Listen On:
Sign up for alerts on new podcasts:
Episodes:

CMMC at Scale: Securing Enterprise & Supply Chain
In this episode of the Cuick 10 Podcast, filmed live at #CUICON 2025, Derek White, Chief Operating Officer of Cuick Trac, is joined by Chuck Orlowski, BISO/CISO at GE Vernova, to discuss the challenges of managing CMMC compliance at enterprise scale.
Chuck shares how his team is driving cultural change across one of the world’s largest energy portfolios while tackling CMMC readiness internally and throughout their supply chain. He speaks candidly about what’s still unclear from the DoD, the risks of ignoring contract implications, and why smaller contractors need shared solutions to survive the cybersecurity demands being pushed downstream.

CMMC Assessments Are Here: What You Need to Know
In this episode of the Cuick 10 Podcast, filmed live at #CUICON 2025, Derek White, Chief Operating Officer of Cuick Trac, is joined by Fernando Machado, Managing Principal and CISO at CyberSec Investments, to share lessons from the first wave of official CMMC Level 2 assessments.
Fernando explains how the landscape has changed now that C3PAOs are actively certifying OSCs, what contractors should expect during scheduling, and what happens if you’re not ready. He also addresses the nuances around significant changes to a system post-certification — and what still needs clarification from the DoD.

Bridging the Gaps: DFARS vs. CMMC
In this episode of the Cuick 10 Podcast, filmed live at #CUICON 2025, Derek White, Chief Operating Officer of Cuick Trac, is joined by Carter Schoenberg, Vice President & Chief Cybersecurity Officer at SoundWay Consulting, to discuss the often-misunderstood divide between DFARS contract requirements and CMMC Level 2 assessments.
Carter shares what he’s seen across dozens of readiness reviews and client assessments—including how organizations are still falling short when it comes to incident response planning, asset inventory, and understanding their obligations. He also explains why contractors should be getting on a C3PAO’s schedule sooner rather than later—before the demand outpaces capacity.

Behind the Scenes of CMMC Assessments
In this episode of the Cuick 10 Podcast, recorded live at #CUICON 2025, Derek White, Chief Operating Officer of Cuick Trac, is joined by Steven Molter, Solutions Architect at IntelliGRC, to explore what’s actually happening inside CMMC Level 2 assessments right now.
Steven shares what he’s seeing across multiple client engagements, including inconsistencies between C3PAOs, scoping guidance that’s still evolving, and practical strategies for addressing tough requirements like continuous monitoring. He also highlights how IntelliGRC is helping organizations ditch spreadsheet chaos and stay organized for audit success.

CMMC & Your Affirming Official
In this episode of the Cuick 10 Podcast, Derek White, Chief Operating Officer of Cuick Trac, is joined by Justin Orcutt, Director of Cybersecurity for the Aerospace and Defense Market at Microsoft, to break down the role of the affirming official in CMMC compliance. Justin discusses the shift of accountability to senior business leaders, the need for annual self-assessments, and the importance of maintaining continuous compliance with CMMC Level 2 requirements.
