CYBERSECURITY
JUST IN: Assessors Report Contract Cancellations, Layoffs After CMMC Pause
By Stew Magnuson
iStock illustration
AUGUSTA, Georgia — Third-party assessment firms are laying off employees and seeing contracts cancelled as a result of the Pentagon pausing the controversial Cybersecurity Maturity Model Certification program for 60 days to carry out a reassessment.
The Defense Department on July 13 announced a 60-day suspension of the program's Phase II requirements, which would have introduced in applicable Pentagon solicitations the condition that companies receive Level 2 certification via a certified third-party assessor starting on Nov. 10. Failing to achieve this status would mean a business could not compete for contracts that contained this requirement.
The pause is already sparking layoffs at the some 100-plus assessment organizations and defense firms to cancel contracts for previously scheduled assessments, said Fernando Machado, managing principal and chief information security officer at Cybersec Investments.
At least temporarily, the pause is driving assessment costs up, he said. Like anything else, more volume of business drives down costs.
The third-party assessors pushed back on the notion put forth by the Small Business Administration that gaining the Level 2 certification was going to cost more than $500,000.
“What was happening was a lot of organizations were conflating the cost of implementation and readiness with the cost of assessment,” Machado said.
These are separate costs, and the cybersecurity protections must be done anyway, he said. Cybersec Investments' assessment fees for small businesses are under $100,000, he said.
The small businesses that hadn’t taken any action to implement the department's cybersecurity requirements were going to the government and complaining that they would now incur costs of up to half a million dollars, the figure cited by the Small Business Administration, he said.
“Those [implementation] costs should have already been incurred,” he said.
Machado also pushed back on the notion that there weren’t enough third-party assessors to conduct the Level 2 certifications. It is true that there are now 111 such firms for the more than 100,000 companies that need Level 2 certification, but among the cybersecurity firms are some 3,200 individuals who can conduct the assessment, he added.
“I think I can speak for everyone here … that none of us have ever had to turn a contractor away because we didn’t have enough assessors,” Machado said.
Daniel Turissini, a third-party assessor and chair of AFCEA’s Homeland Security Committee, said: “This pause is going to make it very hard to keep costs down because there has been a lot of cancellations over the past couple of weeks. Now, I think that will level out.”
Prices were coming down when the pause was implemented, he said, adding that his estimate was $30,000 to $70,000 for small businesses, which could be spread out over three years.
One workshop participant said the assessment fees and the operational costs for small businesses under 20 people will drive them under.
“For a small business — I would say anyone under 20 people — the operational costs don’t necessarily equal out to the contract revenue value. And like a lot of small businesses, we are going to wind up going under because we can’t support the cost of assessments and the operational end,” the participant said.
Machado said operational cybersecurity expenditures are allowable costs under a contract. The only extra cost should be the assessor fee.
Small and medium-sized businesses should continue to work toward Level 2 certification because the large prime contractors many of them work with are demanding it, Machado said. He showed letters from Boeing, L3Harris, Elbit Systems of America and Leonardo DRS sent to subcontractors warning them they they would not continue working with them if they are not certified.
“If you’re not certified, they simply won’t do business with you,” he said.
Turissini said there was an increase in assessments over the past year because the primes were pushing for them. They are not going to risk their business with subcontractors who have only done a Level 1 or Level 2 self-assessment, he added.
Ali Pabrai, CEO of ecfirst, said: “The pause is actually an opportunity for organizations to leap ahead and to build that resilience and mitigate that risk” of having data stolen.
Topics: Defense Department, Industrial Base