Trust Issues
CMMC Paused. Your Security Obligations Did Not
August 5, 2026
The CMMC Level 2 suspension has led some contractors to relax, but Dr. Beloved Smart says that is exactly the wrong move. In this episode of Trust Issues, Brandon and Bruno Lecoq speak with Dr. Smart about why CMMC is not going away, why tools without documentation still fail audits, why CMMC Level 1 is basic cybersecurity hygiene, and why AI governance is already becoming the next risk companies are not ready for.
The CMMC Level 2 suspension has created a dangerous misunderstanding.

Some contractors are treating the pause like permission to slow down. But Dr. Beloved Smart is clear: the audit timeline may have shifted, but the obligation to protect CUI under NIST 800-171 and DFARS 7012 has not disappeared. In this episode of Trust Issues, Brandon and Bruno Lecoq speak with Dr. Smart, a Fractional CISO and AI governance strategist, about what organizations keep getting wrong about CMMC and security. 

What You’ll Learn: 

Episode chapters:

01:17 Meeting Dr. Beloved Smart
02:10 Dr. Smart’s path into CMMC and security governance
03:49 CMMC vs. ISO 27001
04:49 Documentation vs. implementation
05:17 Why tools do not equal compliance
06:05 Translating CMMC requirements into technical action
07:12 Why half-ready customers are the biggest challenge
08:07 Why the CMMC suspension is not the end of CMMC
08:48 Contractors cannot relax
10:30 Read past the headlines
11:41 Why CMMC is not going away
12:39 Why CUI clarity matters
13:46 ITAR, CUI and basic security gaps
15:30 CMMC level 1 is the baseline
16:29 The $10B company with no security framework
17:19 Why local admin is still a major problem
18:18 Security is a C-suite problem
20:11 Working with leadership, IT, OT and field teams
20:54 Moving into AI governance
21:36 Why Dr. Smart is researching robotics governance
23:57 Where to start with ISO 42001
25:12 AI is already inside your systems
25:32 Why banning AI does not work
28:45 AI risk and enterprise risk management
29:15 Why BEMO mistrusts AI agents by default
29:41 Prompt engineering and challenging AI outputs
30:13 Matching AI agent power to operator expertise
31:20 Why AI agents cannot delete data by default
31:50 Why AI training matters
34:00 Real-world AI adoption inside teams
35:07 Using AI agents for vendor questionnaires
36:38 AI for live compliance evidence collection
38:04 Final thoughts with Dr. Smart

Quotes:

  1. “Most organizations just believe when they have all the necessary tools in place, they’re already compliant.”
  2. “One major gap I see is organizations don’t actually walk the talk.”
  3. “The audit requirement may have changed, but the security requirement definitely has not changed.”
  4. “Security is not an IT problem. Security is the executive problem.”

Connect with the team: 

👉 Dr. Beloved Smart on LinkedIn: https://www.linkedin.com/in/belovedsmartgrcspecialistaicybersecurityinformationsecurity/ 

👉 Bruno Lecoq on LinkedIn: https://www.linkedin.com/in/brunolecoq/ 

👉 Brandon Lecoq on LinkedIn: https://www.linkedin.com/in/brandon-lecoq  

👉 BEMO Website: https://www.bemopro.com/ 


Trust Issues is handcrafted by our friends over at: fame.so