The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
#124Sum IT Up: CMMC News Roundup78.5 / 100Get badge
← The Index
Sum IT Up: CMMC News Roundup artwork
Ops▲2529 this period

Sum IT Up: CMMC News Roundup

Hosted by Summit 7

Listed under Technology, Government

It's difficult to keep up with all of the moving parts that make up the Department of Defense's Cybersecurity Maturity Model Certification Program. It's even more difficult to keep up with the relevant bits and bites that influence CMMC.

169 episodes · publishes weekly · latest 2026-08-06 · ~26 min/episode

Rank

#124

Substance

78.5

/ 100

Breakdown

Scored 2026-08
Updated monthly

Ops rank

#13 of 108

Best B2B Ops Podcasts →

Across the index

#124 of 1479

Substance

Top 8%

outscores 92% of the index

Why it scores where it does

Sum IT Up: CMMC News Roundup ranks #124 on The B2B Podcast Index with a substance score of 78.5 out of 100, scored across 2 recent episodes. It scores highest on specificity & evidence and insight density. Excellent specificity: NIST SP 863 Revision 4 cited by name, NIST SP 800-171 Rev 2/3/5 timelines, DIBCAC Top 10 (MFA as #2 unmet control), specific Microsoft authentication options (Windows Hello, passkeys, FIDO2 keys), concrete examples (PIV/CAC cards), and explicit policy timing (RFI responses mid-August, task group recommendations end of September). Few hand-wavy claims.

The five-dimension breakdown

Averaged across 2 recently scored episodes, with cited evidence.

Insight Density

17.0 / 20

The episode delivers dense technical education about the distinction between replay-resistant and phishing-resistant authentication, with concrete historical context (NIST SP 863 revision timeline, NIST SP 800-171 revision cycles) and specific implementation gaps (MFA being the #2 unmet control per DIBCAC Top 10). However, some sections repeat concepts and include filler banter that dilutes substantive density.

“Phishing resistance is the ability of the authentication protocol to prevent the disclosure of authentication secrets and and valid authenticator outputs to an imposter verifier without reliance on the vigilance of the claimant.”

“The Most vanilla basic 101, just please turn on MFA at all is the number two most common thing that DIBCAC sees. That requirement has been there for 10 years and contractors aren't implementing any form of MFA even when it doesn't have to directly be even replay resistant, to say nothing of phishing resistance.”

Originality

16.0 / 20

The core insight - that DoD's 'Brilliant at the Basics' actually accelerates requirements beyond current NIST baselines before NIST has even codified them - is genuinely contrarian and well-sourced. The tax loophole analogy is fresh. However, the critique of regulatory overreach while simultaneously suspending enforcement is a somewhat familiar theme in policy critique.

“you would again be accelerating the 171 baseline derived from 53 past the revision cycle of 853, which, don't get me wrong, props to you guys. I mean, that is a very innovative way of defeating the slow revision cycle that NIST is on.”

“It's like, okay, uh, people aren't doing mfa. Uh, we have no idea if they're doing MFA without third party verification. So now do a much more advanced and expensive version of mfa, but we're still not going to ask for any proof like, we're going to raise the tax, we're not going to close the loophole.”

Guest Caliber

13.5 / 20

The two speakers appear to be CMMC/compliance practitioners with deep regulatory knowledge and references to real assessments (DIBCAC, GAO reporting, Nick DelRosa's presentations). However, the transcript reveals no formal credentials, titles, or track record of scale. They discuss policy and implementation gaps from an informed practitioner perspective but lack clear seniority markers or evidence of deploying solutions at significant scale.

“This was also found in GAO's independent reporting of the ecosystem was that they found that companies just don't know how to do this stuff.”

“When he gave the deeper explanation it was organizations just aren't fully understanding what it means to implement mfa.”

Specificity & Evidence

18.5 / 20

Excellent specificity: NIST SP 863 Revision 4 cited by name, NIST SP 800-171 Rev 2/3/5 timelines, DIBCAC Top 10 (MFA as #2 unmet control), specific Microsoft authentication options (Windows Hello, passkeys, FIDO2 keys), concrete examples (PIV/CAC cards), and explicit policy timing (RFI responses mid-August, task group recommendations end of September). Few hand-wavy claims.

“Phishing Resistant Authentication. The Brilliant at the Basics document says upgrade your authentication mechanisms to require strong phishing resistant MFA methods for user accounts.”

“863 was last updated in 2025. And that was the first time that they mentioned Phishing Resistant Authentication. So phishing resistance as a security control won't show up until 853 revision 6.”

Conversational Craft

13.5 / 20

Speaker A drives substantive technical discussion with clear logical progression and builds to a strong closing argument. However, conversational craft is limited by the format: Speaker B largely validates and mirrors Speaker A's points rather than challenging them or introducing friction. Few genuine follow-ups that push thinking sideways; mostly agreement and sympathy. The lunch ticket analogy works didactically but isn't a hard question.

“Jason, riddle me this buddy. We're supposed to be reducing cost and burden. That's the whole reason why we went through this phase two suspension. But the DOD CIO's list of basics are not only more advanced than the existing requirements that people were struggling with, but they would be in a lot of ways a huge expansion of what is currently required.”

“So I'm quickly looking up something because I want to see and I don't think that it's true, but is there an ODP assigned to the MFA control for 53 or for Rev3?”

Standout episodes

  • The DoD's "Basic" Cybersecurity Isn't Basic at All

    2026-08-06

    93
  • A Perfect SPRS Score Turned Into a $507K Settlement

    2026-06-25

    64

Rank over time

2 periods tracked.

Episodes

2 scored on substance · 66 tracked in total.

  • The DoD's "Basic" Cybersecurity Isn't Basic at All

    2026-08-06 · 25 min

    93 / 100
  • A Perfect SPRS Score Turned Into a $507K Settlement

    2026-06-25 · 13 min

    64 / 100

Frequently asked

What is Sum IT Up: CMMC News Roundup's substance score?
Sum IT Up: CMMC News Roundup scores 78.5 out of 100 for substance and ranks #124 on The B2B Podcast Index. That puts it ahead of 92% of the B2B podcasts we rank and #13 of 108 in Ops. The score reflects insight density, originality, guest caliber, specificity and conversational craft across recent episodes - not downloads.
Is Sum IT Up: CMMC News Roundup worth listening to?
Yes - Sum IT Up: CMMC News Roundup outscores 92% of the B2B ops podcasts and shows we rank on substance, so a ops operator is likely to come away with something useful.
Who hosts Sum IT Up: CMMC News Roundup?
Sum IT Up: CMMC News Roundup is hosted by Summit 7.
How often does Sum IT Up: CMMC News Roundup publish?
Sum IT Up: CMMC News Roundup publishes weekly, has 169 episodes, released its most recent episode on 2026-08-06.
Which Sum IT Up: CMMC News Roundup episode should I start with?
Our highest-scoring recent episode is "The DoD's "Basic" Cybersecurity Isn't Basic at All" (93/100) - a good place to start.

Show off your #13 rank in Ops

Add this badge to your site - it links back here and updates automatically as you rank.

Ranked #13 on The B2B Podcast Index
Embed code
<a href="https://index.fame.so/show/sum-it-up-cmmc-news-roundup" target="_blank" rel="noopener">
  <img src="https://index.fame.so/badge/sum-it-up-cmmc-news-roundup/badge.svg" alt="Ranked #13 on The B2B Podcast Index" width="360" height="136" />
</a>
Markdown & other formats →

Track Sum IT Up: CMMC News Roundup's rank

Get an email whenever this show moves up or down the Index. Monthly at most, no spam.

Listen / subscribe:WebsiteSpotifyRSS

Frequently discusses

Companies, products and tools that come up most across this show's episodes.

DIBCACDOJDODSPRSNIST Special Publication 800CS2

Topics this show covers

The themes that come up most across this show's episodes.

CMMC · 60DFARS · 58NIST · 58cui · 28cyber · 24dod · 20compliance · 16Cybersecurity · 15dow · 7dib · 4Microsoft · 3DibCAC · 2PasskeysPhishing-resistant MFAWebAuthnNIST SP 800-171 Rev 3NIST SP 800-53Replay-resistant authentication

More Ops podcasts

See all →
  • Cyber Leaders

    SANS Institute

    89.2
  • The Operations Podcast with Fexingo

    Fexingo

    88.6
  • Security & GRC Decoded

    Raj Krishnamurthy

    86.4
  • Rethink Imaging

    Imalogix

    84.3
  • Practical Cybersecurity with Jen Stone

    SecurityMetrics

    84.0
  • Value Based Care Advisory (VBCA) Podcast

    Carenodes

    82.0

Similar shows

Podcasts that dig into the same topics.

  • Trust Issues

    Bruno Lecoq

    78.2
  • Report on Securing and Growing the Digital Economy

    The Commission on Enhancing National Cybersecurity

    29.0
  • Inspiring Tech Leaders

    Dave Roberts

    49.6
  • Security & GRC Decoded

    Raj Krishnamurthy

    86.4
  • TechSurge: Deep Tech Podcast

    Celesta Capital | Deep Tech Venture Capital Firm

    84.4
  • Moody’s Talks: Risk Reframed

    Moody's Analytics

    71.5