2025 Impact Summary is now live (12/16/25)
NSPM-33 Proposed Cybersecurity Controls
Presented By: Michael Corn, Vantage Technology Consulting Group
The proposed guidelines for NSPM-33's cybersecurity requirements include 14 fundamental cybersecurity practices drawn from NSF policy. As a member of the EDUCAUSE & Federal Demonstration Project working group that drafted those guidelines, Mike will be providing an overview of what they are, how they're intended to be understood, and discuss the implications of each for institutions and security practitioners. In short Mike argues - pay attention, but don't panic.
From Learning Assessment to the Real Deal - How UCSD Approached the CMMC L2 Assessment
Presented By: Winston Armstrong and Sandeep Chandra, University of California, San Diego
UC San Diego collaborated with the CyberAB in August 2023 to complete a CMMC L2 learning assessment. In this session, the team reflects on that experience from the other side of certification, sharing what proved valuable, what surprised them during the official assessment, and how they are thinking about sustaining the program moving forward.
[Q&A | Presentation | Recording] **Follow-up Session for Q& A 2/20 @2pm ET / 11 am PT
For full descriptions, download meeting notes, and recordings
Institutional Showcase | Community relationships and collaboration opportunities; Establish Community Inventory; Surface Community Needs; Help emerging centers through CoP and discover mentoring opportunities
AI In Regulated Research: Practical Uses + Cybersecurity Considerations | [Recording] | Jan. '26
Cracking into Culture: Infusing Cybersecurity into the Culture of our Research Enterprise at GTRI [Recording] | Nov. '25
Transforming Endpoints into Beginning Points [Recording] | Sept. '25
Lessons Learned - NC State’s Journey to CMMC Level 2 Compliance [Recording] | Q&A + Office Hours Transcript | Jun. '25
Research Security Offices: Structure, Organization and Operation [Recording] | Apr. '25
Tackling NIST 800-171 HPC Challenges: Insight and Lessons Learned [Recording] | Feb. '25
Do you know your campus government relations team? [Recording] | Nov. '24
Assessment Experiences [Recording] | May '24
NC State Regulated Research Responsibility Ownership [Recording] | Mar. '24
Certifying HiPerGator for Protected Health Information [Recording] | Dec. '23
Debrief of first-ever - CMMC Learning Assessment [Recording] | Nov. '23
CU Boulder CMMC Gap Analysis Lessons Learned [Recording] | Oct. '23
Climbing the NISTy Mountains: A travelers guide [Recording] | Aug. '23
Panel on GRC Tools [Recording] | Apr. '23
Financials & Cost Model [Recording] | Feb. '22
NIST 800-171 Compliance Journey [Recording] | Sep. '22
Impact of Cybersecurity on UCF Research Administration [Recording] and The UChicago Security Research Data Strategy and Secure Data Enclave [Recording] | Nov. '22
System Security Plan Innovators [Recording] | Mar. '22
Researcher Focused Session | Strengthen relationships with impacted domain researcher; Gather feedback on their interests from the community; Develop collaboration opportunities
Facilitating Research: Intersections with Security at UCSD [Recording] | Sep. '23
Compliance & Researchers: Teamwork makes the dream work [Recording] | May '22
Training Topic | Establishing Community Inventory; Develop Community Skills; Address Gaps Missing at the Institutional Level
Sustainable Documentation: Debrief of CPPC'25 Full Day Workshop [Recording] | July '25
What’s In or Out? Compliance Check-In [Recording] | May '25
Flipping the Script on CMMC with ARFL Digital Research | recording by request: info@regulatedresearch.org | Mar. '25
C3PAO Perspective on Sponsorship and Governance [Recording] | Jan. '25
CISA Resources [Recording] | Oct. '24
Navigating Clinical Research Operations and Compliance [Recording] | Jul. '24
Debrief of "A Day with the CMMC Assessors" workshop [Recording] | Jun. '24
What you really need to know about HIPAA [Recording] | Apr. '24
CMMC 2.0 Rulemaking by Jacob Horne [Recording] | Feb. '24
The Path to CMMC Assessment [Recording] | Feb. '23
ChatGPT for CMMC Compliance [Recording] | Mar. '23
System Security Plan Workshop Deliverables [Recording] | May '23
NIST SP 800-171 R3 [Recording] | Jun. '23
Preparing and Engaging with Third-Party Assessors [Recording] | Aug. '22
Making FAQs & Documentation More User-Friendly [Recording] | Apr. ' 22
Convenience vs Security & Debrief from Certified CMMC Professional course [Recording] | Oct. '22
Tales from the IT Policy Office at the University of California [Recording] | Dec. '22
Strategic Partnership | Dedicated time to the partners to hear from the community
Ask the Assessor LIVE + RRCoP Resource Roundup [Recording] | Dec. '25
Bridging the Gap: Developing a Regulated Research Implementation Guide [Recording] | Aug. '25
Trusted CI & RRCoP: The Next Five Years [Recording]| Dec. '24
EDUCAUSE Policy Review [Recording] | Sep. '24
Voices from Aligned Communities [Recording] | Jun. '22
NIST guidance document for implementing controls on HPC systems [Recording] | Jan. '23
Department of the Navy Blue Cyber Education Series for Small Businesses and Academic/Research Institutions [Recording] | Jul. 23
Biomedical Programs & HITRUST [Recording] | Jul. '22
All Hands Meeting | Addressing updates from Academic and Industry
RRCoP Planning and All Hands [Recording] | Jan. '24
Overview of RRCoP and Planning [Recording] | Jan. '22
Assessment | Confirming that RRCoP provides value; Planning for future needs
RRCoP Then & Now [Recording] | Aug. '24
March 11 @ 2 pm EST / 11 am PST
April 8 @ 2 pm EST / 11 am PST
May 13 @ 2 pm EST / 11 am PST
June 10 @ 2 pm EST / 11 am PST
July 8 @ 2 pm EST / 11 am PST
August 12 @ 2 pm EST / 11 am PST
September 9 @ 2 pm EST / 11 am PST
October 14 @ 2 pm EST / 11 am PST
November 12 @ 2 pm EST / 11 am PST
December 9 @ 2 pm EST / 11 am PST
2027
January 13 @ 2 pm EST / 11 am PST
February 10 @ 2 pm EST / 11 am PST
March 10 @ 2 pm EST / 11 am PST
April 14 @ 2 pm EST / 11 am PST
May 12 @ 2 pm EST / 11 am PST
June 9 @ 2 pm EST / 11 am PST
July 14 @ 2 pm EST / 11 am PST
August 11 @ 2 pm EST / 11 am PST
September 8 @ 2 pm EST / 11 am PST
October 13 @ 2 pm EST / 11 am PST
November 10 @ 2 pm EST / 11 am PST
December 8 @ 2 pm EST / 11 am PST
2028
January 12 @ 2 pm EST / 11 am PST
February 9 @ 2 pm EST / 11 am PST
March 8 @ 2 pm EST / 11 am PST
April 12 @ 2 pm EST / 11 am PST
May 10 @ 2 pm EST / 11 am PST
June 14 @ 2 pm EST / 11 am PST
July 12 @ 2 pm EST / 11 am PST
August 9 @ 2 pm EST / 11 am PST
September 13 @ 2 pm EST / 11 am PST
October 11 @ 2 pm EST / 11 am PST
November 8 @ 2 pm EST / 11 am PST
December @ 2 pm EST / 11 am PST
2029
January 10 @ 2 pm EST / 11 am PST
February 14 @ 2 pm EST / 11 am PST
March 14 @ 2 pm EST / 11 am PST
April 11 @ 2 pm EST / 11 am PST
May 9 @ 2 pm EST / 11 am PST
June 13 @ 2 pm EST / 11 am PST
July 11 @ 2 pm EST / 11 am PST
August 8 @ 2 pm EST / 11 am PST
September 12 @ 2 pm EST / 11 am PST
October 10 @ 2 pm EST / 11 am PST
Over the period between 2022–2024, RRCoP is committed to delivering sessions with different areas of focus. Below is the categories, total number of sessions, and a brief description of the content delivered at these meetings.
All Hands Meeting — 6x Addressing updates from Academic and Industry
Established Institutional Showcase — 5x Community relationships and collaboration opportunities; Establish Community Inventory; Surface Community Needs
Institutional Showcase — 4x Help emerging centers through CoP and discover mentoring opportunities
Researcher Focused Session — 3x Strengthen relationships with impacted domain researcher; Gather feedback on their interests from the community; Develop collaboration opportunities
Training Topic — 9x Establishing Community Inventory; Develop Community Skills; Address gaps missing at institutional level
Assessment Baseline & Planning — 3x Confirming that RRCoP provide value; Planning for future needs
Strategic Partnership — 6x Dedicated time to the partners to hear from the community