PodcastsGovernmentSum IT Up: CMMC News Roundup

Sum IT Up: CMMC News Roundup

Summit 7
Sum IT Up: CMMC News Roundup
Latest episode

145 episodes

  • Sum IT Up: CMMC News Roundup

    48% vs 9%? The DoD's CUI Numbers Don't Add Up

    2026/02/19 | 33 mins.
    The DoD Inspector General is raising concerns about CUI marking again and the numbers don't add up.



    In 2023, the IG found that 48% of reviewed CUI documents lack proper markings. Yet the DoD CUI Program website reports only 9% were unmarked that same year. So which is it?



    In this episode we break down the latest DoD IG management advisory, where the recommendations fall short, and why the CUI program and the CMMC program (although closely related) are owned by different offices that can't fix each other's problems.



    For defense contractors, this isn't academic. CMMC enforcement depends on the integrity of the CUI program. If CUI marking is inconsistent, compliance risk increases downstream.



    Summit 7 Live: https://www.summit7.us/s7live



    2026 IG Report: https://www.dodig.mil/reports.html/Article/4397146/management-advisory-dod-policy-and-training-on-dissemination-controls-for-contr/



    2023 IG Report: https://www.dodig.mil/reports.html/Article/3413433/audit-of-the-dods-implementation-and-oversight-of-the-controlled-unclassified-i/
  • Sum IT Up: CMMC News Roundup

    No CMMC, No Contract: Why You're Already Too Late for NAVAIR

    2026/02/12 | 27 mins.
    CMMC is a condition of contract award and many defense contractors are waiting until they see CMMC requirements in a solicitation to get started. But the department of defense wants the period between solicitation and award to be as short as possible. This week we crunch the numbers on 1,070 upcoming Navy contracts to see what a realistic timeline ought to look like.



    Summit 7 Live: https://www.summit7.us/s7live



    PALT Pod 2024: https://youtu.be/NZs4f5voyrg?si=S-xarOpYyiSG00Bs



    NAVAIR Forecast: https://www.navair.navy.mil/LRAE
  • Sum IT Up: CMMC News Roundup

    The End of SPRS Scores (sort of)

    2026/02/05 | 33 mins.
    The largest change to DFARS cybersecurity requirements other than CMMC took place on February 1st, 2026, and nobody knew it happened. DFARS 7019 and 7020 have been replaced by DFARS clause 252.240-7997. Basic self-assessments have been eliminated. FAR 52.204-21 has a new number. And none of this went through rulemaking. This week we're diving deep into the mysterious world of class deviations and what they mean for defense contractors moving forward.



    RFO Website: https://www.acquisition.gov/far-overhaul



    DFARS RFO Deviations: https://www.acq.osd.mil/dpap/dars/dfars_far_overhaul_class_deviations.html



    CMMC class deviation: https://youtu.be/vC4IJ2JQ5NU?si=B8I9DII4ZEbQ2dNx



    7012 class deviation: https://youtu.be/voziZRAMvv4?si=HxIkpUWnxyergEUQ
  • Sum IT Up: CMMC News Roundup

    Monthly Cyber AB Town Hall Recap (January)

    2026/01/29 | 46 mins.
    After a brief hiatus, the Cyber AB has gathered the CMMC Ecosystem to deliver its monthly update. On this week's show, we breakdown the information distributed on this month's meeting that you need to know. Things like:



    • Who is the new DoW CIO?



    • Pending shutdown and CMMC Impacts



    • Ecosystem Growth and Certification updates



    • Does this show count for CPEs?



    And so much more...Tune in to find out!



    ISACA Webinar - CMMC: Requirements, Roles, and Professional Credentials: https://store.isaca.org/s/community-event?id=a33VQ000001otC1YAI



    DAU CMMC microlearning: https://www.dau.edu/acquipedia?combine=cmmc&title=C&field_functional_area_target_id=All&field_topic_area_target_id=All



    ISACA CMMC Page: https://www.isaca.org/credentialing/cmmc
  • Sum IT Up: CMMC News Roundup

    CMMC for GSA Contractors?

    2026/01/22 | 18 mins.
    Defense contractors aren't the only ones who need to implement NIST cybersecurity requirements for CUI. The big question has always been whether other agencies would require proof of implementation via the CMMC program. The GSA just revised their process for assessing nonfederal systems handling controlled unclassified information and it's way closer to NIST's Risk Management Framework than CMMC.



    CIO-IT Security-21-112r1 (PDF): https://www.gsa.gov/system/files/Protecting-Controlled-Unclassified-Information-%28CUI%29-in-Nonfederal-Systems-and-Organizations-Process-%5BCIO-IT-Security-21-112-Rev-1%5D.pdf



    Summit 7 Live San Diego: https://www.summit7.us/s7live

More Government podcasts

About Sum IT Up: CMMC News Roundup

It's difficult to keep up with all of the moving parts that make up the Department of Defense's Cybersecurity Maturity Model Certification Program. It's even more difficult to keep up with the relevant bits and bites that influence CMMC. This weekly podcast sums up the news and developments relevant to CMMC; DFARS and other regulations; and NIST standards such as SP 800-171, SP 800-53, the NIST Cybersecurity Framework, and others.
Podcast website

Listen to Sum IT Up: CMMC News Roundup, Direct Current - An Energy.gov Podcast and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features

Sum IT Up: CMMC News Roundup: Podcasts in Family

Social
v8.7.0 | © 2007-2026 radio.de GmbH
Generated: 2/24/2026 - 4:26:19 PM