
CMMC Phase II Suspension: What Changed on July 13, 2026?
A plain-English guide to the July 2026 suspension of CMMC Phase II, what Phase I still requires, and what defense contractors should keep doing now.
Read guide →Practical articles for defense contractors, organized around the questions that cause real scope, evidence, proposal, and assessment problems. Updated for the July 2026 CMMC program change.

A plain-English guide to the July 2026 suspension of CMMC Phase II, what Phase I still requires, and what defense contractors should keep doing now.
Read guide →
What Phase I means after the 2026 policy change, with a practical checklist for self-assessment, affirmation, SPRS, and award readiness.
Read guide →
A focused Level 1 checklist for contractors handling FCI, based on the 15 FAR 52.204-21 safeguarding requirements and current CMMC self-assessment logic.
Read guide →
How Level 2 self-assessment works, what to scope, how to build evidence, and why current contract language matters in 2026.
Read guide →
Compare Level 2 Self and Level 2 C3PAO without relying on outdated rollout assumptions after the 2026 Phase II suspension.
Read guide →
A data-first way to understand CMMC Level 1 and Level 2 by separating FCI from CUI before choosing controls, tools, or assessors.
Read guide →
What a CMMC Unique Identifier represents, how it relates to a contractor information system, and why it can appear in proposal requirements.
Read guide →
How current CMMC status, affirmations, and SPRS records connect to award eligibility when a solicitation includes CMMC requirements.
Read guide →
Why NIST Rev. 3 is final while CMMC work can still depend on Rev. 2, and how to avoid mixing assessment baselines.
Read guide →
A practical explanation of the current NIST SP 800-171 DoD Basic Assessment requirement, SPRS record, and three-year currency rule.
Read guide →
A bid-readiness workflow for checking NIST SP 800-171 assessment currency in SPRS before proposals, options, and extensions.
Read guide →A small-business guide to safeguarding covered defense information, NIST requirements, cloud use, incident reporting, evidence preservation, and flowdown.
Read guide →What the 72-hour reporting clock means, what to prepare before an incident, and how evidence preservation affects the response process.
Read guide →A source-first explanation of the DFARS cloud requirement when an external provider stores, processes, or transmits covered defense information.
Read guide →Read the CMMC contract clause as an operational checklist: current status, affirmation, system boundaries, POA&M closeout, and subcontractor handling.
Read guide →How to read 252.204-7025 for the required level, SPRS status, affirmations, conditional status, and CMMC UIDs before bidding.
Read guide →How the COTS-only exception works, why 'commercial' is not automatically 'COTS,' and what to verify before excluding cybersecurity clauses.
Read guide →A practical method to scope systems that process, store, transmit, or protect CUI without turning the entire company network into the assessment boundary.
Read guide →How a CUI enclave can reduce assessment complexity, what it does not solve, and which hidden dependencies often pull systems back into scope.
Read guide →What remote work changes in a CMMC environment: endpoints, local storage, printing, networking, support, physical exposure, and evidence.
Read guide →Why bring-your-own-device access creates CUI scope and evidence problems, plus safer patterns for small contractors that need flexibility.
Read guide →How printers and multifunction devices can process or store CUI, plus the configuration and evidence questions teams often miss.
Read guide →Why backups can silently expand CUI scope and how to document storage, encryption, access, retention, restoration, and provider responsibilities.
Read guide →How to analyze managed service providers that administer, monitor, back up, or secure a CUI environment without assuming outsourcing transfers responsibility.
Read guide →Separate the systems that hold CUI from the systems that protect them, with practical examples for identity, logging, EDR, firewalls, and management tools.
Read guide →How to think about CMMC plans of action and milestones, conditional status, non-deferrable gaps, and the evidence needed for closeout.
Read guide →A project plan for organizations that receive Conditional CMMC status and need to close eligible POA&M items within the program window.
Read guide →How to turn an SSP into a usable system description that connects scope, requirements, implementation owners, and evidence.
Read guide →A practical evidence system for policies, configuration, logs, tickets, interviews, and observations—organized by requirement and owner.
Read guide →The columns a small contractor needs to understand CUI scope, ownership, location, security role, data flow, and assessment status.
Read guide →A lightweight evidence-index design that lets a small team answer assessment questions without digging through scattered folders.
Read guide →A practical workflow for deciding when safeguarding and incident-reporting obligations need to reach subcontractors that handle covered defense information.
Read guide →A practical guide to DFARS 252.204-7020 Medium and High NIST SP 800-171 DoD Assessments, contractor access duties, rebuttal timing, SPRS records, and subcontract implications.
Read guide →Who qualifies as a CMMC Affirming Official, when affirmations are required, what is being attested to, and how to build a defensible internal sign-off process before SPRS submission.
Read guide →A focused Level 2 guide to Contractor Risk Managed Assets: what qualifies, why CRMAs stay in scope, what belongs in the SSP and network diagram, and when assessors can perform limited checks.
Read guide →How CMMC Level 2 treats Specialized Assets such as OT, IoT/IIoT, Government Furnished Equipment, restricted systems, and test equipment that can handle CUI but cannot be fully secured.
Read guide →How Level 2 out-of-scope treatment works, what separation must accomplish, why 'no CUI intended' is not enough, and how the VDI keyboard/video/mouse condition affects endpoint scoping.
Read guide →A contractor-focused CUI marking guide covering banner markings, Basic vs Specified CUI, email and media handling, source authority, and what to do when markings are missing or unclear.
Read guide →A practical guide to handling CUI in email: when the mailbox enters scope, message bodies vs attachments, forwarding and mobile access, encryption, external recipients, and assessment evidence.
Read guide →A precise guide to NIST SP 800-171 Rev. 2 requirement 3.5.3 for CMMC Level 2, including privileged vs non-privileged access, local vs network access, common bypasses, and assessor-ready evidence.
Read guide →How CMMC Level 2 applies NIST SP 800-171 Rev. 2 least-privilege requirements to administrators, separate daily accounts, privileged functions, logging, approvals, and access reviews.
Read guide →How shared logins and service identities interact with CMMC requirements for identification, unique user traceability, least privilege, authentication, and assessor evidence.
Read guide →A practical guide to NIST SP 800-171 Rev. 2 audit requirements 3.3.1 through 3.3.9, including event selection, retention, user traceability, clock synchronization, log protection, failure alerts, and assessor evidence.
Read guide →How to implement NIST SP 800-171 Rev. 2 requirement 3.11.2 without inventing a quarterly rule: systems and applications, periodic scans, new-vulnerability triggers, missed devices, exclusions, and evidence.
Read guide →A focused guide to NIST SP 800-171 Rev. 2 requirement 3.14.1 and its relationship to vulnerability scanning and risk remediation, including patch SLAs, exceptions, emergency fixes, verification, and evidence.
Read guide →A precise guide to NIST SP 800-171 Rev. 2 requirements 3.13.16 and 3.13.11 for CUI at rest, covering endpoints, servers, backups, cloud storage, removable media, key handling, physical safeguards, and evidence.
Read guide →How to implement NIST SP 800-171 Rev. 2 requirements 3.13.8 and 3.13.11 for CUI in transit, including transfer-path inventory, alternative physical safeguards, FIPS-validated cryptography, TLS/VPN/SFTP configuration, and evidence.
Read guide →A focused guide to NIST SP 800-171 Rev. 2 media requirements for USB drives and portable storage, including 3.8.7, 3.8.8, transport accountability, encryption, approved-device models, technical enforcement, and evidence.
Read guide →How to implement NIST SP 800-171 Rev. 2 media sanitization requirements for drives, SSDs, paper, printers, equipment sent for maintenance, reused devices, and destruction records without confusing decontrol with public release.
Read guide →How CMMC Level 2 applies NIST SP 800-171 Rev. 2 wireless requirements 3.1.16 and 3.1.17 to corporate Wi-Fi, guest networks, access points, rogue devices, remote sites, authentication, encryption, and assessment evidence.
Read guide →A practical guide to NIST SP 800-171 Rev. 2 requirements 3.1.18 and 3.1.19 for mobile devices, including connection control, CUI encryption, MDM, apps, screenshots, local downloads, cloud backup, loss, remote wipe, and assessor evidence.
Read guide →A detailed Level 2 tabletop guide for NIST SP 800-171 Rev. 2 incident response requirements 3.6.1–3.6.3, with scenarios, injects, roles, evidence, action tracking, DFARS 252.204-7012 reporting, and 90-day image preservation.
Read guide →