Cybersecurity Maturity Model Certification (CMMC) Unlocked
Cybersecurity Maturity Model Certification (CMMC) Unlocked

Cybersecurity Maturity Model Certification (CMMC) Unlocked

This podcast contains dialog, voices and materials that are generated by Artificial Intelligence tools, but reviewed and published by the creator. Welcome to CMMC Unlocked, the definitive podcast for defense contractors, cybersecurity professionals, and compliance leaders navigating the complex world of the Cybersecurity Maturity Model Certification (CMMC). Hosted by a seasoned Certified CMMC Assessor and Instructor with years of hands-on experience in assessments, gap analyses, and implementation services, this series pulls back the curtain on what it really takes to achieve and maintain CMMC compliance. This podcast contains dialog, voices and materials that are generated by Artificial Intelligence tools, but reviewed and published by the creator. Each episode dives deep into the practical realities of CMMC—from interpreting the latest updates from the DoD and Cyber-AB, to demystifying assessment criteria, to sharing real-world lessons learned from the field. Whether you're a small business just starting your compliance journey or a prime contractor preparing for a Level 2 assessment, this podcast delivers actionable insights, expert interviews, and strategic guidance to help you succeed. What You’ll Learn: How to prepare for a CMMC assessment (and what assessors are really looking for) Common pitfalls and how to avoid them Implementation strategies that work for organizations of all sizes Updates on CMMC rulemaking, timelines, and policy changes Stories from the field: anonymized case studies and lessons learned Why Listen? Because compliance isn’t just about checking boxes—it’s about protecting our national defense supply chain. And no one understands that better than someone who’s been in the trenches, guiding organizations from uncertainty to certification.

Episodes (47)

CMMC Phase II Paused: What Small Defense Vendors Need to Know

CMMC Phase II Paused: What Small Defense Vendors Need to Know

Breaking the CMMC Assessment Bottleneck

Breaking the CMMC Assessment Bottleneck

Stop Writing SSPs Like Paperweights

Stop Writing SSPs Like Paperweights

Why CMMC Certification Could Take 97.5 Years

Why CMMC Certification Could Take 97.5 Years

CUI Compliance: From Executive Order to DFARS

CUI Compliance: From Executive Order to DFARS

Who Must Mark CUI? DoD Contracting Risks Explained

Who Must Mark CUI? DoD Contracting Risks Explained

CUI Clarity: What Contractors Need to Know

CUI Clarity: What Contractors Need to Know

CMMC Is a Program, Not a Project

CMMC Is a Program, Not a Project

SSP Breadcrumbs: Proving Controls, Scope, and Inheritance

SSP Breadcrumbs: Proving Controls, Scope, and Inheritance

CMMC 3.14: System Integrity, Malware Defense, and Monitoring

CMMC 3.14: System Integrity, Malware Defense, and Monitoring

CMMC SC Controls: Protecting Boundaries and Data in Transit

CMMC SC Controls: Protecting Boundaries and Data in Transit

CA Controls Unlocked: Security Plans, POA&Ms, and Continuous Monitoring

CA Controls Unlocked: Security Plans, POA&Ms, and Continuous Monitoring

Cyber Trust Mark: What IoT Labels Teach Us About Trust, Risk, and CMMC

Cyber Trust Mark: What IoT Labels Teach Us About Trust, Risk, and CMMC

CMMC "Significant Changes": Do They Really Invalidate Your Certification?

CMMC "Significant Changes": Do They Really Invalidate Your Certification?

Making CMMC Risk Management Practical: RA Domain, Policies, and Change Management

Making CMMC Risk Management Practical: RA Domain, Policies, and Change Management

Securing Access Unlocking Personnel Screening

Securing Access Unlocking Personnel Screening

Lockdown Success Physical Security in CMMC

Lockdown Success Physical Security in CMMC

Mastering Media Security for CMMC Success

Mastering Media Security for CMMC Success

Understanding Covered Defense Information in Defense Contracting

Understanding Covered Defense Information in Defense Contracting

Mastering the Maintenance "MA" Family for CMMC Level 2

Mastering the Maintenance "MA" Family for CMMC Level 2

False Claims Act and the Cybersecurity Compliance Trap

False Claims Act and the Cybersecurity Compliance Trap

NIST Incident Response

NIST Incident Response

Training and Awareness Essentials for NIST SP800-171 Controls

Training and Awareness Essentials for NIST SP800-171 Controls

Mastering NIST SP 800-171 Audit and Accountability (AU) Controls

Mastering NIST SP 800-171 Audit and Accountability (AU) Controls

When Is MFA Really Required? Navigating CMMC, NIST, and Kerberos in Practice

When Is MFA Really Required? Navigating CMMC, NIST, and Kerberos in Practice

Configuration Management Essentials for NIST SP800-171

Configuration Management Essentials for NIST SP800-171

The Power of Acceptable Use Policies for CMMC Level 2

The Power of Acceptable Use Policies for CMMC Level 2

Eliminating the Line: Rethinking Basic and Derived Security Requirements in NIST SP 800-171 Revision 3

Eliminating the Line: Rethinking Basic and Derived Security Requirements in NIST SP 800-171 Revision 3

System Security Plan Templates Demystified

System Security Plan Templates Demystified

Building a Bulletproof Incident Response Plan

Building a Bulletproof Incident Response Plan

Real-World Cyber Incident Response Beyond the Tabletop

Real-World Cyber Incident Response Beyond the Tabletop

Demystifying DoD Cloud Security: SRGs, STIGs, and CMMC Alignment

Demystifying DoD Cloud Security: SRGs, STIGs, and CMMC Alignment

Deep Dive: NIST Risk Assessment & Prioritization Process

Deep Dive: NIST Risk Assessment & Prioritization Process

Supporting Documentation and Procedures for Access Control Compliance

Supporting Documentation and Procedures for Access Control Compliance

Aligning the AI Risk Management Framework with CUI Risk Assessment Requirements

Aligning the AI Risk Management Framework with CUI Risk Assessment Requirements

Incident Response Interlaced: DFARS 252.204-7012 and NIST SP800-171

Incident Response Interlaced: DFARS 252.204-7012 and NIST SP800-171

CMMC Rollout Countdown and the Road to 2025

CMMC Rollout Countdown and the Road to 2025

How Long and How Much? Realistic Timelines and Costs for CMMC & NIST SP 800-171 Compliance

How Long and How Much? Realistic Timelines and Costs for CMMC & NIST SP 800-171 Compliance

What Happens Next for 48 CFR 204.75: Timeline to CMMC Enforcement

What Happens Next for 48 CFR 204.75: Timeline to CMMC Enforcement

Self-Assess or Certify: The New DoD CUI Assessment Split

Self-Assess or Certify: The New DoD CUI Assessment Split

Unpacking MSSP Challenges in CMMC Environments

Unpacking MSSP Challenges in CMMC Environments

CMMC Scoping guides

CMMC Scoping guides

Risk Assessments and Meeting NIST SP 800-171 Control 3.11.1

Risk Assessments and Meeting NIST SP 800-171 Control 3.11.1

Unlocking Federal Rulemaking and CMMC Implementation

Unlocking Federal Rulemaking and CMMC Implementation

Continuous Compliance in Action

Continuous Compliance in Action

CMMC 2.0 Rollout and Realities

CMMC 2.0 Rollout and Realities

Safeguarding CUI and Data Rights

Safeguarding CUI and Data Rights