Kiteworks moderates a National Cyber Summit 2026 panel featuring ControlCase and other thought leaders on verifying vendor security claims for federal and state agencies and their contractors
San Mateo, California | September 18, 2026
Kiteworks, which empowers organizations to effectively manage risk in every send, share, receive, and use of private data, today announced that Craig Pfister, VP of Global Sales Engineering at Kiteworks, will moderate “Verify, Don’t Assume” at the National Cyber Summit 2026 in Huntsville, Alabama, Wednesday, September 23, 8:00 to 8:45 a.m. CDT, at Exhibit Hall Stage 1. Panelists include Wayne Blockel, CISO at Yulista, and Eric Levitas, VP of Business Development at ControlCase, a global compliance assessment firm.
The panel comes as federal cloud authorization is moving faster than ever and zero trust is expanding from the network to the data itself. More than 500 cloud services now hold FedRAMP authorization, with the newest processed through the FedRAMP 20x program in an average of five weeks, down from more than a year. For technology leaders vetting vendors at that pace, the question is no longer whether a vendor claims to be compliant. It is whether that claim can be verified independently, down to how data is governed once the vendor is inside the network.
Kiteworks control plane for secure data exchange is built directly around that question for the federal sector, extending zero trust from the network to the data itself. Rather than granting broad access once a user or system is inside the network, it verifies every access request at the data layer, the same standard the panel will hold up against FedRAMP authorization and CMMC self-assessment alike.
For the defense contractors who work alongside those same agencies, the stakes are related but distinct. DFARS Class Deviation 2026-O0025, Revision 3, wrote the CMMC Phase 2 suspension into contract text on September 3, letting Level 1 and Level 2 status be satisfied through self-assessment while Phase 2 stays paused. DIBCAC and the Department of Justice keep full authority to assess any covered contractor directly, self-assessed or not, and a DCMA finding still outranks a contractor’s own Self status.
“Whether you’re the agency running the procurement or the contractor being assessed, the same problem shows up: a claim without evidence behind it is not worth much,” said Sean Kelley, Global Director of Strategic Alliances at Kiteworks. “That is true whether we’re talking about FedRAMP authorization, zero trust architecture, or a self-assessed CMMC score. We wanted ControlCase in the room because verification is their whole business.”
The session also reflects an existing partnership between Kiteworks and ControlCase, pairing the Kiteworks Control Plane with ControlCase’s compliance assessment services. The two companies, which have not yet formally announced the partnership, are exhibiting at National Cyber Summit 2026 with adjacent booths (#319 and #320).
“Agencies and contractors both come to us with the same ask: prove it,” said Eric Levitas, VP of Business Development at ControlCase. “For an agency that means showing a vendor’s FedRAMP authorization and zero-trust controls hold up under scrutiny. For a contractor it means showing a self-assessed score would survive a DIBCAC review. This panel walks through what we actually look for on both sides.”
Kiteworks invites National Cyber Summit 2026 attendees to schedule a meeting or product demonstration at the Kiteworks booth.
What the Panel Will Address
- Why the FedRAMP 20x program’s five-week average authorization timeline raises the bar for how agencies vet a vendor’s security claims.
- How the Kiteworks Control Plane extends zero trust from the network perimeter to the data layer itself.
- What changed, and what did not, under the September 3 CMMC Phase 2 suspension.
- What any vendor should be able to prove today, evidence-backed, not compiled after an assessor asks.
Session Details
Event: National Cyber Summit 2026
Session: “Verify, Don’t Assume”
Date and Time: Wednesday, September 23, 2026, 8:00 to 8:45 a.m. CDT
Location: Exhibit Hall Stage 1
Moderator: Craig Pfister, VP of Global Sales Engineering, Kiteworks
Panelists: Wayne Blockel, CISO, Yulista; Eric Levitas, VP of Business Development, ControlCase
About Kiteworks
Kiteworks’ mission is to empower organizations to effectively manage risk in every send, share, receive, and use of private data. The Kiteworks platform provides customers with a secure data exchange that delivers data governance, compliance, and protection in a unified control plane. Kiteworks unifies, tracks, controls, and secures sensitive data moving within, into, and out of their organization, significantly improving risk management and ensuring regulatory compliance on all private data exchanges. Headquartered in Silicon Valley, Kiteworks protects over 100 million end-users and thousands of global enterprises and government agencies.
About ControlCase ControlCase is a global provider of Compliance as a Service, helping organizations achieve and maintain certification across PCI DSS, ISO 27001, HIPAA, and CMMC, among other frameworks. The company holds accreditation as a PCI DSS Qualified Security Assessor and Approved Scanning Vendor, and as an Authorized CMMC Third-Party Assessment Organization (C3PAO) and Registered Provider Organization (RPO), qualified to conduct official CMMC Level 2 assessments. Headquartered in Fairfax, Virginia, with offices across North America, Europe, Asia/Pacific, Latin America, Australia, and the Middle East, ControlCase has assisted hundreds of clients worldwide.
Media Contact:
David Schutzman
PR Manager
david.schutzman@kiteworks.com
About Accellion
Kiteworks’ mission is to empower organizations to effectively manage risk in every send, share, receive, and save of sensitive data. The Kiteworks platform provides customers with a Private Data Network that delivers data governance, compliance, and protection. The platform unifies, tracks, controls, and secures sensitive data moving within, into, and out of their organization, significantly improving risk management and ensuring regulatory compliance on all private data communications.
Media Contacts
Additional Resources