5 min read

Fear Is Not a Compliance Strategy. A Process Is.

Featured Image

Boe Quisenberry, vCISO at Qultimate, breaks down why CMMC decisions built on panic and guesswork cost more than the ones built on a repeatable, fact-based process.

Key Takeaways

  • The CMMC pause suspended phases two and three, but the NIST 800-171 obligations behind it, and the November 2028 final deadline, were not removed.
  • Complicated-sounding compliance questions usually have a clear answer already published in the regulation and the assessment guide. Guessing is unnecessary.
  • Framing risk in dollar terms, rather than vague warnings, gives executives a more accurate basis for decisions.
  • In the CMMC space, fear is a common, and costly, driver of hiring and vendor decisions.
  • The first diagnostic question in any engagement is where an organization's CUI lives, followed by whether they can picture that environment simply.
  • Not every client needs the same response. A small business that isn't storing CUI needs documentation and training, not an audit or a GCC High enclave.

Table of Contents

  1. The Deadline That Didn't Move
  2. Read The Rule Before You Panic
  3. Fear Is Expensive. Facts Are Cheap.
  4. The Warning Sign Boe Watches For When Hiring
  5. Every Engagement Starts With One Question
  6. Not Every Client Needs A GCC High Enclave

Most of the current conversation around CMMC is about timing: what the pause changes, what it doesn't, and what to do while phases two and three sit suspended. Boe Quisenberry, vCISO at Qultimate, spends his days advising contractors through exactly that uncertainty, and he has noticed a pattern in how organizations respond to it.

Some treat the pause as permission to stop planning. Others let fear, of missing a deadline, of hiring the wrong vendor, of underestimating a risk, drive decisions that a calmer process would make better and cheaper.

Quisenberry's approach cuts against both instincts. Read the actual rule before reacting to it. Put a real number on a risk before letting a vague warning make the decision. Ask one diagnostic question before assuming how much work an engagement actually requires. What follows is how he applies that discipline across a pause, a hiring decision, an executive conversation, and a client engagement.

 

The Deadline That Didn't Move

"If I had one takeaway," Quisenberry says, "it's that phase two and phase three were suspended. That's in the class deviation memo."

But that pause, in his view, is easy to misread. "The NIST 800-171 obligations have been around for a long time, and those obligations remain," he says. The November 2028 deadline for the program's final installment was not removed either.

His guidance for organizations sitting on that fact is simple: keep moving. "I think organizations should continue to plan to move towards that deadline until told otherwise," he says.

 

Read The Rule Before You Panic

Quisenberry describes compliance as more approachable than most people assume. "CMMC and compliance itself is not rocket science," he says. "It's a very straightforward, simple thing, right? The regulation's published, the assessment guide's published."

When a hard question comes up, he doesn't guess. "I don't go to the internet. I don't speculate. I just go read the rule, and then I give an answer based on what the rule says," he says. Only when a question gets genuinely complicated does he loop in his network, and even then, most answers are already sitting in the text.

That same instinct for clarity shapes how he sequences client work. "The most important piece of advice I would give is divide work into durable work versus timing sensitive work," he says, a distinction that keeps teams from treating every task like an emergency.

 

Fear Is Expensive. Facts Are Cheap.

Quisenberry uses a simple example to make an abstract idea concrete. Telling an executive "you're taking on more risk" rarely changes behavior, because it doesn't give them anything to act on. Quantifying it does. "If you take this risk on, there's a 10% chance that you're gonna end up spending $5 million down the road on this," he says, describing the alternative framing. "If that was a known quantity, that CEO would probably be informed differently and take different action."

The lesson generalizes past any one conversation. Executives don't need to be scared into a decision. They need the actual number.

 

The Warning Sign Boe Watches For When Hiring

When Quisenberry is the one hiring a contractor, he starts with a simple filter: he's either mitigating risk, supplementing staff, or saving money, and he has to know which one before anything else. For CMMC specifically, it's usually the first two. "Probably not so much the cost savings as that's well documented," he says.

That same clarity, he argues, should run in both directions during the interview itself. "In the CMMC space, I think it's very easy for people to allow fear to drive their decisions," he says. If a candidate leans on urgency instead of explanation, essentially saying "you need me so that you can solve this problem, but I don't really understand what the problem is," he treats it as a warning flag, not a selling point.

 

Every Engagement Starts With One Question

Every new client believes they know where they stand, and Quisenberry has learned that belief is usually only partly true. "They're not necessarily where they think they are from a compliance perspective, even if their security is in pretty good shape," he says.

So he starts in the same place every time. "Looking at CMMC specifically, my first question almost always is: where does your CUI live?" If a client can answer that, his second question follows immediately: "Do you have a picture of it? Just a simple picture, one that anybody can understand." Only once a client can see their own environment at that level does he move into the details of the POA&M and the rest of the assessment.

 

Not Every Client Needs A GCC High Enclave

The same first question also determines how much a client actually needs to do. Quisenberry describes a small, roughly 30-to-35-person client that reached out for help on a cost-favorable, supplementary basis. His opening question was the usual one: where does your CUI live? The client's answer was straightforward. "We're not storing any."

That answer changed the entire engagement. "Let's not rush into an audit. Let's not rush into building a GCC High enclave," he told them. "Let's document that. Let's put everything into awareness and training, acceptable use policy, so that you don't start storing and transmitting CUI."

The standard Quisenberry describes isn't complicated: read the actual rule before speculating, put a real number on the risk before reacting to it, and size the response to what an organization's environment actually requires. Everything else is fear filling in for information.

BEMO builds CMMC programs around that same discipline, scoping the work to what a client's environment actually requires and tying every recommendation back to the regulation rather than a worst-case assumption, so decisions get made on facts instead of urgency.

 

Frequently Asked Questions

Did the CMMC pause remove the compliance deadline?

No. Phase two and phase three of the rollout were suspended, per the class deviation memo, but the NIST 800-171 obligations behind CMMC remain in place, and the November 2028 deadline for the program's final installment was not removed.

Where should a CMMC engagement start?

With one question: where does the organization's CUI live. Quisenberry follows that with a second question, asking whether the client can produce a simple picture of that environment, before moving into the POA&M and deeper assessment work.

Book a Free Consultation

Does every organization need the same level of CMMC investment?

No. Quisenberry right-sizes the response to what a client's environment actually requires. A small business that isn't storing CUI may only need documentation, training, and an acceptable use policy, not an audit or a GCC High enclave.

How does Quisenberry frame risk for executives?

In dollar terms rather than vague warnings. Telling a CEO they are "taking on more risk" is abstract; quantifying the odds and dollar exposure of a specific outcome gives them something they can actually act on.

What's the biggest driver of bad CMMC decisions?

Fear. Fear-driven hiring and vendor decisions as a recurring pattern in the CMMC space, and treats a candidate or vendor who leans on urgency instead of explanation as a warning sign.

Leave us a comment!