A federal contract can look great on paper and still be a bad deal once CMMC enters the picture.
In this episode of Trust Issues, Bruno Lecoq and Jeremy Patterson speak with Christine Hopkins, President and CEO of Advanced Supply Chain International (ASCI), about the real cost of CMMC, why compliance cannot live with IT alone, and why leaders need to understand the full business impact before chasing the contract.
CMMC has a price tag. But Christine Hopkins says the number that matters is not just what the enclave, audit, or IT hire costs. It is what the entire decision costs the business.
In this episode of Trust Issues, Bruno Lecoq and Jeremy Patterson sit down with Christine Hopkins, President and CEO of Advanced Supply Chain International (ASCI), to talk about CMMC from the perspective of a small business leader who has had to make the numbers work.
Christine explains why a $10 million contract may still fail the math once NIST requirements enter the picture and why the biggest cost of compliance can sometimes be the opportunities leadership misses while preparing for it.
What You’ll Learn:
- Why CMMC is a leadership issue, not only an IT issue
- Why Christine believes a lone NIST-required contract may need to be worth around $10 million annually to justify the cost
- How enclave costs, IT staffing, and narrow margins change the contract math
- Why leadership bandwidth is part of the real cost of compliance
- How a misunderstanding around CUI can trigger unnecessary work
- Why NIST, DCAA, procurement, ISO, and other requirements can pile up quickly
- What Christine would change to make CMMC more accessible to small businesses
- How to use AI to reduce writing without removing human judgment
Episode chapters:
00:34 Welcome to Trust Issues
00:56 Meet Christine Hopkins
02:57 CMMC and NIST: the small business reality
05:04 When a $5M contract does not justify compliance
06:14 Why waiting too long can cost opportunities
07:29 The hidden opportunity cost of compliance
08:07 CMMC is a company program, not an IT project
08:30 Why CUI confusion gets expensive
12:03 Why leadership needs to understand CMMC
13:21 Preparing for CMMC with a mock audit
15:50 Building a contract evaluation framework
18:10 The $10M rule for NIST compliance
20:45 When federal compliance requirements start stacking
22:26 Understanding the full ripple effect
23:01 Making CMMC easier for small businesses
24:18 Building AI tools around human judgment
25:41 Less writing, more thinking
26:38 What happens next with CMMC?
27:17 Leading through a 90% revenue loss
28:43 Where to find Christine
Quotes:
- “CMMC is not an IT project. Your entire leadership team needs to be aware of what is involved.”
- “If it’s not worth at least $10M a year, it’s not worth it.”
- “Take the time to understand it and understand the ripple effect impact it’s gonna have on your business, fully.”
- “If we do it wrong, it doesn’t go to the IT person. It comes to me.”
- “They have to do the critical thinking, and then the tool produces the output. So that’s less writing, more thinking.”