Video

Where to Begin on Your CMMC Compliance Journey

Axiom Podcasts Climbing Mount CMMC

In this episode of Climbing Mount CMMC, Kaleigh Floyd and Kelly Hood discuss the essential steps for small businesses to navigate the complexities of CMMC compliance. They emphasize the importance of understanding the foundational reasons behind CMMC, the necessity of leadership involvement, and the identification of internal roles and responsibilities. The conversation also covers practical strategies for implementing NIST 800-171 controls, the significance of scoping, and tips for writing an effective System Security Plan (SSP). Throughout the discussion, they highlight the need for a cultural shift towards security and the importance of collaboration across departments.

I recently had the chance to catch up with Kaleigh Floyd on the Climbing Mount CMMC podcast to talk about what companies actually need to know when they start tackling CMMC.

A lot of people feel lost when they first look at the requirements. They feel big and messy. We broke it down into the things that really matter in the beginning.

◾ Know why CMMC exists so you can make better decisions as you go
◾ Get leadership involved early
◾ Figure out who owns what inside the company
◾ Scope your environment before you start buying things
◾ Keep your SSP clear and practical

We also talked about the mindset shift that makes CMMC work. It is not just an IT issue. It takes people across the business working together.

If you’re getting started with CMMC and want a straightforward conversation (without the jargon), this episode is worth a listen!

Author
  • Kelly Hood
    Kelly Hood
    EVP & Cybersecurity Engineer