<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel>
<title>Capital Cyber News</title><link>https://news.capital-cyber.com/</link>
<description>CMMC, NIST 800-171 and current threats, explained plainly.</description>
<lastBuildDate>Mon, 17 Aug 2026 19:12:47 GMT</lastBuildDate>
<item><title>What CMMC Is, and What Changed in July 2026</title><link>https://news.capital-cyber.com/what-cmmc-is-and-what-changed-july-2026/</link><guid>https://news.capital-cyber.com/what-cmmc-is-and-what-changed-july-2026/</guid><pubDate>Mon, 17 Aug 2026 19:12:47 GMT</pubDate><description>Understand CMMC, the July 2026 suspension of third party certification, and what defense contractors must still do for compliance.</description></item>
<item><title>CMMC Level 1 or Level 2: How to Tell Which One Applies to You</title><link>https://news.capital-cyber.com/cmmc-level-1-vs-level-2/</link><guid>https://news.capital-cyber.com/cmmc-level-1-vs-level-2/</guid><pubDate>Mon, 17 Aug 2026 19:12:47 GMT</pubDate><description>Confused about CMMC Level 2? Learn how to determine if Level 1 or Level 2 applies, based on whether you handle FCI or CUI, and what to do next.</description></item>
<item><title>FCI and CUI: The Difference That Decides Your Entire Scope</title><link>https://news.capital-cyber.com/fci-vs-cui-difference/</link><guid>https://news.capital-cyber.com/fci-vs-cui-difference/</guid><pubDate>Mon, 17 Aug 2026 19:12:47 GMT</pubDate><description>Understand the difference between FCI and CUI, why CUI drives your compliance scope, and how correct marking under 32 CFR Part 2002 can save costs and risk.</description></item>
<item><title>The 110 NIST 800-171 Controls, Family by Family</title><link>https://news.capital-cyber.com/the-110-controls-by-family/</link><guid>https://news.capital-cyber.com/the-110-controls-by-family/</guid><pubDate>Mon, 17 Aug 2026 19:12:47 GMT</pubDate><description>Understand all 14 families of NIST 800-171 controls, including practice counts and what each family requires for Level 2 compliance.</description></item>
<item><title>CMMC Scoping: The Five Asset Categories Most Companies Get Wrong</title><link>https://news.capital-cyber.com/cmmc-scoping-five-asset-categories/</link><guid>https://news.capital-cyber.com/cmmc-scoping-five-asset-categories/</guid><pubDate>Mon, 17 Aug 2026 19:12:47 GMT</pubDate><description>Understand CMMC scoping with a focus on the five asset categories in 32 CFR 170.19(c)(1) Table 3 to avoid common mistakes and improve compliance.</description></item>
<item><title>The Four Scoping Documents an Assessor Will Ask You For</title><link>https://news.capital-cyber.com/four-scoping-artifacts-assessors-ask-for/</link><guid>https://news.capital-cyber.com/four-scoping-artifacts-assessors-ask-for/</guid><pubDate>Mon, 17 Aug 2026 19:12:47 GMT</pubDate><description>Understand the four essential documents needed for a CMMC assessment: CUI Flow Diagram, Network Boundary Diagram, Physical Site Diagram, and Authorized User List.</description></item>
<item><title>Your SPRS Score: How It Is Calculated and Why the Average Is 60</title><link>https://news.capital-cyber.com/sprs-score-explained/</link><guid>https://news.capital-cyber.com/sprs-score-explained/</guid><pubDate>Mon, 17 Aug 2026 19:12:47 GMT</pubDate><description>Understand how your SPRS score is calculated, what a negative score means, and why the DIB average SPRS score lags behind the required 110.</description></item>
<item><title>The System Security Plan: What It Is and What Happens Without One</title><link>https://news.capital-cyber.com/system-security-plan-ssp/</link><guid>https://news.capital-cyber.com/system-security-plan-ssp/</guid><pubDate>Mon, 17 Aug 2026 19:12:47 GMT</pubDate><description>Learn what a System Security Plan is, why CA.L2-3.12.4 mandates it for defense contractors, and the real consequences of failing to maintain one.</description></item>
<item><title>POA&amp;Ms: What They Cover and the 180 Day Clock</title><link>https://news.capital-cyber.com/poam-explained/</link><guid>https://news.capital-cyber.com/poam-explained/</guid><pubDate>Mon, 17 Aug 2026 19:12:47 GMT</pubDate><description>Learn what a POA&amp;M is, how it works at Level 2 for CMMC and NIST SP 800-171, and why POA&amp;Ms are not permitted at Level 3. Understand the 180 day rule.</description></item>
<item><title>After the Suspension: What You Still Have to Do</title><link>https://news.capital-cyber.com/self-assessment-after-the-suspension/</link><guid>https://news.capital-cyber.com/self-assessment-after-the-suspension/</guid><pubDate>Mon, 17 Aug 2026 19:12:47 GMT</pubDate><description>The CMMC self-assessment process remains mandatory for defense contractors. Learn what requirements still apply after the suspension of third-party certification.</description></item>
<item><title>What Is Actually in CISA’s Known Exploited Vulnerabilities Catalog Right Now</title><link>https://news.capital-cyber.com/kev-catalog-what-is-in-it-now/</link><guid>https://news.capital-cyber.com/kev-catalog-what-is-in-it-now/</guid><pubDate>Mon, 17 Aug 2026 19:12:47 GMT</pubDate><description>The CISA KEV catalog lists 1665 exploited vulnerabilities, including threats with confirmed ransomware use. Learn how to use it to prioritize patching.</description></item>
<item><title>The Vulnerabilities Ransomware Crews Are Actually Exploiting</title><link>https://news.capital-cyber.com/ransomware-exploited-vulnerabilities-2026/</link><guid>https://news.capital-cyber.com/ransomware-exploited-vulnerabilities-2026/</guid><pubDate>Mon, 17 Aug 2026 19:12:47 GMT</pubDate><description>Learn which ransomware vulnerabilities are actively used in attacks, with real CVEs, vendors, and dates based on the CISA Known Exploited Vulnerabilities Catalog.</description></item>
<item><title>When Your IT Provider Is the Attack Path</title><link>https://news.capital-cyber.com/n-able-n-central-msp-supply-chain/</link><guid>https://news.capital-cyber.com/n-able-n-central-msp-supply-chain/</guid><pubDate>Mon, 17 Aug 2026 19:12:47 GMT</pubDate><description>Learn how the recent CVE-2026-18556 in N-able N-central highlights the risks of MSP supply chain attack and what you should ask your IT provider.</description></item>
<item><title>Edge Devices and Ransomware: The SonicWall SMA1000 Entries</title><link>https://news.capital-cyber.com/sonicwall-sma1000-ransomware/</link><guid>https://news.capital-cyber.com/sonicwall-sma1000-ransomware/</guid><pubDate>Mon, 17 Aug 2026 19:12:47 GMT</pubDate><description>The SonicWall vulnerability, flagged for ransomware use, highlights why remote access appliances demand urgent attention from small businesses.</description></item>
<item><title>SharePoint Server Under Active Exploitation</title><link>https://news.capital-cyber.com/sharepoint-server-exploitation/</link><guid>https://news.capital-cyber.com/sharepoint-server-exploitation/</guid><pubDate>Mon, 17 Aug 2026 19:12:47 GMT</pubDate><description>Learn about the SharePoint vulnerability CVE-2026-45659, its ransomware use, and why on-premises collaboration servers pose scoping and security risks.</description></item>
<item><title>Your Firewall Is a Target, Not Just a Control</title><link>https://news.capital-cyber.com/firewall-appliance-vulnerabilities/</link><guid>https://news.capital-cyber.com/firewall-appliance-vulnerabilities/</guid><pubDate>Mon, 17 Aug 2026 19:12:47 GMT</pubDate><description>Firewall vulnerability is a real risk for any business. Learn what recent exploited firewall vulnerabilities mean for your patching and compliance.</description></item>
<item><title>Ransomware and the Ten Person Company</title><link>https://news.capital-cyber.com/small-business-ransomware-reality/</link><guid>https://news.capital-cyber.com/small-business-ransomware-reality/</guid><pubDate>Mon, 17 Aug 2026 19:12:47 GMT</pubDate><description>Small business ransomware threats target familiar products like cPanel and WordPress. Learn what matters most for your company’s risk and compliance.</description></item>
<item><title>The Old Bugs That Never Stopped Working</title><link>https://news.capital-cyber.com/legacy-software-still-exploited/</link><guid>https://news.capital-cyber.com/legacy-software-still-exploited/</guid><pubDate>Mon, 17 Aug 2026 19:12:47 GMT</pubDate><description>Attackers keep using the same legacy vulnerability year after year. Learn why asset inventory is your best defense against old, still-exploited bugs.</description></item>
<item><title>How a Small Team Should Decide What to Patch First</title><link>https://news.capital-cyber.com/patch-prioritization-for-small-teams/</link><guid>https://news.capital-cyber.com/patch-prioritization-for-small-teams/</guid><pubDate>Mon, 17 Aug 2026 19:12:47 GMT</pubDate><description>Patch management is critical for compliance and risk reduction. Learn how small teams can prioritize using the KEV Catalog and meet SI.L2-3.14.1 requirements.</description></item>
<item><title>Credential Theft Is Still the Cheapest Way In</title><link>https://news.capital-cyber.com/credential-theft-and-mfa-gaps/</link><guid>https://news.capital-cyber.com/credential-theft-and-mfa-gaps/</guid><pubDate>Mon, 17 Aug 2026 19:12:47 GMT</pubDate><description>Credential theft remains the most cost-effective attack method. Learn what IA.L2-3.5.3 requires and how to protect your business from stolen credentials.</description></item>
<item><title>MFA: What Actually Satisfies IA.L2-3.5.3</title><link>https://news.capital-cyber.com/mfa-what-satisfies-ia-3-5-3/</link><guid>https://news.capital-cyber.com/mfa-what-satisfies-ia-3-5-3/</guid><pubDate>Mon, 17 Aug 2026 19:12:47 GMT</pubDate><description>Understand what counts as multifactor authentication CMMC compliance, why SMS is weak, and how to meet requirements for privileged and non-privileged accounts.</description></item>
<item><title>Backups: The Control Nobody Documents Until They Need It</title><link>https://news.capital-cyber.com/backups-the-undocumented-control/</link><guid>https://news.capital-cyber.com/backups-the-undocumented-control/</guid><pubDate>Mon, 17 Aug 2026 19:12:47 GMT</pubDate><description>Backup compliance is more than having backups. Level 2 companies must prove CUI backup protection and restore capability for NIST SP 800-171 and CMMC.</description></item>
<item><title>Incident Response and the DFARS 72 Hour Clock</title><link>https://news.capital-cyber.com/incident-response-72-hour-clock/</link><guid>https://news.capital-cyber.com/incident-response-72-hour-clock/</guid><pubDate>Mon, 17 Aug 2026 19:12:47 GMT</pubDate><description>Understand DFARS 72 hour reporting, DIBNet incident submissions, and what the DFARS 252.204-7012 requirements mean for your company’s incident response.</description></item>
<item><title>Why You Should Start Vulnerability Scanning Before You Think You Need To</title><link>https://news.capital-cyber.com/vulnerability-scanning-start-early/</link><guid>https://news.capital-cyber.com/vulnerability-scanning-start-early/</guid><pubDate>Mon, 17 Aug 2026 19:12:47 GMT</pubDate><description>Learn why starting vulnerability scanning early is essential for compliance and how scan history impacts NIST SP 800-171 and CMMC Level 2 self-assessments.</description></item>
<item><title>Least Privilege When Everyone Does Everything</title><link>https://news.capital-cyber.com/least-privilege-in-a-small-company/</link><guid>https://news.capital-cyber.com/least-privilege-in-a-small-company/</guid><pubDate>Mon, 17 Aug 2026 19:12:47 GMT</pubDate><description>Least privilege is required even when roles overlap. Learn how AC.L2-3.1.5 applies when one person handles IT, finance, and shipping in your business.</description></item>
<item><title>Media Protection: The Cheapest Control to Fail</title><link>https://news.capital-cyber.com/media-protection-and-disposal/</link><guid>https://news.capital-cyber.com/media-protection-and-disposal/</guid><pubDate>Mon, 17 Aug 2026 19:12:47 GMT</pubDate><description>Media sanitization is a critical requirement under NIST SP 800-171. Learn how improper media protection can undo your compliance efforts and what to do next.</description></item>
<item><title>What CMMC Level 2 Actually Costs</title><link>https://news.capital-cyber.com/what-cmmc-actually-costs/</link><guid>https://news.capital-cyber.com/what-cmmc-actually-costs/</guid><pubDate>Mon, 17 Aug 2026 19:12:47 GMT</pubDate><description>Understand real CMMC cost benchmarks for Level 2, including assessment, remediation, and consulting. Learn how scoping and enclaves affect your budget.</description></item>
<item><title>The CGA CMMC Gap Assessment Grant: What It Covers and Who Qualifies</title><link>https://news.capital-cyber.com/cga-cmmc-gap-assessment-grant/</link><guid>https://news.capital-cyber.com/cga-cmmc-gap-assessment-grant/</guid><pubDate>Mon, 17 Aug 2026 19:12:47 GMT</pubDate><description>Learn what the CMMC gap assessment grant from Cyber Grants Alliance covers, who qualifies, and how it supports defense contractors with NIST 800-171 compliance.</description></item>
<item><title>The False Claims Act Is Now a Cybersecurity Risk</title><link>https://news.capital-cyber.com/false-claims-act-and-cybersecurity/</link><guid>https://news.capital-cyber.com/false-claims-act-and-cybersecurity/</guid><pubDate>Mon, 17 Aug 2026 19:12:47 GMT</pubDate><description>The False Claims Act cybersecurity risk is real for defense contractors. Learn from recent cases, what actions led to liability, and how to reduce exposure.</description></item>
<item><title>If You Have Not Started: What to Do in the Next 30 Days</title><link>https://news.capital-cyber.com/first-30-days-if-you-have-not-started/</link><guid>https://news.capital-cyber.com/first-30-days-if-you-have-not-started/</guid><pubDate>Mon, 17 Aug 2026 19:12:47 GMT</pubDate><description>Your first 30 days matter. Use this CMMC compliance checklist to scope assets, inventory systems, and build your SSP for NIST SP 800-171 readiness.</description></item>
</channel></rss>