Épisodes

  • So Much for CMMC Level 2 Self-Assessments
    Feb 20 2025

    The DoD has released guidance to the contracting workforce that implements the 32 CFR CMMC final rule. This week we discuss the two big takeaways for defense contractors. 1) Level 2 self-assessments are unlikely for 99% of companies. 2) CMMC waivers will be even more rare.

    Register for CS2 Reston: https://cs2.cloud/reston

    Pathfinder 101: https://www.summit7.us/pathfinder

    Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

    Memo (PDF): https://dodprocurementtoolbox.com/uploads/DOPSR_Cleared_OSD_Memo_CMMC_Implementation_Policy_d26075de0f.pdf

    NARA CUI Registry: https://www.archives.gov/cui/registry/category-list DoDI 5230.24 (PDF): https://www.esd.whs.mil/portals/54/documents/dd/issuances/dodi/523024p.pdf

    Voir plus Voir moins
    22 min
  • DoD Inspector General vs CMMC
    Feb 13 2025

    This week we continue our exploration of DoD Inspector General audit of the CMMC C3PAO authorization process. The majority of the recommendations pertain to the Cyber AB, but are all of the recommendations even actionable? We think you'll be surprised at the disparity between the headlines and what the report actually says.

    Register for CS2 Reston: https://cs2.cloud/reston

    Pathfinder 101: https://www.summit7.us/pathfinder

    Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

    Part 1: https://youtu.be/RNafaUlgBGo?si=2gzHIeHv0JevFwbx

    DoD IG report: https://www.dodig.mil/reports.html/Article/4028189/audit-of-the-dods-process-for-authorizing-third-party-organizations-to-perform/

    Voir plus Voir moins
    31 min
  • CMMC’s smoking gun? (DoD IG Audit)
    Feb 6 2025

    The DoD Inspector General's report on the C3PAO authorization process is out and people haven't been shy with their takes on the findings. This week we dive into the first set of recommendations to see if there really is a smoking gun. We think you'll be surprised at the disparity between the headlines and what the report actually says.

    Register for CS2 Reston: https://cs2.cloud/reston

    Pathfinder 101: https://www.summit7.us/pathfinder

    Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

    DoD IG report: https://www.dodig.mil/reports.html/Article/4028189/audit-of-the-dods-process-for-authorizing-third-party-organizations-to-perform/

    Voir plus Voir moins
    35 min
  • What’s New with the Cyber AB?
    Jan 30 2025

    The Cyber AB is back with their monthly Town Hall meeting. This week we dive into the current status of the CMMC Program, the last checklist item before official L2 certification announcements, and more.

    Register for CS2 Reston: https://cs2.cloud/reston - Use code SUMITUPRESTON for listener discount

    Pathfinder 101: https://www.summit7.us/pathfinder

    Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

    AB Town Halls: https://cyberab.org/News-Events/Town-Halls/Details/february-town-hall

    “Freeze” Memo: https://youtu.be/L6FUBpogntM?si=0blDfn4tj3E6y_hC

    Voir plus Voir moins
    17 min
  • Is CMMC on Ice? (Freeze Memo?)
    Jan 23 2025

    Regulatory “freeze memos” have been common practice for new presidential administrations since 2001. Some people believe the most recent freeze memo spells the end of CMMC. Those people are incorrect for an assortment of reasons that we dive into this week.

    Register for CS2 Reston: https://cs2.cloud/reston

    Pathfinder 101: https://www.summit7.us/pathfinder

    Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

    The “freeze memo” (2025): https://www.whitehouse.gov/presidential-actions/2025/01/regulatory-freeze-pending-review/

    The “freeze memo” (2021) (PDF): https://www.regulationwriters.com/downloads/Klain_Freeze_Memo-012021.pdf

    The “freeze memo” (2017): https://trumpwhitehouse.archives.gov/presidential-actions/memorandum-heads-executive-departments-agencies/

    The “freeze memo” (2009) (PDF): https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/agencyinformation_memoranda_2009_pdf/m09-08.pdf

    The “freeze memo” (2001): https://www.presidency.ucsb.edu/documents/memorandum-from-andrew-card

    CMMC (32 CFR 170): https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-G/part-170

    Voir plus Voir moins
    18 min
  • What is the FAR CUI Rule?
    Jan 16 2025

    Cybersecurity requirements for protecting controlled unclassified information (CUI) aren't just for defense contractors anymore. The FAR CUI rule will affect all federal contractors handling CUI (and even those who don't). This episode introduces the main elements of the rule at a 30,000-foot level.

    Register for CS2 Reston: https://cs2.cloud/reston

    Pathfinder 101: https://www.summit7.us/pathfinder

    Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

    32 CFR CMMC Webinar: https://www.summit7.us/webinars/cmmc-32-cfr-final-rule

    2024 Predictions: https://youtu.be/YzFkJGzny20?si=H7UurOVBgKPxpH7Q

    FedRAMP memo: https://youtu.be/torWNL3U7ZY?si=_yFHuMqXpCg6hYWy

    FAR CUI Rule: https://youtu.be/-bYjDy7z7BA?si=sYytd46cIhmXIP8A

    The NARA CUI Registry: https://www.archives.gov/cui/registry/category-list

    Cost estimate of 171 (2023): https://youtu.be/DkYefZn_wNk

    How to submit effective public comments: https://youtu.be/1T_62cYiUA4

    Voir plus Voir moins
    48 min
  • CMMC Predictions for 2025
    Jan 9 2025

    It's that time of year again where we stake our reputations on predicting the future of the CMMC regulatory landscape. What does our crystal ball say about the future hold for rulemaking, FedRAMP, and the CMMC ecosystem in general?

    Register for CS2 Reston: https://cs2.cloud

    Pathfinder 101: https://www.summit7.us/pathfinder

    Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

    32 CFR CMMC Webinar: https://www.summit7.us/webinars/cmmc-32-cfr-final-rule

    2024 Predictions: https://youtu.be/YzFkJGzny20?si=H7UurOVBgKPxpH7Q

    FedRAMP memo: https://youtu.be/torWNL3U7ZY?si=_yFHuMqXpCg6hYWy

    FAR CUI Rule: https://youtu.be/-bYjDy7z7BA?si=sYytd46cIhmXIP8A

    Voir plus Voir moins
    25 min
  • Revisiting Our 2024 CMMC Predictions
    Jan 2 2025

    A year ago we made seven predictions for the CMMC landscape. We got some right, we got a few mostly right, and we got a few “wrong”.

    Register for CS2 Reston with code SUMITUPRESTON: https://cs2.cloud/reston

    Pathfinder 101: https://www.summit7.us/pathfinder

    Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo

    32 CFR CMMC Webinar: https://www.summit7.us/webinars/cmmc-32-cfr-final-rule

    2024 Predictions: https://youtu.be/YzFkJGzny20?si=H7UurOVBgKPxpH7Q

    Voir plus Voir moins
    20 min