
Hosted by Summit 7
Listed under Technology, Government
It's difficult to keep up with all of the moving parts that make up the Department of Defense's Cybersecurity Maturity Model Certification Program. It's even more difficult to keep up with the relevant bits and bites that influence CMMC.
169 episodes · publishes weekly · latest 2026-08-06 · ~26 min/episode
Rank
#124
Substance
78.5
/ 100
Breakdown
Scored 2026-08
Updated monthly
Across the index
#124 of 1479
Substance
Top 8%
outscores 92% of the index
Sum IT Up: CMMC News Roundup ranks #124 on The B2B Podcast Index with a substance score of 78.5 out of 100, scored across 2 recent episodes. It scores highest on specificity & evidence and insight density. Excellent specificity: NIST SP 863 Revision 4 cited by name, NIST SP 800-171 Rev 2/3/5 timelines, DIBCAC Top 10 (MFA as #2 unmet control), specific Microsoft authentication options (Windows Hello, passkeys, FIDO2 keys), concrete examples (PIV/CAC cards), and explicit policy timing (RFI responses mid-August, task group recommendations end of September). Few hand-wavy claims.
Averaged across 2 recently scored episodes, with cited evidence.
The episode delivers dense technical education about the distinction between replay-resistant and phishing-resistant authentication, with concrete historical context (NIST SP 863 revision timeline, NIST SP 800-171 revision cycles) and specific implementation gaps (MFA being the #2 unmet control per DIBCAC Top 10). However, some sections repeat concepts and include filler banter that dilutes substantive density.
“Phishing resistance is the ability of the authentication protocol to prevent the disclosure of authentication secrets and and valid authenticator outputs to an imposter verifier without reliance on the vigilance of the claimant.”
“The Most vanilla basic 101, just please turn on MFA at all is the number two most common thing that DIBCAC sees. That requirement has been there for 10 years and contractors aren't implementing any form of MFA even when it doesn't have to directly be even replay resistant, to say nothing of phishing resistance.”
The core insight - that DoD's 'Brilliant at the Basics' actually accelerates requirements beyond current NIST baselines before NIST has even codified them - is genuinely contrarian and well-sourced. The tax loophole analogy is fresh. However, the critique of regulatory overreach while simultaneously suspending enforcement is a somewhat familiar theme in policy critique.
“you would again be accelerating the 171 baseline derived from 53 past the revision cycle of 853, which, don't get me wrong, props to you guys. I mean, that is a very innovative way of defeating the slow revision cycle that NIST is on.”
“It's like, okay, uh, people aren't doing mfa. Uh, we have no idea if they're doing MFA without third party verification. So now do a much more advanced and expensive version of mfa, but we're still not going to ask for any proof like, we're going to raise the tax, we're not going to close the loophole.”
The two speakers appear to be CMMC/compliance practitioners with deep regulatory knowledge and references to real assessments (DIBCAC, GAO reporting, Nick DelRosa's presentations). However, the transcript reveals no formal credentials, titles, or track record of scale. They discuss policy and implementation gaps from an informed practitioner perspective but lack clear seniority markers or evidence of deploying solutions at significant scale.
“This was also found in GAO's independent reporting of the ecosystem was that they found that companies just don't know how to do this stuff.”
“When he gave the deeper explanation it was organizations just aren't fully understanding what it means to implement mfa.”
Excellent specificity: NIST SP 863 Revision 4 cited by name, NIST SP 800-171 Rev 2/3/5 timelines, DIBCAC Top 10 (MFA as #2 unmet control), specific Microsoft authentication options (Windows Hello, passkeys, FIDO2 keys), concrete examples (PIV/CAC cards), and explicit policy timing (RFI responses mid-August, task group recommendations end of September). Few hand-wavy claims.
“Phishing Resistant Authentication. The Brilliant at the Basics document says upgrade your authentication mechanisms to require strong phishing resistant MFA methods for user accounts.”
“863 was last updated in 2025. And that was the first time that they mentioned Phishing Resistant Authentication. So phishing resistance as a security control won't show up until 853 revision 6.”
Speaker A drives substantive technical discussion with clear logical progression and builds to a strong closing argument. However, conversational craft is limited by the format: Speaker B largely validates and mirrors Speaker A's points rather than challenging them or introducing friction. Few genuine follow-ups that push thinking sideways; mostly agreement and sympathy. The lunch ticket analogy works didactically but isn't a hard question.
“Jason, riddle me this buddy. We're supposed to be reducing cost and burden. That's the whole reason why we went through this phase two suspension. But the DOD CIO's list of basics are not only more advanced than the existing requirements that people were struggling with, but they would be in a lot of ways a huge expansion of what is currently required.”
“So I'm quickly looking up something because I want to see and I don't think that it's true, but is there an ODP assigned to the MFA control for 53 or for Rev3?”
2 periods tracked.
2 scored on substance · 66 tracked in total.
Add this badge to your site - it links back here and updates automatically as you rank.
<a href="https://index.fame.so/show/sum-it-up-cmmc-news-roundup" target="_blank" rel="noopener">
<img src="https://index.fame.so/badge/sum-it-up-cmmc-news-roundup/badge.svg" alt="Ranked #13 on The B2B Podcast Index" width="360" height="136" />
</a>Track Sum IT Up: CMMC News Roundup's rank
Get an email whenever this show moves up or down the Index. Monthly at most, no spam.
Companies, products and tools that come up most across this show's episodes.
The themes that come up most across this show's episodes.
Podcasts that dig into the same topics.
Trust Issues
Bruno Lecoq
Report on Securing and Growing the Digital Economy
The Commission on Enhancing National Cybersecurity
Inspiring Tech Leaders
Dave Roberts
Security & GRC Decoded
Raj Krishnamurthy
TechSurge: Deep Tech Podcast
Celesta Capital | Deep Tech Venture Capital Firm
Moody’s Talks: Risk Reframed
Moody's Analytics