<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:podcast="https://podcastindex.org/namespace/1.0" xmlns:jellypod="https://jellypod.ai/namespace/1.0" xmlns:psc="http://podlove.org/simple-chapters"><channel><title><![CDATA[Cybersecurity Maturity Model Certification (CMMC) Unlocked]]></title><description><![CDATA[This podcast contains dialog, voices and materials that are generated by Artificial Intelligence tools, but reviewed and published by the creator.

Welcome to CMMC Unlocked, the definitive podcast for defense contractors, cybersecurity professionals, and compliance leaders navigating the complex world of the Cybersecurity Maturity Model Certification (CMMC). Hosted by a seasoned Certified CMMC Assessor and Instructor with years of hands-on experience in assessments, gap analyses, and implementation services, this series pulls back the curtain on what it really takes to achieve and maintain CMMC compliance. This podcast contains dialog, voices and materials that are generated by Artificial Intelligence tools, but reviewed and published by the creator.

Each episode dives deep into the practical realities of CMMC—from interpreting the latest updates from the DoD and Cyber-AB, to demystifying assessment criteria, to sharing real-world lessons learned from the field. Whether you're a small business just starting your compliance journey or a prime contractor preparing for a Level 2 assessment, this podcast delivers actionable insights, expert interviews, and strategic guidance to help you succeed.

What You’ll Learn:

How to prepare for a CMMC assessment (and what assessors are really looking for)
Common pitfalls and how to avoid them
Implementation strategies that work for organizations of all sizes
Updates on CMMC rulemaking, timelines, and policy changes
Stories from the field: anonymized case studies and lessons learned

Why Listen? Because compliance isn’t just about checking boxes—it’s about protecting our national defense supply chain. And no one understands that better than someone who’s been in the trenches, guiding organizations from uncertainty to certification. (Powered by Jellypod)]]></description><link>https://cmmc-elysian.jellypod.com</link><generator>Powered by Jellypod (https://www.jellypod.com)</generator><lastBuildDate>Thu, 28 May 2026 10:49:54 GMT</lastBuildDate><atom:link href="https://cmmc-elysian.jellypod.com/rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 11 Jul 2025 14:47:38 GMT</pubDate><copyright><![CDATA[Copyright 2026 Cybersecurity Maturity Model Certification (CMMC) Unlocked]]></copyright><language><![CDATA[en]]></language><podcast:locked owner="feed+6939f554@podcasts.jellypod.com">yes</podcast:locked><podcast:guid>a615cc29-4f63-4949-a363-2825116c8d1f</podcast:guid><itunes:author>Jellypod</itunes:author><itunes:subtitle>This podcast contains dialog, voices and materials that are generated by Artificial Intelligence tools, but reviewed and published by the creator.

Welcome to CMMC Unlocked, the definitive podcast for defense contractors, cybersecurity professionals, and </itunes:subtitle><itunes:summary>This podcast contains dialog, voices and materials that are generated by Artificial Intelligence tools, but reviewed and published by the creator.

Welcome to CMMC Unlocked, the definitive podcast for defense contractors, cybersecurity professionals, and compliance leaders navigating the complex world of the Cybersecurity Maturity Model Certification (CMMC). Hosted by a seasoned Certified CMMC Assessor and Instructor with years of hands-on experience in assessments, gap analyses, and implementation services, this series pulls back the curtain on what it really takes to achieve and maintain CMMC compliance. This podcast contains dialog, voices and materials that are generated by Artificial Intelligence tools, but reviewed and published by the creator.

Each episode dives deep into the practical realities of CMMC—from interpreting the latest updates from the DoD and Cyber-AB, to demystifying assessment criteria, to sharing real-world lessons learned from the field. Whether you&apos;re a small business just starting your compliance journey or a prime contractor preparing for a Level 2 assessment, this podcast delivers actionable insights, expert interviews, and strategic guidance to help you succeed.

What You’ll Learn:

How to prepare for a CMMC assessment (and what assessors are really looking for)
Common pitfalls and how to avoid them
Implementation strategies that work for organizations of all sizes
Updates on CMMC rulemaking, timelines, and policy changes
Stories from the field: anonymized case studies and lessons learned

Why Listen? Because compliance isn’t just about checking boxes—it’s about protecting our national defense supply chain. And no one understands that better than someone who’s been in the trenches, guiding organizations from uncertainty to certification. (Powered by Jellypod)</itunes:summary><itunes:type>episodic</itunes:type><itunes:owner><itunes:name>Jellypod</itunes:name><itunes:email>feed+6939f554@podcasts.jellypod.com</itunes:email></itunes:owner><itunes:explicit>false</itunes:explicit><itunes:category text="Technology"/><itunes:category text="Business"/><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/uZE5qQb-8_EzqLIUrFmOV.jpg"/><item><title><![CDATA[CUI Compliance: From Executive Order to DFARS]]></title><description><![CDATA[This episode breaks down how Controlled Unclassified Information evolved from a patchwork of agency labels into a single federal framework under Executive Order 13556, NARA, and DoDI 5200.48. It also explains how technical data controls, distribution statements, and DFARS clauses turn policy into enforceable contractor obligations.]]></description><link>https://cmmc-elysian.jellypod.com/episodes/21f36574-a42b-4fd6-9036-c8efb26aac61</link><guid isPermaLink="false">21f36574-a42b-4fd6-9036-c8efb26aac61</guid><pubDate>Tue, 26 May 2026 11:44:55 GMT</pubDate><enclosure url="https://op3.dev/e,pg=a615cc29-4f63-4949-a363-2825116c8d1f/auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/21f36574-a42b-4fd6-9036-c8efb26aac61/audio.mp3" length="0" type="audio/mpeg"/><podcast:generator uri="https://www.jellypod.com"></podcast:generator><podcast:episode>43</podcast:episode><podcast:transcript url="https://auth.jellypod.ai/storage/v1/object/public/Podcasts/21f36574-a42b-4fd6-9036-c8efb26aac61/captions_1779795887.srt" type="application/x-subrip" language="en" rel="captions"></podcast:transcript><itunes:author>Jellypod</itunes:author><itunes:subtitle>This episode breaks down how Controlled Unclassified Information evolved from a patchwork of agency labels into a single federal framework under Executive Order 13556, NARA, and DoDI 5200.48. It also explains how technical data controls, distribution stat</itunes:subtitle><itunes:summary>This episode breaks down how Controlled Unclassified Information evolved from a patchwork of agency labels into a single federal framework under Executive Order 13556, NARA, and DoDI 5200.48. It also explains how technical data controls, distribution statements, and DFARS clauses turn policy into enforceable contractor obligations.</itunes:summary><itunes:explicit>false</itunes:explicit><itunes:duration>00:14:17</itunes:duration><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/uZE5qQb-8_EzqLIUrFmOV.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Who Must Mark CUI? DoD Contracting Risks Explained]]></title><description><![CDATA[Eric, Paul, and Roz unpack why the DoD—not the contractor—bears the burden of identifying and marking CUI, and why accepting unlabelled data can create serious compliance and False Claims Act exposure.They also trace how DFARS clauses, NIST SP 800-171, and pre-award CIO variance approval shape the procurement process and set the system boundaries for CDI, CTI, and CUI.]]></description><link>https://cmmc-elysian.jellypod.com/episodes/b6cf3330-2cc7-4981-9252-2dc22aa85afb</link><guid isPermaLink="false">b6cf3330-2cc7-4981-9252-2dc22aa85afb</guid><pubDate>Wed, 20 May 2026 20:19:19 GMT</pubDate><enclosure url="https://op3.dev/e,pg=a615cc29-4f63-4949-a363-2825116c8d1f/auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/b6cf3330-2cc7-4981-9252-2dc22aa85afb/audio.mp3" length="0" type="audio/mpeg"/><podcast:generator uri="https://www.jellypod.com"></podcast:generator><podcast:episode>42</podcast:episode><podcast:transcript url="https://auth.jellypod.ai/storage/v1/object/public/Podcasts/b6cf3330-2cc7-4981-9252-2dc22aa85afb/captions_1779308350.srt" type="application/x-subrip" language="en" rel="captions"></podcast:transcript><itunes:author>Jellypod</itunes:author><itunes:subtitle>Eric, Paul, and Roz unpack why the DoD—not the contractor—bears the burden of identifying and marking CUI, and why accepting unlabelled data can create serious compliance and False Claims Act exposure.They also trace how DFARS clauses, NIST SP 800-171, an</itunes:subtitle><itunes:summary>Eric, Paul, and Roz unpack why the DoD—not the contractor—bears the burden of identifying and marking CUI, and why accepting unlabelled data can create serious compliance and False Claims Act exposure.They also trace how DFARS clauses, NIST SP 800-171, and pre-award CIO variance approval shape the procurement process and set the system boundaries for CDI, CTI, and CUI.</itunes:summary><itunes:explicit>false</itunes:explicit><itunes:duration>00:10:43</itunes:duration><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/uZE5qQb-8_EzqLIUrFmOV.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[CUI Clarity: What Contractors Need to Know]]></title><description><![CDATA[Eric Marquette and Paul Netopski, a CMMC expert, break down how to identify CUI, where to look in contract artifacts like CDRLs and DIDs, and why export control, OPSEC, and CPI don’t always mean the same thing. They also cover how to handle unclear or inconsistent contract language, confirm obligations, and avoid costly marking and protection mistakes.]]></description><link>https://cmmc-elysian.jellypod.com/episodes/888d93a7-6480-4ec8-82b3-bb9a55352898</link><guid isPermaLink="false">888d93a7-6480-4ec8-82b3-bb9a55352898</guid><pubDate>Mon, 04 May 2026 14:37:02 GMT</pubDate><enclosure url="https://op3.dev/e,pg=a615cc29-4f63-4949-a363-2825116c8d1f/auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/888d93a7-6480-4ec8-82b3-bb9a55352898/audio.mp3" length="0" type="audio/mpeg"/><podcast:generator uri="https://www.jellypod.com"></podcast:generator><podcast:episode>41</podcast:episode><podcast:transcript url="https://auth.jellypod.ai/storage/v1/object/public/Podcasts/888d93a7-6480-4ec8-82b3-bb9a55352898/captions_1777905404.srt" type="application/x-subrip" language="en" rel="captions"></podcast:transcript><itunes:author>Jellypod</itunes:author><itunes:subtitle>Eric Marquette and Paul Netopski, a CMMC expert, break down how to identify CUI, where to look in contract artifacts like CDRLs and DIDs, and why export control, OPSEC, and CPI don’t always mean the same thing. They also cover how to handle unclear or inc</itunes:subtitle><itunes:summary>Eric Marquette and Paul Netopski, a CMMC expert, break down how to identify CUI, where to look in contract artifacts like CDRLs and DIDs, and why export control, OPSEC, and CPI don’t always mean the same thing. They also cover how to handle unclear or inconsistent contract language, confirm obligations, and avoid costly marking and protection mistakes.</itunes:summary><itunes:explicit>false</itunes:explicit><itunes:duration>00:10:45</itunes:duration><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/uZE5qQb-8_EzqLIUrFmOV.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[CMMC Is a Program, Not a Project]]></title><description><![CDATA[This episode breaks down why CMMC success depends on lifecycle planning, from scoping contracts and data flows to building evidence, remediation, and formal assessment readiness. The hosts also dig into real-world scope traps, crosswalking existing controls, and why steady-state monitoring matters after certification.]]></description><link>https://cmmc-elysian.jellypod.com/episodes/0d7f627c-6416-4c09-b54d-ab49b4d46e4d</link><guid isPermaLink="false">0d7f627c-6416-4c09-b54d-ab49b4d46e4d</guid><pubDate>Tue, 28 Apr 2026 16:13:21 GMT</pubDate><enclosure url="https://op3.dev/e,pg=a615cc29-4f63-4949-a363-2825116c8d1f/auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/0d7f627c-6416-4c09-b54d-ab49b4d46e4d/audio.mp3" length="0" type="audio/mpeg"/><podcast:generator uri="https://www.jellypod.com"></podcast:generator><podcast:episode>40</podcast:episode><podcast:transcript url="https://auth.jellypod.ai/storage/v1/object/public/Podcasts/0d7f627c-6416-4c09-b54d-ab49b4d46e4d/captions_1777392790.srt" type="application/x-subrip" language="en" rel="captions"></podcast:transcript><itunes:author>Jellypod</itunes:author><itunes:subtitle>This episode breaks down why CMMC success depends on lifecycle planning, from scoping contracts and data flows to building evidence, remediation, and formal assessment readiness. The hosts also dig into real-world scope traps, crosswalking existing contro</itunes:subtitle><itunes:summary>This episode breaks down why CMMC success depends on lifecycle planning, from scoping contracts and data flows to building evidence, remediation, and formal assessment readiness. The hosts also dig into real-world scope traps, crosswalking existing controls, and why steady-state monitoring matters after certification.</itunes:summary><itunes:explicit>false</itunes:explicit><itunes:duration>00:09:20</itunes:duration><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/uZE5qQb-8_EzqLIUrFmOV.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[SSP Breadcrumbs: Proving Controls, Scope, and Inheritance]]></title><description><![CDATA[This episode breaks down what assessors actually need from your System Security Plan control implementation summary: precise control status, exact evidence references, and the real mechanisms behind each claim. It also explains how to handle scoping, inheritance, and external services without leaving gaps or ambiguity.]]></description><link>https://cmmc-elysian.jellypod.com/episodes/bf9b97f6-a7b4-43a4-99d1-078d17cd8f3c</link><guid isPermaLink="false">bf9b97f6-a7b4-43a4-99d1-078d17cd8f3c</guid><pubDate>Mon, 20 Apr 2026 18:00:48 GMT</pubDate><enclosure url="https://op3.dev/e,pg=a615cc29-4f63-4949-a363-2825116c8d1f/auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/bf9b97f6-a7b4-43a4-99d1-078d17cd8f3c/audio.mp3" length="0" type="audio/mpeg"/><podcast:generator uri="https://www.jellypod.com"></podcast:generator><podcast:episode>39</podcast:episode><podcast:transcript url="https://auth.jellypod.ai/storage/v1/object/public/Podcasts/bf9b97f6-a7b4-43a4-99d1-078d17cd8f3c/captions_1776708036.srt" type="application/x-subrip" language="en" rel="captions"></podcast:transcript><itunes:author>Jellypod</itunes:author><itunes:subtitle>This episode breaks down what assessors actually need from your System Security Plan control implementation summary: precise control status, exact evidence references, and the real mechanisms behind each claim. It also explains how to handle scoping, inhe</itunes:subtitle><itunes:summary>This episode breaks down what assessors actually need from your System Security Plan control implementation summary: precise control status, exact evidence references, and the real mechanisms behind each claim. It also explains how to handle scoping, inheritance, and external services without leaving gaps or ambiguity.</itunes:summary><itunes:explicit>false</itunes:explicit><itunes:duration>00:08:17</itunes:duration><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/uZE5qQb-8_EzqLIUrFmOV.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[CMMC 3.14: System Integrity, Malware Defense, and Monitoring]]></title><description><![CDATA[Paul and Roz break down the System and Information Integrity controls in CMMC 3.14.1 through 3.14.7, focusing on flaw remediation, malicious code protection, alert monitoring, scanning, and detecting unauthorized use with assessor-ready evidence.They also connect the requirements to NIST guidance and Appendix D, showing how SI-2, SI-3, and SI-4 map to real-world policies, tools, tickets, and logs.]]></description><link>https://cmmc-elysian.jellypod.com/episodes/ca5f201c-905b-4e1c-b62c-32c23a17e8ed</link><guid isPermaLink="false">ca5f201c-905b-4e1c-b62c-32c23a17e8ed</guid><pubDate>Tue, 07 Apr 2026 11:22:54 GMT</pubDate><enclosure url="https://op3.dev/e,pg=a615cc29-4f63-4949-a363-2825116c8d1f/auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/ca5f201c-905b-4e1c-b62c-32c23a17e8ed/audio.mp3" length="0" type="audio/mpeg"/><podcast:generator uri="https://www.jellypod.com"></podcast:generator><podcast:episode>38</podcast:episode><podcast:transcript url="https://auth.jellypod.ai/storage/v1/object/public/Podcasts/ca5f201c-905b-4e1c-b62c-32c23a17e8ed/captions_1775560965.srt" type="application/x-subrip" language="en" rel="captions"></podcast:transcript><itunes:author>Jellypod</itunes:author><itunes:subtitle>Paul and Roz break down the System and Information Integrity controls in CMMC 3.14.1 through 3.14.7, focusing on flaw remediation, malicious code protection, alert monitoring, scanning, and detecting unauthorized use with assessor-ready evidence.They also</itunes:subtitle><itunes:summary>Paul and Roz break down the System and Information Integrity controls in CMMC 3.14.1 through 3.14.7, focusing on flaw remediation, malicious code protection, alert monitoring, scanning, and detecting unauthorized use with assessor-ready evidence.They also connect the requirements to NIST guidance and Appendix D, showing how SI-2, SI-3, and SI-4 map to real-world policies, tools, tickets, and logs.</itunes:summary><itunes:explicit>false</itunes:explicit><itunes:duration>00:11:16</itunes:duration><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/uZE5qQb-8_EzqLIUrFmOV.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[CMMC SC Controls: Protecting Boundaries and Data in Transit]]></title><description><![CDATA[This episode breaks down CMMC System and Communications Protection controls, from defining boundaries and separating public-facing systems to enforcing deny-by-default network rules and stopping split tunneling.It also covers secure design, role separation, shared resource protections, and how to safeguard CUI while it moves across networks.]]></description><link>https://cmmc-elysian.jellypod.com/episodes/a56af569-bc24-4204-85ea-995f29d21e41</link><guid isPermaLink="false">a56af569-bc24-4204-85ea-995f29d21e41</guid><pubDate>Mon, 30 Mar 2026 21:19:58 GMT</pubDate><enclosure url="https://op3.dev/e,pg=a615cc29-4f63-4949-a363-2825116c8d1f/auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/a56af569-bc24-4204-85ea-995f29d21e41/audio.mp3" length="0" type="audio/mpeg"/><podcast:generator uri="https://www.jellypod.com"></podcast:generator><podcast:episode>37</podcast:episode><podcast:transcript url="https://auth.jellypod.ai/storage/v1/object/public/Podcasts/a56af569-bc24-4204-85ea-995f29d21e41/captions_1774905571.srt" type="application/x-subrip" language="en" rel="captions"></podcast:transcript><itunes:author>Jellypod</itunes:author><itunes:subtitle>This episode breaks down CMMC System and Communications Protection controls, from defining boundaries and separating public-facing systems to enforcing deny-by-default network rules and stopping split tunneling.It also covers secure design, role separatio</itunes:subtitle><itunes:summary>This episode breaks down CMMC System and Communications Protection controls, from defining boundaries and separating public-facing systems to enforcing deny-by-default network rules and stopping split tunneling.It also covers secure design, role separation, shared resource protections, and how to safeguard CUI while it moves across networks.</itunes:summary><itunes:explicit>false</itunes:explicit><itunes:duration>00:15:16</itunes:duration><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/uZE5qQb-8_EzqLIUrFmOV.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[CA Controls Unlocked: Security Plans, POA&Ms, and Continuous Monitoring]]></title><description><![CDATA[In this episode, we break down the three core compliance documents that make the CA domain real in practice: the System Security Plan, the Plan of Action and Milestones, and Continuous Monitoring. We’ll explain what each document is, what it should contain, and how assessors and compliance teams use them together to support CMMC and NIST SP 800-171 implementation.]]></description><link>https://cmmc-elysian.jellypod.com/episodes/154fce8b-79a3-4f3d-a291-778bb42a382b</link><guid isPermaLink="false">154fce8b-79a3-4f3d-a291-778bb42a382b</guid><pubDate>Mon, 23 Mar 2026 18:49:15 GMT</pubDate><enclosure url="https://op3.dev/e,pg=a615cc29-4f63-4949-a363-2825116c8d1f/auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/154fce8b-79a3-4f3d-a291-778bb42a382b/audio.mp3" length="0" type="audio/mpeg"/><podcast:generator uri="https://www.jellypod.com"></podcast:generator><podcast:episode>36</podcast:episode><podcast:transcript url="https://auth.jellypod.ai/storage/v1/object/public/Podcasts/154fce8b-79a3-4f3d-a291-778bb42a382b/captions_1774291738.srt" type="application/x-subrip" language="en" rel="captions"></podcast:transcript><itunes:author>Jellypod</itunes:author><itunes:subtitle>In this episode, we break down the three core compliance documents that make the CA domain real in practice: the System Security Plan, the Plan of Action and Milestones, and Continuous Monitoring. We’ll explain what each document is, what it should contai</itunes:subtitle><itunes:summary>In this episode, we break down the three core compliance documents that make the CA domain real in practice: the System Security Plan, the Plan of Action and Milestones, and Continuous Monitoring. We’ll explain what each document is, what it should contain, and how assessors and compliance teams use them together to support CMMC and NIST SP 800-171 implementation.</itunes:summary><itunes:explicit>false</itunes:explicit><itunes:duration>00:13:30</itunes:duration><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/uZE5qQb-8_EzqLIUrFmOV.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Cyber Trust Mark: What IoT Labels Teach Us About Trust, Risk, and CMMC]]></title><description><![CDATA[This episode explores the FCC’s U.S. Cyber Trust Mark for consumer IoT devices and asks a bigger question: what can defense contractors learn from a public-facing cybersecurity label?We break down how the voluntary labeling program works, where it mirrors Energy Star, and why familiar cybersecurity signals matter to buyers, regulators, and the broader market. We also examine the practical limits of labels, including consumer misunderstanding, uneven adoption, and the gap between baseline assurances and real-world security outcomes.Finally, we connect the Cyber Trust Mark back to CMMC by showing how both efforts rely on trust signals, documented controls, and evidence-based confidence rather than marketing claims alone.]]></description><link>https://cmmc-elysian.jellypod.com/episodes/37a3acab-5350-4c99-9cda-f37239c2a906</link><guid isPermaLink="false">37a3acab-5350-4c99-9cda-f37239c2a906</guid><pubDate>Tue, 17 Mar 2026 11:22:32 GMT</pubDate><enclosure url="https://op3.dev/e,pg=a615cc29-4f63-4949-a363-2825116c8d1f/auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/37a3acab-5350-4c99-9cda-f37239c2a906/audio.mp3" length="0" type="audio/mpeg"/><podcast:generator uri="https://www.jellypod.com"></podcast:generator><podcast:episode>35</podcast:episode><podcast:transcript url="https://auth.jellypod.ai/storage/v1/object/public/Podcasts/37a3acab-5350-4c99-9cda-f37239c2a906/captions_1773746543.srt" type="application/x-subrip" language="en" rel="captions"></podcast:transcript><itunes:author>Jellypod</itunes:author><itunes:subtitle>This episode explores the FCC’s U.S. Cyber Trust Mark for consumer IoT devices and asks a bigger question: what can defense contractors learn from a public-facing cybersecurity label?We break down how the voluntary labeling program works, where it mirrors</itunes:subtitle><itunes:summary>This episode explores the FCC’s U.S. Cyber Trust Mark for consumer IoT devices and asks a bigger question: what can defense contractors learn from a public-facing cybersecurity label?We break down how the voluntary labeling program works, where it mirrors Energy Star, and why familiar cybersecurity signals matter to buyers, regulators, and the broader market. We also examine the practical limits of labels, including consumer misunderstanding, uneven adoption, and the gap between baseline assurances and real-world security outcomes.Finally, we connect the Cyber Trust Mark back to CMMC by showing how both efforts rely on trust signals, documented controls, and evidence-based confidence rather than marketing claims alone.</itunes:summary><itunes:explicit>false</itunes:explicit><itunes:duration>00:11:27</itunes:duration><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/uZE5qQb-8_EzqLIUrFmOV.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[CMMC "Significant Changes": Do They Really Invalidate Your Certification?]]></title><description><![CDATA[In this episode of CMMC Unlocked, host Paul Netopski breaks down one of the most misunderstood phrases in the new CMMC rule set and CyberAB guidance: “significant changes.” Many small defense contractors and their advisors worry that any major IT or organizational change will automatically invalidate a hard‑won Level 2 certification. Paul walks through what the 32 CFR Part 170 preamble, the Level 2 Scoping Guide, and the Level 2 Assessment Guide actually say—and what they don’t.We unpack the distinction between:When “significant architectural or boundary changes” require a new certification assessment, andWhen “significant changes” simply require you to update your CMMC Level 2 self‑assessment and affirmation, in line with your ongoing risk management and change‑management processes.Drawing on earlier episodes about risk assessments and continuous monitoring, Paul offers practical guidance for small DIB organizations and consultants on how to:Define what “significant change” means for your environment using NIST SP 800‑37, 800‑53, and 800‑53A concepts.Build change‑management checkpoints that flag potential CMMC impact early.Decide when a change triggers a new self‑assessment and SPRS update versus when it’s covered by your annual affirmation.Keep your System Security Plan, asset inventory, and CMMC Assessment Scope aligned as your environment evolves.If you’re worried that a tech refresh, cloud migration, or acquisition will blow up your CMMC status, this episode will help you separate rumor from requirement and integrate “significant change” into a mature, risk‑based compliance program.]]></description><link>https://cmmc-elysian.jellypod.com/episodes/cf215c28-ac5f-4f20-adba-6123c938feb9</link><guid isPermaLink="false">cf215c28-ac5f-4f20-adba-6123c938feb9</guid><pubDate>Tue, 03 Mar 2026 15:23:34 GMT</pubDate><enclosure url="https://op3.dev/e,pg=a615cc29-4f63-4949-a363-2825116c8d1f/auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/cf215c28-ac5f-4f20-adba-6123c938feb9/audio.mp3" length="0" type="audio/mpeg"/><podcast:generator uri="https://www.jellypod.com"></podcast:generator><podcast:episode>34</podcast:episode><podcast:transcript url="https://auth.jellypod.ai/storage/v1/object/public/Podcasts/cf215c28-ac5f-4f20-adba-6123c938feb9/captions_1772551402.srt" type="application/x-subrip" language="en" rel="captions"></podcast:transcript><itunes:author>Jellypod</itunes:author><itunes:subtitle>In this episode of CMMC Unlocked, host Paul Netopski breaks down one of the most misunderstood phrases in the new CMMC rule set and CyberAB guidance: “significant changes.” Many small defense contractors and their advisors worry that any major IT or organ</itunes:subtitle><itunes:summary>In this episode of CMMC Unlocked, host Paul Netopski breaks down one of the most misunderstood phrases in the new CMMC rule set and CyberAB guidance: “significant changes.” Many small defense contractors and their advisors worry that any major IT or organizational change will automatically invalidate a hard‑won Level 2 certification. Paul walks through what the 32 CFR Part 170 preamble, the Level 2 Scoping Guide, and the Level 2 Assessment Guide actually say—and what they don’t.We unpack the distinction between:When “significant architectural or boundary changes” require a new certification assessment, andWhen “significant changes” simply require you to update your CMMC Level 2 self‑assessment and affirmation, in line with your ongoing risk management and change‑management processes.Drawing on earlier episodes about risk assessments and continuous monitoring, Paul offers practical guidance for small DIB organizations and consultants on how to:Define what “significant change” means for your environment using NIST SP 800‑37, 800‑53, and 800‑53A concepts.Build change‑management checkpoints that flag potential CMMC impact early.Decide when a change triggers a new self‑assessment and SPRS update versus when it’s covered by your annual affirmation.Keep your System Security Plan, asset inventory, and CMMC Assessment Scope aligned as your environment evolves.If you’re worried that a tech refresh, cloud migration, or acquisition will blow up your CMMC status, this episode will help you separate rumor from requirement and integrate “significant change” into a mature, risk‑based compliance program.</itunes:summary><itunes:explicit>false</itunes:explicit><itunes:duration>00:17:01</itunes:duration><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/uZE5qQb-8_EzqLIUrFmOV.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Making CMMC Risk Management Practical: RA Domain, Policies, and Change Management]]></title><description><![CDATA[A practical how-to episode on the CMMC 2.0 Level 2 Risk Assessment (RA) domain for defense contractors. Paul Netopski and Roz the Rulemaker walk through the three RA practices from NIST SP 800-171 (3.11.1, 3.11.2, 3.11.3), show how to build and use a Risk Management Policy aligned to NIST and ISO 31000, and connect risk assessment to real-world threats, third-party risks, business risk appetite, and change management. The hosts reference prior episodes on Configuration/Change Management and other domains to help contractors integrate risk into everyday decisions about people, places, and technology in CUI scope.]]></description><link>https://cmmc-elysian.jellypod.com/episodes/afe85327-e897-46d7-9ba5-11f2422ceeb4</link><guid isPermaLink="false">afe85327-e897-46d7-9ba5-11f2422ceeb4</guid><pubDate>Tue, 03 Mar 2026 13:11:58 GMT</pubDate><enclosure url="https://op3.dev/e,pg=a615cc29-4f63-4949-a363-2825116c8d1f/auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/afe85327-e897-46d7-9ba5-11f2422ceeb4/audio.mp3" length="0" type="audio/mpeg"/><podcast:generator uri="https://www.jellypod.com"></podcast:generator><podcast:episode>33</podcast:episode><podcast:transcript url="https://auth.jellypod.ai/storage/v1/object/public/Podcasts/afe85327-e897-46d7-9ba5-11f2422ceeb4/captions_1772543506.srt" type="application/x-subrip" language="en" rel="captions"></podcast:transcript><itunes:author>Jellypod</itunes:author><itunes:subtitle>A practical how-to episode on the CMMC 2.0 Level 2 Risk Assessment (RA) domain for defense contractors. Paul Netopski and Roz the Rulemaker walk through the three RA practices from NIST SP 800-171 (3.11.1, 3.11.2, 3.11.3), show how to build and use a Risk</itunes:subtitle><itunes:summary>A practical how-to episode on the CMMC 2.0 Level 2 Risk Assessment (RA) domain for defense contractors. Paul Netopski and Roz the Rulemaker walk through the three RA practices from NIST SP 800-171 (3.11.1, 3.11.2, 3.11.3), show how to build and use a Risk Management Policy aligned to NIST and ISO 31000, and connect risk assessment to real-world threats, third-party risks, business risk appetite, and change management. The hosts reference prior episodes on Configuration/Change Management and other domains to help contractors integrate risk into everyday decisions about people, places, and technology in CUI scope.</itunes:summary><itunes:explicit>false</itunes:explicit><itunes:duration>00:22:35</itunes:duration><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/uZE5qQb-8_EzqLIUrFmOV.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Securing Access Unlocking Personnel Screening]]></title><description><![CDATA[Explore the critical personnel security requirements within NIST SP800-171 and CMMC 2.0 Level 2 standards. Learn practical processes for screening, onboarding, and access approvals, and uncover the nuances between standard employment screening and federal background investigations to safeguard Controlled Unclassified Information.]]></description><link>https://cmmc-elysian.jellypod.com/episodes/7a988e13-9707-48c4-adad-7f039e068553</link><guid isPermaLink="false">7a988e13-9707-48c4-adad-7f039e068553</guid><pubDate>Wed, 28 Jan 2026 23:14:05 GMT</pubDate><enclosure url="https://op3.dev/e,pg=a615cc29-4f63-4949-a363-2825116c8d1f/auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/7a988e13-9707-48c4-adad-7f039e068553/audio.mp3" length="0" type="audio/mpeg"/><podcast:generator uri="https://www.jellypod.com"></podcast:generator><podcast:episode>32</podcast:episode><podcast:transcript url="https://auth.jellypod.ai/storage/v1/object/public/Podcasts/7a988e13-9707-48c4-adad-7f039e068553/captions_1769642024.srt" type="application/x-subrip" language="en" rel="captions"></podcast:transcript><itunes:author>Jellypod</itunes:author><itunes:subtitle>Explore the critical personnel security requirements within NIST SP800-171 and CMMC 2.0 Level 2 standards. Learn practical processes for screening, onboarding, and access approvals, and uncover the nuances between standard employment screening and federal</itunes:subtitle><itunes:summary>Explore the critical personnel security requirements within NIST SP800-171 and CMMC 2.0 Level 2 standards. Learn practical processes for screening, onboarding, and access approvals, and uncover the nuances between standard employment screening and federal background investigations to safeguard Controlled Unclassified Information.</itunes:summary><itunes:explicit>false</itunes:explicit><itunes:duration>00:11:40</itunes:duration><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/uZE5qQb-8_EzqLIUrFmOV.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Lockdown Success Physical Security in CMMC]]></title><description><![CDATA[Dive into essential physical security controls within CMMC 2.0, from access management to safeguarding support infrastructure. Learn real-world lessons from defense contractors who strengthened facility security and avoided common pitfalls.]]></description><link>https://cmmc-elysian.jellypod.com/episodes/0b1797bc-1db9-41cb-b525-42ebe1a877d9</link><guid isPermaLink="false">0b1797bc-1db9-41cb-b525-42ebe1a877d9</guid><pubDate>Tue, 20 Jan 2026 12:33:57 GMT</pubDate><enclosure url="https://op3.dev/e,pg=a615cc29-4f63-4949-a363-2825116c8d1f/auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/0b1797bc-1db9-41cb-b525-42ebe1a877d9/audio.mp3" length="0" type="audio/mpeg"/><podcast:generator uri="https://www.jellypod.com"></podcast:generator><podcast:episode>31</podcast:episode><podcast:transcript url="https://auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/0b1797bc-1db9-41cb-b525-42ebe1a877d9/captions_1768912354.srt" type="application/x-subrip" language="en" rel="captions"></podcast:transcript><itunes:author>Jellypod</itunes:author><itunes:subtitle>Dive into essential physical security controls within CMMC 2.0, from access management to safeguarding support infrastructure. Learn real-world lessons from defense contractors who strengthened facility security and avoided common pitfalls.</itunes:subtitle><itunes:summary>Dive into essential physical security controls within CMMC 2.0, from access management to safeguarding support infrastructure. Learn real-world lessons from defense contractors who strengthened facility security and avoided common pitfalls.</itunes:summary><itunes:explicit>false</itunes:explicit><itunes:duration>00:14:42</itunes:duration><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/uZE5qQb-8_EzqLIUrFmOV.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Mastering Media Security for CMMC Success]]></title><description><![CDATA[Explore key strategies for protecting Controlled Unclassified Information across physical and digital media. Learn practical approaches to handling, marking, encryption, and auditing that ensure compliance and safeguard your organization.]]></description><link>https://cmmc-elysian.jellypod.com/episodes/2d90d5a8-6c20-499a-a4b8-1816705a4523</link><guid isPermaLink="false">2d90d5a8-6c20-499a-a4b8-1816705a4523</guid><pubDate>Tue, 13 Jan 2026 20:13:00 GMT</pubDate><enclosure url="https://op3.dev/e,pg=a615cc29-4f63-4949-a363-2825116c8d1f/auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/2d90d5a8-6c20-499a-a4b8-1816705a4523/audio.mp3" length="0" type="audio/mpeg"/><podcast:generator uri="https://www.jellypod.com"></podcast:generator><podcast:episode>30</podcast:episode><podcast:transcript url="https://auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/2d90d5a8-6c20-499a-a4b8-1816705a4523/captions_1768335127.srt" type="application/x-subrip" language="en" rel="captions"></podcast:transcript><itunes:author>Jellypod</itunes:author><itunes:subtitle>Explore key strategies for protecting Controlled Unclassified Information across physical and digital media. Learn practical approaches to handling, marking, encryption, and auditing that ensure compliance and safeguard your organization.</itunes:subtitle><itunes:summary>Explore key strategies for protecting Controlled Unclassified Information across physical and digital media. Learn practical approaches to handling, marking, encryption, and auditing that ensure compliance and safeguard your organization.</itunes:summary><itunes:explicit>false</itunes:explicit><itunes:duration>00:12:24</itunes:duration><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/uZE5qQb-8_EzqLIUrFmOV.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Understanding Covered Defense Information in Defense Contracting]]></title><description><![CDATA[This episode guides listeners through key aspects of Covered Defense Information (CDI), from core definitions and marking requirements to contract data rights and procurement compliance. Hosts Eric, Paul, and Roz break down regulations, risks, and real-world examples to help users, product owners, and procurement staff safeguard sensitive information effectively.]]></description><link>https://cmmc-elysian.jellypod.com/episodes/edfa6c73-f06b-4285-ba1a-0922d62ba8f5</link><guid isPermaLink="false">edfa6c73-f06b-4285-ba1a-0922d62ba8f5</guid><pubDate>Mon, 05 Jan 2026 16:57:44 GMT</pubDate><enclosure url="https://op3.dev/e,pg=a615cc29-4f63-4949-a363-2825116c8d1f/auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/edfa6c73-f06b-4285-ba1a-0922d62ba8f5/audio.mp3" length="0" type="audio/mpeg"/><podcast:generator uri="https://www.jellypod.com"></podcast:generator><podcast:episode>29</podcast:episode><podcast:transcript url="https://auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/edfa6c73-f06b-4285-ba1a-0922d62ba8f5/captions_1767632146.srt" type="application/x-subrip" language="en" rel="captions"></podcast:transcript><itunes:author>Jellypod</itunes:author><itunes:subtitle>This episode guides listeners through key aspects of Covered Defense Information (CDI), from core definitions and marking requirements to contract data rights and procurement compliance. Hosts Eric, Paul, and Roz break down regulations, risks, and real-wo</itunes:subtitle><itunes:summary>This episode guides listeners through key aspects of Covered Defense Information (CDI), from core definitions and marking requirements to contract data rights and procurement compliance. Hosts Eric, Paul, and Roz break down regulations, risks, and real-world examples to help users, product owners, and procurement staff safeguard sensitive information effectively.</itunes:summary><itunes:explicit>false</itunes:explicit><itunes:duration>00:13:08</itunes:duration><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/uZE5qQb-8_EzqLIUrFmOV.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Mastering the Maintenance "MA" Family for CMMC Level 2]]></title><description><![CDATA[Join Eric, Paul, and Roz as they break down the CMMC Level 2 Maintenance (MA) family: what each control requires, implementation strategies, and special considerations when working with Managed Service Providers. Discover how MA controls intersect with other CMMC families, and how third-party maintenance impacts your compliance journey.]]></description><link>https://cmmc-elysian.jellypod.com/episodes/60beb8bc-c403-46e5-bedf-2b4b3827745e</link><guid isPermaLink="false">60beb8bc-c403-46e5-bedf-2b4b3827745e</guid><pubDate>Tue, 23 Dec 2025 15:38:11 GMT</pubDate><enclosure url="https://op3.dev/e,pg=a615cc29-4f63-4949-a363-2825116c8d1f/auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/60beb8bc-c403-46e5-bedf-2b4b3827745e/audio.mp3" length="0" type="audio/mpeg"/><podcast:generator uri="https://www.jellypod.com"></podcast:generator><podcast:episode>28</podcast:episode><podcast:transcript url="https://auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/60beb8bc-c403-46e5-bedf-2b4b3827745e/captions_1766504197.srt" type="application/x-subrip" language="en" rel="captions"></podcast:transcript><itunes:author>Jellypod</itunes:author><itunes:subtitle>Join Eric, Paul, and Roz as they break down the CMMC Level 2 Maintenance (MA) family: what each control requires, implementation strategies, and special considerations when working with Managed Service Providers. Discover how MA controls intersect with ot</itunes:subtitle><itunes:summary>Join Eric, Paul, and Roz as they break down the CMMC Level 2 Maintenance (MA) family: what each control requires, implementation strategies, and special considerations when working with Managed Service Providers. Discover how MA controls intersect with other CMMC families, and how third-party maintenance impacts your compliance journey.</itunes:summary><itunes:explicit>false</itunes:explicit><itunes:duration>00:09:32</itunes:duration><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/uZE5qQb-8_EzqLIUrFmOV.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[False Claims Act and the Cybersecurity Compliance Trap]]></title><description><![CDATA[Dive deep into the False Claims Act, the Civil Cyber-Fraud Initiative, and how lapses in cybersecurity compliance with DFARS and NIST SP 800-171 can lead to hefty fines. Our hosts unpack how qui tam whistleblowers bring these cases to light by exploring high-profile settlements, revealing the potential for severe financial and reputational fallout across the defense contracting world. None of these cases have involved our clients, but the lessons are critical for everyone navigating cybersecurity compliance.]]></description><link>https://cmmc-elysian.jellypod.com/episodes/62fd8251-698e-4de2-b93a-d6155e6d4c84</link><guid isPermaLink="false">62fd8251-698e-4de2-b93a-d6155e6d4c84</guid><pubDate>Mon, 15 Dec 2025 22:40:30 GMT</pubDate><enclosure url="https://op3.dev/e,pg=a615cc29-4f63-4949-a363-2825116c8d1f/auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/62fd8251-698e-4de2-b93a-d6155e6d4c84/audio.mp3" length="0" type="audio/mpeg"/><podcast:generator uri="https://www.jellypod.com"></podcast:generator><podcast:episode>27</podcast:episode><podcast:transcript url="https://auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/62fd8251-698e-4de2-b93a-d6155e6d4c84/captions_1765838346.srt" type="application/x-subrip" language="en" rel="captions"></podcast:transcript><itunes:author>Jellypod</itunes:author><itunes:subtitle>Dive deep into the False Claims Act, the Civil Cyber-Fraud Initiative, and how lapses in cybersecurity compliance with DFARS and NIST SP 800-171 can lead to hefty fines. Our hosts unpack how qui tam whistleblowers bring these cases to light by exploring h</itunes:subtitle><itunes:summary>Dive deep into the False Claims Act, the Civil Cyber-Fraud Initiative, and how lapses in cybersecurity compliance with DFARS and NIST SP 800-171 can lead to hefty fines. Our hosts unpack how qui tam whistleblowers bring these cases to light by exploring high-profile settlements, revealing the potential for severe financial and reputational fallout across the defense contracting world. None of these cases have involved our clients, but the lessons are critical for everyone navigating cybersecurity compliance.</itunes:summary><itunes:explicit>false</itunes:explicit><itunes:duration>00:11:25</itunes:duration><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/uZE5qQb-8_EzqLIUrFmOV.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[NIST Incident Response]]></title><description><![CDATA[Incident Response for NIST CSF 2.0, NIST SP800-171r2 and CMMC 2.13]]></description><link>https://cmmc-elysian.jellypod.com/episodes/15879154-666f-4d24-a147-57453d9e2b9c</link><guid isPermaLink="false">15879154-666f-4d24-a147-57453d9e2b9c</guid><pubDate>Mon, 08 Dec 2025 14:00:57 GMT</pubDate><enclosure url="https://op3.dev/e,pg=a615cc29-4f63-4949-a363-2825116c8d1f/auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/15879154-666f-4d24-a147-57453d9e2b9c/audio.mp3" length="0" type="audio/mpeg"/><podcast:generator uri="https://www.jellypod.com"></podcast:generator><podcast:episode>26</podcast:episode><podcast:transcript url="https://auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/15879154-666f-4d24-a147-57453d9e2b9c/captions_1765202384.srt" type="application/x-subrip" language="en" rel="captions"></podcast:transcript><itunes:author>Jellypod</itunes:author><itunes:subtitle>Incident Response for NIST CSF 2.0, NIST SP800-171r2 and CMMC 2.13</itunes:subtitle><itunes:summary>Incident Response for NIST CSF 2.0, NIST SP800-171r2 and CMMC 2.13</itunes:summary><itunes:explicit>false</itunes:explicit><itunes:duration>00:15:57</itunes:duration><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/uZE5qQb-8_EzqLIUrFmOV.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Training and Awareness Essentials for NIST SP800-171 Controls]]></title><description><![CDATA[Explore how awareness and training align with NIST SP800-171 security controls. We break down each control, connect them to specific CDSE course catalog options, and discuss assessment objectives crucial for defense contractors and cybersecurity teams.]]></description><link>https://cmmc-elysian.jellypod.com/episodes/185636c6-3508-4634-b263-2c52277b1518</link><guid isPermaLink="false">185636c6-3508-4634-b263-2c52277b1518</guid><pubDate>Mon, 01 Dec 2025 22:39:00 GMT</pubDate><enclosure url="https://op3.dev/e,pg=a615cc29-4f63-4949-a363-2825116c8d1f/auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/185636c6-3508-4634-b263-2c52277b1518/audio.mp3" length="0" type="audio/mpeg"/><podcast:generator uri="https://www.jellypod.com"></podcast:generator><podcast:episode>25</podcast:episode><podcast:transcript url="https://auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/185636c6-3508-4634-b263-2c52277b1518/captions_1764628627.srt" type="application/x-subrip" language="en" rel="captions"></podcast:transcript><itunes:author>Jellypod</itunes:author><itunes:subtitle>Explore how awareness and training align with NIST SP800-171 security controls. We break down each control, connect them to specific CDSE course catalog options, and discuss assessment objectives crucial for defense contractors and cybersecurity teams.</itunes:subtitle><itunes:summary>Explore how awareness and training align with NIST SP800-171 security controls. We break down each control, connect them to specific CDSE course catalog options, and discuss assessment objectives crucial for defense contractors and cybersecurity teams.</itunes:summary><itunes:explicit>false</itunes:explicit><itunes:duration>00:11:38</itunes:duration><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/uZE5qQb-8_EzqLIUrFmOV.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Mastering NIST SP 800-171 Audit and Accountability (AU) Controls]]></title><description><![CDATA[Explore the Audit and Accountability (AU) domain of NIST SP 800-171 with actionable strategies for compliance in defense contracting. Dive into the essentials of system audit logs, open-source accountability tools, and best practices for working with MSSPs. Learn how to create a robust monitoring program to detect and respond to unauthorized activity while meeting regulatory demands.]]></description><link>https://cmmc-elysian.jellypod.com/episodes/48961ee6-2830-4eb2-8125-818b60f4c6f6</link><guid isPermaLink="false">48961ee6-2830-4eb2-8125-818b60f4c6f6</guid><pubDate>Mon, 01 Dec 2025 22:34:53 GMT</pubDate><enclosure url="https://op3.dev/e,pg=a615cc29-4f63-4949-a363-2825116c8d1f/auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/48961ee6-2830-4eb2-8125-818b60f4c6f6/audio.mp3" length="0" type="audio/mpeg"/><podcast:generator uri="https://www.jellypod.com"></podcast:generator><podcast:episode>24</podcast:episode><podcast:transcript url="https://auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/48961ee6-2830-4eb2-8125-818b60f4c6f6/captions_1764628409.srt" type="application/x-subrip" language="en" rel="captions"></podcast:transcript><itunes:author>Jellypod</itunes:author><itunes:subtitle>Explore the Audit and Accountability (AU) domain of NIST SP 800-171 with actionable strategies for compliance in defense contracting. Dive into the essentials of system audit logs, open-source accountability tools, and best practices for working with MSSP</itunes:subtitle><itunes:summary>Explore the Audit and Accountability (AU) domain of NIST SP 800-171 with actionable strategies for compliance in defense contracting. Dive into the essentials of system audit logs, open-source accountability tools, and best practices for working with MSSPs. Learn how to create a robust monitoring program to detect and respond to unauthorized activity while meeting regulatory demands.</itunes:summary><itunes:explicit>false</itunes:explicit><itunes:duration>00:12:35</itunes:duration><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/uZE5qQb-8_EzqLIUrFmOV.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[When Is MFA Really Required? Navigating CMMC, NIST, and Kerberos in Practice]]></title><description><![CDATA[Eric, Paul, and Roz break down one of the most debated aspects of CMMC 2.0 compliance: when exactly multifactor authentication must be enforced for users and administrators. The team references NIST SP800-171, SP800-53, and practical deployment scenarios—exploring the nuanced requirements around MFA, Kerberos, and different types of system access. Real-world examples and lessons learned bring much-needed clarity to a common challenge in identification and authentication.]]></description><link>https://cmmc-elysian.jellypod.com/episodes/4fdb87fe-a167-4a14-8c7e-51d1809b230d</link><guid isPermaLink="false">4fdb87fe-a167-4a14-8c7e-51d1809b230d</guid><pubDate>Mon, 01 Dec 2025 14:39:46 GMT</pubDate><enclosure url="https://op3.dev/e,pg=a615cc29-4f63-4949-a363-2825116c8d1f/auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/4fdb87fe-a167-4a14-8c7e-51d1809b230d/audio.mp3" length="0" type="audio/mpeg"/><podcast:generator uri="https://www.jellypod.com"></podcast:generator><podcast:episode>23</podcast:episode><podcast:transcript url="https://auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/4fdb87fe-a167-4a14-8c7e-51d1809b230d/captions_1764599882.srt" type="application/x-subrip" language="en" rel="captions"></podcast:transcript><itunes:author>Jellypod</itunes:author><itunes:subtitle>Eric, Paul, and Roz break down one of the most debated aspects of CMMC 2.0 compliance: when exactly multifactor authentication must be enforced for users and administrators. The team references NIST SP800-171, SP800-53, and practical deployment scenarios—</itunes:subtitle><itunes:summary>Eric, Paul, and Roz break down one of the most debated aspects of CMMC 2.0 compliance: when exactly multifactor authentication must be enforced for users and administrators. The team references NIST SP800-171, SP800-53, and practical deployment scenarios—exploring the nuanced requirements around MFA, Kerberos, and different types of system access. Real-world examples and lessons learned bring much-needed clarity to a common challenge in identification and authentication.</itunes:summary><itunes:explicit>false</itunes:explicit><itunes:duration>00:13:36</itunes:duration><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/uZE5qQb-8_EzqLIUrFmOV.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Configuration Management Essentials for NIST SP800-171]]></title><description><![CDATA[Dive deep into the fundamentals of configuration management for NIST SP800-171 compliance. This episode covers why a Configuration Management Plan matters, explores policy requirements, and examines baseline examples for applications, firmware, hardware, and operating systems.]]></description><link>https://cmmc-elysian.jellypod.com/episodes/3370c3f6-7d3f-4123-9d7d-5ca01029c450</link><guid isPermaLink="false">3370c3f6-7d3f-4123-9d7d-5ca01029c450</guid><pubDate>Mon, 24 Nov 2025 14:11:28 GMT</pubDate><enclosure url="https://op3.dev/e,pg=a615cc29-4f63-4949-a363-2825116c8d1f/auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/3370c3f6-7d3f-4123-9d7d-5ca01029c450/audio.mp3" length="0" type="audio/mpeg"/><podcast:generator uri="https://www.jellypod.com"></podcast:generator><podcast:episode>22</podcast:episode><podcast:transcript url="https://auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/3370c3f6-7d3f-4123-9d7d-5ca01029c450/captions_1763993402.srt" type="application/x-subrip" language="en" rel="captions"></podcast:transcript><itunes:author>Jellypod</itunes:author><itunes:subtitle>Dive deep into the fundamentals of configuration management for NIST SP800-171 compliance. This episode covers why a Configuration Management Plan matters, explores policy requirements, and examines baseline examples for applications, firmware, hardware, </itunes:subtitle><itunes:summary>Dive deep into the fundamentals of configuration management for NIST SP800-171 compliance. This episode covers why a Configuration Management Plan matters, explores policy requirements, and examines baseline examples for applications, firmware, hardware, and operating systems.</itunes:summary><itunes:explicit>false</itunes:explicit><itunes:duration>00:13:51</itunes:duration><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/uZE5qQb-8_EzqLIUrFmOV.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[The Power of Acceptable Use Policies for CMMC Level 2]]></title><description><![CDATA[Explore how an Acceptable Use Policy (AUP) underpins compliance for CMMC Level 2. We'll break down key NIST SP800-171 requirements that users need to understand, and discuss how communicating policy expectations empowers organizations to enforce controls and drive accountability.]]></description><link>https://cmmc-elysian.jellypod.com/episodes/e93bae75-9d4f-4d0c-9af7-ddc4953eec56</link><guid isPermaLink="false">e93bae75-9d4f-4d0c-9af7-ddc4953eec56</guid><pubDate>Tue, 18 Nov 2025 12:55:43 GMT</pubDate><enclosure url="https://op3.dev/e,pg=a615cc29-4f63-4949-a363-2825116c8d1f/auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/e93bae75-9d4f-4d0c-9af7-ddc4953eec56/audio.mp3" length="0" type="audio/mpeg"/><podcast:generator uri="https://www.jellypod.com"></podcast:generator><podcast:episode>21</podcast:episode><podcast:transcript url="https://auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/e93bae75-9d4f-4d0c-9af7-ddc4953eec56/captions_1763470453.srt" type="application/x-subrip" language="en" rel="captions"></podcast:transcript><itunes:author>Jellypod</itunes:author><itunes:subtitle>Explore how an Acceptable Use Policy (AUP) underpins compliance for CMMC Level 2. We&apos;ll break down key NIST SP800-171 requirements that users need to understand, and discuss how communicating policy expectations empowers organizations to enforce controls </itunes:subtitle><itunes:summary>Explore how an Acceptable Use Policy (AUP) underpins compliance for CMMC Level 2. We&apos;ll break down key NIST SP800-171 requirements that users need to understand, and discuss how communicating policy expectations empowers organizations to enforce controls and drive accountability.</itunes:summary><itunes:explicit>false</itunes:explicit><itunes:duration>00:10:09</itunes:duration><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/uZE5qQb-8_EzqLIUrFmOV.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Eliminating the Line: Rethinking Basic and Derived Security Requirements in NIST SP 800-171 Revision 3]]></title><description><![CDATA[This episode unpacks the elimination of the basic and derived security requirement distinction in NIST SP 800-171 revision 3, the assessment methodologies surrounding them, and the practical effects on DoD contractors, especially primes managing supplier risk. Our hosts dive into how the structure of NIST SP 800-171 assessments has evolved, the rationale for the new approach, and what subcontractors and primes alike can expect under the updated rules.]]></description><link>https://cmmc-elysian.jellypod.com/episodes/4025bae3-8537-4a15-a374-4aa75b449aea</link><guid isPermaLink="false">4025bae3-8537-4a15-a374-4aa75b449aea</guid><pubDate>Fri, 14 Nov 2025 12:58:49 GMT</pubDate><enclosure url="https://op3.dev/e,pg=a615cc29-4f63-4949-a363-2825116c8d1f/auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/4025bae3-8537-4a15-a374-4aa75b449aea/cPdzC6BVFyU1ZMVFZ4c2x.mp3" length="0" type="audio/mpeg"/><podcast:generator uri="https://www.jellypod.com"></podcast:generator><podcast:episode>20</podcast:episode><podcast:transcript url="https://auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/4025bae3-8537-4a15-a374-4aa75b449aea/captions_1763125041.srt" type="application/x-subrip" language="en" rel="captions"></podcast:transcript><itunes:author>Jellypod</itunes:author><itunes:subtitle>This episode unpacks the elimination of the basic and derived security requirement distinction in NIST SP 800-171 revision 3, the assessment methodologies surrounding them, and the practical effects on DoD contractors, especially primes managing supplier </itunes:subtitle><itunes:summary>This episode unpacks the elimination of the basic and derived security requirement distinction in NIST SP 800-171 revision 3, the assessment methodologies surrounding them, and the practical effects on DoD contractors, especially primes managing supplier risk. Our hosts dive into how the structure of NIST SP 800-171 assessments has evolved, the rationale for the new approach, and what subcontractors and primes alike can expect under the updated rules.</itunes:summary><itunes:explicit>false</itunes:explicit><itunes:duration>00:10:40</itunes:duration><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/uZE5qQb-8_EzqLIUrFmOV.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[System Security Plan Templates Demystified]]></title><description><![CDATA[Explore the essentials of the NIST SP800-171 System Security Plan (SSP), the key requirements from NIST SP800-53r5, and recommended sections to create a plan that's truly fit for your organization. We'll break down what must be included, what can be added for clarity, and how to make your SSP a practical tool for security and compliance.]]></description><link>https://cmmc-elysian.jellypod.com/episodes/724b5fd0-f062-43d4-981f-66658d84eded</link><guid isPermaLink="false">724b5fd0-f062-43d4-981f-66658d84eded</guid><pubDate>Mon, 20 Oct 2025 13:00:49 GMT</pubDate><enclosure url="https://op3.dev/e,pg=a615cc29-4f63-4949-a363-2825116c8d1f/auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/724b5fd0-f062-43d4-981f-66658d84eded/3051ff5b.mp3?" length="0" type="audio/mpeg"/><podcast:generator uri="https://www.jellypod.com"></podcast:generator><podcast:episode>19</podcast:episode><podcast:transcript url="https://auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/724b5fd0-f062-43d4-981f-66658d84eded/captions_1760965211.srt" type="application/x-subrip" language="en" rel="captions"></podcast:transcript><itunes:author>Jellypod</itunes:author><itunes:subtitle>Explore the essentials of the NIST SP800-171 System Security Plan (SSP), the key requirements from NIST SP800-53r5, and recommended sections to create a plan that&apos;s truly fit for your organization. We&apos;ll break down what must be included, what can be added</itunes:subtitle><itunes:summary>Explore the essentials of the NIST SP800-171 System Security Plan (SSP), the key requirements from NIST SP800-53r5, and recommended sections to create a plan that&apos;s truly fit for your organization. We&apos;ll break down what must be included, what can be added for clarity, and how to make your SSP a practical tool for security and compliance.</itunes:summary><itunes:explicit>false</itunes:explicit><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/uZE5qQb-8_EzqLIUrFmOV.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Building a Bulletproof Incident Response Plan]]></title><description><![CDATA[This episode dives into the essentials of incident response plans required by NIST standards, explores best practices and testing, and highlights how to leverage providers like Vertek and your MSSP for superior readiness. Our hosts break down actionable steps, useful examples, and real-world MSSP integration strategies, making your compliance journey clear and manageable.]]></description><link>https://cmmc-elysian.jellypod.com/episodes/15751fc9-7023-4b6f-a1a1-6f4335d76857</link><guid isPermaLink="false">15751fc9-7023-4b6f-a1a1-6f4335d76857</guid><pubDate>Wed, 15 Oct 2025 16:42:52 GMT</pubDate><enclosure url="https://op3.dev/e,pg=a615cc29-4f63-4949-a363-2825116c8d1f/auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/15751fc9-7023-4b6f-a1a1-6f4335d76857/1b086bc9.mp3?" length="0" type="audio/mpeg"/><podcast:generator uri="https://www.jellypod.com"></podcast:generator><podcast:episode>18</podcast:episode><podcast:transcript url="https://auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/15751fc9-7023-4b6f-a1a1-6f4335d76857/captions_1760546534.srt" type="application/x-subrip" language="en" rel="captions"></podcast:transcript><itunes:author>Jellypod</itunes:author><itunes:subtitle>This episode dives into the essentials of incident response plans required by NIST standards, explores best practices and testing, and highlights how to leverage providers like Vertek and your MSSP for superior readiness. Our hosts break down actionable s</itunes:subtitle><itunes:summary>This episode dives into the essentials of incident response plans required by NIST standards, explores best practices and testing, and highlights how to leverage providers like Vertek and your MSSP for superior readiness. Our hosts break down actionable steps, useful examples, and real-world MSSP integration strategies, making your compliance journey clear and manageable.</itunes:summary><itunes:explicit>false</itunes:explicit><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/uZE5qQb-8_EzqLIUrFmOV.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Real-World Cyber Incident Response Beyond the Tabletop]]></title><description><![CDATA[Explore how Bridgewater State University's Cyber Range revolutionizes cybersecurity training, making incident response testing more immersive than traditional tabletop exercises. Hear insights on simulating real attacks, following NIST guidance, and how organizations can use this environment for CMMC and real-world readiness.]]></description><link>https://cmmc-elysian.jellypod.com/episodes/7250303c-4891-4c5b-ae3c-623c188b4266</link><guid isPermaLink="false">7250303c-4891-4c5b-ae3c-623c188b4266</guid><pubDate>Wed, 15 Oct 2025 16:26:53 GMT</pubDate><enclosure url="https://op3.dev/e,pg=a615cc29-4f63-4949-a363-2825116c8d1f/auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/7250303c-4891-4c5b-ae3c-623c188b4266/e059f4e2.mp3?" length="0" type="audio/mpeg"/><podcast:generator uri="https://www.jellypod.com"></podcast:generator><podcast:episode>17</podcast:episode><podcast:transcript url="https://auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/7250303c-4891-4c5b-ae3c-623c188b4266/captions_1760545572.srt" type="application/x-subrip" language="en" rel="captions"></podcast:transcript><itunes:author>Jellypod</itunes:author><itunes:subtitle>Explore how Bridgewater State University&apos;s Cyber Range revolutionizes cybersecurity training, making incident response testing more immersive than traditional tabletop exercises. Hear insights on simulating real attacks, following NIST guidance, and how o</itunes:subtitle><itunes:summary>Explore how Bridgewater State University&apos;s Cyber Range revolutionizes cybersecurity training, making incident response testing more immersive than traditional tabletop exercises. Hear insights on simulating real attacks, following NIST guidance, and how organizations can use this environment for CMMC and real-world readiness.</itunes:summary><itunes:explicit>false</itunes:explicit><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/uZE5qQb-8_EzqLIUrFmOV.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Demystifying DoD Cloud Security: SRGs, STIGs, and CMMC Alignment]]></title><description><![CDATA[This episode unpacks how the DoD's cloud security requirements come together across SRGs, STIGs, and CMMC, clarifying regulatory foundations, Impact Levels, and the real-world implications for cloud service providers and mission owners. The hosts decode recent changes, practical responsibilities, and the intersection of CMMC with FedRAMP, NIST, and DFARS. Whether you’re a DoD contractor, a cloud service provider, or a compliance leader, get the plain-English guidance you need to understand the nuances of today’s cloud compliance landscape.]]></description><link>https://cmmc-elysian.jellypod.com/episodes/2d2ddaca-4cc4-4204-82ea-545bdd0bd98e</link><guid isPermaLink="false">2d2ddaca-4cc4-4204-82ea-545bdd0bd98e</guid><pubDate>Tue, 07 Oct 2025 12:35:59 GMT</pubDate><enclosure url="https://op3.dev/e,pg=a615cc29-4f63-4949-a363-2825116c8d1f/auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/2d2ddaca-4cc4-4204-82ea-545bdd0bd98e/41d3bdb9.mp3" length="0" type="audio/mpeg"/><podcast:generator uri="https://www.jellypod.com"></podcast:generator><podcast:episode>16</podcast:episode><itunes:author>Jellypod</itunes:author><itunes:subtitle>This episode unpacks how the DoD&apos;s cloud security requirements come together across SRGs, STIGs, and CMMC, clarifying regulatory foundations, Impact Levels, and the real-world implications for cloud service providers and mission owners. The hosts decode r</itunes:subtitle><itunes:summary>This episode unpacks how the DoD&apos;s cloud security requirements come together across SRGs, STIGs, and CMMC, clarifying regulatory foundations, Impact Levels, and the real-world implications for cloud service providers and mission owners. The hosts decode recent changes, practical responsibilities, and the intersection of CMMC with FedRAMP, NIST, and DFARS. Whether you’re a DoD contractor, a cloud service provider, or a compliance leader, get the plain-English guidance you need to understand the nuances of today’s cloud compliance landscape.</itunes:summary><itunes:explicit>false</itunes:explicit><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/uZE5qQb-8_EzqLIUrFmOV.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Deep Dive: NIST Risk Assessment & Prioritization Process]]></title><description><![CDATA[Join Eric, Ruby, Paul, and Roz as they break down the NIST IR 8286 series and SP 800-30 guidance for cybersecurity risk assessment. This episode explores how to set enterprise risk appetite, create and score risk scenarios (including threats and vulnerabilities), use business impact analysis for prioritization, and aggregate, monitor, and report risks for executive risk decisions. The team uses relatable examples and practical case studies to show how to turn risk analysis into real-world, risk-based decisions.]]></description><link>https://cmmc-elysian.jellypod.com/episodes/56d8611d-9a79-43f0-82e2-03e5c7447beb</link><guid isPermaLink="false">56d8611d-9a79-43f0-82e2-03e5c7447beb</guid><pubDate>Tue, 07 Oct 2025 12:24:18 GMT</pubDate><enclosure url="https://op3.dev/e,pg=a615cc29-4f63-4949-a363-2825116c8d1f/auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/56d8611d-9a79-43f0-82e2-03e5c7447beb/38cb1d7f.mp3" length="0" type="audio/mpeg"/><podcast:generator uri="https://www.jellypod.com"></podcast:generator><podcast:episode>15</podcast:episode><itunes:author>Jellypod</itunes:author><itunes:subtitle>Join Eric, Ruby, Paul, and Roz as they break down the NIST IR 8286 series and SP 800-30 guidance for cybersecurity risk assessment. This episode explores how to set enterprise risk appetite, create and score risk scenarios (including threats and vulnerabi</itunes:subtitle><itunes:summary>Join Eric, Ruby, Paul, and Roz as they break down the NIST IR 8286 series and SP 800-30 guidance for cybersecurity risk assessment. This episode explores how to set enterprise risk appetite, create and score risk scenarios (including threats and vulnerabilities), use business impact analysis for prioritization, and aggregate, monitor, and report risks for executive risk decisions. The team uses relatable examples and practical case studies to show how to turn risk analysis into real-world, risk-based decisions.</itunes:summary><itunes:explicit>false</itunes:explicit><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/uZE5qQb-8_EzqLIUrFmOV.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Supporting Documentation and Procedures for Access Control Compliance]]></title><description><![CDATA[This episode explores the essential supporting documents and general procedures needed for the Access Control Family under CMMC. Learn which records are vital, how to structure compliant procedures, and practical tips for streamlined documentation. Hear real-world insights and specific examples from seasoned practitioners and compliance experts.]]></description><link>https://cmmc-elysian.jellypod.com/episodes/efbf4342-863b-4e15-8bf4-99a39e68909a</link><guid isPermaLink="false">efbf4342-863b-4e15-8bf4-99a39e68909a</guid><pubDate>Mon, 06 Oct 2025 12:42:55 GMT</pubDate><enclosure url="https://op3.dev/e,pg=a615cc29-4f63-4949-a363-2825116c8d1f/auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/efbf4342-863b-4e15-8bf4-99a39e68909a/1795dcce.mp3" length="0" type="audio/mpeg"/><podcast:generator uri="https://www.jellypod.com"></podcast:generator><podcast:episode>14</podcast:episode><itunes:author>Jellypod</itunes:author><itunes:subtitle>This episode explores the essential supporting documents and general procedures needed for the Access Control Family under CMMC. Learn which records are vital, how to structure compliant procedures, and practical tips for streamlined documentation. Hear r</itunes:subtitle><itunes:summary>This episode explores the essential supporting documents and general procedures needed for the Access Control Family under CMMC. Learn which records are vital, how to structure compliant procedures, and practical tips for streamlined documentation. Hear real-world insights and specific examples from seasoned practitioners and compliance experts.</itunes:summary><itunes:explicit>false</itunes:explicit><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/uZE5qQb-8_EzqLIUrFmOV.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Aligning the AI Risk Management Framework with CUI Risk Assessment Requirements]]></title><description><![CDATA[This episode breaks down how the NIST AI Risk Management Framework (AI RMF 1.0) supports a robust, continual approach to AI risk assessment, with a special focus on how to meet NIST SP 800-171 rev 2 control 3.11.1 for assessing risk to CUI. We connect specific core functions of the AI RMF—Govern, Map, Measure, and Manage—to compliance requirements and practical periodic risk reviews in organizations running or deploying AI systems.]]></description><link>https://cmmc-elysian.jellypod.com/episodes/e2657e67-9ac5-41ae-a77b-b28cc8ea2143</link><guid isPermaLink="false">e2657e67-9ac5-41ae-a77b-b28cc8ea2143</guid><pubDate>Fri, 26 Sep 2025 14:42:25 GMT</pubDate><enclosure url="https://op3.dev/e,pg=a615cc29-4f63-4949-a363-2825116c8d1f/auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/e2657e67-9ac5-41ae-a77b-b28cc8ea2143/9361a25a.mp3" length="0" type="audio/mpeg"/><podcast:generator uri="https://www.jellypod.com"></podcast:generator><podcast:episode>13</podcast:episode><itunes:author>Jellypod</itunes:author><itunes:subtitle>This episode breaks down how the NIST AI Risk Management Framework (AI RMF 1.0) supports a robust, continual approach to AI risk assessment, with a special focus on how to meet NIST SP 800-171 rev 2 control 3.11.1 for assessing risk to CUI. We connect spe</itunes:subtitle><itunes:summary>This episode breaks down how the NIST AI Risk Management Framework (AI RMF 1.0) supports a robust, continual approach to AI risk assessment, with a special focus on how to meet NIST SP 800-171 rev 2 control 3.11.1 for assessing risk to CUI. We connect specific core functions of the AI RMF—Govern, Map, Measure, and Manage—to compliance requirements and practical periodic risk reviews in organizations running or deploying AI systems.</itunes:summary><itunes:explicit>false</itunes:explicit><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/uZE5qQb-8_EzqLIUrFmOV.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Incident Response Interlaced: DFARS 252.204-7012 and NIST SP800-171]]></title><description><![CDATA[Explore how incident response requirements from DFARS 252.204-7012 and NIST SP800-171 complement and amplify each other. Our experts dissect what each demands, how they mesh in practice, and what that means for defense contractors. This episode highlights actionable steps and noticeable pitfalls, with real-life examples from industry and government.]]></description><link>https://cmmc-elysian.jellypod.com/episodes/bc28b205-c3fa-4fdd-9aa4-1e0ad39d2b67</link><guid isPermaLink="false">bc28b205-c3fa-4fdd-9aa4-1e0ad39d2b67</guid><pubDate>Mon, 22 Sep 2025 11:45:50 GMT</pubDate><enclosure url="https://op3.dev/e,pg=a615cc29-4f63-4949-a363-2825116c8d1f/auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/bc28b205-c3fa-4fdd-9aa4-1e0ad39d2b67/c1d26722.mp3" length="0" type="audio/mpeg"/><podcast:generator uri="https://www.jellypod.com"></podcast:generator><podcast:episode>12</podcast:episode><itunes:author>Jellypod</itunes:author><itunes:subtitle>Explore how incident response requirements from DFARS 252.204-7012 and NIST SP800-171 complement and amplify each other. Our experts dissect what each demands, how they mesh in practice, and what that means for defense contractors. This episode highlights</itunes:subtitle><itunes:summary>Explore how incident response requirements from DFARS 252.204-7012 and NIST SP800-171 complement and amplify each other. Our experts dissect what each demands, how they mesh in practice, and what that means for defense contractors. This episode highlights actionable steps and noticeable pitfalls, with real-life examples from industry and government.</itunes:summary><itunes:explicit>false</itunes:explicit><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/uZE5qQb-8_EzqLIUrFmOV.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[CMMC Rollout Countdown and the Road to 2025]]></title><description><![CDATA[What does the final year before full CMMC implementation look like? In this episode, we explore the definitive schedule, key requirements, and what defense contractors should expect as the November 10, 2025 effective date for DFARS 204.75 approaches.]]></description><link>https://cmmc-elysian.jellypod.com/episodes/a3862ba5-8f19-4d1a-bf4c-c3f5e54fcf7f</link><guid isPermaLink="false">a3862ba5-8f19-4d1a-bf4c-c3f5e54fcf7f</guid><pubDate>Fri, 19 Sep 2025 15:03:18 GMT</pubDate><enclosure url="https://op3.dev/e,pg=a615cc29-4f63-4949-a363-2825116c8d1f/auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/a3862ba5-8f19-4d1a-bf4c-c3f5e54fcf7f/cfeb80a3.mp3" length="0" type="audio/mpeg"/><podcast:generator uri="https://www.jellypod.com"></podcast:generator><podcast:episode>11</podcast:episode><itunes:author>Jellypod</itunes:author><itunes:subtitle>What does the final year before full CMMC implementation look like? In this episode, we explore the definitive schedule, key requirements, and what defense contractors should expect as the November 10, 2025 effective date for DFARS 204.75 approaches.</itunes:subtitle><itunes:summary>What does the final year before full CMMC implementation look like? In this episode, we explore the definitive schedule, key requirements, and what defense contractors should expect as the November 10, 2025 effective date for DFARS 204.75 approaches.</itunes:summary><itunes:explicit>false</itunes:explicit><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/uZE5qQb-8_EzqLIUrFmOV.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[How Long and How Much? Realistic Timelines and Costs for CMMC & NIST SP 800-171 Compliance]]></title><description><![CDATA[This episode unpacks the complete journey to CMMC/NIST SP 800-171 compliance, breaking down the phases, expected timelines, and real-world costs using authoritative federal guidance and hands-on field experience. Drawing from key federal regulations and the Critical Prism Defense whitepaper, we deliver facts and planning models for organizations at any starting point.]]></description><link>https://cmmc-elysian.jellypod.com/episodes/4748c813-420e-45fd-9039-b08877adecde</link><guid isPermaLink="false">4748c813-420e-45fd-9039-b08877adecde</guid><pubDate>Mon, 08 Sep 2025 21:50:44 GMT</pubDate><enclosure url="https://op3.dev/e,pg=a615cc29-4f63-4949-a363-2825116c8d1f/auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/4748c813-420e-45fd-9039-b08877adecde/347351a1.mp3" length="0" type="audio/mpeg"/><podcast:generator uri="https://www.jellypod.com"></podcast:generator><podcast:episode>10</podcast:episode><itunes:author>Jellypod</itunes:author><itunes:subtitle>This episode unpacks the complete journey to CMMC/NIST SP 800-171 compliance, breaking down the phases, expected timelines, and real-world costs using authoritative federal guidance and hands-on field experience. Drawing from key federal regulations and t</itunes:subtitle><itunes:summary>This episode unpacks the complete journey to CMMC/NIST SP 800-171 compliance, breaking down the phases, expected timelines, and real-world costs using authoritative federal guidance and hands-on field experience. Drawing from key federal regulations and the Critical Prism Defense whitepaper, we deliver facts and planning models for organizations at any starting point.</itunes:summary><itunes:explicit>false</itunes:explicit><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/uZE5qQb-8_EzqLIUrFmOV.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[What Happens Next for 48 CFR 204.75: Timeline to CMMC Enforcement]]></title><description><![CDATA[The team unpacks the next phases now that 48 CFR Subpart 204.75 has cleared OIRA review, mapping out what’s ahead for activation and enforcement—including the practical timeline to a live, enforceable CMMC rule. Special focus is given to rulemaking milestones, contract impacts, and how the DoD’s phase-in policy shapes when CMMC compliance becomes required for defense contractors.]]></description><link>https://cmmc-elysian.jellypod.com/episodes/6fef57cb-0ab0-4741-af71-ab796db08567</link><guid isPermaLink="false">6fef57cb-0ab0-4741-af71-ab796db08567</guid><pubDate>Mon, 08 Sep 2025 17:49:19 GMT</pubDate><enclosure url="https://op3.dev/e,pg=a615cc29-4f63-4949-a363-2825116c8d1f/auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/6fef57cb-0ab0-4741-af71-ab796db08567/8eeaa746.mp3" length="0" type="audio/mpeg"/><podcast:generator uri="https://www.jellypod.com"></podcast:generator><podcast:episode>9</podcast:episode><podcast:transcript url="https://auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/6fef57cb-0ab0-4741-af71-ab796db08567/captions_1757353715.srt" type="application/x-subrip" language="en" rel="captions"></podcast:transcript><itunes:author>Jellypod</itunes:author><itunes:subtitle>The team unpacks the next phases now that 48 CFR Subpart 204.75 has cleared OIRA review, mapping out what’s ahead for activation and enforcement—including the practical timeline to a live, enforceable CMMC rule. Special focus is given to rulemaking milest</itunes:subtitle><itunes:summary>The team unpacks the next phases now that 48 CFR Subpart 204.75 has cleared OIRA review, mapping out what’s ahead for activation and enforcement—including the practical timeline to a live, enforceable CMMC rule. Special focus is given to rulemaking milestones, contract impacts, and how the DoD’s phase-in policy shapes when CMMC compliance becomes required for defense contractors.</itunes:summary><itunes:explicit>false</itunes:explicit><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/uZE5qQb-8_EzqLIUrFmOV.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Self-Assess or Certify: The New DoD CUI Assessment Split]]></title><description><![CDATA[This episode breaks down the Department of Defense’s recent decision on when contractors can self-assess for CMMC Level 2, and when a third-party assessment is required. The hosts clarify how the NARA and DoD CUI registries impact assessment requirements, and explain why ACAT categories are no longer the dividing line.]]></description><link>https://cmmc-elysian.jellypod.com/episodes/b202ddad-b027-4dd7-a3cb-d9afd11f6e8c</link><guid isPermaLink="false">b202ddad-b027-4dd7-a3cb-d9afd11f6e8c</guid><pubDate>Fri, 29 Aug 2025 13:30:42 GMT</pubDate><enclosure url="https://op3.dev/e,pg=a615cc29-4f63-4949-a363-2825116c8d1f/auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/b202ddad-b027-4dd7-a3cb-d9afd11f6e8c/e87736c4.mp3" length="0" type="audio/mpeg"/><podcast:generator uri="https://www.jellypod.com"></podcast:generator><podcast:episode>8</podcast:episode><podcast:transcript url="https://auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/b202ddad-b027-4dd7-a3cb-d9afd11f6e8c/captions_1756474200.srt" type="application/x-subrip" language="en" rel="captions"></podcast:transcript><itunes:author>Jellypod</itunes:author><itunes:subtitle>This episode breaks down the Department of Defense’s recent decision on when contractors can self-assess for CMMC Level 2, and when a third-party assessment is required. The hosts clarify how the NARA and DoD CUI registries impact assessment requirements,</itunes:subtitle><itunes:summary>This episode breaks down the Department of Defense’s recent decision on when contractors can self-assess for CMMC Level 2, and when a third-party assessment is required. The hosts clarify how the NARA and DoD CUI registries impact assessment requirements, and explain why ACAT categories are no longer the dividing line.</itunes:summary><itunes:explicit>false</itunes:explicit><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/uZE5qQb-8_EzqLIUrFmOV.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Unpacking MSSP Challenges in CMMC Environments]]></title><description><![CDATA[Eric, Ruby, Paul, and Roz explore the unique CMMC compliance complexities that arise when a Managed Security Service Provider (MSSP) delivers a Security Operations Center (SOC), SIEM, and SOAR—especially when CUI and privileged access are in play. Using real examples and asset categories from the latest CMMC scoping guides, the hosts dig into scoping, asset classification, and responsibilities.]]></description><link>https://cmmc-elysian.jellypod.com/episodes/7e20591b-f580-4df6-a7b5-564deed106fa</link><guid isPermaLink="false">7e20591b-f580-4df6-a7b5-564deed106fa</guid><pubDate>Fri, 29 Aug 2025 12:23:38 GMT</pubDate><enclosure url="https://op3.dev/e,pg=a615cc29-4f63-4949-a363-2825116c8d1f/auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/7e20591b-f580-4df6-a7b5-564deed106fa/3ab10557.mp3" length="0" type="audio/mpeg"/><podcast:generator uri="https://www.jellypod.com"></podcast:generator><podcast:episode>7</podcast:episode><podcast:transcript url="https://auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/7e20591b-f580-4df6-a7b5-564deed106fa/captions_1756470171.srt" type="application/x-subrip" language="en" rel="captions"></podcast:transcript><itunes:author>Jellypod</itunes:author><itunes:subtitle>Eric, Ruby, Paul, and Roz explore the unique CMMC compliance complexities that arise when a Managed Security Service Provider (MSSP) delivers a Security Operations Center (SOC), SIEM, and SOAR—especially when CUI and privileged access are in play. Using r</itunes:subtitle><itunes:summary>Eric, Ruby, Paul, and Roz explore the unique CMMC compliance complexities that arise when a Managed Security Service Provider (MSSP) delivers a Security Operations Center (SOC), SIEM, and SOAR—especially when CUI and privileged access are in play. Using real examples and asset categories from the latest CMMC scoping guides, the hosts dig into scoping, asset classification, and responsibilities.</itunes:summary><itunes:explicit>false</itunes:explicit><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/uZE5qQb-8_EzqLIUrFmOV.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[CMMC Scoping guides]]></title><description><![CDATA[Review of CMMC Scoping guides.  In this episode we dive into the CMMC L2 Scoping guide and provide a summary of the categories and details within.]]></description><link>https://cmmc-elysian.jellypod.com/episodes/6ccc704a-b25c-4cc6-b4ad-f66b9016e514</link><guid isPermaLink="false">6ccc704a-b25c-4cc6-b4ad-f66b9016e514</guid><pubDate>Mon, 18 Aug 2025 21:26:55 GMT</pubDate><enclosure url="https://op3.dev/e,pg=a615cc29-4f63-4949-a363-2825116c8d1f/auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/6ccc704a-b25c-4cc6-b4ad-f66b9016e514/53f3d697.mp3" length="0" type="audio/mpeg"/><podcast:generator uri="https://www.jellypod.com"></podcast:generator><podcast:episode>6</podcast:episode><podcast:transcript url="https://auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/6ccc704a-b25c-4cc6-b4ad-f66b9016e514/captions_1755552375.srt" type="application/x-subrip" language="en" rel="captions"></podcast:transcript><itunes:author>Jellypod</itunes:author><itunes:subtitle>Review of CMMC Scoping guides.  In this episode we dive into the CMMC L2 Scoping guide and provide a summary of the categories and details within.</itunes:subtitle><itunes:summary>Review of CMMC Scoping guides.  In this episode we dive into the CMMC L2 Scoping guide and provide a summary of the categories and details within.</itunes:summary><itunes:explicit>false</itunes:explicit><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/uZE5qQb-8_EzqLIUrFmOV.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Risk Assessments and Meeting NIST SP 800-171 Control 3.11.1]]></title><description><![CDATA[Dive into how risk assessments underpin NIST SP 800-171 compliance, with a focus on control 3.11.1. Our expert hosts break down what assessors look for, walk through real-world approaches, and share lessons learned from the field.]]></description><link>https://cmmc-elysian.jellypod.com/episodes/57a887a9-9fe2-4131-8af0-51f9cca12cd5</link><guid isPermaLink="false">57a887a9-9fe2-4131-8af0-51f9cca12cd5</guid><pubDate>Thu, 14 Aug 2025 13:50:14 GMT</pubDate><enclosure url="https://op3.dev/e,pg=a615cc29-4f63-4949-a363-2825116c8d1f/auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/57a887a9-9fe2-4131-8af0-51f9cca12cd5/b153ee0e.mp3" length="0" type="audio/mpeg"/><podcast:generator uri="https://www.jellypod.com"></podcast:generator><podcast:episode>5</podcast:episode><podcast:transcript url="https://auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/57a887a9-9fe2-4131-8af0-51f9cca12cd5/captions_1755179366.srt" type="application/x-subrip" language="en" rel="captions"></podcast:transcript><itunes:author>Jellypod</itunes:author><itunes:subtitle>Dive into how risk assessments underpin NIST SP 800-171 compliance, with a focus on control 3.11.1. Our expert hosts break down what assessors look for, walk through real-world approaches, and share lessons learned from the field.</itunes:subtitle><itunes:summary>Dive into how risk assessments underpin NIST SP 800-171 compliance, with a focus on control 3.11.1. Our expert hosts break down what assessors look for, walk through real-world approaches, and share lessons learned from the field.</itunes:summary><itunes:explicit>false</itunes:explicit><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/uZE5qQb-8_EzqLIUrFmOV.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Unlocking Federal Rulemaking and CMMC Implementation]]></title><description><![CDATA[Dive into the federal rulemaking process and how it shapes cybersecurity requirements for defense contractors. This episode explores how the 32 CFR 170 rule went from concept to implementation, and previews how the forthcoming 48 CFR 204 changes may follow that path. Hear practical insights relevant for anyone in federal compliance, cybersecurity, and defense acquisition.]]></description><link>https://cmmc-elysian.jellypod.com/episodes/16b141f1-7a14-4f6b-8b49-14e80d5032cf</link><guid isPermaLink="false">16b141f1-7a14-4f6b-8b49-14e80d5032cf</guid><pubDate>Fri, 25 Jul 2025 16:26:03 GMT</pubDate><enclosure url="https://op3.dev/e,pg=a615cc29-4f63-4949-a363-2825116c8d1f/auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/16b141f1-7a14-4f6b-8b49-14e80d5032cf/87039f14.mp3" length="0" type="audio/mpeg"/><podcast:generator uri="https://www.jellypod.com"></podcast:generator><podcast:episode>4</podcast:episode><podcast:transcript url="https://auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/16b141f1-7a14-4f6b-8b49-14e80d5032cf/captions_1753460717.srt" type="application/x-subrip" language="en" rel="captions"></podcast:transcript><itunes:author>Jellypod</itunes:author><itunes:subtitle>Dive into the federal rulemaking process and how it shapes cybersecurity requirements for defense contractors. This episode explores how the 32 CFR 170 rule went from concept to implementation, and previews how the forthcoming 48 CFR 204 changes may follo</itunes:subtitle><itunes:summary>Dive into the federal rulemaking process and how it shapes cybersecurity requirements for defense contractors. This episode explores how the 32 CFR 170 rule went from concept to implementation, and previews how the forthcoming 48 CFR 204 changes may follow that path. Hear practical insights relevant for anyone in federal compliance, cybersecurity, and defense acquisition.</itunes:summary><itunes:explicit>false</itunes:explicit><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/A%20professional%20podcast%20cover%20for%20a%20cybersecurity%20podcast%20titled%20&apos;CMMC%20Unlocked%20Inside%20the%20Cybersecu.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Continuous Compliance in Action]]></title><description><![CDATA[Explore how continuous CMMC monitoring transforms cybersecurity for defense contractors and compliance teams. Discover essential strategies, real-time tools, and practical steps for maintaining readiness in a dynamic threat landscape.]]></description><link>https://cmmc-elysian.jellypod.com/episodes/5d5a8339-ba7b-482d-b5e9-206576e9ed1a</link><guid isPermaLink="false">5d5a8339-ba7b-482d-b5e9-206576e9ed1a</guid><pubDate>Mon, 14 Jul 2025 16:35:53 GMT</pubDate><enclosure url="https://op3.dev/e,pg=a615cc29-4f63-4949-a363-2825116c8d1f/auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/5d5a8339-ba7b-482d-b5e9-206576e9ed1a/9c9d0238.mp3" length="0" type="audio/mpeg"/><podcast:generator uri="https://www.jellypod.com"></podcast:generator><podcast:episode>3</podcast:episode><podcast:transcript url="https://auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/5d5a8339-ba7b-482d-b5e9-206576e9ed1a/captions_1752510920.srt" type="application/x-subrip" language="en" rel="captions"></podcast:transcript><itunes:author>Jellypod</itunes:author><itunes:subtitle>Explore how continuous CMMC monitoring transforms cybersecurity for defense contractors and compliance teams. Discover essential strategies, real-time tools, and practical steps for maintaining readiness in a dynamic threat landscape.</itunes:subtitle><itunes:summary>Explore how continuous CMMC monitoring transforms cybersecurity for defense contractors and compliance teams. Discover essential strategies, real-time tools, and practical steps for maintaining readiness in a dynamic threat landscape.</itunes:summary><itunes:explicit>false</itunes:explicit><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/756d13c7-c5b6-4b2c-886a-0431211f6aca.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[CMMC 2.0 Rollout and Realities]]></title><description><![CDATA[Explore the phased rollout of CMMC 2.0, how the new rules impact defense contractors, and what it takes to maintain compliance. Our hosts break down the assessment process, key requirements, and real-world implications—plus, share surprising insights and practical examples from the field.]]></description><link>https://cmmc-elysian.jellypod.com/episodes/fa9efc77-8d7b-48cd-be7e-158ef02c70bb</link><guid isPermaLink="false">fa9efc77-8d7b-48cd-be7e-158ef02c70bb</guid><pubDate>Sun, 13 Jul 2025 12:50:29 GMT</pubDate><enclosure url="https://op3.dev/e,pg=a615cc29-4f63-4949-a363-2825116c8d1f/auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/fa9efc77-8d7b-48cd-be7e-158ef02c70bb/3799d1b8.mp3" length="0" type="audio/mpeg"/><podcast:generator uri="https://www.jellypod.com"></podcast:generator><podcast:episode>2</podcast:episode><podcast:transcript url="https://auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/fa9efc77-8d7b-48cd-be7e-158ef02c70bb/captions_1752410983.srt" type="application/x-subrip" language="en" rel="captions"></podcast:transcript><itunes:author>Jellypod</itunes:author><itunes:subtitle>Explore the phased rollout of CMMC 2.0, how the new rules impact defense contractors, and what it takes to maintain compliance. Our hosts break down the assessment process, key requirements, and real-world implications—plus, share surprising insights and </itunes:subtitle><itunes:summary>Explore the phased rollout of CMMC 2.0, how the new rules impact defense contractors, and what it takes to maintain compliance. Our hosts break down the assessment process, key requirements, and real-world implications—plus, share surprising insights and practical examples from the field.</itunes:summary><itunes:explicit>false</itunes:explicit><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/824a599d-8a1c-48fa-a5d9-1255df372f61.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Safeguarding CUI and Data Rights]]></title><description><![CDATA[This episode uncovers how organizations in the defense sector can identify, handle, and protect Controlled Unclassified Information (CUI), Covered Defense Information (CDI), and Controlled Technical Information (CTI). We examine contract requirements, marking guidance, and the latest resources to help contractors navigate CMMC compliance and data rights management.]]></description><link>https://cmmc-elysian.jellypod.com/episodes/1d7d9cd6-bc15-4fac-9a6c-8db925a4b97a</link><guid isPermaLink="false">1d7d9cd6-bc15-4fac-9a6c-8db925a4b97a</guid><pubDate>Sun, 13 Jul 2025 12:46:34 GMT</pubDate><enclosure url="https://op3.dev/e,pg=a615cc29-4f63-4949-a363-2825116c8d1f/auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/1d7d9cd6-bc15-4fac-9a6c-8db925a4b97a/1eb763e2.mp3" length="0" type="audio/mpeg"/><podcast:generator uri="https://www.jellypod.com"></podcast:generator><podcast:episode>1</podcast:episode><podcast:transcript url="https://auth.jellypod.ai/storage/v1/object/public/Podcasts/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/1d7d9cd6-bc15-4fac-9a6c-8db925a4b97a/captions_1752410750.srt" type="application/x-subrip" language="en" rel="captions"></podcast:transcript><itunes:author>Jellypod</itunes:author><itunes:subtitle>This episode uncovers how organizations in the defense sector can identify, handle, and protect Controlled Unclassified Information (CUI), Covered Defense Information (CDI), and Controlled Technical Information (CTI). We examine contract requirements, mar</itunes:subtitle><itunes:summary>This episode uncovers how organizations in the defense sector can identify, handle, and protect Controlled Unclassified Information (CUI), Covered Defense Information (CDI), and Controlled Technical Information (CTI). We examine contract requirements, marking guidance, and the latest resources to help contractors navigate CMMC compliance and data rights management.</itunes:summary><itunes:explicit>false</itunes:explicit><itunes:image href="https://auth.jellypod.ai/storage/v1/object/public/CoverImages/org_01K7D9HMARAYC5PAV3P54DZ6FS/users/user_01K7D9HM3ZKY7WZ11JNDE76E0X/6417a6f3-7041-465c-bbcc-52e10a780dcf.webp"/><itunes:episodeType>full</itunes:episodeType></item></channel></rss>