bR2bR Compliance Officer — DOD & Government Contracting
Run CMMC and DFARS readiness reviews on bRRAIn: scoped, evidence-bound, honest about status, ready for Phase 2.
- Level
- Expert
- Learning time
- 45 hours
- Price
- $499
- Credential
- Valid 3 years
What changed in this edition.
- bR2bR is now taught as an engagement method built from real bRRAIn mechanisms (recorded scope, two recorded approvals, Robo Compliance sealed sessions and the auditor portal's expiring share tokens, per-project Read grants, the hash-chained audit log). v1's Bind step, co-signatures, zero-exfiltration architecture and sandbox were not real and are gone.
- Regulatory content brought current: the 48 CFR CMMC acquisition rule, revised DFARS 252.204-7021 and the new 252.204-7025, and the phased rollout with Phase 2 (Level 2 C3PAO) beginning 10 November 2026.
- Corrected the basics v1 got wrong: assessments are against NIST SP 800-171 Rev 2 under Class Deviation 2024-O0013 (no engagement-letter choice), and Level 1 is 15 requirements.
- New modules on scoping, objective-level assessment across all fourteen Level 2 families, scoring with the DoD Assessment Methodology, POA&M eligibility and Conditional status, and briefing Affirming Officials and contracting officers.
- The daily method is now MCP-first (start_brain_session, record_decision, record_learning) with records visible in Nexus → Memory; open.md and closure.md remain only as the git variant.
- Every lab is an AI role-play with a published rubric (auditee CISO, C3PAO lead assessor, contracting officer and more), plus a capstone closing meeting scored against a published rubric and four anchor exemplars.
- Re-levelled to Expert: 45 hours, a 60-item LOFT exam with six AI-conducted performance tasks, provisional pass mark 75.
What you will be able to do.
- You will be able to determine which CMMC level, assessment type and DFARS clauses apply to a contract, and plan backwards from the Phase 2 date and the expected award.
- You will be able to scope an assessment boundary for FCI and CUI, including service providers, cloud services and the organization's own bRRAIn deployment and AI models.
- You will be able to set up, run and close a bR2bR engagement between two bRRAIn organizations with recorded scope, two recorded approvals, sealed evidence, expiring access and a complete audit trail.
- You will be able to assess Level 1 and Level 2 requirements at the assessment-objective level using examine, interview and test, with evidence you can cite.
- You will be able to verify DFARS 7012 incident-reporting, cloud and SPRS posture and explain where NIST SP 800-171 Rev 3 fits.
- You will be able to use an AI co-pilot under the bRRAIn session method while detecting and correcting its compliance-specific failure modes.
- You will be able to write findings, estimate a score, determine POA&M eligibility and Conditional status, and plan remediation against the rollout timeline.
- You will be able to brief executives, the Affirming Official and contracting officers accurately, without overclaiming status.
Who it's for
- Compliance officers and CISOs at defense-industrial-base contractors preparing for CMMC assessments
- Consultants and audit firms running CMMC readiness (mock) assessments for primes and subcontractors
- Supplier-risk teams at primes assessing subcontractors' CMMC and DFARS posture
- Internal audit leads at federal contractors
Not covered here
- Conducting CMMC certification assessments (requires an authorized C3PAO and CMMC Certified Assessors, or DCMA DIBCAC at Level 3)
- ITAR and EAR export-control law (counsel-led)
- Classified systems
- Other industry overlays: financial (compliance-financial), healthcare (compliance-healthcare), energy (compliance-energy)
14 modules, 140 lessons.
About 45 hours of learning. Open a module to see every lesson.
-
The role, the CMMC program and the limits of this credential
What a DOD compliance officer does, how CMMC Levels 1-3 and the assessment ecosystem work under 32 CFR 170, and where readiness work ends and certification begins.
- Module 1 pretest
- The DOD compliance officer's job: engagement types and the readiness boundary
- CMMC Levels 1, 2 and 3 under 32 CFR 170
- The CMMC ecosystem: DoD CIO, Cyber AB, C3PAOs, CCAs and DIBCAC
- Status, affirmation and liability: Conditional, Final and the Affirming Official
- The assessor's standard of care: independence, skepticism and documentation
- What you can and cannot say: readiness opinions versus certification claims
- Lab 1: Set the terms of a readiness engagement with a DIB CEO
- Lab 2: Hand-off conversation with a C3PAO lead assessor
- Retrieval: Module 1 check
-
Contract clauses and the CMMC rollout timeline
How FAR 52.204-21 and the DFARS 7012/7019/7020/7021/7025 family put cybersecurity obligations into contracts, why assessments use NIST SP 800-171 Rev 2, and how to plan against the phased rollout, with Phase 2 beginning 10 November 2026.
- Module 2 pretest
- FAR 52.204-21 and FCI: the fifteen basic safeguards
- The DFARS clause family: 7012, 7019, 7020, 7021 and 7025
- The 48 CFR CMMC acquisition rule: revised 7021 and the new 7025
- The phased rollout: Phase 2 begins 10 November 2026
- Why assessments use NIST SP 800-171 Rev 2: Class Deviation 2024-O0013
- Flow-down: subcontractor levels, status checks and the prime's diligence
- Lab 3: Read a solicitation with the contracts manager
- Lab 4: Flow-down decisions with a prime's supplier-risk manager
- Retrieval: Module 2 check
-
Scoping FCI and CUI environments
Classify a contractor's information, categorize every asset, draw a testable boundary, test external service providers and decide where bRRAIn and its AI models sit relative to CUI.
- Module 3 pretest
- FCI, CUI and covered defense information: what triggers which obligation
- Level 2 asset categories: CUI, security protection, risk-managed, specialized, out of scope
- Boundaries and enclaves: drawing the assessment scope
- External service providers, cloud and the customer responsibility matrix
- The SSP, inventory and diagrams: scoping evidence an assessor will test
- Where bRRAIn sits in the boundary: CUI, hosting options and AI models
- Lab 5: Scoping workshop with an IT director
- Lab 6: Test a managed service provider's compliance claims
- Retrieval: Module 3 check
-
The bR2bR engagement method on bRRAIn
Run an assessment engagement between two bRRAIn organizations from real mechanisms: a recorded scope, two recorded approvals, sealed Robo Compliance sessions on expiring share tokens, narrow project grants, the audit and download logs, and a recorded close.
- Module 4 pretest
- bR2bR as a method: two bRRAIn organizations, one governed engagement
- The engagement scope spec: subject, framework, time window, evidence class, purpose and duration
- Dual approval and access grants on the auditee side
- Sealed sessions and the auditor portal: evidence an auditor can rely on
- Audit trail and termination: proving what the auditor saw, then closing the door
- Keeping the auditee's data in the auditee's bRRAIn
- Lab 7: Stand up a bR2bR engagement with the auditee's CISO
- Lab 8: A mid-engagement scope change
- Retrieval: Module 4 check
-
Running the engagement with your AI co-pilot
Use the MCP-first session method, framed prompts and the 'AI says no' discipline to produce evidence-bound determinations, pace a one-day review, keep records future audits inherit, and choose models by what the content is.
- Module 5 pretest
- The auditor's daily session: MCP-first memory for engagement work
- Context engineering for assessment work: requirement, objective, evidence, scope
- The 'AI says no' discipline: no finding without evidence
- The evidence walk: pacing a one-day readiness review
- Engagement records in the vault: decisions, learnings and working papers future audits inherit
- Choosing models for assessment work: the Handler, opt-in commercial models and CUI
- Lab 9: Drive an evidence walk with your AI co-pilot
- Lab 10: Working-paper quality review
- Retrieval: Module 5 check
-
Assessment methodology and CMMC Level 1
Read requirements precisely, reach MET, NOT MET and N/A determinations from NIST SP 800-171A objectives with examine, interview and test evidence, walk the fifteen Level 1 requirements, plan a Level 2 walk and set up Robo Compliance frameworks honestly.
- Module 6 pretest
- Reading a requirement: identifiers, NIST SP 800-171 Rev 2 and FAR sources
- Assessment objectives: why one unmet objective makes a requirement NOT MET
- Examine, interview, test: gathering evidence an assessor accepts
- Walking the fifteen Level 1 requirements
- Planning a Level 2 walk across fourteen families
- Loading the framework into Robo Compliance: templates, custom CSV frameworks and Crossmap
- Lab 11: Review a Level 1 self-assessment before the affirmation
- Lab 12: Assessment interview with a system administrator
- Retrieval: Module 6 check
-
Level 2 walk I: AC, AT, AU, CM and IA
Walk the 54 Access Control, Awareness and Training, Audit and Accountability, Configuration Management and Identification and Authentication requirements at objective level, finding the exceptions where determinations change.
- Module 7 pretest
- Access Control (AC): the twenty-two requirements an assessor tests first
- Awareness and Training (AT): proving people know their duties
- Audit and Accountability (AU): logs that answer who did what, when
- Configuration Management (CM): baselines, change control and least functionality
- Identification and Authentication (IA): identities, MFA and passwords
- Worked example: objective-level determinations for six requirements
- Lab 13: Walk AC and IA with the auditee's CISO
- Lab 14: Walk AU and CM with the IT operations lead
- Retrieval: Module 7 check
-
Level 2 walk II: IR, MA, MP, PS, PE, RA, CA, SC and SI
Finish the Level 2 walk against NIST SP 800-171 Rev 2: incident response, maintenance, media, personnel, physical, risk, security assessment, communications protection and system integrity, assessed objective by objective.
- Module 8 pretest
- Incident Response (IR) and Maintenance (MA)
- Media Protection (MP) and Physical Protection (PE)
- Personnel Security (PS) and Risk Assessment (RA)
- Security Assessment (CA): the SSP, POA&M and continuous monitoring
- System and Communications Protection (SC): boundaries, encryption and FIPS validation
- System and Information Integrity (SI): flaws, malicious code and monitoring
- Lab 15: Walk SC encryption and boundary requirements
- Lab 16: Walk PE and MP with the facilities manager
- Retrieval: Module 8 check
-
DFARS 7012, SPRS, cloud and the Rev 3 horizon
Verify DFARS 252.204-7012 incident handling and cloud use, calculate and defend SPRS scores under the DoD Assessment Methodology, and plan for NIST SP 800-171 Rev 3 while assessing against Rev 2.
- Module 9 pretest
- DFARS 252.204-7012 in depth: safeguarding, reporting, preservation and flow-down
- Worked scenarios: verifying a 72-hour incident report
- Cloud under 7012: FedRAMP Moderate and the equivalency standard
- SPRS and the DoD Assessment Methodology: Basic, Medium and High
- NIST SP 800-171 Rev 3: what changes and why it is not today's yardstick
- Organization-defined parameters: planning a Rev 3 readiness program
- Lab 17: Verify a DFARS 7012 incident report
- Lab 18: Cloud equivalency review with the CIO
- Retrieval: Module 9 check
-
Evidence and institutional memory
What an organization's recorded memory can prove, how history should shape a review, when evidence is too old, and how to build, verify and defend evidence chains a reviewer can re-walk.
- Module 10 pretest
- Institutional memory as assessment evidence
- Weighting prior incidents and prior assessments
- Evidence validity windows: when evidence is too old to rely on
- The evidence chain: locators a reviewer can re-walk
- Verifying sealed evidence: pod verify, offline verify and the audit log
- Worked review: an evidence package under challenge
- Lab 19: Weight twelve months of institutional memory
- Lab 20: The evidence that changed
- Retrieval: Module 10 check
-
AI failure modes in compliance work
Detect and correct the predictable ways AI drafts fail in assessment work (mis-cited requirements, fabricated evidence, scope creep, time confusion, revision and rule confusion, and overclaiming) with mechanical checks and recorded corrections.
- Module 11 pretest
- Failure mode: the mis-cited requirement
- Failure mode: the fabricated evidence reference
- Failure mode: scope creep mid-engagement
- Failure mode: timestamp and time-zone confusion
- Failure mode: revision and rule confusion (Rev 2 vs Rev 3, 17 vs 15, superseded clauses)
- Failure mode: overclaiming language in AI drafts
- Lab 21: Catch three induced AI failures
- Lab 22: Red-team an AI-drafted readiness report
- Retrieval: Module 11 check
-
Findings and scoring
Turn determinations into DOD-ready findings, a score estimate with its arithmetic, floor and coverage, a POA&M-eligibility analysis, and a readiness report with defined caveats and sign-offs that passes quality review.
- Module 12 pretest
- Finding classes and severity
- Writing a DOD-ready finding: requirement, objective, evidence, determination
- The requirements that decide the outcome: 5-point and POA&M-ineligible requirements
- Calculating a score with the DoD Assessment Methodology
- The readiness report: structure, caveats and sign-off
- Quality review of a findings package
- Lab 23: Defend your findings to the auditee's CISO
- Lab 24: Score and status conversation with the CFO
- Retrieval: Module 12 check
-
POA&M, remediation and communication
Turn findings into a CMMC POA&M and a dated remediation roadmap, then communicate the position accurately to executives, the Affirming Official and contracting officers, and close the engagement cleanly.
- Module 13 pretest
- The POA&M: eligibility, content and the 180-day clock
- Remediation roadmaps: priority, effort, dependencies and the Phase 2 date
- Briefing executives and the Affirming Official
- Talking to the contracting officer: notices, status changes and the 72-hour clock
- Supporting the affirmation decision without making it
- Closing the engagement: access, records, learnings and the regulatory watch
- Lab 25: Build the POA&M with the VP of operations
- Lab 26: Brief a contracting officer on a status lapse
- Retrieval: Module 13 check
-
Capstone and exam readiness
Prepare for and complete the capstone closing meeting, then prepare for the certification exam with practice scenarios, exam strategy and the distinctions that matter most.
- Module 14 pretest
- The capstone brief: what you will do and how it is scored
- Pacing a closing meeting: from evidence to decisions in forty minutes
- The readiness package: contents, records and caveats
- How the anchor exemplars were scored
- Practice scenarios with worked answers
- Exam strategy: LOFT forms, performance tasks and time
- Ten distinctions you must not blur
- Capstone: Closing meeting for a Level 2 readiness review
- Retrieval: Module 14 check
Practice against someone who pushes back.
Labs run in your browser as AI role-plays. An AI plays the person on the other side of the scenario — with their own goals and objections — and your work is scored against the published rubric. There is nothing to install.
-
Lab 1 · The role, the CMMC program and the limits of this credential
AI role-play with Dana Whitcomb, CEO of Kestrel Precision Machining (fictional): set the terms of a Level 2 (C3PAO) readiness engagement, refuse certification and score overclaims, and plan backwards to an April 2027 award
-
Lab 2 · The role, the CMMC program and the limits of this credential
AI role-play with Marcus Oyelaran, lead CCA at Ironbridge Assessments (fictional C3PAO): hand off a Brightwater readiness engagement accurately while protecting independence and evidence access
-
Lab 3 · Contract clauses and the CMMC rollout timeline
AI role-play with Teresa Lindqvist, contracts manager at Halvorsen Avionics (fictional): read a solicitation carrying DFARS 7025 at Level 2 (C3PAO) with a March 2027 award, judge eligibility, post-award obligations and a backwards plan
-
Lab 4 · Contract clauses and the CMMC rollout timeline
AI role-play with Gwen Achterberg, supplier-risk manager at Corvane Systems (fictional prime): set flow-down levels, verify status and plan monitoring for five subcontractors
-
Lab 5 · Scoping FCI and CUI environments
AI role-play with Luis Ferreira, IT director at Tamsin Composites (fictional): run a scoping workshop, reject an inadequate two-laptop enclave, categorize assets and propose a testable boundary
-
Lab 6 · Scoping FCI and CUI environments
AI role-play with Brooke Danforth, account manager at NorthGate Managed IT (fictional MSP): test 'we're CMMC compliant' and FedRAMP claims, scope the MSP's tools and people, and agree a request list including a customer responsibility matrix
-
Lab 7 · The bR2bR engagement method on bRRAIn
AI role-play with Elena Varga, CISO of a fictional defense electronics contractor: agree scope and design approvals and grants for a bR2bR readiness review
-
Lab 8 · The bR2bR engagement method on bRRAIn
AI role-play with Owen Mbeki, Access Controller: handle a co-pilot's request for HR project access mid-engagement
-
Lab 9 · Running the engagement with your AI co-pilot
AI role-play with Nadia Kowalski, engagement manager, and the firm's co-pilot: correct three co-pilot determinations with framed prompts and evidence locators
-
Lab 10 · Running the engagement with your AI co-pilot
AI role-play with Graham Holt, quality reviewer: answer eight working-paper review points before a readiness report is issued
-
Lab 11 · Assessment methodology and CMMC Level 1
AI role-play with Ray Dunmore, owner of Dunmore Fasteners (fictional, FCI only): review his Level 1 self-assessment, give evidence-based determinations and advise on the affirmation
-
Lab 12 · Assessment methodology and CMMC Level 1
AI role-play with Keisha Brandt, system administrator at Arcadia Optics (fictional): conduct an assessment interview on AC.L2-3.1.6, AC.L2-3.1.10 and IA.L2-3.5.3 and state preliminary objective-level determinations
-
Lab 13 · Level 2 walk I: AC, AT, AU, CM and IA
AI role-play with Victor Haas, CISO at Pellucid Sensors (fictional): walk six AC and IA requirements, resolve inheritance and N/A claims, and give preliminary objective-level determinations
-
Lab 14 · Level 2 walk I: AC, AT, AU, CM and IA
AI role-play with Mei Tanaka, IT operations lead at Pellucid Sensors (fictional): walk seven AU and CM requirements, address managed-provider and emergency-change positions, and prioritize remediation
-
Lab 15 · Level 2 walk II: IR, MA, MP, PS, PE, RA, CA, SC and SI
AI role-play with Andre Koval, network engineer at Granite Ridge Ordnance Systems (fictional): determine five SC requirements from boundary and CMVP certificate evidence and state the SC.L2-3.13.11 scoring and POA&M position
-
Lab 16 · Level 2 walk II: IR, MA, MP, PS, PE, RA, CA, SC and SI
AI role-play with Lorraine Bassett, facilities manager at Granite Ridge Ordnance Systems (fictional): determine PE and MP requirements from sampled records and observation and correct a POA&M misconception
-
Lab 17 · DFARS 7012, SPRS, cloud and the Rev 3 horizon
AI role-play with Jonah Petrakis, incident response lead at Saltmarsh Marine Systems (fictional): verify a past incident's 72-hour DIBNet report, DC3 handling, 90-day preservation and a subcontractor's reporting
-
Lab 18 · DFARS 7012, SPRS, cloud and the Rev 3 horizon
AI role-play with Farah Qureshi, CIO at Saltmarsh Marine Systems (fictional): give service-by-service FedRAMP Moderate authorization or equivalency determinations, residual responsibilities, and an accurate answer on bRRAIn hosting and AI models
-
Lab 19 · Evidence and institutional memory
AI role-play with Colin Ashby, compliance manager at Redfern Aerostructures (fictional): classify and weight twelve institutional-memory records and determine three RA and SI requirements
-
Lab 20 · Evidence and institutional memory
AI role-play with Hannah Okafor, IT manager at Redfern Aerostructures (fictional): respond to a pod Verify hash mismatch on a sealed session, set reliance and records, and re-base determinations
-
Lab 21 · AI failure modes in compliance work
AI role-play with Bernard Cole, engagement partner at a fictional assurance firm, who also voices the co-pilot's drafts: catch a mis-cited requirement, a fabricated evidence reference and scope creep through an unapproved grant, and correct the determinations
-
Lab 22 · AI failure modes in compliance work
AI role-play with Isabel Moreno, engagement partner who wants to send today: red-team an AI-drafted readiness report for a fictional antenna maker and produce send-ready rewrites
-
Lab 23 · Findings and scoring
AI role-play with Ruth Akande, CISO of a fictional machining contractor: defend five draft findings against pushback and re-determine one on new evidence
-
Lab 24 · Findings and scoring
AI role-play with Philip Grange, CFO and Affirming Official of a fictional machining contractor: present the score estimate, POA&M eligibility and status implications, and advise on SPRS, affirmation and contracting-officer statements
-
Lab 25 · POA&M, remediation and communication
AI role-play with Curtis Fairbanks, VP operations of a fictional foundry: classify eight findings, calculate the score and build the CMMC POA&M and must-fix plan
-
Lab 26 · POA&M, remediation and communication
AI role-play with Diane Mercer, a fictional DoD contracting officer: as the contractor's compliance officer, brief an expired Conditional status and commit to the 7021 written notice
-
Lab 27 · Capstone and exam readiness
AI role-play with Helena Strand (CISO) and Martin Calder (CEO and Affirming Official) of a fictional Navy circuit-board maker: the closing meeting of a Level 2 readiness review (capstone)
Closing meeting for a Level 2 readiness review (Calder Point Electronics, fictional)
AI role-play scored against the published rubric
Pass mark: 75%
Scored on
- Engagement governance and records15%
- Determinations and evidence25%
- Scoring, POA&M and status reasoning20%
- Regulatory accuracy and timeline15%
- Communication and integrity under pressure15%
- Remediation priorities and close-out10%
One exam. A credential anyone can verify.
The exam
- Items per form
- 66
- Time allowed
- 180 min
- Pass mark
- 75%
- Performance tasks
- 6
- Attempts included
- 2
- Wait between attempts
- 7 days
- Online and timed, taken on learn.brrain.io.
- Your form is assembled for you from the course's item bank, so no two candidates sit the same paper.
- Performance tasks are conducted by an AI examiner: you work through a realistic scenario and are scored against a published rubric.
The credential
- A verifiable digital badge in your name.
- A public verification page at learn.brrain.io/verify, so an employer or client can confirm it.
- Valid for 3 years.
- Renewal: At 3 years, by passing the then-current exam
Where this course sits.
Frequently asked.
Do I need to install anything for the labs?
No. Labs and the capstone run in your browser on learn.brrain.io as AI role-plays: an AI plays the person on the other side of the scenario, and your work is scored against the rubric published with the course.
How is the exam delivered?
Online and timed: 66 items in 180 minutes, on a form assembled for you from the course's item bank. 6 of the items are performance tasks conducted by an AI examiner: you do the work rather than pick an answer. The pass mark is 75%.
What if I don't pass first time?
You have 2 attempts, with a 7-day wait after an unsuccessful attempt. Further exam attempts can be bought for $299 each.
How long is the credential valid?
3 years. You receive a verifiable digital badge with a public verification page at learn.brrain.io/verify, so anyone can confirm it is genuine.
I hold the v1 credential. Is it still valid?
Yes. Credentials earned on v1 remain valid and verifiable at learn.brrain.io/verify. When you renew, you sit the then-current version of the exam.
Can my company enroll a team?
Yes. Firms can buy a certification bundle for $2,999 per firm per year — see the pricing page — or contact us to arrange enrollment for a larger group.
bR2bR Compliance Officer — DOD & Government Contracting
Run CMMC and DFARS readiness reviews on bRRAIn: scoped, evidence-bound, honest about status, ready for Phase 2.