CMMC Compliance Guide

CMMC Compliance Guide

Our experiences inspired the creation of The CMMC Compliance Guide Podcast and its accompanying resources. The podcast began as a way to share what we learned through real-world challenges—like helping that aerospace machine shop—and to provide accessible education for businesses navigating DoD cybersecurity requirements. The CMMC Compliance Guide Podcast breaks down complex topics like NIST 800-171 and CMMC into actionable, easy-to-understand steps. Whether you’re a subcontractor struggling to meet compliance deadlines or a business owner looking to secure your supply chain, the guide offers practical advice to help you take control of your cybersecurity journey.

  1. 4d ago ·  Video

    The 10 CMMC Questions Defense Suppliers Ask Us Most: A Self-Check for Your Compliance Program

    Submit any questions you would like answered on the podcast! These are the 10 questions Stacey and Brooke hear more than any other from defense suppliers, and most companies get at least half of them wrong without realizing it. If you've ever wondered whether your setup would actually hold up to a close look, this episode is your self-check. In this episode: Do you actually need to worry about CMMC right now, with the certification requirement on contracts still paused?How to actually figure out whether you're Level 1 or Level 2 (and why you should push back on vague answers about what counts as CUI)What "compliant" actually looks like day to day, not just the technical controls, but the ongoing documentation and change management behind themWhy "our IT provider handles all of it" is rarely true, and the specific questions to ask them (CRM/SRM, CCP, RP, CCA credentials)Why companies with mature cybersecurity programs often still fail on documentation, even when their technical controls are solidThe biggest real-world mistakes: shared shop-floor logins that fail CUI access requirements, misunderstanding what the controls actually mean, and manually "reviewing logs" instead of using a SIEMWhat an assessor actually checks first (hint: it's your scope definition, not your tools)Why buying a compliance tool or downloading a template package doesn't mean you're done, and what you actually have to prove objective by objectiveHow to implement all of this without grinding operations to a haltWhere most companies actually land when they get an honest gap assessment

  2. Sep 25 ·  Video

    SPRS Scoring Explained in Plain English: How the 110-to-Negative-203 Scale Works and How to Fix a Bad Score

    Submit any questions you would like answered on the podcast! Your SPRS score can quietly decide whether your company is even eligible to bid on a DoD contract, and defense contractors have already paid millions in False Claims Act settlements for getting that number wrong. Austin and Brooke break down exactly how SPRS scoring works, what score you actually need, and how to make sure your number is accurate before a government audit finds you. In this episode: What SPRS (Supplier Performance Risk System) actually is, and why it's the DoD's authoritative source for your compliance statusHow the scoring math really works: starting at 110, deducting 5, 3, or 1 points per missed control, and how you can end up as low as negative 203Why missing just a couple of five-point controls can put your score under 100 fast, and why negative 50 to negative 70 scores are common in real gap assessmentsThe one control (3.12.4, your SSP) that can single-handedly tank your entire assessment if it's incompleteWhy an 88 is the minimum score to bid on a contract, and what that means for your POA&MThe six-month clock: what happens if you report a POA&M and don't close it out in timeWhy misrepresentation, not the underlying gap itself, is what actually triggers False Claims Act exposureThe 2026 timeline of changes: the February class deviation, the July 16th revision that formalized the Phase 2 pause, and the September 3rd updateWho can actually see your SPRS score (hint: it's not primes, and it's not your competitors)How to actually register and submit a score: getting a CAGE code through SAM.gov and navigating PIEE

  3. Sep 11 ·  Video

    CMMC Level 2 Explained in Plain English: Phases, POA&M Rules, Assessments, and What Level You Actually Need

    Submit any questions you would like answered on the podcast! What does CMMC Level 2 actually require, and how does it connect to the four-phase rollout, the POA&M process, and the assessment you'll eventually go through? Austin and Brooke break down Level 2 in plain English, a few days ahead of the DoD's September update on the Phase 2 pause. In this episode: Where things stand with the Phase 2 pause right now, and what's not paused (your obligation to be compliant with NIST 800-171 R2)Why "just give me the CMMC checklist" doesn't work, and what CMMC actually is (a collection of DFARS rules built on NIST 800-171)The four-phase rollout explained: what phase you're actually in, what's paused, and what flows down regardless of the pauseWhat CMMC Level 2 requires: 110 controls, 320 assessment objectives, and the "CMMC overlay" on top of NIST 800-171POA&M rules explained: the 180-day clock, the minimum 88 score, and which controls can never go on a POA&MWhat "ready for assessment" actually means (hint: it's a lot more than an SSP and a POA&M, often 400+ documents and artifacts)Self-assessment vs. C3PAO certification: what a real assessment guide-based self-assessment looks like, and why assessors can't consult or advise youWhy the "100 assessors" claim used to justify the pause doesn't hold up (there are over 1,000 CCAs)Level 1 vs. Level 2 vs. Level 3: what determines which level actually applies to you, and why most companies who think they need Level 3 don'tWhy asking your IT person to self-score your own compliance program is a liability risk, even with good intentions

  4. Aug 28 ·  Video

    CMMC Vendor Marketing Claims Decoded: What "Covers 90 of 110 Controls" Actually Means

    Submit any questions you would like answered on the podcast! Every CMMC vendor says the same thing: "we cover 80 out of 110 controls" or "90 out of 110." Austin and Brooke break down what that claim actually means, why "maps to," "satisfies," and "supports" are not interchangeable words, and why you almost always still have work to do even after buying the solution. In this episode: What vendors actually mean when they claim to cover a specific number of the 110 controlsWhy "maps to," "satisfies," and "supports" are different claims with different implications for your compliance programWhy you can't stack vendors (40 controls from Vendor A plus 50 from Vendor B does not equal 90 covered)The moment your computer enters scope even when you're using a fully FedRAMP-compliant vendor: downloading, caching, or transmitting CUI through itWhy "I never saved it to my computer, I just passed it through" doesn't get you out of scope (process, store, or transmit is the bar)How to use a CRM (customer responsibility matrix) or SRM (shared responsibility matrix) to know exactly where a vendor's responsibility ends and yours beginsWhy your MSP or IT provider needs a CRM too, not just your cloud vendorsThe exact questions to ask any vendor before you buy: which control numbers, full satisfaction vs. contribution, which systems and assets it applies to, and what's still on youWhy vendors can only speak to their own product, not your specific environment, and why you need someone (in-house or outsourced) who understands your full compliance picture

  5. Aug 21 ·  Video

    The Real Cost of CMMC Scoping Mistakes: Is "Six Figures" Real or Just Marketing?

    Submit any questions you would like answered on the podcast! Is the "six-figure CMMC scoping mistake" a real number, or just something people throw around to sound scary? Stacey and Brooke break down where these numbers actually come from, what over-scoping really costs versus under-scoping, and what a defensible scope actually looks like. In this episode: Where the "six figures" scoping numbers actually come from (and why the DoW CIO and SBA's recent numbers conflated compliance cost with certification cost)What over-scoping actually costs: pulling in unnecessary cloud systems, remote users, and locationsWhat under-scoping actually costs: a $30k-$40k assessment redo at best, a False Claims Act investigation at worstThe most commonly missed scoping items: downloaded CUI, cached files, backups, CNC-connected computers, and cloud file-sync tools like Prevail DriveWhy vendors and IT providers (MSPs, MSSPs) are an underscoping trap if their CRM/SRM documentation isn't in placeWhy most over-scoping actually traces back to primes and the government not clearly marking what is and isn't CUI2026 scoping clarifications: encryption doesn't create a CUI boundary, paper-only CUI can limit flowdown, and why FedRAMP 20X won't satisfy DoW requirementsReal False Claims Act cases where scoping was the legal basis (including a Georgia Tech case)What a defensible scope actually looks like in your SSPNIST 800-171 Revision 3 on the horizon, and why you need to start planning for it now regardless of what happens with the CMMC pause

  6. Aug 14 ·  Video

    The Complete CMMC Compliance Checklist for 2026: Phase 2 Pause, Level 1 vs Level 2, Scoping, and Vendor Documentation

    Submit any questions you would like answered on the podcast! This is the all-in-one CMMC checklist episode. Austin and Brooke pull together everything into one place: what the 60-day Phase 2 pause actually changed (and didn't), what CMMC Level 1 really requires, what Level 2 really requires, why scoping is the foundation everything else depends on, and where most assessments actually fall apart. In this episode: What CIO Kirsten Davies' memo suspended, and what it left completely alone (spoiler: almost everything)Why the government's stated reasoning for the pause (cost, assessor shortage) doesn't hold up against real assessment pricingThe RFI and task force timeline: what happens on August 14th, and what to expect around September 14thWhat happens to contracts that already have Phase 2 certification language written inWhere to actually focus your compliance budget and effort during the pauseCMMC Level 1: the checklist most people gloss over, and why it's not "nothing"CMMC Level 2: the 110 controls and 320 assessment objectives, POA&M rules, and the controls that most commonly get missedWhy scoping has to come first, and what happens when you skip it (including a mole infestation analogy that actually makes sense)Whether your G-code, derivative drawings, and CAD pull-outs are CUIESPs, CSPs, MSPs, and MSSPs: what each one means for your documentation and your assessmentThe two most common reasons assessments fail: documentation gaps and vendor/CRM gapsJustice IT Consulting's own path to CMMC Level 2 certification, completed right after the pause was announced

  7. Jul 31 ·  Video

    Cyber AB June 2026 Town Hall Recap: Enforcement Data, Paper CUI Rules, Choosing a C3PAO, and the FAR CUI Update

    Submit any questions you would like answered on the podcast! We're recapping the Cyber AB's June 2026 Town Hall, five topics every DoD contractor needs to hear, plus what's changed since (including the CMMC Phase 2 pause that landed after this town hall happened). Stacey and Brooke break down the real enforcement numbers, the paper CUI rules everyone gets wrong, how to actually vet a C3PAO, and the FAR CUI rule updates working their way through public comment. In this episode: False Claims Act enforcement: why almost every case comes from whistleblowers, not breaches, and why the discrepancies are massive (think negative scores, not "110 vs. 107")Paper-only CUI: when you're exempt from CMMC Level 2 controls, and the exact moment that exemption disappears (scanning, photographing, emailing it)How the town hall's November 10th "full steam ahead" messaging got overtaken by the Phase 2 pause memo weeks laterWhat to actually ask when interviewing C3PAOs (assessor headcount, 1099 vs. employee, on-site requirements, SOCI screening status)FAR CUI rule updates: the incident reporting window moving to 72 hours, and the mislabeled/unlabeled CUI reporting requirement getting struckWhy NIST 800-171 and CMMC were built for ongoing management, not a one-time snapshot, and what that means for your evidence and documentationJustice IT Consulting's own path through certification, and why that certification still matters even during the pause

  8. Jul 17

    CMMC Phase 2 Paused: Why the DoD's Reasoning Doesn't Add Up, and What to Expect After the 60-Day Review

    Submit any questions you would like answered on the podcast! The Department of War's pause on CMMC Phase 2 sparked a wave of panic, and a wave of misinformation right behind it. In this episode, Stacey and Brooke go deeper than the headline: what the pause actually changes, why the stated justification (cost, assessor capacity) doesn't hold up against the numbers, and what's realistically likely to come out of the 60-day review. In this episode: What "Phase 2 is paused" actually means (it's the third-party certification requirement on new contracts, not your obligation to be compliant)The biggest misconception floating around: "CMMC is suspended" vs. what's actually trueWhy the capacity argument (claims of "only 100 assessors") doesn't match reality (there are over 1,000 CCAs)Why the cost argument conflates "cost of certification" with "cost of actually being compliant," which have always been expensiveWhy self-assessments may face MORE scrutiny, not less, while third-party validation is pausedHistorical precedent: every incoming DoD/DoW CIO has paused and retooled this program since 2021, and it's never been canceledWhat to actually do this week if you're mid-remediation, mid-contract, or have a mock or certification assessment already scheduledThe open RFI (Request for Information) the DoD posted, and why submitting a response mattersJustice IT Consulting's own CMMC Level 2 certification newsThe mark-your-calendar date: September 14th is when the 60-day window closes and we should learn more about what comes next.  Read the actual DoD memo here: https://federalnewsnetwork.com/wp-content/uploads/2026/07/CIO-CMMC-Reform-Memo_26-P-1023.pdf?hss_channel=lcp-348902  Submit your own response to the DoD's RFI here: https://sam.gov/workspace/contract/opp/89ef9bfb0834473791e991c712698d94/view

About

Our experiences inspired the creation of The CMMC Compliance Guide Podcast and its accompanying resources. The podcast began as a way to share what we learned through real-world challenges—like helping that aerospace machine shop—and to provide accessible education for businesses navigating DoD cybersecurity requirements. The CMMC Compliance Guide Podcast breaks down complex topics like NIST 800-171 and CMMC into actionable, easy-to-understand steps. Whether you’re a subcontractor struggling to meet compliance deadlines or a business owner looking to secure your supply chain, the guide offers practical advice to help you take control of your cybersecurity journey.

You Might Also Like