I have recently started with a company that is looking to achieve CMMC L2 compliance. I have worked at other organizations that were already 'in the process' of gaining some level of compliance, but have never been in a position to 'start from scratch'.
There are so many vendors schlepping their services, so many websites with scattered information, etc. So, I guess my question is: Where in the heck does one even begin? I thought it was with "Start reading up on everything", but then the question is "when the heck do I stop reading?", heh.
I have been in IT for decades, but CMMC is a beast in and of itself.
[link] [comments]