CMMC CHAOS
The Pentagon Hit Pause. Your Contracts Didn’t.

Join Denver’s defense contractors, manufacturers, engineering firms, and compliance professionals for an evening of practical guidance on what the suspension of CMMC Phase 2 actually means for your business.

Presenting an eCreek Event

CMMC Chaos

The Department of Defense recently suspended CMMC Phase 2, delaying the third-party certification
requirement that
was scheduled to begin on November 10, 2026. 

That announcement created more questions than answers. 

Does CMMC still apply? 

Do you still need NIST 800-171? 

Will prime contractors continue requiring compliance? 

What happens after the Pentagon’s 60-day review? 

If you’re a Colorado manufacturer, engineering firm, aerospace supplier, construction contractor, or any company working within the Defense Industrial Base (DIB), those questions matter right now. 

This is not a technical seminar or a sales presentation. 

This event is designed to help you separate headlines from reality and understand what your organization should actually be doing today. 

Event Details

Date: Thursday, August 27th, 2026
Time: 6-9 PM
Location: Carboy Winery
400 E 7th Ave, Denver, CO 80203

Enjoy drinks, light appetizers, networking, and an interactive panel discussion with those living and breathing compliance requirements on a daily basis. 

Attendance is complimentary, but space is limited. 

What We’ll Discuss 

  • What the CMMC Phase 2 suspension actually means for defense contractors. 
  • What’s still required today, including NIST SP 800-171, DFARS, and prime contractor expectations.  
  • What your business should be doing now instead of waiting for the next DoD announcement.  
  • What could change next following the Pentagon’s 60-day review.  
  • Live Q&A with cybersecurity and defense contracting experts.  

You’ll Leave With 

  • A clear understanding of today’s CMMC landscape  
  • Practical next steps for your organization  
  • Answers to your biggest compliance questions  
  • New connections with Colorado’s defense contracting community  

Why Attend  

Get Straight Answers From People Living It Every Day 

This isn’t another webinar full of theory. 

You’ll hear from experts representing multiple perspectives across defense contracting and cybersecurity compliance. 

You’ll learn: 

  • What the suspension of CMMC Phase 2 actually changed 
  • Which compliance requirements remain in effect today 
  • Why NIST 800-171 is still critical 
  • What prime contractors are likely to expect from suppliers 
  • How the Pentagon’s 60-day review could reshape implementation 
  • What Colorado contractors should do now to avoid falling behind  

Bring your questions. 

Bring your concerns. 

Leave with a practical understanding of your next steps. 

Meet the Panel

Industry Experts From Both Sides of Compliance 

RJ Garma, Ph.D. 

Defense Contractor | Former U.S. Air Force Officer 

RJ Garma, Ph.D. brings decades of experience spanning military service, aerospace, and defense contracting. A former U.S. Air Force officer with an M.S. in Astronautical Engineering from the University of Southern California, RJ has held leadership and technical roles supporting national security missions at the National Geospatial-Intelligence Agency (NGA), Ball Aerospace, and Lockheed Martin. He also directed mission assurance support during the construction of the first-ever West Coast Falcon 9 Space Launch Complex, helping ensure one of the nation’s most significant commercial space infrastructure projects met rigorous security and operational standards. Today, RJ provides the real-world perspective of a defense contractor navigating CMMC, cybersecurity, and federal compliance requirements every day.  

 

Zach Horton 

Cybersecurity Compliance Expert • CMMC Certified 

Zach is eCreek IT’s resident Compliance expert, bringing a proactive, strategic approach to compliance readiness, cybersecurity risk management, and operational resilience. As a CMMC Certified Professional, Zach helps organizations navigate evolving regulatory requirements, strengthen their security posture, and build scalable compliance programs designed to support long-term growth and contract readiness. In addition to his extensive experience guiding organizations through CMMC preparedness, Zach is also well versed in HIPAA and healthcare security best practices. His real-world guidance has helped clients improve compliance maturity, reduce risk exposure, and secure high-value business opportunities through stronger security and compliance positioning. 

 

Mike Carroll, Ph.D. 

Research Scientist | Engineer | Government Contractor 

Mike Carroll, Ph.D. is a research scientist and engineer whose work focuses on advanced energy technologies supporting government and national laboratory initiatives. At the National Renewable Energy Laboratory (NREL), Mike works at the intersection of cutting-edge research, engineering, and federal program execution, giving him firsthand insight into the need for cybersecurity, compliance, and operational challenges facing organizations working with government agencies. As both an engineer and active government contractor, Mike understands how evolving CMMC requirements affect technical teams, research organizations, and suppliers. He brings a practical perspective on balancing innovation with compliance while preparing organizations for an evolving defense and federal contracting landscape.

Reserve Your Spot

Space is intentionally limited to keep the evening conversational and valuable for attendees.

Frequently Asked Questions

Is CMMC still required after Phase 2 was suspended?

Yes. While the Department of Defense suspended Phase 2 implementation, organizations should continue preparing for cybersecurity requirements including NIST 800-171 and contractual obligations that remain in effect. 

What changed with the Pentagon's announcement?

The DoD paused implementation of the third-party certification requirement while conducting a 60-day review of the program. Existing cybersecurity expectations and many contractual requirements continue to apply. 

Who should attend this event?

Business owners, IT leaders, compliance managers, engineering firms, manufacturers, aerospace companies, construction contractors, and any organization pursuing or supporting Department of Defense contracts. 

Is this event only for existing defense contractors?

 No. Companies interested in entering the defense market or preparing for future federal contracts will also benefit. 

Is there a cost?

No. Attendance is complimentary, but registration is required because seating is limited.