Do Not Fall Into a Trap: Review Your CMMC Policies Now

On July 13, the US Department of Defense/War (DoD) announced the immediate suspension of the Cybersecurity Maturity Model Certification (CMMC) Phase 2 requirements, which previously were scheduled to go into effect November 10. Contractors were subsequently invited to comment on the future of the CMMC.

On

Read our prior alerts: DoD Suspends CMMC Phase 2 Rollout: What Contractors Need to Know and CMMC Reform Task Force RFI: Defense Contractors Have a Chance to Shape Federal Cybersecurity Requirements.

The government’s review of the CMMC program does not, of course, eliminate the threats that effective cybersecurity controls are designed and intended to mitigate, or nullify existing cybersecurity programs designed around the CMMC framework — some form of which is almost certain to remain following the suspension period.

For contractors already operating under the security controls of NIST 800-171 and the CMMC framework — and contractors continuing to work towards that goal — we see a recurring need for contractors to carefully review their policies and procedures that govern access to information systems that contain Federal Contract Information (FCI) and Controlled, Unclassified Information (CUI) to ensure that those policies do not inadvertently create extraneous or unachievable approval requirements.

General issues to be considered include the following.

  • What approvals are required under the company’s policies related to access to controlled information, as opposed to government authorizations?

  • Do those policies require approval from:

    • Relevant company personnel?

    • The owner of the data?

    • The appropriate governing agency?

  • If the policy identifies more than one required approver, must approval be obtained from all parties? 

These questions are arising with regularity because there is not a one-size-fits-all approval process that applies to all types of controlled data. For instance, CUI data may, or may not, be export controlled. If a policy does not distinguish between export-controlled CUI and non-export-controlled CUI — for instance, if the policy includes a blanket requirement that non-US persons obtain an export license before accessing CUI, that requirement cannot be fulfilled if the CUI at issue is not export controlled. Depending on the wording of the policy, the failure to obtain an export license might technically be a deviation from or non-compliance with company policy, which would raise issues under the CMMC. 

A useful way to think about the CMMC is that it constitutes the rules on how to protect data that must be protected, but not the rules that define what data must be protected, who is authorized under law to access the data, or the process to obtain government approvals. Hence, it is critical for purposes of their CMMC policies that contractors consider the full scope of controlled unclassified information that they hold and that they ensure their policies are drafted to describe how controlled data are protected without creating requirements to obtain approvals — particularly approvals from third parties — that do not otherwise exist. 

Contacts

Continue Reading