Semel Consulting

Semel Consulting The trusted compliance expert helping you to secure your business since 1980. CMMC - DFARS - HIPAA - NIST

06/19/2026

The drawing is not the end of the CMMC problem.

It is the beginning of it.

To understand how CUI spreads through your shop, you have to understand the derived data rule.

When a prime contractor or government agency provides CUI-marked specifications, that CUI status flows from the source document to the documents and data created from it.

A specification becomes a drawing.
The drawing becomes machine code.
The machined part creates CMM reports.
Quality creates inspection records and certifications of conformance.

If it is derived, it is also CUI.

That is where many manufacturers get scope wrong. They protect the original drawing and miss the data created from it.

CMMC does not stop at the source file.
It follows the work.

06/17/2026

A lot of defense contractors believe they are not receiving CUI when they are.
That is where the problem starts.

In plain terms, if a file, drawing, document, email, or piece of data came from a defense contractor or the military, and it describes how a part is built, tested, or used, it is very likely CUI.

The other mistake is assuming that missing markings make the data safe.
They do not.

A drawing received from a Department of War customer does not lose its protection just because someone forgot to mark it as CUI.

If you are not sure whether you have CUI, contact your Department of War contract manager or your prime contractor. Until you are told that information is not CUI, assume it is and protect it accordingly.

That one assumption can prevent a lot of expensive mistakes.

A lot of CMMC advice is not completely wrong.That is what makes it dangerous.It may be right about the tool and wrong ab...
06/16/2026

A lot of CMMC advice is not completely wrong.

That is what makes it dangerous.

It may be right about the tool and wrong about the scope. It may be right about documentation and wrong about how the work actually moves. It may be right about the MSP’s responsibility and still miss what the contractor owns. It may be right in theory and still not hold up in the company’s actual environment.

That is the part contractors need to understand.

CMMC does not evaluate one clean slice of the business. It evaluates whether the company can support what it is claiming.

That includes the contract, the information, the systems, the workflows, the people, the provider relationship, the evidence, and the assessment process itself.

This is why I keep saying that CMMC gets expensive when companies work in the wrong order.

Good advice aimed at the wrong problem still creates rework.

What part of your CMMC plan is based on something you know, and what part is based on advice that only looked at one piece of the problem?

If you have tried to understand CMMC from vendor slides, summaries, and secondhand explanations, you already know the pr...
06/15/2026

If you have tried to understand CMMC from vendor slides, summaries, and secondhand explanations, you already know the problem.

A lot of it sounds clear until you try to apply it to a real company.
That is where contractors get hurt.

CMMC is not just a cybersecurity checklist. It is an assessment process. That means the question is not whether something sounds reasonable in a meeting. The question is whether it will hold up when the company has to show what it actually does, who owns it, where the information goes, and what supports the claim.

This is why who you learn from matters.

A tool vendor may understand the tool. An MSP may understand the systems. A documentation person may understand the paperwork. All of that can help.

But none of that replaces understanding how the assessment process sees the whole company.

If your contracts depend on getting CMMC right, are you learning from someone who understands the full assessment process, or from someone who only sees one part of it?

06/11/2026

Most manufacturers do not realize how much of their work may already be in CMMC scope.

If CUI is flowing from your blueprint all the way through your inspection reports, the issue is not just the engineering system that stores the original file.

Engineering systems that store, access, or generate CUI are in scope. Boundary systems can be in scope. Machines on the shop floor can be in scope. Cloud-based software can be in scope. Security tools, external IT providers, contractor risk managed assets, facility systems, test equipment, and operational technology can all matter.

That is where companies get surprised.

They think they are scoping a few obvious systems. Then the work is tested and the scope follows how the data actually moves through the business.

If you are preparing for CMMC Level 2, do not start by guessing what is in scope.

Start by following the CUI.

With Matt Travis, CEO of the Cyber AB, the official CMMC accreditation body, at the CMMC conference in San Diego.
06/09/2026

With Matt Travis, CEO of the Cyber AB, the official CMMC accreditation body, at the CMMC conference in San Diego.

More than 200 people registered for the CMMC Roundtable, and more than 100 attended live.That says a lot about where the...
06/05/2026

More than 200 people registered for the CMMC Roundtable, and more than 100 attended live.

That says a lot about where the market is right now.

People know CMMC matters.

The harder question is what to do next.

That is where my work usually starts.

As a CMMC Certified Assessor, I see companies trying to solve different problems with the same answer.

Some contractors need training because the right people inside the company still do not understand what CMMC requires. Some need a QuickStart because they need to know whether their scope is right before more money gets spent. Some need assessment preparation because the pressure is already real.

MSPs are in a similar position.

Some are helping clients move in the right direction. Some are trying to understand where their responsibility starts and stops. Some are being pulled into CMMC conversations their clients do not fully understand yet.

Those are different situations.
They should not all be solved the same way.

That is why the roundtable was valuable. It brought together respected leaders from across the CMMC ecosystem to keep the conversation practical and moving in the right direction.

The work now is helping contractors and MSPs take the right next step before the wrong one is devastatingly expensive. Watch the replay here:
https://bit.ly/CMMC-roundtable-interview
Passcode:
M ?m^V

Most of the webinar panel in the pit lane at the Indianapolis Motor Speedway.

One of the best parts of the CMMC Roundtable was hearing the same challenge from different parts of the ecosystem.Each g...
06/05/2026

One of the best parts of the CMMC Roundtable was hearing the same challenge from different parts of the ecosystem.

Each group touches CMMC from a different angle.

This is important because contractors are not preparing for a conversation. They are preparing for an assessment.

As a CMMC Certified Assessor, I look at these conversations through one lens:

What will actually hold up when the company is evaluated?

An MSP can be doing good technical work and still not own the whole business process. Documentation can look clear and still not match how work actually happens. Assessment preparation can be underway and still be aimed at the wrong scope.

That is not about blame.

That is how complicated CMMC gets when contracts, systems, workflows, providers, and assessment expectations all come together.

That is why conversations like this matter. They bring the right people into the same discussion so contractors and MSPs can get closer to the real process, not just one piece of it.

If you want to hear more of our conversation and how it can help your business, I’ll leave a link to the webinar replay in the comments.

3rd Annual CMMC Roundtable WebinarExcited to have been part of the webinar panel in the Lifeline Data Centers suite at t...
06/03/2026

3rd Annual CMMC Roundtable Webinar

Excited to have been part of the webinar panel in the Lifeline Data Centers suite at the Indianapolis Motor Speedway during INDY 500 weekend this year.

If you want to hear the real state of CMMC from respected leaders across CyberAB, C3PAOs, GRC, MSPs, and the broader CMMC ecosystem, I will leave the link in the comments.

I am proud to be associated with such a strong group of professionals and organizations who continue working to move the industry in a positive direction.

Conversations like these are what help strengthen the program and support the Defense Industrial Base moving forward.

Rose and I arrived last night in Albany, NY where we are speaking at the New York State Cybersecurity Conference this mo...
06/02/2026

Rose and I arrived last night in Albany, NY where we are speaking at the New York State Cybersecurity Conference this morning.

Address

6547 Midnight Pass Road #90
Sarasota, FL
34242

Alerts

Be the first to know and let us send you an email when Semel Consulting posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Share