Breaking Down the CMMC Assessment Process w/ Michael Brooks | A-LIGN
  • Services
        • SOC Assessments 

        • SOC 1
        • SOC 2
        • ISO Certifications 

        • ISO 27001
        • ISO 27701
        • ISO 22301
        • ISO 42001
        • Healthcare Assessments 

        • All Healthcare
        • HITRUST
        • HIPAA
        • Federal Assessments 

        • All Government
        • FedRAMP
        • GovRAMP
        • FISMA
        • CMMC
        • NIST 800-171
        • PCI Assessments 

        • PCI DSS
        • PCI SSF
        • Cybersecurity 

        • Penetration testing
        • Red team services
        • Ransomware preparedness assessment
        • Social engineering
        • Vulnerability assessment service
        • Privacy 

        • GDPR
        • CCPA/CPRA
        • Additional Services 

        • International Services
        • Multi-Framework
        • Microsoft SSPA
        • NIS2
        • C5
        • SOX 404
        • CSA STAR
        • Business Continuity & Disaster Recovery
        • Limited Access Death Master File
        • All Services
  • Platform
  • Company
        • About Us
        • Partners
        • Meet our team
        • Board of Directors
        • Careers
        • image

          Tampa, Fla. – 10/1/2025 – A-LIGN, a leading provider in cybersecurity compliance, has added five…

          Learn more
  • Customers
  • Resources
        • Quick links

        • Resource Center
        • Blogs
        • Case Studies 
        • Videos
        • Events
        • By service

        • SOC 2 
        • ISO 27001 
        • ISO 42001 
        • CMMC
        • FedRAMP
        • HITRUST 
        • PenTest
        • Featured Resources

          image
          image
          image
          image
  • A-SCEND Login
  • Careers
CONTACT US

Breaking Down the CMMC Assessment Process w/ Michael Brooks

by: A-LIGN 45 min

CMMCCompliance

  • SHARE

Welcome to another episode of Mostly Compliant, hosted by Matt Bruggeman, Director of Federal GTM at A-LIGN.

In this episode, Matt sits down with Michael Brooks, Lead CMMC Assessor at A-LIGN, to break down the CMMC Assessment Process (CAP) for Level 2 certification. Together, they explore the CAP’s purpose, its four key phases, and why Phase 1 — the pre-assessment — is essential for ensuring readiness.

The conversation dives into the importance of system security plans (SSPs), scoping, and evidence preparation, while also addressing common misconceptions about Phase 1 and how it differs from a mock audit. Michael shares expert advice on navigating the process, avoiding pitfalls, and setting your organization up for success in the formal assessment.

Listen to this episode on your favorite platform: lnk.to/X2VoDS

About Mostly Compliant: Hosted by Matt Bruggeman, Director of Federal GTM at A-LIGN, Mostly Compliant is a cybersecurity podcast that brings together experts from across the federal compliance landscape to discuss CMMC, FedRAMP, and other key topics shaping the industry.

A-LIGN is the leading provider of high-quality, efficient cybersecurity compliance programs. Combining experienced auditors and audit management technology, A-LIGN provides the widest breadth and depth of services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI.

CONTACT US
  • Services
  • SOC 1
  • SOC 2
  • ISO 27001
  • ISO 42001
  • CMMC
  • HITRUST
  • FedRAMP
  • Penetration Testing
  • PCI DSS
  • HIPAA
  • International Services
  • Multi-Framework
  • All Services
  • Company 
  • About us
  • Partners
  • Platform
  • Careers
  • Our Team
  • Contact Us
  • Resources
  • Resource Center
  • Blogs
  • Case Studies
  • Videos
  • Events
  • Customers 
  • Customer Stories 
  • Resource Hubs
  • SOC 2 Resources
  • ISO 27001 Resources
  • CMMC Resources
  • ISO 42001 Resources
  • Pen Test Resources
  • Guides
  • SOC 2 Compliance
  • ISO 27001 Certification
  • CMMC Compliance
  • ISO 42001 Compliance
  • HITRUST Certification
  • ISO Certificate Directory
  • Privacy Policy
  • Cookie Policy
  • Impartiality and Inquiries
  • Acceptable Use Policy
  • Sitemap

Price and Associates CPAs, LLC dba A-LIGN ASSURANCE is a licensed certified public accounting firm registered with the Public Company Accounting Oversight Board (PCAOB). A-LIGN Compliance and Security, Inc. dba A-LIGN is a leading cybersecurity and compliance professional services firm.

A-LIGN 2025. All rights reserved.

  • Services
    • SOC Assessments
      • SOC 1
      • SOC 2
    • ISO Certifications 
      • ISO 27001
      • ISO 27701
      • ISO 22301
      • ISO 42001
    • Healthcare Assessments 
      • All Healthcare
      • HITRUST
      • HIPAA
    • Federal Assessments
      • All Government
      • FedRAMP
      • StateRAMP
      • FISMA
      • CMMC
      • NIST 800-171
    • PCI Assessments
      • PCI DSS
      • PCI SSF
    • Cybersecurity
      • Penetration testing
      • Red team services
      • Ransomware preparedness assessment
      • Social engineering
      • Vulnerability assessment service
    • Privacy
      • GDPR
      • CCPA/CPRA
    • Additional Services
      • International Services 
      • Multi-Framework 
      • Microsoft SSPA
      • NIS2
      • C5
      • SOX 404
      • CSA STAR
      • Business Continuity & Disaster Recovery
      • Limited Access Death Master File
    • All Services
  • Platform
  • Company
    • About Us
    • Partners
    • Meet our team
    • Board of Directors
    • Careers
  • Customers
  • Resources
    • Resource Center
    • Blogs
    • Case Studies 
    • Videos 
    • Events
    • By Service
      • SOC 2 
      • ISO 27001 
      • ISO 42001 
      • CMMC
      • FedRAMP
      • HITRUST
      • PenTest 
  • A-SCEND Login
  • Careers
CONTACT US