Beyond the Audit: CMMC, FedRAMP, and Compliance at Mission Speed Webinar
Register

Beyond the Audit: CMMC, FedRAMP, and Compliance at Mission Speed Webinar

Tuesday, September 29, 2026 1:00pm-2:00pm EST   Virtual, ON24

The suspension of CMMC Phase II did not lower the cybersecurity bar. It exposed a harder problem: how to verify security across a large and diverse defense industrial base without creating a process too costly and complex to scale.

As the Department of War reexamines CMMC and FedRAMP modernizes its own framework, contractors have an opportunity to move beyond point-in-time audit preparation toward reusable evidence, continuous assurance, and clearly defined responsibility.

In this session, John Bullough will explain what the CMMC pause changed, which obligations for protecting Controlled Unclassified Information remain, and how FedRAMP-certified cloud services can support a more efficient and defensible compliance program. He will break down what providers can substantiate through independently validated controls and reusable evidence, what remains the contractor’s responsibility, and how to evaluate cloud services without relying on labels alone.

Attendees will leave with a practical approach to making compliance investments that improve security, reduce duplicated reviews, and help their organizations move at mission speed.

Key takeaways

  • What the CMMC Phase II suspension changed—and what remains required for contractors handling CUI..
  • How CMMC and FedRAMP fit together, including where FedRAMP can provide independently validated controls and reusable evidence..
  • How to distinguish provider responsibilities from the controls, configurations, processes, and documentation the contractor still owns..
  • A practical framework for evaluating cloud providers and focusing compliance investments on meaningful security and operational outcomes..


 

  • John Bullough
    John Bullough -
    Chief Information Security Officer, Procurement Sciences AI

    John Bullough serves as the Chief Information Security Officer at Procurement Sciences. He brings over 15 years of experience building and scaling security programs across high-growth technology and fintech companies. As CISO, John leads security, compliance, IT, and infrastructure, ensuring that Awarded AI meets the rigorous standards required by defense contractors and government agencies handling sensitive data, including the security of AI models and data pipelines that power the platform. Prior to joining Procurement Sciences, John led security, IT, and DevOps at Jasper AI, an early AI-native company, where he built the security program from the ground up. In this role, he established the compliance and security infrastructure that enabled a generative AI platform to earn customer trust in enterprise and regulated environments. Before Jasper, he established the security program at Divvy (acquired by Bill.com for over $2 billion). John has a proven track record of partnering with Sales and Customer Success teams to communicate security posture and accelerate customer trust, directly supporting the successful deployment and adoption of the Awarded AI platform by government and defense clients. John holds a Bachelor of Science in Information Systems and Technology from Weber State University. He is dedicated to helping customers find, win, and deliver government contracts faster and smarter, without compromising security.

  • 1:00pm - 2:00pm EST

    Webinar Discussion with John Bullough, Chief Information Security Officer at Procurement Sciences

Platinum Sponsor