CMMC Level 2: Documentation, Costs, and Audit Readiness | Interview with Bruno Lecoq episode artwork

EPISODE · Aug 10, 2026 · 41 MIN

CMMC Level 2: Documentation, Costs, and Audit Readiness | Interview with Bruno Lecoq

from Secure & Simple — Podcast for Consultants and vCISOs on Cybersecurity Governance and Compliance · host Dejan Kosutic

Dejan Kosutic hosts Bruno Lecoq (co-founder, CEO, and CISO at BEMO) to explain CMMC compliance for Department of Defense contractors and suppliers, including those outside the U.S. They cover CMMC basics (levels, CUI vs. FCI, C3PAO assessments, phase 1 boundary review and phase 2 audit), current capacity challenges (about 93 C3PAOs vs. roughly 200,000 contractors), and why many companies fail early due to incomplete documentation. Bruno shares BEMO's experience (29 policies, 46 procedures, 14 configuration documents, 700+ pieces of evidence, and a 300-page SSP) and emphasizes leadership buy-in, parallel technical and documentation work, proof-based evidence, ongoing monthly/quarterly reviews, and maintaining compliance after certification. They discuss scoping CUI boundaries, tooling constraints (e.g., GCC/GCC High), subcontractor requirements varying by contract, and typical assessment costs ($45K–$55K plus ~$10K mock).Note: This interview was recorded in June 2026, before the U.S. Department of Defense suspended the planned rollout of CMMC Phase 2.Links from the episode: - Conformio software to streamline and scale ISO 27001 implementation and maintenance for your clients: https://advisera.co/Conformio-software- White label documentation toolkits for NIS2, DORA, ISO 27001, and other ISO standards to create all the required documents for your clients: https://advisera.co/page-all-toolkits - Accredited Lead Auditor and Lead Implementer courses for various standards and frameworks to show your expertise to potential clients: https://advisera.co/Consultant-Courses- Company Training Academy with numerous videos for NIS2, DORA, ISO 27001, and other frameworks to organize training and awareness programs for your client’s workforce: https://advisera.co/page-Company-Training-Account  - Beginner's Course for ISO, Cybersecurity, and AI Consultants: https://www.youtube.com/playlist?list=PLHwD3nQun7caKFq80LxNNYKIabATlyA7t- How to Grow Your Cybersecurity, ISO, or AI Consultancy: Advanced Course:https://advisera.co/GrowYourConsultancyTraining  (00:00) - Interview with Bruno Lecoq (01:00) - Who CMMC Applies To (05:31) - Assessors Capacity Bottleneck (08:30) - Audit Phases Evidence Review (15:12) - CMMC vs NIST 800-171 (16:25) - Best Practice Implementation Steps (18:55) - How Does the Audit Look? (22:16) - Project Success Factors (23:50) - Defining CUI Scope (28:58) - Subcontractors And Contracts (33:21) - Risk Flexibility (36:21) - Costs And Timelines (39:47) - Resources for Consultants and Security Officers

Episode metadata supplied by the publisher feed · Published Aug 10, 2026

Embed this episode

Ready to play

CMMC Level 2: Documentation, Costs, and Audit Readiness | Interview with Bruno Lecoq

0:00 41:08

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Secure & Simple — Podcast for Consultants and vCISOs on Cybersecurity Governance and Compliance?

This episode is 41 minutes long.

When was this Secure & Simple — Podcast for Consultants and vCISOs on Cybersecurity Governance and Compliance episode published?

This episode was published on August 10, 2026.

Can I download this Secure & Simple — Podcast for Consultants and vCISOs on Cybersecurity Governance and Compliance episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!