CMMC Compliance Guide

CMMC Compliance Guide

Our experiences inspired the creation of The CMMC Compliance Guide Podcast and its accompanying resources. The podcast began as a way to share what we learned through real-world challenges—like helping that aerospace machine shop—and to provide accessible education for businesses navigating DoD cybersecurity requirements. The CMMC Compliance Guide Podcast breaks down complex topics like NIST 800-171 and CMMC into actionable, easy-to-understand steps. Whether you’re a subcontractor struggling to meet compliance deadlines or a business owner looking to secure your supply chain, the guide offers practical advice to help you take control of your cybersecurity journey.

  1. 2d ago

    CMMC Phase 2 Paused: Why the DoD's Reasoning Doesn't Add Up, and What to Expect After the 60-Day Review

    Submit any questions you would like answered on the podcast! The Department of War's pause on CMMC Phase 2 sparked a wave of panic, and a wave of misinformation right behind it. In this episode, Stacey and Brooke go deeper than the headline: what the pause actually changes, why the stated justification (cost, assessor capacity) doesn't hold up against the numbers, and what's realistically likely to come out of the 60-day review. In this episode: What "Phase 2 is paused" actually means (it's the third-party certification requirement on new contracts, not your obligation to be compliant)The biggest misconception floating around: "CMMC is suspended" vs. what's actually trueWhy the capacity argument (claims of "only 100 assessors") doesn't match reality (there are over 1,000 CCAs)Why the cost argument conflates "cost of certification" with "cost of actually being compliant," which have always been expensiveWhy self-assessments may face MORE scrutiny, not less, while third-party validation is pausedHistorical precedent: every incoming DoD/DoW CIO has paused and retooled this program since 2021, and it's never been canceledWhat to actually do this week if you're mid-remediation, mid-contract, or have a mock or certification assessment already scheduledThe open RFI (Request for Information) the DoD posted, and why submitting a response mattersJustice IT Consulting's own CMMC Level 2 certification newsThe mark-your-calendar date: September 14th is when the 60-day window closes and we should learn more about what comes next.  Read the actual DoD memo here: https://federalnewsnetwork.com/wp-content/uploads/2026/07/CIO-CMMC-Reform-Memo_26-P-1023.pdf?hss_channel=lcp-348902  Submit your own response to the DoD's RFI here: https://sam.gov/workspace/contract/opp/89ef9bfb0834473791e991c712698d94/view

  2. 4d ago

    CMMC Phase 2 Certification Paused for 60 Days: What the DoD Memo Really Changes (and What It Doesn't)

    Submit any questions you would like answered on the podcast! Here are the actual memos (Definitely worth a read):   https://federalnewsnetwork.com/wp-content/uploads/2026/07/CIO-CMMC-Reform-Memo_26-P-1023.pdf?hss_channel=lcp-348902https://federalnewsnetwork.com/wp-content/uploads/2026/07/CIO-CMMC-Reform-Memo_26-P-1023.pdf?hss_channel=lcp-348902https://dodcio.defense.gov/Portals/0/Documents/Library/ImplementingSuspensionCMMC-PhaseII.pdfThe Department of War just paused the rollout of CMMC Phase 2's third-party certification requirement for 60 days. Austin breaks down what the memo actually says, what it doesn't say, and why "certification is paused" is not the same thing as "compliance is paused." In this episode: What the 60-day pause on CMMC Phase 2 actually covers (hint: it's the certification verification process, not the underlying NIST 800-171 requirements)Why this could ultimately make your path to CMMC less expensive, and why that's not a reason to slow downWhy contractors who are already deep into implementation are in the strongest position no matter which direction this goesWhy assuming "compliance has disappeared" is the riskiest read of this newsWhat happens if third-party certification gets replaced with a stronger self-attestation or spot-check model, and why unsupported SPRS scores are already a liabilityA trade show story about a Department of War investigator actively pursuing ITAR fraud leads, and what that says about enforcement appetite right nowWhat to actually do in the next 60 days while DoD figures out the future of the verification model

  3. Jul 10

    CMMC for Small Aerospace Suppliers: Real Costs, DIY Limits, Level 1 vs 2, and the November 2026 Deadline

    Submit any questions you would like answered on the podcast! Small aerospace suppliers are getting hit with the same CMMC questions over and over: what do I actually need to do if my contract requirements aren't clear yet, does redacting a drawing get it out of CUI territory, will a tool like ThreatLocker or Prevail make me compliant, and what is this actually going to cost. In this episode, Stacey and Brooke from Justice IT Consulting go through the real answers small manufacturers, machine shops, and engineering firms need before the November 10, 2026 DFARS CMMC requirement hits new DOD contracts. Topics covered: Why you can't fully plan compliance without knowing FCI vs. CUI exposure, and what that means for your Microsoft 365 environment (GCC vs. GCC High)Why redacting a customer name or contract number from a drawing does NOT remove CUI statusWhy compliance tools alone (ThreatLocker, Prevail, etc.) can't get you certifiedRealistic cost ranges for CMMC Level 2 certification, and why "$5,000" and "$20,000" quotes are misleadingHow far a small company can actually get doing CMMC in-house, including where AI-generated policies fall shortWhether to start at Level 1 and move up later, or go straight to Level 2What changes for new DOD contracts after November 10, 2026How to get an honest readiness check with a gaps assessment before spending moneyWe're also co-hosting a free live webinar with FutureFeed and Preveil on shared responsibility in CMMC assessments, covering how to read a customer responsibility matrix and close gaps before they become assessment findings. Tuesday, July 21st at 12 PM Central.  Register (free, recording sent to all registrants): cmmccomplianceguide.com/podcast

About

Our experiences inspired the creation of The CMMC Compliance Guide Podcast and its accompanying resources. The podcast began as a way to share what we learned through real-world challenges—like helping that aerospace machine shop—and to provide accessible education for businesses navigating DoD cybersecurity requirements. The CMMC Compliance Guide Podcast breaks down complex topics like NIST 800-171 and CMMC into actionable, easy-to-understand steps. Whether you’re a subcontractor struggling to meet compliance deadlines or a business owner looking to secure your supply chain, the guide offers practical advice to help you take control of your cybersecurity journey.

You Might Also Like