GRC Academy

CMMC 2.0 Is FINALLY Here - What Happens Next (with Stacy Bostjanick)


Listen Later

It’s been a long and wild ride on this #cmmc ship! ⛵

In this episode, I speak with Stacy Bostjanick who is the Director of the CMMC program at DoD CIO!

Here are some highlights from the episode:

  • Expectations for the initial phase in of CMMC
  • Who determines CMMC levels for contracts?
  • How will CMMC waivers work?
  • Criteria for CMMC level 2 self-assessments and CMMC level 3
  • Early use of NIST 800-171 r3
  • And so much more!

First mentioned in 2019, CMMC 1.0 was released in 2020 under the Trump administration.

CMMC 1.0 was reviewed during the Biden administration, they released CMMC 2.0 in late 2021, and then… There was a great silence.

If you threw a small rock, you’d hit ten people who thought CMMC was going away.

All this time though, the DoD was quietly marching on.

They released the proposed CMMC program rule in December 2023 and released the final CMMC program rule in October 2024 - which is now EFFECTIVE.

After all of that, CMMC will FINALLY begin to phase into DoD solicitations and contracts by this summer.

CMMC has been a LONG time coming, and it was an honor to hear the back story and why certain decisions were made!

What were your biggest takeaways? Let me know in the comments!

Follow Stacy on LinkedIn: https://www.linkedin.com/in/stacy-bostjanick-a3b67173/

DoD CIO CMMC website: https://dodcio.defense.gov/CMMC/

-----------

Thanks to our sponsor Vanta!

Want to save time filling out security questionnaires?

Experience questionnaire automation here: https://vanta.com/grcacademy

-----------

Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!

Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s1-e43&utm_campaign=courses

#cmmc #nist #cybersecurity

...more
View all episodesView all episodes
Download on the App Store

GRC AcademyBy Jacob Hill

  • 5
  • 5
  • 5
  • 5
  • 5

5

4 ratings


More shows like GRC Academy

View all
Risky Business by Patrick Gray

Risky Business

361 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

628 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,007 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

7,865 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

171 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

187 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

74 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

129 Listeners

Cyberspin by Redspin

Cyberspin

0 Listeners

Sum IT Up: CMMC News Roundup by Summit 7

Sum IT Up: CMMC News Roundup

14 Listeners

The AI Daily Brief (Formerly The AI Breakdown): Artificial Intelligence News and Analysis by Nathaniel Whittemore

The AI Daily Brief (Formerly The AI Breakdown): Artificial Intelligence News and Analysis

456 Listeners

Climbing Mount CMMC by Bobby Guerra

Climbing Mount CMMC

2 Listeners

CMMC Proof by Derrich Phillips

CMMC Proof

0 Listeners

CMMC Compliance Guide by CMMC Compliance Guide

CMMC Compliance Guide

0 Listeners

CUI Hotline: Live CMMC Q&A by Summit 7

CUI Hotline: Live CMMC Q&A

0 Listeners