# Jacob Anderson on How to Avoid Common CMMC Level 2 Mistakes

_CMMC Level 2 reaches well beyond email encryption and passwords. Jacob Anderson, Founder at Beyond Ordinary Software Solutions, walks through the areas that catch teams off guard, and what it actually takes to be assessment-ready._

CMMC Level 2 self-certification used to be a spreadsheet and a score. That’s not the case anymore. The process has changed, the requirements reach further than most teams expect, and the consequences of getting it wrong are big.

Jacob Anderson is the Founder at **Beyond Ordinary Software Solutions**, an RPO that helps defense contractors navigate CMMC implementation. He’s a CISSP, certified Registered Practitioner, and CMMC Certified Professional with over 40 years in software and cybersecurity.

Below, he shares what’s changed in recent years, what’s *at stake if you do CMMC the wrong way, and the five things you need to get right before the assessor shows up.*

## **Key Takeaways**

- CMMC Level 2 self-certification now requires stepping through each control individually with documented evidence
- Misrepresenting compliance status can lead to contract removal, debarment, and fraud enforcement
- Physical access, FIPs mode, and MFA are the gaps that catch most teams off guard

## How Self-Certification Has Changed

Contractors used to fill out a spreadsheet, get a SPRS score, upload it, and move on. Now the process requires stepping through each control individually, certifying you understand it, confirming you’ve implemented it, and attesting that it’s true.

> _“It’s the old adage of, it’s been working fine, I haven’t had an issue, so it must be fine. So I’m gonna check the box.”_ — Jacob Anderson

That mindset doesn’t survive the new process. And the standard itself goes further than most teams realize. It’s not just about electronic security. Physical access, encryption compatibility, personnel accountability, and evidence documentation are all in scope.

> _“Your cyber starts with the people. And physical access to all the stuff that the people have access to. So you need to start there and secure that.”_ — Jacob Anderson

## What’s at Stake

The consequences of misrepresenting your compliance status go beyond rework. The government is actively pursuing fraud enforcement against contractors who certify controls they haven’t actually implemented.

> _“They can remove you from a contract and debar you. That means you can’t compete on new task orders or contracts. You’re going to essentially disappear.”_ — Jacob Anderson

In Jacob’s words, the outcome of getting this right is simple: **staying in business.**

## Five Things to Get Right Before the Assessor Shows Up

These are the areas Jacob’s team works through with every contractor. They’re the gaps that make the biggest difference in how smoothly the assessment goes.

1. **Lock Down Physical Access**  
CMMC requires that the physical spaces where people access controlled data are secured and documented. That means key fob access control, entry logs, controlled access hours, and ongoing auditing.

2. **Enable FIPs Mode and Understand What Breaks**  
Handling CUI requires FIPs (Federal Information Processing Standards) compliance. On Windows, that means toggling FIPs mode on.

3. **Implement MFA Across the Board**  
Multi-factor authentication is a core requirement and one of the most common sources of friction.

4. **Build Your Evidence Packet**  
Self-certification now requires documented evidence for every control. You have to certify that you actually did the things, not that you intend to.

5. **Assign a Security Lead and Build Your Training Matrix**  
CMMC requires a specific person identified as responsible for security, trained and accountable, with a documented training matrix that’s actively maintained.

## The Bottom Line

CMMC Level 2 certification isn’t about checking boxes anymore. The process has changed, the stakes are real, and the gaps that catch contractors are the ones they haven’t mapped yet: physical access, FIPs compatibility, MFA, evidence documentation, and the people accountable for all of it.
