What Is CMMC And Why Should You Be Concerned? episode artwork

EPISODE · Aug 9, 2021 · 42 MIN

What Is CMMC And Why Should You Be Concerned?

from Making Chips Podcast for Manufacturing Leaders · host Jason Zenger, Jim Carr, Paul Van Metre, John Bilek

What is the Cybersecurity Maturity Model Certification (CMMC)? The DOD is implementing the CMMC to normalize and standardize cybersecurity preparedness across the Federal government's defense industrial base. Meaning? If you're doing DOD work, they're mandating that you get this certification. So you need to know what this is all about. We've brought in Paul Van Metre and John Bilek to help fill in the blanks. Check it out! Segments [0:00] Amper Technologies machine monitoring systems [3:39] Cybersecurity Maturity Model Certification (CMMC) [5:05] Let's talk acronyms (there's one for everything) [7:20] What's happening at ZENGERS? [8:20] The amount of money wasted on cybersecurity [11:05] We welcome our two guests to the show [14:48] What is CMMC really all about? [17:09] Who is impacted by the CMMC requirement?  [19:44] Check out ProShop ERP for more information on manufacturing software! [20:44] The five levels of CMMC compliance [21:56] The CMMC implementation process [27:19] What does "CMMC Compliant" mean? [29:02] What ProShop ERP is rolling out to enhance security The amount of money wasted on cybersecurity Cybersecurity is a large problem. Most attacks originate from Russia but there's also a lot of domestic hacking happening. Because of this—according to MXD—the DOD is now spending more than $300 billion each year on government contracts. The DOD Directive 8140 requires that any contractor must satisfy specific training and certification provisions to ensure sensitive data remains secure. The qualifications can be transferable and useful across the board.  Jason points out that this cybersecurity effort is how we protect our country, industry, economy, and more. Our enemies want to steal our technology, which is why we must keep it secure. Because manufacturing is a huge part of what the DOD does, anyone in their supply chain must follow the same cybersecurity protocols.  Who is impacted by the CMMC requirement?  CMMC applies to anyone in the defense contract supply chain. That includes both contractors who engage directly with the DOD and subcontractors who fulfill and/or execute those contracts. The CMMC standards will affect over 300,000 organizations. If you want to continue to do work for the DOD, you will have to get certified over the next 4–5 years.  Paul has heard of shops that are starting to lose work because they aren't on track to get the CMMC certification. John has been asked multiple times if he's been certified. While you cannot get certified yet, he is working toward compliance. There are five different levels of CMMC compliance. Most machine shops are expected to be certified at level three. How soon do you have to implement this? Paul points out that you can't sit on this. There are very few approved auditors, so if you wait until the last minute you'll lose out on a significant amount of your sales. If 30% of your business deals with the DOD, you could lose millions without the certification.  The financial impact on machine shops In May 2021, an entity was announced that would start handling the CMMC audits. What kind of costs will be put on machine shops? It's going to be far more expensive to implement than an AS9100 audit. The CMMC is built on cybersecurity standards, the main one being the NIST 800-171 standard.  If a company is already compliant with that standard, they can likely check off the boxes for CMMC Level one. If you aren't compliant with this standard, to reach level one compliance could cost you between $5,000 to $25,000. For level three, it will be around $15,000 to $100,000, depending on the size of your shop. This is going to be a large financial hit no matter what you do. The certification is costly—but if you don't get it, the loss of business may cost you more. A shop in Florida was quoted $100,000 for a company to "help" them get CMMC certified. Be wary of who you look to for help—a lot of unscrupulous people will take advantage of this rollout. Find accredited and reputable consultants. There will be grant money offered to help companies get this certification. Can you swing the cost of the certification?  What can help cover some of these costs? IMEC gave Carr Machine a grant to get ISO certified years ago, which covered some of the implementation and auditor fees. IMEC will be giving grants out to augment the cost of implementing this. Paul points out that the MEP gets its money from the Federal government and allocates it to different organizations like IMEC. The unknown? The amount of labor you may have to invest in to get to level three certification.  So what does CMMC compliant actually mean? How is ProShop ERP implementing updates to help you walk through the process? John and Paul share a few examples, so keep listening! If you have an idea for a MakingChips message, please ask us a question or leave us a message at 312-725-0245 and let us know! Resources mentioned on this episode Get The Boring Bar Newsletter - Text CHIPS to 38470 to subscribe! John Bilek MXD USA The DOD Directive 8140  ITAR IMEC Making Chips Episode #1 The NIST 800-171 standard 85 FR 51161 - Award Format for DoD Grants and Cooperative Agreements Connect With MakingChips www.MakingChips.com On Facebook On LinkedIn On Instagram On Twitter On YouTube

NOW PLAYING

What Is CMMC And Why Should You Be Concerned?

0:00 42:00

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

French Your Way Jessica: Native French teacher founder of French Your Way Boost your French listening skills and test your comprehension with this one of a kind series of podcasts. Get the chance to listen to a real conversation between native speakers talking at normal speed AND customise your learning experience through carefully designed sets of questions (2 levels of difficulty) available for download at www.frenchvoicespodcast.com. All interviews also come with the transcript. French teacher Jessica interviews native speakers of French from around the world who share a bit of their life and passion. Where else would you meet in one same place a French yoga teacher based in Melbourne, a soap manufacturer from Provence, or a couple cycling around the world? That Hoarder: Overcome Compulsive Hoarding That Hoarder Hoarding disorder is stigmatised and people who hoard feel vast amounts of shame. This podcast began life as an audio diary, an anonymous outlet for somebody with this weird condition. That Hoarder speaks about her experiences living with compulsive hoarding, she interviews therapists, academics, researchers, children of hoarders, professional organisers and influencers, and she shares insight and tips for others with the problem. Listened to by people who hoard as well as those who love them and those who work with them, Overcome Compulsive Hoarding with That Hoarder aims to shatter the stigma, share the truth and speak openly and honestly to improve lives. The Small Business Startup School – Business Notes | Financial Literacy | Retail Psychology – For Professionals & Entrepreneurs The Small Business Startup School Inc. Starting or buying a small business? While personal circumstances may vary, business patterns remain timeless. On The Small Business Startup School, we explore strategies, insights, and practical solutions to help entrepreneurs confidently navigate their journey.Hosted by Ola Williams—a retail entrepreneur, fintech founder, and financial coach with over two decades of experience—this podcast marries financial awareness and retail psychology with optimism to deliver actionable takeaways.Join us to learn, grow, and connect as we uncover the keys to business success.Let’s continue to learn together and be encouraged to keep on connecting! HOMELAND HOMELAND The Church is a body not a building. It's the bride of Jesus Christ! Jesus is coming back for a mature bride. That means it's time for the church of Jesus Christ to move from milk to meat. This is the hour of maturity!HOMELAND is an announcement that the church is being set free. Only the church has the ability to transform the world. The kingdom's of this world will become the kingdoms of our Lord and Savior!All of creation has been waiting for this moment! Sons and daughters of God are rising up and taking their seat!

Frequently Asked Questions

How long is this episode of Making Chips Podcast for Manufacturing Leaders?

This episode is 42 minutes long.

When was this Making Chips Podcast for Manufacturing Leaders episode published?

This episode was published on August 9, 2021.

What is this episode about?

What is the Cybersecurity Maturity Model Certification (CMMC)? The DOD is implementing the CMMC to normalize and standardize cybersecurity preparedness across the Federal government's defense industrial base. Meaning? If you're doing DOD work,...

Can I download this Making Chips Podcast for Manufacturing Leaders episode?

Yes, you can download this episode by clicking the download button on the episode player, or subscribe to the podcast in your preferred podcast app for automatic downloads.
URL copied to clipboard!