CMMC: Preparing your business for the US Defence supply chain
Description
Cybersecurity Maturity Model Certification (CMMC) is becoming an increasingly important requirement for Australian organisations working with, or seeking opportunities within, the US Department of Defense (DoD) supply chain.
But who actually needs CMMC? What does certification involve? And how does it fit alongside Australian cyber security requirements such as DISP and the Essential Eight?
Understanding these requirements early can help businesses avoid unnecessary cost and complexity, identify capability gaps and ensure they are prepared when CMMC requirements arise.
Having supported more than 300 organisations across Australia with Defence security and compliance, De Stefano & Co understands the challenges businesses face in navigating cyber security frameworks across international jurisdictions and determining which requirements apply to them.
To help organisations understand CMMC and what it means in practice, we're running two FREE one-hour webinar sessions on Tuesday 29 September and Thursday 22 October. Both sessions will cover the same content, giving you two opportunities to attend.
If you'd prefer to register for Webinar #1 on Tuesday 29 September, click here.
Join Jeremy Watkinson and Vanessa Wong as they break down CMMC requirements and provide practical guidance for Australian organisations considering or pursuing opportunities within the US DoD supply chain.
Topics will include:
What CMMC is, why it exists and how it is being introduced into the US DoD supply chain
Who needs CMMC, what level may apply and when certification is required
Understanding CMMC Levels 1, 2 and 3, including the relationship between CMMC Level 2 and NIST SP 800-171
CMMC vs DISP and the Essential Eight: Where they overlap, where they differ and what existing Australian compliance work can be leveraged
Beyond cyber: Understanding the broader CMMC requirements, including physical protection, personnel security and other organisational security controls
Key decisions to consider before commencing CMMC uplift and practical steps you can take now to understand your readiness for CMMC
Funding your CMMC uplift: Understanding potential grant funds to support your CMMC compliance and certification
There will also be time for questions, giving attendees the opportunity to discuss CMMC requirements and considerations with our presenters.
Whether you're already pursuing US Defence opportunities, working within a supply chain where CMMC may become relevant, or simply want to understand how the framework could affect your organisation, this session will help you answer three important questions: Does CMMC apply to us? How prepared are we? And what should we do next?
EVENT DETAILS
Date:
Webinar #2: Thursday 22 October 2026
Time:
Adelaide – 2:00pm to 3:00pm ACDT
Perth – 11:30am to 12:30pm AWST
Darwin – 1:00pm to 2:00pm ACST
Brisbane – 1:30pm to 2:30pm AEST
Melbourne/Sydney/Canberra/Hobart – 2:30pm to 3:30pm AEDT
Where:
Online via Teams
YOUR PRESENTERS
| Jeremy Watkinson – Head of Protective Security Services Jeremy is an experienced cyber security professional and a Governance, Risk and Compliance (GRC) specialist, able to assist with technical security assessments for classified environments, as well as cyber security strategy, implementation and training. Following a long career in the Australian Defence Force and the Commonwealth Government, including roles in international diplomacy, trade policy, border security and intelligence analysis, Jeremy has gone on to work with global software and cloud services providers, and most recently led the cyber security team at one of the Big 4. |
|---|---|
| Vanessa Wong – Senior Cyber Security Advisor Vanessa is Senior Cyber Security Advisor at De Stefano & Co, leading complex security engagements across Defence, critical infrastructure, government and highly regulated sectors. An experienced cyber security leader, Vanessa helps organisations assess risk, strengthen security maturity and translate complex requirements into practical, risk-based solutions. She is an ISO 27001 Lead Auditor, qualified IRAP assessor and Certified Information Security Manager (CISM), with extensive experience advising senior executives and boards. |
Tickets for good, not greed Humanitix dedicates 100% of profits from booking fees to charity






