The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Marketing/Trust Issues
Trust Issues artwork

How BEMO Aced CMMC Level 2

Trust Issues · 2026-05-19 · 42 min

0:00--:--

Key moments - from our scoring

Substance score

54 / 100

Five dimensions, 20 points each

Insight Density10 / 20
Originality8 / 20
Guest Caliber11 / 20
Specificity & Evidence14 / 20
Conversational Craft11 / 20

BEMO, an MSSP, recently achieved CMMC Level 2 certification with Insight Assurance as their C3PAO after completing both a mock audit and final certification audit. Bruno and the team share their experience navigating the rigorous five-day mock audit, which involved 320 Assessment Objectives (AOs) across 14 control families, with 240 classified as non-negotiable failures - meaning a single failure in those areas triggers automatic recertification in six months. The mock audit proved invaluable: BEMO discovered five documentation discrepancies (including a password policy misaligned with actual implementation at 14 characters versus the documented 12) that would have caused immediate failure in the official assessment. Their team of six - including their 28O admin Catherine Chamizo, HR representative Sylvia, ticketing manager Adamar, and compliance lead Cindy - spent 10 days fixing these issues before passing the official audit on May 12th. The discussion covers the courtroom-like intensity of the process, the critical importance of cross-referencing 36 policies, 46 procedures, and over 700 pieces of evidence compiled into a 300+ page SSP, and how BEMO automated evidence collection and monthly reporting to sustain compliance at scale for their customers. Operators running CMMC programs, MSSPs preparing for certification, and compliance teams managing GRC documentation will find practical insights into audit preparation, evidence management, and the business case for automation.

Key takeaways

  • →Conduct a mock audit before your official assessment - BEMO found five documentation discrepancies during their mock that would have resulted in failure on the official audit, and the mock gave them 10 days to remediate before re-assessment.
  • →Out of 320 assessment objectives in CMMC Level 2, approximately 240 are non-negotiable failures that immediately fail your certification, while 80 are remediable with up to six months to fix and re-audit.
  • →Documentation must be tightly synchronized across policies, procedures, and actual system configurations - BEMO failed a control because their password policy stated 12 characters while their Intune implementation enforced 14 characters.
  • →The audit process requires 6+ people across HR, IT, compliance, and operations to be available simultaneously for five days, with specific control families assigned to different team members to prevent burnout and ensure consistent coverage.
  • →BEMO automated their evidence collection and monthly compliance work using scripts that automatically pull logs from Intune and Purify, create reports, and open tickets - reducing ongoing audit maintenance burden for both their own certification and customer support.

In this episode

  1. 1BEMO's CMMC Level 2 Certification Achievement
  2. 2The Mock Audit Experience: Structure and Intensity
  3. 3Policy, Procedure, and Evidence: The Three-Layer Framework
  4. 4Documentation Issues and the 10-Day Fix Window
  5. 5Team Preparation and Control Evidence Mapping
  6. 6Final Audit and Scaling Compliance for Customers

Mentioned

BEMOInsight AssuranceCMMCIntuneEntraPurviewBruno

Guests

Bruno

Topics in this episode

SSP (System Security Plan)CMMC Level 2Insight AssuranceC3PAOAssessment Objectives (AO)Microsoft IntuneEntraPrivileged Identity Management (PIM)MSSPDefense contractorsCMMC Level 2 certificationCMMC audit processmock audit preparationMSSP complianceCUI data handling

Questions this episode answers

How many assessment objectives must be passed to achieve CMMC Level 2 certification?

There are 320 Assessment Objectives (AOs) total, with 240 classified as non-negotiable - failing even one of these non-negotiable AOs results in immediate failure and mandatory re-audit in six months. The remaining 80 AOs can be failed with remediation allowed within the six-month window.

What is the difference between a CMMC policy and a procedure?

A policy states the requirement (e.g., 'passwords must be 14 characters'), while a procedure describes how compliance is verified and maintained (e.g., the process for checking Intune settings to confirm the 14-character minimum is enforced).

How long does a CMMC Level 2 mock audit typically take?

BEMO's mock audit ran five consecutive days, from 7am to 3pm Pacific time (with breaks), going through all 320 Assessment Objectives one by one with three assessors and six organizational representatives present via Teams.

What happens if you fail a CMMC Level 2 mock audit?

The mock audit is a test run with no pass/fail consequence. Failures identified during the mock provide 10 days to remediate before the official certification audit; if issues aren't fixed within 10 days, the audit restarts from zero.

How does BEMO automate CMMC evidence collection and compliance reporting?

BEMO automatically collects monthly Intune and Purview logs on the first day of each month, generates reports, and creates tickets for remediation - reducing manual documentation burden and enabling the same automation to scale for their customers.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

10 / 20

Contains genuinely useful CMMC-specific tactics (do a mock audit, the '240 non-poamable objectives' rule, boundary/scope determines everything) but is heavily diluted by rambling, repetition and broken sentences that pad out the 42 minutes.

you have to do a mock to the mock
out of the 320, um, I think it's 240 are failing. So which means if you fail one of the 220, they are not what's called poemable, which means you cannot sell, you just fail

Originality

8 / 20

Mostly an experiential recap of a certification process rather than fresh thinking; the 'compliance first, security second' reframing and 'game the system' single-laptop discussion are mildly interesting but largely conventional compliance wisdom.

now we are compliance company first, security second
what if I make my boundary the single laptop

Guest Caliber

11 / 20

Speaker A is a practicing CISO who personally led the CMMC Level 2 certification as an MSSP - a genuine practitioner living the thing - but this is an internal team chat rather than an external expert, limiting breadth of perspective.

me as a ciso
BMO is officially CMMC Level two. Certified ourselves as an mssp

Specificity & Evidence

14 / 20

Strong on concrete numbers: 320 assessment objectives, 110 controls across 14 families, 700+ pieces of evidence, 36 policies, 46 procedures, a 300+ page SSP, five documentation issues, 10-day fix window, $55K re-audit fee, and a December-to-May timeline.

we have 36 policies, 46 procedures, more than 700 piece of evidence
you have 14 family, 110 controls, 320 AO

Conversational Craft

11 / 20

The host asks useful clarifying questions (policy vs procedure, what happens if you run over) and builds on answers, but it's a supportive internal conversation with no real pushback or challenge to claims.

What's the difference between a policy and a procedure?
what happens if like you take too long?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker A73%
  • Speaker B27%

Most-used words

mock26audit23sure23show22perspective16five15policy15customers14procedure14fail13back13check13three13interesting11control11evidence11

Episode notes

Getting CMMC Level 2 certified isn't about checking a box. It's about fundamentally transforming how your organization operates, and the path to certification is far more rigorous than most companies anticipate. In this episode of Trust Issues, Brandon and Bruno Lecoq share their firsthand experience achieving CMMC Level 2 certification as an MSSP, walking through the mock audit process, the documentation challenges they encountered, and the operational changes required to maintain compliance at scale. This is a candid breakdown of what actually happens during a five-day assessment, why the preparation phase matters more than most realize, and how scoping decisions made early can make or break your certification timeline.

Full transcript

42 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: It's like going to a trial. A lawyer asks you a question, you

Speaker B: answer in 10, you're on the stand for 320 questions out of the 320,

Speaker A: but I think it's 240 are failing, which means if you fail one of the 220, you just fail. Welcome to Trust Issue by Demo, the podcast where we go beyond checkbox compliance and get real about security. In every present, we break down what's happening in the world of cmmc, cybersecurity and grc, straight from the people building auditing and living it. Real conversation about real security.

Speaker B: All right, well, as of this morning, uh, BMO is officially CMMC Level two. Certified ourselves as an mssp. Uh, finally. It's been months in the, you know, months in the making. Uh, but what we'd like to do today is kind of talk about what was that experience like? Uh, you know, we're finally over, you know, over the threshold. Um, um, we completed our mock audit as well as our final certification with Insight assurance, our C3PAO. Uh, Bruno. Uh, maybe let's just start off with how are you feeling?

Speaker A: Again? It feels very good. You know, it's just like I went and said, has been, you know, many long nights of prepping and all of that. And again, from a. From our perspective on bmo, what's interesting, everything, the prep we do is to be certified for us, but how do we scale it with our customers? So it's always everything we do is it was just certification on itself, just for us done. But it's not just for us. It's from the learning. How do we scale? How do we. So this is right.

Speaker B: What happens when you have, uh, 10, 20, 50 customers? And I have to repeat, how do

Speaker A: you run the automation and all of that? So again, it was, you know, so again, so what I would say to all our customers, you have to do a mock to the mock. So what was interesting from a BMO perspective is we did the mock. So again, it was one week, uh, starting at 7:00am Pacific, and it was until 3:00pm so it's every day for five days. So very intense. You go through with the assessor, they go through all your controls. And so from a people perspective on an IT, we had 100% no problem, no control. Uh, we end up with five documentation issues. And again, it's just. By the way, I give an example, one that we had was at bmo, we are passwordless. Okay? But we still have to have a policy, because in Casio, you need to go to Password, you need to have it. So by default, from a BMO perspective, within the intune, we have minimum 14 characters. Okay. You go to your procedure. It said, how do we verify we have 14 characters? But our policy was saying 12. All right. Boom. Yeah. Ding. You got no. You know, and if, uh, we would have not done the mock, we would have failed because of the document not being synced.

Speaker B: You wouldn't have had a second chance.

Speaker A: We wouldn't have had a second chance. And again, from my perspective, even the auditor, we laugh, but let's say if I play by the rule, it's just you. So we had five documentation errors. Well, with all the mock would have failed and I would have to re. Pass retack again. So the advantage here is again, we fixed it and then went.

Speaker B: Except that you would have then had to tell everybody else that you failed or uploaded your SPRs score. Right, exactly. And now it doesn't look good.

Speaker A: Right, exactly.

Speaker B: For something that was in this case very kind of dumb. Right.

Speaker A: Like you, but you. Well, yeah, to get people in perspective, we have uh, 36 policies, 46 procedures, more than 700 piece of evidence, you know, and your SSP and your SSP or SSP. 300 pages. So think all the cross checks that you have to go across all of that, you make a change somewhere. Do you have it? You know, it's just like you go

Speaker B: verify, you validate, they're interdependent on each other.

Speaker A: Yes.

Speaker B: And you're talking about hundreds and hundreds of pages and you're like, do you really know this book? I mean, that's a book, right? Do you know the books by heart?

Speaker A: It's a huge. I think if I had the SSP and all the procedure and I will go run the math, but at the end you have something more than a thousand pages. Uh, yes. You have more than I am. So just imagine the old days. Which page? Oh, I need to go back. You know, so it's.

Speaker B: Yeah, I mean it's a lot of details. Um, and one or two people, like you need a lot of people involved to be able to cross check everything. Right?

Speaker A: Correct. So again it's so again, I feel like it's uh. I also feel like the way it is, it's like any exam, you know, you take a certification and at least you get a test run and you know, they. And practice SAT and going through it now, it was very good. You can see how the assessor looked at it. What you know is just, you know, again, so, so tell me.

Speaker B: Um, let's Talk about just like, what is, like, what is the mock audit like? Why do you recommend the mock audit? Like, what is the experience of like going through a mock audit?

Speaker A: So it's the same. So again, for more perspective. So we are live. So you are live with uh, so in our case, three assessors. So within site, three assessors on their side. And on our side we were six people. So you know, again, four people. We had our HR person because HR is. But again it's not only it. You have the HR person, we have a compliance again. So everyone, you know, the two IT person, me as a ciso. So it's kind of a group and you go through all the controls. So even from the um.

Speaker B: What does it mean to like go through the controls? Like you're on a teams call and you're sharing screens.

Speaker A: So you're on team calls, you share your screen. Okay, so you are live. You are live, everyone from 7am M.

Speaker B: To 3pm for five days.

Speaker A: Yes, for five minutes. You have a break between. But you know, it's uh, you know, it's, it's, it's intense, you know, again, for I think, of course after the second day you start to understand, you know, it's. You understand how it works. And again you're on the mock. So you're like, okay, you know, you know when you say, for example, like, okay, so we screwed up on the password, you know, it kind of give you a bad test. But I would have hated to fail because of that. Because at the end our system was correct just how we report it. So you go. So you go through the 14. You have the 14 controls. You have uh, the 14. You have 14 family, 110 controls, 320 AO. So you go AO one by one. So the assets always, he always starts from a policy. Okay, for this control, what is your. How do you make sure this is happening? Okay, this is all policy. You can check the policies. Let's check.

Speaker B: Okay, so you go down, um, one by one for all 300.

Speaker A: One by one. The 321 by one. So it's why it takes five days,

Speaker B: let's say show me the policy of what it means to do password.

Speaker A: Show me the. Oh, you want to. Okay, here I can show you how the policy, what it means. Okay, how do you make sure it happens? This is our ah, procedure. Let me show you the procedure that is linked to the policy.

Speaker B: What's the difference between a policy and a procedure?

Speaker A: Uh, a policy is e.g. gateway. Just to give an idea, our password needs to be 14 characters. The procedure is how do you check? How do you make sure this happened, that you always have 14? We'll go check. What is the process of checking? Okay, and so this is the procedure. And then. Now show me the proof. So the proof is you uh, have screenshot or in our case we go live, depending. Sometimes the screenshot was good, sometimes go live. And you go live, you go to in tune or you do collisional access and you show the screenshot. Okay. Um, and they take the screenshot. Okay, let's go now to 3.1.1 B. 3.1.1 C. And you go through this exercise.

Speaker B: Uh, and so what happens if like you take too long? Because like I could easily imagine that you could go over five days if you're that.

Speaker A: No, no, no, I think, you know. No, I don't think at the end. No, I don't think you need. I mean, maybe because we are very ready and we divide same thing in a team of who does what.

Speaker B: There's six people on our side who are doing this, right?

Speaker A: Yeah, yeah, exactly. Six people on our side, you know, and also to divide for him. Um, if you don't want the person to be uh, on the spot for 30 hours, it's just like, okay, how do I do it? So we divided the role, who did what. And also think of our be careful of in a week as a team. Don't talk too much. Again, it's an ancestor. It's just anything when you share your screen. You share your screen, you show what you do and you cut the screen sharing. You don't want to show more because it's evidence for them.

Speaker B: Right.

Speaker A: Okay.

Speaker B: So it's like I always take more questions.

Speaker A: It's like going to a trial, I guess. I've never been, but my expectation is a lawyer asks you a question, you answer in 10. Mhm. Hey, you know, you know, so it's right.

Speaker B: You're on the stand for 320 questions.

Speaker A: Exactly, you're on the stand for 300. And again, out of the 320, um, I think it's 240 are failing. So which means if you fail one of the 220, they are not what's called poemable, which means you cannot sell, you just fail.

Speaker B: It's an honor.

Speaker A: So you have 240, you need to make sure the other one, if you fail them, you may have up to six months to fix it and you have to re audit. So it's kind of. Yeah, right.

Speaker B: So there are some that are non negotiable and um.

Speaker A: 200 failures that are non negotiable fail

Speaker B: the entire mock audit.

Speaker A: Exactly. M. Yeah, no, the more coded you will not fail. You will lose your 5 points or your 10 points points or whatever. But if it was the official assessment, there is no.

Speaker B: That's it, stop here. See you in six months.

Speaker A: Exactly.

Speaker B: And I'll collect another 55,000 from you.

Speaker A: Yes, I will come back and so. Yes, so it's exactly. Okay.

Speaker B: Um, and you said on their side for these five days they have two. Two assessors, three.

Speaker A: They need to have minimum three. So okay, what was interesting for us when we work with insight, the first call there were element of them. Yeah. Wow. So this is impressive because now you see your team and I don't know again, maybe some are in training, I don't know why they're living and you don't ask the question. It's just like. And then after it was only three during the mok all the time, three people. So they divide. One person will do a control, another one will do another control. There they all have which control. You know, it's not the same person, same thing for them.

Speaker B: M. They probably have decided, they probably have segments in it by families. Right.

Speaker A: So what's good for listener again is, you know, there is all the wonder on hr. So again at the end it's our HR person is the one answering the question, showing her document, showing her procedure, showing her workflow. And also you know, maybe talk a

Speaker B: bit more about the. Who are the six people in our side and why like why is this not just it but maybe talk about like what are the different um, organizations within represented there by demo.

Speaker A: Yeah, so uh, we had, you know, we have our 280 admin, so Catherine Chamizo, the 280 admin. Uh then we have Sylvia with our HR person and then we have Adamar. So Adamar manage all our data ticketing. Ah, so again everything you do in a CMMC world start with a ticket, you know, uh, I'll give an example. So for example, uh, iOS they just did yesterday. So they push an update which means we go to intune, we open a ticket and saying we are going to raise the minimum version required, you know 25. We put a ticket, it's approved. Qatar go and go change it so you can trace it. So again, so it's again the world for many people, but it's how the world works. So everything. So during the audit you have to show your those tickets. How are you doing it? Show me a ticket. Show Me, you know, so it's kind of a. Yeah. So, uh, and then we have, we have Cindy, who is in charge of our compliance team. Again, same thing from the poem, the risk assessment, how the, you know, how the whole thing works.

Speaker B: Yeah. So that's a lot of people people.

Speaker A: It's against all automation again. So. And what I will tell to our listener again, we. We just got married here. Well, we got a certification, but you have to keep it. And it's month of, you know, you have. We have our um, monthly security team with stuff we have to do and there is a monthly compliance team that does, you know, and both have to, you know.

Speaker B: And so what's the monthly like work involved? Like now that it's over? Like, do you get like surprised?

Speaker A: I think it's the same as before. I mean the work is, I mean the extra work we had to do here was to make sure all the documents shows well. But from the. Nothing changed with last month. You know, the ticketing is the same, the monthly recurring. So again, so the advantage of bmo because we are pretty advanced on AI, you know, there's a lot of things that we are automating, you know, collection evidence and you know, so again, it's just how much, how much you can automate. So on our case, for example, the first day of the month, we automatically get the last month log of intune of purview. So it's all common. We have 60, 60 logs, they all come automatically. And then our uh, agent runs and automatically create reports, open tickets. So again it's all automation. We saw of course now pass the audit. I can see tricks I want to do. And again for us is we do that and make sure. Okay, how we'll use the same automation that we will give to our customers to do their automation.

Speaker B: Right. Because the idea is not only do we have to support this for our customers, but if you are the esp, uh, for a defense contractor, you as the MSSP also has to be CMMC level 2 compliant.

Speaker A: Right. And as the MSSP, we have to provide. So again, we have customers that will use BMO to do everything. Some customer, they will just ask for it and they have their own rpo. But we have to provide from an IT perspective. We have to provide data, uh, monthly to the rpo. So if we don't give it, if we are the rpo, we give it to ourselves. But the work is the same. Yeah, yeah, yeah, yeah, yeah.

Speaker B: Interesting. Okay.

Speaker A: So you give the, you know, you give the evidence every month. Yeah.

Speaker B: So at the end of this mock audit, right? Like, it's Friday. Uh, what. What happened at the end? Like, you just have, like, oh.

Speaker A: Uh, so after that we had 10 days. So this. So we finished was May 1st. Okay. And we had 10 days to fix our file issue that were found. And then, uh, we restarted the audit. So now, again, now it goes back outside of mock. Let's re audit you. And now that's it. So you did your trial run. Great. Do it again. Right. The auditor.

Speaker B: It's now May 12th. We restarted on, uh, May 11th. Right. Um, and, um, so the process went a lot.

Speaker A: Again, a lot faster again, they have to see, you know. But, uh, yeah, yesterday was tense. It was interesting because now you have the mod before you know, Even if you don't want to fail, you are like, if I fail, it's okay. I have a net. You're like, hey, what if, uh, they don't like how we fix the five issue? Or what if they find one? You don't know? It's just like now, yesterday you could feel the team tension of like, okay,

Speaker B: now, did I ask, did I actually go fix those things correctly? Right. Because it's not like they're. From my understanding, the, um, audit, they

Speaker A: cannot tell you how. They're not telling you how to fix it. You fail. We needed to see that. We didn't see it. Or this, you know, this was wrong. But now you go fix it. Don't tell you. So it's not like you come back and like, I m hope this time they would like how we fix or what we change, you know, so.

Speaker B: Right, right. You don't get to ask them, does

Speaker A: this work for you? Yeah, exactly. Doesn't work this way.

Speaker B: So.

Speaker A: Yeah. And so again, I will recommend. I love working with Insight. They were very professional, but they knew where not to cross the line. We knew it was clear.

Speaker B: Okay, so when, um, so my guess is they gave you 10 days to fix it. Uh, seems like it's up to the auditor to determine how much time. So 10 days isn't necessarily like, the norm.

Speaker A: No, no, no. For what we. After the mock, you have 10 days. If it's more than 10 days, it's kind of. You restart from zero. So you only have 10 days. So because again, then for them it's fresh. It's also, if we do it within the 10 days, then, uh, they go through the process better, faster.

Speaker B: And, um, if they find too many problems during the mock, then what happens? They just say, like, see you in six months.

Speaker A: Oh, you keep the mock Is your. It's your test run, you know, so at the end you're like, you know, I'm sure it's like, I'm sure for them would be like, those guys would have a problem to pass. I'm sure. Again, I kind of. I don't know what they think and what they do. But on our side, for sure, we would have had, you know, for me, I was very proud to have no IT issue like for my 100% on it. So at least I knew for we

Speaker B: only had documentation issues.

Speaker A: So from my perspective, it's okay. I know our IT system is solid. What we do on our customer, because we do the same is solid. So it was a good. Ah, cool. It was cool to see. I would have felt bad to say, whoa, your IT is failing here and here. No, we are not.

Speaker B: So it's honestly good because a, uh, documentation issue is a lot easier to resolve within 10 days versus you have an actual IT issue where you need to figure out how to find an implementation solution could potentially take you a lot longer.

Speaker A: Right, Exactly. No, so it's just, you know, and all of them were all those cross issue of, uh, he had a detail between a procedure and a policy. That was not so again, you saw it, I can fix it. Even, you know. So I think even from then, you know, they told us they were impressed by all it, uh, you know, how solid our IT was, you know, the knowledge. So I think also is just like, hey, I would expect from them. Their goal is, you know, make sure the IT works. You know, so.

Speaker B: So if you're in, um, you know, let's call it the mock audit plus the audit. And hypothetically you could go over for, let's say two weeks, right? Uh, you know, five days and five days. Um, you know, maybe it doesn't go quite that far. Maybe it's only eight business days, right, Instead of, instead of five. But, um, during that time, like you basically all the people involved just have to stop their jobs because.

Speaker A: Oh, yes, you can't. You can't.

Speaker B: Yeah.

Speaker A: No, from perspective is we had a schedule, so we knew when we need our headshot person. Okay, when she will come. Her control will be on that day. She came on that day and went out. She didn't have to stay all the time.

Speaker B: Right? So the CTRPO gives you a schedule, a day by day schedule of like, okay, it's very. All right. It's very organized.

Speaker A: It's very organized. I will do Those control from 8 to 10, this one from 10 to 12. I will do this other control. So uh, which also even for us the night before, you know, you prep, you know, making sure. Because now you are live and it's for everyone. It's like you have your screen with your uh, policy and your procedure and your evidence and you have your ssd.

Speaker B: Yeah. So tell me what it's like maybe even on. On your side as the, you know, the organization seeking compliance. Uh, if you let's say during your block of time we're going to go through this family of controls. You what just have like hundreds of tabs open already just ready to go.

Speaker A: Yes, again. So I will have my. So I have my policy folder. So at least I know they are there. I have my procedure folders. I had the screen with uh, uh, intune. So ah. Intune ready. Uh, entra. You know, kind of already, you know. And at BMO we have a PIM of two hours. So every two hours, you know, you always. You were always worried that you demonstrate

Speaker B: you have to reallovate your privileges.

Speaker A: Yeah. So that uh, you have your evidence, you have your uh, ssp. You go so. So, you know, you go so. And at least it was. It was good for me. Again, it's why you do it from an IT perspective with you know, it was Kata and Chamizo and then me sometimes. So again between the three of us sometimes. Hey, Katase. I have it on my screen. Very good. He has it. He will share because we know already which control. So sometimes we try to be too controlling ahead so to try to make it, you know. And we from a BMO perspective didn't want, you know, the assessor to be waiting five minutes for each time to,

Speaker B: you know, just for a window to load.

Speaker A: You want to roll. You know, just. They are. Yeah. Even more for us. You're happy. One family done check.

Speaker B: Met.

Speaker A: You know, because as they go. Met. M. Met. Met. Met. You're like, okay, so even in your head you are like sure. So. And I think for us what was interesting is on day one, we had a perfect one perfect day. So at least I think it set the mood of like okay, good. Because you don't know what we expect. We had our. And I think when we lost some point was on the second day, you know, of our documentation. So what was good is I think well maybe also after they won, we are very confident. Oh I would you know, like ah, yeah. Easy plus you know, with something with not the easy control line. Then there's day two. Boom. You kind of like boom. Get slapped like one. You Know, two do accommodation error. And you're like, so now. Yeah, M. You know, let's make sure we don't take it too comfortable. There's a bit too comfortable here, you know, because, you know, again, this is their job. You know, for me, they were very professional. They did their job. But it's just, you know.

Speaker B: So are you making changes from, like, day to day? At night, like. No. You're not making any changes? No, no.

Speaker A: Yeah. For me, it's just at least I will talk for me. And I know from the team, the night. So in the afternoon. So we finished. So for me, 2pm Pacific. 2pm Pacific, because they were eastern. We were starting early in the morning, 6 or 7am and uh, then after that, you will prep, you know, the next day. Okay. I would talk about those controls. So again, you do a. On our side with your dry run with it. You know, just.

Speaker B: You did a dry run internally before that.

Speaker A: Internally. Because you have to think at one point. Again, what do we think the assessor will ask for evidence. For this one, it's a log. For this one is this. And this for this one. So. Oh, yeah. So, and it's always, for example, where do you show that? You, uh, have, for example, TLS 1.2. Okay, where do I show that?

Speaker B: Yes, this is inside this one here.

Speaker A: So from an it, we have two. Okay. Because it's not like it's from ourself and we can go find it. And it takes 10 mil, no problem. No, here is. So for every evidence, we have a path check. Every single path. So when we are arriving at that check, check, I can live and.

Speaker B: Right. You have to make sure that it's easy enough to go find. All the information to go find.

Speaker A: It's. Yeah, exactly. So it's, you know, everyone could find it. Everyone. But just when you're under pressure, you know you have, uh, three people looking at your screen.

Speaker B: Yeah. You know that you have maybe 90 seconds.

Speaker A: Uh, exactly.

Speaker B: You'll find everything. And you're like, okay, where do I click?

Speaker A: Yeah, exactly. Where do I click? And you. Okay, great. This is what I was looking for. Great. Okay, let me take a screenshot of that. Good, good.

Speaker B: Uh, when you think of 700 pieces of evidence, you gotta think that if you have to go log into portals and go click around to go find 700 pieces of evidence, there's a lot of clicking around.

Speaker A: And so far, again, very detailed. Oh, show me where you show your 15 minutes. Show me 15 minutes. 15 minutes. You know that when your screen, for example, one of the rules you get, your screen will uh, automatically lock if you don't use your computer for 15 minutes.

Speaker B: Yeah, go back, go to the screensaver.

Speaker A: So, okay, well you said, you know. And we said this at like forever. So. Okay, yeah, when you go, okay, you

Speaker B: go set this up years ago.

Speaker A: Yeah. So again, we have baseline policy that we have set that we deploy on our customers. So yeah, it's just, you know, stuff. So we open every single baseline one, you know, so it's just, uh, you know, where do you show that? Where do you show, you know. So no. So again, if I go back against, uh, people for sure underestimate the prep. Again, it's a. I can see prep.

Speaker B: But like, well, the IT work is a lot. But what you're saying is, but from

Speaker A: an IT perspective, for example, if people work with us, we do the it. But what people not realize from their side is at the end we go with them to their audit, no problem. But at the end we are only it. We are not the hr. We are not the one who represents their company. Again, we will answer many of the questions on the it, but all in on it. Their procedure is their procedure. We give you a template, you update. But at the end you have to know your procedure. You have to know the policy because it's your policy. So the question are answered by you, not bimo.

Speaker B: So even though I'm doing the work, you have to be able to represent

Speaker A: like exactly the work I do. You have to understand the work I do because at the end you're the one talking. It's like uh, someone, uh, you're the legal assistant that prep your lawyer. But at the end the lawyer needs to know what since.

Speaker B: Yeah, exactly.

Speaker A: Uh, maybe like you said, if you do a mock, it's a 40 hours, one week and then after that, one week to update and a week after you are back again for the 40 hours. So again, if I look at, you know, from your perspective, um, that you have blocked three weeks. This is before, this is from the mock two, but not even all the work before. So again, it's just maybe talk about,

Speaker B: um, like the 10 days that you had, but in between or even kind of the last minute prep, um, do you feel like this was something that you and the other team members were working like a normal, like nine to five to complete or like were you working on weekend, Were you working late

Speaker A: at night the after? So the between. No, it. It became more normal. You know, it was more. It was, it was crazy before the crazy before. But you Know, and. But after, again, because again, we didn't have much, we didn't have much update to do. So, you know, it's more. I think it's more. What about the before?

Speaker B: Like what, what do you mean by before? Like, what do you mean?

Speaker A: Crazy. Right. Before you have to create your ssp. So you create your ssp, you create your evidence, you create, you know, and the work of like I mentioned to make sure that everything cross correctly, you know, because, you know, before, when we do it for ourselves. Yeah, theism. It's not like, you know, it's now someone is going to look at your work and you know, in our case, a mistake on the password number on one of the document. Well, if it's a document they happen to read, you know, so again, so it's all this, you know, you want to polish as much.

Speaker B: How long do you feel like that took, um, the six of you guys to prep? Like, are we talking months? Are we talking days? Like, what's the.

Speaker A: So we really started. We did our first SSP in December.

Speaker B: Okay. December 2025. It is now May 12th.

Speaker A: May. Okay.

Speaker B: Yeah.

Speaker A: And you know, we exit, you know, and you know, so in what, like

Speaker B: you just added like pages. Like I started offping 100 pages.

Speaker A: Yeah, you had pages. You have, you know, you add pages and then you realize as you. Again as you go. I forgot to talk about those, to add, uh, those procedures and I forgot all these policies. And again, in our case, again in our case, which was interesting from a bmo, if it was just bmo because we don't deal with cui.

Speaker B: Yeah.

Speaker A: Okay.

Speaker B: We're just mssp. Like we're never going to deal with cui.

Speaker A: Yeah. So from our perspective, it would have been very simple how to put our boundaries. But because the way we had to do it is, the way we do it is we have to assume. So we work with customers with cui. And if by mistake they show give us a cui, how do we handle it?

Speaker B: Yeah.

Speaker A: Uh, so again, so in that case it changed the entire scope. So now it was not the scope for BMO as a company, it was the scope as bmo. How do we handle our customers and how do we make sure that when we'll go, when our customer will go to an audit of cmmc. That again, because of that Bibel is part of the scope that we make it as easy as possible to prove that BMO was ready and make it easier. So we make the scope a lot bigger, which took, you know, so it was very. Again, an interesting, you know, back and forth about, you know, at the end it was not for bmo. It was what's best for our customer.

Speaker B: When a defense contractor gets audited, right. They go through their own certification. Um, and let's say they, they use an msp, right? Um, does the MSP just show them their CMC certification?

Speaker A: So for us, we will show, we will give our CMC certification because again, we have the share's, uh, responsibility. Again. What do we do? What do we do for the uh.

Speaker B: Right. You have a racy.

Speaker A: We have a racy. This is what we do for you. And to prove to you how do we manage those control and we can show it. So as part of the assessment, we'll come back with this or be more proof we do all of that. Okay. And by the way, we are same MC as well. So we already were audited how we do this, right.

Speaker B: And so if the defense contractor happens to be using an MSSP, but that MSSP is not CMMC Level 2 certified. Is it just like a. No, that's not allowed. Or is it just.

Speaker A: Now the MSP is part of the full audit with them, with the customer. Sure. So now again it's uh. Well, you have an MSP and for whatever reason they are not able to prove correctly, then you will fail because then you will fail, right? Because.

Speaker B: Wow. Okay. Yeah. That's a lot of complexity, right?

Speaker A: It's a lot of complex and it's a lot of. It's a big risk. I think I can imagine a company that is not, uh, again, is not used to running. And if I think of BMO where we were eight years ago and where we are now, now we are compliance company first, security second. So again we run like I mentioned, I know our IT department assets. I think it's really how it's turning. I always said eight years ago, uh, BMO Admin was a global admin by default. Yeah, we can do whatever. Then came pim. Uh, everyone added, now I have to go request get and every two hours have to redo it. Now people don't even think. Now people feel like, of course we have that. You know, it's good we do that. Now I can tell you for the last few months, you know, that we said, hey, we open tickets. You start with a ticket. Oh, I'm an IT guy like before, I could just do my payment, go do my work, do whatever. Not anymore.

Speaker B: Everything has to be logged, right?

Speaker A: Anywhere to be logged. I have no dot where I can read. For me going through that CMMC is a best practice. And I will never run a business, uh, without running it the way CMMC does it. Yes, it's more work ways, but it makes total sense. I have a different perspective of, you know, I have learned a best practice and now BMO is following that best practice. And yes, it's more work, but at the end I know I make my customers and BMO a lot more secure.

Speaker B: Right? Like in the end it, it doesn't really have anything to do with government per se. Uh, it is, uh, uh, right. The NIST framework. Right. The NIST framework is just a great framework, uh, to run a technology organization or any organization. Right? For best practices.

Speaker A: But for me, what is interesting, I see it with our customers that we are working on today that come to us and say, hey, I was already a, uh, self, uh, assessment say savest and I'm good. And now you open the wood, you're like, but there's no way you could have passed that. No way. Hey. And you can see they are not ruining their poem the way they should. They don't have the ticketing. They don't.

Speaker B: So, yeah, it's, it's really interesting. I feel like the, the new thing, um, that has been kind of happening now is uh, people can't say, hey, Brandon, um, I have an SSP check, check done. I have my poem check done. And I'm in. What I'm doing now is saying, okay, well just because you have it doesn't necessarily. Someone could have, uh, could say they have an SSP and it's five pages, right? Like there's an ass. I check that's not a checkbox, right? And so now what we're seeing is we're taking that and um, we're comparing it to, um, comparing it to BMOs. We're comparing it to just uh, the. All the assessment objectives and running it through copilot and determining, okay, how far off base are you? And nobody is even close, right? Everybody's at 20, 30% and they say, I have an SSP. Yeah, I'm done. Yeah, I haven't updated. And they find stuff when you upload things via copilot, they'll say, uh, yeah, there's a piece in here that hasn't been updated since December 2022. And you're like, whoa, there's so much cross checking that you really have to go do.

Speaker A: So for me it was good, at least. Again, we learn. And again we had our own uh, uh, consultant that help us to draft a very good ssp because again, it's interesting from what's a good ssp, what look like, what doesn't. And everyone has an opinion. So again we go to one helpers and I can see our ssp. I can see how the SSO use the SSP and I can see how SSP was well done. This was well done, was clear. Every appendix work you could relate. You know, just there is nothing that the assessor said, I don't find it in your ssp. They told us your SSP is very good.

Speaker B: Right. So it's kind of crazy how there's actually a lot of like steps to this. Right? So like the final step is like the audit. But then what you really should be doing before that is the mock audit, right. Which is, you know, an official thing.

Speaker A: But you have to think. But you only do the mock audit when you think you are ready to uh, you are ready because don't waste. It's like you have one shot as a free test. Do it and make sure that you know they are going to go through everything and they will only find hopefully not too many. So at least you are prepped to go take the test.

Speaker B: But it seems like what you're saying is there's a step even before the mock audit which is, hey, you uh, hired a uh, lead CCA who is this like independent consultant, uh, to do

Speaker A: the mock of the mock.

Speaker B: Basically do the mock of the mock. So it's like all these like prep steps.

Speaker A: So it's. Why from all our customers. For all our customers. So the uh, assessor that we use, we are putting the same assessor as part of our fee within the offering. So again it's going to be bit more from an IT and this third party data assessor that again we like very much did a good job that will make sure again prep you into setting the boundaries again making sure that. How are you thinking of your cui? Is your boundary set correctly? Because this is the key of the whole thing. If you set your boundary correctly to start with, then your documentation and everything will connect to it. Uh, what took us a long time from a BMO again as I mentioned is because first we went off what is good for bimo. Oh, let's go. We were planning to use Prevail. Okay. We draft everything. Boom. And then we changed our mind. We went with a different. We rewrote everything and then, you know, so we changed three times. So we redid all our documentation and it says speed three times. Wow.

Speaker B: Because redid the boundary.

Speaker A: We redid the boundary three times and it Changed the whole thing. So this is, you know, so again it's. So again, we are in a special case because none of our customer will be an mssp. So yeah, this is unique to us because of.

Speaker B: But I do hear like on calls. I think the thing that I hear um, the most frequently is uh, people trying to game the system. Or I should say this, this doesn't come up with the people who are all governments in which case they just migrate to like a GCC Moderate or GCC High. And it's. It's just like done story completely fine. Where I find the people really trying to maybe game the system and think that the system can be gamed is the people who have a mix of commercial business and government business. And what they do is they say, well, what if I make my boundary the single laptop. Right. Um, I'm just going to uh, set up a new GCC moderate tenant and I'm going to set it on one laptop and it's going to be very simple. Right. And I say, but that's just like not realistic. Like auditor is just going to see through that.

Speaker A: Be like, what do you mean?

Speaker B: Like you don't just work on laptop.

Speaker A: Exactly, exactly. So again, they will be surprised that again their boundary is not good. Uh, you will go to your first. Okay, this is phase one when you start with your auditor.

Speaker B: Yeah, the scope.

Speaker A: Right? Yeah, the scope. So again, when the first meeting that you had was review the binary and they will. Your question a lot you discussed. But they will tell you I don't think it works. I think it works. So you don't get the end.

Speaker B: Yeah. And I think people aren't really prepped for that part. I sense that, uh, the scoping session I think tends to be the most crucial piece on the C3PO side where they want to make sure that it's scoped correctly. Otherwise they don't want to take the business and then waste their time down the road. Yes.

Speaker A: And my thing is. Well, and I think it goes back to the same thing we had with all other certifications we manage with customers, whatever is so Daiso. There is a difference between the one that just won the certificate. So here is. I want to spend the.

Speaker B: You're right. Compliant on paper. Do the bare minimum to get me through.

Speaker A: Exactly. Yeah. Versus the one that. No, I have cui. I want to manage it correctly. Let's copy it correctly. You know and best you know, therefore my business is what makes sense and is what the scope. And yes, and yes, we agree. This is what you Know.

Speaker B: Yeah, the, the, the other piece where I see like, the second piece is like, I think where people are going to be surprised as they get to the scoping session thinking like, oh, I got my little boundary. And it's, and it's. And you know, they're not going to, whatever, question it too much. And we're going to go through the audit with this tiny little scope. And instead what's actually going to happen is if the C3PO says, this is not real, this is not going to be realistic, come, uh, back to me in three months. Uh, when you.

Speaker A: No, it will say, it will say, no pass. So again, no pass. And then it will say, you can come back once. And so it's how it works. If you don't pass, you can come back once. Otherwise they charge you each time. Yeah, yeah. So, which is fair because at the end he's like, hey, plus, the part is they cannot tell you how, uh, to do it. They will just tell you the scope is not. Correct.

Speaker B: Yeah, yeah, exactly.

Speaker A: They don't tell you how to do it. They will tell you, no, this doesn't work. This doesn't work. But, uh, yeah, yeah.

Speaker B: So you could easily find yourself in a situation where you thought you were in a. You're saying, oh, I'm going through the audit and it's like phase one, and it's just like, uh, nope, you don't pass.

Speaker A: Nope.

Speaker B: Like what I have to do. And they say that's up for you to figure out. Right?

Speaker A: Yeah, exactly.

Speaker B: And suddenly you've delayed potentially something by six months or more. Right. Uh, it's very scary.

Speaker A: Okay, go on. Again, that is another episode of trust issue in this conversation. Help you think differently about compliance, security or trust. Share it to help someone who is still stuck in a checkbox mode. Each week we will keep bringing you more episodes, resources and real world insight from the BMO team. Wherever you are listening from, don't forget to rate the podcast and follow us to stay up to date on the latest development in the GRC space. Remember, compliance gets you certified, but real security, that earns trust. Thank you for listening.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • [REPLAY] Think Financial, Act CustomerProduct Rebels · on Entra88 / 100
  • What Every MSP Needs to Know About CMMC (feat. Matt Travis, CEO of Cyber AB)Climbing Mount CMMC · on CMMC Level 279 / 100
  • The Evolving World of Cybersecurity Compliance, with Nathanael DickIT Matters · on Defense contractors76 / 100
  • Cyber News: Iran Attacks, Greyware, and Backdoor CodeThe Audit · on Microsoft Intune76 / 100
  • Episode 122: Microsoft Ignite 2025 Wrap-upThe Azure Security Podcast · on Entra73 / 100
  • New CMMC FAQ Clarifications: Joint Ventures, Paper-Only CUI, Reassessment Triggers & Where MSPs Actually Fit in ScopeCMMC Compliance Guide · on CMMC Level 2 certification66 / 100

More from Trust Issues

All episodes →
  • How to Build a Cross-Functional CMMC Readiness Team74 / 100
  • Why CMMC became necessary in the first place.88 / 100
  • Has CMMC Changed Cybersecurity Culture Forever?65 / 100
  • The four phases of a CMMC assessment84 / 100
  • Treat AI agents like human employees80 / 100
Explore the best B2B Marketing podcasts →
All Trust Issues episodes →