From proving access control in the SSP to the history behind DFARS 252.204-7012, NIST 800-171, and CMMC, Brandon and Bruno revisit why contractors cannot treat CMMC like paperwork, a tool purchase, or a paused deadline. The message is simple: the audit timeline may change, but your security obligation does not. This compilation episode of Trust Issues pulls together some of the clearest CMMC reality checks from past conversations.
CMMC is synonymous with confusion at this point. But this episode of Trust Issues should clear it right up.
In this compilation episode of the podcast, Brandon and Bruno Lecoq revisit key insights from past conversations to cut through the noise around CMMC, documentation, self-attestation, and the Phase 2 suspension.
What You’ll Learn:
- Why technical implementation can still fail if the SSP does not prove the process
- Why “periodically” needs to be clearly defined before assessors hold you to it
- Why CMMC exists because self-attestation stopped being credible
- How DFARS 252.204-7012 and NIST 800-171 led to today’s CMMC requirements
- Why the Phase 2 suspension is not permission to pause cybersecurity
- Why protecting CUI remains a contractual obligation, regardless of the audit timeline
Episode chapters:
00:00 The CMMC reality check
00:26 CMMC Phase 2 suspended, cybersecurity did not
00:37 Why contractors cannot relax
00:56 CUI obligations under NIST 800-171 and DFARS 7012
02:13 False claims risk and inaccurate compliance representations
03:57 Why technical implementation is not enough
04:14 Your SSP has to prove your process
04:32 The danger of overpromising “periodic” reviews
06:13 How DFARS 252.204-7012 led to NIST 800-171
06:32 Why self-attestation stopped working
06:51 The SSPs and POA&Ms that exposed the problem
10:45 Why CMMC became a validation requirement
13:23 Final takeaway: stop treating CMMC like paperwork
Quotes:
- You can have the most perfect implementation of the technical side and fail within 15 minutes of your assessment because you don’t have the processes to prove that you are controlling access.” - Brandon
- “The 252.204-7012 clause, that effort was started in like 2013. They originally said, ‘We want you to do the 800-53.’ Industry went, ‘Are you kidding? No way.’ So NIST formulated the 800-171 specifically for industry.” - Stacy
- “CMMC Phase 2 suspended, cybersecurity is not. You still have to continue.” - Dr. Smart
- “The audit requirement may have changed, but the security requirement definitely has not changed.” - Dr. Smart
Connect with the team: