Loading Events

Events

The CMMC 2.0 Paradigm and Contractor Supply Chain Risk Management Obligations

Since January 2018, the Defense Department (and now other agencies) has required prime contractors and subcontractors at all tiers to implement NIST SP 800-171, “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations.” Between January 2018 and November 2021, the Defense Department issued numerous guidance memoranda regarding NIST-171 and set up an arrangement with the Cybersecurity Maturity Model Certification – Accreditation Board. In turn, the CMMC-AB developed a “CMMC ecosystem” based on NIST-171 and related NIST guidance in order to identify NIST-171 cybersecurity objectives intended for contractors and subcontractors who handle, create or store “controlled unclassified information” or CUI. A significant element of this ecosystem was the creation of an infrastructure which facilitates education, training and third-party assessment leading to the certification of a DIB company’s implementation of CMMC 1.0 compliance.

The Defense Department paused implementation of the CMMC 1.0 program by introducing CMMC 2.0 through an Advanced Notice of Proposed Rulemaking published November 4, 2021. DoD did not pause compliance with FAR 52.204-2 or DFARS 252.204-7012.

Your company’s level of CMMC 2.0 “cyber hygiene” will directly impact your eligibility to contract or subcontract with the Defense Department (and likely non-DoD agencies such as the GSA and the DHS) as well as impact your competitive posture anywhere in the DoD supply or service chain.

In this Program, you will learn about:

  • The prospective CMMC 2.0 schedule;
  • Federal cybersecurity vocabulary: CUI, FCI, CDI, CTI;
  • CUI marking obligations by government personnel and contractor personnel
  • How CMMC 2.0 “Level 1” (the foundational level) effectively applies to all federal agencies;
  • The requirements of FAR 52.204-21 and DFARS 252.204-7012 and the current DFARS 252.204-7019, 7020, and 7021 clauses;
  • DoD’s Assessment Methodology;
  • The Supplier Performance Risk System (SPRS);
  • The DoD guidance available to achieve CMMC 2.0 Level 1 and Level 2 (the advanced level);
  • The available self-assessment programs;
  • The requirements under [Draft] NIST SP 800-172 contained in CMMC Level 3 to address Advance Persistent Threats;
  • The quality of a System Security Plan and the CMMC 2.0 emphasis of a Plan of Action & Milestones)
  • CMMC 2.0, the Cloud and FedRAMP;
  • The government-wide supply chain obligations regarding Chinese sources
    • DoD guidance
    • GSA guidance
  • DoD supply chain obligations regarding Chinese and Russian sources
    • DoD guidance
Register Now

Event Date March, 3

Event Time 5:30am - 7:00am

Featured News

March 30, 2026

Blue Sky Innovators Invests $7 million to Expand Operations in Fairfax County

Blue Sky Innovators, Inc., a dual-use technology company delivering insight to operations for government and commercial customers, will invest $7 million to expand its footprint in Fairfax County, Virginia. The expansion will support the creation of 175 new jobs and the buildout of approximately 20,000 square feet of secure innovation and laboratory space above its existing office at 12120 Sunset Hills Road, Reston. The expanded facility will house SkyLab, a secure, collaborative innovation environment purpose-built to accelerate advanced research, rapid prototyping,…
Read More
March 11, 2026

FCEDA’s 2026 Tech and Cyber Hiring Event Draws Record Attendance, Connecting Talent to Critical Hiring Needs

At Capital One Hall in Tysons, the Fairfax County Economic Development Authority (FCEDA) celebrated record-breaking attendance for this year’s Tech and Cyber Networking and Hiring event on January 22, 2026. Forty employers met with hundreds of job seekers from across the region, bringing together talent from a wide range of backgrounds and experience, including those holding active security clearances. Employers connected with transitioning federal workers and contractors, veterans, and students choosing to take the next step in their careers. One attendee shared her…
Read More
February 23, 2026

FCEDA President and CEO Victor Hoskins Will Return to Private Sector This Fall

Fairfax County, VA – The Fairfax County Economic Development Authority (FCEDA) Commission announced today that President and CEO Victor Hoskins will be returning to the private sector this fall, concluding an extraordinary era of visionary leadership. During his six-year tenure, Hoskins elevated Fairfax County’s global competitiveness, drove significant investment and job growth, and strengthened the County’s position as the economic engine of the region. “Victor Hoskins has been an exceptional economic leader for Fairfax County and a strategic force for…
Read More