Episode Details

Back to Episodes

New CMMC FAQ Clarifications: Joint Ventures, Paper-Only CUI, Reassessment Triggers & Where MSPs Actually Fit in Scope

Episode 62 Published 3Β months, 1Β week ago
Description

Submit any questions you would like answered on the podcast!

The Department of Defense just updated its CMMC FAQ document β€” and the clarifications inside answer some of the most common (and costly) assumptions contractors make. In this episode, Brooke and Stacey break down what changed for joint ventures, paper-only CUI, significant change triggers, and how MSPs and MSSPs actually fit into assessment scope.

If you're navigating a merger, working with subcontractors, or relying on an MSP to manage your environment, this episode clears up exactly where you stand β€” and where you don't.


πŸ“Œ What You'll Learn:

  • Why joint ventures do NOT automatically inherit a company's CMMC certification status
  • The new guidance on paper-only CUI β€” and when it does NOT require Level 2 assessment
  • What actually counts as a "significant change" that triggers reassessment (mergers, system consolidation, and more)
  • Why MSPs don't need their own CMMC certification β€” but still carry major assessment responsibilities
  • The difference between CUI scope and Security Protection Data (SPD) scope for MSPs/MSSPs
  • The five-part test for whether an MSP counts as a Cloud Service Provider (CSP)
  • Listener Q&A: Do subcontractors need cybersecurity training and screening too?


Listen Now

Love PodBriefly?

If you like Podbriefly.com, please consider donating to support the ongoing development.

Support Us