white listing or allow listing type software that some of those things that you may not have in other clients, just depending on how you approach your services, and so there's of course all of the things that go in for an MSP to decide whether this is worth their time and effort, but there's also a role for an MSP, even if you don't decide you're going to pursue it, they're not necessarily pursue it, but there's still the conversation for you to have with your clients, you know being prepared to get them through the exercise of is this business viable for us to go through this, because there's you a lot of small widget shops, I used to support a when CMMC first came out, I was supporting a concrete company in North Carolina, they had contracts to pour concrete for DOD, you know FCI, CUI was going, they didn't mark anything, they didn't label anything, they were doing everything the incorrect way, and we started having those conversations with them about even you know back eight years, you know six years ago, five years ago, when it first came around, they didn't know, they couldn't swallow the cost then, so there is a need and an art to having that conversation with your clients, one you know for their benefit, for also for your benefit, because you know that's it, that's potentially a cliff for them. Absolutely, we have worked with, we worked with a small machine company that, or fabrication company, and they made a bracket for one of the fighter jets, and they're about a 20-30 person shop, and that bracket, what they did for the prime contractor that they did it for, was a very very small percentage of their business, we took them through a gap assessment, we worked with them, you know with their, you know their client, as to what they needed to do, did they need to be level one or level two, which we'll talk about, but they had CUI, so they need to be level two, they did the level one gap assessment, or the, not level one, they did a gap assessment, we got their risk score and everything updated and submitted, but they decided not to move forward any further, the cost for a contractor, regardless of size, I mean when you get bigger, it's even more, but even the smallest contractors, it's 200, 250, all the way up to 500,000 dollars, and that's to get ready, and then the assessment is anywhere from, I've been talking to several C3PO's, the lowest ones I've been working with are about 40,000, and they go up over six figures, if you have multiple locations, or a bigger shop, so, and that's every three years, and you have to keep everything up in between, because every year, the senior official of the contracting company, one of their executives has to affirm that all of their controls have been in place all year, so, and there's risk of not just civil penalties, but actual criminal penalties for fraud, if they knowingly attest falsely that they had their controls in place all year, DOD is very serious about these penalties and holding the contractors accountable, so, right now, what they're doing is, there's a number of companies are going after for false claims act, because they said they were all in place, they either had a breach, or the DOD, some, for some reason, had suspicion and went in and audited them, or a whistleblower came forward in a lot of cases, and, you know, then the DOD is working with the false claims act, so, it's serious, you have to decide either to get in or not, and if you're going to get in, you need to either have somebody that really gets trained thoroughly, or partner with somebody like, like us at Prescott, or another RPO that can come in and has the expertise to guide you through it. Again, challenges for the MSPs, challenges for the businesses, and like you said, there have already been actions brought for, you know, negligence, falsification of information, doing things they were claiming, and not doing those things, and that's something, I think, for a lot of MSPs, for the culture and the mindset of a lot of MSPs, they're not used to having somebody being able to knock on the door and say, show us everything, and that's kind of, this is an arena where it's, that knock can come on the door, and they say, show everything, and you have to show everything. So, if you're not comfortable, that's another thing is, are you even comfortable with that principle, that you will have to expose everything about what you do, potentially? Yeah, it's another level of accountability, for sure. So, we've talked a lot about, you know, challenges, opportunities, what it is, but let's get into, you know, what the actual levels we have right now, because CMMC version one, we had five different levels of, five different levels that you could pursue, but that was reworked down to three. We're now left with levels one, two, and three. So, let's start out with level one. What's required there? So, level one is when you're storing, processing, or transmitting federal contract information. So, think about pricing, logistics, you know, if you're shipping products to bases or to different locations for the military, you know, where those quantities cost, but sometimes even just the fact that you have a contract, they don't want that publicly disseminated. So, level one requires, there's 17 controls, 59 assessment objectives. It's really basic cyber hygiene, but you still have to do a self-attestment, self-attest that you have put in place all 59 objectives and the 17 controls and that you meet them. So, it's a much lower bar, but it only applies when you have just federal contract information. And there's a lot of contractors that do, especially when you get far enough down the supply chain. A lot of times, the CUI is pulled out by the higher level contractor, your customer or their customer. So, you just get federal contract information and your contracting officer from your customer should be able to tell you that. And before we move on to level two, there's something here that I always like digging into because it makes people kind of, well, we were not doing what we were supposed to do for how long? That, you know, even FCI is covered underneath FAR. That's been around for quite a while that you have to treat FCI in a certain way. So, that requirement, while it is included in CMMC level one and on, that's something that you are outside of CMMC, you're already supposed to have been doing. So, that kind of just reinforces that CMMC is as much as it is a, this is what you should do. It's also more that it is an enforcement, a component of an enforcement mechanism. So, for level two, what does that look like? What is, you know, what does level two require you to achieve? So, level two is when you have controlled unclassified information, CUI or CUI. It requires a higher level of protection. So, and again, your contracting officer from your customer or from the prime should be able to tell you if that contract contains CUI and what the CUI is. I will say the DoD and prime contractors have not been very good at this. In fact, they've been terrible at it. They are, there's a lot of training going on within the DoD and the primes trying to get this better. One of the FAR rules, the CUI FAR rule for all federal agencies that's in rulemaking right now, if that gets published the way it was proposed, there will be a form that's attached to every contract that says what level you have to be certified at and what in the contract is FCI or CUI. That would be wonderful, especially if they learn how to do it right. But so with level two, you have to, it's the 110 controls, but more importantly, it's the 320 assessment objectives from NIS 800-171A, the assessment guide. And the assessment guide is wonderful. You can go to the DoD site, the resource site and get it. It has suggested evidence. It has recommendations for the assessors and how they're going to assess each one of those objectives. So that gets a lot more detailed into that. But basically, I'll give you a quick example. So one of the controls is timeout, if you idle timeout. So you have to have a policy that says what your timeout length is. If it's 15 minutes, fine. It can't be three hours or eight hours. It has to be reasonable. But if it's 15 minutes, it has to be defined. Then you have to have procedures. Then you have to actually configure it in the system. When the assessor comes in, they're going to ask you to pull up that screen. You're probably going to have a screenshot. They're probably going to look over your shoulder and have you pull up that screen and show them that it's still configured that way. And then they're going to sit there for 15 minutes looking over your shoulder and wait for it to timeout and log you off. And if it doesn't, you're going to have it not met. But that's the level of evidence and proof that you'll have to provide to the assessment or the auditor. And for ongoing support of those efforts, that's where it's so important to have somebody or the capabilities on your team to monitor those elements long term so that whenever you do have configuration drift or something falls out of scope, you know about it and can respond about it because you don't want to be on the other end of a knock, knock, let us see, and you don't have a way to produce evidence that those systems were configured that way at this time, at this date, and that you didn't file any milestones or remediations to have to correct it. Yeah, those types of tools are critical. You can monitor that. And with another thing with Level 2, for at least whenever I started looking into Level 2 from the perspective of MSPs, it was like a, this is best practices. I don't want to say that it's, you know, this is universal best practices, but it was always a, well, this is stuff you should have been doing any way if you were properly, you know, if you're implementing proper risk management. How has that part of the conversation, that risk management part of the conversation, which is really what all of this is about, it's risk management and, you know, how are you going to either accept risk, defer risk, mitigate risk, remediate risk, all those things you have to do. For the MSPs you've worked with, has that risk conversation been a For the MSPs you've worked with, has that risk conversation been a cultural shift for them? Yeah, this whole thing is, when I first got introduced to CMMC, I had come from a large enterprise manufacturing firm where I was doing IT governance and compliance, and we dealt with the same thing there. It's an organizational change management, it's a culture shift to run a compliance program. And with the small companies it's even more of an issue, but having risk management is part of the controls that you have to have in place. It doesn't have to be really complicated, but it has to be practiced and it has to be followed. So one of the MSPs changed their ticketing so that when they open a change request, it asks, is this a high, medium, low threat? And they have some definitions for that. Is it a high, medium, low vulnerability? It builds it right into the ticket as it's been risk rated, and then they have different actions depending on where that is. Same thing with vulnerability management, you can base your risk on CVSS score, and obviously the higher the score, the higher the risk, the quicker it has to be remediated. You can define all of that in a risk plan and policies and procedures, but then you have to implement it and make sure. So if you say if it's a 9 or 10, it has to be patched within three days of a patch being available, and your four or five days, then your control has failed. And so don't be overly aggressive with those, document it. And then if you find that you can't meet it, raise a change request, do a risk rating on that, implement the change, show that you recognize what your capabilities are and that you can meet the control. So that is a big organizational change, culture change. That's why I say it'll make an MSP better, it'll make the client better because of that type of enterprise level policy and procedure of doing these things. And, you know, we think big enterprises, oh, they've always been doing this. Eh, not so much. Some have, but not all of them, especially in the manufacturing industry. The company I was with was 15,000 people. And when I first started there, not that long ago, less than 15 years ago, they didn't even have a cyber department, cyber security team. So they've matured a lot since then, but it, you know, even the big companies struggle with this sometimes. So yeah, it's definitely a culture change. Yeah, because it was all, you know, 15 years ago, it was, you were doing well if you had a NOC, let alone a SOC operation running. So, you know, for MSPs, this is a course, you know, this represents, you know, this is business. And for everybody else that's subject to it, it is businesses. So in business, there's always pitfalls you want to try to avoid. There's things you want to look out on the horizon and try to avoid. One of the things that I always did was one of the quick, my quickest answer for how much of a headache a potential client would be around this was always, who is your data officer and who's responsible for marking the CUI that comes in? And that's just a, well, we don't have anybody doing that. And for me, that was always just one of my quick ways of gauging, have y'all, have you even looked into this yet, really? So what are the pitfalls that you're seeing from the MSP side and from the businesses that are under, other businesses that are under scope of CMMC? What are they, what are they falling for? You know, one of the things I should have mentioned is I owned an MSP for 15 years, eventually sold it and, and then helped another company do their MSP program. And then I kind of transitioned over to compliance with the manufacturing firm. So I get it from an MSP standpoint. It's, it's a hard business decision, but some of the pitfalls are, I think unless you're really got somebody, a compliance-minded person that you can dedicate to this to learn it, it's not going outside for help. And then finding help that's got experience, you want to, you want to know that they've been through assessments, that they've been doing this for a while, that, so one of the, there's two different designations, the registered practitioner organization and the C3PAO, the certified third-party assessor organization. Both types of organizations can help prepare you. And of course, if a C3PAO helps prepare you, they can't do the assessment because that'd be a conflict of interest. And, and right now, most of them are so swamped, they've stopped doing the readiness. They really are focusing on assessments. But if you go with an RPO, I recommend that you find an RPO that has, when it comes to the individual certification, that they have CCPs or CCAs, so CMMC certified professionals or CMMC certified assessors on staff. They only are required to have registered practitioners or registered practitioner advance. The difference is the registered practitioner preparation takes about four or five hours, and it's an open book, untimed test. So pretty low bar to pass. CCP requires a 40-hour class and a three-hour proctored exam, so it's not open book. So you, you just have to memorize a lot more of it. You have to be a lot more comfortable with the material to, to pass that bar. And, and then there's a background check and some things there too. So even CCPs, until they've got some experience, I know when I first passed my CCP, I'm going, great. Then I started working with our senior consultant who's been doing this from day one. He was one of the provisional assessors. He's been an enclave manager for one of the C3PAOs and led them through the DBCAC assessment. And he starts explaining to me what's really required around the SSP and risk plans and change management program and stuff. And it's like, oh, okay. This is even a lot more detailed than what I learned in class. So that kind of experience is really important that you vet whoever you're going to use, if you're going to use somebody from the outside. So I think that's one of the biggest pitfalls to avoid. The other one is thinking that, and we talked about this, but it's only NIST 800-171 with 110 controls. It's really the 320 assessment objectives behind those, because you have to meet each one individually. And I think those are the two biggest things. And another one is underestimating the effort and the resources it's going to take to do it. I recommend to the MSPs we work with, when we, because as an RPO, we're required to have a written contract with who we're helping to get ready. So if it's the MSP's client, we have a written contract with their client. We're providing services to them. We're also working with the MSP at the same time to bring them up to speed. And the MSP is usually setting in on all of the meetings with the client. They should be charging for that time. So this should be a revenue source even to get the client ready, because that's not included in a normal managed service agreement. And then when they're done, like we talked about before, the extra premium per seat pricing to provide all the tools and all the extra due diligence that's required for meeting the program requirements. So those are things, thinking through it, preparing, even having a separate product class SKU for the GRC clients, if you will, governance risk compliance or compliance clients. So one of the MSPs we work with has a regular managed service and a GRC managed service per seat pricing. So those are all things to think through and be prepared for. One of the ways that I've always thought was a good kind of, do I have the talent in-house is as inexpensive as it is, even though it is, you know, not the most glorious and the most impressive of credentials, the registered practitioner is like, you know, take somebody off your team, put them through the RP, let them go through the RP. It doesn't take a lot of time. It doesn't take a lot of effort, but if it is a challenge for them, and that's the person you are expecting to lead the effort, really good early indicator without a lot of money spent that this is a steeper hill for you to climb than you thought it might have been. Yeah, I think that's a good, it's a great place to start. And if they're going to be leading the effort, even internally, even if they're working with an outside source, it still gives them a real good introduction to what they're going to be dealing with. And it makes it a when their consultant is telling them what they have to do, if they can tie it into what they've learned. So it is a good starting point. And then there's the RP and the RPA. And the RPA has always interested me because the RPA carries just the extra kind of expectation of this individual has knowledge and experience on implementing what 50 plus of the controls that are called for. The RP is just, and even the CCP is really only covers the 17 controls for FCI. The CCA and of course the RPA cover the rest of the controls. I may be wrong on the RPA because I don't really look at that one much, but I know CCA of course covers all 320 assessment objectives, all 110 control families. So yeah, it is more advanced. It is worth pursuing. And I believe it kind of goes like it, starting at the bottom, it's like RP, RPA, RPO. So the RPO is the organization versus the individual. Right. And the RPO. And then there's, there's additional one, there's educator certifications. There are, there's tons of opportunities here. So even if you decide you don't want to approach it from the, that the, my MSP is going to support this for the client, there are other opportunities within the infrastructure of all this. And cyber eight, the cyber AB, the cyber accreditation board, they're the ones that are handling the certifications and a lot of what else is under their purview. So they have Keiko, which is under their purview, which does more around the training partners and the training materials. And then they have all of the individual certifications. So the CCP, CCA, RP, and RPA are the four certification. Well, and then there are the instructor ones as well, like you said. And so, yeah, you can always go down the instructional route as well, become an instructor in this. You have to be a CCP. I think you have to be a CCA to become an instructor. So there's that foundational work and you have to be a CCP to become a CCA. So they kind of make you jump through those hoops to, to get it. So you have the foundation and then you build on it and they oversee that. They also are the ones that do the accreditation of the C3 PAOs. So the organizational levels, there's on the doing side, there's the RPOs that can help companies get ready. And then there's the C3 PAOs that can do the assessments and help companies get ready. And then there's, oh, they changed the acronyms recently, but like basically an LTP, there's a training provider and the training material provider, the license material provider. So, and I know they changed the names of those when they did the final rule. So I have, I'm not involved so much on that side. So I'll memorize, but there are a lot of opportunities. Yeah, there, there are a lot of opportunities and we, we focused a lot on, you know, MSPs, there's of course, you know, IT professionals, for the individual that's interested in this. And it's like, they are looking, you know, down the road for their own professional progression. What would be a starting point for them? Yeah, if you're interested in getting into compliance, and that's really what this is, security compliance. It's not technical. We don't deal with the technical for us. We don't deal with the technical controls. We use the MSP or internal IT departments to do those. But it's, it's the organizational change management, all of the different plans, those types of things. So the path really, there's, there's kind of twofold because to be a CCP or CCA, you have to have another professional certification, whether it's a CISSP, whether one of the SANS, Ethical Hacker, you know, different, there's, there's a number, but there's a DOD website that lists all of the certifications for a lot of different things. But certifications for a lot of different things but they use that platform or they that website as the list of qualified credentials so you have to have one of those credentials to get to the CCP or CCA level and that that's good to go check out work on those credentials if you don't already have them get that and then if you do I took the route of I did my CCP first and then I did the RP certification because I needed it for our RPO because that's what you have to have if you have two RPs for to be an RPO and that was it the RP was I actually looked at the material but where's the rest of it it's so much different than the CCP but it's so if you do CCP first the RP is just kind of a natural follow-on to get it done but you can start with the RP and that gives you a good foundation to then build on for your CCP and you know resources are scarce there's last time I looked there's like 337 CCAs period which means you have two CCAs a lead assessor and an assessor and then you have to have a quality assurance assessor so technically you have to have three assessors on every assessment the first two are going to be dedicated to that assessment the third one the quality control can probably handle multiple assessments at a time but even with the two of them you're looking at 160 170 assessments that can be done at any one time and there's even by the Department of Defense's estimates there's 80,000 companies that have to be certified we didn't really talk about the phased in rollout but essentially when the 48 CFR the contract clause gets finalized the first year you can do self-assessment for level 2 but at the end of the first year so we're estimating sometime late next year 2026 companies will have to be certified with a certification for level 2 in order to bid on any level 2 contracts or to be awarded them not to bid on it but to be awarded of course the prime is putting out the contracts aren't gonna let them bid if they're not already certified because they don't want them to win and then not be able to award them the contract so at the most we have about 12 to 15 months to get ready if a company hasn't started at all the estimates 12 to 24 months so time to get going right now but the opportunity for individuals is there you can become a CCP once you get some experience with CCP or CCA salaries are you know six figures and above and it's it's good good positions 150 to 200 thousand for an experience CCP CCAs can be even higher yeah it is a field where it is a field that is not saturated at the moment probably not be saturated for quite a few more years so it is a for the even for the individual like we said it's a good path for the individual as well so mark it's been a pleasure before we in this session is there any other additional places or sources of information anybody can look to if they want to know more about a CMMC yeah a great place is the DoD CMMC website if you search DoD.gov CMMC I think it's just slash CMMC or CMMC info they have a whole list of all of the assessment guides and I mean there's there's a whole page of links there for different things training there's certain CUI training that your staff has to do over a year if you're gonna do this that type of stuff and it's straightforward simple and free but that's a great place to start I know we've worked with enable I'm not sure it's actually published yet maybe it is but a 20-page booklet that gives you as an MSP a good base knowledge and then I know you know we're working on some other things with enable you know materials more of how-tos and things like that that are going to be coming out so those and our Prescott.us site there's some different information there and of course CyberAV.org is also a great site there's a marketplace there that lists all the individuals that are certified all of the companies for RPOs and C-3POs are all listed in their marketplace as well well thank you Mark for the conversation today I always love talking about CMMC anything that's regulation compliance always gets me excited just because I know it's a headache for everybody else and I'll be looking forward to hopefully Prescott.us will have even more that we'll be doing together over time with CMMC since it is so important for our for the channel for our partners thank you Mark. Thank you Louis, I'm looking forward to doing more of these.