177 episodes
- Managed Service Provider (MSP) Grader: https://summit7.us/mspgrader
Congress has introduced new legislation aimed at helping small businesses navigate CMMC, promising clearer guidance, lower costs, and better federal assistance.
But then the CMMC provisions changed before the bill even left committee.
We break down what the Cybersecurity for Small Businesses Act actually requires, what it doesn't give the SBA authority to do, how the amended version differs from the original, and whether it would meaningfully change anything for defense contractors struggling with CMMC.
Press Release: https://wied.house.gov/media/press-releases/rep-wied-introduces-bill-strengthen-cybersecurity-and-reduce-costs-small
Bill tracker: https://www.govtrack.us/congress/bills/119/hr10238 - CMMC L2 Suspended, Learn What This Means For You: https://summit7.us/blog/cmmc-phase-2-suspended-with-60-day-review-what-happens-next
DoD said it was conducting a 60-day review of CMMC. More than 60 days later, contractors are still waiting for answers. We break down the conflicting CMMC timelines, the additional 15-day window described by DoD CIO Kirsten Davies, what the suspension actually means today, and when we might realistically see the CMMC Reform Task Force recommendations.
July 13th memo: https://dodcio.defense.gov/Portals/0/Documents/Library/CMMC-ReformMemo.pdf
Davies (DefenseScoop): https://defensescoop.com/2026/07/17/pentagon-task-force-to-review-cmmc-hits-the-ground-running/ - Rachel Tenney was working in counterintelligence and insider risk at Honeywell when she raised cybersecurity concerns involving sensitive defense technology. Years later, her False Claims Act case ended in a $2 million settlement.
In this episode, Rachel joins us to tell the story from her perspective: SolarWinds, raising concerns inside Honeywell, becoming a relator, the years-long government investigation, and what security practitioners, CISOs and defense contractors can learn from her experience.
Settlement: https://www.justice.gov/opa/pr/honeywell-aerospace-inc-agrees-pay-over-2m-settle-false-claims-act-allegations-failing
Solarwinds (GAO): https://www.gao.gov/products/gao-22-104746 - Speak With Our Team: https://summit7.us/contact
CMMC may be on hold, but cybersecurity rulemaking isn't. We break down five major requirements defense contractors need to watch, including the FAR CUI rule, CIRCIA, DFARS 252.204-7012 updates, CMMC 3.0, and post-quantum cryptography.
FAR CUI Proposed Rule: https://www.federalregister.gov/d/2026-12559/p-116
FAR CUI pod: https://youtu.be/l7BHnTdD9yM?si=7LQJ9LDup4LoJaCr
CIRCIA: https://www.regulations.gov/docket/CISA-2022-0010
CIRCIA pod: https://youtu.be/bvwnNSpDZgU?si=PvyO3JaXJJFWJFRi
CMMC 3.0: https://www.reginfo.gov/public/do/eAgendaViewRule?pubId=202510&RIN=0790-AM01
DFARS 7012: https://www.reginfo.gov/public/do/eAgendaViewRule?pubId=202510&RIN=0750-AM24
PQC: https://youtu.be/6zqaXGhP7SE?si=jefs2Pbjm_sPknnV - Speak With Our Team: https://summit7.us/contact
DoD already solved the problem of CMMC requiring NIST SP 800-171 Rev. 2 while other cybersecurity requirements moved to Rev. 3. Then it suspended CMMC Phase 2.
Now the FAR CUI rule is approaching with Rev. 3, CMMC remains tied to Rev. 2, and defense contractors could once again find themselves juggling different cybersecurity baselines for the same data. We break down how DoD got here, the options for fixing it, and why CMMC reform could make the problem even more complicated.
Crisis Averted (2024): https://youtu.be/voziZRAMvv4?si=LLlm4VUmBR-G3hno
Phase 2 Suspension: https://www.war.gov/News/Releases/Release/Article/4542329/forging-the-arsenal-of-freedom-department-of-war-suspends-cmmc-phase-ii-require/
Unified Agenda: https://www.reginfo.gov/public/do/eAgendaViewRule?pubId=202510&RIN=0790-AM01
DoD CIO (Feb 2026): https://www.linkedin.com/posts/dow-cio_ot-cyber-cybersecurity-activity-7433151492745879552-b_It
More Government podcasts
Trending Government podcasts
About Sum IT Up: CMMC News Roundup
It's difficult to keep up with all of the moving parts that make up the Department of Defense's Cybersecurity Maturity Model Certification Program. It's even more difficult to keep up with the relevant bits and bites that influence CMMC. This weekly podcast sums up the news and developments relevant to CMMC; DFARS and other regulations; and NIST standards such as SP 800-171, SP 800-53, the NIST Cybersecurity Framework, and others.
Podcast websiteListen to Sum IT Up: CMMC News Roundup, The Lawfare Podcast and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


Sum IT Up: CMMC News Roundup
Scan code,
download the app,
start listening.
download the app,
start listening.
Sum IT Up: CMMC News Roundup: Podcasts in Family



















