Wilson Bautista Jr.
CMMC News by Jun Cyber
This podcast is dedicated for those who want to stay up to date with the Cybersecurity Maturity Model Certification news. It utilizes Notebook LM to synthesize news articles from Jun Cyber's blog as well as other official CMMC documentation and produces a podcast. Podcast Description Disclaimer: The content presented in CMMC News is generated by AI and is intended for informational and educational purposes only. It should not be taken as official guidance for Cybersecurity Maturity Model Certification (CMMC) compliance. For accurate and tailored advice, we recommend consulting a qualified CMM...
Author
Wilson Bautista Jr.
Category
Podcast website
Latest episode
Jun 25, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Manufacturers & CMMC: What to Know 12.07.2025 10:13
Send us Fan Mail 🚨 N𝗲𝘄 𝗣𝗼𝗱𝗰𝗮𝘀𝘁 𝗘𝗽𝗶𝘀𝗼𝗱𝗲 𝗔𝗹𝗲𝗿𝘁! 🚨 We’re breaking down 𝗖𝗠𝗠𝗖 𝗖𝗲𝗿𝘁𝗶𝗳𝗶𝗰𝗮𝘁𝗶𝗼𝗻 𝗥𝗲𝗮𝗱𝗶𝗻𝗲𝘀𝘀 for manufacturers navigating defense contracts 🛡️🏭 If you’re part of the DoD supply chain, this episode is your essential guide to prepping for CMMC success. 🎙️ What’s Inside: ✅ What manufacturers need to know about CMMC 2.0 ✅ Common pitfalls and how to avoid them ✅ Steps to get audit-ready wit...
CMMC 2.0 Unpacked: What Defense Contractors Must Know 12.07.2025 11:39
Send us Fan Mail 🚨 CMMC 2.0 Is Rolling Out: Is Your Business Ready? The latest version of the Cybersecurity Maturity Model Certification (CMMC) is reshaping how contractors handle security across the Defense Industrial Base. From new assessment levels to increased scrutiny, the changes are significant—and noncompliance could cost you contracts. Understand what’s changed 🧩 Learn how implementati...
Standardizing Security: A Deep Dive into DoD CUI Rules 11.06.2025 23:27
Send us Fan Mail In this episode of CMMC News, we break down DoD Instruction 5200.48—the Department of Defense’s rulebook for handling Controlled Unclassified Information (CUI). Hosts take you through what CUI really means, why the DoD created a standardized approach, and what it takes to handle, mark, and share sensitive information properly. Learn why it’s critical for both DoD staff and contrac...
CMMC 2.0: What Is a C3PAO and What Does It Cost? 09.06.2025 15:21
Send us Fan Mail If you're a Department of Defense (DoD) contractor, navigating the world of CMMC 2.0 is essential—and it starts with understanding the role of a C3PAO. In this episode, we break down what a Certified Third-Party Assessor Organization (C3PAO) is, why it matters, and what to expect during a third-party CMMC assessment. You’ll learn: What a C3PAO does and how they’re approved...
Navigating New DOD ODP Mandates in NIST SP 800-171 Revision 3 05.05.2025 25:36
Send us Fan Mail 🚨 Working with the Department of Defense or handling Controlled Unclassified Information (CUI)? Here’s what you need to know about the DOD’s new approach to NIST SP 800-171 Revision 3 ODP values. Just listened to the latest episode of CMMC News, where the hosts did a deep dive into the recent DOD memo standardizing “Organization Defined Parameters” (ODPs) for protecting CUI. If y...
The Essentials of Cyber Incident Reporting for Defense Contractors 26.03.2025 22:50
Send us Fan Mail Hello LinkedIn community! 🌐 As we delve deeper into the cybersecurity requirements for Department of Defense (DOD) contracts, understanding DFARS Clause 252.204-7012 is crucial. It outlines safeguarding covered defense information (CDI) and protocols for cyber incident reporting. Here are three key takeaways for businesses and contractors engaging with the DOD: Understanding CDI...
SPRS and You: Managing DOD Cybersecurity Expectations 26.03.2025 11:37
Send us Fan Mail We just dived deep into the Department of Defense's NIST SP 800-171 assessment requirements. This is crucial for any contractor involved with DoD contracts, especially when it comes to cybersecurity. Here are three key takeaways: Assessment Frequency: If you're implementing NIST SP 800-171, make sure you have a recent assessment conducted within the last three years for...
Navigating DFARS Clause and Cybersecurity Assessments for DOD Contracts 26.03.2025 16:14
Send us Fan Mail 🔍 Want to stay ahead in the world of government contracts and cybersecurity? Dive into our latest CMMC News episode where we explore the NIST SP 800-171 DoD Assessment Requirements. It's all about breaking through the wall of acronyms and jargon to ensure you know exactly what the Department of Defense expects when it comes to protecting sensitive information. Here are 3 key...
Breaking Down CMMC ESPs and Inherited Controls: What DOD Contractors Need to Know 17.03.2025 16:31
Send us Fan Mail 🚀 New Episode Alert: Navigating CMMC Compliance with ESPs and Inherited Controls 🚀 In our latest episode of CMMC News, we dive deep into the complexities of CMMC compliance and how to effectively manage the relationship with your External Service Providers (ESPs). This episode is packed with insights that are crucial for any DOD contractor aiming to unravel the intricacies of in...
Secure Your Defense Contracts: Navigating CMMC Levels with NIST Publications 17.03.2025 13:33
Send us Fan Mail 🚀 Exciting Insights from Our Latest Deep Dive on the CMMC News Podcast! 🎧 In our newest episode, we unpack the intricacies of the Cybersecurity Maturity Model Certification (CMMC) and its alignment with NIST standards, essential for those engaged with Department of Defense contracts. Dive into the details with us as we explore practical implications and strategic alignments. 🔹...
Understanding How ESPs Fit into Your CMMC Assessment Puzzle 17.03.2025 30:27
Send us Fan Mail 🌟 Just listened to another insightful episode of the CMMC News podcast, where the hosts take a deep dive into the complexities of CMMC, focusing on ESPs, SPAs, and VDIs. Here's what stood out to me: 🔍 Key Takeaways: Scoping ESPs in CMMC: The involvement of External Service Providers in the CMMC assessment depends largely on their interaction with Controlled Unclassified Inf...
Choosing a CMMC Consultant: Certification, Experience, and Fit 31.01.2025 10:49
Send us Fan Mail In this episode of CMMC News, host Wilson Bautista Jr. breaks down the crucial factors to consider when choosing a CMMC consultant. He outlines five essential criteria: ensuring proper CMMC certification, verifying real audit experience, evaluating communication skills, determining consultation needs (assessment vs. implementation), and assessing cultural fit with your organizatio...
Navigating CMMC Compliance: Selecting the Best C3PAO 21.01.2025 6:19
Send us Fan Mail Welcome to another episode of CMMC News! Today, we're simplifying the complexities of cybersecurity compliance, specifically diving into how to choose the right Certified Third Party Assessment Organization (C3PAO) to guide your organization to CMMC compliance. I'm your host, Wilson Bautista Jr., and in this episode, we'll break down the key considerations to make t...
Audit of the DoD’s Process for Authorizing Third Party Organizations to Perform Cybersecurity Maturity Model Certification 2.0 Assessments (Report No. DODIG-2025-056) 14.01.2025 21:49
Send us Fan Mail A Department of Defense Inspector General audit (DODIG-2025-056) revealed that the Department of Defense (DoD) inadequately implemented its process for authorizing third-party organizations to conduct Cybersecurity Maturity Model Certification (CMMC) 2.0 assessments. The audit found that the DoD failed to ensure all required steps were completed before authorizing these organizati...
Congressional Review Act Targets CMMC Rollback 07.01.2025 14:02
Send us Fan Mail Representative Gary Palmer introduced a resolution to overturn a Pentagon rule establishing the Cybersecurity Maturity Model Certification (CMMC) program. This Congressional Review Act resolution aims to allow Congress a vote on significant regulatory actions. The Department of Defense completed the necessary steps to implement the CMMC rule, which adds third-party assessments to...
FEDRAMP Moderate Equivalency for Cloud Service Providers 07.01.2025 16:45
Send us Fan Mail This memorandum from the Department of Defense outlines requirements for cloud service providers (CSPs) seeking FEDRAMP Moderate equivalency . It details the necessary assessments and documentation , including security plans and testing procedures, that CSPs must meet. The memorandum emphasizes the importance of compliance with specified Defense Federal Acquisition Regulations Sup...
Overview of the CMMC: A Framework for Cybersecurity Excellence 31.12.2024 40:47
Send us Fan Mail In this episode of CMMC News , we provide an in-depth overview of the Cybersecurity Maturity Model Certification (CMMC), the Department of Defense’s framework for enhancing the cybersecurity posture of contractors and subcontractors. We explore the three maturity levels and their requirements, which are derived from FAR 52.204-21, NIST SP 800-171 Rev 2, and NIST SP 800-172. Listen...
Level 1 CMMC Assessment Guide: A Step-by-Step Overview 31.12.2024 23:05
Send us Fan Mail In this episode of CMMC News , we unpack the Level 1 Cybersecurity Maturity Model Certification (CMMC) Assessment Guide, designed to help organizations self-assess their compliance with 15 basic cybersecurity requirements for protecting Federal Contract Information (FCI). We cover key aspects of the guide, including how to define the scope, clarify custom terms, apply assessment c...
CMMC Level 2 Assessment Guide: Comprehensive Compliance Insights 31.12.2024 29:21
Send us Fan Mail In this episode of CMMC News , we explore the Cybersecurity Maturity Model Certification (CMMC) Assessment Guide for Level 2, Version 2.13. This comprehensive guide provides instructions for conducting both self-assessments and certification assessments, detailing security requirements across key domains like access control, awareness and training, audit and accountability, and co...
Defining the Scope: A Guide to Level 3 CMMC Assessments 31.12.2024 27:59
Send us Fan Mail In this episode of CMMC News , we dive into the guidance for defining the scope of a Level 3 Cybersecurity Maturity Model Certification (CMMC) assessment. We discuss the asset categories—CUI Assets, Security Protection Assets, Specialized Assets, and Out-of-Scope Assets—and their specific requirements. Learn how to categorize and document assets in an inventory and network diagram...
Final CMMC Program Rule Unveiled by DOD 31.12.2024 16:47
Send us Fan Mail Certainly! Here’s a polished description for your podcast episode: 🎙️ Episode Title: Demystifying the CMMC Final Rule: What It Means for Defense Contractors In this episode of CMMC News, we delve into the recently unveiled CMMC Final Rule by the Department of Defense. Join our AI hosts as they unpack the critical updates, explain what’s new in the compliance landscape, and provide...
CMMC Tax Credit for Small Defense Contractors 31.12.2024 18:44
Send us Fan Mail In this episode of CMMC News , we explore the proposed CMMC Tax Credit and its potential to provide financial relief for small defense contractors navigating the complexities of Cybersecurity Maturity Model Certification (CMMC) compliance. Discover how this tax credit could offset costs like technology upgrades, staff training, and third-party assessments, helping small businesses...
Defining the Scope: A Guide to Level 2 CMMC Assessment 31.12.2024 20:38
Send us Fan Mail In this episode of CMMC News , we break down the essential guidance on defining the scope of a Level 2 Cybersecurity Maturity Model Certification (CMMC) assessment. We explore the key asset categories—CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, and Specialized Assets—and provide insights into categorizing and documenting them effectively. Learn about th...
Level 1 CMMC Scoping Guidance: A Practical Guide to Compliance 31.12.2024 27:02
Send us Fan Mail In this episode of CMMC News , we explore the key guidance for conducting a Level 1 Cybersecurity Maturity Model Certification (CMMC) self-assessment. We discuss how to define the scope, including which assets—such as those processing, storing, or transmitting Federal Contract Information (FCI)—are included, and which, like IoT devices and Government Furnished Equipment, are exclu...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.