CMMC Compliance Guide

CMMC Compliance Guide

Our experiences inspired the creation of The CMMC Compliance Guide Podcast and its accompanying resources. The podcast began as a way to share what we learned through real-world challenges—like helping that aerospace machine shop—and to provide accessible education for businesses navigating DoD cybersecurity requirements. The CMMC Compliance Guide Podcast breaks down complex topics like NIST 800-171 and CMMC into actionable, easy-to-understand steps. Whether you’re a subcontractor struggling to meet compliance deadlines or a business owner looking to secure your supply chain, the guide offers practical advice to help you take control of your cybersecurity journey.

  1. 2d ago ·  Video

    CMMC Vendor Marketing Claims Decoded: What "Covers 90 of 110 Controls" Actually Means

    Submit any questions you would like answered on the podcast! Every CMMC vendor says the same thing: "we cover 80 out of 110 controls" or "90 out of 110." Austin and Brooke break down what that claim actually means, why "maps to," "satisfies," and "supports" are not interchangeable words, and why you almost always still have work to do even after buying the solution. In this episode: What vendors actually mean when they claim to cover a specific number of the 110 controlsWhy "maps to," "satisfies," and "supports" are different claims with different implications for your compliance programWhy you can't stack vendors (40 controls from Vendor A plus 50 from Vendor B does not equal 90 covered)The moment your computer enters scope even when you're using a fully FedRAMP-compliant vendor: downloading, caching, or transmitting CUI through itWhy "I never saved it to my computer, I just passed it through" doesn't get you out of scope (process, store, or transmit is the bar)How to use a CRM (customer responsibility matrix) or SRM (shared responsibility matrix) to know exactly where a vendor's responsibility ends and yours beginsWhy your MSP or IT provider needs a CRM too, not just your cloud vendorsThe exact questions to ask any vendor before you buy: which control numbers, full satisfaction vs. contribution, which systems and assets it applies to, and what's still on youWhy vendors can only speak to their own product, not your specific environment, and why you need someone (in-house or outsourced) who understands your full compliance picture

  2. Aug 21 ·  Video

    The Real Cost of CMMC Scoping Mistakes: Is "Six Figures" Real or Just Marketing?

    Submit any questions you would like answered on the podcast! Is the "six-figure CMMC scoping mistake" a real number, or just something people throw around to sound scary? Stacey and Brooke break down where these numbers actually come from, what over-scoping really costs versus under-scoping, and what a defensible scope actually looks like. In this episode: Where the "six figures" scoping numbers actually come from (and why the DoW CIO and SBA's recent numbers conflated compliance cost with certification cost)What over-scoping actually costs: pulling in unnecessary cloud systems, remote users, and locationsWhat under-scoping actually costs: a $30k-$40k assessment redo at best, a False Claims Act investigation at worstThe most commonly missed scoping items: downloaded CUI, cached files, backups, CNC-connected computers, and cloud file-sync tools like Prevail DriveWhy vendors and IT providers (MSPs, MSSPs) are an underscoping trap if their CRM/SRM documentation isn't in placeWhy most over-scoping actually traces back to primes and the government not clearly marking what is and isn't CUI2026 scoping clarifications: encryption doesn't create a CUI boundary, paper-only CUI can limit flowdown, and why FedRAMP 20X won't satisfy DoW requirementsReal False Claims Act cases where scoping was the legal basis (including a Georgia Tech case)What a defensible scope actually looks like in your SSPNIST 800-171 Revision 3 on the horizon, and why you need to start planning for it now regardless of what happens with the CMMC pause

  3. Aug 14 ·  Video

    The Complete CMMC Compliance Checklist for 2026: Phase 2 Pause, Level 1 vs Level 2, Scoping, and Vendor Documentation

    Submit any questions you would like answered on the podcast! This is the all-in-one CMMC checklist episode. Austin and Brooke pull together everything into one place: what the 60-day Phase 2 pause actually changed (and didn't), what CMMC Level 1 really requires, what Level 2 really requires, why scoping is the foundation everything else depends on, and where most assessments actually fall apart. In this episode: What CIO Kirsten Davies' memo suspended, and what it left completely alone (spoiler: almost everything)Why the government's stated reasoning for the pause (cost, assessor shortage) doesn't hold up against real assessment pricingThe RFI and task force timeline: what happens on August 14th, and what to expect around September 14thWhat happens to contracts that already have Phase 2 certification language written inWhere to actually focus your compliance budget and effort during the pauseCMMC Level 1: the checklist most people gloss over, and why it's not "nothing"CMMC Level 2: the 110 controls and 320 assessment objectives, POA&M rules, and the controls that most commonly get missedWhy scoping has to come first, and what happens when you skip it (including a mole infestation analogy that actually makes sense)Whether your G-code, derivative drawings, and CAD pull-outs are CUIESPs, CSPs, MSPs, and MSSPs: what each one means for your documentation and your assessmentThe two most common reasons assessments fail: documentation gaps and vendor/CRM gapsJustice IT Consulting's own path to CMMC Level 2 certification, completed right after the pause was announced

  4. Jul 31 ·  Video

    Cyber AB June 2026 Town Hall Recap: Enforcement Data, Paper CUI Rules, Choosing a C3PAO, and the FAR CUI Update

    Submit any questions you would like answered on the podcast! We're recapping the Cyber AB's June 2026 Town Hall, five topics every DoD contractor needs to hear, plus what's changed since (including the CMMC Phase 2 pause that landed after this town hall happened). Stacey and Brooke break down the real enforcement numbers, the paper CUI rules everyone gets wrong, how to actually vet a C3PAO, and the FAR CUI rule updates working their way through public comment. In this episode: False Claims Act enforcement: why almost every case comes from whistleblowers, not breaches, and why the discrepancies are massive (think negative scores, not "110 vs. 107")Paper-only CUI: when you're exempt from CMMC Level 2 controls, and the exact moment that exemption disappears (scanning, photographing, emailing it)How the town hall's November 10th "full steam ahead" messaging got overtaken by the Phase 2 pause memo weeks laterWhat to actually ask when interviewing C3PAOs (assessor headcount, 1099 vs. employee, on-site requirements, SOCI screening status)FAR CUI rule updates: the incident reporting window moving to 72 hours, and the mislabeled/unlabeled CUI reporting requirement getting struckWhy NIST 800-171 and CMMC were built for ongoing management, not a one-time snapshot, and what that means for your evidence and documentationJustice IT Consulting's own path through certification, and why that certification still matters even during the pause

  5. Jul 17

    CMMC Phase 2 Paused: Why the DoD's Reasoning Doesn't Add Up, and What to Expect After the 60-Day Review

    Submit any questions you would like answered on the podcast! The Department of War's pause on CMMC Phase 2 sparked a wave of panic, and a wave of misinformation right behind it. In this episode, Stacey and Brooke go deeper than the headline: what the pause actually changes, why the stated justification (cost, assessor capacity) doesn't hold up against the numbers, and what's realistically likely to come out of the 60-day review. In this episode: What "Phase 2 is paused" actually means (it's the third-party certification requirement on new contracts, not your obligation to be compliant)The biggest misconception floating around: "CMMC is suspended" vs. what's actually trueWhy the capacity argument (claims of "only 100 assessors") doesn't match reality (there are over 1,000 CCAs)Why the cost argument conflates "cost of certification" with "cost of actually being compliant," which have always been expensiveWhy self-assessments may face MORE scrutiny, not less, while third-party validation is pausedHistorical precedent: every incoming DoD/DoW CIO has paused and retooled this program since 2021, and it's never been canceledWhat to actually do this week if you're mid-remediation, mid-contract, or have a mock or certification assessment already scheduledThe open RFI (Request for Information) the DoD posted, and why submitting a response mattersJustice IT Consulting's own CMMC Level 2 certification newsThe mark-your-calendar date: September 14th is when the 60-day window closes and we should learn more about what comes next.  Read the actual DoD memo here: https://federalnewsnetwork.com/wp-content/uploads/2026/07/CIO-CMMC-Reform-Memo_26-P-1023.pdf?hss_channel=lcp-348902  Submit your own response to the DoD's RFI here: https://sam.gov/workspace/contract/opp/89ef9bfb0834473791e991c712698d94/view

  6. Jul 15

    CMMC Phase 2 Certification Paused for 60 Days: What the DoD Memo Really Changes (and What It Doesn't)

    Submit any questions you would like answered on the podcast! Here are the actual memos (Definitely worth a read):   https://federalnewsnetwork.com/wp-content/uploads/2026/07/CIO-CMMC-Reform-Memo_26-P-1023.pdf?hss_channel=lcp-348902https://federalnewsnetwork.com/wp-content/uploads/2026/07/CIO-CMMC-Reform-Memo_26-P-1023.pdf?hss_channel=lcp-348902https://dodcio.defense.gov/Portals/0/Documents/Library/ImplementingSuspensionCMMC-PhaseII.pdfThe Department of War just paused the rollout of CMMC Phase 2's third-party certification requirement for 60 days. Austin breaks down what the memo actually says, what it doesn't say, and why "certification is paused" is not the same thing as "compliance is paused." In this episode: What the 60-day pause on CMMC Phase 2 actually covers (hint: it's the certification verification process, not the underlying NIST 800-171 requirements)Why this could ultimately make your path to CMMC less expensive, and why that's not a reason to slow downWhy contractors who are already deep into implementation are in the strongest position no matter which direction this goesWhy assuming "compliance has disappeared" is the riskiest read of this newsWhat happens if third-party certification gets replaced with a stronger self-attestation or spot-check model, and why unsupported SPRS scores are already a liabilityA trade show story about a Department of War investigator actively pursuing ITAR fraud leads, and what that says about enforcement appetite right nowWhat to actually do in the next 60 days while DoD figures out the future of the verification model

  7. Jul 10

    CMMC for Small Aerospace Suppliers: Real Costs, DIY Limits, Level 1 vs 2, and the November 2026 Deadline

    Submit any questions you would like answered on the podcast! Small aerospace suppliers are getting hit with the same CMMC questions over and over: what do I actually need to do if my contract requirements aren't clear yet, does redacting a drawing get it out of CUI territory, will a tool like ThreatLocker or Prevail make me compliant, and what is this actually going to cost. In this episode, Stacey and Brooke from Justice IT Consulting go through the real answers small manufacturers, machine shops, and engineering firms need before the November 10, 2026 DFARS CMMC requirement hits new DOD contracts. Topics covered: Why you can't fully plan compliance without knowing FCI vs. CUI exposure, and what that means for your Microsoft 365 environment (GCC vs. GCC High)Why redacting a customer name or contract number from a drawing does NOT remove CUI statusWhy compliance tools alone (ThreatLocker, Prevail, etc.) can't get you certifiedRealistic cost ranges for CMMC Level 2 certification, and why "$5,000" and "$20,000" quotes are misleadingHow far a small company can actually get doing CMMC in-house, including where AI-generated policies fall shortWhether to start at Level 1 and move up later, or go straight to Level 2What changes for new DOD contracts after November 10, 2026How to get an honest readiness check with a gaps assessment before spending moneyWe're also co-hosting a free live webinar with FutureFeed and Preveil on shared responsibility in CMMC assessments, covering how to read a customer responsibility matrix and close gaps before they become assessment findings. Tuesday, July 21st at 12 PM Central.  Register (free, recording sent to all registrants): cmmccomplianceguide.com/podcast

About

Our experiences inspired the creation of The CMMC Compliance Guide Podcast and its accompanying resources. The podcast began as a way to share what we learned through real-world challenges—like helping that aerospace machine shop—and to provide accessible education for businesses navigating DoD cybersecurity requirements. The CMMC Compliance Guide Podcast breaks down complex topics like NIST 800-171 and CMMC into actionable, easy-to-understand steps. Whether you’re a subcontractor struggling to meet compliance deadlines or a business owner looking to secure your supply chain, the guide offers practical advice to help you take control of your cybersecurity journey.

You Might Also Like