Active Defense Contractors attend for $399 (approval and CAGE code required). Register now

The Official Conference of The Cyber AB

CS5 East 2026

Conference Agenda · October 22-23, 2026

Gaylord National Resort & Convention Center, National Harbor, MD

Agenda subject to change. All times in ET.

Filter Sessions:

Thursday, October 22nd, 2026

8:00 am - 9:00 am

BREAKFAST

Exhibitor Hall (Potomac Ballroom A/B)
9:00 am - 9:30 am

Welcome Remarks

Potomac Ballroom C/D
Jessica Morin Jessica Morin CEO, Forum Makers
Matthew Travis Matthew Travis CEO, The Cyber AB
9:30 am - 10:15 am

Keynote

Potomac Ballroom C/D
Keynote Speaker TBD
10:15 am - 10:30 am

BREAK

10:30 am - 11:15 am

It All Starts with CUI

Identifying, marking, and scoping the data that drives CMMC success

Potomac Ballroom C/D
Speaker(s) TBD
Many organizations begin their CMMC journey by identifying the systems, users, and assets they believe are in scope. Effective scoping starts earlier - with understanding what Controlled Unclassified Information your organization receives, creates, processes, stores, or transmits, and how it moves through your environment. That's harder than it sounds: markings don't tell the whole story, and in modern hybrid environments CUI hides in email, cloud collaboration platforms, file shares, third-party services, and user endpoints. This session brings together three perspectives on the data identification problem: • How CUI designation differs from marking - and the contractor's responsibility when information is unmarked, improperly marked, or unclear • Practical strategies for tracing CUI data flows and defining a defensible assessment boundary • The common pitfalls - over-scoping, overlooked assets, and assumptions that become difficult to defend during an assessment - that drive up certification cost, complexity, and risk Attendees leave with actionable guidance for identifying CUI, documenting decisions, and building a clear, defensible scope that supports a more efficient path to certification.
11:25 am - 12:10 pm

Beyond the Baseline: Measuring the Effectiveness of NIST SP 800-172 Against Advanced Persistent Threats

Potomac Ballroom C/D
Jacob Horne Jacob Horne Summit 7
NIST SP 800-172 is often described as the security standard for organizations facing advanced persistent threats (APTs). But how well does it actually defend against real-world adversary tradecraft? This session moves beyond theory by mapping publicly documented nation-state techniques from the MITRE ATT&CK framework to the enhanced security requirements in NIST SP 800-172. Building on previous research analyzing NIST SP 800-171 against Iranian APT activity, this presentation examines how the additional safeguards in SP 800-172 improve defensive coverage, where meaningful gaps remain, and which enhanced requirements provide the greatest increase in security. The session also explores the implications of NIST SP 800-172 Revision 3. As NIST modernizes the enhanced requirements, attendees will see how proposed changes could improve resilience against contemporary APT campaigns and better align with evolving adversary behavior. Rather than asking whether compliance equals security, this presentation asks a more useful question: How much additional security does SP 800-172 provide, and where should the next generation of requirements go from here? Attendees will leave with a data-driven understanding of: • How SP 800-172 maps real-world APT techniques. • Which enhanced requirements provide the greatest defensive value. • Where sophisticated adversaries can still evade or succeed. • How Revision 3 has the potential to further strengthen the baseline for high-risk organizations.
12:10 pm - 1:30 pm

LUNCH

Exhibitor Hall (Potomac Ballroom A/B)
1:30 pm - 2:20 pm
📋 Contractor Track

AI Enhanced CMMC

Inside the Next Generation of Assessment Readiness and Validation

Potomac Ballroom C/D
Speaker(s) TBD
As CMMC assessments become more complex and artifact-heavy, C3PAOs are increasingly turning to AI to streamline preparation, accelerate reviews, and improve consistency across engagements. This session explores how AI is being used as an augmenting force - not a replacement - for human assessors. We'll walk through how AI assists in pre-assessment evidence organization, identify gaps across SSPs and artifacts, analyzes patterns in control implementation, and highlights inconsistencies that could signal risk. Attendees will learn how AI helps assessors validate scope, map artifacts to the correct controls, and maintain uniform interpretation of control objectives - while all judgments and findings remain human-led. The session also covers how DIB organizations can prepare their documentation and evidence repositories to leverage these AI-accelerated workflows, reducing assessment friction and improving readiness outcomes.
1:30 pm - 4:30 pm 3-Hour Breakout Sessions
CMMC Scoping

CMMC Out of Scope: The Mobile Gap No One is Talking About

Interactive three-hour workshop on mobile access, CUI, and assessment scope

Potomac 1
Matt Stern Matt Stern (Facilitator) Chief Security Officer, Hypori
Most CMMC scoping conversations focus on networks, servers, and managed endpoints, but few account for the mobile devices employees actually use to access Controlled Unclassified Information (CUI) and Federal Contract Information (FCI). While CMMC requirements continue to evolve, the obligation to protect CUI and FCI under NIST SP 800-171 and DFARS 252.204-7012 remains. That leaves government contractors with a common challenge: how do you enable a mobile workforce without quietly expanding assessment scope, increasing compliance risk, or creating productivity-killing workarounds? This isn't theoretical. From the U.S. Army's transition from its legacy DMUC mobile program to the Army Mobility Program (AMP), to mergers and acquisitions, globally distributed workforces, and complex contractor ecosystems, government contractors and subcontractors of every size are navigating the same tradeoff - providing secure mobile access without giving up control of sensitive data. This interactive three-hour workshop explores why mobile devices quietly expand assessment scope, examines today's mobile threat landscape (including unmanaged devices, BYOD, Shadow IT, and AI-driven threats) and draws on real-world government and industry examples to illustrate practical approaches organizations are using today. Attendees will also work through a practical five-part framework for evaluating mobile access that can be applied whether preparing for a C3PAO, government-led assessment, or a self-assessment. WORKSHOP AGENDA The Problem → Use Cases → Mobile Threat Landscape → Applying the Framework → Assessment Readiness → Open Discussion ATTENDEES WILL LEARN HOW TO • Identify where mobile devices quietly expand CMMC assessment scope and compliance risk. • Apply lessons learned from real-world government and Defense Industrial Base mobile modernization initiatives. • Recognize how today's mobile threat landscape (including BYOD, Shadow IT, and AI-enabled attacks) targets unmanaged endpoints. • Apply a practical five-part framework to evaluate mobile access within their own environment. • Secure access to CUI and FCI without unnecessarily increasing compliance scope or operational burden. • Document mobile access strategies within the System Security Plan (SSP) and understand how a Shared Responsibility Matrix supports inherited controls. • Leave with a practical mobile assessment checklist that can be used immediately to evaluate their organization's environment.
Sponsored & Presented by:Hypori
Artificial Intelligence

Transform, Implement, Secure: A Practical Roadmap for Scaling AI and Agents with Measurable Business Impact

Interactive executive workshop · three integrated 45-minute workstreams plus discussion and Q&A

Potomac 2
This interactive executive workshop provides a practical roadmap for scaling AI and agents with measurable business impact. Through business-focused examples, selected demonstrations, implementation guidance, and governance strategies, attendees will learn how to prioritize high-value use cases, build scalable AI-enabled solutions, measure ROI, manage costs, and govern AI responsibly across the enterprise. Format: Three integrated workstreams (45 minutes each) plus discussion and Q&A. WORKSTREAM 1 (45 MINUTES) Transform: Identifying High-Value AI Opportunities and Measuring Impact AI success starts with business outcomes, not technology. This session explores how leading organizations identify, prioritize, and scale the use cases that generate the greatest value. Attendees will learn practical approaches for linking AI initiatives to strategic objectives, defining measurable KPIs, establishing ROI frameworks, and tracking business impact. Real-world examples and case studies will highlight how organizations are accelerating productivity, improving decision-making, and transforming business processes through AI. Key Topics • Prioritizing high-value AI use cases • Aligning AI initiatives to business strategy • Defining and measuring ROI • Establishing KPIs and value realization frameworks • Real-world transformation examples and lessons learned WORKSTREAM 2 (45 MINUTES) Implement: Building Agents, Automating Work, and Scaling Responsibly Moving from ideas to production requires a scalable implementation strategy. This session explores the foundational principles behind agent development, workflow orchestration, and enterprise automation. Through practical examples and interactive demonstrations, attendees will learn how agents can work alongside employees, how automation accelerates business processes, and how organizations can manage consumption through AI FinOps practices. The discussion will focus on building sustainable architectures that balance innovation, operational efficiency, and cost management. Key Topics • Agent architecture and design principles • Agent-to-agent and human-to-agent collaboration • Automation and workflow orchestration • AI FinOps and consumption management • Cost optimization and responsible scaling WORKSTREAM 3 (45 MINUTES) Secure: Governing AI with Confidence As AI becomes integrated into business-critical processes, governance becomes a business enabler rather than a constraint. This session explores the security, risk, compliance, and governance capabilities organizations need to scale AI responsibly. Attendees will learn how to establish governance frameworks, manage access and identity, protect sensitive data, monitor agent behavior, and create sustainable operating models that enable innovation while maintaining trust. Key Topics • AI governance operating models • Data security and information protection • Identity, access, and agent governance • Compliance, risk, and regulatory considerations • Monitoring, observability, and control frameworks • Scaling AI securely across the enterprise
Sponsored & Presented by:Protiviti
Aerospace & Defense

Rocket Science or Fear Tactics? A Working Session on CMMC 2.0 for Aerospace & Defense

Three hours. Real assessments. Straight answers.

Potomac 3
Kia Smith Kia Smith RSM US LLP
Charles Barley, Jr. Charles Barley, Jr. RSM US LLP
Thomas Turner Thomas Turner RSM US LLP
CMMC is no longer a planning exercise. DFARS 252.204-7021 has been showing up in Department of Defense solicitations since November 2025, and on November 10, 2026 (the odds are non-zero), third-party certification (crystal ball is buffering) becomes the expectation for most Level 2 contracts involving CUI. For aerospace and defense companies, that turns a compliance project into a bid eligibility problem, and it doesn't leave much runway to spend on bad information. That's the other problem worth naming. Search for CMMC guidance and you'll find a hundred confident answers, a fair number of which are wrong. Some of it is honest confusion. Some of it is fear being sold as urgency. This session is about separating the parts that are genuinely hard from the parts someone made up. We walk the full path to a passing Level 2 assessment, told by people who have actually been through it. Advisory first: policies and procedures that hold up under scrutiny, a System Security Plan that matches how your business actually operates, and using a POA&M correctly instead of as a place to park problems. Then technical remediation: enclave versus taking the whole environment in, what FIPS-validated and FedRAMP actually requires and why assessors care so much, and the requirements that quietly sink assessments: scoping calls, external service providers, security protection assets, and evidence nobody generated until someone asked for it. Then management: the shared responsibility matrix with your cloud and service providers, and what IT and leadership have to do every day to keep a certification valid once you have one. We close on the assessment itself: prep, the days in the room with a C3PAO, and what actually goes wrong. Come with questions. Clients who have passed Level 2 will be here, along with Certified CMMC Assessors and Certified CMMC Professionals. If you've heard something about CMMC and thought "that sounds made up," this is the room to find out. Bring the question you've been sitting on. Asking "for a friend" is completely acceptable.
Sponsored & Presented by:RSM
CMMC Bootcamp

The CMMC Readiness Bootcamp

Potomac 4
Michael Brooks Michael Brooks CMMC Strategy & Engagement Director, A-LIGN
Jason Sproesser Jason Sproesser Director of Solution Architects, Summit 7
Richard Wakeman Richard Wakeman Chief Security Architect, Defense Industrial Base, Microsoft
If you aren't CMMC certified yet, your time is almost out before enforcement cracks down. Join a comprehensive CMMC readiness bootcamp to learn from experts at top assessor A-LIGN, MSP partner Summit 7, and Microsoft for real-world lessons during CMMC assessments and how to get your organization ramped up for assessment as soon as possible. We'll cover: • Lessons from more than 100 CMMC assessments • Ensuring your assessment is properly scoped • How to prepare your team for your CMMC assessment
Sponsored & Presented by:A-LIGN
Service Provider

Service Provider Breakout

Potomac 5
Sponsored & Presented by:ATX Defense
Supply Chain

Supply Chain Breakout

Potomac 6
Bo Birdwell Michael "Bo" Birdwell (Leader) Director of Supply Chain Resilience, Elbit Systems
You may know what requirements your suppliers have. Do you know what you actually need to know about them, how much confidence you should have in the answers, and whether your supply chain can still deliver when something changes? HOUR 1 Everyone Is Somebody's Supplier: What Do You Need to Know? Supply chain risk starts with visibility. What do we actually need to know about our suppliers, sub-tiers, products, data, dependencies, and exposures? The answer is probably different depending on where you sit in the supply chain. HOUR 2 Requirements vs. Assurance: How Much Confidence Is Enough? A requirement creates an obligation. It does not automatically create assurance. What should a customer ask a supplier to demonstrate? When is an attestation enough? When do we need evidence? When is independent verification justified? And at what point are we simply adding cost without meaningfully reducing risk? HOUR 3 Every Supplier Meets the Requirement. Are You Resilient? A supplier can meet every applicable requirement and we can still have a serious resilience problem. Single-source dependencies. Obsolescence. Counterfeit parts. Critical materials. Cyber risk. Provenance. Geopolitical exposure. Fragile sub-tiers. The question that ultimately matters is much simpler: Can we still deliver when conditions change?
1:30 pm - 4:20 pm
Roundtable Revolution
Roundtable Revolution

36 roundtable topics across three 50-minute rounds. Each round features a different set of 12 topics - select a round to see its lineup. Facilitators will be announced soon.

Subcontractors, ESPs and External Systems, Oh My!

1:30 pm - 2:20 pm
Potomac Ballroom A/B Stage
Facilitator TBD

CMMC and NIST SP 800-171r3: Implementation Ideas and Insights

1:30 pm - 2:20 pm
Potomac Ballroom A/B Stage
Facilitator TBD

Using AI with CUI Data: Your Engineers are already doing it.

1:30 pm - 2:20 pm
Potomac Ballroom A/B Stage
Facilitator TBD

AI FinOps: Managing AI Spend While Maximizing Business Value

1:30 pm - 2:20 pm
Potomac Ballroom A/B Stage
Facilitator TBD

The Assessment Process - Pre / Phase 1 / Phase 2 Sequencing

1:30 pm - 2:20 pm
Potomac Ballroom A/B Stage
Facilitator TBD

From Compliance to Culture: The Leadership Mindset Needed to Achieve CMMC Excellence.

1:30 pm - 2:20 pm
Potomac Ballroom A/B Stage
Facilitator TBD

The CMMC Pause: What the Government Could and Should Do

1:30 pm - 2:20 pm
Potomac Ballroom A/B Stage
Facilitator TBD

One Objective Away: How CMMC Scoring and POA&M Rules Really Decide Your Assessment

1:30 pm - 2:20 pm
Potomac Ballroom A/B Stage
Facilitator TBD

You, Me, and Rev 3: Why Now?

1:30 pm - 2:20 pm
Potomac Ballroom A/B Stage
Facilitator TBD

The Operational Side of CMMC: What We've Learned from Real Implementations

1:30 pm - 2:20 pm
Potomac Ballroom A/B Stage
Facilitator TBD

Client-Owned vs. Provider-Owned Compliance Solutions: Long-Term Risk, Cost, and Control

1:30 pm - 2:20 pm
Potomac Ballroom A/B Stage
Facilitator TBD

Breaking Organizational Silos: Building the Cross-Functional Tiger Team for CMMC Success

1:30 pm - 2:20 pm
Potomac Ballroom A/B Stage
Facilitator TBD

After the Pause: What Did Your Shop Actually Do on 14 July?

2:30 pm - 3:20 pm
Potomac Ballroom A/B Stage
Facilitator TBD

Caught Between Revisions: Navigating the Rev 2-to-Rev 3 Uplift Under the New FAR CUI Rule

2:30 pm - 3:20 pm
Potomac Ballroom A/B Stage
Facilitator TBD

CMMC for Beginners

2:30 pm - 3:20 pm
Potomac Ballroom A/B Stage
Facilitator TBD

Understanding the CMMC L2 Certification Process

2:30 pm - 3:20 pm
Potomac Ballroom A/B Stage
Facilitator TBD

The Fully Managed Enclave: Maximizing Inheritance to Reduce Cost, Risk, and Time to CMMC Compliance

2:30 pm - 3:20 pm
Potomac Ballroom A/B Stage
Facilitator TBD

From DIBCAC to CMMC: What Really Makes an Organization Assessment Ready?

2:30 pm - 3:20 pm
Potomac Ballroom A/B Stage
Facilitator TBD

AMA: A MSP, a C3PAO, and an ESP walk into a bar...

2:30 pm - 3:20 pm
Potomac Ballroom A/B Stage
Facilitator TBD

DFARS 252.204-7012: The Obligations That Don't Go Away

2:30 pm - 3:20 pm
Potomac Ballroom A/B Stage
Facilitator TBD

Evidence That Survives Scrutiny: Building Consistent CMMC Assessment Readiness

2:30 pm - 3:20 pm
Potomac Ballroom A/B Stage
Facilitator TBD

Checking the Checker - How to Monitor Your Supply Chain within CMMC

2:30 pm - 3:20 pm
Potomac Ballroom A/B Stage
Facilitator TBD

Budgeting for CMMC Conversation

2:30 pm - 3:20 pm
Potomac Ballroom A/B Stage
Facilitator TBD

Inside ISO/IEC 17020 Accreditation for C3PAOs: What Assessors Focus on for Impartiality, Competence, and Consistency

2:30 pm - 3:20 pm
Potomac Ballroom A/B Stage
Facilitator TBD

Agents at Scale: Building the Enterprise Workforce of the Future

3:30 pm - 4:20 pm
Potomac Ballroom A/B Stage
Facilitator TBD

Cost and ROI for small and midsize contractors

3:30 pm - 4:20 pm
Potomac Ballroom A/B Stage
Facilitator TBD

Subcontractor flow-down risk

3:30 pm - 4:20 pm
Potomac Ballroom A/B Stage
Facilitator TBD

Broader DIB cybersecurity: CMMC and Beyond

3:30 pm - 4:20 pm
Potomac Ballroom A/B Stage
Facilitator TBD

NIST 800-171 Rev 3 and ODP Deep Dive

3:30 pm - 4:20 pm
Potomac Ballroom A/B Stage
Facilitator TBD

Defending against top cyber adversaries

3:30 pm - 4:20 pm
Potomac Ballroom A/B Stage
Facilitator TBD

C3PAO's ONLY Roundtable: Compare Notes and Forward Planning

3:30 pm - 4:20 pm
Potomac Ballroom A/B Stage
Facilitator TBD

The Manufacturer's Shop Floor: Planning for success (IT/OT discussion)

3:30 pm - 4:20 pm
Potomac Ballroom A/B Stage
Facilitator TBD

RMF, AI, and the future of cybersecurity

3:30 pm - 4:20 pm
Potomac Ballroom A/B Stage
Facilitator TBD

How does threat management factor into operationalizing the organizations strategy?

3:30 pm - 4:20 pm
Potomac Ballroom A/B Stage
Facilitator TBD

Using AI to write policy and procedure

3:30 pm - 4:20 pm
Potomac Ballroom A/B Stage
Facilitator TBD

The Affirming Official's CM and AU Challenge: What to Ask Your MSP or MSSP before the Annual Affirmation

3:30 pm - 4:20 pm
Potomac Ballroom A/B Stage
Facilitator TBD

Round 2 of Roundtable Revolution and Breakout Sessions

2:30 pm - 3:20 pm
2:30 pm - 3:20 pm
📋 Contractor Track

CMMC: Understanding DoW Contract Terms

Making sense of the rules, the clauses, and what they mean for your next bid

Potomac Ballroom C/D
Speaker(s) TBD
The alphabet soup is real: the 32 CFR program rule, the 48 CFR acquisition rule, DFARS 252.204-7012, -7019, -7020, and -7021, FAR flow-downs - and somewhere in there, your contract. This session makes sense of it all and turns it into a bidding strategy: • Which rule does what - the 32 CFR CMMC program rule vs. the 48 CFR contract clause, and how the DFARS clauses fit together • Where an organization should start • How certification requirements change contract bids - and the Option Year renewal concerns nobody warns you about • The prime contractor flow-down: what primes will require, and when • Where ITAR and EAR fit in the picture - and why export-controlled data changes your CUI story • How to bid an effective and accurate timeline for compliance implementation, assessment, and contract proposals

Round 3 of Roundtable Revolution and Breakout Sessions

3:30 pm - 4:20 pm
3:30 pm - 4:20 pm
📋 Contractor Track

NIST SP 800-171 Rev 3: The Future of CMMC Starts Now

Audit-prep dos and don'ts, learned the hard way

Potomac Ballroom C/D
Speaker(s) TBD
The required use of NIST SP 800-171 Rev 3 is still in rulemaking - but the changes from Rev 2 are not insignificant, and forward-leaning, forward-thinking organizations are examining them now. This panel steps through what's actually different and what it means for your compliance program: • The headline changes - restructured and consolidated requirements, new control families including Planning, System and Services Acquisition, and Supply Chain Risk Management, and tighter alignment with NIST SP 800-53 Rev 5 • Organization-Defined Parameters (ODPs) - and why they change how requirements will be specified, interpreted, and assessed • What the transition means in practice for your System Security Plan, policies, procedures, and the evidence behind them • Timing and approach - when to start, what to sequence first, and how to prepare for Rev 3 while Rev 2 still governs your contracts Our panelists offer practical guidance for navigating the change ahead so your CUI environment is compliant when the new requirements arrive. 2027 starts now.
4:30 pm - 5:30 pm

HAPPY HOUR

Exhibitor Hall (Potomac Ballroom A/B)
Emcee TBD
Sponsored by: Edwards Performance Solutions

Friday, October 23rd, 2026

8:00 am - 9:00 am

BREAKFAST

Exhibitor Hall (Potomac Ballroom A/B)
9:00 am - 9:50 am
📋 Contractor Track

CMMC Flow-Down or Fall Down

Building Confidence in the Affirming Official's Supply Chain

Potomac Ballroom C/D
Speaker(s) TBD
Most Affirming Officials are affirming what they cannot see. Their direct CUI environment, sometimes. Their service providers and supply chain, rarely. This session looks at supply chain risk from the AO's chair, drawing on lessons learned from 100+ NIST 800-171 assessments across primes, mid-market, and small business suppliers. Attendees leave with a three-principle framework - visibility, tiering, action - for building reasonable assurance into their flow-down program.
9:00 am - 12:00 pm 3-Hour Breakout Sessions
Manufacturing

Stop Assessing a Whiteboard: The Shop Floor Realities of CUI Compliance

Potomac 1
Ben Tchoubineh Ben Tchoubineh (Leader) CEO, LEXX
Tariq Azmi Tariq Azmi Founding Partner, Ember Technology
Joy Beland Joy Beland VP Cybersecurity Compliance, Summit7
Allison Giddens Allison Giddens President of operations, Win-Tech, Inc
Back by popular demand! If your CUI strategy stops at the network perimeter, your shop floor is already non-compliant. This critical session, updated from the well-received CS5 West workshop, addresses the biggest CMMC implementation questions around securing manufacturing equipment (including IoT), aligning workflow processes and practical considerations for preparing to meet the criteria of NIST 800-171 Rev 3. If necessary, this session will include the most up-to-date information on new requirements to secure OT controls, based on the results of the CMMC pause and the resulting impact these changes will have on manufacturers. Participants will dive into the following areas with our panel of manufacturing experts, leveraging a valuable workbook and a copy of the deck: • CUI - to be, or not to be? What qualifies as CUI, what is "derivative CUI" and what do you do about the "not really CUI?"     ◦ How to contact DoD CIO directly for guidance     ◦ How to work with primes     ◦ Ensuring proper flow-down to your supply chain     ◦ ITAR considerations • Understand the applicability of G-CODE in NIST 800-171, with perspective on subtractive vs. 3D • Applicable Rev 3 ODPs and their implications for manufacturers • Securing OT & IoT according to asset scoping and the Specialized Asset requirements • Physical security considerations for manufacturers • Proven staff training and workflow improvements to get and stay compliant (if time allows)
Sponsored by:
CohnReznick
Artificial Intelligence

Artificial Intelligence Breakout (2 of 2)

Potomac 2
Presenter Pending
Higher Education

Higher Education Breakout

Potomac 3
Presenter Pending
Demo

DEMO Breakout

Potomac 4
Presenter Pending
C3PAO

C3PAO Breakout

Potomac 5
Presenter Pending
NIST Rev 3

NIST Rev 3 Deep Dive / Brilliant at the Basics

Potomac 6
Presenter Pending
9:00 am - 11:50 am
Roundtable Revolution
Roundtable Revolution

36 roundtable topics across three 50-minute rounds (repeat of the Day 1 topics, same order). Each round features a different set of 12 topics - select a round to see its lineup. Facilitators will be announced soon.

Subcontractors, ESPs and External Systems, Oh My!

9:00 am - 9:50 am
Potomac Ballroom A/B Stage
Facilitator TBD

CMMC and NIST SP 800-171r3: Implementation Ideas and Insights

9:00 am - 9:50 am
Potomac Ballroom A/B Stage
Facilitator TBD

Using AI with CUI Data: Your Engineers are already doing it.

9:00 am - 9:50 am
Potomac Ballroom A/B Stage
Facilitator TBD

AI FinOps: Managing AI Spend While Maximizing Business Value

9:00 am - 9:50 am
Potomac Ballroom A/B Stage
Facilitator TBD

The Assessment Process - Pre / Phase 1 / Phase 2 Sequencing

9:00 am - 9:50 am
Potomac Ballroom A/B Stage
Facilitator TBD

From Compliance to Culture: The Leadership Mindset Needed to Achieve CMMC Excellence.

9:00 am - 9:50 am
Potomac Ballroom A/B Stage
Facilitator TBD

The CMMC Pause: What the Government Could and Should Do

9:00 am - 9:50 am
Potomac Ballroom A/B Stage
Facilitator TBD

One Objective Away: How CMMC Scoring and POA&M Rules Really Decide Your Assessment

9:00 am - 9:50 am
Potomac Ballroom A/B Stage
Facilitator TBD

You, Me, and Rev 3: Why Now?

9:00 am - 9:50 am
Potomac Ballroom A/B Stage
Facilitator TBD

The Operational Side of CMMC: What We've Learned from Real Implementations

9:00 am - 9:50 am
Potomac Ballroom A/B Stage
Facilitator TBD

Client-Owned vs. Provider-Owned Compliance Solutions: Long-Term Risk, Cost, and Control

9:00 am - 9:50 am
Potomac Ballroom A/B Stage
Facilitator TBD

Breaking Organizational Silos: Building the Cross-Functional Tiger Team for CMMC Success

9:00 am - 9:50 am
Potomac Ballroom A/B Stage
Facilitator TBD

After the Pause: What Did Your Shop Actually Do on 14 July?

10:00 am - 10:50 am
Potomac Ballroom A/B Stage
Facilitator TBD

Caught Between Revisions: Navigating the Rev 2-to-Rev 3 Uplift Under the New FAR CUI Rule

10:00 am - 10:50 am
Potomac Ballroom A/B Stage
Facilitator TBD

CMMC for Beginners

10:00 am - 10:50 am
Potomac Ballroom A/B Stage
Facilitator TBD

Understanding the CMMC L2 Certification Process

10:00 am - 10:50 am
Potomac Ballroom A/B Stage
Facilitator TBD

The Fully Managed Enclave: Maximizing Inheritance to Reduce Cost, Risk, and Time to CMMC Compliance

10:00 am - 10:50 am
Potomac Ballroom A/B Stage
Facilitator TBD

From DIBCAC to CMMC: What Really Makes an Organization Assessment Ready?

10:00 am - 10:50 am
Potomac Ballroom A/B Stage
Facilitator TBD

AMA: A MSP, a C3PAO, and an ESP walk into a bar...

10:00 am - 10:50 am
Potomac Ballroom A/B Stage
Facilitator TBD

DFARS 252.204-7012: The Obligations That Don't Go Away

10:00 am - 10:50 am
Potomac Ballroom A/B Stage
Facilitator TBD

Evidence That Survives Scrutiny: Building Consistent CMMC Assessment Readiness

10:00 am - 10:50 am
Potomac Ballroom A/B Stage
Facilitator TBD

Checking the Checker - How to Monitor Your Supply Chain within CMMC

10:00 am - 10:50 am
Potomac Ballroom A/B Stage
Facilitator TBD

Budgeting for CMMC Conversation

10:00 am - 10:50 am
Potomac Ballroom A/B Stage
Facilitator TBD

Inside ISO/IEC 17020 Accreditation for C3PAOs: What Assessors Focus on for Impartiality, Competence, and Consistency

10:00 am - 10:50 am
Potomac Ballroom A/B Stage
Facilitator TBD

Agents at Scale: Building the Enterprise Workforce of the Future

11:00 am - 11:50 am
Potomac Ballroom A/B Stage
Facilitator TBD

Cost and ROI for small and midsize contractors

11:00 am - 11:50 am
Potomac Ballroom A/B Stage
Facilitator TBD

Subcontractor flow-down risk

11:00 am - 11:50 am
Potomac Ballroom A/B Stage
Facilitator TBD

Broader DIB cybersecurity: CMMC and Beyond

11:00 am - 11:50 am
Potomac Ballroom A/B Stage
Facilitator TBD

NIST 800-171 Rev 3 and ODP Deep Dive

11:00 am - 11:50 am
Potomac Ballroom A/B Stage
Facilitator TBD

Defending against top cyber adversaries

11:00 am - 11:50 am
Potomac Ballroom A/B Stage
Facilitator TBD

C3PAO's ONLY Roundtable: Compare Notes and Forward Planning

11:00 am - 11:50 am
Potomac Ballroom A/B Stage
Facilitator TBD

The Manufacturer's Shop Floor: Planning for success (IT/OT discussion)

11:00 am - 11:50 am
Potomac Ballroom A/B Stage
Facilitator TBD

RMF, AI, and the future of cybersecurity

11:00 am - 11:50 am
Potomac Ballroom A/B Stage
Facilitator TBD

How does threat management factor into operationalizing the organizations strategy?

11:00 am - 11:50 am
Potomac Ballroom A/B Stage
Facilitator TBD

Using AI to write policy and procedure

11:00 am - 11:50 am
Potomac Ballroom A/B Stage
Facilitator TBD

The Affirming Official's CM and AU Challenge: What to Ask Your MSP or MSSP before the Annual Affirmation

11:00 am - 11:50 am
Potomac Ballroom A/B Stage
Facilitator TBD

Round 2 of Roundtable Revolution and Breakout Sessions

10:00 am - 10:50 am
10:00 am - 10:50 am
📋 Contractor Track

Why the Best Cybersecurity Programs Start in the CFO's Office

From the perspective of a CCA

Potomac Ballroom C/D
Speaker(s) TBD
Many OSCs approach CMMC as a compliance expense. The conversation often starts with: How much will this cost? What is the minimum we have to do? How do we get through assessment? Instead, ask different questions: • What revenue depends on this? • What contracts become available because of this? • What business risk are we reducing? • What operational capabilities are we building? This product-agnostic session reframes CMMC as a business and executive leadership discussion, not just a technical and compliance exercise. The most sustainable CMMC programs do not start with technical controls - they start with leadership understanding why those controls exist. Drawing from real-world CMMC environments, the session explores why successful programs are less about a specific technology stack and more about executive clarity, business objectives, and intentional architecture. If an organization spends $X to preserve eligibility for $X million in defense revenue, is that merely a compliance expense - or a business continuity investment? Attendees will work through executive-level questions such as: • How much annual revenue is tied to DoW contracts and subcontracts? • Could commercial revenue replace that loss within 12 months? • What value is tied to your reputation and position in the defense supply chain? • What is the cost of validating assumptions before implementation vs. discovering six months later they were wrong? "CMMC is not for us" may be the right answer - the goal is to make that decision intentionally, financially, and strategically. The CFO will be your best friend here. Time is reserved for facilitated audience discussion and Q&A on how organizations can slow down enough to make sound business decisions while moving fast enough to meet contract demand.

Round 3 of Roundtable Revolution and Breakout Sessions

11:00 am - 11:50 am
11:00 am - 11:50 am
📋 Contractor Track

The Cost of Compliance vs. The Price of Fraud

Navigating False Claims Act Risk in CMMC Attestations

Potomac Ballroom C/D
Speaker(s) TBD
With the formal roll-out of CMMC, the stakes for DoW contractors have fundamentally shifted from operational eligibility to legal accountability. Under the DOJ's Civil Cyber-Fraud Initiative, the government is increasingly leveraging the False Claims Act (FCA) to pursue treble damages and hefty penalties against companies that knowingly misrepresent their cybersecurity posture in the Supplier Performance Risk System (SPRS). This session addresses a critical friction point in the DIB: the disconnect between the IT and security teams tracking technical controls and the C-suite executives who must legally sign off on compliance attestations. Through an objective, non-commercial breakdown of recent FCA cyber-fraud enforcement actions, we'll map out exactly where organizations stumble - how incomplete System Security Plans (SSPs), unvetted Plans of Action and Milestones (POA&Ms), and "paper compliance" create devastating legal liabilities. Participants receive a step-by-step framework to establish a legally defensible compliance process: executive validation protocols, absolute alignment between technical evidence and legal affirmations, and internal whistleblower mitigation strategies. This session moves past standard control checklists to deliver an essential governance playbook for surviving the new era of regulatory enforcement.
12:00 pm - 1:00 pm

LUNCH

Exhibitor Hall (Potomac Ballroom A/B)
1:00 pm - 2:15 pm

Crystal Ball Session

Answering your burning questions from all corners of the ecosystem

Potomac Ballroom C/D
Panelists TBD
2:15 pm - 3:30 pm

Mock Assessment

Potomac Ballroom C/D
Fernando Machado
Additional Speaker TBD
Full session details, speakers, and topics will be announced soon. Check back for updates.
linkedin facebook pinterest youtube rss twitter instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter instagram