bR2bR Compliance · Expert
v2.0

bR2bR Compliance Officer — DOD & Government Contracting

Run CMMC and DFARS readiness reviews on bRRAIn: scoped, evidence-bound, honest about status, ready for Phase 2.

Level
Expert
Learning time
45 hours
Price
$499
Credential
Valid 3 years
What's new in v2.0

What changed in this edition.

  • bR2bR is now taught as an engagement method built from real bRRAIn mechanisms (recorded scope, two recorded approvals, Robo Compliance sealed sessions and the auditor portal's expiring share tokens, per-project Read grants, the hash-chained audit log). v1's Bind step, co-signatures, zero-exfiltration architecture and sandbox were not real and are gone.
  • Regulatory content brought current: the 48 CFR CMMC acquisition rule, revised DFARS 252.204-7021 and the new 252.204-7025, and the phased rollout with Phase 2 (Level 2 C3PAO) beginning 10 November 2026.
  • Corrected the basics v1 got wrong: assessments are against NIST SP 800-171 Rev 2 under Class Deviation 2024-O0013 (no engagement-letter choice), and Level 1 is 15 requirements.
  • New modules on scoping, objective-level assessment across all fourteen Level 2 families, scoring with the DoD Assessment Methodology, POA&M eligibility and Conditional status, and briefing Affirming Officials and contracting officers.
  • The daily method is now MCP-first (start_brain_session, record_decision, record_learning) with records visible in Nexus → Memory; open.md and closure.md remain only as the git variant.
  • Every lab is an AI role-play with a published rubric (auditee CISO, C3PAO lead assessor, contracting officer and more), plus a capstone closing meeting scored against a published rubric and four anchor exemplars.
  • Re-levelled to Expert: 45 hours, a 60-item LOFT exam with six AI-conducted performance tasks, provisional pass mark 75.
Outcomes

What you will be able to do.

  • You will be able to determine which CMMC level, assessment type and DFARS clauses apply to a contract, and plan backwards from the Phase 2 date and the expected award.
  • You will be able to scope an assessment boundary for FCI and CUI, including service providers, cloud services and the organization's own bRRAIn deployment and AI models.
  • You will be able to set up, run and close a bR2bR engagement between two bRRAIn organizations with recorded scope, two recorded approvals, sealed evidence, expiring access and a complete audit trail.
  • You will be able to assess Level 1 and Level 2 requirements at the assessment-objective level using examine, interview and test, with evidence you can cite.
  • You will be able to verify DFARS 7012 incident-reporting, cloud and SPRS posture and explain where NIST SP 800-171 Rev 3 fits.
  • You will be able to use an AI co-pilot under the bRRAIn session method while detecting and correcting its compliance-specific failure modes.
  • You will be able to write findings, estimate a score, determine POA&M eligibility and Conditional status, and plan remediation against the rollout timeline.
  • You will be able to brief executives, the Affirming Official and contracting officers accurately, without overclaiming status.

Who it's for

  • Compliance officers and CISOs at defense-industrial-base contractors preparing for CMMC assessments
  • Consultants and audit firms running CMMC readiness (mock) assessments for primes and subcontractors
  • Supplier-risk teams at primes assessing subcontractors' CMMC and DFARS posture
  • Internal audit leads at federal contractors

Not covered here

  • Conducting CMMC certification assessments (requires an authorized C3PAO and CMMC Certified Assessors, or DCMA DIBCAC at Level 3)
  • ITAR and EAR export-control law (counsel-led)
  • Classified systems
  • Other industry overlays: financial (compliance-financial), healthcare (compliance-healthcare), energy (compliance-energy)
Syllabus

14 modules, 140 lessons.

About 45 hours of learning. Open a module to see every lesson.

  1. The role, the CMMC program and the limits of this credential 10 lessons · 3 h 15 min

    What a DOD compliance officer does, how CMMC Levels 1-3 and the assessment ecosystem work under 32 CFR 170, and where readiness work ends and certification begins.

    1. Module 1 pretest Diagnostic pretest · 5 min
    2. The DOD compliance officer's job: engagement types and the readiness boundary Reading · 15 min
    3. CMMC Levels 1, 2 and 3 under 32 CFR 170 Reading · 15 min
    4. The CMMC ecosystem: DoD CIO, Cyber AB, C3PAOs, CCAs and DIBCAC Reading · 15 min
    5. Status, affirmation and liability: Conditional, Final and the Affirming Official Scenario · 15 min
    6. The assessor's standard of care: independence, skepticism and documentation Reading · 15 min
    7. What you can and cannot say: readiness opinions versus certification claims Worked example · 15 min
    8. Lab 1: Set the terms of a readiness engagement with a DIB CEO AI role-play lab · 45 min
    9. Lab 2: Hand-off conversation with a C3PAO lead assessor AI role-play lab · 45 min
    10. Retrieval: Module 1 check Retrieval check · 10 min
  2. Contract clauses and the CMMC rollout timeline 10 lessons · 3 h 15 min

    How FAR 52.204-21 and the DFARS 7012/7019/7020/7021/7025 family put cybersecurity obligations into contracts, why assessments use NIST SP 800-171 Rev 2, and how to plan against the phased rollout, with Phase 2 beginning 10 November 2026.

    1. Module 2 pretest Diagnostic pretest · 5 min
    2. FAR 52.204-21 and FCI: the fifteen basic safeguards Reading · 15 min
    3. The DFARS clause family: 7012, 7019, 7020, 7021 and 7025 Reading · 15 min
    4. The 48 CFR CMMC acquisition rule: revised 7021 and the new 7025 Reading · 15 min
    5. The phased rollout: Phase 2 begins 10 November 2026 Scenario · 15 min
    6. Why assessments use NIST SP 800-171 Rev 2: Class Deviation 2024-O0013 Reading · 15 min
    7. Flow-down: subcontractor levels, status checks and the prime's diligence Worked example · 15 min
    8. Lab 3: Read a solicitation with the contracts manager AI role-play lab · 45 min
    9. Lab 4: Flow-down decisions with a prime's supplier-risk manager AI role-play lab · 45 min
    10. Retrieval: Module 2 check Retrieval check · 10 min
  3. Scoping FCI and CUI environments 10 lessons · 3 h 15 min

    Classify a contractor's information, categorize every asset, draw a testable boundary, test external service providers and decide where bRRAIn and its AI models sit relative to CUI.

    1. Module 3 pretest Diagnostic pretest · 5 min
    2. FCI, CUI and covered defense information: what triggers which obligation Reading · 15 min
    3. Level 2 asset categories: CUI, security protection, risk-managed, specialized, out of scope Reading · 15 min
    4. Boundaries and enclaves: drawing the assessment scope Worked example · 15 min
    5. External service providers, cloud and the customer responsibility matrix Reading · 15 min
    6. The SSP, inventory and diagrams: scoping evidence an assessor will test Reading · 15 min
    7. Where bRRAIn sits in the boundary: CUI, hosting options and AI models Scenario · 15 min
    8. Lab 5: Scoping workshop with an IT director AI role-play lab · 45 min
    9. Lab 6: Test a managed service provider's compliance claims AI role-play lab · 45 min
    10. Retrieval: Module 3 check Retrieval check · 10 min
  4. The bR2bR engagement method on bRRAIn 10 lessons · 3 h 15 min

    Run an assessment engagement between two bRRAIn organizations from real mechanisms: a recorded scope, two recorded approvals, sealed Robo Compliance sessions on expiring share tokens, narrow project grants, the audit and download logs, and a recorded close.

    1. Module 4 pretest Diagnostic pretest · 5 min
    2. bR2bR as a method: two bRRAIn organizations, one governed engagement Reading · 15 min
    3. The engagement scope spec: subject, framework, time window, evidence class, purpose and duration Reading · 15 min
    4. Dual approval and access grants on the auditee side Worked example · 15 min
    5. Sealed sessions and the auditor portal: evidence an auditor can rely on Reading · 15 min
    6. Audit trail and termination: proving what the auditor saw, then closing the door Reading · 15 min
    7. Keeping the auditee's data in the auditee's bRRAIn Scenario · 15 min
    8. Lab 7: Stand up a bR2bR engagement with the auditee's CISO AI role-play lab · 45 min
    9. Lab 8: A mid-engagement scope change AI role-play lab · 45 min
    10. Retrieval: Module 4 check Retrieval check · 10 min
  5. Running the engagement with your AI co-pilot 10 lessons · 3 h 15 min

    Use the MCP-first session method, framed prompts and the 'AI says no' discipline to produce evidence-bound determinations, pace a one-day review, keep records future audits inherit, and choose models by what the content is.

    1. Module 5 pretest Diagnostic pretest · 5 min
    2. The auditor's daily session: MCP-first memory for engagement work Reading · 15 min
    3. Context engineering for assessment work: requirement, objective, evidence, scope Worked example · 15 min
    4. The 'AI says no' discipline: no finding without evidence Reading · 15 min
    5. The evidence walk: pacing a one-day readiness review Scenario · 15 min
    6. Engagement records in the vault: decisions, learnings and working papers future audits inherit Worked example · 15 min
    7. Choosing models for assessment work: the Handler, opt-in commercial models and CUI Reading · 15 min
    8. Lab 9: Drive an evidence walk with your AI co-pilot AI role-play lab · 45 min
    9. Lab 10: Working-paper quality review AI role-play lab · 45 min
    10. Retrieval: Module 5 check Retrieval check · 10 min
  6. Assessment methodology and CMMC Level 1 10 lessons · 3 h 15 min

    Read requirements precisely, reach MET, NOT MET and N/A determinations from NIST SP 800-171A objectives with examine, interview and test evidence, walk the fifteen Level 1 requirements, plan a Level 2 walk and set up Robo Compliance frameworks honestly.

    1. Module 6 pretest Diagnostic pretest · 5 min
    2. Reading a requirement: identifiers, NIST SP 800-171 Rev 2 and FAR sources Reading · 15 min
    3. Assessment objectives: why one unmet objective makes a requirement NOT MET Reading · 15 min
    4. Examine, interview, test: gathering evidence an assessor accepts Worked example · 15 min
    5. Walking the fifteen Level 1 requirements Worked example · 15 min
    6. Planning a Level 2 walk across fourteen families Reading · 15 min
    7. Loading the framework into Robo Compliance: templates, custom CSV frameworks and Crossmap Reading · 15 min
    8. Lab 11: Review a Level 1 self-assessment before the affirmation AI role-play lab · 45 min
    9. Lab 12: Assessment interview with a system administrator AI role-play lab · 45 min
    10. Retrieval: Module 6 check Retrieval check · 10 min
  7. Level 2 walk I: AC, AT, AU, CM and IA 10 lessons · 3 h 15 min

    Walk the 54 Access Control, Awareness and Training, Audit and Accountability, Configuration Management and Identification and Authentication requirements at objective level, finding the exceptions where determinations change.

    1. Module 7 pretest Diagnostic pretest · 5 min
    2. Access Control (AC): the twenty-two requirements an assessor tests first Reading · 15 min
    3. Awareness and Training (AT): proving people know their duties Reading · 15 min
    4. Audit and Accountability (AU): logs that answer who did what, when Reading · 15 min
    5. Configuration Management (CM): baselines, change control and least functionality Reading · 15 min
    6. Identification and Authentication (IA): identities, MFA and passwords Reading · 15 min
    7. Worked example: objective-level determinations for six requirements Worked example · 15 min
    8. Lab 13: Walk AC and IA with the auditee's CISO AI role-play lab · 45 min
    9. Lab 14: Walk AU and CM with the IT operations lead AI role-play lab · 45 min
    10. Retrieval: Module 7 check Retrieval check · 10 min
  8. Level 2 walk II: IR, MA, MP, PS, PE, RA, CA, SC and SI 10 lessons · 3 h 15 min

    Finish the Level 2 walk against NIST SP 800-171 Rev 2: incident response, maintenance, media, personnel, physical, risk, security assessment, communications protection and system integrity, assessed objective by objective.

    1. Module 8 pretest Diagnostic pretest · 5 min
    2. Incident Response (IR) and Maintenance (MA) Reading · 15 min
    3. Media Protection (MP) and Physical Protection (PE) Reading · 15 min
    4. Personnel Security (PS) and Risk Assessment (RA) Reading · 15 min
    5. Security Assessment (CA): the SSP, POA&M and continuous monitoring Reading · 15 min
    6. System and Communications Protection (SC): boundaries, encryption and FIPS validation Worked example · 15 min
    7. System and Information Integrity (SI): flaws, malicious code and monitoring Reading · 15 min
    8. Lab 15: Walk SC encryption and boundary requirements AI role-play lab · 45 min
    9. Lab 16: Walk PE and MP with the facilities manager AI role-play lab · 45 min
    10. Retrieval: Module 8 check Retrieval check · 10 min
  9. DFARS 7012, SPRS, cloud and the Rev 3 horizon 10 lessons · 3 h 15 min

    Verify DFARS 252.204-7012 incident handling and cloud use, calculate and defend SPRS scores under the DoD Assessment Methodology, and plan for NIST SP 800-171 Rev 3 while assessing against Rev 2.

    1. Module 9 pretest Diagnostic pretest · 5 min
    2. DFARS 252.204-7012 in depth: safeguarding, reporting, preservation and flow-down Reading · 15 min
    3. Worked scenarios: verifying a 72-hour incident report Worked example · 15 min
    4. Cloud under 7012: FedRAMP Moderate and the equivalency standard Reading · 15 min
    5. SPRS and the DoD Assessment Methodology: Basic, Medium and High Reading · 15 min
    6. NIST SP 800-171 Rev 3: what changes and why it is not today's yardstick Reading · 15 min
    7. Organization-defined parameters: planning a Rev 3 readiness program Scenario · 15 min
    8. Lab 17: Verify a DFARS 7012 incident report AI role-play lab · 45 min
    9. Lab 18: Cloud equivalency review with the CIO AI role-play lab · 45 min
    10. Retrieval: Module 9 check Retrieval check · 10 min
  10. Evidence and institutional memory 10 lessons · 3 h 15 min

    What an organization's recorded memory can prove, how history should shape a review, when evidence is too old, and how to build, verify and defend evidence chains a reviewer can re-walk.

    1. Module 10 pretest Diagnostic pretest · 5 min
    2. Institutional memory as assessment evidence Reading · 15 min
    3. Weighting prior incidents and prior assessments Scenario · 15 min
    4. Evidence validity windows: when evidence is too old to rely on Reading · 15 min
    5. The evidence chain: locators a reviewer can re-walk Reading · 15 min
    6. Verifying sealed evidence: pod verify, offline verify and the audit log Worked example · 15 min
    7. Worked review: an evidence package under challenge Worked example · 15 min
    8. Lab 19: Weight twelve months of institutional memory AI role-play lab · 45 min
    9. Lab 20: The evidence that changed AI role-play lab · 45 min
    10. Retrieval: Module 10 check Retrieval check · 10 min
  11. AI failure modes in compliance work 10 lessons · 3 h 15 min

    Detect and correct the predictable ways AI drafts fail in assessment work (mis-cited requirements, fabricated evidence, scope creep, time confusion, revision and rule confusion, and overclaiming) with mechanical checks and recorded corrections.

    1. Module 11 pretest Diagnostic pretest · 5 min
    2. Failure mode: the mis-cited requirement Reading · 15 min
    3. Failure mode: the fabricated evidence reference Reading · 15 min
    4. Failure mode: scope creep mid-engagement Scenario · 15 min
    5. Failure mode: timestamp and time-zone confusion Reading · 15 min
    6. Failure mode: revision and rule confusion (Rev 2 vs Rev 3, 17 vs 15, superseded clauses) Reading · 15 min
    7. Failure mode: overclaiming language in AI drafts Worked example · 15 min
    8. Lab 21: Catch three induced AI failures AI role-play lab · 45 min
    9. Lab 22: Red-team an AI-drafted readiness report AI role-play lab · 45 min
    10. Retrieval: Module 11 check Retrieval check · 10 min
  12. Findings and scoring 10 lessons · 3 h 15 min

    Turn determinations into DOD-ready findings, a score estimate with its arithmetic, floor and coverage, a POA&M-eligibility analysis, and a readiness report with defined caveats and sign-offs that passes quality review.

    1. Module 12 pretest Diagnostic pretest · 5 min
    2. Finding classes and severity Reading · 15 min
    3. Writing a DOD-ready finding: requirement, objective, evidence, determination Worked example · 15 min
    4. The requirements that decide the outcome: 5-point and POA&M-ineligible requirements Reading · 15 min
    5. Calculating a score with the DoD Assessment Methodology Worked example · 15 min
    6. The readiness report: structure, caveats and sign-off Reading · 15 min
    7. Quality review of a findings package Scenario · 15 min
    8. Lab 23: Defend your findings to the auditee's CISO AI role-play lab · 45 min
    9. Lab 24: Score and status conversation with the CFO AI role-play lab · 45 min
    10. Retrieval: Module 12 check Retrieval check · 10 min
  13. POA&M, remediation and communication 10 lessons · 3 h 15 min

    Turn findings into a CMMC POA&M and a dated remediation roadmap, then communicate the position accurately to executives, the Affirming Official and contracting officers, and close the engagement cleanly.

    1. Module 13 pretest Diagnostic pretest · 5 min
    2. The POA&M: eligibility, content and the 180-day clock Reading · 15 min
    3. Remediation roadmaps: priority, effort, dependencies and the Phase 2 date Worked example · 15 min
    4. Briefing executives and the Affirming Official Reading · 15 min
    5. Talking to the contracting officer: notices, status changes and the 72-hour clock Scenario · 15 min
    6. Supporting the affirmation decision without making it Scenario · 15 min
    7. Closing the engagement: access, records, learnings and the regulatory watch Reading · 15 min
    8. Lab 25: Build the POA&M with the VP of operations AI role-play lab · 45 min
    9. Lab 26: Brief a contracting officer on a status lapse AI role-play lab · 45 min
    10. Retrieval: Module 13 check Retrieval check · 10 min
  14. Capstone and exam readiness 10 lessons · 2 h 45 min

    Prepare for and complete the capstone closing meeting, then prepare for the certification exam with practice scenarios, exam strategy and the distinctions that matter most.

    1. Module 14 pretest Diagnostic pretest · 5 min
    2. The capstone brief: what you will do and how it is scored Reading · 15 min
    3. Pacing a closing meeting: from evidence to decisions in forty minutes Reading · 15 min
    4. The readiness package: contents, records and caveats Reading · 15 min
    5. How the anchor exemplars were scored Worked example · 15 min
    6. Practice scenarios with worked answers Worked example · 15 min
    7. Exam strategy: LOFT forms, performance tasks and time Reading · 15 min
    8. Ten distinctions you must not blur Reading · 15 min
    9. Capstone: Closing meeting for a Level 2 readiness review AI role-play lab · 45 min
    10. Retrieval: Module 14 check Retrieval check · 10 min
Labs and capstone

Practice against someone who pushes back.

Labs run in your browser as AI role-plays. An AI plays the person on the other side of the scenario — with their own goals and objections — and your work is scored against the published rubric. There is nothing to install.

  • Lab 1 · The role, the CMMC program and the limits of this credential

    AI role-play with Dana Whitcomb, CEO of Kestrel Precision Machining (fictional): set the terms of a Level 2 (C3PAO) readiness engagement, refuse certification and score overclaims, and plan backwards to an April 2027 award

  • Lab 2 · The role, the CMMC program and the limits of this credential

    AI role-play with Marcus Oyelaran, lead CCA at Ironbridge Assessments (fictional C3PAO): hand off a Brightwater readiness engagement accurately while protecting independence and evidence access

  • Lab 3 · Contract clauses and the CMMC rollout timeline

    AI role-play with Teresa Lindqvist, contracts manager at Halvorsen Avionics (fictional): read a solicitation carrying DFARS 7025 at Level 2 (C3PAO) with a March 2027 award, judge eligibility, post-award obligations and a backwards plan

  • Lab 4 · Contract clauses and the CMMC rollout timeline

    AI role-play with Gwen Achterberg, supplier-risk manager at Corvane Systems (fictional prime): set flow-down levels, verify status and plan monitoring for five subcontractors

  • Lab 5 · Scoping FCI and CUI environments

    AI role-play with Luis Ferreira, IT director at Tamsin Composites (fictional): run a scoping workshop, reject an inadequate two-laptop enclave, categorize assets and propose a testable boundary

  • Lab 6 · Scoping FCI and CUI environments

    AI role-play with Brooke Danforth, account manager at NorthGate Managed IT (fictional MSP): test 'we're CMMC compliant' and FedRAMP claims, scope the MSP's tools and people, and agree a request list including a customer responsibility matrix

  • Lab 7 · The bR2bR engagement method on bRRAIn

    AI role-play with Elena Varga, CISO of a fictional defense electronics contractor: agree scope and design approvals and grants for a bR2bR readiness review

  • Lab 8 · The bR2bR engagement method on bRRAIn

    AI role-play with Owen Mbeki, Access Controller: handle a co-pilot's request for HR project access mid-engagement

  • Lab 9 · Running the engagement with your AI co-pilot

    AI role-play with Nadia Kowalski, engagement manager, and the firm's co-pilot: correct three co-pilot determinations with framed prompts and evidence locators

  • Lab 10 · Running the engagement with your AI co-pilot

    AI role-play with Graham Holt, quality reviewer: answer eight working-paper review points before a readiness report is issued

  • Lab 11 · Assessment methodology and CMMC Level 1

    AI role-play with Ray Dunmore, owner of Dunmore Fasteners (fictional, FCI only): review his Level 1 self-assessment, give evidence-based determinations and advise on the affirmation

  • Lab 12 · Assessment methodology and CMMC Level 1

    AI role-play with Keisha Brandt, system administrator at Arcadia Optics (fictional): conduct an assessment interview on AC.L2-3.1.6, AC.L2-3.1.10 and IA.L2-3.5.3 and state preliminary objective-level determinations

  • Lab 13 · Level 2 walk I: AC, AT, AU, CM and IA

    AI role-play with Victor Haas, CISO at Pellucid Sensors (fictional): walk six AC and IA requirements, resolve inheritance and N/A claims, and give preliminary objective-level determinations

  • Lab 14 · Level 2 walk I: AC, AT, AU, CM and IA

    AI role-play with Mei Tanaka, IT operations lead at Pellucid Sensors (fictional): walk seven AU and CM requirements, address managed-provider and emergency-change positions, and prioritize remediation

  • Lab 15 · Level 2 walk II: IR, MA, MP, PS, PE, RA, CA, SC and SI

    AI role-play with Andre Koval, network engineer at Granite Ridge Ordnance Systems (fictional): determine five SC requirements from boundary and CMVP certificate evidence and state the SC.L2-3.13.11 scoring and POA&M position

  • Lab 16 · Level 2 walk II: IR, MA, MP, PS, PE, RA, CA, SC and SI

    AI role-play with Lorraine Bassett, facilities manager at Granite Ridge Ordnance Systems (fictional): determine PE and MP requirements from sampled records and observation and correct a POA&M misconception

  • Lab 17 · DFARS 7012, SPRS, cloud and the Rev 3 horizon

    AI role-play with Jonah Petrakis, incident response lead at Saltmarsh Marine Systems (fictional): verify a past incident's 72-hour DIBNet report, DC3 handling, 90-day preservation and a subcontractor's reporting

  • Lab 18 · DFARS 7012, SPRS, cloud and the Rev 3 horizon

    AI role-play with Farah Qureshi, CIO at Saltmarsh Marine Systems (fictional): give service-by-service FedRAMP Moderate authorization or equivalency determinations, residual responsibilities, and an accurate answer on bRRAIn hosting and AI models

  • Lab 19 · Evidence and institutional memory

    AI role-play with Colin Ashby, compliance manager at Redfern Aerostructures (fictional): classify and weight twelve institutional-memory records and determine three RA and SI requirements

  • Lab 20 · Evidence and institutional memory

    AI role-play with Hannah Okafor, IT manager at Redfern Aerostructures (fictional): respond to a pod Verify hash mismatch on a sealed session, set reliance and records, and re-base determinations

  • Lab 21 · AI failure modes in compliance work

    AI role-play with Bernard Cole, engagement partner at a fictional assurance firm, who also voices the co-pilot's drafts: catch a mis-cited requirement, a fabricated evidence reference and scope creep through an unapproved grant, and correct the determinations

  • Lab 22 · AI failure modes in compliance work

    AI role-play with Isabel Moreno, engagement partner who wants to send today: red-team an AI-drafted readiness report for a fictional antenna maker and produce send-ready rewrites

  • Lab 23 · Findings and scoring

    AI role-play with Ruth Akande, CISO of a fictional machining contractor: defend five draft findings against pushback and re-determine one on new evidence

  • Lab 24 · Findings and scoring

    AI role-play with Philip Grange, CFO and Affirming Official of a fictional machining contractor: present the score estimate, POA&M eligibility and status implications, and advise on SPRS, affirmation and contracting-officer statements

  • Lab 25 · POA&M, remediation and communication

    AI role-play with Curtis Fairbanks, VP operations of a fictional foundry: classify eight findings, calculate the score and build the CMMC POA&M and must-fix plan

  • Lab 26 · POA&M, remediation and communication

    AI role-play with Diane Mercer, a fictional DoD contracting officer: as the contractor's compliance officer, brief an expired Conditional status and commit to the 7021 written notice

  • Lab 27 · Capstone and exam readiness

    AI role-play with Helena Strand (CISO) and Martin Calder (CEO and Affirming Official) of a fictional Navy circuit-board maker: the closing meeting of a Level 2 readiness review (capstone)

Capstone

Closing meeting for a Level 2 readiness review (Calder Point Electronics, fictional)

AI role-play scored against the published rubric

Pass mark: 75%

Scored on

  • Engagement governance and records15%
  • Determinations and evidence25%
  • Scoring, POA&M and status reasoning20%
  • Regulatory accuracy and timeline15%
  • Communication and integrity under pressure15%
  • Remediation priorities and close-out10%
Exam and credential

One exam. A credential anyone can verify.

The exam

Items per form
66
Time allowed
180 min
Pass mark
75%
Performance tasks
6
Attempts included
2
Wait between attempts
7 days
  • Online and timed, taken on learn.brrain.io.
  • Your form is assembled for you from the course's item bank, so no two candidates sit the same paper.
  • Performance tasks are conducted by an AI examiner: you work through a realistic scenario and are scored against a published rubric.

The credential

  • A verifiable digital badge in your name.
  • A public verification page at learn.brrain.io/verify, so an employer or client can confirm it.
  • Valid for 3 years.
  • Renewal: At 3 years, by passing the then-current exam
Before and after

Where this course sits.

Stacks well with

Questions

Frequently asked.

Do I need to install anything for the labs?

No. Labs and the capstone run in your browser on learn.brrain.io as AI role-plays: an AI plays the person on the other side of the scenario, and your work is scored against the rubric published with the course.

How is the exam delivered?

Online and timed: 66 items in 180 minutes, on a form assembled for you from the course's item bank. 6 of the items are performance tasks conducted by an AI examiner: you do the work rather than pick an answer. The pass mark is 75%.

What if I don't pass first time?

You have 2 attempts, with a 7-day wait after an unsuccessful attempt. Further exam attempts can be bought for $299 each.

How long is the credential valid?

3 years. You receive a verifiable digital badge with a public verification page at learn.brrain.io/verify, so anyone can confirm it is genuine.

I hold the v1 credential. Is it still valid?

Yes. Credentials earned on v1 remain valid and verifiable at learn.brrain.io/verify. When you renew, you sit the then-current version of the exam.

Can my company enroll a team?

Yes. Firms can buy a certification bundle for $2,999 per firm per year — see the pricing page — or contact us to arrange enrollment for a larger group.

Enroll

bR2bR Compliance Officer — DOD & Government Contracting

Run CMMC and DFARS readiness reviews on bRRAIn: scoped, evidence-bound, honest about status, ready for Phase 2.