Subcontractor Questionnaire – Discussion Draft

We are excited to release a discussion draft of our new CUI Recipient Preparedness questionnaire. The questionnaire helps organizations who want to disseminate CUI to others to better achieve 32 CFR 2002’s “reasonable certainty” that an intended recipient can properly handle CUI.

Please help us build a better resource for the community.

Questions, comments, and enhancements to the questionnaire are welcome!

FAR and Above and SPRS Scoring Tool Downloaded Over 11,000 Times! New Update Available!

Our automated SPRS and FAR and Above scoring tool has been downloaded over 11,000 times since the first version was released in 2021! We recently updated the tool to version 2023.02a. The changes include a bug fix to the SPRS scoring for 3.13.11, the addition of FAR and Above and SPRS scores to the SSP (more…)

2022 Year End CMMC Program Status Update

2022 saw a lot of changes to the CMMC program, and even to the government’s approach to supply chain cybersecurity. In this post, we summarize some of the key DoD-related changes in an effort to help contractors understand what they will likely encounter in 2023.

Certified CMMC Assessor Program Update

2023 is shaping up to be a HUGE year for the CMMC program! DoD closed out 2023 by kicking off the “Joint Surveillance Program” (“JSP”) assessments of some DoD contractors, and many more are scheduled for 2023. If you aren’t familiar with the JSP assessments, they are voluntary assessments that are led by DoD’s DIBCAC (more…)

Pentagon’s Joint Surveillance Program in Full Swing

The United States Department of Defense (“DoD”) has begun its “Joint Surveillance Program” in conjunction with the CyberAB, the organization tasked with overseeing the CMMC ecosystem. Under the Joint Surveillance Program, members of DoD’s Defense Industrial Base Cybersecurity Assessment Center (“DIBCAC”) accompany and oversee representatives from CyberAB authorized Certified 3rd Party Assessment Organizations (“C3PAOs”) as (more…)

Rule Change is Imminent. Are You Ready?

The CMMC Implementation Conference is being held January 18-20 at the beautiful University of San Diego. Chock full of valuable tips and tools for business owners, service providers, and those charged with implementing the CMMC requirements, CIC2023 is NOT your ordinary CMMC conference. Learn how to Stop Talking. Start Doing. You can even take CCP or (the first ever) CCA training classes before the conference and reinforce your learning at the conference! Register today at https://CIC2023.org

NIST SP 800-171/CMMC 2.0 Self-Assessment Tool Updated to Include Automated FAR and Above and SPRS Scoring, and More

We are excited to announce the release of the new version of our CMMC 2.0/NIST SP 800-171 Self-Assessment Tool. This version includes automated FAR and Above and SPRS scoring and much more!

CMMC 2.0 Model and Scoping Guide Now Available

The US Department of Defense updated their main website (OUSD A&S – Cybersecurity Maturity Model Certification (CMMC) (osd.mil)) to include an updated CMMC Model consistent with the information released on Nov. 4 about CMMC 2.0. They also released scoping guidance for CMMC 2.0 Levels 1 and 2, and a hashing approach for preserving evidence. Among (more…)

Can DCMA’s DIBCAC Teams Handle the CMMC C3PAO Authorization Workload?

CMMC depends upon Authorized C3PAOs. DCMA’s DIBCAC team plays a crucial role in the C3PAO authorization process. However, the DIBCAC teams’ calendars were already full prior to CMMC. In this article, co-authored with Kyle Lai, Carter Schoenberg, Tony Buenger, and Derek White, we discuss whether the current system is likely to clear the CMMC C3PAO backlog in a timely manner and explore a few alternatives.