Decoding the CMMC 2.0 Enigma: Insights for the Modern Contractor, Companies, and Public Institutions
2024-04-20 , Track 2

Navigating the labyrinth of government requirements often feels like decoding an ancient script—filled with urgency, confusion, and concern. Enter the Cybersecurity Maturity Model Certification (CMMC) 2.0, the Department of Defense's latest mandate that sets the gold standard for handling Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) across the defense industry and beyond. With the introduction of CMMC 2.0, the DoD is not only tightening the reins on contractors and companies but is also extending its reach to public education institutions, demanding swift compliance to safeguard sensitive government data.

This session cuts through the fog of CMMC 2.0, providing an overview of its requirements, processes, and far-reaching implications. We'll dissect the updated framework, shining a spotlight on its streamlined procedures, hierarchical compliance levels, and the novel introduction of self-assessments for certain categories. Our mission? To equip defense contractors, educational bodies, and public institutions with the insights needed to navigate the national security ecosystem's evolving demands seamlessly.


This session promises to be engaging and hands-on, steering clear of the mundane to offer tangible solutions for navigating the complexities of CMMC 2.0 compliance. Our focus extends beyond a mere introduction to the updated Cybersecurity Maturity Model Certification; we aim to equip attendees with actionable security controls directly applicable to the Department of Defense's latest guidelines. With the CMMC still closely tied to NIST SP 800-171, we will provide an in-depth exploration of these essential controls and how they apply to your organization.

We'll address key questions that matter to you: How do we differentiate FCI from CUI data? Can cloud services ensure compliance? What responsibilities should our Managed Service Providers (MSPs) assume? This talk is designed to demystify these critical topics, delivering clear answers and strategies. Whether you're a contractor, company, or public institution, join us to gain insights that will prepare you to meet and exceed the new standards set forth by CMMC 2.0.

Jered Bare is a cyber security professional, renowned for his "chaotic good" approach and a decade of expertise in information security. His skills span from cyber defense to purple team operations and application security, making him a pivotal influencer at major conferences. Internationally recognized, Jered was invited by the Panamanian government to lead a specialized course in packet analysis, marking his global impact. Additionally, his commitment extends to national security through his service in the Air National Guard, focusing on Cyber Defense Operations. Jered Bare embodies the intersection of knowledge, passion, and practical application in the cybersecurity domain, making his work both vital and inspirational.