What to Expect in a CCA Course and How to Pass on the First Attempt
Joseph Lissenden Joseph Lissenden

What to Expect in a CCA Course and How to Pass on the First Attempt

A lot of students come into the CCA course not knowing what to expect. Some are nervous. Some think it will be easier than it is. I want to give you an honest picture of what the course covers, what the exam tests, and what separates students who pass on the first attempt from those who do not.

Read More
How Long Does It Take to Become a CMMC Certified Assessor?
Joseph Lissenden Joseph Lissenden

How Long Does It Take to Become a CMMC Certified Assessor?

One of the first questions people ask when they start exploring the CCA is how long it takes. The honest answer is that it depends on where you are starting from, but I can give you a realistic timeline based on what I see with students who go through this process.

Read More
What Is the CMMC CCA and Who Needs It?
Joseph Lissenden Joseph Lissenden

What Is the CMMC CCA and Who Needs It?

A lot of students come into the CCA course not knowing what to expect. Some are nervous. Some think it will be easier than it is. I want to give you an honest picture of what the course covers, what the exam tests, and what separates students who pass on the first attempt from those who do not.

Read More
The CCA Window Is Closing. Here Is What That Actually Means.
Joseph Lissenden Joseph Lissenden

The CCA Window Is Closing. Here Is What That Actually Means.

If you have been sitting on the Certified CMMC Assessor (CCA) credential decision, the calculus just got simpler. Not because of a marketing deadline. Because the pathway itself is changing in ways that will make the credential more expensive, more complicated, and more time-consuming to obtain starting later this year.

Read More
Big Changes Ahead for CMMC: What You Need to Know Before April 1
Joseph Lissenden Joseph Lissenden

Big Changes Ahead for CMMC: What You Need to Know Before April 1

April 1 marks a major milestone for the CMMC community. ISACA has officially assumed CAICO operations, and with that comes a few important updates. If you are working toward a CCP, CCA, or LCCA, or already hold one, this transition matters to you.

Let’s start with the question many of you are asking: Should I wait to take my exam?

Read More
After 50+ CMMC Gap Assessments, I Can Predict Assessment Failure in the First 10 Minutes. Here's What C3PAOs Look For Immediately.
Joseph Lissenden Joseph Lissenden

After 50+ CMMC Gap Assessments, I Can Predict Assessment Failure in the First 10 Minutes. Here's What C3PAOs Look For Immediately.

've conducted over 50 CMMC gap assessments for defense contractors. Within the first 10 minutes of an opening meeting, I can usually predict whether an organization will pass or fail their C3PAO assessment. It's not about technical sophistication or budget. It's about specific tells that reveal whether the CMMC program is real or just documentation.

Here's what I look for in those critical first minutes.

Read More
Why Documentation Fails More CMMC Audits Than Missing Technical Controls in 2026
Joseph Lissenden Joseph Lissenden

Why Documentation Fails More CMMC Audits Than Missing Technical Controls in 2026

The harsh reality of CMMC assessments in 2026: organizations with mature security programs are failing audits not because their cybersecurity is weak, but because their documentation can't prove it exists.

After reviewing hundreds of assessment outcomes, a clear pattern emerges. Technical controls are usually implemented. The failures happen in the evidence package, System Security Plan structure, and Plan of Action & Milestones management. Here's what's actually causing organizations to fail and how to avoid these traps.

Read More
Stop. Your CMMC Scoping Strategy Might Be Built on Lies.
Joseph Lissenden Joseph Lissenden

Stop. Your CMMC Scoping Strategy Might Be Built on Lies.

If you're counting on encrypted networks to keep assets out of scope, or assuming your VDI endpoints are safe by default, you're walking into a C3PAO assessment with a target on your back.

The DoW just dropped CMMC FAQ Revision 2.2 (January 2026), and it systematically dismantles five assumptions contractors are still using to shrink their assessment boundaries. These aren't edge cases. These are the shortcuts people take when they're trying to make CMMC cheaper or faster, and the DoW just said no.

Read More
Best Way to Structure an SSP for CMMC: Policies, Plans, and Procedures
Joseph Lissenden Joseph Lissenden

Best Way to Structure an SSP for CMMC: Policies, Plans, and Procedures

Your System Security Plan (SSP) is the foundation of CMMC compliance. For CMMC Level 2, assessors rely on it to understand your environment, your controls, and how security is actually implemented. A weak or disorganized SSP is one of the most common reasons assessments stall or fail.

Read More
NIST SP 800-171 vs. CMMC: What’s the Difference?
Joseph Lissenden Joseph Lissenden

NIST SP 800-171 vs. CMMC: What’s the Difference?

NIST SP 800-171 and the Cybersecurity Maturity Model Certification (CMMC) both exist to protect Controlled Unclassified Information (CUI), but they are not interchangeable. The key difference is simple: CMMC adds enforcement.

Read More
The Most Common Scoping Mistakes Sabotaging CMMC Level 2 Readiness in 2026 (and How to Fix Them)
Joseph Lissenden Joseph Lissenden

The Most Common Scoping Mistakes Sabotaging CMMC Level 2 Readiness in 2026 (and How to Fix Them)

Scoping is the single biggest reason Level 2 assessments are failing or stalling in early 2026. Consultants, early C3PAO mock assessments, and readiness reviews consistently show scoping errors in roughly 40-60% of cases. Get the boundary wrong and you either fail outright (under-scoping) or burn six-figure budgets remediating assets that never touch CUI (over-scoping). The DoW Scoping Guide Level 2 (October 2024 final rule version, with 2025 errata) is the canonical reference, yet many organizations still misapply it.

Read More