Table of contents
This blog post should not exist, but it does due to an unfortunate reality: Many large prime defense contractors are attempting to impose CMMC Level 2 audit requirements on subcontractors that do not handle Controlled Unclassified Information (CUI). Defense subcontractors that do not handle CUI should only be subject to CMMC Level 1 self-assessment requirements. This leaves subcontractors with a difficult choice between pushing back on the unnecessary requirements from upstream contractors or wasting the resources to implement and audit compliance with CMMC Level 2 requirements that should not apply.
Contractors that choose to “check the box” to win contracts, rather than pushing back on unnecessary requirements, will find themselves building a CMMC enclave (the vault) that will likely never actually handle the CUI it was designed to safeguard (the treasure). This post will help subcontractors understand the easiest path to gain a CMMC Level 2 C3PAO certification when they are not handling CUI and therefore have no treasure to safeguard.
This post will cover:
- How CMMC levels are supposed to apply to subcontractors
- How subcontractors end up with unnecessary CMMC Level 2 requirements and what can be done about it
- Basic principles for CMMC scope and how to design a CUI enclave
- Recommendations for simple enclave designs that can be implemented by subcontractors that do not expect to handle CUI
- How subcontractors should handle Federal Contract Information (FCI) regardless of their approach to CUI
Overview
According to the official government CMMC requirements, a contractor should only insert CMMC Level 2 requirements in a subcontract if the upstream contractor will flow CUI down to the subcontractor as part of that specific contract. Furthermore, CMMC Level 2 C3PAO audit requirements are supposed to be limited to subcontracts that involve handlingCUI under a prime contract with Level 2 C3PAO assessment or Level 3 requirements; subcontracts under prime contracts with Level 2 self-assessment requirements should only flow down Level 2 self-assessment requirements.
Unfortunately, many contractors either do not understand the CMMC flow-down requirements or are not willing to keep track of which types of information are flowing down. This has resulted in subcontractors receiving supposed CMMC Level 2 C3PAO audit requirements from upstream contractors when it's not necessary.
Limiting CMMC Level 2 scope is accomplished by designing an enclave within which all CUI will (theoretically) be handled. When done correctly, anything outside the enclave will be out of scope for CMMC Level 2, and only the assets within the enclave will be subject to CMMC Level 2 requirements and assessments. The goal for a subcontractor that is subject to unnecessary CMMC Level 2 requirements is to build the simplest possible enclave that could handle CUI in a compliant manner if the need ever arose and therefore pass a C3PAO assessment. This approach requires:
- Defining a system that includes at least one (1) device intended to handle CUI should it ever become necessary
- Using the virtual desktop scope exception to allow access to the enclave without bringing additional devices into scope
- Limiting the security infrastructure devices that will be in scope by understanding the CMMC scoping rules
- Only allowing the use of CMMC-compliant External Service Providers for IT and/or cybersecurity services within the enclave
Some simple enclave designs that can effectively minimize CMMC Level 2 compliance effort for subcontractors now handling CUI include:
- Implementing an on-premises enclave with limited capabilities
- Implementing a cloud-based enclave with limited capabilities
- Limiting the scope to a single workstation with no network connectivity
Even though this post focuses on CMMC Level 2, defense subcontractors should remember that they will almost always have CMMC Level 1 obligations for any devices that process, store, or transmit FCI outside of their CMMC Level 2 enclave and separate from any real or imagined CMMC Level 2 obligations.
How CMMC Should Apply to Subcontractors
Three (3) standardized government contract clauses impose CMMC and related requirements on contractors, and they all contain paragraphs requiring contractors to flow the text of these clauses down in subcontracts under specific circumstances.
These requirements are based on the handling of two (2) types of information:
Federal Contract Information (FCI) | FCI is information that is provided by or generated for the government under a contract except for information that is intended for public release or simple transactional information. FCI does not carry any special markings to identify it as FCI. |
Controlled Unclassified Information (CUI) | CUI is information that laws, regulations, or government-wide policies require the government itself to safeguard or control the dissemination of. All CUI must be marked by the government before it is transmitted to contractors. Contractors that create CUI will be instructed as to what information will be CUI and how it must be marked. There are currently 126 categories of CUI listed in the NARA CUI registry. |
Some contractors are confused about what information qualifies as CUI. Our post on Dealing With Unmarked and Mismarked CUI can help contractors understand what is (and is not) CUI.
The contract clauses related to these types of information include:
Clause | What It Is | Subcontractor Flow Down |
|---|---|---|
FAR 52.240-21 (Basic Safeguarding of Covered Contractor Information Systems) | Government-wide contract clause that requires contractors to safeguard (FCI) using 15 basic safeguard requirements | Paragraph (c) requires flow-down in subcontracts that will involve handling of FCI |
DFARS 252.204-7012 (Safeguarding Covered Defense Information and Cyber Incident Reporting) | Department of Defense (DoD) contract clause that requires contractors to safeguard CUI using the requirements in NIST SP 800-171r2 and report cybersecurity incidents involving CUI | Paragraph (m)(1) requires flow-down in subcontracts that will involve handling of CUI |
DFARS 252.204-7021 (Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements) | DoD contract clause that requires to assess and report their compliance with FCI and/or CUI safeguarding requirements from FAR 52.204-21 and DFARS 252.204-7012 | Paragraph(f)(1) requires flow-down in subcontracts that will involve handling of FCI or CUI Paragraph(f)(2) requires contractors to flow down only the CMMC level and assessment requirements that are applicable to the information being flowed down in a subcontract (as per the criteria in 32 CFR 170.23):
|
The flow-down requirements make it clear that a subcontract should only contain DFARS 252.204-7012 and CMMC Level 2 requirements related to the safeguarding of CUI if the subcontractor will be receiving CUI from an upstream contractor. Subcontracts that do not involve handling CUI should only contain FAR 52.204-21 and CMMC Level 1 requirements for safeguarding FCI regardless of what requirements were in the prime contract.
Furthermore, subcontractors that handle CUI should be able to self-assess compliance with CMMC Level 2 unless the prime contract requires a Level 2 C3PAO audit or Level 3 DIBCAC audit.
More details on what CMMC level should apply in each contract is in our previous blog post CMMC Level and Assessment Requirements for Defense Contractors.
The Prime Contractor Problem
The main problem that led to this post is that some large prime contractors have decided to not keep track of which subcontracts will involve handling CUI in accordance with the requirements of the prime contract. Instead, these contractors are unilaterally imposing CMMC Level 2 C3PAO audit requirements on all of their subcontractors regardless of whether the subcontractor will handle CUI. These unnecessary subcontract requirements then flow further down the supply chain, creating confusion and unnecessary extra cost.
DoD estimates that 63% of defense contractors only require CMMC Level 1. This means there are potentially 139,201 contractors that should be able to self-assess compliance with Level 1 but will instead be implementing CMMC Level 2 unnecessarily and seeking unnecessary Level 2 C3PAO audits.
Subcontractors can push back on these unnecessary requirements by asking upstream contractors what CUI will be handled under a subcontract. If CUI will not be handled, subcontractors should request that contract clauses be adjusted to reflect a CMMC Level 1 Self-Assessment.
There are a few issues with this approach:
- Some prime contracting personnel have demonstrated that they do not understand the CUI program.
- As an example, TrustedSec clients have reported a very large prime DoD contractors informing them that all information sent under a subcontract is CUI, which simply cannot be true due to the narrow definition of and marking requirements for CUI.
- Some prime contractors may flat out refuse to adjust the clauses, even if they know the clauses are incorrect.
- This seems to be common with large prime contractors; they are simply being lazy by applying every possible contract clause to every potential subcontractor and seem to have no intent to follow the actual CMMC flow-down requirements.
- Some subcontractors are concerned that pushing back in any way will result in subcontracts going to competitors that don’t complain about the unnecessary clauses.
This leaves potential subcontractors that are not willing or able to alter contract clauses with the choice of either declining to bid on subcontracts with unnecessary requirements or incurring the cost of implementing CMMC Level 2 requirements and undergoing an audit despite the lack of CUI in their environment.
This is not a decision to take lightly. DoD estimates the cost to attain CMMC Level 2 C3PAO certification every three (3) years at $104,000-$118,000. This cost estimate is for the certification process only and does not include the cost of implementing the CMMC Level 2 requirements necessary to pass the audit and maintaining compliance indefinitely.
Designing Enclaves
Subcontractors that decide to forge ahead with CMMC Level 2 certification, even though they are not expecting to handle CUI, will likely desire to do so with minimal cost and effort.
While the “vault with no treasure” approach described in this post is intended to help subcontractors that do not handle CUI to meet this need, some of the approaches described in this post can be used by contractors to build the foundation of a CMMC compliant system that can be expanded to address actual CUI handling needs in the future.
Defining Systems
NIST SP 800-171 and CMMC compliance are based around the concept of systems, which are each made up of a number of assets (e.g., workstations, servers, printers, CNC machines, network switches, firewalls) and are documented in a System Security Plan (SSP). A subcontractor that signs a subcontract with a CMMC clause is effectively agreeing that FCI and/or CUI will only be processed, stored, and/or transmitted on devices that are part of one (1) or more systems that have passed the appropriate level and type of CMMC assessment.
A contractor may have multiple defined systems, each of which may have different CMMC level and assessment requirements. Most contractors that handle CUI would have defined at least one (1) Level 2 system to handle CUI and another Level 1 system that handles FCI but not CUI. Contractors may also have one (1) or more Level 3 systems, or multiple Level 1 and/or Level 2 systems for handling FCI and/or CUI in different formats.
This concept of a defined system is what allows a subcontractor to implement and assess CMMC Level 2 compliance within a very small scope while keeping the rest of their business operations and assets out of scope. CMMC Level 2 requirements and assessments only apply to the assets that are part of the defined systems that handle CUI. Any other devices the subcontractor operates are irrelevant to CMMC Level 2 assessments and do not need to be compliant as long as they are outside the scope of the defined systems that will be used to handle CUI.
The word “enclave” is often used when discussing CMMC. This term simply refers to a system designed to handle CUI that is isolated from other devices that a contractor or subcontractor wants to keep out of their CMMC scope. The “vault with no treasure” approach described here is based on designing a very small and simple enclave that could handle CUI in a compliant manner should the need arise and therefore can pass a CMMC Level 2 assessment.
There are limits to how small and simple a system can be. CMMC contains scope rules that tell us what devices must be included within a system based on the relationship between the devices and CUI.
Basic CMMC Scoping
Understanding how to implement a minimalist enclave requires understanding some basic CMMC Level 2 scope concepts. A more detailed description of CMMC scope is contained in our previous post CMMC Scope - Understanding the Sprawl.
Four (4) categories of devices are in scope for CMMC as defined in 32 CFR 170.19(c) and described in the CMMC Level 2 Scoping Guide:
Scope Category | What They Are | Why They Matter |
|---|---|---|
CUI Assets | Devices that process, store, or transmit CUI | We must add at least one (1) CUI Asset to the enclave so the C3PAO has something to assess. As this post is focused on subcontractors that will not handle CUI, we should think of CUI Assets as the devices within the enclave that could theoretically process, store, or transmit CUI someday if the need arose. |
Specialized Assets | IoT, IIoT, OT, Government Furnished Equipment, Restricted Information Systems, and Test Equipment that process, store, or transmit CUI but are unable to meet CMMC Level 2 requirements | Specialized Assets should be irrelevant in this context because there should be no reason to include any of these devices in the enclave if no CUI will be handled. |
Contractor Risk Managed Assets | Oversimplifying a bit: devices that can establish a network connection to a CUI Asset | A primary goal of this approach is to ensure no devices fall into the Contractor Risk Managed category by completely isolating the enclave from the rest of the environment via network segmentation. |
Security Protection Assets | Devices that provide security functions or capabilities to any of the above | Another goal of this approach is to minimize the number of devices that fall into the Security Protection Assets category by carefully designing how CMMC safeguarding requirements will be met. |
To be considered out of scope for CMMC, a device must:
- Not process, store, or transmit CUI
- Not provide security protections for CUI Assets
- Be physically or logically separated from CUI Assets
- Not otherwise fall into any of the in-scope categories
We want to ensure every device the subcontractor operates that doesn’t need to be part of the enclave meets these criteria to remain out of scope.
The Virtual Desktop Exception
The CMMC Level 2 scope rules contain an exception for virtual desktop clients that is very relevant to a minimalist enclave. The CMMC scope rules state:
“An endpoint hosting a VDI [Virtual Desktop Infrastructure] client configured to not allow any processing, storage, or transmission of CUI beyond the Keyboard/Video/Mouse sent to the VDI client is considered an Out-of-Scope Asset.” |
This allows subcontractors to access CUI within the enclave from their normal workstations without those workstations falling into the CUI Asset or Contractor Risk Managed Asset scope categories. This is a very powerful tool for building an enclave without bringing workstations that access it into the CMMC Level 2 scope.
External Service Providers
Any organization that is providing or managing IT and/or cybersecurity services for a CMMC Level 2 enclave may be considered in scope as an External Service Provider (ESP) if the service provider processes, stores, or transmits CUI or Security Protection Data (SPD) on their own systems. Subcontractors must carefully design their enclaves to avoid including ESPs that are not CMMC compliant. A system cannot pass a CMMC assessment unless all in-scope ESPs also meet the applicable CMMC requirements.
We must treat CUI Assets as if they may handle CUI in the future in order to pass an assessment. This means any ESPs that would handle CUI if it were in the enclave will also be in scope for assessment purposes.
SPD is perhaps a more significant problem than CUI as many managed and outsourced IT and cybersecurity services will be much more likely to handle SPD than CUI. SPD is defined as security-relevant information stored or processed by a subcontractor’s Security Protection Assets and explicitly includes:
- Configuration data required to operate a Security Protection Asset
- Log files generated by or ingested by a Security Protection Asset
- Data related to the configuration or vulnerability status of in-scope assets
- Passwords that grant access to the in-scope environment
The specific requirements that apply to ESPs also vary depending on whether the ESP is a cloud service provider and whether the ESP is handling CUI or just SPD:
ESP Type | Requirements |
|---|---|
Cloud service providers that process, store, or transmit CUI | FedRAMP Moderate Certification or Equivalent |
Cloud service providers that process, store, or transmit SPD but not CUI | CMMC Level 2 |
Non-cloud service providers that process, store, or transmit CUI and/or SPD | CMMC Level 2 |
ESPs may voluntarily undergo their own CMMC assessments, in which case the assessment level and type must match or exceed the subcontractor’s obligations. Otherwise, the ESP must be included within the scope of the subcontractor’s assessment (i.e., the subcontractor must pay their C3PAO to assess the ESP, and the subcontractor cannot pass its assessment unless the ESP also passes its assessment).
More information on CMMC compliance with ESPs is available in our previous post on CMMC Subcontractors and Service Providers.
Simple Enclave Designs
The following designs are starting points that subcontractors can use to design a minimal enclave. These fall into three (3) categories, each described in more detail below:
- On-Premises Enclave
- Cloud Enclave
- Offline Workstation
Subcontractors that may need to handle CUI in the future should consider a design that can be easily expanded to meet the need when the time comes. The details will depend on what format the subcontractor will receive CUI in (e.g., product specifications, design drawings) and what the subcontractor will need to do with this information once they have it. The on-premises enclave is the most flexible approach in this regard as it can more easily incorporate devices that require physical interaction (e.g., printers and CNC machines) than a cloud-based solution while the Offline Workstation is the least flexible approach as it is completely incapable of network communication.
On-Premises Enclave
A minimal network-connected enclave should include:
- A file sharing portal used to receive CUI from and transmit CUI to other contractors
- A virtual desktop host used to review and manipulate CUI within the enclave while keeping other workstations out of the CMMC Level 2 scope via the virtual desktop exception described above
A subcontractor could easily add other applications and devices to this enclave in the future. For example, CAD software could be installed on the virtual desktop host if a subcontractor must manipulate part drawings that are marked as CUI and a dedicated printer could be connected within the enclave.
Deciding how to implement the Security Protection Assets necessary to meet CMMC Level 2 requirements will likely be the most difficult challenge when designing an on-premises enclave. These may include SIEMs, authentication management, configuration and patch management systems, vulnerability scanners, etc.
Two (2) approaches to implementing Security Protection Assets include:
Approach | Pro | Con |
|---|---|---|
Enclave Native Services: Implement the necessary security functions via dedicated Security Protection Assets within the enclave | Existing security infrastructure does not need to meet CMMC Level 2 requirements | Incurs extra cost and overhead due to duplication of security functionality that exists outside the enclave |
Shared Services: Existing security infrastructure provides service to the enclave as well as other devices that are not in the CMMC Level 2 scope | Avoids extra cost and overhead by using infrastructure that already exists | Existing security infrastructure is in scope for CMMC as Security Protection Assets and must implement all applicable CMMC Level 2 controls |
This does not need to be an all-or-nothing approach. A subcontractor may choose to re-implement some security functions within the enclave while leveraging existing security infrastructure for other security functions. This is ultimately a business decision for each subcontractor to determine which approach will have the least impact for each Security Protection Asset necessary to meet Level 2 requirements.
Subcontractors must also remember the impact of ESPs on their CMMC scope when determining how to implement Security Protection Assets. Any third-party that handles SPD from the enclave due to their management of a Security Protection Asset is considered an ESP and will be in scope. Subcontractors should strongly consider re-implementing existing security infrastructure that is managed by an organization that is not compliant or switching to a service provider that meets CMMC Level 2 requirements.
Cloud Enclave
The primary function of a basic cloud and an on-premises enclave is the same: host a file sharing portal suitable for exchanging CUI with other contractors and provide a way to interact with CUI if necessary. Many subcontractors see a 100% cloud-based enclave as an easy solution to CMMC compliance, but putting a CMMC Level 2 enclave in the cloud comes with many of the same challenges as an on-premises enclave.
Requiring all access to the cloud-based enclave via a virtual desktop host will be necessary to keep local workstations out of scope. The CMMC scope rules do not change just because the enclave is in the cloud, so any workstation that directly connects to a cloud-based CUI Asset (without using a virtual desktop solution) would be in scope.
A drawback of the cloud enclave is that it may be more difficult to add capabilities if the subcontractor needs to handle CUI in the future. Software licensing may be different for cloud applications, lag introduced by virtual desktop sessions may make some applications more difficult to use, and any need for CUI to enter the physical world (e.g., transmission to a printer or manufacturing equipment) will require connections to on-premises equipment that would be in scope for CMMC (necessitating an on-premises extension of the enclave).
Scope rules and requirements related to ESPs must be at the forefront when implementing a cloud-based enclave. As the enclave could (theoretically) handle CUI, the cloud service itself must meet FedRAMP Moderate requirements. Subcontractors should strongly consider choosing a cloud service provider that has a FedRAMP Certification or be very familiar with the requirements related to FedRAMP Equivalency for cloud service providers that do not have a Certification.
As per 32 CFR 170.19(c)(2)(ii), a subcontractor is responsible for documenting how the cloud-based CMMC Level 2 system is implemented in its SSP. Subcontractors should receive a Customer Responsibility Matrix (CRM) from their cloud service provider that describes which requirements are handled by the ESP, which are the responsibility of the subcontractor, and which are shared. Subcontractors must implement all CMMC Level 2 requirements that the ESP indicates are subcontractor or shared responsibilities.
Subcontractors must consider how the security functions required by CMMC Level 2 (but not listed as ESP responsibilities in the CRM) will be implemented. Subcontractors are faced with the same choice as described for an on-premises enclave:
- Re-implement the security functions in the cloud enclave at extra cost
OR
- Leverage existing security infrastructure, dragging on-premises Security Protection Assets and potentially other ESPs into scope
Offline Workstation
Perhaps the simplest (but least useful) CMMC enclave is a single air gapped workstation. This workstation would be the sole device authorized to handle CUI and must not be connected to the Internet or any other network. This approach would have absolutely no impact on the subcontractor’s network or other systems.
In order for this approach to be feasible, the subcontractor must require upstream contractors to transfer CUI via a removable drive that can be connected to the workstation.
Most of the technical CMMC Level 2 requirements can be implemented on the workstation itself. Requirement MP.L2-3.8.6 - Portable Storage Encryption will be very relevant due to the potential use of removable media for transferring CUI to and from the workstation. Various other non-technical requirements related to physical protection, awareness and training, etc., will also apply as they would in any CMMC Level 2 scope.
A struggle with this approach is that some CMMC Level 2 requirements would be difficult or impossible to implement on an offline workstation, for example:
- AU.L2-3.3.7 - Authoritative Time Source requires systems to synchronize their clocks with an authoritative source, which is impossible for an offline workstation without special hardware to receive time signals via GPS or radio.
- Requirements for Audit Failure Alerting (AU.L2-3.3.4), Audit Correlation (AU.L2-3.3.5), and Reduction & Reporting (AU.L2-3.3.6) are usually implemented via a SIEM, which would not be available to an offline workstation, although these functions could theoretically be implemented on the workstation itself.
Another struggle is that many of the CMMC Level 2 requirements would be Not Applicable because they are irrelevant to an offline workstation, for example:
- Requirements related to remote access in AC.L2-3.1.12 through AC.L2-3.1.15
- Requirements related to wireless access in AC.L2-3.1.16 and AC.L2-3.1.17
- SC.L2-3.13.6 - Network Communication
- SC.L2-3.13.8 - Data in Transit
- SC.L2-3.13.9 - Connection termination
- SI.L2-3.14.6 - Monitor Communications for Attacks
While the prospect of marking many requirements Not Applicable may seem like a good thing, it generates more paperwork that subcontractors may wish to avoid. DFARS 252.204-7012(b)(2)(ii)(B) requires contractors to submit requests in writing to the Contracting Officer if they wish to vary from the requirements of NIST SP 800-171 and await adjudication from an authorized representative of the DoD CIO.
Any subcontractor that intends to take this hyper-minimalist approach to an enclave would be well advised to confer with their C3PAO to determine exactly how an offline workstation would be assessed and what solutions the C3PAO would consider acceptable for the Level 2 requirements that do not make sense in this context.
CMMC Compliance for FCI
While this post primarily focused on CUI, subcontractors should remember they still have CMMC Level 1 requirements separate from any real or unnecessary CMMC Level 2 requirements.
TrustedSec recommends implementing the 15 Basic Safeguards for FCI on all subcontractor systems that could potentially receive or create any non-public information under a federal contract so that subcontractors do not need to worry about controlling the flow of FCI within their environment. CMMC Level 1 only requires self-assessment, so the cost of assessing the entire subcontractor environment should also be minimal.
This recommendation is made for three (3) reasons:
- FCI is much more common than CUI due to the broadness of its definition.
- FCI is not marked, so it is much harder to keep track of than CUI.
- CMMC Level 1 requirements (the 15 Basic Safeguards for FCI) are much easier to implement than the 110 NIST SP 800-171r2 safeguards for CUI (which are identical to the CMMC Level 2 requirements).
If you're in need of assistance on this, please get in touch with us.
