Sum IT Up: CMMC News Roundup

Sum IT Up: CMMC News Roundup

Download on the App Store

Sum IT Up: CMMC News Roundup episodes

  • CIRCIA Final Rule Is Coming: What Defense Contractors Need to Know
    AUSA Supply Chain Cyber Readiness Preview: https://tinyurl.com/AUSAsupplychain
    The CIRCIA final rule has entered regulatory review, putting publication potentially just months away. For defense contractors, one major question remains unresolved: will CISA accept existing DFARS 252.204-7012 cyber incident reports, or will contractors have to report the same incident twice?
    We break down why the two 72-hour reporting requirements are far less similar than they appear, what “substantially similar” actually means, and why CIRCIA could create an entirely new reporting obligation for the defense industrial base.
    CIRCIA Proposed Rule: https://www.federalregister.gov/documents/2024/04/04/2024-06526/cyber-incident-reporting-for-critical-infrastructure-act-circia-reporting-requirements
    CIRCIA Pod 1: https://youtu.be/bvwnNSpDZgU?si=bJjZjrhzHJQxqYKH
    CIRCIA Pod 2: https://youtu.be/ngYSaO5fg5Y?si=vk-9dTSqT1HrNakq
    CIRCIA Pod 3: https://youtu.be/kUdhl5QfziU?si=kEnHdlWD8D17w0Pf
    21 min
  • Congress Changed Its CMMC Small Business Bill at the Last Minute
    Managed Service Provider (MSP) Grader: https://summit7.us/mspgrader
    Congress has introduced new legislation aimed at helping small businesses navigate CMMC, promising clearer guidance, lower costs, and better federal assistance.
    But then the CMMC provisions changed before the bill even left committee.
    We break down what the Cybersecurity for Small Businesses Act actually requires, what it doesn't give the SBA authority to do, how the amended version differs from the original, and whether it would meaningfully change anything for defense contractors struggling with CMMC.
    Press Release: https://wied.house.gov/media/press-releases/rep-wied-introduces-bill-strengthen-cybersecurity-and-reduce-costs-small
    Bill tracker: https://www.govtrack.us/congress/bills/119/hr10238
    19 min
  • DoD Said 60 Days. So Where Is the CMMC Report?
    CMMC L2 Suspended, Learn What This Means For You: https://summit7.us/blog/cmmc-phase-2-suspended-with-60-day-review-what-happens-next
    DoD said it was conducting a 60-day review of CMMC. More than 60 days later, contractors are still waiting for answers. We break down the conflicting CMMC timelines, the additional 15-day window described by DoD CIO Kirsten Davies, what the suspension actually means today, and when we might realistically see the CMMC Reform Task Force recommendations.
    July 13th memo: https://dodcio.defense.gov/Portals/0/Documents/Library/CMMC-ReformMemo.pdf
    Davies (DefenseScoop): https://defensescoop.com/2026/07/17/pentagon-task-force-to-review-cmmc-hits-the-ground-running/
    15 min
  • The Honeywell Cyber Whistleblower Tells Her Story
    Rachel Tenney was working in counterintelligence and insider risk at Honeywell when she raised cybersecurity concerns involving sensitive defense technology. Years later, her False Claims Act case ended in a $2 million settlement.
    In this episode, Rachel joins us to tell the story from her perspective: SolarWinds, raising concerns inside Honeywell, becoming a relator, the years-long government investigation, and what security practitioners, CISOs and defense contractors can learn from her experience. 
    Settlement: https://www.justice.gov/opa/pr/honeywell-aerospace-inc-agrees-pay-over-2m-settle-false-claims-act-allegations-failing 
     Solarwinds (GAO): https://www.gao.gov/products/gao-22-104746
    44 min
  • DoD Paused CMMC. Here Are 5 Cyber Rules Coming Anyway.

    Speak With Our Team: https://summit7.us/contact

    CMMC may be on hold, but cybersecurity rulemaking isn't. We break down five major requirements defense contractors need to watch, including the FAR CUI rule, CIRCIA, DFARS 252.204-7012 updates, CMMC 3.0, and post-quantum cryptography.

    FAR CUI Proposed Rule: https://www.federalregister.gov/d/2026-12559/p-116

    FAR CUI pod: https://youtu.be/l7BHnTdD9yM?si=7LQJ9LDup4LoJaCr

    CIRCIA: https://www.regulations.gov/docket/CISA-2022-0010

    CIRCIA pod: https://youtu.be/bvwnNSpDZgU?si=PvyO3JaXJJFWJFRi

    CMMC 3.0: https://www.reginfo.gov/public/do/eAgendaViewRule?pubId=202510&RIN=0790-AM01

    DFARS 7012: https://www.reginfo.gov/public/do/eAgendaViewRule?pubId=202510&RIN=0750-AM24

    PQC: https://youtu.be/6zqaXGhP7SE?si=jefs2Pbjm_sPknnV

    36 min
  • Defense Contractors Have a rev. 2 vs rev.3 Problem (again)

    Speak With Our Team: https://summit7.us/contact

    DoD already solved the problem of CMMC requiring NIST SP 800-171 Rev. 2 while other cybersecurity requirements moved to Rev. 3. Then it suspended CMMC Phase 2.

    Now the FAR CUI rule is approaching with Rev. 3, CMMC remains tied to Rev. 2, and defense contractors could once again find themselves juggling different cybersecurity baselines for the same data. We break down how DoD got here, the options for fixing it, and why CMMC reform could make the problem even more complicated.

    Crisis Averted (2024): https://youtu.be/voziZRAMvv4?si=LLlm4VUmBR-G3hno

    Phase 2 Suspension: https://www.war.gov/News/Releases/Release/Article/4542329/forging-the-arsenal-of-freedom-department-of-war-suspends-cmmc-phase-ii-require/

    Unified Agenda: https://www.reginfo.gov/public/do/eAgendaViewRule?pubId=202510&RIN=0790-AM01

    DoD CIO (Feb 2026): https://www.linkedin.com/posts/dow-cio_ot-cyber-cybersecurity-activity-7433151492745879552-b_It

    26 min
  • DoD Paused CMMC Over Costs. Get Ready to Pay More.

    Speak With Our Team: https://summit7.us/contact

    DoD suspended CMMC Phase 2 amid concerns about cost and burden on small businesses. Now it is hoping those same contractors will embrace cybersecurity practices that are broader, more complex, and potentially more expensive than their existing requirements.

    We break down DoD's remarkable explanation for its “Brilliant at the Basics” campaign, the push toward phishing-resistant MFA and broader operational technology security, and NDIA survey data showing what defense contractors already spend implementing and maintaining NIST SP 800-171 and how many lack the resources to manage those requirements.

    Will the result of the CMMC Review be a more expensive cybersecurity baseline with less assurance that it is actually being implemented?

    Register for Summit 7 Live: https://www.summit7.us/s7live

    National Defense Magazine: https://www.nationaldefensemagazine.org/articles/2026/8/25/new-cyber-campaign-contradicts-cmmc-pause-expert-says

    Brilliant at the Basics: https://dowcio.war.gov/BrilliantBasics/

    Phishing resistant MFA: https://youtu.be/7aMxKNNlOxo?si=zX7Iri6uV0uVBJLJ

    DIBCAC Top 10: https://summit7.us/blog/tools-to-take-on-nist-800-171

    2019 DoD IG Report: https://www.dodig.mil/reports.html/Article/1916036/audit-of-protection-of-dod-controlled-unclassified-information-on-contractor-ow/

    25 min
  • Are There Really Too Few CMMC Assessors?

    Speak With Our Team: https://summit7.us/contact

    Everyone says CMMC has an assessor shortage.

    The July numbers tell a different story.

    We break down the latest CMMC ecosystem data, DoD's own demand estimates, and why the real bottleneck is contractor readiness, not assessment capacity.

    Register for Summit 7 Live: https://www.summit7.us/s7live

    Cyber AB Town Hall: https://cyberab.org/News-Events/Town-Hall

    DoD Capacity Estimates: https://www.federalregister.gov/d/2024-22905/p-1240

    23 min
  • DoD Already Told Contractors What’s Coming After CMMC

    Speak With Our Team: https://summit7.us/contact

    DoD is reconsidering CMMC assessments and talking about reducing costs for defense contractors. But months before the Phase 2 suspension, the DoD CIO published a strategy saying the Defense Industrial Base will migrate to post-quantum cryptography, CMMC will be updated to include PQC requirements, and “costs will be incurred.”

    We break down why quantum computing threatens modern encryption, the federal government's 2030/2031 migration timeline, what DoD has already said about CMMC, and what the transition could eventually cost defense contractors.

    Register for Summit 7 Live: https://www.summit7.us/s7live

    DoD PQC Strategy: https://dowcio.war.gov/Portals/0/Documents/Library/DoW-PQC-Strategy.pdf

    NFO Controls: https://youtu.be/YEQd--RIUkU?si=iQpR2sZY7taAbi9k

    NIST PQC 101: https://www.nist.gov/cybersecurity-and-privacy/what-post-quantum-cryptography

    Congress (2022): https://www.congress.gov/bill/117th-congress/house-bill/7535

    PQC Report (2024): https://bidenwhitehouse.archives.gov/wp-content/uploads/2024/07/REF_PQC-Report_FINAL_Send.pdf

    PQC Executive Order: https://www.whitehouse.gov/presidential-actions/2026/06/securing-the-nation-against-advanced-cryptographic-attacks/

    28 min
  • The DoD's "Basic" Cybersecurity Isn't Basic at All

    The DoD says it's reducing cybersecurity burden on the Defense Industrial Base. At the same time, the first recommendation in the new "Brilliant at the Basics" campaign calls for phishing-resistant multi-factor authentication, a capability that goes well beyond today's NIST SP 800-171 requirements.

    In this episode we break down replay resistance vs. phishing resistance, explain why they are different security properties, and explore where phishing-resistant authentication fits into the NIST standards lifecycle. We also ask a simple question:

    If this is now considered "basic," why isn't it in the NIST control catalog yet?

    800-63: https://csrc.nist.gov/pubs/sp/800/63/b/4/final

    Brilliant at the Basics: https://dowcio.war.gov/BrilliantBasics/

    25 min

About Sum IT Up: CMMC News Roundup

From the publisher's feed

It's difficult to keep up with all of the moving parts that make up the Department of Defense's Cybersecurity Maturity Model Certification Program. It's even more difficult to keep up with the…

More shows like Sum IT Up: CMMC News Roundup

Fantasy Footballers - Fantasy Football Podcast by Fantasy Football

Fantasy Footballers - Fantasy Football Podcast

29,954 Listeners

Jocko Podcast by Jocko DEFCOR Network

Jocko Podcast

30,720 Listeners

REAL AF with Andy Frisella by Andy Frisella

REAL AF with Andy Frisella

32,768 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,011 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

191 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

My First Million by Hubspot Media

My First Million

2,645 Listeners

The Shawn Ryan Show by Shawn Ryan

The Shawn Ryan Show

46,095 Listeners

Cyberspin by Redspin

Cyberspin

2 Listeners

New Heights with Jason & Travis Kelce by Wondery

New Heights with Jason & Travis Kelce

17,805 Listeners

GRC Academy by Jacob Hill

GRC Academy

3 Listeners

Climbing Mount CMMC by Bobby Guerra

Climbing Mount CMMC

2 Listeners

CMMC Compliance Guide by CMMC Compliance Guide

CMMC Compliance Guide

0 Listeners

That CMMC Show by Summit 7

That CMMC Show

2 Listeners

CUI Hotline: Live CMMC Q&A by Summit 7

CUI Hotline: Live CMMC Q&A

0 Listeners