Loading Events

Events

The CMMC 2.0 Paradigm and Contractor Supply Chain Risk Management Obligations

Since January 2018, the Defense Department (and now other agencies) has required prime contractors and subcontractors at all tiers to implement NIST SP 800-171, “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations.” Between January 2018 and November 2021, the Defense Department issued numerous guidance memoranda regarding NIST-171 and set up an arrangement with the Cybersecurity Maturity Model Certification – Accreditation Board. In turn, the CMMC-AB developed a “CMMC ecosystem” based on NIST-171 and related NIST guidance in order to identify NIST-171 cybersecurity objectives intended for contractors and subcontractors who handle, create or store “controlled unclassified information” or CUI. A significant element of this ecosystem was the creation of an infrastructure which facilitates education, training and third-party assessment leading to the certification of a DIB company’s implementation of CMMC 1.0 compliance.

The Defense Department paused implementation of the CMMC 1.0 program by introducing CMMC 2.0 through an Advanced Notice of Proposed Rulemaking published November 4, 2021. DoD did not pause compliance with FAR 52.204-2 or DFARS 252.204-7012.

Your company’s level of CMMC 2.0 “cyber hygiene” will directly impact your eligibility to contract or subcontract with the Defense Department (and likely non-DoD agencies such as the GSA and the DHS) as well as impact your competitive posture anywhere in the DoD supply or service chain.

In this Program, you will learn about:

  • The prospective CMMC 2.0 schedule;
  • Federal cybersecurity vocabulary: CUI, FCI, CDI, CTI;
  • CUI marking obligations by government personnel and contractor personnel
  • How CMMC 2.0 “Level 1” (the foundational level) effectively applies to all federal agencies;
  • The requirements of FAR 52.204-21 and DFARS 252.204-7012 and the current DFARS 252.204-7019, 7020, and 7021 clauses;
  • DoD’s Assessment Methodology;
  • The Supplier Performance Risk System (SPRS);
  • The DoD guidance available to achieve CMMC 2.0 Level 1 and Level 2 (the advanced level);
  • The available self-assessment programs;
  • The requirements under [Draft] NIST SP 800-172 contained in CMMC Level 3 to address Advance Persistent Threats;
  • The quality of a System Security Plan and the CMMC 2.0 emphasis of a Plan of Action & Milestones)
  • CMMC 2.0, the Cloud and FedRAMP;
  • The government-wide supply chain obligations regarding Chinese sources
    • DoD guidance
    • GSA guidance
  • DoD supply chain obligations regarding Chinese and Russian sources
    • DoD guidance
Register Now

Event Date March, 3

Event Time 5:30am - 7:00am

Featured News

June 10, 2026

Applied Atomics Emerges from Stealth with More Than $500 Million in Demand Commitments to Build Star Reacher Network, the Next Infrastructure Layer of the Space Economy

Fairfax County, Virginia — Applied Atomics, a transatlantic aerospace and defense company building Star Reacher Network, the first in-space mobility network, emerged from stealth and entered the U.S. market today with more than $500 million in letters of intent and memoranda of understanding, a $4 million, oversubscribed pre-seed financing round led by Oxford Science Enterprises, an a growing portfolio of partnerships spanning the United States, Europe, and the United Kingdom. “The biggest constraint in space is no longer getting there,…
Read More
June 9, 2026

Scout Space Announces $1 Million Investment to Expand Manufacturing Capacity in Fairfax County

Fairfax County, VA – Scout Space, a technology company specializing in sensors and software deployed on satellite systems, today announced plans to invest more than $1 million to expand the company’s operations in Fairfax County, creating 31 new jobs. Expanding its footprint beyond its existing location in Reston, Scout Space will add 2,650 square feet of space with its new manufacturing facility in Merrifield. “Fairfax County offers an exceptional environment for innovation, talent, and collaboration, making it the ideal location…
Read More
June 9, 2026

10 Fairfax County Headquartered Companies Make the 2026 Fortune 500 Rankings

Fairfax NOVA remains strong in the 2026 Fortune 500 rankings, with 10 Fairfax-headquartered companies listed among the largest publicly traded corporations in the United States. Among the most notable additions is Amentum, which debuted at #313 with $14.4B in revenue following its public launch in late 2024. Amentum’s Fortune 500 debut highlights the continued growth and prominence of the region’s aerospace, defense, and government contracting sector. The company joins a strong roster of Fairfax NOVA-based industry leaders on the list, including Freddie Mac…
Read More