Trust Issues
Where to Actually Start CMMC Level 2 Compliance
July 21, 2026
A lot of contractors start CMMC Level 2 in the wrong place: vendor calls, policy drafts, and documentation work before they have a clear view of what they actually need to prove. In this solo episode of Trust Issues, Brandon Lecoq breaks down why contractors should start with the 320 assessment objectives, build a responsibility matrix, identify ownership gaps, and only then move into vendors, policies, procedures, and evidence.
A lot of contractors start CMMC Level 2 in the wrong place. They talk to five vendors, get five different answers, start drafting policies, and then realize halfway through that they still do not know who owns what or which gaps they actually need to close.

In this solo episode of Trust Issues, Brandon Lecoq walks through the more practical way to start: work backward from the audit. That means beginning with the 320 assessment objectives, going line by line with the right people in the company, and being honest about what is done, what is not, and what is unclear.

What You’ll Learn: 

Episode chapters:

00:00 Introduction
00:15 Where to start with CMMC level 2 research
00:30 Why vendor advice gets confusing
00:45 Working backward from the audit
01:00 Start with the 320 assessment objectives
01:30 CMMC as the enforcement layer of NIST 800-171
02:00 The 110 controls explained
02:45 Why 320 assessment objectives matter
03:15 Controls vs. assessment objectives
04:00 What the C3PAO actually assesses
04:30 One control can have multiple parts
05:28 The boring spreadsheet work you cannot skip
06:30 How to run your internal gap assessment
07:15 Why every assessment objective needs an owner
08:00 Building your shared responsibility matrix
08:45 Assigning ownership across IT, HR, operations, and vendors
09:16 Ask vendors exactly what they own
10:30 Why the RACI process takes time
11:30 Moving from ownership into documentation
11:45 What your SSP actually needs to explain
12:45 Why the SSP is only one part of the documentation
13:00 83 documents and 1,500+ pages of proof
14:30 Policy, procedure, and proof
17:15 Why does evidence come after the documentation
18:15 What the C3PAO audit actually looks like
19:15 Work backward from the spreadsheet
20:21 Don’t start with the SSP
21:15 Why early documentation creates rework
22:00 When vendor conversations should begin
22:30 Identifying the tools you still need
23:30 Why ITAR can change your tool choices
24:15 How certified MSPs, MSSPs, and RPOs can help
25:30 How BEMO can share CMMC responsibility
26:30 Assigning ownership across the full company
27:15 Why SMBs often need outside support
27:44 Bring the shared responsibility matrix to every vendor conversation
28:41 Final takeaway: stop guessing before the audit

Quotes:

“You have your 110 controls, but then there are 320 assessment objectives related to those 110 controls. You just have to do it. It’s extremely boring, and it’s going to be time-consuming to go through 320 rows on a spreadsheet.”

“You should not even tackle the SSP and policies and procedures and the evidence package until you’ve truthfully completed the first three steps.”

“When you are equipped with that spreadsheet, you are no longer doing all this hand-waving when you’re talking to vendors.”

“Start by going line by line through the assessment objectives and security controls and trying to determine who owns what.”

Connect with the team: 

👉 Brandon Lecoq on LinkedIn: https://www.linkedin.com/in/brandon-lecoq  

👉 Bruno Lecoq on LinkedIn: https://www.linkedin.com/in/brunolecoq/ 

👉 BEMO Website: https://www.bemopro.com/ 



Trust Issues is handcrafted by our friends over at: fame.so