Trust Issues · 2026-05-26 · 36 min
Key moments - from our scoring
Substance score
58 / 100
Five dimensions, 20 points each
BMO's CMMC Level 2 certification journey reveals critical lessons about preparation, scope definition, and the fundamentally different nature of CMMC audits compared to SOC 2 and ISO 27001. Bruno (CEO/CISO), David (senior delivery consultant), Cindy (senior director of operations), and the technical team discuss how CMMC functions like an IRS audit - requiring exhaustive evidence for every control point rather than the sampling approach of traditional compliance frameworks. The team switched from their custom 10-year baseline to Microsoft's out-of-the-box baseline one week before audit to eliminate assessor questioning, discovered that configuration management and change management are defined separately by government (not overlapping as in IT vernacular), and had to rebuild their SSP and CUI boundary three times because they didn't involve their lead CCA early enough. Key insights include the importance of deciding evidence presentation strategy upfront (documents vs. live demonstrations), treating CMMC like building an operating system where policy changes cascade through operations, and automating compliance evidence collection into daily workflows rather than maintaining separate documentation. The post-audit burden falls heaviest on IT, with WDAC policies creating operational friction that persists long after certification.
CMMC audits function like IRS audits, requiring exhaustive evidence for every single control point and question, whereas SOC 2 and ISO audits sample approximately 60-80% of controls and may skip follow-up questions if the auditor is satisfied. CMMC is more invasive and demands answers for everything point-by-point.
While change management and configuration management overlap in standard IT terminology, the government defines them separately. Configuration management requires documenting a baseline configuration and tracking all historical changes to it (often in external documents like Excel files), whereas change management follows approval processes for implementing those changes.
Your CUI boundary determines what the auditor will examine and how deeply they investigate. Each boundary change requires rewriting your SSP and all related policies and procedures. BMO changed their boundary three times (Prevail-only, one device, then everyone), forcing complete rework of documentation and implementation each time.
BMO switched from their custom 10-year baseline to Microsoft's out-of-the-box baseline one week before audit because assessors don't question Microsoft baselines, which eliminated a significant source of auditor scrutiny and follow-up questions, even though it was a late-stage decision.
Cindy recommends conducting an upfront NIST 800-171 review session with your lead CCA to lock in your CUI boundary before implementation work begins, rather than discovering scope issues after policies and procedures are already written and systems are configured.
Our reviewer’s read on each dimension, with quotes from the episode.
Contains genuinely useful tactical lessons for CMMC-bound orgs (scope boundary decisions, config vs change management, evidence artifacts vs having a process), but padded with heavy repetition of the same two takeaways ('prepare earlier' and 'bring the CCA earlier').
a lot of organizations will have the process in place, but they won't have the artifacts to turn that into evidence
boundary decides what your auditor is going to look at, how deeply they're going to look into you
The 'IRS audit' analogy, 'operating system' framing, and 'audit story' concept offer some fresh operational lenses, but most content is experiential recounting rather than contrarian or first-principles thinking.
it's much more like an, I would call an IRS audit
CMMC felt way more like building an operating system versus SOC2
These are actual practitioners who just completed CMMC Level 2 certification - CISO, delivery consultant, ops director, security admins - so they've genuinely done the thing, though it's a single internal team debrief rather than voices from multiple scaled operations.
Bruno, uh, you know he is the co host and BMOs CEO and CISO
the team that was involved during the CMMC level two certification
Good domain-specific concreteness - named controls (3.4.1), Microsoft baseline, WDAC, Intune, Prevail, NIST 800-171, quarterly reconciliation, the three specific boundary scopes - but almost no dollar figures, hard timelines, or quantified outcomes.
you may have control 3.4.1
the quarterly reconciliation report that you have to compare what is live active in iTune versus your asset registry
The host asks reasonable clarifying follow-ups and pushes for definitions ('what is an audit story?'), but questions are mostly leading softballs to his own team with little challenge or productive disagreement.
Is that something that you guys know ahead of time or is it just like the auditor puts you on the spot
What is that? What is an audit story?
Computed from the transcript - who did the talking, and the words that came up most.
The phrase “Third time’s the charm” gets a makeover in the latest episode of Trust Issues as Brandon and Bruno Lecoq take us behind the scenes of BEMO’s journey to CMMC success and how they finally cracked it on their fourth try. Hear from their team - Cindy, David, Ademar, Cata, Bruno, Shamiso, and Sylwia - about the critical decisions, surprising challenges, and hard-won lessons that determined their outcome. Together, they walk us through why switching between document and live evidence types demands obsessive preparation, how defining your CUI boundary early prevents costly rework, and why configuration management emerged as the most underestimated control area.
Transcribed and scored by The B2B Podcast Index.
Guest: We felt like from a BMO security, we had been developing our own baseline for the last 10 years and we were very happy with it. But we fetch like at the time of going to cmmc you said hey, this is my BMO baseline and how I came up with it or I'm using out of the box the Microsoft baseline. So we made the decision to go Microsoft which we felt was very good because again the assessor, uh, don't question Microsoft baseline. This removed a lot of noise into the old system, but we did that like a week before going. Welcome to Trust Issue by Demo, the podcast where we go beyond Checkbox compliance and get real about security. In every episode we will break down what's happening in the world of CMMC cybersecurity and grc straight from the people building auditing and living it. Real conversation about real security
Speaker B: all.
Shamizo: Ah, right.
Bruno: Let's introduce our panel. We have Bruno, uh, you know he is the co host and BMOs CEO and CISO. We have uh, David who is our senior delivery consultant. Cindy who is our senior Director of operations. Shamizo who is our senior security administrator. Adamar our senior Data scientist. Sylvia our senior Director of people and Kata who is our security and IT administrator. Hello everybody. Welcome uh, back. Uh, I decided this week to bring the team that was involved during the CMMC level two certification. Uh, we thought this time around we'd get everybody's uh, kind of collect a bunch of responses from everybody, kind of see what their experience was like. Uh, because this wasn't just like uh, uh a one person show. There was a lot of different people involved, a lot of different roles M And uh, essentially what I'm going to do is I'm just going to go down. We uh, kind of collected responses, kind of uh, some broad themes and I decided to kind of pick a couple uh, that I thought were pretty interesting. Um, all right, so let's get ready everybody. All right, so the first question uh, I'm going to ask is um, kind of uh, so the first question was uh, what's one thing you wish you had known earlier in the audit process? And both Adamar and Kata had uh, something that was really similar responses which was uh, we should decide kind of what controls um, evidence wise get viewed in a document versus what gets shown live. So maybe both of you maybe want to talk about like what your experience was like there and why maybe one versus the other, um, makes things more challenging.
Adamar: Yeah, I can go ahead, start. So I think what was interesting is that during the live Audit, since we go control by control and then the sub, uh, processors within those controls, you kind of have to switch very fast between evidence types. So for example, you may have control 3.4.1. And then first line item is if X process is defined and then in that case you need to show your policy or your procedure and it is signed or not. The next one, letter B must be, you know, show evidence on how you track that. So maybe that's a ticket evidence on. You get the alert, you track the alert, you respond to the alert, or it will ask you to show the configuration itself. So this is where, you know, you would live screen intune and then go into the actual configuration and then show that to the auditor. So I think you have to be really prepared on switching between evidence types from your sign policies to live intune configuration to sign procedures to your ticketing system. It pretty much goes, you know, balls around the entire court.
Bruno: Is that something that you guys know ahead of time or is it just like the auditor puts you on the spot and says, oh, actually this thing in the document isn't good enough. Can you switch the live, you know, beforehand?
Adamar: Because everything is based on your ssp. So if you tell in your SSP that you define certain process in your policy, you know that that's where you're going to show. But then as you're showing, the evidence auditor may also jump in with extra questions if they think what you're showing or what you have defined is not sufficient for that control. So everything that you define in your SSP is pretty much what you have to show. But then there's also, if that is not enough, you may be prompted to extra questions and need to be ready to show those.
Bruno: And so are you guys coordinating between yourselves? Like, do you guys all just have like a hundred tabs open, like at all time? And it's just like, sometimes Kat is like, oh, I got this one. Or Adamar, like, I got this one.
Shamizo: Yeah. So we, There is a teamwork, right? So we had several meetings, weekly meetings. We went through the. So going back to the ssp, I would say be careful of what you're asking for in an ssp, because you got to be prepared to show that, right? So, and you have to be fast, right? You cannot just, uh, stumble around and go, oh, is it in defender? Is it in baseline? Is it in, you know. So, um, yeah, we have to answer your question. Yes, we had several meetings. We got prepared, we got screenshots. Uh, and basically we also had like a script. Where do I Go. What do I do? Um, sometimes I get, okay, Shamizo, help me out here, you know, so basically
Bruno: you already have to have the path of knowing how to. If it's live, at least you already have to know the documented path of how do I get there, the exact clicks. Because I can't be messing around live.
Shamizo: You feel like you're a trial, right? You're on the bench and you have
Bruno: to, you know, David, you mentioned, um, that you wish you had a greater understanding of ah, how different the CMMC certification audit process was going to differ from like uh, I guess the other audits that we've gone through, such as SOC, uh, two type two, ISO, uh, 27001. Um, how would we maybe have known that note, something like that?
David: Well, if, if we had read up on CMMC from dod, we would have noticed that it's much more like an, I would call an IRS audit. Um, they want to see all of the evidence, they want to see the procedures, they want to know everything and they go through it point by point on everything. If you go and look at a SOC audit or a ISO audit, it's very, um, well, let's look at 80% or 60% of the things and then you will be asked some questions maybe if they don't really get it or if they don't really trust your answer. But with the cmmc, you're asked everything, you have to have an answer for everything. And it's just, it's very, I would say it's almost invasive or the other ones were very passive.
Bruno: Yeah, it's kind of like getting popcorn in class where it's like, okay, maybe you could ask one or two questions. And if I feel like David did his homework last night, then I'm not going to pick on him again and I'm just going to move on to the next thing. Whereas cmmc, it's, it's very much like no, you're going to answer every single one of these one by one. Right? Uh, okay, cool. Cindy, you mentioned um, something that was really interesting to me and that was uh, the words operating system, um, that you had talked that uh, uh, you mentioned that CMMC felt way more like building an operating system versus SOC2, um, and ISO. Uh, what do you mean by that?
Cindy: So change, uh, every change across the policy or across the control groups impacts operation. So whatever you do so because operations is people, process technology, everything we look at, it's like, okay, we have to have a process for this. We need to make sure it's documented and so that impacted the way we operationalize something. So, so taking a step back and saying, how do we do it today? Uh, can we do it better? Uh, can we automate this? So even in the poem creation that became, well, we're just not going to write a document that's just too cumbersome to keep track of, right? So how we come out with the same output but have it automated for us as part of the work we do. So whenever we come in to enter in a ticket for something or have a risk for something or uh, do a view within our compliance controls, any, uh, output of that creates a ticket, that ticket create has its categorization. That categorization can then be reported on and then we can track it in our system. And we don't have a separate kind of ad hoc document that we have to keep track of. Right. It's part of the way we do work. So automating and operationalizing the things we do in the context of what CMMC asks us to deliver, uh, was another lens that we took and uh, to minimize the external kind of documentation that would be ah, external from uh, the systems that we use as control groups.
Bruno: And was a lot of that stuff new, New for bmo, like, was that stuff that we were maybe doing in the past or is different?
Cindy: No, just I, uh, would say that we utilized existing processes we had. We just filled in the blanks, right? Oh, we don't have category for this. We just need to create a new category of it. We don't. We should have, should we have a separate form? Should we use the same form that we're using today? Uh, what do we want to trigger off of? Uh, so just kind of step by step going through that process flow and coming up with the best solution. And uh, my partner in crime is always Adamar and so he uh, and I would work late nights, you know, just kind of like, okay, here's how it's going to work. And then I would give him that. He gets up, you know, he's two hours earlier than me or so. And so by morning we would have it done and we would be able to demo and okay. The team would be like, okay, check that one off, we're done. You know, we have this control group's done and it's operationalized now and we have data in it and we can represent it in the audit.
Bruno: Next question we asked all of you was, uh, from your department's perspective, what was the biggest challenge during CMMC level two? Um, both David and Adamar kind of brought up the same thing which was uh, configuration management versus Change management. So David uh, talked about understanding the difference and relationship between change management and configuration management. Um, and then Adamar brought up that configuration management was the biggest challenge because it required cross checking policies, procedures, tickets, uh, live intune entry, uh, reviews. So um, what was, I guess uh, we'll start off with David um, what was so challenging between the change management versus Configuration management?
David: Well in, in English change management and configuration management are pretty much the same thing. Um, and the government definitely has a separate understanding of what each one is and they separate them where in my mind they overlapped an awful lot. So we had to come at it from a government perspective, not from uh, our own perspective. And that was a uh, big learning during IT because it was one of the biggest areas in the whole CMMC process.
Cindy: Here at BMO Change Management we use the itsm, the IT service model, uh, here. And so we had already defined processes for change management in place and uh, those are being followed you know pretty, pretty regularly and our IT security team follows those processes. I think on the configuration management side we tend to manage everything within our systems and then have the ability to look at like ah, things that are like fall outside and then resurrect those through ticket management or whatever. So. But we didn't have an actual document. Right. And so what the audit auditors were looking for was did you document this in an external Excel file or something that you're, you have a baseline configuration management across your system and then can you show me the changes you've made historically to that configuration or not?
Speaker B: Right.
Cindy: And so we had the first part of it in terms of the changes that were coming in and tracking the change approval. We didn't have the outcome of actually putting it in a document and saying this is now our new baseline.
Kata: Right.
Cindy: So that was something we had to right size to this particular uh, compliance methodology.
Speaker B: Great.
Bruno: Anything else you'd add Edamar?
Adamar: Um, yes, I think as David mentioned, I think this is applicable a lot to the configuration management because of the size of IT and the amount of sub process that came with it. But one thing that is true to all controls is that you may have their policy and your procedure and you sign those, you uh, review those yearly and sign those yearly. But then within them you may have a lot of sub processes that you document within them and that you require evidence for it. So for example within configuration Management you have your asset registry, right? And that may be a procedure that you review yearly but then within the asset registry, you have a lot of sub items, such as the quarterly reconciliation report that you have to compare what is live active in iTune versus your asset registry spreadsheet or inventory and make sure that those are aligned. And then what you define there is that you review those quarterly with your IT team and it's signed by the ciso, so you need evidence for that. So you may need a ticket with a screenshot and a timestamp. And this is just one line item within a procedure within the configuration management. And I think that's the biggest challenge because it's one of the major ones. But that is true to pretty much all the procedures. You also have to keep in mind those line items within your procedure, the who, the what, the when and the how you do it, and have evidence for that.
Bruno: Yeah. Wow, that sounds like a lot of extra work. Yes.
Shamizo: Kata, can I ask you a question? Do you know who's suffering most of after the CMMMC implementation? The IT department. I still have a CMMC PTSD, uh, suffering recovery. Because when you open the hood and you start implementing all the changes and stuff, you gotta have to have a lot of people screaming after the fact. So you gotta know, you gotta know how to adjust all these policies, you know, you gotta know how to, you know, go around.
Guest: And the worst for Kata is the post cmmc.
Bruno: Why kata, Tell me, why is it, uh, what has changed in your day to day life so much?
Shamizo: Well, because CMMC is so tied up, right? The system imposes so many restrictive access to everything. WDAC application control policy. Right. That ties up a lot of, and creates a lot of, um, I'm going to put a quote unquote noise because people are screaming, hey, I'm blocked to install PowerShell module. Okay, uh, go and adjust the policy. Um, and wdac, it's not an easy policy to um, manipulate, let me put it that way.
Bruno: So things just take a lot longer to go complete.
Shamizo: Basically the system, it's very secure. Let me put it that way, Jen.
Bruno: Both you and Bruno uh, talk about uh, changing from uh, I guess what be no baselines to uh, I guess Microsoft's uh, baseline. And you guys did that kind of close to the audits. Uh, why was that something that you guys decided to do? Yeah, I can tell you.
Guest: So with fetchlag and from the BMO security, we had been developing our own baseline for the last 10 years and we were very happy with it. But we fetch lag at the time of going to cmmc. What do you say? Say hey, this is my BMO baseline and how I came up with it, or I am using out of the box the Microsoft baseline. So we made the decision to go Microsoft, which we failed, was very good because again, the assessor, uh, don't question. Oh, it's Microsoft baseline. I'm not sure, but could have been more. Oh, how do you decide that? And that and that. So this removed a lot of noise into the old system, but we did that like, uh, a week before going. So it's.
Bruno: Did that break anything?
Guest: I don't think so. W dag did more damage than the policies.
Shamizo: Well, baseline works hand in hand with wdag. Let me, let me put it that way. So you kind of have to know where to go and adjust.
Speaker B: Mhm.
Bruno: Um, all right, to the next group of questions. Uh, what decision made by another department impacted your work the most? Uh, during the audits, uh, Bruno talks about how, uh, we decided to change our CUI boundary three times, which forced us to redo our SSP and all those policies, uh, three times. Uh, and I see everybody kind of laughing and smiling about this. Uh, why is the CUI boundary so important? And why did that mess things up for us?
Guest: So I will start and people can comment. So from a BMO perspective, again, we don't have CUI because, you know, we don't, we don't deploy government, uh, stuff. So we don't. So we had to think about what does it mean for our customers. So we first designed the best line for us for bmo. We were happy with all, you know, a bunch of. And then, uh, you know, we work with a, uh, lead CCA on our side to kind of help us review our, uh, boundaries. And after it was discussion, okay, do we care about BMO or do we care for customers? And we say, oh, at the end we are doing that for customers so that when they will have their CMMC audit, you know, we're bad. So we tweak, we tweak, you know, and we tweak three times. So at the end, you change boundaries, you change your ssp, you change.
Bruno: What were the three different, um, without going too deep, what were the three different kind of scopes that you guys originally went through?
Guest: The first one is we're planning on using Prevail. So, uh, we say, okay, we'll use Prevail. The second one is, okay, let's just go and do one computer that will have cui. And at the end we end up being like, hey, anyone at BMO can deal with our customer who could handle cui which means we could. So it was if, you know, we change the scope. So and of course when you do that three times, so we know ISSP
David: back now, boundary decides what your auditor is going to look at, how deeply they're going to look into you. And if you open it up to, um, we're going to allow, uh, five people in our company to store stuff in Prevail. But then anybody could talk to those five people. Well, now you've opened up your entire company's IT architecture to be, uh, investigated for cmmc. Whereas if you scope it down, then the auditor cannot ask questions outside of that boundary. So it's very important to think of what your boundary is because that's what you have to expose and answer and be ready to defend. So doing it three times from three different perspectives changed what we had to look at. And that just difficult. Don't anybody ever do that?
Speaker B: Yeah. So just want to add what David has said. If we had decided to just scope to one device, we are just going to have the 110 controls evidence by evidence for that one device. So it was so much better to scope it to everyone so that you show the controls 110 for everyone. Because one device we are just going to do the same thing that we did for the like 20 computers we have. So it was so much easier to do for everyone.
Bruno: That's interesting. Like I would have thought that choosing one device or just going with Prevail. The idea, the idea is that it would actually make the boundary smaller and simpler by only having one device or whatever. But it seemed like it would actually ended up being easier by just saying everybody could go do it again.
Guest: To your point, Brennan, it depends from which hat. If it's just for Bibo, prevail. Okay. But once now next time we have an audit for customer as an audit and has to look at the BMO IT perspective then would have fire back at us. So it's kind of, you know, it depends on which hat you put.
Adamar: Sure.
Bruno: So when our customers get audited and we are the esp, it will actually be easier for them. Or I should say, uh, there's a higher likelihood that they pass because of the way we set up our boundary now.
David: Yes, they inherit a lot from us
Bruno: now I'm just thinking theoretically now potentially there's a lot of contractors kind of down the road or maybe they have an MSP that said, oh, hey, I got Prevail or oh, I decided to do it this way, and then they're about to go into their Customer's audit and the auditor is now going to have a different opinion and saying, oh, actually that doesn't work anymore.
David: Yeah, they're going, they're going to have to justify things that we have already been certified on. We can bypass it by saying we're certified, here's our certification. And if it uh, if the MSP is not certified, they're going to have to say, hey, now come and audit me. So it's going to be double what our customers do if the uh, MSP is not already certified.
Bruno: Yeah. If you're a contractor, you probably don't really want to risk that because it's not really up to you.
Cindy: Right.
Bruno: It's up to your msp.
David: M. It's not up to you. Yeah, exactly. Exactly.
Shamizo: Yeah.
David: Try to tell your MSP how they should run their shop.
Shamizo: Now also keep in mind, BMO is quote unquote, kind of a baseline for our customers. Whatever security we have, that's how we start with. Right. And then we customize uh, um, our customers based on their needs. Right.
Bruno: So Cindy, uh, if you could do redo one part of the process, what would you change?
Cindy: I think that I would have pulled the team together and we all would have had a NIST 800, 171 review session. We would uh, go through the SSP line by line and um, have interviewed our CCA first to ensure that our boundary was all in. Like looking at things from, as Bruno said, customer and BMO perspective and that we are setting ourselves up at first to ensure our boundary was good for our customers. And then we set from there what our policies and procedures would be that would have prevented our uh, three time redo of our boundary. And it would have set the stage for how we need to tackle the control groups and at what level of scrutiny. We would have known right up front, uh, where we needed to go with that, uh, how we needed to write our policies and what uh, our procedure base would have to be in order to meet those controls. And that all in and of itself would have been a, uh, good set of time up front and would have. I don't know if it would have. I think it would have saved us time and rework certainly on the boundary and then in tightening our policies and procedures. So uh, we would have known that every single assessment objective, we would need the wall through one Ragwan and test, uh, upfront. You know, we couldn't assume that, yep, this kind of, these procedures and what we do in uh, our systems is enough. You know, it just wasn't enough to have the list in intune, we also had to have a separate document. So I think working with our CCA up front would have given us that excite, and we would have been far ahead of the deliverables we bring to the table.
Bruno: Right. All right. Bring the lead CCA way earlier to get the scope correct so that we don't waste our time doing all this implementation work and all this writing, um, downstream. Yeah. Right. Shamizo.
Speaker B: Yeah. For me, I would say, um, preparing the audits earlier because we had a lot of sleepless nights trying to get the controls to see is it matching with what Bruno said in the ssp, trying to make the configurations match. So I think that process, if we had done it earlier, it was gonna be better and at least we'd have rested and, you know, because we had lots of sleepless. Nice just to get things in place. So. Yeah.
Bruno: So basically, you have the audit, you have the pre. You have the mock audit, and then before that you would have a pre audit just internally.
Speaker B: Yeah. So I think preparation Ellie would have made things easier for us from the technical side and even from Bruno and Cindy, because they were. We're saying, okay, this is not it. We have to change the policy. And Bruno would go and make the change. Then I come to come back again and say, bruno, we need this procedure. It's not like it's not there. So you'd go again and say, ah, uh, no, we need to tweak this again so that if we have made, like, met earlier, made the preparations. Yeah, it would have made a huge difference.
Bruno: What about, um, prepping for, um. When you guys had talked about finding, like, the path for the. If you had to show something live, I would imagine that probably takes a lot of time to go prepare for. Like, what do I need to click? And what's the path to go show evidence live.
Speaker B: So we had to meet with Kata and. And Bruno before the audit. Because sometimes what we said in ssp, we have to be confident to show it and sometimes to just maybe the auditor would say, okay, you mentioned this, but it's not there. But then we have to quick think, like, to do a quick think, like, say, okay, uh, the auditor wants this. So what should we show? What. Where we do we go. Because the policy is like the baseline. It's a big policy. So we have to know exactly where we should go and click so that we don't take too much time. So the preparation, like meeting before the audit also made a huge difference for us.
Bruno: Okay, great. Thank you. Uh, David, what about you? What would you have done differently?
David: Same basic thing is that we would have done everything earlier. Um, but the CUI boundary, uh, to me it was just so eye opening of how much it can control what the auditor looks at you for that we should have understood that and prepared for it and had it done before we even went in and started our ssp. We should know what our boundary is and then define it as opposed to define it and then come back and kind of hope that it's something cohesive.
Bruno: From my understanding though, we started in December. So you would have started even earlier.
Kata: Well,
David: I would have started in a different way. Okay. We should have gone in knowing a lot more. We were very, very, um, naive going in. And I don't think anybody should ever go in that way. But I can only imagine with the 3,000 companies that are going to have to do this, uh, there's going to be 2,950 that are going to be naive.
Shamizo: Yeah.
Guest: The interesting part for me goes to
Adamar: kind of, uh,
Guest: what David was saying was at the end of the day, from an assessor perspective, we know we are 100% correct on an it. They say, well, your it is very good, you know, very good. So all our issue were on documentation. And I think it goes back to the best thing we did is at one point and we hired a lead CCA that was very good that, you know, could ask questions. So we got a question, I think, you know, his name was Nicholas. We were able to make our boundary fixed and then after that everything comes together. So if we had to redo it, bring in the lead CCA earlier so you can ask questions outside of your C3PAO and having meal. So this was, for me, it seemed
Bruno: like it was also really good that Nicholas, um, besides also being a lead cca, had already been certified himself also. And so it sounds like one of the themes is also being able to use a resource that is already certified actually helps tremendously. Um, what.
Guest: Nicholas is not only the lead CA, but he is also an IT director. So he has both sides and he's on Microsoft like us. So it was again the perfect combination of Adamar.
Bruno: What about you? What would you have done differently going into this?
Adamar: Um, well, still keeping the preparation topic as everyone, but I would say focus on the process side of things. Um, we talked about Cindy mentioned and David as well. I think a lot of organizations will face the same that we may have processes that we do on it. So you have it there, you have it establish, you do it even automatically. But from an evidence perspective, you will not have artifacts to prove that you do this process, and that is across organization. So I think my recommendation would be me to. With every process leader. So, for example, even from a HR perspective, during onboarding, who owns this? Who owns that? And then make sure that every process that you do have will be able to be, you know, taken for evidence, and you have record for that. So I think a lot of organizations will have the process in place, but they won't have the artifacts to turn that into evidence. And that is, like, the challenge. So I would say also start early by interviewing and checking all the processes that, uh, the organization having from an operational perspective.
Bruno: Sounds like all this prep, though, requires a lot of free time
Guest: to go
Bruno: do all that stuff. Right. It seems like all this is really eating up a lot of your time. The last, let's call it six months of generating all these new artifacts. Um, interviewing people, doing an internal audit before the mock audit. Right. All those sleepless nights. It sounds like there's sort of just no way of. There's no really shortcut to this. No. All right. Thank you. Uh, all right, Sylvia, um, what would you have done differently going into this?
Kata: So same as everyone. Uh, bring Nicholas earlier and do the kind of mock of the mock. Right. That he was showing us, how the editors will really ask us questions. Right. So that was guillotine. Uh, but from HR perspective, as we already had a process, but we had to change the process to meet the cmmc, uh, requirements. Right. So even if we had the process before, the steps are a little bit different and needs to be done before people are joining the company. Right. So, uh, for me and Kata, actually, we had to sit down and walk through our process, change our process as we work closely together during the onboarding and offboarding. So that was the major change. And I think that, um, for the big company, that could be something that they need to be aware of.
David: Cool.
Bruno: What about you, Kata? Last but not least, um, I think
Shamizo: I should maybe redesign the process to lead, um, with the audit story and demo flow, and then build the evidence to support that story.
Bruno: What is that? What is an audit story?
Shamizo: Not the other way around. Right. Not the other way. So go know what the auditor wants. Now we know. Right? So now we kind of know and then start building the evidence based on that flow. Right? So because right when we did it, it was like, okay, we start from mssp. Now go. Is this is. This is how we're gonna go about it? Or, you know, what.
Bruno: What what is an audit story?
Shamizo: Well, it's basically their, their script, their what, what they're looking for.
Bruno: Right, so basically putting things in the right order to make the right order.
Kata: Yeah.
David: Yeah.
Guest: Okay, cool.
Bruno: Well, thank you everybody for joining. Uh, as you can see it takes a uh, village to go get CMMC level two certified. Um, and glad uh, to have everybody here to be able to kind of give their perspectives, um, and probably change a lot of the ways. Probably giving us a lot of ideas on how we'll go implement this across all of our customers. So again, thank you very much and have a great week everybody.
Guest: That is another episode of trust issue in this conversation. Help you think differently about compliance, security or trust. Share it to help someone who is still stuck in a checkbox mode. Each week we will keep bringing you more episodes resources and real world insight from the BMO team. Wherever you are listening from, don't forget to rate the podcast and follow us to stay up to date on the latest development in the GRC space. Remember, compliance gets you set certified, but real security that earn trust. Thank you for listening.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.