CMMC CON 2026 - Eric Crusius - Partner at Hunton Andrews Kurth LLP - Speaker Announcement

Get the legal perspective on CMMC enforcement at CMMC CON 2026

The suspension of CMMC Phase 2 took mandatory third-party C3PAO assessments off the table — for now. But the Pentagon’s Defense Contract Management Agency continues to conduct assessments of contractor compliance with NIST SP 800-171. In June, those assessments led to a $507,144 False Claims Act settlement after defense contractor LOGZONE scored -170 on a scale where 110 is passing. That case was one of several enforcement actions in the past year, and it won’t be the last.

At CMMC CON 2026, Eric Crusius, Partner at law firm Hunton, will walk through the enforcement pattern and the broader regulatory picture in a session called “Legal Insights: Regulatory Landscape with Guest Counsel,” on Sept. 24 at 11 a.m. ET. Crusius chairs the firm’s government contracts practice and has represented clients in cybersecurity and federal regulatory matters for more than 15 years. He is ranked by Chambers as a leading government contracts and cybersecurity lawyer.

His session covers four areas:

  • The governmentwide regulatory picture, including a proposed FAR Part 40 rule published in June that would consolidate security and supply chain controls across all federal agencies
  • The current state of CMMC implementation, including timing nuances around when requirements apply to existing contracts and option periods
  • The enforcement trend, from the DOJ’s $4.6 million MORSECORP settlement to criminal fraud charges against an individual contractor manager
  • Emerging cybersecurity initiatives at GSA that extend Controlled Unclassified Information protection requirements beyond Pentagon contracts

Register now for CMMC CON 2026 to hear Crusius lay out how enforcement has changed and what contractors should prepare for if the DCMA conducts an audit.