エピソード

  • Defense Contractors Have a rev. 2 vs rev.3 Problem (again)
    2026/09/03

    Speak With Our Team: https://summit7.us/contact

    DoD already solved the problem of CMMC requiring NIST SP 800-171 Rev. 2 while other cybersecurity requirements moved to Rev. 3. Then it suspended CMMC Phase 2.

    Now the FAR CUI rule is approaching with Rev. 3, CMMC remains tied to Rev. 2, and defense contractors could once again find themselves juggling different cybersecurity baselines for the same data. We break down how DoD got here, the options for fixing it, and why CMMC reform could make the problem even more complicated.

    Crisis Averted (2024): https://youtu.be/voziZRAMvv4?si=LLlm4VUmBR-G3hno

    Phase 2 Suspension: https://www.war.gov/News/Releases/Release/Article/4542329/forging-the-arsenal-of-freedom-department-of-war-suspends-cmmc-phase-ii-require/

    Unified Agenda: https://www.reginfo.gov/public/do/eAgendaViewRule?pubId=202510&RIN=0790-AM01

    DoD CIO (Feb 2026): https://www.linkedin.com/posts/dow-cio_ot-cyber-cybersecurity-activity-7433151492745879552-b_It

    続きを読む 一部表示
    26 分
  • DoD Paused CMMC Over Costs. Get Ready to Pay More.
    2026/08/27

    Speak With Our Team: https://summit7.us/contact

    DoD suspended CMMC Phase 2 amid concerns about cost and burden on small businesses. Now it is hoping those same contractors will embrace cybersecurity practices that are broader, more complex, and potentially more expensive than their existing requirements.

    We break down DoD's remarkable explanation for its “Brilliant at the Basics” campaign, the push toward phishing-resistant MFA and broader operational technology security, and NDIA survey data showing what defense contractors already spend implementing and maintaining NIST SP 800-171 and how many lack the resources to manage those requirements.

    Will the result of the CMMC Review be a more expensive cybersecurity baseline with less assurance that it is actually being implemented?

    Register for Summit 7 Live: https://www.summit7.us/s7live

    National Defense Magazine: https://www.nationaldefensemagazine.org/articles/2026/8/25/new-cyber-campaign-contradicts-cmmc-pause-expert-says

    Brilliant at the Basics: https://dowcio.war.gov/BrilliantBasics/

    Phishing resistant MFA: https://youtu.be/7aMxKNNlOxo?si=zX7Iri6uV0uVBJLJ

    DIBCAC Top 10: https://summit7.us/blog/tools-to-take-on-nist-800-171

    2019 DoD IG Report: https://www.dodig.mil/reports.html/Article/1916036/audit-of-protection-of-dod-controlled-unclassified-information-on-contractor-ow/

    続きを読む 一部表示
    25 分
  • Are There Really Too Few CMMC Assessors?
    2026/08/20

    Speak With Our Team: https://summit7.us/contact

    Everyone says CMMC has an assessor shortage.

    The July numbers tell a different story.

    We break down the latest CMMC ecosystem data, DoD's own demand estimates, and why the real bottleneck is contractor readiness, not assessment capacity.

    Register for Summit 7 Live: https://www.summit7.us/s7live

    Cyber AB Town Hall: https://cyberab.org/News-Events/Town-Hall

    DoD Capacity Estimates: https://www.federalregister.gov/d/2024-22905/p-1240

    続きを読む 一部表示
    23 分
  • DoD Already Told Contractors What’s Coming After CMMC
    2026/08/13

    Speak With Our Team: https://summit7.us/contact

    DoD is reconsidering CMMC assessments and talking about reducing costs for defense contractors. But months before the Phase 2 suspension, the DoD CIO published a strategy saying the Defense Industrial Base will migrate to post-quantum cryptography, CMMC will be updated to include PQC requirements, and “costs will be incurred.”

    We break down why quantum computing threatens modern encryption, the federal government's 2030/2031 migration timeline, what DoD has already said about CMMC, and what the transition could eventually cost defense contractors.

    Register for Summit 7 Live: https://www.summit7.us/s7live

    DoD PQC Strategy: https://dowcio.war.gov/Portals/0/Documents/Library/DoW-PQC-Strategy.pdf

    NFO Controls: https://youtu.be/YEQd--RIUkU?si=iQpR2sZY7taAbi9k

    NIST PQC 101: https://www.nist.gov/cybersecurity-and-privacy/what-post-quantum-cryptography

    Congress (2022): https://www.congress.gov/bill/117th-congress/house-bill/7535

    PQC Report (2024): https://bidenwhitehouse.archives.gov/wp-content/uploads/2024/07/REF_PQC-Report_FINAL_Send.pdf

    PQC Executive Order: https://www.whitehouse.gov/presidential-actions/2026/06/securing-the-nation-against-advanced-cryptographic-attacks/

    続きを読む 一部表示
    27 分
  • The DoD's "Basic" Cybersecurity Isn't Basic at All
    2026/08/06

    The DoD says it's reducing cybersecurity burden on the Defense Industrial Base. At the same time, the first recommendation in the new "Brilliant at the Basics" campaign calls for phishing-resistant multi-factor authentication, a capability that goes well beyond today's NIST SP 800-171 requirements.

    In this episode we break down replay resistance vs. phishing resistance, explain why they are different security properties, and explore where phishing-resistant authentication fits into the NIST standards lifecycle. We also ask a simple question:

    If this is now considered "basic," why isn't it in the NIST control catalog yet?

    800-63: https://csrc.nist.gov/pubs/sp/800/63/b/4/final

    Brilliant at the Basics: https://dowcio.war.gov/BrilliantBasics/

    続きを読む 一部表示
    25 分
  • The DoD Said This Was "Out of Scope"... Now They're Asking About It
    2026/07/30

    The DoD's CMMC Reform Task Force wants public feedback on how to reduce cost, complexity, and compliance burdens.

    There's just one problem.

    Many of the questions in the new RFI focus on topics the DoD previously said were outside the scope of the CMMC program, including NIST requirements, CUI policy, DFARS, FedRAMP, and other regulations.

    In this episode, we walk through each RFI question, explain what's actually part of CMMC, and discuss what realistic reform could look like under the rulemaking process.

    The RFI: https://sam.gov/workspace/contract/opp/89ef9bfb0834473791e991c712698d94/view

    Out of Scope comments: https://youtu.be/cqNpO2_PWiw?si=jyt5QVF_-4PqMuKP

    続きを読む 一部表示
    21 分
  • CMMC Phase 2 Is Suspended... So Why Is the DoD Still Assessing Contractors?
    2026/07/23

    Everyone saw the headline that CMMC Phase 2 was suspended.

    Almost nobody read the part that says government-led assessments are still happening.

    In this episode we look at what the DoD actually said, how DIBCAC decides who gets assessed, why the LogZone False Claims Act case matters, and why today's approach looks surprisingly similar to the original CMMC 1.0 phased rollout.

    If you think the suspension means nobody is verifying cybersecurity anymore, you may want to read the Phase 2 suspension memo one more time.

    Phase 2 Suspension: https://youtu.be/TfdwAc5tdMA?si=H8Dtz6Z1UbG_aYpX

    LogZone FCA: https://youtu.be/T5wJYnQzWws?si=ME3p2C8Sx_jhXTGJ

    DFARS 7020: https://youtu.be/D4JLkfvB-Ws?si=rG-4enAdaj0InsfY

    DoD Critical Tech: https://www.cto.mil/osc/critical-technologies/

    CIO Interview: https://defensescoop.com/2026/07/17/pentagon-task-force-to-review-cmmc-hits-the-ground-running/

    Suspension Memo (PDF): https://dodcio.defense.gov/Portals/0/Documents/Library/CMMC-ReformMemo.pdf

    続きを読む 一部表示
    17 分
  • CMMC Phase 2 Is Suspended... But Contractor Liability Just Went UP
    2026/07/16

    Miss the CUI Hotline Telethon? Watch it on-demand: https://summit7.us/event/secure-the-dib-telethon

    The DoD has suspended the November 2026 transition to Phase 2 of CMMC implementation, but that doesn't mean cybersecurity requirements have been relaxed.

    In this episode, we explain what actually changed, what didn't, why Level 2 self-assessments now matter more than ever, and how contractors could expose themselves to significant False Claims Act liability if they misunderstand the news.

    We also discuss the 60-day CMMC program review, the DoD's Request for Information, and what defense contractors should focus on moving forward.

    Phase 2 Announcement: https://www.war.gov/News/Releases/Release/Article/4542329/forging-the-arsenal-of-freedom-department-of-war-suspends-cmmc-phase-ii-require/

    Phase 2 Blog: https://summit7.us/blog/cmmc-phase-2-suspended-with-60-day-review-what-happens-next

    32 CFR 170.16: https://www.ecfr.gov/current/title-32/section-170.16

    32 CFR 170.22: https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-G/part-170/subpart-D/section-170.22

    False Claims Act: https://youtu.be/T5wJYnQzWws?si=pn8iwA7_8Ys_wvdq

    続きを読む 一部表示
    24 分