172 episodes
- Speak With Our Team: https://summit7.us/contact
DoD suspended CMMC Phase 2 amid concerns about cost and burden on small businesses. Now it is hoping those same contractors will embrace cybersecurity practices that are broader, more complex, and potentially more expensive than their existing requirements.
We break down DoD's remarkable explanation for its “Brilliant at the Basics” campaign, the push toward phishing-resistant MFA and broader operational technology security, and NDIA survey data showing what defense contractors already spend implementing and maintaining NIST SP 800-171 and how many lack the resources to manage those requirements.
Will the result of the CMMC Review be a more expensive cybersecurity baseline with less assurance that it is actually being implemented?
Register for Summit 7 Live: https://www.summit7.us/s7live
National Defense Magazine: https://www.nationaldefensemagazine.org/articles/2026/8/25/new-cyber-campaign-contradicts-cmmc-pause-expert-says
Brilliant at the Basics: https://dowcio.war.gov/BrilliantBasics/
Phishing resistant MFA: https://youtu.be/7aMxKNNlOxo?si=zX7Iri6uV0uVBJLJ
DIBCAC Top 10: https://summit7.us/blog/tools-to-take-on-nist-800-171
2019 DoD IG Report: https://www.dodig.mil/reports.html/Article/1916036/audit-of-protection-of-dod-controlled-unclassified-information-on-contractor-ow/ - Speak With Our Team: https://summit7.us/contact
Everyone says CMMC has an assessor shortage.
The July numbers tell a different story.
We break down the latest CMMC ecosystem data, DoD's own demand estimates, and why the real bottleneck is contractor readiness, not assessment capacity.
Register for Summit 7 Live: https://www.summit7.us/s7live
Cyber AB Town Hall: https://cyberab.org/News-Events/Town-Hall
DoD Capacity Estimates: https://www.federalregister.gov/d/2024-22905/p-1240 - Speak With Our Team: https://summit7.us/contact
DoD is reconsidering CMMC assessments and talking about reducing costs for defense contractors. But months before the Phase 2 suspension, the DoD CIO published a strategy saying the Defense Industrial Base will migrate to post-quantum cryptography, CMMC will be updated to include PQC requirements, and “costs will be incurred.”
We break down why quantum computing threatens modern encryption, the federal government's 2030/2031 migration timeline, what DoD has already said about CMMC, and what the transition could eventually cost defense contractors.
Register for Summit 7 Live: https://www.summit7.us/s7live
DoD PQC Strategy: https://dowcio.war.gov/Portals/0/Documents/Library/DoW-PQC-Strategy.pdf
NFO Controls: https://youtu.be/YEQd--RIUkU?si=iQpR2sZY7taAbi9k
NIST PQC 101: https://www.nist.gov/cybersecurity-and-privacy/what-post-quantum-cryptography
Congress (2022): https://www.congress.gov/bill/117th-congress/house-bill/7535
PQC Report (2024): https://bidenwhitehouse.archives.gov/wp-content/uploads/2024/07/REF_PQC-Report_FINAL_Send.pdf
PQC Executive Order: https://www.whitehouse.gov/presidential-actions/2026/06/securing-the-nation-against-advanced-cryptographic-attacks/ - The DoD says it's reducing cybersecurity burden on the Defense Industrial Base. At the same time, the first recommendation in the new "Brilliant at the Basics" campaign calls for phishing-resistant multi-factor authentication, a capability that goes well beyond today's NIST SP 800-171 requirements.
In this episode we break down replay resistance vs. phishing resistance, explain why they are different security properties, and explore where phishing-resistant authentication fits into the NIST standards lifecycle. We also ask a simple question:
If this is now considered "basic," why isn't it in the NIST control catalog yet?
800-63: https://csrc.nist.gov/pubs/sp/800/63/b/4/final
Brilliant at the Basics: https://dowcio.war.gov/BrilliantBasics/ - The DoD's CMMC Reform Task Force wants public feedback on how to reduce cost, complexity, and compliance burdens.
There's just one problem.
Many of the questions in the new RFI focus on topics the DoD previously said were outside the scope of the CMMC program, including NIST requirements, CUI policy, DFARS, FedRAMP, and other regulations.
In this episode, we walk through each RFI question, explain what's actually part of CMMC, and discuss what realistic reform could look like under the rulemaking process.
The RFI: https://sam.gov/workspace/contract/opp/89ef9bfb0834473791e991c712698d94/view
Out of Scope comments: https://youtu.be/cqNpO2_PWiw?si=jyt5QVF_-4PqMuKP
More Government podcasts
Trending Government podcasts
About Sum IT Up: CMMC News Roundup
It's difficult to keep up with all of the moving parts that make up the Department of Defense's Cybersecurity Maturity Model Certification Program. It's even more difficult to keep up with the relevant bits and bites that influence CMMC. This weekly podcast sums up the news and developments relevant to CMMC; DFARS and other regulations; and NIST standards such as SP 800-171, SP 800-53, the NIST Cybersecurity Framework, and others.
Podcast websiteListen to Sum IT Up: CMMC News Roundup, The Interview and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


Sum IT Up: CMMC News Roundup
Scan code,
download the app,
start listening.
download the app,
start listening.
Sum IT Up: CMMC News Roundup: Podcasts in Family





















