CMMC Midwest logo

FALL SESSION TULSA

OCTOBER 1-2 2026

101 ARCHERTULSA • OKLAHOMA

WE’RE TAKING THIS SHOW ON THE ROAD!

JOIN US FOR A FALL SESSION IN BEAUTIFUL DOWNTOWN TULSA

This one is coming together quickly, so keep an eye out for more details as they emerge.

Some highlights from the Spring session in Wichita

SPEAKERS

KEYNOTE SPEAKER

STACY BOSTJANICK

VICE PRESIDENT, GOVERNMENT SERVICES STRATEGY
CYBERSEC INVESTMENTS

Ms. Stacy Bostjanick is the Vice President for Government Services at Cybersec Investments, where she leads the development of the government services division and advances cybersecurity across the U.S. Industrial Base. A 37-year Civil Service veteran and former Senior Executive Service member, she previously served as Chief Defense Industrial Base Cybersecurity and Deputy CIO for Cybersecurity, overseeing the implementation of the Cybersecurity Maturity Model Certification (CMMC) program and guiding it through federal rule making.

She collaborated with key federal partners, led outreach to educate Defense Industrial Base companies, and ensured the Defense Acquisition workforce was prepared to execute cybersecurity requirements. Her earlier roles include Director of SCRM for OCISO(A&S), Head of DIA’s Contracting Activity, Senior Contracting Officer for the Missile Defense Agency managing over $5 billion in missile defense contracts, and Deputy Procurement Executive for the Office of the Director of National Intelligence. Her awards include the Naval Meritorious Civilian Service Award, the David Packard Excellence in Acquisition Award, and the National Intelligence Meritorious Citation.

 

Stacy Bostjanick

STACY BOSTJANICK

CYBERSEC INVESTMENTS

Anwar Kibria

ANWAR KIBRIA

ACE OF CLOUD

Bryan Bell

BRYAN BELL

FRAZIER & DEETER

Heather Siemens

HEATHER SIEMENS

iFORTRISS

Jeff Farr

JEFF FARR

SERA BRYNN

Jered Bare

JERED BARE

ICDS

Katie Dodson

KATIE DODSON

HIVE SYSTEMS

Kelly Hood

KELLY HOOD

OPTIC CYBER SOLUTIONS

Kevin Mann

KEVIN MANN

RESILIENT IT

Kyle Lai

KYLE LAI

KLC CONSULTING

Mark DeBry

MARK DEBRY

1ST DEFENSE CMMC

Nick Marteney

NICK MARTENEY

MOTHERBEAR

Ozzie Saeed

OZZIE SAEED

INTELLIGRC

Preston Smith

PRESTON SMITH

OCII, UNIVERSITY OF TULSA

Rachel Bassford

RACHEL BASSFORD

INFOCOMPLI

Samantha Sherrill

SAMANTHA SHERRILL

FRAZIER & DEETER

Stuart Itkin

STUART ITKIN

AETHON SECURITY

Tariq Azmi

TARIQ AZMI

EMBER TECHNOLOGY

Tiffiney Groce

TIFFINEY GROCE

FUTUREFEED

Todd Pauley

TODD PAULEY

BOEING

Stuart Itkin

ZACH CICERINI

MOTHERBEAR 

SESSIONS & WORKSHOPS

Stacy Bostjanick

State of the Ecosystem

Where we are, and where we’re going

STACY BOSTJANICK

The Cybersecurity Maturity Model Certification (CMMC) program has transitioned from policy to enforcement, marking a fundamental shift in how the Department of Defense (DoD) secures its supply chain. As of 2026, CMMC 2.0 is actively embedded in contracts, with Phase 1 implementation underway since November 2025 and full third-party assessment requirements for Level 2 set to take effect in November 2026.

Looking forward, CMMC is expected to expand both in scope and enforcement rigor. By 2028, certification requirements will be fully integrated across all applicable DoD contracts, making compliance a baseline cost of doing business. Additionally, emerging signals point to broader federal adoption of CMMC-aligned standards and increased legal enforcement tied to certification claims, elevating both the risk and strategic importance of compliance.

This presentation will examine where CMMC stands today, unpack key ecosystem metrics, and explore what must change to close the gap between policy intent and operational reality. Attendees will gain insight into certification bottlenecks, workforce constraints, and the strategic actions organizations should take now to remain competitive in an increasingly regulated defense environment.

Todd Pauley

The Prime Perspective

TODD PAULEY

Don’t settle for hearsay and rumors – at this session, you’ll hear straight from a Prime what the Primes are thinking about the Pause and the path forward. 

Brian Rhodes

A Conversation with the DoD CIO

BRIAN RHODES

Shortly after the pause, Brian was part of a group that met with Department of Defense CIO Kirsten Davies. Hear how that meeting went, and what the CIO had to say about the future of CMMC.

Ben Tchoubineh

What is, and What Is Not, CUI

BEN TCHOUBINEH

This session aims to help eliminate guesswork about what is, what should be, and what is not in fact CUI.

This session is aimed at, but not exclusively for, manufacturers.

Mark DeBry
Katie Dodson

Nightmare on CMMC Street

MARK DEBRY & KATIE DODSON

Just in time for spooky season! Level 2 horror stories…and how to avoid starring in one.

Rachel Bassford

You Can’t Protect what you Haven’t Governed

The Determination Problem Underneath Every CUI Scoping Decision

RACHEL BASSFORD

You’re told to protect the CUI — but no one tells you which drawings, files, or shop-floor steps actually are the CUI. That’s a data governance problem before it’s a compliance problem. This session shows DIB contractors and manufacturers how to determine what the CUI really is — by origin, ownership, and authority — and build a determination you can defend.

 

Stuart Itkin

Helping your Assessor see the Forest for the Trees

STUART ITKIN

The things about assessment your parents never told you! This session explores how to prepare to help your assessor focus on the right things, for a smoother assessment.

Kyle Lai

What to Expect After the CMMC Phase 2 Pause

KYLE LAI

With CMMC Phase 2 paused, many Defense Industrial Base (DIB) organizations are asking: What should we do now, and what should we expect next?

While CMMC may change, important cybersecurity and contractual obligations remain. This session will cover NIST SP 800-171, DFARS 252.204-7012, and applicable SPRS reporting requirements, as well as the responsibilities and risks of CMMC Level 2 Self-Assessments versus C3PAO Certification Assessments.

Drawing from CMMC assessment lessons learned, we will also discuss common mistakes and look ahead to NIST SP 800-171 Revision 3 and how DIB organizations can prepare.

Key Takeaways

  • Understand what remains unchanged during the CMMC Phase 2 pause.
  • Understand the key differences between Level 2 Self-Assessments and C3PAO Certification Assessments.
  • Prepare for NIST SP 800-171 Revision 3 and future CMMC changes.
Tariq Azmi

NIST 800-171 Revision 2 vs. Rev 3 – What you Need to Know

TARIQ AZMI

Description Coming Soon

Anwar Kibria

Love at First Audit: How to Impress your CMMC Auditor

ANWAR KIBRIA 
What separates a smooth CMMC assessment from one that quickly becomes painful? This session takes attendees behind the curtain of a CMMC Level 2 assessment and explores what assessors actually want to see when they walk through the door. We’ll cover how organizations can prepare their environment, documentation, evidence, and people to make a strong first impression and avoid the common mistakes that create unnecessary findings, delays, and headaches. Attendees will leave with practical tips for approaching their assessment confidently, efficiently, and assessor-ready.

 

Jeff Farr

Why the CMMC Assessor You Choose Matters (A Lot)

JEFF FARR

In this session, we’ll explore what separates assessors, the questions organizations should ask before selecting a C3PAO, and how to choose an assessment partner that brings the right level of expertise, consistency, and preparation to your CMMC journey.

Preston Smith

PANEL: C3PAO AAA (Ask Assessors Anything)

MODERATED BY PRESTON SMITH

What happens when you put a bunch of CMMC Assessors at one table, and have an OSC and a room full of people ask them questions?  We will find out together at this panel session.

Kevin Mann

MSP Shared Responsibility Tour

KEVIN MANN

Take a rock-and-roll tour through NIST SP 800-171 shared responsibility. Learn what the organization owns, what the MSP performs, what both parties must document, and how the SSP and responsibility matrix turn managed services into defensible assessment evidence.

Heather Siemens
Ozzie Saeed

WORKSHOP: 320 Controls = 1000+ Decisions

HEATHER SIEMENS & OZZIE SAEED

CMMC Level 2 may have 320 requirements, but implementing them requires hundreds of additional organizational decisions, everything from defining frequencies, thresholds, and parameters to determining responsibilities, scope, processes, and technologies.

In this practical session, Heather Siemens and Ozzie Saeed will explore the decisions organizations must make to turn CMMC requirements into an operational security program. Heather will highlight real-world examples of organizationally defined decisions and explain how those choices can impact scope, architecture, cost, risk, and assessment readiness. Ozzie will demonstrate how IntelliGRC can be used to capture, assign, track, review, and maintain these organizational decisions, providing a practical approach to turning CMMC decision-making into a structured and auditable governance process.

Attendees will leave with a clearer understanding of the decisions behind the 320 requirements and practical strategies for managing them throughout the CMMC lifecycle.

Kelly Hood

WORKSHOP: Getting to 110 in a World of Chutes & Ladders

KELLY HOOD

Earning a CMMC certification can feel like navigating a game of Chutes and Ladders!

Strategic moves take you closer to your 110 score, while missteps can send you sliding back. This interactive workshop helps participants identify the “ladders” that accelerate success, such as stakeholder buy-in and resource alignment; and prepare for the “chutes” that derail forward progress- including scoping errors and CUI challenges.

Through this scenario-based workshop and group collaboration, attendees will map out practical strategies to overcome setbacks, maintain momentum, and climb steadily toward certification readiness.

Samantha Sherrill
Bryan Bell

Leveraging Agentic AI for CMMC Cost Reduction

 SAMANTHA SHERRILL & BRYAN BELL

Learn how to automate documentation and SSP creation. Live examples for how to automate the creation of highly technical system hardening standards for FortiGate firewalls (live case study).

Nick Marteney
Jered Bare

WORKSHOP: CMMC Feud

NICK MARTENEY, JERED BARE & ZACH CICERINI

Survey Says… Show Me the Evidence! Join us for a hands-on session where attendees compete to guess the most common answers to real CMMC compliance questions about scoping, evidence, access control, incident response, and assessment readiness. This interactive session makes CMMC practical, memorable, and fun by focusing on what assessors look for, where organizations get tripped up, and how to think beyond policy to real-world implementation.

Tiffiney Groce

Follow the CUI

TIFFINEY GROCE

This session follows a fictional employee, Alex, through an ordinary workday as CUI moves across people, systems, facilities, suppliers, and physical processes. Instead of starting with a network diagram and drawing a boundary, we follow the work to see where the CUI actually goes and allow the scope to reveal itself. The goal is to make scoping practical, relatable, and something attendees can take back and apply within their own organizations.

LOCATION & TRAVEL INFORMATION

The Conference will run approximately 8 am-5 pm Thursday, and 8 am-Noon on Friday, so if you are traveling to Tulsa for the Conference, we suggest planning your trip accordingly.

CONFERENCE LOCATION

101 ARCHER – UNIVERSITY OF TULSA
101 E Archer Ave, Tulsa, OK  74103

Located in the heart of Tulsa’s Arts District downtown, 101 ARCHER is The University of Tulsa’s arts and culture hub. Lots of hotels, dining, cultural, and entertainment options are nearby.

HOTELS

CMMC Midwest does not have a block of rooms reserved for the Tulsa conference.  However, there are many wonderful hotels nearby to choose from.  Most offer parking and airport shuttles, but please verify before booking if you need those services.

VISITING TULSA

Tulsa is a vibrant and welcoming mid-size city (metro area population is +/- 1.6 million). Originally Indian Territory, the Tulsa of today was largely shaped by the discovery of oil nearby, and the subsequent oil boom left Tulsa with beautiful architecture, much of it Art Deco. Tulsa is also known for a thriving arts and music scene, featuring historic Cain’s Ballroom, the Woody Guthrie Center, and the Bob Dylan Center. 

Route 66 also runs through Tulsa, with plenty to see and do along the Mother Road, in its 100th anniversary year. Don’t miss the “Land of the Giants” Meadow Gold district. 

Transportation:  Rideshares like Uber or Lyft are a common and quick way to get around town, but if you are going to be here for a longer visit or like to explore, you might prefer to rent a car. 

Places to Go and Things to Do:  Visit Tulsa has an excellent website with loads of ideas and information – view the latest Visitor’s Guide here.  Of course, while you are here, feel free to ask the locals for recommendations!

SPONSORSHIP OPPORTUNITIES

Meet. greet, and get your message in front of CMMC Midwest Attendees with your sponsorship of CMMC Midwest Conference!

Our attendees cover the full gamut of the CMMC ecosystem – from Assessors, C3PAOs, and MSPs; OSCs of all sizes, from local machine shops to heavy hitters; Educators and Students, and everything in-between.

Sponsorship helps us to bring you the best conference possible, and continue our mission of bringing education and resources to the Midwestern CMMC community throughout the year.

Thank you for your support.

r

Sponsorship Options Have Changed - Please Read Carefully


NOTE: Your sponsorship MUST BE REGISTERED BY AUGUST 31 in order to be included in print materials such as banners and the Conference Program.

SPONSORSHIP LEVELS

ULTRA SPONSORSHIP

$10,000 – 1 slot available 

Benefits:

  • Registration for six people included
  • Step & Repeat Photo Op banner with your Logo and CMMC Midwest logo
  • Premium double-size booth area
  • Logo Placement on Conference website, banners, and marketing materials
  • CMMC Midwest Co-branded digital marketing assets to share with clients and social media
  • Exclusive discount code to share with clients and prospects for 20% off conference passes
  • Your full-size ad on the inside front cover of the Conference Program

ALPHA SPONSORSHIP

$5,000 – 4 slots available 

Benefits:

  • Registration for four people included
  • Premium booth area
  • Logo Placement on Conference website, banners, and marketing materials
  • CMMC Midwest Co-branded digital marketing assets to share with clients and social media
  • Exclusive discount code to share with clients and prospects for 15% off conference passes
  • Your full-size ad in the Conference Program

BRAVO SPONSORSHIP

$2,500 – 4 slots available 

Benefits:

  • Registration for two people included
  • Booth with table & chairs
  • Logo Placement on Conference website, banners, and marketing materials
  • CMMC Midwest Co-branded digital marketing assets to share with clients and social media
  • Your half-page ad in the Conference Program

CHARLIE SPONSORSHIP

$1,500 – 4 slots available 

Benefits:

  • Registration for one person included
  • Booth with table & chairs
  • Logo Placement on Conference website, banners, and marketing materials
  • CMMC Midwest Co-branded digital marketing assets to share with clients and social media
  • Your quarter-page ad in the Conference Program

DELTA SPONSORSHIP

$750 – 8 slots available 

Benefits:

  • Registration for one person included
  • Logo Placement on Conference website, banners
  • Your eighth-page ad in the Conference Program

HAPPY HOUR SPONSOR

$1500 

Benefits:

  • The Happy Hour will be referred to as “Happy Hour presented
    by {Your Name}” on the website and Conference program
  • Logo on Happy Hour signage and drink tickets
  • Shoutout and time for a brief message at the Happy Hour
  • Logo and mention in the website and  Conference program

BREAKFAST SPONSOR

$1500 

Benefits:

  • Logo on Breakfast signage
  • Shoutout and time for a brief message at both Breakfasts
  • Logo and mention in the website and Conference program

COFFEE & BEVERAGE SPONSOR

$1500 

Benefits:

  • Logo on Coffee & Drink table signage for all-day brand reinforcement
  • Logo and mention in the website and Conference program

LUNCH SPONSOR

$1500 

Benefits:

  • The Lunch will be referred to as “Lunch presented by {Your Name}” on the website and Conference program
  • Logo on Lunch signage
  • Shoutout and time for a brief message at Lunch
  • Logo and mention in the website and Conference program

LANYARD SPONSOR

$500 

Benefits:

  • Your business name/logo printed on the lanyards
  • Option to include a sticker or small gift with every badge
  • Logo and mention in the website and  Conference program

SPONSORSHIP BENEFITS AT A GLANCE

Graph of sponsorship benefits
Sponsorship benefits graph

SPONSORS

ULTRA SPONSOR

Ember Technology Soteria dual logo

ALPHA SPONSORS

BRAVO SPONSORS

ecfirst logo
Summit 7 logo
MotherBear Security logo
Frazier & Deeter logo

CHARLIE SPONSORS

ISI logo
Aethon Security
Digital Beachhead logo
Koniag Cyber logo

DELTA SPONSORS

BREAKFAST SPONSORED BY:

1 plante moran logo

LUNCH SPONSORED BY:

PLANTE MORAN

COFFEE & DRINK STATIONS

SPONSORED BY: SUMMIT 7

Summit 7 logo
Hive Systems logo

HAPPY HOUR SPONSORED BY: HIVE SYSTEMS

LANYARDS SPONSORED BY: MINDLINE

mindline logo

SPECIAL THANKS TO OUR HOSTS

OCII logo

KEEP IN THE LOOP

JOIN THE CMMC MIDWEST MAILING LIST

Don’t miss out on future CMMC Midwest conferences and events, join our mailing list!

No spam, no junk, no worries – we won’t sell your information or overload your inbox.

Just the good stuff: CMMC news and information about future CMMC Midwest events

* indicates required

Intuit Mailchimp

CMMC Midwest logo