CMMC Compliance Guide Podcast By CMMC Compliance Guide cover art

CMMC Compliance Guide

CMMC Compliance Guide

By: CMMC Compliance Guide
Listen for free

Our experiences inspired the creation of The CMMC Compliance Guide Podcast and its accompanying resources. The podcast began as a way to share what we learned through real-world challenges—like helping that aerospace machine shop—and to provide accessible education for businesses navigating DoD cybersecurity requirements.

The CMMC Compliance Guide Podcast breaks down complex topics like NIST 800-171 and CMMC into actionable, easy-to-understand steps. Whether you’re a subcontractor struggling to meet compliance deadlines or a business owner looking to secure your supply chain, the guide offers practical advice to help you take control of your cybersecurity journey.

© 2026 CMMC Compliance Guide
Personal Development Personal Success Political Science Politics & Government
Episodes
  • Can You Create CUI? CMMC Scope, ERP Systems, and Contractor Risk Explained
    Apr 17 2026

    Submit any questions you would like answered on the podcast!

    In this episode of the CMMC Compliance Guide Podcast, we tackle one of the most misunderstood topics in CMMC compliance.

    Many contractors assume that if information is not marked as controlled unclassified information, then it is not CUI. But that assumption can lead to serious compliance risks.

    We break down how manufacturers and machine shops can actually create CUI while performing contract work, even if the original data was not clearly marked.

    We also cover how ERP systems factor into CMMC scope, when systems are considered in or out of scope, and how improper scoping decisions can create major compliance gaps.

    You will learn what derived CUI is, how it applies to things like CNC G code, and why simply removing identifying details from documents does not make them safe.

    We also explain who determines what qualifies as CUI, how scope can expand across your network, and what realistic cost and infrastructure decisions look like for small and mid sized contractors.

    If you are part of the defense supply chain, this episode will help you avoid one of the most common and costly misunderstandings in CMMC.

    Show more Show less
    18 mins
  • The Hidden Operational Workload Behind CMMC Compliance
    Apr 10 2026

    Submit any questions you would like answered on the podcast!

    In this episode of the CMMC Compliance Guide Podcast, we break down one of the biggest misconceptions in CMMC compliance.

    Most contractors think CMMC is just a cybersecurity upgrade. Install a few tools, write some policies, and you are ready for an assessment. But that is not how CMMC actually works.

    The real challenge is the operational workload behind compliance.

    We walk through what that workload actually looks like, including documentation, system security plans, asset management, workforce training, evidence collection, and continuous monitoring. These are the areas that consume the most time and are often underestimated by small and mid sized defense contractors.

    We also cover how CMMC impacts your supply chain, including subcontractor flowdown requirements and what you are responsible for as a prime or subcontractor.

    If you are preparing for CMMC Level 1 or Level 2, this episode will help you understand the true scope of work so you can avoid delays, failed assessments, and costly surprises.

    Show more Show less
    18 mins
  • CMMC Reassessments Explained: What Changes Trigger a New Assessment
    Apr 3 2026

    Submit any questions you would like answered on the podcast!

    In this episode of the CMMC Compliance Guide Podcast, we break down one of the most overlooked risks in CMMC compliance. What actually happens when your environment changes after an assessment?

    Many contractors assume that once they pass a CMMC assessment or complete a self assessment, they are set for the next year or even three years. But recent guidance from the Cyber AB town hall reveals that certain changes can trigger a brand new assessment.

    We walk through what qualifies as a significant change, what does not, and how decisions are made when things fall into the gray area. We also cover real examples like mergers, switching MSPs, expanding networks, and upgrading tools.

    If you are planning changes to your environment or trying to future proof your compliance strategy, this episode will help you avoid costly mistakes and unnecessary reassessments.

    We also answer a listener question about how to identify FCI and how it should be handled under CMMC Level 1 requirements.

    If you are a small or mid sized defense contractor, aerospace supplier, or manufacturer, this is critical guidance you do not want to miss.

    Show more Show less
    49 mins
No reviews yet