7 min read

The Right Way to Sequence Your CMMC Engagement

Featured Image

Linda Morales, EVP and Chief Security Officer at 38North Security and lead of the firm's CMMC practice, explains why she deliberately refuses to talk about technology until the end of every engagement, and what that sequencing looks like in practice.

Most defense contractors hear the word compliance and immediately reach for their tech stack. Which tools need to be replaced? What does the environment need to lock down? Who owns this in IT?

Linda Morales has spent enough time leading CMMC engagements to know why that instinct backfires. As EVP and Chief Security Officer at 38North Security, an authorized Registered Practitioner Organization in the CMMC ecosystem, Linda has advised companies from their first contractual brush with CUI all the way through sitting next to them during the C3PAO assessment itself.

The pattern she sees is consistent. Teams that start with technology spend more money, rebuild more scope, and still end up with gaps on assessment day. Teams that get it right do something counterintuitive. They keep technology off the table until the end.

"Sometimes I won't even talk about technology till the very end of our discussions. That way they share more information." Linda Morales

Here's Linda's sequencing playbook, and why "people, process, technology" is an order, not a slogan.

Key Takeaways

  • CMMC isn't IT centric the way FedRAMP is. It follows the data, which means sales, contracts, and finance almost always come into scope.
  • The strongest mnemonic for a CMMC program is "people, process, technology," and the order matters.
  • Boundary scoping is a marathon of meetings that traces where CUI actually flows, not a tool inventory.
  • Gap analysis and SSP documentation should run concurrently, not sequentially, so decisions and documentation evolve together.
  • Buying an enclave or managed environment doesn't transfer your responsibility. The Shared Responsibility Matrix defines what you still own.

Table of Contents

  1. The Scoping Trap Most CMMC Programs Fall Into
  2. The Shift in Thinking: People, Process, Technology
  3. The Ultimate Sequencing Playbook
  4. Why This Approach Works
  5. Frequently Asked Questions

The Scoping Trap Most CMMC Programs Fall Into

Most compliance frameworks defense contractors have seen before are technical at their core. FedRAMP, for instance, is heavily IT centric. It shares a NIST backbone with CMMC, which is part of why so many teams assume CMMC will feel familiar.

It won't.

"The difference with CMMC is that it's not focused on IT. It's actually focused on following the data through your organization, and that includes the people, processes, and technology where CUI or FCI reside." Linda Morales

That shift in center of gravity matters because it pulls functions into scope that IT rarely touches. Sales teams receive CUI in the first email from a federal buyer. Contracts teams route it through review workflows. Finance teams handle invoices and budget artifacts tied to classified work. None of those functions sit inside IT, and none of them are used to being told their process is now part of a cybersecurity assessment.

"They start asking, why do I have to do this," Linda says. "It's a change in my process."

When a program gets handed to IT with a mandate to go handle it, the scope gets drawn around the network instead of the data. That leads to two expensive outcomes. Either the boundary is too narrow and the assessor finds data in places the program never accounted for, or the boundary is too wide and the company spends far more than it needed to on tools and remediation across systems that were never in scope to begin with.

 

The Shift in Thinking: People, Process, Technology

The whole point of Linda's approach is to break the reflex toward tech first thinking. Her tool for doing that is a mnemonic she repeats until it sinks in.

"I always stress that. People, process, technology. People, process, technology. Drill it into the head." Linda Morales

 

The order is the lesson. Start with the people who handle CUI. Map the processes they follow. Only then decide what technology is right to support them.

Linda takes this further than most advisors. In early conversations she deliberately avoids the topic of technology, even when clients push to discuss it. The reason is practical. When you let technology lead, people answer every question in terms of tools. We use SharePoint. We use Google Drive. We use the ticketing system. That tells you nothing about how CUI actually moves.

When you put technology aside and ask about workflow, people describe what they actually do, including the parts that are off policy. That's where the real work starts.

"Give us all your dirty laundry. You don't want the assessment team to come in and find it." Linda Morales

The companies that trust their advisor with the messy truth are the ones who correct it before a C3PAO ever walks in the door. The ones who don't, land findings.

 

The Ultimate Sequencing Playbook

Here are the five moves Linda runs in order. They're built to protect the program from the IT first reflex without slowing it down.

1. Run a Boundary Scoping Marathon

Boundary scoping isn't a one hour workshop. It's a series of conversations that trace where CUI enters the organization, who touches it, and where it ends up.

"We start with where does the data hit your organization first. Is that your sales team? Is that your contracts team? Is that a federal person that's emailing it to you? Then we follow the trail." Linda Morales

Linda's team starts at the ingress point, confirms who receives the data first, then asks where it goes next. The answer routes the next meeting. If the sales team sends it to three different teams, her team meets with each of those teams. The process ends when the trail stops, either because the data is stored and not forwarded, or because the flow is fully mapped.

For simple environments, this can wrap in a couple of meetings. For complex ones, it becomes literal whiteboarding, with lines drawn between departments, systems, and handoffs. The artifact at the end is a diagram everyone in the room agrees is accurate. That diagram, not an IT inventory, becomes the foundation for the rest of the program.

2. Be Willing to Share the Messy Parts of Your Workflow

Boundary scoping only works if your team is willing to describe the real workflow, including the parts nobody wants to admit to. If a contracts manager is forwarding CUI to a personal Gmail account, your advisor needs to find out in discovery, not in the assessment.

Linda asks her clients for the dirty laundry up front and explains the stakes. The companies that share it land at a defensible scope. The companies that hide it land findings.

The signal that the conversation is working is a shift in tone across the people who actually handle CUI. "Depending on who you talk to, you can see when the light bulb goes off. They're like, oh, I see how that applies to me. And they start giving you more info."

When that shift happens across your sales, contracts, and finance teams, the rest of the playbook becomes possible. Without it, scoping is a guess.

3. Fix Process Before You Buy Technology

Once the data flow is mapped and the real workflows are on the table, the question shifts. Does the current process meet the requirements, with or without changes?

Often the answer is that the current process is close, but needs a small adjustment. Restrict one SharePoint folder. Isolate one Google Drive. Update one approval workflow. The environment stays mostly intact, the requirements get met, and the cost stays low.

Sometimes the answer is different. If the current environment is too open or the timeline is too tight, buying into a purpose built enclave may be the right call, especially when only a handful of people need access to CUI. But that's a decision, not a default.

"It really is a decision about return on investment. Is it worth it to purchase something else or is it worth it to just deal with what we have, implement the requirements, and isolate where that data is stored." Linda Morales

 

💡 BEMO helps defense contractors evaluate the right scope and the right architecture for CMMC before any tools get replaced. Talk to BEMO about CMMC readiness → bemopro.com/compliance

 

4. Run Documentation and Gap Analysis in Parallel

Most teams treat documentation as the last step. Linda runs it concurrently with gap analysis so the two inform each other.

Once the boundary is agreed, her team starts walking each requirement against the environment. They flag high priority gaps for remediation and begin filling in the System Security Plan at the same time. Tools, roles, and processes get documented while decisions are still being made, which means the SSP reflects reality instead of lagging behind it.

This matters on assessment day. Linda's team builds an artifact repository mapped directly to the requirements and hands the C3PAO the exact evidence for each one.

"We'll build an artifact repository mapped to the requirements and say, go look at this specific artifact. We're spoon feeding them the answers at that point." Linda Morales

Assessors don't want to hunt through a share drive. Programs that hand them a clean map get through assessments faster and with fewer findings.

 

5. Treat Enclave Decisions and Shared Responsibility as a Distinct Step

Buying an external enclave or managed environment doesn't hand off your compliance program. It creates a new question. What does the provider actually cover, and what's still yours?

 

Every External Service Provider worth considering publishes a Shared Responsibility Matrix. That document outlines which requirements the provider fully covers, which are shared, and which the customer still owns entirely. Linda's team treats reading and validating that matrix as its own workstream.

"Don't assume that your job is done and you've handed it over to that company, because you still have a responsibility." Linda Morales

Assessors also expect to see that the buyer understands their share of the matrix. Walking into an assessment assuming the enclave vendor carries the whole program is one of the fastest ways to land a finding on something the provider never covered.

CMMC also rates requirements on a one, three, and five point scale. Three and five point items are the riskier controls, and assessors won't proceed if any of those are open. That makes the enclave decision especially important. If the provider leaves any three or five point requirements in the customer's column, those have to be fully implemented before assessment day.

 

Why This Approach Works

Programs that start with technology draw the scope around the network, miss the business functions that handle CUI, and spend heavily on tools protecting the wrong boundary. Programs that start with data and people land at a smaller, more defensible scope, which means less spend, less remediation, and fewer of the open three or five point requirements that stop assessments cold.

The right advisor amplifies all of it. Trust earned early surfaces real problems before the assessor sees them, documentation built alongside decisions keeps the SSP matched to the environment, and an enclave decision made with the Shared Responsibility Matrix in hand leaves no ambiguity about what the customer still owns.

"We're not going tona tell you your baby's pretty all the time. But we'll help you make sure it gets pretty." Linda Morales

Follow the data, map the process, decide on technology last, document as you go, and understand what you still own.

 

BEMO runs CMMC engagements in this order by default. From scoping the CUI boundary across every function that touches it, to parallel gap analysis and SSP documentation, to helping teams evaluate enclave options against the Shared Responsibility Matrix, BEMO manages the full program so the sequence that matters on assessment day is the one the program was built around from day one.

Talk to BEMO about CMMC readiness → Book a Free Consultation

 

Frequently Asked Questions

Is CMMC really different from other NIST based frameworks?

Yes. CMMC shares NIST security requirements with frameworks like FedRAMP, but its center of gravity is different. FedRAMP is IT centric. CMMC follows the data. That means sales, contracts, finance, and anyone else who handles CUI comes into scope, regardless of whether IT owns their tooling.

Does buying an enclave cover all of my CMMC requirements?

No. External Service Providers publish a Shared Responsibility Matrix outlining what they cover, what is shared, and what the customer still owns. Even a well scoped enclave leaves requirements in the buyer's column, and assessors will evaluate whether the buyer understands and has implemented their share.

What's the biggest mistake teams make before an assessment?

Leaving three or five point requirements open. Those are the riskier controls on the CMMC rating scale, and assessors won't proceed if any of them are unresolved. Programs that don't sequence their work around closing those items early often hit a wall on assessment day.

Leave us a comment!