Robert McVay, Cybersecurity Expert heading Smithers Information Security Services, Smithers

Robert McVay, Cybersecurity Expert heading Smithers Information Security Services, Smithers

Cybersecurity Expert heading Smithers Information Security Services

Robert McVay served in the U.S. Army for 30 years. During his military career McVay served at all levels of the Army and was the project manager for two different billion-dollar programs. McVay served as the first chief information security officer as well as deputy chief information officer for Cyberspace Management and Integration at the U.S. Missile Defense Agency. He also was the principal architect and then project manager for the U.S. Army’s most aggressive ERP deployment, which ultimately managed all personnel and payroll actions for more than 1.1 million U.S. Army service members. He then deployed to Afghanistan to build a similar system for the Afghan National Defense Forces. After retiring with distinction, McVay became a managing partner at Optimus Partners. The company specializes in providing strategy and technology consulting to senior and C-suite level executives for international and global firms. McVay has been with Smithers for two years and is the prime force behind the launch of the new Information Security Services of the Quality Assessments Division.

Why are your primes asking you about CMMC compliance?

What’s behind those questions? The short answer is in the 32 CFR part 170.23 Application to Subcontractors.

3 things you need to know about CMMC

Here are the three most important things defense contractors need to focus on now

Self-assessment, self-affirmation, and CMMC

The self-assessment/affirmation are required for all organizations processing, storing, or transmitting Controlled Unclassified Information

ISO 27001 audits versus CMMC assessments

5 steps to Cybersecurity Maturity Model Certification

Are you ready for Cybersecurity Maturity Model Certification (CMMC)?

Is your organization ready for a CMMC assessment?

Plan and prepare now to help prioritize scheduling your assessment.

What’s happening with CMMC?

The publication of the final rule will not translate to a requirement that all companies must be CMMC-certified by September 30, 2024, or by the end of 2024.

If I have an ISO 9001, AS9100, or ISO 27001 certification do I need CMMC?

You may still need to comply with NIST SP 800-171. The differentiator is whether your business handles Controlled Unclassified Information (CUI)

Selecting a C3PAO for your organization

You need to begin the process of scheduling third-party assessments to achieve CMMC certification