GRC Academy cover art

GRC Academy

GRC Academy

By: Jacob Hill
Listen for free

About this listen

Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform for GRC professionals, executives, and anyone else who wants to increase their knowledge in the GRC space!Copyright GRC Academy
Episodes
  • Deltek's Journey to FedRAMP Moderate Equivalency
    Nov 18 2025

    I have a surprise for you --- the last GRC Academy podcast!

    In this last episode, Michael Greenman from Deltek shares the journey to FedRAMP Moderate Equivalency for Deltek Costpoint GovCon Cloud Moderate (GCC-M).

    And let me tell you, it's quite a story: changes in the control baseline, new policy from the DoW, and lessons learned.

    Here are some of the biggest takeaways:

    • The real-world implications of DoW's equivalency definition
    • How the absence of continuous monitoring shapes the trust model
    • How Deltek developed a customer responsibility matrix that reduces friction for their customers
    • Should the DoW blow up FedRAMP moderate equivalency?

    We also discussed improvements that can be made by the DoW, the Cyber AB, and more!

    We recorded this months ago, but this conversation is still very relevant.

    On another note, it is kind of surreal to think this is the last episode of the GRC Academy podcast. I hope you've enjoyed listening!!

    What were your biggest takeaways? Let me know in the comments.

    Follow Michael on LinkedIn: https://www.linkedin.com/in/michael-greenman-94952a3/

    Deltek Costpoint GCC-M: https://www.deltek.com/en/government-contracting/costpoint/cloud

    -----------

    Online GRC Training: https://tekfused.com/marketplace/?utm_source=podcast&utm_medium=s2-12&utm_campaign=marketplace

    #cmmc

    Show More Show Less
    36 mins
  • What's Next for GRC Academy and Jacob Hill
    Sep 4 2025

    I have an incredible announcement to share! 👀

    Before that though, let me share some of my history with you.

    Back in 2016, I started a side-business called TEKFused LLC focused on web design/hosting.

    Fast forward to 2022, I launched GRC Academy, and since then I’ve released 3 CMMC courses, released 50+ podcast episodes, and partnered with some amazing companies.

    Earlier this year, life threw me a curveball when I was laid off from my full-time role.

    Thanks to the incredible support of my AMAZING LinkedIn network, I had new opportunities on the table immediately!

    Within a week, I accepted a role with Summit 7 as Director of Cybersecurity - a company I’ve admired since 2019.

    And here’s the part I NEVER expected:

    👉 Summit 7 has officially acquired GRC Academy!! 🎉🥳🎉

    And guess what?!? I've already completely updated and rerecorded my CMMC training!! And it's even better than it was before!!

    GRC Academy students with active enrollments to my CMMC training will receive access to the new training on Summit 7's platform. It will take some time to get this all together, so keep your eyes open for that announcement.

    I'll be contributing to Summit 7's YouTube channel in the future as well, so subscribe if you haven't already: https://youtube.com/@summit7

    I will still be reselling PECB training at my TEKFused LLC website! If you need to get certified in ISO 27001/42001 (and more), be sure to keep me on your list: https://tekfused.com/courses/?utm_source=podcast&utm_medium=s2-11&utm_campaign=s7-acquisition-announcement

    On a personal note, I’m very thankful that this transition allows me to spend way more time with my family - while continuing my mission of educating the Defense Industrial Base!

    I learned so much during this chapter of my life. I want to thank all of you for your support - it truly made this possible.

    #cmmc #nist #cybersecurity

    Show More Show Less
    4 mins
  • The Business Case for CMMC - Surviving DOGE
    Jun 19 2025

    CMMC certification could be the key to surviving DOGE cuts! 👀

    In this episode, I’m joined by Derek Kernus of Aethon Security to discuss the business case for CMMC!

    This episode was really refreshing to me. Yes, our discussions about deep CMMC topics are important, but learning how to convince your company leadership to make the CMMC investment is even more critical.

    Here are some takeaways:

    • How CMMC early adopters can shape contracts and limit competition
    • How to frame the CMMC investment to internal leadership
    • The impending CMMC bottleneck of doom 👻
    • What mock assessments are and how they can help you prepare
    • Why choosing the wrong MSP could actually kill your chances at certification

    After being impacted by DOGE myself, I've put a lot of thought into how small businesses will be impacted by DOGE + CMMC.

    Most of my concern is for SMBs that haven't started preparing for CMMC. That costs a lot of money, and if SMBs lose revenue due to DOGE cuts before they prepare for CMMC, I'm not sure they'll be able to survive in the defense contracting space.

    But there is great opportunity for CMMC early adopters to be part a small cadre of CMMC certified companies and operate in a much smaller competitive space.

    It turns out CMMC actually could be your business's savior. Who knew!?!

    I really enjoyed this conversation! What were your biggest takeaways? Let me know in the comments.

    Follow Derek on LinkedIn: https://www.linkedin.com/in/derekkernus/

    Aethon Security Website: https://www.aethonsecurity.com/

    -----------

    Thanks to our sponsor Vanta!

    Get back time to focus on strengthening security and scaling your business.

    Discover the new way to GRC here: https://vanta.com/grcacademy

    -----------

    Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!

    Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s2-10&utm_campaign=courses

    #cmmc

    Show More Show Less
    53 mins
No reviews yet
In the spirit of reconciliation, Audible acknowledges the Traditional Custodians of country throughout Australia and their connections to land, sea and community. We pay our respect to their elders past and present and extend that respect to all Aboriginal and Torres Strait Islander peoples today.