The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/Cyberspin
Cyberspin artwork

July 2026 CMMC Connect

Cyberspin · 2026-07-31 · 54 min

0:00--:--

Key moments - from our scoring

Substance score

60 / 100

Five dimensions, 20 points each

Insight Density12 / 20
Originality11 / 20
Guest Caliber13 / 20
Specificity & Evidence14 / 20
Conversational Craft10 / 20

Redspin's CMMC Connect episode addresses widespread confusion about the CMMC Phase 2 pause announced in July 2026. Rob presents insights from recent meetings with DoD CIO Ms. Davies and Deputy Mr. Bishop at the Pentagon, revealing that while C3PAO assessments are paused, DFARS 7012 requirements and NIST 800-171 implementation remain in effect. The DoD is gathering industry feedback on program costs, third-party validation, CUI identification, and potential changes - Ms. Davies expressed concerns that NIST 800-171 is too governance-heavy and antiquated, preferring more focus on penetration testing and operational technology resiliency. Damian and the Redspin team provide actionable guidance: contractors should maintain their SPUR scores, continue NIST 800-171 implementation, prepare for third-party validation, and submit responses to the DoD's RFI. Key discussion points include the distinction between CMMC assessment costs and NIST 800-171 implementation costs, recommended improvements like unlocking the C3PAO team structure and allowing certificate modifications for new CAGE codes, and confirmation that major contractors like Microsoft are continuing certification efforts despite the pause. The episode emphasizes that waiting creates uncertainty and that proper security implementation shouldn't stop.

Key takeaways

  • →DFARS 7012 requirements and NIST 800-171 implementation are not paused - only C3PAO assessments are paused during the 60-day review period.
  • →DoD CIO Ms. Davies views NIST 800-171 as too documentation-heavy and wants greater emphasis on penetration testing, resiliency, and operational technology validation.
  • →Contractors should continue implementing NIST 800-171, maintain accurate SPUR scores, identify CUI storage and transmission, and prepare for third-party validation regardless of final program changes.
  • →Confusion between CMMC assessment costs ($50-85K divided over three years) and NIST 800-171 implementation costs should be clarified - implementation is the expensive requirement mandated by DFARS, not CMMC.
  • →Submitting detailed feedback to the DoD RFI and participating in tiered roundtables is critical, as the Pentagon is actively seeking industry input on program improvements and framework changes.

Guests

Thomas GrahamCarly Salmon

Topics in this episode

DFARS 7012NIST 800-171Penetration testingThird-party validationCMMC Level 2Cyber ABC3PAO assessmentsDoD CIO officeSPUR scoresCUI identification

Questions this episode answers

Is CMMC paused or are the security requirements paused?

Only C3PAO assessments are paused for 60 days. DFARS 7012 requirements and NIST 800-171 implementation requirements remain in effect and contractors should continue moving forward with security implementation.

What does the DoD mean by saying NIST 800-171 is too governance-heavy?

The DoD views the 14 domains and required policies/procedures in NIST 800-171 as overly documentation-focused. They want more emphasis on penetration testing, vulnerability scanning, remediation validation, and operational technology security rather than just documentation.

Should contractors wait for the 60-day pause to end before pursuing CMMC certification?

No. The Redspin team recommends continuing forward - waiting creates uncertainty, the infrastructure is operational, and DFARS 7012 requirements won't change. Most contractors and Primes are still moving forward with assessments.

What are the typical CMMC assessment costs versus implementation costs?

CMMC assessments typically cost $50-85K total, divided by three years for the certificate period. NIST 800-171 implementation costs are significantly higher and were established during the DFARS 7012 rulemaking - these are separate requirements not tied to CMMC.

What actions should contractors take during the 60-day pause?

Maintain SPUR scores, continue NIST 800-171 implementation, identify where CUI is stored and transmitted, prepare for third-party validation, and submit feedback to the DoD RFI. Major contractors are using the pause to run backup restoration testing and security improvements.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

12 / 20

The episode provides moderate substantive content about CMMC Phase 2 pause implications, specific Pentagon meeting outcomes, and regulatory clarifications. However, significant portions consist of polling about Thomas's outfit, casual banter, and event announcements that dilute the insight-to-time ratio. Core substantive segments (Pentagon briefing, RFI guidance, Rev3 preparation) are valuable but interrupted frequently by filler.

The CIO's office had gotten a lot of inaccurate information. And that was part of the goal of this group, was to kind of clarify to level set.
Continue to move forward and do the right thing and you guys should be all right.

Originality

11 / 20

The episode largely rehashes established CMMC guidance ("keep implementing," "don't pause security," "submit to RFI") that has been circulated for months. The Pentagon meeting insights about Ms. Davies' preference for testing over governance-heavy documentation and her concerns about outdated frameworks offer some fresh perspective, but these are relayed observations rather than original analysis. No contrarian arguments or first-principles rethinking present.

She thinks it's outdated. She thinks it's very governance heavy.
there's no such thing as a cmmc implementation. It is a DFARS implementation. CMMC is just the validation mechanism.

Guest Caliber

13 / 20

The panel includes experienced practitioners: Rob and Thomas from Redspin (accredited C3PAO assessors with Pentagon access and years in CMMC), Damian (consulting perspective), Felice (major client experience), and Carly Salmon from Microsoft (post-DIBCAC practitioner with actual assessment experience). However, the guest list is heavily weighted toward Redspin staff promoting their own services, limiting external expert diversity. Brett Cox (Boeing CISO) appears briefly but doesn't drive substantive discussion.

Ms. Davies is not really a fan of NIST 800 171. She thinks it's outdated.
I met with one of the contractors yesterday. They were showing us one of the contracts they just got this week and it's saturated with CMMC Level 2 information.

Specificity & Evidence

14 / 20

The episode includes concrete details: specific Pentagon meetings (Ms. Davies, Mr. Bishop), SPRS score data (1,082 CCAs, 111 C3PAOs, 1,866 CMMC Level 2 certifications as of July 30, 2026), assessment cost ranges ($50-85k divided over 3 years), Rev3 timeline (end of year FAR CUI rule), specific NIST domain counts (14 domains, 140 objectives in Rev3). However, broader industry metrics and customer outcomes lack numerical specificity, and examples of actual implementation costs or breach statistics are absent.

As of today, July 30, 2026, there are 1,082 CCAs and 111 C3 PIOs. One of those 111 is now an accredited C3 PIO. On top of that, we've now probably as of today surpassed 1,866 formal CMMC level 2 certifications.
The assessment itself, you know, at most is anywhere from 50 to 85 case. Divide that by three, because that's what you'll pay annually over the three years.

Conversational Craft

10 / 20

Host Monica Pastor conducts professional moderation but asks largely softball, confirmation-seeking questions rather than provocative follow-ups. Panel members (primarily Redspin staff) are rarely challenged; disagreements are absent. The outfit polling and tangential comments about Thomas's kitten undermine substantive exchange. Questions from the submitted queue are answered competently but without genuine pushback or debate. The conversational dynamic favors consensus and advocacy over critical examination.

So Rob, can you help us clarify what is actually paused, what remains in effect, and Damian can help us with what contractors can do next.
So, Rob, can you share who you met with? If we. What if and what kind of high level what we shared in that meeting and talk a little bit about our, uh, RFI response.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker A49%
  • Speaker D16%
  • Speaker E10%
  • Speaker G6%
  • Speaker C5%
  • Speaker H4%
  • Speaker B4%
  • Speaker F3%
  • Speaker J2%
  • Speaker I1%

Most-used words

cmmc33program24requirements20assessment20pause19question19thomas17forward17self16assessments15folks14nist14level12moving12team12clients12

Episode notes

In this July edition of CMMC Connect, Redspin tackles the biggest news of the year: the CMMC Phase 2 pause. Rob Teague shares takeaways from his in-person meeting at the Pentagon with DoW CIO Kirsten Davies, including her real feedback on NIST 800 171 (she thinks it's too governance heavy) and what she's actually considering next. The panel walks through what's paused, what's still in effect (spoiler: DFARS 7012 and every NIST 800 171 requirement), why third party assessments still matter, and how to make your voice heard through the open RFI. Plus a Rev 3 timeline update, whether your Level 2 certificate is CUI, what to do about uncertified subs mid pause, a fresh ecosystem snapshot (1,866 Level 2 certs, 111 C3PAOs), and a guest appearance from Carly Salmon at Microsoft. Hit play to hear what's actually happening, straight from the people in the room. CMMC Connect happens on the last Thursday of every month at 1 PM ET. Register for the series and submit questions here:

Full transcript

54 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Cyberspin.

Speaker B: Topics you care about by people you trust.

Speaker A: This is Cyberspin, the podcast that helps you navigate cmmc.

Speaker C: And now for the show.

Speaker D: Well, hello, everyone, and welcome to another edition of CMMC Connect. My name is Monica Pastor, Senior Events Marketing Manager here at Redspin, and I'll be your host and your moderator for today's session. Thank you for spending part of your day with us. As everyone knows, there has been a tremendous amount of discussion over the last several weeks regarding the pause to CMMC level two contract enforcement. So we've received questions from contractors trying to understand what this means for their organizations. So today we'll share the latest updates before opening it up for discussion. So, as many of you know, 2026 sparks America's 250th anniversary, and redspin is hosting a patriotic networking event, uh, upcoming during the National Cyber Summit in Hun Fill this September. So, naturally, Dr. Graham needs an outfit that matches the occasion. So Thomas needs your help on deciding which outfit he should purchase. So please give us your feedback on what your best, uh, option is for him. Is it A, star stripes and swagger? B, macho patriot. C, Uncle Glam. Or D, General George Washing Graham. So take a moment, cast your vote, and let us know what Thomas should wear. And, uh, Thomas, before we share the results, do you have a personal favorite of these, or are you willing to trust the judge for the wrong one?

Speaker A: Yeah, well, I will tell you what. I don't want to see him.

Speaker E: Well, these. These outfits all came about because of other ideas I have being vetoed before the larger group found out about them. So this was actually four that was negotiated in advance.

Speaker F: All right, we've got 61% of audience members have voted. We'll give it 10 more seconds. And there is a tie. So it's kind of between B and C. So get your votes in, please.

Speaker D: Uh, four, three, two, one. Let's close it and share the results. So the winner was. Uncle Glam.

Speaker A: Oh, God.

Speaker D: Oh, man.

Speaker A: I will find you, folks.

Speaker D: 30% of you voted Uncle Glenn, huh?

Speaker F: And if you know Thomas Graham, he takes a dare. So we will see. Yeah, something.

Speaker D: Maybe wear a little shirt underneath.

Speaker A: Special for you, Carly. So enjoy.

Speaker D: All right, well, thanks, everybody, for the fun. Before we, uh, get into what we've all been thinking about and wanted to discuss. So over the last several weeks, the CMMC Phase 2 development has been described as everything from a pause to a rollback, creating understandable confusion about whether contractors should delay their plans. Department, uh, of War is gathering feedback, um, industry feedback on costs, third party validation, CUI identification and possible program changes, but no final decisions have been announced. So I'm going to pass the mic over to Rob for the next few slides, uh, to talk us through his most recent meeting at the Pentagon, focused on industry feedback and potential adjustments to the program. So, Rob, can you help us clarify what is actually paused, what remains in effect, and Damian can help us with what contractors can do next. So Rob, I'll turn it over to you.

Speaker A: Yeah, so you know, it's the DOD's world and we're just living in it. That's a direct quote from the Cyber ab, and we absolutely love that because it is true, it is the DoD's program DoW, whichever you prefer. And, uh, you know, we answered the call as C3PAOs, and that's why we're here. While the program is paused, that does not mean the requirements are paused. So you still have requirements that are levied by DFARS 7012 and all of that requires the NIST 800171 requirements to be complied with. So you should continue moving if you're not compliant yet on that path. All right. What most folks are holding off on is the C3PAO assessments, since that was kind of what was called out. So we're waiting to see at the end of this 60 day pause what's going to happen with that. But the bottom line is do not stop protecting the data. That is the key piece of all of this. Remember, CMMC is only a validation program. It's just to validate that the requirements are being met. And, uh, it's just a check the block for the DoD if you will. But more importantly, the C3PAO assessments provide according to the cyber AB, which we agree with, a, uh, security blanket for a lot of those Primes, you know, as a protection from Department of Justice coming after them. So in conversations with a lot of the Primes, they are continuing to move forward and they are still asking their subs to get their certificates. So let's jump to the next slide and talk about what we kind of did last week. So I was privileged to be a part of a small group that got to meet with Ms. Davies at the Dow CIO office and her deputy, Mr. Bishop. The bottom takeaway here is that Ms. Davies is not really a fan of NIST 800 171. She thinks it's outdated. She thinks it's very governance heavy, which it is. It's a roughly 70% governance, 30%. She wants to see more validation testing More resiliency from the contractors. Uh, the fact that breaches have gone up across the DIB community is setting off alarms, uh, in the Pentagon. And, you know, and the way I kind of look at that is as compliance starts to come into place with a lot of these organizations, you should expect the breach reporting to go up because now they're doing what they're supposed to do. So, uh, you know, all of that is kind of tied into there. The main, uh, thing is she was kind of leaning toward looking at a new framework. Don't know what that would look like or how long that would take, because remember, the 32 CFR rule is a regulation. So to make changes to that, it's going to cause another rulemaking process to take place. And we all know how long it took the 32 rule to get in through that process. It was almost a year or so. So it's not anything that's going to happen overnight. So we're just really interested to see what will happen at the end of this. Couple of important things for you. One, she is very, very, very interested in what we feel is wrong right now with the program and any kind of improvements we can make. So as we made a couple of those from this small team that met with her, she was taking those notes down diligently. So take the opportunity if you can get into the RFI and let your voice be heard on what you feel this program. Is it worthwhile for you? Those kinds of things. Also give her some good recommendations if the program is going to stay the way it is. What do you guys want to see improved there? I know we gave her a full list. Uh, but your, your voice matters as well. The, the other thing is, there's a lot of roundtables that are starting to go and there's going to be tiered levels when it comes to this task force that's going to be reaching out to the community. It is starting with the, the Dow themselves and internally within the Pentagon. Then it's shifting into other federal organizations such as, uh, disa, um, you know, all those types of folks. Then the third tier will be the DIB contractors themselves. So they'll hold meetings with you guys to get some insights. And then the final tier, tier four will be the C3 PAOs, the cyber AB, and most likely the CACO, which is ISACA. So all of those folks, you know, with this going on, please get your voice heard. Just like when the rules come out for public comment, if you sit on the bench and wait for things to happen. It's not going to. So you got to get your voice heard. Okay. So far, according to the deputy, I, uh, do want to point this out. He looked directly at each one of us and said, listen, this pause was not intended to stop anything that you guys are doing to include the certification assessments you're performing. So it's almost like per the words of the Cyber AB during their town hall, we're almost back to the ball voluntary certification piece here, at least until the 60 day pause has completed. But most importantly for you guys, continue to move forward. All right, let's go to the next slide and then I'll, uh, pass it off to Damian. We'll talk about some things we have been recommending to our clients over the last few weeks in all kinds of different phone calls, emails, everybody asking us for, you know, our insights. These are kind of the guidelines we provide to a lot of those folks. So, Damian.

Speaker E: Yep.

Speaker G: Uh, probably most importantly is don't take your foot off the gas. Uh, as Rob stated, DFAR 7012 is not going anywhere. The requirements to implement security requirements in NIST, uh, 800171 has not gone anywhere. The requirement to self assess using NIST 800171 Alpha has not gone anywhere. So if you're in the your journey, so to speak, keep going forward. Make sure you're maintaining an accurate and up to date SPUR score. Know where your CUI is stored, processed and transmitted. Prepare for that third party validation. We don't know what form, what changes are going to be made, but there is a lot of value from the Dow's perspective on third party verification and that, you know, kind of that independent check. And also this has been stated by numerous people, Rob even said it too. Um, that third party assessment is your best insurance that you are doing things correctly and probably most importantly, respond to

Speaker A: the RFI so that you know to jump in with you. Damien, there's some things that happened in the last few weeks during this pause that you guys should be aware of if you're not. One was they increased the amount of personnel within the Department of Justice. Hello. Knock, knock on wood, here it comes. And the other piece is they put in additional protections for whistleblowers. So just keep those in mind. Go ahead, Damian. Sorry.

Speaker G: No, that's an excellent point. Thank you. So we don't know what the final recommendation's gonna be. We just, we don't know. Um, a lot of our clients, vast majority of our clients are still continuing forward as planned. We're still doing level Two assessments, we're still consulting, things are still moving forward. You know, per the town hall, the infrastructure that supports CMMC is still in place and still operational. Uh, you know, it's still doing EMASS reports, the AB still functional, the PMO is still functional, everything is still moving forward. And ultimately waiting is going to create more uncertainty. You know, you need to implement 171. Don't stop that. And at the end of this 60 days that is not going to go away. Right? It's still DFAR 7012 is still going to be there and 171 is still

Speaker A: going to be there.

Speaker D: So we do have some questions that came in guys. Dan asked, uh, would you elaborate on what is meant by the concern that the program is compliance heavy and what is the alternative?

Speaker A: Yeah, so kind of a, uh, you know, again she didn't elaborate a lot. She was very guarded obviously, uh, you know, because they don't want to put too much out there as they're still making decisions. Some folks will take that and run with it. So she was very cautious. But what she means by the governance is the fact that there's 14 domains within NIST 800, 171 and per the NFO requirements down in appendix E of that document, you must have a policy and a procedure for all 14 domains. That's a lot, you know, why couldn't you just have a simple policy that states hey, we are such and such organization and we're following NIST 801, 171, blah blah, blah. You know, so the focus seems uh, for the program to be a lot on the documentation piece, which is, don't get me wrong, very important. For example, you know, we over here at Redspin have a fully documented process of everything that we do. That's in case Dr. Thomas Graham wins the lottery, takes off the Bora Bora. Ah, Damian knows how to fill his shoes, right? So that's why your documentation is important. But she feels the focus is too much on that when she really wants to see the focus on the testing of the environment, which NIST 800171 does test. We look at uh, the vulnerability scans, we look at your remediation timeline and then we ask you to pull up some tickets and other things to validate that you're, you're tackling those uh, vulnerabilities within the timeline you've described. So there's a lot of testing that goes on with NIST 800, 171 but where she's really driving it is penetration testing. That is not a requirement for level two, it is for level three. So she wants to see how does organizations, what is their resiliency like, what is it, how do they bounce back from these adverse uh, attempts on their networks and environments. That's what she really wants to focus on. So the other piece as you mentioned, Thomas was ot. She felt that the OT wasn't really wrapped into there as well. So that's what she means by governance.

Speaker D: Heavy and Felice, did you have anything you want to add to that?

Speaker H: Yes, the first week and when the memo originally came out, every call and I, I have a nice group and stay very busy with my redsbank clients and happy to be busy. Every single one of them said full steam ahead, no pause. Now interestingly enough, uh, one of our major international clients had a new uh, CISO level person come into our CMMC meetings and that person had never experienced the pause that all of us have gotten used to some of what I like to call the CMMC roller coaster over the last seven years. And so talking her through just what that meant from a bureaucracy standpoint and what our team, and especially with Rob and Thomas Beast such a big huge part of the leadership from the beginning with cmmc. But every one of my clients, without exception, no pause whatsoever. And they see it as a great business decision to keep going with cmmc.

Speaker C: Mhm.

Speaker A: And we have, you know, as we're reaching out, talking to a lot of our clients and mainly the Primes. One of the Primes is actually taking this 60 day pause and we're really certifying roughly 30 to 60 of their subs right now. And they've kind of paused those individuals assessments until the 60 days is complete and they know what's going on in case she makes any changes to the certification piece of it. But they fully intend for all of their subs to be certified. But during this pause he explained to me that he was having his teams run through backups. So full restore backups, testing that, testing to make sure their personnel know, uh, you know, what are the key restore things that need to come up first, all of that kind of stuff. So talk about leveraging the, the 60 day pause to an advantage for your company. That's one of the best I've seen. So continue to do the right things guys. Uh, you know, the naysayers right now and those that probably most likely have not been doing things right from the beginning, which is what ended up driving this program. They kind of ruined self assessments for all of us, including us because we provide our own self assessments as well. And that's gone now, so because of this program. So we're all in the same boat because of the folks that didn't do things right. So keep going forward and do the right thing and you guys should be all right. And we'll keep you posted as, as changes and updates come out of the the puzzle palace. We'll keep you guys informed.

Speaker F: Hey, really quick, before we go to the next slide, just to recap, going back to your meeting at the Pentagon, Rob, for folks who are listening to this replay as a podcast, can you share who you met with?

Speaker D: Sure.

Speaker F: If we. What if and what kind of high level what we shared in that meeting and talk a little bit about our, uh, RFI response.

Speaker A: Yeah, so, uh, we met with the, the Dow CIO, Ms. Davies herself. Uh, we also met with her deputy, Mr. Bishop, and various, uh, personnel from their staff. So the lead of the CMMC program, internal within the CIO office, et cetera, they were taking a lot of notes, really paying attention to what we were saying. So it's not like they brought us up there just to check a block. They were very interested to hear what we had to say. So that's why I encourage you guys to participate in the rfi. Some of the things we pointed out which have been pain points, I have seen as we've moved through all of the assessments we've completed thus far. And just listening to the DIB contractors because remember, we got to get this certification ourselves. So we also know what the pain points are. One of the biggest ones is the fact that there's a lot of confusion out there between implementation costs and the CMMC assessment cost itself. The CMMC implementation, again, there's no such thing as that. There is implementation of the NIST 800171 requirements per the DFARS 7012 rule. That is a very expensive process to secure this data properly. It is what it is. The assessment itself, you know, at most is anywhere from 50 to 85 case. Divide that by three, because that's what you'll pay annually over the three years. Go ahead, Tom. Hands, uh, up. Jump in, bro.

Speaker E: Hey, look at me. I'm being polite. This.

Speaker A: I know, I'm impressed.

Speaker E: I don't know what's wrong with me.

Speaker A: You are growing up.

Speaker E: But no, I mean, if you've been listening to Connect since the beginning, we've honestly kind of said it about each month that the majority of the cost with this is on the implementation side and all of those costs, honestly were adjudicated during DFARS 7012 rulemaking. The problem now, though, is that a lot of folks are equating implementation to a CMMC requirement. And CMMC doesn't require you to implement anything. It's that validation. But the other issue, which honestly is lost in some of the discussions and you know, being a contractor myself for over a decade, maybe I'm more jaded than most, but had almost a decade to implement them, and now you're trying to implement it within, you know, six to eight months, costs are going to be higher, you know, and that's just a bottom line from it. I know the contractor that I was working with back in 2016 started their process then, and they've been able to spread out, you know, those costs over the time period of their contract. But bottom line, honestly, it sounded like the CIO's office had gotten a lot of inaccurate information. And that was part of the goal of this group, was to kind of clarify to level set. They have asked us for some more information which we're collecting and as a group going to provide back to them. And that's information that can be verified and validated, not just speculation or assumptions.

Speaker A: Yeah, and I don't want to take too much time in this because I do want to get to everybody's questions. But the other thing we pointed out was if they are concerned about the bandwidth of the Cyber AB and the amount of assessors that are available, they need to unlock the team structure. Um, when 32 rule came out, it tied the lead CCA, two of them, and a CCA to the teams. One acts as a QA. But by locking that, they've taken all of the CCPs out of the equation and there's over 2,000 of them. If they would allow the C3 PAOs to determine what the team structure should be based off the scope of the project, then you will not have a backlog issue because we can leverage the CCPs. Second thing we brought up was the fact that for many of the DIB contractors, once they get certified, they start pulling in all these contracts. Well, then they start picking up all new acquisitions to join their company, and that's new CAGE codes. So then they reach out to us and say, hey, can we add this CAGE code to our certificate? Because they're going in the same environment, following the same processes and procedures, and the response right now is no, you have to go through a full recertification. And I don't think Ms. Davies was really tracking that because she looked at me kind of funny and then made sure she took that note down. So that is something that, uh, you know, I never bring up a problem without a suggestion. So one of the things I recommended was, you know, during the assessment, we validate everything that you guys are doing to include your processes. So if we have given you a certificate, that means how you onboard people, organizations, anything has already been vetted and you guys are doing it properly. So based off that, open up the certificate so that it's a administrative adjustment and allow the C3PAOs to go in and adjust the certificates with a, uh, no cost fee to the DIB contractors. So that was another kind of recommendation we brought up. So there was quite a few. The RFI is looking for some specific things, but don't be afraid to put anything else in there that you guys feel is important. Right. Uh, the questions that they're driving at with the RFI may not cover everything. So make sure you get your voice heard. If you see something else that's wrong with the program, put it in there and let's get it cleaned up. Let's take this opportunity and clean this program up while we can. If that's what she's doing with this pause, then let's provide her all the ammunition she needs to take that target down.

Speaker D: All right?

Speaker A: All right. And real quick, before we do go on, we do have somebody, uh, that's joining us in the audience, but is going to be on, on one of our future CMMC Connects and some podcasts with us, Carly Salmon from Microsoft. So, Carly, if you don't mind, what are you guys doing at Microsoft? What is your kind of message to the folks out there? If you want to come off mute and join us.

Speaker B: Yes, hi. Mute. Challenge. Uh, yeah, I mean, we're very much in kind of the same from like a div perspective. We're in the same boat as everybody else. But like you said, and like most of your clients are doing, we're kind of moving forward as is, I mean, I guess, quote unquote. Luckily we've already been assessed, so we're just kind of waiting to see what pans out for if any further actions need to be taken before reassessment. Uh, but between that and, I mean, there's really no input, I guess, if you will, from like a CSP perspective. But we are still, you know, operating as if this is going forward until we get more information from dow, uh, like the rest of the community. So that's kind of where they're at, uh, from our standpoint. But you Know, from the Carly Salmon prior DIBCAC days, I would say don't wait to, you know, to see what the responses are because you don't want to be, you know, it's kind of, it's been like the broken record throughout this entire process over the last, you know, almost 10 years. Like don't wait. You know, everyone knows that self attestation doesn't work and that's why the false, you know, Claims act has been occurring and that can still occur. So. And like you said, the DFARS clause is still in effect, so there are still requirements out there. So all this might change is what this phase two looks like or what the next steps look like. So keep moving forward and trying to secure. I mean you may just be getting more time to have like you said, for some of your clients, they got some more time to do the work themselves but keep moving forward because it's, the requirements are never going to go away. So it's just kind of what this next step looks like, if you will.

Speaker A: Thanks Carly, appreciate it. And yeah, Microsoft, uh, certified under the joint surveillance program first and then actually just this earlier this year finished their recertification. So they're good for the next three years but still, you know, they're sticking their to their guns and moving forward. So that's refreshing to hear. Appreciate that Carly. I'm going to pass this to Lauren because we did get some updates during the Cyber AB town hall Tuesday if you were not able to join. There has been an increase in the production of CCAs and CCPs to include the C3 PAOs.

Speaker F: So Lauren, yes, and I do want to share. Jackie, we saw your hand up. Please, um, please raise it again during the live Q and A and we'll. I want to hear what you have to say. So yep, as Rob said, a quick CMMC ecosystem update. As of today, July 30, 2026, there are 1,082 CCAs and 111 C3 PIOs. One of those 111 is now an accredited C3 PIO. On top of that, we've now probably as of today surpassed 1,866 formal CMMC level 2 certifications. So despite all of the recent headlines and discussions around the Big Pause, organizations are still moving forward, assessments are still happening and the CMMC ecosystem continues to mature. Carly, you asked a question in the chat. What are we seeing our clients do? Majority are moving forward as planned.

Speaker E: Yep.

Speaker A: Thanks Thomas.

Speaker C: Touch on that last bullet there. Thomas already covered it. But just to reiterate one more time. There is no such thing as a cmmc, um, um, implementation. It is a DFARS implementation. CMMC is just the validation mechanism. So that was stressed also in the uh, town hall.

Speaker E: Yep.

Speaker A: Thank you sir and welcome back from your conference. Jeremy. Go ahead, Monica. Sorry.

Speaker D: We've received some several great questions from registrants before today's session, so we'd like to tackle those first before we open up the floor to live Q and A. So let's get to our first question and ah, bear with me. It's a little long but we do want to read it in full for those listening to the podcast. We are a machine shop in Renfrew, Ontario, Canada. With the majority of our contracts from the aerospace and defense sectors. We have a Prevail Enclave 1 subnet only, a Windows domain and Forta Authentication 2 factor, uh, authentication on all workstations, bitlockered and FIPS enforced. All offices with a CUI workstation are locked in the evening. All ITAR cy DFARs are kept in cloud locked prevail drives. This question has to do with perimeter security. Are we required to have video surveillance? Currently, all visitors report to the main entrance and sign in and allocated a CUI restricted or CUI approved badge and escorted through the facility. Is video monitoring required and can it be done internally? As long as it does not show any cui.

Speaker E: Um, no. What, what you actually need is trained attack deer. That is the preferred solution.

Speaker A: First, I was going to say take off some of my favorite Canadian brothers, uh, what's this all about?

Speaker E: But no, in short guys, is video monitoring required? No, the requirement and the objective is just monitoring. You can do that any way that you want. It's just you have to provide evidence that you're doing it, you know, adequately and sufficiently for your scoped environment. That can be cameras, it can be security guards, it can be the attack deer. I was just joking about. I mean honestly, it can be a number of things. It's just most organizations solve this with video cameras. But also understand monitoring doesn't just mean recording from the cameras. You have to have an action associated with, you know, that surveillance.

Speaker C: Mhm.

Speaker A: The other piece is, you know, a lot of organizations are using their personnel. So you know, when you, when you sign in as a visitor, they'll give you a visitor badge. And if you're not showing that badge in some organizations when you're walking around their, their shop floors or whatever the case may be, they're stopping you and saying, hey, I don't see your badge. Do you have your badge. That is one monitoring tool as well. So numerous things to choose from here.

Speaker D: Ah, all right, thank you.

Speaker I: Just real quick, another piece of that question I did mention. As long as the cameras don't capture cui and that would be correct. If you did install cameras, make sure that you don't have PTZs that can drill down on plotters printing technical data or screens or anything like that. So yeah, you'd want to capture the common stuff but not the cui.

Speaker A: Great catch, Les. Thanks.

Speaker E: Yep.

Speaker D: Yeah, thanks team. All right, next question. Any whisperings of Rev3 going around Damian over Uh, to you?

Speaker G: Yes, short, short answer is yes. So the FAR CUI role, I believe it's out for final public comments right now, is using 171Rev3. ISACA is working on updated training for CCTS and CCAS based on Rev3 and some other initiatives that are kind of going on. So Rev3 is coming a hundred percent. The general consensus with the FAR CUI rule is uh, end of the year. Um, whether or not that happens, you know, we hard to say because it's Congress. Right? But uh, in the FAR Council, excuse me, but the general consensus is that will be released by the end of the year. So 100% Rev3 is coming. Uh, your requirements right now are Rev2, be Rev2 compliant, but start preparing for Rev3 and specifically start looking at those ODPs that the DoD released what a year and a half ago because the FAR CUI rule is utilizing those ODPs. So understand those ODPs. Understand Rev 3, start doing your gap assessments and figuring out what you need to do to be ready for Rev 3.

Speaker A: Yeah and the most important thing, as Thomas kind of dumped in the chat for you guys is revisiting Rev3 has less requirements kinda and more objectives. So a lot of the objectives that are currently in Rev 2 have been wrapped up and rolled up into other requirements. So. But the objectives have definitely expanded. I think it's at 140 versus or an additional 140 or something like that. So just take a look at it and then start preparing just in case.

Speaker H: Awesome.

Speaker D: Thanks Damian. Thanks, Rob. Next question. To what extent should OSCS consider using the GAO Fiscam framework to improve traceability for assessors? Thomas, what are your thoughts here?

Speaker E: I mean honestly the Fiscam doesn't really come into play the assessment methodologies that the assessors as well as you guys because guess what, since you're held accountable to self assessment, you have to use the same methodology that's all based around NIST 800171 Alpha. The fiscam, I mean it can help you, but the methodologies to provide the evidence not only for the assessors but also for your self assessments, that's 800171 alpha. And if you're not doing that, then you may not be doing your self assessments correctly and it could invalidate your SPRS score. Short and sweet, Lauren. How do you like that?

Speaker D: Sounds great.

Speaker I: If you don't follow that methodology, you can't have an SPRS score because you don't know what it's asking.

Speaker D: All right, next question. Is the level 2 certificate CUI? If yes, how do we verify level 2 status? Police, will you answer this one for us?

Speaker H: This is a little bit of a tricky one and it's not necessarily cui. When it's, when it is issued to an organization, it is considered proprietary information to that organization. Uh, however, it gets a little murky and I will say this, that when it gets uploaded into eMass, it could be considered CUI as it is now in possession, the government is in possession of it. I recommend having a prior NDA with any organization that you share it with. I recommend using secure file sharing platforms at all times to share that. Do not just openly share it, do not put it on your website. Protect that information. Um, and make certain that you are in control of who is actually sharing it and who is receiving it. That should remain with maybe one or two people in the C suite, for example. I would not even consider sharing hours in any way, shape or form without touching base and talking and giving it over to my bosses in Rob and Thomas and Brian here at Redspin. So protect it, it's your proprietary information. And welcome any other comments from Rob Teague, who I see thoughtfully, uh, ready to respond to that as well?

Speaker A: Yeah. So thanks Felice, and you're spot on. It is not cui, but you should safeguard it. We've already seen, as Thomas put that, an example of somebody that's already falsified a certificate and the DOJ is investigating that. So don't be the one that does that. Right. Um, but you can, when you go into SPRS and you look at your assessment, uh, score and all the information with it, there's an option to print a PDF export and that's what we do. So we print that, that PDF export and those that uh, you know, our clients are looking to do a cloud and our MSS team, uh, providing all the security coverage for them, they want to make sure that they are indeed CMMC level 2 certified. So we give them that PDF printout versus the certificate because we want to maintain control of that cert.

Speaker G: And the PDF export is also what a lot of the Primes are asking for as well.

Speaker A: Yeah, yep, absolutely.

Speaker J: Yeah.

Speaker D: So no matter how excited you are, don't post it on your Facebook.

Speaker H: Absolutely not.

Speaker B: All right, next question.

Speaker D: I did a jsva. Uh, do I have to self certify? Les, can you tell us the answer to this one?

Speaker I: So the JSVA program, do you have to self certify? So yeah, I mean, everybody's got to go in every year and self certify after your assessment is done. So yes, it's absolutely true.

Speaker H: Mhm.

Speaker A: Other thing is, you know, again with Carly, I think Jackie's here too. So Jackie, it's good to have you here joining us as well. But, uh, you know, for those that did do jsba, many of them have already gone through and started their recertification process and Microsoft is one of them. So, uh, it's really a business decision at this point on if you want to pause for that 60 days or do you want to just keep charging along? I will tell you, talking to the Primes, as mentioned earlier, they do want their folks, uh, with that certificate because they would rather spend the money on a C3PAO versus giving the money to the DOJ. So keep that in mind.

Speaker C: And if it was a jsba, odds are pretty good that there's already at least one, possibly more than one, annual self assessment that should have occurred. So, uh, for anyone, whoever it may be, who submitted this question, please go into SPRs, do your self assessment as soon as possible, get that score in there, um, and bring yourself current because that actually is the current compliance obligation is having that self assessment up to date.

Speaker F: And I thought you were going to say Jeremy, and apologies if you did that. If you had a jsba, chances are you're up for recert already after three years.

Speaker C: Mhm.

Speaker E: Yep.

Speaker C: Well, you may be up for research, but you're definitely up, um, for your annual update.

Speaker A: Well, we did notice that trend, Right. With some of the early adopters of joint surveillance. They weren't really tracking the annual requirements. So yes, you have all those annual requirements. You have to keep up with the self assessment, the risk assessment, the certification assessment. Oh, I got a visitor. All that kind of stuff. You need to make sure that you're still performing to stay compliant. Mhm.

Speaker E: Rob, has that kitten done its annual CY training yet?

Speaker A: Yes, this is Mrs. Biggleworth and she has $1 million.

Speaker D: She did it on her kitty laptop.

Speaker A: She did.

Speaker I: Not that again.

Speaker D: All right, next.

Speaker A: It's a real thing.

Speaker D: It really is.

Speaker H: Thank you.

Speaker D: Rob can share it with the group later. Um, what would need to happen to modify the CMM's program completely from.

Speaker A: Yeah, so, I mean, there's a lot of things. So first of all, it's a rule. And again, we've already talked about it would have to go back through rulemaking. But they can do some adjustments, uh, without that full process. And I think that may be what Ms. Davies is looking to leverage with her and her team. Mainly. Uh, really, Lily. Okay, mainly, you know, if they, if the decision is made to get rid of NIST 800, 171 and use a different framework, that's going to require a whole new rulemaking process. But if they're looking to make adjustments to the program, as some of the adjustments I mentioned earlier, that is a quick just adjustment to the program, submit it, and then, uh, we'll be on our way. So I think honestly that's probably what they're looking to do first. And then from there they're going to maybe look at a new requirement or a framework. So again, it's not going to happen anytime soon. Also want to point out that at the end of this 60 days, don't expect something, uh, spectacular or you know, right away some kind of voice from the Dow and the CIO office themselves. You know, that the pause is going to end on a Friday. Typically they don't announce anything on Fridays. It's usually the next Monday and even then it may still be guarded. So just be patient with the process and uh, again, get as much information to the team as you can so they can make an informed decision.

Speaker D: All right. We actually had another question came in, Rob. How does Lily spell her name?

Speaker A: L I. L, L, Y.

Speaker D: Okay. Two L's and a Y. Very cute.

Speaker A: And um, yeah.

Speaker D: All right. I believe this is our last pre submitted question. Our subs and supply chain aren't certified and now with the pause, are putting it off even more. What is their requirement? If they are not certified, does that mean I can't fulfill the contract? Jeremy, can you tell us about this one?

Speaker C: Sure. So I'm assuming this is a situation where the question was submitted by a prime. And you know, they're obviously discussing their supply chain. As a private organization, you can require whatever you wish of those within your supply chain. So, you know, we have primes who have said that they are going to continue and have messaged their supply chains that they expect vendors to be certified by end of year if they want to maintain approved vendor status within the supply chain. Other folks are allowing a bit more time, but it's really up to your organization and your vendor management, you know, structure and policies on what you want to require from your supply chain. As far as the back half of that question, if they are not certified, does that mean I can't fulfill the contract? Part of this current 60 day suspension was putting on hold the November 10th date of when certification would become a contractual requirement for award of DoD contracts. So right now there is not, you shouldn't, I don't think, have a contract that requires CMMC certification both from you and from everyone within your supply chain. Now I don't know what the new timeline is going to be on that, but there's a lot of moving parts here. We've had Some references to Rev3 and that adds, you know, another domain that is very specific to vendor management and supply chain risk and things of that sort. So many of the primes that we have as clients, we've seen getting ahead of this by simply rolling down requirements to their supplier, saying if you want to be an approved vendor with us, you need to get a third party validation of your SPRs score. And that's going to be, you know, the rules moving forward. So I am happy to have a larger conversation on this because there are a lot of moving parts, but that's essentially the gist of it.

Speaker D: Yeah.

Speaker A: So definitely the self assessment needs to be in there. I will tell you, I met with one of the contractors yesterday. They were showing us one of the contracts they just got this week and it's saturated with CMMC Level 2 information and, and the C3PAO assessment and other things. So again, news bad news spreads quickly across the Dow, good news doesn't. So just be patient with the contracting agency as they make adjustments. So again, due diligence, do what you think is right and move forward at

Speaker E: the end of the day, guys, I posted it in the chat for this session but uh, the 48 CFR DFAR 7021 rule is it holds the primes accountable for every single one of their subs and their vendors that are underneath that contract. And you know, regardless of, you know, the various talking heads on LinkedIn, you know, downplaying, can we stop talking about FCA and you know, stuff like that. The bottom line is fca, well, DOJ is going to come knock on the prime store first because it's their responsibility to insure it. So if one of those allegations comes up, it's going to be the prime as well as potentially that sub or the sub. Sub that now gets brought into the discussion. So because of that, most of the primes, they're still requiring the third party assessment because for their legal counsel, this is the only way they have some type of. Of verification that the subs or the vendors are actually adhering to the requirements.

Speaker F: Yep.

Speaker D: Um, all right, thanks, guys. All right, that wraps up the questions we received in advance. Now, we'd love to hear from all of you live. So if you have a question, you can post it in our Q and A or raise your hand and we'll call on you live. And we will answer as many questions as we can before we get to the top of the hour. Jackie, we'd love to open it back up to you if you're available to, um, come off mute.

Speaker A: If not, we can answer Nancy's question. That's a good one. Uh, was the pause driven by the CIO office or triggered by purchasing or someone else within DoD? Seems like the Iran war and Ukraine wars draining resources might be the driver. So, Nancy, you got part of it correct, so we'll give you a half a star.

Speaker I: Ding.

Speaker A: There are many things playing a factor into this. Uh, one of the biggest is midterm elections. Let's not, you know, let's address the elephant in the room. Politics is involved here, so midterm elections are playing a role. The other piece is Ms. Davies is very concerned about the small business contractors that are out there, as is most of the Dow, to be honest. So she has been listening a lot to the Small Business Administration, uh, and their, their problems with the program, et cetera, et cetera. So that is part of it. The other part of it is, yes, the Pete Hegseth himself, the Secretary of War, has stated that, you know, our war stock is depleted. We gave a lot of it off to Ukraine and others to support their efforts. And now with Iran going on, we need our own war stock, and it's not getting replenished fast enough. So, you know, one, you put one and one and two together. And when the question was asked, well, why aren't they producing fast enough? The response is, well, CMMC is slowing everybody down because they can't get scheduled to get their assessments. Again, that is not fact based. So it's a lot of misconceptions, a lot of opinions. But by us sitting with Ms. Davies, uh, we made a note of this right at the beginning of that meeting, was that we're here to bring the facts to you. So if you need facts, let us know. We'll provide anything to you to include how much the assessments cost so that you can make a better informed decision. So with that group that uh, really set that up, that was Fernando Machado, who is one of our partner C3PAOs at CyberSec Investments. We had Corin Weiss there who is with her program. She's also a phenomenal instructor. Many of our assessors have been. She was the teacher. And then we had Michael Dempsey, who is also the owner of Sisiv, another C3PAO. And then, and to shake things up we brought in Brett Cox who is the CISO at Boeing. So an interesting point that uh, uh, Brett brought up that I want to bring to everybody's attention and then let's open it up and see what you guys think. Brett made the comment to Ms. Davies that you know, for a long time he had been supplying his self assessment scores every year just like he was supposed to. It wasn't until he sat on a CMMC assessment that he realized some of those requirements he interpreted wrong. So in a submitting a false assessment report to the DoD so he said the great thing about the CMMC assessments themselves is that we learn what really is required out of NIST 800171 is all of those assessors have gone through the formal training. It's not like we're just out here, you know, willy nilly picking stuff out of the trees and throwing it at you. Uh, we go through a rigorous training to understand the program and the Dow's expectations. So, so that was very interesting and she found that interesting as well. So I guess I open it up to you guys. Uh, what are you guys doing across your organizations? If you don't mind coming off mute and sharing with us, are you continuing to move forward? Have you submitted your SPRS scores, et cetera, et cetera. Come on in and let's have some combos.

Speaker E: Well, there's been quite a few things that have been posted in the chat since you were explaining that Rob and Carly answered one, but, but the CMMC team posted another one talking about AI development and is that actually playing into the pulse? Honestly, and I want to make this short so we can get to Katie's question since she has her hand raised. There's nothing in the current requirements or the current objectives that prohibit AI. It's actually already baked in. I mean if you think about it, you know, in cm, um, what's it talk about? It talks about having A security baseline and, you know, other areas it talks about, you know, development or processes or any of those other things. And in fact, NIST has an AI framework that can tie directly into whatever you're doing. So there's no limitation on using AI, just like. Like, you know, there's no limitation on other stuff. It's just if it you do utilize has to meet the requirements, which could include being Fedramp authorized. But that's me being short and sweet. Katie, I see your hand up. Please ask us your question.

Speaker J: Yes. Uh, I mean, you guys were talking about what are people doing or, you know, out there in the oscs. What are we doing? I mean, we're going full steam ahead, just like you guys have mentioned earlier. Kind of tying back to my previous comment about it isn't just, um, DOD contracts, right? We've got other contracts that are basically eyeballing CMMC and going, why not? Right? If it's. If it's important to them, it's important to us. We've heard, you know, we've run across a gambit of the different agencies. And so we're just going a, uh, full speed ahead. Everybody's getting it. And that way, if we have another bpa, if we have another contract in another area, we're already at that really nice baseline and, you know, securing our environment that if they do decide to flip and start saying, hey, we also want NIST 800 171. Guess what? We're already ahead of the curve of, you know, going after those contracts and again, keeping security in mind. Uh, why wouldn't you?

Speaker A: Yeah, no, thank you for sharing, Katie. That's. Yeah, that. That is the general theme we're hearing out there. So. Yeah. Okay, we're running out of time, folks. I know I probably opened this up so we can get some more responses, but some folks are shy, and that's okay. Thank you for voting for Thomas's outfit for ncs. I'm not happy with the outfit you picked, but, uh, I will make sure that I put my glasses on to where I won't actually see everything that Thomas will be wearing. So I'll pass this back to Lauren so that Monica so that we can close out for the day.

Speaker D: All right, thanks, guys. Um, before everyone jumps off, we'd appreciate your help with, uh, one final item. We recently updated our third annual survey to better understand how organizations across the div. Are responding to the phase two pause. So the survey, um, is shorter, it takes three minutes, and Redspin will still donate $10 to the Gary Sinise foundation for every new completed response. So I think we're adding the survey link to the chat right now and it's also linked in our resources. If you guys can take a couple of minutes to do that, we'd really appreciate hearing, uh, from the industry. So please, uh, take a look at that and fill that out. All right, we're launching a poll now before we wrap up, just to see, um, what upcoming events that you'll be at. The Redspin team will be participating in the SMB CMMC Small Business Roundtable today. It's actually upcoming in a few minutes.

Speaker F: Minutes.

Speaker D: We have linked the registration page as well on the resources tab, if you guys would like to join that. And Rob, did you have any, um, additional info for why people should join the SBA?

Speaker A: Because mainly that's what we are as C3PAOs. We're also small businesses, so took the opportunity to sign up so that we can just kind of hear from the inside what's going on, what are they looking for, and then maybe we can help address their questions and comments and concerns as well. So really just kind of sitting and, and seeing what the larger group of the small businesses are thinking about this program.

Speaker D: Yes. And then also tonight, it's not listed on this page, but, uh, Thomas is speaking at the NDIA Lone Star Chapter meeting tonight in Dallas, I believe, at smu. We have the link on our upcoming events in the resources that you can get registered for that if you're local and able to attend. And then upcoming, uh, in August 11th through the 13th, we'll be at the NDIA Space and Missile Defense Symposium. Greg, uh, Powers will be there walking the show floor. Then we'll be at Navy Gold coast in San Diego at booth 1003. We'd love to meet with you there if you're going to be there. Um, we'll also be speaking and attending the CMMC In Practice Forum, a discussion about Rev 3 with Thomas and Stephanie from our team. And lastly, we'll also be exhibiting at the National Cyber Summit same week in Huntsville, Alabama. Again, we'll be hosting our super fun patriotic networking event. So stay tuned for more information and the details to register for that. So we'd love to see you there in person. All right, on behalf of everyone here at Redspin, thank you for joining us for today's CMMC Connect. A special thank you to all of our panelists for sharing their expertise and answering everyone's questions. And if we didn't get to your question for any reason today, please don't hesitate to reach out to us directly. Our team is always happy to help connect with you and continue the conversation. So thank you again. Have a wonderful day and we hope to see you next month at our next next CMMC um Connect session next month. Take care everybody.

Speaker A: Stay safe but dangerous.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • CMMC Level 2: Documentation, Costs, and Audit Readiness | Interview with Bruno LecoqSecure & Simple · on Cyber AB89 / 100
  • Why CMMC became necessary in the first place.Trust Issues · on NIST 800-17188 / 100
  • The CMMC Reality Check: Gap Assessments, Documentation Overload & Why 30-Day Compliance Claims Are a Red FlagCMMC Compliance Guide · on NIST 800-17180 / 100
  • What Every MSP Needs to Know About CMMC (feat. Matt Travis, CEO of Cyber AB)Climbing Mount CMMC · on CMMC Level 279 / 100
  • The Evolving World of Cybersecurity Compliance, with Nathanael DickIT Matters · on NIST 800-17176 / 100
  • Closing the AI Vulnerability Remediation Gap With CobaltThe Business of Cybersecurity · on Penetration testing74 / 100

More from Cyberspin

All episodes →
  • June 2026 CMMC Connect69 / 100
  • May 2026 CMMC Connect
  • April 2026 CMMC Connect
  • March 2026 CMMC Connect
  • February 2026 CMMC Connect
Explore the best B2B Ops podcasts →
All Cyberspin episodes →