Security & Compliance Intelligence

CMMC.
Intelligence.

Guides, regulatory breakdowns, and assessment readiness resources for defense contractors.

Last updated July 14, 2026

63 Guides & Articles
14 CMMC Domains Covered
110 Requirements Referenced
CMMC
2026-07-14 · 9 min read

DoD Suspends CMMC Phase 2: What Changed, What Didn't, What to Do

On July 13, 2026 the DoD immediately suspended CMMC Phase 2 third-party certification and stood up a 60-day reform task force. The certification mechanism is under review. DFARS 252.204-7012, NIST 800-171, self-assessment, and SPRS scores are not. Here is exactly what changed and what contractors should do.

Read the article →
CM
2026-07-07 · 11 min read

CMMC Specialized Assets: OT, IoT, GFE & Test Equipment Explained

The five CMMC Level 2 Specialized Asset types (OT, IoT/IIoT, GFE, Restricted Information Systems, and Test Equipment): how they are scoped, documented in the SSP, and why they are not assessed against all 110 requirements.

Read the article →
CMMC
2026-07-06 · 14 min read

The Phase 2 Deadline Is a Queue, Not a Date: The C3PAO Capacity Math

Phase 2 is a scheduling problem, not a calendar problem. The real assessment-capacity numbers from the February 2026 Cyber AB Town Hall, the working-backwards timeline, the conditional certification path, and what to do this quarter.

Read the guide →
REG CA
2026-07-01 · 12 min read

CMMC Is Becoming the New SOC 2 — And That's Bigger Than Defense

CMMC Level 2 is more prescriptive than SOC 2, independently verified, and increasingly recognized by cyber insurance underwriters. Here is why that matters even if you never touch a DoD contract.

Read the analysis →
SC MP PE
2026-06-30 · 12 min read

BitLocker, the TPM, and CUI at Rest: Securing Disk Encryption Against the Latest Exploits

BitLocker protects CUI at rest under CMMC, but default TPM-only mode is broken by bitpixie, YellowKey, and TPM bus sniffing. Learn how to harden BitLocker, where FIPS mode matters, and which alternatives qualify.

Read the guide →
SC AC MP
2026-06-16 · 8 min read

Acceptable Methods for Sending and Receiving CUI (2026)

Which methods are actually acceptable for transmitting CUI? Email, file transfer, remote access, and physical media: requirements, approved tools, and common assessment failures explained.

Read the guide →
1%
of Defense Industrial Base contractors are fully prepared for a CMMC Level 2 assessment.
CyberSheath State of the DIB Report, 2025
AC PS SC
2026-06-01 · 13 min read

CMMC Compliance with Remote Employees and Offshore Teams (2026)

Can you get CMMC certification with remote employees or offshore developers? Here is what the rules actually require, where offshore work creates hard stops, and how to structure your team for a passing assessment.

Read the article →
IR
2026-05-12 · 14 min read

Incident Response Tabletop Exercises for CMMC — IR.L2-3.6.3 Guide

How to run, document, and evidence CMMC tabletop exercises that satisfy IR.L2-3.6.3. Includes five ready-to-use scenarios for small DIB contractors, documentation requirements, and what assessors look for.

Read the article →
AC SC AU CM MA MP SI IA PE
2026-05-06 · 17 min read

VDI for CMMC Compliance: Scope Reduction, Requirements, and What It Doesn't Solve

Virtual Desktop Infrastructure can shrink your CMMC assessment boundary by keeping CUI off local endpoints. Here is what VDI actually solves, what it doesn

Read the article →
MP SC AC
2026-04-30 · 13 min read

CUI//SP-CTI: Controlled Technical Information in the Defense Supply Chain

What Controlled Technical Information (CTI) is, how distribution statements B through F make your data CUI, where CTI hides in contractor environments, and what CMMC Level 2 requires to protect it.

Read the guide →
CMMC
2026-04-23 · 11 min read

DLA CMMC Webinar: Key Takeaways for Small Business Suppliers

Summary of the DLA Office of Small Business Programs CMMC webinar. Covers CMMC levels, phase-in dates, DLA-specific contract language, CUI identification, SPRS submission, and POA&M rules.

Read the article →
AU SI AC IA IR CA
2026-04-22 · 11 min read

SI.L2-3.14.6 and SI.L2-3.14.7: CMMC Monitoring and Unauthorized Use Detection

SI.L2-3.14.6 (5 pts) requires monitoring inbound and outbound traffic to detect attacks. SI.L2-3.14.7 (3 pts) requires identifying unauthorized system use. Neither is POA&M eligible. Here is what they require and how to satisfy them before your C3PAO assessment.

Read the article →
What used to take our team three weeks to pull together for an assessment we now produce in an afternoon. The SSP and evidence matrix come out ready to hand to the C3PAO.
IT Director, Tier 2 Defense Manufacturer
CMMC
2026-04-22 · 13 min read

CMMC Registered Practitioner Software Tools: What RPs Use to Serve DIB Clients

CMMC Registered Practitioners need more than a checklist. This guide covers the software tools RPs use to run gap assessments, build SSPs, track POA&Ms, score SPRS, and package C3PAO-ready evidence across multiple clients — including what 1TEN provides specifically for RP engagements.

Read the article →
AT AC MP PE SC IR SI
2026-04-20 · 7 min read

CUI Awareness Training for Defense Contractors | Free CUI Training Template

Free CUI awareness training template for defense contractors. Covers what CUI is, markings, handling, transmission, incident reporting, and the CMMC domains this training supports.

Read the guide →
CA SI
2026-04-15 · 2 min read

The Complete CUI Guide for DoD Contractors (2026)

Everything a defense contractor needs to know about Controlled Unclassified Information: what CUI is, how to identify and scope it, storage and transmission rules, DFARS 7012 obligations, incident reporting, training, subcontractor flow-down, and how to build a compliant program.

Read the guide →
CA RA
2026-04-15 · 10 min read

POA&M for CMMC: The 180-Day Rule & What Can't Go on a POA&M

A POA&M documents unmet CMMC requirements and your remediation plan. Learn the 180-day closeout rule, which requirements can

Read the guide →
PLAN
2026-04-14 · 9 min read

CMMC Grants & Funding — Programs That Help Pay for Compliance

A complete guide to federal and state programs that offset CMMC Level 2 compliance costs: APEX Accelerators, MEP grants, FAR Part 31 cost recovery, state-specific programs, and proposed tax credits.

Read the article →
CA SI
2026-04-13 · 10 min read

CMMC SSP Template: Why It Won't Pass a C3PAO Assessment

A CMMC SSP template gives you a blank form. Your C3PAO assessor needs a document about your organization. Here

Read the guide →
$488K
estimated by the DoD for a small business to achieve and sustain CMMC Level 2 over three years.
DoD CMMC Regulatory Impact Analysis (32 CFR Part 170)
PLAN
2026-04-12 · 9 min read

Best CMMC Compliance Software for Defense Contractors (2026)

The top CMMC compliance software platforms for defense contractors in 2026, ranked and compared. Covers air-gapped appliances, cloud GRC tools, and what to look for before you buy.

Read the article →
PLAN
2026-04-10 · 13 min read

CMMC Annual Affirmation: What It Is, Who Signs It, and What Happens If You Miss It

CMMC Level 2 certification is valid for 3 years, but contractors must submit annual affirmations under 32 CFR Part 117. What the affirmation requires, who can sign it, and the consequences of missing the deadline.

Read the article →
PLAN
2026-04-10 · 1 min read

SPRS Self-Assessment Scoring Tool: Calculate Your CMMC Score

Calculate your SPRS score across all 110 NIST SP 800-171 requirements. Mark each requirement met or not met, track your score live, and download a full results report.

Read the guide →
SI AC
2026-04-09 · 10 min read

End-of-Life Software and CMMC Compliance — SI.L2-3.14.1 and the EOL Risk Every DIB Contractor Carries

How end-of-life software creates CMMC Level 2 findings under SI.L2-3.14.1. What EOL means for your SPRS score, how endoflife.date helps track it, and how 1TEN integrates EOL status into your compliance posture.

Read the article →
AU SI
2026-04-08 · 8 min read

NVD and CMMC: How the National Vulnerability Database Drives Your Compliance Obligation

The NVD is the authoritative CVE database behind your CMMC vulnerability scanning obligation. Learn which requirements apply, how SLA-based tracking works, and what tools fix the findings.

Read the article →
PLAN
2026-04-07 · 9 min read

Top CMMC Level 2 Readiness Gaps Across DIB Contractors

Only 1% of DIB contractors are fully ready for CMMC Level 2. Here are the most common readiness gaps we see across small defense contractors — and what to do about them.

Read the report →
We had a consultant quoted at $180K to get us assessment-ready. 1TEN got us there for a fraction of that. The guided questions alone saved us months of back-and-forth.
VP of Operations, Aerospace Subcontractor
CA SI
2026-04-05 · 10 min read

CMMC SSP System Boundary Description: What It Must Include

The SSP system boundary description tells your C3PAO exactly what is being assessed. Learn what it must cover, what assessors reject, and see strong vs. weak examples.

Read the guide →
IA
2026-04-02 · 8 min read

IA.L2-3.5.4 Replay-Resistant Authentication: CMMC Explained

IA.L2-3.5.4 requires replay-resistant authentication for all network access. Learn what it means, how it differs from MFA, what satisfies it, and how assessors evaluate it.

Read the article →
IA
2026-03-30 · 11 min read

CMMC MFA Requirements: IA.L2-3.5.3 Explained for DIB Contractors

IA.L2-3.5.3 requires MFA in two specific scenarios. This is what applies to VPN users, privileged accounts, and remote workers in a CMMC Level 2 environment.

Read the article →
AT
2026-03-29 · 9 min read

CMMC Training Requirements: AT Domain for Defense Contractors

CMMC Level 2 mandates 3 AT domain requirements covering security awareness, role-based training, and social engineering recognition. Here is what your program must include.

Read the article →
CMMC
2026-03-27 · 9 min read

CMMC FAQ: Official DoD Answers to 25 Common Questions

The DoD published official answers to 25 CMMC questions covering assessments, MSPs, cloud, VDI, subcontractors, and POA&Ms. Here is what the answers actually mean.

Read the article →
SC AC
2026-03-27 · 14 min read

CMMC Network Segmentation: How to Build a CUI Enclave

How to segment CUI from your corporate network for CMMC Level 2. VLANs, firewalls, jump hosts, cloud options, and exactly what C3PAO assessors look for.

Read the article →
Nov 2026
Phase 2 begins. The DoD can start requiring a Level 2 third-party certification in new solicitations. The binding constraint is assessment capacity, not the date.
32 CFR Part 170 phased rollout
PE
2026-03-27 · 13 min read

CMMC Physical Security Requirements: PE Domain Guide

All six CMMC Level 2 physical security requirements explained, including PE.L2-3.10.6 for remote work. What C3PAO assessors look for and how to satisfy each control.

Read the article →
PLAN
2026-03-25 · 22 min read

CMMC Compliance Costs: Allowable Expenses, FAR Recovery & Contract Accounting

How to account for, recover, and quote CMMC compliance costs under government contracts. Covers FAR allowability, indirect rate treatment, forward pricing, and cost recovery strategies for defense contractors.

Read the article →
CA RA
2026-03-24 · 12 min read

CMMC POA&M Template: How to Write Items That Survive C3PAO Review

A field-by-field CMMC POA&M template with the credibility standards C3PAO assessors apply. Covers required fields, milestone writing, SPRS prioritization, and the mistakes that turn a remediation plan into a finding.

Read the guide →
REG
2026-03-23 · 6 min read

NIST SP 800-171 Rev 3 Coming to 1TEN — Updated Requirements Live by July 31, 2026

1TEN is rolling out full support for NIST SP 800-171 Revision 3 with a target completion date of July 31, 2026. Learn what changes in Rev 3, how it affects your CMMC compliance posture, and what 1TEN is doing to make the transition seamless.

Read the guide →
AU SI
2026-03-23 · 6 min read

1TEN Integrating Wazuh for Built-In SIEM — Air-Gapped CMMC SIEM Coverage

1TEN is integrating the open-source Wazuh platform to deliver native SIEM capabilities for CMMC Level 2 compliance — no third-party tool required, fully air-gapped, and mapped directly to NIST SP 800-171 AU, SI, IR, and CA requirements.

Read the article →
SC AC
2026-03-20 · 23 min read

CUI Scoping for CMMC Level 2 — Best Practices for Defining Your Assessment Boundary

A complete guide to CUI scoping for CMMC Level 2. Learn the five asset categories, how to define and document your CUI boundary, common scoping mistakes that create findings, and how proper scoping reduces your assessment cost and complexity.

Read the guide →
Our SPRS score went from -67 to +98 in four months. Having every requirement mapped to evidence in one place made the difference — our assessor commented on how organized the documentation was.
Program Manager, Defense Electronics Contractor
AU SI
2026-03-19 · 19 min read

SIEM Integration for CMMC Compliance — How Centralized Logging Satisfies NIST 800-171

How SIEM integration directly satisfies CMMC Level 2 requirements across AU, SI, IR, and CA domains. Includes a complete requirement mapping table, minimum log source list, alert rule catalog, and C3PAO assessment evidence checklist.

Read the article →
PLAN
2026-03-17 · 8 min read

How Much Does CMMC Level 2 Compliance Cost? (2026 Guide)

The real cost of CMMC Level 2 compliance: DoD official three-year estimate, what contractors actually spend, C3PAO assessment fees, consultant rates, and how to reduce total cost.

Read the article →
CMMC
2026-03-17 · 15 min read

The Operational Leader's Guide to CMMC: What You Own, What You Owe, and What Happens If You Miss It

For VPs of Operations, Directors of Manufacturing, and COOs at defense contractors: CMMC is not an IT project. The production floor, the contracts it supports, and the people who run it are all in scope.

Read the article →
CMMC
2026-03-12 · 6 min read

CMMC Small Business Impacts Roundtable – March 2026

Key takeaways from the DoD CMMC Program Small Business Impacts Roundtable held March 12, 2026. Real cost data, C3PAO capacity concerns, DIB attrition rates, and what small defense contractors need to know.

Read the article →
REG
2026-03-12 · 10 min read

DD Form 2345, the JCP, and CMMC: The Compliance Gap Defense Contractors Miss (2026)

Thousands of defense contractors hold a DD2345 JCP certification but have never mapped it to CMMC. Your authorization to receive militarily critical technical data is not a substitute for protecting it.

Read the article →
AC SC CM
2026-03-05 · 12 min read

Defense Electronics and Sensors: How CUI Flows Through Engineering Documentation

Firmware, circuit designs, and test specifications for defense electronics and sensor systems are CUI. A practical guide to CMMC scope boundaries in defense electronics manufacturing environments.

Read the guide →
320
assessment objectives in NIST SP 800-171A support the 110 security requirements evaluated during a CMMC Level 2 assessment.
NIST SP 800-171A
PLAN
2026-03-04 · 12 min read

CMMC Level 2 Requirements Checklist: All 110 Controls with SPRS Point Weights

Complete checklist of all 110 CMMC Level 2 requirements organized by domain, with SPRS point weights (5/3/1) and POA&M eligibility for each control. Free assessment readiness tool for defense contractors.

See the checklist →
PLAN
2026-03-04 · 6 min read

SPRS Score Explained: How DoD Scoring Works & How to Improve It

Your SPRS score ranges from −203 to 110 and is visible to DoD contracting officers. Learn how it

Read the guide →
CA SI
2026-03-04 · 7 min read

What Is a System Security Plan (SSP)? CMMC Requirements & Guide

A System Security Plan documents how your organization implements all 110 CMMC requirements. Learn what an SSP must contain, how C3PAO assessors evaluate it, and common mistakes that fail assessments.

Read the article →
IR
2026-03-03 · 12 min read

CMMC Incident Response Requirements (2026) — 72-Hour Reporting Guide

CMMC incident response requirements explained: what triggers the 72-hour DIBNet reporting clock, what constitutes a cyber incident under DFARS 7012, evidence preservation obligations, and how to build an IR program that satisfies assessors.

Read the article →
REG
2026-03-02 · 14 min read

CMMC Requirements for Subcontractors (2026) — Do I Need CMMC?

Do subcontractors need CMMC certification? Who the flow-down obligation applies to, what primes must require, how to determine if your subcontract triggers CMMC, and what happens if you ignore it.

Read the guide →
REG
2026-02-27 · 14 min read

CUI Handling Requirements for Defense Contractors (2026)

What Controlled Unclassified Information (CUI) is, how to identify it in your environment, what DFARS 7012 and NIST SP 800-171 require for protecting it, and how to build a compliant CUI handling program.

Read the guide →
3 Years
is the standard validity period of a successful CMMC Level 2 certification.
32 CFR Part 170
REG
2026-02-27 · 14 min read

DFARS 252.204-7012 Compliance Guide for Defense Contractors (2026)

DFARS 252.204-7012 explained: what it requires, who it applies to, how it connects to CMMC, NIST SP 800-171, and SPRS scoring, and what happens if you are not compliant.

Read the guide →
PLAN
2026-02-26 · 10 min read

CMMC Level 2 Compliance Platform for Small Defense Contractors: What to Look For in 2026

A comprehensive guide to CMMC Level 2 compliance platforms for small defense contractors: all 110 requirements as an assessment checklist, honest tool comparisons, pricing transparency, and C3PAO assessment insights.

Read the guide →
PLAN
2026-02-24 · 7 min read

CMMC Level 2 Compliance Software: A Buyer's Guide (2026)

What to require, what to ask, and how to choose CMMC Level 2 compliance software for your defense contracting organization — written for contractors, not consultants.

Read the guide →
REG
2026-02-23 · 3 min read

NIST SP 800-171 Explained — 110 Requirements Across 14 Domains

A complete guide to NIST SP 800-171 Rev 2: all 110 security requirements, the 14 domain structure, requirement numbering, and its relationship to CMMC Level 2 certification.

Read the guide →
AC SC CM
2026-02-19 · 10 min read

CMMC for Weapons and Munitions Manufacturers: Managing CUI in Controlled Production Environments

Weapons and munitions manufacturers integrate physical security with digital compliance in ways no other defense sector does. A practical guide to CMMC scope in controlled production environments.

Read the guide →
PLAN
2026-02-18 · 11 min read

CMMC Compliance Software vs. Spreadsheet: What the Difference Costs You

A spreadsheet can document your CMMC posture. It cannot prove continuous operation, trace your SPRS score to a methodology, or survive C3PAO scrutiny. Here is what that difference costs.

Read the guide →
110
security requirements from NIST SP 800-171 Rev 2 form the foundation of every CMMC Level 2 assessment.
NIST SP 800-171 Rev. 2
AC SC CM
2026-02-05 · 9 min read

CMMC for Naval and Maritime Suppliers: Ship System Data and Assessment Scope

Naval architecture drawings, ship repair specifications, and combat systems documentation present distinct CMMC scoping challenges. A practical guide for naval and maritime defense suppliers.

Read the guide →
CMMC
2026-02-01 · 12 min read

C3PAO Assessment Process: What to Expect at Every Stage (2026 Guide)

The complete C3PAO assessment process explained: the 4 phases, what assessors examine, how scoring works, what causes failures, how to choose a C3PAO, and what happens after certification.

Read the guide →
CMMC
2026-02-01 · 17 min read

What is CMMC 2.0? A Plain-English Guide for Defense Contractors (2026)

CMMC 2.0 explained for defense contractors: what it requires, who it applies to, the 3 certification levels, how it differs from NIST 800-171, the enforcement timeline, and what a C3PAO assessment involves.

Read the overview →
AC SC CM
2026-01-22 · 10 min read

MRO Contractors and CMMC: Why Sustainment Work Is Often the Most Complex Scope

Maintenance records, technical manuals, and repair specifications for active defense platforms represent some of the most complex CMMC scoping challenges. A practical guide for MRO contractors.

Read the guide →
AC SC CM
2026-01-08 · 10 min read

CMMC for Ground Vehicle Manufacturers and Tier 2 Suppliers: Navigating Flow-Down Requirements

Prime contractor flow-down audits are happening now. Sub-tier ground vehicle suppliers face CMMC obligations they may not have formally accepted. A practical guide to navigating flow-down requirements.

Read the guide →
CMMC
2026-01-01 · 6 min read

CMMC Software for Small Defense Contractors (2026)

Most CMMC compliance software was built for large primes and scaled down. 1TEN was built from the ground up for small defense contractors: air-gapped, affordable, and designed to be run without a compliance team.

Read the article →
14
security domains organize the 110 CMMC Level 2 requirements, from Access Control to System & Information Integrity.
NIST SP 800-171 Rev. 2
AC SC CM
2025-12-26 · 12 min read

CMMC Level 2 for Aerospace & Defense Manufacturers: What Counts as CUI on Your Shop Floor

Technical drawings, CNC programs, inspection records, and ERP data — a practical guide to identifying CUI scope for aerospace and defense manufacturers facing CMMC Level 2 assessment.

Read the guide →
AC CA CM IA RA SC SI
2025-06-15 · 8 min read

NIST SP 800-171 Rev 2 vs Rev 3: What Changed (2025)

A side-by-side breakdown of NIST SP 800-171 Rev 2 and Rev 3: requirement count changes, new controls, removed controls, and what the transition means for CMMC Level 2 contractors.

Read the guide →

Miss nothing.

1TEN gives your team the structure to govern CMMC compliance without building a compliance department around it.

Request a Demo