CMMC Level 2: Documentation, Costs, and Audit Readiness | Interview with Bruno Lecoq

Dejan Kosutic:

Welcome to Secure and Simple Podcast. In this podcast, we demystify cybersecurity governance compliance with various standards and regulations and other topics that are of interest for consultants, CISOs and other cybersecurity professionals. Hello, I'm Dejan Kosutic, the CEO at Advisera and the host of Secure and Simple Podcast. Today my guest is Bruno Lecoq and he's the Co Founder, CEO and CISO at BEMO. BEMO is a managed IT service provider for security and compliance.

Dejan Kosutic:

So BEMO as a company is already CMMC certified together with other standards like 27,001, SOC two and HIPAA. They're also working on ISO 42,001. And, basically, in today's podcast, you'll learn what are the best practices to comply with CMMC and also how to avoid most common problems. So welcome to the show, Bruno.

Bruno Lecoq:

Thank you. Thank you for having me.

Dejan Kosutic:

Great to have you here. So tell me, is this CMMC really relevant only for US companies or is this also relevant for companies outside of The United States?

Bruno Lecoq:

So for sure, CMMC is mainly for US company. But again, in the world of CMMC, the assessor that will assess your system, they are called C3PAO. Mhmm. And they already register some C3PAO outside of The US. So I know some I know some in Canada.

Bruno Lecoq:

I know some in South Korea. So, again, it's starting to go outside The US. So because of that, my assumption is, I guess, some other company will outside The US can be compliant. But, again, the number one thing is really for company doing business with the Department of Defense.

Dejan Kosutic:

US Department of Defense. Right?

Bruno Lecoq:

Yes.

Dejan Kosutic:

Yes. Yeah. Okay. But there are many suppliers to US Department of Defense from other countries like, okay, South Korea or probably from NATO countries, from Europe and so on.

Bruno Lecoq:

Exactly. Exactly.

Dejan Kosutic:

Yeah. Okay. Very good. Okay. Just for our listeners who are not very familiar with the CMMC, can you tell me a little bit about the basics of CMMC?

Dejan Kosutic:

So, basically, who needs to comply? What are these levels? What are the deadlines?

Bruno Lecoq:

So so I guess from where we are now, so if you think, I will go back in the last so since 2013, you are supposed to as a contractor for the US Department of Defense, you are supposed to self attest. So again, it's based on NIST 807 '71, and you are supposed every year to do the self attest assessment and upload your score. And I guess the US government has realized, you know, that, you know, many people will self attest, but they are not really secure. So they cannot, you know, create CMMC and made it mandatory. So by this November, this coming November, that the now your contractor, so depending on which agency you work with, may ask you to be CMMC compliant by this November.

Bruno Lecoq:

So today, again, the number that, you know, I hear is there is about 200,000 contractors in The US, and as of right now, only 3,000 are CMMC level two compliant. So it's kind of the of the level of the story. So, again, out of that CMMC, it's not that it's not only a 90. Again, it covers HR from onboarding, offboarding. There's operations.

Bruno Lecoq:

So 80% from my perspective, 80% is IT, 20% is non IT. Okay? And the 3CPAO, a federal agency, will come and assess your system, and then will give you your grade out of 110 and they will be the one uploading the score to the US department website.

Dejan Kosutic:

Okay. So if I understood the well, Level two, right, Level two CMMC is where this C3PAO actually needs to come in and actually certify a company, whereas Level one is still self assessed, right? Correct. Yeah, okay. And there is also a Level three, right?

Dejan Kosutic:

But this is very rare.

Bruno Lecoq:

Reward three is coming. It's still in development. So again, you can see the SELFAT test, but at the end it's Yes. So again, Level three will really be the big guys, the Lockheed Martin, the really the

Dejan Kosutic:

Now what distinguishes the level one and two?

Bruno Lecoq:

So the difference is as soon as you have to deal with CUI, again, so as soon as you have CUI, you have to be level two.

Dejan Kosutic:

Okay. So CUI stands for let me see. I have my notes here. CUI stands for Controlled Unclassified Information. Right?

Bruno Lecoq:

Correct.

Dejan Kosutic:

Okay. And level one is only federal contract.

Bruno Lecoq:

It's only federal.

Dejan Kosutic:

Yes, FCI. Okay, good. Very good.

Bruno Lecoq:

So most, again, I think most I can see from our customer, most of the customer now what we have is Level two in the world of CFMC. A few of them are Level one.

Dejan Kosutic:

Okay. And you mentioned the number of what, 200,000? So it's a huge number. I mean, it's really...

Bruno Lecoq:

It's a huge number. And it's going to be interesting what happened in November, because again, at the end of the day, one and maybe 2% of the base will be there. So, again, I'm very curious to see what the US government is going to do.

Dejan Kosutic:

Okay. Now, let's speak a little bit about this assessor, right, the C3PAOs. So, how many actually of these assessors are worldwide or in The US at least?

Bruno Lecoq:

To my knowledge, because I I attend. So the CMMC program is managed by a group called Cyber AB, and they do a monthly meeting. So they're the other one releasing the number. And to my last meeting, it was 93 C3PAO registered.

Dejan Kosutic:

I mean, how are going to, you know, these 100 C3PAOs, how are they going to kind of swallow 200,000?

Bruno Lecoq:

What's very interesting today is, again, I talked with many of them, and the issue is there is so it looks like there's not enough bandwidth, but right now, when company come to them, they don't even pass phase one. So again, from phase one, you have to set what are the boundaries of your COI, how you present, and they come to the first meeting and they already rejected because the people don't have their documentation together. They don't have their the basic together. They cannot even move forward. So there is a huge so the numbers that,

Bruno Lecoq:

I know, was told by Cyber AB is about 87% of the people don't pass phase one. So they are not prepped because many people think CMMC is IT, and those companies will be IT. But it's, you know, I I would give an example from a BEMO perspective. So in order for us to be CMMC We have 29 policies. Uh-huh. We we have 46 procedure. Mhmm. We have 14 configuration document and more than 700 evidence.

Bruno Lecoq:

Mhmm. And what was interesting, so we demo, we did a mock. So to explain for a mock is you your assessor is kind of they will assess you, but it doesn't count against your score. Mhmm. And so they're able to do this kind of a a free test.

Bruno Lecoq:

You can do it's not free because you have to pay the new test.

Bruno Lecoq:

We, at 100% from an IT perspective, but they find five errors, and the five errors were in documentation. So Uh-huh. I will give an example. We, BEMO, we are we use passkey. We don't use password.

Bruno Lecoq:

But because we have pass we have passkey, we need to have password as backup. And within our procedure, our procedure said our minimum characters for the password was 14 digit. Mhmm. Okay. Four 14 characters.

Bruno Lecoq:

When we go to the procedure so within our system, because you have to show the c three p o live, so you go to the configuration and you show it was 14. But in our policy, it was written 12. Okay? Because of that boom, we lost five points. If we would have done a mock, we wouldn't have passed.

Bruno Lecoq:

Yeah. And you're like, wow. You know, it took us two minutes to fix. But it's just just too short that, again, it's not only it's not only that.

Dejan Kosutic:

Mhmm. Okay. So do these assessors, I mean, C3PAOs do they have these stages like in ISO 27,000 certification? Like, first stage is a a documentation review and then the second one is the main audit?

Bruno Lecoq:

So on average, so they have a phase one. So the phase one is to assess your boundaries. So, again because the main thing is you have to have CUI. If you don't have CUI, you cannot do a same in c level two.

Bruno Lecoq:

So you have CUI. So the idea is you present, how are you going to protect your CUI? Where are your CUI in your system? So you present that. Then you meet with your C3PO and they will say, okay.

Bruno Lecoq:

Yes. We understand your system. We think your strategy is good. Great. We can go to phase two, and phase two is the assessment.

Dejan Kosutic:

Yeah, the main audit where they find evidence, right?

Bruno Lecoq:

And then the audit, yes. And again, and after the audit, then there is a report. So it's kind of the

Dejan Kosutic:

Yeah, so it's very similar to other, let's say ISO certification, yeah. Okay. And okay. So as you mentioned, most companies have problems with the documentation and you mentioned that you have written, what, around a 100 documents, if I calculated correctly.

Bruno Lecoq:

Well, anyway, if I if if I look at it, even our SSPs so we have our SSPs 300 pages long. Okay? So 300 so I'm sorry. I'm saying we are pages? 300 pages.

Dejan Kosutic:

300 pages for SSPs or CSP plan. Right?

Bruno Lecoq:

Yes. Yes.

Dejan Kosutic:

Wow. It's quite long.

Bruno Lecoq:

Yes. And So Mhmm. The the I think the challenge that we had, and I see with our customers, is making sure that all document they they cross reference correctly.

Bruno Lecoq:

You know? And your evidence because I also think for people, don't understand. Same MCs always say, being same MCs like having a baby. Okay? You you certify you are certified with your baby, but you still have to deal at least with the baby for eighteen years.

Bruno Lecoq:

Same thing with compliance with CMMC. You have to do your monthly audit, your monthly, you know, it's still work after the certification.

Dejan Kosutic:

So what do you see as the biggest challenge beyond the documentation for companies? Is this, let's say, maintenance, these regular audits?

Bruno Lecoq:

Yeah, I think it's for me, CMMC is not an IT project, it's a company project and it's a way of life. So if I go back if I go back in time, you know, ten years ago, any IT admin were global admin on the system. Mhmm. Then came PIM. So now you're an admin, and you have to race.

Bruno Lecoq:

And I think now, I take I take BEMO, is everything starts with a ticket. Mhmm. I wanna do something. I open a ticket. Why am I doing that?

Bruno Lecoq:

There is a ticket. You you know, it's approved. You know? You do the work, and then you close it. So I think it's kind of the evolution that I see.

Bruno Lecoq:

So it's a looking at it now, I would not wanna run the IT or BEMO any other way because because I think, again, I think this is a very good framework, and that you know? I think it's very good what we get by, again, by reviewing monthly and quarterly. But it's a mind shift. It's a mindset and a mind shift of how you will run your company.

Dejan Kosutic:

So, you saying that when introducing CMMC companies actually what exactly companies need to, let's say, change?

Bruno Lecoq:

No. So this is what I always find very interesting because by default, all those companies have sent sent a test for the last thirteen years. So they were supposed to just do it. So if I found a company, I should be able to go to my c three PEO with no changes and do it.

Bruno Lecoq:

So when I see companies saying, woah. This is will cost me more money and more work. And you are like, woah. So what have you been doing the last thirteen years? I when when I look at your score, you are telling me you have a 110 or 110.

Bruno Lecoq:

So, again, it's a company should have been again, I should have my recommendation up to date. I should do my the review of my controls every month, every quarter, depending on the controls. And I should have my my poem, you know, up to date. So, again, it's a you know, I signed up. I should have done it.

Bruno Lecoq:

So it should be nothing new.

Dejan Kosutic:

Okay, I mean, but this is, let's say, for companies that already declared as being CMMC compliant in the past, right? But if a company is, let's say, going for the CMMC for the first time, what is kind of the biggest change that they have to introduce in their, let's say, operations?

Bruno Lecoq:

I think for again, from an operation, I think the biggest change from a so I will give you two examples. So from a NetSharp perspective, so Mhmm. I think from a NetSharp perspective, even we've been able to change. We if we hire a so you hire an employee. Mhmm.

Bruno Lecoq:

The first thing is the HR person does a background check.

Bruno Lecoq:

And as soon as the background check is done, our HR person will open a ticket. Mhmm. That will come to me as a CISO and say, hey. I'm really we are ready to create this account or this person. This person has a background check.

Bruno Lecoq:

Mhmm. I will say, Approve. Go create the account. The IT person create the account, and then we create the account. And then the employee will go through a training first.

Bruno Lecoq:

We'll go through a training before the account is granted.

Bruno Lecoq:

Okay. If you if need it when before, well, my sharp person will do the background check. We'll go to the IT person. He will create the account. The person is in, and the person will do training after.

Bruno Lecoq:

So, yeah, this is a change that we have to do. Now if I go from a a 90 perspective, I have you know, there's 110 control for 320 AOS, and I have to I have about 66. Like, on the monthly review, we review 66 AOS every month, making sure, you know, I and so, again, one of them is I go check through the logs. I go check, you know, my end trial, my preview. So there's a lot of thing that I need to check-in, make sure that there is no issue.

Bruno Lecoq:

Only days an issue, a ticket is open. And, you know, so it's yeah. And so an auditor can just go through with you every month what has been done, what the issue you encounter. Okay. How long was this issue up?

Dejan Kosutic:

Mhmm. So if I understood well, the biggest change is on one hand documented documenting every everything. I mean, let's say, through tickets and and making sure that you kind of make a record of everything that you're doing. It's

Bruno Lecoq:

it's you have to prove to someone's needs outside. It's not just now UI, know, ITT.

Dejan Kosutic:

Okay. Yeah. That's interesting.

Dejan Kosutic:

Okay. And if I understood well, this CMMC is really basically, at least at level two, is about implementing NIST standard SP eight hundred-one 171. Correct? So can we then say that basically CMMC is like an auditing standard, which actually helps 3CPO audit the companies? And because I'm just trying to understand what is basically the the difference between CMMC and this NIST 171?

Bruno Lecoq:

Yeah. I think it's, you know, the NIST, you know, the pure NIST will be the IT. And for me, what I see is on top of CMMC, they have added some, again, non IT controls, you know, like I say, HR and stuff like that, wrapped it, and the c two p o will use it for as a audit.

Dejan Kosutic:

Okay. But so are all the controls actually described in an EAST one seventy one or are there some addition?

Bruno Lecoq:

No. They are.

Dejan Kosutic:

They are. Okay. So there are no additional controls in CMMC. Right? No.

Dejan Kosutic:

Okay. Yeah. So, okay. So CMMC is basically a framework for C3PAOs, right, to kind of assess if the company is compliant, right? Yes.

Dejan Kosutic:

Okay. So when a company is implementing CMMC and this NIST eight hundred-one 171, so what do you see as the from your experience working with your clients, what do you see as the most, let's say, the best, most appropriate steps actually for a company to become compliant?

Bruno Lecoq:

So I can tell you, so we see just from our call number one, from a presale perspective, when a company come to BEMO, we know all of call number one if if the company will be successful or how long it will take them. And that's very interesting. And so for me, a successful company is someone on a c suite come with the IT person and said, hey. As a company, we need to be CMMC. We would like to know, you know, can you help us getting there?

Bruno Lecoq:

When it's only the IT person coming, very often, it takes forever because, again, it's a, you know, poor IT team. Someone told them, go do it. They go do it, but it's not only IT.

Dejan Kosutic:

And this poor guy will will, you know, lose a huge amount of time actually without achieving...

Bruno Lecoq:

Amount of time and just, you know, he is running and he's realizing that he needs help outside of IT, but the person the people were told by the leadership team, you need to play with them. We as a company need to be CMMC.

Dejan Kosutic:

Mhmm. Yeah. Okay. So one of the obviously preconditions is that what? You have a project team with included both IT and business side, if I understood well?

Bruno Lecoq:

Yes.

Dejan Kosutic:

Okay. And then once you have a project team in place, what kind of, let's say, stages you have in a project or what kind of steps do you have?

Bruno Lecoq:

So from our perspective, we do so we do thing in parallel. So we have two thing in parallel. One is from an IT security. So, again, how do we how do we make sure the 110 control are configured correctly? This is one.

Bruno Lecoq:

And while in parallel, you work on your policies and procedures. So again, two things goes, you know, in parallel for us to and per our schedule to meet and be completed at the time prior to the audit.

Dejan Kosutic:

Mhmm. Mhmm. Okay. If I understood well, there is also some kind of an assessment that the company needs to do itself. Is this, let's say, similar to internal audits in twenty seven thousand and one or

Bruno Lecoq:

Yeah, you still have to do an internal audit too.

Dejan Kosutic:

Okay, so it's a similar concept there.

Bruno Lecoq:

System is a serial concept.

Dejan Kosutic:

Okay, and regarding documentation, so you mentioned that your company went for, again, for these roughly 100 documents. Is it really mandatory that all companies have that big amount of, let's say, policies and procedures and guidances, or is this more flexible?

Bruno Lecoq:

Every company, again, so when we did, when we first did for us, so this what we what was interesting when you go to the so once we have the the audit so the audit is you need to have the c three p o, need to have three auditor online. So you're online. So it's, again, it's shared. They they come, you share the screen. They screen it on the other side, and they go through control by controls.

Bruno Lecoq:

They go even from arrows by arrows, and it always start by, this is my policy for this control. Okay. This is how I make sure policy. This is how we have our procedure. How do we make sure we do it?

Bruno Lecoq:

And now let me show you. So to show you can be live in a you know, I can be on Max of Entra or I could be via a screenshot. So it's live. You have to demonstrate. So so everything you do, you know and so for a full week, you know, so, you know, to five, you know, whole week with the answer, and you go through every single one for the same process.

Dejan Kosutic:

So Okay.

Bruno Lecoq:

We use every policies and procedure as part of it. From all our customers, we make them do the same thing and they are able to pass. At least we have seen a winning from our perspective, winning strategy.

Dejan Kosutic:

Okay. If understood well in this NIST 171 standard, are what, 110 requirements, if understand well.

Bruno Lecoq:

110 control.

Dejan Kosutic:

Okay. So are you saying that for each control you would have a separate document or?

Bruno Lecoq:

No. No. You have you have some control that depending on the control. One control can like, one policy may may work on 10 controls. Mhmm.

Bruno Lecoq:

And so it's not one policy. We have 29 policy for 110 controls. So it's, you know and so some control can, you know, are broad.

Bruno Lecoq:

So it's not one to one.

Dejan Kosutic:

Okay. And when the assessors are looking for evidence, are they basically looking into, let's say, records or logs of your CISOs?

Bruno Lecoq:

Oh, yes. They ask us so. You know, of course, we have to take them. Okay. I think what I see with when I compare with ISO, I think in ISO, the assessor by default is trust you.

Bruno Lecoq:

Oh, yes. We do that. We do that. We do that. I see in same MCs.

Bruno Lecoq:

I don't trust you. You show me. So the difference is now we go in our ticketing system. Let me show you, you know, can you show me the off boarding of an employee? Okay.

Bruno Lecoq:

Show me the last one. Okay. You go through the ticketing system. You can go through the line. Okay.

Bruno Lecoq:

I can see. Yes. You know? So it's not you cannot just say, oh, we do it. No.

Bruno Lecoq:

No. Show me how you do it. So it's think it's a big difference between for me the ISO and CMMC.

Dejan Kosutic:

Yep. I mean, but ISO 27,000 certification bodies should do the same. Right? They should also check the records.

Bruno Lecoq:

Yeah. But I I have I have felt like the the bar is lower, at least my perspective.

Bruno Lecoq:

I think, like, SOC two is the bottom one, I think. Middle one would be ISO and CMMC is the both former.

Dejan Kosutic:

That's interesting. Yeah. So from your perspective, again, you're helping companies beyond, let's say, having the right people in the project, beyond having the right documentation, what else is needed for success and to run this project in some reasonable amount of time?

Bruno Lecoq:

I think if you have a commitment from the leadership team, you have a knowledgeable IT person, you know, I think, you know, at at the end of the day, it's not rocket science. You know? It's just again, it's a so from an IT perspective, it it also depends where you start from. So, again, there's some customer that will come. They are on Microsoft commercial, Office three sixty five commercial.

Bruno Lecoq:

Mhmm. And, oh, we have to move them to GCC or GCC High. So in that case, oh, you have a migration first.

Dejan Kosutic:

Oh, yeah.

Bruno Lecoq:

And all you have companies that will say, hey. We have both business in my company. We do commercial and government.

Dejan Kosutic:

Mhmm.

Bruno Lecoq:

So, you know, so sometimes we will leave them on commercial, but we create an an AVD enclave. So for people doing, you know, government, they can just go to this enclave. So depending on every business, it depends on the boundary of your CUI. K? What type of CUI do you deal with?

Bruno Lecoq:

What the quantity? How do you do you receive them, do you modify? So there's a lot of questions based on that, how do you protect it?

Dejan Kosutic:

Okay. From what I understood, there is a lot of, let's say, unclarity about the scope really of the implementation. So how do companies actually define the clear scope for CMMC certification?

Bruno Lecoq:

I think the from the scope is always so we don't have to think about, okay, first is, again, the CUI. Do what do you create? So do you create like, do you create CUI or do you just receive you just receive CUI, do nothing? So there is a so, again, it goes back to, oh, I have this CUI. What is life cycle within your company?

Bruno Lecoq:

Do you share it across other company or it's just for you? It's just you know? So based on that, will it go through your email system? Will it go through third party system? Again, it's kind of what's the life cycle of your CUI?

Dejan Kosutic:

In other words, companies should have, let's say, first of all, clear asset management to have clear view of And what assets they on the other hand, processes, right? Yes.

Bruno Lecoq:

Without That's why it goes back to, you know, one of the an assessed list is one of the requirement that you have to have. So, again, if you so and now how do you manage your assets? How do you keep it up to date? You know?

Bruno Lecoq:

Yeah. This is one. Then do you have a workflow about your CUI? For very often companies, they don't. You know, it's in the head of someone and, okay, you go.

Bruno Lecoq:

So and and it's why because of that, it's never the same not every company protect the CUI the same way or has to protect it the same way.

Dejan Kosutic:

Okay. You mentioned also this SSP, right? The system security plan. So why is it so lengthy and why is it so important?

Bruno Lecoq:

Oh, I figured the end from the audit perspective, when is the audit, they only use your SSP. So, like, you they take your SSP and you go through them, you know, pretty much page by page, and they will go. So in our case, you know, section one, section two is all around CUI boundaries. You know? You have a section that is your 110 control with the 320 AOS.

Bruno Lecoq:

And, again, they go through you know, you you share the screen, and it's okay. Now control three point one point one. Okay. Let's you know, how do you do that? 3102, 3 so you go through every single you know?

Bruno Lecoq:

And then what we include as part of it, again, you include also all your your documents. So, again, network diagram, CUI flows, so it's all there. And you also have your roles and responsibility metrics. So, again, between what is, for example, BEMO doing for the company and for the company and what is Microsoft doing. Again, Microsoft has some role.

Bruno Lecoq:

You us BEMO as the MSSP have a role and you as a client as a role. So it's all defined so that when you discuss with the c three p o, this is how we do the control. It's okay. This is what Microsoft does. This is what BEMO does.

Bruno Lecoq:

And this is what yeah.

Dejan Kosutic:

Okay. And how does this document differ from, let's say, the statement of applicability from ISO 27,001? Is there any, let's say, similarity between these two documents or it is very different?

Bruno Lecoq:

So I will say some some part are similar, but at the end, it's yeah. You know, from an ISO perspective, document is not that big. It's a lot smaller. So there is not I think what makes it longer is because the three the three hundred three hundred twenty a o's, you know, again, it's a very detailed. So it's what, you know, at the end is, other than 300 pages, pretty much 200 pages are wrong, that document, you know?

Bruno Lecoq:

So you don't have that in the ISO world.

Dejan Kosutic:

Yeah. Yeah. Okay. Okay. Good.

Dejan Kosutic:

But if I understood well, this security plan does actually overview give them give an overview of all the controls. Right?

Bruno Lecoq:

Oh, yes.

Dejan Kosutic:

Yes. Okay. Yeah. In that regards, it it's kind of slightly...

Bruno Lecoq:

When you go to the audit, because we did both the first time with I am we forgot we sent the SSP non was not signed. Boom. First first meeting, poof. Yeah. Yeah.

Bruno Lecoq:

Yeah. We learn also, you know, make sure it's signed, you know, so, you know, it's kind of a Mhmm.

Dejan Kosutic:

Okay. And so the the what is, let's say, the role of training in when you implement CMMC? So do you need to have professionals who are trained for CMMC or this is not the case? So how does it work for CMMC?

Bruno Lecoq:

So training from which perspective?

Dejan Kosutic:

Do they need to have a specific certificate, CMMC certificate actually to, you know, run CMMC program or implement CMMC?

Bruno Lecoq:

No. I think, again, like I said, CMMC is managed by Cyber AB. Cyber AB offers certification. So I think for company, if they want, I think I will say it may be a good idea for you to go tender training. So then when you start when you will start implementing CMMC, you may have a better understanding what is expected of you, but it's not required.

Dejan Kosutic:

Okay. Okay. Understood. Understood. Okay.

Dejan Kosutic:

Now, how does CMMC or I mean, NIST one hundred seventy one, how does it treat subcontractors? Right? So if a company is directly a contractor of the Department of Defense, what happens to the subcontractors of this of this first level contractor?

Bruno Lecoq:

So every agency is different. So it going it will go to you know, one agency will say, I want everyone or my sub and subcontractor to be seven c level two. Some may say, you don't need to. Again, It's all. So it's not a blanket of everyone.

Bruno Lecoq:

It depends. So for every customer that we have, we ask them, hey. Per your contract, what does your contract what does your agency in contract require? And based on that, you follow it. So it's it's starting from there, from the contract that you signed.

Dejan Kosutic:

Okay, okay. So it's not from the standard to the buyer actually defines how this Yes. Okay. And so if I understood well, then an agency can require that a subcontractor is also CMMC compliant, right?

Bruno Lecoq:

Yes. Okay. And for us, same thing. So the thing what is interesting, so with many of our customers where the agents so some agency will say, by November, we are fine if you are self CMMC self attest.

Bruno Lecoq:

Whereas some agency will say, no. You need it you need to be by November. Or even some may say, need to be by July. So it depends on you know?

Dejan Kosutic:

Mhmm. Okay. Now, you mentioned when we corresponded earlier, you basically said the biggest gap is aligning business velocity with security rigor, not technical controls. So what exactly do you mean by this?

Bruno Lecoq:

I think it's a what what I've seen is I have many customer that come in, again, they want a piece of paper. They just think, give me my certification. And it it is the same for CMMC, but it's the same for software ISO. When a company said, I want how fast can you make me there? And you're always like, okay.

Bruno Lecoq:

For me, you always start from the wrong perspective. If you start by that, you will have a tough time. You know? So, yes, to it it's more like, well, I have a company. I wanna make sure that my data, you know, it's it's secure.

Bruno Lecoq:

I wanna make I want to have someone that come outside to prove to me or at least, you know, look at my system and give it, you know, tell me, oh, this is where you fail and where you are good. So it start from a business need. So it start from as a business, do you need to be CLMC? Because, again, it costs you it costs money, and I always tell people compliance is expensive. If you don't need to go there, don't go there because once you start, you cannot stop.

Bruno Lecoq:

You have to. So it's it's also why you start from a business. Why do you need compliance? And do you really need it?

Bruno Lecoq:

And then if you need it, understand as a business leader and business team, your life will change. It's that's it. It's a you know? Once you accept that, then you can move down from an IT, but it's all so it's why I always emphasize the the need of the leadership team to understand what compliance mean to them.

Dejan Kosutic:

And of course, the leadership needs I mean, there needs to be a business reason for a company to go for compliance. Otherwise, it doesn't make sense really. But this part that you were saying, you know, security rigor versus technical control. So what do you actually mean by security rigor, which is not directly I mean, which is not Yeah. The same thing?

Bruno Lecoq:

Because I think there is there is for me a difference between, you know, as part of the compliance. You know, you are supposed to check your log. You are supposed to check and it's a and independent if you are compliant or not, you should be doing it. You know? It's it's not just, you know, you but you'll be surprised how many people don't.

Bruno Lecoq:

You know? And I think, again, it's so it goes back to how as if you are the CISO of a company, what is your belief? How do you, know, how do you manage your security internally outside of compliance?

Bruno Lecoq:

So if you are doing correctly, compliance come with needs and you will realize, woah. I'm pretty much doing what needs tell me I should be doing. I may tweak it versus, woah. I am doing nothing of what needs required. Woah.

Bruno Lecoq:

So, again, it's where is your security level? Where is your practice? Know?

Dejan Kosutic:

Mhmm. Mhmm. Yeah. And it's interesting. I mean, for example, in twenty seven thousand and one, which is a risk based standard, it does really allow you to kind of determine the level of security that you need, right?

Dejan Kosutic:

And which is, I would say, pretty flexible, suits, I would say, most of the companies. And does it work actually in the same way for CMMC? So is I mean, is CMMC it, also risk based or is it more predefined through this list of controls?

Bruno Lecoq:

Oh, you know, even my source, it's it's funny you're asking that because for me, see that if I take a c three p a o, again, at the end, it's still the human can still make you know, when you read how would I be assessed against that, it's not always a clear cut. And sometimes you can have a lot of conversation with c three p o. No. No. I'm I'm compliant.

Bruno Lecoq:

No. You are not. And you go you know, it's not just very simple on saying you have it or you don't. You know? Mhmm.

Bruno Lecoq:

So so so that's why they see this flexibility of again, the c three p o will not tell you how to do it. You will just have to show them the output they wanna see, independent on how, you know, how you have implemented. So you still have flexibility on the how, how you want, you know, how much security as, you know.

Dejan Kosutic:

Okay. Which, I mean, does make sense. When I connect it to the thing that we spoke about earlier, you know, if there is such a flexibility, then it's easier to integrate these security into into these regular operations, which which is then obviously much, much better for a company. Okay. I heard that So

Bruno Lecoq:

I'll come back and we'll do here. One thing that I see here, it all also depends if you have to be, for example so we have customer that do they have to be ITAR compliant. So, again, very, you know, very first, so, you know, as as you you have to export, you know, so which mean you have to be on GCCI. And beyond GCCI now, you can only use systems, you know, most of the system that are FedRAMP compliant. So I have seen customers that will come, they were on Microsoft commercial with, you know, SaaS system that come out, and now we tell them we have to migrate you to GCCI.

Bruno Lecoq:

Oh, well, but you cannot use this tool and this tool and this tool because they will not pass a note. They are not compliant from the government perspective. So this is the part that people have to think that depending on the level of, you know, do you have to be on GCC or GCCI? It may change your system depending on what, you know, what you start from.

Dejan Kosutic:

Mhmm. So if I understood well companies that want to be compliant with CMMC, also, is a kind of list of allowed or not allowed tools or or systems that they can use. It's very important. Yeah. Similar thing is coming in Europe with the EASE two and and Dora.

Dejan Kosutic:

Basically, it's it's also yeah. Okay. Okay. Very well. So I heard that CMMC is very expensive.

Dejan Kosutic:

Right? So is it true, I mean, that certification or these assessments are very, very expensive?

Bruno Lecoq:

So on average, C3PAO will charge today between 45,000 to $55,000 for an audit.

Dejan Kosutic:

Even for smaller companies. Right?

Bruno Lecoq:

I think it's why it depends on size. We, BEMO, we only do company from 10 user to a thousand users. So we do what we call SMB, small business.

Bruno Lecoq:

So for the size of client that we do, it's about the range that we see, you know, 45 to 55. If you wanna do a mock, which, again, I will tell everyone, you do a mock because, again, this is the you know, test it's an extra 10,000 on average. So it's kind of on average your pricing from that. Mhmm. The rest after that, again, is from a perspective of self if I'm an existing company, I have self attest.

Bruno Lecoq:

I I should have already the people in place to do If I am a new if I'm a new business, at the minimum, you you need to have an IT person, and you have to have someone that will run compliance. It's kind of, for me, the two roles that you have to have by default.

Dejan Kosutic:

Yeah. And that you need to have the budget for these kind of things. By the way, this is much more expensive than ISO certifications. ISO certifications start from, I think, something like 10 k in The US. For very small companies, okay.

Dejan Kosutic:

They obviously go much higher for larger ones.

Bruno Lecoq:

It's one thing. It I think it's also more expensive because again, it's a lot more, again, from a when you are going to be one week with three assessor online looking at your system, again, it's a

Dejan Kosutic:

Pretty intense, yeah.

Bruno Lecoq:

It's very intense. It's intense, it's a slab. You you you can see you can see the company that can handle stress.

Dejan Kosutic:

I can imagine. Yeah. Okay. So let's wrap up the call. So what would you say are the three most important things companies need to keep in mind when going for CMMC?

Bruno Lecoq:

So to summarize, again, I mentioned leadership team buying number one. Again, it's another 90 project. It's a company project. This will be one. The the second from a IT perspective is, again, it depends where you start from.

Bruno Lecoq:

You know, if you already you have a great IT system, it could go as fast as three months. But I see on average, us on average company, it take nine nine month to a year to get it. So when someone say, hey, Bruno. You know, we enjoy. Can I be compliant in November?

Bruno Lecoq:

It's always like, woah. Not not many. Where do you start from? You know? And after one call, you realize where they are and you say no.

Bruno Lecoq:

So then they will, you know, say, okay. Let me find someone that will make me by November. So okay. So this would be number two. And number three is once you are compliant, you have to keep the compliance.

Bruno Lecoq:

Again, I think it's almost more work post compliance than pre compliance.

Dejan Kosutic:

Okay, great. Thanks for these insights, Bruno. It's been a pleasure talking to

Bruno Lecoq:

Thank you. And thank you for having me.

Dejan Kosutic:

Thanks again. And thanks. Thank you everyone for listening or watching this podcast and see you again in two weeks time in our new episode of Secure and Simple Podcast. Thanks for making it this far in today's episode of Secure and Simple podcast. Here's some useful info for consultants and other professionals who do cybersecurity governance and compliance for a living.

Dejan Kosutic:

On Advisera website, you can check out various tools that can help your business. For example, Conformio software enables you to streamline and scale ISO 27,001 implementation and maintenance for your clients. White label documentation toolkits for NIS2, DORA, ISO 27,001 and other ISO standards enable you to create all the required documents for your clients. Accredited Lead Auditor and Lead Implementer courses for various standards and frameworks enable you to show your expertise to potential clients. And a learning management system called Company Training Academy with numerous videos for NIS2, DORA, ISO 27,001 and other frameworks enable you to organize training and awareness programs for your clients workforce.

Dejan Kosutic:

Check out the links in the description below for more information. If you like this podcast please give it a thumbs up, it helps us with better ranking and I would also appreciate if you share it with your colleagues. That's it for today, stay safe!

Creators and Guests

person
Host
Dejan Kosutic
CEO at Advisera & Cybersecurity governance expert
CMMC Level 2: Documentation, Costs, and Audit Readiness | Interview with Bruno Lecoq
Broadcast by