A lot of contractors start CMMC Level 2 in the wrong place. They talk to five vendors, get five different answers, start drafting policies, and then realize halfway through that they still do not know who owns what or which gaps they actually need to close.
In this solo episode of Trust Issues, Brandon Lecoq walks through the more practical way to start: work backward from the audit. That means beginning with the 320 assessment objectives, going line by line with the right people in the company, and being honest about what is done, what is not, and what is unclear.
What You’ll Learn:
- Why the 320 assessment objectives are the best place to start
- How to avoid getting stuck between conflicting vendor recommendations
- Why CMMC Level 2 is not just 110 controls
- How to build a responsibility matrix before writing policies
- What to ask vendors before buying tools or services
- Why starting with the SSP can create months of unnecessary rework
Episode chapters:
00:00 Introduction00:15 Where to start with CMMC level 2 research00:30 Why vendor advice gets confusing00:45 Working backward from the audit01:00 Start with the 320 assessment objectives01:30 CMMC as the enforcement layer of NIST 800-17102:00 The 110 controls explained02:45 Why 320 assessment objectives matter03:15 Controls vs. assessment objectives04:00 What the C3PAO actually assesses04:30 One control can have multiple parts05:28 The boring spreadsheet work you cannot skip06:30 How to run your internal gap assessment07:15 Why every assessment objective needs an owner08:00 Building your shared responsibility matrix08:45 Assigning ownership across IT, HR, operations, and vendors09:16 Ask vendors exactly what they own10:30 Why the RACI process takes time11:30 Moving from ownership into documentation11:45 What your SSP actually needs to explain12:45 Why the SSP is only one part of the documentation13:00 83 documents and 1,500+ pages of proof14:30 Policy, procedure, and proof17:15 Why does evidence come after the documentation18:15 What the C3PAO audit actually looks like19:15 Work backward from the spreadsheet20:21 Don’t start with the SSP21:15 Why early documentation creates rework22:00 When vendor conversations should begin22:30 Identifying the tools you still need23:30 Why ITAR can change your tool choices24:15 How certified MSPs, MSSPs, and RPOs can help25:30 How BEMO can share CMMC responsibility26:30 Assigning ownership across the full company27:15 Why SMBs often need outside support27:44 Bring the shared responsibility matrix to every vendor conversation28:41 Final takeaway: stop guessing before the audit
Quotes:
“You have your 110 controls, but then there are 320 assessment objectives related to those 110 controls. You just have to do it. It’s extremely boring, and it’s going to be time-consuming to go through 320 rows on a spreadsheet.”
“You should not even tackle the SSP and policies and procedures and the evidence package until you’ve truthfully completed the first three steps.”
“When you are equipped with that spreadsheet, you are no longer doing all this hand-waving when you’re talking to vendors.”
“Start by going line by line through the assessment objectives and security controls and trying to determine who owns what.”
Connect with the team: 👉 Brandon Lecoq on LinkedIn: https://www.linkedin.com/in/brandon-lecoq
👉 Bruno Lecoq on LinkedIn: https://www.linkedin.com/in/brunolecoq/
👉 BEMO Website: https://www.bemopro.com/
Trust Issues is handcrafted by our friends over at: fame.so