
Cybersecurity Maturity Model Certification (CMMC) Unlocked
This podcast contains dialog, voices and materials that are generated by Artificial Intelligence tools, but reviewed and published by the creator.
Welcome to CMMC Unlocked, the definitive podcast for defense contractors, cybersecurity professionals, and compliance leaders navigating the complex world of the Cybersecurity Maturity Model Certification (CMMC). Hosted by a seasoned Certified CMMC Assessor and Instructor with years of hands-on experience in assessments, gap analyses, and implementation services, this series pulls back the curtain on what it really takes to achieve and maintain CMMC compliance. This podcast contains dialog, voices and materials that are generated by Artificial Intelligence tools, but reviewed and published by the creator.
Each episode dives deep into the practical realities of CMMC—from interpreting the latest updates from the DoD and Cyber-AB, to demystifying assessment criteria, to sharing real-world lessons learned from the field. Whether you're a small business just starting your compliance journey or a prime contractor preparing for a Level 2 assessment, this podcast delivers actionable insights, expert interviews, and strategic guidance to help you succeed.
What You’ll Learn:
How to prepare for a CMMC assessment (and what assessors are really looking for)
Common pitfalls and how to avoid them
Implementation strategies that work for organizations of all sizes
Updates on CMMC rulemaking, timelines, and policy changes
Stories from the field: anonymized case studies and lessons learned
Why Listen? Because compliance isn’t just about checking boxes—it’s about protecting our national defense supply chain. And no one understands that better than someone who’s been in the trenches, guiding organizations from uncertainty to certification.
Episodes (47)
CMMC Phase II Paused: What Small Defense Vendors Need to Know
Breaking the CMMC Assessment Bottleneck
Stop Writing SSPs Like Paperweights
Why CMMC Certification Could Take 97.5 Years
CUI Compliance: From Executive Order to DFARS
Who Must Mark CUI? DoD Contracting Risks Explained
CUI Clarity: What Contractors Need to Know
CMMC Is a Program, Not a Project
SSP Breadcrumbs: Proving Controls, Scope, and Inheritance
CMMC 3.14: System Integrity, Malware Defense, and Monitoring
CMMC SC Controls: Protecting Boundaries and Data in Transit
CA Controls Unlocked: Security Plans, POA&Ms, and Continuous Monitoring
Cyber Trust Mark: What IoT Labels Teach Us About Trust, Risk, and CMMC
CMMC "Significant Changes": Do They Really Invalidate Your Certification?
Making CMMC Risk Management Practical: RA Domain, Policies, and Change Management
Securing Access Unlocking Personnel Screening
Lockdown Success Physical Security in CMMC
Mastering Media Security for CMMC Success
Understanding Covered Defense Information in Defense Contracting
Mastering the Maintenance "MA" Family for CMMC Level 2
False Claims Act and the Cybersecurity Compliance Trap
NIST Incident Response
Training and Awareness Essentials for NIST SP800-171 Controls
Mastering NIST SP 800-171 Audit and Accountability (AU) Controls
When Is MFA Really Required? Navigating CMMC, NIST, and Kerberos in Practice
Configuration Management Essentials for NIST SP800-171
The Power of Acceptable Use Policies for CMMC Level 2
Eliminating the Line: Rethinking Basic and Derived Security Requirements in NIST SP 800-171 Revision 3

System Security Plan Templates Demystified

Building a Bulletproof Incident Response Plan

Real-World Cyber Incident Response Beyond the Tabletop

Demystifying DoD Cloud Security: SRGs, STIGs, and CMMC Alignment

Deep Dive: NIST Risk Assessment & Prioritization Process

Supporting Documentation and Procedures for Access Control Compliance

Aligning the AI Risk Management Framework with CUI Risk Assessment Requirements

Incident Response Interlaced: DFARS 252.204-7012 and NIST SP800-171

CMMC Rollout Countdown and the Road to 2025

How Long and How Much? Realistic Timelines and Costs for CMMC & NIST SP 800-171 Compliance

What Happens Next for 48 CFR 204.75: Timeline to CMMC Enforcement

Self-Assess or Certify: The New DoD CUI Assessment Split

Unpacking MSSP Challenges in CMMC Environments

CMMC Scoping guides

Risk Assessments and Meeting NIST SP 800-171 Control 3.11.1

Unlocking Federal Rulemaking and CMMC Implementation

Continuous Compliance in Action

CMMC 2.0 Rollout and Realities
