On Demand
A Practical Guide to CMMC Implementation & Certification: Expert Perspectives From Advisory to Assessment
Overview
Achieving the Cybersecurity Maturity Model Certification (CMMC) requires far more than checking off controls. It demands clear scoping, disciplined implementation, and a realistic understanding of the assessment process.
In this joint session from risk3sixty and Schellman, we will explore the CMMC certification journey from implementation to certification.
Drawing on perspectives from both advisory and assessment experts, the session will share practical insights into what CMMC implementation really entails and how to avoid common pitfalls in the CMMC process.
What to Expect:
- CMMC Overview: Framework requirements, levels, timelines.
- CMMC Implementation: Practical steps, scoping, what to avoid.
- CMMC Assessment and Certification: What to expect, how assessors think, common pitfalls to avoid.
Get the session instantly by email
Meet the Presenters
Andrew Parks
Manager, Advisory and Assurance
Andrew Parks is a Manager on the Advisory and Assurance team at risk3sixty, specializing in Payment Card Industry (PCI) and CMMC compliance. He has served as a PCI Qualified Security Assessor (QSA) for more than five years and previously held the role of PCI Internal Security Assessor (ISA), bringing his total PCI experience to over a decade.
More recently, Andrew has obtained the CMMC certification of Registered Practitioner (RP).Andrew leverages a strong technical background in his work as both a PCI QSA and CMMC advisor. He holds certifications in cloud technologies and Kubernetes (KCNA), enabling him to effectively support clients operating in complex technical environments to achieve and maintain compliance.
Joey Braido
Principal Consultant, Advisory and Assurance
Joey Braido is a Principal Consultant at risk3sixty, where he helps organizations align security and privacy initiatives and strengthen data protection programs. With a foundation in quality and regulatory practices from the pharmaceutical and medical device industries, he brings a practical, risk-based perspective to cybersecurity compliance.
Joey has over 12 years of experience spanning quality, regulatory, and security domains. He currently specializes in CMMC, ISO 27001, and ISO 27701, supporting clients across implementation, readiness, and alignment with business objectives.
Marci Womack
Managing Director, Federal Practice at Schellman
Marci Womack is a Managing Director in Schellman’s federal practice and oversees the emerging CMMC assessment program, the established FedRAMP assessment program, and related areas such as StateRAMP, FISMA, and other NIST 800-53 derivatives such as CJIS and MARS-E.
Marci is on the Cyber AB C3PAO Advisory Council and she previously served a 2-year term as the FedRAMP 3PAO representative on the Federal Secure Cloud Advisory Committee (FSCAC). Marci has over 12 years of information security experience across various industries and holds key certifications, including CISSP, CISA, CEH, and CMMC Lead CCA.
Jay Molnar
Manager, Federal Practice at Schellman
Jay Molnar is a Manager in Schellman’s Federal Practice based in Washington, DC, where he focuses on the emerging CMMC program.
Prior to joining Schellman in 2021, Jay served as a Senior with Ernst & Young’s Government Contract Services, specializing in NIST SP 800-171 and CMMC compliance. He played a lead role in piloting early DIBCAC High Confidence Assessments under the Joint Surveillance Voluntary Assessment (JSVA) program and continues to support the program as a lead assessor.
Jay holds several key certifications, including CISSP, CISA, CMMC Lead CCA, and CCP.
Raving Fans
Positive Business Outcomes
See how Platform.sh saved 75% by harmonizing SOC 2, PCI DSS, and HIPAA.

Joey Stanford
VP of Security & Privacy
Salesloft obtained certification across SOC 2 and ISO 27001 in one harmonized workstream.

Mike Meyer
SVP of Security
Fullstory harmonized 10 frameworks and becomes ISO 42001 early adopter

Anne Turner
Director of GRC
Powered By

It’s like hiring a whole team of consultants, but in a platform
We bring the right people, playbooks, and platform to scale your security compliance program.







