🚨 Want to break into DoD cybersecurity but don't have eMASS experience? Gain hands on experience with RMF Academy eMASS Lab Access and build the confidence employers are looking for. Link below 👇
https://www.rmfacademy.io/courses/RMF-Academy-eMASS-Lab-Access
🚀 Ready to break into DoD cybersecurity? RMF Academy gives you the hands on training, practical resources, and real world guidance to build the skills employers are looking for. Link below 👇
https://www.rmfacademy.io/
Timestamps:
00:00 Introduction
00:59 Meet CMMC Assessor Carter Schoenberg
02:23 What Is CMMC and Who Actually Needs It?
05:49 What Is CUI?
06:40 CMMC Levels Explained
09:03 The Problem With CUI and Government Contracts
10:43 CMMC Phase 1 and Phase 2 Explained
11:38 What Happened to CMMC Phase 2?
14:28 The Real Cost of CMMC Compliance
16:54 Why Protecting CUI Matters
19:42 How Companies Should Start Preparing for CMMC
24:04 Understanding Your CUI Data Flow
24:24 What CMMC Assessors Look for in Documentation
25:36 What Actually Happens During a CMMC Assessment
27:50 How to Prepare Your CMMC Evidence and Artifacts
29:27 Common CMMC Documentation Mistakes
31:11 How CMMC Controls Are Actually Assessed
32:31 What Happens After the Assessment?
33:18 What Happens When Evidence Is Missing?
36:33 Should You Get a CMMC Mock Assessment?
38:06 Why So Many Companies Use Microsoft Intune for CMMC
40:11 CMMC Implementation Mistakes to Avoid
42:50 What It Takes to Pass a CMMC Assessment
46:29 CMMC Assessment Preparation Checklist
48:40 How to Use the CMMC Assessor Guides
49:24 Understanding CUI Assets and Assessment Scope
50:40 Why Universities May Need CMMC
52:03 Universities Already Being Required to Meet CMMC Level 2
53:01 CMMC vs Other Cybersecurity Assessments
54:49 The Future of CUI Requirements
57:34 CMMC Level 2 Certification Requirements
59:57 The Cost of CMMC Implementation and Certification
01:01:49 How to Choose a Good CMMC Assessor
01:04:00 Final Thoughts
VIdeo Description:
What does a CMMC assessor actually look for during an assessment? In this episode of the Tech Woke Podcast, Christopher Okpala sits down with CMMC assessor Carter Schoenberg to break down the CMMC assessment process, what organizations should expect, and how defense contractors can properly prepare before an assessor arrives.
We discuss CMMC, Controlled Unclassified Information (CUI), CMMC Level 2, assessment scope, security controls, evidence, artifacts, documentation, and implementation. Carter explains why simply having policies isn't enough and what organizations need to demonstrate to show that their cybersecurity practices are actually implemented. We also discuss common documentation mistakes, missing evidence, mock assessments, Microsoft Intune, the cost of CMMC compliance, and what happens when an assessor identifies gaps.
If you're an ISSO, GRC professional, cybersecurity professional, government contractor, CMMC consultant, MSP/MSSP, or business operating within the Defense Industrial Base (DIB), this conversation provides a practical look at how CMMC assessments work and how organizations can prepare.
In this episode:
What CMMC is and who needs it
What CUI is and why it must be protected
CMMC levels and assessment requirements
How to prepare for a CMMC assessment
What CMMC assessors actually look for
How to prepare controls, evidence, and artifacts
CMMC documentation requirements
How assessors validate control implementation
What happens when evidence is missing
Common CMMC preparation mistakes
Why companies use Microsoft Intune for CMMC environments
CMMC assessment scope and CUI data flows
Whether companies should conduct mock assessments
The cost of preparing for CMMC
How to choose a CMMC assessor or consultant
How cybersecurity professionals can get involved in the CMMC ecosystem
If your organization is preparing for a CMMC assessment, don't wait until assessment day to figure out whether your documentation, evidence, and technical implementation align. This episode gives you an assessor's perspective on what preparation actually looks like.
Subscribe to Tech Woke for more conversations about CMMC, RMF, GRC, ISSO careers, federal cybersecurity, GovTech, eMASS, NIST 800-53, and cybersecurity compliance.
Question for you: Is your organization currently preparing for CMMC?
#CMMC #Cybersecurity #GRC