We are all in this together. Building a CMMC community does not happen by accident. It happens with intention. We are so grateful for your interest in traveling to CEIC West and sharing your knowledge.
In recognition of that, and with the intention of helping build the CMMC community, we are doing the following things in comparison to other conferences.
First, we are doubling the number of speakers, with a minimum of two per session. That does two things. It gives more people a chance to spend time on stage. And it also creates an opportunity for two knowledgeable speakers to collaborate to build their joint presentations. You get to know someone in a way that just isn't the same as "networking" because you'll be working together towards a common goal.
We also are adding nearly 1/3 more presentations. Most track sessions which were 60 minutes in the past will be 45 minutes now. That puts more people on stage, and it shows an awareness of our audience's ever shrinking, 2025, attention span.
To provide these additional opportunities, we are asking speakers to contribute to their registration by offering nearly 60% off the standard ticket price of $1195, with a flat registration fee of $500. This will help defray some of the costs for supporting what could be more than 60 speakers at the conference, while keeping audience ticket prices down.
We understand that this may be a burden for some speakers in our nascent industry. We don't want you and your ideas to be excluded. So, if you are selected and you require support beyond the discount, email [email protected] and we will work with you to make sure that you can attend.
Once again, our gratitude is deep for considering CEIC West as the venue to share your knowledge, and our anticipation for the event is palpable.
We'll see you in Vegas in May!
-Mark Berman
CEO, Forum Makers
Wednesday, May 21st
Duration: 30 mins.
Speaker 1: TBD
Speaker 2: TBD
Compliance with CMMC Level 1, mandated by FAR clause 52.204-21(b)(1), isn’t just a box to check—it’s a chance to unlock value for both contractors and service providers. For contractors, it provides an opportunity to strengthen operations and build trust with customers. For service providers, it’s a pathway to deepen client relationships and differentiate their offerings. This session explores how both groups can collaborate to implement Level 1 compliance in a way that drives not only security but also profitability.
We’ll explore:
This session will show you how compliance can be more than a mandate—it’s a bridge to stronger partnerships, more secure operations, and greater profitability for everyone involved.
Wednesday, May 21st
Duration: 30 mins.
Speaker 1: TBD
Speaker 2: TBD
The CMMC ecosystem demands skilled talent to meet compliance requirements, offering individuals a fast track to six-figure salaries while helping contractors and service providers succeed. But a single CCP class isn’t enough. This session explores how individuals, contractors, and service providers can collaborate to develop a workforce that drives compliance, fosters cybersecurity awareness, and builds resilience.
We’ll discuss:
This session equips individuals, contractors, and service providers with actionable strategies to align efforts, ensuring compliance success while strengthening and empowering the CMMC ecosystem.
Thursday, May 22nd
Duration: 40 mins.
Speaker 1: TBD
Speaker 2: TBD
The "Delta" Session
Get up to date with all of the rule changes since last December and those that are coming up:
Thursday, May 22nd
Duration: 40 mins.
Speaker 1: Robert Metzger facilitated by Mark Berman
Speaker 2: TBD
The Now and Future of CMMC under the Trump Administration
Thursday, May 22nd
Duration: 40 mins.
Speaker: Tom Bendien
Panelist 1: TBD
Panelist 2: TBD
Panelist 3: TBD
Panelist 4: TBD
Panelist 5: TBD
Artificial Intelligence (AI) is transforming how organizations approach compliance, offering powerful tools to streamline assessments, manage risks, and craft effective policies. But with these opportunities come critical questions: Where does AI truly add value, and where could it create unintended vulnerabilities? This split session will explore both the potential and the pitfalls of using AI in compliance for the Defense Industrial Base (DIB).
Part 1: AI in Action (with Tom Bendien)
Part 2: Panel Discussion
Join industry experts to discuss where AI should—and should not—be used in compliance.
This session challenges you to reframe your perspective on AI: not as a replacement for human judgment, but as a powerful tool for augmenting compliance efforts. Leave with practical insights into how AI can be responsibly leveraged to strengthen your compliance program while managing its inherent risks.
Thursday, May 22nd
Duration: 40 mins.
Speaker 1: Michael Gruden
Speaker 2: Kayli Keogh, Honeywell
Speaker 3: Jennie Von Cannon, DO
The influence of CMMC is growing rapidly, moving beyond its origins in the Department of Defense (DoD) to appear in RFPs and RFQs and impacting industries and governments worldwide. This session explores the expanding role of CMMC, providing practical insights for contractors and organizations navigating this evolving compliance landscape.
We’ll cover:
This session equips attendees with actionable knowledge to anticipate CMMC’s growing impact across industries and borders, helping organizations stay ahead in a world where compliance is becoming a critical competitive advantage.
Friday, May 23rd
Duration: 30 mins.
Speaker 1: Emery Csulak
Speaker 2: TBD
Speaker 3: TBD
The influence of CMMC is growing rapidly, moving beyond its origins in the Department of Defense (DoD) to appear in RFPs and RFQs and impacting industries and governments worldwide. This session explores the expanding role of CMMC, providing practical insights for contractors and organizations navigating this evolving compliance landscape.
We’ll cover:
This session equips attendees with actionable knowledge to anticipate CMMC’s growing impact across industries and borders, helping organizations stay ahead in a world where compliance is becoming a critical competitive advantage.
Friday, May 23rd
Duration: 75 mins.
Speaker 1: TBD
Speaker 2: TBD
What happens in the room during a CMMC assessment can make or break your compliance journey. This session combines a live mock assessment with strategic insights to prepare you for the Certification Assessment Process (CAP). You'll gain a comprehensive understanding of how assessments are conducted and learn how to approach them with confidence and precision.
The session kicks off with a 15-minute educational overview, covering:
The main event is a live, simulated mock assessment, featuring a fictitious Organization Seeking Certification (OSC) and a Certified Third-Party Assessor Organization (C3PAO) team.
You’ll experience:
This session delivers a practical, immersive experience that prepares you to navigate the CAP effectively, ensuring you’re equipped to handle the pace and expectations of a real CMMC assessment.
Wednesday, May 21st
Duration: 20 mins.
Speaker 1: TBD
Speaker 2: TBD
The world of CMMC is full of acronyms, jargon, and technical terms that can leave contractors feeling overwhelmed. In just 20 minutes, this session will break down the key terminology you need to know to navigate CMMC confidently. From understanding what terms like “FCI,” “CUI,” and “POA&M” to evolving ecosystem terms like "CCA", "OSC", "CCP", "RPO", "RP", PI", "LTP", technical terms like "FIPS" and so many more. We’ll cut through the complexity to give you a clear understanding of the language of compliance.
You’ll learn:
Wednesday, May 21st
Duration: 60 mins.
Speaker 1: TBD
Speaker 2: TBD
Scoping for CMMC is a high-stakes balancing act. Done right, it reduces costs, simplifies IT, and minimizes training overhead by isolating compliance efforts to a controlled enclave. But done wrong, it can introduce unexpected risks, create unmanageable complexity, and leave critical data—like CAD vaults in manufacturing—vulnerable.
This session explores the fine line between efficiency and exposure, walking through the risks of over-scoping (wasted resources) and under-scoping (compliance failures and security gaps). We’ll also delve into strategies for establishing strong boundaries between the enclave and the rest of your organization, ensuring only authorized people and devices access the protected environment. With real-world examples of scoping missteps and successes, this talk equips you with the tools to scope smart, not risky.
Key Takeaways:
Wednesday, May 21st
Duration: 40 mins.
Speaker 1: TBD
Speaker 2: TBD
As a contractor, your ability to achieve and maintain CMMC compliance often depends on the service providers you rely on—your MSPs, MSSPs, and CSPs. Equally important is your choice of a Certified Third-Party Assessment Organization (C3PAO) to certify your compliance. But how can you tell if these partners are delivering a complete solution or leaving critical gaps that could cost you time, money, and compliance?
This session will help you evaluate your service providers’ offerings and your options for selecting the right C3PAO.
We’ll cover:
Service Providers:
Selecting a C3PAO:
By the end of this session, you’ll be equipped to vet your service providers effectively, select the right C3PAO, and hold all your partners accountable for helping you achieve and maintain CMMC compliance without surprises.
Thursday, May 22nd
Duration: 40 mins.
Speaker 1: Michael Gruden
Speaker 2: Jennie Von Cannon, DOJ
Speaker 3: TBD
Since the Civil Cyber Fraud Initiative, the Department of Justice has brought forth endless cases and penalties against companies that fail to implement cybersecurity requirements. Join former Department of Justice cybersecurity prosecutor and former Pentagon IT Acquisition Branch Chief Michael Gruden, now both cybersecurity Partners at Crowell & Moring LLP, as they discuss the key cybersecurity gaps and omissions the government has enforced in CCFI cases and which CMMC controls are most commonly affected. During this robust conversation, common CMMC control vulnerabilties will be addressed and considerations to harden potential gaps.
Thursday, May 22nd
Duration: 40 mins.
Panelist 1: TBD
Panelist 2: TBD
Panelist 3: TBD
Panelist 4: TBD
Panelist 5: TBD
With the CMMC Assessment Process (CAP) newly published in December, everyone is navigating an evolving compliance landscape. This panel brings together diverse perspectives from:
Panelists will share lessons learned from the JVSA process, insights into what went right and wrong, and strategies to apply these experiences to your C3PAO-based certification. You'll also gain practical tips on managing variances in C3PAO criteria, leveraging data governance to control costs, and preparing for success in a rapidly changing compliance environment.
Thursday, May 22nd
Duration: 30 mins.
Speaker 1: TBD
Speaker 2: TBD
This session focuses on the practical application of CEIC West insights to document and prepare the body of evidence for two specific CMMC controls—one simple and one complex. Attendees will learn how to create compliance statements for each control objective and assemble the evidence required for the Examine, Interview, and Test phases of an assessment.
We’ll cover:
This session provides a detailed walkthrough of how to effectively document and prepare evidence for two controls, giving attendees the tools to ensure their body of evidence meets assessment standards.
Friday, May 23rd
Duration: 30 mins.
Speaker 1: Mike Bramm
Speaker 2: TBD
How to keep the momentum on the CMMC process
Wednesday, May 21st
Duration: 20 mins.
Speaker 1: TBD
As the CMMC ecosystem evolves, staying certified requires service providers to stay ahead of critical updates from CAICO. One of the most important developments is the introduction of "delta" training, designed to bridge the gap for professionals who completed certification before the CMMC rule release. This session will provide an essential update on CAICO's training oversight, certification pathways, and the implications for service providers.
You’ll learn:
This session equips you with the knowledge to stay certified, support your clients effectively, and ensure your organization remains competitive in the CMMC ecosystem.
Wednesday, May 21st
Duration: 60 mins.
Speaker 1: TBD
Speaker 2: TBD
Thriving as an External Service Provider (ESP) or C3PAO in the CMMC Market
Thriving as an External Service Provider (ESP) in the CMMC market isn’t just about delivering great technical services—it’s about mastering compliance, managing costs, and building trust with your clients. Whether you’re an MSP, MSSP, CSP, or aspiring to become a Certified Third-Party Assessment Organization (C3PAO), understanding how to align your services with CMMC requirements is critical to staying competitive and profitable. This session focuses on the practical, real-world steps ESPs and C3PAOs need to take to succeed in this challenging market.
For External Service Providers (ESPs):
For C3PAOs:
This session provides a no-nonsense look at what it takes to not just survive, but thrive, in the CMMC ecosystem as a trusted, profitable ESP or C3PAO.
Wednesday, May 21st
Duration: 40 mins.
Speaker 1: Noel Vestal
Speaker 2: TBD
Speaker 3: TBD
When it comes to CMMC compliance, your policies, procedures, and documentation are your first—and often most critical—line of defense. But what does "good" actually look like? This session dives into the practical strategies and lessons learned from real-world assessments to help you build documentation that not only satisfies assessors but also supports your organization’s long-term success.
We’ll cover:
Join a certified C3PAO assessor and a DIB company representative as they break down what works, what doesn’t, and how you can turn your documentation into a competitive advantage. Whether you’re just starting or fine-tuning your approach, this session will leave you with actionable steps to streamline your compliance journey.
Wednesday, May 21st
Duration: 40 mins.
Speaker 1: Terrence "Terry" McGraw
Speaker 2: TBD
In recent years, the cybersecurity industry has been characterized by what economists term as a "market for lemons," where the quality of security products and services often remains opaque to buyers, leading to a market dominated by potentially substandard offerings. This talk will explore how this asymmetric information problem in cybersecurity parallels George Akerlof's classic "Market for Lemons" theory, where buyers cannot discern the quality of products, leading to market failure.
We will discuss how the introduction of the Cybersecurity Maturity Model Certification (CMMC) program by the U.S. Department of Defense aims to address these issues by standardizing and verifying the cybersecurity practices of its contractors. The CMMC framework is designed to increase transparency and trust by certifying companies based on their cybersecurity maturity levels, thereby ensuring that those handling sensitive information meet certain security standards.
However, the sustainability of CMMC's effectiveness hinges on its own transparency and rigor. This presentation will analyze the challenges the CMMC must overcome to avoid becoming another "market for lemons" itself, including maintaining impartiality in assessments, ensuring assessor competence, and adapting to evolving cyber threats. We'll examine the potential pitfalls if these standards are not upheld and explore how continuous oversight, public scrutiny, and stakeholder engagement can safeguard the integrity of the CMMC process.
This talk will offer insights into how the cybersecurity landscape can evolve from a market of lemons into one where quality, trust, and transparency prevail, with CMMC potentially leading the way, provided it adheres to its foundational principles of high standards and transparenc
Thursday, May 22nd
Duration: 40 mins.
Speaker 1: Chris Haigh
Speaker 2: TBD
Service providers play a pivotal role in helping contractors navigate the complexities of CMMC compliance, but the way you communicate about CMMC can make or break a client’s understanding and buy-in. This session focuses on how service providers can effectively frame the benefits of compliance while addressing the common concerns and opportunities that contractors face in the Defense Industrial Base (DIB).
We’ll cover:
This session equips service providers with actionable insights and conversation strategies to educate contractors on the value of CMMC, address objections, and guide them toward successful compliance outcomes.
Thursday, May 22nd
Duration: 40 mins.
Speaker 1: Kenneth Benjamin
Speaker 2: TBD
For service providers, recommending Virtual Desktop Infrastructure (VDI) as part of a CMMC compliance strategy requires balancing security, cost, and user experience. In this session, we’ll explore how VDI can help centralize data and reduce compliance scope while addressing its potential challenges, including its impact on the end-user experience. You’ll learn how to evaluate whether VDI aligns with your clients’ needs and how to set realistic expectations for its implementation.
We’ll cover:
By the end of this session, you’ll have the insights to help your clients make informed decisions about VDI, ensuring their compliance efforts succeed without compromising the user experience.
Thursday, May 22nd
Duration: 40 mins.
Speaker 1: TBD
Speaker 2: TBD
Managing CMMC compliance is no small feat for large organizations and Higher Education Institutions (HEIs). With complex IT systems, diverse departments, and collaborations with third-party vendors, ensuring compliance can feel overwhelming. For HEIs, the challenge is compounded by siloed projects with separate budgets and leadership, many of whom lack the bandwidth or understanding to navigate CMMC requirements effectively. This session provides practical strategies to streamline the compliance process while addressing these unique hurdles.
We’ll cover:
By the end of this session, you’ll have actionable insights to build a scalable, sustainable compliance system that addresses the specific challenges of your organization—whether you're a large enterprise or a Higher Education Institution.
Friday, May 23rd
Duration: 30 mins.
Speaker 1: TBD
Speaker 2: TBD
Encryption is a foundational requirement for protecting Controlled Unclassified Information (CUI) under CMMC and NIST 800-171, particularly through SC.L2-3.13.11, which mandates the use of FIPS 140-2 validated encryption. While this requirement enhances security, its implementation across diverse IT systems—such as data storage, communication channels, and authentication—can be complex. This session breaks down the essentials for achieving encryption compliance without compromising system functionality or business operations.
We’ll cover:
This session offers actionable insights to help you implement encryption across your IT landscape, ensuring compliance while strengthening your organization’s security posture.
Friday, May 23rd
Duration: 30 mins.
Speaker 1: TBD
Speaker 2: TBD
Developing a Shared Responsibility Matrix (SRM) and Customer Responsibility Matrix (CRM) is more than a compliance exercise—it’s an opportunity to clarify roles and responsibilities in ways that contracts often fail to do. For service providers, these tools are essential for aligning expectations with clients, minimizing disputes, and ensuring seamless compliance with frameworks like CMMC and NIST 800-171.
We’ll cover:
This session offers practical strategies for service providers to create SRM and CRM tools that drive clarity, foster stronger client relationships, and ensure compliance while avoiding costly misunderstandings.
Friday, May 23rd
Duration: 30 mins.
Speaker 1: TBD
Speaker 2: TBD
For service providers, guiding contractors through Plan of Action and Milestones (POA&M) remediation is critical to achieving CMMC certification. This session provides actionable insights for managing the complexities of remediation, including understanding the distinct roles of RPOs and C3PAOs, setting realistic timelines, addressing enduring exceptions, and preparing for reassessments or appeals.
Key Topics:
This session equips service providers with the tools and strategies needed to ensure contractors successfully remediate POA&Ms, address enduring exceptions, and stay on track for certification.