<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet href="https://rss.buzzsprout.com/styles.xsl" type="text/xsl"?>
<rss version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:podcast="https://podcastindex.org/namespace/1.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:psc="http://podlove.org/simple-chapters" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <atom:link href="https://rss.buzzsprout.com/2428223.rss" rel="self" type="application/rss+xml" />
  <atom:link href="https://pubsubhubbub.appspot.com/" rel="hub" xmlns="http://www.w3.org/2005/Atom" />
  <title>CMMC Compliance Guide</title>

  <lastBuildDate>Fri, 10 Jul 2026 07:00:02 -0400</lastBuildDate>
  <link>https://cmmccomplianceguide.com/home</link>
  <language>en-us</language>
  <copyright>© 2026 CMMC Compliance Guide</copyright>
  <podcast:locked>yes</podcast:locked>
    <podcast:guid>8c577d25-3a03-5d31-8661-085f6b802faa</podcast:guid>
  <podcast:txt purpose="verify">sflores@justiceitc.com</podcast:txt>
  <itunes:author>CMMC Compliance Guide</itunes:author>
  <itunes:type>episodic</itunes:type>
  <itunes:explicit>false</itunes:explicit>
  <description><![CDATA[<p>Our experiences inspired the creation of The CMMC Compliance Guide Podcast and its accompanying resources. The podcast began as a way to share what we learned through real-world challenges—like helping that aerospace machine shop—and to provide accessible education for businesses navigating DoD cybersecurity requirements.<br><br></p><p>The CMMC Compliance Guide Podcast breaks down complex topics like NIST 800-171 and CMMC into actionable, easy-to-understand steps. Whether you’re a subcontractor struggling to meet compliance deadlines or a business owner looking to secure your supply chain, the guide offers practical advice to help you take control of your cybersecurity journey.</p>]]></description>
  <generator>Buzzsprout (https://www.buzzsprout.com)</generator>
  <itunes:keywords>CMMC, NIST 800-171, DFARS compliance, SPRS score, DoD contracts, aerospace manufacturing, government contracting, cybersecurity compliance, defense contractors, SSP and POAM, compliance audit, FedRAMP</itunes:keywords>
  <itunes:owner>
    <itunes:name>CMMC Compliance Guide</itunes:name>
    <itunes:email>sflores@justiceitc.com</itunes:email>
  </itunes:owner>
  <image>
     <url>https://storage.buzzsprout.com/opzruxtnkbvrmmuz9vfrshsfvdve?.jpg</url>
     <title>CMMC Compliance Guide</title>
     <link>https://cmmccomplianceguide.com/home</link>
  </image>
  <itunes:image href="https://storage.buzzsprout.com/opzruxtnkbvrmmuz9vfrshsfvdve?.jpg" />
  <itunes:category text="Technology" />
  <itunes:category text="Government" />
  <itunes:category text="Education">
    <itunes:category text="Self-Improvement" />
  </itunes:category>
  <podcast:person role="host" href="https://linktr.ee/brookejustice" img="https://storage.buzzsprout.com/0t4gofoq0w3hcy0kjdyjor27f42u">Brooke Justice</podcast:person>
  <podcast:person role="co-host" href="https://linktr.ee/austinjustice" img="https://storage.buzzsprout.com/3a34tkangozy1dx307qq2okottyx">Austin Justice</podcast:person>
  <podcast:person role="co-host" href="https://www.linkedin.com/in/stacey-f-82b45a232/" img="https://storage.buzzsprout.com/txgrwq5bir2dpexrgoskmnkp1fyg">Stacey Flores</podcast:person>
  <item>
    <itunes:title>CMMC for Small Aerospace Suppliers: Real Costs, DIY Limits, Level 1 vs 2, and the November 2026 Deadline</itunes:title>
    <title>CMMC for Small Aerospace Suppliers: Real Costs, DIY Limits, Level 1 vs 2, and the November 2026 Deadline</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! Small aerospace suppliers are getting hit with the same CMMC questions over and over: what do I actually need to do if my contract requirements aren't clear yet, does redacting a drawing get it out of CUI territory, will a tool like ThreatLocker or Prevail make me compliant, and what is this actually going to cost. In this episode, Stacey and Brooke from Justice IT Consulting go through the real answers small manufacturers, machine ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>Small aerospace suppliers are getting hit with the same CMMC questions over and over: what do I actually need to do if my contract requirements aren&apos;t clear yet, does redacting a drawing get it out of CUI territory, will a tool like ThreatLocker or Prevail make me compliant, and what is this actually going to cost. In this episode, Stacey and Brooke from Justice IT Consulting go through the real answers small manufacturers, machine shops, and engineering firms need before the November 10, 2026 DFARS CMMC requirement hits new DOD contracts.</p><p>Topics covered:</p><ul><li>Why you can&apos;t fully plan compliance without knowing FCI vs. CUI exposure, and what that means for your Microsoft 365 environment (GCC vs. GCC High)</li><li>Why redacting a customer name or contract number from a drawing does NOT remove CUI status</li><li>Why compliance tools alone (ThreatLocker, Prevail, etc.) can&apos;t get you certified</li><li>Realistic cost ranges for CMMC Level 2 certification, and why &quot;$5,000&quot; and &quot;$20,000&quot; quotes are misleading</li><li>How far a small company can actually get doing CMMC in-house, including where AI-generated policies fall short</li><li>Whether to start at Level 1 and move up later, or go straight to Level 2</li><li>What changes for new DOD contracts after November 10, 2026</li><li>How to get an honest readiness check with a gaps assessment before spending money</li></ul><p>We&apos;re also co-hosting a free live webinar with FutureFeed and Preveil on shared responsibility in CMMC assessments, covering how to read a customer responsibility matrix and close gaps before they become assessment findings. Tuesday, July 21st at 12 PM Central. </p><p>Register (free, recording sent to all registrants): <a href='https://cmmccomplianceguide.com/podcast'>cmmccomplianceguide.com/podcast</a></p> ]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>Small aerospace suppliers are getting hit with the same CMMC questions over and over: what do I actually need to do if my contract requirements aren&apos;t clear yet, does redacting a drawing get it out of CUI territory, will a tool like ThreatLocker or Prevail make me compliant, and what is this actually going to cost. In this episode, Stacey and Brooke from Justice IT Consulting go through the real answers small manufacturers, machine shops, and engineering firms need before the November 10, 2026 DFARS CMMC requirement hits new DOD contracts.</p><p>Topics covered:</p><ul><li>Why you can&apos;t fully plan compliance without knowing FCI vs. CUI exposure, and what that means for your Microsoft 365 environment (GCC vs. GCC High)</li><li>Why redacting a customer name or contract number from a drawing does NOT remove CUI status</li><li>Why compliance tools alone (ThreatLocker, Prevail, etc.) can&apos;t get you certified</li><li>Realistic cost ranges for CMMC Level 2 certification, and why &quot;$5,000&quot; and &quot;$20,000&quot; quotes are misleading</li><li>How far a small company can actually get doing CMMC in-house, including where AI-generated policies fall short</li><li>Whether to start at Level 1 and move up later, or go straight to Level 2</li><li>What changes for new DOD contracts after November 10, 2026</li><li>How to get an honest readiness check with a gaps assessment before spending money</li></ul><p>We&apos;re also co-hosting a free live webinar with FutureFeed and Preveil on shared responsibility in CMMC assessments, covering how to read a customer responsibility matrix and close gaps before they become assessment findings. Tuesday, July 21st at 12 PM Central. </p><p>Register (free, recording sent to all registrants): <a href='https://cmmccomplianceguide.com/podcast'>cmmccomplianceguide.com/podcast</a></p> ]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/19454243-cmmc-for-small-aerospace-suppliers-real-costs-diy-limits-level-1-vs-2-and-the-november-2026-deadline.mp3" length="23614936" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-19454243</guid>
    <pubDate>Fri, 10 Jul 2026 06:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/19454243/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/19454243/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/19454243/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/19454243/transcript.vtt" type="text/vtt" />
    <podcast:chapters url="https://www.buzzsprout.com/2428223/19454243/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Welcome And What We Cover" />
  <psc:chapter start="1:19" title="Planning Without Clear Flowdowns" />
  <psc:chapter start="5:45" title="Why Redacting Drawings Changes Nothing" />
  <psc:chapter start="7:22" title="Tools Do Not Equal Compliance" />
  <psc:chapter start="9:14" title="The Real Cost For Small Suppliers" />
  <psc:chapter start="12:22" title="How Far You Can DIY" />
  <psc:chapter start="15:32" title="Ongoing Workload And Automation" />
  <psc:chapter start="19:59" title="Level One Or Jump To Level Two" />
  <psc:chapter start="23:25" title="Templates And AI With Guardrails" />
  <psc:chapter start="27:03" title="What Changes After November 10" />
  <psc:chapter start="29:36" title="Readiness Checks With Gap Assessments" />
  <psc:chapter start="32:27" title="Webinar Invite And Closing Notes" />
</psc:chapters>
    <itunes:duration>1965</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>64</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Cyber AB May 2026 Town Hall Recap: External Service Providers, Marketplace 2.0, New Leadership &amp; OSC Accountability Explained</itunes:title>
    <title>Cyber AB May 2026 Town Hall Recap: External Service Providers, Marketplace 2.0, New Leadership &amp; OSC Accountability Explained</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! The Cyber AB's May 2026 Town Hall packed in major updates and if you work with an MSP, use cloud services, or are trying to figure out where your compliance responsibility actually ends, this episode is required listening. Brooke and Stacey break down everything contractors need to know: ESP vs. CSP distinctions, FedRAMP changes, new leadership, Marketplace 2.0, and the single biggest takeaway every OSC needs to hear.   📌 What You'l...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>The Cyber AB&apos;s May 2026 Town Hall packed in major updates and if you work with an MSP, use cloud services, or are trying to figure out where your compliance responsibility actually ends, this episode is required listening. Brooke and Stacey break down everything contractors need to know: ESP vs. CSP distinctions, FedRAMP changes, new leadership, Marketplace 2.0, and the single biggest takeaway every OSC needs to hear.</p><p><br/></p><p><b>📌 What You&apos;ll Learn:</b></p><ul><li>What the new joint venture FAQ clarifies — and what actually changes (hint: less than you think)</li><li>The status of the official CMMC certification badge and what you can display right now</li><li>How FedRAMP 20X is changing authorization language — and why DoD&apos;s &quot;moderate equivalency&quot; standard isn&apos;t moving</li><li>The three questions every OSC must answer about their ESP</li><li>How to tell the difference between an MSP and a CSP — in plain English</li><li>The 5 NIST 800-145 criteria that determine whether a service counts as cloud computing</li><li>Cyber AB ecosystem updates: monthly RPO meetings launching in July and Marketplace 2.0 preview</li><li>The biggest takeaway from the town hall — and why the burden always lands on the OSC</li><li><b>Webinar Announcement:</b> <em>Whose Control Is It Anyway?</em> — free live event July 21st at 12 p.m. CT - Sign up by clicking <a href='https://cmmccomplianceguide.com/podcast'>HERE</a></li></ul>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>The Cyber AB&apos;s May 2026 Town Hall packed in major updates and if you work with an MSP, use cloud services, or are trying to figure out where your compliance responsibility actually ends, this episode is required listening. Brooke and Stacey break down everything contractors need to know: ESP vs. CSP distinctions, FedRAMP changes, new leadership, Marketplace 2.0, and the single biggest takeaway every OSC needs to hear.</p><p><br/></p><p><b>📌 What You&apos;ll Learn:</b></p><ul><li>What the new joint venture FAQ clarifies — and what actually changes (hint: less than you think)</li><li>The status of the official CMMC certification badge and what you can display right now</li><li>How FedRAMP 20X is changing authorization language — and why DoD&apos;s &quot;moderate equivalency&quot; standard isn&apos;t moving</li><li>The three questions every OSC must answer about their ESP</li><li>How to tell the difference between an MSP and a CSP — in plain English</li><li>The 5 NIST 800-145 criteria that determine whether a service counts as cloud computing</li><li>Cyber AB ecosystem updates: monthly RPO meetings launching in July and Marketplace 2.0 preview</li><li>The biggest takeaway from the town hall — and why the burden always lands on the OSC</li><li><b>Webinar Announcement:</b> <em>Whose Control Is It Anyway?</em> — free live event July 21st at 12 p.m. CT - Sign up by clicking <a href='https://cmmccomplianceguide.com/podcast'>HERE</a></li></ul>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/19418222-cyber-ab-may-2026-town-hall-recap-external-service-providers-marketplace-2-0-new-leadership-osc-accountability-explained.mp3" length="13914791" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-19418222</guid>
    <pubDate>Fri, 03 Jul 2026 06:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/19418222/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/19418222/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/19418222/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/19418222/transcript.vtt" type="text/vtt" />
    <podcast:chapters url="https://www.buzzsprout.com/2428223/19418222/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Welcome And What We Cover" />
  <psc:chapter start="1:08" title="May 2026 Town Hall Overview" />
  <psc:chapter start="1:29" title="New Leadership And Joint Venture FAQ" />
  <psc:chapter start="3:46" title="Certification Badge And FedRAMP Changes" />
  <psc:chapter start="6:48" title="ESP Basics And Why OSC Owns It" />
  <psc:chapter start="9:50" title="MSP Versus CSP In Plain Terms" />
  <psc:chapter start="11:42" title="Five Signs Something Is Cloud" />
  <psc:chapter start="14:15" title="Ecosystem Meetings And Marketplace 2.0" />
  <psc:chapter start="16:26" title="Biggest Takeaway Shared Responsibility" />
  <psc:chapter start="18:14" title="Free Webinar Invite And Closing" />
</psc:chapters>
    <itunes:duration>1157</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>63</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>New CMMC FAQ Clarifications: Joint Ventures, Paper-Only CUI, Reassessment Triggers &amp; Where MSPs Actually Fit in Scope</itunes:title>
    <title>New CMMC FAQ Clarifications: Joint Ventures, Paper-Only CUI, Reassessment Triggers &amp; Where MSPs Actually Fit in Scope</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! The Department of Defense just updated its CMMC FAQ document — and the clarifications inside answer some of the most common (and costly) assumptions contractors make. In this episode, Brooke and Stacey break down what changed for joint ventures, paper-only CUI, significant change triggers, and how MSPs and MSSPs actually fit into assessment scope. If you're navigating a merger, working with subcontractors, or relying on an MSP to ma...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>The Department of Defense just updated its CMMC FAQ document — and the clarifications inside answer some of the most common (and costly) assumptions contractors make. In this episode, Brooke and Stacey break down what changed for joint ventures, paper-only CUI, significant change triggers, and how MSPs and MSSPs actually fit into assessment scope.</p><p>If you&apos;re navigating a merger, working with subcontractors, or relying on an MSP to manage your environment, this episode clears up exactly where you stand — and where you don&apos;t.</p><p><br/></p><p><b>📌 What You&apos;ll Learn:</b></p><ul><li>Why joint ventures do NOT automatically inherit a company&apos;s CMMC certification status</li><li>The new guidance on paper-only CUI — and when it does NOT require Level 2 assessment</li><li>What actually counts as a &quot;significant change&quot; that triggers reassessment (mergers, system consolidation, and more)</li><li>Why MSPs don&apos;t need their own CMMC certification — but still carry major assessment responsibilities</li><li>The difference between CUI scope and Security Protection Data (SPD) scope for MSPs/MSSPs</li><li>The five-part test for whether an MSP counts as a Cloud Service Provider (CSP)</li><li><b>Listener Q&amp;A:</b> Do subcontractors need cybersecurity training and screening too?</li></ul><p><br/></p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>The Department of Defense just updated its CMMC FAQ document — and the clarifications inside answer some of the most common (and costly) assumptions contractors make. In this episode, Brooke and Stacey break down what changed for joint ventures, paper-only CUI, significant change triggers, and how MSPs and MSSPs actually fit into assessment scope.</p><p>If you&apos;re navigating a merger, working with subcontractors, or relying on an MSP to manage your environment, this episode clears up exactly where you stand — and where you don&apos;t.</p><p><br/></p><p><b>📌 What You&apos;ll Learn:</b></p><ul><li>Why joint ventures do NOT automatically inherit a company&apos;s CMMC certification status</li><li>The new guidance on paper-only CUI — and when it does NOT require Level 2 assessment</li><li>What actually counts as a &quot;significant change&quot; that triggers reassessment (mergers, system consolidation, and more)</li><li>Why MSPs don&apos;t need their own CMMC certification — but still carry major assessment responsibilities</li><li>The difference between CUI scope and Security Protection Data (SPD) scope for MSPs/MSSPs</li><li>The five-part test for whether an MSP counts as a Cloud Service Provider (CSP)</li><li><b>Listener Q&amp;A:</b> Do subcontractors need cybersecurity training and screening too?</li></ul><p><br/></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/19363239-new-cmmc-faq-clarifications-joint-ventures-paper-only-cui-reassessment-triggers-where-msps-actually-fit-in-scope.mp3" length="14234145" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-19363239</guid>
    <pubDate>Fri, 19 Jun 2026 06:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/19363239/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/19363239/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/19363239/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/19363239/transcript.vtt" type="text/vtt" />
    <podcast:chapters url="https://www.buzzsprout.com/2428223/19363239/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Welcome And What’s Changing" />
  <psc:chapter start="1:33" title="Joint Ventures Don’t Inherit Certification" />
  <psc:chapter start="3:33" title="Paper-Only CUI And Assessment Rules" />
  <psc:chapter start="5:55" title="Significant Changes And Reassessment Triggers" />
  <psc:chapter start="8:53" title="MSPs In Scope Without Certification" />
  <psc:chapter start="12:20" title="MSSPs, SPD, And Security Tool Scope" />
  <psc:chapter start="15:25" title="When An MSP Is Not A CSP" />
  <psc:chapter start="17:24" title="Subcontractor Access And Required Training" />
  <psc:chapter start="19:34" title="Wrap Up And How To Send Questions" />
</psc:chapters>
    <itunes:duration>1184</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>62</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>The CMMC Reality Check: Gap Assessments, Documentation Overload &amp; Why 30-Day Compliance Claims Are a Red Flag</itunes:title>
    <title>The CMMC Reality Check: Gap Assessments, Documentation Overload &amp; Why 30-Day Compliance Claims Are a Red Flag</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! Most defense contractors don't realize how complex CMMC compliance really is until they're already in trouble. In this episode, Brooke and Stacey break down the exact moments where contractors hit their wake-up call, what to expect from a gap assessment, and why waiting until the last minute could cost you your DoD contracts. Whether you're just starting your CMMC journey or think you're close to ready, this episode will show you wh...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>Most defense contractors don&apos;t realize how complex CMMC compliance really is until they&apos;re already in trouble. In this episode, Brooke and Stacey break down the exact moments where contractors hit their wake-up call, what to expect from a gap assessment, and why waiting until the last minute could cost you your DoD contracts.</p><p>Whether you&apos;re just starting your CMMC journey or think you&apos;re close to ready, this episode will show you what you&apos;re probably missing and how to get ahead of it.</p> ]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>Most defense contractors don&apos;t realize how complex CMMC compliance really is until they&apos;re already in trouble. In this episode, Brooke and Stacey break down the exact moments where contractors hit their wake-up call, what to expect from a gap assessment, and why waiting until the last minute could cost you your DoD contracts.</p><p>Whether you&apos;re just starting your CMMC journey or think you&apos;re close to ready, this episode will show you what you&apos;re probably missing and how to get ahead of it.</p> ]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/19320468-the-cmmc-reality-check-gap-assessments-documentation-overload-why-30-day-compliance-claims-are-a-red-flag.mp3" length="20264225" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-19320468</guid>
    <pubDate>Fri, 12 Jun 2026 06:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/19320468/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/19320468/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/19320468/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/19320468/transcript.vtt" type="text/vtt" />
    <podcast:chapters url="https://www.buzzsprout.com/2428223/19320468/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="The CMMC Reality Check: Gap Assessments, Documentation Overload &amp; Why 30-Day Compliance Claims Are a Red Flag" />
  <psc:chapter start="0:42" title="Welcome And Today’s Warning" />
  <psc:chapter start="1:34" title="Gap Assessments Reveal Missing Controls" />
  <psc:chapter start="3:23" title="Mapping CUI Turns Into Spaghetti" />
  <psc:chapter start="5:12" title="Documentation Becomes The Real Work" />
  <psc:chapter start="8:48" title="CMMC Is A Business Problem" />
  <psc:chapter start="10:25" title="Tools And Enclaves Can Mislead" />
  <psc:chapter start="13:55" title="Realistic Timelines And Hidden Time Sinks" />
  <psc:chapter start="20:09" title="Legal Risk And The False Claims Act" />
  <psc:chapter start="21:38" title="Biggest Takeaway And Do Not Wait" />
  <psc:chapter start="24:57" title="Listener Question On Windows Upgrades" />
  <psc:chapter start="28:01" title="How To Send Questions And Subscribe" />
</psc:chapters>
    <itunes:duration>1686</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>61</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>CS5 West 2026 CMMC Recap for Defense Contractor</itunes:title>
    <title>CS5 West 2026 CMMC Recap for Defense Contractor</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! In this episode of the CMMC Compliance Guide Podcast, Brooke breaks down the biggest takeaways from CS5 West 2026, one of the largest conferences in the CMMC ecosystem. The biggest message from the conference was clear: CMMC is no longer theoretical. Assessments are happening now, companies are already getting certified, and many contractors are running out of time to prepare before Phase 2 requirements begin appearing on contracts....]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>In this episode of the CMMC Compliance Guide Podcast, Brooke breaks down the biggest takeaways from CS5 West 2026, one of the largest conferences in the CMMC ecosystem.</p><p>The biggest message from the conference was clear: CMMC is no longer theoretical. Assessments are happening now, companies are already getting certified, and many contractors are running out of time to prepare before Phase 2 requirements begin appearing on contracts.</p><p>We discuss what assessors are seeing during mock and certification assessments, why documentation continues to be one of the biggest failure points, and why scoping mistakes are still creating major problems for manufacturers and defense contractors.</p><p>We also cover:</p><ul><li> Why small contractors are struggling with implementation </li><li> How primes are pressuring subcontractors to get certified early </li><li> Why enclave strategies are often misunderstood </li><li> The ongoing debate around G-code and CUI </li><li> Why continuous compliance matters after certification </li><li> The importance of mock assessments </li><li> How False Claims Act risk ties into annual affirmations </li></ul><p>If you are a defense contractor trying to understand where CMMC enforcement is heading and what the industry is seeing right now, this episode gives you a practical, real-world update from inside the ecosystem.</p> ]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>In this episode of the CMMC Compliance Guide Podcast, Brooke breaks down the biggest takeaways from CS5 West 2026, one of the largest conferences in the CMMC ecosystem.</p><p>The biggest message from the conference was clear: CMMC is no longer theoretical. Assessments are happening now, companies are already getting certified, and many contractors are running out of time to prepare before Phase 2 requirements begin appearing on contracts.</p><p>We discuss what assessors are seeing during mock and certification assessments, why documentation continues to be one of the biggest failure points, and why scoping mistakes are still creating major problems for manufacturers and defense contractors.</p><p>We also cover:</p><ul><li> Why small contractors are struggling with implementation </li><li> How primes are pressuring subcontractors to get certified early </li><li> Why enclave strategies are often misunderstood </li><li> The ongoing debate around G-code and CUI </li><li> Why continuous compliance matters after certification </li><li> The importance of mock assessments </li><li> How False Claims Act risk ties into annual affirmations </li></ul><p>If you are a defense contractor trying to understand where CMMC enforcement is heading and what the industry is seeing right now, this episode gives you a practical, real-world update from inside the ecosystem.</p> ]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/19177053-cs5-west-2026-cmmc-recap-for-defense-contractor.mp3" length="21272530" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-19177053</guid>
    <pubDate>Fri, 29 May 2026 06:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/19177053/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/19177053/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/19177053/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/19177053/transcript.vtt" type="text/vtt" />
    <podcast:chapters url="https://www.buzzsprout.com/2428223/19177053/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Welcome And Why CS5 Matters" />
  <psc:chapter start="1:28" title="CMMC Moves From Theory To Reality" />
  <psc:chapter start="4:31" title="Phase Deadlines And The Time Crunch" />
  <psc:chapter start="9:12" title="Scope Mistakes And Enclave Myths" />
  <psc:chapter start="12:19" title="CMMC Is A Business Change" />
  <psc:chapter start="14:09" title="Continuous Compliance And Ongoing Evidence" />
  <psc:chapter start="16:44" title="Mock Assessments And Documentation Gaps" />
  <psc:chapter start="21:51" title="G-Code Debate And Defining CUI" />
  <psc:chapter start="24:29" title="Annual Affirmations And False Claims Risk" />
  <psc:chapter start="26:53" title="The One Takeaway: Do Not Wait" />
  <psc:chapter start="29:27" title="How To Send Questions And Subscribe" />
</psc:chapters>
    <itunes:duration>1770</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>60</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>How Small Defense Contractors Can Handle CMMC Compliance</itunes:title>
    <title>How Small Defense Contractors Can Handle CMMC Compliance</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! In this episode of the CMMC Compliance Guide Podcast, we tackle one of the biggest challenges in the Defense Industrial Base: how small contractors without internal IT teams are realistically handling CMMC compliance. Many small manufacturers, machine shops, and defense suppliers feel overwhelmed by CMMC because they do not have dedicated cybersecurity, compliance, or IT security staff. Instead, employees wear multiple hats while tr...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>In this episode of the CMMC Compliance Guide Podcast, we tackle one of the biggest challenges in the Defense Industrial Base: how small contractors without internal IT teams are realistically handling CMMC compliance.</p><p>Many small manufacturers, machine shops, and defense suppliers feel overwhelmed by CMMC because they do not have dedicated cybersecurity, compliance, or IT security staff. Instead, employees wear multiple hats while trying to keep daily operations moving.</p><p>We break down what compliance actually looks like for smaller contractors, what can realistically be outsourced, what responsibilities still stay with the company, and why buying tools like Microsoft 365 GCC High does not automatically make you compliant.</p><p>We also explain why data flow mapping and scope are critical, how shared responsibility matrices work with MSPs and MSSPs, and the biggest mistakes smaller companies make when trying to shortcut compliance.</p><p>If you are a small or mid-sized defense contractor trying to understand how to approach CMMC without a massive budget or internal compliance department, this episode will help you build a realistic roadmap.</p> ]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>In this episode of the CMMC Compliance Guide Podcast, we tackle one of the biggest challenges in the Defense Industrial Base: how small contractors without internal IT teams are realistically handling CMMC compliance.</p><p>Many small manufacturers, machine shops, and defense suppliers feel overwhelmed by CMMC because they do not have dedicated cybersecurity, compliance, or IT security staff. Instead, employees wear multiple hats while trying to keep daily operations moving.</p><p>We break down what compliance actually looks like for smaller contractors, what can realistically be outsourced, what responsibilities still stay with the company, and why buying tools like Microsoft 365 GCC High does not automatically make you compliant.</p><p>We also explain why data flow mapping and scope are critical, how shared responsibility matrices work with MSPs and MSSPs, and the biggest mistakes smaller companies make when trying to shortcut compliance.</p><p>If you are a small or mid-sized defense contractor trying to understand how to approach CMMC without a massive budget or internal compliance department, this episode will help you build a realistic roadmap.</p> ]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/19171170-how-small-defense-contractors-can-handle-cmmc-compliance.mp3" length="28650821" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-19171170</guid>
    <pubDate>Fri, 22 May 2026 06:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/19171170/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/19171170/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/19171170/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/19171170/transcript.vtt" type="text/vtt" />
    <podcast:chapters url="https://www.buzzsprout.com/2428223/19171170/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Welcome And The Small Business Problem" />
  <psc:chapter start="1:50" title="Why CMMC Hits Small Teams Hard" />
  <psc:chapter start="4:57" title="The GCC High Tool Trap" />
  <psc:chapter start="9:42" title="Identify CUI And Map Data Flow" />
  <psc:chapter start="10:12" title="What You Can Outsource Safely" />
  <psc:chapter start="13:14" title="Shared Responsibility Matrix Basics" />
  <psc:chapter start="19:43" title="Cut Costs By Shrinking Scope" />
  <psc:chapter start="24:28" title="Common Mistakes And What Works" />
  <psc:chapter start="34:00" title="Measure Twice Cut Once Mindset" />
  <psc:chapter start="37:16" title="Biggest Takeaway And How To Get Help" />
</psc:chapters>
    <itunes:duration>2385</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>59</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Why Contractors Fail CMMC Assessments and How to Prepare</itunes:title>
    <title>Why Contractors Fail CMMC Assessments and How to Prepare</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! In this episode of the CMMC Compliance Guide Podcast, we break down one of the most frustrating realities for defense contractors thinking you are ready for a CMMC assessment, only to find out you are not. Many companies believe they are compliant because they have security tools in place, policies written, and even a high SPRS score. But when assessors actually evaluate the environment, major gaps often appear. We explain why this ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>In this episode of the CMMC Compliance Guide Podcast, we break down one of the most frustrating realities for defense contractors thinking you are ready for a CMMC assessment, only to find out you are not.</p><p>Many companies believe they are compliant because they have security tools in place, policies written, and even a high SPRS score. But when assessors actually evaluate the environment, major gaps often appear.</p><p>We explain why this happens, how C3PAOs actually assess your environment, and what separates companies that pass their CMMC Level 2 assessment from those that fall short.</p><p>You will learn how assessors use examine, interview, and test methods, why the 320 assessment objectives matter more than the 110 controls, and how small documentation inconsistencies can lead to failed controls.</p><p>We also cover the importance of mock assessments, why your evidence package is critical, and how scope decisions can dramatically impact your assessment outcome.</p><p>If you are preparing for a CMMC assessment, or think you are ready, this episode will help you avoid costly surprises and approach your assessment with confidence.</p> ]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>In this episode of the CMMC Compliance Guide Podcast, we break down one of the most frustrating realities for defense contractors thinking you are ready for a CMMC assessment, only to find out you are not.</p><p>Many companies believe they are compliant because they have security tools in place, policies written, and even a high SPRS score. But when assessors actually evaluate the environment, major gaps often appear.</p><p>We explain why this happens, how C3PAOs actually assess your environment, and what separates companies that pass their CMMC Level 2 assessment from those that fall short.</p><p>You will learn how assessors use examine, interview, and test methods, why the 320 assessment objectives matter more than the 110 controls, and how small documentation inconsistencies can lead to failed controls.</p><p>We also cover the importance of mock assessments, why your evidence package is critical, and how scope decisions can dramatically impact your assessment outcome.</p><p>If you are preparing for a CMMC assessment, or think you are ready, this episode will help you avoid costly surprises and approach your assessment with confidence.</p> ]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/19121676-why-contractors-fail-cmmc-assessments-and-how-to-prepare.mp3" length="28489291" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-19121676</guid>
    <pubDate>Fri, 15 May 2026 06:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/19121676/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/19121676/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/19121676/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/19121676/transcript.vtt" type="text/vtt" />
    <podcast:chapters url="https://www.buzzsprout.com/2428223/19121676/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Welcome And The Big Surprise" />
  <psc:chapter start="1:11" title="Why Confidence Collapses In Assessments" />
  <psc:chapter start="6:08" title="The Evidence Package Wake Up Call" />
  <psc:chapter start="7:21" title="How Assessors Examine Interview Test" />
  <psc:chapter start="10:14" title="Why Objectives Matter More" />
  <psc:chapter start="14:15" title="Making Mocks Actually Useful" />
  <psc:chapter start="17:30" title="Who To Hire And When" />
  <psc:chapter start="21:24" title="Documentation That Fails On Review" />
  <psc:chapter start="26:03" title="SPRS Scores Versus Real Readiness" />
  <psc:chapter start="27:09" title="Scope Decisions That Change Everything" />
  <psc:chapter start="32:21" title="What Separates 110 From 109" />
  <psc:chapter start="39:19" title="Wrap Up And How To Reach Us" />
</psc:chapters>
    <itunes:duration>2371</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>58</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Top CMMC Compliance Mistakes and How to Avoid Them</itunes:title>
    <title>Top CMMC Compliance Mistakes and How to Avoid Them</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! In this episode of the CMMC Compliance Guide Podcast, we break down the most common mistakes defense contractors make when preparing for CMMC compliance and how those mistakes can cost you time, money, and even future contracts. Even though CMMC 2.0 is now enforceable, many companies are still struggling with readiness. The issue is not effort, it is approach. Many contractors start in the wrong place, leading to overspending, faile...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>In this episode of the CMMC Compliance Guide Podcast, we break down the most common mistakes defense contractors make when preparing for CMMC compliance and how those mistakes can cost you time, money, and even future contracts.</p><p>Even though CMMC 2.0 is now enforceable, many companies are still struggling with readiness. The issue is not effort, it is approach. Many contractors start in the wrong place, leading to overspending, failed assessments, or compliance gaps that could have been avoided.</p><p>We cover critical topics like scoping mistakes, why treating CMMC as an IT-only project creates problems, and how focusing on tools too early can lead to unnecessary costs. We also explain why documentation and ongoing evidence are essential for passing an assessment and building trust with assessors.</p><p>You will also learn why submitting an inaccurate SPRS score can create serious legal risk, how long CMMC actually takes to implement, and why waiting too long to start can put your contracts in jeopardy.</p><p>If you are a small or mid-sized contractor in the defense industrial base, this episode will help you avoid the most common pitfalls and take a smarter approach to compliance.</p> ]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>In this episode of the CMMC Compliance Guide Podcast, we break down the most common mistakes defense contractors make when preparing for CMMC compliance and how those mistakes can cost you time, money, and even future contracts.</p><p>Even though CMMC 2.0 is now enforceable, many companies are still struggling with readiness. The issue is not effort, it is approach. Many contractors start in the wrong place, leading to overspending, failed assessments, or compliance gaps that could have been avoided.</p><p>We cover critical topics like scoping mistakes, why treating CMMC as an IT-only project creates problems, and how focusing on tools too early can lead to unnecessary costs. We also explain why documentation and ongoing evidence are essential for passing an assessment and building trust with assessors.</p><p>You will also learn why submitting an inaccurate SPRS score can create serious legal risk, how long CMMC actually takes to implement, and why waiting too long to start can put your contracts in jeopardy.</p><p>If you are a small or mid-sized contractor in the defense industrial base, this episode will help you avoid the most common pitfalls and take a smarter approach to compliance.</p> ]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/19121433-top-cmmc-compliance-mistakes-and-how-to-avoid-them.mp3" length="49168596" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-19121433</guid>
    <pubDate>Fri, 08 May 2026 06:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/19121433/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/19121433/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/19121433/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/19121433/transcript.vtt" type="text/vtt" />
    <podcast:chapters url="https://www.buzzsprout.com/2428223/19121433/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Welcome And What’s At Stake" />
  <psc:chapter start="1:54" title="Scope Starts With Data Flows" />
  <psc:chapter start="6:26" title="Why “Enclave” Misleads Teams" />
  <psc:chapter start="14:18" title="CMMC Is Not Just IT" />
  <psc:chapter start="21:44" title="Evidence That Builds Assessor Trust" />
  <psc:chapter start="27:11" title="Tools Come After The Controls" />
  <psc:chapter start="32:52" title="Buying GCC High Is Not Compliance" />
  <psc:chapter start="39:30" title="Start Now Or Miss Deadlines" />
  <psc:chapter start="45:25" title="SPRS Scores And False Claims Risk" />
  <psc:chapter start="51:41" title="CMMC Applies To Subs Too" />
  <psc:chapter start="56:20" title="Why Seemingly Small Data Matters" />
  <psc:chapter start="1:04:36" title="Level One Controls Listener Question" />
  <psc:chapter start="1:08:08" title="Free Help And Closing" />
</psc:chapters>
    <itunes:duration>4095</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>57</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Can You Create CUI? CMMC Scope, ERP Systems, and Contractor Risk Explained</itunes:title>
    <title>Can You Create CUI? CMMC Scope, ERP Systems, and Contractor Risk Explained</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! In this episode of the CMMC Compliance Guide Podcast, we tackle one of the most misunderstood topics in CMMC compliance. Many contractors assume that if information is not marked as controlled unclassified information, then it is not CUI. But that assumption can lead to serious compliance risks. We break down how manufacturers and machine shops can actually create CUI while performing contract work, even if the original data was not...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>In this episode of the CMMC Compliance Guide Podcast, we tackle one of the most misunderstood topics in CMMC compliance.</p><p>Many contractors assume that if information is not marked as controlled unclassified information, then it is not CUI. But that assumption can lead to serious compliance risks.</p><p>We break down how manufacturers and machine shops can actually create CUI while performing contract work, even if the original data was not clearly marked.</p><p>We also cover how ERP systems factor into CMMC scope, when systems are considered in or out of scope, and how improper scoping decisions can create major compliance gaps.</p><p>You will learn what derived CUI is, how it applies to things like CNC G code, and why simply removing identifying details from documents does not make them safe.</p><p>We also explain who determines what qualifies as CUI, how scope can expand across your network, and what realistic cost and infrastructure decisions look like for small and mid sized contractors.</p><p>If you are part of the defense supply chain, this episode will help you avoid one of the most common and costly misunderstandings in CMMC.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>In this episode of the CMMC Compliance Guide Podcast, we tackle one of the most misunderstood topics in CMMC compliance.</p><p>Many contractors assume that if information is not marked as controlled unclassified information, then it is not CUI. But that assumption can lead to serious compliance risks.</p><p>We break down how manufacturers and machine shops can actually create CUI while performing contract work, even if the original data was not clearly marked.</p><p>We also cover how ERP systems factor into CMMC scope, when systems are considered in or out of scope, and how improper scoping decisions can create major compliance gaps.</p><p>You will learn what derived CUI is, how it applies to things like CNC G code, and why simply removing identifying details from documents does not make them safe.</p><p>We also explain who determines what qualifies as CUI, how scope can expand across your network, and what realistic cost and infrastructure decisions look like for small and mid sized contractors.</p><p>If you are part of the defense supply chain, this episode will help you avoid one of the most common and costly misunderstandings in CMMC.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/18994599-can-you-create-cui-cmmc-scope-erp-systems-and-contractor-risk-explained.mp3" length="12747884" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18994599</guid>
    <pubDate>Fri, 17 Apr 2026 06:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18994599/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18994599/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18994599/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18994599/transcript.vtt" type="text/vtt" />
    <podcast:chapters url="https://www.buzzsprout.com/2428223/18994599/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Welcome And The CUI Trap" />
  <psc:chapter start="1:50" title="ERP Systems And CMMC Scope" />
  <psc:chapter start="3:38" title="Using An Enclave To Isolate CUI" />
  <psc:chapter start="5:26" title="Drawings Are Not The Whole Story" />
  <psc:chapter start="9:19" title="Derived CUI Like CNC G Code" />
  <psc:chapter start="10:37" title="Who Decides What Is CUI" />
  <psc:chapter start="11:58" title="When One System Expands Scope" />
  <psc:chapter start="12:46" title="Cost Reality And Upgrade Decisions" />
  <psc:chapter start="16:09" title="Compliant Cloud Options For ERP" />
  <psc:chapter start="17:33" title="Free Help And How To Reach Us" />
</psc:chapters>
    <itunes:duration>1060</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>56</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>The Hidden Operational Workload Behind CMMC Compliance</itunes:title>
    <title>The Hidden Operational Workload Behind CMMC Compliance</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! In this episode of the CMMC Compliance Guide Podcast, we break down one of the biggest misconceptions in CMMC compliance. Most contractors think CMMC is just a cybersecurity upgrade. Install a few tools, write some policies, and you are ready for an assessment. But that is not how CMMC actually works. The real challenge is the operational workload behind compliance. We walk through what that workload actually looks like, including d...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>In this episode of the CMMC Compliance Guide Podcast, we break down one of the biggest misconceptions in CMMC compliance.</p><p>Most contractors think CMMC is just a cybersecurity upgrade. Install a few tools, write some policies, and you are ready for an assessment. But that is not how CMMC actually works.</p><p>The real challenge is the operational workload behind compliance.</p><p>We walk through what that workload actually looks like, including documentation, system security plans, asset management, workforce training, evidence collection, and continuous monitoring. These are the areas that consume the most time and are often underestimated by small and mid sized defense contractors.</p><p>We also cover how CMMC impacts your supply chain, including subcontractor flowdown requirements and what you are responsible for as a prime or subcontractor.</p><p>If you are preparing for CMMC Level 1 or Level 2, this episode will help you understand the true scope of work so you can avoid delays, failed assessments, and costly surprises.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>In this episode of the CMMC Compliance Guide Podcast, we break down one of the biggest misconceptions in CMMC compliance.</p><p>Most contractors think CMMC is just a cybersecurity upgrade. Install a few tools, write some policies, and you are ready for an assessment. But that is not how CMMC actually works.</p><p>The real challenge is the operational workload behind compliance.</p><p>We walk through what that workload actually looks like, including documentation, system security plans, asset management, workforce training, evidence collection, and continuous monitoring. These are the areas that consume the most time and are often underestimated by small and mid sized defense contractors.</p><p>We also cover how CMMC impacts your supply chain, including subcontractor flowdown requirements and what you are responsible for as a prime or subcontractor.</p><p>If you are preparing for CMMC Level 1 or Level 2, this episode will help you understand the true scope of work so you can avoid delays, failed assessments, and costly surprises.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/18988955-the-hidden-operational-workload-behind-cmmc-compliance.mp3" length="12891469" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18988955</guid>
    <pubDate>Fri, 10 Apr 2026 06:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18988955/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18988955/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18988955/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18988955/transcript.vtt" type="text/vtt" />
    <podcast:chapters url="https://www.buzzsprout.com/2428223/18988955/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="The Hidden Operational Workload Behind CMMC Compliance" />
  <psc:chapter start="0:42" title="Welcome And What To Expect" />
  <psc:chapter start="1:07" title="The Hidden Operational Workload" />
  <psc:chapter start="1:53" title="Why IT Upgrade Thinking Fails" />
  <psc:chapter start="3:10" title="SSP Documentation Tells The Story" />
  <psc:chapter start="5:07" title="Asset Scoping Gets Complicated Fast" />
  <psc:chapter start="6:21" title="Training Beyond Basic Awareness" />
  <psc:chapter start="8:25" title="Evidence Collection And AI Caution" />
  <psc:chapter start="12:15" title="Compliance Never Truly Ends" />
  <psc:chapter start="13:36" title="Supply Chain Flowdown To Subcontractors" />
  <psc:chapter start="17:46" title="How To Reach Us And Subscribe" />
</psc:chapters>
    <itunes:duration>1072</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>55</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>CMMC Reassessments Explained: What Changes Trigger a New Assessment</itunes:title>
    <title>CMMC Reassessments Explained: What Changes Trigger a New Assessment</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! In this episode of the CMMC Compliance Guide Podcast, we break down one of the most overlooked risks in CMMC compliance. What actually happens when your environment changes after an assessment? Many contractors assume that once they pass a CMMC assessment or complete a self assessment, they are set for the next year or even three years. But recent guidance from the Cyber AB town hall reveals that certain changes can trigger a brand ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>In this episode of the CMMC Compliance Guide Podcast, we break down one of the most overlooked risks in CMMC compliance. What actually happens when your environment changes after an assessment?</p><p>Many contractors assume that once they pass a CMMC assessment or complete a self assessment, they are set for the next year or even three years. But recent guidance from the Cyber AB town hall reveals that certain changes can trigger a brand new assessment.</p><p>We walk through what qualifies as a significant change, what does not, and how decisions are made when things fall into the gray area. We also cover real examples like mergers, switching MSPs, expanding networks, and upgrading tools.</p><p>If you are planning changes to your environment or trying to future proof your compliance strategy, this episode will help you avoid costly mistakes and unnecessary reassessments.</p><p>We also answer a listener question about how to identify FCI and how it should be handled under CMMC Level 1 requirements.</p><p>If you are a small or mid sized defense contractor, aerospace supplier, or manufacturer, this is critical guidance you do not want to miss.</p> ]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>In this episode of the CMMC Compliance Guide Podcast, we break down one of the most overlooked risks in CMMC compliance. What actually happens when your environment changes after an assessment?</p><p>Many contractors assume that once they pass a CMMC assessment or complete a self assessment, they are set for the next year or even three years. But recent guidance from the Cyber AB town hall reveals that certain changes can trigger a brand new assessment.</p><p>We walk through what qualifies as a significant change, what does not, and how decisions are made when things fall into the gray area. We also cover real examples like mergers, switching MSPs, expanding networks, and upgrading tools.</p><p>If you are planning changes to your environment or trying to future proof your compliance strategy, this episode will help you avoid costly mistakes and unnecessary reassessments.</p><p>We also answer a listener question about how to identify FCI and how it should be handled under CMMC Level 1 requirements.</p><p>If you are a small or mid sized defense contractor, aerospace supplier, or manufacturer, this is critical guidance you do not want to miss.</p> ]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/18950607-cmmc-reassessments-explained-what-changes-trigger-a-new-assessment.mp3" length="36044269" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18950607</guid>
    <pubDate>Fri, 03 Apr 2026 06:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18950607/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18950607/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18950607/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18950607/transcript.vtt" type="text/vtt" />
    <podcast:chapters url="https://www.buzzsprout.com/2428223/18950607/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Welcome And Town Hall Updates" />
  <psc:chapter start="2:26" title="When Changes Trigger Reassessment" />
  <psc:chapter start="5:41" title="What Counts As Significant Change" />
  <psc:chapter start="14:20" title="Mergers Networks MSP Swaps" />
  <psc:chapter start="18:35" title="Normal Operations That Stay Safe" />
  <psc:chapter start="22:55" title="Who Decides And Legal Risk" />
  <psc:chapter start="28:10" title="Plan Scope So You Don’t Stall" />
  <psc:chapter start="33:20" title="Getting Outside Guidance Without Conflicts" />
  <psc:chapter start="36:50" title="Annual Affirmations And Ongoing Accountability" />
  <psc:chapter start="40:35" title="FAR CUI Rule And Paper CUI" />
  <psc:chapter start="43:40" title="Listener Question How To Spot FCI" />
  <psc:chapter start="49:40" title="Wrap Up And How To Contact Us" />
</psc:chapters>
    <itunes:duration>3001</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>54</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>How Prime Contractors Evaluate Supplier Cybersecurity and CMMC Compliance</itunes:title>
    <title>How Prime Contractors Evaluate Supplier Cybersecurity and CMMC Compliance</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! What are prime contractors actually expecting from suppliers when it comes to CMMC and cybersecurity? In this episode of the CMMC Compliance Guide Podcast, Austin and Brooke sit down with Bo Birdwell from Elbit Systems of America to get the prime contractor perspective on what suppliers need to understand right now. They break down how primes are thinking about CMMC, what they are looking for in small and mid-sized defense suppliers...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>What are prime contractors actually expecting from suppliers when it comes to CMMC and cybersecurity?</p><p>In this episode of the CMMC Compliance Guide Podcast, Austin and Brooke sit down with Bo Birdwell from Elbit Systems of America to get the prime contractor perspective on what suppliers need to understand right now. They break down how primes are thinking about CMMC, what they are looking for in small and mid-sized defense suppliers, and why some companies are about to hit a major inflection point if they are still treating CMMC like it is optional.</p><p>Bo shares how Elbit evaluates supplier cybersecurity posture, the red flags that stand out immediately, and why companies that wait too long may not lose the bus forever, but they may lose their place in line. The conversation also covers flowdown realities, the difference between FCI and CUI risk, why COTS matters, what “adequate security” is really about, and why suppliers need to start making serious decisions now if they want to keep or win defense work.</p><p>If you are a machine shop, aerospace supplier, manufacturer, subcontractor, or small business in the defense industrial base trying to understand how primes view CMMC readiness, this episode gives you a rare inside look at the other side of the table.</p> ]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>What are prime contractors actually expecting from suppliers when it comes to CMMC and cybersecurity?</p><p>In this episode of the CMMC Compliance Guide Podcast, Austin and Brooke sit down with Bo Birdwell from Elbit Systems of America to get the prime contractor perspective on what suppliers need to understand right now. They break down how primes are thinking about CMMC, what they are looking for in small and mid-sized defense suppliers, and why some companies are about to hit a major inflection point if they are still treating CMMC like it is optional.</p><p>Bo shares how Elbit evaluates supplier cybersecurity posture, the red flags that stand out immediately, and why companies that wait too long may not lose the bus forever, but they may lose their place in line. The conversation also covers flowdown realities, the difference between FCI and CUI risk, why COTS matters, what “adequate security” is really about, and why suppliers need to start making serious decisions now if they want to keep or win defense work.</p><p>If you are a machine shop, aerospace supplier, manufacturer, subcontractor, or small business in the defense industrial base trying to understand how primes view CMMC readiness, this episode gives you a rare inside look at the other side of the table.</p> ]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/18879669-how-prime-contractors-evaluate-supplier-cybersecurity-and-cmmc-compliance.mp3" length="31071110" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18879669</guid>
    <pubDate>Fri, 27 Mar 2026 06:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18879669/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18879669/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18879669/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18879669/transcript.vtt" type="text/vtt" />
    <podcast:chapters url="https://www.buzzsprout.com/2428223/18879669/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Welcome And Guest Introduction" />
  <psc:chapter start="3:51" title="Bo’s Role Inside Elbit" />
  <psc:chapter start="8:01" title="From Air Force To Cyber Risk" />
  <psc:chapter start="11:35" title="Why CMMC Became Nonnegotiable" />
  <psc:chapter start="16:45" title="The Inflection Point Suppliers Miss" />
  <psc:chapter start="22:25" title="What CMMC Is Really For" />
  <psc:chapter start="27:50" title="How Ready The Supply Chain Is" />
  <psc:chapter start="32:05" title="Supplier Signals And Red Flags" />
  <psc:chapter start="37:35" title="Flowdown, COTS, And Data Sharing" />
  <psc:chapter start="41:05" title="Where To Start And Next Steps" />
</psc:chapters>
    <itunes:duration>2587</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>53</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
    <podcast:person role="guest" href="https://www.linkedin.com/in/bobirdwell/" img="https://storage.buzzsprout.com/q3i8gmwz6y1oa2g0w3c97tvg49xa">Bo Birdwell</podcast:person>
    <podcast:person role="host" href="https://linktr.ee/brookejustice" img="https://storage.buzzsprout.com/0t4gofoq0w3hcy0kjdyjor27f42u">Brooke Justice</podcast:person>
    <podcast:person role="co-host" href="https://linktr.ee/austinjustice" img="https://storage.buzzsprout.com/3a34tkangozy1dx307qq2okottyx">Austin Justice</podcast:person>
    <podcast:person role="co-host" href="https://www.linkedin.com/in/stacey-f-82b45a232/" img="https://storage.buzzsprout.com/txgrwq5bir2dpexrgoskmnkp1fyg">Stacey Flores</podcast:person>
  </item>
  <item>
    <itunes:title>CMMC Supplier Questions Answered: Level 1 vs Level 2, Costs, Scope, and Flowdown for DoW Contractors</itunes:title>
    <title>CMMC Supplier Questions Answered: Level 1 vs Level 2, Costs, Scope, and Flowdown for DoW Contractors</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! What do small machine shops, aerospace suppliers, and defense manufacturers really need to know about CMMC right now? In this episode of the CMMC Compliance Guide Podcast, Austin and Brooke answer some of the most common supplier questions they hear from companies trying to prepare for CMMC compliance. They break down how small suppliers can plan when contract requirements are still unclear, what level of compliance may be needed, h...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>What do small machine shops, aerospace suppliers, and defense manufacturers really need to know about CMMC right now?</p><p>In this episode of the CMMC Compliance Guide Podcast, Austin and Brooke answer some of the most common supplier questions they hear from companies trying to prepare for CMMC compliance. They break down how small suppliers can plan when contract requirements are still unclear, what level of compliance may be needed, how far requirements flow down the supply chain, and why scope matters so much when building your compliance strategy.</p><p>They also explain common myths around redacted drawings, whether tools alone can make you compliant, what CMMC actually costs, whether small companies can do CMMC themselves, how big the jump is from Level 1 to Level 2, and what happens when CMMC becomes mandatory on contracts. If you are a DoW supplier, subcontractor, aerospace machine shop, or manufacturer trying to understand how CMMC will affect your business, this episode will help you cut through the confusion</p> ]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>What do small machine shops, aerospace suppliers, and defense manufacturers really need to know about CMMC right now?</p><p>In this episode of the CMMC Compliance Guide Podcast, Austin and Brooke answer some of the most common supplier questions they hear from companies trying to prepare for CMMC compliance. They break down how small suppliers can plan when contract requirements are still unclear, what level of compliance may be needed, how far requirements flow down the supply chain, and why scope matters so much when building your compliance strategy.</p><p>They also explain common myths around redacted drawings, whether tools alone can make you compliant, what CMMC actually costs, whether small companies can do CMMC themselves, how big the jump is from Level 1 to Level 2, and what happens when CMMC becomes mandatory on contracts. If you are a DoW supplier, subcontractor, aerospace machine shop, or manufacturer trying to understand how CMMC will affect your business, this episode will help you cut through the confusion</p> ]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/18857366-cmmc-supplier-questions-answered-level-1-vs-level-2-costs-scope-and-flowdown-for-dow-contractors.mp3" length="38085092" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18857366</guid>
    <pubDate>Fri, 20 Mar 2026 08:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18857366/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18857366/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18857366/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18857366/transcript.vtt" type="text/vtt" />
    <podcast:chapters url="https://www.buzzsprout.com/2428223/18857366/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="CMMC Supplier Questions Answered: Level 1 vs Level 2, Costs, Scope, and Flowdown for DoW Contractors" />
  <psc:chapter start="0:42" title="Welcome And What We Do" />
  <psc:chapter start="1:14" title="Rapid-Fire Supplier Questions" />
  <psc:chapter start="2:16" title="Planning Without Clear Flowdown" />
  <psc:chapter start="11:01" title="Upcoming Guests From Primes" />
  <psc:chapter start="13:43" title="Redaction Myths And G-Code Risk" />
  <psc:chapter start="20:05" title="Tools Help But Do Not Comply" />
  <psc:chapter start="24:07" title="What CMMC Really Costs" />
  <psc:chapter start="34:13" title="Can A Small Shop DIY" />
  <psc:chapter start="41:06" title="The Recurring Work And Evidence" />
  <psc:chapter start="43:30" title="Level One First Or Not" />
  <psc:chapter start="45:36" title="How Big The Level Jump Is" />
  <psc:chapter start="47:53" title="Policy Templates With Caution" />
  <psc:chapter start="50:37" title="When CMMC Turns Mandatory" />
  <psc:chapter start="52:41" title="How To Reach Us And Subscribe" />
</psc:chapters>
    <itunes:duration>3171</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>52</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>CMMC Level 1 Self-Attestation Explained: Requirements, Evidence, and Risk</itunes:title>
    <title>CMMC Level 1 Self-Attestation Explained: Requirements, Evidence, and Risk</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast!  lot of contractors assume CMMC Level 1 is just a simple checkbox. It is not. In this episode, Austin and Brooke break down what CMMC Level 1 actually requires, what a self-assessment really looks like, and why self-attestation without documentation can create serious risk. They cover the difference between Level 1 and Level 2, what Federal Contract Information (FCI) actually is, how Level 1 maps to the formal assessment proces...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p> lot of contractors assume CMMC Level 1 is just a simple checkbox. It is not.</p><p>In this episode, Austin and Brooke break down what CMMC Level 1 actually requires, what a self-assessment really looks like, and why self-attestation without documentation can create serious risk.</p><p>They cover the difference between Level 1 and Level 2, what Federal Contract Information (FCI) actually is, how Level 1 maps to the formal assessment process, and why organizations need policies, evidence, and artifacts before signing an attestation.</p><p>This episode also explains:</p><ul><li>What CMMC Level 1 covers and what it does not</li><li>Why Level 1 is always self-assessed, not C3PAO certified</li><li>The difference between self-assessment and self-attestation</li><li>What documentation and evidence should exist before attesting</li><li>Why authorized users, devices, processes, visitor logs, and physical access controls matter</li><li>What the CFR says about evidence retention</li><li>When a Level 1 claim may actually be scrutinized</li><li>How whistleblowers, breaches, or customer requests can trigger verification</li><li>The False Claims Act risk of saying you are compliant when you are not</li></ul><p>If you are planning to self-attest to CMMC Level 1, this episode will help you understand what the government expects before you sign your name to anything.</p> ]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p> lot of contractors assume CMMC Level 1 is just a simple checkbox. It is not.</p><p>In this episode, Austin and Brooke break down what CMMC Level 1 actually requires, what a self-assessment really looks like, and why self-attestation without documentation can create serious risk.</p><p>They cover the difference between Level 1 and Level 2, what Federal Contract Information (FCI) actually is, how Level 1 maps to the formal assessment process, and why organizations need policies, evidence, and artifacts before signing an attestation.</p><p>This episode also explains:</p><ul><li>What CMMC Level 1 covers and what it does not</li><li>Why Level 1 is always self-assessed, not C3PAO certified</li><li>The difference between self-assessment and self-attestation</li><li>What documentation and evidence should exist before attesting</li><li>Why authorized users, devices, processes, visitor logs, and physical access controls matter</li><li>What the CFR says about evidence retention</li><li>When a Level 1 claim may actually be scrutinized</li><li>How whistleblowers, breaches, or customer requests can trigger verification</li><li>The False Claims Act risk of saying you are compliant when you are not</li></ul><p>If you are planning to self-attest to CMMC Level 1, this episode will help you understand what the government expects before you sign your name to anything.</p> ]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/18835749-cmmc-level-1-self-attestation-explained-requirements-evidence-and-risk.mp3" length="31412114" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18835749</guid>
    <pubDate>Fri, 13 Mar 2026 06:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18835749/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18835749/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18835749/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18835749/transcript.vtt" type="text/vtt" />
    <podcast:chapters url="https://www.buzzsprout.com/2428223/18835749/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="CMMC Level 1 Self-Attestation Explained: Requirements, Evidence, and Risk" />
  <psc:chapter start="1:27" title="Is There A Formal Level 1 Assessment" />
  <psc:chapter start="2:31" title="Why People Misunderstand CMMC Level 1" />
  <psc:chapter start="3:46" title="What CMMC Level 1 Actually Covers" />
  <psc:chapter start="5:31" title="What FCI Means in Plain English" />
  <psc:chapter start="7:26" title="How Level 1 Compares to Level 2" />
  <psc:chapter start="10:55" title="Why People Assume Level 1 Needs a Third-Party Assessment" />
  <psc:chapter start="12:40" title="Walking Through the CFR and Level 1 Requirements" />
  <psc:chapter start="15:50" title="What Self-Assessment and Self-Attestation Really Mean" />
  <psc:chapter start="17:45" title="What Evidence Should Exist Before Signing" />
  <psc:chapter start="20:50" title="Access Control Examples and Authorized Users, Devices, and Processes" />
  <psc:chapter start="25:40" title="Physical Protection Examples Like Visitor Logs and Keys" />
  <psc:chapter start="29:40" title="Why Evidence Retention Matters for Six Years" />
  <psc:chapter start="31:50" title="Why Level 1 Still Matters If You Have a Level 2 Enclave" />
  <psc:chapter start="34:00" title="What a Mock Review for Level 1 Should Look Like" />
  <psc:chapter start="36:40" title="When Level 1 Claims May Actually Be Verified" />
  <psc:chapter start="38:55" title="Breaches, Whistleblowers, and Customer Verification Requests" />
  <psc:chapter start="40:50" title="False Claims Act Risk for Bad Self-Attestation" />
  <psc:chapter start="42:20" title="Final Takeaway" />
</psc:chapters>
    <itunes:duration>2615</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>51</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>CMMC Scoping 101: The Most Expensive Mistake Contractors Make (And How to Fix It)</itunes:title>
    <title>CMMC Scoping 101: The Most Expensive Mistake Contractors Make (And How to Fix It)</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! Scope is the foundation of your CMMC compliance program and getting it wrong is one of the most expensive mistakes a DoD contractor can make. In this episode, Austin and Brooke break down what “scope” actually means in plain English, why contractors skip scoping early on, and how one small miss, like a downloads folder or a USB handoff, can quietly pull major systems into scope. We cover: What CMMC scope really is, including process...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>Scope is the foundation of your CMMC compliance program and getting it wrong is one of the most expensive mistakes a DoD contractor can make.</p><p>In this episode, Austin and Brooke break down what “scope” actually means in plain English, why contractors skip scoping early on, and how one small miss, like a downloads folder or a USB handoff, can quietly pull major systems into scope.</p><p>We cover:</p><ul><li>What CMMC scope really is, including processed, stored, and transmitted CUI</li><li>Why contractors start with tools and policies too early</li><li>The data flow diagram exercise that reveals hidden scope issues</li><li>How scope mistakes turn into rework, delays, and major cost increases</li><li>Why “enclave” is often misunderstood and what it really means</li><li>What to do if you think you got scope wrong</li><li>How to self-check readiness using NIST 800-171A and the CMMC Assessment Process (CAP)</li><li>Why documentation and evidence, not just controls, become the real burden</li></ul><p>If you are planning for a Level 2 assessment, scope should be your first move, not your last-minute scramble.</p> ]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>Scope is the foundation of your CMMC compliance program and getting it wrong is one of the most expensive mistakes a DoD contractor can make.</p><p>In this episode, Austin and Brooke break down what “scope” actually means in plain English, why contractors skip scoping early on, and how one small miss, like a downloads folder or a USB handoff, can quietly pull major systems into scope.</p><p>We cover:</p><ul><li>What CMMC scope really is, including processed, stored, and transmitted CUI</li><li>Why contractors start with tools and policies too early</li><li>The data flow diagram exercise that reveals hidden scope issues</li><li>How scope mistakes turn into rework, delays, and major cost increases</li><li>Why “enclave” is often misunderstood and what it really means</li><li>What to do if you think you got scope wrong</li><li>How to self-check readiness using NIST 800-171A and the CMMC Assessment Process (CAP)</li><li>Why documentation and evidence, not just controls, become the real burden</li></ul><p>If you are planning for a Level 2 assessment, scope should be your first move, not your last-minute scramble.</p> ]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/18775293-cmmc-scoping-101-the-most-expensive-mistake-contractors-make-and-how-to-fix-it.mp3" length="26837602" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18775293</guid>
    <pubDate>Fri, 06 Mar 2026 06:00:00 -0600</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18775293/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18775293/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18775293/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18775293/transcript.vtt" type="text/vtt" />
    <itunes:duration>2234</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>50</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Key Takeaways from the January 2026 CMMC Town Hall: Hard Copy CUI, Scope, and Program Changes</itunes:title>
    <title>Key Takeaways from the January 2026 CMMC Town Hall: Hard Copy CUI, Scope, and Program Changes</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! The January 2026 CMMC Town Hall brought several important clarifications and program updates that directly impact Department of War (DoD) contractors. In this episode of the CMMC Compliance Guide Podcast, we break down what changed, what was clarified, and what contractors should take away from the latest guidance. We cover: New DOW CIO leadership changes and what they mean for CMMCUpdated clarification on Hard Copy CUI (and what qu...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>The January 2026 CMMC Town Hall brought several important clarifications and program updates that directly impact Department of War (DoD) contractors.</p><p>In this episode of the CMMC Compliance Guide Podcast, we break down what changed, what was clarified, and what contractors should take away from the latest guidance.</p><p>We cover:</p><ul><li>New DOW CIO leadership changes and what they mean for CMMC</li><li>Updated clarification on Hard Copy CUI (and what qualifies)</li><li>Why encryption alone does NOT define scope</li><li>Government shutdown impact on assessments</li><li>C3PAO reauthorization and ISO 17020 accreditation</li><li>KECO transition to ISACA and certification updates</li><li>What all of this means for contractors planning in 2026</li></ul><p>The biggest theme? CMMC is not slowing down. It’s becoming more standardized, more mature, and more defined.</p><p>If you’re planning contracts in 2026, now is the time to understand how these updates affect your scope, documentation, and assessment strategy.</p> ]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>The January 2026 CMMC Town Hall brought several important clarifications and program updates that directly impact Department of War (DoD) contractors.</p><p>In this episode of the CMMC Compliance Guide Podcast, we break down what changed, what was clarified, and what contractors should take away from the latest guidance.</p><p>We cover:</p><ul><li>New DOW CIO leadership changes and what they mean for CMMC</li><li>Updated clarification on Hard Copy CUI (and what qualifies)</li><li>Why encryption alone does NOT define scope</li><li>Government shutdown impact on assessments</li><li>C3PAO reauthorization and ISO 17020 accreditation</li><li>KECO transition to ISACA and certification updates</li><li>What all of this means for contractors planning in 2026</li></ul><p>The biggest theme? CMMC is not slowing down. It’s becoming more standardized, more mature, and more defined.</p><p>If you’re planning contracts in 2026, now is the time to understand how these updates affect your scope, documentation, and assessment strategy.</p> ]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/18676783-key-takeaways-from-the-january-2026-cmmc-town-hall-hard-copy-cui-scope-and-program-changes.mp3" length="21013991" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18676783</guid>
    <pubDate>Fri, 13 Feb 2026 10:00:00 -0600</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18676783/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18676783/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18676783/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18676783/transcript.vtt" type="text/vtt" />
    <itunes:duration>1749</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>49</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Why Feeling “CMMC Ready” Isn’t the Same as Passing a Level 2 Assessment</itunes:title>
    <title>Why Feeling “CMMC Ready” Isn’t the Same as Passing a Level 2 Assessment</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! Many DoW contractors feel confident they’re ready for a CMMC Level 2 assessment until assessors get involved. That’s when gaps in documentation, scope, and operational maturity start to surface. In this episode of the CMMC Compliance Guide Podcast, Brooke breaks down why implementation alone does not equal readiness. We walk through what assessors look for before technical testing even begins, why documentation is often the rea...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>Many DoW contractors feel confident they’re ready for a <b>CMMC Level 2 assessment</b> until assessors get involved. That’s when gaps in documentation, scope, and operational maturity start to surface.</p><p>In this episode of the <b>CMMC Compliance Guide Podcast</b>, Brooke breaks down why <em>implementation alone</em> does not equal readiness. We walk through what assessors look for <b>before technical testing even begins</b>, why documentation is often the real reason companies fail, and how poor scoping or misaligned staff interviews can derail an assessment.</p><p>You’ll learn:</p><ul><li>Why “feeling ready” is not the same as being assessment-ready</li><li>What assessors review first during the readiness and pre-assessment phase</li><li>How SSP quality can make or break your assessment</li><li>Why screenshots alone are not sufficient evidence</li><li>How POAMs are viewed during Level 2 assessments</li><li>The role of operational maturity and ongoing proof</li><li>How scope and employee interviews expose readiness gaps</li><li>How to realistically self-check readiness before scheduling an assessment</li></ul><p>If you’re preparing for a CMMC Level 2 assessment or think you’re close this episode will help you identify blind spots <em>before</em> they cost you time, money, or certification.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>Many DoW contractors feel confident they’re ready for a <b>CMMC Level 2 assessment</b> until assessors get involved. That’s when gaps in documentation, scope, and operational maturity start to surface.</p><p>In this episode of the <b>CMMC Compliance Guide Podcast</b>, Brooke breaks down why <em>implementation alone</em> does not equal readiness. We walk through what assessors look for <b>before technical testing even begins</b>, why documentation is often the real reason companies fail, and how poor scoping or misaligned staff interviews can derail an assessment.</p><p>You’ll learn:</p><ul><li>Why “feeling ready” is not the same as being assessment-ready</li><li>What assessors review first during the readiness and pre-assessment phase</li><li>How SSP quality can make or break your assessment</li><li>Why screenshots alone are not sufficient evidence</li><li>How POAMs are viewed during Level 2 assessments</li><li>The role of operational maturity and ongoing proof</li><li>How scope and employee interviews expose readiness gaps</li><li>How to realistically self-check readiness before scheduling an assessment</li></ul><p>If you’re preparing for a CMMC Level 2 assessment or think you’re close this episode will help you identify blind spots <em>before</em> they cost you time, money, or certification.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/18624834-why-feeling-cmmc-ready-isn-t-the-same-as-passing-a-level-2-assessment.mp3" length="14594723" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18624834</guid>
    <pubDate>Fri, 06 Feb 2026 06:00:00 -0600</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18624834/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18624834/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18624834/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18624834/transcript.vtt" type="text/vtt" />
    <itunes:duration>1214</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>48</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>CMMC FAQ Update: Timeline, Subcontractor Flowdowns, Enclaves, Cloud Rules, and VDI Scope Explained</itunes:title>
    <title>CMMC FAQ Update: Timeline, Subcontractor Flowdowns, Enclaves, Cloud Rules, and VDI Scope Explained</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! The DoW just released updated CMMC FAQs that clarify the rules contractors keep getting wrong. In this episode, Austin and Brooke break down what the new guidance actually says, what it means for your scope, and where vendor and architecture decisions can derail an assessment before it even starts. We cover the most important FAQ clarifications, including: The real CMMC timeline and what Phase 1 vs Phase 2 changesWhy primes may dema...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>The DoW just released updated CMMC FAQs that clarify the rules contractors keep getting wrong. In this episode, Austin and Brooke break down what the new guidance actually says, what it means for your scope, and where vendor and architecture decisions can derail an assessment before it even starts.</p><p>We cover the most important FAQ clarifications, including:</p><ul><li>The real CMMC timeline and what Phase 1 vs Phase 2 changes</li><li>Why primes may demand Level 2 earlier than the official dates</li><li>Flowdown requirements for subcontractors (and what “defensible” verification looks like)</li><li>The myth that encrypted CUI is no longer CUI (it is still CUI)</li><li>Whether CMMC assessment results will be public (they will not)</li><li>POAM vs “operational POAM” and why the distinction matters</li><li>Hard copy only CUI: when Level 2 may not apply (and the strict caveats)</li><li>Why encryption does not create logical separation or reduce scope</li><li>Enclaves and enterprise networking components: what pulls systems in scope (and what does not)</li><li>Cloud storage rules: why non-FedRAMP clouds cannot store encrypted CUI</li><li>MSP requirements: do MSPs need CMMC certification (and what a CRM must include)</li><li>VDI scope rules: when endpoints can be out of scope, and when they are automatically in scope</li></ul><p>If you are making decisions around scope, vendors, cloud tools, backups, enclaves, or VDI, this episode will help you avoid assumptions that assessors will not accept.</p> ]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>The DoW just released updated CMMC FAQs that clarify the rules contractors keep getting wrong. In this episode, Austin and Brooke break down what the new guidance actually says, what it means for your scope, and where vendor and architecture decisions can derail an assessment before it even starts.</p><p>We cover the most important FAQ clarifications, including:</p><ul><li>The real CMMC timeline and what Phase 1 vs Phase 2 changes</li><li>Why primes may demand Level 2 earlier than the official dates</li><li>Flowdown requirements for subcontractors (and what “defensible” verification looks like)</li><li>The myth that encrypted CUI is no longer CUI (it is still CUI)</li><li>Whether CMMC assessment results will be public (they will not)</li><li>POAM vs “operational POAM” and why the distinction matters</li><li>Hard copy only CUI: when Level 2 may not apply (and the strict caveats)</li><li>Why encryption does not create logical separation or reduce scope</li><li>Enclaves and enterprise networking components: what pulls systems in scope (and what does not)</li><li>Cloud storage rules: why non-FedRAMP clouds cannot store encrypted CUI</li><li>MSP requirements: do MSPs need CMMC certification (and what a CRM must include)</li><li>VDI scope rules: when endpoints can be out of scope, and when they are automatically in scope</li></ul><p>If you are making decisions around scope, vendors, cloud tools, backups, enclaves, or VDI, this episode will help you avoid assumptions that assessors will not accept.</p> ]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/18579905-cmmc-faq-update-timeline-subcontractor-flowdowns-enclaves-cloud-rules-and-vdi-scope-explained.mp3" length="37410331" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18579905</guid>
    <pubDate>Fri, 30 Jan 2026 06:00:00 -0600</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18579905/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18579905/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18579905/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18579905/transcript.vtt" type="text/vtt" />
    <itunes:duration>3115</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>47</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>How to Triage CMMC Compliance When You’re Overwhelmed and Short on Time</itunes:title>
    <title>How to Triage CMMC Compliance When You’re Overwhelmed and Short on Time</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! When CMMC compliance starts to feel overwhelming, most companies don’t fail because they lack effort, they fail because they don’t know where to start.  In this episode of the CMMC Compliance Guide Podcast, Brooke and Stacey break down why CMMC feels so urgent and high-risk for small and mid-sized DoD contractors, and how to triage your compliance work so you can make real progress without burning out.  This episode covers:   Why st...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>When CMMC compliance starts to feel overwhelming, most companies don’t fail because they lack effort, they fail because they don’t know where to start.<br/><br/>In this episode of the CMMC Compliance Guide Podcast, Brooke and Stacey break down why CMMC feels so urgent and high-risk for small and mid-sized DoD contractors, and how to triage your compliance work so you can make real progress without burning out.<br/><br/>This episode covers:<br/><br/></p><ul><li>Why starting at control 3.1.1 is a mistake for most companies</li><li>How poor scoping makes CMMC feel impossible</li><li>What assessors actually prioritize first</li><li>Which controls are non-POAMable and must be addressed early</li><li>How to reduce scope without cutting corners</li><li>When tools help and when they waste time and money</li><li>How to approach SSPs, policies, and POAMs the right way</li><li>Practical steps small teams can take to regain control of CMMC</li></ul><p><br/>If CMMC feels like everything is urgent and nothing is moving fast enough, this episode will help you slow down, focus, and build a plan that actually works.</p> ]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>When CMMC compliance starts to feel overwhelming, most companies don’t fail because they lack effort, they fail because they don’t know where to start.<br/><br/>In this episode of the CMMC Compliance Guide Podcast, Brooke and Stacey break down why CMMC feels so urgent and high-risk for small and mid-sized DoD contractors, and how to triage your compliance work so you can make real progress without burning out.<br/><br/>This episode covers:<br/><br/></p><ul><li>Why starting at control 3.1.1 is a mistake for most companies</li><li>How poor scoping makes CMMC feel impossible</li><li>What assessors actually prioritize first</li><li>Which controls are non-POAMable and must be addressed early</li><li>How to reduce scope without cutting corners</li><li>When tools help and when they waste time and money</li><li>How to approach SSPs, policies, and POAMs the right way</li><li>Practical steps small teams can take to regain control of CMMC</li></ul><p><br/>If CMMC feels like everything is urgent and nothing is moving fast enough, this episode will help you slow down, focus, and build a plan that actually works.</p> ]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/18533289-how-to-triage-cmmc-compliance-when-you-re-overwhelmed-and-short-on-time.mp3" length="21354375" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18533289</guid>
    <pubDate>Fri, 23 Jan 2026 06:00:00 -0600</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18533289/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18533289/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18533289/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18533289/transcript.vtt" type="text/vtt" />
    <itunes:duration>1777</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>46</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>CMMC Evidence 101: How to Prove NIST 800-171 Compliance in a Level 2 Assessment</itunes:title>
    <title>CMMC Evidence 101: How to Prove NIST 800-171 Compliance in a Level 2 Assessment</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! Get your free SPRS Roadmap here: https://cmmccomplianceguide.com/free-sprs-roadmap In this episode of the CMMC Compliance Guide Podcast, Austin and Brooke break down the #1 thing that trips companies up before a CMMC Level 2 assessment: evidence.  Having a binder of policies (or a 300-page SSP) is not enough. Assessors want proof you are doing what you say you do consistently, over time and they want it organized so they can quickly...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>Get your free SPRS Roadmap here: <a href='https://cmmccomplianceguide.com/free-sprs-roadmap'>https://cmmccomplianceguide.com/free-sprs-roadmap</a></p><p>In this episode of the CMMC Compliance Guide Podcast, Austin and Brooke break down the #1 thing that trips companies up before a CMMC Level 2 assessment: evidence.<br/><br/>Having a binder of policies (or a 300-page SSP) is not enough. Assessors want proof you are doing what you say you do consistently, over time and they want it organized so they can quickly map evidence to controls and assessment objectives.<br/><br/>You’ll learn:</p><ul><li>What assessors mean by “acceptable evidence” (and what doesn’t count)</li><li>The “who, what, when, where” test for logs and proof</li><li>How tickets, approvals, and checklists strengthen your evidence trail</li><li>What to avoid putting in cloud ticketing systems (SPD risks)</li><li>Manufacturer-specific pitfalls assessors notice on the shop floor</li><li>Why “fresh out of the oven” evidence raises red flags</li><li>How GRC tools can make evidence collection and linking easier</li></ul> ]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>Get your free SPRS Roadmap here: <a href='https://cmmccomplianceguide.com/free-sprs-roadmap'>https://cmmccomplianceguide.com/free-sprs-roadmap</a></p><p>In this episode of the CMMC Compliance Guide Podcast, Austin and Brooke break down the #1 thing that trips companies up before a CMMC Level 2 assessment: evidence.<br/><br/>Having a binder of policies (or a 300-page SSP) is not enough. Assessors want proof you are doing what you say you do consistently, over time and they want it organized so they can quickly map evidence to controls and assessment objectives.<br/><br/>You’ll learn:</p><ul><li>What assessors mean by “acceptable evidence” (and what doesn’t count)</li><li>The “who, what, when, where” test for logs and proof</li><li>How tickets, approvals, and checklists strengthen your evidence trail</li><li>What to avoid putting in cloud ticketing systems (SPD risks)</li><li>Manufacturer-specific pitfalls assessors notice on the shop floor</li><li>Why “fresh out of the oven” evidence raises red flags</li><li>How GRC tools can make evidence collection and linking easier</li></ul> ]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/18501061-cmmc-evidence-101-how-to-prove-nist-800-171-compliance-in-a-level-2-assessment.mp3" length="52311060" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18501061</guid>
    <pubDate>Fri, 16 Jan 2026 08:00:00 -0600</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18501061/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18501061/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18501061/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18501061/transcript.vtt" type="text/vtt" />
    <itunes:duration>4357</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>45</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>What CMMC Assessors Notice First: Early Red Flags That Fail Level 2 Assessments</itunes:title>
    <title>What CMMC Assessors Notice First: Early Red Flags That Fail Level 2 Assessments</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! What do CMMC Level 2 assessors notice first, sometimes within the first day, before they ever dig into your firewall configs or deep technical testing? In this episode of the CMMC Compliance Guide Podcast, Austin and Brooke break down the early red flags that can derail your assessment fast. We cover what assessors ask for right out of the gate (and how quickly you need to respond), why generic SSPs create problems, how scoping mist...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>What do CMMC Level 2 assessors notice first, sometimes within the first day, before they ever dig into your firewall configs or deep technical testing?</p><p>In this episode of the CMMC Compliance Guide Podcast, Austin and Brooke break down the early red flags that can derail your assessment fast. We cover what assessors ask for right out of the gate (and how quickly you need to respond), why generic SSPs create problems, how scoping mistakes happen in the real world (downloads folders, copiers, shop floor machines), and what it means when your policies do not match what employees actually do.</p><p>If you want to pass your CMMC Level 2 assessment, this episode will help you tighten your documentation, evidence, and scope before the assessor ever starts technical validation.</p> ]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>What do CMMC Level 2 assessors notice first, sometimes within the first day, before they ever dig into your firewall configs or deep technical testing?</p><p>In this episode of the CMMC Compliance Guide Podcast, Austin and Brooke break down the early red flags that can derail your assessment fast. We cover what assessors ask for right out of the gate (and how quickly you need to respond), why generic SSPs create problems, how scoping mistakes happen in the real world (downloads folders, copiers, shop floor machines), and what it means when your policies do not match what employees actually do.</p><p>If you want to pass your CMMC Level 2 assessment, this episode will help you tighten your documentation, evidence, and scope before the assessor ever starts technical validation.</p> ]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/18444377-what-cmmc-assessors-notice-first-early-red-flags-that-fail-level-2-assessments.mp3" length="33057144" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18444377</guid>
    <pubDate>Fri, 09 Jan 2026 06:00:00 -0600</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18444377/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18444377/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18444377/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18444377/transcript.vtt" type="text/vtt" />
    <itunes:duration>2752</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>44</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>CMMC Paperwork Without the Pain: How to Simplify Policies, SSP, and Evidence (Level 1 vs Level 2)</itunes:title>
    <title>CMMC Paperwork Without the Pain: How to Simplify Policies, SSP, and Evidence (Level 1 vs Level 2)</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! Most small and mid-sized manufacturers do not fail CMMC because of “tech.” They fail because their documentation does not match how the shop actually runs. In this episode, Austin and Brooke break down how to build CMMC documentation that is concise, accurate, and assessor-friendly without drowning in templates that were never written for your business. You will learn why template overload causes gaps, how to keep policies aligned t...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>Most small and mid-sized manufacturers do not fail CMMC because of “tech.” They fail because their documentation does not match how the shop actually runs.</p><p>In this episode, Austin and Brooke break down how to build CMMC documentation that is concise, accurate, and assessor-friendly without drowning in templates that were never written for your business. You will learn why template overload causes gaps, how to keep policies aligned to real workflows, and what “minimally sufficient” documentation looks like for both Level 1 and Level 2.</p><p>We also cover the difference between CMMC Level 1 and Level 2 documentation expectations, why evidence retention and verifiable processes matter, and how to decide between a file system approach vs a GRC tool to keep version control and proof organized for assessment day.</p><p>If you are a machine shop, aerospace manufacturer, or engineering firm trying to get compliant without creating a 400-page monster, this is your playbook.</p> ]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>Most small and mid-sized manufacturers do not fail CMMC because of “tech.” They fail because their documentation does not match how the shop actually runs.</p><p>In this episode, Austin and Brooke break down how to build CMMC documentation that is concise, accurate, and assessor-friendly without drowning in templates that were never written for your business. You will learn why template overload causes gaps, how to keep policies aligned to real workflows, and what “minimally sufficient” documentation looks like for both Level 1 and Level 2.</p><p>We also cover the difference between CMMC Level 1 and Level 2 documentation expectations, why evidence retention and verifiable processes matter, and how to decide between a file system approach vs a GRC tool to keep version control and proof organized for assessment day.</p><p>If you are a machine shop, aerospace manufacturer, or engineering firm trying to get compliant without creating a 400-page monster, this is your playbook.</p> ]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/18406027-cmmc-paperwork-without-the-pain-how-to-simplify-policies-ssp-and-evidence-level-1-vs-level-2.mp3" length="39981718" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18406027</guid>
    <pubDate>Fri, 02 Jan 2026 06:00:00 -0600</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18406027/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18406027/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18406027/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18406027/transcript.vtt" type="text/vtt" />
    <itunes:duration>3329</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>43</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>How CMMC Became a Competitive Advantage for DoD Contractors</itunes:title>
    <title>How CMMC Became a Competitive Advantage for DoD Contractors</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! CMMC is no longer just a compliance requirement. It is now a competitive advantage that directly impacts who wins and who loses DoD contracts.  In this episode of the CMMC Compliance Guide Podcast, Stacey and Brooke break down how the final 48 CFR rule has changed the contracting landscape and why primes are now aggressively pushing CMMC requirements down to their subcontractors. We explain how CMMC certification, SPRS scores, and a...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>CMMC is no longer just a compliance requirement. It is now a competitive advantage that directly impacts who wins and who loses DoD contracts.<br/><br/>In this episode of the CMMC Compliance Guide Podcast, Stacey and Brooke break down how the final 48 CFR rule has changed the contracting landscape and why primes are now aggressively pushing CMMC requirements down to their subcontractors. We explain how CMMC certification, SPRS scores, and assessment status are already being used to evaluate risk and readiness, even before certification becomes mandatory on every contract.<br/><br/>You will learn why contractors who are already certified, or at least scheduled for certification, are gaining an edge over competitors who waited too long. We also cover how flow-down requirements work, how primes protect themselves from False Claims Act risk, and why small businesses face a higher barrier to entry than midsize firms.<br/><br/>This episode also explains how contracting officers and primes view SPRS scores, what happens once certifications are uploaded through EMASS, and why CMMC status is not likely to become publicly searchable. Finally, Brooke walks through what contractors should be doing right now to stay competitive, including scoping CUI, running gap assessments, engaging a C3PAO early, and preparing subcontractor oversight.<br/><br/>If you want to keep winning DoD contracts in 2026 and beyond, this episode will help you understand how CMMC is reshaping the defense industrial base and what actions you need to take now.</p> ]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>CMMC is no longer just a compliance requirement. It is now a competitive advantage that directly impacts who wins and who loses DoD contracts.<br/><br/>In this episode of the CMMC Compliance Guide Podcast, Stacey and Brooke break down how the final 48 CFR rule has changed the contracting landscape and why primes are now aggressively pushing CMMC requirements down to their subcontractors. We explain how CMMC certification, SPRS scores, and assessment status are already being used to evaluate risk and readiness, even before certification becomes mandatory on every contract.<br/><br/>You will learn why contractors who are already certified, or at least scheduled for certification, are gaining an edge over competitors who waited too long. We also cover how flow-down requirements work, how primes protect themselves from False Claims Act risk, and why small businesses face a higher barrier to entry than midsize firms.<br/><br/>This episode also explains how contracting officers and primes view SPRS scores, what happens once certifications are uploaded through EMASS, and why CMMC status is not likely to become publicly searchable. Finally, Brooke walks through what contractors should be doing right now to stay competitive, including scoping CUI, running gap assessments, engaging a C3PAO early, and preparing subcontractor oversight.<br/><br/>If you want to keep winning DoD contracts in 2026 and beyond, this episode will help you understand how CMMC is reshaping the defense industrial base and what actions you need to take now.</p> ]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/18358989-how-cmmc-became-a-competitive-advantage-for-dod-contractors.mp3" length="19804872" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18358989</guid>
    <pubDate>Fri, 26 Dec 2025 06:00:00 -0600</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18358989/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18358989/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18358989/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18358989/transcript.vtt" type="text/vtt" />
    <itunes:duration>1648</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>42</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>NIST 800-171 and CMMC 2.0: How Assessors Actually Score You</itunes:title>
    <title>NIST 800-171 and CMMC 2.0: How Assessors Actually Score You</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! Are assessors judging you on CMMC or NIST 800 171 when audit day arrives?  In this episode of the CMMC Compliance Guide Podcast, Stacey and Brooke break down the real relationship between CMMC 2.0 and NIST 800 171 so you are not guessing when it matters most.  We walk through how the 110 NIST 800 171 controls and 320 assessment objectives drive your CMMC level 2 certification, and what CMMC layers on top, including POA&amp;M limits,...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>Are assessors judging you on CMMC or NIST 800 171 when audit day arrives?<br/><br/>In this episode of the CMMC Compliance Guide Podcast, Stacey and Brooke break down the real relationship between CMMC 2.0 and NIST 800 171 so you are not guessing when it matters most.<br/><br/>We walk through how the 110 NIST 800 171 controls and 320 assessment objectives drive your CMMC level 2 certification, and what CMMC layers on top, including POA&amp;M limits, timelines, and who is allowed to certify you. You will hear practical examples around SPAs, cloud tools, customer responsibility matrices, FedRAMP, and how assessors actually validate things like MFA, logging, and scope.<br/><br/>We also explain the difference between a NIST self assessment and a CMMC level 2 certification by a C3PAO, clear up common misconceptions about “being NIST compliant”, and talk about False Claims Act risk when SSPs, inventories, and controls are not kept current. Finally, Brooke shares a step by step path for contractors: identify your CUI, scope systems, run a gap analysis, build your SSP and POA&amp;M, collect evidence, and engage a C3PAO for a mock and full assessment.<br/><br/>If you are a small or midsized defense contractor trying to get ready for 2026, this episode will help you focus on what assessors really care about so you can prepare with confidence.</p> ]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>Are assessors judging you on CMMC or NIST 800 171 when audit day arrives?<br/><br/>In this episode of the CMMC Compliance Guide Podcast, Stacey and Brooke break down the real relationship between CMMC 2.0 and NIST 800 171 so you are not guessing when it matters most.<br/><br/>We walk through how the 110 NIST 800 171 controls and 320 assessment objectives drive your CMMC level 2 certification, and what CMMC layers on top, including POA&amp;M limits, timelines, and who is allowed to certify you. You will hear practical examples around SPAs, cloud tools, customer responsibility matrices, FedRAMP, and how assessors actually validate things like MFA, logging, and scope.<br/><br/>We also explain the difference between a NIST self assessment and a CMMC level 2 certification by a C3PAO, clear up common misconceptions about “being NIST compliant”, and talk about False Claims Act risk when SSPs, inventories, and controls are not kept current. Finally, Brooke shares a step by step path for contractors: identify your CUI, scope systems, run a gap analysis, build your SSP and POA&amp;M, collect evidence, and engage a C3PAO for a mock and full assessment.<br/><br/>If you are a small or midsized defense contractor trying to get ready for 2026, this episode will help you focus on what assessors really care about so you can prepare with confidence.</p> ]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/18317693-nist-800-171-and-cmmc-2-0-how-assessors-actually-score-you.mp3" length="23505691" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18317693</guid>
    <pubDate>Fri, 19 Dec 2025 06:00:00 -0600</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18317693/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18317693/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18317693/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18317693/transcript.vtt" type="text/vtt" />
    <itunes:duration>1956</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>41</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Top CMMC Myths Debunked: Cloud, Vendors, Firewalls, and MFA Mistakes Explained</itunes:title>
    <title>Top CMMC Myths Debunked: Cloud, Vendors, Firewalls, and MFA Mistakes Explained</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! Today’s episode of the CMMC Compliance Guide Podcast dives into the biggest myths that machine shops, fabricators, CNC shops, and mid-sized defense contractors still believe about CMMC. From cloud misconceptions to vendor promises that fall short, Brooke breaks down why these misunderstandings lead to failed assessments and what contractors should be doing instead. We walk through common assumptions like “cloud keeps me out of scope...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>Today’s episode of the CMMC Compliance Guide Podcast dives into the biggest myths that machine shops, fabricators, CNC shops, and mid-sized defense contractors still believe about CMMC. From cloud misconceptions to vendor promises that fall short, Brooke breaks down why these misunderstandings lead to failed assessments and what contractors should be doing instead.</p><p>We walk through common assumptions like “cloud keeps me out of scope,” “my vendor is compliant so I’m compliant,” “MFA on email is enough,” “my firewall makes everything compliant,” and “cyber insurance handles reporting.” Each of these has a grain of truth but none of them meet the actual requirements in NIST 800-171 or CMMC Level 2.</p><p>You’ll learn:</p><ul><li>Why cloud environments don’t remove your endpoints from scope</li><li>How caching, downloads, and browser access pull systems <em>back</em> into scope</li><li>What vendor claims really <em>don’t</em> cover</li><li>Why MFA must be implemented everywhere CUI is accessed, not just email</li><li>The truth about firewalls and why they’re not “compliance shields”</li><li>Why VDI is helpful but not a magic solution</li><li>What cyber insurance does (and doesn’t) do during an incident</li><li>Why remote workstations and home offices still introduce scope and risk</li></ul><p>This episode is packed with clarity, not fear so manufacturers, CNC shops, and GovCon SMBs can make informed decisions, avoid costly assumptions, and protect their DoD contracts.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>Today’s episode of the CMMC Compliance Guide Podcast dives into the biggest myths that machine shops, fabricators, CNC shops, and mid-sized defense contractors still believe about CMMC. From cloud misconceptions to vendor promises that fall short, Brooke breaks down why these misunderstandings lead to failed assessments and what contractors should be doing instead.</p><p>We walk through common assumptions like “cloud keeps me out of scope,” “my vendor is compliant so I’m compliant,” “MFA on email is enough,” “my firewall makes everything compliant,” and “cyber insurance handles reporting.” Each of these has a grain of truth but none of them meet the actual requirements in NIST 800-171 or CMMC Level 2.</p><p>You’ll learn:</p><ul><li>Why cloud environments don’t remove your endpoints from scope</li><li>How caching, downloads, and browser access pull systems <em>back</em> into scope</li><li>What vendor claims really <em>don’t</em> cover</li><li>Why MFA must be implemented everywhere CUI is accessed, not just email</li><li>The truth about firewalls and why they’re not “compliance shields”</li><li>Why VDI is helpful but not a magic solution</li><li>What cyber insurance does (and doesn’t) do during an incident</li><li>Why remote workstations and home offices still introduce scope and risk</li></ul><p>This episode is packed with clarity, not fear so manufacturers, CNC shops, and GovCon SMBs can make informed decisions, avoid costly assumptions, and protect their DoD contracts.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/18300109-top-cmmc-myths-debunked-cloud-vendors-firewalls-and-mfa-mistakes-explained.mp3" length="12255315" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18300109</guid>
    <pubDate>Fri, 12 Dec 2025 06:00:00 -0600</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18300109/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18300109/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18300109/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18300109/transcript.vtt" type="text/vtt" />
    <itunes:duration>1019</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>40</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Plain English Guide to CMMC Level 1: Basic Cybersecurity Without the Headache</itunes:title>
    <title>Plain English Guide to CMMC Level 1: Basic Cybersecurity Without the Headache</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! CMMC Level 1 Self- Assessment Guide: https://dodcio.defense.gov/Portals/0/Documents/CMMC/AG_Level1_V2.0_FinalDraft_20211210_508.pdf  In this episode of the CMMC Compliance Guide Podcast, Stacey and Austin from Justice IT Consulting break down CMMC Level 1 in clear, simple terms: what it is, who it applies to, and the exact steps small and mid-sized contractors must take to protect Federal Contract Information (FCI).  You’ll learn wh...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>CMMC Level 1 Self- Assessment Guide: <a href='https://dodcio.defense.gov/Portals/0/Documents/CMMC/AG_Level1_V2.0_FinalDraft_20211210_508.pdf'>https://dodcio.defense.gov/Portals/0/Documents/CMMC/AG_Level1_V2.0_FinalDraft_20211210_508.pdf</a><br/><br/>In this episode of the CMMC Compliance Guide Podcast, Stacey and Austin from Justice IT Consulting break down CMMC Level 1 in clear, simple terms: what it is, who it applies to, and the exact steps small and mid-sized contractors must take to protect Federal Contract Information (FCI).<br/><br/>You’ll learn what the government expects from Level 1 contractors, how the 15 required practices actually work in real life, what documentation you must maintain for six years, and why the new annual self-assessment requirement matters more than ever.<br/><br/>Whether you’re a machine shop, fabricator, engineering firm, or small manufacturer supporting a prime contractor, this episode gives you the Level 1 foundation you must have in place.<br/><br/><br/></p> ]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>CMMC Level 1 Self- Assessment Guide: <a href='https://dodcio.defense.gov/Portals/0/Documents/CMMC/AG_Level1_V2.0_FinalDraft_20211210_508.pdf'>https://dodcio.defense.gov/Portals/0/Documents/CMMC/AG_Level1_V2.0_FinalDraft_20211210_508.pdf</a><br/><br/>In this episode of the CMMC Compliance Guide Podcast, Stacey and Austin from Justice IT Consulting break down CMMC Level 1 in clear, simple terms: what it is, who it applies to, and the exact steps small and mid-sized contractors must take to protect Federal Contract Information (FCI).<br/><br/>You’ll learn what the government expects from Level 1 contractors, how the 15 required practices actually work in real life, what documentation you must maintain for six years, and why the new annual self-assessment requirement matters more than ever.<br/><br/>Whether you’re a machine shop, fabricator, engineering firm, or small manufacturer supporting a prime contractor, this episode gives you the Level 1 foundation you must have in place.<br/><br/><br/></p> ]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/18244793-plain-english-guide-to-cmmc-level-1-basic-cybersecurity-without-the-headache.mp3" length="20917097" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18244793</guid>
    <pubDate>Fri, 05 Dec 2025 06:00:00 -0600</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18244793/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18244793/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18244793/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18244793/transcript.vtt" type="text/vtt" />
    <itunes:duration>1741</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>39</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Top 12 CMMC Level 2 Requirements Explained: Gap Assessments, Scope, SSP, and POA&amp;M</itunes:title>
    <title>Top 12 CMMC Level 2 Requirements Explained: Gap Assessments, Scope, SSP, and POA&amp;M</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! In this episode of the CMMC Compliance Guide Podcast, Stacey and Austin from Justice IT Consulting walk through the top 12 essentials every contractor needs to achieve CMMC Level 2 compliance especially small and mid-sized defense manufacturers.  You’ll learn how to start compliance the right way with a formal gap assessment, define and shrink your CUI scope, and build a System Security Plan (SSP) that maps to all 110 NIST 800-171 c...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>In this episode of the CMMC Compliance Guide Podcast, Stacey and Austin from Justice IT Consulting walk through the top 12 essentials every contractor needs to achieve CMMC Level 2 compliance especially small and mid-sized defense manufacturers.<br/><br/>You’ll learn how to start compliance the right way with a formal gap assessment, define and shrink your CUI scope, and build a System Security Plan (SSP) that maps to all 110 NIST 800-171 controls. We break down how to write an actionable Plan of Action &amp; Milestones (POA&amp;M), implement MFA correctly, enforce least-privilege access control, and deploy proper device protection across your environment.<br/><br/>We also cover commonly misunderstood requirements around FIPS-validated encryption, centralized logging/SIEM, removable media, CNC/OT assets, data handling, and ongoing vulnerability + risk assessments.<br/><br/>Finally, we answer a listener question on secure data transfer and why customer portals or GCC/GCC High environments are often superior to “secure links” inside commercial Microsoft 365 tenants.</p> ]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>In this episode of the CMMC Compliance Guide Podcast, Stacey and Austin from Justice IT Consulting walk through the top 12 essentials every contractor needs to achieve CMMC Level 2 compliance especially small and mid-sized defense manufacturers.<br/><br/>You’ll learn how to start compliance the right way with a formal gap assessment, define and shrink your CUI scope, and build a System Security Plan (SSP) that maps to all 110 NIST 800-171 controls. We break down how to write an actionable Plan of Action &amp; Milestones (POA&amp;M), implement MFA correctly, enforce least-privilege access control, and deploy proper device protection across your environment.<br/><br/>We also cover commonly misunderstood requirements around FIPS-validated encryption, centralized logging/SIEM, removable media, CNC/OT assets, data handling, and ongoing vulnerability + risk assessments.<br/><br/>Finally, we answer a listener question on secure data transfer and why customer portals or GCC/GCC High environments are often superior to “secure links” inside commercial Microsoft 365 tenants.</p> ]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/18247518-top-12-cmmc-level-2-requirements-explained-gap-assessments-scope-ssp-and-poa-m.mp3" length="31589486" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18247518</guid>
    <pubDate>Fri, 28 Nov 2025 06:00:00 -0600</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18247518/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18247518/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18247518/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18247518/transcript.vtt" type="text/vtt" />
    <itunes:duration>2630</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>38</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Cyber AB Town Hall Breakdown: Legal Lessons, Ecosystem Growth, and CMMC Phase 2 Progress</itunes:title>
    <title>Cyber AB Town Hall Breakdown: Legal Lessons, Ecosystem Growth, and CMMC Phase 2 Progress</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! In this episode of the CMMC Compliance Guide Podcast, Brooke and Stacey from Justice IT Consulting unpack the biggest updates from the Cyber AB’s October 2025 Town Hall and what they mean for defense contractors preparing for CMMC certification. You’ll learn: Why the government shutdown isn’t delaying CMMC or the 48 CFR rolloutThe $875K False Claims Act case against Georgia Tech and what it teaches all contractorsHow the CMMC ecosys...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>In this episode of the CMMC Compliance Guide Podcast, Brooke and Stacey from Justice IT Consulting unpack the biggest updates from the Cyber AB’s October 2025 Town Hall and what they mean for defense contractors preparing for CMMC certification.</p><p>You’ll learn:</p><ul><li>Why the government shutdown isn’t delaying CMMC or the 48 CFR rollout</li><li>The $875K False Claims Act case against Georgia Tech and what it teaches all contractors</li><li>How the CMMC ecosystem is expanding with more certified assessors and C3PAOs</li><li>Key insights from the University of Southern California’s Level 2 certification journey</li><li>Practical advice for small contractors: data mapping, documentation, and shrinking your CUI boundary</li><li>New ethics reminders and upcoming assessor certification updates from the Cyber AB</li></ul><p>This episode delivers plain-English explanations and real-world lessons to help contractors stay compliant, avoid legal risk, and prepare for CMMC Phase 2.</p> ]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>In this episode of the CMMC Compliance Guide Podcast, Brooke and Stacey from Justice IT Consulting unpack the biggest updates from the Cyber AB’s October 2025 Town Hall and what they mean for defense contractors preparing for CMMC certification.</p><p>You’ll learn:</p><ul><li>Why the government shutdown isn’t delaying CMMC or the 48 CFR rollout</li><li>The $875K False Claims Act case against Georgia Tech and what it teaches all contractors</li><li>How the CMMC ecosystem is expanding with more certified assessors and C3PAOs</li><li>Key insights from the University of Southern California’s Level 2 certification journey</li><li>Practical advice for small contractors: data mapping, documentation, and shrinking your CUI boundary</li><li>New ethics reminders and upcoming assessor certification updates from the Cyber AB</li></ul><p>This episode delivers plain-English explanations and real-world lessons to help contractors stay compliant, avoid legal risk, and prepare for CMMC Phase 2.</p> ]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/18146450-cyber-ab-town-hall-breakdown-legal-lessons-ecosystem-growth-and-cmmc-phase-2-progress.mp3" length="21624620" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18146450</guid>
    <pubDate>Fri, 07 Nov 2025 06:00:00 -0600</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18146450/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18146450/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18146450/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18146450/transcript.vtt" type="text/vtt" />
    <itunes:duration>1799</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>37</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Highlights from CS5 East 2025: Operation Midnight Hammer, CMMC Updates, and AI Insights</itunes:title>
    <title>Highlights from CS5 East 2025: Operation Midnight Hammer, CMMC Updates, and AI Insights</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! Get the inside scoop from CS5 East 2025, the largest cybersecurity and compliance event for the Defense Industrial Base. In this episode, Brooke and Stacey from Justice IT Consulting breaks down the biggest CMMC updates, Operation Midnight Hammer, and how AI is reshaping compliance.  Learn what the Cyber AB announced, how CMMC Phase 2 is rolling out, and what contractors should expect next. Whether you’re a Compliance Officer, DoD P...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>Get the inside scoop from CS5 East 2025, the largest cybersecurity and compliance event for the Defense Industrial Base. In this episode, Brooke and Stacey from Justice IT Consulting breaks down the biggest CMMC updates, Operation Midnight Hammer, and how AI is reshaping compliance.<br/><br/>Learn what the Cyber AB announced, how CMMC Phase 2 is rolling out, and what contractors should expect next. Whether you’re a Compliance Officer, DoD Program Manager, or small-business GovCon, this recap gives you the context and clarity you need to stay ahead.</p> ]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>Get the inside scoop from CS5 East 2025, the largest cybersecurity and compliance event for the Defense Industrial Base. In this episode, Brooke and Stacey from Justice IT Consulting breaks down the biggest CMMC updates, Operation Midnight Hammer, and how AI is reshaping compliance.<br/><br/>Learn what the Cyber AB announced, how CMMC Phase 2 is rolling out, and what contractors should expect next. Whether you’re a Compliance Officer, DoD Program Manager, or small-business GovCon, this recap gives you the context and clarity you need to stay ahead.</p> ]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/18105866-highlights-from-cs5-east-2025-operation-midnight-hammer-cmmc-updates-and-ai-insights.mp3" length="34478116" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18105866</guid>
    <pubDate>Fri, 31 Oct 2025 06:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18105866/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18105866/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18105866/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/18105866/transcript.vtt" type="text/vtt" />
    <itunes:duration>2871</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>36</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>How to Prove CMMC Compliance to Prime Contractors (Before You Lose Contracts)</itunes:title>
    <title>How to Prove CMMC Compliance to Prime Contractors (Before You Lose Contracts)</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! 🎯 Get your Free SPRS Roadmap Session: https://cmmccomplianceguide.com/free-sprs-roadmap Our experts will review your SPRS score, documentation, and setup to help you hit 110 with a clear action plan at no cost.  Prime contractors like Lockheed Martin, Raytheon, and Parker Hannifin are demanding proof of compliance before awarding new work — and subcontractors who can’t prove it risk losing contracts.  In this episode, Brooke and Aus...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>🎯 Get your Free SPRS Roadmap Session: <a href='https://cmmccomplianceguide.com/free-sprs-roadmap'>https://cmmccomplianceguide.com/free-sprs-roadmap</a><br/>Our experts will review your SPRS score, documentation, and setup to help you hit 110 with a clear action plan at no cost.<br/><br/>Prime contractors like Lockheed Martin, Raytheon, and Parker Hannifin are demanding proof of compliance before awarding new work — and subcontractors who can’t prove it risk losing contracts.<br/><br/>In this episode, Brooke and Austin from Justice IT Consulting explain exactly what primes are asking for, what documentation they expect (SPRS, SSP, POA&amp;M), and the most common mistakes subcontractors make when trying to prove compliance.<br/><br/>You’ll learn:</p><ul><li> Why primes are suddenly enforcing subcontractor compliance</li><li> What documents and proof you need ready (SPRS, SSP, POA&amp;M)</li><li> The biggest mistakes that lead to false claims risk</li><li> What happens when you inflate your SPRS score</li><li> How to show compliance even before your Level 2 certification</li><li> What steps to take now to get audit-ready and stay competitive</li></ul><p><br/>Whether you’re still working toward compliance or just need a second set of eyes, this episode breaks down how to prove your CMMC compliance with confidence — before your primes stop sending work your way.</p> ]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>🎯 Get your Free SPRS Roadmap Session: <a href='https://cmmccomplianceguide.com/free-sprs-roadmap'>https://cmmccomplianceguide.com/free-sprs-roadmap</a><br/>Our experts will review your SPRS score, documentation, and setup to help you hit 110 with a clear action plan at no cost.<br/><br/>Prime contractors like Lockheed Martin, Raytheon, and Parker Hannifin are demanding proof of compliance before awarding new work — and subcontractors who can’t prove it risk losing contracts.<br/><br/>In this episode, Brooke and Austin from Justice IT Consulting explain exactly what primes are asking for, what documentation they expect (SPRS, SSP, POA&amp;M), and the most common mistakes subcontractors make when trying to prove compliance.<br/><br/>You’ll learn:</p><ul><li> Why primes are suddenly enforcing subcontractor compliance</li><li> What documents and proof you need ready (SPRS, SSP, POA&amp;M)</li><li> The biggest mistakes that lead to false claims risk</li><li> What happens when you inflate your SPRS score</li><li> How to show compliance even before your Level 2 certification</li><li> What steps to take now to get audit-ready and stay competitive</li></ul><p><br/>Whether you’re still working toward compliance or just need a second set of eyes, this episode breaks down how to prove your CMMC compliance with confidence — before your primes stop sending work your way.</p> ]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/17972511-how-to-prove-cmmc-compliance-to-prime-contractors-before-you-lose-contracts.mp3" length="19792056" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17972511</guid>
    <pubDate>Fri, 10 Oct 2025 06:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17972511/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17972511/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17972511/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17972511/transcript.vtt" type="text/vtt" />
    <itunes:duration>1647</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>35</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Cyber AB Town Hall September 2025: Key CMMC Compliance Updates</itunes:title>
    <title>Cyber AB Town Hall September 2025: Key CMMC Compliance Updates</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! The September 2025 Cyber AB Town Hall dropped big updates for contractors navigating CMMC and NIST 800-171 compliance.  In this episode of the CMMC Compliance Guide Podcast, Brooke and Austin break down what the final CMMC rule (Title 48A) means for defense contractors, subcontractors, and service providers.  We cover the timeline for implementation, prime and subcontractor flow-down requirements, service provider risks (MSPs, ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>The September 2025 Cyber AB Town Hall dropped big updates for contractors navigating CMMC and NIST 800-171 compliance. </p><p>In this episode of the CMMC Compliance Guide Podcast, Brooke and Austin break down what the final CMMC rule (Title 48A) means for defense contractors, subcontractors, and service providers.<br/><br/>We cover the timeline for implementation, prime and subcontractor flow-down requirements, service provider risks (MSPs, CSPs, ESPs), and how a government shutdown could affect CMMC. You’ll also hear insights on ongoing compliance, documentation, FedRAMP requirements, advisory councils, and what primes will expect from their supply chains.<br/><br/>Whether you’re a compliance officer, program manager, or DoD subcontractor, this episode gives you clear, actionable takeaways so you can prepare before deadlines hit.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>The September 2025 Cyber AB Town Hall dropped big updates for contractors navigating CMMC and NIST 800-171 compliance. </p><p>In this episode of the CMMC Compliance Guide Podcast, Brooke and Austin break down what the final CMMC rule (Title 48A) means for defense contractors, subcontractors, and service providers.<br/><br/>We cover the timeline for implementation, prime and subcontractor flow-down requirements, service provider risks (MSPs, CSPs, ESPs), and how a government shutdown could affect CMMC. You’ll also hear insights on ongoing compliance, documentation, FedRAMP requirements, advisory councils, and what primes will expect from their supply chains.<br/><br/>Whether you’re a compliance officer, program manager, or DoD subcontractor, this episode gives you clear, actionable takeaways so you can prepare before deadlines hit.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/17951199-cyber-ab-town-hall-september-2025-key-cmmc-compliance-updates.mp3" length="24447361" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17951199</guid>
    <pubDate>Fri, 03 Oct 2025 10:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17951199/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17951199/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17951199/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17951199/transcript.vtt" type="text/vtt" />
    <itunes:duration>2035</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>34</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Handling CUI Correctly: Compliance Risks and Best Practices</itunes:title>
    <title>Handling CUI Correctly: Compliance Risks and Best Practices</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! Worried about mishandling Controlled Unclassified Information (CUI)?  In this episode of the CMMC Compliance Guide Podcast, Brooke and Stacey break down what CUI really is, why it matters in defense contracting, and the biggest mistakes contractors make when handling it. You’ll also learn the real-world risks of CUI mishandling, how assessors check compliance during a CMMC Level 2 assessment, and the low-cost, practical solutio...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>Worried about mishandling Controlled Unclassified Information (CUI)? </p><p>In this episode of the CMMC Compliance Guide Podcast, Brooke and Stacey break down what CUI really is, why it matters in defense contracting, and the biggest mistakes contractors make when handling it.</p><p>You’ll also learn the real-world risks of CUI mishandling, how assessors check compliance during a CMMC Level 2 assessment, and the low-cost, practical solutions you can implement right now to protect sensitive data.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>Worried about mishandling Controlled Unclassified Information (CUI)? </p><p>In this episode of the CMMC Compliance Guide Podcast, Brooke and Stacey break down what CUI really is, why it matters in defense contracting, and the biggest mistakes contractors make when handling it.</p><p>You’ll also learn the real-world risks of CUI mishandling, how assessors check compliance during a CMMC Level 2 assessment, and the low-cost, practical solutions you can implement right now to protect sensitive data.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/17899216-handling-cui-correctly-compliance-risks-and-best-practices.mp3" length="12344616" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17899216</guid>
    <pubDate>Fri, 26 Sep 2025 06:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17899216/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17899216/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17899216/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17899216/transcript.vtt" type="text/vtt" />
    <itunes:duration>1026</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>33</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>CMMC Final Rule Explained: Deadlines, Requirements, and Next Steps for Defense Contractors</itunes:title>
    <title>CMMC Final Rule Explained: Deadlines, Requirements, and Next Steps for Defense Contractors</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! The wait is over: the Department of Defense has finalized the CMMC rule, officially making it part of DFARS. That means compliance isn’t “coming soon”, it’s now in your contracts.  In this episode of the CMMC Compliance Guide Podcast, Austin and Brooke from Justice IT Consulting break down what the final rule means for DoD contractors and subcontractors, the key deadlines you need to know, and the exact steps to prepare for Level 2 ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>The wait is over: the Department of Defense has finalized the CMMC rule, officially making it part of DFARS. That means compliance isn’t “coming soon”, it’s now in your contracts.<br/><br/>In this episode of the CMMC Compliance Guide Podcast, Austin and Brooke from Justice IT Consulting break down what the final rule means for DoD contractors and subcontractors, the key deadlines you need to know, and the exact steps to prepare for Level 2 certification before requirements hit contracts in November 2026.<br/><br/>What you’ll learn in this episode:<br/><br/>- The new CMMC final rule and when it goes into effect<br/>- How the 4-phase rollout impacts primes and subcontractors<br/>- What’s different about this update (and why it’s not another delay)<br/>- Key requirements: SPRS score, POAM limits, affirming officials, and more<br/>- How to prepare your subcontractors with questionnaires and attestations<br/>- Why you need to start engaging with C3PAOs now before schedules fill up<br/><br/>If you’re a DoD contractor, aerospace manufacturer, or subcontractor, this is the update you can’t afford to ignore.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>The wait is over: the Department of Defense has finalized the CMMC rule, officially making it part of DFARS. That means compliance isn’t “coming soon”, it’s now in your contracts.<br/><br/>In this episode of the CMMC Compliance Guide Podcast, Austin and Brooke from Justice IT Consulting break down what the final rule means for DoD contractors and subcontractors, the key deadlines you need to know, and the exact steps to prepare for Level 2 certification before requirements hit contracts in November 2026.<br/><br/>What you’ll learn in this episode:<br/><br/>- The new CMMC final rule and when it goes into effect<br/>- How the 4-phase rollout impacts primes and subcontractors<br/>- What’s different about this update (and why it’s not another delay)<br/>- Key requirements: SPRS score, POAM limits, affirming officials, and more<br/>- How to prepare your subcontractors with questionnaires and attestations<br/>- Why you need to start engaging with C3PAOs now before schedules fill up<br/><br/>If you’re a DoD contractor, aerospace manufacturer, or subcontractor, this is the update you can’t afford to ignore.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/17872110-cmmc-final-rule-explained-deadlines-requirements-and-next-steps-for-defense-contractors.mp3" length="11229667" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17872110</guid>
    <pubDate>Fri, 19 Sep 2025 08:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17872110/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17872110/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17872110/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17872110/transcript.vtt" type="text/vtt" />
    <itunes:duration>933</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>32</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>The Role of NIST 800-171 in Your CMMC Assessment</itunes:title>
    <title>The Role of NIST 800-171 in Your CMMC Assessment</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! Confused about where NIST 800-171 fits into your CMMC 2.0 assessment? You’re not alone.   In this episode of the CMMC Compliance Guide, Brooke and Stacey from Justice IT Consulting break it all down in plain English.  We cover the foundation of NIST 800-171, how it maps into the CMMC levels, what assessors actually look for during an audit, and the most common mistakes contractors make. We’ll also touch on the latest updates in...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>Confused about where NIST 800-171 fits into your CMMC 2.0 assessment? You’re not alone. <br/><br/>In this episode of the CMMC Compliance Guide, Brooke and Stacey from Justice IT Consulting break it all down in plain English.<br/><br/>We cover the foundation of NIST 800-171, how it maps into the CMMC levels, what assessors actually look for during an audit, and the most common mistakes contractors make. We’ll also touch on the latest updates including: NIST 800-171 Rev 3 and the DoD’s enforcement timelines and finish by answering real listener questions on VoIP, Microsoft 365, and more.<br/><br/>Whether you’re a small defense contractor or managing compliance for a larger team, this episode gives you the practical steps you need to stay compliant, stay secure, and stay ready for your assessment.</p> ]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>Confused about where NIST 800-171 fits into your CMMC 2.0 assessment? You’re not alone. <br/><br/>In this episode of the CMMC Compliance Guide, Brooke and Stacey from Justice IT Consulting break it all down in plain English.<br/><br/>We cover the foundation of NIST 800-171, how it maps into the CMMC levels, what assessors actually look for during an audit, and the most common mistakes contractors make. We’ll also touch on the latest updates including: NIST 800-171 Rev 3 and the DoD’s enforcement timelines and finish by answering real listener questions on VoIP, Microsoft 365, and more.<br/><br/>Whether you’re a small defense contractor or managing compliance for a larger team, this episode gives you the practical steps you need to stay compliant, stay secure, and stay ready for your assessment.</p> ]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/17797404-the-role-of-nist-800-171-in-your-cmmc-assessment.mp3" length="22408527" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17797404</guid>
    <pubDate>Fri, 12 Sep 2025 06:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17797404/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17797404/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17797404/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17797404/transcript.vtt" type="text/vtt" />
    <itunes:duration>1865</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>31</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>The Truth About CMMC Enclaves: Pros, Cons, and Compliance Risks</itunes:title>
    <title>The Truth About CMMC Enclaves: Pros, Cons, and Compliance Risks</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! Thinking about building an enclave for CMMC compliance? Not so fast.  In this episode of the CMMC Compliance Guide Podcast, Austin and Brooke from Justice IT Consulting break down: What an enclave actually is (in plain English)When an enclave makes sense (and saves you money)When it can hurt your compliance effortsWhat assessors will really be looking for in your auditIf you’ve ever asked, “Do I need an enclave for CMMC?”,&nbsp...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>Thinking about building an enclave for CMMC compliance? Not so fast. </p><p>In this episode of the <em>CMMC Compliance Guide Podcast</em>, Austin and Brooke from Justice IT Consulting break down:</p><ul><li>What an enclave actually is (in plain English)</li><li>When an enclave makes sense (and saves you money)</li><li>When it can hurt your compliance efforts</li><li>What assessors will really be looking for in your audit</li></ul><p>If you’ve ever asked, <em>“Do I need an enclave for CMMC?”, </em>this episode is your roadmap to making the right call for your business.</p> ]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>Thinking about building an enclave for CMMC compliance? Not so fast. </p><p>In this episode of the <em>CMMC Compliance Guide Podcast</em>, Austin and Brooke from Justice IT Consulting break down:</p><ul><li>What an enclave actually is (in plain English)</li><li>When an enclave makes sense (and saves you money)</li><li>When it can hurt your compliance efforts</li><li>What assessors will really be looking for in your audit</li></ul><p>If you’ve ever asked, <em>“Do I need an enclave for CMMC?”, </em>this episode is your roadmap to making the right call for your business.</p> ]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/17748489-the-truth-about-cmmc-enclaves-pros-cons-and-compliance-risks.mp3" length="22178470" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17748489</guid>
    <pubDate>Fri, 29 Aug 2025 06:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17748489/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17748489/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17748489/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17748489/transcript.vtt" type="text/vtt" />
    <itunes:duration>1846</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>30</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Are You Really Ready for a CMMC Assessment?</itunes:title>
    <title>Are You Really Ready for a CMMC Assessment?</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! Think you’re ready for your CMMC assessment?  In this episode of the CMMC Compliance Guide Podcast, Austin and Brooke break down the difference between being “paper ready” and truly “assessment ready.” From documentation gaps to overlooked technical controls, they share insider tips to help you pass with confidence. We’ll walk you through the common blind spots that can derail an assessment, how to stress test your compliance p...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>Think you’re ready for your CMMC assessment? </p><p>In this episode of the CMMC Compliance Guide Podcast, Austin and Brooke break down the difference between being “paper ready” and truly “assessment ready.” From documentation gaps to overlooked technical controls, they share insider tips to help you pass with confidence.</p><p>We’ll walk you through the common blind spots that can derail an assessment, how to stress test your compliance program, and what assessors <em>really</em> look for when they walk in the door.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>Think you’re ready for your CMMC assessment? </p><p>In this episode of the CMMC Compliance Guide Podcast, Austin and Brooke break down the difference between being “paper ready” and truly “assessment ready.” From documentation gaps to overlooked technical controls, they share insider tips to help you pass with confidence.</p><p>We’ll walk you through the common blind spots that can derail an assessment, how to stress test your compliance program, and what assessors <em>really</em> look for when they walk in the door.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/17677429-are-you-really-ready-for-a-cmmc-assessment.mp3" length="23002230" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17677429</guid>
    <pubDate>Fri, 22 Aug 2025 08:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17677429/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17677429/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17677429/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17677429/transcript.vtt" type="text/vtt" />
    <itunes:duration>1914</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>29</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>When ‘Not Applicable’ Can Cost You Contracts</itunes:title>
    <title>When ‘Not Applicable’ Can Cost You Contracts</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! Marking a CMMC control as “Not Applicable” might feel like an easy shortcut but get it wrong, and you could fail your assessment, lose contracts, or even face legal trouble.  In this episode of The CMMC Compliance Guide, Brooke and Stacey from Justice IT Consulting break down the real risks of misusing N/A, share common mistakes companies make, and explain how to properly justify a not applicable control so you stay compliant and av...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>Marking a CMMC control as “Not Applicable” might feel like an easy shortcut but get it wrong, and you could fail your assessment, lose contracts, or even face legal trouble.<br/><br/>In this episode of The CMMC Compliance Guide, Brooke and Stacey from Justice IT Consulting break down the real risks of misusing N/A, share common mistakes companies make, and explain how to properly justify a not applicable control so you stay compliant and avoid False Claims Act issues.<br/><br/>We cover everything from Wi-Fi misconceptions to remote access oversights, mobile device scoping, assessor validation methods, and the legal risks nobody talks about. Whether you’re a one-person shop or managing a complex network, these insights could save you from major headaches come assessment day.</p><p><a href='https://cyberab.org/Catalog#!/c/s/Results/Format/list/Page/1/Size/9/Sort/NameAscending'>CyberAB Marketplace</a></p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>Marking a CMMC control as “Not Applicable” might feel like an easy shortcut but get it wrong, and you could fail your assessment, lose contracts, or even face legal trouble.<br/><br/>In this episode of The CMMC Compliance Guide, Brooke and Stacey from Justice IT Consulting break down the real risks of misusing N/A, share common mistakes companies make, and explain how to properly justify a not applicable control so you stay compliant and avoid False Claims Act issues.<br/><br/>We cover everything from Wi-Fi misconceptions to remote access oversights, mobile device scoping, assessor validation methods, and the legal risks nobody talks about. Whether you’re a one-person shop or managing a complex network, these insights could save you from major headaches come assessment day.</p><p><a href='https://cyberab.org/Catalog#!/c/s/Results/Format/list/Page/1/Size/9/Sort/NameAscending'>CyberAB Marketplace</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/17653217-when-not-applicable-can-cost-you-contracts.mp3" length="12159325" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17653217</guid>
    <pubDate>Fri, 15 Aug 2025 06:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17653217/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17653217/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17653217/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17653217/transcript.vtt" type="text/vtt" />
    <itunes:duration>1011</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>28</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>How to Make Real CMMC Progress: Even if Compliance Isn’t Your Full-Time Job</itunes:title>
    <title>How to Make Real CMMC Progress: Even if Compliance Isn’t Your Full-Time Job</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! Schedule your free SPRS Roadmap Session and get a step-by-step plan to close gaps and stay defensible: 👉 https://cmmccomplianceguide.com/free-sprs-roadmap Is CMMC just one of many hats you wear at your company? You’re not alone and you’re not out of luck. In this episode of the CMMC Compliance Guide, we break down how overworked and under-resourced compliance leads can still make meaningful progress toward CMMC and NIST 800-171. Whe...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>Schedule your free SPRS Roadmap Session and get a step-by-step plan to close gaps and stay defensible:<br/>👉 <a href='https://cmmccomplianceguide.com/free-sprs-roadmap'>https://cmmccomplianceguide.com/free-sprs-roadmap</a></p><p><b>Is CMMC just one of many hats you wear at your company? You’re not alone and you’re not out of luck.</b></p><p>In this episode of the CMMC Compliance Guide, we break down how overworked and under-resourced compliance leads can still make meaningful progress toward CMMC and NIST 800-171. Whether you&apos;re a part-time compliance officer, the IT guy, or the quality manager who just got handed CMMC, we’ll walk you through a phased, practical approach you can tackle in just a few hours a week.</p><p>From identifying CUI and building your data flow diagrams to implementing MFA, FIPS, and policy templates the right way—this is your guide to making CMMC doable without the burnout.</p> ]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>Schedule your free SPRS Roadmap Session and get a step-by-step plan to close gaps and stay defensible:<br/>👉 <a href='https://cmmccomplianceguide.com/free-sprs-roadmap'>https://cmmccomplianceguide.com/free-sprs-roadmap</a></p><p><b>Is CMMC just one of many hats you wear at your company? You’re not alone and you’re not out of luck.</b></p><p>In this episode of the CMMC Compliance Guide, we break down how overworked and under-resourced compliance leads can still make meaningful progress toward CMMC and NIST 800-171. Whether you&apos;re a part-time compliance officer, the IT guy, or the quality manager who just got handed CMMC, we’ll walk you through a phased, practical approach you can tackle in just a few hours a week.</p><p>From identifying CUI and building your data flow diagrams to implementing MFA, FIPS, and policy templates the right way—this is your guide to making CMMC doable without the burnout.</p> ]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/17595655-how-to-make-real-cmmc-progress-even-if-compliance-isn-t-your-full-time-job.mp3" length="33910713" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17595655</guid>
    <pubDate>Fri, 01 Aug 2025 06:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17595655/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17595655/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17595655/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17595655/transcript.vtt" type="text/vtt" />
    <itunes:duration>2823</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>27</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>What You Missed: June Cyber AB Town Hall CMMC Highlights</itunes:title>
    <title>What You Missed: June Cyber AB Town Hall CMMC Highlights</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! 48 CFR UPDATE: https://www.ecfr.gov/current/title-48/chapter-2/subchapter-A/part-204/subpart-204.75  Missed the June 2024 Cyber AB Town Hall? We’ve got you covered.  In this episode of the CMMC Compliance Guide, Brooke and Austin break down the biggest takeaways — including how recent leadership changes, service provider requirements, and G-code classification are shaping the path to CMMC compliance.  If you're a DoD contractor or M...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p><b>48 CFR UPDATE:</b> <a href='https://www.ecfr.gov/current/title-48/chapter-2/subchapter-A/part-204/subpart-204.75'>https://www.ecfr.gov/current/title-48/chapter-2/subchapter-A/part-204/subpart-204.75</a><br/><br/>Missed the June 2024 Cyber AB Town Hall? We’ve got you covered.<br/><br/>In this episode of the CMMC Compliance Guide, Brooke and Austin break down the biggest takeaways — including how recent leadership changes, service provider requirements, and G-code classification are shaping the path to CMMC compliance.<br/><br/>If you&apos;re a DoD contractor or MSP supporting government clients, this is the update you can&apos;t afford to miss.<br/><br/><b>INSIDE THE EPISODE:</b><br/>- What the new Undersecretary means for CMMC rulemaking<br/>- ESP vs. CSP vs. MSP — and why the difference matters<br/>- Why your IT provider will be assessed with your environment<br/>- How your CAGE code could delay certification<br/>- What assessors say about G-code and CUI<br/>- Upcoming CMMC events you should have on your calendar<br/><br/><b>UPCOMING CMMC EVENTS MENTIONED:</b><br/>- Carahsoft CMMC Webinar Series: <a href='https://www.carahsoft.com/learn/event/71021-proofpoint-and-microsoft-cmmc-webinar'>https://www.carahsoft.com/learn/event/71021-proofpoint-and-microsoft-cmmc-webinar</a><br/><br/>- National Cyber Summit: <a href='https://www.nationalcybersummit.com/'>https://www.nationalcybersummit.com/</a><br/><br/>- CS5 East 2025: <a href='https://cyberab.org/News-Events/CS5-Conference'>https://cyberab.org/News-Events/CS5-Conference</a></p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p><b>48 CFR UPDATE:</b> <a href='https://www.ecfr.gov/current/title-48/chapter-2/subchapter-A/part-204/subpart-204.75'>https://www.ecfr.gov/current/title-48/chapter-2/subchapter-A/part-204/subpart-204.75</a><br/><br/>Missed the June 2024 Cyber AB Town Hall? We’ve got you covered.<br/><br/>In this episode of the CMMC Compliance Guide, Brooke and Austin break down the biggest takeaways — including how recent leadership changes, service provider requirements, and G-code classification are shaping the path to CMMC compliance.<br/><br/>If you&apos;re a DoD contractor or MSP supporting government clients, this is the update you can&apos;t afford to miss.<br/><br/><b>INSIDE THE EPISODE:</b><br/>- What the new Undersecretary means for CMMC rulemaking<br/>- ESP vs. CSP vs. MSP — and why the difference matters<br/>- Why your IT provider will be assessed with your environment<br/>- How your CAGE code could delay certification<br/>- What assessors say about G-code and CUI<br/>- Upcoming CMMC events you should have on your calendar<br/><br/><b>UPCOMING CMMC EVENTS MENTIONED:</b><br/>- Carahsoft CMMC Webinar Series: <a href='https://www.carahsoft.com/learn/event/71021-proofpoint-and-microsoft-cmmc-webinar'>https://www.carahsoft.com/learn/event/71021-proofpoint-and-microsoft-cmmc-webinar</a><br/><br/>- National Cyber Summit: <a href='https://www.nationalcybersummit.com/'>https://www.nationalcybersummit.com/</a><br/><br/>- CS5 East 2025: <a href='https://cyberab.org/News-Events/CS5-Conference'>https://cyberab.org/News-Events/CS5-Conference</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/17559223-what-you-missed-june-cyber-ab-town-hall-cmmc-highlights.mp3" length="22662455" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17559223</guid>
    <pubDate>Fri, 25 Jul 2025 06:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17559223/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17559223/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17559223/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17559223/transcript.vtt" type="text/vtt" />
    <itunes:duration>1886</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>26</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>6 Critical CMMC Questions Every Small DoD Contractor Should Know</itunes:title>
    <title>6 Critical CMMC Questions Every Small DoD Contractor Should Know</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! Are you trying to navigate CMMC and NIST 800-171 with a small team and limited resources?   You're not alone. In this episode of the CMMC Compliance Guide, we’re breaking down six of the most common and confusing questions small DoD contractors ask—and giving you clear, practical answers you can act on immediately. Join Brooke &amp; Stacey from Justice IT Consulting as they unpack risks of misinterpreting controls, mobile device sco...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p><b>Are you trying to navigate CMMC and NIST 800-171 with a small team and limited resources?</b></p><p><br/> You&apos;re not alone. In this episode of the <em>CMMC Compliance Guide</em>, we’re breaking down six of the most common and confusing questions small DoD contractors ask—and giving you <em>clear, practical answers</em> you can act on immediately.</p><p>Join Brooke &amp; Stacey from Justice IT Consulting as they unpack risks of misinterpreting controls, mobile device scope, admin account misuse, CUI data flow diagrams, remote access, and more. Whether you’re prepping for a CMMC Level 2 assessment or just trying to stay ahead, this episode is packed with actionable advice.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p><b>Are you trying to navigate CMMC and NIST 800-171 with a small team and limited resources?</b></p><p><br/> You&apos;re not alone. In this episode of the <em>CMMC Compliance Guide</em>, we’re breaking down six of the most common and confusing questions small DoD contractors ask—and giving you <em>clear, practical answers</em> you can act on immediately.</p><p>Join Brooke &amp; Stacey from Justice IT Consulting as they unpack risks of misinterpreting controls, mobile device scope, admin account misuse, CUI data flow diagrams, remote access, and more. Whether you’re prepping for a CMMC Level 2 assessment or just trying to stay ahead, this episode is packed with actionable advice.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/17526126-6-critical-cmmc-questions-every-small-dod-contractor-should-know.mp3" length="12629883" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17526126</guid>
    <pubDate>Fri, 18 Jul 2025 09:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17526126/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17526126/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17526126/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17526126/transcript.vtt" type="text/vtt" />
    <itunes:duration>1050</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>25</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>CMMC on the Shop Floor: A No-BS Guide for CNC &amp; Aerospace Machine Shops</itunes:title>
    <title>CMMC on the Shop Floor: A No-BS Guide for CNC &amp; Aerospace Machine Shops</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! Happy 4th of July from the team at CMMC Compliance Guide Podcast! While you're celebrating freedom, hot dogs, and fireworks — don’t forget about safeguarding the data that defends that freedom. 🛡️ In this special edition, we're tackling what really works for CMMC compliance on the shop floor. From coolant-soaked travelers to ancient XP machines, this is your no-nonsense guide to staying compliant in real-world CNC and aerospace manu...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>Happy 4th of July from the team at <b>CMMC Compliance Guide Podcast</b>! While you&apos;re celebrating freedom, hot dogs, and fireworks — don’t forget about safeguarding the data that defends that freedom. 🛡️</p><p>In this <b>special edition</b>, we&apos;re tackling what <em>really</em> works for CMMC compliance on the shop floor. From coolant-soaked travelers to ancient XP machines, this is your no-nonsense guide to staying compliant in real-world CNC and aerospace manufacturing environments.</p><p>Skip the theory. Get the real-world playbook. Because you can&apos;t afford to shut down production just to pass an audit.</p><p><br/></p><p> 📞 <b>Need help with CMMC or NIST 800-171?</b><br/> We fast-track defense manufacturers to compliance — or give you the tools to do it yourself.</p><p><br/> 👉 Visit <a href='https://www.cmmccomplianceguide.com'>https://www.cmmccomplianceguide.com</a> to download free resources or schedule a discovery call. </p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>Happy 4th of July from the team at <b>CMMC Compliance Guide Podcast</b>! While you&apos;re celebrating freedom, hot dogs, and fireworks — don’t forget about safeguarding the data that defends that freedom. 🛡️</p><p>In this <b>special edition</b>, we&apos;re tackling what <em>really</em> works for CMMC compliance on the shop floor. From coolant-soaked travelers to ancient XP machines, this is your no-nonsense guide to staying compliant in real-world CNC and aerospace manufacturing environments.</p><p>Skip the theory. Get the real-world playbook. Because you can&apos;t afford to shut down production just to pass an audit.</p><p><br/></p><p> 📞 <b>Need help with CMMC or NIST 800-171?</b><br/> We fast-track defense manufacturers to compliance — or give you the tools to do it yourself.</p><p><br/> 👉 Visit <a href='https://www.cmmccomplianceguide.com'>https://www.cmmccomplianceguide.com</a> to download free resources or schedule a discovery call. </p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/17444719-cmmc-on-the-shop-floor-a-no-bs-guide-for-cnc-aerospace-machine-shops.mp3" length="19358517" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17444719</guid>
    <pubDate>Fri, 04 Jul 2025 07:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17444719/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17444719/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17444719/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17444719/transcript.vtt" type="text/vtt" />
    <itunes:duration>1611</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>24</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Ceasefire’s Here, But Your Shop’s Still a Target: What the DoD CIO Just Told Defense Contractors</itunes:title>
    <title>Ceasefire’s Here, But Your Shop’s Still a Target: What the DoD CIO Just Told Defense Contractors</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! 🆓 Need help getting your SPRS score to 110? Schedule your free SPRS Roadmap Session and get a step-by-step plan to close gaps and stay defensible: 👉 https://cmmccomplianceguide.com/free-sprs-roadmap  The Department of Defense just issued a critical cybersecurity memo—and it's not just for the Lockheeds and Raytheons. In this episode, we break down what small and mid-sized DoD contractors must do now to respond to rising cyber threat...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>🆓 Need help getting your SPRS score to 110?<br/>Schedule your free SPRS Roadmap Session and get a step-by-step plan to close gaps and stay defensible:<br/>👉 <a href='https://cmmccomplianceguide.com/free-sprs-roadmap'>https://cmmccomplianceguide.com/free-sprs-roadmap</a><br/><br/>The Department of Defense just issued a critical cybersecurity memo—and it&apos;s not just for the Lockheeds and Raytheons. In this episode, we break down what small and mid-sized DoD contractors must do now to respond to rising cyber threats—even amid headlines of ceasefire. From multi-factor authentication and patching systems to cloud security guidance and SPRS score readiness, we walk you through the exact steps your organization needs to take.<br/><br/>Resources Mentioned:<br/>Memo: <a href='https://media.licdn.com/dms/document/media/v2/D561FAQFbAPookqu2zw/feedshare-document-pdf-analyzed/B56ZefAj13HoAY-/0/1750719415748?e=1751500800&amp;v=beta&amp;t=O6aY3UDi5ijLTGOa6RP4xAWABMPZh-ZKRkXRikiCywg '>https://media.licdn.com/dms/document/media/v2/D561FAQFbAPookqu2zw/feedshare-document-pdf-analyzed/B56ZefAj13HoAY-/0/1750719415748?e=1751500800&amp;v=beta&amp;t=O6aY3UDi5ijLTGOa6RP4xAWABMPZh-ZKRkXRikiCywg </a><br/><br/><a href='https://www.cisa.gov/known-exploited-vulnerabilities-catalog '>https://www.cisa.gov/known-exploited-vulnerabilities-catalog </a><br/><a href='https://www.cisa.gov/news-events/directives/bod-25-01-implementing-secure-practices-cloud-services '>https://www.cisa.gov/news-events/directives/bod-25-01-implementing-secure-practices-cloud-services </a><br/><a href='https://www.cisa.gov/cyber-hygiene-services '>https://www.cisa.gov/cyber-hygiene-services </a><br/><a href='https://www.nsa.gov/About/Cybersecurity-Collaboration-Center/DIB-Cybersecurity-Services/ '>https://www.nsa.gov/About/Cybersecurity-Collaboration-Center/DIB-Cybersecurity-Services/ </a><br/><a href='https://www.dc3.mil/Missions/DIB-Cybersecurity/DCISE-Resources/ '>https://www.dc3.mil/Missions/DIB-Cybersecurity/DCISE-Resources/ </a><br/><br/>#CMMC #DODCompliance #CyberSecurity #SPRS #DefenseContractor #CyberThreats #NIST800171 #CMMCComplianceGuide</p> ]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>🆓 Need help getting your SPRS score to 110?<br/>Schedule your free SPRS Roadmap Session and get a step-by-step plan to close gaps and stay defensible:<br/>👉 <a href='https://cmmccomplianceguide.com/free-sprs-roadmap'>https://cmmccomplianceguide.com/free-sprs-roadmap</a><br/><br/>The Department of Defense just issued a critical cybersecurity memo—and it&apos;s not just for the Lockheeds and Raytheons. In this episode, we break down what small and mid-sized DoD contractors must do now to respond to rising cyber threats—even amid headlines of ceasefire. From multi-factor authentication and patching systems to cloud security guidance and SPRS score readiness, we walk you through the exact steps your organization needs to take.<br/><br/>Resources Mentioned:<br/>Memo: <a href='https://media.licdn.com/dms/document/media/v2/D561FAQFbAPookqu2zw/feedshare-document-pdf-analyzed/B56ZefAj13HoAY-/0/1750719415748?e=1751500800&amp;v=beta&amp;t=O6aY3UDi5ijLTGOa6RP4xAWABMPZh-ZKRkXRikiCywg '>https://media.licdn.com/dms/document/media/v2/D561FAQFbAPookqu2zw/feedshare-document-pdf-analyzed/B56ZefAj13HoAY-/0/1750719415748?e=1751500800&amp;v=beta&amp;t=O6aY3UDi5ijLTGOa6RP4xAWABMPZh-ZKRkXRikiCywg </a><br/><br/><a href='https://www.cisa.gov/known-exploited-vulnerabilities-catalog '>https://www.cisa.gov/known-exploited-vulnerabilities-catalog </a><br/><a href='https://www.cisa.gov/news-events/directives/bod-25-01-implementing-secure-practices-cloud-services '>https://www.cisa.gov/news-events/directives/bod-25-01-implementing-secure-practices-cloud-services </a><br/><a href='https://www.cisa.gov/cyber-hygiene-services '>https://www.cisa.gov/cyber-hygiene-services </a><br/><a href='https://www.nsa.gov/About/Cybersecurity-Collaboration-Center/DIB-Cybersecurity-Services/ '>https://www.nsa.gov/About/Cybersecurity-Collaboration-Center/DIB-Cybersecurity-Services/ </a><br/><a href='https://www.dc3.mil/Missions/DIB-Cybersecurity/DCISE-Resources/ '>https://www.dc3.mil/Missions/DIB-Cybersecurity/DCISE-Resources/ </a><br/><br/>#CMMC #DODCompliance #CyberSecurity #SPRS #DefenseContractor #CyberThreats #NIST800171 #CMMCComplianceGuide</p> ]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/17403298-ceasefire-s-here-but-your-shop-s-still-a-target-what-the-dod-cio-just-told-defense-contractors.mp3" length="18062683" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17403298</guid>
    <pubDate>Fri, 27 Jun 2025 07:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17403298/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17403298/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17403298/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17403298/transcript.vtt" type="text/vtt" />
    <itunes:duration>1503</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>23</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Breaking Down the Real Cost of CMMC Compliance for Small Businesses</itunes:title>
    <title>Breaking Down the Real Cost of CMMC Compliance for Small Businesses</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! Why is CMMC compliance so expensive—especially for small businesses?  In this episode of the CMMC Compliance Guide Podcast, Austin and Brooke from Justice IT Consulting break down what really drives up the cost of CMMC and NIST 800-171 compliance, and more importantly—how you can cut costs without cutting corners. We cover: The four stages of compliance cost: paperwork, project work, ongoing maintenance, and assessmentsWhat ass...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p><b>Why is CMMC compliance so expensive—especially for small businesses?</b> </p><p>In this episode of the <em>CMMC Compliance Guide Podcast</em>, Austin and Brooke from Justice IT Consulting break down what really drives up the cost of CMMC and NIST 800-171 compliance, and more importantly—how you can <b>cut costs without cutting corners</b>.</p><p>We cover:</p><ul><li>The four stages of compliance cost: paperwork, project work, ongoing maintenance, and assessments</li><li>What assessors can and <em>can’t</em> help with</li><li>Enclave strategies that can save you thousands</li><li>Why smaller companies feel a heavier burden—and how to manage it</li><li>Smart scoping, VDI, and how not to overspend on your CMMC journey</li></ul><p>If you’re trying to balance compliance with a tight budget, this episode is a must-listen.</p><p>👉 Need help or have questions? Contact us for free advice at <a href='https://cmmccomplianceguide.com'>CMMCComplianceGuide.com</a>.</p><p>🔔 Don’t forget to like, subscribe, and share!</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p><b>Why is CMMC compliance so expensive—especially for small businesses?</b> </p><p>In this episode of the <em>CMMC Compliance Guide Podcast</em>, Austin and Brooke from Justice IT Consulting break down what really drives up the cost of CMMC and NIST 800-171 compliance, and more importantly—how you can <b>cut costs without cutting corners</b>.</p><p>We cover:</p><ul><li>The four stages of compliance cost: paperwork, project work, ongoing maintenance, and assessments</li><li>What assessors can and <em>can’t</em> help with</li><li>Enclave strategies that can save you thousands</li><li>Why smaller companies feel a heavier burden—and how to manage it</li><li>Smart scoping, VDI, and how not to overspend on your CMMC journey</li></ul><p>If you’re trying to balance compliance with a tight budget, this episode is a must-listen.</p><p>👉 Need help or have questions? Contact us for free advice at <a href='https://cmmccomplianceguide.com'>CMMCComplianceGuide.com</a>.</p><p>🔔 Don’t forget to like, subscribe, and share!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/17353986-breaking-down-the-real-cost-of-cmmc-compliance-for-small-businesses.mp3" length="22875636" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17353986</guid>
    <pubDate>Fri, 20 Jun 2025 06:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17353986/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17353986/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17353986/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17353986/transcript.vtt" type="text/vtt" />
    <itunes:duration>1904</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>22</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>How to Scope CMMC Correctly: Avoid Audit Failures, Over-Scoping, and Cloud Risks</itunes:title>
    <title>How to Scope CMMC Correctly: Avoid Audit Failures, Over-Scoping, and Cloud Risks</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! Is your CMMC scope setting you up for success—or failure? In this episode of the CMMC Compliance Guide, Brooke and Stacey from Justice IT Consulting break down one of the most misunderstood (and expensive) parts of your compliance journey: scoping. Learn how to define your CUI boundary the right way, avoid common over-scoping mistakes, and streamline your assessment with clear documentation strategies. Whether you're prepping for a ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p><b>Is your CMMC scope setting you up for success—or failure?</b></p><p>In this episode of the <b>CMMC Compliance Guide</b>, Brooke and Stacey from Justice IT Consulting break down one of the most misunderstood (and expensive) parts of your compliance journey: <b>scoping</b>.</p><p>Learn how to define your CUI boundary the right way, avoid common over-scoping mistakes, and streamline your assessment with clear documentation strategies. Whether you&apos;re prepping for a formal CMMC assessment or self-assessing for NIST 800-171, this episode gives you real-world insights that can save you time, money, and frustration.</p><p>🔍 We cover:</p><ul><li>What really defines your CMMC scope (it&apos;s more than just your server)</li><li>The hidden risks of over-scoping and cloud blind spots</li><li>Third-party service provider mistakes that can blow your scope</li><li>Must-have documentation: data flow diagrams, network diagrams, and asset inventories</li><li>A practical checklist to get your scope right before the audit</li></ul><p>🛠 Need a faster path to compliance without cutting corners? Visit <a href='http://www.CMMCComplianceGuide.com'>www.CMMCComplianceGuide.com</a> for free resources, expert help, or to book a discovery call.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p><b>Is your CMMC scope setting you up for success—or failure?</b></p><p>In this episode of the <b>CMMC Compliance Guide</b>, Brooke and Stacey from Justice IT Consulting break down one of the most misunderstood (and expensive) parts of your compliance journey: <b>scoping</b>.</p><p>Learn how to define your CUI boundary the right way, avoid common over-scoping mistakes, and streamline your assessment with clear documentation strategies. Whether you&apos;re prepping for a formal CMMC assessment or self-assessing for NIST 800-171, this episode gives you real-world insights that can save you time, money, and frustration.</p><p>🔍 We cover:</p><ul><li>What really defines your CMMC scope (it&apos;s more than just your server)</li><li>The hidden risks of over-scoping and cloud blind spots</li><li>Third-party service provider mistakes that can blow your scope</li><li>Must-have documentation: data flow diagrams, network diagrams, and asset inventories</li><li>A practical checklist to get your scope right before the audit</li></ul><p>🛠 Need a faster path to compliance without cutting corners? Visit <a href='http://www.CMMCComplianceGuide.com'>www.CMMCComplianceGuide.com</a> for free resources, expert help, or to book a discovery call.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/17318743-how-to-scope-cmmc-correctly-avoid-audit-failures-over-scoping-and-cloud-risks.mp3" length="8870790" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17318743</guid>
    <pubDate>Fri, 13 Jun 2025 08:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17318743/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17318743/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17318743/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17318743/transcript.vtt" type="text/vtt" />
    <itunes:duration>737</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>21</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>What You Missed at CEIC West 2025: CMMC Culture, AI Labeling, and Subcontractor Risks</itunes:title>
    <title>What You Missed at CEIC West 2025: CMMC Culture, AI Labeling, and Subcontractor Risks</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! Missed CEIC West 2025 in Las Vegas? We’ve got your insider recap. In this episode of the CMMC Compliance Guide, Austin and Brooke break down the most critical insights defense contractors need to know—from Katie Arrington’s keynote to real-world flowdown risks, mock assessment walkthroughs, and what AI means for your CUI documentation. If you’re a small or mid-sized DoD contractor trying to stay compliant with CMMC, NIST 800-171, an...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>Missed <b>CEIC West 2025</b> in Las Vegas? We’ve got your insider recap. In this episode of the <em>CMMC Compliance Guide</em>, Austin and Brooke break down the most critical insights defense contractors need to know—from Katie Arrington’s keynote to real-world flowdown risks, mock assessment walkthroughs, and what AI means for your CUI documentation.</p><p>If you’re a small or mid-sized DoD contractor trying to stay compliant with CMMC, NIST 800-171, and DFARS, this episode gives you the takeaways that actually matter.</p><p><br/></p><p> 📞 Have questions? Text, call, or email us. We’ll answer them for free on the podcast.</p><p><br/> 🔗 Visit <a href='http://www.cmmccomplianceguide.com'>www.cmmccomplianceguide.com</a> for free resources</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>Missed <b>CEIC West 2025</b> in Las Vegas? We’ve got your insider recap. In this episode of the <em>CMMC Compliance Guide</em>, Austin and Brooke break down the most critical insights defense contractors need to know—from Katie Arrington’s keynote to real-world flowdown risks, mock assessment walkthroughs, and what AI means for your CUI documentation.</p><p>If you’re a small or mid-sized DoD contractor trying to stay compliant with CMMC, NIST 800-171, and DFARS, this episode gives you the takeaways that actually matter.</p><p><br/></p><p> 📞 Have questions? Text, call, or email us. We’ll answer them for free on the podcast.</p><p><br/> 🔗 Visit <a href='http://www.cmmccomplianceguide.com'>www.cmmccomplianceguide.com</a> for free resources</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/17254894-what-you-missed-at-ceic-west-2025-cmmc-culture-ai-labeling-and-subcontractor-risks.mp3" length="37362033" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17254894</guid>
    <pubDate>Fri, 30 May 2025 13:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17254894/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17254894/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17254894/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17254894/transcript.vtt" type="text/vtt" />
    <itunes:duration>3111</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>20</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>How to Identify and Fix Your NIST 800-171 Weak Spots</itunes:title>
    <title>How to Identify and Fix Your NIST 800-171 Weak Spots</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! Are you sure you're NIST 800-171 compliant? In this episode of the CMMC Compliance Guide Podcast, Austin and Brooke break down the most overlooked NIST 800-171 requirements that continue to trip up DoD contractors—and what you can do today to avoid those costly mistakes. From data flow diagrams to documentation pitfalls, supply chain risks, and misunderstood MFA and logging requirements, this episode is packed with practical insight...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>Are you <em>sure</em> you&apos;re NIST 800-171 compliant? In this episode of the <b>CMMC Compliance Guide Podcast</b>, Austin and Brooke break down the most overlooked NIST 800-171 requirements that continue to trip up DoD contractors—and what you can do today to avoid those costly mistakes.</p><p>From data flow diagrams to documentation pitfalls, supply chain risks, and misunderstood MFA and logging requirements, this episode is packed with practical insights and actionable takeaways. If you’re pursuing <b>CMMC Level 2</b> or just trying to boost your <b>SPRS score</b>, this is a must-listen.</p><p>💡 You’ll Learn:</p><ul><li>Why poor <b>scoping</b> is the #1 mistake in compliance</li><li>How to map your <b>CUI data flow</b> across systems and subcontractors</li><li>What assessors <em>really</em> expect from your <b>MFA, logging, and risk assessment</b> controls</li><li>Why your <b>documentation strategy</b> can make or break your assessment</li><li>What it takes to maintain compliance <em>after</em> you’re “done”</li><li>How to use the <b>NIST 800-171A Assessment Guide</b> to conduct a real gap analysis</li><li>The truth about <b>ongoing compliance</b> vs. one-time audits</li><li>GRC tools, POAMs, and how to build your project roadmap</li></ul><p>This episode is your self-assessment gut check. Whether you&apos;re just starting or already deep into your compliance journey, don’t miss these expert tips.</p><p>🔗 For free resources, visit: <a href='https://cmmccomplianceguide.com'>https://cmmccomplianceguide.com</a><br/> 📅 Meet us at <a href='https://www.dibcon.net/'><b>DibCon</b></a>, June 3–5, in Oklahoma City!</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>Are you <em>sure</em> you&apos;re NIST 800-171 compliant? In this episode of the <b>CMMC Compliance Guide Podcast</b>, Austin and Brooke break down the most overlooked NIST 800-171 requirements that continue to trip up DoD contractors—and what you can do today to avoid those costly mistakes.</p><p>From data flow diagrams to documentation pitfalls, supply chain risks, and misunderstood MFA and logging requirements, this episode is packed with practical insights and actionable takeaways. If you’re pursuing <b>CMMC Level 2</b> or just trying to boost your <b>SPRS score</b>, this is a must-listen.</p><p>💡 You’ll Learn:</p><ul><li>Why poor <b>scoping</b> is the #1 mistake in compliance</li><li>How to map your <b>CUI data flow</b> across systems and subcontractors</li><li>What assessors <em>really</em> expect from your <b>MFA, logging, and risk assessment</b> controls</li><li>Why your <b>documentation strategy</b> can make or break your assessment</li><li>What it takes to maintain compliance <em>after</em> you’re “done”</li><li>How to use the <b>NIST 800-171A Assessment Guide</b> to conduct a real gap analysis</li><li>The truth about <b>ongoing compliance</b> vs. one-time audits</li><li>GRC tools, POAMs, and how to build your project roadmap</li></ul><p>This episode is your self-assessment gut check. Whether you&apos;re just starting or already deep into your compliance journey, don’t miss these expert tips.</p><p>🔗 For free resources, visit: <a href='https://cmmccomplianceguide.com'>https://cmmccomplianceguide.com</a><br/> 📅 Meet us at <a href='https://www.dibcon.net/'><b>DibCon</b></a>, June 3–5, in Oklahoma City!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/17195827-how-to-identify-and-fix-your-nist-800-171-weak-spots.mp3" length="26407466" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17195827</guid>
    <pubDate>Fri, 23 May 2025 07:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17195827/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17195827/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17195827/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17195827/transcript.vtt" type="text/vtt" />
    <itunes:duration>2198</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>19</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>CMMC Day 2025 Recap: Key Takeaways, Real-World Mistakes &amp; What SMBs Must Fix Now</itunes:title>
    <title>CMMC Day 2025 Recap: Key Takeaways, Real-World Mistakes &amp; What SMBs Must Fix Now</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! Get the latest insider takeaways from CMMC Day 2025 straight from Washington D.C. In this episode of the CMMC Compliance Guide Podcast, Brooke and Austin break down the most critical updates small and midsized businesses (SMBs) in the defense supply chain need to know now. We cover:  ✅ Why CMMC is NOT going away (despite what skeptics think)  ✅ Critical mistakes businesses still make with SSPs, scoping, and access control ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>Get the latest insider takeaways from <b>CMMC Day 2025</b> straight from Washington D.C. In this episode of the <b>CMMC Compliance Guide Podcast</b>, Brooke and Austin break down the most critical updates small and midsized businesses (SMBs) in the defense supply chain need to know now.</p><p>We cover:<br/> ✅ Why CMMC is NOT going away (despite what skeptics think)<br/> ✅ Critical mistakes businesses still make with SSPs, scoping, and access control<br/> ✅ Real-world assessment horror stories you need to avoid<br/> ✅ Why subcontractors can&apos;t hide in the supply chain anymore<br/> ✅ Tools, technology, and zero trust lessons from the show floor</p><p>Whether you&apos;re a manufacturer, IT lead, or compliance manager, this episode delivers actionable insights to help you stay off the DoD&apos;s naughty list and win more contracts in 2025.</p><p>🎯 Need help? Get your free SPRS Score Roadmap → <a href='https://cmmccomplianceguide.com/free-sprs-roadmap'>https://cmmccomplianceguide.com/free-sprs-roadmap</a></p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>Get the latest insider takeaways from <b>CMMC Day 2025</b> straight from Washington D.C. In this episode of the <b>CMMC Compliance Guide Podcast</b>, Brooke and Austin break down the most critical updates small and midsized businesses (SMBs) in the defense supply chain need to know now.</p><p>We cover:<br/> ✅ Why CMMC is NOT going away (despite what skeptics think)<br/> ✅ Critical mistakes businesses still make with SSPs, scoping, and access control<br/> ✅ Real-world assessment horror stories you need to avoid<br/> ✅ Why subcontractors can&apos;t hide in the supply chain anymore<br/> ✅ Tools, technology, and zero trust lessons from the show floor</p><p>Whether you&apos;re a manufacturer, IT lead, or compliance manager, this episode delivers actionable insights to help you stay off the DoD&apos;s naughty list and win more contracts in 2025.</p><p>🎯 Need help? Get your free SPRS Score Roadmap → <a href='https://cmmccomplianceguide.com/free-sprs-roadmap'>https://cmmccomplianceguide.com/free-sprs-roadmap</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/17151791-cmmc-day-2025-recap-key-takeaways-real-world-mistakes-what-smbs-must-fix-now.mp3" length="40969742" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17151791</guid>
    <pubDate>Fri, 16 May 2025 07:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17151791/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17151791/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17151791/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17151791/transcript.vtt" type="text/vtt" />
    <itunes:duration>3412</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>18</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Decoding NIST 800-171: Your Plain English Path to CMMC Level 2 Compliance</itunes:title>
    <title>Decoding NIST 800-171: Your Plain English Path to CMMC Level 2 Compliance</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! Feeling overwhelmed by CMMC compliance and NIST 800-171’s 110 controls? You’re not alone — but you don’t have to be stuck. In this episode of the CMMC Compliance Guide Podcast, Brooke and Austin break down NIST 800-171 Revision 2 in plain English — no government-speak, no tech jargon — so you can finally understand what each control family means for your business. You'll learn: What NIST 800-171 really requires (and why it matters f...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p><b>Feeling overwhelmed by CMMC compliance and NIST 800-171’s 110 controls? You’re not alone — but you don’t have to be stuck.</b></p><p>In this episode of the <em>CMMC Compliance Guide Podcast</em>, Brooke and Austin break down NIST 800-171 Revision 2 in plain English — no government-speak, no tech jargon — so you can finally understand what each control family means for your business.</p><p>You&apos;ll learn:</p><ul><li>What NIST 800-171 really requires (and why it matters for your SPRS score)</li><li>How to tackle key control families like Access Control, Awareness &amp; Training, and Audit &amp; Accountability</li><li>The critical mistakes contractors make (and how to avoid them)</li><li>Why <b>documentation</b> is the #1 secret weapon for CMMC success</li><li>Real-world tips for manufacturing, machine shop, and aerospace contractors navigating CMMC Level 2</li></ul><p>🔥 Don’t wait until an assessor says “No Soup for You” — build a compliance system that actually protects your business and wins contracts.</p><p>👉 <b>Need help fast-tracking your compliance journey?</b> </p><p>Visit <a href='https://cmmccomplianceguide.com'>https://cmmccomplianceguide.com</a> to download free resources or schedule a discovery call.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p><b>Feeling overwhelmed by CMMC compliance and NIST 800-171’s 110 controls? You’re not alone — but you don’t have to be stuck.</b></p><p>In this episode of the <em>CMMC Compliance Guide Podcast</em>, Brooke and Austin break down NIST 800-171 Revision 2 in plain English — no government-speak, no tech jargon — so you can finally understand what each control family means for your business.</p><p>You&apos;ll learn:</p><ul><li>What NIST 800-171 really requires (and why it matters for your SPRS score)</li><li>How to tackle key control families like Access Control, Awareness &amp; Training, and Audit &amp; Accountability</li><li>The critical mistakes contractors make (and how to avoid them)</li><li>Why <b>documentation</b> is the #1 secret weapon for CMMC success</li><li>Real-world tips for manufacturing, machine shop, and aerospace contractors navigating CMMC Level 2</li></ul><p>🔥 Don’t wait until an assessor says “No Soup for You” — build a compliance system that actually protects your business and wins contracts.</p><p>👉 <b>Need help fast-tracking your compliance journey?</b> </p><p>Visit <a href='https://cmmccomplianceguide.com'>https://cmmccomplianceguide.com</a> to download free resources or schedule a discovery call.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/17059656-decoding-nist-800-171-your-plain-english-path-to-cmmc-level-2-compliance.mp3" length="42751175" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17059656</guid>
    <pubDate>Fri, 02 May 2025 08:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17059656/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17059656/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17059656/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/17059656/transcript.vtt" type="text/vtt" />
    <itunes:duration>3560</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>17</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>How to Improve Your SPRS Score Before It Costs You Contracts</itunes:title>
    <title>How to Improve Your SPRS Score Before It Costs You Contracts</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! Is your SPRS score putting your DoD contracts at risk? In this episode of the CMMC Compliance Guide, we break down exactly what the SPRS score is, why it matters, and how to improve it fast—before you lose out on federal work.  Whether you're stuck at -72 or hovering at 80, we’ll walk you through how to get to 110 with practical, plain-English guidance. From gap analysis to POA&amp;Ms, system security plans, encryption, MFA, and the...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>Is your SPRS score putting your DoD contracts at risk? In this episode of the CMMC Compliance Guide, we break down exactly what the SPRS score is, why it matters, and how to improve it fast—before you lose out on federal work.<br/><br/>Whether you&apos;re stuck at -72 or hovering at 80, we’ll walk you through how to get to 110 with practical, plain-English guidance. From gap analysis to POA&amp;Ms, system security plans, encryption, MFA, and the best GRC tools—we’re covering it all.<br/><br/>👉 Schedule your FREE SPRS Roadmap Session (Limited Time):  <a href='https://cmmccomplianceguide.com/free-sprs-roadmap'>www.cmmccomplianceguide.com/free-sprs-roadmap</a><br/>✅ $1,500 Value — No pitch, no pressure. Just expert help.</p><p>🎯 What You&apos;ll Learn:<br/>✅What an SPRS score is and why it matters<br/>✅How to assess your current score (and why most are wrong)<br/>✅What documentation and tech controls you must have<br/>✅How to get to 110 — even if you’re starting from a negative score</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>Is your SPRS score putting your DoD contracts at risk? In this episode of the CMMC Compliance Guide, we break down exactly what the SPRS score is, why it matters, and how to improve it fast—before you lose out on federal work.<br/><br/>Whether you&apos;re stuck at -72 or hovering at 80, we’ll walk you through how to get to 110 with practical, plain-English guidance. From gap analysis to POA&amp;Ms, system security plans, encryption, MFA, and the best GRC tools—we’re covering it all.<br/><br/>👉 Schedule your FREE SPRS Roadmap Session (Limited Time):  <a href='https://cmmccomplianceguide.com/free-sprs-roadmap'>www.cmmccomplianceguide.com/free-sprs-roadmap</a><br/>✅ $1,500 Value — No pitch, no pressure. Just expert help.</p><p>🎯 What You&apos;ll Learn:<br/>✅What an SPRS score is and why it matters<br/>✅How to assess your current score (and why most are wrong)<br/>✅What documentation and tech controls you must have<br/>✅How to get to 110 — even if you’re starting from a negative score</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/16962784-how-to-improve-your-sprs-score-before-it-costs-you-contracts.mp3" length="6652327" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-16962784</guid>
    <pubDate>Fri, 11 Apr 2025 12:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16962784/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16962784/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16962784/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16962784/transcript.vtt" type="text/vtt" />
    <podcast:soundbite startTime="89.417" duration="30.0" />
    <itunes:duration>552</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>16</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>The E.A.S.Y Framework That Makes CMMC Actually Doable</itunes:title>
    <title>The E.A.S.Y Framework That Makes CMMC Actually Doable</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! If someone tells you CMMC compliance can't be easy… they’re not necessarily wrong — but they’re also missing the point.  In this episode of the CMMC Compliance Guide Podcast, Austin and Brooke from Justice IT Consulting break down one of the biggest myths in the compliance space: that achieving CMMC compliance has to be overwhelming, time-consuming, and painfully complex.  Using our E.A.S.Y. framework, we’re showing you how strategi...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>If someone tells you CMMC compliance can&apos;t be easy… they’re not necessarily wrong — but they’re also missing the point.<br/><br/>In this episode of the CMMC Compliance Guide Podcast, Austin and Brooke from Justice IT Consulting break down one of the biggest myths in the compliance space: that achieving CMMC compliance has to be overwhelming, time-consuming, and painfully complex.<br/><br/>Using our E.A.S.Y. framework, we’re showing you how strategic companies are simplifying their compliance efforts and turning cybersecurity into a competitive edge:<br/><br/>✅ E – Expert Guided: Why going it alone can cost you more in time and money.<br/>✅ A – Aligned to Requirements: How to avoid the tech-first trap and focus on business process.<br/>✅ S – Streamlined Approach: Proven tools, trusted frameworks, and no need to reinvent the wheel.<br/>✅ Y – Your Competitive Advantage: Compliance isn’t just a checkbox — it’s a business differentiator.<br/><br/>Whether you&apos;re a defense contractor starting your compliance journey or trying to stay ahead of evolving requirements, this episode gives you the mindset and framework to make CMMC easier — not effortless, but easier.<br/><br/>📞 Need help fast-tracking your compliance? <br/>Reach out at: <a href='https://cmmccomplianceguide.com/podcast'>cmmccomplianceguide.com/podcast</a> — we’ll answer your questions for free right here on the show.<br/><br/><br/></p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>If someone tells you CMMC compliance can&apos;t be easy… they’re not necessarily wrong — but they’re also missing the point.<br/><br/>In this episode of the CMMC Compliance Guide Podcast, Austin and Brooke from Justice IT Consulting break down one of the biggest myths in the compliance space: that achieving CMMC compliance has to be overwhelming, time-consuming, and painfully complex.<br/><br/>Using our E.A.S.Y. framework, we’re showing you how strategic companies are simplifying their compliance efforts and turning cybersecurity into a competitive edge:<br/><br/>✅ E – Expert Guided: Why going it alone can cost you more in time and money.<br/>✅ A – Aligned to Requirements: How to avoid the tech-first trap and focus on business process.<br/>✅ S – Streamlined Approach: Proven tools, trusted frameworks, and no need to reinvent the wheel.<br/>✅ Y – Your Competitive Advantage: Compliance isn’t just a checkbox — it’s a business differentiator.<br/><br/>Whether you&apos;re a defense contractor starting your compliance journey or trying to stay ahead of evolving requirements, this episode gives you the mindset and framework to make CMMC easier — not effortless, but easier.<br/><br/>📞 Need help fast-tracking your compliance? <br/>Reach out at: <a href='https://cmmccomplianceguide.com/podcast'>cmmccomplianceguide.com/podcast</a> — we’ll answer your questions for free right here on the show.<br/><br/><br/></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/16916610-the-e-a-s-y-framework-that-makes-cmmc-actually-doable.mp3" length="9566952" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-16916610</guid>
    <pubDate>Fri, 04 Apr 2025 09:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16916610/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16916610/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16916610/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16916610/transcript.vtt" type="text/vtt" />
    <podcast:soundbite startTime="24.833" duration="35.0" />
    <itunes:duration>795</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>15</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>CMMC Compliance Consulting vs. DIY Compliance: Which Is the Smarter, More Cost-Effective Choice?</itunes:title>
    <title>CMMC Compliance Consulting vs. DIY Compliance: Which Is the Smarter, More Cost-Effective Choice?</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! In this episode of The CMMC Compliance Guide Podcast, Brooke and Austin dive into a key question many DoD contractors face: Should you handle CMMC compliance yourself or hire a consultant?  We break down the risks, costs, and benefits to help you make the best decision for your business. Discover the 6 major risks of DIY compliance, including:  1️⃣ Losing DoD contracts due to non-compliance 2️⃣ Keeping up with ever-changing CMMC req...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>In this episode of The CMMC Compliance Guide Podcast, Brooke and Austin dive into a key question many DoD contractors face: Should you handle CMMC compliance yourself or hire a consultant?<br/><br/>We break down the risks, costs, and benefits to help you make the best decision for your business. Discover the 6 major risks of DIY compliance, including:<br/><br/>1️⃣ Losing DoD contracts due to non-compliance<br/>2️⃣ Keeping up with ever-changing CMMC requirements<br/>3️⃣ Hidden costs that make DIY compliance more expensive<br/>4️⃣ The gap in IT teams’ compliance expertise<br/>5️⃣ Security risks that linger even after passing an assessment<br/>6️⃣ How CMMC assessors prioritize well-prepared organizations<br/><br/>🎯 Whether you’re starting your compliance journey or stuck midway, this episode offers actionable advice to help you stay compliant and secure.<br/><br/>🔗 For expert guidance and resources, visit <a href='https://cmmccomplianceguide.com/'>https://cmmccomplianceguide.com/</a><br/><br/>👍 Don&apos;t forget to like, comment, and subscribe for more tips on achieving CMMC compliance with confidence.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>In this episode of The CMMC Compliance Guide Podcast, Brooke and Austin dive into a key question many DoD contractors face: Should you handle CMMC compliance yourself or hire a consultant?<br/><br/>We break down the risks, costs, and benefits to help you make the best decision for your business. Discover the 6 major risks of DIY compliance, including:<br/><br/>1️⃣ Losing DoD contracts due to non-compliance<br/>2️⃣ Keeping up with ever-changing CMMC requirements<br/>3️⃣ Hidden costs that make DIY compliance more expensive<br/>4️⃣ The gap in IT teams’ compliance expertise<br/>5️⃣ Security risks that linger even after passing an assessment<br/>6️⃣ How CMMC assessors prioritize well-prepared organizations<br/><br/>🎯 Whether you’re starting your compliance journey or stuck midway, this episode offers actionable advice to help you stay compliant and secure.<br/><br/>🔗 For expert guidance and resources, visit <a href='https://cmmccomplianceguide.com/'>https://cmmccomplianceguide.com/</a><br/><br/>👍 Don&apos;t forget to like, comment, and subscribe for more tips on achieving CMMC compliance with confidence.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/16836328-cmmc-compliance-consulting-vs-diy-compliance-which-is-the-smarter-more-cost-effective-choice.mp3" length="23991645" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-16836328</guid>
    <pubDate>Fri, 28 Mar 2025 08:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16836328/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16836328/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16836328/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16836328/transcript.vtt" type="text/vtt" />
    <podcast:soundbite startTime="435.305" duration="30.0" />
    <itunes:duration>1997</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>14</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Your IT Provider: The Keystone to Passing CMMC – or the Hidden Risk That Could Cost You Everything</itunes:title>
    <title>Your IT Provider: The Keystone to Passing CMMC – or the Hidden Risk That Could Cost You Everything</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! In this episode of The CMMC Compliance Guide Podcast, Brooke and Stacey reveal a critical factor that could make or break your compliance journey: your IT provider.  ✅ Discover why your IT provider plays a crucial role in your CMMC assessment. ✅ Learn the risks of working with an unqualified IT provider — and how they could cost you contracts. ✅ Find out what a qualified IT provider should bring to the table to simplify your complia...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>In this episode of The CMMC Compliance Guide Podcast, Brooke and Stacey reveal a critical factor that could make or break your compliance journey: your IT provider.<br/><br/>✅ Discover why your IT provider plays a crucial role in your CMMC assessment.<br/>✅ Learn the risks of working with an unqualified IT provider — and how they could cost you contracts.<br/>✅ Find out what a qualified IT provider should bring to the table to simplify your compliance process.<br/>✅ Get actionable tips on how to vet an IT provider to ensure they’re an asset — not a liability.<br/><br/>🎯 Don’t leave your compliance journey to chance. Tune in to learn how to make your IT provider your strongest ally.<br/><br/>🔗 For more resources, visit <a href='https://cmmccomplianceguide.com/'>https://cmmccomplianceguide.com/</a></p><p>❗Get past all the CMMC jargon by downloading our CMMC Glossary: <a href='https://cmmccomplianceguide.com/glossary'>https://cmmccomplianceguide.com/glossary</a></p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>In this episode of The CMMC Compliance Guide Podcast, Brooke and Stacey reveal a critical factor that could make or break your compliance journey: your IT provider.<br/><br/>✅ Discover why your IT provider plays a crucial role in your CMMC assessment.<br/>✅ Learn the risks of working with an unqualified IT provider — and how they could cost you contracts.<br/>✅ Find out what a qualified IT provider should bring to the table to simplify your compliance process.<br/>✅ Get actionable tips on how to vet an IT provider to ensure they’re an asset — not a liability.<br/><br/>🎯 Don’t leave your compliance journey to chance. Tune in to learn how to make your IT provider your strongest ally.<br/><br/>🔗 For more resources, visit <a href='https://cmmccomplianceguide.com/'>https://cmmccomplianceguide.com/</a></p><p>❗Get past all the CMMC jargon by downloading our CMMC Glossary: <a href='https://cmmccomplianceguide.com/glossary'>https://cmmccomplianceguide.com/glossary</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/16823166-your-it-provider-the-keystone-to-passing-cmmc-or-the-hidden-risk-that-could-cost-you-everything.mp3" length="6198122" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-16823166</guid>
    <pubDate>Fri, 21 Mar 2025 08:00:00 -0500</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16823166/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16823166/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16823166/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16823166/transcript.vtt" type="text/vtt" />
    <podcast:soundbite startTime="446.0" duration="23.0" />
    <podcast:chapters url="https://www.buzzsprout.com/2428223/16823166/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Your IT Provider: The Keystone to Passing CMMC – or the Hidden Risk That Could Cost You Everything" />
  <psc:chapter start="1:41" title="How IT Providers are Included in CMMC Assessments" />
  <psc:chapter start="2:10" title="Risks of Working with an Unqualified IT Provider" />
  <psc:chapter start="2:41" title="What a Qualified IT Provider Brings to the Table" />
  <psc:chapter start="3:07" title="Key Certifications to Look for in an IT Provider" />
  <psc:chapter start="5:00" title="Importance of IT Providers with C3PAO Relationships" />
  <psc:chapter start="6:02" title="Key Questions to Ask When Vetting IT Providers" />
  <psc:chapter start="6:37" title="When Should IT Provider Answers Be a Red Flag?" />
  <psc:chapter start="6:40" title="Explaining Certifications: CCP, RP, and RPO" />
  <psc:chapter start="7:43" title="Why Industry Involvement Matters for IT Providers" />
</psc:chapters>
    <itunes:duration>514</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>13</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>How the DoD’s Cybersecurity Crackdown Could Impact Your Aerospace Contracts</itunes:title>
    <title>How the DoD’s Cybersecurity Crackdown Could Impact Your Aerospace Contracts</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! The DoD is tightening its cybersecurity regulations, and your aerospace contracts could be on the line. In this episode of The CMMC Compliance Guide Podcast, we break down the latest changes to CMMC, DFARS, and FAR that could directly impact your business.  Join Austin and Brooke from Justice IT Consulting as they explain: ✅ The upcoming CMMC, DFARS, and FAR rule changes &amp; deadlines ✅ Why self-reported compliance is no longer en...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>The DoD is tightening its cybersecurity regulations, and your aerospace contracts could be on the line. In this episode of The CMMC Compliance Guide Podcast, we break down the latest changes to CMMC, DFARS, and FAR that could directly impact your business.<br/><br/>Join Austin and Brooke from Justice IT Consulting as they explain:<br/>✅ The upcoming CMMC, DFARS, and FAR rule changes &amp; deadlines<br/>✅ Why self-reported compliance is no longer enough<br/>✅ How SPRS scores and third-party assessments will determine contract eligibility<br/>✅ The legal risks of non-compliance, including False Claims Act violations<br/>✅ Steps you must take right now to stay ahead of the cybersecurity crackdown<br/><br/>Don’t wait until it’s too late! Compliance deadlines are fast approaching, and failing to prepare could mean losing out on DoD contracts. Stay informed, stay compliant, and protect your business.<br/><br/>📌 Download your free guide here: https://cmmccomplianceguide.com/ultimate-aerospace-contractor-guide<br/><br/>📌 Need help with compliance? Contact us at https://cmmccomplianceguide.com<br/><br/><br/></p> ]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>The DoD is tightening its cybersecurity regulations, and your aerospace contracts could be on the line. In this episode of The CMMC Compliance Guide Podcast, we break down the latest changes to CMMC, DFARS, and FAR that could directly impact your business.<br/><br/>Join Austin and Brooke from Justice IT Consulting as they explain:<br/>✅ The upcoming CMMC, DFARS, and FAR rule changes &amp; deadlines<br/>✅ Why self-reported compliance is no longer enough<br/>✅ How SPRS scores and third-party assessments will determine contract eligibility<br/>✅ The legal risks of non-compliance, including False Claims Act violations<br/>✅ Steps you must take right now to stay ahead of the cybersecurity crackdown<br/><br/>Don’t wait until it’s too late! Compliance deadlines are fast approaching, and failing to prepare could mean losing out on DoD contracts. Stay informed, stay compliant, and protect your business.<br/><br/>📌 Download your free guide here: https://cmmccomplianceguide.com/ultimate-aerospace-contractor-guide<br/><br/>📌 Need help with compliance? Contact us at https://cmmccomplianceguide.com<br/><br/><br/></p> ]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/16746372-how-the-dod-s-cybersecurity-crackdown-could-impact-your-aerospace-contracts.mp3" length="37443199" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-16746372</guid>
    <pubDate>Fri, 07 Mar 2025 08:00:00 -0600</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16746372/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16746372/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16746372/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16746372/transcript.vtt" type="text/vtt" />
    <podcast:soundbite startTime="835.0" duration="30.0" />
    <itunes:duration>3118</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>12</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>CyberAB January Town Hall Updates: Key CMMC &amp; FAR CUI Rule Insights for DoD Contractors</itunes:title>
    <title>CyberAB January Town Hall Updates: Key CMMC &amp; FAR CUI Rule Insights for DoD Contractors</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! In this episode of The CMMC Compliance Guide Podcast, we break down the most important updates from the CyberAB January Town Hall. From the latest developments in CMMC implementation to the newly proposed FAR CUI rule, we discuss what these changes mean for DoD contractors and beyond. Key Takeaways: The CMMC program is officially live under CFR 32—what this means for your business.The FAR CUI rule and how it expands compliance beyon...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>In this episode of <em>The CMMC Compliance Guide Podcast</em>, we break down the most important updates from the CyberAB January Town Hall. From the latest developments in CMMC implementation to the newly proposed FAR CUI rule, we discuss what these changes mean for DoD contractors and beyond.</p><p><b>Key Takeaways:</b></p><ul><li>The CMMC program is officially live under CFR 32—what this means for your business.</li><li>The FAR CUI rule and how it expands compliance beyond the DoD.</li><li>What DoD contractors should be doing <b>right now</b> to stay ahead of upcoming certification requirements.</li><li>The latest challenges in obtaining CMMC Level 2 certification and how to navigate delays.</li></ul><p>If your business is in the Defense Industrial Base (DIB) or sells to the Federal Government, this episode is a must-listen! Stay informed, stay compliant, and don’t get left behind.</p><p>📩 Got questions? Contact us at <a href='https://cmmccomplianceguide.com/podcast'>cmmccomplianceguide.com/podcast</a> – we’ll answer them for free on the podcast!</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>In this episode of <em>The CMMC Compliance Guide Podcast</em>, we break down the most important updates from the CyberAB January Town Hall. From the latest developments in CMMC implementation to the newly proposed FAR CUI rule, we discuss what these changes mean for DoD contractors and beyond.</p><p><b>Key Takeaways:</b></p><ul><li>The CMMC program is officially live under CFR 32—what this means for your business.</li><li>The FAR CUI rule and how it expands compliance beyond the DoD.</li><li>What DoD contractors should be doing <b>right now</b> to stay ahead of upcoming certification requirements.</li><li>The latest challenges in obtaining CMMC Level 2 certification and how to navigate delays.</li></ul><p>If your business is in the Defense Industrial Base (DIB) or sells to the Federal Government, this episode is a must-listen! Stay informed, stay compliant, and don’t get left behind.</p><p>📩 Got questions? Contact us at <a href='https://cmmccomplianceguide.com/podcast'>cmmccomplianceguide.com/podcast</a> – we’ll answer them for free on the podcast!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/16684528-cyberab-january-town-hall-updates-key-cmmc-far-cui-rule-insights-for-dod-contractors.mp3" length="11324329" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-16684528</guid>
    <pubDate>Fri, 28 Feb 2025 08:00:00 -0600</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16684528/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16684528/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16684528/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16684528/transcript.vtt" type="text/vtt" />
    <itunes:duration>941</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>11</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>CMMC Compliance: How to Win DoD Contracts &amp; Avoid Costly Mistakes</itunes:title>
    <title>CMMC Compliance: How to Win DoD Contracts &amp; Avoid Costly Mistakes</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! In this week’s episode, Brooke Justice and guest cohost Stacey break down one of the most crucial topics for DoD contractors: how CMMC compliance directly impacts your ability to win and keep defense contracts. From understanding compliance levels to avoiding costly mistakes, we’ll walk you through everything you need to know to stay competitive and avoid compliance pitfalls. You’ll learn: ✅ Why CMMC is becoming a non-negotiable req...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>In this week’s episode, Brooke Justice and guest cohost Stacey break down one of the most crucial topics for DoD contractors: how CMMC compliance directly impacts your ability to win and keep defense contracts.</p><p>From understanding compliance levels to avoiding costly mistakes, we’ll walk you through everything you need to know to stay competitive and avoid compliance pitfalls. You’ll learn:</p><p>✅ Why CMMC is becoming a non-negotiable requirement for DoD contracts<br/>✅ How being CMMC compliant gives you a competitive edge<br/>✅ What compliance level you should aim for to secure future opportunities<br/>✅ The biggest mistakes companies make that put their contracts at risk<br/>✅ How to ensure your supply chain isn’t a weak link</p><p>Whether you’re a prime contractor, subcontractor, or just starting your CMMC journey, this episode is packed with actionable insights to help you navigate the compliance landscape.</p><p>💡 Have questions? We want to hear from you! Send us your questions at <a href='https://cmmccomplianceguide.com/podcast'>cmmccomplianceguide.com</a> and we’ll answer them in a future episode—for free!</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>In this week’s episode, Brooke Justice and guest cohost Stacey break down one of the most crucial topics for DoD contractors: how CMMC compliance directly impacts your ability to win and keep defense contracts.</p><p>From understanding compliance levels to avoiding costly mistakes, we’ll walk you through everything you need to know to stay competitive and avoid compliance pitfalls. You’ll learn:</p><p>✅ Why CMMC is becoming a non-negotiable requirement for DoD contracts<br/>✅ How being CMMC compliant gives you a competitive edge<br/>✅ What compliance level you should aim for to secure future opportunities<br/>✅ The biggest mistakes companies make that put their contracts at risk<br/>✅ How to ensure your supply chain isn’t a weak link</p><p>Whether you’re a prime contractor, subcontractor, or just starting your CMMC journey, this episode is packed with actionable insights to help you navigate the compliance landscape.</p><p>💡 Have questions? We want to hear from you! Send us your questions at <a href='https://cmmccomplianceguide.com/podcast'>cmmccomplianceguide.com</a> and we’ll answer them in a future episode—for free!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/16553632-cmmc-compliance-how-to-win-dod-contracts-avoid-costly-mistakes.mp3" length="19032497" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-16553632</guid>
    <pubDate>Fri, 07 Feb 2025 08:00:00 -0600</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16553632/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16553632/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16553632/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16553632/transcript.vtt" type="text/vtt" />
    <itunes:duration>1583</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>10</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>FedRAMP Authorization vs. Equivalency: What Your Business Needs to Know</itunes:title>
    <title>FedRAMP Authorization vs. Equivalency: What Your Business Needs to Know</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! In this episode of The CMMC Compliance Guide Podcast, Brooke and Stacey from Justice IT Consulting dive deep into the critical distinctions between FedRAMP Authorization and FedRAMP Equivalency. Whether you're leveraging cloud services for compliance or planning your next steps in CMMC certification, understanding these two pathways is crucial. We break down the key differences, discuss how each impacts your compliance journey, and ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>In this episode of <em>The CMMC Compliance Guide Podcast</em>, Brooke and Stacey from Justice IT Consulting dive deep into the critical distinctions between <b>FedRAMP Authorization</b> and <b>FedRAMP Equivalency</b>. Whether you&apos;re leveraging cloud services for compliance or planning your next steps in CMMC certification, understanding these two pathways is crucial. We break down the key differences, discuss how each impacts your compliance journey, and provide actionable advice to help you make the right choice for your business.</p><p>Tune in to learn:</p><ul><li>What FedRAMP is and why it matters for cloud security.</li><li>The pros and cons of Authorization vs. Equivalency.</li><li>How each option affects your CMMC assessment timelines and costs.</li><li>Practical tips to stay ahead in your compliance efforts.</li></ul><p>Got questions? We’re answering them for free on the podcast! Reach out via text, email, or call at <a href='http://cmmccomplianceguide.com'>cmmccomplianceguide.com</a>.</p><p><b>Don&apos;t miss this essential episode—subscribe now and stay compliant, stay secure!</b></p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>In this episode of <em>The CMMC Compliance Guide Podcast</em>, Brooke and Stacey from Justice IT Consulting dive deep into the critical distinctions between <b>FedRAMP Authorization</b> and <b>FedRAMP Equivalency</b>. Whether you&apos;re leveraging cloud services for compliance or planning your next steps in CMMC certification, understanding these two pathways is crucial. We break down the key differences, discuss how each impacts your compliance journey, and provide actionable advice to help you make the right choice for your business.</p><p>Tune in to learn:</p><ul><li>What FedRAMP is and why it matters for cloud security.</li><li>The pros and cons of Authorization vs. Equivalency.</li><li>How each option affects your CMMC assessment timelines and costs.</li><li>Practical tips to stay ahead in your compliance efforts.</li></ul><p>Got questions? We’re answering them for free on the podcast! Reach out via text, email, or call at <a href='http://cmmccomplianceguide.com'>cmmccomplianceguide.com</a>.</p><p><b>Don&apos;t miss this essential episode—subscribe now and stay compliant, stay secure!</b></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/16485617-fedramp-authorization-vs-equivalency-what-your-business-needs-to-know.mp3" length="10401130" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-16485617</guid>
    <pubDate>Fri, 24 Jan 2025 08:00:00 -0600</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16485617/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16485617/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16485617/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16485617/transcript.vtt" type="text/vtt" />
    <itunes:duration>864</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>9</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>2024 Compliance Wrapped: Insights from CEIC East</itunes:title>
    <title>2024 Compliance Wrapped: Insights from CEIC East</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! In this episode of The CMMC Compliance Guide Podcast, Brooke Justice is joined by guest cohost Stacey Flores, stepping in for Austin Justice, to bring you the key takeaways from the recent CEIC East conference. If you missed the event, don’t worry—Brooke and Stacey are here to fill you in on everything you need to know to navigate the ever-evolving world of CMMC compliance in 2024. What’s in Store: 🚀 CMMC Rollout Updates: Find out w...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>In this episode of <em>The CMMC Compliance Guide Podcast</em>, <b>Brooke Justice</b> is joined by guest cohost <b>Stacey Flores</b>, stepping in for Austin Justice, to bring you the key takeaways from the recent CEIC East conference. If you missed the event, don’t worry—Brooke and Stacey are here to fill you in on everything you need to know to navigate the ever-evolving world of CMMC compliance in 2024.</p><p><b>What’s in Store:</b></p><ul><li>🚀 <b>CMMC Rollout Updates:</b> Find out why the rollout is moving faster than expected and how prime contractors might push subs to certify early.</li><li>📋 <b>Certification Timing Tips:</b> Learn how to avoid assessment bottlenecks and prepare your organization now.</li><li>🔐 <b>Key Regulatory Changes:</b> Get the latest on POAM limits, FIPS encryption updates, ESP requirements, and more.</li><li>🛠️ <b>Actionable Advice:</b> Practical tips for refining your SSP, aligning with ESPs, and staying ahead in compliance.</li></ul><p>Brooke and Stacey dive deep into the insights gained from networking with policy experts, vendors, and assessors at CEIC East, offering practical advice to help you stay on track with compliance and secure your contracts.</p><p>Whether you’re a seasoned compliance pro or just starting your journey, this episode has something for everyone.</p><p><b>Engage with Us:</b><br/>Have questions or need more guidance? Reach out to us at <a href='https://cmmccomplianceguide.com/'>cmmccomplianceguide.com</a>—we’re here to help!</p> ]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>In this episode of <em>The CMMC Compliance Guide Podcast</em>, <b>Brooke Justice</b> is joined by guest cohost <b>Stacey Flores</b>, stepping in for Austin Justice, to bring you the key takeaways from the recent CEIC East conference. If you missed the event, don’t worry—Brooke and Stacey are here to fill you in on everything you need to know to navigate the ever-evolving world of CMMC compliance in 2024.</p><p><b>What’s in Store:</b></p><ul><li>🚀 <b>CMMC Rollout Updates:</b> Find out why the rollout is moving faster than expected and how prime contractors might push subs to certify early.</li><li>📋 <b>Certification Timing Tips:</b> Learn how to avoid assessment bottlenecks and prepare your organization now.</li><li>🔐 <b>Key Regulatory Changes:</b> Get the latest on POAM limits, FIPS encryption updates, ESP requirements, and more.</li><li>🛠️ <b>Actionable Advice:</b> Practical tips for refining your SSP, aligning with ESPs, and staying ahead in compliance.</li></ul><p>Brooke and Stacey dive deep into the insights gained from networking with policy experts, vendors, and assessors at CEIC East, offering practical advice to help you stay on track with compliance and secure your contracts.</p><p>Whether you’re a seasoned compliance pro or just starting your journey, this episode has something for everyone.</p><p><b>Engage with Us:</b><br/>Have questions or need more guidance? Reach out to us at <a href='https://cmmccomplianceguide.com/'>cmmccomplianceguide.com</a>—we’re here to help!</p> ]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/16454172-2024-compliance-wrapped-insights-from-ceic-east.mp3" length="20976373" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-16454172</guid>
    <pubDate>Fri, 17 Jan 2025 10:00:00 -0600</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16454172/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16454172/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16454172/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16454172/transcript.vtt" type="text/vtt" />
    <podcast:chapters url="https://www.buzzsprout.com/2428223/16454172/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="2024 Compliance Wrapped: Insights from CEIC East" />
  <psc:chapter start="0:24" title="CMMC Compliance Seek East Recap" />
  <psc:chapter start="5:08" title="CMMC Compliance Certification Updates Await" />
  <psc:chapter start="17:44" title="CMMC Compliance Certification Preparation Advice" />
</psc:chapters>
    <itunes:duration>1745</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>8</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>A Digital War or an Unreasonable Ask for SMB&#39;s? (WARNING: SOAPBOX EPISODE)</itunes:title>
    <title>A Digital War or an Unreasonable Ask for SMB&#39;s? (WARNING: SOAPBOX EPISODE)</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! In this thought-provoking episode of the CMMC Compliance Guide Podcast, Brooke and Austin Justice tackle a question that’s top of mind for many small and medium-sized businesses in the defense supply chain: Is CMMC a necessary defense in a digital war, or an unreasonable burden on SMBs?  Key Discussion Points: The sustainability of CMMC for SMBs: Is it too complex and costly?The DoD’s perspective on cybersecurity as a digital war ag...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>In this thought-provoking episode of the CMMC Compliance Guide Podcast, Brooke and Austin Justice tackle a question that’s top of mind for many small and medium-sized businesses in the defense supply chain: Is CMMC a necessary defense in a digital war, or an unreasonable burden on SMBs?<br/><br/><b>Key Discussion Points:</b></p><ul><li>The sustainability of CMMC for SMBs: Is it too complex and costly?</li><li>The DoD’s perspective on cybersecurity as a digital war against threats like IP theft.</li><li>Strategies for SMBs to balance compliance costs with staying in defense contracts.</li><li>Practical steps for SMBs to start their compliance journey today.</li></ul><p><br/><br/><br/></p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>In this thought-provoking episode of the CMMC Compliance Guide Podcast, Brooke and Austin Justice tackle a question that’s top of mind for many small and medium-sized businesses in the defense supply chain: Is CMMC a necessary defense in a digital war, or an unreasonable burden on SMBs?<br/><br/><b>Key Discussion Points:</b></p><ul><li>The sustainability of CMMC for SMBs: Is it too complex and costly?</li><li>The DoD’s perspective on cybersecurity as a digital war against threats like IP theft.</li><li>Strategies for SMBs to balance compliance costs with staying in defense contracts.</li><li>Practical steps for SMBs to start their compliance journey today.</li></ul><p><br/><br/><br/></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/16178302-a-digital-war-or-an-unreasonable-ask-for-smb-s-warning-soapbox-episode.mp3" length="36249905" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-16178302</guid>
    <pubDate>Tue, 26 Nov 2024 10:00:00 -0600</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16178302/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16178302/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16178302/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16178302/transcript.vtt" type="text/vtt" />
    <podcast:chapters url="https://www.buzzsprout.com/2428223/16178302/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="A Digital War or an Unreasonable Ask for SMB&#39;s? (WARNING: SOAPBOX EPISODE)" />
  <psc:chapter start="0:41" title="Introduction" />
  <psc:chapter start="1:21" title="Main Discussion" />
  <psc:chapter start="7:21" title="The Broader Perspective" />
  <psc:chapter start="23:21" title="Economic Considerations for SMBs" />
  <psc:chapter start="34:21" title="Practical Steps for SMBs" />
  <psc:chapter start="44:21" title="Closing Thoughts and Next Steps" />
</psc:chapters>
    <itunes:duration>3018</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>7</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>November 2024 CyberAB Town Hall Recap: Essential CMMC 2.0 Updates for Defense Contractors</itunes:title>
    <title>November 2024 CyberAB Town Hall Recap: Essential CMMC 2.0 Updates for Defense Contractors</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! In this episode, Brooke and Austin Justice dive into the latest CyberAB townhall update, sharing key insights for defense contractors. Stay informed on the latest CMMC developments, compliance changes, and how they could impact your business. Whether you're navigating CMMC 2.0 or simply trying to stay ahead of cybersecurity requirements, this recap is for you!  Topics Covered: Important updates from CyberABKey compliance insights fo...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>In this episode, Brooke and Austin Justice dive into the latest CyberAB townhall update, sharing key insights for defense contractors. Stay informed on the latest CMMC developments, compliance changes, and how they could impact your business. Whether you&apos;re navigating CMMC 2.0 or simply trying to stay ahead of cybersecurity requirements, this recap is for you!<br/><br/><b>Topics Covered:</b></p><ul><li>Important updates from CyberAB</li><li>Key compliance insights for contractors</li><li>How these changes affect your CMMC journey</li></ul><p><a href='https://www.justiceitc.com/48cfr/'>Download Your Copy of the 48 CFR Guidebook Here</a></p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>In this episode, Brooke and Austin Justice dive into the latest CyberAB townhall update, sharing key insights for defense contractors. Stay informed on the latest CMMC developments, compliance changes, and how they could impact your business. Whether you&apos;re navigating CMMC 2.0 or simply trying to stay ahead of cybersecurity requirements, this recap is for you!<br/><br/><b>Topics Covered:</b></p><ul><li>Important updates from CyberAB</li><li>Key compliance insights for contractors</li><li>How these changes affect your CMMC journey</li></ul><p><a href='https://www.justiceitc.com/48cfr/'>Download Your Copy of the 48 CFR Guidebook Here</a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/16178280-november-2024-cyberab-town-hall-recap-essential-cmmc-2-0-updates-for-defense-contractors.mp3" length="23328631" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-16178280</guid>
    <pubDate>Tue, 26 Nov 2024 10:00:00 -0600</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16178280/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16178280/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16178280/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16178280/transcript.vtt" type="text/vtt" />
    <podcast:chapters url="https://www.buzzsprout.com/2428223/16178280/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="November 2024 CyberAB Town Hall Recap: Essential CMMC 2.0 Updates for Defense Contractors" />
  <psc:chapter start="0:41" title="Introduction" />
  <psc:chapter start="1:21" title="CyberAB Town Hall Overview" />
  <psc:chapter start="1:49" title="32 CFR Final Rule Published" />
  <psc:chapter start="3:21" title="Implications of 32 CFR and Assessment Readiness" />
  <psc:chapter start="4:56" title="M&amp;A Activity and Compliance" />
  <psc:chapter start="7:21" title="ESPs (External Service Providers) Clarifications" />
  <psc:chapter start="12:41" title="The Risks of Failing an Assessment" />
  <psc:chapter start="14:32" title="False Claims Act and Compliance Accountability" />
  <psc:chapter start="16:53" title="48 CFR Proposed Rule and Rollout Timeline" />
  <psc:chapter start="27:27" title="Flow-Down Rule and Subcontractor Responsibilities" />
  <psc:chapter start="29:35" title="Practical Preparation Tips" />
</psc:chapters>
    <itunes:duration>1941</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>6</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>A Conversation with an Assessor ft. Chris Silvers</itunes:title>
    <title>A Conversation with an Assessor ft. Chris Silvers</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! In this special episode of the CMMC Compliance Guide Podcast, hosts Brooke and Austin Justice are joined by Chris Silvers, one of less than 100 individuals officially certified as both a Certified CMMC Provisional Assessor and Instructor. With over 25 years of cybersecurity experience, Chris has led CMMC instruction for more than 1,000 students and has developed courses and practice exams with one of the only 51 Licensed Training Pr...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>In this special episode of the CMMC Compliance Guide Podcast, hosts Brooke and Austin Justice are joined by Chris Silvers, one of less than 100 individuals officially certified as both a Certified CMMC Provisional Assessor and Instructor. With over 25 years of cybersecurity experience, Chris has led CMMC instruction for more than 1,000 students and has developed courses and practice exams with one of the only 51 Licensed Training Providers recognized today. His active roles in thought leadership bodies such as the CMMC Industry Standards Council and the C3PAO Forum place him on the front lines of the CMMC 2.0 rollout, making him uniquely equipped to guide defense contractors through the certification process.<br/><br/><b>Key Topics Discussed:</b></p><ul><li>The role of a Certified CMMC Assessor and how they support businesses</li><li>Common pitfalls businesses face and how to avoid them</li><li>How to prepare financially and strategically for the assessment</li><li>Best practices for working with an assessor</li></ul>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>In this special episode of the CMMC Compliance Guide Podcast, hosts Brooke and Austin Justice are joined by Chris Silvers, one of less than 100 individuals officially certified as both a Certified CMMC Provisional Assessor and Instructor. With over 25 years of cybersecurity experience, Chris has led CMMC instruction for more than 1,000 students and has developed courses and practice exams with one of the only 51 Licensed Training Providers recognized today. His active roles in thought leadership bodies such as the CMMC Industry Standards Council and the C3PAO Forum place him on the front lines of the CMMC 2.0 rollout, making him uniquely equipped to guide defense contractors through the certification process.<br/><br/><b>Key Topics Discussed:</b></p><ul><li>The role of a Certified CMMC Assessor and how they support businesses</li><li>Common pitfalls businesses face and how to avoid them</li><li>How to prepare financially and strategically for the assessment</li><li>Best practices for working with an assessor</li></ul>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/16178268-a-conversation-with-an-assessor-ft-chris-silvers.mp3" length="49791649" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-16178268</guid>
    <pubDate>Tue, 26 Nov 2024 10:00:00 -0600</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16178268/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16178268/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16178268/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16178268/transcript.vtt" type="text/vtt" />
    <itunes:duration>4147</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>5</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>October 2024 CyberAB Town Hall Recap: CMMC 2.0 Updates You Can&#39;t Miss!</itunes:title>
    <title>October 2024 CyberAB Town Hall Recap: CMMC 2.0 Updates You Can&#39;t Miss!</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! In this episode, Brooke and Austin Justice dive into the latest CyberAB townhall update, sharing key insights for defense contractors. Stay informed on the latest CMMC developments, compliance changes, and how they could impact your business. Whether you're navigating CMMC 2.0 or simply trying to stay ahead of cybersecurity requirements, this recap is for you!  Topics Covered: Important updates from CyberABKey compliance insights fo...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>In this episode, Brooke and Austin Justice dive into the latest CyberAB townhall update, sharing key insights for defense contractors. Stay informed on the latest CMMC developments, compliance changes, and how they could impact your business. Whether you&apos;re navigating CMMC 2.0 or simply trying to stay ahead of cybersecurity requirements, this recap is for you!<br/><br/><b>Topics Covered:</b></p><ul><li>Important updates from CyberAB</li><li>Key compliance insights for contractors</li><li>How these changes affect your CMMC journey</li></ul>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>In this episode, Brooke and Austin Justice dive into the latest CyberAB townhall update, sharing key insights for defense contractors. Stay informed on the latest CMMC developments, compliance changes, and how they could impact your business. Whether you&apos;re navigating CMMC 2.0 or simply trying to stay ahead of cybersecurity requirements, this recap is for you!<br/><br/><b>Topics Covered:</b></p><ul><li>Important updates from CyberAB</li><li>Key compliance insights for contractors</li><li>How these changes affect your CMMC journey</li></ul>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/16178166-october-2024-cyberab-town-hall-recap-cmmc-2-0-updates-you-can-t-miss.mp3" length="11264422" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-16178166</guid>
    <pubDate>Tue, 26 Nov 2024 10:00:00 -0600</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16178166/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16178166/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16178166/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16178166/transcript.vtt" type="text/vtt" />
    <itunes:duration>936</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>4</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>How It All Began: The CMMC Compliance Guide Podcast Origin Story</itunes:title>
    <title>How It All Began: The CMMC Compliance Guide Podcast Origin Story</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! In this special episode, we take you behind the scenes to explore the origin story of the CMMC Compliance Guide Podcast. Join hosts, Austin and Brooke Justice as they share how the podcast began, its mission to help defense contractors navigate the complexities of CMMC compliance, and what drives our passion for making the process hassle-free. Whether you’re new to CMMC or a seasoned professional, this episode offers insights into h...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>In this special episode, we take you behind the scenes to explore the origin story of the CMMC Compliance Guide Podcast. Join hosts, Austin and Brooke Justice as they share how the podcast began, its mission to help defense contractors navigate the complexities of CMMC compliance, and what drives our passion for making the process hassle-free. Whether you’re new to CMMC or a seasoned professional, this episode offers insights into how we started and why we’re dedicated to supporting your compliance journey.<br/><br/><b>Key Takeaways:</b></p><ul><li>Why we launched the CMMC Compliance Guide Podcast</li><li>The challenges that led to the podcast&apos;s creation</li><li>How our mission evolved to simplify CMMC compliance for defense contractors</li><li>What&apos;s next for the podcast and our community</li></ul><p><br/><br/></p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>In this special episode, we take you behind the scenes to explore the origin story of the CMMC Compliance Guide Podcast. Join hosts, Austin and Brooke Justice as they share how the podcast began, its mission to help defense contractors navigate the complexities of CMMC compliance, and what drives our passion for making the process hassle-free. Whether you’re new to CMMC or a seasoned professional, this episode offers insights into how we started and why we’re dedicated to supporting your compliance journey.<br/><br/><b>Key Takeaways:</b></p><ul><li>Why we launched the CMMC Compliance Guide Podcast</li><li>The challenges that led to the podcast&apos;s creation</li><li>How our mission evolved to simplify CMMC compliance for defense contractors</li><li>What&apos;s next for the podcast and our community</li></ul><p><br/><br/></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/16178154-how-it-all-began-the-cmmc-compliance-guide-podcast-origin-story.mp3" length="13771539" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-16178154</guid>
    <pubDate>Tue, 26 Nov 2024 10:00:00 -0600</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16178154/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16178154/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16178154/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16178154/transcript.vtt" type="text/vtt" />
    <itunes:duration>1145</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>3</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>32 CFR Rule Explained: Key Compliance Guide for DoD Contractors</itunes:title>
    <title>32 CFR Rule Explained: Key Compliance Guide for DoD Contractors</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! Are you a DoD contractor navigating the complexities of the 32 CFR Rule? In this video, we break down the key aspects of the 32 CFR Rule, explaining how it impacts defense contractors and the steps you need to take to stay compliant. Whether you're new to the defense industry or need a refresher, this video offers valuable insights into ensuring your business meets the Department of Defense's strict regulations. Avoid costly mistake...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>Are you a DoD contractor navigating the complexities of the 32 CFR Rule? In this video, we break down the key aspects of the 32 CFR Rule, explaining how it impacts defense contractors and the steps you need to take to stay compliant. Whether you&apos;re new to the defense industry or need a refresher, this video offers valuable insights into ensuring your business meets the Department of Defense&apos;s strict regulations. Avoid costly mistakes and protect your contracts by understanding the full scope of 32 CFR compliance.<br/><b><br/>What You’ll Learn:</b></p><ul><li>An overview of the 32 CFR Rule</li><li>How the 32 CFR Rule impacts DoD contractors</li><li>Key compliance strategies for DoD contractors</li><li>Essential steps to avoid common compliance pitfalls</li></ul><p><br/>Stay ahead of the competition and ensure your compliance with the latest regulations!</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>Are you a DoD contractor navigating the complexities of the 32 CFR Rule? In this video, we break down the key aspects of the 32 CFR Rule, explaining how it impacts defense contractors and the steps you need to take to stay compliant. Whether you&apos;re new to the defense industry or need a refresher, this video offers valuable insights into ensuring your business meets the Department of Defense&apos;s strict regulations. Avoid costly mistakes and protect your contracts by understanding the full scope of 32 CFR compliance.<br/><b><br/>What You’ll Learn:</b></p><ul><li>An overview of the 32 CFR Rule</li><li>How the 32 CFR Rule impacts DoD contractors</li><li>Key compliance strategies for DoD contractors</li><li>Essential steps to avoid common compliance pitfalls</li></ul><p><br/>Stay ahead of the competition and ensure your compliance with the latest regulations!</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/16178139-32-cfr-rule-explained-key-compliance-guide-for-dod-contractors.mp3" length="38102717" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-16178139</guid>
    <pubDate>Tue, 26 Nov 2024 10:00:00 -0600</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16178139/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16178139/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16178139/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16178139/transcript.vtt" type="text/vtt" />
    <itunes:duration>3173</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>2</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Navigating the 48 CFR Rule: Essential Insights for DoD Contractors on CMMC 2.0 Compliance</itunes:title>
    <title>Navigating the 48 CFR Rule: Essential Insights for DoD Contractors on CMMC 2.0 Compliance</title>
    <itunes:summary><![CDATA[Submit any questions you would like answered on the podcast! In this in-depth discussion, Austin and Brooke Justice from Justice IT Consulting break down the critical updates and challenges associated with the new 48 CFR proposed rule for CMMC 2.0 compliance. Learn about the key differences from previous regulations, the most significant hurdles DoD contractors will face, and the vital steps you must take to ensure your business stays compliant.  Discover how the proposed rule makes CMMC 2.0 ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>In this in-depth discussion, Austin and Brooke Justice from Justice IT Consulting break down the critical updates and challenges associated with the new 48 CFR proposed rule for CMMC 2.0 compliance. Learn about the key differences from previous regulations, the most significant hurdles DoD contractors will face, and the vital steps you must take to ensure your business stays compliant.<br/><br/>Discover how the proposed rule makes CMMC 2.0 a reality, the importance of early preparation, and how subcontractors can navigate the complexities of this process. Brooke Justice, our resident compliance expert, offers practical advice on how to avoid common pitfalls, manage the overwhelming documentation requirements, and ensure your business is ready when the final rule comes into effect.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/2428223/fan_mail/new">Submit any questions you would like answered on the podcast!</a></p><p>In this in-depth discussion, Austin and Brooke Justice from Justice IT Consulting break down the critical updates and challenges associated with the new 48 CFR proposed rule for CMMC 2.0 compliance. Learn about the key differences from previous regulations, the most significant hurdles DoD contractors will face, and the vital steps you must take to ensure your business stays compliant.<br/><br/>Discover how the proposed rule makes CMMC 2.0 a reality, the importance of early preparation, and how subcontractors can navigate the complexities of this process. Brooke Justice, our resident compliance expert, offers practical advice on how to avoid common pitfalls, manage the overwhelming documentation requirements, and ensure your business is ready when the final rule comes into effect.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2428223/episodes/16178090-navigating-the-48-cfr-rule-essential-insights-for-dod-contractors-on-cmmc-2-0-compliance.mp3" length="26985264" type="audio/mpeg" />
    <itunes:author>CMMC Compliance Guide</itunes:author>
    <guid isPermaLink="false">Buzzsprout-16178090</guid>
    <pubDate>Tue, 26 Nov 2024 10:00:00 -0600</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16178090/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16178090/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16178090/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2428223/16178090/transcript.vtt" type="text/vtt" />
    <itunes:duration>2246</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>1</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
</channel>
</rss>
