
Sign up to save your podcasts
Or


Thank you for visiting our podcasts on CMMC Cybersecurity!
Explore more insights, updates, and expert discussions on our blog: https://cybercomply.us/blog-list
Luis G. Batista C.P.M., CPSM
Founder & CEO, Armada Cyber Defense | CyberComply
[email protected]
Office: (305) 306-1800 Ext. 800
CAGE: 9QG33 UEI: K6UZHLE1WUA7
Schedule Introduction: https://calendly.com/cybercomplygrc/schedule-armada-cyber-defense-cybercomply-introduction
LinkedIn: https://www.linkedin.com/in/luis-g-batista/
ArmadaCyberDefense.us: https://www.armadacyberdefense.us/
CyberGap.us https://cybercomply.us/cybergap (Free CMMC Level 1 & 2 Gap Assessment Tool)
CyberComply.us: https://cybercomply.us/ (CMMC Level 1 & 2 GRC)
Thank you for visiting our podcasts on CMMC Cybersecurity!
Explore more insights, updates, and expert discussions on our blog: https://cybercomply.us/blog-list
Luis G. Batista C.P.M., CPSM
Founder & CEO, Armada Cyber Defense | CyberComply
[email protected]
Office: (305) 306-1800 Ext. 800
CAGE: 9QG33 UEI: K6UZHLE1WUA7
Schedule Introduction: https://calendly.com/cybercomplygrc/schedule-armada-cyber-defense-cybercomply-introduction
LinkedIn: https://www.linkedin.com/in/luis-g-batista/
ArmadaCyberDefense.us: https://www.armadacyberdefense.us/
CyberGap.us https://cybercomply.us/cybergap (Free CMMC Level 1 & 2 Gap Assessment Tool)
CyberComply.us: https://cybercomply.us/ (CMMC Level 1 & 2 GRC)
Thank you for visiting our podcasts on CMMC Cybersecurity!
Explore more insights, updates, and expert discussions on our blog: https://cybercomply.us/blog-list
Luis G. Batista C.P.M., CPSM
Founder & CEO, Armada Cyber Defense | CyberComply
[email protected]
Office: (305) 306-1800 Ext. 800
CAGE: 9QG33 UEI: K6UZHLE1WUA7
Schedule Introduction: https://calendly.com/cybercomplygrc/schedule-armada-cyber-defense-cybercomply-introduction
LinkedIn: https://www.linkedin.com/in/luis-g-batista/
ArmadaCyberDefense.us: https://www.armadacyberdefense.us/
CyberGap.us https://cybercomply.us/cybergap (Free CMMC Level 1 & 2 Gap Assessment Tool)
CyberComply.us: https://cybercomply.us/ (CMMC Level 1 & 2 GRC)
Thank you for visiting our podcasts on CMMC Cybersecurity!
Explore more insights, updates, and expert discussions on our blog: https://cybercomply.us/blog-list
Luis G. Batista C.P.M., CPSM
Founder & CEO, Armada Cyber Defense | CyberComply
[email protected]
Office: (305) 306-1800 Ext. 800
CAGE: 9QG33 UEI: K6UZHLE1WUA7
Schedule Introduction: https://calendly.com/cybercomplygrc/schedule-armada-cyber-defense-cybercomply-introduction
LinkedIn: https://www.linkedin.com/in/luis-g-batista/
ArmadaCyberDefense.us: https://www.armadacyberdefense.us/
CyberGap.us https://cybercomply.us/cybergap (Free CMMC Level 1 & 2 Gap Assessment Tool)
CyberComply.us: https://cybercomply.us/ (CMMC Level 1 & 2 GRC)
Thank you for visiting our podcasts on CMMC Cybersecurity!
Explore more insights, updates, and expert discussions on our blog: https://cybercomply.us/blog-list
Luis G. Batista C.P.M., CPSM
Founder & CEO, Armada Cyber Defense | CyberComply
[email protected]
Office: (305) 306-1800 Ext. 800
CAGE: 9QG33 UEI: K6UZHLE1WUA7
Schedule Introduction: https://calendly.com/cybercomplygrc/schedule-armada-cyber-defense-cybercomply-introduction
LinkedIn: https://www.linkedin.com/in/luis-g-batista/
ArmadaCyberDefense.us: https://www.armadacyberdefense.us/
CyberGap.us https://cybercomply.us/cybergap (Free CMMC Level 1 & 2 Gap Assessment Tool)
CyberComply.us: https://cybercomply.us/ (CMMC Level 1 & 2 GRC)
Thank you for visiting our podcasts on CMMC Cybersecurity!
Explore more insights, updates, and expert discussions on our blog: https://cybercomply.us/blog-list
Luis G. Batista C.P.M., CPSM
Founder & CEO, Armada Cyber Defense | CyberComply
[email protected]
Office: (305) 306-1800 Ext. 800
CAGE: 9QG33 UEI: K6UZHLE1WUA7
Schedule Introduction: https://calendly.com/cybercomplygrc/schedule-armada-cyber-defense-cybercomply-introduction
LinkedIn: https://www.linkedin.com/in/luis-g-batista/
ArmadaCyberDefense.us: https://www.armadacyberdefense.us/
CyberGap.us https://cybercomply.us/cybergap (Free CMMC Level 1 & 2 Gap Assessment Tool)
CyberComply.us: https://cybercomply.us/ (CMMC Level 1 & 2 GRC)
Thank you for visiting our podcasts on CMMC Cybersecurity!
Explore more insights, updates, and expert discussions on our blog: https://cybercomply.us/blog-list
Luis G. Batista C.P.M., CPSM
Founder & CEO, Armada Cyber Defense | CyberComply
[email protected]
Office: (305) 306-1800 Ext. 800
CAGE: 9QG33 UEI: K6UZHLE1WUA7
Schedule Introduction: https://calendly.com/cybercomplygrc/schedule-armada-cyber-defense-cybercomply-introduction
LinkedIn: https://www.linkedin.com/in/luis-g-batista/
ArmadaCyberDefense.us: https://www.armadacyberdefense.us/
CyberGap.us https://cybercomply.us/cybergap (Free CMMC Level 1 & 2 Gap Assessment Tool)
CyberComply.us: https://cybercomply.us/ (CMMC Level 1 & 2 GRC)
The Department of Defense is making one of the most significant changes to cybersecurity compliance in over a decade: a move from the Risk Management Framework (RMF) to the Cybersecurity Risk Management Construct (CSRMC).
For defense contractors, integrators, and managed service providers, this shift will redefine how compliance is achieved and measured. The message is clear: point in time checklists are out, continuous and automated compliance is in.
What is CSRMC?
CSRMC is the DoD’s new model for managing cyber risk. It takes the foundation of RMF and re-aligns it to modern operational needs, emphasizing:
The goal is to move away from static compliance paperwork and toward a living cybersecurity posture that evolves with threats.
Why It Matters to Contractors
For small and mid-sized businesses in the Defense Industrial Base, CSRMC may sound intimidating. New requirements often bring new tools, higher costs, and more time away from core operations.
The good news is that if you are preparing for CMMC (Cybersecurity Maturity Model Certification), you are already building toward CSRMC readiness. Many of the same principles, including critical controls, ongoing monitoring, training, and evidence management, are shared across both models.
The real question is: are you aligned now, or will you scramble to catch up later?
CyberComply: CSRMC Ready Today
CyberComply was designed to solve this exact challenge. Built by Armada Cyber Defense, it is a CMMC compliance platform built on GRC principles, and it already aligns with most of CSRMC’s tenets.
Here is how:
What You Should Do Now
Bottom Line
The DoD is moving from RMF to CSRMC, and the shift is already underway. CyberComply keeps you ahead of the curve. CMMC compliance today, CSRMC alignment tomorrow.
Thank you for visiting our podcasts on CMMC Cybersecurity!
Explore more insights, updates, and expert discussions on our blog: https://cybercomply.us/blog-list
Luis G. Batista C.P.M., CPSM
Founder & CEO, Armada Cyber Defense | CyberComply
[email protected]
Office: (305) 306-1800 Ext. 800
CAGE: 9QG33 UEI: K6UZHLE1WUA7
Schedule Introduction: https://calendly.com/cybercomplygrc/schedule-armada-cyber-defense-cybercomply-introduction
LinkedIn: https://www.linkedin.com/in/luis-g-batista/
ArmadaCyberDefense.us: https://www.armadacyberdefense.us/
CyberGap.us https://cybercomply.us/cybergap (Free CMMC Level 1 & 2 Gap Assessment Tool)
CyberComply.us: https://cybercomply.us/ (CMMC Level 1 & 2 GRC)
Thank you for visiting our podcasts on CMMC Cybersecurity!
Explore more insights, updates, and expert discussions on our blog: https://cybercomply.us/blog-list
Luis G. Batista C.P.M., CPSM
Founder & CEO, Armada Cyber Defense | CyberComply
[email protected]
Office: (305) 306-1800 Ext. 800
CAGE: 9QG33 UEI: K6UZHLE1WUA7
Schedule Introduction: https://calendly.com/cybercomplygrc/schedule-armada-cyber-defense-cybercomply-introduction
LinkedIn: https://www.linkedin.com/in/luis-g-batista/
ArmadaCyberDefense.us: https://www.armadacyberdefense.us/
CyberGap.us https://cybercomply.us/cybergap (Free CMMC Level 1 & 2 Gap Assessment Tool)
CyberComply.us: https://cybercomply.us/ (CMMC Level 1 & 2 GRC)
One of the most common questions Defense Industrial Base (DIB) contractors face is: “What CMMC Level do I need in order to respond to this solicitation?” The answer depends entirely on the contract language and the type of information your organization will handle. Let’s break it down into plain terms.
Step 1: Look for DFARS 252.204-7012 or NIST SP 800-171 References
If the solicitation includes DFARS 252.204-7012 or explicitly requires compliance with NIST SP 800-171, you are dealing with Controlled Unclassified Information (CUI). That means your organization must achieve CMMC Level 2.
Level 2 represents the “advanced” tier of cybersecurity, aligning directly with NIST SP 800-171’s 110 controls. In short: if you see 7012 or NIST 800-171, think Level 2.
Step 2: Check for FAR 52.204-21 Only
If the solicitation only lists FAR 52.204-21 (Basic Safeguarding of Covered Contractor Information Systems) and no DFARS clauses, then you’re only required to protect Federal Contract Information (FCI). In this case, CMMC Level 1 is the right fit.
Level 1 is considered “foundational” and focuses on 17 practices that address the basic safeguarding of FCI.
Step 3: Identify if You Handle CUI
Even if the solicitation doesn’t explicitly mention DFARS 252.204-7012, if your role in the contract involves handling CUI—such as technical data, ITAR/EAR information, or export-controlled details—you’ll need CMMC Level 2. Subcontractors that only work with FCI may remain at Level 1, but those touching CUI must step up to Level 2.
Step 4: Watch for “Undetermined” Situations
Some solicitations may be vague or missing clear guidance. If none of the clauses are referenced, and your role doesn’t involve handling FCI or CUI, the requirement may be undetermined or not applicable. In these cases, it’s wise to seek clarification from the contracting officer before making assumptions.
Quick Reference Table
Why This Matters
Bidding on a solicitation without the right CMMC level could disqualify your company, or worse, lead to compliance issues down the road. By knowing how to read the contract language and identify the associated data types, DIB contractors can quickly determine their path to compliance and stay competitive.
Luis G. Batista C.P.M., CPSM
[email protected]
Office: (305) 306-1800 Ext. 800
Website LinkedIn Schedule Appointment
CAGE: 9QG33 UEI: K6UZHLE1WUA7
CyberComply CMMC GRC
A Product of Armada Cyber Defense
From the publisher's feed
CMMC Academy is a podcast dedicated to helping businesses understand and achieve Cybersecurity Maturity Model Certification (CMMC) compliance. Each episode offers practical insights, expert…