CMMC Level 2 will never work if it gets dumped on just one IT person. It needs leadership, finance, HR, operations, compliance, and security all moving in the same direction. In this solo episode of Trust Issues, Brandon Lecoq breaks down why CMMC is a company-wide initiative, what BEMO’s own internal ownership model looks like, and why the cost only makes sense when leaders understand the contract revenue at stake.
CMMC Level 2 just does not work when it gets dumped on one IT person.
In this solo episode of Trust Issues, Brandon Lecoq explains why CMMC readiness has to become a company-wide initiative, not an IT side quest. He walks through the roles involved in BEMO’s own CMMC Level 2 program and shows why security, compliance, HR, operations, finance, and leadership all have real ownership.
The episode is a practical reality check for contractors who still think CMMC can be handled quietly in IT. It cannot; if leadership is not involved, if the CFO does not understand the ROI and if HR and operations are not ready to provide evidence, the program is already in trouble.
What You’ll Learn:
- Why leadership involvement is non-negotiable for CMMC Level 2
- Why the CFO needs to understand contract value before rejecting the budget
- How one-person IT ownership creates serious compliance risk
- Why HR, operations, compliance and security all own parts of CMMC
- What BEMO’s nine-person internal CMMC support model reveals about the workload
- Why CMMC should be treated as one of the company’s biggest initiatives for the year
Episode chapters:
00:00 Introduction
01:01 Why CMMC needs a real team
01:30 BEMO’s own CMMC level 2 setup
02:00 Why nine people are involved in BEMO’s program
02:30 Why CMMC takes more than one IT person
03:00 Why the CEO has to be involved
03:30 Leadership silence is a CMMC failure risk
04:00 Why the CFO has to understand the cost
04:35 The real annual cost of CMMC level 2
05:15 Contract value, growth planning, and November 2026
06:15 Why CMMC spend needs to be tied to revenue risk
07:00 Kata’s role in security engineering
07:45 The single-person IT risk
08:30 Why responsibilities need to be distributed
09:00 Jeremiah’s role in compliance documentation
09:30 Binny’s role in evidence collection
10:00 Why CMMC takes a village
10:15 Ron’s role in program management
10:50 Cindy’s role in operations controls
11:20 Sylvia’s role in HR and personnel security
12:00 Why all control owners show up during the audit
12:45 Julio’s role in security operations
13:15 Why security owns 59% of the controls
14:00 Why non-IT stakeholders still matter
14:30 Building the internal coalition for CMMC
15:00 Why CMMC may be your top initiative of the year
15:20 Contract value vs. compliance cost
Quotes:
- “If leadership does not get involved, you will absolutely never become CMMC Level 2 compliant.”
- “The number one leading factor for why organizations never become ready and will not pass CMMC is because they silo everything into IT.”
- “The CFO is really going to have to be involved because most of your companies, this is going to cost you a pretty penny.”
- “CMMC Level 2 has many controls and assessment objectives that IT is not responsible for. You will fail if this stays within the IT organization by itself.”