エピソード

  • Ep. 6 – Navigating FedRAMP and DoD Compliance w/ Tony Bai
    2025/12/09

    Welcome back to Mostly Compliant, the cybersecurity show for professionals with trust issues, hosted by Matt Bruggeman, Director of Federal GTM at A-LIGN.

    In this episode, Matt is joined by Tony Bai, Chief Solutions Officer at RiskPoint and a seasoned expert in federal compliance frameworks. Together, they dive deep into the complexities of FedRAMP and its intersection with the DoD provisional authorization process for cloud service providers. Tony breaks down the nuances of impact levels, the additional controls required for DoD compliance, and the challenges of navigating FedRAMP equivalency.

    The conversation also explores the relationship between FedRAMP, CMMC, and controlled unclassified information (CUI), offering practical insights for cloud service providers working with DoD agencies.

    About Mostly Compliant: Hosted by Matt Bruggeman, Director of Federal GTM at A-LIGN, Mostly Compliant is a cybersecurity podcast that brings together experts from across the federal compliance landscape to discuss CMMC, FedRAMP, and other key topics shaping the industry.

    続きを読む 一部表示
    34 分
  • Ep. 5 – Breaking Down the CMMC Assessment Process w/ Michael Brooks
    2025/11/18

    Welcome to another episode of Mostly Compliant, hosted by Matt Bruggeman, Director of Federal GTM at A-LIGN.

    In this episode, Matt sits down with Michael Brooks, Lead CMMC Assessor at A-LIGN, to break down the CMMC Assessment Process (CAP) for Level 2 certification. Together, they explore the CAP’s purpose, its four key phases, and why Phase 1 — the pre-assessment — is essential for ensuring readiness.

    The conversation dives into the importance of system security plans (SSPs), scoping, and evidence preparation, while also addressing common misconceptions about Phase 1 and how it differs from a mock audit. Michael shares expert advice on navigating the process, avoiding pitfalls, and setting your organization up for success in the formal assessment.

    Listen to this episode on your favorite platform: lnk.to/X2VoDS

    About Mostly Compliant: Hosted by Matt Bruggeman, Director of Federal GTM at A-LIGN, Mostly Compliant is a cybersecurity podcast that brings together experts from across the federal compliance landscape to discuss CMMC, FedRAMP, and other key topics shaping the industry.

    続きを読む 一部表示
    37 分
  • Ep. 4 – Avoiding CMMC compliance missteps w/ Jacob Horne
    2025/11/04

    Welcome to another episode of Mostly Compliant, hosted by Matt Bruggeman, Director of Federal GTM at A-LIGN.

    In this episode, Matt is joined by Jacob Horne, Chief Security Evangelist at Summit 7 and a leading expert in cybersecurity compliance for the Aerospace and Defense industry. Together, they explore the challenges contractors face as CMMC becomes enforceable, including the risks of last-minute preparation, misconceptions about self-assessments, and the critical role of procurement timelines. Matt and Jacob also discuss the overconfidence many organizations have in their compliance status and the importance of acting now to avoid costly missteps.

    続きを読む 一部表示
    33 分
  • Ep. 3 – Understanding the False Claims Act in CMMC compliance w/ Eric Crusius
    2025/09/30
    Welcome to another episode of Mostly Compliant, hosted by Matt Bruggeman, Director of Federal GTM at A-LIGN. In this episode, Matt tackles the often misunderstood topic of the False Claims Act (FCA) and its implications for contractors in the CMMC space. To break it all down, he’s joined by Eric Crusius, a partner at Hunton Andrews Kurth’s DC office, specializing in government contracts, cybersecurity, and privacy law. Together, they explore the nuances of the FCA, including what it is, how cases typically arise, and real-world examples. Matt and Eric also share critical insights on what defense contractors should watch for in upcoming CMMC requirements to avoid potential FCA violations. About Mostly Compliant: Hosted by Matt Bruggeman, Director of Federal GTM at A-LIGN, Mostly Compliant is a cybersecurity podcast that brings together experts from across the federal compliance landscape to discuss CMMC, FedRAMP, and other key topics shaping the industry.
    続きを読む 一部表示
    37 分
  • Ep. 2 – A contract officer's take on CMMC w/ Kevin Jans
    2025/09/16

    In this episode, Matt sits down with Kevin Jans, a former contract officer and the founder and CEO of Skyway Acquisitions, a consulting organization made up of former contract officers dedicated to bridging the gap between contractors and government buyers. Together, they dive into the role of contract officers in the CMMC ecosystem, exploring their influence on requiring CMMC clauses in contracts, the number of bids needed to award new contracts, and the significant competitive advantage organizations can gain by achieving CMMC certification early.

    続きを読む 一部表示
    31 分
  • Ep. 1 – CMMC and the Microsoft solution: an MSP’s perspective w/ David Akridge
    2025/08/18

    Welcome to the first episode of Mostly Compliant, hosted by Matt Bruggeman, Director of Federal GTM at A-LIGN.

    On today's episode, we’re joined by the Director of Sales Engagement at Summit 7, Daniel Akridge. Matt and Daniel discuss the overall strategy of CMMC Level 2 compliance, explaining the distinction between technical and non-technical requirements, how Microsoft solutions can help with technical challenges, and the critical role of outside experts in the process.

    続きを読む 一部表示
    35 分