cmmctrade-pressNewsThe Broadside3 min read

PSC urges CMMC alignment with NIST 800-171 Rev. 3

The contracting group wants risk-tiered assessments but acknowledges that easing small-business requirements widens the supply-chain attack surface.


TL;DR

The Professional Services Council filed comments Aug. 14 on DoD's CMMC review, asking for alignment with NIST 800-171 Rev. 3, reciprocity with FedRAMP Moderate, and grandfathering of existing Level 2 certifications. The filing also recommends risk-tiered C3PAO assessments, then undercuts its own case, conceding that "sophisticated threat actors routinely target the least-protected organization in a supply chain" and "the sensitivity of CUI does not change based on company size."

DoD's CMMC Reform Task Force has about 60 days to deliver recommendations, and PSC's Aug. 14 filing to the department's July RFI is the first major industry submission to surface publicly. The timing matters: DoD paused CMMC Level 2 implementation on July 13, just months before it was set to begin appearing in solicitations. Contractors who'd already paid for third-party assessments are now wondering whether those certifications still count.

PSC's filing is built on three asks. First, it wants the Pentagon to coordinate with the FAR Council so the entire federal enterprise uses the same revision of NIST 800-171. The FAR Council proposed a rule in June aligned with Rev. 3; CMMC still references Rev. 2. Leaving those out of sync would force contractors to maintain dual compliance postures, which is precisely the duplication the program was supposed to eliminate. Second, PSC asks for FedRAMP Moderate reciprocity, if a cloud environment is already authorized at Moderate, it should be sufficient for CUI without an additional CMMC assessment. Third, existing Level 2 certifications should be treated "as an asset rather than something to reset," either by letting contracting officers use them as a positive discriminator in source selection or by grandfathering them outright.

The tension PSC can't resolve

The most interesting section of the filing is its treatment of risk-tiering. PSC argues that requirements should be calibrated to "data sensitivity, contractor role, and organizational size rather than applying a one-size-fits-all model." It floats making C3PAO assessments optional or risk-tiered, paired with stronger self-assessment.

Then the filing does something unusual for an industry comment: it names the problem with its own proposal. "Sophisticated threat actors routinely target the least-protected organization in a supply chain as an entry point into larger prime contractors and government programs," PSC writes. That means reducing requirements for small businesses doesn't lower system-wide risk, it concentrates it on the weakest link. And "the sensitivity of CUI does not change based on company size."

This isn't a rhetorical slip. PSC is surfacing a genuine structural tension in the CMMC debate: the compliance burden on small businesses is real and disproportionate, but lowering the bar creates the kind of supply-chain seam adversaries have exploited for years. The filing's answer (better CUI marking, standardized flow-down, more government assistance) is a process fix for a security problem. Whether the task force finds that adequate is an open question.

What practitioners should watch

For contractors who've already obtained a Level 2 certification, the near-term signal is cautiously positive. PSC's grandfathering recommendation aligns with what DoD's task force is likely to hear from other industry groups. For those waiting to begin the process, the Rev. 2-to-Rev. 3 transition is the bigger variable. If the FAR Council finalizes its rule on Rev. 3 and DoD follows (as PSC is urging) the control set you're planning against today could shift before you complete an assessment. The filing acknowledges this implicitly: it asks for coordination "on a single Revision," which means picking one and moving, not straddling two indefinitely.


Published ·Updated ·Deep Fathom