About Course
Understanding CMMC requirements is only the beginning. Defense contractors must be able to demonstrate that security controls are properly scoped, implemented, documented, tested, and supported by reliable evidence.
The CMMC 2.0 Readiness Course from Akitra Academy is a practical, implementation-focused course designed to help defense contractors move from CMMC requirements to assessment readiness.
Rather than providing another high-level introduction to CMMC, this course focuses on the operational work required to protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI), implement NIST SP 800-171 requirements, prepare evidence, identify gaps, and maintain continuous readiness.
Whether you are preparing for a self-assessment or a C3PAO assessment, this course gives you a structured roadmap for building a defensible CMMC program.
What You’ll Learn
By completing this course, you’ll learn how to:
- Determine your CMMC level and assessment path based on FCI, CUI, and contractual requirements.
- Define your CUI boundary and identify systems, users, applications, cloud services, and third-party dependencies.
- Turn NIST SP 800-171 requirements into repeatable operational security controls.
- Build and maintain an accurate System Security Plan (SSP).
- Create a structured control-to-evidence architecture for assessment readiness.
- Perform CMMC readiness assessments using evidence sampling, interviews, and technical validation.
- Understand SPRS scoring and manage remediation through POA&Ms.
- Maintain readiness through access reviews, vulnerability management, configuration monitoring, and evidence refresh.
- Use automation and AI to continuously monitor controls, identify gaps, and streamline evidence management.
Who Should Take This Course?
This course is designed for professionals responsible for CMMC implementation and readiness, including:
- Defense contractors and subcontractors
- CMMC and compliance program managers
- CISOs and security leaders
- GRC professionals
- IT and cybersecurity teams
- Government contracting teams
- MSP and managed security teams supporting defense contractors
- Organizations preparing to handle FCI or CUI
Frequently Asked Questions
Who should take this CMMC 2.0 course?
This course is designed for defense contractors and subcontractors, CISOs, security teams, GRC professionals, compliance managers, IT teams, and service providers responsible for protecting FCI or CUI and preparing organizations for CMMC assessments.
Does this course cover CMMC Level 1 and Level 2?
Yes. The course explains how FCI and CUI influence CMMC applicability, how to determine the appropriate CMMC level and assessment path, and how organizations preparing for Level 2 can operationalize NIST SP 800-171 security requirements
What will I learn about CUI scoping?
You'll learn how to discover where CUI exists, map CUI data flows, identify in-scope assets, evaluate cloud and third-party dependencies, define CUI enclaves, use segmentation, and document security responsibilities.
Does the course cover NIST SP 800-171 implementation?
Yes. You'll learn how to turn NIST SP 800-171 requirements into operational controls covering areas such as identity and access management, MFA, privileged access, encryption, configuration management, logging, vulnerability management, and incident response.
Will I learn how to prepare for a CMMC assessment?
Yes. The course covers readiness and gap assessments, evidence sampling, technical validation, stakeholder interviews, control testing, documentation gaps, implementation gaps, remediation, and assessment preparation.
Does the course cover SSPs, SPRS, and POA&Ms?
Yes. You'll learn how to build and maintain a System Security Plan (SSP), understand NIST SP 800-171 assessment scoring and SPRS reporting, and manage permitted POA&Ms through clear ownership, deadlines, remediation, and closure evidence.
Course Content
Scope Your CMMC 2.0 Environment
-
Define the CUI Boundary & System Scope
00:00 -
Determine Your CMMC Level & Assessment Path
00:00