PodcastsGovernmentSum IT Up: CMMC News Roundup

Sum IT Up: CMMC News Roundup

Summit 7
Sum IT Up: CMMC News Roundup
Latest episode

157 episodes

  • Sum IT Up: CMMC News Roundup

    Lessons Learned from 100 Level 2 Client Certifications

    2026/05/14 | 26 mins.
    It's milestone season in the CMMC world. Just six months into the Phased Rollout and there are 2.5x more Level 2 certifications than DoD expected. Meanwhile, a significant portion of those certs are Summit 7 clients. We now work with more than 100 Level 2 certified companies. Last but not least, Summit 7 was awarded the Army's NCODE contract to help bring secure and compliant enclaves to micro-sized defense contractors. Exciting times.



    Register for Summit 7 Live: https://www.summit7.us/s7live



    100 Level 2-Certified Clients: https://www.summit7.us/blog/100-cmmc-l2-certified-clients



    NCODE: https://www.summit7.us/blog/ncode-contract-award
  • Sum IT Up: CMMC News Roundup

    The Numbers Behind CMMC Assessment Capacity

    2026/05/07 | 28 mins.
    Everyone keeps saying there aren't enough CMMC assessors. The data tells a very different story.

    In this episode we break down actual assessment capacity using the current number of certified assessors, DoD's rollout estimates, and capacity growth rates across the ecosystem.

    How quickly is the ecosystem scaling toward future demand targets of 16,000 and even 25,000 assessments per year?

    Turns out the real bottleneck isn't assessor capacity at all.

    ...

    Register for Summit 7 Live: https://www.summit7.us/s7live

    GAO Report (2026): https://www.gao.gov/products/gao-26-107955



    GAO Report (2021): https://www.gao.gov/products/gao-22-104679
  • Sum IT Up: CMMC News Roundup

    April Cyber AB Town Hall Recap

    2026/04/30 | 28 mins.
    We are back at it again with another rundown of the Cyber AB's monthly town hall and there sure was a lot of valuable information distributed during the meeting. Join us for this episode of we discuss some of the key information dished out this month and weigh on any impact it may have on the CMMC Program.



    Things like:

    • Changes in ecosystem engagement?

    • Do we have enough steps are in the T3 process?

    • Has certification output increased? And so much more...Tune in to find out!

    Cyber AB TH Replay's: https://cyberab.org/News-Events/Town-Hall

    ISACA Website: https://www.isaca.org/

    T3 Inquiries (older than 6 months): https://dowcio.war.gov/CMMC/Contact/
  • Sum IT Up: CMMC News Roundup

    L3Harris Won a Big Contract, Now You Need CMMC By July

    2026/04/23 | 20 mins.
    L3Harris Missile Solutions recently sent a letter informing their suppliers that they will need to achieve CMMC Level 2 (C3PAO) Status by July, 30th 2026. Two weeks later, L3Harris announced that they had been awarded a new contract for the Army Tactical Missile System.

    Coincidence? We think not.

    Not only do subcontractors need to provide their Level 2 certification, they also need to provide their Level 2 assessment report.

    This week we talk about whether this is an anomaly or a sign of things to come.

    Register for Summit 7 Live: https://www.summit7.us/s7live



    L3Harris Letter: https://www.summit7.us/blog/l3harris-supply-chain-notice



    Primes can't waive CMMC: https://youtu.be/haVzS8j7Qz4?si=F2RICMKbCNRu-1uh



    CMMC CAP (PDF): https://cyberab.org/Portals/0/CMMC%20Assessment%20Process%20v2.0.pdf
  • Sum IT Up: CMMC News Roundup

    NIST 800-171 rev. 3 is Coming ... But Not How You Think

    2026/04/16 | 21 mins.
    NIST SP 800-171 Revision 3 has been out for two years.



    DFARS 252.204-7012 says to use the most current version.



    So why are defense contractors still using Revision 2?



    Because they're supposed to.



    In this episode, we break down the temporary rule that overrides the DFARS clause and keeps the entire ecosystem aligned on Revision 2.



    We cover:

    • What a class deviation actually is and why it matters

    • Why DoD had to pause the shift to Revision 3

    • How CMMC rulemaking controls the transition

    • And when Revision 3 will realistically start showing up in contracts



    Bottom line: contractors aren't behind. The rules haven't changed yet.

    .......

    Register for Summit 7 Live: https://www.summit7.us/s7live



    171r3: https://csrc.nist.gov/pubs/sp/800/171/r3/final



    DFARS 7012 deviation (PDF): https://www.acq.osd.mil/dpap/policy/policyvault/USA001074-24-DPC.pdf



    32 CFR 170: https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-G/part-170



    Class deviation podcast: https://youtu.be/voziZRAMvv4?si=3xHm7I_gIeQTQxLf



    Class deviation press release: https://www.war.gov/News/Releases/Release/Article/3763953/department-of-defense-issues-class-deviation-on-cybersecurity-standards-for-cov/
More Government podcasts
About Sum IT Up: CMMC News Roundup
It's difficult to keep up with all of the moving parts that make up the Department of Defense's Cybersecurity Maturity Model Certification Program. It's even more difficult to keep up with the relevant bits and bites that influence CMMC. This weekly podcast sums up the news and developments relevant to CMMC; DFARS and other regulations; and NIST standards such as SP 800-171, SP 800-53, the NIST Cybersecurity Framework, and others.
Podcast website

Listen to Sum IT Up: CMMC News Roundup, Londongrad and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features
Sum IT Up: CMMC News Roundup: Podcasts in Family