エピソード

  • Ep. 14 – AI, FedRAMP, and the Future of Federal Compliance w/ Jacob Hill
    24 分
  • Ep. 13 – Inside the FedRAMP 20X Pilot: A Firsthand Look w/ Entratus
    2026/06/16

    Welcome back to another episode of Mostly Compliant, the cybersecurity show for professionals with trust issues, hosted by Matt Bruggeman, Director of Federal GTM at A-LIGN.

    In this episode, Matt sits down with the team from Entratus, one of the few organizations that actually participated in the FedRAMP 20X pilot program. Together, they explore what the pilot experience was really like, how 20X compares to the traditional Rev. 5 process, and where the program stands today.

    Listen to this episode on your favorite platform: https://lnk.to/X2VoDS

    About Mostly Compliant: Hosted by Matt Bruggeman, Director of Federal GTM at A-LIGN, Mostly Compliant is a cybersecurity podcast that brings together experts from across the federal compliance landscape to discuss CMMC, FedRAMP, and other key topics shaping the industry.

    続きを読む 一部表示
    27 分
  • Ep. 12 – The Evolution of FedRAMP: Exploring 20X w/ Matt Earley
    2026/05/12

    Welcome back to another episode of Mostly Compliant, the cybersecurity show for professionals with trust issues, hosted by Matt Bruggeman, Director of Federal GTM at A-LIGN.

    In this episode, Matt is joined by Matt Earley, President and Founder of 38North Security, to dive into the evolution of FedRAMP and the FedRAMP 20X program. Together, they explore the shift from traditional, documentation-heavy processes to a modernized, continuous validation model. They discuss what FedRAMP 20X means for cloud service providers, the challenges of adopting this engineering-first approach, and the opportunities it presents for streamlining compliance.

    About Mostly Compliant: Hosted by Matt Bruggeman, Director of Federal GTM at A-LIGN, Mostly Compliant is a cybersecurity podcast that brings together experts from across the federal compliance landscape to discuss CMMC, FedRAMP, and other key topics shaping the industry.

    続きを読む 一部表示
    28 分
  • Ep. 11 – Demystifying FedRAMP Equivalency w/ Josh Chua and Emily Cummins
    2026/04/21

    Welcome back to another episode of Mostly Compliant, the cybersecurity show for professionals with trust issues, hosted by Matt Bruggeman, Director of Federal GTM at A-LIGN.

    In this episode, Matt dives into the niche topic of FedRAMP equivalency with Josh, Co-Founder of NextStage, and Emily, their Chief Information Security Officer. Together, they unravel the confusion surrounding when and why FedRAMP equivalency is needed, how it ties to CMMC, and the differences between FedRAMP authorization and equivalency assessments. Josh also shares his personal journey navigating these requirements and the steps NextStage took to achieve compliance.

    About Mostly Compliant:

    Hosted by Matt Bruggeman, Director of Federal GTM at A-LIGN, Mostly Compliant is a cybersecurity podcast that brings together experts from across the federal compliance landscape to discuss CMMC, FedRAMP, and other key topics shaping the industry.

    続きを読む 一部表示
    23 分
  • Ep. 10 – Inside the Role of the Affirming Official w/ Michael Brooks
    2026/03/24

    Welcome back to another episode of Mostly Compliant, the cybersecurity show for professionals with trust issues, hosted by Matt Bruggeman, Director of Federal GTM at A-LIGN.

    In this episode, Matt is joined by Michael Brooks, Lead CMMC Assessor at A-LIGN. Together, they explore the role of the affirming official in years two and three following CMMC certification. They discuss who the affirming official is, their responsibilities, and the risks they may encounter.

    About Mostly Compliant: Hosted by Matt Bruggeman, Director of Federal GTM at A-LIGN, Mostly Compliant is a cybersecurity podcast that brings together experts from across the federal compliance landscape to discuss CMMC, FedRAMP, and other key topics shaping the industry.

    続きを読む 一部表示
    27 分
  • Ep. 9 – Mobile Solutions & Compliance w/ Matt Stern
    2026/02/24

    Welcome back to Mostly Compliant, the cybersecurity show for professionals with trust issues, hosted by Matt Bruggeman, Director of Federal GTM at A-LIGN.

    In this episode, Matt is joined by Matt Stern from Hypori to explore the intersection of mobile solutions and compliance, particularly in the context of CMMC. Together, they dive into the growing necessity of secure mobile solutions in today’s work environment and the risks posed by shadow IT.

    About Mostly Compliant: Hosted by Matt Bruggeman, Director of Federal GTM at A-LIGN, Mostly Compliant is a cybersecurity podcast that brings together experts from across the federal compliance landscape to discuss CMMC, FedRAMP, and other key topics shaping the industry.

    続きを読む 一部表示
    32 分
  • Ep. 8 – The Competitive Edge of CMMC Level 2 w/ Bo Birdwell
    2026/02/03

    Description:

    Welcome back to Mostly Compliant, the cybersecurity show for professionals with trust issues, hosted by Matt Bruggeman, Director of Federal GTM at A-LIGN.

    In this episode, Matt sits down with Bo Birdwell, a lead CCA and a key player at Elbit, a major prime contractor in the DoD supply chain. Bo brings a unique perspective to the table, sharing insights not only from his own experience navigating compliance but also from Elbit's efforts to encourage their suppliers to take CMMC seriously.

    The conversation delves into the differences between DIBCAC assessments and CMMC Level 2 assessments, while emphasizing the urgency and massive competitive advantage of achieving Level 2 certification in the next 12 to 18 months.

    About Mostly Compliant: Hosted by Matt Bruggeman, Director of Federal GTM at A-LIGN, Mostly Compliant is a cybersecurity podcast that brings together experts from across the federal compliance landscape to discuss CMMC, FedRAMP, and other key topics shaping the industry.

    続きを読む 一部表示
    30 分
  • Ep. 7 – The SSP: An Autobiography of Your System w/ Kenny Scott
    2026/01/14

    Welcome back to Mostly Compliant, the cybersecurity show for professionals with trust issues, hosted by Matt Bruggeman, Director of Federal GTM at A-LIGN.

    In this episode, Matt is joined by Kenny Scott, the Founder and CEO of Paramify, to discuss the past, present, and future of the System Security Plan (SSP). The conversation explores the core purpose of an SSP and why it's more than just a document — it's the autobiography of your system.

    Kenny offers practical advice for organizations navigating the requirements of FedRAMP and CMMC, highlighting the power of automation in reducing complexity and ensuring accuracy, with an insiders look into the FedRAMP 20X process.

    About Mostly Compliant: Hosted by Matt Bruggeman, Director of Federal GTM at A-LIGN, Mostly Compliant is a cybersecurity podcast that brings together experts from across the federal compliance landscape to discuss CMMC, FedRAMP, and other key topics shaping the industry.

    続きを読む 一部表示
    31 分