
Develop a complete defensible CMMC 2.0 program from zero knowledge to readiness, delivering your own SSP, SPRS score, a tailored 86-file package, and practical scenario walkthroughs.
Navigate the CMMC 2.0 roadmap from foundation to practice in 6 hours, with 5 blocks, 14 control families, and two scenario-based walkthroughs to reach assessment readiness.
Discover the 86-file downloadable document package for CMMC 2.0, organized into eight categories from governance to logs, with templates and a master index to start building your system security plan.
CMMC exists to protect CUI, addressing the defense industrial base’s exposure to adversary threats, by replacing self-attestation with third-party verification via C3PAOs.
Understand the three DFARS clauses—7012, 7009, and 7121—that enforce NIST 800-171, 72-hour incident reporting, and flow-down to subs, and how SPRS scores tie to award, so start preparing now.
Compare CMMC 1.0 and 2.0, showing simplification to three levels and level 2’s mapping to NIST 800-171. Emphasize documentation and evidence to reduce costs for defense contractors.
Navigate the four phases of CMMC rollout from 32 CFR Part 170 to final DFARS implementation, preparing now with self-assessments, SPRS scoring, early C3PAO engagement, and a structured evidence library.
Learn the CMMC level 1 baseline, 17 practices, and self-assessment, then examine level 2's 110 NIST Special Publication 800.171 requirements, third-party assessments, and POA milestones.
Discover how the 110 NIST 800.171 controls organize into 14 families and emphasize access control, identification, audit, and boundary protection, illustrated with AC2 and SC7 examples.
Understand your CMMC 2.0 assessment path: level 1 self-assessment, level 2 by a C3PAO, or level 3 government-led. C3PAO assessments expect site visits, evidence review, interviews, and testing.
Learn how a POA&M acts as a remediation roadmap in CMMC 2.0, detailing current state, actions, responsibilities, milestones, and how non-critical controls may be deferred for level 2 assessments.
Learn how awareness, training, and audit and accountability controls use annual and role-based training, insider threat recognition, anonymous reporting, and rigorous log auditing to protect systems.
Explore how configuration management sets baselines, documents standards, applies change control, and minimizes attack surfaces through least functionality. Understand incident response and maintenance duties, policy, evidence preservation, and remote maintenance.
Learn to enforce media protection and physical safeguards, including MP2 access control, MP3 labeling and inventory, MP5 transport, PE3 access, PE4/PE6 surveillance, and PS1 background checks.
Master RA risk assessments to identify top assets and threats, apply CA and SC controls, and strengthen SI integrity through vulnerability scanning, cryptographic protection, boundary protection, and network segmentation.
Learn how the CyberAB standardizes CMMC assessments, accredits C3PAOs and assessors, maintains the marketplace, and handles remediation, disputes, and ongoing standards updates for trusted compliance.
Learn how RPOs and RPs help implement CMMC controls, how consultants advise versus assessors evaluate, avoid conflicts, verify credentials, and use hybrid planning for efficient, compliant readiness.
Identify your role in the defense contractor ecosystem and implement proportionate CMMC flow-down with primes and subcontractors, while appointing a coordinator to plan a 12–18 month rollout and verify compliance.
Identify FCI versus CUI to determine CMMC levels in your planning phase; if FCI only, achieve level one, but any CUI triggers level two.
Run a CUI discovery workshop to locate sensitive data across technical docs, design files, and email. Then map its journey through people and systems to prepare for CMMC assessment.
Mark CUI documents with top-of-page banners such as CUITechData and CUITechnicalData, note multi-category and portion markings, and enforce access controls, encrypted storage, NIST-based destruction, and annual training.
Define your CMMC assessment boundary by identifying CUI assets, security protection assets, and contractor risk managed assets; document scoping decisions to avoid over- and underscoping.
Design networks with strong separation, using air gaps and VLANs with strict firewall rules to isolate CUI enclaves and reduce assessment scope. Document cloud and on-prem boundaries.
Inventory federal contracts to determine CUI versus FCI, map in-scope systems, and document rationale with asset worksheets to apply the scoping guide for CMMC 2.0.
Identify who needs access to CUI systems, enforce access controls and physical access measures, restrict USB drives, apply password requirements, and monitor logs with antivirus.
Perform a level 1 self-assessment using a 17-practice matrix, document evidence, and create remediation plans; submit an annual DoD affirmation through the CMMC portal.
Keep real level 1 evidence for access control, password, patch management, antivirus, monitoring, incident response, physical access, and backup; organize for quarterly reviews.
Prepare for level 2 assessment by addressing all 110 NIST 800-171 controls across 14 families, ensure a system security plan, MFA-enabled baseline, and six-month readiness from gap analysis to assessment.
Implement the access control family by managing accounts with RBAC, documented procedures, and quarterly access reviews; enforce default deny, MFA, VPN, and zero-trust through Active Directory and groups.
Learn identification and authentication, enforce multi-factor authentication, manage unique accounts, require strong passwords with hashing and salting, and implement auditing with a SIAM and log retention for IA and AU.
Master configuration management with baselines for Windows Server 2022, Linux Cent OS, and network devices, CM2, CM3, CM7 change controls, and boundary protection with deny-by-default firewalls and TLS 1.2+.
Implement incident response policy with detection, containment, recovery, and post-incident activities, plus notifications to legal, HR, customers, and regulators. Train annually with tabletop drills and enforce maintenance and media protection.
Enforce physical and personnel security with controlled access, visitor logs, and CCTV retention; escort vendors with non-disclosure agreements. Conduct risk assessments and vulnerability scanning, plus timely termination and policy enforcement.
Practice the opening meeting and assessment process with a mock team, defining scope, system boundaries, and documentation, then role-play interviews to verify MFA, access controls, and evidence.
Develop a living system security plan (SSP) that clearly documents controls, evidence, and roles to meet NIST requirements and guide assessors with a current, accurate picture.
Explore the SSP structure through a section by section walkthrough, covering system identification, boundary, architecture diagram, and core 110 NIST 800-171 control implementations, including TLS 1.2 and API keys.
Write precise control implementation statements for CMMC 2.0 that describe external boundary monitoring, internal network segmentation with VLANs, deny-by-default firewall rules, and documented verification through testing, examination, and interviews.
Conduct an annual SSP review aligned to the fiscal year, verify deployment accuracy, and update changes; maintain version control, change logs, and secure storage linked to POANM and continuous monitoring.
This course contains the use of artificial intelligence.
Stop drowning in compliance jargon. This course gives you the exact playbook defense contractors use to pass a CMMC Level 1 or Level 2 self-assessment — without hiring a $50,000 consultant.
By the end of this course you will be able to scope your environment, write your System Security Plan, score all 110 NIST 800-171 controls, submit your SPRS score, build a defensible POA&M, and maintain your assessment year after year. And you will do it with downloadable Word and Excel templates that I walk you through on screen.
What makes this course different
Most CMMC courses stop at theory. This one ends with two complete scenario walkthroughs — a Level 1 small machine shop and a Level 2 engineering firm — where you watch every decision, every document, and every remediation sprint from start to finish. You see how the framework actually gets applied in a real business.
What's inside (17 sections, step-by-step)
• Regulatory foundation — DFARS, the CMMC 2.0 final rule, and the phased rollout timeline
• The three CMMC levels and exactly what assessors look for
• All 14 NIST 800-171 families and 110 controls explained in plain English
• The CMMC ecosystem — Cyber AB, C3PAOs, RPOs, and where you fit
• FCI vs CUI discovery and the scoping guide applied to your environment
• Full Level 1 and Level 2 implementation walkthroughs
• Building the SSP section by section — with a template you can reuse
• POA&M rules, SPRS score calculation, and submission
• The C3PAO assessment — selecting, engaging, and passing it
• Continuous monitoring and sustainment after certification
• Two end-to-end scenarios: Precision Parts Inc. (Level 1) and Apex Defense Solutions (Level 2)
• A 90-day action plan to put everything into practice
Who this course is for
Small and mid-sized defense contractors — primes, subs, manufacturers — IT leads, compliance managers, and security officers who need to get their organization CMMC-ready without losing months to trial and error.
What you get
Over 6 hours of on-demand video, a full downloadable document package (SSP template, POA&M template, policy set, self-assessment checklist), and two complete scenario case studies. Lifetime access and 30-day money-back guarantee.