Dejan Kosutic hosts Bruno Lecoq (co-founder, CEO, and CISO at BEMO) to explain CMMC compliance for Department of Defense contractors and suppliers, including those outside the U.S. They cover CMMC basics (levels, CUI vs. FCI, C3PAO assessments, phase 1 boundary review and phase 2 audit), current capacity challenges (about 93 C3PAOs vs. roughly 200,000 contractors), and why many companies fail early due to incomplete documentation. Bruno shares BEMO's experience (29 policies, 46 procedures, 14 configuration documents, 700+ pieces of evidence, and a 300-page SSP) and emphasizes leadership buy-in, parallel technical and documentation work, proof-based evidence, ongoing monthly/quarterly reviews, and maintaining compliance after certification. They discuss scoping CUI boundaries, tooling constraints (e.g., GCC/GCC High), subcontractor requirements varying by contract, and typical assessment costs ($45K–$55K plus ~$10K mock).
Note: This interview was recorded in June 2026, before the U.S. Department of Defense suspended the planned rollout of CMMC Phase 2.
Podden och tillhörande omslagsbild på den här sidan tillhör
Dejan Kosutic. Innehållet i podden är skapat av Dejan Kosutic och inte av,
eller tillsammans med, Poddtoppen.