Kiteworks to spotlight vendor verification at National Cyber Summit 2026

Sep. 21, 2026
By AI, Created 12:00 UTC, Sep 21, 2026, AGP -

Kiteworks will moderate a National Cyber Summit 2026 panel on verifying vendor security claims as federal cloud authorization speeds up and zero trust moves deeper into the data layer. The discussion arrives as agencies and contractors face growing pressure to prove compliance with evidence, not assumptions.

Why it matters: - Federal and state agencies are making security decisions faster, which raises the risk of relying on vendor claims that cannot be independently verified. - The shift from network-focused security to data-layer zero trust changes how agencies and contractors evaluate cloud services, compliance, and access controls. - Defense contractors still face scrutiny even as parts of CMMC Phase 2 are paused, because self-assessments do not eliminate government review authority.

What happened: - Kiteworks said Craig Pfister, VP of Global Sales Engineering, will moderate “Verify, Don’t Assume” at National Cyber Summit 2026 in Huntsville, Alabama. - The session is scheduled for Wednesday, September 23, from 8:00 to 8:45 a.m. CDT at Exhibit Hall Stage 1. - Panelists will include Wayne Blockel, CISO at Yulista, and Eric Levitas, VP of Business Development at ControlCase. - Kiteworks and ControlCase will also exhibit at the conference from adjacent booths, #319 and #320. - Kiteworks is inviting attendees to schedule a meeting or product demonstration at its booth.

The details: - The panel will focus on how agencies can verify vendor security claims as more than 500 cloud services now hold FedRAMP authorization. - The newest services processed through FedRAMP 20x have been authorized in an average of five weeks, down from more than a year. - Kiteworks said its Control Plane for secure data exchange is designed to extend zero trust from the network to the data itself. - The platform verifies each access request at the data layer rather than granting broad access after a user or system is inside the network. - The discussion will compare that approach with FedRAMP authorization and CMMC self-assessment. - On September 3, DFARS Class Deviation 2026-O0025, Revision 3, wrote the CMMC Phase 2 suspension into contract text. - The deviation allows Level 1 and Level 2 status to be satisfied through self-assessment while Phase 2 remains paused. - DIBCAC and the Department of Justice still retain authority to assess covered contractors directly. - A DCMA finding still outranks a contractor’s own Self status. - Kiteworks holds FedRAMP High authorization in process and has held FedRAMP Moderate Authorization since 2017. - ControlCase provides compliance assessment services and is accredited as a PCI DSS Qualified Security Assessor, Approved Scanning Vendor, Authorized CMMC Third-Party Assessment Organization, and Registered Provider Organization.

Between the lines: - The panel reflects a broader procurement shift: agencies and contractors are being pushed to document evidence before they buy, not after a review starts. - Kiteworks and ControlCase have not formally announced a partnership, but the companies are already pairing their products and services in a shared conference presence. - Sean Kelley, Global Director of Strategic Alliances at Kiteworks, framed the issue as a verification problem across FedRAMP, zero trust, and CMMC self-assessments. - Eric Levitas said agencies and contractors both want proof that a vendor’s authorization or a contractor’s score would withstand scrutiny.

What's next: - National Cyber Summit attendees will hear the panel’s discussion on what any vendor should be able to prove today, with evidence available before an assessor asks. - Kiteworks and ControlCase are expected to use the event to show how their control plane and assessment services fit together for federal and contractor buyers. - The session may also signal how buyers will handle faster authorization timelines and stricter evidence checks going forward.

The bottom line: - As cloud authorization accelerates, the standard is shifting from claimed compliance to verifiable proof.

Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.

Sign up for:

World Politics Report

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.

Share this page:

Advanced Search Options

Search for:

Search scope:

Type:

Search in:

Date range:

The last

Sort by:

Sign up for:

World Politics Report

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.