Summit 7 Presents: Sum It Up: Recent Episodes

Dustin Bingaman

It's difficult to keep up all of the moving parts that make up the Department of Defense's Cybersecurity Maturity Model Certification Program. It's even more difficult to keep up with the relevant bits and bites that influence CMMC. This monthly podcast sums up the news and developments relevant to CMMC; DFARS and other regulations; and NIST standards such as SP 800-171, SP 800-53, the NIST Cybersecurity Framework, and others.

View Details

The DoD says it's reducing cybersecurity burden on the Defense Industrial Base. At the same time, the first recommendation in the new "Brilliant at the Basics" campaign calls for phishing-resistant multi-factor authentication, a capability that goes well beyond today's NIST SP 800-171 requirements.

In this episode we break down replay resistance vs. phishing resistance, explain why they are different security properties, and explore where phishing-resistant authentication fits into the NIST standards lifecycle. We also ask a simple question:

If this is now considered "basic," why isn't it in the NIST control catalog yet?

800-63: https://csrc.nist.gov/pubs/sp/800/63/b/4/final

Brilliant at the Basics: https://dowcio.war.gov/BrilliantBasics/

View Details

The DoD's CMMC Reform Task Force wants public feedback on how to reduce cost, complexity, and compliance burdens.

There's just one problem.

Many of the questions in the new RFI focus on topics the DoD previously said were outside the scope of the CMMC program, including NIST requirements, CUI policy, DFARS, FedRAMP, and other regulations.

In this episode, we walk through each RFI question, explain what's actually part of CMMC, and discuss what realistic reform could look like under the rulemaking process.

The RFI: https://sam.gov/workspace/contract/opp/89ef9bfb0834473791e991c712698d94/view

Out of Scope comments: https://youtu.be/cqNpO2_PWiw?si=jyt5QVF_-4PqMuKP

View Details

Everyone saw the headline that CMMC Phase 2 was suspended.

Almost nobody read the part that says government-led assessments are still happening.

In this episode we look at what the DoD actually said, how DIBCAC decides who gets assessed, why the LogZone False Claims Act case matters, and why today's approach looks surprisingly similar to the original CMMC 1.0 phased rollout.

If you think the suspension means nobody is verifying cybersecurity anymore, you may want to read the Phase 2 suspension memo one more time.

Phase 2 Suspension: https://youtu.be/TfdwAc5tdMA?si=H8Dtz6Z1UbG_aYpX

LogZone FCA: https://youtu.be/T5wJYnQzWws?si=ME3p2C8Sx_jhXTGJ

DFARS 7020: https://youtu.be/D4JLkfvB-Ws?si=rG-4enAdaj0InsfY

DoD Critical Tech: https://www.cto.mil/osc/critical-technologies/

CIO Interview: https://defensescoop.com/2026/07/17/pentagon-task-force-to-review-cmmc-hits-the-ground-running/

Suspension Memo (PDF): https://dodcio.defense.gov/Portals/0/Documents/Library/CMMC-ReformMemo.pdf

View Details

Miss the CUI Hotline Telethon? Watch it on-demand: https://summit7.us/event/secure-the-dib-telethon

The DoD has suspended the November 2026 transition to Phase 2 of CMMC implementation, but that doesn't mean cybersecurity requirements have been relaxed.

In this episode, we explain what actually changed, what didn't, why Level 2 self-assessments now matter more than ever, and how contractors could expose themselves to significant False Claims Act liability if they misunderstand the news.

We also discuss the 60-day CMMC program review, the DoD's Request for Information, and what defense contractors should focus on moving forward.

Phase 2 Announcement: https://www.war.gov/News/Releases/Release/Article/4542329/forging-the-arsenal-of-freedom-department-of-war-suspends-cmmc-phase-ii-require/

Phase 2 Blog: https://summit7.us/blog/cmmc-phase-2-suspended-with-60-day-review-what-happens-next

32 CFR 170.16: https://www.ecfr.gov/current/title-32/section-170.16

32 CFR 170.22: https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-G/part-170/subpart-D/section-170.22

False Claims Act: https://youtu.be/T5wJYnQzWws?si=pn8iwA7_8Ys_wvdq

View Details

Register for Secure The DIB: https://summit7.us/event/secure-the-dib-telethon

The public comment period for the proposed FAR CUI rule closes on July 23, making this your last opportunity to influence one of the biggest cybersecurity changes coming to federal contracting.

Simply supporting or opposing the rule isn't enough. In this episode, we break down the Government's own guidance for writing effective public comments and explain the seven principles that make comments persuasive.

You'll learn the common mistakes to avoid, how to build evidence-based arguments, and how to give regulators constructive recommendations they can actually use.

Whether you're planning to comment on the FAR CUI rule or want to better understand how federal rulemaking works, this episode will help you make your comment count before the deadline.

Register for Summit 7 Live: https://www.summit7.us/s7live

FAR CUI Rule: https://www.federalregister.gov/documents/2026/06/23/2026-12559/federal-acquisition-regulation-revolutionary-federal-acquisition-regulation-overhaul-parts-1-2-4-33

GSA Comment Guidance: https://www.regulations.gov/commenting-guidance

View Details

Another 279 companies achieved CMMC Level 2 certification in June 2026, bringing the total to 1,717 certified organizations.

That's a record month and far ahead of DoD's original projections. But the data also shows something surprising: the industry still isn't using all of its available assessment capacity.

In this episode, we break down the latest Cyber AB numbers, explain our assessment capacity methodology, and discuss why contractor readiness, not assessor availability, remains the biggest constraint on CMMC adoption.

Topics covered:

• June 2026 CMMC Level 2 certification numbers

• Available CMMC assessment capacity

• Why the assessor shortage narrative doesn't match the data

• The connection between CMMC readiness and DFARS 252.204-7012 compliance

• What these trends could mean for the rest of the phased rollout

Have questions? Contact us: https://summit7.us/

Register for Secure The DIB: https://summit7.us/event/secure-the-dib-telethon

Monthly Cyber AB Town Hall: https://cyberab.org/News-Events/Town-Halls/pager/7916/page/2

View Details

The DOJ has announced its first cybersecurity False Claims Act settlement of 2026, and the details should get every defense contractor's attention.

In this episode, we break down the LOGZONE settlement, the difference between DFARS 252.204-7012 and CMMC, how a perfect SPRS score became a DIBCAC assessment score of -170, and why this case may be a preview of additional enforcement actions still working their way through the system.

Topics covered:

• LOGZONE FCA settlement details

• DFARS 252.204-7012, 7019, and 7020

• SPRS self-assessment scores

• DIBCAC medium assessments

• Why no whistleblower was required

• What this means for defense contractors moving forward

Settlement and source documents linked below.

Register for Secure The DIB: http://summit7.us/event/secure-the-dib-telethon

Register for Summit 7 Live: https://www.summit7.us/s7live

DOJ Settlement: https://www.justice.gov/opa/pr/alabama-defense-contractor-agrees-pay-507144-resolve-false-claims-act-liability-relating

DoD IG + DOJ (2023): https://youtu.be/_3GLX6ele_E?t=448

FCA pod w/ Alexander Canizares: https://youtu.be/Tga0krfIrEk?si=i6E2FuLY7QLNGmos

FCA pod w/ Stephanie Siegmann: https://youtu.be/d1yweDy2wV4?si=drOwbWxBm9GAlh38

FCA w/ Bruce Judge: https://youtu.be/tqT_5yQBlOk?si=xgmqev-87KTKpxUJ

View Details

Register for Secure The DIB: https://www.summit7.us/secure-the-dib-telethon

Over the last two months, we ran the CMMC Challenge Bracket.

Eight matchups, 907 participants, 2,005 votes.

The winner? Leadership Buy-In.

But the final standings were only part of the story.

In this episode, we break down the voting trends, coalition shifts, and comment analysis to understand what the community actually believes is holding organizations back from CMMC success.

View Details

Back in January, we made seven predictions about where the CMMC ecosystem would be by the end of 2026.

Now that we're halfway through the year, we're checking the scoreboard.

In this episode:

• Level 2 certification growth

• False Claims Act enforcement trends

• Funding and compliance assistance programs

• The FAR CUI rule

• CMMC 3.0 and NIST SP 800-171 Rev. 3

• Early Level 3 activity

• What the GAO report actually found

Some predictions are looking strong. Others are too close to call. And at least one is trending in the wrong direction.

Here's our mid-year reality check on CMMC in 2026.

Register for Summit 7 Live: https://www.summit7.us/s7live

2026 Predictions (January): https://youtu.be/WxgGtKpF3_s?si=I9MfjmkBDojCRThv

GAO Report podcast: https://youtu.be/U0VhiN3qpdE?si=lD-Pbl3vyfbIMPw7

NCODE for SMBs: https://www.summit7.us/blog/ncode-contract-award

Assessment Capacity podcast: https://youtu.be/e_1FztgNCHM?si=PdpkkVk3SSa1V4-2

CIRCIA update: https://youtu.be/bvwnNSpDZgU?si=bS0ARRUfvvzLemmK

View Details

Remember CIRCIA?

The proposed rule would create mandatory cyber incident reporting requirements for more than 300,000 organizations across 16 critical infrastructure sectors, including the Defense Industrial Base.

Now CISA is holding a new round of town halls to gather feedback before issuing a final rule.

In this episode, we explain why CIRCIA isn't just another version of DFARS 252.204-7012, the seven biggest differences defense contractors need to understand, and why the upcoming town halls may be the DIB's best opportunity to influence the final rule.

Registration links for the CIRCIA Town Halls are included below.

Register for Summit 7 Live: https://www.summit7.us/s7live

CIRCIA Town Halls: https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing/cyber-incident-reporting-critical-infrastructure-act-2022-circia

CIRCIA Proposed Rule Pod (2024): https://youtu.be/ngYSaO5fg5Y?si=VoVW54QvAzKe6r-r

Proposed Rule: https://www.federalregister.gov/documents/2024/04/04/2024-06526/cyber-incident-reporting-for-critical-infrastructure-act-circia-reporting-requirements

Congressional Research Service Report (PDF): https://www.congress.gov/crs-product/R48025

CIRCIA Hearing: https://homeland.house.gov/hearing/surveying-circia-sector-perspectives-on-the-notice-of-proposed-rulemaking/

View Details

The Cyber AB brought the ecosystem together to deliver pretty exciting news during the May monthly town hall. Join us for this week's episode as we break down some of the topics a little deeper to see what it actually means for the ecosystem.

Things like:

• Has production accelerated within the ecosystem?

• Who is the new EVP of the Cyber AB?

• Who actually attends these meetings?

And so much more...Tune in to find out!

Cyber AB TH Replay's: https://cyberab.org/News-Events/Town-Hall

ISACA Website: https://www.isaca.org/

T3 Inquiries (older than 6 months): https://dowcio.war.gov/CMMC/Contact/

NIST SP 800-145: https://csrc.nist.gov/pubs/sp/800/145/final

View Details

DoD has updated the CMMC FAQs again, and the revision history doesn't tell the full story. In this episode, we break down the most important FAQ 2.3 changes, including significant changes, annual affirmations, CMMC UIDs, joint ventures, hard-copy CUI, and why the Affirming Official is one of the most important CMMC roles inside your company.

Register for Summit 7 Live: https://www.summit7.us/s7live

100 Level 2-Certified Clients: https://www.summit7.us/blog/100-cmmc-l2-certified-clients

NCODE: https://www.summit7.us/blog/ncode-contract-award

CMMC FAQs: https://dodcio.defense.gov/CMMC/

January FAQ Pod: https://youtu.be/8ZxqqH0zws8?si=m5n8WQttWsZV8n24

Paper CUI Pod: https://youtu.be/lcIaxVBjyr0?si=17LdlP92NuCGa_ph

View Details

It's milestone season in the CMMC world. Just six months into the Phased Rollout and there are 2.5x more Level 2 certifications than DoD expected. Meanwhile, a significant portion of those certs are Summit 7 clients. We now work with more than 100 Level 2 certified companies. Last but not least, Summit 7 was awarded the Army's NCODE contract to help bring secure and compliant enclaves to micro-sized defense contractors. Exciting times.

Register for Summit 7 Live: https://www.summit7.us/s7live

100 Level 2-Certified Clients: https://www.summit7.us/blog/100-cmmc-l2-certified-clients

NCODE: https://www.summit7.us/blog/ncode-contract-award

View Details

Everyone keeps saying there aren't enough CMMC assessors. The data tells a very different story.

In this episode we break down actual assessment capacity using the current number of certified assessors, DoD's rollout estimates, and capacity growth rates across the ecosystem.

How quickly is the ecosystem scaling toward future demand targets of 16,000 and even 25,000 assessments per year?

Turns out the real bottleneck isn't assessor capacity at all.

...

Register for Summit 7 Live: https://www.summit7.us/s7live

GAO Report (2026): https://www.gao.gov/products/gao-26-107955

GAO Report (2021): https://www.gao.gov/products/gao-22-104679

View Details

We are back at it again with another rundown of the Cyber AB's monthly town hall and there sure was a lot of valuable information distributed during the meeting. Join us for this episode of we discuss some of the key information dished out this month and weigh on any impact it may have on the CMMC Program.

Things like:

• Changes in ecosystem engagement?

• Do we have enough steps are in the T3 process?

• Has certification output increased? And so much more...Tune in to find out!

Cyber AB TH Replay's: https://cyberab.org/News-Events/Town-Hall

ISACA Website: https://www.isaca.org/

T3 Inquiries (older than 6 months): https://dowcio.war.gov/CMMC/Contact/

View Details

L3Harris Missile Solutions recently sent a letter informing their suppliers that they will need to achieve CMMC Level 2 (C3PAO) Status by July, 30th 2026. Two weeks later, L3Harris announced that they had been awarded a new contract for the Army Tactical Missile System.

Coincidence? We think not.

Not only do subcontractors need to provide their Level 2 certification, they also need to provide their Level 2 assessment report.

This week we talk about whether this is an anomaly or a sign of things to come.

Register for Summit 7 Live: https://www.summit7.us/s7live

L3Harris Letter: https://www.summit7.us/blog/l3harris-supply-chain-notice

Primes can't waive CMMC: https://youtu.be/haVzS8j7Qz4?si=F2RICMKbCNRu-1uh

CMMC CAP (PDF): https://cyberab.org/Portals/0/CMMC%20Assessment%20Process%20v2.0.pdf

View Details

NIST SP 800-171 Revision 3 has been out for two years.

DFARS 252.204-7012 says to use the most current version.

So why are defense contractors still using Revision 2?

Because they're supposed to.

In this episode, we break down the temporary rule that overrides the DFARS clause and keeps the entire ecosystem aligned on Revision 2.

We cover:

• What a class deviation actually is and why it matters

• Why DoD had to pause the shift to Revision 3

• How CMMC rulemaking controls the transition

• And when Revision 3 will realistically start showing up in contracts

Bottom line: contractors aren't behind. The rules haven't changed yet.

.......

Register for Summit 7 Live: https://www.summit7.us/s7live

171r3: https://csrc.nist.gov/pubs/sp/800/171/r3/final

DFARS 7012 deviation (PDF): https://www.acq.osd.mil/dpap/policy/policyvault/USA001074-24-DPC.pdf

32 CFR 170: https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-G/part-170

Class deviation podcast: https://youtu.be/voziZRAMvv4?si=3xHm7I_gIeQTQxLf

Class deviation press release: https://www.war.gov/News/Releases/Release/Article/3763953/department-of-defense-issues-class-deviation-on-cybersecurity-standards-for-cov/

View Details

This week we sit down with a C3PAO who has completed over 100 CMMC Level 2 assessments. We chat cost, timeframe, assessor backlogs and the most common issues facing defense contractors.

Register for Summit 7 Live: https://www.summit7.us/s7live

GAO Report (2026): https://www.gao.gov/products/gao-26-107955

GAO Report (2021): https://www.gao.gov/products/gao-22-104679

View Details

We are back at it again with another rundown of the Cyber AB's monthly town hall and there sure was a lot of valuable information distributed during the meeting. Join us for this episode of we discuss some of the key information dished out this month and weigh on any impact it may have on the CMMC Program.

Things like:

• Milestones achieved by the program this month!

• Why was the new DoW CIO talking to Armed Services committees?

• How is the ecosystem growing?

• What to expect in the CAICO transfer to ISACA.

And so much more...Tune in to find out!

Cyber AB TH Replay's: https://cyberab.org/News-Events/Town-Hall

ISACA Website: https://www.isaca.org/

View Details

Everyone is talking about a “November 2026 deadline” for CMMC Level 2.

There's just one problem… it's not real.

In this episode, we break down what the CMMC rule actually says about Phase 2, what really happens starting in November 2026, and why most contractors are misunderstanding the rollout.

If you're in the defense industrial base, this is the clarity you need to plan your timeline the right way.

Key topics:

• What Phase 2 actually means

• When Level 2 requirements apply (and when they don't)

• Why this isn't a mass certification deadline

• How to think about your real CMMC timeline

• Stop chasing phantom deadlines and start focusing on the contracts that matter.

Register for Summit 7 Live: https://www.summit7.us/s7live

PALT: https://youtu.be/C50UXJyz4PA?si=ySn1oIS4FaK4Si9f

32 CFR 170.3: https://www.ecfr.gov/current/title-32/section-170.3

Jan 2025 memo:

https://dodprocurementtoolbox.com/uploads/DOPSR_Cleared_OSD_Memo_CMMC_Implementation_Policy_d26075de0f.pdf

View Details

GAO's latest report on CMMC sounds cautious. They warn about external risks, ecosystem constraints, and gaps in DoD's strategy.

But that framing misses the bigger story.

Since the 2021 report, CMMC has gone from a fragmented concept to a functioning system. The ecosystem exists. Training exists. Small business support is working.

So why does the report feel so negative?

In this episode, we break down where GAO is right, where they're overstating the risk, and why the real story is the program's quiet but meaningful progress.

Register for Summit 7 Live: https://www.summit7.us/s7live

GAO Report (2026): https://www.gao.gov/products/gao-26-107955

GAO Report (2021): https://www.gao.gov/products/gao-22-104679

View Details

Most defense contractors assume everything written in the CMMC Level 2 Assessment Guide is a requirement. But that's not actually how the framework works.

In this episode we break down the structure of the assessment guide and explain why roughly 75% of the document is explanatory text, not normative requirements.

You'll learn:

Where the real requirements come from in NIST SP 800-171

How verification procedures in NIST SP 800-171A become assessment objectives

Why discussion sections and examples are informative, not prescriptive

Understanding the difference between requirements, assessment objectives, and explanatory guidance can help contractors avoid unnecessary controls, reduce documentation overhead, and simplify CMMC compliance.

CMMC Assessment Guides: https://dodcio.defense.gov/cmmc/Resources-Documentation/

NIST SP 800-171: https://csrc.nist.gov/pubs/sp/800/171/r2/upd1/final

NIST SP 800-171A: https://csrc.nist.gov/pubs/sp/800/171/a/final

View Details

Iranian cyber actors are targeting the Defense Industrial Base.

So does CMMC actually help?

In this episode, we mapped 130 real-world techniques used by five Iranian threat groups to the controls behind NIST SP 800-171 using the MITRE ATT&CK framework.

Here is what the data shows:

• 100% of techniques are detectable

• 68% are mitigated with preventative controls

• Just a handful of core controls drive most of the defensive impact

We also examine what that means for Cybersecurity Maturity Model Certification and why 800-171 remains a strong floor for protecting CUI.

But there is a gap. Only about half of the relevant NIST SP 800-53 that mitigate known Iranian techniques are represented in the 800-171 baseline.

If you are a defense contractor, this episode will show you what compliance actually buys you and where you may need to go further.

Register for Summit 7 Live: https://www.summit7.us/s7live

MITRE ATT&CK: https://attack.mitre.org/

Mappings Explorer: https://ctid.mitre.org/projects/mappings-explorer

CISA Alert: https://www.cisa.gov/topics/cyber-threats-and-advisories/advanced-persistent-threats/iran

NIST SP 800-53: https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final

NIST SP 800-171: https://csrc.nist.gov/pubs/sp/800/171/r2/upd1/final

View Details

The Cyber AB has once again summoned the CMMC Ecosystem to deliver its monthly update and on this week's show we are going to break it down for you. Join us as we take all the information distributed during the meeting and dish out the information you need to know.

Things like: Can my FSO check on my Tier 3?

Have we eclipsed the 1,000 assessments milestone?

When does a mock assessment stop “mocking”?

Updates on the ISACA/ CAICO switchover

And so much more...Tune in to find out!

Sum It Up: “The End of SPRS Scores (sort of)”: https://youtu.be/_UFN7fubgQY?si=EgtchmuAHti24Cr8

Cyber AB TH Recordings: https://cyberab.org/News-Events/Town-halls

ISACA Webinar - CMMC: Requirements, Roles, and Professional Credentials: https://store.isaca.org/s/community-event?id=a33VQ000001otC1YAI

ISACA CMMC Page: https://www.isaca.org/credentialing/cmmc

View Details

The DoD Inspector General is raising concerns about CUI marking again and the numbers don't add up.

In 2023, the IG found that 48% of reviewed CUI documents lack proper markings. Yet the DoD CUI Program website reports only 9% were unmarked that same year. So which is it?

In this episode we break down the latest DoD IG management advisory, where the recommendations fall short, and why the CUI program and the CMMC program (although closely related) are owned by different offices that can't fix each other's problems.

For defense contractors, this isn't academic. CMMC enforcement depends on the integrity of the CUI program. If CUI marking is inconsistent, compliance risk increases downstream.

Summit 7 Live: https://www.summit7.us/s7live

2026 IG Report: https://www.dodig.mil/reports.html/Article/4397146/management-advisory-dod-policy-and-training-on-dissemination-controls-for-contr/

2023 IG Report: https://www.dodig.mil/reports.html/Article/3413433/audit-of-the-dods-implementation-and-oversight-of-the-controlled-unclassified-i/

View Details

CMMC is a condition of contract award and many defense contractors are waiting until they see CMMC requirements in a solicitation to get started. But the department of defense wants the period between solicitation and award to be as short as possible. This week we crunch the numbers on 1,070 upcoming Navy contracts to see what a realistic timeline ought to look like.

Summit 7 Live: https://www.summit7.us/s7live

PALT Pod 2024: https://youtu.be/NZs4f5voyrg?si=S-xarOpYyiSG00Bs

NAVAIR Forecast: https://www.navair.navy.mil/LRAE

View Details

The largest change to DFARS cybersecurity requirements other than CMMC took place on February 1st, 2026, and nobody knew it happened. DFARS 7019 and 7020 have been replaced by DFARS clause 252.240-7997. Basic self-assessments have been eliminated. FAR 52.204-21 has a new number. And none of this went through rulemaking. This week we're diving deep into the mysterious world of class deviations and what they mean for defense contractors moving forward.

RFO Website: https://www.acquisition.gov/far-overhaul

DFARS RFO Deviations: https://www.acq.osd.mil/dpap/dars/dfars_far_overhaul_class_deviations.html

CMMC class deviation: https://youtu.be/vC4IJ2JQ5NU?si=B8I9DII4ZEbQ2dNx

7012 class deviation: https://youtu.be/voziZRAMvv4?si=HxIkpUWnxyergEUQ

View Details

After a brief hiatus, the Cyber AB has gathered the CMMC Ecosystem to deliver its monthly update. On this week's show, we breakdown the information distributed on this month's meeting that you need to know. Things like:

• Who is the new DoW CIO?

• Pending shutdown and CMMC Impacts

• Ecosystem Growth and Certification updates

• Does this show count for CPEs?

And so much more...Tune in to find out!

ISACA Webinar - CMMC: Requirements, Roles, and Professional Credentials: https://store.isaca.org/s/community-event?id=a33VQ000001otC1YAI

DAU CMMC microlearning: https://www.dau.edu/acquipedia?combine=cmmc&title=C&field_functional_area_target_id=All&field_topic_area_target_id=All

ISACA CMMC Page: https://www.isaca.org/credentialing/cmmc

View Details

Defense contractors aren't the only ones who need to implement NIST cybersecurity requirements for CUI. The big question has always been whether other agencies would require proof of implementation via the CMMC program. The GSA just revised their process for assessing nonfederal systems handling controlled unclassified information and it's way closer to NIST's Risk Management Framework than CMMC.

CIO-IT Security-21-112r1 (PDF): https://www.gsa.gov/system/files/Protecting-Controlled-Unclassified-Information-%28CUI%29-in-Nonfederal-Systems-and-Organizations-Process-%5BCIO-IT-Security-21-112-Rev-1%5D.pdf

Summit 7 Live San Diego: https://www.summit7.us/s7live

View Details

This week we sit down with Supply Chain Director Bo Birdwell to discuss Elbit America's latest open letter to suppliers regarding CMMC. Elbit's letter doesn't mince words: CMMC is here and the time to act is now. Bo not only walks us through the perspective of a major prime contractor on cost, timelines, outsourced services, CMMC Level 3, and more – he also drops a ton of helpful tips for current and prospective suppliers.

Elbit Supplier Page: https://www.elbitamerica.com/suppliers#cyber

MSP Collective: https://www.mspcollective.org/

Bo Birdwell: https://www.linkedin.com/in/bobirdwell/

View Details

The defense department has updated the CMMC FAQs for the second time in 3 months. In lieu of rulemaking updates the CMMC FAQs are the best place for updated guidance. This week we're exploring DoD's answers regarding everything from encryption to enclaves to VDI endpoints.

CMMC FAQs: https://dodcio.defense.gov/CMMC/

View Details

Another year another set of eerily accurate predictions about defense cybersecurity requirements and the CMMC program. Like usual we got most of our 2025 predictions correct. For 2026 we're getting specific with False Claims settlements, CMMC 3.0, FAR CUI, and more!

FCA episode: https://youtu.be/tPA-ALjW1Hk?si=KgPUAo4VqqmX3mNF

DoD IG report: https://www.youtube.com/watch?v=RNafaUlgBGo

Golden Dome: https://youtu.be/y88JqZdJsj0?si=eGpIm1jqKRYpW4n3

View Details

Defense Logistics Agency suppliers got a special Christmas gift: detailed estimates of CMMC requirements by DLA supply class! The Defense Department buys a lot of different products and services and the estimates make it clear that different types of contractors will experience CMMC requirements in very different ways. If only we could get every agency and mega prime to put out info like this.

Episode Links:

DLA SMB Website: https://www.dla.mil/Small-Business/Resource-Center/Cybersecurity-Resources/

What DLA Buys: https://www.dla.mil/Small-Business/Getting-Started/What-DLA-Buys/

Supply Classes: https://www.dau.edu/acquipedia-article/supply-classes

View Details

Another defense contractor is paying six figure fines after settling with the Department of Justice for allegedly failing to comply with DFARS clause 252.204-7012. The kicker: their own employee blew the noncompliance whistle and got a cut of penalty money. This is the fifth such settlement in 2025 and the DOJ is crystal clear that the don't discriminate just because a company is small.

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

Memo: https://dodcio.defense.gov/cmmc/Resources-Documentation/

Swiss Automation: https://www.justice.gov/opa/pr/illinois-precision-machining-company-agrees-pay-421234-resolve-alleged-false-claims-act

MORSECORP: https://www.youtube.com/watch?v=ZnePk6jaezA

Raytheon: https://www.justice.gov/opa/pr/raytheon-companies-and-nightwing-group-pay-84m-resolve-false-claims-act-allegations-relating

Aero Turbine: https://www.youtube.com/watch?v=hFEEVGXv_00

GTRC: https://www.justice.gov/opa/pr/georgia-tech-research-corporation-agrees-pay-875000-resolve-civil-cyber-fraud-litigation

DFARS 7012: https://youtu.be/cy4e28YAkXU?si=MqGKGNAHTPyvj-DI

View Details

A recent webinar from the US Army Corps of Engineers told suppliers that if they only handle paper CUI, then CMMC requirements don't apply to them. That's a significant concession to industry on par with COTS exemption and POAMs. But is this USACE flexing their discretion or are they setting up a conflict by setting policy around CMMC applicability?

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

View Details

Register for CMMC Industry Week: https://www.summit7.us/industry-week

Since the 48 CFR CMMC final rule was published in September 2025 we've seen supplier notices from Lockheed, RTX, BAE, HII, and many others. Most recently, Northrop Grumman recently published a supplier announcement titled “CMMC 2.0 is Final – Are You Ready?”. The big takeaway: don't expect CMMC waivers from your prime customers because they can't grant them to you.

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

DFARS 7012: https://youtu.be/cy4e28YAkXU?si=KvezY7Vu7zXf9qYZ

32 CFR Final rule: https://www.federalregister.gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-certification-cmmc-program

48 CFR Final rule: https://www.federalregister.gov/documents/2025/09/10/2025-17359/defense-federal-acquisition-regulation-supplement-assessing-contractor-implementation-of

January Memo (PDF): https://dodprocurementtoolbox.com/uploads/DOPSR_Cleared_OSD_Memo_CMMC_Implementation_Policy_d26075de0f.pdf

View Details

While everyone has been focused on the start of CMMC phase 1, many contractors are discovering that DFARS clause 252.204-7020 has been lurking in their contracts since 2020. DoD reserves the right to show up at any time and audit compliance with DFARS clause 252.204-7012. This week we're diving into everything that DIBCAC will be asking for when they show up on your doorstep. Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

DIBCAC intake forms: https://www.dcma.mil/DIBCAC/

DFARS 252.204-7012: https://youtu.be/cy4e28YAkXU?si=x4tmDKcCc44dLnJE

DFARS 252.204-7020: https://youtu.be/D4JLkfvB-Ws?si=6_yyMYrU7DVoxoBt

View Details

The final Cyber AB TH of 2025 took place this week which means it's time for the team to unpack all the important information you need to know. On this week's show, Jason and Joy sit down for one one last time in 2025 as we discuss things like:

•The final ecosystem update of 2025

•The biggest highlights of 2025

•DO I have to affirm my C3PAO assessment score?

•What the AB expects for 2026

Tune in as we close out this year of Cyber AB Town Halls with a little fun!

Summit 7 Live: https://www.summit7.us/S7Live

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

AB Town Halls: https://cyberab.org/News-Events/Town-Halls/Details/march-town-hall

View Details

As of November 10th, 2025, CMMC is now a condition of award for new defense contracts. “Phase 1” of the CMMC rollout will last until November 10th, 2026. This week we discuss seven predictions we have for the new normal.

Summit 7 Live: https://www.summit7.us/S7Live

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

32 CFR 170.3(e): https://www.ecfr.gov/current/title-32/part-170#p-170.3(e)

DFARS 7012: https://youtu.be/cy4e28YAkXU?si=yC_wKI42JNxIHKME

Phase 1 Blog: https://www.summit7.us/blog/cmmc-begins-today

View Details

After four years of rulemaking here we are at the last podcast before the official start of CMMC phase 1. What better way to usher in the new normal of CMMC than a quick refresher on how and why CMMC became a thing in the first place? Nothing helps contextualize the CMMC program like remembering how resistant the DoD has been to third party verification until they were left with no other choice.

View Details

On this week's spine-tingling episode of the show, Jason and Joy sit down unwrap the October Cyber AB Town Hall like a bag of pillowcase full of candy. With less than two weeks until the November 10th launch, this marks the final town hall before the CMMC becomes a fully operational reality. Tune in as we mix up a cauldron of all the important information you need to know to assure no tricks as you pursue your CMMC bag of treats… no costumes required!

Summit 7 Live: https://www.summit7.us/S7Live

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

AB Town Halls: https://cyberab.org/News-Events/Town-Halls/Details/march-town-hall

View Details

CMMC officially goes into effect on November 10th, 2025, at which point all new DoD solicitations and contracts will include at least CMMC Level 1 status requirements. While the government shutdown might affect the pace of new contract awards, it doesn't change anything about the effective date of CMMC specifically. This week we're looking at the trickle of contract notices that are letting people know CMMC is very real and will absolutely be required (including level 2).

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

NAVSEA (Level 2): https://sam.gov/workspace/contract/opp/0a92f866231546828b3fd11cf1146a8a/view

USSOCOM (Level 1): https://sam.gov/workspace/contract/opp/eb3d38dd00e845579212f724b6dedd37/view

USACE (Level 2): https://sam.gov/workspace/contract/opp/e0a817b5b7c74c319ebaa2df9cd3d637/view

View Details

The Senate has passed their version of the FY26 NDAA and they want annual contractor performance measurements to focus exclusively on “negative performance events”. Per the Senate Armed Services Committee that includes failing to meet cyber requirements, failing to flow down requirements to subcontractors, and submission of false claims (cyber). Add this one to the growing pile of evidence that the government really, really wants contractors to take cybersecurity seriously.

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

Memo: https://dodcio.defense.gov/cmmc/Resources-Documentation/

Senate NDAA: https://www.congress.gov/bill/119th-congress/senate-bill/2296/text

View Details

Watch full webinar here: https://www.summit7.us/webinars/cmmc-phase-1-the-final-rule-is-here

The start of CMMC phase 1 is just around the corner. Starting on November 10th, 2025, DoD contracting officers will begin inserting CMMC status requirements in new solicitations and contracts. We recently held a webinar on the CMMC final rule to get people up to speed so this week we're bringing you our key takeaways. If you want all the details, the webinar is available on demand (registration link is in the show notes).

Find out where you are on your CMMC journey here: https://www.summit7.us/pathfinder

View Details

September has come to a close and despite all the moving parts, name changes, and other potential roadblocks, the CMMC program is humming along. Assessments are being conducted at a blazing pace, the AB staff is growing, and people are still not sure if they should identify as an ESP or CSP.On this week's show, we dig into the September Cyber AB Town Hall and break down all the important details you need to know!

Summit 7 Live: https://www.summit7.us/S7Live

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

AB Town Halls: https://cyberab.org/News-Events/Town-Halls/Details/march-town-hall

View Details

DFARS clause 252.204-7021 goes into effect on November 10th, 2025, but there's more under the hood than just the text of the contract clause. Contracting officers have an entire set of procedures they must follow that dictate when and if the 7021 clause should be included in a defense contract at all. In this episode we're looking at the other side of the coin to the infamous CMMC DFARS clause.

Final Rule Webinar: https://www.summit7.us/webinars/cmmc-phase-1-the-final-rule-is-here?hsCtaAttrib=195767465874

Summit 7 Live: https://www.summit7.us/S7Live

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

2025 CMMC Final Rule (48 CFR): https://www.federalregister.gov/documents/2025/09/10/2025-17359/defense-federal-acquisition-regulation-supplement-assessing-contractor-implementation-of

DFARS 7008: https://youtu.be/vgrRGIWboKc?si=chKYMNRUea9eqpn-

DFARS 7012: https://youtu.be/cy4e28YAkXU?si=OO3IEXYvfGqZQ3op

DFARS 7019: https://youtu.be/7gW_82Cus7Y?si=IT2ORlBlZELxxbdu

DFARS 7020: https://youtu.be/D4JLkfvB-Ws?si=-hMhIq6dJLxu1NU4

DFARS 7025: https://youtu.be/LtJK-CHuyp8?si=A6WoUGBEEgVxp5Jx

DFARS 7009: https://youtu.be/kfecRRrd41w?si=PNXrbcvRLHc5GoUg

32 CFR 170 Webinar: https://www.summit7.us/webinars/cmmc-32-cfr-final-rule?_gl=11qpc6eg_upMQ.._gs*MQ..

View Details

Final Rule Webinar: https://www.summit7.us/webinars/cmmc-phase-1-the-final-rule-is-here?hsCtaAttrib=195767465874

The regulation that finalizes CMMC guidance for DoD contracting officers and program managers officially goes into effect on November 10th, 2025. The highlight of the regulation is the final text of DFARS clause 252.204-7021 which tells contractors which CMMC level they need to achieve in order to take award of a contract. But the regulation also created DFARS provision 252.204-7025 which officially notifies offerors of the requirements contained in the 7021 clause and it's only three paragraphs long!

Summit 7 Live: https://www.summit7.us/S7Live

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

2025 CMMC Final Rule (48 CFR): https://www.federalregister.gov/documents/2025/09/10/2025-17359/defense-federal-acquisition-regulation-supplement-assessing-contractor-implementation-of

View Details

Register for the upcoming webinar: https://www.summit7.us/webinars/cmmc-phase-1-the-final-rule-is-here

It's official: CMMC Phase 1 begins on November 10th, 2025 when the 48 CFR CMMC final rule goes into effect. After that point all new Department of Defense/War contracts will contain some level of CMMC requirement. But just when things seem certain, people are wondering about the recent class deviation regarding DFARS clause 252.204-7021. Is the use of the CMMC clause actually suspended? Spoiler: no, not even close.

Final Rule Webinar: https://www.summit7.us/webinars/cmmc-phase-1-the-final-rule-is-here?hsCtaAttrib=195767465874

Summit 7 Live: https://www.summit7.us/S7Live

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

2025 CMMC Final Rule (48 CFR): https://www.federalregister.gov/documents/2025/09/10/2025-17359/defense-federal-acquisition-regulation-supplement-assessing-contractor-implementation-of

Aug Class Deviation: https://www.acq.osd.mil/dpap/policy/policyvault/USA001756-25-DPCAP.pdf

View Details

A lot of defense contractors are betting that the DoD will only require CMMC Level 2 self-assessments during the first 12 months of CMMC (“Phase 1”). Since December 2024 there have been three official policies outlining what can be required in Phase 1 and none of them prohibit Level 2 certification assessments. Instead, every policy we can find reinforces the idea that many companies will be required to achieve CMMC Level 2 certification in Phase 1. In this episode we walk through all 3 policies so you can decide for yourself if that's a risk you want to take with your business.

Summit 7 Live: https://www.summit7.us/S7Live

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

32 CFR 170.3(e): https://www.ecfr.gov/current/title-32/part-170#p-170.3(e)

The January Memo (PDF): https://dodprocurementtoolbox.com/uploads/DOPSR_Cleared_OSD_Memo_CMMC_Implementation_Policy_d26075de0f.pdf

The July Memo (PDF): https://dodprocurementtoolbox.com/uploads/PTDO_Do_D_CIO_Memo_Resources_for_CMMC_Implemtation_dtd_20250728_25_T_2704_cleared_20250807_e53aa02e78.pdf

View Details

The Summer is all but over, but that's ok because the CMMC program is just getting started! On this week's episode, we cover the Cyber AB's Monthly Townhall for August and break down all the things you need to know.

Things like:

• Did assessment progress slow down?

• Are there any reported failures?

• Are people finally interpreting the 10-day post assessment rule correctly?

• Will the DoD be represented at CS5?

• What is the C3PAO Advisory Council?

And so much more... Tune in to find out!

Summit 7 Live: https://www.summit7.us/S7Live

Women of CMMC Dinner: https://cs5global.org/women-of-cmmc-dinner/

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

AB Town Halls: https://cyberab.org/News-Events/Town-Halls/Details/march-town-hall

View Details

Register for Secure The DIB: https://www.summit7.us/secure-the-dib-2025

Golden Dome promises to be the largest and most complex defense initiatives in American history. Countless contractors, subcontractors, and suppliers will be called on to help build the ultimate system of systems. But those suppliers are the targets of cyber espionage, disruption, and IP theft – regardless of their size. So it's no surprise that as the Golden Dome program lifts off, the DoD is out in front with some pretty intense cybersecurity requirements.

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

DFARS 7012: https://youtu.be/cy4e28YAkXU?si=KvezY7Vu7zXf9qYZ

View Details

Register for Secure The DIB: https://securethedib.us/

Voluntarily disclose your DFARS cybersecurity noncompliance? That'll be $1.75M, please. This week we're looking at the details of a recent False Claims Act settlement involving a small defense contractor. Turns out that mistaking export controls for cyber controls and relying on the wrong external service providers can controls can cost you a lot of money.

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

DOJ Settlement: https://www.justice.gov/opa/pr/california-defense-contractor-and-private-equity-firm-agree-pay-175m-resolve-false-claims

DFARS 7012: https://youtu.be/cy4e28YAkXU?si=KvezY7Vu7zXf9qYZ

View Details

Register for Secure The DIB: https://www.summit7.us/secure-the-dib-2025

We can't remember a 30-day stretch in the history of CMMC that had more milestones and memos than July 2025. The ecosystem is closing-in on 300 Level 2 certified companies, mega primes have put everyone on notice, the phased roll-out is weeks away, the secretary of defense, the Army Corps of Engineers, you name it – everybody is gearing up for the big day. This week we're talking about 5 things you might have missed while on summer vacation.

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

Secure the DIB: https://www.summit7.us/secure-the-dib-2025

Lockheed Memo: https://youtu.be/gMHWhXhe_Uo?si=FtkziMSqBWfzWAWp

SECDEF Memo: https://media.defense.gov/2025/Jul/22/2003759081/-1/-1/1/ENHANCING-SECURITY-PROTOCOLS-FOR-THE-DEPARTMENT-OF-DEFENSE.PDF

48 CFR Progress: https://youtu.be/Q2qeJhA4oIs?si=b1bRqxcR0MbTOWIj

USACE Notice: https://sam.gov/workspace/contract/opp/0b14a472d53b454ea6bca0893b2647d0/view

View Details

Register for Secure The DIB: https://www.summit7.us/secure-the-dib-2025

The Cyber AB brought the CMMC Ecosystem together once again for the July 2025 installment of their monthly Town Hall series. Join us for this week's show as we discuss all the information distributed during the meeting that you need to know; answers to questions like:

After your assessment, you get 10 days to do what?

How many CMMC assessments took place in July?

Does anyone fail their assessment, and do they keep track of them? And so much more... Tune in to find out!

Secure the DIB: https://www.summit7.us/secure-the-dib-2025

CMMC Just Crossed A Huge Rulemaking Milestone: https://youtu.be/Q2qeJhA4oIs?si=IQ1bYI6jH3VGuxAa

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

AB Town Halls: https://cyberab.org/News-Events/Town-Halls/Details/march-town-hall

View Details

Register for Secure The DIB: https://www.summit7.us/secure-the-dib-2025

The final rule that allows DoD to include CMMC requirements in defense contracts and solicitations has officially moved into regulatory review. This is the last milestone before official publication and the start of the CMMC “phased roll-out". Because this final rule simply implements CMMC policy that went into effect in December 2024, we believe CMMC will start showing up in contracts as early as late October.

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

Secure the DIB: https://www.summit7.us/secure-the-dib-2025

Self-Assessments/Waivers: https://youtu.be/LTgmrsFGr9s?si=jm7U4s4vQpgvj4J-

PALT: https://youtu.be/NZs4f5voyrg?si=mjzethgW61SLad7t

View Details

Register for Secure The DIB 2025: https://www.summit7.us/secure-the-dib-2025

When it comes to cyber incident reporting requirements people are always concerned with how well the government will protect a company's breach information. When the DoD overhauled contractor cyber requirements in 2016 to focus on incident reporting they included a clause that specifically addresses those concerns: DFARS 252.204-7009.

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplx

SfvkaRVhRo

OPM Data Breach: https://en.wikipedia.org/wiki/Office_of_Personnel_Management_data_breach

DFARS 7008: https://youtu.be/vgrRGIWboKc?si=g4vc5bKG6Y6G-DDo

DFARS 7012: https://youtu.be/cy4e28YAkXU?si=ImBm-iI6mh3Xs1sF

DFARS 7019: https://youtu.be/7gW_82Cus7Y?si=LxB__5jeSuJMoL5C

DFARS 7020: https://youtu.be/D4JLkfvB-Ws?si=YG6CRn2w7rRv2Ofo

View Details

An industry event for DoD Contractors & Higher Education Institutions: https://www.summit7.us/secure-the-dib-2025

Lockheed Martin wants their suppliers to know two things. First, suppliers should be fully and confidently compliant with existing DFARS cybersecurity requirements. Second, suppliers should be fully transitioned to the “Cybersecurity Compliance and Risk Assessment” tool. All of this before CMMC ever shows up in contracts. This shouldn't come as a surprise to anyone because this is the 6th CMMC memo from Lockheed in the last 18 months. This week we take a look at each one to see where things are headed (hint: they all say the same thing).

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

Blog: https://www.summit7.us/blog/lockheed-martin-pushes-suppliers-toward-urgent-cybersecurity-compliance

Lockheed Memo: https://www.lockheedmartin.com/en-us/suppliers/news/features/2025/cybersecurity-program-rule.html

Memo Recap: https://youtu.be/IKpH2F259J8?si=qmCyo4Mi57UvMx0g

DFARS 7012: https://youtu.be/cy4e28YAkXU?si=RJwhoS6NrZJgo9Xj

DFARS 7012 Class Deviation: https://youtu.be/voziZRAMvv4?si=Pm3mtgR338PE3B7b

DFARS 7020: https://youtu.be/D4JLkfvB-Ws?si=aa45Tr3_UhtbtH4t

View Details

Continuing our back-to-basics series of the “DFARS Cyber Series” of provisions and clauses brings us to clause 252.204-7020. This clause applies to defense contractors who are required to comply with DFARS clause 252.204-7012. Through DFARS 7020 the DoD reserves the right to conduct a higher-level assessment of a contractor's cybersecurity compliance. Additionally, defense contractors must give DoD assessors full access to their facilities, systems, and personnel.

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

DFARS 7008: https://youtu.be/vgrRGIWboKc?si=g4vc5bKG6Y6G-DDo

DFARS 7012: https://youtu.be/cy4e28YAkXU?si=ImBm-iI6mh3Xs1sF

DFARS 7019: https://youtu.be/7gW_82Cus7Y?si=LxB__5jeSuJMoL5C

View Details

The Cyber AB brought the CMMC Ecosystem together once again for the June 2025 installment of their monthly Town Hall series. Join us for this week's show as we discuss all the information distributed during the meeting that you need to know; answers to questions like:

Is the Ecosystem growing?

How many certifications were awarded this month?

Does Microsoft have to be at my assessment?

And so much more... Tune in to find out!

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

AB Town Halls: https://cyberab.org/News-Events/Town-Halls/Details/march-town-hall

View Details

System Security Plans are the single most fundamental documents underpinning cybersecurity compliance for defense contractors. But even after nearly 40 years of using SSPs for federal information systems there are essentially zero examples of what good looks like. Thankfully NIST is revising SP 800-18 guidance on developing SSPs and wants your comments. This is a crash course on SSPs so you can get caught up before the July 30th comment deadline.

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

DFARS 7008: https://youtu.be/vgrRGIWboKc?si=g4vc5bKG6Y6G-DDo

DFARS 7012: https://youtu.be/cy4e28YAkXU?si=ImBm-iI6mh3Xs1sF

DFARS 7019: https://youtu.be/7gW_82Cus7Y?si=LxB__5jeSuJMoL5C

NIST SP 800-18r2: https://csrc.nist.gov/pubs/sp/800/18/r2/ipd#:~:text=NIST%20Special%20Publication%20800%2D18r2,and%20mission%2Fbusiness%20process%20requirements.

NIST SP 800-18r1: https://csrc.nist.gov/pubs/sp/800/18/r1/final

The History of CMMC: https://youtu.be/jbY2irZ1ePg?si=_Ay66UqRUU9ShhJV

View Details

The CMMC program has been in-effect for six months and hundreds of early adopters have achieved CMMC Level 2 status. Today we speak with Fernando Machado, managing principal at Cybersec Investments, an authorized C3PAO. Fernando has completed 25 CMMC Level 2 assessments and he has a ton of valuable takeaways to share.

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

Fernando (LinkedIn): https://www.linkedin.com/in/fernando-machado-cissp-cism-cca-ccp-5b5581124/

Fernando pod (Dec 2024): https://youtu.be/KKJtW4G44WA?si=qzAnzp7_VrCl2Rdu

View Details

We're back to basics this week with DFARS provision 252.204-7019. SPRS scores? DIBCAC High assessments? DoD Assessment Methodology? It all started in 2020 with a humble four paragraph provision that was overshadowed by CMMC 1.0. These days the Department of Justice is settling False Claims Act lawsuits for millions and defense contracts aren't getting renewed all thanks to the DFARS cyber provision everyone loves to forget.

View Details

The Cyber AB has once again convened the CMMC ecosystem to deliver the monthly Town Hall covering the latest news and information about the CMMC Program. Join Jason and Joy as they talk about the latest ecosystem happening for the month of May.

There has been another branding change, an event filled week in Vegas, more conversations around 10-day re-evaluation periods for CMMC assessments, stats on completed assessments and ecosystem growth, ESP and CSP clarification, and so much more...

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

AB Town Halls: https://cyberab.org/News-Events/Town-Halls/Details/march-town-hall

View Details

The CMMC program regulation went into effect in December 2024, but the DoD can't insert CMMC requirements in contracts until they finish revising regulatory contract clause language. The window for the long-awaited contract clause final rule is opening next month. We predict that CMMC will start showing up in defense contracts between June – October 2025.

Episode Links:

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

DFARS 7012: https://youtu.be/cy4e28YAkXU?si=enUg-mPyZgl3FlYK

PALT: https://youtu.be/NZs4f5voyrg?si=KOEiREzXFe5LNAXZ

Katie's Keynote: https://youtu.be/OrPsD24j2Es?si=NSyhli9NW7Y1HJSH

Contractor noncompliance: https://youtu.be/lsiR1KSQKUo?si=hSGzUzJFj1x8PT48

View Details

Katie Arrington is the architect of the CMMC program, currently performing the duties of the DoD CIO, and she is ultra pissed that defense contractors haven't improved their cybersecurity posture while she was gone for 3 short years. This week we dive into Katie's keynote at AFCEA TechNet Cyber 2025 where she didn't mince words about CMMC, the DIB, and the coming storm.

Register for CEIC West: https://ceicwest.com/

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

Katie's Keynote: https://www.youtube.com/watch?v=n4dNFn_HX20

DFARS 7012: https://youtu.be/cy4e28YAkXU?si=F8FSzFqaWMXQ2h8e

View Details

The Cyber AB has once again convened the CMMC ecosystem to deliver the monthly Town Hall covering the latest news and information about the CMMC Program; and Joy has once again joined the show so we can talk about the latest ecosystem happening for the month of April. A change in CAICO leadership, stats on completed assessments, another audit, a “ESP, not a CSP” MythBusters/Ecosystem ethics fusion, and so much more...

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

AB Town Halls: https://cyberab.org/News-Events/Town-Halls/Details/march-town-hall

View Details

It's that time of year again and this time CS2 is coming to Reston, VA. This week we walk through the agenda adn talk about the sessions we're most excited for. Whistleblower attorneys? C3PAO lessons learned? Real world defense contractors who have completed CMMC Level 2? Prime contractor perspectives on upcoming requirements? CS2 has it all.

Register for CS2 Reston: https://cs2.cloud/reston

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

View Details

DoD has officially released their parameters for NIST SP 800-171 revision 3 requirements. Defense contractors now have a clear picture of their future compliance requirements and what assessors will ask for under “CMMC 3.0”. But if SP 800-171r3 won't be required for some time, why did the DoD publish their organizationally defined values? In this episode we dive into the basics of “ODPs”, why they matter, and how contractors can leverage them now to future-proof their systems against regulatory updates.

Register for CS2 Reston: https://cs2.cloud/reston

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

Memo: https://dodcio.defense.gov/cmmc/Resources-Documentation/

ODP Deep Dive: https://www.youtube.com/watch?v=QXfzSo4_F54

Deep Dive w/ Ron Ross: https://www.youtube.com/watch?v=x37V6fE-ies

171r3: https://www.youtube.com/watch?v=TAzYQjLfPY0

7012 Class Deviation: https://www.youtube.com/watch?v=voziZRAMvv4

View Details

Most people mistaken believe that their cybersecurity requirements stem from the Cybersecurity Maturity Model Certification Program (CMMC). CMMC is simply a verification program that proves if you have implemented the requirements imposed by DFARS clause 252.204-7012. Ultimately, DFARS clause 252.204-7012 is the center of gravity for all the cybersecurity stuff that comes with being a defense contractor. This week is an important primer on DFARS 7012 because even though it's only 13 paragraphs long, few people take the time to read it closely.

Register for CS2 Reston: https://cs2.cloud/reston

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

DFARS 7008: https://youtu.be/vgrRGIWboKc?si=TFuX_wYBgfDhNQ8X

DFARS 7012: https://www.acquisition.gov/dfars/252.204-7012-safeguarding-covered-defense-information-and-cyber-incident-reporting.

The History of CMMC: https://youtu.be/jbY2irZ1ePg?si=Khw6kLH5JnXfiTs6

7012 Class Deviation: https://youtu.be/voziZRAMvv4?si=2TczM85cISzpd63V

FedRAMP equivalency memo: https://youtu.be/torWNL3U7ZY?si=_tAubFpxJxtqrS6L

View Details

After 100 episodes diving into every possible rabbit hole to help illuminate the bigger picture around CMMC we're starting over at square zero: the “DFARS Cyber Series” of contract clauses. First up: the solicitation provision 252.204-7008. Although 7008 doesn't have the notoriety of it's big brother DFARS 252.204-7012, it is the first domino that triggers the cascade of cybersecurity compliance obligations that ultimately culminate in CMMC assessment.

Register for CS2 Reston: https://cs2.cloud/reston

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

DFARS 252.204-7008: https://www.acquisition.gov/dfars/252.204-7008-compliance-safeguarding-covered-defense-information-controls.

The 2016 final rule: https://www.federalregister.gov/documents/2016/10/21/2016-25315/defense-federal-acquisition-regulation-supplement-network-penetration-reporting-and-contracting-for

View Details

The Department of Justice finally did it: they went after a small defense contractor for failure to comply with their contractually obligated cybersecurity requirements. This case has it all from fake SPRS scores to whistleblowers getting paid hundreds of thousands of dollars to contractors paying millions in fines. All thanks to the same set of contract clauses in every DoD contract and the same errors committed by the vast majority of defense contractors.

Register for CS2 Reston: https://cs2.cloud/reston

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

DOJ press release: https://www.justice.gov/opa/pr/defense-contractor-morsecorp-inc-agrees-pay-46-million-settle-cybersecurity-fraud

Law firm press release: https://www.prnewswire.com/news-releases/morsecorp-agrees-to-pay-4-6-million-to-settle-landmark-cybersecurity-false-claims-act-case-brought-by-whistleblower-law-collaborative-client-302412118.html?tc=eml_cleartime

FCA w/ Stephanie Siegmann: https://youtu.be/d1yweDy2wV4?si=_CgQ3WTV2ynVbEyL

FCA w/ Alex Canizares: https://youtu.be/Tga0krfIrEk?si=oOXG-zvYcV_mGTL2

View Details

The Cyber AB is back with their monthly Town Hall meeting which can only mean one thing; Joy is here to co-host the show, and we are gonna break down the information distributed during the meeting. The ecosystem is growing, CMMC is going international, and so much more! Tune in to see what we have to say!

Register for CS2 Reston: https://cs2.cloud/reston

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

Sum IT Up ‘Canada's CMMC': https://youtu.be/AFe8CeIosYk?si=3Um3sXa1IEoTvAbD

AB Town Halls: https://cyberab.org/News-Events/Town-Halls/Details/march-town-hall

View Details

The Canadian Program for Cyber Security Certification (CPCSC) requires defense contractors to undergo assessment against NIST SP 800-171 revision 3. That's a big problem for contractors who also do work for the U.S. Department of Defense because CMMC currently evaluates NIST SP 800-171 revision 2 and will for quite some time. In this episode we dive into what we know about Canada's version of CMMC and how close (or far) we are from reciprocity between the programs and what might be done to close the gap.

Register for CS2 Reston: https://cs2.cloud/reston

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

CPCSC Info: https://www.canada.ca/en/public-services-procurement/services/industrial-security/security-requirements-contracting/cyber-security-certification-defence-suppliers-canada.html

View Details

At long last we've come to the fourth and final episode covering every finding and allegation in the DoD Inspector General Report on the CMMC process for authorizing 3rd-party assessment organizations. So far none of the 10 findings come anywhere close spelling doom for the CMMC program. Perhaps the juiciest scandals were saved for last?

Register for CS2 Reston: https://cs2.cloud/reston

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

DoD IG report: https://www.dodig.mil/reports.html/Article/4028189/audit-of-the-dods-process-for-authorizing-third-party-organizations-to-perform/

IG Report Part 1: https://youtu.be/RNafaUlgBGo?si=4prcpAp3GUAhk8nN

IG Report Part 2: https://youtu.be/_kU7N2uI3xU?si=li1PwnG-FRSBjzyb

IG Report Part 3: https://youtu.be/3ND8RG2cKEc?si=ap5N5jasjYSztUVn

View Details

We're almost done with our exploration of DoD Inspector General audit of the CMMC C3PAO authorization process. The last two recommendations might be the most perplexing of all. Maybe the Inspector General saved the best for last?

Register for CS2 Reston: https://cs2.cloud/reston

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

DoD IG report: https://www.dodig.mil/reports.html/Article/4028189/audit-of-the-dods-process-for-authorizing-third-party-organizations-to-perform/

IG Report Part 1: https://youtu.be/RNafaUlgBGo?si=4prcpAp3GUAhk8nN

IG Report Part 2: https://youtu.be/_kU7N2uI3xU?si=li1PwnG-FRSBjzyb

View Details

The Cyber AB is back with their monthly Town Hall meeting. This week we dive into “what's new” with the CMMC Program for the month of February covering things like: What do the ecosystem numbers look like right now? What's up with T3 suitability? Can people announce if they're certified yet? And so much more!

Register for CS2 Reston: https://cs2.cloud/reston

Register for S7 Live: https://www.summit7.us/s7live

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

View Details

The DoD has released guidance to the contracting workforce that implements the 32 CFR CMMC final rule. This week we discuss the two big takeaways for defense contractors. 1) Level 2 self-assessments are unlikely for 99% of companies. 2) CMMC waivers will be even more rare.

Register for CS2 Reston: https://cs2.cloud/reston

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

Memo (PDF): https://dodprocurementtoolbox.com/uploads/DOPSR_Cleared_OSD_Memo_CMMC_Implementation_Policy_d26075de0f.pdf

NARA CUI Registry: https://www.archives.gov/cui/registry/category-list DoDI 5230.24 (PDF): https://www.esd.whs.mil/portals/54/documents/dd/issuances/dodi/523024p.pdf

View Details

This week we continue our exploration of DoD Inspector General audit of the CMMC C3PAO authorization process. The majority of the recommendations pertain to the Cyber AB, but are all of the recommendations even actionable? We think you'll be surprised at the disparity between the headlines and what the report actually says.

Register for CS2 Reston: https://cs2.cloud/reston

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

Part 1: https://youtu.be/RNafaUlgBGo?si=2gzHIeHv0JevFwbx

DoD IG report: https://www.dodig.mil/reports.html/Article/4028189/audit-of-the-dods-process-for-authorizing-third-party-organizations-to-perform/

View Details

The DoD Inspector General's report on the C3PAO authorization process is out and people haven't been shy with their takes on the findings. This week we dive into the first set of recommendations to see if there really is a smoking gun. We think you'll be surprised at the disparity between the headlines and what the report actually says.

Register for CS2 Reston: https://cs2.cloud/reston

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

DoD IG report: https://www.dodig.mil/reports.html/Article/4028189/audit-of-the-dods-process-for-authorizing-third-party-organizations-to-perform/

View Details

The Cyber AB is back with their monthly Town Hall meeting. This week we dive into the current status of the CMMC Program, the last checklist item before official L2 certification announcements, and more.

Register for CS2 Reston: https://cs2.cloud/reston - Use code SUMITUPRESTON for listener discount

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

AB Town Halls: https://cyberab.org/News-Events/Town-Halls/Details/february-town-hall

“Freeze” Memo: https://youtu.be/L6FUBpogntM?si=0blDfn4tj3E6y_hC

View Details

Regulatory “freeze memos” have been common practice for new presidential administrations since 2001. Some people believe the most recent freeze memo spells the end of CMMC. Those people are incorrect for an assortment of reasons that we dive into this week.

Register for CS2 Reston: https://cs2.cloud/reston

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

The “freeze memo” (2025): https://www.whitehouse.gov/presidential-actions/2025/01/regulatory-freeze-pending-review/

The “freeze memo” (2021) (PDF): https://www.regulationwriters.com/downloads/Klain_Freeze_Memo-012021.pdf

The “freeze memo” (2017): https://trumpwhitehouse.archives.gov/presidential-actions/memorandum-heads-executive-departments-agencies/

The “freeze memo” (2009) (PDF): https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/agencyinformation_memoranda_2009_pdf/m09-08.pdf

The “freeze memo” (2001): https://www.presidency.ucsb.edu/documents/memorandum-from-andrew-card

CMMC (32 CFR 170): https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-G/part-170

View Details

Cybersecurity requirements for protecting controlled unclassified information (CUI) aren't just for defense contractors anymore. The FAR CUI rule will affect all federal contractors handling CUI (and even those who don't). This episode introduces the main elements of the rule at a 30,000-foot level.

Register for CS2 Reston: https://cs2.cloud/reston

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

32 CFR CMMC Webinar: https://www.summit7.us/webinars/cmmc-32-cfr-final-rule

2024 Predictions: https://youtu.be/YzFkJGzny20?si=H7UurOVBgKPxpH7Q

FedRAMP memo: https://youtu.be/torWNL3U7ZY?si=_yFHuMqXpCg6hYWy

FAR CUI Rule: https://youtu.be/-bYjDy7z7BA?si=sYytd46cIhmXIP8A

The NARA CUI Registry: https://www.archives.gov/cui/registry/category-list

Cost estimate of 171 (2023): https://youtu.be/DkYefZn_wNk

How to submit effective public comments: https://youtu.be/1T_62cYiUA4

View Details

It's that time of year again where we stake our reputations on predicting the future of the CMMC regulatory landscape. What does our crystal ball say about the future hold for rulemaking, FedRAMP, and the CMMC ecosystem in general?

Register for CS2 Reston: https://cs2.cloud

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

32 CFR CMMC Webinar: https://www.summit7.us/webinars/cmmc-32-cfr-final-rule

2024 Predictions: https://youtu.be/YzFkJGzny20?si=H7UurOVBgKPxpH7Q

FedRAMP memo: https://youtu.be/torWNL3U7ZY?si=_yFHuMqXpCg6hYWy

FAR CUI Rule: https://youtu.be/-bYjDy7z7BA?si=sYytd46cIhmXIP8A

View Details

A year ago we made seven predictions for the CMMC landscape. We got some right, we got a few mostly right, and we got a few “wrong”.

Register for CS2 Reston with code SUMITUPRESTON: https://cs2.cloud/reston

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

32 CFR CMMC Webinar: https://www.summit7.us/webinars/cmmc-32-cfr-final-rule

2024 Predictions: https://youtu.be/YzFkJGzny20?si=H7UurOVBgKPxpH7Q

View Details

The Cyber AB has officially released the CMMC Assessment Process Guide. Now that the “CAP” is official, CMMC “false starts” are officially something that defense contractors need to be aware of.

Register for CS2 | Reston with code SUMITUPRESTON for 15% off here: https://cs2.cloud/reston

CMMC Cap (PDF): https://cyberab.org/Portals/0/Documents/Process-Documents/CMMC-Assessment-Process-CAP-v1.0.pdf

False starts 1.0 (June ‘24): https://youtu.be/zwU4u86L_5A

NFO Controls: https://youtu.be/YEQd--RIUkU

Documentation Deep Dive: https://youtu.be/TXsKdH3hC6E

View Details

The CMMC Program has reached it “Birth” date and part of the celebration was the rellease ong the newly revised, effective, and in-force version of the CMMC Assessment Process (CAP, and the CMMC Code of Professional Conduct (CoPC). Jason and Joy have been picking apart these documents since their release; and on this week's show, they offer their 7 “high level” takeaways from CAP 2.0 & CoPC 2.0.

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

CS2: Reston : https://cs2.cloud/reston

View Details

This week we're joined by Fenando Machado of Cybersec Investments, an authorized CMMC C3PAO. Fernando has been around the CMMC space for years and has helped a ton of companies successfully pass their Joint Surveillance Assessments. Fernando shares what he's learned ahead of the effective date of the 32 CFR CMMC final rule and the rest of the phased roll-out.

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

32 CFR CMMC Webinar: https://www.summit7.us/webinars/cmmc-32-cfr-final-rule

Fernando: https://www.linkedin.com/in/fernando-machado-cissp-cism-cca-ccp-5b5581124/

Cybersec Investments (C3PAO): https://cybersecinvestments.com/

(0:00 – 3:17): Intro (3:18 – 6:42): What's the key to assessment success? (6:43 – 8:48): What's the key to perfect scores? (8:49 – 11:42): Most problematic controls? (11:43 – 12:52): What's harder: technical or non-technical? (12:53 – 14:42): Are “False Starts” real? (14:43 – 17:44): How important is an MSP? (17:45 – 20:45): Current backlog? (20:46 – 22:38): $100k assessments? (22:39 – 24:27): Outro

View Details

What is the CMMC phased roll-out? How will the CMMC phased roll-out affect defense contractors and when? Most importantly: How should companies strategize based on the CMMC phased roll-out? We get into all of that and more this week.

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

32 CFR CMMC Webinar: https://www.summit7.us/webinars/cmmc-32-cfr-final-rule

View Details

Who decides what CMMC status level is required in defense contracts? How do they decide? Q2 2025 is just around the corner and this week we dive into the decision factors that lead to CMMC status level requirements.

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

32 CFR CMMC Webinar: https://www.summit7.us/webinars/cmmc-32-cfr-final-rule

48 CFR proposed rule podcast: https://youtu.be/Fzi3SFEs92U

View Details

A Joint Resolution of Disapproval has been submitted to disapprove the 32 CFR CMMC final rule. Is this the end of CMMC as we know it? Or, as is usually the case, has the ecosystem jumped to conclusions and let their confirmation bias get the better of them? This week we go deep into the Congressional Review Act and why there's much more to the story of Representative Palmer's resolution.

Pathfinder 101: https://www.summit7.us/pathfinder

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

32 CFR CMMC Webinar: https://www.summit7.us/webinars/cmmc-32-cfr-final-rule

Palmer's Resolution: https://www.congress.gov/bill/118th-congress/house-joint-resolution/221/text

GAO Report on the CMMC final rule: https://www.gao.gov/products/b-336776

View Details

CMMC Pathfinder Tool | In 5 minutes or less, this free tool will give you a clear path from where you are now to CMMC confidence: https://www.summit7.us/pathfinder

Start working on that beach body of evidence because all signs point to CMMC showing up in defense contracts in Summer 2025. Turns out that our Summer estimate is more conservative than government estimates. However, if you're a subcontractor then it doesn't matter much because the big primes are already telling people what time it is.

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

32 CFR CMMC Webinar: https://www.summit7.us/webinars/cmmc-32-cfr-final-rule

SBA Blog: https://advocacy.sba.gov/2024/10/24/dod-final-cmmc-rule/

32 CFR Final Rule: https://www.federalregister.gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-certification-cmmc-program

View Details

CMMC Pathfinder Tool | In 5 minutes or less, this free tool will give you a clear path from where you are now to CMMC confidence: https://www.summit7.us/pathfinder

As a result of the 32 CFR Final CMMC rule, many organizations will be looking for help comprehending and implementing the imposed requirements. On this episode of the show, Jason and Joy dig into the differences between the Registered Practitioner (RP) certificate, and the Certified CMMC Professional (CCP) certification to highlight the value of the trainings for OSAs and ESP, and point out the importance of due dillegence above all!

[Webinar] CMMC Finalized: The 32 CFR CMMC Final Rule | Register Now: https://www.summit7.us/webinars/cmmc-32-cfr-final-rule

SPRS Scoring Webinar with Koren Wise - https://us06web.zoom.us/meeting/register/tZIoceihrTgoEtIS5scNKD_VWYB5IvLdYjSq

View Details

[Webinar] CMMC Finalized: The 32 CFR CMMC Final Rule | Register Now: https://www.summit7.us/webinars/cmmc-32-cfr-final-rule

The Cyber AB Townhall for the Month of October is the First TH since the publishing of the 32 CFR Final CMMC rule. On this episode of the show, Jason and Joy dig into the information distributed during the Townhall surrounding the re-authorization of C3PAOs and the eligibility of CMMC Certified Assesors (CCA).

CMMC Pathfinder Tool: https://www.summit7.us/pathfinder

View Details

[Webinar] CMMC Finalized: The 32 CFR CMMC Final Rule | Register Now: https://www.summit7.us/webinars/cmmc-32-cfr-final-rule

After years of waiting the FAR CUI rule has cleared regulatory review and we should see the proposed rule published in just a few weeks. In this episode we briefly cover the history of the FAR CUI rule and discuss what we know about it (and what we think we know).

The FAR CUI rule review page: https://www.reginfo.gov/public/do/eoDetails?rrid=539461

CMMC Pathfinder Tool: https://www.summit7.us/pathfinder

View Details

CMMC Pathfinder Tool | In 5 minutes or less, this free tool will give you a clear path from where you are now to CMMC confidence: https://www.summit7.us/pathfinder

The 32 CFR CMMC final rule is finally final! It's also 470 pages long. What gives? Public comment responses. Literally just 230 pages of responses to public comments. While some of the responses are helpful, much of the time DoD was forced to take the time and space to explain why comments weren't relevant to the CMMC program at all.

Final Rule Webinar: https://www.summit7.us/webinars/cmmc-32-cfr-final-rule

Effective Comments How To: https://youtu.be/1T_62cYiUA4?feature=shared

Pathfinder Demo: https://youtu.be/JiDTCchfCa0?feature=shared

View Details

CMMC Pathfinder Tool | In 5 minutes or less, this free tool will give you a clear path from where you are now to CMMC confidence: https://www.summit7.us/pathfinder

Yet another report analyzing defense contractor cybersecurity and compliance with DFARS contract clauses has found that adoption remains low. Even when companies are aware of their obligations, believe that CMMC will happen in 2024, and support minimum requirements there is no guarantee that implementation will happen. This week we dive into why that might be.

View Details

CMMC Pathfinder Tool | In 5 minutes or less, this free tool will give you a clear path from where you are now to CMMC confidence: https://www.summit7.us/pathfinder

Calculating a self-assessment score is a fundamental part of complying with DoD cyber regulations. Unfortunately, Project Spectrum, the resource that DoD recommends more than any other no longer calculates an “SPRS score”. In this episode we briefly explain the requirement to self-assessment, the basics of calculating a score, and a little-known tool from DoD that can help.

Summit 7 Pathfinder Tool: https://www.summit7.us/pathfinder

Fuzzy Math (2021): https://youtu.be/843K3hkLquk

Project Spectrum: https://www.projectspectrum.io/#/

DIBCAC: https://www.dcma.mil/DIBCAC/

DoDAM (PDF): https://www.acq.osd.mil/asda/dpc/cp/cyber/docs/safeguarding/NIST-SP-800-171-Assessment-Methodology-Version-1.2.1-6.24.2020.pdf

CMMC Scoring: https://www.federalregister.gov/d/2023-27280/p-1429

CMMC False Starts: https://youtu.be/zwU4u86L_5A?

View Details

CMMC Pathfinder Tool | In 5 minutes or less, this free tool will give you a clear path from where you are now to CMMC confidence: https://www.summit7.us/pathfinder

The Cyber AB held the monthly Townhall for September. And with the 32 CFR rule imminent, they have a lot of information to put out lately. On this week's episode, Jason and Joy are joined by Kyle Gingrich, Interim Executive Director of the CAICO, as they cover the information distributed during this months townhall, changes to CMMC Ecosystem roles, the gold ole' days of CMMC, and so much more.

Sum IT Up “CMMC Final Rule Publication: Imminent” : Driving a Future-Ready Transportation Sector (youtube.com)

Link to FedRAMp Equivalency Memo: FEDRAMP-EquivalencyCloudServiceProviders.pdf (defense.gov)

View Details

CMMC Pathfinder Tool | In 5 minutes or less, this free tool will give you a clear path from where you are now to CMMC confidence: https://www.summit7.us/pathfinder

The 32 CFR CMMC final rule has officially cleared regulatory review. Next step: publication in the Federal Register. At this point the commercially availability of CMMC assessments is weeks away. This week Jacob and Jason go over the basics of rulemaking, the details of the CMMC rulemaking timeline, what's left in the process, and how to get started once and for all.

Summit 7 Pathfinder Tool: https://www.summit7.us/pathfinder

The History of CMMC (2010 – 2020): https://youtu.be/jbY2irZ1ePg

Pathfinder Tool Demo: https://youtu.be/JiDTCchfCa0?

View Details

CMMC Pathfinder Tool | In 5 minutes or less, this free tool will give you a clear path from where you are now to CMMC confidence: https://www.summit7.us/pathfinder

This week we're deep diving into the details of DoD distribution statements with guest host Defcert CEO, Ryan Bonner. Hoping that your customer will proactively minimize CUI for you just isn't a viable strategy in this cruel world. Instead, Ryan walks us through his process for reverse engineering the government's decision to mark something (or not). Armed with this information, contractors can more easily push back on their customers and scope their DFARS and CMMC environments – the holy grail.

Summit 7 Pathfinder Tool: https://www.summit7.us/pathfinder

Ryan CS2 Denver: https://youtu.be/IEy-TkmKMt8?si=euj5dH7shvrvpbAt

RTX Charging Letter: https://www.linkedin.com/posts/jacob-evan-horne_whoopsie-daisy-62b-defense-corporation-activity-7237851962417774594-tbly

DoD CUI Registry: https://www.dodcui.mil/

NARA CUI Registry: https://www.archives.gov/cui/registry/category-list

View Details

CMMC Pathfinder Tool | In 5 minutes or less, this free tool will give you a clear path from where you are now to CMMC confidence: https://www.summit7.us/pathfinder

Special guest host Daniel Akridge walks us through a visual of Procurement Administrative Lead Time compared to the CMMC rulemaking timelines. Daniel also walks us through Summit 7's CMMC Pathfinder Tool - a free resource companies can use to know exactly what steps they should take and what solutions might work best.

Connect with Daniel on LinkedIn: https://www.linkedin.com/in/danielakridge/

Connect with Jacob on LinkedIn: https://www.linkedin.com/in/jacob-evan-horne/

PALT Podcast: https://www.youtube.com/watch?v=NZs4f5voyrg

CMMC Pathfinder Tool: https://www.summit7.us/pathfinder

View Details

The team is back from Navy Gold Coast 2024, and we have some thoughts and takeaways from one of the largest defense industry conferences of the year. The DoD and small businesses are looking ahead to 2025 acquisition calendars while CMMC inches closer by the day.

Follow Hollie: https://www.linkedin.com/in/hollieflanner/

48 CFR Rule: https://youtu.be/Fzi3SFEs92U?si=HrOU9ZnlrSd_-hPr

PALT: https://youtu.be/NZs4f5voyrg?si=RNq22xmwbd7oZUxZ

National Defense Strategy Pod: https://youtu.be/TZtNQ8rg8eI?si=UKMscIx6tlkjKKuL

The DIB Cyber Strategy Pod: https://youtu.be/JYsmwcWzglU?si=veyhdqi0T2Dnhpsc

The National Defense Industrial Strategy Pod: https://youtu.be/ZKKkyK5PeOc?si=109D07JfcZFSVaXf

View Details

CMMC isn't a requirement to bid on defense contractors, but CMMC is a requirement to take award of DoD contracts. That means the most important metric is how much time you have between bidding and taking award. Turns out that “PALT” times are rarely long enough to go from zero to certified and that's a big, big problem for companies who are waiting on CMMC.

Episode Links:

48 CFR Proposed Rule: https://youtu.be/Fzi3SFEs92U?si=jUpnHDQvFiiqOuc8

GAO report on PALT: https://www.gao.gov/products/gao-24-106528

Secure the DIB replay: https://www.summit7.us/securethedib

View Details

1,417 days after the original CMMC contract clause was created and 1,003 days after the announcement of CMMC 2.0 here we are – the proposed rule revising DFARS clause 252.204-7021. This is the piece of the puzzle that will actually show up in your RFPs, contracts, awards, orders, etc. What does it say? Who does it affect? When will it show up? We step through it line-by-line.

View Details

If you haven't caught a Cyber AB Town Hall lately, then you're missing out on valuable information. This week we give our take on the AB's rulemaking timeline, what the FY25 NDAA says about CMMC, the upcoming DoD IG report on the Cyber AB, and more!

Cyber AB Town Halls: https://cyberab.org/News-Events/Town-Halls

Secure the DIB replay: https://www.summit7.us/securethedib

View Details

Register for Secure the DIB: Summer Camp for FREE here: https://www.securethedib.us/

You're not crazy. According to a new inspector general report the federal CUI Program has been in hibernation for the last few years. But the story goes much deeper than run-of-the-mill findings. Desperately overworked civil servants, stubbornly non-compliant federal agencies, the lofty heights of the National Security Council, and even rumors of a new CUI executive order. This story might seem a world away from the day-to-day concerns of defense contractors, but what happens on top of the mountain inevitably rolls downhill.

ISOO IG Report: https://naraoig.oversight.gov/reports/audit/audit-naras-information-security-oversight-office

History of CMMC (2010 – 2020): https://youtu.be/jbY2irZ1ePg?si=bGiInfLCpr-WFvcF

View Details

Register for Secure the DIB: Summer Camp for FREE here: https://www.securethedib.us/

Summer is coming to a close and that means it's time for our annual Secure the DIB Summer Camp webinar. Summit 7's Daniel Akridge joins the show this week to share what he's seeing and hearing from defense contractors regarding market dynamics, what the primes are up to, and how companies are dealing with the cost of compliance.

Episode Links:

DIB Summer Camp: https://www.summit7.us/securethedib

Big Dan: https://www.linkedin.com/in/danielakridge/

View Details

Register for Secure the DIB: Summer Camp for FREE here: https://www.securethedib.us/

The DoD's Center for Manufacturing Cybersecurity has released a report documenting the level of confidence that defense contractors have in their cybersecurity posture. The conclusion? There is a systemic cybersecurity overconfidence problem in the DIB.

Episode Links:

DIB Summer Camp: https://www.summit7.us/securethedib

MxD Report: https://www.mxdusa.org/cyber/cyberreport/

View Details

Register for Secure the DIB: Summer Camp for FREE here: https://www.securethedib.us/

The 32 CFR CMMC final rule has officially left the DoD and is currently undergoing final regulatory review. This is the last step before publication in the Federal Register. Based on what we know, CMMC should be a reality before the end of 2024.

Episode Links: Proposed Rule Webinar: https://www.summit7.us/webinars/proposed-cmmc-rule

View Details

Now that SP 800-171 revision 3 is official, organizationally defined parameters (ODPs) are officially a part of our the rest of our lives. Like most things in SP 800-171 there are great details in SP 800-53 that help explain what's going on. In this episode we take a deep dive in requirement 3.1.8 through the lens of ODPs.

Episode Links:

SP 800-53: https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final

FedRAMP baselines: https://www.fedramp.gov/baselines/

View Details

The good news about NIST SP 800-171 revision 2 being the standard for the next few years is it's a smaller standard compared to revision 3. However, there are some confusing aspects to NIST SP 800-171 revision 2 that defense contractors can't afford to overlook. The most important? NFO Controls.

Episode Links:

NIST SP 800-171r2: https://csrc.nist.gov/pubs/sp/800/171/r3/final

DFARS 7012 Class Deviation: https://youtu.be/voziZRAMvv4?si=yPaUuHLnHIQsfGQu

Policy and Procedure Deep Dive: https://youtu.be/TXsKdH3hC6E?si=GoAlpEuMqQWAsOzr

View Details

NIST has released four introductory training courses for the 800 series of special publications that make up the basis for the NIST Risk Management Framework. Each 60 minute course does a great job covering SP 800-37, 53, 53A, and 53B. If you need a leg up on the knowledge that forms the basis of CMMC training, you should check out the courses.

NIST Training Courses:

NIST CPRT: https://csrc.nist.gov/projects/cprt/catalog#/cprt/home

View Details

Although CMMC assessments are difficult, CMMC certifications are achievable (assuming you have passed through the “assessment feasibility determination” prior to the actual assessment. For many companies, failing CMMC assessments won't be their biggest problem – it will be qualifying for the assessment in the first place.

Episode Links:

CMMC Cap (PDF): https://cyberab.org/Portals/0/Documents/Process-Documents/CMMC-Assessment-Process-CAP-v1.0.pdf

CMMC Fuzzy Math (2021): https://youtu.be/843K3hkLquk?si=aDuiomqVxSSwnExI

NIST Policy Controls: https://youtu.be/TXsKdH3hC6E?si=24svcK18w20DbLP_

View Details

This week we dive into the details of NIST policy and procedure controls. Love it or hate it, SP 800-171 requires policies and procedures regardless of revision. Luckily, it's easy to know what a good template looks like because policies have been outlined in NIST SP 800-53 for 20 years.

Episode Links:

NIST SP 800-53: https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final

NIST SP 800-53A: https://csrc.nist.gov/pubs/sp/800/53/a/r5/final

View Details

The FAR CUI proposed rule has officially moved into regulatory review with the Office of Information and Regulatory Affairs (OIRA). With the FAR CUI rule one step away from publication in the Federal Register, we dive a little deeper into what it is and some open questions we're looking forward to resolving when the rule, after nearly 10 years, is finally released.

Episode Links:

FAR CUI Rule Episode: https://youtu.be/lZv3JwJNfcQ?si=lBM8sF7sF2xyLwmB

FAR CUI Rule: https://www.reginfo.gov/public/do/eAgendaViewRule?pubId=202310&RIN=9000-AN56

View Details

After more than a year of development, revision 3 of SP 800-171 and 171A are officially done. This week we're joined by Dr. Ron Ross to discuss what NIST learned from public comments, why NIST decided to add 19 new requirements, the thought process behind “ORC” controls, and what the future holds for the CUI series, rulemaking, and the SP 800-53 catalog.

Episode Links:

171r3 overview: https://youtu.be/TAzYQjLfPY0?si=TTP49MujwB3Obchl

171r3 overview blog: https://www.summit7.us/blog/nist-800-171-revision-3

Dr. Ross on the 171r3 final draft: https://youtu.be/IMms3dlPUGo?si=8Wd3p0At4BUhMkCq

NIST deep dive with Dr. Ross: https://youtu.be/vAPFmga_NtI?si=9_n5kXvTUYPcmUys

Scott Goodwin at CS2 Boston: https://youtu.be/LFfbDpZRM_M?si=yVcd4BxiwpNPzdRO

View Details

DoD has officially submitted the 48 CFR CMMC proposed rule for regulatory review. As a result, we can now estimate the timelines for CMMC rules. Whatever was delaying the 48 CFR rule has apparently been fixed and that means contractors need to start getting serious about preparing for the coming CMMC roll-outs.

Episode links:

48 CFR CMMC: https://www.reginfo.gov/public/do/eAgendaViewRule?pubId=202310&RIN=0750-AK81

32 CFR CMMC: https://www.summit7.us/webinars/proposed-cmmc-rule

DIB CS Final Rule: https://youtu.be/E7GsBZMM1CI?si=3um3RYk8pDZH29Ca

CIRCIA Rule pt. 1: https://youtu.be/ngYSaO5fg5Y?si=1Z3G7_jGkmZ8KFxI

CIRCIA Rule pt. 2: https://youtu.be/kUdhl5QfziU?si=EIMlHpu_KMtcdAVX

SP 800-171r3 overview: https://youtu.be/TAzYQjLfPY0?si=32QowzgK33D9YLQx

DFARS 7012 class deviation: https://youtu.be/voziZRAMvv4?si=hHigkKuWpdbvDjW4

FAR CUI Rule: https://youtu.be/lZv3JwJNfcQ?si=6OKA2Kwz6tc_cMyS

View Details

NIST SP 800-171 revision 3 and SP 800-171A revision have been officially released. Although revision 3 won't be required for defense contractors for some time, it pays to see exactly what the future holds. On the surface revision 3 has fewer requirements than revision 2. However, under the hood of 171Ar3 there is actually a 32% increase in the number of verification questions that need to be answered. Overall, 171r3 is progress in the right direction even if it comes with a few warts.

Episode Links:

SP 800-171r3: https://csrc.nist.gov/pubs/sp/800/171/r3/final

SP 800-171Ar3: https://csrc.nist.gov/pubs/sp/800/171/a/r3/final

View Details

The obligation for defense contractors to implement NIST SP 800-171 revision 3 has been delayed indefinitely thanks to a recent “class deviation” published by the DoD. The 2023 CMMC proposed rule specified that it will assess SP 800-171 revision 2, but language in defense contracts would have triggered a crisis – until now. Nevertheless, SP 800-171 revision 3 will be the requirement, but contractors have some room to breathe.

Lauren Ayers: https://www.linkedin.com/in/laurencayers/

Lauren Episode: https://youtu.be/t9nLlcu47IU?si=RzCn1RsM4N7waGmF

DFARS “Effective Date”: https://youtu.be/Vuz56hPs4Ng?si=pgK8qmbbtRGT2DkP

Class Deviation: https://www.defense.gov/News/Releases/Release/Article/3763953/department-of-defense-issues-class-deviation-on-cybersecurity-standards-for-cov/

View Details

Register for our upcoming CS2 Replay here: https://www.summit7.us/webinars/exploring-the-real-world-security-value-of-cmmc

According to a very scientific LinkedIn poll, 61% of respondents think that DFARS clause 252.204-7012 incident reporting requirements should expand to match CIRCIA reporting requirements. While this move would make things more efficient for defense contractors, we're pretty sure folks are underestimating exactly how detailed a proposed CIRCIA incident report will be.

Episode Links:

CIRCIA Primer: https://youtu.be/ngYSaO5fg5Y?si=RSg4sWRRWuyrCr9S

View Details

Register for our upcoming CS2 Replay here: https://www.summit7.us/webinars/exploring-the-real-world-security-value-of-cmmc

Q2 2024 is upon us so this week we are updating the rulemaking calendar based on what we know about DFARS, CMMC, the FAR, and NIST revisions. If the Summer doldrums push things into the Fall then we could be in for a relentless holiday season.

Episode links:

CS2 Replay: https://www.summit7.us/webinars/exploring-the-real-world-security-value-of-cmmc

Q1 Rulemaking Calendar: https://youtu.be/IgebrVfrgWs?si=3mf5n2l1ODIlCUPt

View Details

Defense contractors have had cyber incident reporting obligations under DFARS clause 252.204-7012 for many years. Recently, however, CISA issued a 457-page proposed rule implementing the 2022 Cyber Incident Reporting for Critical Infrastructure Act. Unless CISA and DoD can reach an agreement, DIB contractors will have duplicative incident reporting obligations for two different agencies.

Episode Links:

CIRCIA Proposed Rule: https://www.federalregister.gov/documents/2024/04/04/2024-06526/cyber-incident-reporting-for-critical-infrastructure-act-circia-reporting-requirements

Congressional Research Service Report (PDF): https://crsreports.congress.gov/product/pdf/R/R48025

How to submit effective comments: https://youtu.be/1T_62cYiUA4?si=sp91i_cXFGiyD7JW

View Details

At long last the DIB Cybersecurity Strategy has officially been released and it's ... not great. One thing is clear: CMMC is a key part of the DoD's strategy and there are many DoD resources specifically designed to help contractors deal with it. Instead, the DoD is focused on coordination, communication, and threat intelligence sharing.

Episode Links:

DIB Cyber Strategy: https://www.defense.gov/News/Releases/Release/Article/3723439/dod-releases-defense-industrial-base-cybersecurity-strategy/

GCC: https://www.cisa.gov/resources-tools/groups/government-coordinating-councils

SCC: https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/defense-industrial-base-sector/sector-charters-and-membership

CIPAC: https://www.cisa.gov/resources-tools/resources/cipac-2022-charter

NSA Enduring Security Framework: https://www.nsa.gov/About/Cybersecurity-Collaboration-Center/Enduring-Security-Framework/

View Details

Register for CS2 | Boston here: https://cs2.cloud/boston

Even before the CMMC proposed rule looped managed service providers into CMMC certification, defense contractors needed to be aware of how long it takes their MSP to get ready to support their assessment. This week we preview a talk from CS2 Boston focusing on the rocky road for MSPs featuring Ryan Bonner and Daniel Akridge.

Podcast listeners use code SUMITUPBOSTON for a discount on registration

Episode Links:

Summit 7 Webinar: https://www.summit7.us/webinars/can-my-msp-do-cmmc

Daniel: https://www.linkedin.com/in/danielakridge/

Defcert: https://defcert.com/

Ryan: https://www.linkedin.com/in/rybonner/

GAO on lead times: https://www.linkedin.com/posts/jacob-evan-horne_gao-defense-contract-lead-times-activity-7174430584172138498-oSfY

View Details

Register for CS2 | Boston here: https://cs2.cloud/boston

After nearly two years of silence and almost a decade of waiting the FAR CUI rule is one step closer to reality. In this episode we dive into what the FAR CUI rule is and what it means for federal contractors outside of the defense industrial base.

Podcast listeners use code SUMITUPBOSTON for a discount on CS2 registration!

View Details

Register for CS2 | Boston here: https://cs2.cloud/boston

On March 11th, the DoD issued a final rule expanding eligibility for the DIB Cybersecurity Program to non-cleared defense contractors and their managed service providers. This week we dive into the features of the rule, how it lines up with CMMC, and why the DoD final expanded the program after 12 years.

Podcast listeners use the code SUMITUPBOSTON for a discount on registration!

The DIB CS Final Rule: https://www.federalregister.gov/documents/2024/03/12/2024-04752/department-of-defense-dod-defense-industrial-base-dib-cybersecurity-cs-activities

DCISE: https://www.dc3.mil/Missions/DIB-Cybersecurity/DIB-Cybersecurity-DCISE/

The 2020 Cyberspace Solarium Commission Report: https://www.solarium.gov/report

The 2023 Cyberspace Solarium Implementation Report: https://cybersolarium.org/annual-assessment/2023-annual-report-on-implementation/

View Details

Register for CS2 | Boston here: https://cs2.cloud/boston

NIST has released their summary of public comments received on the final drafts of SP 800-171 revision 3 and SP 800-171A revision 3. Jason and Jacob dive into when to expect the final revisions and what to expect in the revised requirements.

Podcast listeners get a discount on CS2 registration, just use the code: SUMITUPBOSTON

Episode Links:

NIST CUI Project Page: https://csrc.nist.gov/projects/protecting-controlled-unclassified-information

171r3 Blog: https://www.summit7.us/blog/nist-800-171-rev3-final-draft

ORC Control Poll: https://www.linkedin.com/posts/jacob-evan-horne_supply-chain-security-pop-quiz-nist-control-activity-7168287222444576769-7iw_

View Details

Register for CS2 | Boston here: https://cs2.cloud/boston

The public comment period on the CMMC proposed rule has closed so what happens next? In this episode we wade through the red tape in store over the next 12 months.

Podcast listeners use code SUMITUPBOSTON for a discount on registration

Episode Links: CS2 Boston: https://cs2.cloud/boston

“Midnight Rulemaking”: https://www.gao.gov/products/gao-23-105510

DoD's Rule Overview: https://youtu.be/DqRf0DiVBVI?si=2kTZcX45zD5ZPsnp

We Are the World: https://youtu.be/cYfe8RYcz-w

View Details

Register for CS2 | Boston here: https://cs2.cloud/boston

It's almost Springtime and that means it's almost time for another CS2 conference. CS2 Boston will be the 13th event in the series and, as always, there's an all-star lineup covering every nook and cranny of DFARS, NIST, and CMMC.

Podcast listeners get 20% off registration with the code SUMITUPBOSTON

Episode Links:

CS2 Boston: https://cs2.cloud/boston

DoD video overview: https://youtu.be/DqRf0DiVBVI?si=rDYWHsAHr6jwPPVm

View Details

Register for CS2 | Boston here: https://cs2.cloud/boston

If you thought the publication of one major DoD cyber rule at the end of 2023 caused a lot of issues how about FIVE potential rules and two NIST revisions in 2024? This week we outline the seven rules to watch for in 2024.

Listener discount code: SUMITUPBOSTON

Episode Links:

[Webinar] The Top 10 Questions From the CMMC Rule: https://www.summit7.us/webinars/the-top-10-questions-from-the-cmmc-rule

CS2 Boston: https://cs2.cloud/boston

Midnight Rulemaking: https://www.gao.gov/products/gao-23-105510

View Details

Register for CS2 | Boston: https://cs2.cloud/boston

This week we're joined by Alex Canizares to catch up on enforcement trends under the False Claims Act. As a former DOJ trial attorney, Alex walks us through the finer details of FCA cases and what it means for CMMC, defense contractors, and the road ahead.

Episode Links:

Alex Canizares: https://www.linkedin.com/in/alexandercanizares/

Perkins Coie Blog: https://www.perkinscoie.com/en/news-insights/dod-issues-proposed-cmmc-rule-requiring-cybersecurity-assessments-of-contractors.html

Perkins Coie Blog: https://www.perkinscoie.com/en/news-insights/proposed-far-rules-introduce-new-compliance-obligations-and-false-claims-act-risks-for-government-contractors.html

Cyber Civil Fraud Initiative: https://www.justice.gov/opa/pr/deputy-attorney-general-lisa-o-monaco-announces-new-civil-cyber-fraud-initiative

CS2 discount code for our listeners: SUMITUPBOSTON

View Details

The Supreme Court is set to upend decades of administrative law doctrine and it will have huge impacts on the cyber regulation landscape. In this episode we sit down with Jim Dempsey, a lecturer at the UC Berkeley Law School and a senior policy advisor at the Stanford Cyber Policy Center, to understand what SCOTUS is up to and what the heck is has to do with CMMC?

Episode Links:

Cyber Law Fundamentals: https://iapp.org/resources/article/cybersecurity-law-fundamentals/

Lawfare Article: https://www.lawfaremedia.org/article/a-cyber-threat-to-u.s.-drinking-water

Cyber Law Podcast: https://open.spotify.com/show/3Co2wdTUaZr4Xqnlxs4soG?si=64382c0b7b7a49c9

Tech Policy Podcast: https://open.spotify.com/episode/1klWdGIAxI7YBTljMvI412?si=ea93f23b3f9143cb

Dissed Podcast: https://open.spotify.com/episode/70GmGuWyEyKI2qNLcqlSIv?si=c69a3b6337ea4227

National Cyber Strategy: https://www.whitehouse.gov/briefing-room/statements-releases/2023/03/02/fact-sheet-biden-harris-administration-announces-national-cybersecurity-strategy/

Chevon Deference: https://ballotpedia.org/Chevron_deference_(doctrine)

Auer Deference: https://ballotpedia.org/Auer_deference

View Details

With five rulemaking efforts, multiple NIST revisions, and everything else going on in the DoD cyber regulation space it's hard to keep up with what's happening. In this episode we try and predict what's coming around the corner in 2024.

Episode Links:

Register for CS2 Boston: https://cs2.cloud/boston

DoD IG Report Episode: https://youtu.be/_3GLX6ele_E?si=KKhtgbjsxiLXWVJd

Stephanie Siegmann: https://youtu.be/d1yweDy2wV4?si=naLAhZPV794TAC66

DoD IG Audit: https://www.linkedin.com/posts/jacob-evan-horne_dod-ig-dod-process-for-accrediting-c3paos-activity-7114319133088866304-uhU5

RAS Syndrome: https://en.wikipedia.org/wiki/RAS_syndrome

View Details

The DoD has released yet another strategy document that claims to have the answer for expanding the defense supply chain while also increasing cybersecurity requirements. Maybe this time it will be different? This week we dive into the National Defense Industrial Strategy to see if there is anything to learn about the DoD's position on the impacts of CMMC.

Episode Links:

Register for CS2 Boston: https://cs2.cloud/boston

NDIS: https://www.businessdefense.gov/NDIS.html

DoD Cyber Strat: https://www.defense.gov/News/Releases/Release/Article/3523199/dod-releases-2023-cyber-strategy-summary/

“The Last Supper”: https://www.washingtonpost.com/archive/business/1997/07/04/how-a-dinner-led-to-a-feeding-frenzy/13961ba2-5908-4992-8335-c3c087cdebc6/

View the full webinar, CMMC Published: A Comprehensive Overview of the Proposed CMMC Rule On-Demand here: https://www.summit7.us/webinars/proposed-cmmc-rule

View Details

FedRAMP moderate “equivalency” has been a thing since 2016, but DoD never really defined the term until January 2024. “The memo” has defense suppliers and the people behind their cloud apps in panic mode. In this episode we dive into what the memo says, potential reasons why, and whether equivalency will still be a thing in the future at all.

Episode Links:

DFARS 7012: https://www.acq.osd.mil/dpap/dars/dfars/html/current/252204.htm#252.204-7012

The memo (PDF): https://dodcio.defense.gov/Portals/0/Documents/Library/FEDRAMP-EquivalencyCloudServiceProviders.pdf

Equivalency circa 2018: https://www.nist.gov/news-events/events/2018/10/controlled-unclassified-information-security-requirements-workshop

FedRAMP: https://www.fedramp.gov/program-basics/

NIST SP 800-171r3: https://csrc.nist.gov/pubs/sp/800/171/r3/fpd

View Details

Register for the upcoming webinar; CMMC Published: A Comprehensive Overview of the Proposed CMMC Rule: https://www.summit7.us/webinars/proposed-cmmc-rule

Thinking about submitting comments on the CMMC proposed rule? Not sure where to start? In this episode we go over the “commenter's checklist” from regulations.gov to help you evaluate the quality of your public comments on federal rules, NIST publications, and more.

Episode Links:

Summit 7 Webinar: https://www.summit7.us/webinars/proposed-cmmc-rule

Commenter's Checklist (PDF): https://s3.amazonaws.com/prod-regulations-faq/pdf/Tips-For-Submitting-Effective-Comments.pdf

CMMC Proposed Rule: https://www.federalregister.gov/documents/2023/12/26/2023-27280/cybersecurity-maturity-model-certification-cmmc-program

CMMC Guidance Documents: https://www.federalregister.gov/documents/2023/12/26/2023-27281/cybersecurity-maturity-model-certification-cmmc-program-guidance

NIST SP 800-171 revision 3 draft: https://csrc.nist.gov/projects/protecting-controlled-unclassified-information

View Details

Register for the upcoming webinar; CMMC Published: A Comprehensive Overview of the Proposed CMMC Rule: https://www.summit7.us/webinars/proposed-cmmc-rule

The 2023 CMMC rule was published the Friday before Christmas and most people haven’t fully digested all 234 pages yet. In this episode Jason and Jacob cover the rule at 30,000 feet so you can hit the ground running in 2024.

Episode Links:

.....

CMMC on the Federal Register: https://www.federalregister.gov/documents/2023/12/26/2023-27280/cybersecurity-maturity-model-certification-cmmc-program

.....

The CMMC documents: https://www.federalregister.gov/documents/2023/12/26/2023-27281/cybersecurity-maturity-model-certification-cmmc-program-guidance

View Details

Summit 7 CMMC Solutions: https://www.summit7.us/cmmc-level-solution-sets

The DoD Inspector General released a special report comparing their contractor cyber assessment findings with their findings during DOJ false claims act investigations. No surprise, the same cybersecurity issues pop up again and again. Will this add fuel the CMMC fire?

Episode Links:

The IG Report: https://www.dodig.mil/reports.html/Article/3606026/special-report-common-cybersecurity-weaknesses-related-to-the-protection-of-dod/ The IG project announcement for C3PAOs: https://www.dodig.mil/reports.html/Article/3536652/project-announcement-audit-of-the-dods-process-for-accrediting-third-party-orga/

171r3 Webinar (NIST): https://csrc.nist.gov/Events/2024/critical-updates-to-nist-cui-publications

171r3 Comments Extended: https://csrc.nist.gov/News/2023/drafts-of-800-171-rev-3-and-800-171a-rev-3-availab

Halloween episode: https://youtu.be/jy2AHrSztjM?si=7h6cW30Gr25Gx11X

View Details

There are two different CMMC rules. One rule pertains to the CMMC program while the other pertains to the CMMC contract clause. The Fall 2023 Unified Agenda is out and it provides all the details about why there are two rules and what it means for defense contractors.

Episode Links:

Unified Agenda: https://www.reginfo.gov/public/do/eAgendaMain

.

32 CFR CMMC: https://www.reginfo.gov/public/do/eAgendaViewRule?pubId=202310&RIN=0790-AL49

.

48 CFR CMMC: https://www.reginfo.gov/public/do/eAgendaViewRule?pubId=202310&RIN=0750-AK81

View Details

It's Christmas time so we put together our wishlist of what we'd like to see in the upcoming CMMC rule.

.

For CMMC resources, solutions & more visit: https://www.summit7.us/cmmc-level-solution-sets

View Details

The November Cyber AB Town Hall was recapped the CMMC ecosystem highlights from 2023. Assessor numbers have increased, but will there be enough assessment capacity to meet demand?

Episode links:

Cyber AB Town Halls: https://cyberab.org/News-Events/Town-halls/Details/november-town-hall

.

Natty Stratty Discussion: https://youtu.be/QvaLdx_wb1U?si=pgIabPLZJpGGVDS-

View Details

OIRA's review of the CMMC rule is nearly complete and we expect the CMMC proposed rule to be published sometime between Thanksgiving and mid-December. On top of that, DoD has initiated rulemaking to revise DFARS clause 252.204-7012. In this episode we dive into the rulemaking feast.

View Details

The great and powerful Dr. Ron Ross returns to walk us through the latest drafts of NIST SP 800-171 and SP 800-171A: what they are, why they are, where they're going, and what's in store for federal contractors handling controlled unclassified information (CUI).

Episode Links:

.

NIST Controls Deep Dive w/ Ron Ross (May 2023): https://youtu.be/vAPFmga_NtI?si=kfmdKyXaHiTCpFiq

.

171r3 (Final Draft) - 7 Things to Know: https://www.summit7.us/blog/nist-800-171-rev3-final-draft

.

800-171r3 Final Draft: https://csrc.nist.gov/pubs/sp/800/171/r3/fpd

.

800-171Ar3 Initial Draft: https://csrc.nist.gov/pubs/sp/800/171/a/fpd

.

Protecting CUI Project: https://csrc.nist.gov/projects/protecting-controlled-unclassified-information

View Details

The final draft of NIST SP 800-171 revision 3 and the initial draft of SP 800-171A are out. There are simultaneously more and fewer requirements. ODPs have gone away, but not really. Problematic assumptions were reversed only to be repeated. Up is down; left is right; and the final revisions are expected in a few short months. Today we dive into the first 7 things you need to know.

Episode Links:

.

800-171r3 Final Draft: https://csrc.nist.gov/pubs/sp/800/171/r3/fpd

.

800-171Ar3 Initial Draft: https://csrc.nist.gov/pubs/sp/800/171/a/fpd

.

Protecting CUI Project: https://csrc.nist.gov/projects/protecting-controlled-unclassified-information

.

Sum IT Up: Live (CS2 Denver): https://youtu.be/td8Te1LZfEI?si=Yh7SIM2A9SFjMVMK

View Details

The final draft of NIST SP 800-171 revision 3 and the initial draft of SP 800-171A are due to be published soon. In this episode we dive into seven questions at the front of our minds before the big day.

.

Episode Links:

.

SP 800-171r3: https://csrc.nist.gov/pubs/sp/800/171/r3/ipd

.

Protecting CUI Project: https://csrc.nist.gov/projects/protecting-controlled-unclassified-information

View Details

Get any good candy for Halloween? The CMMC rule got a 30-day extension for the pre-publication review by the Office of Information and Regulatory Affairs (OIRA). The Cyber AB got notice that the DoD Inspector General is auditing the accreditation process for C3PAOs. In this episode we discuss why both of these things aren't as big of a deal as they might seem.

Episode Links:

Cyber AB Town Halls: https://cyberab.org/News-Events/Town-Halls

DoD IG Project Announcement: https://www.dodig.mil/reports.html/Article/3536652/project-announcement-audit-of-the-dods-process-for-accrediting-third-party-orga/

OMB Rulemaking Dashboard: https://www.reginfo.gov/public/jsp/EO/eoDashboard.myjsp

View Details

The regulatory review of the CMMC rule is coming to an end. That means we should see a published CMMC rule in the next few weeks. In this episode Jason and Jacob dive into 7 things you need to know to hit the ground running when the public comment window opens.

Episode Links: CMMC rulemaking entry: https://www.reginfo.gov/public/do/eAgendaViewRule?pubId=202304&RIN=0790-AL49

View Details

The government recently released a new federal acquisition regulation that requires NIST SP 800-53 controls for federal information systems operated by contractors. Buried inside that rule are several cost estimates for implementing and maintaining SP 800-53. Meanwhile, the government has never published cost estimates for NIST SP 800-171 even though it is derived directly from SP 800-53. In this episode we use are knowledge of SP 800-53 to do the impossible and estimate SP 800-171 using the government's own numbers.

Episode Links:

LinkedIn Poll: https://www.linkedin.com/posts/jacob-evan-horne_information-hazards-are-one-of-my-favorite-activity-7116107489045004288-BfrM

FAR Rule: https://www.federalregister.gov/documents/2023/10/03/2023-21327/federal-acquisition-regulation-standardizing-cybersecurity-requirements-for-unclassified-federal

Fuzzy Math @ CS2 San Diego (2021): https://www.youtube.com/watch?v=843K3hkLquk

SolarWinds Hack: https://www.gao.gov/blog/solarwinds-cyberattack-demands-significant-federal-and-private-sector-response-infographic

EO 14028: https://www.whitehouse.gov/briefing-room/presidential-actions/2021/05/12/executive-order-on-improving-the-nations-cybersecurity/

DFARS 7012: https://www.acquisition.gov/dfars/252.204-7012-safeguarding-covered-defense-information-and-cyber-incident-reporting.

DFARS 7010: https://www.acquisition.gov/dfars/252.239-7010-cloud-computing-services.

FIPS 199: https://csrc.nist.gov/pubs/fips/199/final

SP 800-53: https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final

SP 800-171: https://csrc.nist.gov/pubs/sp/800/171/r2/upd1/final

SP 800-171B cost estimate (2019): https://csrc.nist.gov/pubs/sp/800/171/b/ipd

View Details

In this episode we dive into best practices for submitting comments on the next drafts of NIST SP 800-171r3 and SP 800-171A. We also go deep on the contours of NIST SP 800-172. Happy 1 year anniversary to the show!

View Details

Register for CS2 | Denver: https://cs2.cloud/

The biggest debate around CMMC: whether the rule should be “interim final” or “proposed”. On average it takes around a year longer for proposed rules to go into effect. This begs the question: if the 2020 CMMC rule was interim final, why wouldn't the 2023 CMMC rule be interim final as well? Has the national security justification for interim final status in previous rules changed for the better?

CS2 | Denver discount code: SUMITUPCS2DEN

Episode Links:

CS2 Denver: https://cs2.cloud/

2020 Rule: https://www.federalregister.gov/documents/2020/09/29/2020-21123/defense-federal-acquisition-regulation-supplement-assessing-contractor-implementation-of

2016 Rule: https://www.federalregister.gov/documents/2016/10/21/2016-25315/defense-federal-acquisition-regulation-supplement-network-penetration-reporting-and-contracting-for

2013 Rule: https://www.federalregister.gov/documents/2013/11/18/2013-27313/defense-federal-acquisition-regulation-supplement-safeguarding-unclassified-controlled-technical

LinkedIn Poll: https://www.linkedin.com/posts/jacob-evan-horne_3-years-ago-this-month-the-dod-issued-the-activity-7110270262020857856-l6Om

View Details

It can be easy to lose perspective on the critical role that the CMMC program plays in the larger national defense strategy of the United States – especially if you don't work in the Pentagon. On top of that, the DoD is in full radio silence until the end of the public comment period on the upcoming CMMC rule. However, if you dig deep enough into DoD's strategy documents you'll quickly find that the CMMC program is a critical element of the national defense strategy of the United States.

Episode Links:

CS2 Denver: https://cs2.cloud/

2023 DoD Cyber Strat: https://www.defense.gov/News/Releases/Release/Article/3523199/dod-releases-2023-cyber-strategy-summary/#:~:text=The%20strategy%20highlights%20DOD's%20actions,protect%20the%20defense%20industrial%20base

2022 National Defense Strategy: https://www.defense.gov/News/News-Stories/Article/Article/3202438/dod-releases-national-defense-strategy-missile-defense-nuclear-posture-reviews/#:~:text=The%202022%20National%20Defense%20Strategy%2C%20or%20NDS%2C%20places,of%20U.S.%20allies%20and%20partners%20on%20shared%20objectives.

2023 National Cyber Strategy: https://www.whitehouse.gov/briefing-room/statements-releases/2023/03/02/fact-sheet-biden-harris-administration-announces-national-cybersecurity-strategy/

Additional Context: https://www.linkedin.com/posts/jacob-evan-horne_2023-dod-cyber-strat-summary-activity-7107765455938822145-ibdi

CMMC in Canada: https://www.ccc.ca/en/announcements/government-of-canada-program-for-cyber-security-certification/

Register for CS2 | Denver: https://cs2.cloud/

View Details

Register for CS2 | Denver: https://cs2.cloud/

If you google DFARS 7021 you'll see that the CMMC contract clause has an “effective date” that isn't very old. Recently this has caused a folks to think that something has changed with CMMC before the rulemaking process has finished. In this episode we dive into what's going on with “effective date” disparities, the rulemaking process, and how to sniff out bad information.

Episode Links:

Deep dive with Lauren Ayers: https://youtu.be/lPQbO9872IQ?si=h8ojZyOYTxEkxeWY

Rulemaking update: https://youtu.be/qyLDQxo-YPg?si=SHGUHNzlY_4-XkBA

https://www.ecfr.gov/

https://www.acquisition.gov/

CS2 discount code for Sum IT Up listeners: SUMITUPCS2DEN

View Details

Register for CS2 | Denver: https://cs2.cloud/

The 2023 Federal Cybersecurity Vulnerability Reduction Act directs the government to change cybersecurity requirements for contractors. How will changes to federal acquisition regulations affect defense contractors? How many more vulnerability controls does NIST have on-deck that could be included? This week Jason and Jacob dive into what's coming around the bend.

Episode Links:

Legislation: https://www.congress.gov/bill/118th-congress/house-bill/5255/text

LinkedIn Discussion: https://www.linkedin.com/posts/jacob-evan-horne_federal-cybersecurity-vulnerability-reduction-activity-7102336020951519233-kM1L

800-53B: https://csrc.nist.gov/pubs/sp/800/53/b/upd1/final

800-171r3 IPD: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171r3.ipd.pdf

View Details

The Cyber AB Town Hall for August 2023 was full of encouraging numbers. The number of people certified in various CMMC ecosystem roles continues to increase. Successful Joint Surveillance Assessments are also up and a recent Reddit post contained fascinating details about the the cost and complexity of a real-world CMMC assessment.

Episode Links:

https://old.reddit.com/r/CMMC/comments/15zawp6/mission_accomplished/

https://old.reddit.com/r/NISTControls/comments/15zaxnl/mission_accomplished/

OIRA Leak Episode: https://youtu.be/b_CthhFXLfw?si=hD9RJHTU_D7jqm85

Register for CS2 | Denver: https://cs2.cloud/

CS2 | Denver podcast discount code: SUMITUPCS2DEN

View Details

Register for CS2 | Denver and catch the Sum IT Up 1 Year Anniversary show LIVE: https://cs2.cloud/

Just a few weeks after the end of the public comment period on NIST SP 800-171r3 and NIST has released their official summary. Timelines are on track and industry focused overwhelmingly on just a few things. Overall, NIST is planning some changes that will likely result in a larger 171r3. This week Jacob and Jason dive into what NIST is saying between the lines.

ERRATA: NIST plans to release the next drafts in Q4 2023, not Q4 2024

Episode Links:

171r3 Project page: https://csrc.nist.gov/projects/protecting-controlled-unclassified-information

CS2 Denver: https://cs2.cloud/

View Details

What to make of the 1,700+ comments submitted on the initial public draft of NIST Special Publication 800-171 revision 3? Jacob and Jason give their high-level takeaways and expectations for the future of the standard.

Register for CS2 | Denver and see the Sum IT Up 1 year anniversary show LIVE: https://cs2.cloud/

Podcast listeners 15% discount code for CS2 | Denver: SUMITUPCS2DEN

Episode Links:

Jacob's LinkedIN Poll on ODPS: https://www.linkedin.com/posts/jacob-evan-horne_last-week-nist-posted-the-public-comments-activity-7092152417344999424--IvO?utm_source=share&utm_medium=member_desktop

NIST Webinar of NIST 800-171r3: https://csrc.nist.gov/Events/2023/protecting-cui-draft-sp800171-rev3

NIST SP 800-171r3 IPD: https://csrc.nist.gov/pubs/sp/800/171/r3/ipd

NIST Protecting CUI Project: https://csrc.nist.gov/projects/protecting-controlled-unclassified-information

Sum It Up w/ Ron Ross: https://youtu.be/vAPFmga_NtI

View Details

Not even a week after DoD submitted the CMMC rule for regulatory review and the Office of Information and Regulatory Affairs accidentally posted the updated (draft) documents for all 3 levels of CMMC. In this episode we dive deep into new information about CMMC Level 3 and share our key takeaways from sneak peek of what's to come.

Episode Links: SP 800-171r2 : Protecting Controlled Unclassified Information in Nonfederal Systems (nist.gov) SP 800-172: Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST Special Publication 800-171 SP 800-171 ODP Poll Results: https://www.linkedin.com/posts/jacob-evan-horne_last-week-nist-posted-the-public-comments-activity-7092152417344999424--IvO

View Details

In November 2021 the #DoD announced CMMC 2.0. Then they announced that it would 9 – 24 months to go through rulemaking for #CMMC to become a reality. On July 24th, 2023, roughly 20 months later, DoD officially submitted the CMMC rule to the Office of Management and Budget. In this episode Jason and Jacob dive into what it all means for defense contractors moving forward.

Episode Links:

Cyber AB Town Hall (July ‘23): https://cyberab.org/News-Events/Town-Halls/Details/july-2023-town-hall

7 Things to Know About Rulemaking: https://www.summit7.us/blog/cmmc-rulemaking-updates-august-2023

Amira Armond on assessment types/pros/cons: https://www.linkedin.com/posts/amira-armond-25a77a141_cmmc-nist800171-activity-7092146281032122370-XXIs

Acronym Soup: https://www.acronymsoup.org/

View Details

Episode Links: Cyber AB June TH: https://cyberab.org/News-Events/Town-Halls CMMC Ecosystem Summit Call For Speakers: https://na.eventscloud.com/cmmcpapers Recording of the June 6th.2023 NIST Webinar on 800-171 r3: https://csrc.nist.gov/Events/2023/protecting-cui-draft-sp800171-rev3#:~:text=On%20June%206%2C%202023%2C%20NIST,in%20Nonfederal%20Systems%20and%20Organizations. DOD IG Report on Implementation and Oversight of the Controlled Unclassified Information Program: https://www.dodig.mil/reports.html/Article/3413433/audit-of-the-dods-implementation-and-oversight-of-the-controlled-unclassified-i/ Stephanie's LinkedIn: https://www.linkedin.com/in/bstephaniesiegmann/ Cyber Civil-Fraud Initiative: https://www.justice.gov/opa/pr/deputy-attorney-general-lisa-o-monaco-announces-new-civil-cyber-fraud-initiative Aerojet Rocketdyne FCA claim: https://www.justice.gov/opa/pr/aerojet-rocketdyne-agrees-pay-9-million-resolve-false-claims-act-allegations-cybersecurity UBER CISO Convicted of Covering up Data Breach: https://www.justice.gov/usao-ndca/pr/former-chief-security-officer-uber-convicted-federal-charges-covering-data-breach Supreme Court FCA Ruling: supremecourt.gov/opinions/22pdf/21-1326_6jfl.pdf Lauren's LinkedIn: https://www.linkedin.com/in/laurencayers/ Professional Services Council: www.pscouncil.orgg

View Details

In this episode Jacob and Jason discuss their takeaways from the May Cyber AB Town Hall, including Jacob's guest appearance. The initial public draft of NIST SP 800-171r3 was released; and in this episode the fellas give their initial feedback and analysis on it. Additionally, we discuss the propped rule to expand eligibility into the DIB CS program, the recently published ND-ISAC Cybersecurity Handbook for SMBs, and the MS Volt Typhoon campaign. Episode Links: NIST SP 800-171r3 Draft: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171r3.ipd.pdf NIST Security Controls: Deep Dive with Dr. Ron Ross: NIST Security Controls: Deep Dive with Dr. Ron Ross - YouTube Cooey Center of Excellence:: https://discord.com/invite/rPtTes5bqA NIST SP 800-53r5: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf The Cyber AB May Townhall: May 2023 Town Hall - CyberAB DIB CS Proposed Rule: Federal Register :: Department of Defense (DoD) Defense Industrial Base (DIB) Cybersecurity (CS) Activities ND-ISAC Handbook for SMBs: https://ndisac.org/wp-content/uploads/2023/05/Securing-SMB-Manufacturing-Supply-Chain-Resource-Handbook-Final_4MAY2023.pdf MS Volt Typhoon Threat Brief: Volt Typhoon Targets US Critical Infrastructure: Latest Cybersecurity News Today | Security Insider (microsoft.com)

View Details

At first glance the initial public draft of NIST Special Publication (SP) 800-171 revision 3 is a big change compared to previous versions. Formatting changes, variable parameters, and new requirements have seemingly come out of nowhere. In reality SP 800-171 is a reflection of the much larger SP 800-53. The evolution of SP 800-53 over time has a direct effect on the look and feel of SP 800-171 and the cost, burden, and impact of assessment programs like CMMC. NIST Fellow Dr. Ron Ross joins the show to walk us through where SP 800-53 has been, where it's going, and how a broader understanding helps put SP 800-171 into context for federal contractors. For more information and resources please visit: https://www.summit7.us/resources#resources_nist

Episode Links:

Rainbow Series: https://en.wikipedia.org/wiki/Rainbow_Series

Anderson Report (PDF): https://csrc.nist.rip/publications/history/ande72.pdf

Ware Report: https://en.wikipedia.org/wiki/Ware_report

A Vulnerable System: https://www.amazon.com/Vulnerable-System-Information-Security-Computer-ebook/dp/B08YP9XH84

The Perfect Weapon: https://www.amazon.com/Perfect-Weapon-Sabotage-Fear-Cyber/dp/0451497899

FISMA: https://en.wikipedia.org/wiki/Federal_Information_Security_Management_Act_of_2002

FIPS 200: https://csrc.nist.gov/publications/detail/fips/200/final

FIPS 199: https://csrc.nist.gov/publications/detail/fips/199/final RMF: https://csrc.nist.gov/projects/risk-management/about-rmf

Alan Paller: https://www.sans.org/about/our-founder/

Metrics as surrogates: https://hbr.org/2019/09/dont-let-metrics-undermine-your-business

EO 13556: https://obamawhitehouse.archives.gov/the-press-office/2010/11/04/executive-order-13556-controlled-unclassified-information

CUI Registry: https://www.archives.gov/cui/registry/category-list

SP 800-171 r3 initial draft: https://csrc.nist.gov/publications/detail/sp/800-171/rev-3/draft

SP 800-53 r5: https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final

View Details

In this episode Jacob and Jason discuss their takeaways from the Cyber AB Town Hall and dive into several great questions asked during the extended Q&A. Amira Armond stops by to deep dive into the Top 10 “Other Than Satisfied” requirements found during DIBCAC audits. Lauren Ayers also stops by to teach us how to read DFARS clauses like a contracting officer.

Amira's LinkedIn: https://www.linkedin.com/in/amira-armond-25a77a141/

Kieri Solutions: https://www.kieri.com/

Amira's Blog: https://www.cmmcaudit.org/

Lauren LinkedIn: https://www.linkedin.com/in/laurencayers/

Professional Services Council: www.pscouncil.org

PSC June Conference: https://www.pscouncil.org/AcquisitionConference

Cooey Center of Excellence: https://discord.com/invite/rPtTes5bqA

DCMA DIBCAC: https://www.dcma.mil/DIBCAC/

DFARS Cyber FAQs: https://dodprocurementtoolbox.com/faqs/cybersecurity

Stacy Bostjanick at CS2 Huntsville: https://youtu.be/ZvBvzZkwmZg

NARA CUI Registry: https://www.archives.gov/cui/registry/category-list

CMMC CAP (PDF): https://cyberab.org/Portals/0/Documents/Process-Documents/CMMC-Assessment-Process-CAP-v1.0.pdf

CMMC Assessment Guides: https://dodcio.defense.gov/CMMC/Documentation/

NIST RMF: https://csrc.nist.gov/projects/risk-management/about-rmf

NIST SP 800-37: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final

2018 CUI Industry Day: https://www.nist.gov/news-events/events/2018/10/controlled-unclassified-information-security-requirements-workshop

The DFARS: https://acquisition.gov/

NMCARS: https://www.secnav.navy.mil/rda/DASN-P/Pages/NMCARS.aspx

View Details

In this episode Jacob and Jason discuss their takeaways from the Cyber AB Town Hall, CS2 Huntsville, and other interesting topics from March 2023 including recent #DoD testimony before Congress, #DIBCAC perspectives on Multifactor Authentication and #FIPS validated encryption, and other exciting topics. This month we were joined by our first ever podcast guest: DefCERT founder and CEO Ryan Bonner helps tackle a few complicated #CUI questions submitted during the Town Hall.

Episode Links:

DefCERT: https://defcert.com/

Ryan Bonner: https://www.linkedin.com/in/rybonner/

March AB Town Hall: https://cyberab.org/News-Events/Town-Halls/Details/march-2023-town-hall

Upcoming Natty Stratty Implementation Plan: https://federalnewsnetwork.com/cybersecurity/2023/03/white-house-aims-to-issue-cyber-strategy-implementation-plan-by-june/

DoDI 5230.24 (PDF): https://www.esd.whs.mil/portals/54/documents/dd/issuances/dodi/523024p.pdf

CUI Registry CTI: https://www.archives.gov/cui/registry/category-detail/controlled-technical-info.html

DFARS 252.204-7012: https://www.acq.osd.mil/dpap/dars/dfars/html/current/252204.htm#252.204-7012

DFARS Rights in Technical Data: https://www.acq.osd.mil/dpap/dars/dfars/html/current/227_71.htm

CMMC Scoping Guide: https://dodcio.defense.gov/CMMC/Documentation/

DI MGMT 82247: https://www.acq.osd.mil/asda/dpc/cp/cyber/docs/safeguarding/Assess-Compliance-and-Enhance-Protection-of-Contractor-System-with-Attachments-11-6-2018.pdf

CMMC Rulemaking Overview: https://youtu.be/in69ORYRx4Y

32 CFR: https://www.ecfr.gov/current/title-32

48 CFR: https://www.ecfr.gov/current/title-48

Draft CAP (PDF): https://cyberab.org/Portals/0/Documents/Process-Documents/CMMC-Assessment-Process-CAP-v1.0.pdf GAO Report: https://www.gao.gov/products/gao-23-105510

CMMC Scaling vs DIBCAC: https://www.federalregister.gov/d/2020-21123/p-49

CMMC Assessment Guide: https://dodcio.defense.gov/CMMC/Documentation/

NIST SP 800-171A: https://www.nist.gov/news-events/news/2018/06/nist-publishing-special-publication-sp-800-171a-assessing-security

SPRS Rule: https://www.federalregister.gov/documents/2023/03/22/2023-05671/defense-federal-acquisition-regulation-supplement-use-of-supplier-performance-risk-system-sprs

Bob Metzger's Take on SPRS Rule: https://www.linkedin.com/posts/robertmetzger_sprs-evaluation-criteria-manual-activity-7046888772768067584-7bHW

Jacob's CS2 Session: https://youtu.be/hipUN_4rfOs

Stacy's CS2 Session: https://youtu.be/ZvBvzZkwmZg

DoD Testimony 1: https://www.armed-services.senate.gov/hearings/to-receive-testimony-on-enterprise-cybersecurity-to-protect-the-department-of-defense-information-networks

DoD Testimony 2: https://armedservices.house.gov/hearings/cyber-information-technologies-and-innovation-subcommittee-hearing-defense-digital-era

Amira Armond: https://www.linkedin.com/in/amira-armond-25a77a141/

View Details

In this episode Jacob and Jason discuss their takeaways from the February Cyber AB Town Hall. This month saw some amazing questions on #CUI, working with #DoD CIO, continuous monitoring, the cost of assessments, and #CMMC rulemaking. They also give their thoughts on the Project Spectrum feature segment of the Town Hall. Jacob and Jason also provide an overview and their takeaways from the newly released 2023 National Cybersecurity Strategy and what it means for defense contractors and CMMC.

CORRECTION 3/3/2023: DOUBLE CHECK YOUR PROJECT SPECTRUM SELF-ASSESSMENT ANSWERS FOR PARTIAL SCORING AND SYSTEM SECURITY PLANS

Episode Links:

Cyber AB Town Hall: https://cyberab.org/News-Events/Town-Halls

CMMC Rulemaking Overview: https://youtu.be/in69ORYRx4Y

Project Spectrum: https://www.projectspectrum.io/#/

DHS CSET Assessment Tool: https://www.cisa.gov/stopransomware/cyber-security-evaluation-tool-csetr

DHS CUI Rule: https://www.reginfo.gov/public/do/eAgendaViewRule?pubId=202210&RIN=1601-AA76

NIST SP 800-53: https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final

“Common” Controls: https://csrc.nist.gov/glossary/term/common_control

“Hybrid” Controls: https://csrc.nist.gov/glossary/term/hybrid_control

“Inheritance”: https://csrc.nist.gov/glossary/term/inheritance

FedRAMP Baselines: https://www.fedramp.gov/baselines/

DoDI 5230.24 (PDF): https://www.esd.whs.mil/portals/54/documents/dd/issuances/dodi/523024p.pdf

CUI Registry: https://www.archives.gov/cui/registry/category-list

CUI Overview: https://youtu.be/bEW7VgbIE_8

CMMC Level 1 Guide: https://www.microsoft.com/cms/api/am/binary/RE54xON

National Cyber Strategy: https://www.whitehouse.gov/briefing-room/statements-releases/2023/03/02/fact-sheet-biden-harris-administration-announces-national-cybersecurity-strategy/

Cyber Strategy Overview: https://www.youtube.com/watch?v=6Fwtvcf2A2c

Sector Risk Management Agencies: https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/defense-industrial-base-sector

Vital Signs 2023 Report: https://www.ndia.org/about/press/press-releases/2023/2/8/ndia-president-urges-congress-to-ready-defense-sector-for-great-power-competition

State of the DIB Testimony: https://youtu.be/n62KE-1yQu4

View Details

In this episode Jacob and Jason discuss their takeaways from the January Cyber AB Town Hall including several great questions submitted from the #CMMC ecosystem. They also cover some great questions submitted by podcast listeners. Jacob breaks down the upcoming agenda for #CS2 Huntsville (there may or may not be a discount code for podcast listeners). Another #CISA alert related to managed service providers popped up in January. Additionally, a handful of #DoD reports on the level of internal resourcing and funding for cybersecurity shed light on the idea that DoD will have a CMMC cloud enclave ready for everyone in the #DIB on day 1 (or at all). Finally, several very interesting reports came out regarding the larger cyber-regulatory ecosystem. It helps to look up from the details of the CMMC debate from time to time in order to see which way the winds are blowing overall.

CS2 Huntsville: https://cs2.cloud/huntsville

Episode Links:

January AB Town Hall: https://cyberab.org/News-Events/Town-Halls/Details/january-town-hall Understanding CMMC

Rulemaking: https://info.summit7.us/blog/cmmc-compliance-deadline CMMC CAP & Comments: https://cyberab.org/CMMC-

Ecosystem/Member-Area-Downloads-and-Forums DoDI 5230.24: https://www.esd.whs.mil/portals/54/documents/dd/issuances/dodi/523024p.pdf

CUI Registry (CTI): https://www.archives.gov/cui/registry/category-detail/controlled-technical-info.html

CUI on Game Forums: https://www.pcgamer.com/more-restricted-military-intel-ends-up-on-the-war-thunder-forums/ More CUI on Game Forums: https://www.pcgamer.com/wait-again-war-thunder-fans-just-cant-help-themselves-when-it-comes-to-posting-sensitive-military-documents/

DoD IG on CUI Overmarking: https://www.stripes.com/theaters/us/2023-01-03/congress-orders-pentagon-controlled-unclassified-8639918.html

Production Machining Article: https://www.productionmachining.com/articles/a-small-cnc-machine-shops-journey-to-cmmc- CS2 Huntsville: https://cs2.cloud/huntsville

CISA Alert on RMM Software: https://www.cisa.gov/uscert/ncas/alerts/aa23-025a DoD IG on "SUNET": https://www.dodig.mil/reports.html/Article/2931705/project-announcement-evaluation-of-dods-secure-unclassified-network-sunet-cyber/

DoD Annual OT&E Report: https://www.dote.osd.mil/annualreport/

Minihan Memo: https://www.airandspaceforces.com/read-full-memo-from-amc-gen-mike-minihan/

CSIS Wargame Video: https://www.youtube.com/watch?v=YZ6HJEl7Q90

Compliance Statistics: https://secureframe.com/blog/compliance-statistics

World Economic Forum Cyber Outlook: https://www.weforum.org/reports/global-cybersecurity-outlook-2023

Daniel on Cloud Enclaves: https://www.youtube.com/watch?v=_Ka-AOzb54s

CSF 2.0 Concept Paper: https://csrc.nist.gov/News/2023/csf-2-0-concept-paper-released

Cyber Requirements as "Outcomes": https://www.garp.org/risk-intelligence/technology/cyber-risk-landscape-011322

Regulation Predictions: https://www.hstoday.us/featured/column-avoiding-regulatory-pitfalls-in-cyberspace/

John Ellis on DIBCAC Assessments for SMBs: https://youtu.be/NA_th4wmUuY

Jim Dempsey Lecture: https://www.youtube.com/watch?v=-ZfXB78vB10

View Details

In this episode we reflect on a few items from December 2022 and the story of #CMMC (rulemaking) in 2022 overall. We cover listener questions and Jason's experience taking (and passing) his #CCP exam. After a deep dive into the current status of CMMC rulemaking we discuss #DoD estimates about the size of the defense industrial base. We also cover a report on the status of NIST SP 800-171 implementation for DoD contractors. We wrap up with our predictions for 2023.

Episode Links:

Cooey Center of Excellence Discord Server: https://discord.com/invite/rPtTes5bq

A CMMC Rulemaking "Delay": https://insidecybersecurity.com/daily-news/pentagon%E2%80%99s-cmmc-program-launch-faces-delay-omb-rulemaking-review-shifts-january

Merrill Research Report: https://www.scmagazine.com/analysis/third-party-risk/most-us-defense-contractors-fail-basic-cybersecurity-requirements

Old school security advisory: https://www.cisa.gov/uscert/ncas/archives/alerts/TA04-111

Correction: In this episode (1:31:16), Jason mentions that Multifactor Authentication or “MFA” first started appearing in CISA Cybersecurity advisories in 2004. Although individual recommended security actions in CSAs that align with the requirements of NIST SP 800-171 can be found in alerts dating as far back as 2004, the recommendation for MFA was not introduced as a recommended mitigation action in a CISA CSA until 2014. We apologize for the error.... sometimes numbers get him excited.

View Details

In this episode Jacob and Jason dive into the November 2022 Cyber AB Town Hall and provide takeaways the Cyber AB's inaugural #CMMC Ecosystem Summit. Jacob and Jason also explore the findings of a GAO report on cyber incident reporting and handling by the #DoD and Defense Industrial Base contractors while connecting the dots to #DIBCAC findings featured in Episode 2. November 2022 is the 12th anniversary of Executive Order 13556 which establish the federal #CUI program. Of course, Jacob and Jason just so happened to find a clear example of overmarked CUI on a public DoD webpage. Episode Links: Cyber AB November Town Hall: https://cyberab.org/News-Events/Town-halls/Details/november-town-hall Executive Order 13556: https://obamawhitehouse.archives.gov/the-press-office/2010/11/04/executive-order-13556-controlled-unclassified-information GAO Report: https://www.gao.gov/products/gao-23-105084 Kelly Kiernan: https://www.linkedin.com/in/kelley-kiernan-cto/ Blue Cyber: https://www.safcn.af.mil/CISO/Small-Business-Cybersecurity-Information/ DoD Zero Trust Strategy: https://dodcio.defense.gov/Portals/0/Documents/Library/DoD-ZTStrategy.pdf SP 800-171 vs NIST CSF Ransomware Profile: https://www.linkedin.com/posts/jacob-evan-horne_nist-sp-800-171-by-nist-csf-ransomware-profile-activity-6928378291812786176-Env7

View Details

In this episode Jacob and Jason dive into the October 2022 Cyber AB Town Hall by exploring the questions (both answered and unanswered) submitted during the town hall Q&A segment. Jason provides his thoughts on the quality of the updated Registered Practitioner training. Time is spent on Rumor Control: Large prime contractors are seemingly requiring everyone to get #CMMC Level 2 certified and there's not much that #DoD can do to stop them. Jacob discusses the specter of #NIST SP #800-171 Appendix E and why they remain a thorn in everyone's sides. Other questions addressed: Are the rumors of Congressional funding for CMMC actually true? Is DoD actually bad at communicating? Why is it so hard to know how many requirements correspond to CMMC Level 1? The show wraps up with a brief discussion of NIST SP 800-172 and the newly released #CISA Cross-Sector Cybersecurity Performance Goals.

View Details

In this episode Jacob and Jason dive into the September 2022 Cyber AB Town Hall including their takeaways on the new Cybersecurity Assessor and Instructor Certification Organization ("CAICO"); the Certified CMMC Professional (CCP) beta exam; and recent assessment data provided by Nick Delrosso of the Defense Contract Management Agency's (DCMA) Defense Industrial Base Cyber Assessment Center (DIBCAC). Jason discusses the relevance of a new alert from the Cybersecurity & Infrastructure Security Agency (CISA) to DIBCAC "medium" assessment results. Jacob discusses initial takeaways from the pre-draft public comments submitted ahead of NIST SP 800-171 revision 3 and their implications for federal contractors and DoD's CMMC program moving forward. Takeaways from recent industry events in September are discussed. The hosts wrap up by taking a look at the implications of a recent GAO report on the National Nuclear Security Adminstration's lack of supply chain oversight and assurance and the CMMC Easter egg buried in the report.

Episode Links:

Sep 22 Cyber AB Town Hall: https://cyberab.org/News-Events/Town-halls

CISA Alert: https://www.cisa.gov/uscert/ncas/alerts/aa22-277a

NIST SP 800-171r3 Pre-Draft Comments: https://csrc.nist.gov/Projects/protecting-controlled-unclassified-information/call-for-comments

National Cyber Summit: https://www.nationalcybersummit.com/Home

Navy Gold Coast: https://www.navygoldcoast.org/

GAO Report: https://www.gao.gov/products/gao-22-104810