🚨 Want to break into DoD cybersecurity but don't have eMASS experience? Gain hands on experience with RMF Academy eMASS Lab Access and build the confidence employers are looking for. Link below 👇 https://www.rmfacademy.io/courses/RMF-Academy-eMASS-Lab-Access 🚀 Ready to break into DoD cybersecurity? RMF Academy gives you the hands on training, practical resources, and real world guidance to build the skills employers are looking for. Link below 👇 https://www.rmfacademy.io/ Timestamps: 00:00 Introduction 00:59 Meet CMMC Assessor Carter Schoenberg 02:23 What Is CMMC and Who Actually Needs It? 05:49 What Is CUI? 06:40 CMMC Levels Explained 09:03 The Problem With CUI and Government Contracts 10:43 CMMC Phase 1 and Phase 2 Explained 11:38 What Happened to CMMC Phase 2? 14:28 The Real Cost of CMMC Compliance 16:54 Why Protecting CUI Matters 19:42 How Companies Should Start Preparing for CMMC 24:04 Understanding Your CUI Data Flow 24:24 What CMMC Assessors Look for in Documentation 25:36 What Actually Happens During a CMMC Assessment 27:50 How to Prepare Your CMMC Evidence and Artifacts 29:27 Common CMMC Documentation Mistakes 31:11 How CMMC Controls Are Actually Assessed 32:31 What Happens After the Assessment? 33:18 What Happens When Evidence Is Missing? 36:33 Should You Get a CMMC Mock Assessment? 38:06 Why So Many Companies Use Microsoft Intune for CMMC 40:11 CMMC Implementation Mistakes to Avoid 42:50 What It Takes to Pass a CMMC Assessment 46:29 CMMC Assessment Preparation Checklist 48:40 How to Use the CMMC Assessor Guides 49:24 Understanding CUI Assets and Assessment Scope 50:40 Why Universities May Need CMMC 52:03 Universities Already Being Required to Meet CMMC Level 2 53:01 CMMC vs Other Cybersecurity Assessments 54:49 The Future of CUI Requirements 57:34 CMMC Level 2 Certification Requirements 59:57 The Cost of CMMC Implementation and Certification 01:01:49 How to Choose a Good CMMC Assessor 01:04:00 Final Thoughts VIdeo Description: What does a CMMC assessor actually look for during an assessment? In this episode of the Tech Woke Podcast, Christopher Okpala sits down with CMMC assessor Carter Schoenberg to break down the CMMC assessment process, what organizations should expect, and how defense contractors can properly prepare before an assessor arrives. We discuss CMMC, Controlled Unclassified Information (CUI), CMMC Level 2, assessment scope, security controls, evidence, artifacts, documentation, and implementation. Carter explains why simply having policies isn't enough and what organizations need to demonstrate to show that their cybersecurity practices are actually implemented. We also discuss common documentation mistakes, missing evidence, mock assessments, Microsoft Intune, the cost of CMMC compliance, and what happens when an assessor identifies gaps. If you're an ISSO, GRC professional, cybersecurity professional, government contractor, CMMC consultant, MSP/MSSP, or business operating within the Defense Industrial Base (DIB), this conversation provides a practical look at how CMMC assessments work and how organizations can prepare. In this episode: What CMMC is and who needs it What CUI is and why it must be protected CMMC levels and assessment requirements How to prepare for a CMMC assessment What CMMC assessors actually look for How to prepare controls, evidence, and artifacts CMMC documentation requirements How assessors validate control implementation What happens when evidence is missing Common CMMC preparation mistakes Why companies use Microsoft Intune for CMMC environments CMMC assessment scope and CUI data flows Whether companies should conduct mock assessments The cost of preparing for CMMC How to choose a CMMC assessor or consultant How cybersecurity professionals can get involved in the CMMC ecosystem If your organization is preparing for a CMMC assessment, don't wait until assessment day to figure out whether your documentation, evidence, and technical implementation align. This episode gives you an assessor's perspective on what preparation actually looks like. Subscribe to Tech Woke for more conversations about CMMC, RMF, GRC, ISSO careers, federal cybersecurity, GovTech, eMASS, NIST 800-53, and cybersecurity compliance. Question for you: Is your organization currently preparing for CMMC? #CMMC #Cybersecurity #GRC