Jacob Hill, Director of Cybersecurity at Summit 7, joins Steven Molter for Episode 17 of the IntelliGRC Podcast.
Jacob’s path through the DIB is one of the more interesting ones out there. He started in IT at 19 supporting a defense contractor, spent five years at Marine Corps Systems Command reviewing ATO packages under DIACAP, then built and ran the entire CMMC program at Alamo City Engineering Services on his own. Along the way he founded GRC Academy, launched a podcast, and landed at Summit 7, which acquired GRC Academy in the process. Now he’s building CertPulse AI, a platform that uses AI to track certifications and CPEs and map training to the certs it applies to.
Steven and Jacob also get into the debates the CMMC ecosystem keeps circling:
Why assessor subjectivity didn’t die when assessment objectives arrived
The FedRAMP consolidated rules, 20x, and what happens to moderate equivalency when the documents it depends on no longer exist
The SPA vs FedRAMP misinformation that will not go away
Security protection data and why the definition is still murky
The continuous monitoring gap between point-in-time CMMC assessments, and what ISO 27001 and SOC 2 get right that CMMC doesn’t yet
Whether you’re an MSP serving the DIB, a contractor staring down your first assessment, or a GRC professional trying to keep up with the rule changes, this one covers a lot of ground.
Learn how IntelliGRC helps MSPs and MSSPs manage CMMC compliance at scale: https://intelligrc.com
Watch the Full Video Here
