History tells us that countries tend to fight current wars with previously successful tactics. When they fail, countries adapt.
Today, thousands of companies are trying to comply with CMMC requirements. Just like in history books, they try to apply old tools to a new problem. That results in delays, partial information, and high cost.
Today, Feds at the Edge sits down with four Federal Systems Integrator experts who have successfully dodged the traps of old technology.
Nick Summers from ComplAi puts the problem in perspective. Old regulations and old tools were focused on compliance with a set of rules. Today, CMMC compliance is much more dynamic. Continuous monitoring is demanded, and old approaches won't work.
An example of an old tool, GDIT's John Sahlin has seen companies that operate primarily in the commercial space trying to expand into the federal marketplace. Because they may have used a GRC tool for commercial compliance, they think they can take it off the shelf and handle CMMC—a recipe for disaster.
They also stressed the importance of data inventory, the impact of new laws, and the need for integrators to leverage AI to reduce labor costs and improve efficiency.
The discussion concluded with practical advice on achieving and maintaining CMMC compliance.