Understand CMMC, the July 2026 suspension of third party certification, and what defense contractors must still do for compliance.
CMMC and NIST 800-171
After the Suspension: What You Still Have to Do
The CMMC self-assessment process remains mandatory for defense contractors. Learn what requirements still apply after the suspension of third-party certification.
CMMC and NIST 800-171
9 piecesConfused about CMMC Level 2? Learn how to determine if Level 1 or Level 2 applies, based on whether you handle FCI or CUI, and what to do next.
Understand the difference between FCI and CUI, why CUI drives your compliance scope, and how correct marking under 32 CFR Part 2002 can save costs and risk.
Understand all 14 families of NIST 800-171 controls, including practice counts and what each family requires for Level 2 compliance.
Understand CMMC scoping with a focus on the five asset categories in 32 CFR 170.19(c)(1) Table 3 to avoid common mistakes and improve compliance.
Understand the four essential documents needed for a CMMC assessment: CUI Flow Diagram, Network Boundary Diagram, Physical Site Diagram, and Authorized User List.
Understand how your SPRS score is calculated, what a negative score means, and why the DIB average SPRS score lags behind the required 110.
Learn what a System Security Plan is, why CA.L2-3.12.4 mandates it for defense contractors, and the real consequences of failing to maintain one.
Learn what a POA&M is, how it works at Level 2 for CMMC and NIST SP 800-171, and why POA&Ms are not permitted at Level 3. Understand the 180 day rule.
Threats and Vulnerabilities
10 piecesThe CISA KEV catalog lists 1665 exploited vulnerabilities, including threats with confirmed ransomware use. Learn how to use it to prioritize patching.
Learn which ransomware vulnerabilities are actively used in attacks, with real CVEs, vendors, and dates based on the CISA Known Exploited Vulnerabilities Catalog.
Learn how the recent CVE-2026-18556 in N-able N-central highlights the risks of MSP supply chain attack and what you should ask your IT provider.
The SonicWall vulnerability, flagged for ransomware use, highlights why remote access appliances demand urgent attention from small businesses.
Learn about the SharePoint vulnerability CVE-2026-45659, its ransomware use, and why on-premises collaboration servers pose scoping and security risks.
Firewall vulnerability is a real risk for any business. Learn what recent exploited firewall vulnerabilities mean for your patching and compliance.
Small business ransomware threats target familiar products like cPanel and WordPress. Learn what matters most for your company’s risk and compliance.
Attackers keep using the same legacy vulnerability year after year. Learn why asset inventory is your best defense against old, still-exploited bugs.
Patch management is critical for compliance and risk reduction. Learn how small teams can prioritize using the KEV Catalog and meet SI.L2-3.14.1 requirements.
Credential theft remains the most cost-effective attack method. Learn what IA.L2-3.5.3 requires and how to protect your business from stolen credentials.
Practical Defense
6 piecesUnderstand what counts as multifactor authentication CMMC compliance, why SMS is weak, and how to meet requirements for privileged and non-privileged accounts.
Backup compliance is more than having backups. Level 2 companies must prove CUI backup protection and restore capability for NIST SP 800-171 and CMMC.
Understand DFARS 72 hour reporting, DIBNet incident submissions, and what the DFARS 252.204-7012 requirements mean for your company’s incident response.
Learn why starting vulnerability scanning early is essential for compliance and how scan history impacts NIST SP 800-171 and CMMC Level 2 self-assessments.
Least privilege is required even when roles overlap. Learn how AC.L2-3.1.5 applies when one person handles IT, finance, and shipping in your business.
Media sanitization is a critical requirement under NIST SP 800-171. Learn how improper media protection can undo your compliance efforts and what to do next.
Cost, Grants and Exposure
4 piecesUnderstand real CMMC cost benchmarks for Level 2, including assessment, remediation, and consulting. Learn how scoping and enclaves affect your budget.
Learn what the CMMC gap assessment grant from Cyber Grants Alliance covers, who qualifies, and how it supports defense contractors with NIST 800-171 compliance.
The False Claims Act cybersecurity risk is real for defense contractors. Learn from recent cases, what actions led to liability, and how to reduce exposure.
Your first 30 days matter. Use this CMMC compliance checklist to scope assets, inventory systems, and build your SSP for NIST SP 800-171 readiness.