Cyberspin

Redspin

A podcast to help you navigate CMMC.

  1. JAN 30

    January 2026 CMMC Connect

    CMMC is moving fast, and the questions from the DIB are getting more specific... In this January 2026 replay of Redspin's live CMMC Connect, our CMMC Certified Assessors (CCAs) unpack the latest updates from the field and answer real-world questions OSCs are facing as CMMC Level 2 assessments ramp up. This episode (literally) covers: Recent DoD CMMC FAQ updates and what they clarify (and don’t) ISACA’s new role as CAICO and what it means for CCP and CCA certifications The growing pace of completed CMMC assessments and what that signals for 2026 Scoping challenges: virtual machines, shared resources, boundaries, and asset definitions Flow-down realities. Why primes are increasingly requiring Level 2 from subs CMMC vs. FedRAMP, and how to tell if you’re an ESP or a CSP CUI marking, mishandling, and what to do when CUI shows up where it shouldn’t FIPS validation pitfalls assessors see all the time Evaluating AI-enabled tools when CUI is involved Common reasons organizations struggle or fail during assessment NIST 800-171  The session wraps with live audience Q&A, candid assessor perspectives, and practical advice drawn directly from active CMMC engagements, no theory, no fluff. If you’re supporting DoD contracts, preparing for CMMC Level 2, or navigating compliance decisions in real time, this episode delivers clarity where it matters most. CMMC Connect happens on the last Thursday of every month at 1 PM ET. Register for the series and submit questions here: https://redspin.com/cmmc-connect-hub/ Subscribe to Cyberspin on Apple iTunes, Spotify, or your preferred podcast platform. You can always stream the latest episodes at redspin.com.

    50 min
  2. 08/01/2025

    July 2025 CMMC Connect

    In this episode, we unpack one of the most common questions in the CMMC space: What actually triggers a reassessment? From changes in CUI flow to infrastructure shifts and company acquisitions, we break down when you might need to re-certify—and what’s still awaiting clarity from the DoD. We also share lessons learned from the field, including common missteps organizations are making in cloud environments. Misconfigured policies, inherited templates, and SSPs that don’t reflect reality are tripping up otherwise prepared teams. Next, we take a closer look at the Shared Responsibility Model. Your External Service Provider (ESP) can’t carry the full weight of compliance. We explain what controls can be inherited, what’s shared, and where your organization is ultimately accountable. Then we dive into key updates on 48 CFR—the rule that puts CMMC into contracts. With final review underway, we discuss what the phased rollout may look like, enforcement timelines, and how this will impact existing agreements. Finally, don’t miss the live Q&A segment, where we tackle everything from overseas CUI control obligations to M365 scoping confusion and the new six-year evidence retention rule. Tune in & take notes! CMMC Connect happens every last Thursday at 1 PM ET. Register: redspin.com/events/cmmc-connect Subscribe to Cyberspin on Apple iTunes, Spotify, or your preferred podcast platform. You can always stream the latest episodes at redspin.com.

    49 min

Ratings & Reviews

5
out of 5
2 Ratings

About

A podcast to help you navigate CMMC.

You Might Also Like