CMMC News by Jun Cyber cover art

CMMC News by Jun Cyber

CMMC News by Jun Cyber

By: Wilson Bautista Jr.
Listen for free

About this listen

This podcast is dedicated for those who want to stay up to date with the Cybersecurity Maturity Model Certification news. It utilizes Notebook LM to synthesize news articles from Jun Cyber's blog as well as other official CMMC documentation and produces a podcast.

Podcast Description Disclaimer:
The content presented in CMMC News is generated by AI and is intended for informational and educational purposes only. It should not be taken as official guidance for Cybersecurity Maturity Model Certification (CMMC) compliance. For accurate and tailored advice, we recommend consulting a qualified CMMC consultant or reaching out to Jun Cyber directly. Always rely on certified experts for guidance specific to your organization's needs.

© 2025 CMMC News by Jun Cyber
Economics Management Management & Leadership Politics & Government
Episodes
  • Navigating New DOD ODP Mandates in NIST SP 800-171 Revision 3
    May 5 2025

    Send us a text

    🚨 Working with the Department of Defense or handling Controlled Unclassified Information (CUI)? Here’s what you need to know about the DOD’s new approach to NIST SP 800-171 Revision 3 ODP values.

    Just listened to the latest episode of CMMC News, where the hosts did a deep dive into the recent DOD memo standardizing “Organization Defined Parameters” (ODPs) for protecting CUI. If you’re a defense contractor—or work in the DIB—these aren’t just guidelines, they are your new minimums.

    🔑 3 Key Takeaways:

    • No More Guesswork: The DOD has filled in the “blanks” of NIST 800-171 R3 by setting specific ODP values. These are now the baseline for all contractors—think max inactivity timeouts, access control reviews, and patching deadlines.
    • Timelines Are Tight: Some key numbers to know:
      • Account inactivity? Disable within 90 days.
      • Privileged session logoff? Required at end of work period.
      • High-risk vulnerability patching? 30 days max.
      • Quarterly updates for password “bad lists” and system inventories.
    • Documentation & Continuous Vigilance: Annual (or more frequent) reviews for policies, logs, training, and agreements are now required. Plus, always justify and document any deviations or risk-based modifications—the DOD wants your decisions traceable.

    The big picture: The DOD is taking out ambiguity. If you handle CUI, you must implement these specific controls—or document strong justification for any flexibility allowed. And these requirements will change as threats evolve, so keep your risk assessments and compliance efforts agile.

    Want the full detail? Highly recommend listening to the episode and reviewing both the NIST SP 800-171 R3 standard and the new DOD ODP memo. Stay compliant, stay secure! 💪

    See the original PDF here: https://drive.google.com/file/d/1rtgUmlaCiUKst-mHR7Fsz5O95g46hCra/view

    #cybersecurity #DoD #NIST #CUI #compliance #riskmanagement #defenseindustry

    Support the show

    Show More Show Less
    26 mins
  • Navigating DFARS Clause and Cybersecurity Assessments for DOD Contracts
    Mar 26 2025

    Send us a text

    🔍 Want to stay ahead in the world of government contracts and cybersecurity? Dive into our latest CMMC News episode where we explore the NIST SP 800-171 DoD Assessment Requirements. It's all about breaking through the wall of acronyms and jargon to ensure you know exactly what the Department of Defense expects when it comes to protecting sensitive information.

    Here are 3 key takeaways:

    • Understand Assessment Levels: We break down the three types of cybersecurity assessments — Basic, Medium, and High — and what each level of confidence means for your contract requirements with the DoD.
    • Supplier Performance Risk System (SPRS): Learn how all assessment scores are recorded in SPRS, the centralized database that helps the DoD gauge the cybersecurity health of their contractors.
    • Subcontractor Compliance: Discover how these requirements flow down to subcontractors and what obligations primes have to ensure their partners are compliant.

    Stay informed, secure those contracts, and fortify your cybersecurity posture! 🎧🔒

    #Cybersecurity #DoD #NISTSP800171 #GovernmentContracts #CMMCNews

    Support the show

    Show More Show Less
    16 mins
  • SPRS and You: Managing DOD Cybersecurity Expectations
    Mar 26 2025

    Send us a text

    We just dived deep into the Department of Defense's NIST SP 800-171 assessment requirements. This is crucial for any contractor involved with DoD contracts, especially when it comes to cybersecurity. Here are three key takeaways:

    • Assessment Frequency: If you're implementing NIST SP 800-171, make sure you have a recent assessment conducted within the last three years for every covered information system tied to DoD contracts.
    • Assessment Levels: There are three types of DoD assessments - Basic, Medium, and High. Understanding which level applies to you and how to proceed can make or break your eligibility for DoD contracts. The details for each can be found in another key document, the NIST SP 800-171 DoD Assessment Methodology.
    • Reporting Requirements: Once your assessment is complete, post your summary level scores in the Supplier Performance Risk System (SPRS). This is a mandatory step to demonstrate your commitment to cybersecurity, and remember, time is of the essence – scores need to be posted within 30 days of assessment completion.

    🔗 If you’re involved in defense contracting, keeping up with these requirements is non-negotiable! Tune into our latest episode for the full breakdown and stay ahead in the ever-evolving landscape of cybersecurity standards.

    For the official CMMC documentation, click this link: https://dodcio.defense.gov/cmmc/Resources-Documentation/

    #DefenseContracting #Cybersecurity #NISTSP800171 #DOD #CMMCNews #PodcastHighlights

    Support the show

    Show More Show Less
    12 mins

What listeners say about CMMC News by Jun Cyber

Average Customer Ratings

Reviews - Please select the tabs below to change the source of reviews.

In the spirit of reconciliation, Audible acknowledges the Traditional Custodians of country throughout Australia and their connections to land, sea and community. We pay our respect to their elders past and present and extend that respect to all Aboriginal and Torres Strait Islander peoples today.