CMMC Ecosystem Summit + CMMC Implementation Conference
CMMC Ecosystem Summit + CMMC Implementation Conference

Building a Community...

We are all in this together.  Building a CMMC community does not happen by accident.  It happens with intention. We are so grateful for your interest in traveling to CEIC West and sharing your knowledge.

In recognition of that, and with the intention of helping build the CMMC community, we are doing the following things in comparison to other conferences.  

First, we are doubling the number of speakers, with a minimum of two per session.  That does two things.  It gives more people a chance to spend time on stage.  And it also creates an opportunity for two knowledgeable speakers to collaborate to build their joint presentations.  You get to know someone in a way that just isn't the same as "networking" because you'll be working together towards a common goal.

We also are adding nearly 1/3 more presentations.  Most track sessions which were 60 minutes in the past will be 45 minutes now.  That puts more people on stage, and it shows an awareness of our audience's ever shrinking, 2025, attention span.  

To provide these additional opportunities, we are asking speakers to contribute to their registration by offering nearly 60% off the standard ticket price of $1195, with a flat registration fee of $500.  This will help defray some of the costs for supporting what could be more than 60 speakers at the conference, while keeping audience ticket prices down.

We understand that this may be a burden for some speakers in our nascent industry.  We don't want you and your ideas to be excluded.  So, if you are selected and you require support beyond the discount, email [email protected] and we will work with you to make sure that you can attend.  

Once again, our gratitude is deep for considering CEIC West as the venue to share your knowledge, and our anticipation for the event is palpable.

We'll see you in Vegas in May!

-Mark Berman
CEO, Forum Makers 

Speaker Information

  • Notification: Selected speakers will be notified of their application status by March 7th, 2025.
  • Respond to your confirmation email signifying your acceptance to speak at the conference.
  • Register for the conference using your unique access code provided in your confirmation email by March 15th.
  • If you are selected to speak with a co-presenter, Forum Makers will make the initial introduction so you can coordinate and prepare prior to your presentation.
  • A PowerPoint presentation is optional. If used, speakers must use the official CEIC West template, which will be provided by April 1st.
  • Make sure to book your hotel by April 18th - view hotel info here.

General Session Topics

SESSION DETAILS

CMMC Level 1 - You and The Other 220,000 Contractors

Wednesday, May 21st
Duration: 30 mins.
Speaker 1: TBD
Speaker 2: TBD

Compliance with CMMC Level 1, mandated by FAR clause 52.204-21(b)(1), isn’t just a box to check—it’s a chance to unlock value for both contractors and service providers. For contractors, it provides an opportunity to strengthen operations and build trust with customers. For service providers, it’s a pathway to deepen client relationships and differentiate their offerings. This session explores how both groups can collaborate to implement Level 1 compliance in a way that drives not only security but also profitability.

We’ll explore:

  • The 15 security practices required for CMMC Level 1 and how to implement them efficiently without unnecessary overhead.
  • How contractors can use compliance to improve processes, win more contracts, and increase customer confidence.
  • The role of service providers in streamlining compliance efforts while creating opportunities for recurring revenue and premium services.
  • Practical strategies to align contractors and service providers for seamless implementation, reduced costs, and shared success.

This session will show you how compliance can be more than a mandate—it’s a bridge to stronger partnerships, more secure operations, and greater profitability for everyone involved.

Feeding the Monster. Recruiting, Training and Attracting the Workforce We Need

Wednesday, May 21st
Duration: 30 mins.
Speaker 1: TBD
Speaker 2: TBD

The CMMC ecosystem demands skilled talent to meet compliance requirements, offering individuals a fast track to six-figure salaries while helping contractors and service providers succeed. But a single CCP class isn’t enough. This session explores how individuals, contractors, and service providers can collaborate to develop a workforce that drives compliance, fosters cybersecurity awareness, and builds resilience.

We’ll discuss:

  • For Individuals: How certifications like CCP and beyond can unlock lucrative career opportunities—and the additional training needed to stand out as a compliance leader.
  • For Contractors: How CCP-trained staff empower organizations to lead culture change, foster cybersecurity awareness, and ensure adherence to SOPs while producing evidence for compliance. Their expertise also enables contractors to become smarter buyers of third-party services, reducing risks and improving outcomes.
  • For Service Providers: Building skilled teams that enhance service delivery, meet client compliance needs, and create value through collaboration and access to hands-on training resources.
    Shared Goals: Creating a workforce pipeline through mentorship, partnerships, and education to attract new talent while upskilling existing teams.

This session equips individuals, contractors, and service providers with actionable strategies to align efforts, ensuring compliance success while strengthening and empowering the CMMC ecosystem.

All the Changes in the Law - Now and Coming Soon

Thursday, May 22nd
Duration: 40 mins.
Speaker 1: TBD
Speaker 2: TBD

The "Delta" Session

Get up to date with all of the rule changes since last December and those that are coming up:

  • Final CMMC Rule (Title 32 Rule) Effective 12/26/2024
  • The CAP (CyberAB CMMC Assessment Process), Effective 12/2024
  • DFARS 7021 Update, Effective 1/17/2025
  • FAR Update (48 CFR), Proposed Rule, 1/15/2025

Supply Change Security Across the Federal Government (and States) 

Thursday, May 22nd
Duration: 40 mins.
Speaker 1: Robert Metzger facilitated by Mark Berman
Speaker 2: TBD

The Now and Future of CMMC under the Trump Administration

Split Session: Tom Bendien on AI Tools
PANEL: Responsible and ethical use and assessment of AI in the CMMC ecosystem.

Thursday, May 22nd
Duration: 40 mins.
Speaker: Tom Bendien
Panelist 1: TBD
Panelist 2: TBD
Panelist 3: TBD
Panelist 4: TBD
Panelist 5: TBD

Artificial Intelligence (AI) is transforming how organizations approach compliance, offering powerful tools to streamline assessments, manage risks, and craft effective policies. But with these opportunities come critical questions: Where does AI truly add value, and where could it create unintended vulnerabilities? This split session will explore both the potential and the pitfalls of using AI in compliance for the Defense Industrial Base (DIB).

Part 1: AI in Action (with Tom Bendien)

  • Discover how AI tools can streamline CMMC assessments with live demos showcasing their capabilities.
  • Gain Pro Tips on how to assess risks, identify gaps, and create tailored policies for the DIB when adopting AI technologies.
  • Explore real-world applications and learn how to integrate AI into compliance processes effectively.

Part 2: Panel Discussion

Join industry experts to discuss where AI should—and should not—be used in compliance.

  • Understand the risks AI introduces, including potential biases and unintended consequences.
  • Learn how to evaluate resources, select trusted advisors, and ensure informed decision-making before adopting AI-driven suggestions.

This session challenges you to reframe your perspective on AI: not as a replacement for human judgment, but as a powerful tool for augmenting compliance efforts. Leave with practical insights into how AI can be responsibly leveraged to strengthen your compliance program while managing its inherent risks.

CMMC Beyond the DoD: Preparing for a Broader Compliance Landscape

Thursday, May 22nd
Duration: 40 mins.
Speaker 1: Michael Gruden
Speaker 2: Kayli Keogh, Honeywell
Speaker 3: Jennie Von Cannon, DO

The influence of CMMC is growing rapidly, moving beyond its origins in the Department of Defense (DoD) to appear in RFPs and RFQs and impacting industries and governments worldwide. This session explores the expanding role of CMMC, providing practical insights for contractors and organizations navigating this evolving compliance landscape.

We’ll cover:

  • CMMC in RFPs and RFQs: Emerging trends in how CMMC is being integrated into DoD solicitations and what contractors need to do to prepare and remain competitive.
  • CMMC’s Expanding Reach: How other federal agencies, private enterprises, and international governments are adopting CMMC principles, and its potential to become a universal cybersecurity standard.
  • Navigating Complex Compliance: Perspectives from an experienced compliance counsel at a leading Aerospace & Defense company on addressing CMMC requirements in multinational environments. Topics include balancing risk tolerance, DOJ enforcement considerations, and implementing effective cybersecurity controls in complex operations.

This session equips attendees with actionable knowledge to anticipate CMMC’s growing impact across industries and borders, helping organizations stay ahead in a world where compliance is becoming a critical competitive advantage.

Creatures of Habit - Cheats and Practices for Annual, Quarterly, Monthly, Weekly Practices to Maintain Certification

Friday, May 23rd
Duration: 30 mins.
Speaker 1: Emery Csulak
Speaker 2: TBD
Speaker 3: TBD

The influence of CMMC is growing rapidly, moving beyond its origins in the Department of Defense (DoD) to appear in RFPs and RFQs and impacting industries and governments worldwide. This session explores the expanding role of CMMC, providing practical insights for contractors and organizations navigating this evolving compliance landscape.

We’ll cover:

  • CMMC in RFPs and RFQs: Emerging trends in how CMMC is being integrated into DoD solicitations and what contractors need to do to prepare and remain competitive.
  • CMMC’s Expanding Reach: How other federal agencies, private enterprises, and international governments are adopting CMMC principles, and its potential to become a universal cybersecurity standard.
  • Navigating Complex Compliance: Perspectives from an experienced compliance counsel at a leading Aerospace & Defense company on addressing CMMC requirements in multinational environments. Topics include balancing risk tolerance, DOJ enforcement considerations, and implementing effective cybersecurity controls in complex operations.

This session equips attendees with actionable knowledge to anticipate CMMC’s growing impact across industries and borders, helping organizations stay ahead in a world where compliance is becoming a critical competitive advantage.

Mock Assessment - Dissecting the CAP: Inside the Room of a CMMC Assessment

Friday, May 23rd
Duration: 75 mins.
Speaker 1: TBD
Speaker 2: TBD

What happens in the room during a CMMC assessment can make or break your compliance journey. This session combines a live mock assessment with strategic insights to prepare you for the Certification Assessment Process (CAP). You'll gain a comprehensive understanding of how assessments are conducted and learn how to approach them with confidence and precision.

The session kicks off with a 15-minute educational overview, covering:

  • The purpose and key phases of the CAP, including planning, evidence review, and final reporting.
  • How to effectively prepare for your assessment by organizing evidence, understanding timelines, and addressing potential gaps.

The main event is a live, simulated mock assessment, featuring a fictitious Organization Seeking Certification (OSC) and a Certified Third-Party Assessor Organization (C3PAO) team.

You’ll experience:

  • What It’s Like to Be in the Room: Insight into the pace, flow, and dynamics of the assessment process.
  • Evidence Review in Action: How assessors validate compliance by examining policies, procedures, and security controls.
  • Interview Strategies: Best practices for interacting with assessors, including how to avoid “saying too much,” staying concise, and preventing dead-end conversations.
  • Common Pitfalls and Outcomes: Identifying errors to avoid and understanding how findings are documented in final reports.

This session delivers a practical, immersive experience that prepares you to navigate the CAP effectively, ensuring you’re equipped to handle the pace and expectations of a real CMMC assessment.

Cotractor's Track Topics

SESSION DETAILS

Level Set - CMMC Terminology

Wednesday, May 21st
Duration: 20 mins.
Speaker 1: TBD
Speaker 2: TBD

The world of CMMC is full of acronyms, jargon, and technical terms that can leave contractors feeling overwhelmed. In just 20 minutes, this session will break down the key terminology you need to know to navigate CMMC confidently. From understanding what terms like “FCI,” “CUI,” and “POA&M” to evolving ecosystem terms like "CCA", "OSC", "CCP", "RPO", "RP", PI", "LTP", technical terms like "FIPS" and so many more. We’ll cut through the complexity to give you a clear understanding of the language of compliance.

You’ll learn:

  • The critical terms and concepts every contractor needs to know to succeed with CMMC.
  • How to differentiate between technical jargon and actionable requirements.
  • Real-world examples of how misinterpreting terminology can lead to compliance gaps.
  • Walk away with a solid foundation in CMMC terminology so you can confidently engage with auditors, service providers, and compliance requirements.

The Scoping Tightrope: Balancing Cost, Complexity, and Risk in CMMC Compliance

Wednesday, May 21st
Duration: 60 mins.
Speaker 1: TBD
Speaker 2: TBD

Scoping for CMMC is a high-stakes balancing act. Done right, it reduces costs, simplifies IT, and minimizes training overhead by isolating compliance efforts to a controlled enclave. But done wrong, it can introduce unexpected risks, create unmanageable complexity, and leave critical data—like CAD vaults in manufacturing—vulnerable.

This session explores the fine line between efficiency and exposure, walking through the risks of over-scoping (wasted resources) and under-scoping (compliance failures and security gaps). We’ll also delve into strategies for establishing strong boundaries between the enclave and the rest of your organization, ensuring only authorized people and devices access the protected environment. With real-world examples of scoping missteps and successes, this talk equips you with the tools to scope smart, not risky.

Key Takeaways:

  • Learn how improper scoping decisions can increase organizational risk, from regulatory non-compliance to data breaches.
  • Explore cost-effective strategies for balancing IT licensing, training, and operational complexity with robust security controls.
  • Understand the importance of clear boundaries within a CMMC enclave and how to prevent spillover risks.
  • Gain actionable insights into protecting in-scope CAD vaults and addressing manufacturing-specific challenges.
  • Avoid common scoping pitfalls with real-world examples of what works—and what doesn’t—in the CMMC landscape.

Selecting the Right CMMC Partners: From Service Providers to Your C3PAO

Wednesday, May 21st
Duration: 40 mins.
Speaker 1: TBD
Speaker 2: TBD

As a contractor, your ability to achieve and maintain CMMC compliance often depends on the service providers you rely on—your MSPs, MSSPs, and CSPs. Equally important is your choice of a Certified Third-Party Assessment Organization (C3PAO) to certify your compliance. But how can you tell if these partners are delivering a complete solution or leaving critical gaps that could cost you time, money, and compliance?

This session will help you evaluate your service providers’ offerings and your options for selecting the right C3PAO.

We’ll cover:

Service Providers:

  • How to determine if your MSP is delivering an “80%” or a “100%” solution for compliance.
  • Common pitfalls, like hidden add-on costs and gaps in services, and how to avoid them.
  • What certifications (SOC 2 Type 2, FedRAMP, CMMC) to look for in your service providers, and when they’re required for your compliance journey.
  • Questions to ask your service providers to ensure they’re meeting your compliance needs.

Selecting a C3PAO:

  • What makes a C3PAO credible and trustworthy in the CMMC ecosystem?
  • Key factors to consider when choosing a C3PAO, including their experience, pricing structure, and availability.
  • Insights from a C3PAO on how to evaluate their services and avoid common contractor missteps.
  • Questions to ask during the selection process to ensure they align with your compliance timeline and goals.

By the end of this session, you’ll be equipped to vet your service providers effectively, select the right C3PAO, and hold all your partners accountable for helping you achieve and maintain CMMC compliance without surprises.

DOJ & CMMC: How the Government Enforces CMMC

Thursday, May 22nd
Duration: 40 mins.
Speaker 1: Michael Gruden
Speaker 2: Jennie Von Cannon, DOJ
Speaker 3: TBD

Since the Civil Cyber Fraud Initiative, the Department of Justice has brought forth endless cases and penalties against companies that fail to implement cybersecurity requirements. Join former Department of Justice cybersecurity prosecutor and former Pentagon IT Acquisition Branch Chief Michael Gruden, now both cybersecurity Partners at Crowell & Moring LLP, as they discuss the key cybersecurity gaps and omissions the government has enforced in CCFI cases and which CMMC controls are most commonly affected. During this robust conversation, common CMMC control vulnerabilties will be addressed and considerations to harden potential gaps.

PANEL - From JVSA to C3PAO: Navigating the New CMMC Landscape for a Smoother Certification

Thursday, May 22nd
Duration: 40 mins.
Panelist 1: TBD
Panelist 2: TBD
Panelist 3: TBD
Panelist 4: TBD
Panelist 5: TBD

With the CMMC Assessment Process (CAP) newly published in December, everyone is navigating an evolving compliance landscape. This panel brings together diverse perspectives from:

  • A company that completed a Joint Surveillance Voluntary Assessment (JVSA)
  • A service provider supporting CMMC readiness
  • A Certified Third-Party Assessment Organization (C3PAO).

Panelists will share lessons learned from the JVSA process, insights into what went right and wrong, and strategies to apply these experiences to your C3PAO-based certification. You'll also gain practical tips on managing variances in C3PAO criteria, leveraging data governance to control costs, and preparing for success in a rapidly changing compliance environment.

Control Deep Dive: Documenting and Preparing Evidence for Two Controls

Thursday, May 22nd
Duration: 30 mins.
Speaker 1: TBD
Speaker 2: TBD

This session focuses on the practical application of CEIC West insights to document and prepare the body of evidence for two specific CMMC controls—one simple and one complex. Attendees will learn how to create compliance statements for each control objective and assemble the evidence required for the Examine, Interview, and Test phases of an assessment.

We’ll cover:

  • Compliance Statements: How to craft precise, objective-aligned compliance statements that clearly define control implementation and effectiveness.
  • Examine Phase: Documenting policies, procedures, and records that are concise yet comprehensive to meet assessor expectations.
  • Interview Phase: Preparing teams to articulate how controls are implemented, backed by documented evidence, while avoiding unnecessary elaboration.
  • Test Phase: Demonstrating operational effectiveness with technical configurations and supporting records that align with documented objectives.
  • Balancing Evidence: Ensuring documentation is neither excessive nor insufficient, avoiding unnecessary complexity while addressing all requirements.

This session provides a detailed walkthrough of how to effectively document and prepare evidence for two controls, giving attendees the tools to ensure their body of evidence meets assessment standards.

False Starts/Knowing-Doing Issues

Friday, May 23rd
Duration: 30 mins.
Speaker 1: Mike Bramm
Speaker 2: TBD

How to keep the momentum on the CMMC process

  • Get C-Suite Buy-In
  • Staying focused and not get distracted by daily tasks
  • Creating new habits for staff
  • Engaging Non-IT Staff
  • Examples of how people go off track and get bogged down

Service Provider's Track Topics

SESSION DETAILS

CAICO Training Updates: Staying Certified in the Evolving CMMC Ecosystem

Wednesday, May 21st
Duration: 20 mins.
Speaker 1: TBD

As the CMMC ecosystem evolves, staying certified requires service providers to stay ahead of critical updates from CAICO. One of the most important developments is the introduction of "delta" training, designed to bridge the gap for professionals who completed certification before the CMMC rule release. This session will provide an essential update on CAICO's training oversight, certification pathways, and the implications for service providers.

You’ll learn:

  • The structure and requirements of "delta" training to ensure certifications remain valid and up-to-date.
  • Key timelines for Certified CMMC Professionals (CCPs), Certified Assessors (CAs), and instructors to maintain compliance.
  • Updates on CAICO’s current training programs and certification pathways, including Provisional Instructor (PI) and Certified CMMC Instructor (CCI).
  • How to prepare your organization and clients for changes in training and certification requirements.
  • Practical insights into leveraging CAICO’s programs to align your services with CMMC expectations.

This session equips you with the knowledge to stay certified, support your clients effectively, and ensure your organization remains competitive in the CMMC ecosystem.

What Does It Take to Be an Effective ESP in the CMMC Market?

Wednesday, May 21st
Duration: 60 mins.
Speaker 1: TBD
Speaker 2: TBD

Thriving as an External Service Provider (ESP) or C3PAO in the CMMC Market

Thriving as an External Service Provider (ESP) in the CMMC market isn’t just about delivering great technical services—it’s about mastering compliance, managing costs, and building trust with your clients. Whether you’re an MSP, MSSP, CSP, or aspiring to become a Certified Third-Party Assessment Organization (C3PAO), understanding how to align your services with CMMC requirements is critical to staying competitive and profitable. This session focuses on the practical, real-world steps ESPs and C3PAOs need to take to succeed in this challenging market.

For External Service Providers (ESPs):

  • The financial and operational impacts of becoming a compliance-focused ESP, including investments in certifications like SOC 2, CMMC, and FedRAMP.
  • How to structure services that meet client compliance needs while maintaining profitability.
  • The role of documentation, QBRs, and consulting in positioning yourself as a trusted partner for your clients’ compliance journey.
  • Why simplifying compliance for your clients isn’t just a value-add—it’s a business necessity in the CMMC market.
  • Strategies to balance profitability with the additional complexity of serving compliance-driven contractors.

For C3PAOs:

  • What it takes to build and become a C3PAO, including ISO requirements, staffing needs, and operational readiness.
  • Key challenges specific to C3PAOs, including navigating accreditation processes and managing auditor capacity.

This session provides a no-nonsense look at what it takes to not just survive, but thrive, in the CMMC ecosystem as a trusted, profitable ESP or C3PAO.

Documentation Done Right: Building a Strong Foundation for CMMC Compliance

Wednesday, May 21st
Duration: 40 mins.
Speaker 1: Noel Vestal
Speaker 2: TBD
Speaker 3: TBD

When it comes to CMMC compliance, your policies, procedures, and documentation are your first—and often most critical—line of defense. But what does "good" actually look like? This session dives into the practical strategies and lessons learned from real-world assessments to help you build documentation that not only satisfies assessors but also supports your organization’s long-term success.

We’ll cover:

  • What Good Looks Like: The essential components of effective policies, procedures, and documentation that stand up to scrutiny.
  • Creating a Configuration Management Plan: Step-by-step guidance on assigning document numbers, establishing authorship, review and approval processes, and using CCBs to manage changes.
  • Lessons from the Field: Insights from over a dozen CMMC Level 2 assessments, including strategies for structuring evidence packages and creating clear, actionable control summaries.
  • Two Approaches to Content: Balancing complete, compliance-focused documentation that meets audit requirements with consumable, employee-friendly materials that guide day-to-day operations.
  • Sustainability in Documentation: How to build maintainable documents with refresh cycles that keep your compliance up to date without overwhelming your team.

Join a certified C3PAO assessor and a DIB company representative as they break down what works, what doesn’t, and how you can turn your documentation into a competitive advantage. Whether you’re just starting or fine-tuning your approach, this session will leave you with actionable steps to streamline your compliance journey.

Looking at CMMC through the lens of George Akerlof's classic "Market for Lemons" theory

Wednesday, May 21st
Duration: 40 mins.
Speaker 1: Terrence "Terry" McGraw
Speaker 2: TBD

In recent years, the cybersecurity industry has been characterized by what economists term as a "market for lemons," where the quality of security products and services often remains opaque to buyers, leading to a market dominated by potentially substandard offerings. This talk will explore how this asymmetric information problem in cybersecurity parallels George Akerlof's classic "Market for Lemons" theory, where buyers cannot discern the quality of products, leading to market failure.

We will discuss how the introduction of the Cybersecurity Maturity Model Certification (CMMC) program by the U.S. Department of Defense aims to address these issues by standardizing and verifying the cybersecurity practices of its contractors. The CMMC framework is designed to increase transparency and trust by certifying companies based on their cybersecurity maturity levels, thereby ensuring that those handling sensitive information meet certain security standards.

However, the sustainability of CMMC's effectiveness hinges on its own transparency and rigor. This presentation will analyze the challenges the CMMC must overcome to avoid becoming another "market for lemons" itself, including maintaining impartiality in assessments, ensuring assessor competence, and adapting to evolving cyber threats. We'll examine the potential pitfalls if these standards are not upheld and explore how continuous oversight, public scrutiny, and stakeholder engagement can safeguard the integrity of the CMMC process.

This talk will offer insights into how the cybersecurity landscape can evolve from a market of lemons into one where quality, trust, and transparency prevail, with CMMC potentially leading the way, provided it adheres to its foundational principles of high standards and transparenc

Talking CMMC: Strategies for Service Providers to Engage Contractors

Thursday, May 22nd
Duration: 40 mins.
Speaker 1: Chris Haigh
Speaker 2: TBD

Service providers play a pivotal role in helping contractors navigate the complexities of CMMC compliance, but the way you communicate about CMMC can make or break a client’s understanding and buy-in. This session focuses on how service providers can effectively frame the benefits of compliance while addressing the common concerns and opportunities that contractors face in the Defense Industrial Base (DIB).

We’ll cover:

  • Framing CMMC Positively: How to position CMMC compliance as an opportunity to enhance cybersecurity posture, win contracts, and safeguard critical data.
  • Talking Points That Resonate: Practical ways to explain why compliance is non-negotiable and the risks of non-compliance, including potential legal and financial repercussions.
  • Tailored Solutions: Strategies to present achievable pathways to compliance that align with a contractor’s resources, timeline, and business goals.
  • Building Trust Through Expertise: The importance of understanding the DoD’s evolving requirements, leveraging real-world examples, and acting as a trusted advisor in the compliance process.

This session equips service providers with actionable insights and conversation strategies to educate contractors on the value of CMMC, address objections, and guide them toward successful compliance outcomes.

VDI and CMMC: What Service Providers Need to Know Before Making a Recommendation

Thursday, May 22nd
Duration: 40 mins.
Speaker 1: Kenneth Benjamin
Speaker 2: TBD

For service providers, recommending Virtual Desktop Infrastructure (VDI) as part of a CMMC compliance strategy requires balancing security, cost, and user experience. In this session, we’ll explore how VDI can help centralize data and reduce compliance scope while addressing its potential challenges, including its impact on the end-user experience. You’ll learn how to evaluate whether VDI aligns with your clients’ needs and how to set realistic expectations for its implementation.

We’ll cover:

  • How VDI can enhance security and simplify compliance by centralizing control and securing endpoints.
    The critical role of user experience in VDI adoption, including potential frustrations with performance, latency, and accessibility.
  • Practical guidance for designing and deploying VDI solutions that balance compliance requirements with usability.
  • Real-world examples of successful VDI implementations—and cautionary tales where poor user experience derailed projects.

By the end of this session, you’ll have the insights to help your clients make informed decisions about VDI, ensuring their compliance efforts succeed without compromising the user experience.

Simplifying CMMC for Large Organizations and Higher Education Institutions

Thursday, May 22nd
Duration: 40 mins.
Speaker 1: TBD
Speaker 2: TBD

Managing CMMC compliance is no small feat for large organizations and Higher Education Institutions (HEIs). With complex IT systems, diverse departments, and collaborations with third-party vendors, ensuring compliance can feel overwhelming. For HEIs, the challenge is compounded by siloed projects with separate budgets and leadership, many of whom lack the bandwidth or understanding to navigate CMMC requirements effectively. This session provides practical strategies to streamline the compliance process while addressing these unique hurdles.

We’ll cover:

  • Overcoming Siloed Operations: How to align separate projects, budgets, and leadership teams under a unified compliance strategy.
  • NIST SP 800-53 Integration: Simplifying the incorporation of these requirements into your compliance framework while maintaining flexibility for diverse projects.
  • Automation and Centralized Tools: Leveraging technology to reduce manual efforts, simplify documentation and reporting, and ensure consistency across departments and systems.
  • Tailored Solutions for HEIs: Strategies for educating leadership, managing grant and research compliance, and balancing academic freedom with security requirements.
  • Building Sustainable Practices: Developing a compliance system that minimizes risk, adapts to changing federal regulations, and works across disparate teams and budgets.

By the end of this session, you’ll have actionable insights to build a scalable, sustainable compliance system that addresses the specific challenges of your organization—whether you're a large enterprise or a Higher Education Institution.

CMMC Encryption: Protecting CUI in IT Systems While Meeting Mission-Critical Needs

Friday, May 23rd
Duration: 30 mins.
Speaker 1: TBD
Speaker 2: TBD

Encryption is a foundational requirement for protecting Controlled Unclassified Information (CUI) under CMMC and NIST 800-171, particularly through SC.L2-3.13.11, which mandates the use of FIPS 140-2 validated encryption. While this requirement enhances security, its implementation across diverse IT systems—such as data storage, communication channels, and authentication—can be complex. This session breaks down the essentials for achieving encryption compliance without compromising system functionality or business operations.

We’ll cover:

  • A comprehensive overview of FIPS 140-2 validated encryption and its role in CMMC compliance.
  • Best practices for implementing FIPS-compliant encryption across IT systems, including data at rest, data in transit, and key management.
  • How to address challenges such as compatibility, performance impact, and cost considerations when applying encryption standards.
  • Clarifying SC.L2-3.13.11’s scope and its application to critical IT assets, including Security Protection Data (SPD).
  • Practical steps to align encryption practices with business objectives and compliance mandates.

This session offers actionable insights to help you implement encryption across your IT landscape, ensuring compliance while strengthening your organization’s security posture.

Building a Compliant, Consumable, and Referenceable SRM/CRM for Service Providers

Friday, May 23rd
Duration: 30 mins.
Speaker 1: TBD
Speaker 2: TBD

Developing a Shared Responsibility Matrix (SRM) and Customer Responsibility Matrix (CRM) is more than a compliance exercise—it’s an opportunity to clarify roles and responsibilities in ways that contracts often fail to do. For service providers, these tools are essential for aligning expectations with clients, minimizing disputes, and ensuring seamless compliance with frameworks like CMMC and NIST 800-171.

We’ll cover:

  • Compliance Alignment: How to design SRM/CRM frameworks that meet regulatory requirements without unnecessary complexity.
  • Consumable Design: Structuring matrices to clearly define “who is responsible for what,” making them actionable and intuitive for both providers and clients.
  • Resolving Ambiguity: Using SRM/CRM tools to reduce points of contention by providing clarity that contracts often lack.
  • Referenceability: Organizing matrices as a reliable source of truth for audits, client discussions, and operational reviews.
  • Sustainability: Maintaining and updating matrices to reflect evolving responsibilities and compliance needs.

This session offers practical strategies for service providers to create SRM and CRM tools that drive clarity, foster stronger client relationships, and ensure compliance while avoiding costly misunderstandings.

Supporting Contractors Through POA&M Remediation: Roles, Timelines, and Certification Success

Friday, May 23rd
Duration: 30 mins.
Speaker 1: TBD
Speaker 2: TBD

For service providers, guiding contractors through Plan of Action and Milestones (POA&M) remediation is critical to achieving CMMC certification. This session provides actionable insights for managing the complexities of remediation, including understanding the distinct roles of RPOs and C3PAOs, setting realistic timelines, addressing enduring exceptions, and preparing for reassessments or appeals.

Key Topics:

  • Clarifying Roles: Understand the boundaries of C3PAO involvement and the hands-on remediation services RPOs can provide.
  • Effective Timelines: Strategies for helping contractors establish and manage remediation timelines to avoid delays.
  • Enduring Exceptions: Practical approaches to identify, document, and handle enduring exceptions while maintaining compliance.
  • Reassessment Readiness: Best practices for transitioning from remediation to reassessment, whether with the same or a different C3PAO.
  • Appeals Support: Guidance on assisting contractors with gathering evidence and navigating the appeals process for unfavorable findings.

This session equips service providers with the tools and strategies needed to ensure contractors successfully remediate POA&Ms, address enduring exceptions, and stay on track for certification.

linkedin facebook pinterest youtube rss twitter instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter instagram