Final Rule Webinar: https://www.summit7.us/webinars/cmmc-phase-1-the-final-rule-is-here?hsCtaAttrib=195767465874
The regulation that finalizes CMMC guidance for DoD contracting officers and program managers officially goes into effect on November 10th, 2025. The highlight of the regulation is the final text of DFARS clause 252.204-7021 which tells contractors which CMMC level they need to achieve in order to take award of a contract. But the regulation also created DFARS provision 252.204-7025 which officially notifies offerors of the requirements contained in the 7021 clause and it's only three paragraphs long!
Summit 7 Live: https://www.summit7.us/S7Live
Pathfinder 101: https://www.summit7.us/pathfinder
Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo
2025 CMMC Final Rule (48 CFR): https://www.federalregister.gov/documents/2025/09/10/2025-17359/defense-federal-acquisition-regulation-supplement-assessing-contractor-implementation-of
--------
29:13
--------
29:13
CMMC: Final Rule vs Class Deviation
Register for the upcoming webinar: https://www.summit7.us/webinars/cmmc-phase-1-the-final-rule-is-here
It's official: CMMC Phase 1 begins on November 10th, 2025 when the 48 CFR CMMC final rule goes into effect. After that point all new Department of Defense/War contracts will contain some level of CMMC requirement. But just when things seem certain, people are wondering about the recent class deviation regarding DFARS clause 252.204-7021. Is the use of the CMMC clause actually suspended? Spoiler: no, not even close.
Final Rule Webinar: https://www.summit7.us/webinars/cmmc-phase-1-the-final-rule-is-here?hsCtaAttrib=195767465874
Summit 7 Live: https://www.summit7.us/S7Live
Pathfinder 101: https://www.summit7.us/pathfinder
Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo
2025 CMMC Final Rule (48 CFR): https://www.federalregister.gov/documents/2025/09/10/2025-17359/defense-federal-acquisition-regulation-supplement-assessing-contractor-implementation-of
Aug Class Deviation: https://www.acq.osd.mil/dpap/policy/policyvault/USA001756-25-DPCAP.pdf
--------
20:11
--------
20:11
Defense Contractors are Betting Their Companies on THIS Assumption About CMMC Phase 1
A lot of defense contractors are betting that the DoD will only require CMMC Level 2 self-assessments during the first 12 months of CMMC (“Phase 1”). Since December 2024 there have been three official policies outlining what can be required in Phase 1 and none of them prohibit Level 2 certification assessments. Instead, every policy we can find reinforces the idea that many companies will be required to achieve CMMC Level 2 certification in Phase 1. In this episode we walk through all 3 policies so you can decide for yourself if that's a risk you want to take with your business.
Summit 7 Live: https://www.summit7.us/S7Live
Pathfinder 101: https://www.summit7.us/pathfinder
Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo
32 CFR 170.3(e): https://www.ecfr.gov/current/title-32/part-170#p-170.3(e)
The January Memo (PDF): https://dodprocurementtoolbox.com/uploads/DOPSR_Cleared_OSD_Memo_CMMC_Implementation_Policy_d26075de0f.pdf
The July Memo (PDF): https://dodprocurementtoolbox.com/uploads/PTDO_Do_D_CIO_Memo_Resources_for_CMMC_Implemtation_dtd_20250728_25_T_2704_cleared_20250807_e53aa02e78.pdf
--------
36:43
--------
36:43
August Cyber AB Town Hall Recap
The Summer is all but over, but that's ok because the CMMC program is just getting started! On this week's episode, we cover the Cyber AB's Monthly Townhall for August and break down all the things you need to know.
Things like:
• Did assessment progress slow down?
• Are there any reported failures?
• Are people finally interpreting the 10-day post assessment rule correctly?
• Will the DoD be represented at CS5?
• What is the C3PAO Advisory Council?
And so much more... Tune in to find out!
Summit 7 Live: https://www.summit7.us/S7Live
Women of CMMC Dinner: https://cs5global.org/women-of-cmmc-dinner/
Pathfinder 101: https://www.summit7.us/pathfinder
Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo
AB Town Halls: https://cyberab.org/News-Events/Town-Halls/Details/march-town-hall
--------
33:27
--------
33:27
(Scoop) Golden Dome Contractor Cyber Requirements
Register for Secure The DIB: https://www.summit7.us/secure-the-dib-2025
Golden Dome promises to be the largest and most complex defense initiatives in American history. Countless contractors, subcontractors, and suppliers will be called on to help build the ultimate system of systems. But those suppliers are the targets of cyber espionage, disruption, and IP theft – regardless of their size. So it's no surprise that as the Golden Dome program lifts off, the DoD is out in front with some pretty intense cybersecurity requirements.
Pathfinder 101: https://www.summit7.us/pathfinder
Pathfinder Demo: https://youtu.be/JiDTCchfCa0?si=JJFplxSfvkaRVhRo
DFARS 7012: https://youtu.be/cy4e28YAkXU?si=KvezY7Vu7zXf9qYZ
It's difficult to keep up with all of the moving parts that make up the Department of Defense's Cybersecurity Maturity Model Certification Program. It's even more difficult to keep up with the relevant bits and bites that influence CMMC. This weekly podcast sums up the news and developments relevant to CMMC; DFARS and other regulations; and NIST standards such as SP 800-171, SP 800-53, the NIST Cybersecurity Framework, and others.