Plain English Guide to NIST 800-171: CMMC Compliance Without the Overwhelm - EP #17
Feeling overwhelmed by CMMC compliance and NIST 800-171’s 110 controls? You’re not alone — but you don’t have to be stuck. In this episode of the CMMC Compliance Guide Podcast, Brooke and Austin break down NIST 800-171 Revision 2 in plain English — no government-speak, no tech jargon — so you can finally understand what each control family means for your business. You'll learn: ✅ What NIST 800-171 really requires (and why it matters for your SPRS score) ✅ How to tackle key control families like Access Control, Awareness & Training, and Audit & Accountability ✅ The critical mistakes contractors make (and how to avoid them) ✅ Why documentation is the #1 secret weapon for CMMC success ✅Real-world tips for manufacturing, machine shop, and aerospace contractors navigating CMMC Level 2 🔥 Don’t wait until an assessor says “No Soup for You” — build a compliance system that actually protects your business and wins contracts. 👉 Need help fast-tracking your compliance journey? Visit https://cmmccomplianceguide.com to download free resources or schedule a discovery call. 🎧 Listen, learn, and stay compliant. Hit LIKE and SUBSCRIBE for more real-world CMMC guidance! TIMESTAMPS 00:00 – Intro: What to Expect from Today’s Episode 00:37 – What is NIST 800-171 and Why It Matters 02:22 – What’s the SPRS Score and Where You Enter It 03:48 – What Are Control Families (and Why They Matter) 04:33 – Access Control (Who Can Access What) 09:17 – Shared Accounts in Manufacturing – Real Talk 14:08 – Admin Rights, Local Users, and Least Privilege 16:31 – Awareness and Training (What You Must Track) 19:00 – DoD Mandatory CUI Training – Gotchas 20:19 – Documenting Access Control the Right Way 22:02 – Audit and Accountability (What You Must Log) 25:36 – Why You Probably Need a SIM + SOC Team 29:10 – Configuration Management (Don’t Skip This One) 32:44 – Why IT Teams Often Miss Config Baselines 34:51 – Identification and Authentication (MFA Musts) 38:50 – Windows Hello for Business as MFA 40:12 – Incident Response (Why You Need a Plan) 44:12 – Reporting Timeline + Certificate Warning 47:30 – Real-Life Incident Story – MFA Saves the Day 50:45 – Maintenance (Proof of Patching & Escorting Vendors) 52:28 – Media Protection (Encrypting USBs & Paper CUI) 56:55 – FIPS Validated Encryption vs. “Compliant” 59:04 – Personnel Security (Screening & Offboarding) 01:00:57 – Physical Protection (Locks, Logs, & Keys) 01:02:48 – Risk Assessment (Vulnerability Scans & Gaps) 01:04:40 – Security Assessment (Review Your Controls) 01:06:03 – System & Communications Protection 01:08:08 – System & Information Integrity (Patch Everything) 01:10:38 – Most Commonly Missed Requirement (Documentation) 01:13:44 – “No Soup for You” if You Don’t Document It 01:15:25 – Outro #CMMC #CMMCCompliance #NIST800171 #DFARS #CybersecurityCompliance #ManufacturingCompliance #DefenseContractor #CUIProtection #SPRSScore #AccessControl #CybersecurityPodcast

CMMC Compliance - Best Strategies - Part 1

How Small Defense Contractors Are Actually Getting Through CMMC - EP #59

Storchennest Live Webcam in Bad Salzungen, Thüringen

NIST 800-171 assessment, from an auditor's perspective

My Weekly Routine - Lied to and Cheated - CLK KOMPRESSOR turns out to be a TOTAL SCAM!

What do tech pioneers think about the AI revolution? - The Engineers, BBC World Service

Polygon U.S. Crypto Hearing | Here's What's at Stake

CS5 West 2026: The Biggest CMMC Warnings Contractors Need to Hear - EP #60

CMMC Level 1 Mock Assessment: From Theory to Practice

Building a Cybersecurity Framework

Practical Steps to Achieve NIST 800-171 Compliance | Guide To NIST 800-171 C.S. Cyber EP. 43

CMMC Enclaves by Industry

Season 1 Ep. 7 Dr. Landon Nauert on TMD, Physical Therapy, Dental Ergonomics & Preventative Rehab

How a Small Business Achieved CMMC Level 2 Certification in Record Time and at Low Cost

NIST SP 800 171 - Why You Cant Just Enter An SPRS Score And Be Done

Brian Tracy on Sales - Nordic Business Forum 2012

CS5 West 2026 CMMC Recap for Defense Contractor

NIST CSF vs 800-53 vs 800-171: Side-by-Side Comparison

Global Disruptions and IT Strategy: Planning for Cyber Risk, AI, Cloud, and Supply Chain Change

