Listen "What to Know From a C3PAO"
Episode Synopsis
This week we're joined by Fenando Machado of Cybersec Investments, an authorized CMMC C3PAO. Fernando has been around the CMMC space for years and has helped a ton of companies successfully pass their Joint Surveillance Assessments. Fernando shares what he's learned ahead of the effective date of the 32 CFR CMMC final rule and the rest of the phased roll-out.
Pathfinder 101: https://www.summit7.us/pathfinder
Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo
32 CFR CMMC Webinar: https://www.summit7.us/webinars/cmmc-32-cfr-final-rule
Fernando: https://www.linkedin.com/in/fernando-machado-cissp-cism-cca-ccp-5b5581124/
Cybersec Investments (C3PAO): https://cybersecinvestments.com/
(0:00 – 3:17): Intro (3:18 – 6:42): What's the key to assessment success? (6:43 – 8:48): What's the key to perfect scores? (8:49 – 11:42): Most problematic controls? (11:43 – 12:52): What's harder: technical or non-technical? (12:53 – 14:42): Are “False Starts” real? (14:43 – 17:44): How important is an MSP? (17:45 – 20:45): Current backlog? (20:46 – 22:38): $100k assessments? (22:39 – 24:27): Outro
Pathfinder 101: https://www.summit7.us/pathfinder
Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo
32 CFR CMMC Webinar: https://www.summit7.us/webinars/cmmc-32-cfr-final-rule
Fernando: https://www.linkedin.com/in/fernando-machado-cissp-cism-cca-ccp-5b5581124/
Cybersec Investments (C3PAO): https://cybersecinvestments.com/
(0:00 – 3:17): Intro (3:18 – 6:42): What's the key to assessment success? (6:43 – 8:48): What's the key to perfect scores? (8:49 – 11:42): Most problematic controls? (11:43 – 12:52): What's harder: technical or non-technical? (12:53 – 14:42): Are “False Starts” real? (14:43 – 17:44): How important is an MSP? (17:45 – 20:45): Current backlog? (20:46 – 22:38): $100k assessments? (22:39 – 24:27): Outro
More episodes of the podcast Sum IT Up: CMMC News Roundup
New CMMC FAQs (January 2026)
08/01/2026
7 CMMC Predictions for 2026
01/01/2026
CMMC Requirements for DLA Suppliers
25/12/2025
FCA Whistleblower Strikes Again
18/12/2025
No CMMC for Hard Copy CUI?
11/12/2025
Primes Can't Waive CMMC
04/12/2025
DIBCAC Assessment Requirements
27/11/2025
November Cyber AB Town Hall Recap
20/11/2025
CMMC Phase 1: What Comes Next?
13/11/2025
CMMC Timeline Refresher
06/11/2025
ZARZA We are Zarza, the prestigious firm behind major projects in information technology.