CMMC at a Crossroads: What Defense Contractors Need to Know—and Do—Now

How defense contractors can navigate CMMC uncertainty—without pausing progress or wasting completed work

August 12 2026
1pm ET

Register

Recent CMMC developments and the latest Request for Information (RFI) have created understandable uncertainty across the defense industrial base. Should you keep preparing? Is an independent assessment still necessary? What obligations remain while the program's future is being decided?

Join compliance, assessment, and technology practitioners for a practical conversation on what may be changing, what has not, and how contractors can make sound decisions now. The panel will explain why NIST SP 800-171, contractual, and evidentiary obligations remain in effect—and why current uncertainty is not a reason to stop the security and compliance work you have already budgeted and begun.

What you'll learn

  • How to decide whether to pause, proceed, or adjust CMMC investments—and how to explain that decision to executives and budget owners
  • Which NIST SP 800-171, contractual, and evidentiary obligations remain regardless of the final assessment model
  • How a self-assessment changes—but does not eliminate—the need for documentation, evidence, and defensibility
  • Why prime contractors and customers may still require independent validation from subcontractors
  • How to protect and build on completed work while preparing for NIST SP 800-171 Revision 3 and broader civilian-agency requirements
  • How to use the RFI process to share your experience and influence the program's direction

Who should attend

  • Defense contractors and subcontractors in the defense industrial base
  • Security, compliance, risk, and IT leaders responsible for NIST SP 800-171 or CMMC readiness
  • Program, contracts, and executive leaders making investment and customer-assurance decisions
  • Organizations preparing for a self-assessment, C3PAO assessment, customer review, or future government inquiry

Don't miss out!

Secure your place now. You'll leave with a clear view of what to keep doing today, how to communicate the situation to leadership, and how to build a compliance program that can withstand customer scrutiny, an independent assessment, or a future government inquiry.
Can't make it live? Register and we'll send you the recording.


Matt Goodrich

Solutions Sales Director, Diligent

Matt Goodrich is a Solutions Sales Director and Federal Security Compliance subject matter expert at Diligent, where he helps organizations build scalable governance, risk, and compliance programs for CMMC, FedRAMP, NIST, and other federal security requirements. Matt brings more than a decade of experience working across government, cybersecurity assessment, and compliance technology. He previously spent nearly ten years supporting and leading the FedRAMP program, including serving as a director responsible for advancing federal cloud security policy and helping agencies and cloud service providers navigate the authorization process. He has also held federal security and go-to-market leadership roles at Salesforce and Schellman, where he worked with organizations pursuing FedRAMP authorizations, independent assessments, and broader public-sector growth strategies.

At Diligent, Matt focuses on translating complex regulatory requirements into practical operating models that help organizations manage assessments, evidence, remediation, and ongoing compliance. He regularly advises defense contractors and federal technology providers on preparing for CMMC, demonstrating compliance with NIST SP 800-171, and building programs that can withstand customer, assessor, and government scrutiny. 

Linda Morales

EVP and Chief Security Officer, 38North

Linda Morales is the Executive Vice President & Chief Security Officer at 38North Security. She leads assessments for customers in the healthcare, federal and commercial spaces looking to expand their product offering to meet US and International standard requirements. She specializes in helping organizations prepare for and complete FISMA, FedRAMP, and HIPAA assessments. Linda is also a recognized expert in Healthcare security, helping Health-IT providers secure and defend Protected Health Information (PHI).    Before 38North, Linda served as a Director at Endeavor Systems, where she played a key role in growing the federal security services practice. She also served as Security Manager for the Federal Aviation Administration’s (FAA) enterprise-wide assessment program, responsible for 150+ systems across FAA.

Linda earned a BS in Computer Science and a Masters in Engineering Management, both from George Washington University, focusing on Information Security. She is also a Certified Information Systems Security Professional (CISSP), Project Management Professional (PMP), and a CMMC-Certified Professional (CCP) with the Cyber Advisory Board (Cyber-AB). 

Michael Brooks

CMMC Strategy and Engagement Director, A-LIGN

Michael Brooks is a retired U.S. Air Force Cyber Operations Officer and former DoD Acquisitions Officer with deep expertise in cybersecurity and defense. A two-time Chief Information Security Officer (CISO) and Lead CMMC Certified Assessor, he has completed over 100 assessments across the Defense Industrial Base (DIB).

As CMMC Strategy & Engagement Director at A-LIGN, Michael advises defense-sector leaders on aligning compliance with business and technology strategies. His mission is to bring perspective, simplify complexity, and ensure decisions are made with clarity, credibility, and confidence, so organizations can protect trust, strengthen resilience, and deliver mission success.