Episode Details
Back to EpisodesThe Complete CMMC Compliance Checklist for 2026: Phase 2 Pause, Level 1 vs Level 2, Scoping, and Vendor Documentation
Episode 68
Published 1 month, 1 week ago
Description
Submit any questions you would like answered on the podcast!
This is the all-in-one CMMC checklist episode. Austin and Brooke pull together everything into one place: what the 60-day Phase 2 pause actually changed (and didn't), what CMMC Level 1 really requires, what Level 2 really requires, why scoping is the foundation everything else depends on, and where most assessments actually fall apart.
In this episode:
- What CIO Kirsten Davies' memo suspended, and what it left completely alone (spoiler: almost everything)
- Why the government's stated reasoning for the pause (cost, assessor shortage) doesn't hold up against real assessment pricing
- The RFI and task force timeline: what happens on August 14th, and what to expect around September 14th
- What happens to contracts that already have Phase 2 certification language written in
- Where to actually focus your compliance budget and effort during the pause
- CMMC Level 1: the checklist most people gloss over, and why it's not "nothing"
- CMMC Level 2: the 110 controls and 320 assessment objectives, POA&M rules, and the controls that most commonly get missed
- Why scoping has to come first, and what happens when you skip it (including a mole infestation analogy that actually makes sense)
- Whether your G-code, derivative drawings, and CAD pull-outs are CUI
- ESPs, CSPs, MSPs, and MSSPs: what each one means for your documentation and your assessment
- The two most common reasons assessments fail: documentation gaps and vendor/CRM gaps
- Justice IT Consulting's own path to CMMC Level 2 certification, completed right after the pause was announced