Navigating CMMC and FedRAMP Together: From Assessment-Ready to Authorized | July 22nd

Contact Us
Services
Services
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
Sustainability Services
Sustainability Services
AI Governance
AI Governance
About Us
About Us
Leadership Team
Leadership Team
Corporate Social Responsibility
Corporate Social Responsibility
Careers
Careers
Strategic Partnerships
Strategic Partnerships

Navigating CMMC and FedRAMP Together: From Assessment-Ready to Authorized

REGISTER NOW

Wednesday, July 22, 2026 @ 1:00 PM EST  |  60 Minutes

About this Event

For defense contractors and cloud service providers navigating CMMC and FedRAMP, preparation is everything. Whether you’re working toward CMMC Level 2 certification ahead of Phase 2 enforcement in November 2026 or pursuing FedRAMP authorization, organizations that start early and arrive assessment-ready have a meaningful advantage in faster timelines, fewer remediation cycles, and stronger positioning for contract opportunities.

Join compliance experts from Schellman and Chainguard for a discussion on what preparation looks like from an assessor’s perspective across both CMMC and FedRAMP — where organizations most commonly have room to strengthen their posture before engaging an assessor, and insights on one of the most impactful areas of readiness: the software supply chain. From open-source dependencies to container image hardening, you’ll leave with a practical picture of what it means to show up assessment-ready across both frameworks.

Key Takeaways

  • When and how to engage a C3PAO to make the most of your assessment timeline
  • The importance of choosing the right software, common pitfalls, and when changes within your environment impact complianceHow to identify and close gaps in container security and software dependencies before your assessment
  • Practical steps to build a defensible, assessment-ready software environment ahead of Phase 2
  • How CMMC and FedRAMP requirements intersect — and how to build a unified compliance strategy that addresses both frameworks.

About this Event

For defense contractors and cloud service providers navigating CMMC and FedRAMP, preparation is everything. Whether you’re working toward CMMC Level 2 certification ahead of Phase 2 enforcement in November 2026 or pursuing FedRAMP authorization, organizations that start early and arrive assessment-ready have a meaningful advantage in faster timelines, fewer remediation cycles, and stronger positioning for contract opportunities.

Join compliance experts from Schellman and Chainguard for a discussion on what preparation looks like from an assessor’s perspective across both CMMC and FedRAMP — where organizations most commonly have room to strengthen their posture before engaging an assessor, and insights on one of the most impactful areas of readiness: the software supply chain. From open-source dependencies to container image hardening, you’ll leave with a practical picture of what it means to show up assessment-ready across both frameworks.

Key Takeaways

  • When and how to engage a C3PAO to make the most of your assessment timeline
  • The importance of choosing the right software, common pitfalls, and when changes within your environment impact complianceHow to identify and close gaps in container security and software dependencies before your assessment
  • Practical steps to build a defensible, assessment-ready software environment ahead of Phase 2
  • How CMMC and FedRAMP requirements intersect — and how to build a unified compliance strategy that addresses both frameworks.

The Presenters

https://216294.fs1.hubspotusercontent-na1.net/hubfs/216294/tim-walsh.jpg

Tim Walsh

Director
Schellman

https://216294.fs1.hubspotusercontent-na1.net/hubfs/216294/john-coffelt-600.jpg

Jon Coffelt

Director
Schellman

https://216294.fs1.hubspotusercontent-na1.net/hubfs/216294/John-Osborne.png

John Osborne

Senior Principal Sales Engineer
Chainguard

Who Should Attend?

This session is especially timely for organizations that have not yet selected a C3PAO or 3PAO and want to understand what readiness looks like before that conversation begins. This webinar is designed for compliance leads, IT security teams, and program managers at organizations pursuing or preparing for CMMC Level 2 certification and/or FedRAMP authorization – particularly those working with cloud-hosted environments, containerized workloads, or third-party dependencies within their CMMC or FedRAMP scope, and those working toward both DoD contract eligibility and federal cloud authorization.