What’s paused, what’s not, and why your signature is now the certification
Get a clear read on which DFARS clauses are already in your contracts, and what an affirming official attests to in SPRS.
Get straight answers from the people that set the bar, met the bar, and measure the bar: the author of NIST 800-171, defense compliance attorneys, C3PAO assessment directors, and CEOs who’ve taken their own companies through certification.
Across 14 sessions and 3 tracks, you’ll learn what’s required of you right now, what it costs, what third-party assessments will actually look like going forward, and what you need to do to remain competitive in the DIB.

Partner
Steptoe LLP

Author of NIST
800-171
CEO, Ron Ross Secure

CEO
StrategicIT Solutions

Dir. of CMMC
Insight Assurance

CEO
APS Global

EVP Commercial Services
Alluvionic

LCCA, GRC Manager
MAD Security

Managing Director
BDO

Chief Engineer
BTI

VP, CMMC Services
Redspin

Co-founder
PreVeil

CTO
DeMase Technical Services

VP
Coalfire Federal

President & CIO
Aethon Security

Director of Cyber Security
FirstCall Consulting
Get a clear read on which DFARS clauses are already in your contracts, and what an affirming official attests to in SPRS.
Meet with our Summit partners to talk through your CMMC questions one-on-one with a compliance expert.
Often, contractors don’t know whether they hold CUI. This session settles that quickly, then turns to the harder question: what CUI obligates you to.
Your SSP is finished but will it hold up when someone who didn’t write it reads it — an assessor, a prime, a partner? This session walks through three of the hardest controls to document and shows a good version and bad version side by side. You’ll leave knowing which one yours resembles.
You’ve told your suppliers they need to be compliant. Have you told them enough to act on it? This session covers what clear flowdown looks like — how you mark and hand off CUI, what you require and what evidence you accept.
You have to protect CUI, but what should it cost? This session reviews the technologies you actually need, where companies overpay for them, and what’s genuinely free. You’ll leave knowing what fits a company your size.
How deep does an assessor actually go? This session is a live mock assessment of a single control — starting with your SSP statement and following it into policy, evidence and interview. You’ll leave knowing what will be asked of you and what will satisfy it.
One defense contractor walks through what it actually took to move their supply chain toward compliance — who they started with, what they asked for, what they had to provide. You’ll leave knowing what the work looks like and how to best prepare.
There is more than one way to get to CMMC compliance, and the right one depends on your size, your budget, and how much of the work you can absorb internally. This session walks through four routes and what each demands. You’ll leave knowing which one is yours.
What does it actually take to keep up your certification? Not the rare, dramatic changes but the ordinary ones such as unpatched systems or inventory that lists machines you decommissioned last year. This session covers what a working compliance program looks like and what yours has to do going forward.
Meet with our Summit partners to talk through your CMMC questions one-on-one with a compliance expert.
CUI doesn’t have to live on your laptops. PreVeil’s new VDI solution gives you a secure virtual desktop to work in, so the computers stay out of your compliance boundary. Live demo.
“We attended last year’s CMMC Summit looking for clarity and practical guidance on our path toward CMMC. The Summit gave us a much better understanding of the requirements and the steps ahead, while reinforcing our confidence in PreVeil as a partner in our compliance journey.”
– CMMC Lead @ Aerospace Company
“I can personally attest that the PreVeil Summit in 2025 was a powerful confirmation that we made the right decision partnering with PreVeil in 2021. The speakers and staff showed exactly why our clients trust the platform and why we continue to appreciate PreVeil’ s support year after year. “
– Cybersecurity Lead @ IT Provider
“The 2025 CMMC Summit gave me valuable insights into how PreVeil and other CMMC partners differentiate themselves while helping organizations navigate complex compliance requirements. It was a worthwhile experience that expanded my perspective on the CMMC community.”
– Manager @ MSP
October 28, 2026 @ 11:00am ET
Virtual
PreVeil is 100% Designed & Developed in the USA