Are Contractors Authorized to Mark Legacy Information or Unmarked Information as CUI?

There is a LOT of confusion in the contractor community over whether contractors have the authority to take it upon themselves to mark legacy information (e.g., FOUO, SBU, etc.) or unmarked information as CUI. In this article, we do a quick analysis based on the governing regulation and agency memorandum.

2022 CMMC Community Contributor Award Winners

Announcing the 2022 CMMC Community Contributor Awardees! These individuals made exceptional contributions to the efforts to protect the US government’s supply chain, and the broader cybersecurity community. We appreciate their efforts and are pleased to recognize the positive contributions they have made!

NIST SP 800-171/CMMC 2.0 Self-Assessment Tool Updated to Include Automated FAR and Above and SPRS Scoring, and More

We are excited to announce the release of the new version of our CMMC 2.0/NIST SP 800-171 Self-Assessment Tool. This version includes automated FAR and Above and SPRS scoring and much more!

The $0 CMMC Level 2 Compliance Fallacy

Government representatives have stated that complying with CMMC 2.0 Level 2 shouldn’t cost contractors or the government anything, because contractors have been attesting to the government that they are doing these things for years. This article explores why this is correct only for a small minority (17 out of 110) of the controls in CMMC 2.0 Level 2.