CMMC CON 2026 - Michael Gruden - Partner Steptoe - Speaker Announcement

Steptoe’s Michael Gruden Breaks Down CMMC Compliance and Enforcement at CMMC CON 2026

On Sept. 1, Honeywell Aerospace agreed to pay more than $2 million to settle False Claims Act allegations that it failed to comply with NIST SP 800-171 cybersecurity requirements on a Pentagon contract. The case, which stemmed from a whistleblower complaint filed by a former employee, covered noncompliance from April 2020 through December 2023. It was the latest in a growing line of DOJ cyber enforcement actions, and it likely won’t be the last.

 

At CMMC CON 2026, Michael Gruden will present a Cybersecurity Masterclass covering the full regulatory picture that contractors need to understand, from the evolution of Pentagon cyber requirements to the DOJ enforcement actions now backing them up. Gruden is a Partner at Steptoe, where he leads the firm’s cybersecurity and incident response practice. He’s a former Pentagon IT Acquisition Branch Chief with nearly 15 years of experience at the Department of Homeland Security and the Pentagon, and he sits on the Cyber AB’s CMMC Appeals Board as a CMMC Registered Practitioner. His session runs on Sept. 23 at 10:30 a.m. ET.

 

Gruden’s session walks through the regulatory requirements clause by clause and explains how each one creates compliance obligations and legal exposure for contractors handling controlled unclassified information. He also covers how contractors should approach scoping their environments, a common area where even well-intentioned companies get it wrong and inadvertently misrepresent their compliance posture.

 

On enforcement, Gruden addresses the DOJ’s Civil Cyber-Fraud Initiative and why the combination of SPRS score submissions, legally binding affirmations, and whistleblower incentives has made cybersecurity noncompliance an increasingly expensive liability. He recommends having cybersecurity assessments conducted under attorney-client privilege to create what he calls a no-fault environment, where companies can identify gaps and potential whistleblower risks before the government does.

 

Register now for CMMC CON 2026, a free two-day virtual conference running Sept. 23-24, to hear Gruden’s full breakdown.