
Secure & Simple · 2026-08-10 · 41 min
Key moments - from our scoring
Substance score
69 / 100
Five dimensions, 20 points each
CMMC Level 2 compliance has become mandatory for US Department of Defense contractors dealing with Controlled Unclassified Information (CUI), with only 3,000 of 200,000 eligible contractors currently certified. Bruno Lecoq discusses how CMMC differs fundamentally from ISO 27001 in its audit approach - assessors require live demonstration of controls and evidence from ticketing systems, logs, and records rather than accepting attestations. Companies typically need 29 policies, 46 procedures, 14 configuration documents, and 700+ pieces of evidence. The System Security Plan (SSP) alone runs 300+ pages and serves as the primary audit document. Lecoq emphasizes that successful implementation requires C-suite commitment, cross-functional project teams including IT and business leadership, and a mindset shift toward continuous monthly and quarterly reviews. The biggest challenge isn't technology but organizational discipline - companies must document everything through tickets, maintain asset inventories, map CUI lifecycles, and establish clear boundaries between what the company, cloud providers like Microsoft, and MSSPs like BEMO each control. Phase One assesses CUI boundaries and strategy; Phase Two is the main assessment. Companies starting fresh face migration costs if moving from commercial to GCC/GCC High cloud environments.
CMMC (Cybersecurity Maturity Model Certification) is a mandatory certification framework for US Department of Defense contractors handling Controlled Unclassified Information (CUI). Level 1 applies to federal contract information (FCI) with self-assessment; Level 2 requires third-party C3PAO auditors and is needed when handling CUI.
Level 1 is self-assessed for companies handling Federal Contract Information (FCI) only; Level 2 requires certified C3PAO auditors and is mandatory when companies handle Controlled Unclassified Information (CUI).
As of the episode, there are 93 registered C3PAOs worldwide to assess approximately 200,000 US contractors, creating a significant bandwidth challenge. Additionally, 87% of companies fail Phase One assessment because they lack proper documentation, further straining the system.
Companies typically need 29 policies, 46 procedures, 14 configuration documents, and 700+ pieces of evidence. The System Security Plan (SSP) is usually 300+ pages and includes CUI boundaries, all 110 controls, procedures, network diagrams, and defined roles across the company, cloud providers, and MSSPs.
CMMC auditors require live demonstration of controls through screenshots, logs, and ticketing system records rather than accepting attestations. ISO 27001 auditors typically trust company statements more, making CMMC more evidence-intensive and rigorous.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode delivers solid, practical information about CMMC implementation with specific numbers (29 policies, 46 procedures, 700 evidence items, 110 controls, 320 AOs, $45-55K audit costs). However, insights are somewhat predictable for target audience (documentation requirements, phased audit process, leadership buy-in) - the core advice reiterates standard compliance wisdom. The specific operational examples (passkey/password discrepancy, onboarding workflows) add texture but don't challenge conventional thinking.
29 policies. Uh-huh. We we have 46 procedure. Mhmm. We have 14 configuration document and more than 700 evidence.
C3PAO will charge today between 45,000 to $55,000 for an audit
The framing around 'security rigor vs. technical controls' and the notion that CMMC is a 'company project, not an IT project' offer some fresh perspective. However, the broader narrative - compliance requires leadership buy-in, documentation discipline, ongoing maintenance - is standard in governance discourse. The comparison to ISO 27K and SOC2 is useful but not novel. No counterintuitive arguments or first-principles rethinking.
CMMC is not an IT project, it's a company project and it's a way of life
I think the NIST, you know, the pure NIST will be the IT. And for me, what I see is on top of CMMC, they have added some, again, non IT controls
Bruno Lecoq is a credible practitioner: CEO and CISO of a CMMC-certified MSSP, has hands-on experience with multiple certifications (27K, SOC2, HIPAA, working on 42K), has led his company through mock and full audits, regularly advises clients, and attends Cyber AB monthly meetings. He speaks from operational trenches, not theory. His firm size focus (10-1000 users) limits scope, but he's clearly done the work at scale.
BEMO as a company is already CMMC certified together with other standards like 27,001, SOC two and HIPAA
we did a mock. So to explain for a mock is you your assessor is kind of they will assess you, but it doesn't count against your score
The episode is concrete where it matters: audit costs ($45-55K + $10K mock), timeline ranges (3 months to 1 year, 9 months average), specific control/AO numbers (110 controls, 320 AOs, 66 monthly reviews), document counts (29 policies, 46 procedures, 700 evidence items), C3PAO numbers (93 registered), 87% phase-one failure rate. Lacks specifics on actual client transformations, ROI, or named customer examples (understandable due to NDAs). SSP page count cited (300 pages) but not comparative data.
200,000 contractors in The US, and as of right now, only 3,000 are CMMC level two compliant
87% of the people don't pass phase one
Host Dejan asks clarifying follow-ups ('Can you tell me about the basics?', 'What distinguishes level one and two?', 'Are all controls in NIST 171?') and gently probes contradictions ('But ISO 27K should also check records, right?'). However, questioning lacks sharpness - few pushbacks on vague claims, limited challenge to guest's framing. Host doesn't press on the cost/burden story or ask harder questions about why 87% fail or what 'security rigor' truly operationalizes. Conversation is friendly but surface-level, missing opportunities to stress-test Bruno's recommendations.
But ISO 27,000 certification bodies should do the same. Right? They should also check the records. Yeah. But I I have I have felt like the the bar is lower
So what exactly do you mean by this? [on business velocity vs. security rigor]
Computed from the transcript - who did the talking, and the words that came up most.
Dejan Kosutic hosts Bruno Lecoq (co-founder, CEO, and CISO at BEMO) to explain CMMC compliance for Department of Defense contractors and suppliers, including those outside the U.S. They cover CMMC basics (levels, CUI vs. FCI, C3PAO assessments, phase 1 boundary review and phase 2 audit), current capacity challenges (about 93 C3PAOs vs. roughly 200,000 contractors), and why many companies fail early due to incomplete documentation. Bruno shares BEMO's experience (29 policies, 46 procedures, 14 configuration documents, 700+ pieces of evidence, and a 300-page SSP) and emphasizes leadership buy-in, parallel technical and documentation work, proof-based evidence, ongoing monthly/quarterly reviews, and maintaining compliance after certification. They discuss scoping CUI boundaries, tooling constraints (e.g., GCC/GCC High), subcontractor requirements varying by contract, and typical assessment costs ($45K - $55K plus ~$10K mock). Note: This interview was recorded in June 2026, before the U.S. Department of Defense suspended the planned rollout of CMMC Phase 2.
Transcribed and scored by The B2B Podcast Index.
Welcome to Secure and Simple Podcast. In this podcast, we demystify cybersecurity governance compliance with various standards and regulations and other topics that are of interest for consultants, CISOs and other cybersecurity professionals. Hello, I'm Dejan Kosutic, the CEO at Advisera and the host of Secure and Simple Podcast. Today my guest is Bruno Lecoq and he's the Co Founder, CEO and CISO at BEMO.
BEMO is a managed IT service provider for security and compliance. So BEMO as a company is already CMMC certified together with other standards like 27,001, SOC two and HIPAA. They're also working on ISO 42,001. And, basically, in today's podcast, you'll learn what are the best practices to comply with CMMC and also how to avoid most common problems.
So welcome to the show, Bruno. Thank you. Thank you for having me. Great to have you here.
So tell me, is this CMMC really relevant only for US companies or is this also relevant for companies outside of The United States? So for sure, CMMC is mainly for US company. But again, in the world of CMMC, the assessor that will assess your system, they are called C3PAO. Mhmm.
And they already register some C3PAO outside of The US. So I know some I know some in Canada. I know some in South Korea. So, again, it's starting to go outside The US.
So because of that, my assumption is, I guess, some other company will outside The US can be compliant. But, again, the number one thing is really for company doing business with the Department of Defense. US Department of Defense. Right?
Yes. Yes. Yeah. Okay.
But there are many suppliers to US Department of Defense from other countries like, okay, South Korea or probably from NATO countries, from Europe and so on. Exactly. Exactly. Yeah.
Okay. Very good. Okay. Just for our listeners who are not very familiar with the CMMC, can you tell me a little bit about the basics of CMMC?
So, basically, who needs to comply? What are these levels? What are the deadlines? So so I guess from where we are now, so if you think, I will go back in the last so since 2013, you are supposed to as a contractor for the US Department of Defense, you are supposed to self attest.
So again, it's based on NIST 807 '71, and you are supposed every year to do the self attest assessment and upload your score. And I guess the US government has realized, you know, that, you know, many people will self attest, but they are not really secure. So they cannot, you know, create CMMC and made it mandatory. So by this November, this coming November, that the now your contractor, so depending on which agency you work with, may ask you to be CMMC compliant by this November.
So today, again, the number that, you know, I hear is there is about 200,000 contractors in The US, and as of right now, only 3,000 are CMMC level two compliant. So it's kind of the of the level of the story. So, again, out of that CMMC, it's not that it's not only a 90. Again, it covers HR from onboarding, offboarding.
There's operations. So 80% from my perspective, 80% is IT, 20% is non IT. Okay? And the 3CPAO, a federal agency, will come and assess your system, and then will give you your grade out of 110 and they will be the one uploading the score to the US department website.
Okay. So if I understood the well, Level two, right, Level two CMMC is where this C3PAO actually needs to come in and actually certify a company, whereas Level one is still self assessed, right? Correct. Yeah, okay.
And there is also a Level three, right? But this is very rare. Reward three is coming. It's still in development.
So again, you can see the SELFAT test, but at the end it's Yes. So again, Level three will really be the big guys, the Lockheed Martin, the really the Now what distinguishes the level one and two? So the difference is as soon as you have to deal with CUI, again, so as soon as you have CUI, you have to be level two. Okay.
So CUI stands for let me see. I have my notes here. CUI stands for Controlled Unclassified Information. Right?
Correct. Okay. And level one is only federal contract. It's only federal.
Yes, FCI. Okay, good. Very good. So most, again, I think most I can see from our customer, most of the customer now what we have is Level two in the world of CFMC.
A few of them are Level one. Okay. And you mentioned the number of what, 200,000? So it's a huge number.
I mean, it's really... It's a huge number. And it's going to be interesting what happened in November, because again, at the end of the day, one and maybe 2% of the base will be there. So, again, I'm very curious to see what the US government is going to do.
Okay. Now, let's speak a little bit about this assessor, right, the C3PAOs. So, how many actually of these assessors are worldwide or in The US at least? To my knowledge, because I I attend.
So the CMMC program is managed by a group called Cyber AB, and they do a monthly meeting. So they're the other one releasing the number. And to my last meeting, it was 93 C3PAO registered. I mean, how are going to, you know, these 100 C3PAOs, how are they going to kind of swallow 200,000?
What's very interesting today is, again, I talked with many of them, and the issue is there is so it looks like there's not enough bandwidth, but right now, when company come to them, they don't even pass phase one. So again, from phase one, you have to set what are the boundaries of your COI, how you present, and they come to the first meeting and they already rejected because the people don't have their documentation together. They don't have their the basic together. They cannot even move forward.
So there is a huge so the numbers that, I know, was told by Cyber AB is about 87% of the people don't pass phase one. So they are not prepped because many people think CMMC is IT, and those companies will be IT. But it's, you know, I I would give an example from a BEMO perspective. So in order for us to be CMMC We have 29 policies.
Uh-huh. We we have 46 procedure. Mhmm. We have 14 configuration document and more than 700 evidence.
Mhmm. And what was interesting, so we demo, we did a mock. So to explain for a mock is you your assessor is kind of they will assess you, but it doesn't count against your score. Mhmm.
And so they're able to do this kind of a a free test. You can do it's not free because you have to pay the new test. We, at 100% from an IT perspective, but they find five errors, and the five errors were in documentation. So Uh-huh.
I will give an example. We, BEMO, we are we use passkey. We don't use password. But because we have pass we have passkey, we need to have password as backup.
And within our procedure, our procedure said our minimum characters for the password was 14 digit. Mhmm. Okay. Four 14 characters.
When we go to the procedure so within our system, because you have to show the c three p o live, so you go to the configuration and you show it was 14. But in our policy, it was written 12. Okay? Because of that boom, we lost five points.
If we would have done a mock, we wouldn't have passed. Yeah. And you're like, wow. You know, it took us two minutes to fix.
But it's just just too short that, again, it's not only it's not only that. Mhmm. Okay. So do these assessors, I mean, C3PAOs do they have these stages like in ISO 27,000 certification?
Like, first stage is a a documentation review and then the second one is the main audit? So on average, so they have a phase one. So the phase one is to assess your boundaries. So, again because the main thing is you have to have CUI.
If you don't have CUI, you cannot do a same in c level two. So you have CUI. So the idea is you present, how are you going to protect your CUI? Where are your CUI in your system?
So you present that. Then you meet with your C3PO and they will say, okay. Yes. We understand your system.
We think your strategy is good. Great. We can go to phase two, and phase two is the assessment. Yeah, the main audit where they find evidence, right?
And then the audit, yes. And again, and after the audit, then there is a report. So it's kind of the Yeah, so it's very similar to other, let's say ISO certification, yeah. Okay.
And okay. So as you mentioned, most companies have problems with the documentation and you mentioned that you have written, what, around a 100 documents, if I calculated correctly. Well, anyway, if I if if I look at it, even our SSPs so we have our SSPs 300 pages long. Okay?
So 300 so I'm sorry. I'm saying we are pages? 300 pages. 300 pages for SSPs or CSP plan.
Right? Yes. Yes. Wow.
It's quite long. Yes. And So Mhmm. The the I think the challenge that we had, and I see with our customers, is making sure that all document they they cross reference correctly.
You know? And your evidence because I also think for people, don't understand. Same MCs always say, being same MCs like having a baby. Okay?
You you certify you are certified with your baby, but you still have to deal at least with the baby for eighteen years. Same thing with compliance with CMMC. You have to do your monthly audit, your monthly, you know, it's still work after the certification. So what do you see as the biggest challenge beyond the documentation for companies?
Is this, let's say, maintenance, these regular audits? Yeah, I think it's for me, CMMC is not an IT project, it's a company project and it's a way of life. So if I go back if I go back in time, you know, ten years ago, any IT admin were global admin on the system. Mhmm.
Then came PIM. So now you're an admin, and you have to race. And I think now, I take I take BEMO, is everything starts with a ticket. Mhmm.
I wanna do something. I open a ticket. Why am I doing that? There is a ticket.
You you know, it's approved. You know? You do the work, and then you close it. So I think it's kind of the evolution that I see.
So it's a looking at it now, I would not wanna run the IT or BEMO any other way because because I think, again, I think this is a very good framework, and that you know? I think it's very good what we get by, again, by reviewing monthly and quarterly. But it's a mind shift. It's a mindset and a mind shift of how you will run your company.
So, you saying that when introducing CMMC companies actually what exactly companies need to, let's say, change? No. So this is what I always find very interesting because by default, all those companies have sent sent a test for the last thirteen years. So they were supposed to just do it.
So if I found a company, I should be able to go to my c three PEO with no changes and do it. So when I see companies saying, woah. This is will cost me more money and more work. And you are like, woah.
So what have you been doing the last thirteen years? I when when I look at your score, you are telling me you have a 110 or 110. So, again, it's a company should have been again, I should have my recommendation up to date. I should do my the review of my controls every month, every quarter, depending on the controls.
And I should have my my poem, you know, up to date. So, again, it's a you know, I signed up. I should have done it. So it should be nothing new.
Okay, I mean, but this is, let's say, for companies that already declared as being CMMC compliant in the past, right? But if a company is, let's say, going for the CMMC for the first time, what is kind of the biggest change that they have to introduce in their, let's say, operations? I think for again, from an operation, I think the biggest change from a so I will give you two examples. So from a NetSharp perspective, so Mhmm.
I think from a NetSharp perspective, even we've been able to change. We if we hire a so you hire an employee. Mhmm. The first thing is the HR person does a background check.
And as soon as the background check is done, our HR person will open a ticket. Mhmm. That will come to me as a CISO and say, hey. I'm really we are ready to create this account or this person.
This person has a background check. Mhmm. I will say, Approve. Go create the account.
The IT person create the account, and then we create the account. And then the employee will go through a training first. We'll go through a training before the account is granted. Okay.
If you if need it when before, well, my sharp person will do the background check. We'll go to the IT person. He will create the account. The person is in, and the person will do training after.
So, yeah, this is a change that we have to do. Now if I go from a a 90 perspective, I have you know, there's 110 control for 320 AOS, and I have to I have about 66. Like, on the monthly review, we review 66 AOS every month, making sure, you know, I and so, again, one of them is I go check through the logs. I go check, you know, my end trial, my preview.
So there's a lot of thing that I need to check-in, make sure that there is no issue. Only days an issue, a ticket is open. And, you know, so it's yeah. And so an auditor can just go through with you every month what has been done, what the issue you encounter.
Okay. How long was this issue up? Mhmm. So if I understood well, the biggest change is on one hand documented documenting every everything.
I mean, let's say, through tickets and and making sure that you kind of make a record of everything that you're doing. It's it's you have to prove to someone's needs outside. It's not just now UI, know, ITT. Okay.
Yeah. That's interesting. Okay. And if I understood well, this CMMC is really basically, at least at level two, is about implementing NIST standard SP eight hundred-one 171.
Correct? So can we then say that basically CMMC is like an auditing standard, which actually helps 3CPO audit the companies? And because I'm just trying to understand what is basically the the difference between CMMC and this NIST 171? Yeah.
I think it's, you know, the NIST, you know, the pure NIST will be the IT. And for me, what I see is on top of CMMC, they have added some, again, non IT controls, you know, like I say, HR and stuff like that, wrapped it, and the c two p o will use it for as a audit. Okay. But so are all the controls actually described in an EAST one seventy one or are there some addition?
No. They are. They are. Okay.
So there are no additional controls in CMMC. Right? No. Okay.
Yeah. So, okay. So CMMC is basically a framework for C3PAOs, right, to kind of assess if the company is compliant, right? Yes.
Okay. So when a company is implementing CMMC and this NIST eight hundred-one 171, so what do you see as the from your experience working with your clients, what do you see as the most, let's say, the best, most appropriate steps actually for a company to become compliant? So I can tell you, so we see just from our call number one, from a presale perspective, when a company come to BEMO, we know all of call number one if if the company will be successful or how long it will take them.
And that's very interesting. And so for me, a successful company is someone on a c suite come with the IT person and said, hey. As a company, we need to be CMMC. We would like to know, you know, can you help us getting there?
When it's only the IT person coming, very often, it takes forever because, again, it's a, you know, poor IT team. Someone told them, go do it. They go do it, but it's not only IT. And this poor guy will will, you know, lose a huge amount of time actually without achieving...
Amount of time and just, you know, he is running and he's realizing that he needs help outside of IT, but the person the people were told by the leadership team, you need to play with them. We as a company need to be CMMC. Mhmm. Yeah.
Okay. So one of the obviously preconditions is that what? You have a project team with included both IT and business side, if I understood well? Yes.
Okay. And then once you have a project team in place, what kind of, let's say, stages you have in a project or what kind of steps do you have? So from our perspective, we do so we do thing in parallel. So we have two thing in parallel.
One is from an IT security. So, again, how do we how do we make sure the 110 control are configured correctly? This is one. And while in parallel, you work on your policies and procedures.
So again, two things goes, you know, in parallel for us to and per our schedule to meet and be completed at the time prior to the audit. Mhmm. Mhmm. Okay.
If I understood well, there is also some kind of an assessment that the company needs to do itself. Is this, let's say, similar to internal audits in twenty seven thousand and one or Yeah, you still have to do an internal audit too. Okay, so it's a similar concept there. System is a serial concept.
Okay, and regarding documentation, so you mentioned that your company went for, again, for these roughly 100 documents. Is it really mandatory that all companies have that big amount of, let's say, policies and procedures and guidances, or is this more flexible? Every company, again, so when we did, when we first did for us, so this what we what was interesting when you go to the so once we have the the audit so the audit is you need to have the c three p o, need to have three auditor online.
So you're online. So it's, again, it's shared. They they come, you share the screen. They screen it on the other side, and they go through control by controls.
They go even from arrows by arrows, and it always start by, this is my policy for this control. Okay. This is how I make sure policy. This is how we have our procedure.
How do we make sure we do it? And now let me show you. So to show you can be live in a you know, I can be on Max of Entra or I could be via a screenshot. So it's live.
You have to demonstrate. So so everything you do, you know and so for a full week, you know, so, you know, to five, you know, whole week with the answer, and you go through every single one for the same process. So Okay. We use every policies and procedure as part of it.
From all our customers, we make them do the same thing and they are able to pass. At least we have seen a winning from our perspective, winning strategy. Okay. If understood well in this NIST 171 standard, are what, 110 requirements, if understand well.
110 control. Okay. So are you saying that for each control you would have a separate document or? No.
No. You have you have some control that depending on the control. One control can like, one policy may may work on 10 controls. Mhmm.
And so it's not one policy. We have 29 policy for 110 controls. So it's, you know and so some control can, you know, are broad. So it's not one to one.
Okay. And when the assessors are looking for evidence, are they basically looking into, let's say, records or logs of your CISOs? Oh, yes. They ask us so.
You know, of course, we have to take them. Okay. I think what I see with when I compare with ISO, I think in ISO, the assessor by default is trust you. Oh, yes.
We do that. We do that. We do that. I see in same MCs.
I don't trust you. You show me. So the difference is now we go in our ticketing system. Let me show you, you know, can you show me the off boarding of an employee?
Okay. Show me the last one. Okay. You go through the ticketing system.
You can go through the line. Okay. I can see. Yes.
You know? So it's not you cannot just say, oh, we do it. No. No.
Show me how you do it. So it's think it's a big difference between for me the ISO and CMMC. Yep. I mean, but ISO 27,000 certification bodies should do the same.
Right? They should also check the records. Yeah. But I I have I have felt like the the bar is lower, at least my perspective.
I think, like, SOC two is the bottom one, I think. Middle one would be ISO and CMMC is the both former. That's interesting. Yeah.
So from your perspective, again, you're helping companies beyond, let's say, having the right people in the project, beyond having the right documentation, what else is needed for success and to run this project in some reasonable amount of time? I think if you have a commitment from the leadership team, you have a knowledgeable IT person, you know, I think, you know, at at the end of the day, it's not rocket science. You know? It's just again, it's a so from an IT perspective, it it also depends where you start from.
So, again, there's some customer that will come. They are on Microsoft commercial, Office three sixty five commercial. Mhmm. And, oh, we have to move them to GCC or GCC High.
So in that case, oh, you have a migration first. Oh, yeah. And all you have companies that will say, hey. We have both business in my company.
We do commercial and government. Mhmm. So, you know, so sometimes we will leave them on commercial, but we create an an AVD enclave. So for people doing, you know, government, they can just go to this enclave.
So depending on every business, it depends on the boundary of your CUI. K? What type of CUI do you deal with? What the quantity?
How do you do you receive them, do you modify? So there's a lot of questions based on that, how do you protect it? Okay. From what I understood, there is a lot of, let's say, unclarity about the scope really of the implementation.
So how do companies actually define the clear scope for CMMC certification? I think the from the scope is always so we don't have to think about, okay, first is, again, the CUI. Do what do you create? So do you create like, do you create CUI or do you just receive you just receive CUI, do nothing?
So there is a so, again, it goes back to, oh, I have this CUI. What is life cycle within your company? Do you share it across other company or it's just for you? It's just you know?
So based on that, will it go through your email system? Will it go through third party system? Again, it's kind of what's the life cycle of your CUI? In other words, companies should have, let's say, first of all, clear asset management to have clear view of And what assets they on the other hand, processes, right?
Yes. Without That's why it goes back to, you know, one of the an assessed list is one of the requirement that you have to have. So, again, if you so and now how do you manage your assets? How do you keep it up to date?
You know? Yeah. This is one. Then do you have a workflow about your CUI?
For very often companies, they don't. You know, it's in the head of someone and, okay, you go. So and and it's why because of that, it's never the same not every company protect the CUI the same way or has to protect it the same way. Okay.
You mentioned also this SSP, right? The system security plan. So why is it so lengthy and why is it so important? Oh, I figured the end from the audit perspective, when is the audit, they only use your SSP.
So, like, you they take your SSP and you go through them, you know, pretty much page by page, and they will go. So in our case, you know, section one, section two is all around CUI boundaries. You know? You have a section that is your 110 control with the 320 AOS.
And, again, they go through you know, you you share the screen, and it's okay. Now control three point one point one. Okay. Let's you know, how do you do that?
3102, 3 so you go through every single you know? And then what we include as part of it, again, you include also all your your documents. So, again, network diagram, CUI flows, so it's all there. And you also have your roles and responsibility metrics.
So, again, between what is, for example, BEMO doing for the company and for the company and what is Microsoft doing. Again, Microsoft has some role. You us BEMO as the MSSP have a role and you as a client as a role. So it's all defined so that when you discuss with the c three p o, this is how we do the control.
It's okay. This is what Microsoft does. This is what BEMO does. And this is what yeah.
Okay. And how does this document differ from, let's say, the statement of applicability from ISO 27,001? Is there any, let's say, similarity between these two documents or it is very different? So I will say some some part are similar, but at the end, it's yeah.
You know, from an ISO perspective, document is not that big. It's a lot smaller. So there is not I think what makes it longer is because the three the three hundred three hundred twenty a o's, you know, again, it's a very detailed. So it's what, you know, at the end is, other than 300 pages, pretty much 200 pages are wrong, that document, you know?
So you don't have that in the ISO world. Yeah. Yeah. Okay.
Okay. Good. But if I understood well, this security plan does actually overview give them give an overview of all the controls. Right?
Oh, yes. Yes. Okay. Yeah.
In that regards, it it's kind of slightly... When you go to the audit, because we did both the first time with I am we forgot we sent the SSP non was not signed. Boom. First first meeting, poof.
Yeah. Yeah. Yeah. We learn also, you know, make sure it's signed, you know, so, you know, it's kind of a Mhmm.
Okay. And so the the what is, let's say, the role of training in when you implement CMMC? So do you need to have professionals who are trained for CMMC or this is not the case? So how does it work for CMMC?
So training from which perspective? Do they need to have a specific certificate, CMMC certificate actually to, you know, run CMMC program or implement CMMC? No. I think, again, like I said, CMMC is managed by Cyber AB.
Cyber AB offers certification. So I think for company, if they want, I think I will say it may be a good idea for you to go tender training. So then when you start when you will start implementing CMMC, you may have a better understanding what is expected of you, but it's not required. Okay.
Okay. Understood. Understood. Okay.
Now, how does CMMC or I mean, NIST one hundred seventy one, how does it treat subcontractors? Right? So if a company is directly a contractor of the Department of Defense, what happens to the subcontractors of this of this first level contractor? So every agency is different.
So it going it will go to you know, one agency will say, I want everyone or my sub and subcontractor to be seven c level two. Some may say, you don't need to. Again, It's all. So it's not a blanket of everyone.
It depends. So for every customer that we have, we ask them, hey. Per your contract, what does your contract what does your agency in contract require? And based on that, you follow it.
So it's it's starting from there, from the contract that you signed. Okay, okay. So it's not from the standard to the buyer actually defines how this Yes. Okay.
And so if I understood well, then an agency can require that a subcontractor is also CMMC compliant, right? Yes. Okay. And for us, same thing.
So the thing what is interesting, so with many of our customers where the agents so some agency will say, by November, we are fine if you are self CMMC self attest. Whereas some agency will say, no. You need it you need to be by November. Or even some may say, need to be by July.
So it depends on you know? Mhmm. Okay. Now, you mentioned when we corresponded earlier, you basically said the biggest gap is aligning business velocity with security rigor, not technical controls.
So what exactly do you mean by this? I think it's a what what I've seen is I have many customer that come in, again, they want a piece of paper. They just think, give me my certification. And it it is the same for CMMC, but it's the same for software ISO.
When a company said, I want how fast can you make me there? And you're always like, okay. For me, you always start from the wrong perspective. If you start by that, you will have a tough time.
You know? So, yes, to it it's more like, well, I have a company. I wanna make sure that my data, you know, it's it's secure. I wanna make I want to have someone that come outside to prove to me or at least, you know, look at my system and give it, you know, tell me, oh, this is where you fail and where you are good.
So it start from a business need. So it start from as a business, do you need to be CLMC? Because, again, it costs you it costs money, and I always tell people compliance is expensive. If you don't need to go there, don't go there because once you start, you cannot stop.
You have to. So it's it's also why you start from a business. Why do you need compliance? And do you really need it?
And then if you need it, understand as a business leader and business team, your life will change. It's that's it. It's a you know? Once you accept that, then you can move down from an IT, but it's all so it's why I always emphasize the the need of the leadership team to understand what compliance mean to them.
And of course, the leadership needs I mean, there needs to be a business reason for a company to go for compliance. Otherwise, it doesn't make sense really. But this part that you were saying, you know, security rigor versus technical control. So what do you actually mean by security rigor, which is not directly I mean, which is not Yeah.
The same thing? Because I think there is there is for me a difference between, you know, as part of the compliance. You know, you are supposed to check your log. You are supposed to check and it's a and independent if you are compliant or not, you should be doing it.
You know? It's it's not just, you know, you but you'll be surprised how many people don't. You know? And I think, again, it's so it goes back to how as if you are the CISO of a company, what is your belief?
How do you, know, how do you manage your security internally outside of compliance? So if you are doing correctly, compliance come with needs and you will realize, woah. I'm pretty much doing what needs tell me I should be doing. I may tweak it versus, woah.
I am doing nothing of what needs required. Woah. So, again, it's where is your security level? Where is your practice?
Know? Mhmm. Mhmm. Yeah.
And it's interesting. I mean, for example, in twenty seven thousand and one, which is a risk based standard, it does really allow you to kind of determine the level of security that you need, right? And which is, I would say, pretty flexible, suits, I would say, most of the companies. And does it work actually in the same way for CMMC?
So is I mean, is CMMC it, also risk based or is it more predefined through this list of controls? Oh, you know, even my source, it's it's funny you're asking that because for me, see that if I take a c three p a o, again, at the end, it's still the human can still make you know, when you read how would I be assessed against that, it's not always a clear cut. And sometimes you can have a lot of conversation with c three p o. No.
No. I'm I'm compliant. No. You are not.
And you go you know, it's not just very simple on saying you have it or you don't. You know? Mhmm. So so so that's why they see this flexibility of again, the c three p o will not tell you how to do it.
You will just have to show them the output they wanna see, independent on how, you know, how you have implemented. So you still have flexibility on the how, how you want, you know, how much security as, you know. Okay. Which, I mean, does make sense.
When I connect it to the thing that we spoke about earlier, you know, if there is such a flexibility, then it's easier to integrate these security into into these regular operations, which which is then obviously much, much better for a company. Okay. I heard that So I'll come back and we'll do here. One thing that I see here, it all also depends if you have to be, for example so we have customer that do they have to be ITAR compliant.
So, again, very, you know, very first, so, you know, as as you you have to export, you know, so which mean you have to be on GCCI. And beyond GCCI now, you can only use systems, you know, most of the system that are FedRAMP compliant. So I have seen customers that will come, they were on Microsoft commercial with, you know, SaaS system that come out, and now we tell them we have to migrate you to GCCI. Oh, well, but you cannot use this tool and this tool and this tool because they will not pass a note.
They are not compliant from the government perspective. So this is the part that people have to think that depending on the level of, you know, do you have to be on GCC or GCCI? It may change your system depending on what, you know, what you start from. Mhmm.
So if I understood well companies that want to be compliant with CMMC, also, is a kind of list of allowed or not allowed tools or or systems that they can use. It's very important. Yeah. Similar thing is coming in Europe with the EASE two and and Dora.
Basically, it's it's also yeah. Okay. Okay. Very well.
So I heard that CMMC is very expensive. Right? So is it true, I mean, that certification or these assessments are very, very expensive? So on average, C3PAO will charge today between 45,000 to $55,000 for an audit.
Even for smaller companies. Right? I think it's why it depends on size. We, BEMO, we only do company from 10 user to a thousand users.
So we do what we call SMB, small business. So for the size of client that we do, it's about the range that we see, you know, 45 to 55. If you wanna do a mock, which, again, I will tell everyone, you do a mock because, again, this is the you know, test it's an extra 10,000 on average. So it's kind of on average your pricing from that.
Mhmm. The rest after that, again, is from a perspective of self if I'm an existing company, I have self attest. I I should have already the people in place to do If I am a new if I'm a new business, at the minimum, you you need to have an IT person, and you have to have someone that will run compliance. It's kind of, for me, the two roles that you have to have by default.
Yeah. And that you need to have the budget for these kind of things. By the way, this is much more expensive than ISO certifications. ISO certifications start from, I think, something like 10 k in The US.
For very small companies, okay. They obviously go much higher for larger ones. It's one thing. It I think it's also more expensive because again, it's a lot more, again, from a when you are going to be one week with three assessor online looking at your system, again, it's a Pretty intense, yeah.
It's very intense. It's intense, it's a slab. You you you can see you can see the company that can handle stress. I can imagine.
Yeah. Okay. So let's wrap up the call. So what would you say are the three most important things companies need to keep in mind when going for CMMC?
So to summarize, again, I mentioned leadership team buying number one. Again, it's another 90 project. It's a company project. This will be one.
The the second from a IT perspective is, again, it depends where you start from. You know, if you already you have a great IT system, it could go as fast as three months. But I see on average, us on average company, it take nine nine month to a year to get it. So when someone say, hey, Bruno.
You know, we enjoy. Can I be compliant in November? It's always like, woah. Not not many.
Where do you start from? You know? And after one call, you realize where they are and you say no. So then they will, you know, say, okay.
Let me find someone that will make me by November. So okay. So this would be number two. And number three is once you are compliant, you have to keep the compliance.
Again, I think it's almost more work post compliance than pre compliance. Okay, great. Thanks for these insights, Bruno. It's been a pleasure talking to Thank you.
And thank you for having me. Thanks again. And thanks. Thank you everyone for listening or watching this podcast and see you again in two weeks time in our new episode of Secure and Simple Podcast.
Thanks for making it this far in today's episode of Secure and Simple podcast. Here's some useful info for consultants and other professionals who do cybersecurity governance and compliance for a living. On Advisera website, you can check out various tools that can help your business. For example, Conformio software enables you to streamline and scale ISO 27,001 implementation and maintenance for your clients.
White label documentation toolkits for NIS2, DORA, ISO 27,001 and other ISO standards enable you to create all the required documents for your clients. Accredited Lead Auditor and Lead Implementer courses for various standards and frameworks enable you to show your expertise to potential clients. And a learning management system called Company Training Academy with numerous videos for NIS2, DORA, ISO 27,001 and other frameworks enable you to organize training and awareness programs for your clients workforce.
Check out the links in the description below for more information. If you like this podcast please give it a thumbs up, it helps us with better ranking and I would also appreciate if you share it with your colleagues. That's it for today, stay safe!
Other episodes covering the same guests and topics, from across The B2B Podcast Index.