Taking CMMC Seriously - What Is The Cost Of Compliance?

JSchaus & Associates
JSchaus & AssociatesFED Govt Contracts Consulting + 1 - 2 0 2 - 3 6 5 - 0 5 9 8 at JSchaus & Associates
Taking CMMC Seriously:
What is the Cost of
Compliance?
September, 19, 2023
Welcome!
Bill Wootton
Chief Revenue Officer
C3 Integrated Solutions
bwootton@C3isit.com
© 2023 C3 Integrated Solutions. All Rights Reserved.
3
Today’s Topics
▸Overview: Major Components of the Cost of CMMC
▸Building a Strategy
▸Deployment
▸Management and Monitoring
▸Compliance
▸Data Enclaves: Options and Impact
▸Three Types of Companies
Building a Strategy
© 2023 C3 Integrated Solutions. All Rights Reserved.
5
Building Your CMMC Strategy
Understanding
your business
Setting the
system
boundary
Determining the
organizational
impact
Determining
the expertise
you need
© 2023 C3 Integrated Solutions. All Rights Reserved.
6
Understanding Your Business
External Factors Internal Factors
▸ Your Customers…
▸ Which agencies do you work with?
▸ Your Partners…
▸ Who are your primes and subs?
▸ What are THEIR requirements to continue
working with them?
▸ Your Contracts…
▸ What clauses are already in your contracts?
▸ Your Future…
▸ Where will your business be in 2-3 years?
▸ Your Data…
▸ Do you have CUI?
▸ Do you have export-controlled data?
▸ Can you segment it from the rest of the
organization?
▸ Your People…
▸ Who directly interacts with CUI
▸ Who indirectly interacts with CUI?
▸ Your Systems…
▸ Which systems store, process, or transit
data?
The better you know your business, the less you will need a consultant to answer these questions.
© 2023 C3 Integrated Solutions. All Rights Reserved.
7
Company Examples: All 100-Person Firms
Research Firm
• Almost all commercial work
• Single DoD contract
• Team segmented from rest
of the firm
Manufacturing Firm
• Approximately 90% DoD
work
• Highly customized parts for
aircraft
• Large amounts of export-
controlled data
Professional Services
• Many distributed contracts
• Team members rotate
between DoD and civilian work
regularly
• Centralized admin supports all
contracts
Current systems are not compliant. No preexisting certifications (e.g. ISO
9001)
© 2023 C3 Integrated Solutions. All Rights Reserved.
8
Employee Access to CUI (100-person
Company)
????????
90 People 10 people
90 People
10 people
Commercial
Within CUI Boundary
Company 1 – Research
Firm
Company 3 – Professional Services Firm
Company 2 – Manufacturing Firm
© 2023 C3 Integrated Solutions. All Rights Reserved.
9
Determining System Boundaries: Enclave or
All-In?
ENCLAVE
Separate environment isolated
from the corporate environment
ALL-IN
Full configuration of corporate
environment to meet CMMC
requirements
Pros
▸ Reduced investment and scope
▸ Smaller attack surface
▸ More controlled system
boundary
▸ Limited (if any) data migration
Cons
▸ Swivel-seat user impact
▸ Illusion of cost savings
▸ Dual administration
▸ Unintended spillage
Pros
▸ Single, consolidated
environment
▸ Eliminates all technical debt
(fresh start)
Cons
▸ Data migration
▸ User impact
▸ Higher deployment costs
▸ Everyone is “locked down”
▸ Non-approved applications
© 2023 C3 Integrated Solutions. All Rights Reserved.
10
Enclave or All-In?
????????
90 People 10 people
90 People
10 people
Commercial
Within CUI Boundary
Company 1 – Research
Firm
Company 3 – Professional
Services
Company 2 - Manufacturing
Enclave
????
All-in
© 2023 C3 Integrated Solutions. All Rights Reserved.
11
Cost Drivers in Building a Strategy
Drivers Costs
▸ Knowledge of business
▸ Knowledge of data
▸ Current situation
▸ Technical debt
▸ Documentation
▸ Previous investment
▸ Internal resources
▸ Expertise/knowledge
▸ Availability
▸ Direct costs
▸ Outside consultant
▸ Internal effort
▸ Indirect costs
▸ Organization impact beyond IT
⁃ Business process changes
⁃ Segmenting and isolating data in an
enclave
▸ Impact of Strategy
⁃ Determines cost of the rest of the
process
▸ Confidence
▸ Risk of pursuing the wrong approach
Strategy costs are
not directly related to
the size of the
company. In most
cases, the scope of
effort drives the cost
profile.
Deployment
© 2023 C3 Integrated Solutions. All Rights Reserved.
13
Setting the System Boundary
System Boundary System Selection
• Communications
• E-mail
• Unified communications
• Collaboration
• Documents
• Other data
• CRM
• Financial
• Operational technology
• Access
• Virtual desktop
• Physical devices
• Mobile devices
• Cloud v. on-premises
• FedRAMP
• Export control
• US data residency
• US persons
Minimizing the
system boundary
reduces the services
that need to be fully
compliant
© 2023 C3 Integrated Solutions. All Rights Reserved.
14
Technology Costs
▸System selection
criteria
▸Accreditations
▸Attestations
▸Export control
▸GovCloud is
typically at least
30% higher
Commercial GCC GCC High
Data Centers Worldwide US Only US only
Accreditation FedRAMP
Moderate*
FedRAMP
Moderate
FedRAMP High
DFARS 7012 No Yes Yes
ITAR/EAR No No Yes
CUI/CDI No Maybe Yes
Customer
Support
Worldwide/Commercial
Personnel
Directory/Nt
k Azure Commercial Azure Gov
M365 G5
($/yr) $684 $684 $1120
Source: Understanding Compliance Between Microsoft 365 Commercial, GCC, GCC-High and DoD Offerings - Microsoft Community Hub
Microsoft 365 Example
Critical to choose the right systems that are accredited and can attest to requirements
© 2023 C3 Integrated Solutions. All Rights Reserved.
15
Deployment Costs
▸Provisioning
▸Establish the tenant
▸Configure
▸Should align to NIST SP 800-171
▸Data migration
▸Proportional to the size of the company
▸Microsoft 365 examples
⁃ Mailboxes
⁃ Teams and SharePoint
• Complexity – Workflows, etc.
Management and
Monitoring
© 2023 C3 Integrated Solutions. All Rights Reserved.
17
Management
Standard Services Compliant Services
▸ System administration
▸ Operational monitoring
▸ Patch management
▸ Support Desk
▸ Moves, adds, changes
▸ Documentation
▸ SLA
▸ SRM
▸ Standardized
procedures
▸ Configuration updates
▸ System reviews
▸ Support for GRC tool
▸ Assessment support
▸ U.S. based
If your corporate IT or
current MSP provider
cannot support
requirements (i.e. US
person only support),
an MSP specializing in
the DIB should be
considered.
© 2023 C3 Integrated Solutions. All Rights Reserved.
18
Monitoring – What to look for
▸ Automation
▸ Export control
▸ 24x7
▸ Documentation
▸SLA
▸SRM
▸IR Plan
▸ Assessment support
▸ Incident response
▸ Certifications
▸SOC-2
▸ Vulnerability scanning
Costs vary widely
depending on the
level of services and
the sophistication of
the solution.
Compliance
© 2023 C3 Integrated Solutions. All Rights Reserved.
20
Cost of Managing Compliance
Initial Costs Ongoing Costs
▸ Pre-assessment review
▸ Documentation
development
▸ System Security Plan (SSP)
▸ Policies
▸ Procedures
▸ Incident response plan
▸ Initial assessment
▸ Gap analysis
▸ POAM development
▸ Initial table-top
▸ Documentation
▸ Management and upkeep
▸ Integration with services?
▸ Assessment support
▸ Annual validations
▸ Table-top
▸ GRC tool
▸ Licensing
▸ Information upkeep
▸ Ad hoc consulting
Compliance costs have a
minimum threshold where
certain activities (i.e.
assessment) are required
regardless of company
size.
Back to Our Examples…
Numbers provided are for illustration purposes only.
© 2023 C3 Integrated Solutions. All Rights Reserved.
22
Cost Profile
Considerations
▸ Commercial v. GCCH M365
▸ IT support costs
▸ Monitoring costs
▸ Users swivel seat
▸ Double count users across both
environments
Not considered
▸ Additional applications
▸ Intangibles
▸User frustration
▸Overhead and administration of multiple
environments
Corporate Government
Microsoft
365
Commercial M365 G5
$57/month
GCC High M365
G5
$1120/year
IT Support
Internal
$150 month
equivalent
Outsourced
$200/month
Monitoring
Commercial Grade
$26/endpoint
Compliant
$35/endpoint
Strategy, deployment and cost of compliance
assumed comparable across examples unless noted.
© 2023 C3 Integrated Solutions. All Rights Reserved.
23
Pre-CMMC Annual IT Budget
▸M365 Commercial
▸G5 license
▸100 users
▸IT Support
▸$150/user cost of operation
▸May be internal or external
▸Monitoring
▸“Commercial grade”
▸$26/endpoint
▸Assume 100 endpoints
▸Annual budget: $279,600
$68,400
$180,00
0
$31,200
$-
$50,000
$100,000
$150,000
$200,000
$250,000
$300,000
Corporate
M365 IT Support Monitoring
© 2023 C3 Integrated Solutions. All Rights Reserved.
24
Company 1: Research Firm
▸GCC High enclave
▸10 users, M365 G5
▸Azure Virtual Desktop
▸User access
▸No additional applications
▸$2000/month usage
▸IT Support
▸$200/user, External vendor
▸Monitoring
▸$35/endpoint (virtual)
▸Total Budget: $343,700
$279,60
0
$64,100
$-
$50,000
$100,000
$150,000
$200,000
$250,000
$300,000
$350,000
$400,000
Annual Budget
Corporate Enclave
© 2023 C3 Integrated Solutions. All Rights Reserved.
25
Company 2: Manufacturing Firm
▸All-In
▸Microsoft 365 GCC High
▸100 users
▸Azure Virtual Desktop
▸Not required
▸Endpoints converted
▸IT Support
▸$200/user
▸External vendor
▸Monitoring
▸$35/endpoint (virtual)
▸Migration costs not considered
▸Total Budget: $401,000
$119,00
0
$240,00
0
$42,000
$-
$50,000
$100,000
$150,000
$200,000
$250,000
$300,000
$350,000
$400,000
$450,000
All-In
M365 IT Support Monitoring
© 2023 C3 Integrated Solutions. All Rights Reserved.
26
Company 3: Professional Services
▸ All-in or Enclave?
▸ Likely the most expensive from a
strategy development perspective
▸ Escalating commitment as users
are added
▸ Increased risk of unintended
spillage
▸ Increased user frustration and
confusion
▸ Break even to go all-in just under
30 users
* Does not consider other applications
nor strain of managing multiple
environments for both IT and users
$-
$100,000
$200,000
$300,000
$400,000
$500,000
$600,000
$700,000
$800,000
0 10 20 30 40 50 60 70 80 90 100
Commerical GCCH Enclave All-In
© 2023 C3 Integrated Solutions. All Rights Reserved.
27
About C3 Integrated Solutions
Technology
Experience
11 years Microsoft partner
6+ years experience in GCC
High
Multiple Gold competencies
Co-Sell Authorized
Client Experience
450+ Microsoft 365 clients
200+ GCC High clients
Deep NIST, DFARS, ITAR
experience
Industry Leader
First to offer GCC High
backup and hosted voice
CMMC Registered
Practitioner Organization
Two successful C3PAO
clients
Wrap-up and Questions
Get Started
Build the barriers that
protect your business,
not disrupt it.
Our mission is to protect sensitive data and prevent breaches by providing world-class
cybersecurity and compliance services to businesses of all sizes.
visit
c3isit.com
1 of 29

Recommended

OPTIMIZING PIPELINES WITH MACHINE LEARNING DECISION SUPPORT by
OPTIMIZING PIPELINES WITH MACHINE LEARNING DECISION SUPPORTOPTIMIZING PIPELINES WITH MACHINE LEARNING DECISION SUPPORT
OPTIMIZING PIPELINES WITH MACHINE LEARNING DECISION SUPPORTwle-ss
20 views29 slides
Cloud ROI and Implementation - A TechBlocks Solutions Guide by
Cloud ROI and Implementation - A TechBlocks Solutions GuideCloud ROI and Implementation - A TechBlocks Solutions Guide
Cloud ROI and Implementation - A TechBlocks Solutions GuideTechBlocks
367 views12 slides
ITAM Tools Day, November 2015 - Concorde by
ITAM Tools Day, November 2015 - ConcordeITAM Tools Day, November 2015 - Concorde
ITAM Tools Day, November 2015 - ConcordeMartin Thompson
443 views14 slides
The CMDB/CMS in the Digital Age: A Bedrock for IT Transformation by
The CMDB/CMS in the Digital Age: A Bedrock for IT TransformationThe CMDB/CMS in the Digital Age: A Bedrock for IT Transformation
The CMDB/CMS in the Digital Age: A Bedrock for IT TransformationEnterprise Management Associates
489 views46 slides
Best Practices for Embedding Analytics by GoodData Product Leader by
Best Practices for Embedding Analytics by GoodData Product LeaderBest Practices for Embedding Analytics by GoodData Product Leader
Best Practices for Embedding Analytics by GoodData Product LeaderProduct School
134 views25 slides
PCM Vision 2019 Keynote: Elliot Baretz by
PCM Vision 2019 Keynote: Elliot BaretzPCM Vision 2019 Keynote: Elliot Baretz
PCM Vision 2019 Keynote: Elliot BaretzPCM
592 views21 slides

More Related Content

Similar to Taking CMMC Seriously - What Is The Cost Of Compliance?

How to Calculate ROI for Network Management & Monitoring by
How to Calculate ROI for Network Management & MonitoringHow to Calculate ROI for Network Management & Monitoring
How to Calculate ROI for Network Management & MonitoringSolarWinds
5.6K views23 slides
Microsoft licensing analysis - an introduction by
Microsoft licensing analysis - an introductionMicrosoft licensing analysis - an introduction
Microsoft licensing analysis - an introductionNiels Jørgen Hansen
1.2K views38 slides
CRMIT Solutions - An Overview by
CRMIT Solutions - An OverviewCRMIT Solutions - An Overview
CRMIT Solutions - An OverviewCRMIT
951 views17 slides
AssetsHub Pitch Deck by
AssetsHub Pitch DeckAssetsHub Pitch Deck
AssetsHub Pitch DeckAssetsHub
25 views15 slides
financial_close_and_disclosure_management_on_cloud by
financial_close_and_disclosure_management_on_cloudfinancial_close_and_disclosure_management_on_cloud
financial_close_and_disclosure_management_on_cloudCharles Wilson
378 views18 slides
Improving Employee Experiences on Cisco RoomOS Devices, Webex, and Microsoft ... by
Improving Employee Experiences on Cisco RoomOS Devices, Webex, and Microsoft ...Improving Employee Experiences on Cisco RoomOS Devices, Webex, and Microsoft ...
Improving Employee Experiences on Cisco RoomOS Devices, Webex, and Microsoft ...ThousandEyes
87 views25 slides

Similar to Taking CMMC Seriously - What Is The Cost Of Compliance? (20)

How to Calculate ROI for Network Management & Monitoring by SolarWinds
How to Calculate ROI for Network Management & MonitoringHow to Calculate ROI for Network Management & Monitoring
How to Calculate ROI for Network Management & Monitoring
SolarWinds5.6K views
CRMIT Solutions - An Overview by CRMIT
CRMIT Solutions - An OverviewCRMIT Solutions - An Overview
CRMIT Solutions - An Overview
CRMIT951 views
AssetsHub Pitch Deck by AssetsHub
AssetsHub Pitch DeckAssetsHub Pitch Deck
AssetsHub Pitch Deck
AssetsHub25 views
financial_close_and_disclosure_management_on_cloud by Charles Wilson
financial_close_and_disclosure_management_on_cloudfinancial_close_and_disclosure_management_on_cloud
financial_close_and_disclosure_management_on_cloud
Charles Wilson378 views
Improving Employee Experiences on Cisco RoomOS Devices, Webex, and Microsoft ... by ThousandEyes
Improving Employee Experiences on Cisco RoomOS Devices, Webex, and Microsoft ...Improving Employee Experiences on Cisco RoomOS Devices, Webex, and Microsoft ...
Improving Employee Experiences on Cisco RoomOS Devices, Webex, and Microsoft ...
ThousandEyes87 views
VMSDeploymentGuide_Extract1a by Tom - Creed
VMSDeploymentGuide_Extract1aVMSDeploymentGuide_Extract1a
VMSDeploymentGuide_Extract1a
Tom - Creed51 views
Under cloud cover: How leaders are accelerating competitive differentiation by Susanne Hupfer, Ph.D.
Under cloud cover: How leaders are accelerating competitive differentiationUnder cloud cover: How leaders are accelerating competitive differentiation
Under cloud cover: How leaders are accelerating competitive differentiation
Migrating apps-to-the-cloud-final by eng999
Migrating apps-to-the-cloud-finalMigrating apps-to-the-cloud-final
Migrating apps-to-the-cloud-final
eng999289 views
Bhawani prasad mdm-cdi-methodology by Bhawani N Prasad
Bhawani prasad mdm-cdi-methodologyBhawani prasad mdm-cdi-methodology
Bhawani prasad mdm-cdi-methodology
Bhawani N Prasad1.5K views
How CMMC Auditors Recommend You Defend Your Organization - Completed March, 2... by Ignyte Assurance Platform
How CMMC Auditors Recommend You Defend Your Organization - Completed March, 2...How CMMC Auditors Recommend You Defend Your Organization - Completed March, 2...
How CMMC Auditors Recommend You Defend Your Organization - Completed March, 2...
MongoDB World 2019: Data Digital Decoupling by MongoDB
MongoDB World 2019: Data Digital DecouplingMongoDB World 2019: Data Digital Decoupling
MongoDB World 2019: Data Digital Decoupling
MongoDB602 views
Critical functionality testing by Maveric Systems
Critical functionality testingCritical functionality testing
Critical functionality testing
Maveric Systems4.3K views
Preview novarica1908 eb-core-business_case by ~Eric Principe
Preview novarica1908 eb-core-business_casePreview novarica1908 eb-core-business_case
Preview novarica1908 eb-core-business_case
~Eric Principe25 views
The Advantages and Pitfalls of Data Centre Consolidation by DAYWATCHER.COM
The Advantages and Pitfalls of Data Centre ConsolidationThe Advantages and Pitfalls of Data Centre Consolidation
The Advantages and Pitfalls of Data Centre Consolidation
DAYWATCHER.COM550 views
Planning for Cloud Profitability From Day One: MSP VAR Companies and Cloud Co... by ProfitBricks
Planning for Cloud Profitability From Day One: MSP VAR Companies and Cloud Co...Planning for Cloud Profitability From Day One: MSP VAR Companies and Cloud Co...
Planning for Cloud Profitability From Day One: MSP VAR Companies and Cloud Co...
ProfitBricks960 views

More from JSchaus & Associates

Sponsored Content: Finding Federal Contract Opportunities (Part 1) by
Sponsored Content: Finding Federal Contract Opportunities (Part 1)Sponsored Content: Finding Federal Contract Opportunities (Part 1)
Sponsored Content: Finding Federal Contract Opportunities (Part 1)JSchaus & Associates
33 views21 slides
Top 40 Federal Contractors - PROFILE #40 - GSK by
Top 40 Federal Contractors - PROFILE #40 - GSKTop 40 Federal Contractors - PROFILE #40 - GSK
Top 40 Federal Contractors - PROFILE #40 - GSKJSchaus & Associates
19 views81 slides
Top 40 Federal Contractors - PROFILE #39 - Hensel Phelps Construction by
Top 40 Federal Contractors - PROFILE #39 - Hensel Phelps ConstructionTop 40 Federal Contractors - PROFILE #39 - Hensel Phelps Construction
Top 40 Federal Contractors - PROFILE #39 - Hensel Phelps ConstructionJSchaus & Associates
18 views77 slides
Top 40 Federal Contractors - PROFILE #38 - Dell by
Top 40 Federal Contractors - PROFILE #38 - DellTop 40 Federal Contractors - PROFILE #38 - Dell
Top 40 Federal Contractors - PROFILE #38 - DellJSchaus & Associates
14 views75 slides
Top 40 Federal Contractors - PROFILE #37 - CACI by
Top 40 Federal Contractors - PROFILE #37 - CACITop 40 Federal Contractors - PROFILE #37 - CACI
Top 40 Federal Contractors - PROFILE #37 - CACIJSchaus & Associates
43 views76 slides
GSA_FedMine_JSchaus_10192023.pptx by
GSA_FedMine_JSchaus_10192023.pptxGSA_FedMine_JSchaus_10192023.pptx
GSA_FedMine_JSchaus_10192023.pptxJSchaus & Associates
17 views46 slides

More from JSchaus & Associates(20)

Sponsored Content: Finding Federal Contract Opportunities (Part 1) by JSchaus & Associates
Sponsored Content: Finding Federal Contract Opportunities (Part 1)Sponsored Content: Finding Federal Contract Opportunities (Part 1)
Sponsored Content: Finding Federal Contract Opportunities (Part 1)
Top 40 Federal Contractors - PROFILE #39 - Hensel Phelps Construction by JSchaus & Associates
Top 40 Federal Contractors - PROFILE #39 - Hensel Phelps ConstructionTop 40 Federal Contractors - PROFILE #39 - Hensel Phelps Construction
Top 40 Federal Contractors - PROFILE #39 - Hensel Phelps Construction
Top 40 Federal Contractors - PROFILE #34 - Steel and Shipbuilding Company by JSchaus & Associates
Top 40 Federal Contractors - PROFILE #34 - Steel and Shipbuilding CompanyTop 40 Federal Contractors - PROFILE #34 - Steel and Shipbuilding Company
Top 40 Federal Contractors - PROFILE #34 - Steel and Shipbuilding Company
GSA Schedule: Requirements, Proposal Prep and - What's Next by JSchaus & Associates
GSA Schedule: Requirements, Proposal Prep and - What's NextGSA Schedule: Requirements, Proposal Prep and - What's Next
GSA Schedule: Requirements, Proposal Prep and - What's Next
Top 40 Federal Contractors - PROFILE #29 - National Security by JSchaus & Associates
Top 40 Federal Contractors - PROFILE #29 - National SecurityTop 40 Federal Contractors - PROFILE #29 - National Security
Top 40 Federal Contractors - PROFILE #29 - National Security
Top 40 Federal Contractors - PROFILE #27 - Oshkosh Defense by JSchaus & Associates
Top 40 Federal Contractors - PROFILE #27 - Oshkosh DefenseTop 40 Federal Contractors - PROFILE #27 - Oshkosh Defense
Top 40 Federal Contractors - PROFILE #27 - Oshkosh Defense

Recently uploaded

2023 First Tee - Greater Richmond Holiday Gift Guide by
2023 First Tee - Greater Richmond Holiday Gift Guide2023 First Tee - Greater Richmond Holiday Gift Guide
2023 First Tee - Greater Richmond Holiday Gift Guidebill151498
80 views14 slides
How can the social and solidarity economy help refugees along their journey? by
How can the social and solidarity economy help refugees along their journey?How can the social and solidarity economy help refugees along their journey?
How can the social and solidarity economy help refugees along their journey?OECD CFE
97 views7 slides
Taking care for elders by
Taking care for eldersTaking care for elders
Taking care for eldersSERUDS INDIA
11 views1 slide
ecb.sp231121_1~8df317dc17.en.pdf by
ecb.sp231121_1~8df317dc17.en.pdfecb.sp231121_1~8df317dc17.en.pdf
ecb.sp231121_1~8df317dc17.en.pdfSociété Tripalio
411 views17 slides
Dr Jean Paul Latyr FAYE - 2023 ReSAKSS Conference.pptx by
Dr Jean Paul Latyr FAYE - 2023 ReSAKSS Conference.pptxDr Jean Paul Latyr FAYE - 2023 ReSAKSS Conference.pptx
Dr Jean Paul Latyr FAYE - 2023 ReSAKSS Conference.pptxAKADEMIYA2063
8 views24 slides
Dr. Ousmane Badiane - 2023 ReSAKSS Conference.pptx by
Dr. Ousmane Badiane - 2023 ReSAKSS Conference.pptxDr. Ousmane Badiane - 2023 ReSAKSS Conference.pptx
Dr. Ousmane Badiane - 2023 ReSAKSS Conference.pptxAKADEMIYA2063
7 views34 slides

Recently uploaded(20)

2023 First Tee - Greater Richmond Holiday Gift Guide by bill151498
2023 First Tee - Greater Richmond Holiday Gift Guide2023 First Tee - Greater Richmond Holiday Gift Guide
2023 First Tee - Greater Richmond Holiday Gift Guide
bill15149880 views
How can the social and solidarity economy help refugees along their journey? by OECD CFE
How can the social and solidarity economy help refugees along their journey?How can the social and solidarity economy help refugees along their journey?
How can the social and solidarity economy help refugees along their journey?
OECD CFE97 views
Dr Jean Paul Latyr FAYE - 2023 ReSAKSS Conference.pptx by AKADEMIYA2063
Dr Jean Paul Latyr FAYE - 2023 ReSAKSS Conference.pptxDr Jean Paul Latyr FAYE - 2023 ReSAKSS Conference.pptx
Dr Jean Paul Latyr FAYE - 2023 ReSAKSS Conference.pptx
AKADEMIYA20638 views
Dr. Ousmane Badiane - 2023 ReSAKSS Conference.pptx by AKADEMIYA2063
Dr. Ousmane Badiane - 2023 ReSAKSS Conference.pptxDr. Ousmane Badiane - 2023 ReSAKSS Conference.pptx
Dr. Ousmane Badiane - 2023 ReSAKSS Conference.pptx
AKADEMIYA20637 views
A terrorist threat originating from Qatar. by fasurijobaf
A terrorist threat originating from Qatar.A terrorist threat originating from Qatar.
A terrorist threat originating from Qatar.
fasurijobaf7 views
Arrow Adoption Training for Kinship Families by ArrowMarketing
Arrow Adoption Training for Kinship FamiliesArrow Adoption Training for Kinship Families
Arrow Adoption Training for Kinship Families
ArrowMarketing40 views
IEA Report: The Oil and Gas Industry in NetZero Transitions by Energy for One World
IEA Report: The Oil and Gas Industry in NetZero TransitionsIEA Report: The Oil and Gas Industry in NetZero Transitions
IEA Report: The Oil and Gas Industry in NetZero Transitions
Social behavioural change to drive community ownership_ Divyang Waghela_Tata ... by India Water Portal
Social behavioural change to drive community ownership_ Divyang Waghela_Tata ...Social behavioural change to drive community ownership_ Divyang Waghela_Tata ...
Social behavioural change to drive community ownership_ Divyang Waghela_Tata ...
Ms. Julie Collins - 2023 ReSAKSS Conference.pptx by AKADEMIYA2063
Ms. Julie Collins - 2023 ReSAKSS Conference.pptxMs. Julie Collins - 2023 ReSAKSS Conference.pptx
Ms. Julie Collins - 2023 ReSAKSS Conference.pptx
AKADEMIYA206310 views
Moving up into upper secondary by Hannah Kitchen - OECD Education Webinar 23N... by EduSkills OECD
Moving up into upper secondary by Hannah Kitchen - OECD Education Webinar 23N...Moving up into upper secondary by Hannah Kitchen - OECD Education Webinar 23N...
Moving up into upper secondary by Hannah Kitchen - OECD Education Webinar 23N...
EduSkills OECD82 views
AABS project overview by WorldFish
AABS project overviewAABS project overview
AABS project overview
WorldFish18 views
UNiTE- Invest to Prevent Violence against Women & Girls! by Christina Parmionova
UNiTE- Invest to Prevent Violence against Women & Girls!UNiTE- Invest to Prevent Violence against Women & Girls!
UNiTE- Invest to Prevent Violence against Women & Girls!
Support a Child Bright Future kurnool by SERUDS INDIA
Support a Child Bright Future kurnoolSupport a Child Bright Future kurnool
Support a Child Bright Future kurnool
SERUDS INDIA8 views

Taking CMMC Seriously - What Is The Cost Of Compliance?

  • 1. Taking CMMC Seriously: What is the Cost of Compliance? September, 19, 2023
  • 2. Welcome! Bill Wootton Chief Revenue Officer C3 Integrated Solutions bwootton@C3isit.com
  • 3. © 2023 C3 Integrated Solutions. All Rights Reserved. 3 Today’s Topics ▸Overview: Major Components of the Cost of CMMC ▸Building a Strategy ▸Deployment ▸Management and Monitoring ▸Compliance ▸Data Enclaves: Options and Impact ▸Three Types of Companies
  • 5. © 2023 C3 Integrated Solutions. All Rights Reserved. 5 Building Your CMMC Strategy Understanding your business Setting the system boundary Determining the organizational impact Determining the expertise you need
  • 6. © 2023 C3 Integrated Solutions. All Rights Reserved. 6 Understanding Your Business External Factors Internal Factors ▸ Your Customers… ▸ Which agencies do you work with? ▸ Your Partners… ▸ Who are your primes and subs? ▸ What are THEIR requirements to continue working with them? ▸ Your Contracts… ▸ What clauses are already in your contracts? ▸ Your Future… ▸ Where will your business be in 2-3 years? ▸ Your Data… ▸ Do you have CUI? ▸ Do you have export-controlled data? ▸ Can you segment it from the rest of the organization? ▸ Your People… ▸ Who directly interacts with CUI ▸ Who indirectly interacts with CUI? ▸ Your Systems… ▸ Which systems store, process, or transit data? The better you know your business, the less you will need a consultant to answer these questions.
  • 7. © 2023 C3 Integrated Solutions. All Rights Reserved. 7 Company Examples: All 100-Person Firms Research Firm • Almost all commercial work • Single DoD contract • Team segmented from rest of the firm Manufacturing Firm • Approximately 90% DoD work • Highly customized parts for aircraft • Large amounts of export- controlled data Professional Services • Many distributed contracts • Team members rotate between DoD and civilian work regularly • Centralized admin supports all contracts Current systems are not compliant. No preexisting certifications (e.g. ISO 9001)
  • 8. © 2023 C3 Integrated Solutions. All Rights Reserved. 8 Employee Access to CUI (100-person Company) ???????? 90 People 10 people 90 People 10 people Commercial Within CUI Boundary Company 1 – Research Firm Company 3 – Professional Services Firm Company 2 – Manufacturing Firm
  • 9. © 2023 C3 Integrated Solutions. All Rights Reserved. 9 Determining System Boundaries: Enclave or All-In? ENCLAVE Separate environment isolated from the corporate environment ALL-IN Full configuration of corporate environment to meet CMMC requirements Pros ▸ Reduced investment and scope ▸ Smaller attack surface ▸ More controlled system boundary ▸ Limited (if any) data migration Cons ▸ Swivel-seat user impact ▸ Illusion of cost savings ▸ Dual administration ▸ Unintended spillage Pros ▸ Single, consolidated environment ▸ Eliminates all technical debt (fresh start) Cons ▸ Data migration ▸ User impact ▸ Higher deployment costs ▸ Everyone is “locked down” ▸ Non-approved applications
  • 10. © 2023 C3 Integrated Solutions. All Rights Reserved. 10 Enclave or All-In? ???????? 90 People 10 people 90 People 10 people Commercial Within CUI Boundary Company 1 – Research Firm Company 3 – Professional Services Company 2 - Manufacturing Enclave ???? All-in
  • 11. © 2023 C3 Integrated Solutions. All Rights Reserved. 11 Cost Drivers in Building a Strategy Drivers Costs ▸ Knowledge of business ▸ Knowledge of data ▸ Current situation ▸ Technical debt ▸ Documentation ▸ Previous investment ▸ Internal resources ▸ Expertise/knowledge ▸ Availability ▸ Direct costs ▸ Outside consultant ▸ Internal effort ▸ Indirect costs ▸ Organization impact beyond IT ⁃ Business process changes ⁃ Segmenting and isolating data in an enclave ▸ Impact of Strategy ⁃ Determines cost of the rest of the process ▸ Confidence ▸ Risk of pursuing the wrong approach Strategy costs are not directly related to the size of the company. In most cases, the scope of effort drives the cost profile.
  • 13. © 2023 C3 Integrated Solutions. All Rights Reserved. 13 Setting the System Boundary System Boundary System Selection • Communications • E-mail • Unified communications • Collaboration • Documents • Other data • CRM • Financial • Operational technology • Access • Virtual desktop • Physical devices • Mobile devices • Cloud v. on-premises • FedRAMP • Export control • US data residency • US persons Minimizing the system boundary reduces the services that need to be fully compliant
  • 14. © 2023 C3 Integrated Solutions. All Rights Reserved. 14 Technology Costs ▸System selection criteria ▸Accreditations ▸Attestations ▸Export control ▸GovCloud is typically at least 30% higher Commercial GCC GCC High Data Centers Worldwide US Only US only Accreditation FedRAMP Moderate* FedRAMP Moderate FedRAMP High DFARS 7012 No Yes Yes ITAR/EAR No No Yes CUI/CDI No Maybe Yes Customer Support Worldwide/Commercial Personnel Directory/Nt k Azure Commercial Azure Gov M365 G5 ($/yr) $684 $684 $1120 Source: Understanding Compliance Between Microsoft 365 Commercial, GCC, GCC-High and DoD Offerings - Microsoft Community Hub Microsoft 365 Example Critical to choose the right systems that are accredited and can attest to requirements
  • 15. © 2023 C3 Integrated Solutions. All Rights Reserved. 15 Deployment Costs ▸Provisioning ▸Establish the tenant ▸Configure ▸Should align to NIST SP 800-171 ▸Data migration ▸Proportional to the size of the company ▸Microsoft 365 examples ⁃ Mailboxes ⁃ Teams and SharePoint • Complexity – Workflows, etc.
  • 17. © 2023 C3 Integrated Solutions. All Rights Reserved. 17 Management Standard Services Compliant Services ▸ System administration ▸ Operational monitoring ▸ Patch management ▸ Support Desk ▸ Moves, adds, changes ▸ Documentation ▸ SLA ▸ SRM ▸ Standardized procedures ▸ Configuration updates ▸ System reviews ▸ Support for GRC tool ▸ Assessment support ▸ U.S. based If your corporate IT or current MSP provider cannot support requirements (i.e. US person only support), an MSP specializing in the DIB should be considered.
  • 18. © 2023 C3 Integrated Solutions. All Rights Reserved. 18 Monitoring – What to look for ▸ Automation ▸ Export control ▸ 24x7 ▸ Documentation ▸SLA ▸SRM ▸IR Plan ▸ Assessment support ▸ Incident response ▸ Certifications ▸SOC-2 ▸ Vulnerability scanning Costs vary widely depending on the level of services and the sophistication of the solution.
  • 20. © 2023 C3 Integrated Solutions. All Rights Reserved. 20 Cost of Managing Compliance Initial Costs Ongoing Costs ▸ Pre-assessment review ▸ Documentation development ▸ System Security Plan (SSP) ▸ Policies ▸ Procedures ▸ Incident response plan ▸ Initial assessment ▸ Gap analysis ▸ POAM development ▸ Initial table-top ▸ Documentation ▸ Management and upkeep ▸ Integration with services? ▸ Assessment support ▸ Annual validations ▸ Table-top ▸ GRC tool ▸ Licensing ▸ Information upkeep ▸ Ad hoc consulting Compliance costs have a minimum threshold where certain activities (i.e. assessment) are required regardless of company size.
  • 21. Back to Our Examples… Numbers provided are for illustration purposes only.
  • 22. © 2023 C3 Integrated Solutions. All Rights Reserved. 22 Cost Profile Considerations ▸ Commercial v. GCCH M365 ▸ IT support costs ▸ Monitoring costs ▸ Users swivel seat ▸ Double count users across both environments Not considered ▸ Additional applications ▸ Intangibles ▸User frustration ▸Overhead and administration of multiple environments Corporate Government Microsoft 365 Commercial M365 G5 $57/month GCC High M365 G5 $1120/year IT Support Internal $150 month equivalent Outsourced $200/month Monitoring Commercial Grade $26/endpoint Compliant $35/endpoint Strategy, deployment and cost of compliance assumed comparable across examples unless noted.
  • 23. © 2023 C3 Integrated Solutions. All Rights Reserved. 23 Pre-CMMC Annual IT Budget ▸M365 Commercial ▸G5 license ▸100 users ▸IT Support ▸$150/user cost of operation ▸May be internal or external ▸Monitoring ▸“Commercial grade” ▸$26/endpoint ▸Assume 100 endpoints ▸Annual budget: $279,600 $68,400 $180,00 0 $31,200 $- $50,000 $100,000 $150,000 $200,000 $250,000 $300,000 Corporate M365 IT Support Monitoring
  • 24. © 2023 C3 Integrated Solutions. All Rights Reserved. 24 Company 1: Research Firm ▸GCC High enclave ▸10 users, M365 G5 ▸Azure Virtual Desktop ▸User access ▸No additional applications ▸$2000/month usage ▸IT Support ▸$200/user, External vendor ▸Monitoring ▸$35/endpoint (virtual) ▸Total Budget: $343,700 $279,60 0 $64,100 $- $50,000 $100,000 $150,000 $200,000 $250,000 $300,000 $350,000 $400,000 Annual Budget Corporate Enclave
  • 25. © 2023 C3 Integrated Solutions. All Rights Reserved. 25 Company 2: Manufacturing Firm ▸All-In ▸Microsoft 365 GCC High ▸100 users ▸Azure Virtual Desktop ▸Not required ▸Endpoints converted ▸IT Support ▸$200/user ▸External vendor ▸Monitoring ▸$35/endpoint (virtual) ▸Migration costs not considered ▸Total Budget: $401,000 $119,00 0 $240,00 0 $42,000 $- $50,000 $100,000 $150,000 $200,000 $250,000 $300,000 $350,000 $400,000 $450,000 All-In M365 IT Support Monitoring
  • 26. © 2023 C3 Integrated Solutions. All Rights Reserved. 26 Company 3: Professional Services ▸ All-in or Enclave? ▸ Likely the most expensive from a strategy development perspective ▸ Escalating commitment as users are added ▸ Increased risk of unintended spillage ▸ Increased user frustration and confusion ▸ Break even to go all-in just under 30 users * Does not consider other applications nor strain of managing multiple environments for both IT and users $- $100,000 $200,000 $300,000 $400,000 $500,000 $600,000 $700,000 $800,000 0 10 20 30 40 50 60 70 80 90 100 Commerical GCCH Enclave All-In
  • 27. © 2023 C3 Integrated Solutions. All Rights Reserved. 27 About C3 Integrated Solutions Technology Experience 11 years Microsoft partner 6+ years experience in GCC High Multiple Gold competencies Co-Sell Authorized Client Experience 450+ Microsoft 365 clients 200+ GCC High clients Deep NIST, DFARS, ITAR experience Industry Leader First to offer GCC High backup and hosted voice CMMC Registered Practitioner Organization Two successful C3PAO clients
  • 29. Get Started Build the barriers that protect your business, not disrupt it. Our mission is to protect sensitive data and prevent breaches by providing world-class cybersecurity and compliance services to businesses of all sizes. visit c3isit.com