CMMC Academy

CMMC Academy

By Armada Cyber Defense LLCEducationHow ToCourses
Download on the App Store

CMMC Academy episodes

  • CMMC Level 1 Certification Explained Self-Assessment Guide (Step-by-Step Walkthrough)



    Thank you for visiting our podcasts on CMMC Cybersecurity!
    Explore more insights, updates, and expert discussions on our blog: https://cybercomply.us/blog-list


    Luis G. Batista C.P.M., CPSM
    Founder & CEO, Armada Cyber Defense | CyberComply
    [email protected]
    Office: (305) 306-1800 Ext. 800
    CAGE: 9QG33   UEI: K6UZHLE1WUA7

    Schedule Introduction: https://calendly.com/cybercomplygrc/schedule-armada-cyber-defense-cybercomply-introduction 

    LinkedIn: https://www.linkedin.com/in/luis-g-batista/

    ArmadaCyberDefense.us: https://www.armadacyberdefense.us/

    CyberGap.us https://cybercomply.us/cybergap (Free CMMC Level 1 & 2 Gap Assessment Tool)

    CyberComply.us: https://cybercomply.us/ (CMMC Level 1 & 2 GRC)

    23 min
  • Armada’s Unified CMMC Compliance Framework



    Thank you for visiting our podcasts on CMMC Cybersecurity!
    Explore more insights, updates, and expert discussions on our blog: https://cybercomply.us/blog-list


    Luis G. Batista C.P.M., CPSM
    Founder & CEO, Armada Cyber Defense | CyberComply
    [email protected]
    Office: (305) 306-1800 Ext. 800
    CAGE: 9QG33   UEI: K6UZHLE1WUA7

    Schedule Introduction: https://calendly.com/cybercomplygrc/schedule-armada-cyber-defense-cybercomply-introduction 

    LinkedIn: https://www.linkedin.com/in/luis-g-batista/

    ArmadaCyberDefense.us: https://www.armadacyberdefense.us/

    CyberGap.us https://cybercomply.us/cybergap (Free CMMC Level 1 & 2 Gap Assessment Tool)

    CyberComply.us: https://cybercomply.us/ (CMMC Level 1 & 2 GRC)

    6 min
  • CMMC Compliance: GRC, PreVeil, and MSSP Synergy



    Thank you for visiting our podcasts on CMMC Cybersecurity!
    Explore more insights, updates, and expert discussions on our blog: https://cybercomply.us/blog-list


    Luis G. Batista C.P.M., CPSM
    Founder & CEO, Armada Cyber Defense | CyberComply
    [email protected]
    Office: (305) 306-1800 Ext. 800
    CAGE: 9QG33   UEI: K6UZHLE1WUA7

    Schedule Introduction: https://calendly.com/cybercomplygrc/schedule-armada-cyber-defense-cybercomply-introduction 

    LinkedIn: https://www.linkedin.com/in/luis-g-batista/

    ArmadaCyberDefense.us: https://www.armadacyberdefense.us/

    CyberGap.us https://cybercomply.us/cybergap (Free CMMC Level 1 & 2 Gap Assessment Tool)

    CyberComply.us: https://cybercomply.us/ (CMMC Level 1 & 2 GRC)

    12 min
  • Untangling the UEI (Parent), CAGE (Child), NIST-800-171 and CMMC Connection



    Thank you for visiting our podcasts on CMMC Cybersecurity!
    Explore more insights, updates, and expert discussions on our blog: https://cybercomply.us/blog-list


    Luis G. Batista C.P.M., CPSM
    Founder & CEO, Armada Cyber Defense | CyberComply
    [email protected]
    Office: (305) 306-1800 Ext. 800
    CAGE: 9QG33   UEI: K6UZHLE1WUA7

    Schedule Introduction: https://calendly.com/cybercomplygrc/schedule-armada-cyber-defense-cybercomply-introduction 

    LinkedIn: https://www.linkedin.com/in/luis-g-batista/

    ArmadaCyberDefense.us: https://www.armadacyberdefense.us/

    CyberGap.us https://cybercomply.us/cybergap (Free CMMC Level 1 & 2 Gap Assessment Tool)

    CyberComply.us: https://cybercomply.us/ (CMMC Level 1 & 2 GRC)

    13 min
  • How to Create Assessment Ready CMMC Documentation





    Thank you for visiting our podcasts on CMMC Cybersecurity!
    Explore more insights, updates, and expert discussions on our blog: https://cybercomply.us/blog-list


    Luis G. Batista C.P.M., CPSM
    Founder & CEO, Armada Cyber Defense | CyberComply
    [email protected]
    Office: (305) 306-1800 Ext. 800
    CAGE: 9QG33   UEI: K6UZHLE1WUA7

    Schedule Introduction: https://calendly.com/cybercomplygrc/schedule-armada-cyber-defense-cybercomply-introduction 

    LinkedIn: https://www.linkedin.com/in/luis-g-batista/

    ArmadaCyberDefense.us: https://www.armadacyberdefense.us/

    CyberGap.us https://cybercomply.us/cybergap (Free CMMC Level 1 & 2 Gap Assessment Tool)

    CyberComply.us: https://cybercomply.us/ (CMMC Level 1 & 2 GRC)

    16 min
  • Understanding the Cyber AB’s Role and how CyberComply Supports the CMMC Ecosystem



    Thank you for visiting our podcasts on CMMC Cybersecurity!
    Explore more insights, updates, and expert discussions on our blog: https://cybercomply.us/blog-list


    Luis G. Batista C.P.M., CPSM
    Founder & CEO, Armada Cyber Defense | CyberComply
    [email protected]
    Office: (305) 306-1800 Ext. 800
    CAGE: 9QG33   UEI: K6UZHLE1WUA7

    Schedule Introduction: https://calendly.com/cybercomplygrc/schedule-armada-cyber-defense-cybercomply-introduction 

    LinkedIn: https://www.linkedin.com/in/luis-g-batista/

    ArmadaCyberDefense.us: https://www.armadacyberdefense.us/

    CyberGap.us https://cybercomply.us/cybergap (Free CMMC Level 1 & 2 Gap Assessment Tool)

    CyberComply.us: https://cybercomply.us/ (CMMC Level 1 & 2 GRC)

    6 min
  • Defining the Line: Understanding CMMC Scope and Boundaries



    Thank you for visiting our podcasts on CMMC Cybersecurity!
    Explore more insights, updates, and expert discussions on our blog: https://cybercomply.us/blog-list


    Luis G. Batista C.P.M., CPSM
    Founder & CEO, Armada Cyber Defense | CyberComply
    [email protected]
    Office: (305) 306-1800 Ext. 800
    CAGE: 9QG33   UEI: K6UZHLE1WUA7

    Schedule Introduction: https://calendly.com/cybercomplygrc/schedule-armada-cyber-defense-cybercomply-introduction 

    LinkedIn: https://www.linkedin.com/in/luis-g-batista/

    ArmadaCyberDefense.us: https://www.armadacyberdefense.us/

    CyberGap.us https://cybercomply.us/cybergap (Free CMMC Level 1 & 2 Gap Assessment Tool)

    CyberComply.us: https://cybercomply.us/ (CMMC Level 1 & 2 GRC)

    15 min
  • Stay Ahead of DoD's Shift from RMF to CSRMC

    The Department of Defense is making one of the most significant changes to cybersecurity compliance in over a decade: a move from the Risk Management Framework (RMF) to the Cybersecurity Risk Management Construct (CSRMC).

    For defense contractors, integrators, and managed service providers, this shift will redefine how compliance is achieved and measured. The message is clear: point in time checklists are out, continuous and automated compliance is in.

    What is CSRMC?

    CSRMC is the DoD’s new model for managing cyber risk. It takes the foundation of RMF and re-aligns it to modern operational needs, emphasizing:

    • Automation instead of manual checklists
    • Cyber Survivability to ensure systems remain functional in contested environments
    • Continuous Monitoring for real time visibility
    • DevSecOps integration for secure development and deployment
    • Reciprocity and Inheritance to reduce duplication of effort across systems

    The goal is to move away from static compliance paperwork and toward a living cybersecurity posture that evolves with threats.

    Why It Matters to Contractors

    For small and mid-sized businesses in the Defense Industrial Base, CSRMC may sound intimidating. New requirements often bring new tools, higher costs, and more time away from core operations.

    The good news is that if you are preparing for CMMC (Cybersecurity Maturity Model Certification), you are already building toward CSRMC readiness. Many of the same principles, including critical controls, ongoing monitoring, training, and evidence management, are shared across both models.

    The real question is: are you aligned now, or will you scramble to catch up later?

    CyberComply: CSRMC Ready Today

    CyberComply was designed to solve this exact challenge. Built by Armada Cyber Defense, it is a CMMC compliance platform built on GRC principles, and it already aligns with most of CSRMC’s tenets.

    Here is how:

    • Automation. CyberComply automates gap assessments, SSPs, POA&Ms, and evidence collection.
    •  Continuous Monitoring. Dashboards and reminders keep compliance active, not static.
    •  Critical Controls. Focused on the core NIST 800-171 subset that matters most for CMMC Levels 1 and 2.
    •  Operationalization. Compliance is tied to workflows, tasks, and real time collaboration.
    •  Cyber Survivability (Add On). AWS Backup integration provides proof of last backup success and restore test evidence.
    •  Training (Add On). Lightweight training evidence tracking keeps you aligned without expensive LMS.

    What You Should Do Now

    1. Understand CSRMC. Recognize that the DoD is raising the bar from paperwork driven compliance to continuous cybersecurity assurance.
    2. Assess your current state. If you are already preparing for CMMC, you are on the right track, but make sure your tools support automation and monitoring, not just document storage.
    3. Choose a platform that keeps pace. CyberComply is purpose built for the Defense Industrial Base and already aligned with CSRMC. That means no re-platforming when DoD requirements shift.

    Bottom Line

    The DoD is moving from RMF to CSRMC, and the shift is already underway. CyberComply keeps you ahead of the curve. CMMC compliance today, CSRMC alignment tomorrow.




    Thank you for visiting our podcasts on CMMC Cybersecurity!
    Explore more insights, updates, and expert discussions on our blog: https://cybercomply.us/blog-list


    Luis G. Batista C.P.M., CPSM
    Founder & CEO, Armada Cyber Defense | CyberComply
    [email protected]
    Office: (305) 306-1800 Ext. 800
    CAGE: 9QG33   UEI: K6UZHLE1WUA7

    Schedule Introduction: https://calendly.com/cybercomplygrc/schedule-armada-cyber-defense-cybercomply-introduction 

    LinkedIn: https://www.linkedin.com/in/luis-g-batista/

    ArmadaCyberDefense.us: https://www.armadacyberdefense.us/

    CyberGap.us https://cybercomply.us/cybergap (Free CMMC Level 1 & 2 Gap Assessment Tool)

    CyberComply.us: https://cybercomply.us/ (CMMC Level 1 & 2 GRC)

    6 min
  • CMMC Level Determination: How to Know What Your Contract Requires



    Thank you for visiting our podcasts on CMMC Cybersecurity!
    Explore more insights, updates, and expert discussions on our blog: https://cybercomply.us/blog-list


    Luis G. Batista C.P.M., CPSM
    Founder & CEO, Armada Cyber Defense | CyberComply
    [email protected]
    Office: (305) 306-1800 Ext. 800
    CAGE: 9QG33   UEI: K6UZHLE1WUA7

    Schedule Introduction: https://calendly.com/cybercomplygrc/schedule-armada-cyber-defense-cybercomply-introduction 

    LinkedIn: https://www.linkedin.com/in/luis-g-batista/

    ArmadaCyberDefense.us: https://www.armadacyberdefense.us/

    CyberGap.us https://cybercomply.us/cybergap (Free CMMC Level 1 & 2 Gap Assessment Tool)

    CyberComply.us: https://cybercomply.us/ (CMMC Level 1 & 2 GRC)

    6 min
  • CMMC Level Determination: How to Know What Your Contract Requires

    One of the most common questions Defense Industrial Base (DIB) contractors face is: “What CMMC Level do I need in order to respond to this solicitation?” The answer depends entirely on the contract language and the type of information your organization will handle. Let’s break it down into plain terms.

    Step 1: Look for DFARS 252.204-7012 or NIST SP 800-171 References

    If the solicitation includes DFARS 252.204-7012 or explicitly requires compliance with NIST SP 800-171, you are dealing with Controlled Unclassified Information (CUI). That means your organization must achieve CMMC Level 2.

    Level 2 represents the “advanced” tier of cybersecurity, aligning directly with NIST SP 800-171’s 110 controls. In short: if you see 7012 or NIST 800-171, think Level 2.

    Step 2: Check for FAR 52.204-21 Only

    If the solicitation only lists FAR 52.204-21 (Basic Safeguarding of Covered Contractor Information Systems) and no DFARS clauses, then you’re only required to protect Federal Contract Information (FCI). In this case, CMMC Level 1 is the right fit.

    Level 1 is considered “foundational” and focuses on 17 practices that address the basic safeguarding of FCI.

    Step 3: Identify if You Handle CUI

    Even if the solicitation doesn’t explicitly mention DFARS 252.204-7012, if your role in the contract involves handling CUI—such as technical data, ITAR/EAR information, or export-controlled details—you’ll need CMMC Level 2. Subcontractors that only work with FCI may remain at Level 1, but those touching CUI must step up to Level 2.

    Step 4: Watch for “Undetermined” Situations

    Some solicitations may be vague or missing clear guidance. If none of the clauses are referenced, and your role doesn’t involve handling FCI or CUI, the requirement may be undetermined or not applicable. In these cases, it’s wise to seek clarification from the contracting officer before making assumptions.

    Quick Reference Table

    • FAR 52.204-21 only (FCI) - Level 1
    • DFARS 252.204-7012 or NIST SP 800-171 (CUI) - Level 2
    • Handling CUI directly - Level 2
    • No clauses, no FCI or CUI - Undetermined / N/A

    Why This Matters

    Bidding on a solicitation without the right CMMC level could disqualify your company, or worse, lead to compliance issues down the road. By knowing how to read the contract language and identify the associated data types, DIB contractors can quickly determine their path to compliance and stay competitive.


    Luis G. Batista C.P.M., CPSM
    [email protected]
    Office: (305) 306-1800 Ext. 800
    Website LinkedIn Schedule Appointment
    CAGE: 9QG33 UEI: K6UZHLE1WUA7
    CyberComply CMMC GRC
    A Product of Armada Cyber Defense

    3 min

About CMMC Academy

From the publisher's feed

CMMC Academy is a podcast dedicated to helping businesses understand and achieve Cybersecurity Maturity Model Certification (CMMC) compliance. Each episode offers practical insights, expert…