This is a reprint of the July 1, 2026, NC Military Business Report, published by Business North Carolina Magazine.
07/01/26
Good morning. Dan here.
Last week, the New York Times published a story about a cybersecurity breach last year of Jaguar Land Rover, described as “a crown jewel of British manufacturing.” The hackers were a group of Russians whose attack “forced Jaguar to lock down its computers and suspend production for five weeks,” the story read. It cost the company about $350 million. There were vulnerabilities, it turns out, in the company’s aged IT infrastructure.
I read the story more closely because last week I sat in on a CMMC webinar. CMMC is the Cybersecurity Maturity Model Certification. You can think of it as a government checklist of things that have to be done to your IT if you want to keep getting defense contracts.
CMMC resulted because the government decided around a decade ago that the defense industry’s doors and windows were unlocked and something had to be done. We had a lot of companies like Jaguar that were sitting ducks for the Russians, the Chinese or just plain criminals. CMMC started off voluntary, but the voluntary part came to a close for a lot of contracts.
The webinar was presented by Brian Vigna, a cybersecurity specialist with N.C. State’s Industry Extension Services. Here is a link to a recording of the webinar. And here is the PowerPoint. This was the presentation for the lowest level CMMC companies, Level 1. It was a good compliance overview of CMMC. There is a second webinar on July 9, titled “Getting Started.” The description is:
In this session, we begin to break down the phases of a CMMC implementation. Participants will be introduced to environment scoping, required policies, procedures, and documentation that must be completed before a final CMMC self-assessment can be conducted.
———————-
And on Aug. 12, a third webinar, titled “Implementation and Documentation,” will be held: This is the description:
In this session, participants will map out their scope, create basic cybersecurity procedures, learn how to capture required evidence, and prepare for a final self-assessment before uploading a score to SPRS.
———————
Last week’s webinar was probably the clearest explanation of CMMC I’ve heard as it affects small businesses. Vigna talked about timetables and defined terms, and gave examples of what companies need to do and why. This is particularly useful for people who run companies and are not IT folks. And he didn’t lecture you for not doing all this stuff already. I suggest listening to last week’s webinar and looking at the PowerPoint.
But here is a sample of what he said:
- There are three levels of CMMC regulations, depending on the sensitivity of federal contract information companies handle. Last week focused on the Level 1 companies. The point of CMMC is to make sure companies protect this information by making their systems harder for hackers – adversaries and criminals – to penetrate.
- “The majority of contractors are going to fall into Level 1 or Level 2, and a very, very small subset are going to fall into Level 3.” At Level 1, companies are handling FCI – Federal Contract Information.
- Phase 1 of the CMMC rollout started last November, CMMC self-assessment requirements for both Level 1 and Level 2 in applicable solicitations.
- Phase 2 begins this November. Level 2 companies will need a third-party external assessment.
- In 2028, every new DoD contract solicitation will come with a CMMC requirement.
- Level 1 companies have to self-assess annually for compliance with 15 basic security requirements.
- Level 2 companies have to meet 110 security requirements that go along with NIST Special Publication 800-171. These are the contractors handling Controlled Unclassified Information, or CUI.
- FCI – Federal Contract Information – is “Sensitive, but not classified, information that is provided by or generated for the government under a contract. It’s information that you would not find on SAM or any other public-facing government websites. So things like contract details, building specs that, again, are not on SAM, project schedules. Communications with a contracting officer, organizational charts, process documentation, contract performance reports, requests for purchase. These are things that you would automatically say, if I have any of these, I am FCI. I am now CMMC Level 1.”
- “Level 2 is all about folks who deal with CUI. That is the more sensitive information. That is, while it’s unclassified, it still needs to be safeguarded in a very different way than FCI. It should be marked CUI when it comes from the government. That is not always happening, unfortunately, so some of this burden does fall on you, the defense contractor, to figure out. Some examples… engineering drawings, Social Security numbers, financial data, trade secrets, applicant data, proprietary business information, unclassified controlled technical information . . . “
- An important first step for Level 1 companies is figuring out the scope of how FCI is handled in your business. “It’s all about the devices, the people, the systems that process, store, and transmit FCI . . . Maybe it’s a flash drive that contains files. Maybe it’s a server, it’s a large server in your company that everyone can access. Maybe this is a OneDrive, maybe this is a SharePoint. These are all examples of things that might contain FCI.”
- A good resource is a Level 1 Self-Assessment Guide. It’s a 54-page government document. “I would strongly encourage anyone, regardless of your position in the company, owner, operator, engineer, IT person, managed service provider, whoever you are in that relationship, you should read this guide. It will help you analyze your current FCI protection.”
- “Start documenting right away. Write down what you do that meets these requirements. Write down what procedures, what policies that you have in place. Even if you’re writing down that we don’t have that policy, or it’s inadequate to meet the assessment objectives, I would highly recommend you record your work as you go. Now, if you say, hey, we do have a policy, when new users are hired, when new people join our company, they get a username and a password, it’s got this length and complexity, and that dictates what devices they can access. Well, that’s great, but that’s a policy on paper. Is it actually effective? Is it being utilized? Are users finding ways around it?”
- “Somewhere, buried in a contract that you’ve signed, there’s most likely a little clause that’s been hiding there that says FAR and has several numbers and dashes after it. Go read more about that, and you’ve already been saying you’re compliant with these basic security requirements. How is CMMC different? Because it’s now a formalized program with assessors, assessment windows, and penalties for those who do not comply.”
- “Well, there’s great news. There’s something called a System Security Plan, which is a formal requirement at Level 2. However, at Level 1, it’s, again, just a strong recommendation. What is a System Security Plan? It’s a living, breathing document that helps you understand the current state of your network, your cybersecurity program, and how your employees and that data is managed.”
Dan Barkin
[email protected]
