Sum IT Up: CMMC News Roundup

CMMC Level 2 Assessment: What to Expect (Insights from 100 assessments)

32 min · 9. april 202632 min
episode CMMC Level 2 Assessment: What to Expect (Insights from 100 assessments) cover

Beskrivelse

This week we sit down with a C3PAO who has completed over 100 CMMC Level 2 assessments. We chat cost, timeframe, assessor backlogs and the most common issues facing defense contractors. Register for Summit 7 Live: https://www.summit7.us/s7live GAO Report (2026): https://www.gao.gov/products/gao-26-107955 GAO Report (2021): https://www.gao.gov/products/gao-22-104679

Kommentarer

0

Vær den første til å kommentere

Registrer deg nå og bli medlem av Sum IT Up: CMMC News Roundup sitt community!

Prøv gratis

Prøv gratis i 14 dager

99 kr / Måned etter prøveperioden. · Avslutt når som helst.

  • Eksklusive podkaster
  • 20 timer lydbøker i måneden
  • Gratis podkaster
Prøv gratis

Alle episoder

154 Episoder

episode L3Harris Won a Big Contract, Now You Need CMMC By July cover

L3Harris Won a Big Contract, Now You Need CMMC By July

L3Harris Missile Solutions recently sent a letter informing their suppliers that they will need to achieve CMMC Level 2 (C3PAO) Status by July, 30th 2026. Two weeks later, L3Harris announced that they had been awarded a new contract for the Army Tactical Missile System. Coincidence? We think not. Not only do subcontractors need to provide their Level 2 certification, they also need to provide their Level 2 assessment report. This week we talk about whether this is an anomaly or a sign of things to come. Register for Summit 7 Live: https://www.summit7.us/s7live [https://www.summit7.us/s7live] L3Harris Letter: https://www.summit7.us/blog/l3harris-supply-chain-notice Primes can't waive CMMC: https://youtu.be/haVzS8j7Qz4?si=F2RICMKbCNRu-1uh CMMC CAP (PDF): https://cyberab.org/Portals/0/CMMC%20Assessment%20Process%20v2.0.pdf

23. april 202620 min
episode NIST 800-171 rev. 3 is Coming ... But Not How You Think cover

NIST 800-171 rev. 3 is Coming ... But Not How You Think

NIST SP 800-171 Revision 3 has been out for two years. DFARS 252.204-7012 says to use the most current version. So why are defense contractors still using Revision 2? Because they're supposed to. In this episode, we break down the temporary rule that overrides the DFARS clause and keeps the entire ecosystem aligned on Revision 2. We cover: • What a class deviation actually is and why it matters • Why DoD had to pause the shift to Revision 3 • How CMMC rulemaking controls the transition • And when Revision 3 will realistically start showing up in contracts Bottom line: contractors aren't behind. The rules haven't changed yet. ....... Register for Summit 7 Live: https://www.summit7.us/s7live 171r3: https://csrc.nist.gov/pubs/sp/800/171/r3/final DFARS 7012 deviation (PDF): https://www.acq.osd.mil/dpap/policy/policyvault/USA001074-24-DPC.pdf 32 CFR 170: https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-G/part-170 Class deviation podcast: https://youtu.be/voziZRAMvv4?si=3xHm7I_gIeQTQxLf Class deviation press release: https://www.war.gov/News/Releases/Release/Article/3763953/department-of-defense-issues-class-deviation-on-cybersecurity-standards-for-cov/

16. april 202621 min
episode The CMMC November 2026 Deadline Is a Myth (Here’s What’s Actually Happening) cover

The CMMC November 2026 Deadline Is a Myth (Here’s What’s Actually Happening)

Everyone is talking about a “November 2026 deadline” for CMMC Level 2. There's just one problem… it's not real. In this episode, we break down what the CMMC rule actually says about Phase 2, what really happens starting in November 2026, and why most contractors are misunderstanding the rollout. If you're in the defense industrial base, this is the clarity you need to plan your timeline the right way. Key topics: • What Phase 2 actually means • When Level 2 requirements apply (and when they don't) • Why this isn't a mass certification deadline • How to think about your real CMMC timeline • Stop chasing phantom deadlines and start focusing on the contracts that matter. Register for Summit 7 Live: https://www.summit7.us/s7live PALT: https://youtu.be/C50UXJyz4PA?si=ySn1oIS4FaK4Si9f 32 CFR 170.3: https://www.ecfr.gov/current/title-32/section-170.3 Jan 2025 memo: https://dodprocurementtoolbox.com/uploads/DOPSR_Cleared_OSD_Memo_CMMC_Implementation_Policy_d26075de0f.pdf

26. mars 202624 min