SHOW / EPISODE

How to Prepare for a CMMC Assessment (CMMC Assessor Explains)

1h 4m | Aug 27, 2026

🚨 Want to break into DoD cybersecurity but don't have eMASS experience? Gain hands on experience with RMF Academy eMASS Lab Access and build the confidence employers are looking for. Link below 👇

https://www.rmfacademy.io/courses/RMF-Academy-eMASS-Lab-Access


🚀 Ready to break into DoD cybersecurity? RMF Academy gives you the hands on training, practical resources, and real world guidance to build the skills employers are looking for. Link below 👇

https://www.rmfacademy.io/


Timestamps:


00:00 Introduction

00:59 Meet CMMC Assessor Carter Schoenberg

02:23 What Is CMMC and Who Actually Needs It?

05:49 What Is CUI?

06:40 CMMC Levels Explained

09:03 The Problem With CUI and Government Contracts

10:43 CMMC Phase 1 and Phase 2 Explained

11:38 What Happened to CMMC Phase 2?

14:28 The Real Cost of CMMC Compliance

16:54 Why Protecting CUI Matters

19:42 How Companies Should Start Preparing for CMMC

24:04 Understanding Your CUI Data Flow

24:24 What CMMC Assessors Look for in Documentation

25:36 What Actually Happens During a CMMC Assessment

27:50 How to Prepare Your CMMC Evidence and Artifacts

29:27 Common CMMC Documentation Mistakes

31:11 How CMMC Controls Are Actually Assessed

32:31 What Happens After the Assessment?

33:18 What Happens When Evidence Is Missing?

36:33 Should You Get a CMMC Mock Assessment?

38:06 Why So Many Companies Use Microsoft Intune for CMMC

40:11 CMMC Implementation Mistakes to Avoid

42:50 What It Takes to Pass a CMMC Assessment

46:29 CMMC Assessment Preparation Checklist

48:40 How to Use the CMMC Assessor Guides

49:24 Understanding CUI Assets and Assessment Scope

50:40 Why Universities May Need CMMC

52:03 Universities Already Being Required to Meet CMMC Level 2

53:01 CMMC vs Other Cybersecurity Assessments

54:49 The Future of CUI Requirements

57:34 CMMC Level 2 Certification Requirements

59:57 The Cost of CMMC Implementation and Certification

01:01:49 How to Choose a Good CMMC Assessor

01:04:00 Final Thoughts


VIdeo Description:


What does a CMMC assessor actually look for during an assessment? In this episode of the Tech Woke Podcast, Christopher Okpala sits down with CMMC assessor Carter Schoenberg to break down the CMMC assessment process, what organizations should expect, and how defense contractors can properly prepare before an assessor arrives.


We discuss CMMC, Controlled Unclassified Information (CUI), CMMC Level 2, assessment scope, security controls, evidence, artifacts, documentation, and implementation. Carter explains why simply having policies isn't enough and what organizations need to demonstrate to show that their cybersecurity practices are actually implemented. We also discuss common documentation mistakes, missing evidence, mock assessments, Microsoft Intune, the cost of CMMC compliance, and what happens when an assessor identifies gaps.


If you're an ISSO, GRC professional, cybersecurity professional, government contractor, CMMC consultant, MSP/MSSP, or business operating within the Defense Industrial Base (DIB), this conversation provides a practical look at how CMMC assessments work and how organizations can prepare.


In this episode:

What CMMC is and who needs it

What CUI is and why it must be protected

CMMC levels and assessment requirements

How to prepare for a CMMC assessment

What CMMC assessors actually look for

How to prepare controls, evidence, and artifacts

CMMC documentation requirements

How assessors validate control implementation

What happens when evidence is missing

Common CMMC preparation mistakes

Why companies use Microsoft Intune for CMMC environments

CMMC assessment scope and CUI data flows

Whether companies should conduct mock assessments

The cost of preparing for CMMC

How to choose a CMMC assessor or consultant

How cybersecurity professionals can get involved in the CMMC ecosystem


If your organization is preparing for a CMMC assessment, don't wait until assessment day to figure out whether your documentation, evidence, and technical implementation align. This episode gives you an assessor's perspective on what preparation actually looks like.


Subscribe to Tech Woke for more conversations about CMMC, RMF, GRC, ISSO careers, federal cybersecurity, GovTech, eMASS, NIST 800-53, and cybersecurity compliance.


Question for you: Is your organization currently preparing for CMMC?


#CMMC #Cybersecurity #GRC

Paused
Audio Player Image
Tech Woke
Loading...