GRC Academy Podcast June 19, 2025 S-2 / E-10 00:53:00

The Business Case for CMMC: Surviving DOGE

Interview with Derek Kernus about how to convince your company's leadership to make the investment in CMMC.

CMMC certification could be the key to surviving DOGE cuts! šŸ‘€

In this episode, I’m joined by Derek Kernus of Aethon Security to discuss the business case for CMMC:

This episode was really refreshing to me. Yes, our discussions about deep CMMC topics are important, but learning how to convince your company leadership to make the CMMC investment is even more critical.

Here are some takeaways:

  • How CMMC early adopters can shape contracts and limit competition
  • How to frame the CMMC investment to internal leadership
  • The impending CMMC bottleneck of doom šŸ‘»
  • What mock assessments are and how they can help you prepare
  • Why choosing the wrong MSP could actually kill your chances at certification

After being impacted by DOGE myself, I’ve put a lot of thought into how small businesses will be impacted by DOGE + CMMC.

Most of my concern is for SMBs that haven’t started preparing for CMMC. That costs a lot of money, and if SMBs lose revenue due to DOGE cuts before they prepare for CMMC, I’m not sure they’ll be able to survive in the defense contracting space.

But there is great opportunity for CMMC early adopters to be part a small cadre of CMMC certified companies and operate in a much smaller competitive space.

It turns out CMMC actually could be your business’s savior. Who knew!?!

I really enjoyed this conversation! What were your biggest takeaways? Let me know in the comments.

Follow Derek on LinkedIn: https://www.linkedin.com/in/derekkernus/

Aethon Security Website: https://www.aethonsecurity.com/


Thanks to our sponsor Vanta!

Get back time to focus on strengthening security and scaling your business.

Discover the new way to GRC here: https://vanta.com/grcacademy