All Episodes

April 4, 2025 13 mins

Submit any questions you would like answered on the podcast!

If someone tells you CMMC compliance can't be easy… they’re not necessarily wrong — but they’re also missing the point.

In this episode of the CMMC Compliance Guide Podcast, Austin and Brooke from Justice IT Consulting break down one of the biggest myths in the compliance space: that achieving CMMC compliance has to be overwhelming, time-consuming, and painfully complex.

Using our E.A.S.Y. framework, we’re showing you how strategic companies are simplifying their compliance efforts and turning cybersecurity into a competitive edge:

✅ E – Expert Guided: Why going it alone can cost you more in time and money.
✅ A – Aligned to Requirements: How to avoid the tech-first trap and focus on business process.
✅ S – Streamlined Approach: Proven tools, trusted frameworks, and no need to reinvent the wheel.
✅ Y – Your Competitive Advantage: Compliance isn’t just a checkbox — it’s a business differentiator.

Whether you're a defense contractor starting your compliance journey or trying to stay ahead of evolving requirements, this episode gives you the mindset and framework to make CMMC easier — not effortless, but easier.

📞 Need help fast-tracking your compliance?
Reach out at: cmmccomplianceguide.com/podcast — we’ll answer your questions for free right here on the show.


Mark as Played
Transcript

Episode Transcript

Available transcripts are automatically generated. Complete accuracy is not guaranteed.
Austin (00:00):
Hey there, welcome to the CMMC Compliance Guide
Podcast.
I'm Austin.
And I'm Brooke.
From Justice IT Consulting.
We're here to help businesseslike yours navigate CMMC and
NIST 800-171 compliance.
We're hired guns gettingcompanies fast-tracked to
compliance, but today we're hereto give you all the secrets for
free, so if you want to tackleit yourself, you are equipped to

(00:20):
do so.
Let's dive into today's episodeand keep your business on
track.
Today, we're tackling one ofthe biggest misconceptions we
hear tattered about CMMCcompliance.
isn't that right brookeabsolutely right that
misconception is that it has tobe difficult overwhelming and
borderline impossible tosimplify cmmc compliance we here
at cmmc compliance guidecompletely reject that idea this

(00:43):
entire channel exists to makecompliance more approachable
more strategic and yes easierthe truth is compliance doesn't
have to be scary Most of theroadblocks people run into are
caused by lack of clearguidance, not because CMMC is
impossible.
Right, Brooke?
That's right.
And that is what we try to dohere.
Today's episode is all aboutshowing you that easy doesn't

(01:04):
mean effortless.
It means being strategic.
We're going to show you exactlywhat that looks like.
Okay, what I'd like to do isbreak down what easy really
means when we talk aboutcompliance and why we believe
that CMMC compliance can be easyif you do it right.
We're using the acronym EASY.
Easy, E-A-S-Y, as a framework.

(01:26):
Let's get into it.
First up in our easy acronym isexpert guided.
One of the biggest mistakes wesee companies make is trying to
go at it alone.
Sure, you can DIY compliance,but it'll take you two or three
times longer And usually costsmore.

Brooke (01:40):
Isn't that right, Brooke?
That's absolutely right.
So, you know, we've talkedabout it on other episodes as
well.
You know, DIY approach is fine,but you need to have your own
experts in-house.
And I mean actual experts, not,you know, Johnny who you don't
like and so you assigned CMMCcompliance to him.
E for expert guided.
You want a CMMC expert.
And so, you know, a lot oftimes instead of DIY, you can

(02:05):
hire somebody expert to comehelp you.
You know, it's about bringingin a coach who can who can guide
you through it and basicallycall the plays right uh they can
uh they don't necessarilythey're not going to be coming
in and and uh running the playsuh scoring the touchdown and all
that kind of fun stuff for younecessarily but but uh they will
call the plays they can theycan call the plays they can help

(02:26):
you strategy and how to how tocomplete all

Austin (02:28):
this so even if someone diys i mean you don't have to
fully outsource your complianceto somebody but it's it's good
to just bring in an exportregardless whether you're going
to do it yourself in-house orjust like you would a lawyer
you're not going to you caneither hire your own lawyer
right or you can have aconsultant they don't have to do

(02:50):
the entire thing for you

Brooke (02:52):
right that's exactly right it's not all or nothing
you know I say if you can youcan outsource every single bit
of it and you can with theunderstanding that that you're
still going to be heavilyinvolved in it, and you have to
know all this, have to have someidea of all the controls and
what you're supposed to be doingbecause you're the one that has
to execute on them no matterwhat.
So there can be somebody thatcomes in and helps you get the

(03:15):
policies done, helps you throughimplementation, helps you with
ongoing support and all that.
So that would be fullyoutsourced, basically.
You still have to be involved.
You still have to understand.
You still have to be part ofthat whole process.
Or if you DIY, you can say,hey, hey, we need somebody
expert to come in and justconsult with us and call the

(03:36):
plays, right, and tell us wherewe're at, where we need to be,
and tell us where we need to go,right?
And so that would be kind ofthe difference.
And you can hire somebody forany part of this, but it's not
necessarily

Austin (03:53):
all or nothing.
So that would be the first stepin making compliance easy would
be having someone that is anexpert come in and at least
consult with you.
Yes.
Absolutely.
Okay.
Next up in our acronym EASY isA.
aligned for requirements.
What we've noticed inconsulting with a lot of
companies and doing theircompliance with them, not for

(04:13):
them, but with them, is how weapproach it.
A huge pitfall that we noticefrom the get-go is most people
tend to focus on tech first,technical.
What firewall do I need?
What tool solves this?
What security license can Ibuy?
And we view that as a hugepitfall.
Can you kind of tell me why?

Brooke (04:34):
Sure.
It is a huge pitfall becauseAnd really because it's not a
technical problem.
It's just not.
It is a business process.
Compliances.
Compliances, yes.
Compliance with CMMC, right?
And really any compliance.
It's business process.
It's the way you do things,right?
And yes, part of that is goingto be technology.
Absolutely.

(04:56):
100% it is.
This is not strictly IT.
It's not strictly technology.
So first of all, you have toknow what you have and why
you're supposed to be compliant,right?
Then you have to know wheredoes that data go?
Where does it come from?
Where does it go?
What happens with it?
And that all helps you to knowwhat you have.
to know what the flow of thedata is to scope your problem

(05:19):
correctly.
Scope your compliancecorrectly.
Once you have that scoped, youmay not necessarily want to
start with access control in theA's.
You may want to start somewhereelse in there, but you really
need to start with knowing whatyou have and where it goes.
And then, of course, you haveto be aligned with controls.

(05:40):
This is where a knowledgeablepartner comes in.
The coach, the expert, they'llhelp you trace everything back
to the appropriate controlsthey'll align everything for you
that's where an expert comes into help you with this and help
you align everything back tocontrols to where it's supposed
to be and not just doing thingswilly-nilly by you know we got

(06:00):
to have the we got to figure outthe technology solutions right
and it's again it's not abouttechnology part of it but it's
it's about the whole businessprocess and making sure you're
aligned to those controls andnot just not just the NIST
controls but the rest of therest

Austin (06:16):
of CMMC.
To your point, you may not wantto start with access control.
And if you're doing techsolutions first, you might end
up with a $15,000 iPad system atthe front door and a man trap
to track all the visitors thatcome through in and out of your
building whenever a piece ofpaper might work.
That's true.

Brooke (06:33):
You know, you can figure out how exactly, once you have
a holistic idea of everything,of what all is needed, which
would be your POAM, right?
Then you can kind of figure outwhere your technology where
your solutions need to be.
Or you can have a $15,000solution for what a piece of
paper might work for, alongwith, you know, other very

(06:54):
expensive solutions that will dothe job that are not necessary.
Right.

Austin (07:00):
Hey, some of us like shiny things, you know.
The next in our acronym, EASY,is S for streamlined approach.
CMMC shouldn't feel like you'rewandering through the dark.
What can you say about that,Brooke?

Brooke (07:11):
The DOD really has laid out some good streamlined
processes.
CAP, the CMMC assessmentprocess, which assessors have to
follow that.
There can always bedifferences, of course, but it
lays out a really goodstreamlined approach to making
sure all the assessments are assimilar as possible.
They've got the assessmentguidelines to show you how

(07:32):
you're supposed to assess thesethings, which you do not have
access to.
We go through and do our gapsanalysis and all that kind of
fun stuff, but they have thethose assessment guidelines to
help you out and help you figurethis out, right?
And then there's commonaccepted tools, you know, like
Microsoft 365 GCC High, youknow?
You don't have to reinvent thewheel on every one of these

(07:53):
things, you know?
Unless you don't want to paythe cost of Microsoft 365 GCC
High, which I understand, youknow, then, you know, do you
want to go with another vendoror do you, what do you want to
do?
But there are some acceptedsolutions that you don't
necessarily have to reinvent

Austin (08:08):
the wheel on.
So really, we're just talkingabout using proven approaches
instead of trying to reinventthe wheel.
Much like I think we've said inprevious episodes, if you're a
metal fabricator or a CNC shop,you're not...
I mean, I guess...
By all means, if you want tobuy the foundry and smelt your
own metal, you can, butsometimes it's easier to bite
the bullet and get the rawmaterials elsewhere, just like

(08:31):
GCC High.
You don't have to use it.
There are other solutions, oryou could go and create your own
email server and prove it to anassessor that that's going to
work, or you could just usesomething that they're familiar
with and that they're morelikely to approve, and that's
kind of what we're suggesting isgo streamline go with what's

(08:54):
accepted practice and make it alittle easier.
You can absolutely

Brooke (08:59):
design your own solutions, but one, is it going
to check off all the boxes?
I have a problem with peoplejust checking boxes, so that's a
different story.
But is it going to check allthe boxes off for this
compliance?
Yes or no, maybe so.
But what's the ongoingmanagement of it?
What does that look like?
If you design your ownsolution, is it going to depend

(09:19):
on what it is, how you get itupdated, how you make sure it
continues to comply How do youdo all these things, right?
Or if you use something that's365 GCC high or Prevail or
something else, you know whereit stands and you know ongoing
what it's going to take.

Austin (09:34):
Why is for you your competitive edge?
Because I stop at E-A-S.
That's no fun.
We have customers andprospective customers that fall
on a couple different camps.
And the ones that we see kindof on the leading edge of things
and that are leaning intocompliance are using this as a

(09:58):
competitive advantage.
And using appliance in theirfavor.
And so, um, I'll let you takeit over from there, but, um, you
know, it kind of, they, theyfeel that helps them with maybe
contracts and stuff in thefuture.

Brooke (10:16):
Absolutely.
That's what we've heard, youknow, and, and, uh, what we can,
what we kind of see is thatforward thinking businesses are,
are, uh, going to use this, uh,as a competitive edge, just
like you said.
Uh, and, and they, they kind ofsee, um, uh, being careful not
to tell you necessarily what I'mthinking, but that's, you know,

(10:37):
This is probably going to washout quite a few suppliers or
some suppliers, however manythat may be.
It's going to wash some outbecause they don't want to deal
with compliance.
Shoot, I had somebody tell methe other day, if I have to do
all this and I have to spend$100,000 just for an assessment
every three years, I'm not goingto do it.
I will go find businesselsewhere.

(10:59):
I don't blame you.
If it's not that much businessto you, then don't blame me a
bit.
It will wash some people out.
The The pool will get smalleras a result of this compliance.
And so those who are left andhave risen to the challenge and
met the bar of compliance andgot their L2 certification, they

(11:20):
will have a competitiveadvantage.
And the sooner you get that,the sooner you'll be able to win
contracts easier because youhave that.
All you have to do is say, hereit is,

Austin (11:28):
basically.
Two sides to every coin.
There is.
In an opportunity or one thatdoesn't look like an
opportunity.
It looks more like animposition.
That's right.
Some people do.
That's right.
Okay, so here's the recap.
Easy doesn't mean thatcompliance is effortless.
It means E, you've got expertguidance instead of going at it
alone.
A, you align everything to theactual real requirements, not

(11:51):
focusing on tools or tech first.
S, you follow a streamlined,proven process instead of
reinventing the wheel.
And Y, you turn your compliancerequirements into a competitive
edge or an advantage.

Brooke (12:04):
And if anybody's telling you that CMMC compliance can't
be easy...
They're not necessarily wrong,but it can be made easier.
That's what people like us areout here to do is help you out,
make it easier, not make iteffortless because there will be
effort involved.
It'll just...
It'll just be less effort andguided expert

Austin (12:28):
help to get you there.
If you have any questions aboutwhat we've covered here, please
reach out to us.
We're here to help fast-trackyour compliance journey.
Please text, email, or call us,and we'll answer your questions
for free here on the podcast.
Find our contact information atcmmccomplianceguide.com.
Stay tuned for our nextepisode.

(12:49):
Until then, stay compliant andstay secure.
Like, subscribe, and share.
Advertise With Us

Popular Podcasts

Bookmarked by Reese's Book Club

Bookmarked by Reese's Book Club

Welcome to Bookmarked by Reese’s Book Club — the podcast where great stories, bold women, and irresistible conversations collide! Hosted by award-winning journalist Danielle Robay, each week new episodes balance thoughtful literary insight with the fervor of buzzy book trends, pop culture and more. Bookmarked brings together celebrities, tastemakers, influencers and authors from Reese's Book Club and beyond to share stories that transcend the page. Pull up a chair. You’re not just listening — you’re part of the conversation.

Dateline NBC

Dateline NBC

Current and classic episodes, featuring compelling true-crime mysteries, powerful documentaries and in-depth investigations. Follow now to get the latest episodes of Dateline NBC completely free, or subscribe to Dateline Premium for ad-free listening and exclusive bonus content: DatelinePremium.com

On Purpose with Jay Shetty

On Purpose with Jay Shetty

I’m Jay Shetty host of On Purpose the worlds #1 Mental Health podcast and I’m so grateful you found us. I started this podcast 5 years ago to invite you into conversations and workshops that are designed to help make you happier, healthier and more healed. I believe that when you (yes you) feel seen, heard and understood you’re able to deal with relationship struggles, work challenges and life’s ups and downs with more ease and grace. I interview experts, celebrities, thought leaders and athletes so that we can grow our mindset, build better habits and uncover a side of them we’ve never seen before. New episodes every Monday and Friday. Your support means the world to me and I don’t take it for granted — click the follow button and leave a review to help us spread the love with On Purpose. I can’t wait for you to listen to your first or 500th episode!

Music, radio and podcasts, all free. Listen online or download the iHeart App.

Connect

© 2025 iHeartMedia, Inc.