PODCAST · technology
Sum IT Up: CMMC News Roundup
by Summit 7
It's difficult to keep up with all of the moving parts that make up the Department of Defense's Cybersecurity Maturity Model Certification Program. It's even more difficult to keep up with the relevant bits and bites that influence CMMC. This weekly podcast sums up the news and developments relevant to CMMC; DFARS and other regulations; and NIST standards such as SP 800-171, SP 800-53, the NIST Cybersecurity Framework, and others.
-
161
CMMC Phase 2 Is Suspended... So Why Is the DoD Still Assessing Contractors?
Everyone saw the headline that CMMC Phase 2 was suspended. Almost nobody read the part that says government-led assessments are still happening. In this episode we look at what the DoD actually said, how DIBCAC decides who gets assessed, why the LogZone False Claims Act case matters, and why today's approach looks surprisingly similar to the original CMMC 1.0 phased rollout. If you think the suspension means nobody is verifying cybersecurity anymore, you may want to read the Phase 2 suspension memo one more time. Phase 2 Suspension: https://youtu.be/TfdwAc5tdMA?si=H8Dtz6Z1UbG_aYpX LogZone FCA: https://youtu.be/T5wJYnQzWws?si=ME3p2C8Sx_jhXTGJ DFARS 7020: https://youtu.be/D4JLkfvB-Ws?si=rG-4enAdaj0InsfY DoD Critical Tech: https://www.cto.mil/osc/critical-technologies/ CIO Interview: https://defensescoop.com/2026/07/17/pentagon-task-force-to-review-cmmc-hits-the-ground-running/ Suspension Memo (PDF): https://dodcio.defense.gov/Portals/0/Documents/Library/CMMC-ReformMemo.pdf
-
160
CMMC Phase 2 Is Suspended... But Contractor Liability Just Went UP
Miss the CUI Hotline Telethon? Watch it on-demand: https://summit7.us/event/secure-the-dib-telethon The DoD has suspended the November 2026 transition to Phase 2 of CMMC implementation, but that doesn't mean cybersecurity requirements have been relaxed. In this episode, we explain what actually changed, what didn't, why Level 2 self-assessments now matter more than ever, and how contractors could expose themselves to significant False Claims Act liability if they misunderstand the news. We also discuss the 60-day CMMC program review, the DoD's Request for Information, and what defense contractors should focus on moving forward. Phase 2 Announcement: https://www.war.gov/News/Releases/Release/Article/4542329/forging-the-arsenal-of-freedom-department-of-war-suspends-cmmc-phase-ii-require/ Phase 2 Blog: https://summit7.us/blog/cmmc-phase-2-suspended-with-60-day-review-what-happens-next 32 CFR 170.16: https://www.ecfr.gov/current/title-32/section-170.16 32 CFR 170.22: https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-G/part-170/subpart-D/section-170.22 False Claims Act: https://youtu.be/T5wJYnQzWws?si=pn8iwA7_8Ys_wvdq
-
159
Last Chance to Influence the FAR CUI Rule
Register for Secure The DIB: https://summit7.us/event/secure-the-dib-telethon The public comment period for the proposed FAR CUI rule closes on July 23, making this your last opportunity to influence one of the biggest cybersecurity changes coming to federal contracting. Simply supporting or opposing the rule isn't enough. In this episode, we break down the Government's own guidance for writing effective public comments and explain the seven principles that make comments persuasive. You'll learn the common mistakes to avoid, how to build evidence-based arguments, and how to give regulators constructive recommendations they can actually use. Whether you're planning to comment on the FAR CUI rule or want to better understand how federal rulemaking works, this episode will help you make your comment count before the deadline. Register for Summit 7 Live: https://www.summit7.us/s7live FAR CUI Rule: https://www.federalregister.gov/documents/2026/06/23/2026-12559/federal-acquisition-regulation-revolutionary-federal-acquisition-regulation-overhaul-parts-1-2-4-33 GSA Comment Guidance: https://www.regulations.gov/commenting-guidance
-
158
There Are Enough CMMC Assessors, Contractors Just Aren't Ready
Another 279 companies achieved CMMC Level 2 certification in June 2026, bringing the total to 1,717 certified organizations. That's a record month and far ahead of DoD's original projections. But the data also shows something surprising: the industry still isn't using all of its available assessment capacity. In this episode, we break down the latest Cyber AB numbers, explain our assessment capacity methodology, and discuss why contractor readiness, not assessor availability, remains the biggest constraint on CMMC adoption. Topics covered: • June 2026 CMMC Level 2 certification numbers • Available CMMC assessment capacity • Why the assessor shortage narrative doesn't match the data • The connection between CMMC readiness and DFARS 252.204-7012 compliance • What these trends could mean for the rest of the phased rollout Have questions? Contact us: https://summit7.us/ Register for Secure The DIB: https://summit7.us/event/secure-the-dib-telethon Monthly Cyber AB Town Hall: https://cyberab.org/News-Events/Town-Halls/pager/7916/page/2
-
157
A Perfect SPRS Score Turned Into a $507K Settlement
The DOJ has announced its first cybersecurity False Claims Act settlement of 2026, and the details should get every defense contractor's attention. In this episode, we break down the LOGZONE settlement, the difference between DFARS 252.204-7012 and CMMC, how a perfect SPRS score became a DIBCAC assessment score of -170, and why this case may be a preview of additional enforcement actions still working their way through the system. Topics covered: • LOGZONE FCA settlement details • DFARS 252.204-7012, 7019, and 7020 • SPRS self-assessment scores • DIBCAC medium assessments • Why no whistleblower was required • What this means for defense contractors moving forward Settlement and source documents linked below. Register for Secure The DIB: http://summit7.us/event/secure-the-dib-telethon Register for Summit 7 Live: https://www.summit7.us/s7live DOJ Settlement: https://www.justice.gov/opa/pr/alabama-defense-contractor-agrees-pay-507144-resolve-false-claims-act-liability-relating DoD IG + DOJ (2023): https://youtu.be/_3GLX6ele_E?t=448 FCA pod w/ Alexander Canizares: https://youtu.be/Tga0krfIrEk?si=i6E2FuLY7QLNGmos FCA pod w/ Stephanie Siegmann: https://youtu.be/d1yweDy2wV4?si=drOwbWxBm9GAlh38 FCA w/ Bruce Judge: https://youtu.be/tqT_5yQBlOk?si=xgmqev-87KTKpxUJ
-
156
What 2,005 Votes Revealed About Why Organizations Struggle With CMMC
Register for Secure The DIB: https://www.summit7.us/secure-the-dib-telethon Over the last two months, we ran the CMMC Challenge Bracket. Eight matchups, 907 participants, 2,005 votes. The winner? Leadership Buy-In. But the final standings were only part of the story. In this episode, we break down the voting trends, coalition shifts, and comment analysis to understand what the community actually believes is holding organizations back from CMMC success.
-
155
We Predicted 2026. Here's What We Got Right (and Wrong) About CMMC
Back in January, we made seven predictions about where the CMMC ecosystem would be by the end of 2026. Now that we're halfway through the year, we're checking the scoreboard. In this episode: • Level 2 certification growth • False Claims Act enforcement trends • Funding and compliance assistance programs • The FAR CUI rule • CMMC 3.0 and NIST SP 800-171 Rev. 3 • Early Level 3 activity • What the GAO report actually found Some predictions are looking strong. Others are too close to call. And at least one is trending in the wrong direction. Here's our mid-year reality check on CMMC in 2026. Register for Summit 7 Live: https://www.summit7.us/s7live 2026 Predictions (January): https://youtu.be/WxgGtKpF3_s?si=I9MfjmkBDojCRThv GAO Report podcast: https://youtu.be/U0VhiN3qpdE?si=lD-Pbl3vyfbIMPw7 NCODE for SMBs: https://www.summit7.us/blog/ncode-contract-award Assessment Capacity podcast: https://youtu.be/e_1FztgNCHM?si=PdpkkVk3SSa1V4-2 CIRCIA update: https://youtu.be/bvwnNSpDZgU?si=bS0ARRUfvvzLemmK
-
154
The Cyber Rule Everyone Forgot About Just Came Back
Remember CIRCIA? The proposed rule would create mandatory cyber incident reporting requirements for more than 300,000 organizations across 16 critical infrastructure sectors, including the Defense Industrial Base. Now CISA is holding a new round of town halls to gather feedback before issuing a final rule. In this episode, we explain why CIRCIA isn't just another version of DFARS 252.204-7012, the seven biggest differences defense contractors need to understand, and why the upcoming town halls may be the DIB's best opportunity to influence the final rule. Registration links for the CIRCIA Town Halls are included below. Register for Summit 7 Live: https://www.summit7.us/s7live CIRCIA Town Halls: https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing/cyber-incident-reporting-critical-infrastructure-act-2022-circia CIRCIA Proposed Rule Pod (2024): https://youtu.be/ngYSaO5fg5Y?si=VoVW54QvAzKe6r-r Proposed Rule: https://www.federalregister.gov/documents/2024/04/04/2024-06526/cyber-incident-reporting-for-critical-infrastructure-act-circia-reporting-requirements Congressional Research Service Report (PDF): https://www.congress.gov/crs-product/R48025 CIRCIA Hearing: https://homeland.house.gov/hearing/surveying-circia-sector-perspectives-on-the-notice-of-proposed-rulemaking/
-
153
May Cyber AB Town Hall Recap
The Cyber AB brought the ecosystem together to deliver pretty exciting news during the May monthly town hall. Join us for this week's episode as we break down some of the topics a little deeper to see what it actually means for the ecosystem. Things like: • Has production accelerated within the ecosystem? • Who is the new EVP of the Cyber AB? • Who actually attends these meetings? And so much more...Tune in to find out! Cyber AB TH Replay's: https://cyberab.org/News-Events/Town-Hall ISACA Website: https://www.isaca.org/ T3 Inquiries (older than 6 months): https://dowcio.war.gov/CMMC/Contact/ NIST SP 800-145: https://csrc.nist.gov/pubs/sp/800/145/final
-
152
DoD Updated the CMMC FAQs Again
DoD has updated the CMMC FAQs again, and the revision history doesn't tell the full story. In this episode, we break down the most important FAQ 2.3 changes, including significant changes, annual affirmations, CMMC UIDs, joint ventures, hard-copy CUI, and why the Affirming Official is one of the most important CMMC roles inside your company. Register for Summit 7 Live: https://www.summit7.us/s7live 100 Level 2-Certified Clients: https://www.summit7.us/blog/100-cmmc-l2-certified-clients NCODE: https://www.summit7.us/blog/ncode-contract-award CMMC FAQs: https://dodcio.defense.gov/CMMC/ January FAQ Pod: https://youtu.be/8ZxqqH0zws8?si=m5n8WQttWsZV8n24 Paper CUI Pod: https://youtu.be/lcIaxVBjyr0?si=17LdlP92NuCGa_ph
-
151
Lessons Learned from 100 Level 2 Client Certifications
It's milestone season in the CMMC world. Just six months into the Phased Rollout and there are 2.5x more Level 2 certifications than DoD expected. Meanwhile, a significant portion of those certs are Summit 7 clients. We now work with more than 100 Level 2 certified companies. Last but not least, Summit 7 was awarded the Army's NCODE contract to help bring secure and compliant enclaves to micro-sized defense contractors. Exciting times. Register for Summit 7 Live: https://www.summit7.us/s7live 100 Level 2-Certified Clients: https://www.summit7.us/blog/100-cmmc-l2-certified-clients NCODE: https://www.summit7.us/blog/ncode-contract-award
-
150
The Numbers Behind CMMC Assessment Capacity
Everyone keeps saying there aren't enough CMMC assessors. The data tells a very different story. In this episode we break down actual assessment capacity using the current number of certified assessors, DoD's rollout estimates, and capacity growth rates across the ecosystem. How quickly is the ecosystem scaling toward future demand targets of 16,000 and even 25,000 assessments per year? Turns out the real bottleneck isn't assessor capacity at all. ... Register for Summit 7 Live: https://www.summit7.us/s7live GAO Report (2026): https://www.gao.gov/products/gao-26-107955 GAO Report (2021): https://www.gao.gov/products/gao-22-104679
-
149
April Cyber AB Town Hall Recap
We are back at it again with another rundown of the Cyber AB's monthly town hall and there sure was a lot of valuable information distributed during the meeting. Join us for this episode of we discuss some of the key information dished out this month and weigh on any impact it may have on the CMMC Program. Things like: • Changes in ecosystem engagement? • Do we have enough steps are in the T3 process? • Has certification output increased? And so much more...Tune in to find out! Cyber AB TH Replay's: https://cyberab.org/News-Events/Town-Hall ISACA Website: https://www.isaca.org/ T3 Inquiries (older than 6 months): https://dowcio.war.gov/CMMC/Contact/
-
148
L3Harris Won a Big Contract, Now You Need CMMC By July
L3Harris Missile Solutions recently sent a letter informing their suppliers that they will need to achieve CMMC Level 2 (C3PAO) Status by July, 30th 2026. Two weeks later, L3Harris announced that they had been awarded a new contract for the Army Tactical Missile System. Coincidence? We think not. Not only do subcontractors need to provide their Level 2 certification, they also need to provide their Level 2 assessment report. This week we talk about whether this is an anomaly or a sign of things to come. Register for Summit 7 Live: https://www.summit7.us/s7live L3Harris Letter: https://www.summit7.us/blog/l3harris-supply-chain-notice Primes can't waive CMMC: https://youtu.be/haVzS8j7Qz4?si=F2RICMKbCNRu-1uh CMMC CAP (PDF): https://cyberab.org/Portals/0/CMMC%20Assessment%20Process%20v2.0.pdf
-
147
NIST 800-171 rev. 3 is Coming ... But Not How You Think
NIST SP 800-171 Revision 3 has been out for two years. DFARS 252.204-7012 says to use the most current version. So why are defense contractors still using Revision 2? Because they're supposed to. In this episode, we break down the temporary rule that overrides the DFARS clause and keeps the entire ecosystem aligned on Revision 2. We cover: • What a class deviation actually is and why it matters • Why DoD had to pause the shift to Revision 3 • How CMMC rulemaking controls the transition • And when Revision 3 will realistically start showing up in contracts Bottom line: contractors aren't behind. The rules haven't changed yet. ....... Register for Summit 7 Live: https://www.summit7.us/s7live 171r3: https://csrc.nist.gov/pubs/sp/800/171/r3/final DFARS 7012 deviation (PDF): https://www.acq.osd.mil/dpap/policy/policyvault/USA001074-24-DPC.pdf 32 CFR 170: https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-G/part-170 Class deviation podcast: https://youtu.be/voziZRAMvv4?si=3xHm7I_gIeQTQxLf Class deviation press release: https://www.war.gov/News/Releases/Release/Article/3763953/department-of-defense-issues-class-deviation-on-cybersecurity-standards-for-cov/
-
146
CMMC Level 2 Assessment: What to Expect (Insights from 100 assessments)
This week we sit down with a C3PAO who has completed over 100 CMMC Level 2 assessments. We chat cost, timeframe, assessor backlogs and the most common issues facing defense contractors. Register for Summit 7 Live: https://www.summit7.us/s7live GAO Report (2026): https://www.gao.gov/products/gao-26-107955 GAO Report (2021): https://www.gao.gov/products/gao-22-104679
-
145
Monthly Cyber AB Town Hall Recap (March)
We are back at it again with another rundown of the Cyber AB's monthly town hall and there sure was a lot of valuable information distributed during the meeting. Join us for this episode of we discuss some of the key information dished out this month and weigh on any impact it may have on the CMMC Program. Things like: • Milestones achieved by the program this month! • Why was the new DoW CIO talking to Armed Services committees? • How is the ecosystem growing? • What to expect in the CAICO transfer to ISACA. And so much more...Tune in to find out! Cyber AB TH Replay's: https://cyberab.org/News-Events/Town-Hall ISACA Website: https://www.isaca.org/
-
144
The CMMC November 2026 Deadline Is a Myth (Here’s What’s Actually Happening)
Everyone is talking about a “November 2026 deadline” for CMMC Level 2. There's just one problem… it's not real. In this episode, we break down what the CMMC rule actually says about Phase 2, what really happens starting in November 2026, and why most contractors are misunderstanding the rollout. If you're in the defense industrial base, this is the clarity you need to plan your timeline the right way. Key topics: • What Phase 2 actually means • When Level 2 requirements apply (and when they don't) • Why this isn't a mass certification deadline • How to think about your real CMMC timeline • Stop chasing phantom deadlines and start focusing on the contracts that matter. Register for Summit 7 Live: https://www.summit7.us/s7live PALT: https://youtu.be/C50UXJyz4PA?si=ySn1oIS4FaK4Si9f 32 CFR 170.3: https://www.ecfr.gov/current/title-32/section-170.3 Jan 2025 memo: https://dodprocurementtoolbox.com/uploads/DOPSR_Cleared_OSD_Memo_CMMC_Implementation_Policy_d26075de0f.pdf
-
143
GAO Gave CMMC a 95%... Then Called It a Problem
GAO's latest report on CMMC sounds cautious. They warn about external risks, ecosystem constraints, and gaps in DoD's strategy. But that framing misses the bigger story. Since the 2021 report, CMMC has gone from a fragmented concept to a functioning system. The ecosystem exists. Training exists. Small business support is working. So why does the report feel so negative? In this episode, we break down where GAO is right, where they're overstating the risk, and why the real story is the program's quiet but meaningful progress. Register for Summit 7 Live: https://www.summit7.us/s7live GAO Report (2026): https://www.gao.gov/products/gao-26-107955 GAO Report (2021): https://www.gao.gov/products/gao-22-104679
-
142
75% of the CMMC Assessment Guide Isn’t Requirements
Most defense contractors assume everything written in the CMMC Level 2 Assessment Guide is a requirement. But that's not actually how the framework works. In this episode we break down the structure of the assessment guide and explain why roughly 75% of the document is explanatory text, not normative requirements. You'll learn: Where the real requirements come from in NIST SP 800-171 How verification procedures in NIST SP 800-171A become assessment objectives Why discussion sections and examples are informative, not prescriptive Understanding the difference between requirements, assessment objectives, and explanatory guidance can help contractors avoid unnecessary controls, reduce documentation overhead, and simplify CMMC compliance. CMMC Assessment Guides: https://dodcio.defense.gov/cmmc/Resources-Documentation/ NIST SP 800-171: https://csrc.nist.gov/pubs/sp/800/171/r2/upd1/final NIST SP 800-171A: https://csrc.nist.gov/pubs/sp/800/171/a/final
-
141
We Mapped 130 Iranian Cyber Attacks to CMMC… Here's What We Found
Iranian cyber actors are targeting the Defense Industrial Base. So does CMMC actually help? In this episode, we mapped 130 real-world techniques used by five Iranian threat groups to the controls behind NIST SP 800-171 using the MITRE ATT&CK framework. Here is what the data shows: • 100% of techniques are detectable • 68% are mitigated with preventative controls • Just a handful of core controls drive most of the defensive impact We also examine what that means for Cybersecurity Maturity Model Certification and why 800-171 remains a strong floor for protecting CUI. But there is a gap. Only about half of the relevant NIST SP 800-53 that mitigate known Iranian techniques are represented in the 800-171 baseline. If you are a defense contractor, this episode will show you what compliance actually buys you and where you may need to go further. Register for Summit 7 Live: https://www.summit7.us/s7live MITRE ATT&CK: https://attack.mitre.org/ Mappings Explorer: https://ctid.mitre.org/projects/mappings-explorer CISA Alert: https://www.cisa.gov/topics/cyber-threats-and-advisories/advanced-persistent-threats/iran NIST SP 800-53: https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final NIST SP 800-171: https://csrc.nist.gov/pubs/sp/800/171/r2/upd1/final
-
140
February Cyber AB Town Hall Recap
The Cyber AB has once again summoned the CMMC Ecosystem to deliver its monthly update and on this week's show we are going to break it down for you. Join us as we take all the information distributed during the meeting and dish out the information you need to know. Things like: Can my FSO check on my Tier 3? Have we eclipsed the 1,000 assessments milestone? When does a mock assessment stop “mocking”? Updates on the ISACA/ CAICO switchover And so much more...Tune in to find out! Sum It Up: “The End of SPRS Scores (sort of)”: https://youtu.be/_UFN7fubgQY?si=EgtchmuAHti24Cr8 Cyber AB TH Recordings: https://cyberab.org/News-Events/Town-halls ISACA Webinar - CMMC: Requirements, Roles, and Professional Credentials: https://store.isaca.org/s/community-event?id=a33VQ000001otC1YAI ISACA CMMC Page: https://www.isaca.org/credentialing/cmmc
-
139
48% vs 9%? The DoD's CUI Numbers Don't Add Up
The DoD Inspector General is raising concerns about CUI marking again and the numbers don't add up. In 2023, the IG found that 48% of reviewed CUI documents lack proper markings. Yet the DoD CUI Program website reports only 9% were unmarked that same year. So which is it? In this episode we break down the latest DoD IG management advisory, where the recommendations fall short, and why the CUI program and the CMMC program (although closely related) are owned by different offices that can't fix each other's problems. For defense contractors, this isn't academic. CMMC enforcement depends on the integrity of the CUI program. If CUI marking is inconsistent, compliance risk increases downstream. Summit 7 Live: https://www.summit7.us/s7live 2026 IG Report: https://www.dodig.mil/reports.html/Article/4397146/management-advisory-dod-policy-and-training-on-dissemination-controls-for-contr/ 2023 IG Report: https://www.dodig.mil/reports.html/Article/3413433/audit-of-the-dods-implementation-and-oversight-of-the-controlled-unclassified-i/
-
138
No CMMC, No Contract: Why You're Already Too Late for NAVAIR
CMMC is a condition of contract award and many defense contractors are waiting until they see CMMC requirements in a solicitation to get started. But the department of defense wants the period between solicitation and award to be as short as possible. This week we crunch the numbers on 1,070 upcoming Navy contracts to see what a realistic timeline ought to look like. Summit 7 Live: https://www.summit7.us/s7live PALT Pod 2024: https://youtu.be/NZs4f5voyrg?si=S-xarOpYyiSG00Bs NAVAIR Forecast: https://www.navair.navy.mil/LRAE
-
137
The End of SPRS Scores (sort of)
The largest change to DFARS cybersecurity requirements other than CMMC took place on February 1st, 2026, and nobody knew it happened. DFARS 7019 and 7020 have been replaced by DFARS clause 252.240-7997. Basic self-assessments have been eliminated. FAR 52.204-21 has a new number. And none of this went through rulemaking. This week we're diving deep into the mysterious world of class deviations and what they mean for defense contractors moving forward. RFO Website: https://www.acquisition.gov/far-overhaul DFARS RFO Deviations: https://www.acq.osd.mil/dpap/dars/dfars_far_overhaul_class_deviations.html CMMC class deviation: https://youtu.be/vC4IJ2JQ5NU?si=B8I9DII4ZEbQ2dNx 7012 class deviation: https://youtu.be/voziZRAMvv4?si=HxIkpUWnxyergEUQ
-
136
Monthly Cyber AB Town Hall Recap (January)
After a brief hiatus, the Cyber AB has gathered the CMMC Ecosystem to deliver its monthly update. On this week's show, we breakdown the information distributed on this month's meeting that you need to know. Things like: • Who is the new DoW CIO? • Pending shutdown and CMMC Impacts • Ecosystem Growth and Certification updates • Does this show count for CPEs? And so much more...Tune in to find out! ISACA Webinar - CMMC: Requirements, Roles, and Professional Credentials: https://store.isaca.org/s/community-event?id=a33VQ000001otC1YAI DAU CMMC microlearning: https://www.dau.edu/acquipedia?combine=cmmc&title=C&field_functional_area_target_id=All&field_topic_area_target_id=All ISACA CMMC Page: https://www.isaca.org/credentialing/cmmc
-
135
CMMC for GSA Contractors?
Defense contractors aren't the only ones who need to implement NIST cybersecurity requirements for CUI. The big question has always been whether other agencies would require proof of implementation via the CMMC program. The GSA just revised their process for assessing nonfederal systems handling controlled unclassified information and it's way closer to NIST's Risk Management Framework than CMMC. CIO-IT Security-21-112r1 (PDF): https://www.gsa.gov/system/files/Protecting-Controlled-Unclassified-Information-%28CUI%29-in-Nonfederal-Systems-and-Organizations-Process-%5BCIO-IT-Security-21-112-Rev-1%5D.pdf Summit 7 Live San Diego: https://www.summit7.us/s7live
-
134
Securing the Supply Chain with Elbit America
This week we sit down with Supply Chain Director Bo Birdwell to discuss Elbit America's latest open letter to suppliers regarding CMMC. Elbit's letter doesn't mince words: CMMC is here and the time to act is now. Bo not only walks us through the perspective of a major prime contractor on cost, timelines, outsourced services, CMMC Level 3, and more – he also drops a ton of helpful tips for current and prospective suppliers. Elbit Supplier Page: https://www.elbitamerica.com/suppliers#cyber MSP Collective: https://www.mspcollective.org/ Bo Birdwell: https://www.linkedin.com/in/bobirdwell/
-
133
New CMMC FAQs (January 2026)
The defense department has updated the CMMC FAQs for the second time in 3 months. In lieu of rulemaking updates the CMMC FAQs are the best place for updated guidance. This week we're exploring DoD's answers regarding everything from encryption to enclaves to VDI endpoints. CMMC FAQs: https://dodcio.defense.gov/CMMC/
-
132
7 CMMC Predictions for 2026
Another year another set of eerily accurate predictions about defense cybersecurity requirements and the CMMC program. Like usual we got most of our 2025 predictions correct. For 2026 we're getting specific with False Claims settlements, CMMC 3.0, FAR CUI, and more! FCA episode: https://youtu.be/tPA-ALjW1Hk?si=KgPUAo4VqqmX3mNF DoD IG report: https://www.youtube.com/watch?v=RNafaUlgBGo Golden Dome: https://youtu.be/y88JqZdJsj0?si=eGpIm1jqKRYpW4n3
-
131
CMMC Requirements for DLA Suppliers
Defense Logistics Agency suppliers got a special Christmas gift: detailed estimates of CMMC requirements by DLA supply class! The Defense Department buys a lot of different products and services and the estimates make it clear that different types of contractors will experience CMMC requirements in very different ways. If only we could get every agency and mega prime to put out info like this. Episode Links: DLA SMB Website: https://www.dla.mil/Small-Business/Resource-Center/Cybersecurity-Resources/ What DLA Buys: https://www.dla.mil/Small-Business/Getting-Started/What-DLA-Buys/ Supply Classes: https://www.dau.edu/acquipedia-article/supply-classes
-
130
FCA Whistleblower Strikes Again
Another defense contractor is paying six figure fines after settling with the Department of Justice for allegedly failing to comply with DFARS clause 252.204-7012. The kicker: their own employee blew the noncompliance whistle and got a cut of penalty money. This is the fifth such settlement in 2025 and the DOJ is crystal clear that the don't discriminate just because a company is small. Pathfinder 101: https://www.summit7.us/pathfinder Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo Memo: https://dodcio.defense.gov/cmmc/Resources-Documentation/ Swiss Automation: https://www.justice.gov/opa/pr/illinois-precision-machining-company-agrees-pay-421234-resolve-alleged-false-claims-act MORSECORP: https://www.youtube.com/watch?v=ZnePk6jaezA Raytheon: https://www.justice.gov/opa/pr/raytheon-companies-and-nightwing-group-pay-84m-resolve-false-claims-act-allegations-relating Aero Turbine: https://www.youtube.com/watch?v=hFEEVGXv_00 GTRC: https://www.justice.gov/opa/pr/georgia-tech-research-corporation-agrees-pay-875000-resolve-civil-cyber-fraud-litigation DFARS 7012: https://youtu.be/cy4e28YAkXU?si=MqGKGNAHTPyvj-DI
-
129
No CMMC for Hard Copy CUI?
A recent webinar from the US Army Corps of Engineers told suppliers that if they only handle paper CUI, then CMMC requirements don't apply to them. That's a significant concession to industry on par with COTS exemption and POAMs. But is this USACE flexing their discretion or are they setting up a conflict by setting policy around CMMC applicability? Pathfinder 101: https://www.summit7.us/pathfinder Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo
-
128
Primes Can't Waive CMMC
Register for CMMC Industry Week: https://www.summit7.us/industry-week Since the 48 CFR CMMC final rule was published in September 2025 we've seen supplier notices from Lockheed, RTX, BAE, HII, and many others. Most recently, Northrop Grumman recently published a supplier announcement titled “CMMC 2.0 is Final – Are You Ready?”. The big takeaway: don't expect CMMC waivers from your prime customers because they can't grant them to you. Pathfinder 101: https://www.summit7.us/pathfinder Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo DFARS 7012: https://youtu.be/cy4e28YAkXU?si=KvezY7Vu7zXf9qYZ 32 CFR Final rule: https://www.federalregister.gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-certification-cmmc-program 48 CFR Final rule: https://www.federalregister.gov/documents/2025/09/10/2025-17359/defense-federal-acquisition-regulation-supplement-assessing-contractor-implementation-of January Memo (PDF): https://dodprocurementtoolbox.com/uploads/DOPSR_Cleared_OSD_Memo_CMMC_Implementation_Policy_d26075de0f.pdf
-
127
DIBCAC Assessment Requirements
While everyone has been focused on the start of CMMC phase 1, many contractors are discovering that DFARS clause 252.204-7020 has been lurking in their contracts since 2020. DoD reserves the right to show up at any time and audit compliance with DFARS clause 252.204-7012. This week we're diving into everything that DIBCAC will be asking for when they show up on your doorstep. Pathfinder 101: https://www.summit7.us/pathfinder Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo DIBCAC intake forms: https://www.dcma.mil/DIBCAC/ DFARS 252.204-7012: https://youtu.be/cy4e28YAkXU?si=x4tmDKcCc44dLnJE DFARS 252.204-7020: https://youtu.be/D4JLkfvB-Ws?si=6_yyMYrU7DVoxoBt
-
126
November Cyber AB Town Hall Recap
The final Cyber AB TH of 2025 took place this week which means it's time for the team to unpack all the important information you need to know. On this week's show, Jason and Joy sit down for one one last time in 2025 as we discuss things like: •The final ecosystem update of 2025 •The biggest highlights of 2025 •DO I have to affirm my C3PAO assessment score? •What the AB expects for 2026 Tune in as we close out this year of Cyber AB Town Halls with a little fun! Summit 7 Live: https://www.summit7.us/S7Live Pathfinder 101: https://www.summit7.us/pathfinder Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo AB Town Halls: https://cyberab.org/News-Events/Town-Halls/Details/march-town-hall
-
125
CMMC Phase 1: What Comes Next?
As of November 10th, 2025, CMMC is now a condition of award for new defense contracts. “Phase 1” of the CMMC rollout will last until November 10th, 2026. This week we discuss seven predictions we have for the new normal. Summit 7 Live: https://www.summit7.us/S7Live Pathfinder 101: https://www.summit7.us/pathfinder Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo 32 CFR 170.3(e): https://www.ecfr.gov/current/title-32/part-170#p-170.3(e) DFARS 7012: https://youtu.be/cy4e28YAkXU?si=yC_wKI42JNxIHKME Phase 1 Blog: https://www.summit7.us/blog/cmmc-begins-today
-
124
CMMC Timeline Refresher
After four years of rulemaking here we are at the last podcast before the official start of CMMC phase 1. What better way to usher in the new normal of CMMC than a quick refresher on how and why CMMC became a thing in the first place? Nothing helps contextualize the CMMC program like remembering how resistant the DoD has been to third party verification until they were left with no other choice.
-
123
October Cyber AB Town Hall Recap
On this week's spine-tingling episode of the show, Jason and Joy sit down unwrap the October Cyber AB Town Hall like a bag of pillowcase full of candy. With less than two weeks until the November 10th launch, this marks the final town hall before the CMMC becomes a fully operational reality. Tune in as we mix up a cauldron of all the important information you need to know to assure no tricks as you pursue your CMMC bag of treats… no costumes required! Summit 7 Live: https://www.summit7.us/S7Live Pathfinder 101: https://www.summit7.us/pathfinder Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo AB Town Halls: https://cyberab.org/News-Events/Town-Halls/Details/march-town-hall
-
122
CMMC Requirements Are Starting To Show Up
CMMC officially goes into effect on November 10th, 2025, at which point all new DoD solicitations and contracts will include at least CMMC Level 1 status requirements. While the government shutdown might affect the pace of new contract awards, it doesn't change anything about the effective date of CMMC specifically. This week we're looking at the trickle of contract notices that are letting people know CMMC is very real and will absolutely be required (including level 2). Pathfinder 101: https://www.summit7.us/pathfinder Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo NAVSEA (Level 2): https://sam.gov/workspace/contract/opp/0a92f866231546828b3fd11cf1146a8a/view USSOCOM (Level 1): https://sam.gov/workspace/contract/opp/eb3d38dd00e845579212f724b6dedd37/view USACE (Level 2): https://sam.gov/workspace/contract/opp/e0a817b5b7c74c319ebaa2df9cd3d637/view
-
121
BIG changes are coming to CPARS (Cyber)
The Senate has passed their version of the FY26 NDAA and they want annual contractor performance measurements to focus exclusively on “negative performance events”. Per the Senate Armed Services Committee that includes failing to meet cyber requirements, failing to flow down requirements to subcontractors, and submission of false claims (cyber). Add this one to the growing pile of evidence that the government really, really wants contractors to take cybersecurity seriously. Pathfinder 101: https://www.summit7.us/pathfinder Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo Memo: https://dodcio.defense.gov/cmmc/Resources-Documentation/ Senate NDAA: https://www.congress.gov/bill/119th-congress/senate-bill/2296/text
-
120
Key Takeaways From Our Final Rule Webinar
Watch full webinar here: https://www.summit7.us/webinars/cmmc-phase-1-the-final-rule-is-here The start of CMMC phase 1 is just around the corner. Starting on November 10th, 2025, DoD contracting officers will begin inserting CMMC status requirements in new solicitations and contracts. We recently held a webinar on the CMMC final rule to get people up to speed so this week we're bringing you our key takeaways. If you want all the details, the webinar is available on demand (registration link is in the show notes). Find out where you are on your CMMC journey here: https://www.summit7.us/pathfinder
-
119
September Cyber AB Town Hall Recap
September has come to a close and despite all the moving parts, name changes, and other potential roadblocks, the CMMC program is humming along. Assessments are being conducted at a blazing pace, the AB staff is growing, and people are still not sure if they should identify as an ESP or CSP.On this week's show, we dig into the September Cyber AB Town Hall and break down all the important details you need to know! Summit 7 Live: https://www.summit7.us/S7Live Pathfinder 101: https://www.summit7.us/pathfinder Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo AB Town Halls: https://cyberab.org/News-Events/Town-Halls/Details/march-town-hall
-
118
What is DFARS 252.204-7021? (Pt. 1)
DFARS clause 252.204-7021 goes into effect on November 10th, 2025, but there's more under the hood than just the text of the contract clause. Contracting officers have an entire set of procedures they must follow that dictate when and if the 7021 clause should be included in a defense contract at all. In this episode we're looking at the other side of the coin to the infamous CMMC DFARS clause. Final Rule Webinar: https://www.summit7.us/webinars/cmmc-phase-1-the-final-rule-is-here?hsCtaAttrib=195767465874 Summit 7 Live: https://www.summit7.us/S7Live Pathfinder 101: https://www.summit7.us/pathfinder Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo 2025 CMMC Final Rule (48 CFR): https://www.federalregister.gov/documents/2025/09/10/2025-17359/defense-federal-acquisition-regulation-supplement-assessing-contractor-implementation-of DFARS 7008: https://youtu.be/vgrRGIWboKc?si=chKYMNRUea9eqpn- DFARS 7012: https://youtu.be/cy4e28YAkXU?si=OO3IEXYvfGqZQ3op DFARS 7019: https://youtu.be/7gW_82Cus7Y?si=IT2ORlBlZELxxbdu DFARS 7020: https://youtu.be/D4JLkfvB-Ws?si=-hMhIq6dJLxu1NU4 DFARS 7025: https://youtu.be/LtJK-CHuyp8?si=A6WoUGBEEgVxp5Jx DFARS 7009: https://youtu.be/kfecRRrd41w?si=PNXrbcvRLHc5GoUg 32 CFR 170 Webinar: https://www.summit7.us/webinars/cmmc-32-cfr-final-rule?_gl=1*1qpc6eg*_up*MQ..*_gs*MQ..
-
117
What is DFARS 252.204-7025?
Final Rule Webinar: https://www.summit7.us/webinars/cmmc-phase-1-the-final-rule-is-here?hsCtaAttrib=195767465874 The regulation that finalizes CMMC guidance for DoD contracting officers and program managers officially goes into effect on November 10th, 2025. The highlight of the regulation is the final text of DFARS clause 252.204-7021 which tells contractors which CMMC level they need to achieve in order to take award of a contract. But the regulation also created DFARS provision 252.204-7025 which officially notifies offerors of the requirements contained in the 7021 clause and it's only three paragraphs long! Summit 7 Live: https://www.summit7.us/S7Live Pathfinder 101: https://www.summit7.us/pathfinder Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo 2025 CMMC Final Rule (48 CFR): https://www.federalregister.gov/documents/2025/09/10/2025-17359/defense-federal-acquisition-regulation-supplement-assessing-contractor-implementation-of
-
116
CMMC: Final Rule vs Class Deviation
Register for the upcoming webinar: https://www.summit7.us/webinars/cmmc-phase-1-the-final-rule-is-here It's official: CMMC Phase 1 begins on November 10th, 2025 when the 48 CFR CMMC final rule goes into effect. After that point all new Department of Defense/War contracts will contain some level of CMMC requirement. But just when things seem certain, people are wondering about the recent class deviation regarding DFARS clause 252.204-7021. Is the use of the CMMC clause actually suspended? Spoiler: no, not even close. Final Rule Webinar: https://www.summit7.us/webinars/cmmc-phase-1-the-final-rule-is-here?hsCtaAttrib=195767465874 Summit 7 Live: https://www.summit7.us/S7Live Pathfinder 101: https://www.summit7.us/pathfinder Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo 2025 CMMC Final Rule (48 CFR): https://www.federalregister.gov/documents/2025/09/10/2025-17359/defense-federal-acquisition-regulation-supplement-assessing-contractor-implementation-of Aug Class Deviation: https://www.acq.osd.mil/dpap/policy/policyvault/USA001756-25-DPCAP.pdf
-
115
Defense Contractors are Betting Their Companies on THIS Assumption About CMMC Phase 1
A lot of defense contractors are betting that the DoD will only require CMMC Level 2 self-assessments during the first 12 months of CMMC (“Phase 1”). Since December 2024 there have been three official policies outlining what can be required in Phase 1 and none of them prohibit Level 2 certification assessments. Instead, every policy we can find reinforces the idea that many companies will be required to achieve CMMC Level 2 certification in Phase 1. In this episode we walk through all 3 policies so you can decide for yourself if that's a risk you want to take with your business. Summit 7 Live: https://www.summit7.us/S7Live Pathfinder 101: https://www.summit7.us/pathfinder Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo 32 CFR 170.3(e): https://www.ecfr.gov/current/title-32/part-170#p-170.3(e) The January Memo (PDF): https://dodprocurementtoolbox.com/uploads/DOPSR_Cleared_OSD_Memo_CMMC_Implementation_Policy_d26075de0f.pdf The July Memo (PDF): https://dodprocurementtoolbox.com/uploads/PTDO_Do_D_CIO_Memo_Resources_for_CMMC_Implemtation_dtd_20250728_25_T_2704_cleared_20250807_e53aa02e78.pdf
-
114
August Cyber AB Town Hall Recap
The Summer is all but over, but that's ok because the CMMC program is just getting started! On this week's episode, we cover the Cyber AB's Monthly Townhall for August and break down all the things you need to know. Things like: • Did assessment progress slow down? • Are there any reported failures? • Are people finally interpreting the 10-day post assessment rule correctly? • Will the DoD be represented at CS5? • What is the C3PAO Advisory Council? And so much more... Tune in to find out! Summit 7 Live: https://www.summit7.us/S7Live Women of CMMC Dinner: https://cs5global.org/women-of-cmmc-dinner/ Pathfinder 101: https://www.summit7.us/pathfinder Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo AB Town Halls: https://cyberab.org/News-Events/Town-Halls/Details/march-town-hall
-
113
(Scoop) Golden Dome Contractor Cyber Requirements
Register for Secure The DIB: https://www.summit7.us/secure-the-dib-2025 Golden Dome promises to be the largest and most complex defense initiatives in American history. Countless contractors, subcontractors, and suppliers will be called on to help build the ultimate system of systems. But those suppliers are the targets of cyber espionage, disruption, and IP theft – regardless of their size. So it's no surprise that as the Golden Dome program lifts off, the DoD is out in front with some pretty intense cybersecurity requirements. Pathfinder 101: https://www.summit7.us/pathfinder Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo DFARS 7012: https://youtu.be/cy4e28YAkXU?si=KvezY7Vu7zXf9qYZ
-
112
Yet Another False Claims Settlement
Register for Secure The DIB: https://securethedib.us/ Voluntarily disclose your DFARS cybersecurity noncompliance? That'll be $1.75M, please. This week we're looking at the details of a recent False Claims Act settlement involving a small defense contractor. Turns out that mistaking export controls for cyber controls and relying on the wrong external service providers can controls can cost you a lot of money. Pathfinder 101: https://www.summit7.us/pathfinder Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo DOJ Settlement: https://www.justice.gov/opa/pr/california-defense-contractor-and-private-equity-firm-agree-pay-175m-resolve-false-claims DFARS 7012: https://youtu.be/cy4e28YAkXU?si=KvezY7Vu7zXf9qYZ
We're indexing this podcast's transcripts for the first time — this can take a minute or two. We'll show results as soon as they're ready.
No matches for "" in this podcast's transcripts.
No topics indexed yet for this podcast.
Loading reviews...
ABOUT THIS SHOW
It's difficult to keep up with all of the moving parts that make up the Department of Defense's Cybersecurity Maturity Model Certification Program. It's even more difficult to keep up with the relevant bits and bites that influence CMMC. This weekly podcast sums up the news and developments relevant to CMMC; DFARS and other regulations; and NIST standards such as SP 800-171, SP 800-53, the NIST Cybersecurity Framework, and others.
HOSTED BY
Summit 7
CATEGORIES
Loading similar podcasts...