<img src="https://ad.doubleclick.net/ddm/activity/src=11631230;type=pagevw0;cat=pw_allpg;dc_lat=;dc_rdid=;tag_for_child_directed_treatment=;tfua=;npa=;gdpr=${GDPR};gdpr_consent=${GDPR_CONSENT_755};ord=1;num=1?" width="1" height="1" alt="">
Webinar

CMMC Compass Webinar - CMMC Phase 2 is Suspended — Your NIST 800-171 Requirements Aren't

July 29, 2026

Virtru + Okta: A better together story of how two enterprise-ready platforms layer together to address a significant portion of NIST 800-171 controls and keep your SPRS score defensible when it matters most.

If you’ve been racing toward the CMMC Phase 2 deadline, the July 13 announcement that the DoD suspended Phase 2 for a 60-day review probably landed hard. But let’s be straight about what actually happened: Third party assessments are simply the inspection mechanism, the core requirements of CMMC haven't changed.

While third-party C3PAO certifications are on hold, your legal obligation to comply with DFARS 7012 and NIST SP 800-171 has not changed. In fact, the shift increases your exposure in one critical way: with third-party auditors sidelined, your self-attested score in SPRS is now the primary metric the government checks. An inflated or non-defensible SPRS score puts contractors directly in the crosshairs of DOJ enforcement under the False Claims Act and Whistleblower suits—enforcement mechanisms that haven't paused for anyone.

The immediate challenge isn't chasing a third-party audit; it's proving a defensible, accurate NIST 800-171 posture right now without blowing up your IT budget or disrupting operational flow.

In this 60-minute session, Andrew Lynch (VP of Velocity Sales at Virtru) and Naveed Mirza (Senior Solutions Engineer at Okta) will break down how to navigate this post-July 13 landscape and demonstrate how two enterprise-ready platforms layer together to address a significant portion of the 110 NIST SP 800-171

What you'll learn:

  • Unpacking the July 13 Reality: What the 60-day review means, how contract modifications for C3PAO/DIBCAC requirements work, and why Phase 1 self-assessment is still urgent.
  • Mitigating False Claims Act Risk: How to ensure your SPRS score is accurate, defensible, and audit-ready against DOJ scrutiny.
  • Right-Sizing NIST 800-171 Controls: How layering Okta (Identity) and Virtru (Data Protection) satisfies key controls across the 110 NIST SP 800-171 requirements for organizations of any size.
Read transcript Hide transcript

Andrew Lynch

00:05 - 02:40

Alright. I think we're good to get started. Well, welcome everyone for joining, those who can.

My name is Andrew Lynch from Virtru. Today we're joined by, Naveed Mirza from Okta.

I'll introduce him shortly. We're going to be discussing, CMMC and some updates that came out around the July 13 Department of War, announcements, and, we'll touch on that lightly.

We wanna spend more time really discussing how two platforms, Virtru and Okta, together can address a significant chunk of, the compliance requirements, which are still required that we're gonna talk about. Just a few housekeeping items.

We are gonna be recording, the meeting today, and we'll share that out afterwards. Also, we're gonna save some time at the end for q and a.

So if you have any questions, just feel free to drop them in the chat box, wherever that's on your screen. For me, it's on the top right, and we will, get to those, as we go through.

So, again, welcome, Naveed Mirza. Naveed is a principal security architect at Okta.

He is significantly more well versed in all things NIST 800 dash one seventy one and some of the other, compliance acronyms that we're gonna be going through today. So I'll be leaning on him, heavily.

But, Naveed, thanks again for joining, and please introduce yourself.

 

Naveed Mirza

02:40 - 04:00

Yeah. Hi, everyone.

As Andrew said, my name is Naveed Mirza. I'm a principal solutions architect here at Okta.

What that means is that I'm one of the ones who comes in and helps our customers better understand how they can integrate Okta with the rest of their environment and really build, you know, build on our capabilities and the interconnects between everything else. My specialty is government compliance.

So, NIST 853, NIST 837, the new, you know, one seventy one require new, one seventy one requirements, as part of CMMC, you know, FedRAMP and all those. Been doing this let's just say I started last century and, and move from there.

But, yeah. So I've been doing this for a long time.

Always had a cybersecurity focus. Yeah.

And then a little bit about Okta. So Okta, we're your identity and access management provider in the cloud, 100% cloud platform.

We operate in FedRAMP high, FedRAMP moderate, DOD IL five, and IL four, as well. And, yeah.

Yeah. Got a lot of customers,.

 

Andrew Lynch

04:00 - 04:01

Great.

 

Naveed Mirza

04:01 - 04:19

Got a lot of great, great things going on. The only time you'll hear me say anything about AI because it's not that kind of brief, our big release, for this year was, the ability to, treat AI, agents as, identities within the Okta Stacks.

 

Andrew Lynch

04:19 - 06:27

That's great. Well, thanks again for joining, Naveed.

Certainly have a lot of, firsthand experience working with organizations that, again, need to meet, some of the compliance requirements and security requirements we're gonna be talking about today. So again, my name is Andrew Lynch.

I specifically lead the velocity sales at Versur. So for us, that's primarily, the smaller to mid sized organizations really in in every segment, nonfederal, but specifically today, we're gonna be talking more about the defense industrial base.

And, really what we do is we help organizations, protect their data. We our cofounder was involved with inventing the trusted data format, which is a open source data centric security standard, protecting data upon creation at the object level.

Virtru is FedRAMP authorized, at the moderate level or certified rather, I should say now. There's been some changes to the terminology, but, in the marketplace, using FIPS and 40 dash two validated encryption.

So specifically where we help is to, again, encrypt c y, whether that's being stored at rest, or in transit, with our end to end encryption, integrating into common workflows that you're using on a regular basis, whether that's Gmail, whether that's Outlook, whether that's Outlook in the commercial cloud or GCC. We're commonly an alternative to allows allow organizations to stay within those platforms that they're already using and not have to go through necessarily a costly migration.

Although we do work in those environments as well and have customers that are using all kinds of software, but as we're gonna talk about today, Virtru plus Okta together really can allow for, speed, agility, and flexibility when it comes to, again, not just meeting compliance because neither of our organizations or compliance organizations, we're truly about security. And so, why don't we jump in now? Again, if anyone has not seen, there was a announcement, on July 13 by the Department of War, around CMMC, specifically some adjustments to phase two.

So, Navin, I'll kick it over to you. Maybe if you wouldn't mind just recapping what happened.

 

Naveed Mirza

06:27 - 08:11

Yeah. Sure.

So, it was, you know, in military speak, a hand grenade down the hallway. All of a sudden, we get a notification that we're suspending phase two of CMMC for, sixty days.

And what does that really mean? It it means that we're carrying on the same way we are right now. All stop.

That's it. We're carrying on the same way that we are right now.

And really what it you know, on the back end, what I think the, the Department of War is doing is taking, you know, a a a, you know, the correct approach and doing an analysis. What's the bang for the buck here? Do we need all of these providers to go through, formal assessments? We accept self assessments.

We built that into the process. Do we need at some point in the time you know, in in the next, you know, sixty days, do we really need this line in the sand where we're gonna say everybody's gotta have these assessments? And, you know, they've they found, that a lot of the small, midsize businesses, it's really not cost effective to them.

You know? And if they have other ways of showing that they have done, you know, the, you know, the correct work, maybe there's an alternative scheme where they're still meeting the same requirements. They're just not that extra burden of, you know, the, the assessment cost.

And I think that that's what they're what they're going in with right now. They've even released an RFI, for, Andrew and I have been talking a little bit about kind of what our, you know, responses are gonna be to that RFI.

And, you know, they they're looking at industry to help right the ship here. You know? Like, you know, what's the what's the course correction we need to make?

 

Andrew Lynch

08:11 - 09:36

Yep. No.

I think I think you, you you kicked it off, in the right way, which is really nothing's changed, in the sense that the need to still, meet level two, and submit a SPUR score, showing that you're meeting or testing rather to meeting, NIST International one seventy one and in turn abiding by the d four seventy twelve clause. That that still remains, specifically, and for those who were not able to join the webinar that Virtue had last week where we went over this in much more detail.

So, again, don't wanna rehash too much. Specifically, just phase two was paused, and that's really the third party verification requirement, that was set to go into effect on November 10.

But the fact remains that, you still need to submit your self assessment score. You still need to have an affirming officer saying that you're meeting those, requirements for all the 110 controls, 320 objectives.

And so, you know, again, that has not changed. Maybe, Naveed, could you just maybe for those who aren't as familiar with, you know, what's the difference between CMMC level two versus NIST 800 dash one seventy one? Are they similar, the same, etcetera? Could you maybe touch on that from your experience? Is is approaching meeting them any different than, again, people that were working towards CMMC level two, for example?

 

Naveed Mirza

09:36 - 10:37

Well, the they are definitely related. Okay.

So one seventy one is a list of security requirements, that give you know, help you meet a security goal. CMMC is a process of vetting that you have met a set of requirements.

It just so happens that CMMC is based upon the one seventy one requirements. So there there's a subtle difference.

You know, one I would throw in the process and procedure bucket, and the other one is, the set of controls. So one seventy one, you know, as you said, you know, DFARS, seventy twelve is still there.

We didn't change it. That hasn't been changed.

So we still need to meet the one seventy one controls. You know, level two basically just says meet all 110 controls, you know, out of that catalog.

And, you know, and they've just really kinda suspended a part of the procedure, the next step in that procedural evolution.

 

Andrew Lynch

10:37 - 12:42

Yep. And so, as Naveed mentioned also, if if you hadn't followed, they, officially, again, paused it, and there's a sixty day review window where they're going to, as Naveed shared, allow anyone, including everyone on this call, to submit the responses to the RFI that was, put out on sam.

gov, where they have a set series of questions that you can answer. And as he shared, they're looking for those in the defense industrial base as well as the CMMC ecosystem, to provide feedback.

And, of course, none of us know what is exactly going to happen. But for those who, again, read the the memo, the official, announcement of phase two being paused, I think it was the second to last paragraph, specifically reminds everyone that, the need to still abide by, contractual obligations that you're bound to remain, which may, again, include the d four seventy twelve clause, and meeting the all the same controls in this international one seventy one that that are found in CMMC level two.

So, and and I I can attest it from my conversations, organizations that I've been speaking with, that were already on their CMMC journey, are realizing that, again, that that has not stopped. This is not a we no longer need to meet this.

It's purely, again, exactly what they said it is, a pause, in phase two, which is where the third party auditor, requirement could show up in contract. So that has been removed, for right now.

For those who, also, maybe haven't had the time to follow along with some other updates that have come out, I saw, Naveed, also, there was a FAQ document, that was released, the same day. And I wasn't sure if you were able to read that, and if you wouldn't mind maybe sharing for those who missed it, some of the updates that were announced in that as well.

 

Naveed Mirza

12:42 - 13:29

Yeah. So, you know, again, that FAQ has, been around there for a while.

They're kind of keeping it maintained. Truth be told, I wish they had a better way for us to provide input, you know, industry to provide input into the FAQ, because I have tried.

But, but yeah. So the they updated it.

They, you know, talked, a little bit more about kinda what the changes, you know, not even the changes, but what the operational pause is, things like that. So, again, you know, I'm not trying to downplay what happened on July 13.

It, but, but I will say that it was not as big of a deal as anybody else, or as a a lot of people in the industry,.

 

Andrew Lynch

13:29 - 13:29

Yeah.

 

Naveed Mirza

13:29 - 13:30

Sebas was.

 

Andrew Lynch

13:30 - 14:17

Yep. Yeah.

Exactly. Meaning, you know, I mean, nothing changed with, for example, you know, CMMC level two.

You're still required to self assess to level two following revision two of NIST 800 dash one seventy one. You know, the revision three has been released, but still CMMC is following level two or excuse me, revision two.

The federal requirements are all the same, you know, federal, moderate, equivalent, or authorized. You know, not nothing changed with that.

So, again, to Naveed's point, for those who have been just wondering, what change, maybe we should make in our approach towards meeting CNMC level two. I guess, what was your response to that being, Naveed? Would you recommend they continue? Would you recommend they pause?

 

Naveed Mirza

14:17 - 15:54

I I recommend you continue. Okay.

So here's the thing. And, you know, we're when you're part of that defense industrial base, you know, you are really you're not really a business anymore.

You are actually part of, you know, this giant conglomerate that is helping protect The United States and protect its data. And that's something I feel strongly about.

And, you know, one seventy one is not a bad set of requirements. There is nothing in there that I would say, oh my god.

We need to throw this out. It's stupid.

Right? And it's very liberal in that it doesn't tell you what screw to turn. It tells you you know, what what length of screw I need or anything like that.

It just says, use Phillips head screws here and everything else, you know, you're fine. It it basically sets a set of standards.

I run into a lot of conversations. In fact, just this morning, I had a conversation with, with one of our customers, where their consultant is telling them, you've got a two you know, well, we're installing, a local firewall on on our servers.

Well, yeah, but you've gotta turn that one on and the OS firewall. Well, why do I have to have both if one's a replacement for the other? Because CMMC requires it.

Well, it doesn't. It doesn't say in there at CMMC, you know, turn everything on and make nothing work.

So, you know, it is very, very flexible. There's a lot it's just it's guidance.

It's good, strong guidance on predicting confidentiality of government information.

 

Andrew Lynch

15:54 - 16:20

Yeah. I think that's an interesting comment too where you mentioned, you know, if you're in the defense industrial base, you're not just a normal small business.

You know, there there is this requirement now, based off of the type of information that you're maybe handling to ensure you're protecting it. And you also made the interesting comment of, you know, CMMC requiring anything where CMMC is the verification process essentially.

Right?

 

Naveed Mirza

16:20 - 16:21

Yep.

 

Andrew Lynch

16:21 - 16:34

Requiring it that has, been needed for some time. Right? Maybe remind everyone how long have, NIST 800 dash one seventy one, requirements been around.

 

Naveed Mirza

16:34 - 16:39

Oh, man. Has it been close to a decade?

 

Andrew Lynch

16:39 - 16:42

I think it was 2017. So, yeah, we're.

we're close.

 

Naveed Mirza

16:42 - 16:50

Yeah. It's been yeah.

Like, nine years, that we're supposed to have been doing this. Yeah.

Yeah.

 

Andrew Lynch

16:50 - 16:50

Yeah.

 

Naveed Mirza

16:50 - 16:52

I you know?

 

Andrew Lynch

16:52 - 16:53

yeah. Sorry.

 

Naveed Mirza

16:53 - 17:33

Oh, no. No.

I mean, you know, and we see it all the time. Right? We see that, a lot of our partners in the DIB, you know, they're losing government data.

We're seeing that time and time again. And most of the time, rarely is it, you know, the nation state, you know, you know, advanced persistent threat kind of a thing.

In a lot of cases, it really is just basic cyber hygiene would have solved some of these things. And,.

 

Andrew Lynch

17:33 - 17:33

Yeah.

 

Naveed Mirza

17:33 - 17:35

yeah, once that we won,.

 

Andrew Lynch

17:35 - 17:35

Yes.

 

Naveed Mirza

17:35 - 17:35

Yep. It's helpful.

 

Andrew Lynch

17:37 - 18:33

Yeah. No.

Again, you know and and I think at this point, this shouldn't be new to everyone, but, you know, if anything, everyone is given, a little extra time to, again, maybe look at which, c three p o they they would like to engage with. But, you know, there's obviously still the benefit and a competitive advantage of having a third party who are experts in ensuring you are actually meeting what you're saying you're meeting.

So you have a little bit more time to get to get that in order. The memo also, and just, you know, any updates have come out since, did remind organizations that, again, the DIBCAC still can conduct audits.

So maybe, Naveed, for those who are not familiar with, what that process is like or have maybe had one, could you just maybe remind everyone, walk everyone through just what is that? How is that different than any other sort of third party audit, and are there implications there?

 

Naveed Mirza

18:33 - 19:56

Yes. So, you know, DibCAC, government organization.

Right? So they're gonna come in, and they're gonna perform the audit. And they're also gonna perform the one seventy one controls in addition to the eight hundred and one seventy two controls.

And if you've looked at those, they are definitely, deeper, I would say. You know, they don't, again, tell you, you know, turn this widget 45 degrees to the left, but they do say you have to have this widget.

You have to have this thing, and it really is more of a large scale enterprise, you know, view of things. So, but, again, if you're operating in an environment where you need to be level three, you're dealing with weapon systems.

You know? You're dealing with these large national security programs, and that's really when we're thinking about nation state aggressors, and you know? So, those deeper level of controls are kind of the what's needed in that in that space. So, again, I feel that CMMC I'm I'm I'm definitely not a CMMC apologist, but I will say that I think that the architects of the CMMC program did a good job of layering the right controls for the type of work at each level.

 

Andrew Lynch

19:56 - 22:28

Yep. Absolutely.

We're gonna jump in here in a minute to how two of those, Virtru and Okta, can be layered on together effectively to achieve really best in class, security. But just, kinda rounding out, again, for those who hadn't been following, we shared again the DIBCAC, they did share in the memo, can still conduct, those audits.

That has not ended. The Department of Justice's is False Claims Act enforcement, still remains active.

And again, not to not to gaslight or scare anyone with, examples. You can research what those are, but there there have been a few in the past year or so, where they were not whistle whistleblowers, for example, who shared, false, attestation.

It was the DIBCAC, audited an organization that saw they were saying they met all one ten and asked for evidence as to how, and they weren't able to. So again, you still need to submit your SPUR score.

You're submitting your, level two self, assessment, in there. You have to do that every year.

And there's really, true risk if you, if you know you're, you're not and you're saying you are, so for those who have began their CMMC journey, whether you've engaged with consultants, or not, or considering using a c three p o. Again, there's a lot of resources available and a very well qualified community, to and and Versa, of course, has worked with with several of them, who can ensure you're helping to get there if you if you have questions.

But, the fact remains that you still just need to meet everything that you've been hearing about for the past two years or so around level two. Again, you just don't have to right now, go get a third party audit completed because that's not gonna be in a contract that that has been paused as of now.

So, Naveed, let's maybe transition into you know, we went over kind of the the risk associated with, you know, not properly meeting each control. And let's jump into, you know, what both of us can do.

Why don't we start with, with Unavide, maybe, beginning with, the identity aspect around protecting data and and where Okta fits in. So so what's a little bit more of your story as to how you guys fit into this international one seventy one and CMMC level two?

 

Naveed Mirza

22:28 - 25:03

Yeah. So, again, earlier I stated that we have FedRAMP high, moderate, and, DOD I l four, I l five offerings.

I'll focus in maybe on our FedRAMP moderate because that is the sweet spot for most CMMC. I would recommend that if you're talking level three or if you're a large enterprise business, really start looking at FedRAMP high, just to kinda give yourself the added protection.

However, out of the NIST, 171 controls, there's a 110 controls there. We clock in at, meeting or supporting, about 50 of those controls.

So anything that deals with identity and access management, which is a lot. Right? If you remember the CIA triad from, you know, from your basic cybersecurity training, you know, we're not you know, one seventy one doesn't talk about availability.

It doesn't talk, too much about integrity, and it really focuses in on the confidentiality. And confidentiality is not always encryption.

Right? So encryption is a piece of it, but it's the access to, the data. So, yeah, it it is definitely skewed towards something, that that, Okta is, very familiar with.

So, we like I said, we support a bunch of those controls, and then we have sort of a layered approach as well. You know, smaller businesses can kinda just buy maybe a core bundle.

And then when you get into larger businesses, one of the you know, some of the controls are like, hey. Prove that you, you know, can do, you know, the move ad change or, you know, join or move or lever, flows.

You can do it manually, and you can just show them a PDF or, you know, you know, when the with a full Okta Suite, with our governance platform, you can show that somebody's onboarded by HR. Their account gets created.

They're added to the correct groups. They get the right identities or, you know, access to the applications based upon their job role in HR, their job role changes, that ripples effects, modifies their account, pulls access from where they no longer need it, grants them access for where they need it.

And then when they finally leave the company, then, you know, we can show that their accounts get, de-provisioned, and you're, you know, no longer, you know, taking access away. So so, yeah, you can show these automated flows to your auditors, and that's just better in the long run than showing that I've got a PDF and a logbook of all the people that have left the company, you know, that that kind of a thing.

 

Andrew Lynch

25:03 - 25:45

Yeah. That's, and he made some interesting points that I think, you know and from the beginning where we thought there was some synergy, you know, between these two, organizations doing this webinar together is that, you know, a couple things.

One, you know, neither of us are just came out for CMMC. And there's nothing wrong with organizations that have done that.

You know, there are, again, roughly, what, a 100,000 organizations that it said need to meet CMMC level two with all different workflow requirements. And there have been no shortage of organizations and tools and softwares that that really popped up, because of the CMMC announcement where, you know, Virtua has been around since 2012.

Okta has been around since roughly when, Naveed?

 

Naveed Mirza

25:45 - 25:47

I think roughly around the same time.

 

Andrew Lynch

25:47 - 25:55

More time. Yeah.

You know, we have over, you know, 6,000 customers in total. Okta has significantly more, I'm sure.

 

Andrew Lynch

25:58 - 27:13

But, you know, at the core, neither of us are compliance companies. You know, we're commonly helping organizations meet compliance.

You know, Virtru, for example, again, works with, you know, the defense industrial base, but also state and local governments, public schools, and thousands of health care providers that need to just protect data. And that was similar to Okta, as well.

Right? Where you guys, you know, didn't come out just to meet one, you know, data or or security requirement rather. You came out for, for several, for organizations as a whole to protect, themselves.

And so why I was getting to that was you mentioned, you know, like an HR use case, for example, where and that's kind of what some some things we're gonna talk about today. Just why would an organization maybe go with an Okta or a Virtru versus just maybe one of these all in one solutions, like an enclave that says they can help with a 108 out of the 110 controls.

So maybe could you speak to a little bit more about that, Naveed, from your perspective with Okta? You know, what would be what would be some of the reasons that you would tell someone if they're asking, well, could couldn't I just use what I already have? It it meets the requirement. What would your response to that be?

 

Naveed Mirza

27:13 - 28:15

it it depends on how much you like pain. Right? So you can always use what you have.

You can always go to more of a monolithic environment. For those of us who've been in IT for a while, that's just not really how computers work.

Everything is modular. And everything that you do, you know, should always be, let me find the best thing for this function.

And when you choose a very carefully chosen stack of, you know, partner applications like Okta and Virtru, you can now really build in that flexibility. You know, I'm not really beholden to whatever monolithic platform a wants me to do.

I can now I've got more switches, more levers, and I can really build my business processes. Because at the very end of the day, CMMC is actually validating that you have secure business processes within your company.

So yeah. We did also have a question, that I did wanna just quickly address.

 

Andrew Lynch

28:15 - 28:16

Sure. Yeah.

 

Naveed Mirza

28:16 - 29:16

And that was, I did mention earlier, that we've released, what we call Okta for AI agents. And what we have done, in that platform, very succinct, is, we have now created a new account type for AI agents, and we can do, what we call cross app, access with AI agents.

So the agent, Naveed creates an agent that, that agent has credentials that are tied to me. So when the agent goes to authenticate against something, then, you know, it'll do us like an an OAuth flow, but it'll be on behalf of and then, you know, you know, it's validated that I am the one who created that agent.

I have part of the signing process, and then now the agent gets granted access. And then that way, we can also use, OAuth scopes, to, you know, kind of put the guardrails on what those agents can do.

If you have more questions, we've got, some, great material on our website, and I'm sure we'd be happy to, you know, have a sit down.

 

Andrew Lynch

29:16 - 35:29

Yeah. Thanks, Naveen.

So yeah. I I I saw the next question, is actually more around, where Virtru fits into this.

And thanks, Naveed, for sharing just a little bit more about kinda where you guys fit in to CMMC, and we'll, of course, continue the conversation there. And so, you know, where Virtru fits in is, I would say slightly different.

You know, at the core, again, Virtru, think of us as an encryption wrapper. We're encrypting data upon creation with separate sets of encryption keys.

So for specifically around AI, you know, we've actually had more of the, I would say, concerns around can AI and how can it access our data and use it, where if it's encrypted with Virtru, it's essentially just gibberish. You know? So, we're wrapping every piece of data with separate sets of keys, allowing our customers to also easily host their own keys to have true ownership, around the decryption of their data.

So specifically for AI, that's actually where we've been having a lot of conversations recently with organizations in every sector putting CMMC aside. Where we fit in specifically again for, you know, CMMC, it's very similar.

You know, a lot of organizations that we're talking to, if they're on GCC high already, for example, you know, why would they want to add in, you know, Virtru, whether it's for an email or a file sharing workflow? Well, one again, it's the level of encryption we're doing and and the fact that it's open source and, you know, the fact that you're not giving all the keys to the kingdom, to one organization. But also as Naveed mentioned around flexibility and speed, you know, having used Okta, prevalently, it's easy.

You know? There are alternatives. I'm sure I I'm not involved in any sort of evaluation of technology tools we're using for compliance.

But I talk to people on a regular basis about encryption, specifically, and that's really big where organizations, they just want it to be easy. Are there other ways to send an encrypted file to someone? Yes.

There are. Absolutely.

Do they meet CMMC requirements? Yep. There are there are a fair amount of those that that do.

But do they have recipients create accounts and remember and create passwords? Most of them do. And so that's one of our, unique differentiators and one of our patents with the Securator where recipients, never need to create usernames or accounts.

They can, they still have to authenticate. Again, insert the, the connectivity with Okta.

So Virtru is using zero trust architecture. You're always having to authenticate, but we allow them to do so with existing credentials.

So there there are no usernames or passwords. I was I was meeting someone yesterday where they asked, you know, what sort of feedback do we hear from customers and complaints? And I joked and said, well, what I can assure you is you're never gonna your IT team is never going to be asked, how do I reset my password? Because there are none.

There are no passwords with Virtru. And it sounds trivial, but if anything, in the in the whole CMMC landscape of conversations, I I yeah.

I I do empathize with organizations who are working towards, meeting this. Maybe they're realistic in saying, hey.

We weren't. We haven't been.

We're getting our act together now. And, how nice is it to just take that off of their plate where they don't have to worry about, those additional requests, the people that they're sharing things to? I mean, I I often hear from customers, you know, that who they're sharing data to, they're actually not allowed to make accounts.

You know, they're just not able to. And so, again, as Naveed shared, it's we're we're working with we we are we're both supporting the the defense industrial base, which is which is then supporting our our our nation.

But, ultimately, everyone I'm talking to, they're usually trying to, you know, fulfill a contract, win business, generate revenue. And if you're using tools that are essentially making that harder to collaborate, well, why? You know, when when is Naveen shared, you're you're going out, you're looking at different options to meet compliance, but really the end goal is sick, you know, is is protecting, information.

And if you have the option of very secure, very hard to use or very secure, flexible, quick, easy to use, why not go with the other? Of course, I know that there are differences as Naveed mentioned with budgets and costs, etcetera. But, you know, really, the true cost of ownership rarely is then higher with tools that are, again, flexible, and foster collaboration.

So, yeah, that's kinda, you know, just a little bit where, you know, some of the recent conversations. I know I kinda started with AI there.

But similar to Navient, of course, we have a a a responsibility matrix showing, you know, which controls we help with. Our ours is we believe we're being a little bit more, conservative than maybe other encryption tools where it's 27 out of 110.

Of course, how you're implementing Virtru, of course, you can, you know, inherit, other, things based off of if you're just using Virtru versus integrating with others. But, so together, you know, we're neither of us are saying that that we do everything.

Right, Naveed? And, you know, having talked to organizations that, are considering, you know, an enclave tool that can help with a 100 plus, those may get you to, again, your, you know, level two certification, quote, faster, you know, but are they also going to then be conducive to conducting business and actually what you need to do? So maybe, Navit, can we talk a little bit more about that again knowing I'm sure Okta has clients in of every size in every industry. But what are some of the, you know, advantages from your perspective of using Okta, you know, with organizations, maybe where it's a larger organization, but they're implementing, you know, Okta for a subset specifically for CMMC.

What maybe additional workflow requirements may they have that come up that from what you've seen, you know, maybe what's included, what they have access to, it would not be conducive for what they need to do.

 

Naveed Mirza

35:29 - 38:13

So, for, like, say, mid to larger size companies where they're gonna have, you know, both civilian, you know, commercial clients as well as, say, military clients, yeah. They tend to split.

You tend to have that separate enclave, type of environment. You know, we use the term enclave.

They're virtual boundaries now. But yeah.

So, a a lot of the things, really, like, in my opinion that, that folks forget about is the governance of the identities. I now have an employee with, identities in two different zones.

Right? That employee is gonna have something in the commercial zone. They'll have something as well in the, in that that CMMC zone.

At Okta, we're living through that. Right? So we have that that kind of separation, you know, within the business.

And, you know, I juggle two different identities. Well, how are they bound together? How if, you know, you know, I I win the lottery and, you know, peace out and, you know, what happens? Again, that's that governance layer, that we put on top where now I can have that life cycle management of my record.

You know? Somebody goes in, into our HR platform and says, hey. Naveed no long Naveed won the lottery.

He no longer works here. You know, and then it backtracks and just removes all access.

That way, you know, my account is still technically there, so now we've got that verifiable, that I was there. It's a deactivated account.

And for any records management purposes, legal purposes down the road, You know, we don't I don't advocate deleting old accounts. I I recommend deactivating them for a period of time.

But yeah. Yeah.

So, you know, we can help with all of that. Attestations are fantastic.

So I I see we've got, you know, quite a few questions, I think, going on about, like, nonhuman identities and things like that. And I don't wanna, drag us too much into that because I think it loses focus from CMMC.

But, what I will say is that, you know, maybe I have my organization, organizational policy such that I have to re-attest, that my AI agents are still there on a semiannual basis, maybe every six months. So maybe every six months, Okta itself sends me an email saying, hey.

You've gotta do this re-attestation campaign, or we'll pull the credentials for your agents. Right? And and that is just a good strong way, to make sure that I don't have, you know, agents, that exist, you know, after the person who was using them, has gone.

 

Andrew Lynch

38:13 - 38:27

Yeah. And you mentioned kind of the audit component.

I know that's obviously big around CMMC. Could you maybe speak a little bit more around, you know, where Okta is helping with meeting some of those controls and objectives?

 

Naveed Mirza

38:27 - 39:44

Oh, yeah. Absolutely.

So, you know, I mean, as far as logging goes, you know, we're we have a very robust logging model. Definitely pair it up with, like, your SIEM tool.

We also, will ingest signals from other tools. So, like, maybe your EDR, you know, now talks to Okta, and we can kinda take that into account.

So, like, hey. The risk of this workstation went high.

Maybe this workstation shouldn't log into business critical applications. You know, so we can kinda do things like that, and then, you know, dump those to logs.

We also have our, posture management, overlay as well that with posture management and linking it to, you know, back into, like, AI. Hey.

I have these agents that have been detected that are not registered in with Okta, so let's find out who they are, who they belong to, get them properly registered in Okta, get them so that Okta manages those accounts for those agents. And then that way, if I ever have to, I can log the agents out and revoke their permissions.

 

Andrew Lynch

39:44 - 41:12

Got it. Yeah.

And similar just with virtual because of how we're doing encryption, we're encrypting every piece of data separately. So for example, if you're sharing an email with a with an attachment, you know, the body is encrypted separately than the attachment versus alternatives are commonly just encrypting the whole payload.

That allows for with the trusted to format granular audit capability, all of that can be also logged into a SIM tool. And, again, you know, where we would integrate, for example, with, with Okta would be allowing, an organization to then, you know, provision, and and manage their virtual licenses, but also then from an authentication perspective, allowing you to not have to create existing or rather new credentials or passwords and just leverage, you know, what authentication tool you're using like Okta, and in turn get the audit trail, picked up, from there as well.

So we kinda touched on Naveed, and this comes up a lot. I know I know more specifically with small businesses, the enclave tools.

Ken, you mentioned Okta, being used in an enclave. I guess from a deployment perspective, what would be the difference in deploying Okta, whether you're deploying it to, you know, 10 users within a 100 employee organization or, you know, 5,000 users within a 5,000 employee organization? What what's the difference? And can you maybe speak to just the overall lift from a deployment perspective?

 

Naveed Mirza

41:12 - 42:52

As well so we're cloud based. So from an actual lift of, like, standing it up, it's about the same lift.

The only difference that I would say is if I've got 10 people, I can maybe be less thoughtful in my approach on day one and get away with it and just, you know, clean things up. If I mess up an application deployment for 5,000 people, that's a little bit, you know, harder to recover from.

So, you know, again, just a thoughtful approach, you know, for the larger businesses. What are my user groups gonna look like? What am I going you know, what, you know, what business units, you know, are there? Like, go down to the business unit level of, like, okay.

I have somebody who works in this business unit. What applications do they need? Figure out what your we call birthright applications are.

What are those applications that all employees need access to? And then, you know, essentially build out a matrix, build your authentication policies for those apps so we can split so that, like, for instance, maybe to log in, to, you know, email or, or something like that, you know, I can use I I hate saying this, but, like, an SMS. Okay? Something like that.

But then mission critical applications or to get into the CMMC side of things, you know, maybe I'm using, you know, a hardware FIDO two token. And it's the same user account.

I just have multiple authentication methods. And at the per application basis, I can set what the authenticators are required for that application.

 

Andrew Lynch

42:52 - 44:42

Yeah. No.

I think very similar with Virtru. And, again, one of the benefits, it's all cloud based, you know, with our email encryption.

We're just integrating directly into the existing mailbox you already have. So you're not setting up a new email address.

There's no gateways you're setting up. You can truly use it within three minutes of purchasing it.

And then with virtual collaborate, which is where you can store, see why you can organize it at rest. You can send and request files.

Again, cloud based, depending on how and if you, you know, provision it and deploy it. Integrating with Okta, for example, that's just one integration.

Same with setting up a SIM integration, for example. But, you know, at a high level, very similar.

You know, more thoughtful approach with larger deployments if we're working with, you know, an entire state, for example, ensuring that we have all of the groups aligned, etcetera. But if it's 10 employees, which you certainly can purchase Virtru for, you know, five to 10 users, you can provision them ad hoc instantly, or create a provisioning group, and be using it truly within the same day, being able to later configure roles, if you'd like to.

And, again, we have from a CMMC support perspective, you know, no shortage of resources to help you ensure you're configuring virtual correctly, setting up rules, setting up your audit trail. So I I would say very similar.

So I I know we've got a few questions, over the course, of the session. I'm glad to see that, we're able to answer those.

I guess before we jump into the the last remaining questions, Naveed, from your perspective, anything else that you wanted to share, maybe an organization who is considering reaching out to Okta for CMMC, and maybe why you recommend that they would?

 

Naveed Mirza

44:42 - 46:34

Oh, yeah. Absolutely.

I I feel like we just have a fantastic value proposition. We'll meet you where you need to be.

You know, sir, some customers, you know, FedRAMP moderate is the right sweet spot. Some places, you know, I've got some large defense customers who, went on the CMMC journey and just decided on day one, no.

We're gonna do FedRAMP high because it makes the most sense for our business. And then that way, they're not having to do separations in these tiny little pockets of FedRAMP high and other places based upon, you know, contract requirements.

Because at the end of the day, this is all about the contract requirement. Like, that's it.

Like, you know, CMMC is a guideline for contracting officers to implement security, you know, in their projects. So, so yeah.

Yeah. The other thing that I would also say is is this, and this is a a tiny little soapbox that I'm I've been on lately, And that is, if you look at the scoping guides, you know, for the scoping guide for level two, you can get away with convincing yourself, that a tool like Okta or even a tool like Virtru might be an SPA and therefore not need to meet, those FedRAMP requirements.

And by the letter of the law, you could probably get away with it. However, if you actually go back and look at the number of controls that a tool like Okta is gonna help you meet out of CMMC, you know, we're, you know, over 45% of the controls.

You know, I think, you know, Okta's gonna be able to help you with. So so why would you not wanna do, you know, at least a FedRAMP moderate instance? And quite honestly, I actually have thrown that question back out to DoW and, have yet to get a response.

 

Andrew Lynch

46:34 - 46:35

Yeah.

 

Naveed Mirza

46:35 - 46:53

But, but, you know, it was like, hey. Should we update the FAQ to really talk about your access control requirements? Because if if they've got a loophole that lets you say that my identity and access control stack doesn't need to be FedRAMP, then why bother with anything else being FedRAMP?

 

Andrew Lynch

46:53 - 48:07

Mhmm. Yeah.

From, my conversations, I mean, most commonly an organization comes to Virtru when they are on a commercial cloud of something. And and and, I would say they they know pretty clearly, hey, we cannot store or send or transmit c y in Microsoft commercial cloud, and and we see Virtru can help us with that, which which we definitely can.

We're not a complete replacement for GCC High, but, rather than a six to twelve month migration and lots of money, you can install Virtru and, still, communicate in certain workflows like email and sharing files that that you need. And specifically, when it comes to the federal, requirements, you know, again, I know you guys have significantly higher attainment with, federal high and I l, IL four.

Virtru is federal authorized at the moderate level. and we hear from lots of organizations, assessors included.

Of course, they have taken unbiased approach, but, that there's there is a difference between FEDRIP authorized and equivalent, you know, from a risk, notification for a breach to the documentation. But, you're truly the gold standard is an authorization, which I think they recently changed to called certified.

 

Naveed Mirza

48:07 - 48:07

Yeah.

 

Andrew Lynch

48:07 - 50:20

But you get. the you get the point.

So, again, we're authorized, and, you know, just my soapbox would be again, it doesn't have to be hard and take a long time. We don't do everything.

We don't say that we do. I've learned from conversations and I believe in options.

I truly do. I've talked to some organizations where I've said, you know, I honestly think one of these all in one solutions like an Enclave, may be better.

You know, if they're saying I've never handled CUI. I don't know if I ever will.

I'm just being told I need to do this. Well, that I would go actually ask the contracting officer for more clarification.

But you get the point where, you know, Virtru and probably Okta two. It's not for everyone, you know, but those who, are, you know, know they need to meet it.

They need to be able to, collaborate in a manner that's conducive to facilitating business and not just checking a box. You know, we we have a saying internally, you know, we really don't work well with box checkers.

You know, there are cheaper solutions. You know, we are a data security tool offering of the highest level of security that's also extremely easy and giving you granular control over your data.

That can be set up and implemented very easily. But we're not gonna be the the cheapest tool out there, for lots of reasons, because that's not easy.

What would the trade offs we're limiting are not easy to do so. That said, rarely are we totally out of someone's budget.

But that would be why, you know, why Virtru is, we can help you get a couple easy quick wins, and truly align to the whole purpose of CMMC, which is actually protecting information, and not just checking a box. So I think we have a couple more questions that came in.

One was just Naveed. Does can Okta be deployed? It's this question for both virtual Okta.

Are there a minimum requirements of number of licenses, that need to be deployed, or can this be used for a small organization?

 

Naveed Mirza

50:20 - 51:05

Yeah. So we're currently tackling that, because CMMC skewed our customer base a little bit, back towards some of those smaller businesses, which I feel is fantastic.

So, what we're working on right now is creating a bundled SKU of, you know, an Okta for small business CMMC kind of a thing. And, hey.

Here, you can get, you know, for, you know, 10 licenses of, you know, the or life cycle management, Okta governance, you know, universal directory, and advanced multi-factor, and that's gonna hit that sweet spot of probably 48 of the 50 controls that we can help you support.

 

Andrew Lynch

51:05 - 51:59

Cool. Yeah.

And so similar with Virtru, you know, we, you know, work with organizations, again, of all sizes. We have some of the largest organizations that need to meet CMMC using Virtru.

We also have lots of really small ones. So we have packages designed for small businesses, that, with us, it's what they're purchasing.

It's, you know, the same coverage from a number of controls and resources, and deployment support that you get. But, yeah, there's no minimum.

It could be it could be one user. It could be a thousand.

So, totally across the gambit. Another question was, can and I again, I think this is pretty easy one, but, are you limited to only using Virtru or Okta for CMMC if you purchase it for CMMC? So I guess the question there is, can you also use it for, you know, commercial, you know, HR.

 

Naveed Mirza

51:59 - 52:30

Oh, abs yeah. Absolutely.

From an Okta standpoint, just out of the box, we have 7,000 plus integrations, with other applications out there. And if we don't have something prepackaged, you can always, build your own custom integration.

It's a little wizard that you walk through, to either do SAML or, or, you know, OIDC, interconnect to the app. So, so, yeah, we we don't put any guardrails on that.

You buy Okta, you buy Okta.

 

Andrew Lynch

52:30 - 53:46

Yeah. Yeah.

And exact same and I would say this is again, definitely different than, again, if you were to go with a CMMC enclave tool, you're probably just gonna be using it for CMMC. But with Virtru, you're you're just buying software that just so happens to meet the CMMC requirements.

It's the same software, that a dentist is using to send patient information. They don't know what FIPS one forty dash two validation is nor do they care.

They just want something to be easy and meeting requirements, and give them control over the data. So exact same, you can use it for all use cases.

You're you know, I just I just had a, a very small one employee defense industrial based customer who, looked into Versa for CMMC and by the end was saying, I'm gonna use this because they're actually hiring their first employee to receive their onboarding, you know, documents, rather than send it just over a a TLS encrypted email. So, certainly, you can use it for all different sorts of use cases.

I think I think we touched on this, but the another question was just around just, what is the level of technical ability needed to deploy Virtru and Okta? So could you maybe speak to do Naveed, could someone who's maybe not extremely technical deploy Okta, or do they need a dedicated IT team or MSP, for example?

 

Naveed Mirza

53:46 - 54:51

I I wouldn't say you need a dedicated IT team, but also, you know, I wouldn't maybe hand, you know, the the the keys over to, you know, a a a teenager with no experience. Again, especially when we're dealing with CMMC, we have to make sure that the policies that we implement make sense and that we're meeting, the meeting the framework.

Okta is just a tool to help you meet it. So I would say that we are extremely easy to use.

You're not gonna be, you know, you know, which app, you know, APT, you know, apt get command do I have to run to get this particular package? So so none of the craziness that you would have in, like, a pure Linux environment or anything like that. So we're very, very turnkey, and we have a lot of great support, you know, on our developer side.

So, you know, we we'll walk you through how to integrate with Office three sixty five. I wanna use Okta as my MFA solution for o three sixty five.

It's a built in, integration, so we'll walk you right through it.

 

Andrew Lynch

54:51 - 54:53

Yeah. Thanks, David.

Yeah.

 

Naveed Mirza

54:53 - 55:03

To do for. your business.

Well, I was gonna say, what you need to do for your business and the policies that you need to follow, that's where you've gotta have some thought.

 

Andrew Lynch

55:03 - 56:15

Yeah. I I I would say similar.

You know, I would say at a high level, you know, our email and file encryption tools, those truly, you don't need to be technical at all. But depending on what additional aspects of virtual you deploy.

For example, we are, a, key manager for, Google Workspace client side encryption where you're essentially setting up your own private key server. So for that, you're gonna need likely someone with technical ability.

Similarly, if you're setting up their virtual private key store to host your encryption keys, or a virtual gateway, for example, yeah, you you'll need, some technical to support. But our basic SaaS offerings are truly very easy to deploy, again, within minutes.

But similar to Naveed, specifically for CMMC, there are, requirements where, you know, you have to have FIPS mode turned on, which we have to turn on for you. And there are some rules you could configure to, you know, ensure certain things don't leave, or warn a sender if, if CUI is detected, for example.

So those all do take, just some configuration, but you, of course, get a customer success manager that's gonna, support you, working through that. So I think that's all the questions we have.

Again, thanks everyone for joining. Thanks, David, for the time.

Appreciate the partnership.

 

Naveed Mirza

56:15 - 56:16

you.

 

Andrew Lynch

56:16 - 56:49

And, again, great to see, all the, joint Virtru and Okta customers who are already working towards or have already achieved level two for CMMC. We, would again advocate and suggest organizations keep working towards it because as Naveed kicked off this session, really nothing has changed.

You still need to meet this. And for those interested, we will ensure that, we'll follow-up with contact to get in touch with, the Okta team as well as Virtru.

Thanks everyone for the time today, and thanks again to Naveed.

 

Naveed Mirza

56:49 - 56:51

Thank you, Andrew.

 

Andrew Lynch

56:51 - 56:53

Take care, everyone.

 

Naveed Mirza

56:53 - 56:54

See you.