CS5

Draft Agenda

Global Conference Session Report
Generated: August 7, 2025

Table of Contents

General Session 4 sessions

Cyber AB Ecosystem Update
DoD CMMC Update
CMMC vs IRGC: Iranian Cyber Threats
Mock Assessment - Assessor's Point of View

Contractor Track 6 sessions

A Non-Technical Guide to Scoping
CMMC Journey - Start to Certified
Supply Chain Demands under CMMC
You Can't Do That with Your ESP
If It's Not Documented, It Didn't Happen
The AI Session - The World is Changing

Service Provider Track 6 sessions

The Most Misunderstood Aspects of CMMC
Tool or Trap? How to Evaluate Compliance Tech
From Self-Attestation to C3PAO Audit
ESP | MSP | CSP - The Definitive Session
The CCP Illusion
Leveraging the Secure Controls Framework

Rejected 3 sessions

Control Responsibility vs. Applicability
Prime and Sub Contractor under one Umbrella
The Cost of Delay: How Non-Compliance Blocks Revenue

Pre-Conference Training 1 session

Executive Forum: Pre-Conference Training

General Session

4 Sessions • 4 Slots
General Session

Cyber AB Ecosystem Update

Spotlight Briefing — Matt Travis on "CMMC After Title 48: Reality, Readiness, and Results"

Session format: 30-minute executive update

Opening remarks: Mark Berman, CEO, Forum Makers LLC (producers of CS5)

Fresh from steering the CMMC ecosystem through Title 48, Matt Travis, CEO of the Cyber AB, delivers a brisk, data-rich briefing that turns regulatory uncertainty into a practical game plan for every defense contractor—from primes to the smallest subs.

What you'll learn

You'll leave with clear numbers, realistic timelines, and focused insights ready for immediate discussion with your leadership team.

Applicants
Matt Travis - Cyber AB
General Session

DoD CMMC Update

Keynote Briefing — "Title 48 Unveiled: CMMC's Next Chapter"

Expected to be fresh from the Federal Register, the new Title 48 rule rewires DoD acquisition and raises the stakes for every defense contractor. In this 90-minute October session, the DoD Chief Information Officer and the head of the CMMC PMO deliver the first authoritative roadmap for navigating the changes.

What they'll cover

A concise joint briefing followed by an extended, moderated Q&A puts your toughest questions straight to the policymakers shaping CMMC's future—equipping executives, program managers, and cybersecurity leads to turn Title 48 from uncertainty into advantage.

Applicants
Katie Arrington - U.S. Department of Defense
General Session

CMMC vs IRGC: How effective is cyber compliance against Iranian cyber threats?

Want to disrupt Iranian nuclear facilities? Send a few stealth bombers. Want to disrupt American stealth bombers? Disrupt the supply chain. While the B-2 Spirit and the B-21 Raider are the tip of the spear, supply chain cybersecurity is our Achilles' Heel.

But how to infiltrate thousands of suppliers spread across nearly every U.S. state a world away? Easy: cyber - a key leverage point for the adversary because it is an afterthought for so many defense contractors.

This presentation will examine how effective CMMC is at mitigating the risks posed by Iranian Advanced Persistent Threats and how Department of Defense cyber requirements can adapt to the threat moving forward.

Applicants
Jacob Horne - Summit 7
General Session

Mock Assessment - Intro: Assessor's Point of View; Bonus: Assessing SCF

Expand your knowledge and skills in assessors, point, view through this educational journey. This educational session explores Updated version of the presentation form The presenter 2024 Id like to attend an extended session where CMMC assessors walk us through a mock assessment simulating what a real The presenter 2 evaluation looks like.

This would be a great opportunity to see how assessors approach the process, what types of evidence they expect, and how they evaluate some of the more challenging controls.

It would be especially helpful to focus on domains like The presenter (AC). where requirements such as enforcing least privilege, managing account access, and using multifactor authentication can be difficult to use and prove.

Id also like to see how assessors review documentation like The presenter Plans (SSPs), verify log monitoring, and evaluate whether controls are actually institutionalized not just written down.

The goal is to better understand how to prepare, what to expect, and where most organizations struggle, directly from the perspective of experienced assessors.

A session like this would provide valuable insight into how to close gaps before a formal assessment and give attendees more confidence in navigating the CMMC process.

Applicants
Matthew Titcombe - Peak InfoSec
Anwelle Serrano - Anyar, Inc.

Contractor Track

6 Sessions • 6 Slots
Contractor Track • Panel

A Non-Technical Guide to Scoping

Scoping shouldn't feel like spelunking through server racks. This fast-paced, plain-English session demystifies the single most misunderstood step in CMMC and other cybersecurity frameworks: figuring out exactly what's in scope, what's out, and why it matters to your bottom line.

Why attend?

Whether you're a CEO budgeting for compliance, a program manager herding silos, or an engineer forced to explain "why that printer counts," you'll leave with the confidence to draw the right lines—and keep them solid—as your business grows. Come for the clarity, stay for the war stories, and walk out ready to scope once, certify faster, and sleep better.

Applicants
Scott Singer - CyberNINES
Bill Wootton - C3 Integrated Solutions and DEFCERT
RJ Williams - Indirect IT
Contractor Track • Panel

CMMC Journey - Start to Certified

Maximizing Each Hour Spent & Each Dollar Burned

When every week on the calendar and line on the budget matters, how do you move from CMMC planning to a fully compliant organization without draining resources? This session answers that question with a battle-tested playbook for squeezing maximum value out of every task, meeting, and dollar along your CMMC journey.

What we'll cover

Whether you're a program manager hunting for efficiencies, a finance lead guarding cash flow, or a CISO orchestrating both, you'll leave with a clear roadmap to deliver compliance on schedule—and on budget—while positioning your organization for future growth.

Applicants
Fred Tschirgi - LRQA
Prabhat Nigam - Golden Five LLC
Brian Rhodes - LRQA
David Bedard - KTL Solutions, Inc.
Carter Schoenberg - SoundWay
Matt Katzer - KAMIND
Contractor Track • Panel

Supply Chain Demands under CMMC

The Two-Way Pain of Flowdown

With Title 48 expected to be finalized by October 2025, keeping suppliers and subcontractors aligned with CMMC and DFARS 252.204-7020/7021 will be a contractual must for every prime contractor. In this panel discussion, supply-chain leads from major defense primes and veteran CMMC advisors outline what large contractors are already asking for and what lower-tier companies must be ready to deliver as final rules take effect.

Discussion highlights

Attendees will gain a clear view of the prime-contract expectations coming with Title 48, the most common pitfalls seen in 2025 audits, and practical steps to keep their supplier chain—and their revenue stream—secure, compliant, and ready for the next contract cycle.

Applicants
Teri Lamie - Skilled Manufacturing Inc
Amy Feldman - RSM US LLP
Contractor Track • Panel

You Can't Do That with Your ESP

Untangling the Truth Behind External Service Provider Promises

External Service Providers (ESPs) can accelerate a CMMC program, but they don't erase your accountability—or an assessor's scrutiny. In this frank panel, a veteran CMMC assessor, an ESP executive, a contracts attorney, and a defense-industry OSC unpack the promises, limits, and documentation every organization must nail down before handing off critical controls.

What the panel will cover

You'll leave with a concise checklist for vetting ESPs, verifying CRMs, and keeping provider support aligned with your obligations—so your organization stays compliant, contract-ready, and firmly in control.

Applicants
Amy Williams - Coalfire Federal
Kevin Mann - Resilient IT
RJ Williams - Indirect IT
Jason Sproesser - Summit 7 Systems
Contractor Track • Panel

If It's Not Documented, It Didn't Happen

The Culture Shift Behind CMMC

CMMC audits live and die on written evidence. Controls may be rock-solid in practice, but if policies, procedures, and activity logs aren't captured and organized, assessors must score them Not Met. This session shows how successful primes and resource-strapped SMBs have transformed "paperwork" into a routine operational output—eliminating last-minute scrambles and costly rework.

Session highlights

Leave with a clear picture of how "write it down, organize it, prove it" becomes second nature—securing certifications, protecting schedules, and freeing your team to focus on real security work.

Applicants
RJ Williams - Indirect IT
Arnold Villeneuve - Achieva Tech Incorporated
Contractor Track • Panel

The AI Session. The World is Changing. So is Compliance.

Do's, Don'ts and Imagination. (and a few other leading edge technologies)

Large-language models can draft policies, summarize logs, and spot data anomalies in seconds—but they'll also invent citations, skip edge-cases, and present an 80 percent answer with 100 percent confidence. CMMC assessors will grade you on the missing 20. This session shows how forward-leaning defense contractors are harnessing artificial intelligence without surrendering accuracy, accountability, or budget.

In 50 minutes we'll cover

Expect candid do's, don'ts, and imaginative next steps—from choosing AI copilots that log every prompt to setting up review queues that turn risky suggestions into assessor-ready artifacts. Leave with a blueprint for faster audits and fewer findings, built on technology you trust and evidence you can prove.

Applicants
Justin Hensley - CloudFit Software
Noel Vestal
Timothy Miller - MF Cyber
Brent Stinar - Technology & Business Solutions LLC

Service Provider Track

6 Sessions • 6 Slots
Service Provider Track • Panel

The Most Misunderstood Aspects of CMMC What MSPs and OSCs Keep Getting Wrong

You manage firewalls, patch fleets, and monitor SIEMs for defense contractors—yet an assessor can still hand your client a Not Met and send everyone back to square one. Why? Because CMMC success hinges as much on how you frame the work as on the work itself. This session flips the script to focus on the missteps service providers most often make when guiding organizations seeking certification (OSCs).

If you're an MSP, MSSP, RPO, or any external team supporting the defense industrial base, this session will sharpen your strategy, tighten your evidence trail, and position both you and your clients for first-pass success.

Applicants
Brian Kirk - Cherry Bekaert Advisory LLC
Ali Pabrai - ecfirst, Inc.
Jason Spencer - GuidePoint Security LLC
RJ Williams - Indirect IT
Brian Hubbard - Evolved Cyber, LLC
John Igbokwe - TechAxia
Service Provider Track • Panel

Tool or Trap? How to Evaluate Compliance Tech

Dashboards that "auto-map" controls, AI engines that "close" POA&Ms, one-click platforms that "solve CMMC." The market is overflowing with products that promise effortless compliance—yet a poor choice can drain budgets, distort scope, and leave gaps an assessor will spot in minutes. This session equips service providers and OSCs with a vendor-agnostic checklist for separating genuine enablers from costly distractions.

Leave with a practical evaluation matrix and the confidence to ask tough questions—so every tool you adopt accelerates compliance and generates management insight instead of becoming your next expensive trap.

Applicants
RJ Williams - Indirect IT
Service Provider Track • Panel

From Self-Attestation to C3PAO Audit: Legal Risks and False Claims Act Exposure

The False Claims Act (FCA) empowers whistleblowers to sue on the government's behalf when they believe a contractor is committing fraud—recovering billions for taxpayers every year. Amid persistent confusion over CMMC, CUI handling, and cybersecurity in general, FCA filings have climbed steadily, and the DOJ's Civil Cyber-Fraud Initiative is accelerating that trend. With Title 48, new DFARS clauses, and a forthcoming FAR CUI rule set to make third-party certification the norm by October 2025, legal exposure for both primes and service providers is poised to spike.

This legal-centric briefing—delivered by government-contract attorneys, former DOJ cyber-fraud prosecutors, and veteran C3PAO assessors—breaks down the latest enforcement data, average settlement figures, and hard-won lessons every contractor and managed service provider needs before their next audit.

Applicants
James Goepel - Fathom Cyber LLC
Joanna Valencia - Summit 7 Systems
Amy Williams - Coalfire Federal
Service Provider Track • Panel

ESP | MSP | CSP - The Definitive Session: Regs, Offerings, Pricing and Profitability

Title 48, DFARS 7020/7021, and the coming FAR CUI rule have thrust service providers onto the front line of CMMC compliance. This session gives providers the playbook to stay profitable while meeting assessor and legal scrutiny.

Hear candid insights from competing MSP leaders, a CMMC assessor, and a contracts attorney—so you can refine offerings, draft stronger CRMs, and navigate the compliance minefield with confidence.

Applicants
Stuart Itkin - MSP Collective
Joy Beland - MSP Collective
Bobby Guerra - Axiom
Kevin Mann - Resilient IT
Jim Johnson - Safran Electrical and Power
Service Provider Track • Panel

The CCP Illusion: Where Certification Ends and Experience Begins

AND... the case for contractors to have their own CCP

The CMMC Certified Professional (CCP) badge is marketed as the on-ramp to assessment teams and consulting roles—yet many new holders discover that real-world credibility demands far more than exam scores. This session dissects the gap between certification and practice, then shows how to turn the CCP into tangible career leverage.

Hear candid insights from CCP holders, OSC security leads, and C3PAO hiring managers who have navigated the reality check—so you can transform a certificate into a thriving career, not a paper credential.

Applicants
Charnice Tatum - Quinn Technology Solutions
Rachel Bassford - EMCOR Government Services
Service Provider Track • Single Speaker

Leveraging the Secure Controls Framework (SCF)

With CMMC live since December 16 2024—and the complementary 48 CFR acquisition rule slated for release this fall—defense contractors now juggle CMMC alongside ISO 27001, NIST CSF, HIPAA, PCI-DSS, and more. Maintaining separate policies and evidence sets for each mandate wastes time and money. The Secure Controls Framework (SCF) fixes that by unifying requirements into a single, outcome-focused control library.

Whether you're an OSC chasing CMMC certification or a service provider supporting multiple frameworks, you'll learn how to deploy SCF to synchronize controls, reduce effort, and future-proof your compliance program.

Applicants
Fernando Machado - Cybersec Investments

Rejected

3 Sessions
Rejected

Control Responsibility vs. Applicability: The Most Important Cost/LOE Factor

This overlooked topic can make or break your budget. Learn how to analyze whether you truly need to implement a control—and if so, who owns it. Mastering this distinction will streamline documentation and cut your consulting or engineering bill in half.

Applicants
RJ Williams - Indirect IT
Rejection Reason
Not sure I get it.
Rejected

Prime and Sub Contractor under one Umbrella & one CMMC certification

This session share how prime and sub contractors can live under one CMMC certification. This session will help OSC to allow sub contractors work under Prime CMMC certification.

Attendees will learn how can they save the cost by living under prime's infrastructure using Sub-contractors enclave. Prime will learn how can they allow subs in their infrastructure and the costing around it.

Starting point is a challenge of losing sub-contractors who are unique and special in their profession but not willing to invest in the CMMC certification. Destination is show case a way of cost saving and still performing their job and staying compliant. Same for prime for still kicking is an option which is available.

This will be a deep dive session on explaining every configuration in detail with costing over the slideshow.

Applicants
Prabhat Nigam - Golden Five LLC
Rejection Reason
Seems crazy and misleading.
Rejected

The Cost of Delay: How Non-Compliance Blocks Revenue

Learn how your current cyber posture may be blocking future contracts, primes, or revenue from higher-tier DoD engagements. Ideal for BD, sales, and executive leadership.

Applicants
RJ Williams - Indirect IT
Rejection Reason
Not enough meat on the bone.

Pre-Conference Training

1 Session • 4 Slots
Pre-Conference Training

Executive Forum: Pre-Conference Training

CMMC Executive Forum – Leading Cybersecurity From the Boardroom

In today's defense-industrial base, Cybersecurity Maturity Model Certification (CMMC) is no longer a technical project—it is a board-level, business-critical mandate. Without clear executive ownership, even the most capable IT teams struggle to implement the 110 NIST 800-171 controls, maintain continuous monitoring, and fund the people and processes required for sustained compliance. This masterclass equips senior leaders with the language, metrics, and mindset to champion CMMC as a strategic advantage rather than a regulatory burden.

Why Attend

What You Will Experience

This interactive forum blends executive-level briefing with practical, real-world scenarios drawn from years of consulting inside prime contractors, subcontractors, and emerging tech suppliers:

Expert Faculty

Your lead facilitator is a nationally recognized CMMC thought leader who has helped organizations of all sizes improve real security while satisfying compliance. Backed by guest panelists from Fortune 500 defense primes and breakthrough small businesses, this team brings board-level gravitas and field-tested advice—not theory.

Key Takeaways

Who Should Attend

CEOs, CFOs, COOs, General Counsel, board directors, private-equity partners, and any executive tasked with protecting revenue, reputation, and mission-critical data while navigating the evolving CMMC landscape.

Join us to transform CMMC from a compliance expense into a competitive differentiator. Lead the cultural overhaul your customers—and regulators—now expect.

Applicants
Jeffrey Smedley - Nspire Group, Inc.
Chuck Orlowski - Former GE Vernova Advanced Research CISO/BISO
RJ Williams - Indirect IT
Stuart Itkin - FutureFeed
Jerry Leishman - CMMC Advisors