The CSfC 24 Conference, May 7, College Park. Survey the market for certified commercial ICT products used in layered solutions protecting classified NSS data.
DIBC26 is a finished!
Thank you to everyone who joined us for CMMC Day, CC Day, CSfC, and DIB Cloud Services Day & brought incredible insight, energy, & collaboration to the series.
Coming back next year? Be sure to lock in your renewal rate at https://t.co/1loBX4vei2.
CMMC Day and CC Day are a wrap 🌯
Today was packed with sessions, meaningful conversations, and real-world takeaways.
Next up tomorrow: CSfC and DIB Cloud Services Day.
If you’re here, don’t miss it.
All part of Defense Industrial Base Cybersecurity Certification Series.
Few people have shaped the Defense Industrial Base’s cybersecurity requirements as much as Stacy Bostjanick.
Now, as she steps out of government, she’s sharing:
What CMMC was designed to solve—and what’s coming next
📍 Secure your spot: https://t.co/vWq8TlnPMd
CMMC is no longer theoretical—it’s contractual.
And no one understands its intent and direction better than Stacy Bostjanick, former Director of CMMC Policy at OUSD A&S.
👉 Join us: https://t.co/vWq8TlnPMd
👉 Speaker profile: https://t.co/LKkL96ixUw
Zero Trust isn’t a slide. It’s a requirement.
At DIB Cloud Services Day (part of DIBC), (Okta) translates this into actual product requirements.
If your roadmap doesn’t reflect this yet, it will.
https://t.co/vWq8TlnPMd
This is a keynote you don’t want to miss.
We’re announcing Stacy Bostjanick—the architect behind CMMC—as the Government Keynote speaker at CMMC Day—part of the DIB Cyber Certification Series .
Learn more + register: https://t.co/vWq8TlnPMd
Speaker: https://t.co/LKkL96ixUw
Most CC delays aren’t technical—they’re self-inflicted.
🎤 Lessons Learned from Recent Certifications with Justin Fisher (Leidos)
This is the CC Day session (part of DIBC) that saves months of rework.
🔗 https://t.co/vWq8TlnPMd
CSfC isn’t standing still—and neither are the Capability Packages.
Get the latest directly from NSA:
Nathan DeGruttola (NSA) will break down the CSfC Engineering Capability Package & Annex Roadmap.
This session alone is worth the trip to DIBC.
🔗 https://t.co/vWq8TlnPMd
Want to know what assessors are actually seeing?
Some valuable sessions:
👉 Andrew Freund
https://t.co/deEYaRPhQB
👉 Michael Brooks
https://t.co/JNumq9xaRi
👉 Corey Garretson (RADICL) – Where companies stumble early
📍 Details: https://t.co/vWq8TlnPMd
FedRAMP is changing — and most product teams aren’t ready.
At DIB Cloud Services Day (part of DIBC), (Red Hat) breaks down:
“FedRAMP Modernization — What Changes for Product Teams and Compliance Ops”
https://t.co/vWq8TlnPMd
NDcPP changes aren’t academic—they impact your roadmap, budget, and timelines.
🎤 Differences Between NDcPP v3.0e and v4.0
with Kristy Knowles (Cisco)
If you’re planning a certification in the next 12–24 months, you need this.
🔗 https://t.co/vWq8TlnPMd
You don’t usually get to ask the CSfC PMO anything you want.
At this conference, you do.
Join the “Ask the PMO” Panel led by:
John Dunker (NSA) and team—focused on program updates, process improvements, and what’s really changing behind the scenes.
🔗 https://t.co/vWq8TlnPMd
CUI scoping is where most companies get it wrong.
Don’t miss:
👉 Kyle Lai (KLC Consulting) – Custom software and CUI realities
https://t.co/f5zoBD4t0y
👉 Rachel Bassford (DEFCERT) – What organizations consistently overlook
https://t.co/Tggo6rIaJS
Most “compliant cloud” architectures fail for one reason:
They weren’t designed for sustained compliance across frameworks.
DIB Cloud Services Day (part of DIBC), breaks down what actually works.
https://t.co/vWq8TlnPMd
What’s happening inside NIAP—and what’s coming next?
Kick off CC Day with:
Common Criteria: What’s Now, What’s Next
with Jon Rolf, Retired NSA NIAP Director
If you’re building or certifying products, this sets the tone for everything that follows.
🔗 https://t.co/vWq8TlnPMd
If you care about CSfC, this is the room you need to be in.
Expect real program updates, direction, and priorities—not recycled slides.
🔗 https://t.co/vWq8TlnPMd
What’s really happening with CMMC—and where is it going?
Start your day with:
Government perspective on why CMMC exists and what’s next
Industry insights from the front lines
📍 Join us at CMMC Day, part of DIBC: https://t.co/vWq8TlnPMd
The agenda for DIB Cloud Services Day (May 5) is now live.
This event is built around what actually matters in 2026:
➡️ Compliance that survives audits
➡️ Architectures that don’t dead-end
➡️ Evidence that works across frameworks
Explore the agenda: https://t.co/vWq8TlnPMd
Common Criteria isn’t going away—it’s evolving fast.
At Common Criteria (CC) Day (part of the DIB Cyber Cert Series), we’re bringing together NIAP leaders, labs, vendors, and integrators to answer the real question:
📅 May 4
🔗 https://t.co/vWq8TlnPMd