Navigating CMMC, FedRAMP 20x & CPCSC

Mike Kim, Ali Aleali, and Ryan Torio discuss what changed for defense contractors, what's coming next, and where teams get stuck along the way.
Mike Kim
Mike Kim
August 27, 2026

What's covered

FCI versus CUI, and why the line matters. The question the team fields more than any other, and what actually turns on the answer.

Why scoping is the hard part. Meeting the CMMC Level 2 controls is rarely what holds a company up. The work that decides how long certification takes happens earlier, in planning.

Secure enclave or internal systems. The two patterns customers keep landing on for handling CUI, and what each one does to the size of your assessment.

Building the data inventory first. Where CUI lives and where it gets transmitted, mapped at the start, and what goes wrong when that step gets skipped.

FedRAMP 20x and continuous monitoring. Where FedRAMP is heading, and the case for CMMC following it rather than staying a point in time exercise.

What Canada calls it instead. CPCSC does not reuse the FCI and CUI labels. If you sell on both sides of the border, expect the terms not to line up one for one.

Learn More

Speakers

Mike Kim, CEO & Co-founder, Mycroft

Ali Aleali, CEO & Co-founder, TRUVO

Ryan Torio, Director of GRC Engineering, Mycroft

We turn the compliance nightmare into a dream

Talk to us