Summit 7

Sum IT Up: CMMC News Roundup

It's difficult to keep up with all of the moving parts that make up the Department of Defense's Cybersecurity Maturity Model Certification Program. It's even more difficult to keep up with the relevant bits and bites that influence CMMC. This weekly podcast sums up the news and developments relevant to CMMC; DFARS and other regulations; and NIST standards such as SP 800-171, SP 800-53, the NIST Cybersecurity Framework, and others.

Author

Summit 7

Category

Technology

Podcast website

summit7.us

Latest episode

Jul 9, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Cyber AB Town Hall Recap 08.08.2024

If you haven't caught a Cyber AB Town Hall lately, then you're missing out on valuable information. This week we give our take on the AB's rulemaking timeline, what the FY25 NDAA says about CMMC, the upcoming DoD IG report on the Cyber AB, and more! Cyber AB Town Halls: https://cyberab.org/News-Events/Town-Halls Secure the DIB replay: https://www.summit7.us/securethedib

New CUI Executive Order in 2024?! 01.08.2024

Register for Secure the DIB: Summer Camp for FREE here: https://www.securethedib.us/ You're not crazy. According to a new inspector general report the federal CUI Program has been in hibernation for the last few years. But the story goes much deeper than run-of-the-mill findings. Desperately overworked civil servants, stubbornly non-compliant federal agencies, the lofty heights of the National Sec...

Secure the DIB Summer Camp 25.07.2024

Register for Secure the DIB: Summer Camp for FREE here: https://www.securethedib.us/ Summer is coming to a close and that means it's time for our annual Secure the DIB Summer Camp webinar. Summit 7's Daniel Akridge joins the show this week to share what he's seeing and hearing from defense contractors regarding market dynamics, what the primes are up to, and how companies are dealing with the cost...

Cyber Overconfidence in the DIB 18.07.2024

Register for Secure the DIB: Summer Camp for FREE here: https://www.securethedib.us/ The DoD's Center for Manufacturing Cybersecurity has released a report documenting the level of confidence that defense contractors have in their cybersecurity posture. The conclusion? There is a systemic cybersecurity overconfidence problem in the DIB. Episode Links: DIB Summer Camp: https://www.summit7.us/secure...

Live, Laugh, Rulemaking 11.07.2024

Register for Secure the DIB: Summer Camp for FREE here: https://www.securethedib.us/ The 32 CFR CMMC final rule has officially left the DoD and is currently undergoing final regulatory review. This is the last step before publication in the Federal Register. Based on what we know, CMMC should be a reality before the end of 2024. Episode Links: Proposed Rule Webinar: https://www.summit7.us/webinars...

What the Heck is an ODP? 04.07.2024

Now that SP 800-171 revision 3 is official, organizationally defined parameters (ODPs) are officially a part of our the rest of our lives. Like most things in SP 800-171 there are great details in SP 800-53 that help explain what's going on. In this episode we take a deep dive in requirement 3.1.8 through the lens of ODPs. Episode Links: SP 800-53: https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/fina...

What is an “NFO Control”? 27.06.2024

The good news about NIST SP 800-171 revision 2 being the standard for the next few years is it's a smaller standard compared to revision 3. However, there are some confusing aspects to NIST SP 800-171 revision 2 that defense contractors can't afford to overlook. The most important? NFO Controls. Episode Links: NIST SP 800-171r2: https://csrc.nist.gov/pubs/sp/800/171/r3/final DFARS 7012 Class Devia...

New NIST Training Courses 20.06.2024

NIST has released four introductory training courses for the 800 series of special publications that make up the basis for the NIST Risk Management Framework. Each 60 minute course does a great job covering SP 800-37, 53, 53A, and 53B. If you need a leg up on the knowledge that forms the basis of CMMC training, you should check out the courses. NIST Training Courses: NIST CPRT: https://csrc.nist.g...

The Rise of CMMC False Starts 13.06.2024

Although CMMC assessments are difficult, CMMC certifications are achievable (assuming you have passed through the “assessment feasibility determination” prior to the actual assessment. For many companies, failing CMMC assessments won't be their biggest problem – it will be qualifying for the assessment in the first place. Episode Links: CMMC Cap (PDF): https://cyberab.org/Portals...

Fun with NIST Policy Controls 06.06.2024

This week we dive into the details of NIST policy and procedure controls. Love it or hate it, SP 800-171 requires policies and procedures regardless of revision. Luckily, it's easy to know what a good template looks like because policies have been outlined in NIST SP 800-53 for 20 years. Episode Links: NIST SP 800-53: https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final NIST SP 800-53A: https://csrc...

FAR CUI Rule Update (May 2024) 30.05.2024

The FAR CUI proposed rule has officially moved into regulatory review with the Office of Information and Regulatory Affairs (OIRA). With the FAR CUI rule one step away from publication in the Federal Register, we dive a little deeper into what it is and some open questions we're looking forward to resolving when the rule, after nearly 10 years, is finally released. Episode Links: FAR CUI Rule Epis...

Understanding 171r3 w/ Dr. Ron Ross 23.05.2024

After more than a year of development, revision 3 of SP 800-171 and 171A are officially done. This week we're joined by Dr. Ron Ross to discuss what NIST learned from public comments, why NIST decided to add 19 new requirements, the thought process behind “ORC” controls, and what the future holds for the CUI series, rulemaking, and the SP 800-53 catalog. Episode Links: 171r3 overview:...

EMERGENCY POD: CMMC Regulatory Review Update 17.05.2024

DoD has officially submitted the 48 CFR CMMC proposed rule for regulatory review. As a result, we can now estimate the timelines for CMMC rules. Whatever was delaying the 48 CFR rule has apparently been fixed and that means contractors need to start getting serious about preparing for the coming CMMC roll-outs. Episode links: 48 CFR CMMC: https://www.reginfo.gov/public/do/eAgendaViewRule?pubId=202...

7 Things to Know About SP 800-171 revision 3 16.05.2024

NIST SP 800-171 revision 3 and SP 800-171A revision have been officially released. Although revision 3 won't be required for defense contractors for some time, it pays to see exactly what the future holds. On the surface revision 3 has fewer requirements than revision 2. However, under the hood of 171Ar3 there is actually a 32% increase in the number of verification questions that need to be answe...

Crisis Averted: DFARS 7012 Class Deviation 09.05.2024

The obligation for defense contractors to implement NIST SP 800-171 revision 3 has been delayed indefinitely thanks to a recent “class deviation” published by the DoD. The 2023 CMMC proposed rule specified that it will assess SP 800-171 revision 2, but language in defense contracts would have triggered a crisis – until now. Nevertheless, SP 800-171 revision 3 will be the requirem...

CIRCIA Reports Require How Much Info?! 02.05.2024

Register for our upcoming CS2 Replay here: https://www.summit7.us/webinars/exploring-the-real-world-security-value-of-cmmc According to a very scientific LinkedIn poll, 61% of respondents think that DFARS clause 252.204-7012 incident reporting requirements should expand to match CIRCIA reporting requirements. While this move would make things more efficient for defense contractors, we're pretty su...

2024 Cybersecurity Rulemaking Calendar (Updated) 25.04.2024

Register for our upcoming CS2 Replay here: https://www.summit7.us/webinars/exploring-the-real-world-security-value-of-cmmc Q2 2024 is upon us so this week we are updating the rulemaking calendar based on what we know about DFARS, CMMC, the FAR, and NIST revisions. If the Summer doldrums push things into the Fall then we could be in for a relentless holiday season. Episode links: CS2 Replay: https:...

CIRCIA Rulemaking: Double Incident Reporting for the DIB 18.04.2024

Defense contractors have had cyber incident reporting obligations under DFARS clause 252.204-7012 for many years. Recently, however, CISA issued a 457-page proposed rule implementing the 2022 Cyber Incident Reporting for Critical Infrastructure Act. Unless CISA and DoD can reach an agreement, DIB contractors will have duplicative incident reporting obligations for two different agencies. Episode L...

The DIB Cybersecurity Strategy 11.04.2024

At long last the DIB Cybersecurity Strategy has officially been released and it's ... not great. One thing is clear: CMMC is a key part of the DoD's strategy and there are many DoD resources specifically designed to help contractors deal with it. Instead, the DoD is focused on coordination, communication, and threat intelligence sharing. Episode Links: DIB Cyber Strategy: https://www.defense.gov/N...

CS2 Boston Preview: MSP Edition 28.03.2024

Register for CS2 | Boston here: https://cs2.cloud/boston Even before the CMMC proposed rule looped managed service providers into CMMC certification, defense contractors needed to be aware of how long it takes their MSP to get ready to support their assessment. This week we preview a talk from CS2 Boston focusing on the rocky road for MSPs featuring Ryan Bonner and Daniel Akridge. Podcast listener...

The FAR CUI Rule Lives 21.03.2024

Register for CS2 | Boston here: https://cs2.cloud/boston After nearly two years of silence and almost a decade of waiting the FAR CUI rule is one step closer to reality. In this episode we dive into what the FAR CUI rule is and what it means for federal contractors outside of the defense industrial base. Podcast listeners use code SUMITUPBOSTON for a discount on CS2 registration!

DIB CS Program for Everyone 14.03.2024

Register for CS2 | Boston here: https://cs2.cloud/boston On March 11th, the DoD issued a final rule expanding eligibility for the DIB Cybersecurity Program to non-cleared defense contractors and their managed service providers. This week we dive into the features of the rule, how it lines up with CMMC, and why the DoD final expanded the program after 12 years. Podcast listeners use the code SUMITU...

What’s Next for 800-171r3? 07.03.2024

Register for CS2 | Boston here: https://cs2.cloud/boston NIST has released their summary of public comments received on the final drafts of SP 800-171 revision 3 and SP 800-171A revision 3. Jason and Jacob dive into when to expect the final revisions and what to expect in the revised requirements. Podcast listeners get a discount on CS2 registration, just use the code: SUMITUPBOSTON Episode Links:...

What comes after CMMC public comments? 29.02.2024

Register for CS2 | Boston here: https://cs2.cloud/boston The public comment period on the CMMC proposed rule has closed so what happens next? In this episode we wade through the red tape in store over the next 12 months. Podcast listeners use code SUMITUPBOSTON for a discount on registration Episode Links: CS2 Boston: https://cs2.cloud/boston “Midnight Rulemaking”: https://www.gao.gov/...

CS2 Boston Preview 22.02.2024

Register for CS2 | Boston here: https://cs2.cloud/boston It's almost Springtime and that means it's almost time for another CS2 conference. CS2 Boston will be the 13th event in the series and, as always, there's an all-star lineup covering every nook and cranny of DFARS, NIST, and CMMC. Podcast listeners get 20% off registration with the code SUMITUPBOSTON Episode Links: CS2 Boston: https://cs2.cl...

Listen to the Sum IT Up: CMMC News Roundup podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.