
Hosted by Redspin
Listed under Technology, Business
A podcast to help you navigate CMMC.
75 episodes · publishes monthly · latest 2026-07-31 · ~32 min/episode
Rank
#269
Substance
74.5
/ 100
Breakdown
Scored 2026-08
Updated monthly
Across the index
#269 of 1506
Substance
Top 18%
outscores 82% of the index
Cyberspin ranks #269 on The B2B Podcast Index with a substance score of 74.5 out of 100, scored across 2 recent episodes. It scores highest on guest caliber and specificity & evidence. The panel includes experienced practitioners: Rob and Thomas from Redspin (accredited C3PAO assessors with Pentagon access and years in CMMC), Damian (consulting perspective), Felice (major client experience), and Carly Salmon from Microsoft (post-DIBCAC practitioner with actual assessment experience). However, the guest list is heavily weighted toward Redspin staff promoting their own services, limiting external expert diversity. Brett Cox (Boeing CISO) appears briefly but doesn't drive substantive discussion.
Averaged across 2 recently scored episodes, with cited evidence.
The episode provides moderate substantive content about CMMC Phase 2 pause implications, specific Pentagon meeting outcomes, and regulatory clarifications. However, significant portions consist of polling about Thomas's outfit, casual banter, and event announcements that dilute the insight-to-time ratio. Core substantive segments (Pentagon briefing, RFI guidance, Rev3 preparation) are valuable but interrupted frequently by filler.
“The CIO's office had gotten a lot of inaccurate information. And that was part of the goal of this group, was to kind of clarify to level set.”
“Continue to move forward and do the right thing and you guys should be all right.”
The episode largely rehashes established CMMC guidance ("keep implementing," "don't pause security," "submit to RFI") that has been circulated for months. The Pentagon meeting insights about Ms. Davies' preference for testing over governance-heavy documentation and her concerns about outdated frameworks offer some fresh perspective, but these are relayed observations rather than original analysis. No contrarian arguments or first-principles rethinking present.
“She thinks it's outdated. She thinks it's very governance heavy.”
“there's no such thing as a cmmc implementation. It is a DFARS implementation. CMMC is just the validation mechanism.”
The panel includes experienced practitioners: Rob and Thomas from Redspin (accredited C3PAO assessors with Pentagon access and years in CMMC), Damian (consulting perspective), Felice (major client experience), and Carly Salmon from Microsoft (post-DIBCAC practitioner with actual assessment experience). However, the guest list is heavily weighted toward Redspin staff promoting their own services, limiting external expert diversity. Brett Cox (Boeing CISO) appears briefly but doesn't drive substantive discussion.
“Ms. Davies is not really a fan of NIST 800 171. She thinks it's outdated.”
“I met with one of the contractors yesterday. They were showing us one of the contracts they just got this week and it's saturated with CMMC Level 2 information.”
The episode includes concrete details: specific Pentagon meetings (Ms. Davies, Mr. Bishop), SPRS score data (1,082 CCAs, 111 C3PAOs, 1,866 CMMC Level 2 certifications as of July 30, 2026), assessment cost ranges ($50-85k divided over 3 years), Rev3 timeline (end of year FAR CUI rule), specific NIST domain counts (14 domains, 140 objectives in Rev3). However, broader industry metrics and customer outcomes lack numerical specificity, and examples of actual implementation costs or breach statistics are absent.
“As of today, July 30, 2026, there are 1,082 CCAs and 111 C3 PIOs. One of those 111 is now an accredited C3 PIO. On top of that, we've now probably as of today surpassed 1,866 formal CMMC level 2 certifications.”
“The assessment itself, you know, at most is anywhere from 50 to 85 case. Divide that by three, because that's what you'll pay annually over the three years.”
Host Monica Pastor conducts professional moderation but asks largely softball, confirmation-seeking questions rather than provocative follow-ups. Panel members (primarily Redspin staff) are rarely challenged; disagreements are absent. The outfit polling and tangential comments about Thomas's kitten undermine substantive exchange. Questions from the submitted queue are answered competently but without genuine pushback or debate. The conversational dynamic favors consensus and advocacy over critical examination.
“So Rob, can you help us clarify what is actually paused, what remains in effect, and Damian can help us with what contractors can do next.”
“So, Rob, can you share who you met with? If we. What if and what kind of high level what we shared in that meeting and talk a little bit about our, uh, RFI response.”
2026-07-31
2026-06-25
2 periods tracked.
2 scored on substance · 61 tracked in total.
Add this badge to your site - it links back here and updates automatically as you rank.
<a href="https://index.fame.so/show/cyberspin" target="_blank" rel="noopener">
<img src="https://index.fame.so/badge/cyberspin/badge.svg" alt="Ranked #23 on The B2B Podcast Index" width="360" height="136" />
</a>Track Cyberspin's rank
Get an email whenever this show moves up or down the Index. Monthly at most, no spam.
Companies, products and tools that come up most across this show's episodes.
The themes that come up most across this show's episodes.
Podcasts that dig into the same topics.