Discover this podcast and so much more

Podcasts are free to enjoy without a subscription. We also offer ebooks, audiobooks, and so much more for just $11.99/month.

What Is CMMC And Why Should You Be Concerned?

What Is CMMC And Why Should You Be Concerned?

FromMaking Chips Podcast for Manufacturing Leaders


What Is CMMC And Why Should You Be Concerned?

FromMaking Chips Podcast for Manufacturing Leaders

ratings:
Length:
42 minutes
Released:
Aug 9, 2021
Format:
Podcast episode

Description

What is the Cybersecurity Maturity Model Certification (CMMC)? The DOD is implementing the CMMC to normalize and standardize cybersecurity preparedness across the Federal government’s defense industrial base. Meaning? If you’re doing DOD work, they’re mandating that you get this certification. So you need to know what this is all about. We’ve brought in Paul Van Metre and John Bilek to help fill in the blanks. Check it out! Segments [0:00] Amper Technologies machine monitoring systems [3:39] Cybersecurity Maturity Model Certification (CMMC) [5:05] Let’s talk acronyms (there’s one for everything) [7:20] What’s happening at ZENGERS? [8:20] The amount of money wasted on cybersecurity [11:05] We welcome our two guests to the show [14:48] What is CMMC really all about? [17:09] Who is impacted by the CMMC requirement?  [19:44] Check out ProShop ERP for more information on manufacturing software! [20:44] The five levels of CMMC compliance [21:56] The CMMC implementation process [27:19] What does “CMMC Compliant” mean? [29:02] What ProShop ERP is rolling out to enhance security The amount of money wasted on cybersecurity Cybersecurity is a large problem. Most attacks originate from Russia but there’s also a lot of domestic hacking happening. Because of this—according to MXD—the DOD is now spending more than $300 billion each year on government contracts. The DOD Directive 8140 requires that any contractor must satisfy specific training and certification provisions to ensure sensitive data remains secure. The qualifications can be transferable and useful across the board.  Jason points out that this cybersecurity effort is how we protect our country, industry, economy, and more. Our enemies want to steal our technology, which is why we must keep it secure. Because manufacturing is a huge part of what the DOD does, anyone in their supply chain must follow the same cybersecurity protocols.  Who is impacted by the CMMC requirement?  CMMC applies to anyone in the defense contract supply chain. That includes both contractors who engage directly with the DOD and subcontractors who fulfill and/or execute those contracts. The CMMC standards will affect over 300,000 organizations. If you want to continue to do work for the DOD, you will have to get certified over the next 4–5 years.  Paul has heard of shops that are starting to lose work because they aren’t on track to get the CMMC certification. John has been asked multiple times if he’s been certified. While you cannot get certified yet, he is working toward compliance. There are five different levels of CMMC compliance. Most machine shops are expected to be certified at level three. How soon do you have to implement this? Paul points out that you can’t sit on this. There are very few approved auditors, so if you wait until the last minute you’ll lose out on a significant amount of your sales. If 30% of your business deals with the DOD, you could lose millions without the certification.  The financial impact on machine shops In May 2021, an entity was announced that would start handling the CMMC audits. What kind of costs will be put on machine shops? It’s going to be far more expensive to implement than an AS9100 audit. The CMMC is built on cybersecurity standards, the main one being the NIST 800-171 standard.  If a company is already compliant with that standard, they can likely check off the boxes for CMMC Level one. If you aren't compliant with this standard, to reach level one compliance could cost you between $5,000 to $25,000. For level three, it will be around $15,000 to $100,000, depending on the size of your shop. This is going to be a large financial hit no matter what you do. The certification is costly—but if you don’t get it, the loss of business may cost you more. A shop in Florida was quoted $100,000 for a company to “help” them get CMMC certified. Be wary of who you look to for help—a lot of unscrupulous people will take advantage of this rollout. Find accredited and reputa
Released:
Aug 9, 2021
Format:
Podcast episode

Titles in the series (100)

MakingChips is hosted by a set of multi-generational manufacturing leaders who are on the factory floor everyday, living their lives in the world of manufacturing—they know first hand that manufacturing can be challenging. Founders Jim Carr and Jason Zenger released their first podcast in late December 2014—releasing over 300 episodes to-date, reaching more than 650,000 downloads—all while striving to deliver on their mission, to “equip and inspire the metalworking nation.” In 2019, Nick Goellner, another multi-generational manufacturing leader, joined the MakingChips hosts, bringing a third generation of manufacturing leaders to the table. Join the hosts as they work through industry challenges with leaders such as Titan Gilroy (Titans of CNC), John Saunders (NYC CNC), Mark Terryberry (Haas Automation) and more.