Guides, regulatory breakdowns, and assessment readiness resources for defense contractors.
Last updated July 14, 2026
Practical CUI best practices across access control, network protection, system configuration, and audit logging. What CMMC assessors verify and how to be ready.
Read the guide →On July 13, 2026 the DoD immediately suspended CMMC Phase 2 third-party certification and stood up a 60-day reform task force. The certification mechanism is under review. DFARS 252.204-7012, NIST 800-171, self-assessment, and SPRS scores are not. Here is exactly what changed and what contractors should do.
Read the article →The five CMMC Level 2 Specialized Asset types (OT, IoT/IIoT, GFE, Restricted Information Systems, and Test Equipment): how they are scoped, documented in the SSP, and why they are not assessed against all 110 requirements.
Read the article →Phase 2 is a scheduling problem, not a calendar problem. The real assessment-capacity numbers from the February 2026 Cyber AB Town Hall, the working-backwards timeline, the conditional certification path, and what to do this quarter.
Read the guide →CMMC Level 2 is more prescriptive than SOC 2, independently verified, and increasingly recognized by cyber insurance underwriters. Here is why that matters even if you never touch a DoD contract.
Read the analysis →BitLocker protects CUI at rest under CMMC, but default TPM-only mode is broken by bitpixie, YellowKey, and TPM bus sniffing. Learn how to harden BitLocker, where FIPS mode matters, and which alternatives qualify.
Read the guide →Which methods are actually acceptable for transmitting CUI? Email, file transfer, remote access, and physical media: requirements, approved tools, and common assessment failures explained.
Read the guide →Can you get CMMC certification with remote employees or offshore developers? Here is what the rules actually require, where offshore work creates hard stops, and how to structure your team for a passing assessment.
Read the article →How to run, document, and evidence CMMC tabletop exercises that satisfy IR.L2-3.6.3. Includes five ready-to-use scenarios for small DIB contractors, documentation requirements, and what assessors look for.
Read the article →Virtual Desktop Infrastructure can shrink your CMMC assessment boundary by keeping CUI off local endpoints. Here is what VDI actually solves, what it doesn
Read the article →What Controlled Technical Information (CTI) is, how distribution statements B through F make your data CUI, where CTI hides in contractor environments, and what CMMC Level 2 requires to protect it.
Read the guide →Summary of the DLA Office of Small Business Programs CMMC webinar. Covers CMMC levels, phase-in dates, DLA-specific contract language, CUI identification, SPRS submission, and POA&M rules.
Read the article →SI.L2-3.14.6 (5 pts) requires monitoring inbound and outbound traffic to detect attacks. SI.L2-3.14.7 (3 pts) requires identifying unauthorized system use. Neither is POA&M eligible. Here is what they require and how to satisfy them before your C3PAO assessment.
Read the article →CMMC Registered Practitioners need more than a checklist. This guide covers the software tools RPs use to run gap assessments, build SSPs, track POA&Ms, score SPRS, and package C3PAO-ready evidence across multiple clients — including what 1TEN provides specifically for RP engagements.
Read the article →Free CUI awareness training template for defense contractors. Covers what CUI is, markings, handling, transmission, incident reporting, and the CMMC domains this training supports.
Read the guide →Everything a defense contractor needs to know about Controlled Unclassified Information: what CUI is, how to identify and scope it, storage and transmission rules, DFARS 7012 obligations, incident reporting, training, subcontractor flow-down, and how to build a compliant program.
Read the guide →A POA&M documents unmet CMMC requirements and your remediation plan. Learn the 180-day closeout rule, which requirements can
Read the guide →A complete guide to federal and state programs that offset CMMC Level 2 compliance costs: APEX Accelerators, MEP grants, FAR Part 31 cost recovery, state-specific programs, and proposed tax credits.
Read the article →A CMMC SSP template gives you a blank form. Your C3PAO assessor needs a document about your organization. Here
Read the guide →The top CMMC compliance software platforms for defense contractors in 2026, ranked and compared. Covers air-gapped appliances, cloud GRC tools, and what to look for before you buy.
Read the article →CMMC Level 2 certification is valid for 3 years, but contractors must submit annual affirmations under 32 CFR Part 117. What the affirmation requires, who can sign it, and the consequences of missing the deadline.
Read the article →Calculate your SPRS score across all 110 NIST SP 800-171 requirements. Mark each requirement met or not met, track your score live, and download a full results report.
Read the guide →How end-of-life software creates CMMC Level 2 findings under SI.L2-3.14.1. What EOL means for your SPRS score, how endoflife.date helps track it, and how 1TEN integrates EOL status into your compliance posture.
Read the article →The NVD is the authoritative CVE database behind your CMMC vulnerability scanning obligation. Learn which requirements apply, how SLA-based tracking works, and what tools fix the findings.
Read the article →Only 1% of DIB contractors are fully ready for CMMC Level 2. Here are the most common readiness gaps we see across small defense contractors — and what to do about them.
Read the report →The SSP system boundary description tells your C3PAO exactly what is being assessed. Learn what it must cover, what assessors reject, and see strong vs. weak examples.
Read the guide →IA.L2-3.5.4 requires replay-resistant authentication for all network access. Learn what it means, how it differs from MFA, what satisfies it, and how assessors evaluate it.
Read the article →IA.L2-3.5.3 requires MFA in two specific scenarios. This is what applies to VPN users, privileged accounts, and remote workers in a CMMC Level 2 environment.
Read the article →CMMC Level 2 mandates 3 AT domain requirements covering security awareness, role-based training, and social engineering recognition. Here is what your program must include.
Read the article →New guides, regulatory breakdowns, and assessment readiness updates, delivered when we publish. No noise.
The DoD published official answers to 25 CMMC questions covering assessments, MSPs, cloud, VDI, subcontractors, and POA&Ms. Here is what the answers actually mean.
Read the article →How to segment CUI from your corporate network for CMMC Level 2. VLANs, firewalls, jump hosts, cloud options, and exactly what C3PAO assessors look for.
Read the article →All six CMMC Level 2 physical security requirements explained, including PE.L2-3.10.6 for remote work. What C3PAO assessors look for and how to satisfy each control.
Read the article →How to account for, recover, and quote CMMC compliance costs under government contracts. Covers FAR allowability, indirect rate treatment, forward pricing, and cost recovery strategies for defense contractors.
Read the article →A field-by-field CMMC POA&M template with the credibility standards C3PAO assessors apply. Covers required fields, milestone writing, SPRS prioritization, and the mistakes that turn a remediation plan into a finding.
Read the guide →1TEN is rolling out full support for NIST SP 800-171 Revision 3 with a target completion date of July 31, 2026. Learn what changes in Rev 3, how it affects your CMMC compliance posture, and what 1TEN is doing to make the transition seamless.
Read the guide →1TEN is integrating the open-source Wazuh platform to deliver native SIEM capabilities for CMMC Level 2 compliance — no third-party tool required, fully air-gapped, and mapped directly to NIST SP 800-171 AU, SI, IR, and CA requirements.
Read the article →A complete guide to CUI scoping for CMMC Level 2. Learn the five asset categories, how to define and document your CUI boundary, common scoping mistakes that create findings, and how proper scoping reduces your assessment cost and complexity.
Read the guide →How SIEM integration directly satisfies CMMC Level 2 requirements across AU, SI, IR, and CA domains. Includes a complete requirement mapping table, minimum log source list, alert rule catalog, and C3PAO assessment evidence checklist.
Read the article →The real cost of CMMC Level 2 compliance: DoD official three-year estimate, what contractors actually spend, C3PAO assessment fees, consultant rates, and how to reduce total cost.
Read the article →For VPs of Operations, Directors of Manufacturing, and COOs at defense contractors: CMMC is not an IT project. The production floor, the contracts it supports, and the people who run it are all in scope.
Read the article →Key takeaways from the DoD CMMC Program Small Business Impacts Roundtable held March 12, 2026. Real cost data, C3PAO capacity concerns, DIB attrition rates, and what small defense contractors need to know.
Read the article →Thousands of defense contractors hold a DD2345 JCP certification but have never mapped it to CMMC. Your authorization to receive militarily critical technical data is not a substitute for protecting it.
Read the article →Firmware, circuit designs, and test specifications for defense electronics and sensor systems are CUI. A practical guide to CMMC scope boundaries in defense electronics manufacturing environments.
Read the guide →Complete checklist of all 110 CMMC Level 2 requirements organized by domain, with SPRS point weights (5/3/1) and POA&M eligibility for each control. Free assessment readiness tool for defense contractors.
See the checklist →Your SPRS score ranges from −203 to 110 and is visible to DoD contracting officers. Learn how it
Read the guide →A System Security Plan documents how your organization implements all 110 CMMC requirements. Learn what an SSP must contain, how C3PAO assessors evaluate it, and common mistakes that fail assessments.
Read the article →CMMC incident response requirements explained: what triggers the 72-hour DIBNet reporting clock, what constitutes a cyber incident under DFARS 7012, evidence preservation obligations, and how to build an IR program that satisfies assessors.
Read the article →Do subcontractors need CMMC certification? Who the flow-down obligation applies to, what primes must require, how to determine if your subcontract triggers CMMC, and what happens if you ignore it.
Read the guide →What Controlled Unclassified Information (CUI) is, how to identify it in your environment, what DFARS 7012 and NIST SP 800-171 require for protecting it, and how to build a compliant CUI handling program.
Read the guide →DFARS 252.204-7012 explained: what it requires, who it applies to, how it connects to CMMC, NIST SP 800-171, and SPRS scoring, and what happens if you are not compliant.
Read the guide →A comprehensive guide to CMMC Level 2 compliance platforms for small defense contractors: all 110 requirements as an assessment checklist, honest tool comparisons, pricing transparency, and C3PAO assessment insights.
Read the guide →What to require, what to ask, and how to choose CMMC Level 2 compliance software for your defense contracting organization — written for contractors, not consultants.
Read the guide →A complete guide to NIST SP 800-171 Rev 2: all 110 security requirements, the 14 domain structure, requirement numbering, and its relationship to CMMC Level 2 certification.
Read the guide →Weapons and munitions manufacturers integrate physical security with digital compliance in ways no other defense sector does. A practical guide to CMMC scope in controlled production environments.
Read the guide →A spreadsheet can document your CMMC posture. It cannot prove continuous operation, trace your SPRS score to a methodology, or survive C3PAO scrutiny. Here is what that difference costs.
Read the guide →Naval architecture drawings, ship repair specifications, and combat systems documentation present distinct CMMC scoping challenges. A practical guide for naval and maritime defense suppliers.
Read the guide →The complete C3PAO assessment process explained: the 4 phases, what assessors examine, how scoring works, what causes failures, how to choose a C3PAO, and what happens after certification.
Read the guide →CMMC 2.0 explained for defense contractors: what it requires, who it applies to, the 3 certification levels, how it differs from NIST 800-171, the enforcement timeline, and what a C3PAO assessment involves.
Read the overview →Maintenance records, technical manuals, and repair specifications for active defense platforms represent some of the most complex CMMC scoping challenges. A practical guide for MRO contractors.
Read the guide →Prime contractor flow-down audits are happening now. Sub-tier ground vehicle suppliers face CMMC obligations they may not have formally accepted. A practical guide to navigating flow-down requirements.
Read the guide →Most CMMC compliance software was built for large primes and scaled down. 1TEN was built from the ground up for small defense contractors: air-gapped, affordable, and designed to be run without a compliance team.
Read the article →Technical drawings, CNC programs, inspection records, and ERP data — a practical guide to identifying CUI scope for aerospace and defense manufacturers facing CMMC Level 2 assessment.
Read the guide →A side-by-side breakdown of NIST SP 800-171 Rev 2 and Rev 3: requirement count changes, new controls, removed controls, and what the transition means for CMMC Level 2 contractors.
Read the guide →1TEN gives your team the structure to govern CMMC compliance without building a compliance department around it.
Request a Demo