Transcript
A (0:02)
All right everybody, it is Thanksgiving. It is November of 2025. So happy Turkey Day to everybody. We got a little bit of a scoop for you here on the show this week. Since the end of October, we have learned of at least half a dozen defense contractors that have received Official notices for DoD's Defense Industrial based cybersecurity Assessment center, the DIBCAC team, informing them that they will be undergoing in person audits of their compliance with DFARS clause 2522047, 0.12, including their implementation of the requirements in this special publication 800 171, Red Alert, Red Flag, nightmare scenario, not the email that anybody wants to get right before the holidays or forever. The problem is that every one of these companies assumed that they would only need to achieve CMMC level one self assessment status. And so while everyone has been focused on CMMC, DFARS clause 252-204-70 20 has been in contracts since the year 2020 and it gives DOD the right to show up at any time and audit your cybersecurity compliance. So what happens when you get the knock on your door? What do these notices actually look like? That's what we're going to talk about today.
B (1:31)
This is one of those times where it's really, really important to read the entire text message. Because when you send me a text message and said, we're doing a Thanksgiving Day show, Jacob, and you said all I read was scoop, assume and knock at the door, I thought it was the people that are about to knock on my door. You were going to be one of them. You were going to have a scoop of delicious ice cream to go on top of a piece of pie that we were going to eat with friends and family. And now you're telling me that DIBCAC might come knocking on the door for some DIV organizations. And that kind of blows my mind because I heard we always had the, the old adage right was dip, CAC may come calling and they may want to see your documentation. You know, they'll call you on Monday and they want to see your documentation on Friday. I thought that would be what people would be more accustomed to. But now we're saying people are thinking that they're going to get level one self assessed and dip.
A (2:15)
Yeah.
B (2:16)
When we're doing a high assessment.
A (2:17)
Yeah. Now it's, it's a whole other conversation around how somebody would think that they were CMMC level one if, I don't know, they were receiving marked cui and they work on critical programs and they're the prime contractor and that they've had these clauses in their contracts all along. Like I said, totally different story. No judgment. We're going to save that for another conversation.
B (2:39)
