The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Marketing/Trust Issues
Trust Issues artwork

How to Build a Cross-Functional CMMC Readiness Team

Trust Issues · 2026-07-28 · 17 min

0:00--:--

Key moments - from our scoring

Substance score

54 / 100

Five dimensions, 20 points each

Insight Density13 / 20
Originality10 / 20
Guest Caliber11 / 20
Specificity & Evidence14 / 20
Conversational Craft6 / 20

Building a successful CMMC Level 2 compliance program requires far more than IT involvement - it demands executive alignment and resource commitment across the entire organization. Using BMO, a 50-person CMMC Level 2 certified MSP, as a case study, this episode breaks down exactly who needs to be involved and why. The CEO must sign the System Security Plan and accept risk; the CFO must approve budget ($300K-$500K annually for small-to-mid-sized firms) and understand contract value at stake; and technical roles like IT Manager Kata (owning 64 of 110 NIST 800-171 controls), Security Operations Manager Julio, Compliance Manager Jeremiah, and Evidence Manager Benny must collaborate with Operations, HR, and a dedicated Program Manager Ron to maintain continuous compliance. The episode emphasizes that siloing CMMC into IT guarantees failure - organizations must recognize this as a top-priority company initiative requiring cross-functional ownership, structured governance, and sustained effort through annual internal assessments and triennial external C3PAO audits. The transcript includes concrete examples of control ownership distribution, hours allocation, and the business case for investment tied to DOD contract value.

Key takeaways

  • →CMMC Level 2 requires nearly 20% of staff involvement across nine functional areas in a 50-person company, not just IT, making it the top organizational priority for the fiscal year.
  • →CEO and CFO must be actively involved - the CEO signs the SSP and accepts risk, while the CFO must fund $300K-$500K annually and understand the business impact of losing DOD contracts (potentially $10M-$30M).
  • →Security and operations roles own 59% of controls and assessment objectives, but HR (personnel security), Operations (physical/supply chain), and Compliance (documentation) each own critical control areas that IT alone cannot address.
  • →Concentrating CMMC responsibility in one person creates severe business continuity risk; the organization should distribute responsibilities across multiple internal staff or engage an MSP/MSSP to ensure program resilience.
  • →Program management is essential to maintain the recurring calendar of monthly, quarterly, and annual compliance activities, internal assessments, and the triennial external certification cycle.

Topics in this episode

CMMC complianceCMMC Level 2CMMC Level 2 certificationSystem Security Plan (SSP)security operations center (SOC)Mobile Device Management (MDM)CMMC readinessCMMC leadershipCMMC team structureNIST 800-171 Rev2DOD contracts and DFAR 7012Microsoft 365 environmentIncident Response PlanNovember 2026 CMMC deadlineEvidence collection and automation

Questions this episode answers

What does a CMMC Level 2 readiness team structure look like for a 50-person company?

BMO's 50-person team allocates 9 staff members across security engineering (IT Manager, Security Ops), compliance documentation (Compliance Manager), evidence collection and automation, program management, operations (physical/supply chain controls), HR (personnel security/training), and CFO oversight - with security and operations roles consuming 59% of all controls and assessment objectives.

How much does CMMC Level 2 certification cost per year for small to mid-sized companies?

For companies with 20-200 employees, CMMC Level 2 readiness costs between $200K and $1M annually, typically $300K-$500K for a 50-person firm, including tooling, vendor costs, C3PAO assessment fees, and internal labor, though most costs stem from infrastructure investments rather than certification itself.

Why do IT-only CMMC programs fail?

IT organizations typically lack visibility into contract value and business risk; when they see $500K annual costs, they perceive it as prohibitively expensive without understanding that losing a $10M-$30M DOD contract makes the investment essential - requiring CEO and CFO buy-in to succeed.

Who owns what CMMC controls in a typical organization?

IT/Security owns 59-64% of controls (NIST 800-171 technical controls), Compliance owns documentation and process controls, Operations owns physical and supply chain controls, HR owns personnel security and training controls, and the CEO/CFO provide governance and risk acceptance.

What is the role of a program manager in CMMC Level 2 readiness?

The program manager (like Ron in this example) coordinates across all nine team members, maintains the compliance calendar for monthly/quarterly/annual activities, tracks the triennial external certification cycle, manages tool renewals, and ensures continuous compliance through structured governance.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

13 / 20

The episode delivers concrete, actionable insights about cross-functional CMMC team composition with specific role allocation and cost ranges ($200K - $1M annually for 20 - 200 employee companies), but relies heavily on a single company's organizational structure as the primary framework. The repetitive emphasis on executive buy-in and the perils of IT siloing, while important, consumes significant runtime without introducing novel operational insights beyond the core thesis.

if your company is making 10, 20, 30 million from these government DOD contracts and you don't spend a 300, 500K, you could find yourself in a position where you are laying off people
for a lot of companies, in the, let's call it 20 to 200 employee space, something like CMC level two, um, is going to cost you somewhere between like 200,000 a year to like a million dollars a year

Originality

10 / 20

The core argument - that CMMC compliance requires cross-functional leadership, not just IT - is sound but well-established in compliance practitioner circles. The originality lies primarily in the detailed team-mapping exercise (CEO, CFO, IT manager, compliance manager, etc.), but this is presented as a single case study walkthrough rather than a contrarian or first-principles perspective. The podcast does not challenge dominant CMMC narratives or offer counterintuitive positioning.

the CEO doesn't want to get involved. This is an IT project. And I will tell you that if leadership does not get involved, you will absolutely never become CMMC M Level 2 compliant
it requires bm, it requires CFO sign off, um, a lot of stuff

Guest Caliber

11 / 20

Speaker A is a practitioner operating a 50-person CMMC Level 2 certified MSP/MSP/RPO and has direct experience auditing and advising other organizations on compliance. This is relevant domain expertise. However, the transcript provides no introduction of credentials, tenure in the space, or notable client work, limiting ability to independently verify caliber. The guest is not a household name in security or a widely-recognized thought leader.

we're a 50 something CMMC level two certified MSP. So we help organizations seeking compliance actually achieve CMMC Level two themselves
I've seen this with my current clients, um, where if the one person leaves, you're really screwed

Specificity & Evidence

14 / 20

The episode provides concrete numbers (9 people out of 50 at BMO; 64 of 110 controls owned by IT manager; $200K - $1M cost range; November 2026 deadline; 320 assessment objectives; 700+ pages of evidence) and named individuals with specific responsibilities (Kata, Jeremiah, Benny, Ron, Cindy, Sylvia, Julio). However, most evidence is drawn from a single company's structure; there are no comparative data points, client case studies with metrics, or external benchmarks beyond the speaker's own organization.

he owns 64 of the 110 controls, the NIST 800171 Rev2 and that basically maps to 190 of the 320 assessment objectives
we have 1, 234-56789 people of our 50. So let's call it like almost 20% of the company

Conversational Craft

6 / 20

This appears to be a monologue or prepared presentation with minimal genuine dialogue. Speaker B provides only a brief welcome and closing; there are no meaningful follow-up questions, no pushback on claims, no exploration of nuance or counterarguments, and no dynamic conversation. The episode reads as a lecture delivered to camera rather than an interview or discussion that tests the guest's claims or probes deeper.

Speaker B: Welcome to Trust Issue by Demo, the podcast where we go beyond checkbox compliance and get real about security
Speaker B: That is another episode of trust issue

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker A95%
  • Speaker B5%

Most-used words

security20cmmc18level16objectives11assessment10everybody9compliance9involved9contracts8controls8program8cost7help7manager7important6team6

Episode notes

CMMC Level 2 just does not work when it gets dumped on one IT person. In this solo episode of Trust Issues, Brandon Lecoq explains why CMMC readiness has to become a company-wide initiative, not an IT side quest. He walks through the roles involved in BEMO’s own CMMC Level 2 program and shows why security, compliance, HR, operations, finance, and leadership all have real ownership. The episode is a practical reality check for contractors who still think CMMC can be handled quietly in IT. It cannot; if leadership is not involved, if the CFO does not understand the ROI and if HR and operations are not ready to provide evidence, the program is already in trouble.

Full transcript

17 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: It's very important that everybody's on the same page and understands that you will fail if this stays within the IT organization by itself. The IT organization usually has no idea how much your contracts are worth. And so when they see something the uh, all in cost is going to be 3 to $500,000 a year, they usually say wow, that's the cost of a new house. Wow, that's super expensive. And yes it is expensive and it would be a lot of money for any of us individually. But if your company is making 10, 20, $30 million from these government DOD contracts and you don't spend a 300, 500K, you could find yourself in a position where you are laying off people.

Speaker B: Welcome to Trust Issue by Demo, the podcast where we go beyond checkbox compliance and get real about security. In every episode we break down what's happening in the world of CMMC Cybersecurity and grc straight from the people building, auditing and living it. Real conversation about real.

Speaker A: This episode of Trust issues we're going to be talking about who is part of the CMMC level 2 team uh within BMO and kind of what that means for organizations seeking compliance that just kind of use as kind of a benchmark of kind of what it takes, what type of people and how many people it takes to really get Everybody involved within BMO. Um, right, we're a 50 something CMMC level two certified MSP. So we help organizations seeking compliance actually achieve CMMC Level two themselves. And we ourselves held our own certification in um, addition to you know, ISO 27001, SOC2, HIPAA et cetera, et cetera, et cetera. Right. So we um, primarily helping people within the Microsoft ecosystem um, achieve these very challenging uh, security frameworks. And so just within BMO, uh, to think about within uh, a 50 person company, um, what does it look like on our own team, um, we have 1, 234-56789 people of our 50. So let's call it like almost 20% of the company um, that is uh, involved in CMMC level 2. That doesn't mean everybody's a control owner or has to meet certain assessment objectives within CMMC Level 2. But there's a lot of enablers and people that uh, maybe you wouldn't expect. So when you think about what it's going to take to get your company to CMMC level 2, it's going to require a lot more than the IT person. Even though uh, the quote unquote IT or security person um, does own. Let's call it 50. You know, I think it's like 60ish percent of the controls. Um, there's a lot of things to think about here. So for the very first part is the CEO. So um, the CEO, they're generally the person who signs the ssp, uh, the security, uh, M security plan, um, and accepts the risks, right? So everything flows up to them and they're basically signing off on, you know, like we're doing everything legit, um, and all that stuff. So the very first thing that I see when uh, I'm talking to a lot of prospects, um, or a lot of, you know, organizations that are, are trying to do this is they're like, oh no, you know, the owners, the owners of the, of the company don't care. Uh, the CEO doesn't want to get involved. This is an IT project. And I will tell you that if leadership does not get involved, you will absolutely never become CMMC M Level 2 compliant. It is the number one leading factor for why organizations literally are never become ready and will not pass CMMC is because uh, they silo everything into it. Because yes, it's an IT thing, uh, or you know, large portions of IT are, uh, but it requires bm, it requires CFO sign off, um, a lot of stuff. So we'll kind of walk through that. Number two cfo, uh, CFO is incredibly important to this conversation. Again, they don't own any controls or objectives. But I will tell you that uh, for a lot of companies, um, in the, let's call it 20 to 200 employee space, something like CMC level two, um, is going to cost you somewhere between like $200,000 a year to like a million dollars a year. Right? And that's not because cmmc, like the CMMC certification itself is only cost like you know, like 50 grand. However, like most, most uh, organizations um, that are doing this have not invested or completely underinvested in their IT and security infrastructure over the last 10 plus years. Right? Uh, basically since DFAR 7012 came out, uh, they basically haven't been doing anything security related. What that means is the CFO is really gonna have to be involved because this is gonna cost you a pretty penny, right? Like let's call it like $500,000 a year, uh, three to $500,000 a year for a company of 50 people, right? And that means the CFO is going to have to get involved. And one of the things that's really important with the CEO is that you identify what is the current contract value from your defense contracts and uh, for any new contracts that you're going to want to bid on past November 2026 or what are those requirements? Right? Like are you going to be able to self attest to level one, level two, are you going to require external certification? Um, what about your current contracts? Are you going to have to do anything for those? Uh, when do they expire? Right. Like there's a lot, a lot of this comes into just like company growth planning and trying to understand the risks of like what happens if we don't do this? Do we lose 10, 20, 30 million dollars with a business? Does uh, it simply mean that we can't grow next year because all the new contracts we want to bid on require an external certification that's really up for you to research. Obviously November 2026 is a big date, but it's not necessarily a big date for everybody and you don't necessarily have to be externally certified by November and a lot of things are going to change over the next three years. Um, but that's good for you to do your own research um, because I can't really pinpoint that number for you. Um, but let me tell you, if something is let's say worth $10 million, then you can bet that 5k, 300k is probably going to be worth it. But again the CFO is going to have to be involved to approve potentially new hires internally, maybe three, four or five new tools or vendors that you're going to need to pay for the C3PAO and all that type of stuff. Now let's go to the team. Um, so the first one that we have, um, I'll just, I'll just talk about is Kata. Uh, Kata is essentially our IT manager and he's in charge of like the day to day security, the day to day implementations of the Microsoft uh, a 365 environment, all of our tools, et cetera. Right. He owns 64 of the 110 controls, the NIST 800171 Rev2 and that basically maps to 190 of the 320 assessment objectives. Right. He's basically the main guy um, that like on a day to day basis. Right. Security engineering he kind of owns. Right. So I think that's why um, a lot of um, um, you know CMMC level two kind of just gets stamp of this is an IT project and then it gets shoved in the closet basically. But he's got a lot of support. Right. Um, and one thing to, to also note about the IT person is there's a huge risk in having everything in one person. Um, you know, especially if you're at a smaller company of maybe 20 to 100 people, you oftentimes will only have zero. One, maybe two people, um, oftentimes one. And what ends up happening is if that person. I've seen this with my current clients, um, where if the one person leaves, you're really screwed. Because oftentimes there might be uh, someone who, like Jeremiah, the compliance manager, who might be like, I'm in charge of the SSP and the policies and the procedures, but I don't know anything about it. Right. And that one person leaves and they basically fumble in terms of like the, they, they don't know how to do anything with the Microsoft environment. Um, they don't know how to, how to maintain any of the IT or security. Right. So that can definitely be scary. Um, I think it's one reason why you should either divvy up the responsibilities into multiple internal people or you start using an uh, MSP or, you know, MSSP or an RPO to kind of have um, shared responsibilities and to have a little bit more business continuity when it comes to the CMMC program. Program now. So Kata just does like all the security, right? All the security. So think about it. Um, primarily like the Microsoft 365, your password vaults, your sock, your SAM, um, kind of all the core stuff, your MDM, your mobile application management, all that stuff. Uh, the Jeremiah. Jeremiah is the compliance manager. He is running, um, and is mostly responsible for all of the documentation, more or less. Um, so ensuring that uh, we have our policies and procedures and they're up to date and we're following the process, following all the things that BMO is saying we're doing on a monthly, quarterly, annual period basis. Right? So he owns 7 controls and 23 assessment objectives. Then we've got Benny, right? So think of this. Ben Binnie is basically the person who is going to maintain and collect all the evidence, do all the automations to get all the evidence on a periodic basis. Right? So sometimes this can be compiled with, set with other people. Right here I have nine people. Uh, but you could have easily put this under one person. The challenge of putting this on one person is they're not going to have time to do all this stuff. Right? Um, we're 50 people. It still takes us like nine different people involved, uh, to kind of maintain this. And we're in mssp, MSP and rpo. That is this for other companies, right? And these people are just doing it for our own they're not doing it for the other companies necessarily. Right. Uh, uh, so it really does take a huge village to go do this. Then you have Ron. Ron is the, essentially the program manager, project manager, uh, for the program itself. So with nine people, as you can imagine, there's, uh, a lot of people that you have to go corral. There's a lot of deadlines, there's, you know, renewals of tools. There's. Within your ssp, when, when you say that you do things periodically or on a monthly, annual, quarterly, whatever basis, like, that means that that's got to be on the calendar and the, and the program manager is going to stay on top of that. Right. And ensure that, uh, you're continuously compliant with the program. Right. Uh, there's, you know, internal assessment, renewals every year, rates, uh, then you have your, your external certification every three years. Right. So there's always going to be, uh, milestones, um, and reoccurring activities that have to get done. And program manager is essentially making sure that that happens. Right. So that's very much a compliance rule, as you can see. We also have Cindy, who's our senior director of operations. Um, she owns the physical, uh, media and supply chain controls and the assessment objectives. Right. But you could definitely see how maybe the operations people kind of get clumped together as well. But it is very important that there is people outside of it and that you have essentially an ops function that is overseeing, um, this entire program. Uh, then we have Sylvia. Sylvia is our senior director of operation, uh, people. So essentially head of hr. Um, and so she has the personal security and, uh, training roles and, uh, objectives. So, uh, as you can see, CMMC M Level 2, it has nothing, you know, there's many controls and assessment objectives that it is not responsible for. Um, you know, they can kind of help and coordinate. But, uh, when it comes time to the audit, um, and to have the audits with your C3PAO, uh, it's going to be Sylvia or whoever your HR person is who's going to be speaking to those and providing the evidence for those and, you know, walking through the auditors for that type of stuff. Right. So when you, when you show up to the audit or to the, to the mock audit, to the external audit, to the internal audit, you're going to have all of these people, um, show up and essentially they're going to take turns. So when the C3PAO goes down, one by one of all 320 assessment objectives, basically, um, each control owner is going to have different Responsibilities and then we also have the people who are like the support and enabler people who are also there to um, help support um, show um, do screen shares of that evidence because as you can imagine, 700 plus pages of evidence, uh, there's a lot of stuff to show and you have to have a lot of tabs up to quickly walk through, improve every single one of those assessment objectives. Right. So it's definitely a lot of work. And then we've got Julio. Um, Julio is security operations. He is uh, Katza's counterparts, uh, uh, so he's doing a lot of like the SOCs in um, the monitoring, the detecting, responding. So essentially incidents response plan. He is in charge of 19 controls and uh, 63 assessment objectives. So there's 1, 2, 3, 4, 5, 5 people who are actually owners and like directly involved. And while maybe their job isn't one, uh, hundred percent, let's call it, they're not each working 173 hours a uh, month doing this. Obviously Kata is and Julio is probably half his time but, but then um, you know you're going to have maybe 10 hours a month from Ron and uh, another 20 hours a month from Jeremiah. And it's a mix. Right. Um, so as you can see it is much more than one headcount, especially for a team of a company of 50 people. And so um, when you kind of like zoom out by function, um, you have security and security operations are 59% of all of the controls and assessment objectives. Right. This is why there's a huge emphasis on it and security. However we have two full time people working on just the security related control synast 800, 171 and we still have people who are in operations, we still have compliance people and we still have HR who help out on a monthly basis. All right, so I hope that was uh, I hope that was helpful. I think this is uh, you know, a good kind of like table to just show um, other people internally and build that coalition uh, to your own leadership team to get Everybody behind the CMMC Level 2 initiative and make sure that everybody's on the same page around it being probably your company's number one, uh, initiative, uh, for the year. If your company is going after CMMC level 2 and if it's an external certification and it's not like a CMMC level one self attest or CMMC level two self attest, this is really good to get everybody on the same page to make sure that they're bought in for the initiative because if it does become an initiative for your company, it will eat up. It will be the number one initiative for the calendar year for your fiscal year. And it will eat up the most resources in terms of time, in terms of people, in terms of capital, most likely. And so it's very important that everybody's on the same page and understands that you will fail if this stays within the IT organization by itself. Right. The IT organization usually has no idea how much your contracts are worth. And so when they see something is, you know, the all in cost is going to be 3 to $500,000 a year, they usually say, wow, that's the cost of a new house. Wow, that's super expensive. And yes it is expensive and it would be a lot of money for any of us individually. But if your company is making, you know, 10, 20, $30 million from these government DOD contracts, um, and you don't spend 300, 500K, you could find yourself in a position where uh, you are laying off people, right? And that's not fun. Um, and nobody wants to do that. We all want to grow, we all want business to be good. Um, and so it's very important that strong leadership and getting buy in from everybody, um, will help you be successful. Um, so thank you very much and I'll see you guys later.

Speaker B: That is another episode of trust issue. If this conversation help you think differently about compliance, security or trust, share it to help someone who is still stuck in a checkbox mode. Each week we will keep bringing you more episodes, resources and real world insight from the BMO team. Wherever you are listening from, don't forget to rate the podcast and follow us to stay up to date on the latest development in the GRC space. Remember, compliance gets you certified, but real security that earn, um, trust. Thank you for listening.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Episode 121: New Open Group Security Standards DocumentationThe Azure Security Podcast · on security operations center (SOC)86 / 100
  • AI Agents vs. AI Agents: The Future of Security Operations | Interview with Monzy MerzaSecure & Simple · on security operations center (SOC)85 / 100
  • Decoding the Cybercriminal Mindset, with Ryan ChapmanThe Cyber Insider · on Mobile Device Management (MDM)85 / 100
  • Can You Create CUI? CMMC Scope, ERP Systems, and Contractor Risk ExplainedCMMC Compliance Guide · on CMMC compliance80 / 100
  • What Every MSP Needs to Know About CMMC (feat. Matt Travis, CEO of Cyber AB)Climbing Mount CMMC · on CMMC Level 279 / 100
  • AI for Security vs Security for AI: From IBM Master Inventor to Microsoft AI ArchitectShipTalk · on security operations center (SOC)78 / 100

More from Trust Issues

All episodes →
  • Why CMMC became necessary in the first place.88 / 100
  • Has CMMC Changed Cybersecurity Culture Forever?65 / 100
  • The four phases of a CMMC assessment84 / 100
  • Treat AI agents like human employees80 / 100
  • The Evolution and Enforcement of CMMC with Jacob Anderson76 / 100
Explore the best B2B Marketing podcasts →
All Trust Issues episodes →