PODCAST · technology
CMMC Compliance Guide
by CMMC Compliance Guide
Our experiences inspired the creation of The CMMC Compliance Guide Podcast and its accompanying resources. The podcast began as a way to share what we learned through real-world challenges—like helping that aerospace machine shop—and to provide accessible education for businesses navigating DoD cybersecurity requirements.The CMMC Compliance Guide Podcast breaks down complex topics like NIST 800-171 and CMMC into actionable, easy-to-understand steps. Whether you’re a subcontractor struggling to meet compliance deadlines or a business owner looking to secure your supply chain, the guide offers practical advice to help you take control of your cybersecurity journey.
-
59
Top CMMC Compliance Mistakes and How to Avoid Them
Submit any questions you would like answered on the podcast!In this episode of the CMMC Compliance Guide Podcast, we break down the most common mistakes defense contractors make when preparing for CMMC compliance and how those mistakes can cost you time, money, and even future contracts.Even though CMMC 2.0 is now enforceable, many companies are still struggling with readiness. The issue is not effort, it is approach. Many contractors start in the wrong place, leading to overspending, failed assessments, or compliance gaps that could have been avoided.We cover critical topics like scoping mistakes, why treating CMMC as an IT-only project creates problems, and how focusing on tools too early can lead to unnecessary costs. We also explain why documentation and ongoing evidence are essential for passing an assessment and building trust with assessors.You will also learn why submitting an inaccurate SPRS score can create serious legal risk, how long CMMC actually takes to implement, and why waiting too long to start can put your contracts in jeopardy.If you are a small or mid-sized contractor in the defense industrial base, this episode will help you avoid the most common pitfalls and take a smarter approach to compliance.
-
58
Can You Create CUI? CMMC Scope, ERP Systems, and Contractor Risk Explained
Submit any questions you would like answered on the podcast!In this episode of the CMMC Compliance Guide Podcast, we tackle one of the most misunderstood topics in CMMC compliance.Many contractors assume that if information is not marked as controlled unclassified information, then it is not CUI. But that assumption can lead to serious compliance risks.We break down how manufacturers and machine shops can actually create CUI while performing contract work, even if the original data was not clearly marked.We also cover how ERP systems factor into CMMC scope, when systems are considered in or out of scope, and how improper scoping decisions can create major compliance gaps.You will learn what derived CUI is, how it applies to things like CNC G code, and why simply removing identifying details from documents does not make them safe.We also explain who determines what qualifies as CUI, how scope can expand across your network, and what realistic cost and infrastructure decisions look like for small and mid sized contractors.If you are part of the defense supply chain, this episode will help you avoid one of the most common and costly misunderstandings in CMMC.
-
57
The Hidden Operational Workload Behind CMMC Compliance
Submit any questions you would like answered on the podcast!In this episode of the CMMC Compliance Guide Podcast, we break down one of the biggest misconceptions in CMMC compliance.Most contractors think CMMC is just a cybersecurity upgrade. Install a few tools, write some policies, and you are ready for an assessment. But that is not how CMMC actually works.The real challenge is the operational workload behind compliance.We walk through what that workload actually looks like, including documentation, system security plans, asset management, workforce training, evidence collection, and continuous monitoring. These are the areas that consume the most time and are often underestimated by small and mid sized defense contractors.We also cover how CMMC impacts your supply chain, including subcontractor flowdown requirements and what you are responsible for as a prime or subcontractor.If you are preparing for CMMC Level 1 or Level 2, this episode will help you understand the true scope of work so you can avoid delays, failed assessments, and costly surprises.
-
56
CMMC Reassessments Explained: What Changes Trigger a New Assessment
Submit any questions you would like answered on the podcast!In this episode of the CMMC Compliance Guide Podcast, we break down one of the most overlooked risks in CMMC compliance. What actually happens when your environment changes after an assessment?Many contractors assume that once they pass a CMMC assessment or complete a self assessment, they are set for the next year or even three years. But recent guidance from the Cyber AB town hall reveals that certain changes can trigger a brand new assessment.We walk through what qualifies as a significant change, what does not, and how decisions are made when things fall into the gray area. We also cover real examples like mergers, switching MSPs, expanding networks, and upgrading tools.If you are planning changes to your environment or trying to future proof your compliance strategy, this episode will help you avoid costly mistakes and unnecessary reassessments.We also answer a listener question about how to identify FCI and how it should be handled under CMMC Level 1 requirements.If you are a small or mid sized defense contractor, aerospace supplier, or manufacturer, this is critical guidance you do not want to miss.
-
55
How Prime Contractors Evaluate Supplier Cybersecurity and CMMC Compliance
Submit any questions you would like answered on the podcast!What are prime contractors actually expecting from suppliers when it comes to CMMC and cybersecurity?In this episode of the CMMC Compliance Guide Podcast, Austin and Brooke sit down with Bo Birdwell from Elbit Systems of America to get the prime contractor perspective on what suppliers need to understand right now. They break down how primes are thinking about CMMC, what they are looking for in small and mid-sized defense suppliers, and why some companies are about to hit a major inflection point if they are still treating CMMC like it is optional.Bo shares how Elbit evaluates supplier cybersecurity posture, the red flags that stand out immediately, and why companies that wait too long may not lose the bus forever, but they may lose their place in line. The conversation also covers flowdown realities, the difference between FCI and CUI risk, why COTS matters, what “adequate security” is really about, and why suppliers need to start making serious decisions now if they want to keep or win defense work.If you are a machine shop, aerospace supplier, manufacturer, subcontractor, or small business in the defense industrial base trying to understand how primes view CMMC readiness, this episode gives you a rare inside look at the other side of the table.
-
54
CMMC Supplier Questions Answered: Level 1 vs Level 2, Costs, Scope, and Flowdown for DoW Contractors
Submit any questions you would like answered on the podcast!What do small machine shops, aerospace suppliers, and defense manufacturers really need to know about CMMC right now?In this episode of the CMMC Compliance Guide Podcast, Austin and Brooke answer some of the most common supplier questions they hear from companies trying to prepare for CMMC compliance. They break down how small suppliers can plan when contract requirements are still unclear, what level of compliance may be needed, how far requirements flow down the supply chain, and why scope matters so much when building your compliance strategy.They also explain common myths around redacted drawings, whether tools alone can make you compliant, what CMMC actually costs, whether small companies can do CMMC themselves, how big the jump is from Level 1 to Level 2, and what happens when CMMC becomes mandatory on contracts. If you are a DoW supplier, subcontractor, aerospace machine shop, or manufacturer trying to understand how CMMC will affect your business, this episode will help you cut through the confusion
-
53
CMMC Level 1 Self-Attestation Explained: Requirements, Evidence, and Risk
Submit any questions you would like answered on the podcast! lot of contractors assume CMMC Level 1 is just a simple checkbox. It is not.In this episode, Austin and Brooke break down what CMMC Level 1 actually requires, what a self-assessment really looks like, and why self-attestation without documentation can create serious risk.They cover the difference between Level 1 and Level 2, what Federal Contract Information (FCI) actually is, how Level 1 maps to the formal assessment process, and why organizations need policies, evidence, and artifacts before signing an attestation.This episode also explains:What CMMC Level 1 covers and what it does notWhy Level 1 is always self-assessed, not C3PAO certifiedThe difference between self-assessment and self-attestationWhat documentation and evidence should exist before attestingWhy authorized users, devices, processes, visitor logs, and physical access controls matterWhat the CFR says about evidence retentionWhen a Level 1 claim may actually be scrutinizedHow whistleblowers, breaches, or customer requests can trigger verificationThe False Claims Act risk of saying you are compliant when you are notIf you are planning to self-attest to CMMC Level 1, this episode will help you understand what the government expects before you sign your name to anything.
-
52
CMMC Scoping 101: The Most Expensive Mistake Contractors Make (And How to Fix It)
Submit any questions you would like answered on the podcast!Scope is the foundation of your CMMC compliance program and getting it wrong is one of the most expensive mistakes a DoD contractor can make.In this episode, Austin and Brooke break down what “scope” actually means in plain English, why contractors skip scoping early on, and how one small miss, like a downloads folder or a USB handoff, can quietly pull major systems into scope.We cover:What CMMC scope really is, including processed, stored, and transmitted CUIWhy contractors start with tools and policies too earlyThe data flow diagram exercise that reveals hidden scope issuesHow scope mistakes turn into rework, delays, and major cost increasesWhy “enclave” is often misunderstood and what it really meansWhat to do if you think you got scope wrongHow to self-check readiness using NIST 800-171A and the CMMC Assessment Process (CAP)Why documentation and evidence, not just controls, become the real burdenIf you are planning for a Level 2 assessment, scope should be your first move, not your last-minute scramble.
-
51
Key Takeaways from the January 2026 CMMC Town Hall: Hard Copy CUI, Scope, and Program Changes
Submit any questions you would like answered on the podcast!The January 2026 CMMC Town Hall brought several important clarifications and program updates that directly impact Department of War (DoD) contractors.In this episode of the CMMC Compliance Guide Podcast, we break down what changed, what was clarified, and what contractors should take away from the latest guidance.We cover:New DOW CIO leadership changes and what they mean for CMMCUpdated clarification on Hard Copy CUI (and what qualifies)Why encryption alone does NOT define scopeGovernment shutdown impact on assessmentsC3PAO reauthorization and ISO 17020 accreditationKECO transition to ISACA and certification updatesWhat all of this means for contractors planning in 2026The biggest theme? CMMC is not slowing down. It’s becoming more standardized, more mature, and more defined.If you’re planning contracts in 2026, now is the time to understand how these updates affect your scope, documentation, and assessment strategy.
-
50
Why Feeling “CMMC Ready” Isn’t the Same as Passing a Level 2 Assessment
Submit any questions you would like answered on the podcast!Many DoW contractors feel confident they’re ready for a CMMC Level 2 assessment until assessors get involved. That’s when gaps in documentation, scope, and operational maturity start to surface.In this episode of the CMMC Compliance Guide Podcast, Brooke breaks down why implementation alone does not equal readiness. We walk through what assessors look for before technical testing even begins, why documentation is often the real reason companies fail, and how poor scoping or misaligned staff interviews can derail an assessment.You’ll learn:Why “feeling ready” is not the same as being assessment-readyWhat assessors review first during the readiness and pre-assessment phaseHow SSP quality can make or break your assessmentWhy screenshots alone are not sufficient evidenceHow POAMs are viewed during Level 2 assessmentsThe role of operational maturity and ongoing proofHow scope and employee interviews expose readiness gapsHow to realistically self-check readiness before scheduling an assessmentIf you’re preparing for a CMMC Level 2 assessment or think you’re close this episode will help you identify blind spots before they cost you time, money, or certification.
-
49
CMMC FAQ Update: Timeline, Subcontractor Flowdowns, Enclaves, Cloud Rules, and VDI Scope Explained
Submit any questions you would like answered on the podcast!The DoW just released updated CMMC FAQs that clarify the rules contractors keep getting wrong. In this episode, Austin and Brooke break down what the new guidance actually says, what it means for your scope, and where vendor and architecture decisions can derail an assessment before it even starts.We cover the most important FAQ clarifications, including:The real CMMC timeline and what Phase 1 vs Phase 2 changesWhy primes may demand Level 2 earlier than the official datesFlowdown requirements for subcontractors (and what “defensible” verification looks like)The myth that encrypted CUI is no longer CUI (it is still CUI)Whether CMMC assessment results will be public (they will not)POAM vs “operational POAM” and why the distinction mattersHard copy only CUI: when Level 2 may not apply (and the strict caveats)Why encryption does not create logical separation or reduce scopeEnclaves and enterprise networking components: what pulls systems in scope (and what does not)Cloud storage rules: why non-FedRAMP clouds cannot store encrypted CUIMSP requirements: do MSPs need CMMC certification (and what a CRM must include)VDI scope rules: when endpoints can be out of scope, and when they are automatically in scopeIf you are making decisions around scope, vendors, cloud tools, backups, enclaves, or VDI, this episode will help you avoid assumptions that assessors will not accept.
-
48
How to Triage CMMC Compliance When You’re Overwhelmed and Short on Time
Submit any questions you would like answered on the podcast!When CMMC compliance starts to feel overwhelming, most companies don’t fail because they lack effort, they fail because they don’t know where to start.In this episode of the CMMC Compliance Guide Podcast, Brooke and Stacey break down why CMMC feels so urgent and high-risk for small and mid-sized DoD contractors, and how to triage your compliance work so you can make real progress without burning out.This episode covers:Why starting at control 3.1.1 is a mistake for most companiesHow poor scoping makes CMMC feel impossibleWhat assessors actually prioritize firstWhich controls are non-POAMable and must be addressed earlyHow to reduce scope without cutting cornersWhen tools help and when they waste time and moneyHow to approach SSPs, policies, and POAMs the right wayPractical steps small teams can take to regain control of CMMCIf CMMC feels like everything is urgent and nothing is moving fast enough, this episode will help you slow down, focus, and build a plan that actually works.
-
47
CMMC Evidence 101: How to Prove NIST 800-171 Compliance in a Level 2 Assessment
Submit any questions you would like answered on the podcast!Get your free SPRS Roadmap here: https://cmmccomplianceguide.com/free-sprs-roadmapIn this episode of the CMMC Compliance Guide Podcast, Austin and Brooke break down the #1 thing that trips companies up before a CMMC Level 2 assessment: evidence.Having a binder of policies (or a 300-page SSP) is not enough. Assessors want proof you are doing what you say you do consistently, over time and they want it organized so they can quickly map evidence to controls and assessment objectives.You’ll learn:What assessors mean by “acceptable evidence” (and what doesn’t count)The “who, what, when, where” test for logs and proofHow tickets, approvals, and checklists strengthen your evidence trailWhat to avoid putting in cloud ticketing systems (SPD risks)Manufacturer-specific pitfalls assessors notice on the shop floorWhy “fresh out of the oven” evidence raises red flagsHow GRC tools can make evidence collection and linking easier
-
46
What CMMC Assessors Notice First: Early Red Flags That Fail Level 2 Assessments
Submit any questions you would like answered on the podcast!What do CMMC Level 2 assessors notice first, sometimes within the first day, before they ever dig into your firewall configs or deep technical testing?In this episode of the CMMC Compliance Guide Podcast, Austin and Brooke break down the early red flags that can derail your assessment fast. We cover what assessors ask for right out of the gate (and how quickly you need to respond), why generic SSPs create problems, how scoping mistakes happen in the real world (downloads folders, copiers, shop floor machines), and what it means when your policies do not match what employees actually do.If you want to pass your CMMC Level 2 assessment, this episode will help you tighten your documentation, evidence, and scope before the assessor ever starts technical validation.
-
45
CMMC Paperwork Without the Pain: How to Simplify Policies, SSP, and Evidence (Level 1 vs Level 2)
Submit any questions you would like answered on the podcast!Most small and mid-sized manufacturers do not fail CMMC because of “tech.” They fail because their documentation does not match how the shop actually runs.In this episode, Austin and Brooke break down how to build CMMC documentation that is concise, accurate, and assessor-friendly without drowning in templates that were never written for your business. You will learn why template overload causes gaps, how to keep policies aligned to real workflows, and what “minimally sufficient” documentation looks like for both Level 1 and Level 2.We also cover the difference between CMMC Level 1 and Level 2 documentation expectations, why evidence retention and verifiable processes matter, and how to decide between a file system approach vs a GRC tool to keep version control and proof organized for assessment day.If you are a machine shop, aerospace manufacturer, or engineering firm trying to get compliant without creating a 400-page monster, this is your playbook.
-
44
How CMMC Became a Competitive Advantage for DoD Contractors
Submit any questions you would like answered on the podcast!CMMC is no longer just a compliance requirement. It is now a competitive advantage that directly impacts who wins and who loses DoD contracts.In this episode of the CMMC Compliance Guide Podcast, Stacey and Brooke break down how the final 48 CFR rule has changed the contracting landscape and why primes are now aggressively pushing CMMC requirements down to their subcontractors. We explain how CMMC certification, SPRS scores, and assessment status are already being used to evaluate risk and readiness, even before certification becomes mandatory on every contract.You will learn why contractors who are already certified, or at least scheduled for certification, are gaining an edge over competitors who waited too long. We also cover how flow-down requirements work, how primes protect themselves from False Claims Act risk, and why small businesses face a higher barrier to entry than midsize firms.This episode also explains how contracting officers and primes view SPRS scores, what happens once certifications are uploaded through EMASS, and why CMMC status is not likely to become publicly searchable. Finally, Brooke walks through what contractors should be doing right now to stay competitive, including scoping CUI, running gap assessments, engaging a C3PAO early, and preparing subcontractor oversight.If you want to keep winning DoD contracts in 2026 and beyond, this episode will help you understand how CMMC is reshaping the defense industrial base and what actions you need to take now.
-
43
NIST 800-171 and CMMC 2.0: How Assessors Actually Score You
Submit any questions you would like answered on the podcast!Are assessors judging you on CMMC or NIST 800 171 when audit day arrives?In this episode of the CMMC Compliance Guide Podcast, Stacey and Brooke break down the real relationship between CMMC 2.0 and NIST 800 171 so you are not guessing when it matters most.We walk through how the 110 NIST 800 171 controls and 320 assessment objectives drive your CMMC level 2 certification, and what CMMC layers on top, including POA&M limits, timelines, and who is allowed to certify you. You will hear practical examples around SPAs, cloud tools, customer responsibility matrices, FedRAMP, and how assessors actually validate things like MFA, logging, and scope.We also explain the difference between a NIST self assessment and a CMMC level 2 certification by a C3PAO, clear up common misconceptions about “being NIST compliant”, and talk about False Claims Act risk when SSPs, inventories, and controls are not kept current. Finally, Brooke shares a step by step path for contractors: identify your CUI, scope systems, run a gap analysis, build your SSP and POA&M, collect evidence, and engage a C3PAO for a mock and full assessment.If you are a small or midsized defense contractor trying to get ready for 2026, this episode will help you focus on what assessors really care about so you can prepare with confidence.
-
42
Top CMMC Myths Debunked: Cloud, Vendors, Firewalls, and MFA Mistakes Explained
Submit any questions you would like answered on the podcast!Today’s episode of the CMMC Compliance Guide Podcast dives into the biggest myths that machine shops, fabricators, CNC shops, and mid-sized defense contractors still believe about CMMC. From cloud misconceptions to vendor promises that fall short, Brooke breaks down why these misunderstandings lead to failed assessments and what contractors should be doing instead.We walk through common assumptions like “cloud keeps me out of scope,” “my vendor is compliant so I’m compliant,” “MFA on email is enough,” “my firewall makes everything compliant,” and “cyber insurance handles reporting.” Each of these has a grain of truth but none of them meet the actual requirements in NIST 800-171 or CMMC Level 2.You’ll learn:Why cloud environments don’t remove your endpoints from scopeHow caching, downloads, and browser access pull systems back into scopeWhat vendor claims really don’t coverWhy MFA must be implemented everywhere CUI is accessed, not just emailThe truth about firewalls and why they’re not “compliance shields”Why VDI is helpful but not a magic solutionWhat cyber insurance does (and doesn’t) do during an incidentWhy remote workstations and home offices still introduce scope and riskThis episode is packed with clarity, not fear so manufacturers, CNC shops, and GovCon SMBs can make informed decisions, avoid costly assumptions, and protect their DoD contracts.
-
41
Plain English Guide to CMMC Level 1: Basic Cybersecurity Without the Headache
Submit any questions you would like answered on the podcast!CMMC Level 1 Self- Assessment Guide: https://dodcio.defense.gov/Portals/0/Documents/CMMC/AG_Level1_V2.0_FinalDraft_20211210_508.pdfIn this episode of the CMMC Compliance Guide Podcast, Stacey and Austin from Justice IT Consulting break down CMMC Level 1 in clear, simple terms: what it is, who it applies to, and the exact steps small and mid-sized contractors must take to protect Federal Contract Information (FCI).You’ll learn what the government expects from Level 1 contractors, how the 15 required practices actually work in real life, what documentation you must maintain for six years, and why the new annual self-assessment requirement matters more than ever.Whether you’re a machine shop, fabricator, engineering firm, or small manufacturer supporting a prime contractor, this episode gives you the Level 1 foundation you must have in place.
-
40
Top 12 CMMC Level 2 Requirements Explained: Gap Assessments, Scope, SSP, and POA&M
Submit any questions you would like answered on the podcast!In this episode of the CMMC Compliance Guide Podcast, Stacey and Austin from Justice IT Consulting walk through the top 12 essentials every contractor needs to achieve CMMC Level 2 compliance especially small and mid-sized defense manufacturers.You’ll learn how to start compliance the right way with a formal gap assessment, define and shrink your CUI scope, and build a System Security Plan (SSP) that maps to all 110 NIST 800-171 controls. We break down how to write an actionable Plan of Action & Milestones (POA&M), implement MFA correctly, enforce least-privilege access control, and deploy proper device protection across your environment.We also cover commonly misunderstood requirements around FIPS-validated encryption, centralized logging/SIEM, removable media, CNC/OT assets, data handling, and ongoing vulnerability + risk assessments.Finally, we answer a listener question on secure data transfer and why customer portals or GCC/GCC High environments are often superior to “secure links” inside commercial Microsoft 365 tenants.
-
39
Cyber AB Town Hall Breakdown: Legal Lessons, Ecosystem Growth, and CMMC Phase 2 Progress
Submit any questions you would like answered on the podcast!In this episode of the CMMC Compliance Guide Podcast, Brooke and Stacey from Justice IT Consulting unpack the biggest updates from the Cyber AB’s October 2025 Town Hall and what they mean for defense contractors preparing for CMMC certification.You’ll learn:Why the government shutdown isn’t delaying CMMC or the 48 CFR rolloutThe $875K False Claims Act case against Georgia Tech and what it teaches all contractorsHow the CMMC ecosystem is expanding with more certified assessors and C3PAOsKey insights from the University of Southern California’s Level 2 certification journeyPractical advice for small contractors: data mapping, documentation, and shrinking your CUI boundaryNew ethics reminders and upcoming assessor certification updates from the Cyber ABThis episode delivers plain-English explanations and real-world lessons to help contractors stay compliant, avoid legal risk, and prepare for CMMC Phase 2.
-
38
Highlights from CS5 East 2025: Operation Midnight Hammer, CMMC Updates, and AI Insights
Submit any questions you would like answered on the podcast!Get the inside scoop from CS5 East 2025, the largest cybersecurity and compliance event for the Defense Industrial Base. In this episode, Brooke and Stacey from Justice IT Consulting breaks down the biggest CMMC updates, Operation Midnight Hammer, and how AI is reshaping compliance.Learn what the Cyber AB announced, how CMMC Phase 2 is rolling out, and what contractors should expect next. Whether you’re a Compliance Officer, DoD Program Manager, or small-business GovCon, this recap gives you the context and clarity you need to stay ahead.
-
37
How to Prove CMMC Compliance to Prime Contractors (Before You Lose Contracts)
Submit any questions you would like answered on the podcast!🎯 Get your Free SPRS Roadmap Session: https://cmmccomplianceguide.com/free-sprs-roadmapOur experts will review your SPRS score, documentation, and setup to help you hit 110 with a clear action plan at no cost.Prime contractors like Lockheed Martin, Raytheon, and Parker Hannifin are demanding proof of compliance before awarding new work — and subcontractors who can’t prove it risk losing contracts.In this episode, Brooke and Austin from Justice IT Consulting explain exactly what primes are asking for, what documentation they expect (SPRS, SSP, POA&M), and the most common mistakes subcontractors make when trying to prove compliance.You’ll learn: Why primes are suddenly enforcing subcontractor compliance What documents and proof you need ready (SPRS, SSP, POA&M) The biggest mistakes that lead to false claims risk What happens when you inflate your SPRS score How to show compliance even before your Level 2 certification What steps to take now to get audit-ready and stay competitiveWhether you’re still working toward compliance or just need a second set of eyes, this episode breaks down how to prove your CMMC compliance with confidence — before your primes stop sending work your way.
-
36
Cyber AB Town Hall September 2025: Key CMMC Compliance Updates
Submit any questions you would like answered on the podcast!The September 2025 Cyber AB Town Hall dropped big updates for contractors navigating CMMC and NIST 800-171 compliance. In this episode of the CMMC Compliance Guide Podcast, Brooke and Austin break down what the final CMMC rule (Title 48A) means for defense contractors, subcontractors, and service providers.We cover the timeline for implementation, prime and subcontractor flow-down requirements, service provider risks (MSPs, CSPs, ESPs), and how a government shutdown could affect CMMC. You’ll also hear insights on ongoing compliance, documentation, FedRAMP requirements, advisory councils, and what primes will expect from their supply chains.Whether you’re a compliance officer, program manager, or DoD subcontractor, this episode gives you clear, actionable takeaways so you can prepare before deadlines hit.
-
35
Handling CUI Correctly: Compliance Risks and Best Practices
Submit any questions you would like answered on the podcast!Worried about mishandling Controlled Unclassified Information (CUI)? In this episode of the CMMC Compliance Guide Podcast, Brooke and Stacey break down what CUI really is, why it matters in defense contracting, and the biggest mistakes contractors make when handling it.You’ll also learn the real-world risks of CUI mishandling, how assessors check compliance during a CMMC Level 2 assessment, and the low-cost, practical solutions you can implement right now to protect sensitive data.
-
34
CMMC Final Rule Explained: Deadlines, Requirements, and Next Steps for Defense Contractors
Submit any questions you would like answered on the podcast!The wait is over: the Department of Defense has finalized the CMMC rule, officially making it part of DFARS. That means compliance isn’t “coming soon”, it’s now in your contracts.In this episode of the CMMC Compliance Guide Podcast, Austin and Brooke from Justice IT Consulting break down what the final rule means for DoD contractors and subcontractors, the key deadlines you need to know, and the exact steps to prepare for Level 2 certification before requirements hit contracts in November 2026.What you’ll learn in this episode:- The new CMMC final rule and when it goes into effect- How the 4-phase rollout impacts primes and subcontractors- What’s different about this update (and why it’s not another delay)- Key requirements: SPRS score, POAM limits, affirming officials, and more- How to prepare your subcontractors with questionnaires and attestations- Why you need to start engaging with C3PAOs now before schedules fill upIf you’re a DoD contractor, aerospace manufacturer, or subcontractor, this is the update you can’t afford to ignore.
-
33
The Role of NIST 800-171 in Your CMMC Assessment
Submit any questions you would like answered on the podcast!Confused about where NIST 800-171 fits into your CMMC 2.0 assessment? You’re not alone. In this episode of the CMMC Compliance Guide, Brooke and Stacey from Justice IT Consulting break it all down in plain English.We cover the foundation of NIST 800-171, how it maps into the CMMC levels, what assessors actually look for during an audit, and the most common mistakes contractors make. We’ll also touch on the latest updates including: NIST 800-171 Rev 3 and the DoD’s enforcement timelines and finish by answering real listener questions on VoIP, Microsoft 365, and more.Whether you’re a small defense contractor or managing compliance for a larger team, this episode gives you the practical steps you need to stay compliant, stay secure, and stay ready for your assessment.
-
32
The Truth About CMMC Enclaves: Pros, Cons, and Compliance Risks
Submit any questions you would like answered on the podcast!Thinking about building an enclave for CMMC compliance? Not so fast. In this episode of the CMMC Compliance Guide Podcast, Austin and Brooke from Justice IT Consulting break down:What an enclave actually is (in plain English)When an enclave makes sense (and saves you money)When it can hurt your compliance effortsWhat assessors will really be looking for in your auditIf you’ve ever asked, “Do I need an enclave for CMMC?”, this episode is your roadmap to making the right call for your business.
-
31
Are You Really Ready for a CMMC Assessment?
Submit any questions you would like answered on the podcast!Think you’re ready for your CMMC assessment? In this episode of the CMMC Compliance Guide Podcast, Austin and Brooke break down the difference between being “paper ready” and truly “assessment ready.” From documentation gaps to overlooked technical controls, they share insider tips to help you pass with confidence.We’ll walk you through the common blind spots that can derail an assessment, how to stress test your compliance program, and what assessors really look for when they walk in the door.
-
30
When ‘Not Applicable’ Can Cost You Contracts
Submit any questions you would like answered on the podcast!Marking a CMMC control as “Not Applicable” might feel like an easy shortcut but get it wrong, and you could fail your assessment, lose contracts, or even face legal trouble.In this episode of The CMMC Compliance Guide, Brooke and Stacey from Justice IT Consulting break down the real risks of misusing N/A, share common mistakes companies make, and explain how to properly justify a not applicable control so you stay compliant and avoid False Claims Act issues.We cover everything from Wi-Fi misconceptions to remote access oversights, mobile device scoping, assessor validation methods, and the legal risks nobody talks about. Whether you’re a one-person shop or managing a complex network, these insights could save you from major headaches come assessment day.CyberAB Marketplace
-
29
How to Make Real CMMC Progress: Even if Compliance Isn’t Your Full-Time Job
Submit any questions you would like answered on the podcast!Schedule your free SPRS Roadmap Session and get a step-by-step plan to close gaps and stay defensible:👉 https://cmmccomplianceguide.com/free-sprs-roadmapIs CMMC just one of many hats you wear at your company? You’re not alone and you’re not out of luck.In this episode of the CMMC Compliance Guide, we break down how overworked and under-resourced compliance leads can still make meaningful progress toward CMMC and NIST 800-171. Whether you're a part-time compliance officer, the IT guy, or the quality manager who just got handed CMMC, we’ll walk you through a phased, practical approach you can tackle in just a few hours a week.From identifying CUI and building your data flow diagrams to implementing MFA, FIPS, and policy templates the right way—this is your guide to making CMMC doable without the burnout.
-
28
What You Missed: June Cyber AB Town Hall CMMC Highlights
Submit any questions you would like answered on the podcast!48 CFR UPDATE: https://www.ecfr.gov/current/title-48/chapter-2/subchapter-A/part-204/subpart-204.75Missed the June 2024 Cyber AB Town Hall? We’ve got you covered.In this episode of the CMMC Compliance Guide, Brooke and Austin break down the biggest takeaways — including how recent leadership changes, service provider requirements, and G-code classification are shaping the path to CMMC compliance.If you're a DoD contractor or MSP supporting government clients, this is the update you can't afford to miss.INSIDE THE EPISODE:- What the new Undersecretary means for CMMC rulemaking- ESP vs. CSP vs. MSP — and why the difference matters- Why your IT provider will be assessed with your environment- How your CAGE code could delay certification- What assessors say about G-code and CUI- Upcoming CMMC events you should have on your calendarUPCOMING CMMC EVENTS MENTIONED:- Carahsoft CMMC Webinar Series: https://www.carahsoft.com/learn/event/71021-proofpoint-and-microsoft-cmmc-webinar- National Cyber Summit: https://www.nationalcybersummit.com/- CS5 East 2025: https://cyberab.org/News-Events/CS5-Conference
-
27
6 Critical CMMC Questions Every Small DoD Contractor Should Know
Submit any questions you would like answered on the podcast!Are you trying to navigate CMMC and NIST 800-171 with a small team and limited resources? You're not alone. In this episode of the CMMC Compliance Guide, we’re breaking down six of the most common and confusing questions small DoD contractors ask—and giving you clear, practical answers you can act on immediately.Join Brooke & Stacey from Justice IT Consulting as they unpack risks of misinterpreting controls, mobile device scope, admin account misuse, CUI data flow diagrams, remote access, and more. Whether you’re prepping for a CMMC Level 2 assessment or just trying to stay ahead, this episode is packed with actionable advice.
-
26
CMMC on the Shop Floor: A No-BS Guide for CNC & Aerospace Machine Shops
Submit any questions you would like answered on the podcast!Happy 4th of July from the team at CMMC Compliance Guide Podcast! While you're celebrating freedom, hot dogs, and fireworks — don’t forget about safeguarding the data that defends that freedom. 🛡️In this special edition, we're tackling what really works for CMMC compliance on the shop floor. From coolant-soaked travelers to ancient XP machines, this is your no-nonsense guide to staying compliant in real-world CNC and aerospace manufacturing environments.Skip the theory. Get the real-world playbook. Because you can't afford to shut down production just to pass an audit. 📞 Need help with CMMC or NIST 800-171? We fast-track defense manufacturers to compliance — or give you the tools to do it yourself. 👉 Visit https://www.cmmccomplianceguide.com to download free resources or schedule a discovery call.
-
25
Ceasefire’s Here, But Your Shop’s Still a Target: What the DoD CIO Just Told Defense Contractors
Submit any questions you would like answered on the podcast!🆓 Need help getting your SPRS score to 110?Schedule your free SPRS Roadmap Session and get a step-by-step plan to close gaps and stay defensible:👉 https://cmmccomplianceguide.com/free-sprs-roadmapThe Department of Defense just issued a critical cybersecurity memo—and it's not just for the Lockheeds and Raytheons. In this episode, we break down what small and mid-sized DoD contractors must do now to respond to rising cyber threats—even amid headlines of ceasefire. From multi-factor authentication and patching systems to cloud security guidance and SPRS score readiness, we walk you through the exact steps your organization needs to take.Resources Mentioned:Memo: https://media.licdn.com/dms/document/media/v2/D561FAQFbAPookqu2zw/feedshare-document-pdf-analyzed/B56ZefAj13HoAY-/0/1750719415748?e=1751500800&v=beta&t=O6aY3UDi5ijLTGOa6RP4xAWABMPZh-ZKRkXRikiCywg https://www.cisa.gov/known-exploited-vulnerabilities-catalog https://www.cisa.gov/news-events/directives/bod-25-01-implementing-secure-practices-cloud-services https://www.cisa.gov/cyber-hygiene-services https://www.nsa.gov/About/Cybersecurity-Collaboration-Center/DIB-Cybersecurity-Services/ https://www.dc3.mil/Missions/DIB-Cybersecurity/DCISE-Resources/ #CMMC #DODCompliance #CyberSecurity #SPRS #DefenseContractor #CyberThreats #NIST800171 #CMMCComplianceGuide
-
24
Breaking Down the Real Cost of CMMC Compliance for Small Businesses
Submit any questions you would like answered on the podcast!Why is CMMC compliance so expensive—especially for small businesses? In this episode of the CMMC Compliance Guide Podcast, Austin and Brooke from Justice IT Consulting break down what really drives up the cost of CMMC and NIST 800-171 compliance, and more importantly—how you can cut costs without cutting corners.We cover:The four stages of compliance cost: paperwork, project work, ongoing maintenance, and assessmentsWhat assessors can and can’t help withEnclave strategies that can save you thousandsWhy smaller companies feel a heavier burden—and how to manage itSmart scoping, VDI, and how not to overspend on your CMMC journeyIf you’re trying to balance compliance with a tight budget, this episode is a must-listen.👉 Need help or have questions? Contact us for free advice at CMMCComplianceGuide.com.🔔 Don’t forget to like, subscribe, and share!
-
23
How to Scope CMMC Correctly: Avoid Audit Failures, Over-Scoping, and Cloud Risks
Submit any questions you would like answered on the podcast!Is your CMMC scope setting you up for success—or failure?In this episode of the CMMC Compliance Guide, Brooke and Stacey from Justice IT Consulting break down one of the most misunderstood (and expensive) parts of your compliance journey: scoping.Learn how to define your CUI boundary the right way, avoid common over-scoping mistakes, and streamline your assessment with clear documentation strategies. Whether you're prepping for a formal CMMC assessment or self-assessing for NIST 800-171, this episode gives you real-world insights that can save you time, money, and frustration.🔍 We cover:What really defines your CMMC scope (it's more than just your server)The hidden risks of over-scoping and cloud blind spotsThird-party service provider mistakes that can blow your scopeMust-have documentation: data flow diagrams, network diagrams, and asset inventoriesA practical checklist to get your scope right before the audit🛠 Need a faster path to compliance without cutting corners? Visit www.CMMCComplianceGuide.com for free resources, expert help, or to book a discovery call.
-
22
What You Missed at CEIC West 2025: CMMC Culture, AI Labeling, and Subcontractor Risks
Submit any questions you would like answered on the podcast!Missed CEIC West 2025 in Las Vegas? We’ve got your insider recap. In this episode of the CMMC Compliance Guide, Austin and Brooke break down the most critical insights defense contractors need to know—from Katie Arrington’s keynote to real-world flowdown risks, mock assessment walkthroughs, and what AI means for your CUI documentation.If you’re a small or mid-sized DoD contractor trying to stay compliant with CMMC, NIST 800-171, and DFARS, this episode gives you the takeaways that actually matter. 📞 Have questions? Text, call, or email us. We’ll answer them for free on the podcast. 🔗 Visit www.cmmccomplianceguide.com for free resources
-
21
How to Identify and Fix Your NIST 800-171 Weak Spots
Submit any questions you would like answered on the podcast!Are you sure you're NIST 800-171 compliant? In this episode of the CMMC Compliance Guide Podcast, Austin and Brooke break down the most overlooked NIST 800-171 requirements that continue to trip up DoD contractors—and what you can do today to avoid those costly mistakes.From data flow diagrams to documentation pitfalls, supply chain risks, and misunderstood MFA and logging requirements, this episode is packed with practical insights and actionable takeaways. If you’re pursuing CMMC Level 2 or just trying to boost your SPRS score, this is a must-listen.💡 You’ll Learn:Why poor scoping is the #1 mistake in complianceHow to map your CUI data flow across systems and subcontractorsWhat assessors really expect from your MFA, logging, and risk assessment controlsWhy your documentation strategy can make or break your assessmentWhat it takes to maintain compliance after you’re “done”How to use the NIST 800-171A Assessment Guide to conduct a real gap analysisThe truth about ongoing compliance vs. one-time auditsGRC tools, POAMs, and how to build your project roadmapThis episode is your self-assessment gut check. Whether you're just starting or already deep into your compliance journey, don’t miss these expert tips.🔗 For free resources, visit: https://cmmccomplianceguide.com 📅 Meet us at DibCon, June 3–5, in Oklahoma City!
-
20
CMMC Day 2025 Recap: Key Takeaways, Real-World Mistakes & What SMBs Must Fix Now
Submit any questions you would like answered on the podcast!Get the latest insider takeaways from CMMC Day 2025 straight from Washington D.C. In this episode of the CMMC Compliance Guide Podcast, Brooke and Austin break down the most critical updates small and midsized businesses (SMBs) in the defense supply chain need to know now.We cover: ✅ Why CMMC is NOT going away (despite what skeptics think) ✅ Critical mistakes businesses still make with SSPs, scoping, and access control ✅ Real-world assessment horror stories you need to avoid ✅ Why subcontractors can't hide in the supply chain anymore ✅ Tools, technology, and zero trust lessons from the show floorWhether you're a manufacturer, IT lead, or compliance manager, this episode delivers actionable insights to help you stay off the DoD's naughty list and win more contracts in 2025.🎯 Need help? Get your free SPRS Score Roadmap → https://cmmccomplianceguide.com/free-sprs-roadmap
-
19
Decoding NIST 800-171: Your Plain English Path to CMMC Level 2 Compliance
Submit any questions you would like answered on the podcast!Feeling overwhelmed by CMMC compliance and NIST 800-171’s 110 controls? You’re not alone — but you don’t have to be stuck.In this episode of the CMMC Compliance Guide Podcast, Brooke and Austin break down NIST 800-171 Revision 2 in plain English — no government-speak, no tech jargon — so you can finally understand what each control family means for your business.You'll learn:What NIST 800-171 really requires (and why it matters for your SPRS score)How to tackle key control families like Access Control, Awareness & Training, and Audit & AccountabilityThe critical mistakes contractors make (and how to avoid them)Why documentation is the #1 secret weapon for CMMC successReal-world tips for manufacturing, machine shop, and aerospace contractors navigating CMMC Level 2🔥 Don’t wait until an assessor says “No Soup for You” — build a compliance system that actually protects your business and wins contracts.👉 Need help fast-tracking your compliance journey? Visit https://cmmccomplianceguide.com to download free resources or schedule a discovery call.
-
18
How to Improve Your SPRS Score Before It Costs You Contracts
Submit any questions you would like answered on the podcast!Is your SPRS score putting your DoD contracts at risk? In this episode of the CMMC Compliance Guide, we break down exactly what the SPRS score is, why it matters, and how to improve it fast—before you lose out on federal work.Whether you're stuck at -72 or hovering at 80, we’ll walk you through how to get to 110 with practical, plain-English guidance. From gap analysis to POA&Ms, system security plans, encryption, MFA, and the best GRC tools—we’re covering it all.👉 Schedule your FREE SPRS Roadmap Session (Limited Time): www.cmmccomplianceguide.com/free-sprs-roadmap✅ $1,500 Value — No pitch, no pressure. Just expert help.🎯 What You'll Learn:✅What an SPRS score is and why it matters✅How to assess your current score (and why most are wrong)✅What documentation and tech controls you must have✅How to get to 110 — even if you’re starting from a negative score
-
17
The E.A.S.Y Framework That Makes CMMC Actually Doable
Submit any questions you would like answered on the podcast!If someone tells you CMMC compliance can't be easy… they’re not necessarily wrong — but they’re also missing the point.In this episode of the CMMC Compliance Guide Podcast, Austin and Brooke from Justice IT Consulting break down one of the biggest myths in the compliance space: that achieving CMMC compliance has to be overwhelming, time-consuming, and painfully complex.Using our E.A.S.Y. framework, we’re showing you how strategic companies are simplifying their compliance efforts and turning cybersecurity into a competitive edge:✅ E – Expert Guided: Why going it alone can cost you more in time and money.✅ A – Aligned to Requirements: How to avoid the tech-first trap and focus on business process.✅ S – Streamlined Approach: Proven tools, trusted frameworks, and no need to reinvent the wheel.✅ Y – Your Competitive Advantage: Compliance isn’t just a checkbox — it’s a business differentiator.Whether you're a defense contractor starting your compliance journey or trying to stay ahead of evolving requirements, this episode gives you the mindset and framework to make CMMC easier — not effortless, but easier.📞 Need help fast-tracking your compliance? Reach out at: cmmccomplianceguide.com/podcast — we’ll answer your questions for free right here on the show.
-
16
CMMC Compliance Consulting vs. DIY Compliance: Which Is the Smarter, More Cost-Effective Choice?
Submit any questions you would like answered on the podcast!In this episode of The CMMC Compliance Guide Podcast, Brooke and Austin dive into a key question many DoD contractors face: Should you handle CMMC compliance yourself or hire a consultant?We break down the risks, costs, and benefits to help you make the best decision for your business. Discover the 6 major risks of DIY compliance, including:1️⃣ Losing DoD contracts due to non-compliance2️⃣ Keeping up with ever-changing CMMC requirements3️⃣ Hidden costs that make DIY compliance more expensive4️⃣ The gap in IT teams’ compliance expertise5️⃣ Security risks that linger even after passing an assessment6️⃣ How CMMC assessors prioritize well-prepared organizations🎯 Whether you’re starting your compliance journey or stuck midway, this episode offers actionable advice to help you stay compliant and secure.🔗 For expert guidance and resources, visit https://cmmccomplianceguide.com/👍 Don't forget to like, comment, and subscribe for more tips on achieving CMMC compliance with confidence.
-
15
Your IT Provider: The Keystone to Passing CMMC – or the Hidden Risk That Could Cost You Everything
Submit any questions you would like answered on the podcast!In this episode of The CMMC Compliance Guide Podcast, Brooke and Stacey reveal a critical factor that could make or break your compliance journey: your IT provider.✅ Discover why your IT provider plays a crucial role in your CMMC assessment.✅ Learn the risks of working with an unqualified IT provider — and how they could cost you contracts.✅ Find out what a qualified IT provider should bring to the table to simplify your compliance process.✅ Get actionable tips on how to vet an IT provider to ensure they’re an asset — not a liability.🎯 Don’t leave your compliance journey to chance. Tune in to learn how to make your IT provider your strongest ally.🔗 For more resources, visit https://cmmccomplianceguide.com/❗Get past all the CMMC jargon by downloading our CMMC Glossary: https://cmmccomplianceguide.com/glossary
-
14
How the DoD’s Cybersecurity Crackdown Could Impact Your Aerospace Contracts
Submit any questions you would like answered on the podcast!The DoD is tightening its cybersecurity regulations, and your aerospace contracts could be on the line. In this episode of The CMMC Compliance Guide Podcast, we break down the latest changes to CMMC, DFARS, and FAR that could directly impact your business.Join Austin and Brooke from Justice IT Consulting as they explain:✅ The upcoming CMMC, DFARS, and FAR rule changes & deadlines✅ Why self-reported compliance is no longer enough✅ How SPRS scores and third-party assessments will determine contract eligibility✅ The legal risks of non-compliance, including False Claims Act violations✅ Steps you must take right now to stay ahead of the cybersecurity crackdownDon’t wait until it’s too late! Compliance deadlines are fast approaching, and failing to prepare could mean losing out on DoD contracts. Stay informed, stay compliant, and protect your business.📌 Download your free guide here: https://cmmccomplianceguide.com/ultimate-aerospace-contractor-guide📌 Need help with compliance? Contact us at https://cmmccomplianceguide.com
-
13
CyberAB January Town Hall Updates: Key CMMC & FAR CUI Rule Insights for DoD Contractors
Submit any questions you would like answered on the podcast!In this episode of The CMMC Compliance Guide Podcast, we break down the most important updates from the CyberAB January Town Hall. From the latest developments in CMMC implementation to the newly proposed FAR CUI rule, we discuss what these changes mean for DoD contractors and beyond.Key Takeaways:The CMMC program is officially live under CFR 32—what this means for your business.The FAR CUI rule and how it expands compliance beyond the DoD.What DoD contractors should be doing right now to stay ahead of upcoming certification requirements.The latest challenges in obtaining CMMC Level 2 certification and how to navigate delays.If your business is in the Defense Industrial Base (DIB) or sells to the Federal Government, this episode is a must-listen! Stay informed, stay compliant, and don’t get left behind.📩 Got questions? Contact us at cmmccomplianceguide.com/podcast – we’ll answer them for free on the podcast!
-
12
CMMC Compliance: How to Win DoD Contracts & Avoid Costly Mistakes
Submit any questions you would like answered on the podcast!In this week’s episode, Brooke Justice and guest cohost Stacey break down one of the most crucial topics for DoD contractors: how CMMC compliance directly impacts your ability to win and keep defense contracts.From understanding compliance levels to avoiding costly mistakes, we’ll walk you through everything you need to know to stay competitive and avoid compliance pitfalls. You’ll learn:✅ Why CMMC is becoming a non-negotiable requirement for DoD contracts✅ How being CMMC compliant gives you a competitive edge✅ What compliance level you should aim for to secure future opportunities✅ The biggest mistakes companies make that put their contracts at risk✅ How to ensure your supply chain isn’t a weak linkWhether you’re a prime contractor, subcontractor, or just starting your CMMC journey, this episode is packed with actionable insights to help you navigate the compliance landscape.💡 Have questions? We want to hear from you! Send us your questions at cmmccomplianceguide.com and we’ll answer them in a future episode—for free!
-
11
FedRAMP Authorization vs. Equivalency: What Your Business Needs to Know
Submit any questions you would like answered on the podcast!In this episode of The CMMC Compliance Guide Podcast, Brooke and Stacey from Justice IT Consulting dive deep into the critical distinctions between FedRAMP Authorization and FedRAMP Equivalency. Whether you're leveraging cloud services for compliance or planning your next steps in CMMC certification, understanding these two pathways is crucial. We break down the key differences, discuss how each impacts your compliance journey, and provide actionable advice to help you make the right choice for your business.Tune in to learn:What FedRAMP is and why it matters for cloud security.The pros and cons of Authorization vs. Equivalency.How each option affects your CMMC assessment timelines and costs.Practical tips to stay ahead in your compliance efforts.Got questions? We’re answering them for free on the podcast! Reach out via text, email, or call at cmmccomplianceguide.com.Don't miss this essential episode—subscribe now and stay compliant, stay secure!
-
10
2024 Compliance Wrapped: Insights from CEIC East
Submit any questions you would like answered on the podcast!In this episode of The CMMC Compliance Guide Podcast, Brooke Justice is joined by guest cohost Stacey Flores, stepping in for Austin Justice, to bring you the key takeaways from the recent CEIC East conference. If you missed the event, don’t worry—Brooke and Stacey are here to fill you in on everything you need to know to navigate the ever-evolving world of CMMC compliance in 2024.What’s in Store:🚀 CMMC Rollout Updates: Find out why the rollout is moving faster than expected and how prime contractors might push subs to certify early.📋 Certification Timing Tips: Learn how to avoid assessment bottlenecks and prepare your organization now.🔐 Key Regulatory Changes: Get the latest on POAM limits, FIPS encryption updates, ESP requirements, and more.🛠️ Actionable Advice: Practical tips for refining your SSP, aligning with ESPs, and staying ahead in compliance.Brooke and Stacey dive deep into the insights gained from networking with policy experts, vendors, and assessors at CEIC East, offering practical advice to help you stay on track with compliance and secure your contracts.Whether you’re a seasoned compliance pro or just starting your journey, this episode has something for everyone.Engage with Us:Have questions or need more guidance? Reach out to us at cmmccomplianceguide.com—we’re here to help!
We're indexing this podcast's transcripts for the first time — this can take a minute or two. We'll show results as soon as they're ready.
No matches for "" in this podcast's transcripts.
No topics indexed yet for this podcast.
Loading reviews...
ABOUT THIS SHOW
Our experiences inspired the creation of The CMMC Compliance Guide Podcast and its accompanying resources. The podcast began as a way to share what we learned through real-world challenges—like helping that aerospace machine shop—and to provide accessible education for businesses navigating DoD cybersecurity requirements.The CMMC Compliance Guide Podcast breaks down complex topics like NIST 800-171 and CMMC into actionable, easy-to-understand steps. Whether you’re a subcontractor struggling to meet compliance deadlines or a business owner looking to secure your supply chain, the guide offers practical advice to help you take control of your cybersecurity journey.
HOSTED BY
CMMC Compliance Guide
CATEGORIES
Loading similar podcasts...