Steven Molter sits down with Matthew Travis, CEO of the Cyber AB, in what may be the most in-depth conversation Matt has given on the record. They scheduled this episode roughly an hour before the DoD announced the suspension of CMMC Phase 2, so the timing could not have been better. The first half is the story almost nobody in the ecosystem has heard: growing up in Terre Haute playing driveway basketball against Larry Bird, Notre Dame and NROTC, boarding cargo ships in the Red Sea as an interdiction officer, waltzing lessons and state dinners as a White House social aide, building and selling Obsidian Analysis, and helping stand up CISA as its first deputy director. The second half goes straight at the news. Matt explains why the Cyber AB had no advance warning, why he is surprised and disappointed by how the pause was messaged, and what he expects the 60-day reform task force to actually conclude. He and Steven get into the funding model behind the Cyber AB, the original board’s conflict of interest problem, the new Cyber Engagement Forum, and why he still believes third-party certification is the only model that works. Topics covered: Why the Cyber AB has no control over CIO decisions, and why this was never their program to change What the pause actually changed, and what did not change at all The case that there is no such thing as “CMMC implementation,” and Steven’s pushback on CMMC-specific scoping costs What the numbers say about small businesses, with roughly 1,800 Level 2 certifications issued and most going to small businesses Certification as the best available insurance against False Claims Act exposure Where Matt is now open to change, including delta assessments, continuous monitoring, and the ESP and MSP gap in 32 CFR The Cyber Engagement Forum, the marketplace overhaul, and CMMC going international IntelliGRC is the multi-tenant CMMC compliance platform built for MSPs, MSSPs, and the Defense Industrial Base.
Watch the full Video Here
