Meeting & Event Information

2026 April 09 - Security from FAR to CMMC

 

April 09, 2026
11:00 AM - 1:00 PM
Add to Calendar

 

The Ballroom at Tanglewood
5340 Westheimer Road
Houston, TX 77056
http://www.theballroomhouston.com
Directions

AGENDA: 
  11:00 AM - 12:00 PM ISSA South Texas Registration and Chapter meeting
  12:00 PM - 1:00 PM Meeting Presentation
Cost:  
  ISSA South Texas Members $23.18
  Non ISSA South Texas Members: $28.52
  Walk-in Registration:  $30
CPE Hours:  2  
Prerequisite: Basic Cyber Security knowledge
Fundamental knowledge of supply chain risk management
 

Presentation Information:
Speaker: Dr. Tom Duffey, former South Texas ISSA Education Director 
Title: Government Security Regulation and the Evolution from FAR to CMMC
Abstract:

In 1984, a U.S. Government Council (DOD, GSA, and NASA) introduced the Federal Acquisition Regulation (FAR), codified in 48 CFR, addressing supply chain procedures and contract termination. Over the next 40-plus years, federal regulations, including government safeguards for procurement and cybersecurity, evolved, with the addition of the Defense FAR Supplement (DFARS), which supplements the FAR and applies to all DoD contracts and subcontracts.

Following an extended drafting period, accompanied by evolving changes to 32 CFR and 48 CFR, long-awaited Cybersecurity Maturity Model Certification (CMMC) supply chain security requirements for protecting Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) finally became mandatory in November 2025. CMMC, currently in Phase I of rollout, leverages FAR, DFARS, and NIST Special Publication (SP) 800-171 security controls/countermeasures, accompanied by mandatory assessments and penalties for non-compliance.

During this session, regulatory subject-matter advisor and former South Texas ISSA Education Director, Dr. Tom Duffey, will discuss the evolution of supply chain security from FAR to CMMC. Dr. Tom spent over a decade working as a defense contractor for multiple military branches before transitioning his career to industry. As an ISSO and DIACAP/DoD RMF Project Manager, he observed the changes taking place firsthand. During his career, Dr. Tom has continued to work with various regulatory compliance mandates and OT/IT security frameworks. Last year, Dr. Tom leveraged his defense roots to earn his Cyber-AB certifications as a certified lead assessor, professional, and instructor.

Join us for this month's chapter meeting and hear Dr. Tom discuss his regulatory compliance journey, gain vital knowledge on how the recently implemented CMMC mandates impact the defense industrial base (DIB), and learn how you can start or continue your CMMC journey.

Bio:

Dr. Tom is an engineer, consultant, thought leader, project manager, instructor, and OT/IT cybersecurity and regulatory compliance professional with over 30 years of experience in the defense, energy, and healthcare sectors. His diverse experience also includes supporting multiple U.S. military branches. Dr. Tom spent over a decade as a defense contractor and was an ISSO and DIACAP/DoD RMF Program Manager for a three-star global military command before shifting his focus to industry. He holds multiple DoD 8570/8140 credentials and is a certified CMMC professional, lead assessor, and instructor.

Along with his extensive defense background, Dr. Tom has worked in both commercial IT and OT environments. Dr. Tom specializes in NIST, ISA/IEC, and ISO security frameworks, as well as CMMC, NERC CIP, TSA SD02, HIPAA, and the DoD RMF regulatory mandates. He also serves as the Vice Chair of the NERC Supply Chain Subcommittee (SCS). Through his alliance with Adodo.ai, a Cyber-AB-certified C3PAO and Approved Training Provider (ATP), Dr. Tom leads CMMC compliance and training efforts.

Dr. Tom's motto, which he has adhered to throughout his career and firmly believes in, is "growing" oneself, others, and the organization while giving back to the security community. Therefore, he has participated in various NERC efforts and served in other supporting board and leadership roles for ISA Houston, South Texas ISSA, and the InfraGard Energy CSC. He enjoys helping/mentoring others, and currently has multiple mentees. Teaching and learning remain two of Dr. Tom's biggest passions. In addition to the CMMC curriculum courses (CCP and CCA), he teaches classes for the International Society of Automation (ISA) and Texas A&M Engineering Extension (TEEX).

Along with his doctoral dissertation on NERC CIP regulatory compliance, Dr. Tom is a respected thought leader. He has contributed to numerous security thought-leadership efforts, including a World Economic Forum white paper on electric-industry cyber resilience and domain content for the EC-Council C|CISO certification Body of Knowledge. Outside of work, Dr. Tom also enjoys traveling and working on various projects. He and his wife, Jeanine, also serve on the hospitality team for their local church.

Register Now

If the registration button (above) doesn't work, use this link to go to the EventBrite page - https://www.eventbrite.com/e/south-texas-issa-chapter-meeting-government-security-from-far-to-cmmc-tickets-1985038335096?aff=oddtdtcreator

 

Please Note:  The South Texas ISSA Chapter may record (Video and or Audio and or Photograph) the monthly chapter meetings. We may record (Video and or Audio and or Photographs ) at this event as we believe it brings great value to our membership.  While we are not planning, or anticipating, to record (Video and or Audio) the general audience, we are obligated to inform you that you may be recorded (Video and or Audio and or Photograph) during the course of the event.  Therefor as a condition of attendance to the event, we require the following release and consent for use.  

 Effective as of May 12, 2016 and beyond CONSENT and RELEASE is being granted by the REGISTRANT(RECORDED PARTY) to South Texas ISSA (the RELEASED PARTY) to use Video and or Audio and or Photographic recordings taken during the South Texas ISSA Chapter Meetings.  I confirm that the RECORDED PARTY is an adult and is fully authorized to agree to this Consent and Release.  In exchange for access to the Chapter Meeting and payment as indicated in the fee structure, the REGISTRANT/RECORDED PARTY hereby grants consent to South Texas ISSA and or its agents (collectively, the RELEASED PARTY) and authorizes the use of any and all Video and or  Audio and or Photographic recordings taken of me and any reproduction of them in any form in any media whatsoever and any derivative work based hereon throughout the world, for the use of documentation, publicity, promotion, and advertisement of the RELEASED PARTY events.  The REGISTRANT/RECORDED PARTY also consents to the use of his/her own name or any fictitious name which may be employed in connection with the aforesaid Video and or Audio and or  Photographic recordings.  The REGISTRANT/RECORDED PARTY hereby releases any and all claims for Video and or Audio and or Photographic materials collected at this event for the sole use of documentation, publicity, promotion advertisement of the RELEASED PARTIES events. The REGISTRANT/RECORDED PARTY hereby waives any right that he/she may have to inspect and/or approve the documentation, publicity, promotion and advertisement materials that may be created from them. BY COMPLETING THE REGISTRATION, THE RECORDED PARTY WARRANTS THAT HE/SHE HAS READ THIS CONSENT AND RELEASE PRIOR TO THE COMPLETION OF THE REGISTRATION PROCESS, AND UNDERSTANDS IT, AND FREELY ENTERS INTO THIS CONSENT AND RELEASE.