2026 PreVeil CMMC Summit

Join us at America’s most attended CMMC event

Get straight answers from the people that set the bar, met the bar, and measure the bar: the author of NIST 800-171, defense compliance attorneys, C3PAO assessment directors, and CEOs who’ve taken their own companies through certification.

Across 14 sessions and 3 tracks, you’ll learn what’s required of you right now, what it costs, what third-party assessments will actually look like going forward, and what you need to do to remain competitive in the DIB.

Sponsors

Diamond

Gold

Silver

Bronze

Partner

Steptoe LLP

Author of NIST

800-171

CEO, Ron Ross Secure

CEO

StrategicIT Solutions

Dir. of CMMC

Insight Assurance

CEO

APS Global

EVP Commercial Services

Alluvionic

LCCA, GRC Manager

MAD Security

Managing Director

BDO

Chief Engineer

BTI

VP, CMMC Services

Redspin

Co-founder

PreVeil

CTO

DeMase Technical Services

VP

Coalfire Federal

President & CIO

Aethon Security

Director of Cyber Security

FirstCall Consulting

Agenda

–11:40 am Keynote
Keynote

What’s paused, what’s not, and why your signature is now the certification

Get a clear read on which DFARS clauses are already in your contracts, and what an affirming official attests to in SPRS.

Michael GrudenPartner, Steptoe LLP
–12:15 pm Keynote

NIST + CMMC in the era of AI attacks

Keynote

Dr. Ron RossAuthor, NIST 800-171
–12:50 pm Keynote
Keynote

How AI is reshaping the threat landscape

Dr. Raluca PopaCo-founder, PreVeil
–1:25 pm Break
Partner break

Meet our partners

Meet with our Summit partners to talk through your CMMC questions one-on-one with a compliance expert.

–2:00 pm 3 parallel tracks — choose one
Foundational

Have CUI? Here Comes the Responsibility

Often, contractors don’t know whether they hold CUI. This session settles that quickly, then turns to the harder question: what CUI obligates you to.

Dan CiarletteCTO, DeMase Technical Services
Jay HillSenior Cyber Security Manager, Global GRC
Andy PaulCTO, Teramis
Advanced

SSP Teardown: Would Yours Hold Up?

Your SSP is finished but will it hold up when someone who didn’t write it reads it — an assessor, a prime, a partner? This session walks through three of the hardest controls to document and shows a good version and bad version side by side. You’ll leave knowing which one yours resembles.

Christina ReynoldsManaging Director, BDO
Robert TeagueVP, CMMC Services, Redspin
Primes

Flowdown That Works: Instructions Subs Can Act On

You’ve told your suppliers they need to be compliant. Have you told them enough to act on it? This session covers what clear flowdown looks like — how you mark and hand off CUI, what you require and what evidence you accept.

Dave Bullis
Travis GoldbachVP, Coalfire Federal
–2:35 pm 3 parallel tracks — choose one
Foundational

Protecting CUI Without Overpaying: What to Buy, What to Skip, What’s Free

You have to protect CUI, but what should it cost? This session reviews the technologies you actually need, where companies overpay for them, and what’s genuinely free. You’ll leave knowing what fits a company your size.

Michael Barker
Adam GloverDir. of CMMC, Insight Assurance
Advanced

Mock Assessment: One Control, Live

How deep does an assessor actually go? This session is a live mock assessment of a single control — starting with your SSP statement and following it into policy, evidence and interview. You’ll leave knowing what will be asked of you and what will satisfy it.

Noël VestalPresident & CIO, Aethon Security
Primes

How We Got Our Suppliers Compliant

One defense contractor walks through what it actually took to move their supply chain toward compliance — who they started with, what they asked for, what they had to provide. You’ll leave knowing what the work looks like and how to best prepare.

Elizabeth HuyEVP Commercial Services, Alluvionic
Manas DasCEO, StrategicIT Solutions
–3:10 pm 3 parallel tracks — choose one
Foundational

Four paths to compliance. Which is right for your company?

There is more than one way to get to CMMC compliance, and the right one depends on your size, your budget, and how much of the work you can absorb internally. This session walks through four routes and what each demands. You’ll leave knowing which one is yours.

Travis SandsDirector of Cyber Security, FirstCall Consulting
Jaclyn JonesLCCA, GRC Manager, MAD Security
Advanced

You Passed Your Assessment. You’re Not Done.

What does it actually take to keep up your certification? Not the rare, dramatic changes but the ordinary ones such as unpatched systems or inventory that lists machines you decommissioned last year. This session covers what a working compliance program looks like and what yours has to do going forward.

Kevin SchaaffChief Engineer, BTI
Alex JohnsonSnr. Solutions Engineer, PreVeil
Primes

Session TBD

Speaker to be announced
–3:45 pm Break
Partner break

Meet our partners

Meet with our Summit partners to talk through your CMMC questions one-on-one with a compliance expert.

–4:10 pm Closing
Closing

Introducing PreVeil VDI – the fastest, simplest way to compliance

CUI doesn’t have to live on your laptops. PreVeil’s new VDI solution gives you a secure virtual desktop to work in, so the computers stay out of your compliance boundary. Live demo.

Gregg LarocheVP Product Management, PreVeil
–4:30 pm Closing
Closing fireside

AI and CMMC: separating signal from noise

Dr. Rick HansenCEO, APS Global

Event Reviews

“We attended last year’s CMMC Summit looking for clarity and practical guidance on our path toward CMMC. The Summit gave us a much better understanding of the requirements and the steps ahead, while reinforcing our confidence in PreVeil as a partner in our compliance journey.”

– CMMC Lead @ Aerospace Company

“I can personally attest that the PreVeil Summit in 2025 was a powerful confirmation that we made the right decision partnering with PreVeil in 2021. The speakers and staff showed exactly why our clients trust the platform and why we continue to appreciate PreVeil’ s support year after year. “

– Cybersecurity Lead @ IT Provider

“The 2025 CMMC Summit gave me valuable insights into how PreVeil and other CMMC partners differentiate themselves while helping organizations navigate complex compliance requirements. It was a worthwhile experience that expanded my perspective on the CMMC community.”

– Manager @ MSP

Register

October 28, 2026 @ 11:00am ET

Virtual