169 episodes
- The DoD says it's reducing cybersecurity burden on the Defense Industrial Base. At the same time, the first recommendation in the new "Brilliant at the Basics" campaign calls for phishing-resistant multi-factor authentication, a capability that goes well beyond today's NIST SP 800-171 requirements.
In this episode we break down replay resistance vs. phishing resistance, explain why they are different security properties, and explore where phishing-resistant authentication fits into the NIST standards lifecycle. We also ask a simple question:
If this is now considered "basic," why isn't it in the NIST control catalog yet?
800-63: https://csrc.nist.gov/pubs/sp/800/63/b/4/final
Brilliant at the Basics: https://dowcio.war.gov/BrilliantBasics/ - The DoD's CMMC Reform Task Force wants public feedback on how to reduce cost, complexity, and compliance burdens.
There's just one problem.
Many of the questions in the new RFI focus on topics the DoD previously said were outside the scope of the CMMC program, including NIST requirements, CUI policy, DFARS, FedRAMP, and other regulations.
In this episode, we walk through each RFI question, explain what's actually part of CMMC, and discuss what realistic reform could look like under the rulemaking process.
The RFI: https://sam.gov/workspace/contract/opp/89ef9bfb0834473791e991c712698d94/view
Out of Scope comments: https://youtu.be/cqNpO2_PWiw?si=jyt5QVF_-4PqMuKP - Everyone saw the headline that CMMC Phase 2 was suspended.
Almost nobody read the part that says government-led assessments are still happening.
In this episode we look at what the DoD actually said, how DIBCAC decides who gets assessed, why the LogZone False Claims Act case matters, and why today's approach looks surprisingly similar to the original CMMC 1.0 phased rollout.
If you think the suspension means nobody is verifying cybersecurity anymore, you may want to read the Phase 2 suspension memo one more time.
Phase 2 Suspension: https://youtu.be/TfdwAc5tdMA?si=H8Dtz6Z1UbG_aYpX
LogZone FCA: https://youtu.be/T5wJYnQzWws?si=ME3p2C8Sx_jhXTGJ
DFARS 7020: https://youtu.be/D4JLkfvB-Ws?si=rG-4enAdaj0InsfY
DoD Critical Tech: https://www.cto.mil/osc/critical-technologies/
CIO Interview: https://defensescoop.com/2026/07/17/pentagon-task-force-to-review-cmmc-hits-the-ground-running/
Suspension Memo (PDF): https://dodcio.defense.gov/Portals/0/Documents/Library/CMMC-ReformMemo.pdf - Miss the CUI Hotline Telethon? Watch it on-demand: https://summit7.us/event/secure-the-dib-telethon
The DoD has suspended the November 2026 transition to Phase 2 of CMMC implementation, but that doesn't mean cybersecurity requirements have been relaxed.
In this episode, we explain what actually changed, what didn't, why Level 2 self-assessments now matter more than ever, and how contractors could expose themselves to significant False Claims Act liability if they misunderstand the news.
We also discuss the 60-day CMMC program review, the DoD's Request for Information, and what defense contractors should focus on moving forward.
Phase 2 Announcement: https://www.war.gov/News/Releases/Release/Article/4542329/forging-the-arsenal-of-freedom-department-of-war-suspends-cmmc-phase-ii-require/
Phase 2 Blog: https://summit7.us/blog/cmmc-phase-2-suspended-with-60-day-review-what-happens-next
32 CFR 170.16: https://www.ecfr.gov/current/title-32/section-170.16
32 CFR 170.22: https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-G/part-170/subpart-D/section-170.22
False Claims Act: https://youtu.be/T5wJYnQzWws?si=pn8iwA7_8Ys_wvdq - Register for Secure The DIB: https://summit7.us/event/secure-the-dib-telethon
The public comment period for the proposed FAR CUI rule closes on July 23, making this your last opportunity to influence one of the biggest cybersecurity changes coming to federal contracting.
Simply supporting or opposing the rule isn't enough. In this episode, we break down the Government's own guidance for writing effective public comments and explain the seven principles that make comments persuasive.
You'll learn the common mistakes to avoid, how to build evidence-based arguments, and how to give regulators constructive recommendations they can actually use.
Whether you're planning to comment on the FAR CUI rule or want to better understand how federal rulemaking works, this episode will help you make your comment count before the deadline.
Register for Summit 7 Live: https://www.summit7.us/s7live
FAR CUI Rule: https://www.federalregister.gov/documents/2026/06/23/2026-12559/federal-acquisition-regulation-revolutionary-federal-acquisition-regulation-overhaul-parts-1-2-4-33
GSA Comment Guidance: https://www.regulations.gov/commenting-guidance
More Government podcasts
Trending Government podcasts
About Sum IT Up: CMMC News Roundup
It's difficult to keep up with all of the moving parts that make up the Department of Defense's Cybersecurity Maturity Model Certification Program. It's even more difficult to keep up with the relevant bits and bites that influence CMMC. This weekly podcast sums up the news and developments relevant to CMMC; DFARS and other regulations; and NIST standards such as SP 800-171, SP 800-53, the NIST Cybersecurity Framework, and others.
Podcast websiteListen to Sum IT Up: CMMC News Roundup, The DSR Network and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


Sum IT Up: CMMC News Roundup
Scan code,
download the app,
start listening.
download the app,
start listening.
Sum IT Up: CMMC News Roundup: Podcasts in Family

























