The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/AI & Data/The Government Technology Insider Podcast
The Government Technology Insider Podcast artwork

CMMC Readiness Can’t Pause Just Because Phase 2 of the Program Did

The Government Technology Insider Podcast · 2026-08-24 · 17 min

0:00--:--

Key moments - from our scoring

Substance score

58 / 100

Five dimensions, 20 points each

Insight Density12 / 20
Originality10 / 20
Guest Caliber14 / 20
Specificity & Evidence11 / 20
Conversational Craft11 / 20

The Department of Defense's decision to pause CMMC Phase 2 third-party assessment requirements has created uncertainty across the defense industrial base, but Doug Barbon, President and National Managing Principal at Shellman, argues that the security imperatives remain unchanged. While some organizations may interpret the pause as permission to delay compliance work, Barbon emphasizes that Phase 1 self-assessments still mandate protection of controlled unclassified information (CUI) under NIST 800-171, and companies remain liable for false claims if they misrepresent compliance. The episode explores the practical reality: contractors cannot afford to pause security investments since the underlying validation requirements haven't disappeared - only how third-party verification occurs is under review. Barbon highlights that the largest ongoing challenge is identifying and tracking CUI throughout complex supply chains, particularly as it moves between prime contractors and thousands of subcontractors. He advocates for participation in the Department of Defense's RFI process and expresses optimism about emerging hosting services and virtual desktop infrastructure (VDI) solutions that could reduce compliance burden on smaller defense contractors, similar to how PCI compliance evolved in payment processing.

Key takeaways

  • →Phase 1 self-assessment requirements and underlying NIST 800-171 compliance obligations remain fully in effect regardless of the Phase 2 pause, with significant False Claims Act penalties for misrepresentation.
  • →The largest CMMC compliance challenge is identifying where CUI resides and tracking it through complex supply chains with hundreds or thousands of subcontractors, not the assessment mechanism itself.
  • →Third-party assessments retain value even during the Phase 2 pause because they provide defendable documentation that companies are accurately representing their security posture to the government.
  • →Smaller defense contractors should advocate for and adopt managed hosting services and VDI solutions that minimize their direct handling of sensitive data, similar to how PCI compliance evolved for payment processors.
  • →Contractors should respond to the Department of Defense's RFI to influence how CMMC evolves, while continuing security implementation work rather than pausing efforts pending the review outcome.

Guests

Doug Barbon

Topics in this episode

False Claims ActNIST 800-171CMMC (Cybersecurity Maturity Model Certification)Department of DefenseCyber ABControlled Unclassified Information (CUI)ShellmanPhase 1 self-assessmentsPhase 2 third-party assessmentsDefense Industrial Base (DIB)

Questions this episode answers

What CMMC compliance requirements are still in effect after the Phase 2 pause?

Phase 1 self-assessments remain mandatory, companies must still protect controlled unclassified information (CUI) under NIST 800-171, and they must continue submitting self-attestations to the Department of Defense - all original requirements are unchanged; only the third-party validation mechanism is under review.

What is the biggest compliance challenge organizations face when preparing for CMMC?

Identifying and tracking where CUI exists across the organization and throughout supply chains with multiple subcontractors, then ensuring that sensitive data is housed only in controlled, monitored locations rather than scattered across email, file shares, and other unsecured channels.

Should companies delay cybersecurity improvements while the Department of Defense reviews CMMC?

No; the underlying security requirements never changed, companies remain liable for false Claims Act violations if they misrepresent compliance, and continuing security work positions organizations to defend their posture regardless of how Phase 2 is implemented.

How can smaller defense contractors reduce the burden of CMMC compliance?

By adopting managed hosting services or virtual desktop infrastructure (VDI) solutions that allow them to access sensitive data via secure portals without storing CUI directly on their networks, similar to how payment processors evolved to minimize PCI compliance burden.

What should contractors do to influence how CMMC evolves after the Phase 2 pause?

Respond to the Department of Defense's RFI (Request for Information) to share concerns and feedback on what has and hasn't worked with the program, helping shape programmatic changes that support small businesses.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

12 / 20

The episode covers practical challenges in CMMC compliance with some useful specificity (CUI tracking, data lifecycle management, subcontractor information flow), but much of the content restates obvious points (the pause doesn't change underlying requirements, companies should keep going) or relies on abstract frameworks. The guest does provide concrete examples (the Ohio bolt manufacturer, credit card analogy) but these are sparse relative to filler and restatement.

the largest challenge has consistently been the identification and tracking of the cui
companies and organizations are required to protect controlled unclassified information and they're required to do that in accordance with NIST 800 171, just like they were before

Originality

10 / 20

The core message - that the pause shouldn't derail compliance work and that scope/data tracking is the real challenge - is standard industry wisdom, not fresh thinking. The VDI/hosting services analogy to credit card processing and PCI is the only genuinely original comparative framework offered, but it appears late and underdeveloped. Most of the discussion recycled existing CMMC talking points.

whether it's this or even independent assessments, um, regardless of what the reporting requirements are around them, um, are valuable to companies because it gives them a comfort that someone um, other than themselves has reviewed and validated
The goal is not to touch a credit card number. Right. And so the more you can minimize that within your network and you could outsource

Guest Caliber

14 / 20

Doug Barbon is President and National Managing Principal at Shellman, a firm with demonstrated breadth across 30+ compliance frameworks and clear exposure to prime contractors and DIB organizations. He brings practitioner credibility and has clearly advised multiple client types. However, the transcript reveals he is primarily an audit/assessment firm leader, not an operator who has built DIB-scale security infrastructure from first principles, which limits his caliber slightly.

President and National Managing Principal at Shellman
we're privileged to work with, we work with quite a few of the large prime contractors as well as uh, enterprise security and technology providers

Specificity & Evidence

11 / 20

While the guest references specific regulations (NIST 800-171), specific frameworks (PCI, HIPAA), and concrete examples (the Ohio bolt manufacturer, VDI solutions), these are limited in number and often used as analogies rather than hard evidence. No actual metrics, timelines, dollar figures, or named companies appear. The False Claims Act spike is mentioned without numbers or examples. Most claims lack supporting data.

we've already seen throughout the course of the year a significant spike in False Claims act, uh, the violations and fines and investigations
whether it's build an airplane or something along those lines

Conversational Craft

11 / 20

The host asks reasonable setup questions that invite detailed answers, but rarely pushes back, probe deeper follow-ups, or challenge the guest's claims. Questions are largely softball invitations for the guest to restate his firm's perspective. The host doesn't ask about tensions (e.g., what about contractors who genuinely lack resources?), or press the guest on the feasibility of his VDI solution proposal. The conversation reads more like a structured Q&A than sharp investigative dialogue.

Now Doug, with phase one self assessment still required, what compliance obligations remain in place today and what should contractors be focusing on?
Now has the Pentagon's announcement changed your recommendations for organizations that were actively preparing for a certification or is the overall strategy still the same generally?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B86%
  • Speaker A14%

Most-used words

data12third11party11requirements11compliance11contractors11security11self9department8government7assessment7organizations7place7information7program6phase6

Episode notes

In this episode of the Government Technology Insider podcast, host Lucas Hunsicker discussed the practical implications of the CMMC 2.0 pause with Doug Barbin, President and National Managing Principal at Schellman. Barbin explained why the announcement, despite its abruptness, wasn’t entirely unexpected, why identifying and tracking CUI as it moves from primes down through layers of subcontractors continues to be the biggest ongoing challenge, and why the majority of Schellman clients are still moving forward with the certification. He also looked ahead to the DoW’s 60-day review, the significance of responding to the Request for Information (RFI), and where he sees emerging solutions helping smaller contractors shrink their compliance footprint.

Full transcript

17 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Welcome to the Government Technology Insider podcast. I'm your host, Lucas Hunsiker. The Cybersecurity Maturity Model Certification Program, or cmmc, has entered a new phase following the Department of War's decision to suspend the upcoming Phase 2 third party assessment requirements while, uh, it conducts a comprehensive review of the program. Although phase one self assessments remain mandatory, organizations across the defense industrial base are reassessing what the pause means for their compliance strategies and cybersecurity investments. In this episode of the Government Technology Insider podcast, Doug Barbon, President and National Managing Principal at Shellman, discusses the current state of CMMC adoption, what the Pentagon's recent announcement means for defense contractors, and the practical steps companies can take now to be prepared for whatever comes next. I hope you enjoy our conversation. Well, thank you so much for sitting down with me today, Doug. It's a pleasure to speak with you and I'm looking forward to our conversation.

Speaker B: Absolutely. Pleasure.

Speaker A: So the Department of War recently suspended the upcoming phase two third party assessment requirements while it reviews the CMMC program. What was your reaction to the announcement and what does it mean for organizations across the defense industrial base?

Speaker B: Well, I think like, um, you know, most, most companies that have been working, you know, that work in this ecosystem as, as extensively as Shellman does, but also kind of have seen it across, you know, seen some of these patterns across multiple compliance frameworks. It definitely was, uh, um, you know, there had been some, you know, rumors going around that they might delay, uh, the deadline, push it out a little bit further, do some level of review. You know, nothing, nothing around that was particularly shocking. Right. You've got a new set of leadership within the, within the CIO at DOW and others. And um, I mean most big significant strategic programs like this will have some sort of, ah, a review, right? Uh, you know, management review and, or tweak to, you know, their style to line up, up with what their overall, you know, what the overall strategy is, whether it's at the CIO level or whether it's at the uh, at the Secretary of War level. Um, did we think that it was going to be, um, that there was going to be an actual pause of work that was going on? Um, no, not necessarily. I think that part of it has definitely been, um, has been disruptive and I think mostly because, you know, it's the, it's the, it's the, what's next? Right. And so it's the concern around contractors and uh, subcontractors, especially of all sizes. Right. Thinking. Oh, well, I'm just, I'm not Going to do anything now or not? I'm going to wait to do, you know, I'm going to wait to focus on the security improvements that I was making until um, you know, until, until further guidance has, has, has ensued. Now we've, we've seen good things since then. We've seen, you know, we've seen companies that, that do recognize that the security requirements never change, um, validation requirements and, but that, that didn't come out in, at the beginning, right. At first it was, there was a lot of misinformation, there was a lot of kind of knee jerk reactions and so forth as well. So I think over the course of the last close to a month, um, coming up on a month, it's been a little bit, a little bit more balanced, but there's still a lot of questions in the air, a lot of uncertainty as to okay, what's this going to look like going forward?

Speaker A: Excellent. Now Doug, with phase one self assessment still required, what compliance obligations remain in place today and what should contractors be focusing on?

Speaker B: Right, yeah, I mean, great question to answer. The short answer to your question is all of the same. Compliance requirements that were in place yesterday or in place prior to the pause are still in place. Uh, companies and organizations are required to protect controlled unclassified information and they're required to do that in accordance with NIST 800 171, just like they were before. They're required to submit those self attestations, the self assessment self attestations to the Department of War and they're very much still liable if they submit something that's false. Right. Or submit something that's inaccurate. And we've already seen throughout the course of the year a significant spike in False Claims act, uh, the violations and fines and investigations by the Department of Justice for companies that have misstated or misrepresented their compliance with these NIST 800171 requirements. Because again, none of those requirements went away as part of this. The only thing that was paused was the how was it going to be validated? Is it going to be a third party, is it going to be self assessment and so forth. So the, the key message is, yeah, you need to continue to do what you were doing and or should have been doing to protect the cui, uh, within, within your environment, within your control.

Speaker A: Now, do you worry that some organizations will interpret this pause as a reason to delay their cybersecurity efforts? And why? Could that be a mistake?

Speaker B: It would definitely be a mistake. I am, um, I'm going to say somewhat Concerned, I will say that one of the positive things that's come out of this, and now again, every member of this ecosystem, every assessor, is going to have the perspective of the types of companies that they work with. And so at Shellman, we're privileged to work with, we work with quite a few of the large prime contractors as well as uh, enterprise security and technology providers that provide some level of support within the DIB and um, within this space. And I will tell you, for us it has been overwhelmingly, we are continuing forward. As a matter of fact, some of the conversations I've had is, hey, no, we're continuing with our implementation, we're continuing to make sure we meet all of the rules. Um, the ones that have paused have only been to say, okay, we want to make sure the third party validation is correct. We have many other clients who have just been continuing on as planned because they know two things. One, that they believe in the value, they want credit for the work that they've done to get them to this point from a security perspective. And then two, um, they also believe that having third party assurance is something that adds value, that gives them additional comfort. Especially if, especially when you've got all of these different instances of false claims act violations happening and so forth. They've got a more defendable position to be able to say, yeah, we had a third party come in and do the audit. And so again, not a lot of Shelman's clients have actually paused their work for that reason is because they believe that security and doing the right things from, uh, you know, from a security controls and an estate 100, 171 perspective should never have, you know, should never have been paused at all. Do I worry about some on the smaller end? Yes, just mainly through the dialogue that we hear in some of the town halls and the discussions that are happening. I do think that there's a legitimate concern for small businesses to be able to afford the type of infrastructure and services for, um, you know, to be able to comply with these requirements.

Speaker A: Now, where are the biggest challenges organizations continue to face when preparing for cmmc, regardless of where third party assessments resume or not?

Speaker B: Yeah, I mean, the largest challenge, and this has multiple kind of facets to it, the largest challenge has consistently been the identification and tracking of the cui. Right. And this goes, you know, you can kind of get into the nerdy weeds of this and you know, this starts at the DoD DoW from the perspective of how it's defined, the information that's shared with, uh, defense contractors and with the Dib, um, how it's marked, how it's labeled, um, and the impact of it because it starts by the identification of okay, here's data that we, the government or department of war are going to share with you contractor in order to do this job that you've been contracted to do, whether it's build an airplane or something along those lines. Um, but marking what that is, it starts with the identification of when it's coming into the system and then from there where I think that the contractors struggle the most is okay then how is it, how are we tracking, how are we managing this particular uh, data throughout its life cycle? Right, because you could be a prime or a super prime and you could have hundreds, thousands of subcontractors and maybe there's a 10 person company um, out of uh, Ohio that's manufacturing a bolt that goes on to a fighter jet and they have to have enough information. So how are you sharing information with them that allows them to do their job but doesn't make it so they're not just sending emails uh, with diagrams and specs and things like that throughout the course. And so that's where this really starts to get messy. Right. It's one thing for you start with the getting from having it be marked from a DoD DoW perspective. And then how does that information promulgate throughout the prime as well as their subcontractors and everything else that would need to happen um, from that regard. And so I think that's, and that's where scope comes into play. Everyone says it's all about scope and it's all about scope when you don't know where the information um, doesn't exist. Is it in email, is it in file share, is it in both? How do you, you could go and you could create a perfectly secure file share program um, using either SharePoint or Box or something like that. These are all secure services. But if someone dec decides to email a copy of a sensitive cui, how does that get handled and things like that? So I think it's um, a lot of that. It starts with understanding where the data is and making it so that data is exactly where you want it to be and not anywhere else so that you can control and monitor where access is or where the different access points, monitoring, logging, all of those things apply to wherever the data resides. That still is the large, largest issue and that, that's truthfully the largest issue in any compliance domain. Right. Whether you're trying to figure out where patient health data is for hipaa, uh, or credit Card data is for, for pci.

Speaker A: Now has the Pentagon's announcement changed your recommendations for organizations that were actively preparing for a certification or is the overall strategy still the same generally?

Speaker B: No, I think that, you know, as an audit firm we're in, in many cases bound by the requirements that have been set forth by the accreditation bodies and the bodies that accredit and oversee them. Right. For us, the Cyber AB and the Department of War, which oversees the Cyber ab. And so if they come back and they say that um, okay, this is going to look a little different, there's going to be less companies that have to go through third party certification. Understood. I um, do believe, and we've validated this with a lot of our clients, Again the vast majority of them are continuing on as planned because they see the value in a third party assessment. Now if they come back and if that report needs to look different, if that um, validation needs to look different, different, if it becomes more of an internal report for them, then we'll continue to do that. We'll continue to operate the way that we've operated across 30 plus other compliance, uh, domains and frameworks that we cover, um, you know, that we cover today.

Speaker A: So beyond meeting compliance requirements, how can organizations use CMMC readiness to strengthen their overall cybersecurity posture and reduce business risk?

Speaker B: Yeah, I think it comes down to a couple things. I think that um, most contractors don't have the, you know, some of them don't even have dedicated security teams. I mean why would you, if they were a ten person organization. Um, but I think there's a couple things. So I think readiness allows you to, you know, understand what. And uh, this is coming from Shelman, who's not actually a consulting provider. Um, readiness allows you to understand the scope, allows you to put, maybe uh, draw some boxes around where that sensitive data may lie and then apply the controls to that. It also provides insight to the management team as to the types of things that they need to be thinking about when handling um, this type of information. But at the end of the day, I think whether it's this or even independent assessments, um, regardless of what the reporting requirements are around them, um, are valuable to companies because it gives them a comfort that someone um, other than themselves has reviewed and validated uh, what has gone into their security program. So uh, it's an important thing. And this is nothing that doesn't exist, hasn't existed in security for eons or uh, across other areas of our life. Right. I mean there is value to third party assurance in whatever way that that looks, um, and giving companies the comfort, especially ones that, to your point earlier, I mean, phase one, self certification is still in play. C levels at, you know, whether CEO, CEOs are there signing off on these self attestations and affirmations that are going to the government. Um, if they get it wrong, there's significant implications. And so there's comfort in having a third party review to make sure that, uh, you're getting it right.

Speaker A: Well, excellent. Now looking ahead, what should contractors be watching for as the Department of War completes its review? And how can they position themselves to adapt to any future changes?

Speaker B: Yeah, I think that's a good question. Uh, I think first we encourage everyone, uh, in the space to respond to the rfi, which is due this Friday. Shellman, uh, will be responding. I know, I think, I think I read somewhere that there's been well over 100 RFI responses already and there'll be several hundred more that are expected by the end of this week. But I think this is a great opportunity for the Department of War and the office of the CIO to get feedback, critical feedback on what has worked, what we're worried about and what hasn't worked. And there's a lot of things that can be done from a programmatic perspective, uh, to help small businesses. But I think one, participate in the rfi, share your concerns, but also seek to learn about what the, uh, you know, the why, right. In terms of why these, why these rules were put in place in the first place, what the concerns are, what you can do. I am personally excited, even though it has nothing to do with, uh, Shoman's assessment program. But I've heard some talks around innovative solutions. Maybe it's hosting services or vdi, whether it's the government, Microsoft, the prime contractors, whoever it may be, right. Providing some of the level of hosting services and managing and housing this data, this sensitive data so the small companies don't have to. So if you're a small provider that works on, uh, a bolt for an airplane as the example, right. You might have the ability to just log into a secure portal via VDI or something like that and get access to what you need and when you need it, and therefore you're not even having to worry about, um, where the data may be sitting on your network. And again, this is for Shellman, this is nothing new. When we look at all of the other types of compliance frameworks and so forth that we've assessed over years and years and years. Right. And credit card, if you look at credit card. The goal is not to touch a credit card number. Right. And so the more you can minimize that within your network and you could outsource. Right. Your barbers and hairdressers and contractors. Right. They're not burdened by PCI compliance anymore. Right. Because there are technology solutions in place that allow someone else to handle the sensitive data and you just use it for, you need to use it for. Right. Which is to get paid. And so I am optimistic that we'll see solutions like that present themselves more in the marketplace, uh, than they have been so far to date. And I think that's going to have the biggest impact, uh, on smaller contractors in particular. But again, the guidance is let's continue to pay attention, let's continue to self assess as to where we are today, uh, and see what we can do to reduce that security footprint, but also, you know, provide meaningful security and compliance.

Speaker A: Thank you, Doug, for joining me today and a big thank you to our listeners for tuning in. If you're interested in staying up to date on the latest best practices, lessons learned and proven strategies for leveraging innovative technologies in federal, state and local government, be sure to visit us@Government TechnologyInsider.com I've been your host, Lucas Hunsker. And until next time, so long.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • CMMC Level 2: Documentation, Costs, and Audit Readiness | Interview with Bruno LecoqSecure & Simple · on Cyber AB89 / 100
  • Why CMMC became necessary in the first place.Trust Issues · on NIST 800-17188 / 100
  • July 2026 CMMC ConnectCyberspin · on NIST 800-17180 / 100
  • The CMMC Reality Check: Gap Assessments, Documentation Overload & Why 30-Day Compliance Claims Are a Red FlagCMMC Compliance Guide · on NIST 800-17180 / 100
  • How Do I Continue Self-Assessments Following the CMMC Phase 2 Suspension?Climbing Mount CMMC · on Controlled Unclassified Information (CUI)79 / 100
  • The Evolving World of Cybersecurity Compliance, with Nathanael DickIT Matters · on NIST 800-17176 / 100

More from The Government Technology Insider Podcast

All episodes →
  • ​​AI-Driven Acquisition: Keeping Humans at the Center​ 61 / 100
  • Connecting the National Guard in Austere Environments
  • Speed to Contracting, Speed to Mission for Air Force Connectivity
  • Identity is the New Tier-0
  • ​​Mobile Military Recruitment is Meeting Prospects Where They Are​
Explore the best B2B AI & Data podcasts →
All The Government Technology Insider Podcast episodes →