Blog cover

Perry Johnson Registrars

Blog

Preparing for the Change – Transition to ISO 9001:2026

9/23/2026
A sticky note with FAQ on it stuck on a paper with charts and question marks

Preparing for the Change – Transition to ISO 9001:2026 As everyone in the quality game is aware, the world now has a new version of ISO 9001. ISO standards touch almost everything we do, and they help to make the…

Read more

Preparing for the Change – Transition to ISO 9001:2026

As everyone in the quality game is aware, the world now has a new version of ISO 9001. ISO standards touch almost everything we do, and they help to make the world a safer and more efficient place. This drives the need to evaluate the effectiveness of the standard and make changes to drive continual improvement within our own organizations and industrywide.

The task of understanding the revised standard’s effect on your organization can be overwhelming. We at PJR want to ease our clients and potential clients into this new standard and have composed this simplified FAQ to address some of the most pressing questions and address what steps can be taken now to prepare for the coming change. In addition to this FAQ, PJR also offers an overview of changes via our ISO 9001:2026 webinar, with easy registration available at https://www.pjr.com/upcoming-webinars.

ISO 9001:2026 FAQs

Why is the ISO 9001 standard changing again?

The primary reason for the revision to ISO 9001 on this occasion is the update that took place earlier to the High-Level Outline (Annex SL) by the ISO. The most important change that took place at that level was the introduction of the concept of “culture.” In ISO 9001 this concept manifests as “Quality Culture.” This requirement has been sprinkled throughout ISO 9001 (appearing 13 times overall including 4 references in the auditable portion.) The basic concept can be boiled down to the idea that an ISO 9001 certified company should seek to make their quality management activities a “culture” or an embedded part of company life. The other significant update on this revision is the introduction of climate change language in the high-level outline. We’ve provided a separate Q&A below for this item.

What is the expected timeline?

The new standard was published on September 16, 2026. The GAC (this is the organization that manages ISO 9001 certifications from a high-level perspective) has indicated that they will allow a three-year transition period and will use the “end of the month” markers for the important deadlines. This means that the ISO 9001:2015 standard will become obsolete on September 30, 2029. As a result, all ISO 9001:2015 certifications issued in late 2026 and beyond will have to bear an expiry date of September 30, 2029.

Companies will be permitted to gain a new certification (either through a Stage 2 or Recertification audit) to ISO 9001:2015 through March 30, 2028 (this represents the halfway point of the transition timeline.) Companies will technically be permitted to perform surveillance audits to ISO 9001:2015 through September 30, 2029 – but PJR will cease offering audits of any kind to ISO 9001:2015 on June 30, 2029.

My audits are normally due in late July, and the transition period ends in September. Why can’t my company have its transition audit in late July 2029?

While it is true that the transition period does not end until September 30, 2029, it is not just required that your audit is conducted by this date. If any nonconformities are discovered during the audit, they must be addressed with corrective action, and PJR’s Executive Committee (decision-making body) must review and approve the audit package by the transition deadline. A late July 2029 audit likely does not provide enough time for this to happen. Thus, your organization could transition in July 2027, July 2028 or choose to have an earlier audit in 2029, perhaps May or June, to allow adequate time for completion of the post-audit process.

All transition audits must be completed within 90 days of the transition end date of September 30, 2029. Thus, all transition audits must be completed by June 30, 2029.

My organization is not yet certified. We have been working at implementing ISO 9001:2015 for a while. Can we still seek certification to the 2015 version of the standard and then transition later?

PJR appreciates that a lot of work may have gone into preparing for certification to ISO 9001:2015. Per the GAC requirements we will allow initial audits to the 2015 version of the standard until eighteen months into the transition period, or March 30, 2028.

Keep in mind that ISO 9001:2015 will be obsolete on September 30, 2029. Therefore, the expiration date on any 2015 certificate issued after the publication of ISO 9001:2015 will be September 30, 2029. Thus, it may appear that your organization is not being granted a full, three-year certificate. However, after successful transition to ISO 9001:2026, the expiry date of your certificate will be amended to reflect a full three-year certification.

What if we have a Recertification audit in early 2027, should we just plan on performing that audit to ISO 9001:2026?

This will be a strategic decision that each company makes on its own, but there are a few key points to bear in mind.

  • If you have had a chance to examine your quality system against the revised requirements and feel that you are ready, you can certainly request that your upcoming recertification audit be performed to ISO 9001:2026.
  • Timing the transition to your regular recertification audit is ideal, but not in any way mandatory.
  • You could certainly perform your 2027 Recertification Audit to ISO 9001:2015 and then complete a transition audit to ISO 9001:2026 in 2028 or 2029.

Is it better to transition earlier?

As described in the question above, it is important to avoid waiting until the last minute. However, there is no difference if you transition in April 2027, April 2028 or April 2029, for example. An ISO 9001:2015 certificate is still valid until the end of the transition period. In no way should an ISO 9001:2026 certificate be perceived as better than an ISO 9001:2015 certificate until the obsolescence date of that standard.

What happens if my organization doesn’t transition on time?

If your organization does not have a transition audit prior to the end of the transition period/obsolescence date of ISO 9001:2015, then you will no longer be certified as of the end of the transition period. To become certified to ISO 9001:2026, you will need to start over with an initial audit (Stage 1 and Stage 2).

If your organization does have its transition audit but the audit package is not closed prior to the end of the transition period/obsolescence date of ISO 9001:2015, then an ISO 9001:2026 certificate will be issued as soon as the package can be closed. This means that there will be a lapse in your certification status. Our Scheduling Department will work with you to ensure the timely scheduling of any transition audits that occur later in the transition period to avoid this unfortunate situation.

What are the critical changes?

PJR has prepared a separate presentation showing an overview of the changes to the standard. The summation of that report can be stated as follows: “nothing of significance.” The Quality Culture and Climate Change updates are frankly the only updates of any minor impact. There are other more nuanced changes, but none of these should have any significant impact for a company already certified to ISO 9001:2015.

What is Annex SL, and what does it have to do with ISO 9001?

Annex SL is a portion of the “ISO/IEC Directives Part 1 – Procedures for the technical work – Consolidated ISO Supplement – Procedures specific to ISO” document. This standard regulates and controls the process of developing, updating, and issuing ISO published standards.

The full text of Directives Part 1, including the Annex SL portion can be found here: https://www.iso.org/sites/directives/current/consolidated/index.html

Annex SL can be thought of as a ten-section blueprint to be used for all ISO standards. It promotes (among other things) common terms and core definitions for many of the terms used in the ISO family of standards. It is through the mandatory structure of Annex SL that organizations will be better enabled to achieve multiple certifications such as ISO 9001, ISO 14001, and ISO 45001, because each of these standards will have the same 10 sections and the same core terms and definitions.

We’ve already been certified for a long time, and our procedures are well implemented, do we have to change them?

PJR’s analysis has concluded that for the average ISO 9001:2015 certified company, the impact of the revised standard will be minimal and quite manageable. It is important to bear in mind that the ISO is seeking greater inclusion for the ISO 9001 standard. They want to see it continue to grow into new sectors and be even more user friendly than it is now. Requiring a company to aggressively overhaul their current ISO 9001:2015 system is not consistent with this objective.

Tell me more about the new “Climate Change” requirement

This requirement actually isn’t new. It was originally published as an officially binding addendum to ISO 9001:2015 in 2024. Despite what some sources are claiming, the “climate change” requirements are very minimal in ISO 9001:2026. They can be summarized thusly:
All ISO 9001 certified companies must consider Climate Change as a potentially relevant issue to their quality management system and act accordingly.

Note that it is absolutely possible for an organization to conclude that climate change has no bearing on them or their interested parties – PJR just needs to be able to see evidence of how that decision was reached.

Will our staff have to complete transition training?

It will depend on the extent of revisions that you make to your quality management system, but generally yes, you will be expected to provide some form of transition training to your staff.

At a minimum, PJR would expect that awareness training of the new standard would be provided, as well as an assessment of the new standard’s impact on the various processes and personnel. However, it is entirely conceivable that the majority of your staff will feel no effect from your company’s transition to ISO 9001:2026.

What about our internal auditors, will they have to complete transitional training?

Internal auditing is viewed in the same light as any other required competency within a quality management system. Namely, the organization is responsible for determining what competencies are required for its internal auditors, as well as the methods to be used to achieve those competencies.

To put it more plainly, each organization will have to decide on its own the extent to which transition training will be needed. It is conceivable that a seasoned team of internal auditors could complete a period of self-study and successfully transition to auditing ISO 9001:2026. As has always been the case, the competency of your internal auditors will be judged by the overall effectiveness of your internal audit process.

Will the other standards (AS9100, IATF 16949, etc.) be updated also?

All of the major sector specific standards, including IATF 16949, AS9100, and TL9000 have indicated their intentions to transition and continue their alignment with ISO 9001. The timelines for these other standard updates are not fully known at this time, but a 2026 or 2027 publication date seems likely for all three. At present the only major standard that is not planning to update is ISO 13485:2016.

What steps can we take right now?

PJR recommends the following steps be taken in a transition to ISO 9001:2026:

  1. A full review of the ISO 9001:2026 standard should be performed by Top Management to identify the gaps that need to be addressed.
  2. A plan of implementation should be developed with assigned responsibilities.
  3. All quality management system documents (including the quality and procedures manual, if applicable) should be updated to reflect any new or revised processes.
  4. All necessary awareness and transition training should be completed.
  5. A full system internal audit followed by a Management Review should be complete.
  6. Corrective Actions for all internal audit findings should be in process or complete.
  7. Coordinate with PJR for planning of transition arrangements.

Will extra audit time be needed for my transition audit?

Potentially and only if you plan on transitioning on a surveillance audit. This is based on guidance provided by the GAC which states the following: “In determining if additional audit time is needed, the certification body shall consider, at a minimum, the degree of change to the client’s management system.”

If you plan to transition as part of a surveillance audit you can expect to receive a short pre-audit questionnaire from PJR that will enable us to ascertain how much of an impact ISO 9001:2026 has had on your quality management system. Because surveillance audits are typically shorter in duration than recertification audits, and based on what we learn from the questionnaire, we may conclude that a small measure of added time is needed.

If you plan to transition as part of a recertification audit PJR has concluded that no additional time will be needed.

Our organization is considering transferring our accredited ISO 9001:2015 certification to PJR. How does the transition timeline impact our plans to transfer?

The requirements will be the same whether you are a currently certified PJR client or a transfer candidate. PJR will transfer an ISO 9001:2015 certificate until March 30, 2028. Subsequent to this date, we cannot guarantee that all transition activities will be completed prior to the transition deadline.

These helpful ISO 9001 transition FAQ’s are also be available via download.

Should you have further questions or require assistance please contact PJR for a Project Manager.
Website: www.pjr.com • Phone: (248) 358-3388 • Email: pjr@pjr.com

ISO 9001:2026: What’s Changed (Not Much), and What Has Stayed the Same (A Lot)

8/3/2026
Group of businesspeople holding jigsaw puzzles, team solving and planning together

ISO 9001:2026: What’s Changed (Not Much), and What Has Stayed the Same (A Lot) A plain-language guide to the upcoming revision, from Perry Johnson Registrars, Inc. If you hold, or are pursuing, an ISO 9001 certification, you’ve likely heard about…

Read more

ISO 9001:2026: What’s Changed (Not Much), and What Has Stayed the Same (A Lot)

A plain-language guide to the upcoming revision, from Perry Johnson Registrars, Inc.

If you hold, or are pursuing, an ISO 9001 certification, you’ve likely heard about the upcoming 2026 revision. Perry Johnson Registrars, Inc. (PJR) recently hosted a webinar breaking down what’s on the horizon. The short version: change is coming, but it’s evolutionary, not revolutionary.

A Quick Refresher: Where ISO 9001 Comes From

ISO standards are developed by dedicated Technical Committees. For ISO 9001, that’s Technical Committee 176 (TC 176), which draws members from major industrialized nations, including the American National Standards Institute (ANSI).

A significant portion of the standard’s content is mandatory boilerplate defined by Annex SL, the shared structure that allows ISO 9001 to align with other management system standards.

Where Things Stand: Timeline Update

ISO/FDIS 9001 (Final Draft International Standard) was issued for review and approval voting in May 2026, the last formal step before publication. Earlier milestones:

  • Committee Draft released in April 2024
  • Draft International Standard (DIS) released in June 2025

Publication is expected in September or October 2026. Once published, existing ISO 9001:2015 certifications remain valid for three years.

What’s Staying the Same

The most reassuring takeaway from PJR’s analysis is how much is not changing. Specifically, ISO 9001:2026:

  • Maintains the familiar 10-section auditable structure and section titles used in ISO 9001:2015.
  • Keeps the same minimal documentation requirements; no procedures are mandated.
  • Preserves the process approach that has anchored ISO 9001 since the 2000 revision.
  • Retains the Plan-Do-Check-Act (PDCA) methodology.
  • Introduces no new substantive terminology or definitions beyond what already exists in the 2015 version.
  • Keeps every concept introduced in 2015 fully intact: Risk, Interested Parties, Internal/External Issues, Organizational Knowledge, and Manageent Accountability all remain.

What’s Actually Changing

PJR’s review of the FDIS found few substantive changes, but they’re worth understanding.

Climate Change Language

This isn’t new. A February 2024 amendment added climate change considerations to sections 4.1 and 4.2, and that language carries forward unchanged. Organizations must consider whether climate change is a relevant issue to their quality management system and be able to show the reasoning, even if the answer is “it isn’t relevant to us.”

The Rise of “Quality Culture”

The phrase “Quality Culture” now appears throughout the standard. The idea is straightforward: quality shouldn’t be a checklist exercise; it should be woven into how a company operates day to day. It surfaces in several auditable clauses:

  • Clause 4.1 ties “culture” to the existing concept of organizational “context.”
  • Clause 5.1.1 assigns Top Management responsibility for promoting and empowering a quality culture.
  • Clause 7.1.4 links quality culture to an organization’s environmental factors (social, physical, etc.).
  • Clause 7.3 requires organizations to ensure employees are aware of the quality culture.

“Quality Culture” appears in nine additional places within the FDIS, and final wording may shift before publication.

A Possible Tweak to Your Quality Policy

Clause 5.2.1(e) now requires that an organization’s quality policy “take into account the context of the organization and support its strategic direction.” Most companies already meet this, but it’s a good opportunity to revisit your policy and confirm it still fits.

Risk Triggers Get a Clearer Definition

Clause 6.1.2 now states that organizations must determine, analyze, and evaluate risks affecting their ability to consistently deliver conforming products and services. This clarifies original intent rather than introducing something new.

“Opportunities” Gets Its Own Clause

Previously bundled with Risk, “Opportunities” now has its own clause 6.1.3. The wording mirrors 6.1.2, but the message is clear: risks and opportunities are distinct, and organizations should be ready to explain how each is addressed.

Documented Information Language Shifts Again

ISO 9001:2015 replaced the plain terms “document” and “record” with “documented information,” distinguished only by the verbs “maintain” and “retain.” The 2026 revision doesn’t simplify this; it introduces new phrasing instead:

  • “…shall be available as documented information” implies a document requirement.
  • “Appropriate documented information shall be available as evidence of…” implies a record requirement.

The key word to watch for going forward is “evidence,” which is now the separator between the two.

Customer Communication Adds Contingency Planning

Clause 8.2.1 now requires organizations to communicate with customers about agreed-upon responsibilities for contingency actions, where relevant. Specific guidance is expected after publication.

Social Media as a Customer Satisfaction Input

A new note to clause 9.1.2 recognizes social media as a legitimate source for gauging customer perception. How organizations monitor and act on this will vary by industry and company size.

Other Notable Smaller Changes

  • Clause 5.3: Top Management must now assign responsibility for reporting on opportunities for improvement.
  • Clause 6.3 adds non-binding guidance on planning and executing changes effectively.
  • Clause 8.4.3 adds an “as appropriate” qualifier to purchase order information requirements.
  • Clause 10.2.1 clarifies (via a note) that customer complaints remain a potential, not mandatory, input to Corrective Action.

Annex A Guidance Expands Significantly

Annex A, the non-enforceable guidance portion of the standard, grows from roughly two pages to eleven and has been renumbered to align with the main clause numbers. Nothing in Annex A is auditable, but it now offers expanded guidance on structure and terminology, leadership and commitment, risks and opportunities, and management review intervals.

The Bottom Line: Minimal Disruption Expected

PJR’s conclusion is simple: the substantive changes are minimal, and organizations certified to ISO 9001:2015 should find the shift manageable. PJR does not anticipate changes to its audit process, including the Leadership Interview. A handful of new prompts may be added to audit documentation, but core auditing practices will remain consistent.

How Will the Transition Work?

A three-year transition period will begin once ISO 9001:2026 is formally published. In practical terms:

  • Any organization certified to ISO 9001:2015 after the 2026 standard publishes will receive a certificate valid for less than three years. If the standard publishes October 2, 2026, a company certified December 2, 2026 would receive a certificate expiring October 1, 2029.
  • PJR intends to offer ISO 9001:2026 audits within weeks of publication, prioritizing organizations whose certificates expire between October 2026 and January 2027.
  • Organizations with certificates expiring in 2027 will need to decide how to proceed; recertifying to ISO 9001:2015 first means the transition occurs during a surveillance audit.

PJR has not set a date for when it will stop offering ISO 9001:2015 certifications; that decision likely won’t be finalized until mid-2027.

Will Staff and Internal Auditors Need Training?

In most cases, yes, though the scope depends on how much your quality management system actually changes. At a minimum, PJR recommends awareness training plus an assessment of the standard’s impact on your processes and personnel. Many employees will notice little change day to day.

For internal auditors, the expectation is the same as with any required competency: your organization determines what’s needed. A seasoned team may be able to transition through self-study alone.

Looking Ahead

ISO 9001:2026 continues a standard with nearly 40 years of history. The publication date is still a few months away, but the direction is clear: organizations already doing quality management well won’t need to reinvent their systems. A thoughtful review of your quality policy, risk and opportunity processes, and documentation language will go a long way toward a smooth transition.

PJR will continue to share updates, articles, and webinars as ISO 9001:2026 moves toward publication, and we’re committed to making the transition as smooth as possible.

Contact Perry Johnson Registrars, Inc.
Website: www.pjr.com • Phone: (248) 358-3388 • Email: pjr@pjr.com

CMMC Phase 2 Is Paused. Your Cybersecurity Obligations Are Not.

7/31/2026
Data security on a tablet with touchscreen technology and a hand with a finger pointing at it

CMMC Phase 2 Is Paused. Your Cybersecurity Obligations Are Not. What the Department of Defense review means for contractors handling Controlled Unclassified Information (CUI) and why this is the wrong moment to slow down. The Department of Defense has temporarily…

Read more

CMMC Phase 2 Is Paused. Your Cybersecurity Obligations Are Not.

What the Department of Defense review means for contractors handling Controlled Unclassified Information (CUI) and why this is the wrong moment to slow down.

The Department of Defense has temporarily suspended implementation of CMMC Phase 2 while conducting a 60-day review of the program. Understandably, the announcement has raised questions across the Defense Industrial Base: What happens to our certification timeline? Do we still need to invest in compliance right now?

The timeline may be changing. The underlying requirements are not.

What Has Not Changed

Organizations that handle CUI are still required to meet NIST SP 800-171 and comply with applicable DFARS 252.204-7012 requirements. Self-assessments, accurate SPRS reporting where required, and strong day-to-day cybersecurity practices all remain essential to supporting government contracts.

– A pause in the certification process is not a pause in the obligation to protect sensitive information.

Check Your Contracts Before You Change Your Plans

It is also worth remembering that the Department of Defense is not the only party setting expectations. Some prime contractors continue to require third-party CMMC certification or assessments as a condition of doing business, and those contractual requirements may remain in effect regardless of the Phase 2 pause.

Before adjusting any compliance plan, review your active contracts and confirm your customers’ current expectations directly. A program-level pause does not automatically release you from a commitment you have already signed.

Use The Pause As An Opportunity

We encourage organizations to treat this review period as time gained rather than time off. Improving policies, implementing technical controls, training employees, and documenting processes will continue to deliver value regardless of how the CMMC program ultimately evolves, and every one of those efforts reduces real risk in the meantime.

Self-attestation Carries Real Weight

As certification timelines shift, many organizations may need to self-attest to their compliance with NIST SP 800-171. Because these attestations carry significant responsibility for company leadership, they should be supported by objective evidence and, wherever possible, an independent evaluation.

That is why we continue to recommend:

  • Readiness Assessments – to measure overall preparedness.
  • Mock Audits – to simulate a formal CMMC assessment.
  • NIST SP 800-171 Gap Assessments – to identify and address compliance gaps.

How PJR Can Help

For organizations preparing to meet third-party certification obligations, Perry Johnson Registrars (PJR) is here to help. While PJR is not yet an authorized C3PAO and does not currently perform CMMC certification assessments, we can help with readiness and pre-assessment checks that are led by Lead CMMC Certified Assessors (LCCAs) using a structured, audit-based approach.

An independent assessment provides confidence that your compliance claims are accurate, well documented, and ready to withstand scrutiny. Whether you are preparing for future CMMC certification, supporting a self-attestation, or meeting a prime contractor’s third-party assessment requirement.

Moving Forward With Confidence

Our team will continue monitoring developments and sharing updates as they become available. Whether you are preparing for future certification or strengthening your cybersecurity program today, PJR is here to help you move forward with confidence.

To discuss a Readiness Assessment, Mock Audit, or NIST SP 800-171 Gap Assessment, contact Perry Johnson Registrars, Inc.

Client Spotlight: BruckEdwards, Inc.

7/16/2026
BruckEdwards, Inc. logo

BruckEdwards, Inc. – Delivering Secure Solutions That Go Beyond Expectations For more than two decades, BruckEdwards has been helping federal and commercial organizations secure, modernize, and optimize their operations through innovative technology and consulting services. Headquartered in Reston, Virginia, the…

Read more

BruckEdwards, Inc. – Delivering Secure Solutions That Go Beyond Expectations

For more than two decades, BruckEdwards has been helping federal and commercial organizations secure, modernize, and optimize their operations through innovative technology and consulting services. Headquartered in Reston, Virginia, the company specializes in mission-focused solutions that empower clients to meet today’s evolving security and operational challenges.

BruckEdwards provides solution engineering and operational support for Identity, Credential, and Access Management (ICAM) programs, secure physical and logical access control solutions, cybersecurity, IT service management, and program management support. Their experienced team works closely with clients to implement, operate, and sustain solutions that strengthen security while improving operational performance.

The Value of Certification

Two people sitting at a table looking at a laptopISO certification has played an important role in BruckEdwards’ continued growth and success. Together, certification to ISO/IEC 20000-1:2018, ISO/IEC 27001:2022, and ISO 9001:2015 has strengthened operational maturity, enhanced quality management practices, and reinforced a culture centered on continuous process improvement.

By standardizing business processes and focusing on risk management, performance measurement, and ongoing improvement, BruckEdwards continues to deliver exceptional project outcomes for its clients. Certification has also positioned the company to pursue additional federal contract opportunities where ISO certification is often a key requirement.

A Decade of Partnership with PJR

BruckEdwards has partnered with Perry Johnson Registrars for the past 10 years and values the collaborative relationship that has developed throughout that time.

The team describes their experience with PJR as a true partnership, highlighting the professionalism, knowledge, and positive approach demonstrated throughout every audit. Beyond maintaining a thorough audit process, PJR’s auditors provide valuable insights that help support continual improvement across the organization.

What Sets BruckEdwards Apart

BruckEdwards believes its greatest strength is its people. Rather than simply designing solutions, their team actively implements, operates, and sustains them for clients across the United States.

With employees supporting projects nationwide from its headquarters in Reston, Virginia, the company has built a reputation for solving complex challenges through collaboration, technical expertise, and a commitment to customer success.

Their culture is driven by accountability, employee empowerment, and a “yes we can” mindset that encourages every team member to go beyond expectations while creating lasting value for clients and the communities they serve.

Looking Ahead

As technology and cybersecurity continue to evolve, BruckEdwards is focused on expanding its capabilities in cybersecurity, Identity, Credential, and Access Management (ICAM), Zero Trust solutions, program management, and data analytics.

By strengthening strategic partnerships, expanding contract vehicles, and continuing to invest in innovation, BruckEdwards remains committed to delivering high-quality solutions that help clients confidently meet the challenges of tomorrow.


BruckEdwards, Inc. logo

Company Information

BruckEdwards, Inc.
12355 Sunrise Valley Drive, Suite 340, Reston, Virginia 20191
Phone: (703) 286-5311

PJR and First Defense CMMC – What You Need To Know About CMMC

7/2/2026

What You Need To Know About CMMC In this video, Terry Boboige, President of Perry Johnson Registrars, discusses CMMC readiness with Shannon Craddock, PJR Programs and Accreditation Manager Steve Jurovic, First Defense CMMC Mark Debry, First Defense CMMC The conversation…

Read more

What You Need To Know About CMMC

In this video, Terry Boboige, President of Perry Johnson Registrars, discusses CMMC readiness with

  • Shannon Craddock, PJR Programs and Accreditation Manager
  • Steve Jurovic, First Defense CMMC
  • Mark Debry, First Defense CMMC

The conversation focuses on what defense primary contractors and subcontractors should know before beginning the assessment process.

Viewers will learn

  • Why CMMC matters for organizations that handle Controlled Unclassified Information (CUI)
  • The role CMMC 3rd-Party Assessment Organizations (C3PAOs) play in the process
  • Why many small and mid-sized contractors need to start preparing early

For companies working with the Department of Defense, this conversation gives a clear overview of what to expect and how to avoid costly delays.

Key Topics Covered

  • CMMC requirements for DoD contractors
  • CUI and cybersecurity readiness
  • C3PAO third-party assessments
  • Mock assessments and scoping
  • Documentation and evidence
  • Common assessment pitfalls

Ready for CMMC? Learn more and get your process started!