In Episode 14, Steven sits down with Andy Sauer — founder of Sentinel Blue, C3PAO practice leader, Cyber AB CP-PAC member chairing the External Services Provider subcommittee, admin of the CUI/CMMC “Center of Excellence” Discord, and host of The Watchers podcast.
Andy traces his unconventional path into cybersecurity: from World of Warcraft all-nighters and building his own PCs, to nearly two decades as a firefighter and paramedic, to getting thrown into the deep end of DFARS 7012 and NIST 800-171 at a defense contractor in 2017 — the moment that became the genesis of Sentinel Blue.
The conversation digs into what actually moves the needle in CMMC and why the model, in Andy’s view, is “baked silly”: equally-weighted controls, the analysis paralysis facing small and mid-sized contractors, and the inconsistency in how C3PAOs treat External Service Providers. His advice for surviving it is simple — get informed, ground yourself in the regulation, and don’t lose sight of the point. Turn on MFA before you go hunting for the perfect documentation platform.
They also get into building a values-driven, bootstrapped company in a bottom-line world, why you should hire people who think differently than you, the aggressively anti-vendor culture of the CMMC Discord, and the story behind The Watchers — Andy’s long-form podcast spotlighting the public servants quietly protecting all of us.
Whether you’re a defense contractor staring down a Level 2 assessment, an MSP trying to do right by your clients, or just CMMC-curious, there’s a lot of substance here.
Watch the Full Video Here: Link
