No Time to Waste
If you’re a Tier 1, 2, or 3 automotive supplier working in the Defense Industrial Base, CMMC Level 2 compliance isn’t a future consideration. It’s becoming a contract requirement. Miss it and you’re out of the running, no appeals, no grace period. Just lost revenue.
The problem is the readiness spectrum is wide. Some shops are 80% of the way there and just need to close the gap. Others are starting from scratch and don’t know where to begin. This webinar covers both situations.
Have questions?
We’re ready to help you find the best path forward with certification.

Carter Schoenberg leads compliance and assessment at Koniag Cyber, a Certified Third-Party Assessment Organization (C3PAO). He’s assessed dozens of defense contractors through CMMC compliance.

Mike Hemmingsen manufacturing sales at Vervint. Vervint is a Michigan-based technology partner specializing in manufacturing and industrial operations, working directly with Michigan auto suppliers on IT compliance, infrastructure, and security.
Our top three takeaways:
CMMC Is No Longer
a Future Problem
For years, organizations could afford to wait and see. That window is closing. Whether it’s government requirements, customer expectations, or supply chain pressure, CMMC is rapidly becoming a business reality rather than a future consideration.
The Supply Chain
Is Driving Compliance
One of the biggest surprises from the discussion was that many companies aren’t being pressured by regulators first. They’re being pressured by customers. Large primes and system integrators are increasingly requiring suppliers to demonstrate progress toward compliance before work can continue.
Waiting Creates More
Risk Than Starting
Many organizations are delaying because they don’t feel fully prepared. The irony is that waiting may create a larger problem. Assessment schedules are filling, timelines are tightening, and organizations that start early have significantly more options.
The Full Recap
For years, CMMC occupied a strange place in the minds of manufacturers and suppliers.
Everyone had heard about it. Most understood it was tied to defense contracting. Many believed it would eventually matter.
But there was always a reason to push it to next quarter.
The regulations were evolving. Timelines shifted. Enforcement felt distant. For many organizations, cybersecurity compliance lived somewhere in the gap between “important” and “urgent.”
That gap is disappearing.
In our recent webinar, CMMC expert Carter Schoenberg joined Mike Hemmingsen to discuss what automotive suppliers need to understand about CMMC Level 2 and why many organizations are discovering that the decision is no longer whether to prepare, but how quickly they can get there.
The Automotive Industry Is Closer to This Than It Realizes
One of the most common misconceptions surrounding CMMC is that it only applies to traditional defense contractors.
The reality is far more complicated.
Modern defense manufacturing depends on vast supply chains. Large manufacturers rely on suppliers. Those suppliers rely on their own suppliers. Information, specifications, and requirements move throughout that ecosystem. When defense-related contracts enter the picture, cybersecurity obligations often move with them.
Mike and Carter spent significant time unpacking this reality.
The question is not, “Are we a defense contractor?”
The better question is, “Where do we fit in the supply chain, and what information passes through our business?”
For many organizations, that shift in perspective changes everything.
Compliance Is Becoming a Business Conversation
Carter raised a good point during the discussion. CMMC should not be treated as an IT initiative.
That mindset has created problems for many organizations.
Cybersecurity controls matter, of course. Technology plays a significant role in achieving compliance. But the organizations making the most progress are treating CMMC as a business risk conversation rather than a technical project.
When viewed through that lens, the stakes become easier to understand.
This is not simply about passing an assessment.
It is about preserving opportunities, maintaining customer relationships, and ensuring your organization remains eligible to participate in future contracts.
The Market May Move Faster Than the Government
A particularly interesting theme emerged around enforcement.
When people think about CMMC deadlines, they often focus on government timelines. The assumption is that requirements become real only when a regulation officially takes effect.
The market is proving otherwise.
Large organizations throughout the defense industrial base are already asking questions of their suppliers. Some are requesting concrete plans. Others are setting expectations for certification readiness. In many cases, supply chain pressure is arriving before regulatory pressure.
That changes the timeline considerably.
You may not be preparing for a future government requirement.
You may be preparing for a conversation with a customer that’s already happening.
Waiting Creates Its Own Risk
Carter also brought up assessment readiness and scheduling.
Certification requires assessors. Assessors require scheduling. And as more organizations enter the process, availability becomes more difficult to secure.
The recommendation from Carter was straightforward.
Do not wait until you believe you’re ready before beginning conversations with assessment organizations.
Start earlier than feels necessary.
Understand your options. Learn what availability looks like. Build a plan before you need it.
For organizations targeting certification in the near future, time is becoming one of the most valuable resources in the process.
The Opportunity Hidden Inside Compliance
CMMC is often discussed as a requirement.
A mandate.
A cost of doing business.
But there is another way to think about it.
Organizations that begin tackling these challenges now gain a better understanding of their own operations, vendor relationships, cybersecurity posture, and business risks. They become more resilient not simply because they passed an assessment, but because they built stronger processes along the way.
Compliance may be the driver.
Operational maturity is often the outcome.
What Happens Next
If there was one message that carried through the entire webinar, it was this:
The conversation has changed.
A few years ago, organizations debated whether CMMC would arrive.
Today, the discussion is centered on timing, preparation, and execution.
The suppliers that succeed will likely be the ones that move before they’re forced to move. The ones that treat cybersecurity as a business priority rather than a technical obligation. And the ones that start asking hard questions now instead of waiting for a customer to ask them first.
Ready to get started?
We’re ready to help you find the best path forward with certification.
View The Full Episode Transcript
[00:00:00] Narrator: What happens when a security requirement stops being a compliance discussion and starts becoming a business reality?
[00:00:06] Narrator: In this webinar, Mike Hemmingsen sits down with CMMC expert Carter Schoenberg to discuss why automotive suppliers can no longer afford to take a wait-and-see approach to CMMC Level 2. You’ll hear how cybersecurity requirements are moving through the automotive supply chain, why many organizations are feeling pressure from customers before regulators, and what manufacturers should be doing now to protect future business opportunities.
[00:00:39] Narrator: Carter also shares practical guidance on certification timelines, choosing the right assessment partner, and avoiding some of the most common mistakes organizations make when preparing for compliance. Whether you’re a tier one manufacturer, a tier three supplier, or somewhere in between, this conversation offers a clear look at where CMMC stands today and what happens next. Let’s jump in.
[00:00:56] Mike Hemmingsen: Thank you for joining our CMMC Level 2 for auto suppliers, what you need to do before contracts are on the line. With that being said, I’d like to introduce Carter Schoenberg, who is our CMMC Level 2 expert, subject matter expert, that is. Carter, how are you today?
[00:01:17] Carter Schoenberg: I’m doing well. Thank you for having me on today.
[00:01:19] Mike Hemmingsen: Awesome. Well, Carter, as you and I have talked before we got onto this, we’re going to review in very plain English what CMMC Level 2 is for auto suppliers. It’s not just a defense contractor obligation. It’s really, really growing in the automotive sector. And with that, we’re going to be able to answer some questions for folks today. We’re also going to go in depth on some of the two rules that are going to be really, really the teeth in these certifications and audits that we need to get passed. So with that being said, any additional information from the Koniag Cyber side that you’d like to introduce us with?
[00:01:59] Carter Schoenberg: Oh, absolutely. So again, thank you for having me here. So I have two particular roles within the organization. I’m responsible for the head of our C3PAO program and our professional managed CMMC services and also directly responsible for the cybersecurity posture for us to retain our C3PAO status and ultimately acting as the affirming official. Originally coming from Soundwave Consulting. So Soundwave Consulting was the 24th organization to become an authorized C3PAO in 2022. And as of March of this year, we are now part of the Koniag Cyber family.
[00:02:39] Mike Hemmingsen: We’re excited to have you, Carter, and we’re lucky to have you, to be honest. With that in mind, do you mind us starting and can I ask a few questions just so that I can get some clarity on what are these two rules I see, 32 and 48 CFR? What are those and what’s making it real this time?
[00:03:01] Carter Schoenberg: Sure. So kind of giving a little bit of a backwards-in-time vantage point. So the topic of CMMC has now been around for almost seven years. This is all stepping back from an executive order that came back even years before that. And ultimately, the Defense Federal Acquisition Regulation Supplement created a modification in 2016. They added what’s called a CUI safeguarding rule. It kind of came out with less than a lot of fanfare. And the reality is this industry looked at it as another regulation that the government was never going to police. And guess what, Mike? They never policed it.
[00:03:46] Carter Schoenberg: And if you had to kind of connect the dots between our jet fighter technology winding up in the hands of China, some of our adversarial cyber weaponry winding up in the hands of Russia, at a certain point, I’m convinced that the Joint Chiefs of Staff got together and said just simply putting a DFARS clause into a contract is not enough. So we have to be able to create a mechanism for kind of keeping the government contracting community honest about this.
[00:04:16] Carter Schoenberg: Yeah. So there was an initial version. It had multiple frameworks that were built into it. It was met with a lot of resistance. And then the second iteration came about, which basically reduced it to just one standard, that is the NIST Special Publication 800-171, which is titled Protecting Controlled Unclassified Information in Non-Federal Systems and Organizations.
[00:04:42] Carter Schoenberg: Now, with respect to the DFARS clause that I made reference to previously, you had for probably several years, and actually it’s still happening, a lot of organizations saying, yep, I swear and attest, I’m in conformance with that. Well, the problem is that the government was able to determine that for the majority of the organizations that had made that attestation, it was factually incorrect. They, meaning the government, also clearly understood that they were not in a position to bring to bear to the marketplace having enough government employees to take that on.
[00:05:22] Carter Schoenberg: So therefore, they entered into a single-source, no-cost contract with the Cyber Accreditation Body, which is the ultimate authority on providing oversight for organizations that are defined as a C3PAO, not to be confused with a 3PAO. So 3PAOs are for evaluating companies for software security and FedRAMP certification. C3PAOs are pretty much exclusive to the realm of CMMC.
[00:05:52] Carter Schoenberg: It’s very important for the listeners to understand that when we make reference to CMMC, it is not the same thing as DFARS. All that people really need to understand is that CMMC is a third-party way of policing that you are not in violation of your contractual obligations.
[00:06:12] Carter Schoenberg: So starting in 2019 and then slowly progressing and then kind of going radio silent for many years, a lot of people took the position of, this requirement is never going to get off the ground, so therefore I’m not going to invest any time or effort in trying to satisfy these requirements. And then in 2024, 32 CFR Part 170 was codified. What that basically means is, in the Federal Register, the basis for having CMMC as a formal program became administrative law. Full stop. Okay.
[00:06:54] Carter Schoenberg: Then it alluded to a multi-phase rollout. Phase one, which would basically, each phase would last about a year. And phase one would be for Level 1 self-attestation, which we’ll get to the levels in a minute. Phase two would be for Level 2 self-assessment. I’m sorry, self-certification. Phase three would be at Level 2 independently being certified by a C3PAO like Koniag Cyber. And then phase four, which would be for Level 3.
[00:07:27] Carter Schoenberg: Well, while 32 CFR created the basis for the CMMC program, there still needed to be an official edict, if you will, for directing government contracting officers and officials to put it into contract language. So then you have 48 CFR come out. It became codified and basically was the second part to 32 CFR. So now, organizationally, throughout the entire U.S. government, CMMC is a thing. And now with 48 CFR, the Department of Defense has the statutory authority to require CMMC in all of its contracts moving forward.
[00:08:11] Mike Hemmingsen: So, Carter, thank you. That’s an immense amount of information. We really appreciate it. And I’m glad we’re recording this for people to go back. You know, you talked a lot about Department of Defense, government. How is this applying to automotive suppliers and manufacturers? Where’s that correlation?
[00:08:32] Carter Schoenberg: Yeah, so the automotive sector is, while it is its own vertical, it is notwithstanding the brunt of the tip of the spear, if you will. So an automotive manufacturer, regardless of what tier in the supply chain it is located in, is still subject to these requirements. The easiest way for an organization to determine if these requirements are applicable or not is actually quite simple. Any contract that you have with the Department of Defense, all you have to do is just put in dash 7012, just do Control F, 7012. If that hits, these obligations directly apply to you. They directly apply to your lower-tiered subs because there is a flow-down clause that is applicable and notwithstanding any specific level of tier does it stop at.
[00:09:32] Mike Hemmingsen: That’s great. Thank you. Thank you. I hope our listeners take advantage of that to see if they are required. Can you walk us through, you know, tier one, tier two, three automotive supply chain, what that looks like and how to know whether CMMC lands on them now, here, later, or even if it will be at all?
[00:09:57] Carter Schoenberg: Sure. So let’s focus on tier one. So those are going to be what we would call in government contractor lands, the prime contractor. So the actual entity that actually has the written contract with the U.S. government, in this case, Department of Defense. With respect to how, so we’ll pick on Ford, very large OEM, original equipment manufacturer. So they have a prime contract vehicle with the Department of Defense to make a product, a manufactured automobile product that is going to be used for, let’s say, wartime purposes. So that would be your tier one supplier.
[00:10:40] Carter Schoenberg: Now, if your tier two supplier might be a component manufacturer that is making the engine, if you will, that is going to be sold to Ford to be used in that specific work product based on the specifications coming from the Department of Defense. Yep. Then you have tier three, which might be, I’m being tasked to come up with the creation of the bolts, the nuts, the washers, camshaft, tie rod, whatever the case may be, that’s going to go into that engine. So that would be what we might construe as like your tier three supplier.
[00:11:23] Carter Schoenberg: Yeah, all of which is going to be subject to that original prime contract. It is up to the prime contractor. In this case, in this scenario, Ford would be making the determination of at what point in time are the materials that are going to be within that contract going to be capable of being delisted as CUI.
[00:11:50] Carter Schoenberg: So what do I mean by that? Because I’m not trying to tell your audience that the Ford Motor Company or anybody else gets to sit there and say, well, it says CUI, but it’s not CUI. I’m not suggesting that at all. What I am suggesting is that if you had, let’s say, a schematic, and that schematic is marked CUI, and Ford realizes one-fourth of the schematic needs to be created by the Acme company as a tier three manufacturer, as a tier three supplier, they could theoretically take out that specific component of that schematic and then have that properly secured and safeguarded sent to the tier three supplier without that tier three supplier having to qualify for a Level 2 certification because there’s CUI in play.
[00:12:42] Mike Hemmingsen: Okay. Okay. You know, recently I’ve met with a few manufacturers that aren’t necessarily automotive, but they do tend to every once in a while do business with some of the automotive supplier tier twos. Starting to have a lot of conversation that they’re even getting ready for CMMC Level 2 certification because they see it coming down the pipeline. You know, just probably four or five conversations in the last month with some of our customers. What would you give for a recommendation to those tier threes that maybe right now aren’t, but why would they be interested in looking at something like this?
[00:13:27] Carter Schoenberg: So it’s a great question. The reality is, unfortunately, we’re not in the position any longer as of July 2026 to say, is it not, which way is the wind blowing? Our wind is only blowing in one direction. So out of roughly 300,000 organizations that make up the defense industrial base, about 120,000 of them are going to have to become independently certified. That was based on the initial numbers as provided by the U.S. government. My assumption is that that number will actually be much higher. I think that there was a misunderstanding with regards to the interdependencies between tier two and tier three to the prime contractor.
[00:14:17] Carter Schoenberg: And frankly, what’s driving the lion’s share of the momentum for organizations becoming certified, and I think at last count, there’s roughly 1,200, it’s not even coming from the U.S. government. It’s actually coming from the large system integrators. So, we have a couple of graphics that we can convey and show that in a couple of minutes. But the notion of is it going to apply to them? You have to operate under the assumption that it is going to apply to you.
[00:14:48] Carter Schoenberg: For an organization that’s going to take the position of saying, yes, but what are those additional costs? Okay, what are the costs to your organization if you’re no longer able to do business? I mean, it’s really becoming. That’s a big risk. Yeah, it is a big risk.
[00:15:11] Carter Schoenberg: What we also have consistently seen, not just with Koniag Cyber, but the majority of the C3PAOs that have represented the industry now for several years, is this misunderstanding that CMMC is an IT program and kind of deferring to like the IT person for their take on it, which has historically not worked out very well for those organizations. CMMC is more operational and managerial in nature. It definitely has a technical component to it. But if organizations are not looking at CMMC and the cybersecurity requirements as a business risk instead of an IT issue, they’re going to be positioning themselves for a very long road to hope.
[00:16:00] Mike Hemmingsen: Yeah, and look, I don’t think anybody wants to be in that position. You know, you mentioned earlier big system integrators, right? What we’re starting to hear is that, you know, hey, either you comply or you’re off the team. Regardless of who owns that contract, is this a real enforcement and who’s driving it?
[00:16:25] Carter Schoenberg: Yeah, so great way to kind of set the stage. If our presenters can please pull up that particular slide, that’s great. So right now, the big ones like Raytheon, Northrop Grumman, General Dynamics, Leonardo, and most recently, L3Harris, they are all providing formal letters to their entire supply chain saying do or die. There’s plenty of fish out there. We are more than happy to bring on whomever we need to bring on. But if you’re not in a position to show us that by July 30th, in this particular case for L3Harris, that you are certified or that you have a game plan in writing with contracts in place to get yourself certified, you’re done.
[00:17:14] Mike Hemmingsen: Wow, that’s a huge risk. So, you know, CMMC has been out there. We’ve been talking about it pretty heavily in the last year with a lot of customers. You know, the timeline when it kind of all rolled out versus what’s actually happening on the ground today, can you give us a little insight on that?
[00:17:37] Carter Schoenberg: Sure. So we have actually another graphic that shows a linear timeline. So where you see the calendar view of December 2024 through November 2028. So above that line is academically what was put into print from the U.S. government with regards to those four phases of a rollout that I described earlier in this session. The reality is what we have now seen as a matter of reality is that while phase one, which again is just a requirement for an independent assessment against a total of 59 objectives, that remained constant. What has changed significantly are phase two, Level 2 self-assessment, and phase three, Level 2 independent certifications.
[00:18:35] Carter Schoenberg: It’s very important for people watching today’s session to understand. Well, I’m just going to go the Level 2 self-assessment route. You can take that approach, but you need to understand again from a risk perspective. What does that actually do for your organization from a risk aperture? So if you evaluate the numbers of what the government anticipates it will put out for formal solicitations and contracts that would only require a Level 2 self-certification, it’s roughly 3%. Those are equivalent to the same odds of winning blackjack in Las Vegas. So not very strong odds to take that approach.
[00:19:20] Carter Schoenberg: With regards to Level 2 being independently certified, I actually went on record, I think around November of last year, that my assumptions are that these timelines are going to be consolidated and we’re going to be jumping ahead of it. Now, having said that, I estimated that before the end of the calendar year of 2026, that there would be no less than 100 solicitations that have hit the street that have a Level 2 C3PAO requirement. I believe as of April, and I think we have a graphic there, there were over 60. They have already hit the street that have a Level 2 C3PAO requirement.
[00:20:07] Carter Schoenberg: Now, there can be a variety of reasons for this, but it doesn’t change the fact that as an organization that is dependent upon revenue streams from the U.S. government, specifically the Department of Defense, you can no longer turn a blind eye to how rapidly these requirements are advancing.
[00:20:36] Carter Schoenberg: And I might also add, this might be the first webinar where this is actually being discussed. A news flash came out last night. CMMC is based upon, as I said before, 800-171. As it stands right now, revision three is the most current version. It’s being used and is required by federal civilian agencies. But there was a memorandum that came out from the Department of Defense February of last year, I believe, that basically said, for the purposes of CMMC, we’re going to stay locked in at revision two.
[00:21:23] Carter Schoenberg: There was all types of debate about how long is that going to last. Even members from government and industry trade organizations were saying, well, we anticipate that will happen in 2027. This news flash that came out last night suggests that in August, an interim rule will be coming out that will be pivoting the requirement to go from revision two to revision three. Now, with respect to what is that rollout going to look like, meaning is it going to be 365 days from date of issuance, 90 days from date of issuance, 30 days from date of issuance? That I do not know. But the organizations that are taking the position of, I will put myself into a position to be certified in the calendar year 2027, unfortunately, they’ve done themselves a little bit of a disservice.
[00:22:06] Carter Schoenberg: Because Rev. 2 and Rev. 3, one, for just give me some context. In revision two, there are a total of 110 controls. In revision three, there is a total of 97. So that sounds like it’s good news because you’re reducing the total number of controls by 13. However, in revision two, you have 110 controls, but you have 320 things that you had to show to the assessor. With revision three, that number jumps to 422. So more than 100 more things that you now have to be able to demonstrate. And it also includes the addition of three new control families, which include planning, system and services acquisition, supply chain risk management, all of which are going to land squarely on this topic of how much is it going to impact tier one, tier two, or tier three.
[00:23:08] Mike Hemmingsen: Wow. Look, I’m glad you’re the expert and stay up on all these. Do you just sit and watch news all night?
[00:23:19] Carter Schoenberg: Yeah, actually, in this ecosystem, it’s interesting. There are a number of stakeholders that they are excellent at promoting these updates. So I’m fortunate that I don’t have to scour the Internet because I have colleagues that are more than happy to do it, and giving them credit where credit is due for sure.
[00:23:40] Mike Hemmingsen: Awesome. Awesome. Well, you know, you keep mentioning about, you know, people having to hit these required requirements in 2026, right? We know there’s a potential of the version three coming out, and we don’t know what that looks like going forward. But let’s say I think I’m on a good road, right? And I’m looking to be compliant and ready by the end of 2026. Part of that is we need a C3PAO to certify that, right?
[00:24:11] Carter Schoenberg: Yep.
[00:24:12] Mike Hemmingsen: So if I’m hearing things right, getting some of those folks to come in with their availability is becoming a real bottleneck. What advice can you give to everybody today on how to and when to engage for that? Because it has to be certified by the end of the year.
[00:24:33] Carter Schoenberg: For an organization that is giving themselves a bogey to be certified no later than, let’s say, December 31st of 2026, there are still opportunities out there. However, that window of opportunity is constraining very, very quickly. So a lot of organizations we’re seeing, well, we want to get ourselves ready and then we’re going to contact the C3PAO. The problem with that is the lead time that is now necessary to be able to get onto a C3PAO schedule because of supply and demand. It’s a problematic strategy.
[00:25:12] Carter Schoenberg: So my recommendation is to any organization, if you are feeling pretty comfortable that you’re going to be ready to be evaluated in July, let’s say October, you don’t want to wait until August or September to try to go find these C3PAOs. I mean, you want to be finding them now. You want to have a contract in place now. The fact that it’s going to be done months from now is irrelevant.
[00:25:45] Carter Schoenberg: There’s nothing preventing any organization from reaching out to Koniag Cyber or any C3PAO to say, hey, what does your schedule and availability look like for Q4 calendar year 2026? And what’s it going to take for me to get onto your particular schedule? Sorry, we’re booked. All right, contestant number two, what’s your schedule and availability going to look like? And unfortunately, you’re just going to work your way down that particular list.
[00:26:10] Carter Schoenberg: Having said that, there are some unique challenges that have been identified in the ecosystem. There’s over 100 C3PAOs. The majority of them are very heavily dependent on 1099s. And as a result of that, there are some unique challenges with regards to being able to provide a high level of assurance that the date that the C3PAO is committing to is actually the date of execution, which is why it is critically important sooner rather than later to get something in writing.
[00:26:44] Carter Schoenberg: And also, I would push as the organization seeking certification and for whatever the reason, the schedule is pushing to the right and it’s not my fault. What, if any kind of remuneration am I going to receive from that C3PAO as a result of my delays? That’s not my fault. Excuse me.
[00:27:08] Mike Hemmingsen: Yeah. So, you know, let’s talk automotive supplier, right? What’s the same about CMMC for an automotive supplier that it would be for a defense contractor? You know, things like OT and IoT on the factory floor, you know, that’s going to come into scope.
[00:27:26] Carter Schoenberg: And it will absolutely come into scope. And that’s also something else that any organization seeking certification, otherwise in the industry called an OSC, is going to want to explore. So when I just made reference to contacting C3PAOs, schedule and availability is just part of the calculus. What is the level of experience that those team members have? And even evaluating an environment that has SCADA, OT, IoT types of infrastructure and technologies, because there is a difference between somebody that knows how to, let’s say, assess a cloud-based Microsoft enclave versus not only knowing how to do that, but understanding how does a remote terminal unit interface with a master terminal unit? How does it all interface with the human machine interface? Without having those types of understandings, there’s a very good chance that the timeline and accuracy and efficacy of the assessment could be called into question.
[00:28:30] Mike Hemmingsen: Wow. There’s a lot to this. I’m glad we got Koniag Cyber and you, Carter, to help us through some of this. You know, that brings me to a good question, in my opinion, and that is, so I’m out shopping for a C3PAO. What are some of the questions that I should be asking these folks? And, you know, are they basically paying to learn all this?
[00:29:01] Carter Schoenberg: Yeah, so I would say here would be my top questions. One, how long have you been a C3PAO? Two, can you please provide me referenceable clients? If the organization takes a position of saying, well, that’s of a sensitive nature and we don’t provide that, to me, that’s a red flag. You know, if you’re doing solid work on behalf of your clients, there’s nothing wrong with asking them if they could be defined as a referenceable client. And if they’re not going to be agreeable to be a referenceable client, it kind of begs the question, why not? Because all of these organizations that have now been certified, they’re all chomping at the bit to have a new graphic that is under development from the Cyber Accreditation Body that they can proudly post on their corporate website saying, I’m Level 2 certified.
[00:29:56] Carter Schoenberg: Another question kind of comes back to what we were just talking about. What are the specializations of the individuals on your team? Do they know how to evaluate OT and IoT infrastructure? Do they have any hands-on experience walking a shop floor and being able to understand how hard-copy CUI might be coming into play?
[00:30:19] Carter Schoenberg: I would also ask, you know, the basics, schedule availability, cost of ownership, and also most recently, what is your process for becoming accredited? So as an example, you have authorized, probably being an authorized C3PAO and being an accredited C3PAO. Everybody starts off as an authorized C3PAO, but from the moment that you have been blessed by the Cyber Accreditation Body as of January 2025, you only have 27 months to become fully accredited by ISO, the International Standards Organization. If you are not certified, game over.
[00:31:04] Carter Schoenberg: So as an example, Koniag Cyber, we have until March of 2027, we are already in the process of having our surveillance from the Cyber Accreditation Body to be ISO certified in just a couple of months. So the reason why that’s important for your viewers right now is it goes to the debate on what is the level of quality that I’m going to receive? Is that quality repeatable? And more importantly, is that level of quality going to be something that I can have and have a level of assurance that’s going to be legally defensible if ever called into question?
[00:31:43] Mike Hemmingsen: Yeah, see, this is why we need those accredited C3PAOs, definitely. You know, most suppliers are going to lean on a managed service provider, a managed security service provider, things of that nature. What do you watch for? What SLAs come into play? What is client responsibility versus, you know, assessor just showing up?
[00:32:10] Carter Schoenberg: Yeah. So while we are a certifying body, Koniag Cyber, we also have a fully managed offering that is actually independently certified at Level 2. So we have a great deal of knowledge and experience on being able to convey what an OSC should be looking for or understand what an assessor will be asking of them.
[00:32:31] Carter Schoenberg: So the very first thing that’s going to come into play when you have those initial scoping calls with a C3PAO is a term called a CRM, which stands for Client Responsibility Matrix. So think of this as more likely than not, it could be a SharePoint, it could be a spreadsheet, it could be a Microsoft Word document, but something that’s going to clearly show what, let’s say, the Acme company is your MSSP. What is the Acme company accepting responsibility for lock, stock, and barrel? And how is what they’re accepting responsibility for being aligned to the requirements in 800-171? And what are they advising are clearly the obligations of the system owner itself?
[00:33:21] Carter Schoenberg: The challenge that exists is, at least that I’ve seen with my experience, in many cases, those CRMs do not directly align with the service level agreement. Well, what’s the so what in that? The so what ultimately is the organization providing the services is predicated upon the service level agreement. So if the service level agreement in no way, shape, or form aligns or makes reference to holding them accountable to the CRM, an organization seeking certification could very easily get caught flat-footed with being in the middle of an assessment and saying, well, wait a second, your CRM says that. Well, your SLA doesn’t say that you do that. So it then kind of creates a quandary for the assessor on evaluating who’s actually telling the truth in this circumstance. And if anybody’s ever been involved in any type of audit, the moment an auditor sees a crack in the armor, it’s almost inevitable they’re going to dig deeper and deeper.
[00:34:26] Mike Hemmingsen: Yeah. Well, that’s definitely why we have organizations like Koniag Cyber and folks like you, Carter, to help us through this. I really appreciate you taking the time today to spend with our viewers and with myself. I got a long way and a lot to learn, so I got you to lean on, and I really appreciate that. If there’s any commentary or questions, obviously, you know, the best way to reach us is we’re on the website for Koniag Cyber or for Vervint.com. Reach out to us, ask your questions, and we’ll get an expert out to talk to you. Any kind of closing remarks for us to make sure that the team or for viewers listening, make sure that they leave with the right impression and right guidance.
[00:35:13] Carter Schoenberg: Yeah, certainly. So again, as Mike made reference to you, please don’t stand on ceremony. Please feel free to contact us with any comments, questions, or concerns that you may have as it applies to your pathway towards CMMC conformance. One thing that is going to be a benefit, especially if you are in the Detroit area, the very first conference that specializes in CMMC will be in Detroit at the Detroit Airport Marriott on August 25th and 26th. That’s going to be known as the CPARS tour, and it is being hosted by the ESP, which stands for External Service Provider Collective, which is a not-for-profit organization that directly collaborates with the Cyber Accreditation Body Engagement Forum.
[00:36:00] Mike Hemmingsen: Awesome. Well, I’m looking forward to that. It’s definitely on my calendar. Again, Carter, I really want to thank you for taking the time. I think we have one last question that came in, and I’d like to make sure that we get that answered for our viewer.
[00:36:16] Carter Schoenberg: Sure.
[00:36:18] Mike Hemmingsen: Can you see that question there?
[00:36:24] Carter Schoenberg: Is there a real risk for smaller family-owned suppliers? So one of the things as it comes down to, you know, that they can’t afford it.
[00:36:40] Mike Hemmingsen: Yep.
[00:37:32] Carter Schoenberg: That’s something that I’ve heard over a number of years. And the reality is, unfortunately, there’s really no data that supports such a claim. So I’m going to push back. I’m going to give guidance, but I’m going to push back. There’s absolutely no data to date that supports that. If you are a small business and let’s say that you are making a widget and that unit cost to the government is $1.13 per unit. As a result of these additional costs to be in conformance with these contractual obligations, we have not seen, nor can I point to any document of authority that says a company lost business because they had to increase the unit cost from $1.13 to, say, $1.26 to matriculate these costs across the board. That’s point one.
[00:38:14] Carter Schoenberg: Point two, these are contractual obligations. So upon award, these are things that can be cost deferred, or I should say cost reimbursable. And it’s my understanding as of recently, actually, Detroit, pardon me, the state of Michigan actually has grant funding issued by the state of Michigan with respect to cybersecurity and CMMC programs. So we will, and actually one of the individuals who represents that line of the business for the state of Michigan will actually be speaking at our conference on August 25th.
[00:38:34] Mike Hemmingsen: Excellent, great resource and super good reason to head down on the 25th and 26th to Detroit to get those details and get those introductions. One of our attendees saw on the website that we have free training. Can you walk us through what that entails?
[00:39:23] Carter Schoenberg: So with regards to free training on the website, can you please put up the actual link in question? What I can share is that at this event there will be free training, or I should say there will be training involved at the conference. There will be a speaker session and then there will actually be a half-day workshop for organizations seeking certification and a half-day workshop for external service providers, meaning MSPs and MSSPs, where they will be brought through live-fire exercises so they can really kind of better gauge what they think they know versus what they actually know. Not only learning from experienced practitioners like myself as a lead certified assessor, but also for learning from one another.
[00:39:45] Mike Hemmingsen: Awesome. Awesome. Well, Carter, again, I really want to thank you for taking the time to spend with us. Any of our listeners or viewers out there today, again, any questions, please feel free to reach out to Carter or myself. And thank you. Thank you so much, Carter. This is an important topic, and I’m glad we got to spend some time today on it.
[00:39:47] Carter Schoenberg: Thank you again for having me on today.
[00:39:47] Mike Hemmingsen: All right. Thank you, everyone, and have a great afternoon.