"We are in a messy middle situation, where they don't have funding certainty, but they also don't have regulatory certainty," said Stephanie Kostro. Interview transcript Terry Gerton Two important topics. One is CMMC. The deadline for CMMC reform comments has just passed. PSC submitted comments on that. What were at the top of your list in terms of concerns or feedback on the proposal? Stephanie Kostro So just as a reminder to your listening audience, Terry, PSC represents some 400 member companies that provide services and solutions. And a lot of those are technology companies. And so we were present as the creation here at PSC when CMMC came into being, you know, seven years ago, and this is not the first strategic pause, the first time an executive branch action had been taken to review this program, and we are very, very interested in what happens with CMM see for a couple of reasons. We have long voiced a few overarching concerns with how the federal government as an enterprise tackles cybersecurity internally within the government as well as with its contracting partners. And I’ll let you know what those three overarching concerns that we typically highlight are, one, that any reforms in cybersecurity as it affects contractors and industry that support the government really needs to be consistent. Any rules that they have for cybersecurity if you’re a Department of War or Defense contractor, or if you are a DHS contractor, or a Health and Human Services contractor, doesn’t it make sense to have common cybersecurity standards across the board? From an industry perspective, that makes sense because oftentimes if you a defense contractor, you’re also a Homeland Security contractor. So to have two different standards is problematic and costly, to be honest. The second overarching concern is