Tag: CMMC Scope

How CMMC Drives Long-Term Security Maturity, Not One-Time Compliance ft. Rick Olivier (Ep. 13)

How CMMC Drives Long-Term Security Maturity, Not One-Time Compliance ft. Rick Olivier (Ep. 13)

How should defense contractors respond to the CMMC pause? Questions about assessment timing, preparation costs, and CMMC requirements are leaving many organizations unsure whether to continue.

In this episode, host Tony Pietrocola, President and Co-founder of AgileBlue, and co-host Joe Marquette, AgileBlue CEO and Co-founder, speak with Rick Olivier, Director of Cybersecurity Advisory at Eide Bailly, about how contractors can prepare without overhauling their entire technology environment. Rick explains how controlled unclassified information determines CMMC scope, when a focused enclave may reduce cost and disruption, and how MSP access can expand the assessment scope. They also cover C3PAO assessments, continuous monitoring, and readiness gaps that can waste time and money.

Key takeaways:

  • How the CMMC pause is affecting assessment timelines and contractor preparation
  • Why locating controlled unclassified information is the first step in defining CMMC scope
  • When a focused CMMC enclave may reduce licensing costs and operational disruption
  • How MSPs, MSSPs, and other third parties can expand the scope of a CMMC assessment
  • Why continuous logging, monitoring, documentation, and response support ongoing readiness
  • And more!

Connect with Tony Pietrocola:

Connect with Joe Marquette:

Connect with Rick Olivier: