
Sign up to save your podcasts
Or


About 100 authorized assessors. An estimated 118,000+ companies that need to be assessed. That math is the reason CMMC can't wait — and it's where this conversation starts. Brett Cox, lead CMMC Certified Assessor and head of Boeing's DFARS CMMC Program Management Office, joins host Jen Stone to explain what the Cybersecurity Maturity Model Certification actually requires, why the November 2026 third-party assessment deadline is creating a bottleneck, and how a small or mid-sized contractor should take the first step.
KEY TAKEAWAYS
RESOURCES
DoD CIO CMMC documentation (scoping & assessment guides): https://dowcio.war.gov/CMMC/Resources-Documentation/
Cyber AB Marketplace (find a C3PAO or consultant): https://cyberab.org/marketplace
NIST SP 800-171 https://csrc.nist.gov/Pubs/sp/800/171/r3/final
SecurityMetrics CMMC services: https://www.securitymetrics.com/product/cmmc
About the Guest
Brett Cox — Lead CMMC Certified Assessor; Principal & Team Lead, DFARS CMMC Program Management Office, The Boeing Company. LinkedIn: https://www.linkedin.com/in/brett-r-cox/
A note from Jen: We built Practical Cybersecurity because we were tired of the fear-mongering in this industry. Security shouldn't be a secret club.
Whether you're trying to figure out PCI compliance or need a pen test, my team at SecurityMetrics can help you out: https://www.securitymetrics.com/contact/lets-get-you-to-the-right-place
But if you just want to learn how to protect yourself for free, start here: https://academy.securitymetrics.com/
By SecurityMetrics5
88 ratings
About 100 authorized assessors. An estimated 118,000+ companies that need to be assessed. That math is the reason CMMC can't wait — and it's where this conversation starts. Brett Cox, lead CMMC Certified Assessor and head of Boeing's DFARS CMMC Program Management Office, joins host Jen Stone to explain what the Cybersecurity Maturity Model Certification actually requires, why the November 2026 third-party assessment deadline is creating a bottleneck, and how a small or mid-sized contractor should take the first step.
KEY TAKEAWAYS
RESOURCES
DoD CIO CMMC documentation (scoping & assessment guides): https://dowcio.war.gov/CMMC/Resources-Documentation/
Cyber AB Marketplace (find a C3PAO or consultant): https://cyberab.org/marketplace
NIST SP 800-171 https://csrc.nist.gov/Pubs/sp/800/171/r3/final
SecurityMetrics CMMC services: https://www.securitymetrics.com/product/cmmc
About the Guest
Brett Cox — Lead CMMC Certified Assessor; Principal & Team Lead, DFARS CMMC Program Management Office, The Boeing Company. LinkedIn: https://www.linkedin.com/in/brett-r-cox/
A note from Jen: We built Practical Cybersecurity because we were tired of the fear-mongering in this industry. Security shouldn't be a secret club.
Whether you're trying to figure out PCI compliance or need a pen test, my team at SecurityMetrics can help you out: https://www.securitymetrics.com/contact/lets-get-you-to-the-right-place
But if you just want to learn how to protect yourself for free, start here: https://academy.securitymetrics.com/