Security & Compliance Intelligence

CMMC.
Intelligence.

Guides, regulatory breakdowns, and assessment readiness resources for defense contractors.

Last updated August 4, 2026

66 Guides & Articles
14 CMMC Domains Covered
110 Requirements Referenced
PLAN
2026-08-04 · 18 min read

CMMC Compliance Software: Segments, Use Cases & Platform Comparison (2026)

CMMC compliance software compared by category and use case: purpose-built CMMC platforms, multi-framework GRC tools, and CUI security platforms. Which segment each is ideal for, and what to demand before you buy.

Read the guide →
CMMC
2026-08-04 · 22 min read

Do You Need GCC High for CMMC? A Decision Guide by CUI Category, Export Control & Deployment (2026)

The honest answer to whether your defense contract requires GCC High for CMMC Level 2. Decision tree by CUI category, DFARS 7012 requirements, ITAR/EAR implications, and when Microsoft 365 Commercial or GCC is actually enough.

Read the article →
CMMC
2026-07-28 · 9 min read

JSVA to CMMC Level 2 Conversion: What Happens to Your Certificate Now

If you completed a Joint Surveillance Voluntary Assessment before Phase 2 was suspended, what happens to your conversion credit? Here is what the record actually says, what the July 13 suspension changed, and what JSVA holders should do next.

Read the article →
CMMC
2026-07-21 · 9 min read

CMMC Shared Responsibility Matrix: What Your MSP or Cloud Provider Actually Covers

Assessors will ask for it, and half the contractors we talk to do not have one. A CRM or SRM is the artifact that names, per control, which party actually implements what. Here is what it should contain, where the traps are, and how to build one that survives an assessment.

Read the article →
CMMC
2026-07-14 · 10 min read

CMMC Enclave Strategy: When to Isolate CUI Instead of Rolling Out Full Level 2

Most defense contractors do not need to bring their whole company into CMMC scope. An enclave, done right, isolates the small slice of the business that touches CUI and leaves the rest alone. Here is when it works, when it doesn

Read the article →
1%
of Defense Industrial Base contractors are fully prepared for a CMMC Level 2 assessment.
CyberSheath State of the DIB Report, 2025
CM
2026-07-07 · 11 min read

CMMC Specialized Assets: OT, IoT, GFE & Test Equipment Explained

The five CMMC Level 2 Specialized Asset types (OT, IoT/IIoT, GFE, Restricted Information Systems, and Test Equipment): how they are scoped, documented in the SSP, and why they are not assessed against all 110 requirements.

Read the article →
CMMC
2026-07-06 · 14 min read

The Phase 2 Deadline Is a Queue, Not a Date: The C3PAO Capacity Math

Phase 2 is a scheduling problem, not a calendar problem. The real assessment-capacity numbers from the February 2026 Cyber AB Town Hall, the working-backwards timeline, the conditional certification path, and what to do this quarter.

Read the guide →
AC PS SC
2026-06-01 · 13 min read

CMMC Compliance with Remote Employees and Offshore Teams (2026)

Can you get CMMC certification with remote employees or offshore developers? Here is what the rules actually require, where offshore work creates hard stops, and how to structure your team for a passing assessment.

Read the article →
What used to take our team three weeks to pull together for an assessment we now produce in an afternoon. The SSP and evidence matrix come out ready to hand to the C3PAO.
IT Director, Tier 2 Defense Manufacturer
IR
2026-05-12 · 14 min read

Incident Response Tabletop Exercises for CMMC — IR.L2-3.6.3 Guide

How to run, document, and evidence CMMC tabletop exercises that satisfy IR.L2-3.6.3. Includes five ready-to-use scenarios for small DIB contractors, documentation requirements, and what assessors look for.

Read the article →
AC SC AU CM MA MP SI IA PE
2026-05-06 · 17 min read

VDI for CMMC Compliance: Scope Reduction, Requirements, and What It Doesn't Solve

Virtual Desktop Infrastructure can shrink your CMMC assessment boundary by keeping CUI off local endpoints. Here is what VDI actually solves, what it doesn

Read the article →
CMMC
2026-04-23 · 11 min read

DLA CMMC Webinar: Key Takeaways for Small Business Suppliers

Summary of the DLA Office of Small Business Programs CMMC webinar. Covers CMMC levels, phase-in dates, DLA-specific contract language, CUI identification, SPRS submission, and POA&M rules.

Read the article →
AU SI AC IA IR CA
2026-04-22 · 11 min read

SI.L2-3.14.6 and SI.L2-3.14.7: CMMC Monitoring and Unauthorized Use Detection

SI.L2-3.14.6 (5 pts) requires monitoring inbound and outbound traffic to detect attacks. SI.L2-3.14.7 (3 pts) requires identifying unauthorized system use. Neither is POA&M eligible. Here is what they require and how to satisfy them before your C3PAO assessment.

Read the article →
CMMC
2026-04-22 · 13 min read

CMMC Registered Practitioner Software Tools: What RPs Use to Serve DIB Clients

CMMC Registered Practitioners need more than a checklist. This guide covers the software tools RPs use to run gap assessments, build SSPs, track POA&Ms, score SPRS, and package C3PAO-ready evidence across multiple clients — including what 1TEN provides specifically for RP engagements.

Read the article →
$488K
estimated by the DoD for a small business to achieve and sustain CMMC Level 2 over three years.
DoD CMMC Regulatory Impact Analysis (32 CFR Part 170)
PLAN
2026-04-14 · 9 min read

CMMC Grants & Funding — Programs That Help Pay for Compliance

A complete guide to federal and state programs that offset CMMC Level 2 compliance costs: APEX Accelerators, MEP grants, FAR Part 31 cost recovery, state-specific programs, and proposed tax credits.

Read the article →
We had a consultant quoted at $180K to get us assessment-ready. 1TEN got us there for a fraction of that. The guided questions alone saved us months of back-and-forth.
VP of Operations, Aerospace Subcontractor
PLAN
2026-04-10 · 1 min read

SPRS Self-Assessment Scoring Tool: Calculate Your CMMC Score

Calculate your SPRS score across all 110 NIST SP 800-171 requirements. Mark each requirement met or not met, track your score live, and download a full results report.

Read the guide →
SI AC
2026-04-09 · 10 min read

End-of-Life Software and CMMC Compliance — SI.L2-3.14.1 and the EOL Risk Every DIB Contractor Carries

How end-of-life software creates CMMC Level 2 findings under SI.L2-3.14.1. What EOL means for your SPRS score, how endoflife.date helps track it, and how 1TEN integrates EOL status into your compliance posture.

Read the article →
AU SI
2026-04-08 · 8 min read

NVD and CMMC: How the National Vulnerability Database Drives Your Compliance Obligation

The NVD is the authoritative CVE database behind your CMMC vulnerability scanning obligation. Learn which requirements apply, how SLA-based tracking works, and what tools fix the findings.

Read the article →
PLAN
2026-04-07 · 9 min read

Top CMMC Level 2 Readiness Gaps Across DIB Contractors

Only 1% of DIB contractors are fully ready for CMMC Level 2. Here are the most common readiness gaps we see across small defense contractors — and what to do about them.

Read the report →
IA
2026-04-02 · 8 min read

IA.L2-3.5.4 Replay-Resistant Authentication: CMMC Explained

IA.L2-3.5.4 requires replay-resistant authentication for all network access. Learn what it means, how it differs from MFA, what satisfies it, and how assessors evaluate it.

Read the article →
Nov 2026
Phase 2 begins. The DoD can start requiring a Level 2 third-party certification in new solicitations. The binding constraint is assessment capacity, not the date.
32 CFR Part 170 phased rollout
IA
2026-03-30 · 11 min read

CMMC MFA Requirements: IA.L2-3.5.3 Explained for DIB Contractors

IA.L2-3.5.3 requires MFA in two specific scenarios. This is what applies to VPN users, privileged accounts, and remote workers in a CMMC Level 2 environment.

Read the article →
AT
2026-03-29 · 9 min read

CMMC Training Requirements: AT Domain for Defense Contractors

CMMC Level 2 mandates 3 AT domain requirements covering security awareness, role-based training, and social engineering recognition. Here is what your program must include.

Read the article →
CMMC
2026-03-27 · 9 min read

CMMC FAQ: Official DoD Answers to 25 Common Questions

The DoD published official answers to 25 CMMC questions covering assessments, MSPs, cloud, VDI, subcontractors, and POA&Ms. Here is what the answers actually mean.

Read the article →
SC AC
2026-03-27 · 14 min read

CMMC Network Segmentation: How to Build a CUI Enclave

How to segment CUI from your corporate network for CMMC Level 2. VLANs, firewalls, jump hosts, cloud options, and exactly what C3PAO assessors look for.

Read the article →
PE
2026-03-27 · 13 min read

CMMC Physical Security Requirements: PE Domain Guide

All six CMMC Level 2 physical security requirements explained, including PE.L2-3.10.6 for remote work. What C3PAO assessors look for and how to satisfy each control.

Read the article →
PLAN
2026-03-25 · 22 min read

CMMC Compliance Costs: Allowable Expenses, FAR Recovery & Contract Accounting

How to account for, recover, and quote CMMC compliance costs under government contracts. Covers FAR allowability, indirect rate treatment, forward pricing, and cost recovery strategies for defense contractors.

Read the article →
Our SPRS score went from -67 to +98 in four months. Having every requirement mapped to evidence in one place made the difference — our assessor commented on how organized the documentation was.
Program Manager, Defense Electronics Contractor
AU SI
2026-03-19 · 19 min read

SIEM Integration for CMMC Compliance — How Centralized Logging Satisfies NIST 800-171

How SIEM integration directly satisfies CMMC Level 2 requirements across AU, SI, IR, and CA domains. Includes a complete requirement mapping table, minimum log source list, alert rule catalog, and C3PAO assessment evidence checklist.

Read the article →
PLAN
2026-03-17 · 8 min read

How Much Does CMMC Level 2 Compliance Cost? (2026 Guide)

The real cost of CMMC Level 2 compliance: DoD official three-year estimate, what contractors actually spend, C3PAO assessment fees, consultant rates, and how to reduce total cost.

Read the article →
320
assessment objectives in NIST SP 800-171A support the 110 security requirements evaluated during a CMMC Level 2 assessment.
NIST SP 800-171A
CMMC
2026-03-17 · 15 min read

The Operational Leader's Guide to CMMC: What You Own, What You Owe, and What Happens If You Miss It

For VPs of Operations, Directors of Manufacturing, and COOs at defense contractors: CMMC is not an IT project. The production floor, the contracts it supports, and the people who run it are all in scope.

Read the article →
CMMC
2026-03-12 · 6 min read

CMMC Small Business Impacts Roundtable – March 2026

Key takeaways from the DoD CMMC Program Small Business Impacts Roundtable held March 12, 2026. Real cost data, C3PAO capacity concerns, DIB attrition rates, and what small defense contractors need to know.

Read the article →
REG
2026-03-12 · 10 min read

DD Form 2345, the JCP, and CMMC: The Compliance Gap Defense Contractors Miss (2026)

Thousands of defense contractors hold a DD2345 JCP certification but have never mapped it to CMMC. Your authorization to receive militarily critical technical data is not a substitute for protecting it.

Read the article →
PLAN
2026-03-04 · 12 min read

CMMC Level 2 Requirements Checklist: All 110 Controls with SPRS Point Weights

Complete checklist of all 110 CMMC Level 2 requirements organized by domain, with SPRS point weights (5/3/1) and POA&M eligibility for each control. Free assessment readiness tool for defense contractors.

See the checklist →
3 Years
is the standard validity period of a successful CMMC Level 2 certification.
32 CFR Part 170
PLAN
2026-02-26 · 10 min read

CMMC Level 2 Compliance Platform for Small Defense Contractors: What to Look For in 2026

A comprehensive guide to CMMC Level 2 compliance platforms for small defense contractors: all 110 requirements as an assessment checklist, honest tool comparisons, pricing transparency, and C3PAO assessment insights.

Read the guide →
110
security requirements from NIST SP 800-171 Rev 2 form the foundation of every CMMC Level 2 assessment.
NIST SP 800-171 Rev. 2
PLAN
2026-02-18 · 11 min read

CMMC Compliance Software vs. Spreadsheet: What the Difference Costs You

A spreadsheet can document your CMMC posture. It cannot prove continuous operation, trace your SPRS score to a methodology, or survive C3PAO scrutiny. Here is what that difference costs.

Read the guide →
CMMC
2026-02-01 · 12 min read

C3PAO Assessment Process: What to Expect at Every Stage (2026 Guide)

The complete C3PAO assessment process explained: the 4 phases, what assessors examine, how scoring works, what causes failures, how to choose a C3PAO, and what happens after certification.

Read the guide →
CMMC
2026-02-01 · 17 min read

What is CMMC 2.0? A Plain-English Guide for Defense Contractors (2026)

CMMC 2.0 explained for defense contractors: what it requires, who it applies to, the 3 certification levels, how it differs from NIST 800-171, the enforcement timeline, and what a C3PAO assessment involves.

Read the overview →
14
security domains organize the 110 CMMC Level 2 requirements, from Access Control to System & Information Integrity.
NIST SP 800-171 Rev. 2
CMMC
2026-01-01 · 6 min read

CMMC Software for Small Defense Contractors (2026)

Most CMMC compliance software was built for large primes and scaled down. 1TEN was built from the ground up for small defense contractors: air-gapped, affordable, and designed to be run without a compliance team.

Read the article →

Know your posture.

1TEN is the GRC platform built specifically for small defense manufacturers navigating CMMC Level 2.

Request a Demo