Billington 2026: NSPM-12's first summit, the logging mandate, the acting-CISO gap.
The 17th Billington is the first federal-cyber summit convened after NSPM-12, the White House's new accountability framework for national security systems. It lands with OMB's logging mandate live and the federal CISO seat still filled in an acting capacity.
Context
The 17th Billington CyberSecurity Summit takes over the Walter E. Washington Convention Center on September 9 and 10, and it is the room where CISA, DISA, USCYBERCOM, the agency CISOs, and their entire BD orbit sit in the same building for two days. It matters this year because it is the first federal-cyber gathering convened after NSPM-12, the White House memorandum that just rewired governance and accountability for national security systems.
The year's headline: accountability lands before the leadership does
NSPM-12 is the story. In the spring the White House issued National Security Presidential Memorandum 12, standing up a new governance, oversight, and accountability framework for national security systems (Industrial Cyber, June 2026). Read it alongside OMB and CISA's 'detect, understand, respond' push, which adds fresh logging requirements agencies will soon be graded on (Federal News Network, May 2026), and the shape of 2026 is clear. Last year's Billington was about resilience and the move from reactive to proactive defense (Dataminr and Owl Cyber Defense recaps, September 2025). This year the vocabulary hardens from posture toward accountability. Someone now owns the number.
Here is the wrinkle that makes it a real story instead of a press release. The federal CISO seat that sits at the center of this framework is currently filled in an acting capacity by Michael Duffy at OMB (ExecutiveBiz, May 2026), and the federal CIO tracker reads like a departures board (GovCIO, July 2026). A summit built around a new accountability doctrine, run by principals who may not be confirmed to own it in FY27. That gap is the thing to watch.
Speakers worth showing up for (agenda not public yet, so watch these seats)
The agenda was not public as of mid-2026, so these are seats to watch, not confirmed names. Note: the acting-CISO and rival-summit signals below come from the broader federal cycle, not a released Billington lineup.
The federal CISO plenary. Billington reliably seats the federal CISO. The chair is currently held in an acting capacity by Michael Duffy at OMB, who joined the 2026 speaking circuit this spring (ExecutiveBiz, May 2026), and his office owns NSPM-12 rollout. Ask: which agencies get graded first under the new framework, and what actually happens to a CISO who misses the logging bar.
CISA operational leadership. CISA is driving the 'detect, understand, respond' logging effort, with new data requirements landing soon (Federal News Network, May 2026). Ask: is the logging mandate funded, or is it an unfunded requirement dropping on teams that are already short-staffed.
USCYBERCOM and DISA. The threat framing is set: the PRC is named the most significant long-term cyber threat to defense-aligned organizations (EclecticIQ, 2026). Ask: what does persistent engagement look like when the same operators are being asked to absorb NSPM-12 reporting on top of the mission.
The GovCon acquisition voice. Trump's Frontier Models EO and AI National Security Memo are reshaping how contractors engage on defense tech (ExecutiveGov, June 2026). Ask: does the memo give vendors a clearer path to field AI in cyber operations, or a new approval gauntlet before anything ships.
Breakouts with signal density
Billington runs 50-plus sessions, and the plenaries are the show. The signal lives in the small rooms.
NSPM-12 implementation mechanics. Skip the keynote framing. Find the breakout where someone lays out reporting cadence, thresholds, and who signs. That is where you learn whether the framework has teeth.
Continuous authorization and FedRAMP reality. The 2025 floor was thick with FedRAMP-authorized vendors (iboss, Absolute, 2025). The cATO and continuous-authorization deep-dive is where procurement actually happens, not the exhibit hall.
Measuring zero trust. 2025 ran a session on measuring maturity, not just declaring it (Billington 2025 program, YouTube). The 'how do you score it' room beats the 'why it matters' room every time.
Software supply chain and SBOM. Dataminr's 2025 recap flagged supply chain as a headline thread (Dataminr, September 2025). Watch for the SEI-adjacent breakout on secure software supply chain. That is booth 225's home turf.
Allied threat-sharing. The international partner panel is where the friction in Five-Eyes and allied intel-sharing gets aired, usually the most candid room in the building.
Companies to track at the booths
Sponsor signals came back empty in the spec, so this is read from who was on the 2025 floor and who is already marketing the 2026 room.
Carahsoft. Says: government IT solutions aggregator, out front promoting the summit (Carahsoft, Instagram, 2026). Actually selling: the contract vehicle. The thing on the table is the SEWP and GSA path, not any single product. For this room, Carahsoft is a gate, not a booth.
Four Inc. and Vertosoft. Say: they convene public and private leaders. Four Inc. ran the 3rd State and Local summit with 950-plus attendees from 42 states (Four Inc., May 2026). Actually selling: distribution channel access for emerging vendors who cannot carry their own vehicle yet.
Carnegie Mellon SEI (booth 225, confirmed 2026). Says: a federally funded research and engineering institute (SEI event page, July 2026). Actually selling: neutral-broker credibility. Secure-software-supply-chain frameworks, CMMC guidance, and a workforce pipeline agencies trust precisely because SEI is not pushing a box.
iboss (2025 floor, likely back). Says: FedRAMP-authorized Zero Trust SASE (iboss, 2025). Actually selling: stack consolidation. Replace three point products with one authorized line item. That is a budget argument wearing an architecture costume.
Absolute (2025 floor, likely back). Says: FedRAMP self-healing endpoint (Absolute, 2025). Actually selling: device-level persistence as the endpoint answer to 'detect, understand, respond,' positioning ahead of the logging mandate.
Conversation patterns
Three things get argued in the hallway, and one thing does not.
Debate one: does NSPM-12 have teeth? Either the accountability framework arrives with budget and authority, or it becomes one more compliance overlay agencies paper over (Industrial Cyber, June 2026). The room will split on this by lunch.
Debate two: is the logging mandate fundable? OMB and CISA are adding logging requirements while the Senate defense bill is simultaneously trying to limit civilian layoffs and attract cyber talent (Federal News Network, May and June 2026). More mandates, fewer people. Something gives.
Debate three: does the AI National Security Memo speed things up or slow them down? Trump's memo and Frontier Models EO could hand GovCons a clearer lane to field AI in cyber, or a fresh approval gauntlet (ExecutiveGov, June 2026). Contractors will argue both sides depending on where they sit.
One thing the room will route around: the leadership selling this year's doctrine is largely unconfirmed. An acting federal CISO, a CIO tracker that reads like a departures board (GovCIO, July 2026), and a doctrine that needs a decade of continuity to pay off. Nobody on stage will say the people announcing FY27 priorities may not be holding the pen in FY27, because that sentence is career-expensive in that building. Watch who hedges on timelines. The quieter one: a large share of the 'cybersecurity' booths are contract-vehicle resellers, not builders. The real gate to this market is the aggregator, and everyone knows it and no one puts it on a banner.
The 72-hour window
Billington puts 2,500-plus senior government and industry people under one roof for two days, and most of them get pitched more times than any human could track (Vendelux and Vertosoft attendance figures, 2026). Federal leaders are the most-pitched and least-remembered audience in the sector. They nod, they pocket the card, they forget by the next session. If you are the one doing the following-up, the win is not the stack of cards. It is whether you can act on the eight that mattered before the warm window shuts and you are back at your desk Monday with a rubber band around a hundred strangers. That is the gap Met is built for: capture who you actually met and why while it is fresh, so the follow-up goes out warm instead of never. Free, iPhone only. Download it before you fly to DC.
Download for iPhone
Read by operators heading to Billington who want the intel before they fly.