
Climbing Mount CMMC · 2026-07-23 · 29 min
Key moments - from our scoring
Substance score
59 / 100
Five dimensions, 20 points each
With CMMC Phase 2 paused and organizations remaining in Phase 1, companies must continue conducting self-assessments for Levels 1 and 2. Kayleigh Floyd and Bobbi Guerra from Axiom MSP discuss the critical mistakes organizations make when self-grading their own security controls. The core message: self-assessments demand both internal knowledge (understanding your systems, CUI locations, network architecture) and external knowledge (understanding NIST 800-171 controls at the assessment objective level). Organizations often fail by assigning assessments solely to IT departments without company-wide involvement, or by inflating scores without actually knowing what they're protecting. The hosts stress that signatories are personally liable for attestations and recommend hiring external assessors for the first assessment to establish proper processes. They walk through the foundational documents required (System Security Plan, network diagrams, policies, procedures), point to DOD CIO resources including the assessment and scoping guides, and detail how to build reusable test procedures to streamline future self-assessments. The episode covers evidence retention requirements (six years), version control for SSPs, and honest remediation planning using POA&Ms when gaps are discovered.
You face potential legal consequences; the attestation includes language similar to Miranda rights stating the government can use your signed self-assessment as evidence against you if you intentionally misrepresented your controls or claimed ignorance of non-compliance.
No - while IT may lead the effort, they must have authority to reach out to HR, leadership, and all business units to validate controls; self-assessments cover the entire organization, not just technology, and insufficient involvement means you're not assessing your full scope honestly.
Your first self-assessment takes 1 - 2 weeks because you're creating test procedures from scratch; subsequent years take only 1 - 1.5 days if you document and reuse those test procedures, assuming your architecture hasn't changed significantly.
You need your System Security Plan (with assessment objectives mapped to each control), network diagrams, data flow diagrams, policies, procedures, a customer responsibility matrix (if using third-party services), and access to NIST SP 800-171 Revision 1 and the CMMC Assessment Guide from the DOD CIO website.
Mark the control as not met and create a Plan of Action & Milestones (POA&M) with specific corrective actions and timelines; be honest about what you're not doing rather than inflating scores, and use the POA&M to track remediation.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode provides practical, actionable guidance on conducting CMMC self-assessments with several concrete recommendations (e.g., hiring external assessors first, creating test procedures, documenting findings). However, significant portions are repetitive throat-clearing and casual banter that dilutes the density of novel insights. The core value - process steps and common pitfalls - is real but not exceptional.
Well, it's kind of like where they're like, hey, I'm very safe and secure but I don't know what I'm protecting. You're like, well, how can you be safe and secure if you don't even know what you're protecting?
the first thing I would do is just read through the SSP first. So it's a long document a lot of times for people, but a lot of times they have the preamble section that sort of talks about things and how they operate in general.
The episode recycles standard CMMC assessment guidance (read SSP, use NIST 800-171, understand your environment) without novel frameworks or contrarian insights. The personal anecdote about a company scoring 90 on self-assessment while not knowing where their CUI is located is illustrative but not original thinking. The conversation follows expected best-practice messaging.
Well, you've got to look at your system security plan first. That is going to have all the information that breaks down all the authoritative documents.
the DOD CIO website, which you can go there, they have the resource page that you can go to that has all the authoritative documents that are related to that.
Bobby Guerra appears to be a practitioner with actual CMMC assessment experience (conducted internal self-assessments, taught CCP courses, worked for an MSP), making him more credible than a pure consultant. However, he is not a senior executive or recognized authority figure - he's a solid mid-level operator speaking from experience, not an exceptional caliber guest.
Bobby went through this for us internally as well.
I was literally teaching the CCP course, and that resource location was just gone.
The episode includes one concrete example (company with 90 SPRs score not knowing where CUI is located) and references timelines (1-2 days to a day and a half per year for assessment, 2 weeks for initial attempt), but lacks hard data on failure rates, dollar figures for external assessor costs, or named case studies. Guidance is general-purpose rather than evidence-backed.
they shared with us that they self assessed and they were about at a 90 SPRs score. You know, 110 is ideal.
it took me like two weeks to go through to do it and I was like, I was like cruising on it
The host asks follow-up questions and allows the guest to develop points, but rarely pushes back or challenges claims. Questions are mostly soft prompts ('What's your perspective?', 'Any other things?') rather than sharp probes. The dynamic is collegial but lacks the tension that forces deeper examination of assumptions or tradeoffs.
Bobbi, I'm curious, you've done a self assessment, multiple self assessments. What's your perspective from the first time you ever partook of a self assessment versus the most recent time?
But what about external documents for somebody? You know, Joe Schmo gets off the street, and he's tasked with doing this internally for his company.
Computed from the transcript - who did the talking, and the words that came up most.
In this mid-season finale episode of Climbing Mount CMMC, Kaleigh and Bobby discuss the essentials of conducting a proper self-assessment for CMMC compliance with the new CMMC Phase II suspension in mind. They emphasize the importance of honesty, knowledge, and proper documentation to ensure successful certification. Resources mentioned in podcast: CMMC Phase II Suspension video: Ultimate Guide to a Self-Assessment video: DoW CIO website: CIO - CMMC Resources & Documentation Jacob Hill video: Website: YouTube: Axiom's LinkedIn: Bobby's LinkedIn: Kaleigh's LinkedIn:
Transcribed and scored by The B2B Podcast Index.
Speaker A: Hello climbers and welcome to Climbing Mount Seamum. Back to the five, six. Good job. What is it doing? Looks gas. Hello climbers and welcome back to another episode of Climbing Mount cmmc the podcast. My name is Kayleigh Floyd here and this is Bobbi Guerra and we are a part of an MSP called Axiom that helps clients of ours get CMMC Level 2 certified and go through this whole CMMC journey. So for those of you guys who are not aware, um, if you haven't checked out our last episode that, that we had, we, we did get a pretty big update to the CMMC ecosystem. They shared that we are pausing things for right now, not going into phase two of the CMMC rollout and still staying in phase one. What does that mean? It means level one and level two self assessments so we are able to.
Speaker B: Everybody gets to grade their own paper. Yay.
Speaker A: This is so exciting. So what does that mean? How do I properly grade my own paper? You know, I think we had a podcast episode that, that I can link below where we did Talk about the SPRs like system on the back end and what it looks like to go in and attest and also self assess through there because you have to, you have to basically go through and check all the boxes of each nisty under 171 control of yes or no, yes or no, yes or no. And you're going through and you're, you're saying, yes, I am doing all of these things. But how do you like really do it before going there and Christmas treeing that that sucker, which is not a good idea. Would not recommend. How do you make sure that you're doing a proper self assessment for either level one or level two? So we're going to get into that today. Any, any prerequisites you'd like to share about me before we get started?
Speaker B: Yeah, don't phone it in. I mean the reality is you're putting, you're putting yourself or someone else on the line that has to affirm that's happening the right way. And if you've never done it, it, it'll kind of scare you because it, it has this whole statement that's like, hey, if you're clicking okay on this, it' they say you have the right to remain silent. You know, anything you say can and will be used against you in a court of law. When you click the message, the message basically saying, hey, when you're self, uh, attesting you're going to go through and check all these things and we're going to use this as evidence if you have been intentionally misleading the government or you've just been informed and you just live in this world of ignorance hoping that that'll be enough. They're going to not dissuade, but um, dispossess you of that notion, I guess, or something.
Speaker A: Yeah.
Speaker B: You don't want to find out.
Speaker A: I do think that it's important. Something that you are sharing that I didn't say when you were going through and checking yes or no on each control is that you also have to sign to it at the end, whoever this person is. So if you are the person that's doing this for your company, please be advised that your name is uh, on that chopping block, which is not necessarily fun if you're unsure if what you're saying is true or false. Bobby went through this for us internally as well. Like in our opinion, we want to take this seriously because we don't want to lie to the government. So I would think if, if you're here listening to this today, you also feel the same way. So let's get into how you can do a proper self assessment. And first I want to talk about knowledge, but two types of knowledge, external knowledge and internal knowledge. So here's what I mean by that. Internal knowledge. Know, know thyself, know your own system. Know where your CUI is going, know and is staying and is sitting in your environment. What is your scope? Know your boundaries, your network diagram. Like understand you have to be able to have the knowledge of your environment to be able to do this properly. You know that also goes into play with the other type of knowledge which is external knowledge. You have to understand CMMC and NIST 800171 controls to the assessment objective level to be able to properly do a self assessment. Bobbi, I'm curious, you've done a self assessment, multiple self assessments. What's your perspective from the first time you ever partook of a self assessment versus the most recent time? What have you learned from, from your first Itty baby, little itty bitty self assessment?
Speaker B: Just no one ever does the self assessment right Themselves really uh, at first, unless you're doing it on a regular basis, you understand it, you're, you're not going to do it. So just kind of level set expectations. When you self assess, you're supposed to be self assessing at the level that DIBCAC would assess you at so that you would know that you're doing it right. Right. Okay. So if I'm going to give myself my own Checkup. But a doctor is going to give myself a checkup. I mean those are going to be two different processes. Lots and lots of knowledge and experience and different perspectives. So level set the reality of understanding like know thyself. You're not that knowledgeable.
Speaker A: Yeah, you're not going to get right.
Speaker B: So chances are you're, you're probably not gonna. So now you're exposing yourself to some potential risk about that. Um, so what does that potential risk look like? Well, that you're inflating. You know, I think. What was the story you had about someone that called up and they were asking. It was so funny. You gotta, It's a great story. I don't want to steal it.
Speaker A: Yeah, I was talking, I was talking to a potential sales lead of uh, ours that were just sharing where they're at in their environment. And they shared with us that they self assessed and they were about at a 90 SPRs score. You know, 110 is ideal. And they're on a 90. I mean that's looking really good for the home team, you know. And then they proceeded to ask me after that if I was somebody that specialized in identifying cui. And I said, what do you mean by that? And they said, well, we just want to know like where, like where and what our cui is in the environment. And I was pretty baffled to hear they could do a self assessment of 90 and also not know what cui is or where it was in their environment. At the same time I couldn't truly comprehend how those both could be in play. So I think one is wrong, right?
Speaker B: Yeah.
Speaker A: And I'm going to let you guess which one is wrong.
Speaker B: Well, it's kind of like where they're like, hey, I'm very safe and secure but I don't know what I'm protecting. You're like, well, how can you be safe and secure if you don't even know what you're protecting?
Speaker A: I said to you, I said it's like, it's like, no, no, no. I'm a really good mom. I'm not sure how many kids I have, but I'm really good at being a mom. But I have no.
Speaker B: I mean that just sounds ludicrous, but that's how people think because they're just not, they just don't get it. They don't understand. So you've got to really have a good understanding of your environment internally like you said, and externally of how to do the assessment. Right. So what does that mean? That means you probably the first time you're doing it, you should hire someone externally to do it with you for the first time and they can kind of set up the process, they can validate your architecture and design. Most people, when they're doing the self assessments, they just want to validate their design and architecture the way it is, making sure it looks right, that it's set up the right way, and that then your policies and procedures and the gaps and things can all be identified. A lot of times people, if they have some decent cyber experience and knowledge over the years, they can take it from there and they can follow the same process. Uh, assuming that the design and architecture is okay, or they gave you the guidance, then you can kind of just meet that. And then in general, you could sort of take it from there. Um, so you want to make sure that, I would think when you go to do the self assessment the first time, at least get somebody outside the company to do it. Uh, because it's never a great idea to grade your paper because then you're just, you have this exposure. You don't even realize.
Speaker A: Yeah, that's so true. Another thing I want to add on to that is, um, you can't just throw the self assessment to the IT guy to do. And there's a few reasons why I recommend not doing that. One, because just because somebody knows about information technology or just because they're an IT guy does not mean they know how to do this. Or also if they've done an ISO like 27,001, like have sat through something like that does not mean they immediately know how to do this framework in this perspective, like, that doesn't make any sense. They have to still understand what they're getting at here. But also, it's not an IT problem, It's not a tech guy problem. IT encompasses your entire company. So if you're immediately thinking that a self assessment is going to work, when you just throw it onto the IT department and walk away, you're getting the self assessment done by a small, for a small pool of your whole organization. You're not doing it in its entirety. That person that you're giving the self assessment, um, you know, task two, they have to have access to everything or be able to talk to everybody involved in it. So that's not just the IT department. That's, that's hr, that's leadership, that's your CAB board, that's everything. So you might give it to the IT guy, but they have to be able to then be able to reach out to everybody to get this thing done, it's not just going to stay in the IT department. And that's it.
Speaker B: Yeah. And that, that implies that they have to have the chutzpah, the power, the authority behind them.
Speaker A: And they yell at the, be able
Speaker B: to be like, hey, you need to be in this meeting so we can talk about this. And they're like, I'm just too busy. Like, we, we have not done a, uh, change management meeting all year. We have not done a tabletop. I'm just too busy. We're making money. You're like, okay, but we just affirmed that we're doing this and, and we're not. And so those are the things that are really, um, that you have to be real honest. And then I would say the other thing that you want to make sure is when you go through and you do those assessments, right, you want to make sure that you save that information for at least six years for every time you affirm. So what does that mean? That means you have to have some type of documentation that you've saved and we'll cover this a little bit later, but you want to have some type of documentation that proves that you've done it. And you want to link it to your system security plan. Because one of the things that when you go to a firm, they're going to ask is what version was your SSP when you did your affirmation? And if it was like, my version was 1.1, and they're like, cool. One of the controls is to review your security posture and things. And they're expecting you to have iterative changes to your SSP. If next year it was 1.1 and the following year it was 1.1 and THE following year was still 1.1, you're like, then what have you evolved or changed? Um, and you know, maybe you're a five or ten person company and you haven't changed it. Okay, I get that. But you should at a minimum be having things that are happening, um, that you can prove that you're doing that you have to review, like the tabletop, the, uh, risk reviews, people doing the training backups, uh, vulnerabilities. I mean, I don't care if you have five person vulnerabilities are like, dude, they are like mosquitoes in the afternoon in Florida by the water. Buddy, you're gonna get eat up.
Speaker A: Uh, um.
Speaker B: And they are just all over the place.
Speaker A: There's many of them.
Speaker B: There's many of them and you have to figure out how to address them. And you have to have a Policy that speaks about how you address them. If you're like I patch and that's good enough and then you've never looked at it, you might as well just go ahead and give up on that because that's just not gonna work.
Speaker A: Yeah, so true.
Speaker B: Yeah.
Speaker A: And so another thing I wanted to, to speak to as well is like let's talk very specifically for somebody that is doing this like for the first time in, in their company. And, and we talked about, we talked about evidence, we talked about knowledge externally and internally. I feel like people can really wrap their heads around when I say internal knowledge. Like you get how to, based upon what we've already said, how to wrap your arms around your own environment and yourself. Like you, you get that. But what's practical direction that you can give somebody of how to perform an assessment based upon CMMC like standards and, and regulations, like where would you turn them to? I mean I, I know the answer to this, but I'm asking you just to be able to say it. So like where, what documents and whatnot would somebody need to turn to to be able to know, oh this, this is how I'm conducting in, in a self assessment, you know, correctly. And this looks good. What would you recommend them going to?
Speaker B: Well, you've got to look at your system security plan first. That is going to have all the information that breaks down all the authoritative documents. So if you don't at a minimum have an SSP and that SSP does not break down the eight control at the assessment objective level. So you're going to have to use 171 uh, alpha right. To go through. And then in that SSP it needs to have a network diagram and a data flow diagram and some other additional information. And then those point to the policies about how you work and the procedures of how you operate and those are the things that you have to look at. And then now you have to be actually doing what you say you're doing. Um, and if you never look at those documents, you never look at those policies and you just dust them off. Uh, when you think the DIBCAC is going to show up and that's going to work out, m probably not going to work out so well.
Speaker A: And those are the internal documents that they should have as like a foundation to even be able, you can't do a self assessment without those documents as well as a customer responsibility matrix. And if somebody is externally also helping you, like somebody like a managed service provider and stuff like that, um, obviously that's a requirement for a C3 PAO Level 2 assessment. Like, you need to know what they're doing as well when your self is assessing. Um, so you need to know that. But what about external documents for somebody? You know, Joe Schmo gets off the street, and he's tasked with doing this internally for his company. He's going through the self assessment. How do they know how to conduct an assessment themselves?
Speaker B: Yeah, the DOD CIO website, which you can go there, they have the resource page that you can go to that has all the authoritative documents that are related to that. Um, that was pretty. It's pretty fun. Um, when they did the transition, I was literally teaching the CCP course, and that resource location was just gone.
Speaker A: They just. They just absolutely deleted it. Right.
Speaker B: And I'm like, talking about the authoritative documents in the class. I'm like. And you can go. And like, it wouldn't work. Yeah. So that was very surreal. I was like, I'm not sure what's going on. But the. All the resource documents on the website were gone. All that was happening live while I was.
Speaker A: That's nuts.
Speaker B: Teaching the class, which was pretty crazy.
Speaker A: Yeah.
Speaker B: So, uh, but that's where you go. They have the assessment guide and the scoping guide are on there, which you want to use for your level two. Or if you're doing level one, the scoping guide is going to give you a lot of ideas about how you should do it so you could read through it. But even if you read those documents, reading those documents is like reading how to build an extension onto your house. That doesn't mean. That doesn't mean that I constitute.
Speaker A: You're a carpenter. M and a contractor, and you've got this.
Speaker B: Right? Yeah. Um, I'm gonna DIY this sucker. Hold my beer. Right. Like, no.
Speaker A: Right.
Speaker B: Don't think that's gonna work out real well. So that's why I emphasize, like, the first time. Just get somebody external to do it, then watch how they do it, learn how to do it, watch that process. A lot of times they're gonna have a template that you can follow to record all your findings about how you're gonna do it. So then you can go through it and you're like, great, all right, I'll do this next year. Save that for six years. You're good to go. Um, even if you're not quite doing it right or you're doing M. I mean, you're making a good effort and you're really trying to record it and you're being honest about what you're doing. If you go in, you do the self assessment. You realize that's right, I did not check vulnerabilities the whole year. You're like, then you need to mark it not met. And you have to write some type of corrective actions about how you're going to try to do it. Be honest about it and correct it, but don't lie uh, about what you're doing just because, well, I forgot I'll just write it in here and I'll just keep doing that. Like that's how people bury themselves and fake uh, information. You can, you can have some, some bad experiences doing that. So don't, don't do that.
Speaker A: Yeah. Now with the evidence gathering, is there a recommendation that you would give like if you, if you were just starting off you with something you wish you would have known on the back end of maybe setting yourself up for success when it comes to that evidence gathering, not only of your evidence like itself that you're doing each one of the controls and assessment objectives, but also like housing the SSP and information at time, like snapshot at time of that assessment. What are some things that you would recommend for people that you wish you would have known too?
Speaker B: Um, yeah. So like as far as around doing the self assessment process. Yeah it took me like when. The first time when I was doing the self assessment for us, like doing for us. Uh, it took me like two weeks to go through to do it and I was like, I was like cruising on it like going through and doing it. I mean it took me like two days I felt like to go through 311 uh, because I was just attacking it from different angles. Just trying to understand what about this, how we do this. We do this. I'm doing this thing and do. I mean like um, that's an exaggeration but um, I, you're just such a
Speaker A: try hard, you know.
Speaker B: Well the, the. For me, um, I was trying to figure out um, like making sure that I felt like all the pieces because 311 relies on so much like. So you're authorizing users. So when you're authorizing users you have to do the background check. Right. So that piece connects here.
Speaker A: You were just trying to see if you could poke as many holes potentially as you. As you could just to like not.
Speaker B: Well, yeah, 311 just shoots out to so many different things to make sure that they're behaving the right way, that you're sort of connecting those. So 311 is just sort of that. And I wasn't quite um, used to Documenting and going through to do that. Um, so that's why what I would do is if you have someone, uh, do it for you, you write down the process of what they're checking for each of those things. So you're like, okay, so for Alpha, I'm just authorizing users. So for this one all I have to do is check my authorized list and this is where I keep it. So like once you wrote that down, then the next time you go to do it, you're like, oh, I just go look at this document.
Speaker A: Oh yes, let me look at the
Speaker B: users look at theirs.
Speaker A: This all match up. This is. Okay, see please everyone that is listening to this, hear what he is saying here. Because this is like, this is like Cliff Notes for a book in school that you don't want to read again. You just want to hear the Cliff Notes and move on. It's, it's disregarding having to do the reading comprehension every time of NIST speak. Just get to the point, like, doesn't everybody want that? I wish that I could have had the NIST speak, uh, you know, erase. Then it was just regular speak from the beginning.
Speaker B: And so to me, like, let's, let's, let's back up just a little bit. So let's say that I was going to do a self assessment for myself. The first thing I would do is just read through the SSP first. So it's a long document a lot of times for people, but a lot of times they have the preamble section that sort of talks about things and how they operate in general. Just read through those and make sure that's right. Did you make a change around your architecture stuff? Do you have cameras? And you never did before. You're like, oh crap, I didn't put that anywhere in the system security plan. Well, you're probably going to need to figure out where you want to inject that change, right? And then you might go, oh crap, we didn't do change control on that. Oh crap, we just violated our policies. I just realized that, you know, so if you're not really, you know, someone that has those types of things in front of mind, when you do the self assessment, you might find that you didn't do stuff that you probably should have as you go through to record it. And when you're doing the self assessment, that's okay, you just ding yourself on that. You do it, you figure out how you're gonna remediate it and we'll talk about that in a second. Uh, but what you do is you just go through and you look at those documents. Then you wanna do the objective level. So that's when you have that spreadsheet and you record how you basically put the test procedure of how you're gonna do it. And this is the reason why it took me so long is I created the test procedure and then I did the validation. But the next time I go to do it, I don't have to create the test procedure unless the system changed. If it didn't, then I just do the test procedure. This is how I did it and I'm done, I'm finished. That's it. I go through. And you can do it in a quarter of the time. Like you just fly through it. Because uh, then you have the test procedure say, okay, well this is how I identify uh, authorized processes. Well, the way we authorize processes is we authorize the user because the process is run as a user and we don't have service accounts. I didn't add that. Okay, great. We authorized devices. Great. The way to authorize the devices is this is the list. I go look at that, that list matches. That matches here. Good, I'm done. Moving on to the next thing. I make the notes and you write that down and you just go through. You could go through, you know, a small enclave system in a day. It's a day and a half. So you're going to lose a day to a day and a half a ah, year to do the self assessment for you. And that's not too bad. That's not too bad. But you have it, you save it for there. And you go through all 110 controls.
Speaker A: Yeah.
Speaker B: Um, and you go through and do those. And you can go pretty quickly once you start getting those test procedures. So build those test procedures. Um, but then what do you do if you find something. Yeah, remediation that you didn't do. Okay. So that's when you would have either operational plan of action or a poem that you would catch. Now traditionally the way the poem's written, the poems are only supposed to happen during an assessment. But if you're doing an internal assessment for yourself, I think technically you could consider that a poem item because you're finding things that are not met. Um, so I um, would say in that situation, like say that you didn't do vulnerability, you would have to put in here, we didn't do that. Um, we weren't doing the checks. Uh, shame on me. Uh, and to remediate, here's what I'm going to do. We're Going to, I'm going to put a calendar reminder, I'm going to do it at this interval. This is how we're going to do it. I went ahead and did these things or we didn't do a cab meeting, um, every other week or month, you know, once a quarter. We did it only once that year. So that's a finding. You know, those are the types of things that you would probably get caught on that people a lot of times just don't think about.
Speaker A: Yeah.
Speaker B: So you're going to have to record those findings you did and what steps you're going to try to do to remediate and then try to make sure. But you don't have a time machine. You can't go back and have those happen. Right. That you didn't have happen before. Right. Um, but now one of the things that has in like configuration management is like baselines, like at least once a year you're supposed to look at the baselines of your system.
Speaker A: Mhm.
Speaker B: What does that mean? So that means like um, in your tenant, do you have a basic configuration of how your tenant's built? Okay, you store CUI and SharePoint. Do you have a list of what that library is supposed to look like? Yes or no? Um, because some assessors would look at that and go, well, you don't even have a basic configuration of how you're securing that data. So how do you know if it changed or it's wrong? Um, and so those are the things that people just don't think about. So that's why a lot of times if you use an external user then to do the assessment, they can sort of teach you that stuff and go, oh, we need to. So then you document that stuff and then you go back and you look and you look at it and say, okay, did that change? And if it did, okay, well who changed it? Uh, was it you? Or did you give people access that shouldn't have it? And those are the things that you just take notes and you write that down. Um, and that's, that's how you at least do a pretty good run at it of trying to do that.
Speaker A: I mean it's almost like this seems so hard that it's almost like you need somebody outside to come in and assess you. Because it's so hard to get this right most of the time.
Speaker B: It's frustrating. It can be. But you know, companies that have 10 or 15 people, they're like, you know, I'm going to spend a day and a half going through doing this.
Speaker A: Yeah.
Speaker B: It's not what I do for a living. I don't like you're going to force me to do it. Well, I can understand it's small business and you, that, that's, that doesn't sound exciting. I, you know, I wouldn't really want to do that either. But the fact is they're trusting with that data and you got to protect it. And if you're not protecting it, then maybe you should not be doing that work, you know, um, because this is the thing that sometimes like even, um, Stevie said, look, um, we want to protect the small business and allow for innovation and development. And that's great, everybody should do that. But if they're so innovative, they can't be bothered to do the right security to protect that data. How innovative is that really? Um, um, to me, um, for example, just the story, if you listen, Jacob Hill did a really good thing where he actually interviewed the whistleblower for like Penn State and the arrogance of the professors and the people that were doing it. Like, I just can't be bothered when we're doing this research to put AV on the system. And you're like, what? Um, yeah, it's, you know, it's a small project, we just can't be bothered to do it, you know, and they're, they're taking hundreds and hundreds of thousands of dollars for these things. And you're like, you know, even if they're small businesses, they still need to be able to focus on doing, uh, these types of things. And I think that's where they're looking at possibly trying to reduce some of the burden of some of that for the smaller businesses. They could try to limit some of that, um, effort in some of those areas, but you can't just wipe it all away. Um, and so I don't see them doing away. I think they're just gonna, they're gonna allow people to do more of a self assessment, which means they're gonna put the burden on you to know it. So just realize what you're signing up for that, um, and just be smart about it. At least do the first one externally.
Speaker A: Yeah, uh, in my opinion. Yeah, I love it. Any other things you can think of last minute that you wanna throw in?
Speaker B: Uh, just make sure that you're recording the data and saving it and storing it and being able to back up. Because realize when you're affirming what you're saying, um, and make sure that you realize that if someone's putting pressure on you to do that because they need to get Stuff done. Realize um, what you're signing up for.
Speaker A: Um, and don't put it off because it could, it could very much open a can of worms of other things that you're not doing that you then have to remediate like what you were saying. So it could be a pretty long process if you end up finding a lot of uh, holes in, in your self assessment. So. Yeah, yeah.
Speaker B: And if you're using an external assessor, I mean it, they're usually not that expensive to have done, uh, in, in the scheme of things, you know.
Speaker A: Right.
Speaker B: Um, there'd be thousands of dollars, okay. Not tens and tens of thousands of dollars to do this. Uh, because um, you could even have them do assessments of even, not even all the controls. You could have them do a subset of the controls even just to give a flavor of it. Um, there's ways that you can do it to keep some of the cost down and still have a good perspective.
Speaker A: Right, right, right. Yeah, that's a great point. Well, um, I really do hope uh, that we can potentially continue down the path of doing even more of these, of getting maybe into the weeds of some specific topics that you want to hear about. Self assessments or you know, or any things that we wish we would have known, uh, you know, that we did wrong the first time or just things like that. I think that these people, people are going to be doing a lot of these this year and next year for the first time ever. So now is the time to learn um, from these types of things and people that have already done it before you. So also comment below if you have gone through a self assessment, you know, internally as a contractor or an MSP or whatnot. We'd love to hear your experience or any specific parts that you want to hear about in this ah, episode or next episode. Um, also too, we are going to continue to stay updated in the next 60 days with what the Dow is doing, what's going to be happening with C3PAO assessments or whatnot, um, or if anything happens. So we'll keep you guys updated as we know. Follow us so you can keep track of our updates. Uh, we hope you guys enjoyed today's episode on self assessments. Until next time, remember as always to keep on climbing. See ya.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.