# Secureframe

> Join our 3-day virtual cybersecurity summit May 11-13, 2026. Expert sessions on compliance, threat defense & security culture.

canonical: https://secureframe.com/summit

### Where Security Leaders Come Together

**Built for Security Leaders**

Join CISOs, security engineers, compliance leaders, and technology executives for three days of actionable insights and real-world strategies.


**Connections that Count**

Meet the practitioners building the future of security, exchange ideas with peers, and leave with a concrete plan to level up your organization's security posture.

- # 30+ — Expert Speakers
- # 5k — Attendees
- # 20+ — Sessions
- # 3 — Full Days

## Learn from industry leaders

Security practitioners and executives sharing battle-tested strategies from the front lines.

- Keynote speaker — #### General Paul M. Nakasone, Ret. — Former Commander, U.S. Cyber Command | Former Director, NSA
- Keynote speaker — #### Katie Arrington — Chief Information Officer, ION Q | Former CISO & CIO, Department of Defense
- Keynote speaker — #### Robert Costello — Chief Digital and Information Officer, Merlin Group | Former CIO, CISA
- Keynote Speaker — #### Rob Joyce — NSA Cybersecurity Director (2021-2024) | Former Special Assistant to the President & Acting Homeland Security Advisor
- Keynote Speaker — #### Shrav Mehta — CEO, Secureframe
- Featured Speaker — #### Feross Aboukhadijeh — Founder and CEO, Socket
- Featured speaker — #### Morgan Adamski — Principal, US Cyber, Data & Technology, PwC | Former Executive Director, U.S. Cyber Command
- Featured speaker — #### Vibhav Altekar — CTO, Saronic
- Featured Speaker — #### Varun Badhwar — Founder & CEO, Endor Labs
- Featured Speaker — #### Doug Barbin — President, Schellman
- Featured Speaker — #### Bo Birdwell — Director of Supply Chain Business Excellence, Elbit Systems of America
- Featured Speaker — #### Stacy Bostjanick — VP Government Services Strategy, Cybersec Investments | Former Director of CMMC, DoD
- Featured Speaker — #### Michael Brown — Partner, Shield Capital
- Featured Speaker — #### Dan Chandler — Cloud Security Engineer, FedRAMP, U.S. General Services Administration
- Featured Speaker — #### Sammy Chowdhury — Co-Founder and Chief Compliance Officer, Prescient Security
- Featured Speaker — #### Shahin Farshchi, PhD — Partner, Lux Capital
- Featured Speaker — #### Mike Gallagher — Senior Director of Federal and Advisory Services, A-LIGN
- Featured Speaker — #### Matt Gilbert — Principal, Baker Tilly
- Featured Speaker — #### Adam Glover — Senior Director of CMMC Services, Insight Assurance
- Featured Speaker — #### Travis Goldbach — Vice President | CMMC, Coalfire Federal
- Featured Speaker — #### Thomas Graham, PhD — VP and CISO, Redspin
- Featured Speaker — #### Katie Gray — Partner, In-Q-Tel
- Featured speaker — #### Morgan Hitzig — General Partner, Overmatch
- Featured Speaker — #### Tommy Kromer — GovTech Practice Manager, AWS Security Assurance Services
- Featured speaker — #### Dan Lorenc — CEO, Chainguard
- Featured speaker — #### Fernando Machado — Managing Principal and CISO, Cybersec Investments
- Featured speaker — #### Patrick Morley — Former CEO, Carbon Black
- Featured Speaker — #### Steve Pratt — CISO and Director of Programs, Cyber Risk & Compliance Sector, Sentar
- Featured Speaker — #### Marc Rubbinaccio — Head of Cybersecurity and Compliance, Secureframe
- Featured speaker — #### Mike Snyder — Executive Director of Ecosystem Engagement, The Cyber AB
- Featured Speaker — #### Tristan Thomas — Co-Owner and Managing Director, MeND Sourcing Solutions
- Featured speaker — #### Michael Viscuso — Co-Founder, Carbon Black
- Featured Speaker — #### Richard Wakeman — Chief Security Architect - Defense Industrial Base, Microsoft
- Featured Speaker — #### Koren Wise — CEO, Wise Technical Innovations
- Featured Speaker — #### Marci Womack — Managing Director, Schellman

## Three days of  
deep-dive sessions

All times are in ET

#### Mon, May 11

#### Tue, May 12

#### Wed, May 13

- 9:00 AM - 9:05 AM — Welcome — Opening Remarks — Opening Remarks — - Shrav Mehta - Secureframe
- 9:05 AM - 9:35 AM — Talk — State of CMMC: Where Enforcement Stands and What's Coming — State of CMMC — Where Enforcement Stands and What's Coming — CMMC 2.0 is in contracts. But enforcement reality is still catching up to regulatory intent. This session cuts through the noise on where the program actually stands: which contract clauses are live, how DIBCAC assessments are being prioritized, what's changed since the final rule dropped, and what the pipeline of enforcement activity looks like for the next 12 to 18 months. For contractors still calibrating their timelines, this is the clearest picture of what's required and when. — - Mike Snyder - The CyberAB
- 9:40 AM - 10:40 AM — Panel — CMMC Enclaves 101: What Every DIB Contractor Needs to Know — CMMC Enclaves 101 — What Every DIB Contractor Needs to Know — For most contractors in the defense supply chain right now, the single biggest architectural question on the table is some version of *"is an enclave necessary, and if so, what does that mean?"* This panel answers that question from three different vantage points: the assessor's chair, the operator who has lived inside one, and the platform vendor who built the underlying infrastructure. The conversation covers when an enclave is actually the right architecture (and when it's overkill), the operational reality nobody mentions in the sales cycle, the questions to ask an enclave vendor in the first thirty minutes of a sales call, and where the boundary leaks in ways most contractors don't see coming. — - Thomas Graham, PhD - Redspin
- Steve Pratt - Sentar
- Richard Wakeman - Microsoft
- Shrav Mehta - Secureframe
- 10:45 AM - 11:30 AM — Talk — State of the Ecosystem: Where we are and where we’re going — State of the Ecosystem — Where we are and where we’re going — The Cybersecurity Maturity Model Certification (CMMC) program has transitioned from policy to enforcement, marking a fundamental shift in how the Department of Defense (DoD) secures its supply chain. As of 2026, CMMC 2.0 is actively embedded in contracts, with Phase 1 implementation underway since November 2025 and full third-party assessment requirements for Level 2 set to take effect in November 2026.

Looking forward, CMMC is expected to expand both in scope and enforcement rigor. By 2028, certification requirements will be fully integrated across all applicable DoD contracts, making compliance a baseline cost of doing business. Additionally, emerging signals point to broader federal adoption of CMMC-aligned standards and increased legal enforcement tied to certification claims, elevating both the risk and strategic importance of compliance.

This presentation will examine where CMMC stands today, unpack key ecosystem metrics, and explore what must change to close the gap between policy intent and operational reality. Attendees will gain insight into certification bottlenecks, workforce constraints, and the strategic actions organizations should take now to remain competitive in an increasingly regulated defense environment. — - Stacy Bostjanick - Cybersec Investments
- 12:30 PM - 1:15 PM — Talk — CMMC: Unraveled — CMMC: Unraveled — Every day, our supply chain is under constant cyber attacks. In response, the Department of Defense (DoD) will be imposing new requirements on the Defense Industrial Base (DIB) known as the Cybersecurity Maturity Model Certification (CMMC) to secure our supply chain and protect our most valuable asset: the warfighter. The new 32 CFR Part 170 CMMC rule went into effect on December 16, 2024 and the accompanying DFARS 252.204-7021 clause went into effect on November 10, 2025. Companies handling Controlled Unclassified Information (CUI) will be required to obtain a third-party assessment from an Authorized CMMC 3rd Party Assessment Organization (C3PAO) to maintain or bid on DoD contracts. This presentation, “CMMC: Unraveled”, will go into detail on:

- Common pitfalls contractors make on NIST SP 800-171 implementation
- DoD Assessment Methodology scoring
- DFARS 252.204-7012
- The new 32 CFR Part 170 CMMC Rule
- The new DFARS 252.204-7021 clause
- Review of the top comments provided by contractors and DoD’s responses; and CMMC Assessment Process (CAP) — - Fernando Machado - Cybersec Investments
- 1:20 PM - 2:10 PM — Panel — Inside the Audit: Lessons Learned from CMMC Assessments — Inside the Audit — Lessons Learned from CMMC Assessments — Three of the most active C3PAOs in the country talk candidly about what actually happens on assessment day: what fails, what surprises contractors, and how assessors think. The conversation covers the moment in an assessment when "ready" falls apart, the controls most consistently scored as Not Met, the difference between an SSP that describes how a system should work and one that describes how it actually does, the tension between risk-based and requirements-based audit philosophies, and the Year-2 affirmation problem that's quietly setting up the next wave of False Claims Act cases. Designed for contractors prepping for a first assessment, and for those already mid-prep who want to know what's missing. — - Adam Glover - Insight Assurance
- Mike Gallagher - A-LIGN
- Sammy Chowdhury - Prescient Security
- Shrav Mehta - Secureframe
- 2:15 PM - 3:05 PM — Panel — Certified Today, Vulnerable Tomorrow: What C3PAOs See Between Assessments — Certified Today, Vulnerable Tomorrow — What C3PAOs See Between Assessments — Most CMMC content focuses on getting to certification. This panel is about everything that happens after: the three-year window between assessments, when the assessor is gone, the contract is signed, and the environment keeps changing. That window is where most of the real CMMC risk lives. The conversation covers the first thing that quietly breaks after the assessor leaves the parking lot, what continuous monitoring should actually look like for a 50-person DIB contractor without a SOC, the personal-liability exposure on the annual affirmation that most senior officials don't fully understand, and what to put in place today to make sure the Year-2 affirmation is one a senior official can sign honestly. For contractors who just certified, and for those prepping for cert who need to understand what comes next. — - Matt Gilbert - Baker Tilly
- Tommy Kromer - AWS
- Marci Womack - Schellman
- Shrav Mehta - Secureframe
- 3:10 PM - 4:00 PM — Panel — Drawing the Line: How CMMC Scope Shapes Your Cost, Your Timeline, and Your Security — Drawing the Line — How CMMC Scope Shapes Your Cost, Your Timeline, and Your Security — Scope is the decision that drives everything else. How big a contractor draws the boundary determines what an assessment costs, how long it takes, and (less obviously) how secure the resulting environment actually is. This panel pulls together three voices who see scope decisions from different angles: a major C3PAO with cross-framework assurance experience, a cloud-platform leader who has run his own employer through certification, and an implementer who personally configures small-business enclaves that pass at 110. The conversation covers when smaller scope produces *worse* security, the dollar math nobody publishes, the controls that fail underneath a scoping decision rather than because of one, the FedRAMP equivalency shortcut that mostly isn't, and what M&A does to a boundary that seemed settled. For contractors actively scoping for the first time, and for those who scoped wrong and are paying for it. — - Doug Barbin - Schellman
- Travis Goldbach - Coalfire Federal
- Koren Wise - Wise Technical Innovations
- Marc Rubbinaccio - Secureframe

- 9:00 AM - 9:05 AM — Welcome — Opening Remarks — Opening Remarks — TBD - opening remarks. — - Shrav Mehta - Secureframe
- 9:05 AM - 9:55 AM — Fireside Chat — From Offense to Defense: Building Security Companies in the Shadow of Crisis — From Offense to Defense — Building Security Companies in the Shadow of Crisis — Michael Viscuso spent a decade as an offensive operator for the NSA and CIA before co-founding Carbon Black. Patrick Morley joined as CEO to scale what became the modern EDR category. Then in 2013, Chinese state-sponsored hackers breached Bit9 using the company’s own code-signing certificate because they hadn’t installed their own product everywhere. They lost zero customers. This conversation explores what offensive experience actually teaches you about building defenses, what happens when the security company gets hacked, and how radical transparency in a crisis can become a competitive advantage. — - Michael Viscuso - Carbon Black
- Patrick Morley - Carbon Black
- 10:00 AM - 11:00 AM — Fireside Chat — Fireside Chat with General Paul Nakasone — Fireside Chat with General Paul Nakasone — General Paul Nakasone commanded U.S. Cyber Command and led the NSA through some of the most consequential moments in American cybersecurity history - defending elections, confronting nation-state adversaries, and building the doctrine of persistent engagement that now shapes how the United States operates in cyberspace. In this fireside chat, Nakasone joins Secureframe CEO Shrav Mehta for a wide-ranging conversation on what enterprise security leaders can learn from national defense: how to translate threat intelligence into action, how to balance compliance requirements against real-world risk, and what the convergence of AI and nation-state tradecraft means for organizations that have never thought of themselves as targets. — - General Paul M. Nakasone, Ret. - Former Commander, U.S. CYBERCOM
- Shrav Mehta - Secureframe
- 11:05 AM - 12:00 PM — Panel — Your Code Isn't the Problem: Software Supply Chain Risk — Your Code Isn't the Problem — Software Supply Chain Risk — Most software security work focuses on the code developers write. The attackers have moved on. In 2026, the dangerous code is the code developers didn't write: the npm packages, container base images, GitHub Actions, AI-generated dependencies, and MCP servers that quietly enter the build pipeline every day. This panel brings together three founders making three different bets on how to defend against it: rebuild from clean source, catch malice at the registry edge, and prioritize what's actually reachable in the code. With a defense lens throughout, and a practical view of what CMMC contractors and government-selling startups should actually do next. — - Dan Lorenc - Chainguard
- Feross Aboukhadijeh - Socket.dev
- Varun Badhwar - Endor Labs
- Shrav Mehta - Secureframe
- 12:20 PM - 1:00 PM — Fireside Chat — Why Faster Doesn't Mean Less Secure: Lessons from FedRAMP 20x Pilots — Why Faster Doesn't Mean Less Secure — Lessons from FedRAMP 20x Pilots — Federal agencies have long struggled with the paradox that security processes meant to protect them often leave them vulnerable. FedRAMP authorization, for example, was taking so long that systems were outdated before they were approved. FedRAMP's 20x initiative is designed to break this cycle by radically accelerating authorization timelines while improving security outcomes. This talk explores what the pilots are proving about the relationship between speed and security. — - Dan Chandler - General Services Administration
- Shrav Mehta - Secureframe
- 1:05 PM - 1:55 PM — Panel — Securing the Autonomous Fleet: Cybersecurity When Your Software Ships on the Ocean — Securing the Autonomous Fleet — Cybersecurity When Your Software Ships on the Ocean — Autonomous surface vessels are entering production for the U.S. Navy, and the companies building them face a cybersecurity landscape with no single compliance framework that fully applies. CMMC 2.0 is now live in DoD contracts, but for startups manufacturing physical defense platforms - where software runs on embedded systems at sea in communications-denied environments - the compliance challenge extends far beyond protecting data at rest. Vibhav Altekar is Co-Founder and CTO at Saronic Technologies, a $4 billion defense startup producing autonomous vessels under a $392 million Navy production contract. We'll explore what cybersecurity actually looks like when your attack surface includes GPS spoofing, AI model integrity, and ships built from the keel up, and how a fast-moving defense startup navigates overlapping frameworks when some of the rules are still being written. — - Vibhav Altekar - Saronic Technologies
- Shrav Mehta - Secureframe
- 2:00 PM - 2:55 PM — Panel — The Biggest Threats Facing Startups and Organizations with National Security Missions — The Biggest Threats Facing Startups and Organizations with National Security Missions — A panel of defense-focused investors on the trends shaping national security technology - from the emerging threat landscape for startups serving national security missions, to how VCs counsel portfolio companies on compliance and security, to the pathways they see for portfolio companies to achieve compliance while still moving quickly to get product to market. — - Michael Brown - Shield Capital
- Shahin Farshchi - Lux Capital
- Morgan Hitzig - Overmatch
- Katie Gray - In-Q-Tel
- 3:00 PM - 4:00 PM — Fireside Chat — A Fireside Chat with Robert Costello, Former CIO at CISA — What Enterprise Leaders Can Learn from Federal Cybersecurity — A Fireside Chat with Robert Costello, Former CIO at CISA — Robert Costello spent nearly five years as CIO of CISA, leading the modernization of one of the federal government's most critical, and newest, agencies. From driving zero trust adoption across DHS infrastructure to rethinking how continuous ATO actually works in practice, he operated at the intersection of bureaucratic constraint and urgent national need. Having recently departed the role, Costello joins Secureframe for a candid conversation on what enterprise security leaders can take from the federal experience: how to drive real culture change inside resistant organizations, what AI adoption looks like when the stakes are national infrastructure, and why the gap between compliance and genuine security posture remains one of the hardest problems in the field. — - Robert Costello - Merlin Group
- Shrav Mehta - Secureframe

- 9:00 AM - 9:05 AM — Welcome — Opening Remarks — Opening Remarks — - Shrav Mehta - Secureframe
- 9:05 AM - 9:55 AM — Talk — Accelerating CMMC on the Microsoft Government Cloud — Accelerating CMMC on the Microsoft Government Cloud — Microsoft has multiple cloud paths to CMMC compliance, and most contractors get the architecture decision wrong on the first pass. This session covers the practical differences between M365 Commercial, GCC, GCC High, and the Azure Gov / Secret / TS tiers, then digs into the central question every DIB contractor faces: start with a swivel-seat enclave to get to L2, or commit to GCC High across the business. The pros and cons of each, and how to set up coexistence between GCC High and Commercial for cross-cloud collaboration when both end up in the picture. — - Richard Wakeman, Microsoft
- 10:00 AM - 11:00 AM — Keynote — Keynote: Katie Arrington — Keynote: Katie Arrington — Keynote — - Katie Arrington - IonQ
- 11:05 AM - 12:00 PM — Fireside Chat — What the Government Knows That Your Security Team Doesn't & How That Gap Is Closing — What the Government Knows That Your Security Team Doesn't — And How That Gap Is Closing — For years, the most actionable threat intelligence in the world sat inside NSA and CYBERCOM and never reached the organizations being targeted. Morgan Adamski built the program that started to change that - NSA's Cybersecurity Collaboration Center - and then led AI adoption for cyber operations at the highest level of DoD. Now at PwC, she's doing the translation work in real time. This conversation covers what government-grade threat intelligence actually looks like, how AI is collapsing the gap between knowing about a threat and acting on it, and what private sector security leaders should be demanding from public-private partnerships that too often produce white papers instead of protection. — - Morgan Adamski - PwC
- Shrav Mehta - Secureframe
- 1:00 PM - 1:55 PM — Talk — How to Bid Effectively with the DLA — How to Bid Effectively with the DLA — The Defense Logistics Agency awarded over $68 billion in contracts in 2025, yet many defense contractors either don't know how to access that opportunity or make avoidable mistakes that cost them bids. This session walks through the entire DLA bidding process from start to finish, covering the most common challenges contractors face: reviewing RFQs, meeting bidding timeframes, packaging requirements, and payment and invoicing. We'll also walk through the tools available to help you move faster and bid more accurately. By the end of the session, you'll have a clear picture of how to work with the DLA effectively and the confidence to start bidding. — - Tristan Thomas - MeND Sourcing
- 2:00 PM - 2:55 PM — Talk — CMMC from the Buyer’s Seat: What Actually Gets Suppliers Selected (and What Gets Them Eliminated) — CMMC from the Buyer’s Seat — What Actually Gets Suppliers Selected (and What Gets Them Eliminated) — The voice missing from the CMMC conversation is the buyer's: the prime contractor on the other side of the purchase order, deciding which suppliers are safe to buy from. Bo is a Lead CCA and senior cybersecurity leader at Elbit Systems of America, drawing on five years of integrating CMMC inside a major prime. He'll walk through what a prime actually evaluates in a CMMC-ready supplier, the metrics that matter when you're signing the check, and the cross-functional decisions that separate a compliance program from a compliance project. He'll also get into what the industry isn't addressing publicly: the 'crystal palace' problem with enclaves, why email and SFTP are still how CUI actually moves, who owns CUI flowdown across a hundred-plus suppliers, and why CMMC refuses to stay in the stovepipes most organizations are built on. — - Bo Birdwell - Elbit Systems of America
- 3:00 PM - 4:00 PM — Keynote — Closing Keynote: The Evolution of Global Cyber Threats and National Defense — Closing Keynote: The Evolution of Global Cyber Threats and National Defense — with Former NSA Cybersecurity Director Rob Joyce — Keynote — - Rob Joyce - Former NSA Cybersecurity Director 
                     Former Special Assistant to the President & Acting 
                     Homeland Security Advisor

### Save Your Spot
