Summit 7
Sum IT Up: CMMC News Roundup
It's difficult to keep up with all of the moving parts that make up the Department of Defense's Cybersecurity Maturity Model Certification Program. It's even more difficult to keep up with the relevant bits and bites that influence CMMC. This weekly podcast sums up the news and developments relevant to CMMC; DFARS and other regulations; and NIST standards such as SP 800-171, SP 800-53, the NIST Cybersecurity Framework, and others.
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Last Chance to Influence the FAR CUI Rule 09.07.2026 17:16
Register for Secure The DIB: https://summit7.us/event/secure-the-dib-telethon The public comment period for the proposed FAR CUI rule closes on July 23, making this your last opportunity to influence one of the biggest cybersecurity changes coming to federal contracting. Simply supporting or opposing the rule isn't enough. In this episode, we break down the Government's own guidance for writing ef...
There Are Enough CMMC Assessors, Contractors Just Aren't Ready 02.07.2026 10:24
Another 279 companies achieved CMMC Level 2 certification in June 2026, bringing the total to 1,717 certified organizations. That's a record month and far ahead of DoD's original projections. But the data also shows something surprising: the industry still isn't using all of its available assessment capacity. In this episode, we break down the latest Cyber AB numbers, explain our assessment capaci...
A Perfect SPRS Score Turned Into a $507K Settlement 25.06.2026 13:24
The DOJ has announced its first cybersecurity False Claims Act settlement of 2026, and the details should get every defense contractor's attention. In this episode, we break down the LOGZONE settlement, the difference between DFARS 252.204-7012 and CMMC, how a perfect SPRS score became a DIBCAC assessment score of -170, and why this case may be a preview of additional enforcement actions still wor...
What 2,005 Votes Revealed About Why Organizations Struggle With CMMC 18.06.2026 20:47
Register for Secure The DIB: https://www.summit7.us/secure-the-dib-telethon Over the last two months, we ran the CMMC Challenge Bracket. Eight matchups, 907 participants, 2,005 votes. The winner? Leadership Buy-In. But the final standings were only part of the story. In this episode, we break down the voting trends, coalition shifts, and comment analysis to understand what the community actually b...
We Predicted 2026. Here's What We Got Right (and Wrong) About CMMC 11.06.2026 19:54
Back in January, we made seven predictions about where the CMMC ecosystem would be by the end of 2026. Now that we're halfway through the year, we're checking the scoreboard. In this episode: • Level 2 certification growth • False Claims Act enforcement trends • Funding and compliance assistance programs • The FAR CUI rule • CMMC 3.0 and NIST SP 800-171 Rev. 3 • Early...
The Cyber Rule Everyone Forgot About Just Came Back 04.06.2026 22:42
Remember CIRCIA? The proposed rule would create mandatory cyber incident reporting requirements for more than 300,000 organizations across 16 critical infrastructure sectors, including the Defense Industrial Base. Now CISA is holding a new round of town halls to gather feedback before issuing a final rule. In this episode, we explain why CIRCIA isn't just another version of DFARS 252.204-7012, the...
May Cyber AB Town Hall Recap 28.05.2026 25:58
The Cyber AB brought the ecosystem together to deliver pretty exciting news during the May monthly town hall. Join us for this week's episode as we break down some of the topics a little deeper to see what it actually means for the ecosystem. Things like: • Has production accelerated within the ecosystem? • Who is the new EVP of the Cyber AB? • Who actually attends these meetings? A...
DoD Updated the CMMC FAQs Again 21.05.2026 18:53
DoD has updated the CMMC FAQs again, and the revision history doesn't tell the full story. In this episode, we break down the most important FAQ 2.3 changes, including significant changes, annual affirmations, CMMC UIDs, joint ventures, hard-copy CUI, and why the Affirming Official is one of the most important CMMC roles inside your company. Register for Summit 7 Live: https://www.summit7.us/s7liv...
Lessons Learned from 100 Level 2 Client Certifications 14.05.2026 26:06
It's milestone season in the CMMC world. Just six months into the Phased Rollout and there are 2.5x more Level 2 certifications than DoD expected. Meanwhile, a significant portion of those certs are Summit 7 clients. We now work with more than 100 Level 2 certified companies. Last but not least, Summit 7 was awarded the Army's NCODE contract to help bring secure and compliant enclaves to micro-siz...
The Numbers Behind CMMC Assessment Capacity 07.05.2026 28:54
Everyone keeps saying there aren't enough CMMC assessors. The data tells a very different story. In this episode we break down actual assessment capacity using the current number of certified assessors, DoD's rollout estimates, and capacity growth rates across the ecosystem. How quickly is the ecosystem scaling toward future demand targets of 16,000 and even 25,000 assessments per year? Turns out...
April Cyber AB Town Hall Recap 30.04.2026 28:47
We are back at it again with another rundown of the Cyber AB's monthly town hall and there sure was a lot of valuable information distributed during the meeting. Join us for this episode of we discuss some of the key information dished out this month and weigh on any impact it may have on the CMMC Program. Things like: • Changes in ecosystem engagement? • Do we have enough steps are in t...
L3Harris Won a Big Contract, Now You Need CMMC By July 23.04.2026 20:28
L3Harris Missile Solutions recently sent a letter informing their suppliers that they will need to achieve CMMC Level 2 (C3PAO) Status by July, 30th 2026. Two weeks later, L3Harris announced that they had been awarded a new contract for the Army Tactical Missile System. Coincidence? We think not. Not only do subcontractors need to provide their Level 2 certification, they also need to provide thei...
NIST 800-171 rev. 3 is Coming ... But Not How You Think 16.04.2026 21:10
NIST SP 800-171 Revision 3 has been out for two years. DFARS 252.204-7012 says to use the most current version. So why are defense contractors still using Revision 2? Because they're supposed to. In this episode, we break down the temporary rule that overrides the DFARS clause and keeps the entire ecosystem aligned on Revision 2. We cover: • What a class deviation actually is and why it matte...
CMMC Level 2 Assessment: What to Expect (Insights from 100 assessments) 09.04.2026 32:49
This week we sit down with a C3PAO who has completed over 100 CMMC Level 2 assessments. We chat cost, timeframe, assessor backlogs and the most common issues facing defense contractors. Register for Summit 7 Live: https://www.summit7.us/s7live GAO Report (2026): https://www.gao.gov/products/gao-26-107955 GAO Report (2021): https://www.gao.gov/products/gao-22-104679
Monthly Cyber AB Town Hall Recap (March) 02.04.2026 32:07
We are back at it again with another rundown of the Cyber AB's monthly town hall and there sure was a lot of valuable information distributed during the meeting. Join us for this episode of we discuss some of the key information dished out this month and weigh on any impact it may have on the CMMC Program. Things like: • Milestones achieved by the program this month! • Why was the new Do...
The CMMC November 2026 Deadline Is a Myth (Here’s What’s Actually Happening) 26.03.2026 24:01
Everyone is talking about a “November 2026 deadline” for CMMC Level 2. There's just one problem… it's not real. In this episode, we break down what the CMMC rule actually says about Phase 2, what really happens starting in November 2026, and why most contractors are misunderstanding the rollout. If you're in the defense industrial base, this is the clarity you need to plan your...
GAO Gave CMMC a 95%... Then Called It a Problem 19.03.2026 39:35
GAO's latest report on CMMC sounds cautious. They warn about external risks, ecosystem constraints, and gaps in DoD's strategy. But that framing misses the bigger story. Since the 2021 report, CMMC has gone from a fragmented concept to a functioning system. The ecosystem exists. Training exists. Small business support is working. So why does the report feel so negative? In this episode, we break d...
75% of the CMMC Assessment Guide Isn’t Requirements 12.03.2026 26:42
Most defense contractors assume everything written in the CMMC Level 2 Assessment Guide is a requirement. But that's not actually how the framework works. In this episode we break down the structure of the assessment guide and explain why roughly 75% of the document is explanatory text, not normative requirements. You'll learn: Where the real requirements come from in NIST SP 800-171 How verificat...
We Mapped 130 Iranian Cyber Attacks to CMMC… Here's What We Found 05.03.2026 36:12
Iranian cyber actors are targeting the Defense Industrial Base. So does CMMC actually help? In this episode, we mapped 130 real-world techniques used by five Iranian threat groups to the controls behind NIST SP 800-171 using the MITRE ATT&CK framework. Here is what the data shows: • 100% of techniques are detectable • 68% are mitigated with preventative controls • Just a handful...
February Cyber AB Town Hall Recap 26.02.2026 29:12
The Cyber AB has once again summoned the CMMC Ecosystem to deliver its monthly update and on this week's show we are going to break it down for you. Join us as we take all the information distributed during the meeting and dish out the information you need to know. Things like: Can my FSO check on my Tier 3? Have we eclipsed the 1,000 assessments milestone? When does a mock assessment stop “...
48% vs 9%? The DoD's CUI Numbers Don't Add Up 19.02.2026 33:02
The DoD Inspector General is raising concerns about CUI marking again and the numbers don't add up. In 2023, the IG found that 48% of reviewed CUI documents lack proper markings. Yet the DoD CUI Program website reports only 9% were unmarked that same year. So which is it? In this episode we break down the latest DoD IG management advisory, where the recommendations fall short, and why the CUI prog...
No CMMC, No Contract: Why You're Already Too Late for NAVAIR 12.02.2026 27:42
CMMC is a condition of contract award and many defense contractors are waiting until they see CMMC requirements in a solicitation to get started. But the department of defense wants the period between solicitation and award to be as short as possible. This week we crunch the numbers on 1,070 upcoming Navy contracts to see what a realistic timeline ought to look like. Summit 7 Live: https://www.sum...
The End of SPRS Scores (sort of) 05.02.2026 33:38
The largest change to DFARS cybersecurity requirements other than CMMC took place on February 1st, 2026, and nobody knew it happened. DFARS 7019 and 7020 have been replaced by DFARS clause 252.240-7997. Basic self-assessments have been eliminated. FAR 52.204-21 has a new number. And none of this went through rulemaking. This week we're diving deep into the mysterious world of class deviations and...
Monthly Cyber AB Town Hall Recap (January) 29.01.2026 46:42
After a brief hiatus, the Cyber AB has gathered the CMMC Ecosystem to deliver its monthly update. On this week's show, we breakdown the information distributed on this month's meeting that you need to know. Things like: • Who is the new DoW CIO? • Pending shutdown and CMMC Impacts • Ecosystem Growth and Certification updates • Does this show count for CPEs? And so much more...T...
CMMC for GSA Contractors? 22.01.2026 18:55
Defense contractors aren't the only ones who need to implement NIST cybersecurity requirements for CUI. The big question has always been whether other agencies would require proof of implementation via the CMMC program. The GSA just revised their process for assessing nonfederal systems handling controlled unclassified information and it's way closer to NIST's Risk Management Framework than CMMC....
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.