The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/Practical Cybersecurity with Jen Stone
Practical Cybersecurity with Jen Stone artwork

You're Probably Behind on CMMC. Here’s What To Do Next. (ep 11)

Practical Cybersecurity with Jen Stone · 2026-07-07 · 17 min

0:00--:--

Episode notes

About 100 authorized assessors. An estimated 118,000+ companies that need to be assessed. That math is the reason CMMC can't wait - and it's where this conversation starts. Brett Cox, lead CMMC Certified Assessor and head of Boeing's DFARS CMMC Program Management Office, joins host Jen Stone to explain what the Cybersecurity Maturity Model Certification actually requires, why the November 2026 third-party assessment deadline is creating a bottleneck, and how a small or mid-sized contractor should take the first step. KEY TAKEAWAYS Phase 2 - the third-party (C3PAO) assessment requirement - goes live November 10, 2026. The right to waive the requirement goes away in 2028. Under CMMC, you must verify the subcontractor below you holds the required level before you can award them work. Their compliance is now your problem. The bottleneck is real: ~100 assessors vs. ~118,000 companies. Expect a months-long queue - get in line now. COTS (unmodified commercial off-the-shelf) is the only exemption, and there's no minimum dollar threshold. Modify a part and it's no longer exempt. You can't use the same company for both readiness consulting and your assessment.

More from Practical Cybersecurity with Jen Stone

All episodes →
  • AI Didn't Change the Rules, It Raised the Stakes (ep.13)85 / 100
  • Which PCI SAQ Do You Actually Need? (ep. 10)81 / 100
  • The Expert Guide to Defeating eSkimmers (ep. 8)86 / 100
  • Your PCI Scope is Too Big (and how to fix it) Ep.12
  • Passkeys: An Upgrade You Didn't Know You Needed (ep. 9)
Explore the best B2B Ops podcasts →
All Practical Cybersecurity with Jen Stone episodes →