<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet href="https://rss.buzzsprout.com/styles.xsl" type="text/xsl"?>
<rss version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:podcast="https://podcastindex.org/namespace/1.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:psc="http://podlove.org/simple-chapters" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <atom:link href="https://rss.buzzsprout.com/2640812.rss" rel="self" type="application/rss+xml" />
  <atom:link href="https://pubsubhubbub.appspot.com/" rel="hub" xmlns="http://www.w3.org/2005/Atom" />
  <title>The CMMC Hot Mic</title>

  <lastBuildDate>Thu, 03 Sep 2026 06:00:03 -0400</lastBuildDate>
  <link>https://www.buzzsprout.com/2640812</link>
  <language>en-us</language>
  <copyright>© 2026 The CMMC Hot Mic</copyright>
  <podcast:locked>yes</podcast:locked>
    <podcast:guid>d79f36db-8118-54b7-abd8-0fcc6bdeac1a</podcast:guid>
  <itunes:author>Regis</itunes:author>
  <itunes:type>episodic</itunes:type>
  <itunes:explicit>false</itunes:explicit>
  <description><![CDATA[<p><b>The CMMC Hot Mic</b> is where the Defense Industrial Base comes to hear the conversations shaping cybersecurity, compliance, and government contracting.</p><p><br></p><p>Hosted by Regis DeVeaux, <em>The GovCon CMMC Nerd</em>, the show brings together defense contractor owners, CMMC authorities, GovCon leaders, attorneys, assessors, cybersecurity professionals, and industry connectors for candid conversations about what it really takes to compete, grow, and protect sensitive information in the federal marketplace.</p><p><br></p><p>Some episodes go inside the businesses navigating the realities of government contracting. Others bring in the experts interpreting CMMC, NIST 800-171, DFARS, assessments, enforcement, and emerging cybersecurity requirements.</p><p><br></p><p>No generic webinars. No compliance theater. Just practical conversations about what contractors are facing, what the experts are seeing, and what business leaders should do next.</p><p><br></p><p><b>Operators. Authorities. Influencers. One mic.</b></p><p><br></p><p>Welcome to <b>The CMMC Hot Mic</b>.</p>]]></description>
  <generator>Buzzsprout (https://www.buzzsprout.com)</generator>
  <itunes:owner>
    <itunes:name>Regis</itunes:name>
  </itunes:owner>
  <image>
     <url>https://storage.buzzsprout.com/kg3qbgvx2fh0dv6epaqyidtm4jyf?.jpg</url>
     <title>The CMMC Hot Mic</title>
     <link>https://www.buzzsprout.com/2640812</link>
  </image>
  <itunes:image href="https://storage.buzzsprout.com/kg3qbgvx2fh0dv6epaqyidtm4jyf?.jpg" />
  <itunes:category text="Arts" />
  <item>
    <itunes:title>CMMC Pause Explained: What Defense Contractors Should Really Do Now with Derek Phillips of Aspire Cyber</itunes:title>
    <title>CMMC Pause Explained: What Defense Contractors Should Really Do Now with Derek Phillips of Aspire Cyber</title>
    <itunes:summary><![CDATA[CMMC phase 2 is paused, but the compliance burden isn’t. Derek Phillips, founder of Aspire Cyber and a CMMC Lead Certified Assessor, breaks down what the CMMC pause really means, what has not been suspended, and how defense contractors should respond. Drawing on 22+ years of cybersecurity experience from the U.S. Army, defense contractor roles with Lockheed Martin in Iraq and Afghanistan, and corporate stints at Hewlett Packard Enterprise and Bank of America, Derek explains how to stay compli...]]></itunes:summary>
    <description><![CDATA[<p>CMMC phase 2 is paused, but the compliance burden isn’t. Derek Phillips, founder of Aspire Cyber and a CMMC Lead Certified Assessor, breaks down what the CMMC pause really means, what has <em>not</em> been suspended, and how defense contractors should respond. Drawing on 22+ years of cybersecurity experience from the U.S. Army, defense contractor roles with Lockheed Martin in Iraq and Afghanistan, and corporate stints at Hewlett Packard Enterprise and Bank of America, Derek explains how to stay compliant with NIST SP 800-171, protect against False Claims Act risk, and turn CMMC into a competitive advantage instead of a cost sink. </p><p> </p><p>CMMC Phase 2 is paused, but NIST SP 800‑171, DFARS 7012, and Phase 1 self‑assessments are still fully in force, so contractors cannot treat CMMC as “over.” Derek Phillips explains that third‑party C3PAO assessments are likely to remain a core part of the ecosystem and that Level 2 certification is already a competitive advantage with primes and the DoD. A defensible SPRS score requires a detailed System Security Plan, adequate and sufficient evidence, and tight alignment between written policies, staff behavior, and technical configurations. Small and midsize contractors often struggle with scoping (over‑including systems and users, creating a costly “CMMC tax”) and with treating CMMC as a checkbox rather than a culture shift built on training, incident response planning, and continuous improvement. Derek recommends that unprepared orgs urgently fix scope and cloud usage, “paper‑thin” orgs shore up POA&amp;Ms and evidence with expert help, and nearly‑ready orgs move ahead with Level 2 certification to gain ground while others stall during the pause. </p><p> </p><p><b>Takeaways: </b></p><ol><li>CMMC Pause: What Actually Changed (and What Didn’t) </li><li>Defensible SPRS Scores and the Real Compliance Burden </li><li>Smart Scoping, Culture Shift, and Using Level 2 as a Competitive Edge </li></ol><p> </p><p><b>Quotes:</b></p><ol><li>“Checking your own homework self‑attestation is not a viable path forward to securing national security and sensitive information.” </li><li>“Your system security plan tells your compliance story; it can’t be a three‑page document if you’re trying to address 110 requirements and 320 assessment objectives.” </li><li>“Our adversaries aren’t pausing, so if you pause your CMMC efforts now, you’re going to pay a much higher price trying to regain that momentum later.” </li></ol><p> </p><p><b>Conclusion: </b></p><p>CMMC’s Phase 2 pause might have rattled the headlines, but Derek Phillips makes it clear that the real obligations, risks, and opportunities for defense contractors haven’t gone anywhere. The organizations that treat this period as extra runway, tightening scope, hardening their SPRS story, and building a true security culture will be the ones primes and the DoD trust most when the dust settles. Rather than waiting for perfect clarity from Washington, Derek’s guidance is to keep moving: get your environment compliant, your evidence defensible, and, if you’re close, push through to Level 2. The pause is temporary; the need to safeguard national security data is permanent.</p>]]></description>
    <content:encoded><![CDATA[<p>CMMC phase 2 is paused, but the compliance burden isn’t. Derek Phillips, founder of Aspire Cyber and a CMMC Lead Certified Assessor, breaks down what the CMMC pause really means, what has <em>not</em> been suspended, and how defense contractors should respond. Drawing on 22+ years of cybersecurity experience from the U.S. Army, defense contractor roles with Lockheed Martin in Iraq and Afghanistan, and corporate stints at Hewlett Packard Enterprise and Bank of America, Derek explains how to stay compliant with NIST SP 800-171, protect against False Claims Act risk, and turn CMMC into a competitive advantage instead of a cost sink. </p><p> </p><p>CMMC Phase 2 is paused, but NIST SP 800‑171, DFARS 7012, and Phase 1 self‑assessments are still fully in force, so contractors cannot treat CMMC as “over.” Derek Phillips explains that third‑party C3PAO assessments are likely to remain a core part of the ecosystem and that Level 2 certification is already a competitive advantage with primes and the DoD. A defensible SPRS score requires a detailed System Security Plan, adequate and sufficient evidence, and tight alignment between written policies, staff behavior, and technical configurations. Small and midsize contractors often struggle with scoping (over‑including systems and users, creating a costly “CMMC tax”) and with treating CMMC as a checkbox rather than a culture shift built on training, incident response planning, and continuous improvement. Derek recommends that unprepared orgs urgently fix scope and cloud usage, “paper‑thin” orgs shore up POA&amp;Ms and evidence with expert help, and nearly‑ready orgs move ahead with Level 2 certification to gain ground while others stall during the pause. </p><p> </p><p><b>Takeaways: </b></p><ol><li>CMMC Pause: What Actually Changed (and What Didn’t) </li><li>Defensible SPRS Scores and the Real Compliance Burden </li><li>Smart Scoping, Culture Shift, and Using Level 2 as a Competitive Edge </li></ol><p> </p><p><b>Quotes:</b></p><ol><li>“Checking your own homework self‑attestation is not a viable path forward to securing national security and sensitive information.” </li><li>“Your system security plan tells your compliance story; it can’t be a three‑page document if you’re trying to address 110 requirements and 320 assessment objectives.” </li><li>“Our adversaries aren’t pausing, so if you pause your CMMC efforts now, you’re going to pay a much higher price trying to regain that momentum later.” </li></ol><p> </p><p><b>Conclusion: </b></p><p>CMMC’s Phase 2 pause might have rattled the headlines, but Derek Phillips makes it clear that the real obligations, risks, and opportunities for defense contractors haven’t gone anywhere. The organizations that treat this period as extra runway, tightening scope, hardening their SPRS story, and building a true security culture will be the ones primes and the DoD trust most when the dust settles. Rather than waiting for perfect clarity from Washington, Derek’s guidance is to keep moving: get your environment compliant, your evidence defensible, and, if you’re close, push through to Level 2. The pause is temporary; the need to safeguard national security data is permanent.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/2640812/episodes/19738587-cmmc-pause-explained-what-defense-contractors-should-really-do-now-with-derek-phillips-of-aspire-cyber.mp3" length="39274728" type="audio/mpeg" />
    <itunes:author>Regis</itunes:author>
    <guid isPermaLink="false">Buzzsprout-19738587</guid>
    <pubDate>Thu, 03 Sep 2026 06:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/2640812/19738587/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/2640812/19738587/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/2640812/19738587/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/2640812/19738587/transcript.vtt" type="text/vtt" />
    <itunes:duration>3268</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
</channel>
</rss>
