Episode Details

Back to Episodes

CMMC Level 2 Explained in Plain English: Phases, POA&M Rules, Assessments, and What Level You Actually Need

Episode 71 Published 2 weeks ago
Description

Submit any questions you would like answered on the podcast!

What does CMMC Level 2 actually require, and how does it connect to the four-phase rollout, the POA&M process, and the assessment you'll eventually go through? Austin and Brooke break down Level 2 in plain English, a few days ahead of the DoD's September update on the Phase 2 pause.

In this episode:

  • Where things stand with the Phase 2 pause right now, and what's not paused (your obligation to be compliant with NIST 800-171 R2)
  • Why "just give me the CMMC checklist" doesn't work, and what CMMC actually is (a collection of DFARS rules built on NIST 800-171)
  • The four-phase rollout explained: what phase you're actually in, what's paused, and what flows down regardless of the pause
  • What CMMC Level 2 requires: 110 controls, 320 assessment objectives, and the "CMMC overlay" on top of NIST 800-171
  • POA&M rules explained: the 180-day clock, the minimum 88 score, and which controls can never go on a POA&M
  • What "ready for assessment" actually means (hint: it's a lot more than an SSP and a POA&M, often 400+ documents and artifacts)
  • Self-assessment vs. C3PAO certification: what a real assessment guide-based self-assessment looks like, and why assessors can't consult or advise you
  • Why the "100 assessors" claim used to justify the pause doesn't hold up (there are over 1,000 CCAs)
  • Level 1 vs. Level 2 vs. Level 3: what determines which level actually applies to you, and why most companies who think they need Level 3 don't
  • Why asking your IT person to self-score your own compliance program is a liability risk, even with good intentions
Listen Now

Love PodBriefly?

If you like Podbriefly.com, please consider donating to support the ongoing development.

Support Us