Trust Issues
The CUI Scoping Mistake Blows Up CMMC Budgets
August 26, 2026
CMMC costs can spiral fast, and the problem usually starts even before a single control is implemented. In this episode of Trust Issues, Bruno Lecoq speaks with Christina Reynolds, Registered Practitioner Organization leader and author of Scope Small, Win Big, about why contractors need to scope CUI before securing everything, why Microsoft 365 Commercial can sink a CMMC package, and why Phase One scoring requirements still matter even while Phase Two is paused.
A lot of contractors hear “CMMC” and immediately think of a six-figure bill.

According to Christina Reynolds, that’s the wrong place to start. 

In this episode of Trust Issues, Bruno Lecoq speaks with Christina Reynolds, Registered Practitioner Organization leader and author of Scope Small, Win Big, about where CMMC costs really come from. Her point is clear: certification is not usually the cost problem. Bad implementation decisions are.

What You’ll Learn: 

Episode chapters:

00:26 Welcome to Trust Issues
00:48 Christina’s journey in defense contracting
02:55 The biggest misconception about CMMC cost
03:06 CMMC certification is not the real cost driver
05:03 Why aggregated CUI can become a bigger security risk
06:15 CMMC certification vs. DFARS 7012 implementation
08:20 What the DoD actually wants to protect 
10:20 The secret to scoping CUI correctly
12:10 How scoping can keep CMMC costs reasonable
13:19 What C3PAO assessments actually cost
15:13 Why 110 self-attestation often falls apart
16:19 Why self-assessment does not work
16:55 Microsoft 365 Commercial as a CMMC failure point
17:45 ITAR, endpoint devices, and foreign-soil violations
20:10 Why GovCloud VDI matters for ITAR data
21:21 CAD systems, CUI assets, and scoping decisions
22:04 Why CMMC guidance is not your implementation guide
24:48 Revision 3, quantum, and rising security standards
25:29 What FAR changes could mean for contractors
30:22 Why FedRAMP requirements are a major cost driver
32:13 How FedRAMP 20x could help software vendors
34:05 Why FIPS validation adds cost
35:05 CMMC Pacific Northwest Conference revelations 
36:03 Why the Phase Two pause is not a reason to stop
37:05 Phase One requirements are still active
37:35 The hidden metrics blocking DOD contract awards
39:26 How SPRS scoring affects award qualification
42:41 Final advice: scope small and keep moving

Quotes:

  1. “CMMC doesn’t tell you to do it. All CMMC tells you is you’ve got to go seek an independent party that’s been properly trained to certify you.”
  2. “When you let grade school students grade their own test, they all achieve a 100 somehow. But when you have the teacher grade their test, usually, there’s a different story to be told.”
  3. “Scope small, win big.”
  4. “Don’t assume that CUI is everything, everywhere, and omnipresent on every system in your environment.”
  5. “All CMMC is, is show me what you’ve written for your security program, and now prove you’ve done it.”

Connect with the team: 

👉 Christina Reynolds on LinkedIn: https://www.linkedin.com/in/christina-reynolds-6705256
👉 Bruno Lecoq on LinkedIn: https://www.linkedin.com/in/brunolecoq/
👉 BEMO Website: https://www.bemopro.com/ 

Trust Issues is handcrafted by our friends over at: fame.so