The DoD hit pause on CMMC Phase 2, and everyone in the Defense Industrial Base is asking the same question: what happens next? George Perezdiaz has a few answers, and they might surprise you. In Episode 18 of the IntelliGRC Podcast, Steven Molter sits down with George Perezdiaz, founder of Perezdiaz LLC, an authorized C3PAO. George’s road to CMMC runs through the Dominican Republic, nine years in the Air Force, the State Department, nuclear command and control at the Pentagon, and Corning Inc., where he helped build a CUI program that scoped a 50,000 employee enterprise down to under 3,000 and passed one of the earliest DIBCAC assessments. Steven and George get into what the CMMC pause has actually meant for clients on the ground, why most organizations are staying the course, and what they both expect to come out of the 60 day review: harmonization across agencies, more intentional application of C3PAO assessments, machine readable assessment data, and a serious look at NIST SP 800-171 Rev 3. George breaks down the three new Rev 3 domains, why supply chain risk management will catch organizations off guard, how ODPs and ODVs could change, and why beautiful documentation (“compliance poetry”) does not mean you are ready for an assessment. They also cover Perezdiaz LLC’s internal audit approach to readiness, mock assessments, compensating controls, and the free self assessment tools George is building that export to JSON and plug into GRC platforms like IntelliGRC. Connect with George: perezdiaz.com | cmmc@perezdiaz.com | George Perezdiaz on LinkedIn
🎧 Subscribe for more conversations on CMMC, GRC, and the Defense Industrial Base.
