Episode Description
The CMMC Phase 2 pause did not erase NIST 800-171, and it did not hand MSPs or contractors a permission slip. What it has done is resurface some of the same problems CMMC has faced for years - misinformation, gate keeping, and confusion.
This week, Isabel Rivera from Pentakt and Niels Petersen from ECN IT Solutions join Jared and Michael to explain what assessors expect, where technical teams get tripped up, and why waiting may cost more than moving forward. - Why the Phase 2 pause does not eliminate existing NIST 800-171 work- How 110 controls translate into roughly 320 assessment objectives, including HR, approvals, evidence, and separation of duties- Why having no SSP can drive an SPRS score to -203, and why an internal plan of action is not a C3PAO POA&M- What continuous monitoring should include and why your next assessment may require three years of evidence
Get NIST-y is Blacksmith InfoSec’s practical podcast for MSPs and SMBs that want compliance to produce real security, not checkbox theater. Make sure to follow the podcast or ask your own questions at:https://blacksmithinfosec.com/nisty/
Want to get in touch with our guests?
Niels Petersen: npetersen@ecnitsolutions.com
Isabel Rivera: irivera@pentakt.com