As of November 10th, 2025, CMMC is now a condition of award for new defense contracts. “Phase 1” of the CMMC rollout will last until November 10th, 2026. This week we discuss seven predictions we have for the new normal.
Summit 7 Live: https://www.summit7.us/S7Live
Pathfinder 101: https://www.summit7.us/pathfinder
Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo
32 CFR 170.3(e): https://www.ecfr.gov/current/title-32/part-170#p-170.3(e)
DFARS 7012: https://youtu.be/cy4e28YAkXU?si=yC_wKI42JNxIHKME
Phase 1 Blog: https://www.summit7.us/blog/cmmc-begins-today
-------- Â
30:25
--------
30:25
CMMC Timeline Refresher
After four years of rulemaking here we are at the last podcast before the official start of CMMC phase 1. What better way to usher in the new normal of CMMC than a quick refresher on how and why CMMC became a thing in the first place? Nothing helps contextualize the CMMC program like remembering how resistant the DoD has been to third party verification until they were left with no other choice.
-------- Â
40:33
--------
40:33
October Cyber AB Town Hall Recap
On this week's spine-tingling episode of the show, Jason and Joy sit down unwrap the October Cyber AB Town Hall like a bag of pillowcase full of candy. With less than two weeks until the November 10th launch, this marks the final town hall before the CMMC becomes a fully operational reality. Tune in as we mix up a cauldron of all the important information you need to know to assure no tricks as you pursue your CMMC bag of treats… no costumes required!
Summit 7 Live: https://www.summit7.us/S7Live
Pathfinder 101: https://www.summit7.us/pathfinder
Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo
AB Town Halls: https://cyberab.org/News-Events/Town-Halls/Details/march-town-hall
-------- Â
25:55
--------
25:55
CMMC Requirements Are Starting To Show Up
CMMC officially goes into effect on November 10th, 2025, at which point all new DoD solicitations and contracts will include at least CMMC Level 1 status requirements. While the government shutdown might affect the pace of new contract awards, it doesn't change anything about the effective date of CMMC specifically. This week we're looking at the trickle of contract notices that are letting people know CMMC is very real and will absolutely be required (including level 2).
Pathfinder 101: https://www.summit7.us/pathfinder
Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo
NAVSEA (Level 2): https://sam.gov/workspace/contract/opp/0a92f866231546828b3fd11cf1146a8a/view
USSOCOM (Level 1): https://sam.gov/workspace/contract/opp/eb3d38dd00e845579212f724b6dedd37/view
USACE (Level 2): https://sam.gov/workspace/contract/opp/e0a817b5b7c74c319ebaa2df9cd3d637/view
-------- Â
20:24
--------
20:24
BIG changes are coming to CPARS (Cyber)
The Senate has passed their version of the FY26 NDAA and they want annual contractor performance measurements to focus exclusively on “negative performance events”. Per the Senate Armed Services Committee that includes failing to meet cyber requirements, failing to flow down requirements to subcontractors, and submission of false claims (cyber). Add this one to the growing pile of evidence that the government really, really wants contractors to take cybersecurity seriously.
Pathfinder 101: https://www.summit7.us/pathfinder
Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo
Memo: https://dodcio.defense.gov/cmmc/Resources-Documentation/
Senate NDAA: https://www.congress.gov/bill/119th-congress/senate-bill/2296/text
It's difficult to keep up with all of the moving parts that make up the Department of Defense's Cybersecurity Maturity Model Certification Program. It's even more difficult to keep up with the relevant bits and bites that influence CMMC. This weekly podcast sums up the news and developments relevant to CMMC; DFARS and other regulations; and NIST standards such as SP 800-171, SP 800-53, the NIST Cybersecurity Framework, and others.