Guides, regulatory breakdowns, and assessment readiness resources for defense contractors.
Last updated August 4, 2026
Practical CUI best practices across access control, network protection, system configuration, and audit logging. What CMMC assessors verify and how to be ready.
Read the guide →CMMC compliance software compared by category and use case: purpose-built CMMC platforms, multi-framework GRC tools, and CUI security platforms. Which segment each is ideal for, and what to demand before you buy.
Read the guide →The honest answer to whether your defense contract requires GCC High for CMMC Level 2. Decision tree by CUI category, DFARS 7012 requirements, ITAR/EAR implications, and when Microsoft 365 Commercial or GCC is actually enough.
Read the article →If you completed a Joint Surveillance Voluntary Assessment before Phase 2 was suspended, what happens to your conversion credit? Here is what the record actually says, what the July 13 suspension changed, and what JSVA holders should do next.
Read the article →Assessors will ask for it, and half the contractors we talk to do not have one. A CRM or SRM is the artifact that names, per control, which party actually implements what. Here is what it should contain, where the traps are, and how to build one that survives an assessment.
Read the article →Most defense contractors do not need to bring their whole company into CMMC scope. An enclave, done right, isolates the small slice of the business that touches CUI and leaves the rest alone. Here is when it works, when it doesn
Read the article →The five CMMC Level 2 Specialized Asset types (OT, IoT/IIoT, GFE, Restricted Information Systems, and Test Equipment): how they are scoped, documented in the SSP, and why they are not assessed against all 110 requirements.
Read the article →Phase 2 is a scheduling problem, not a calendar problem. The real assessment-capacity numbers from the February 2026 Cyber AB Town Hall, the working-backwards timeline, the conditional certification path, and what to do this quarter.
Read the guide →Can you get CMMC certification with remote employees or offshore developers? Here is what the rules actually require, where offshore work creates hard stops, and how to structure your team for a passing assessment.
Read the article →How to run, document, and evidence CMMC tabletop exercises that satisfy IR.L2-3.6.3. Includes five ready-to-use scenarios for small DIB contractors, documentation requirements, and what assessors look for.
Read the article →Virtual Desktop Infrastructure can shrink your CMMC assessment boundary by keeping CUI off local endpoints. Here is what VDI actually solves, what it doesn
Read the article →Summary of the DLA Office of Small Business Programs CMMC webinar. Covers CMMC levels, phase-in dates, DLA-specific contract language, CUI identification, SPRS submission, and POA&M rules.
Read the article →SI.L2-3.14.6 (5 pts) requires monitoring inbound and outbound traffic to detect attacks. SI.L2-3.14.7 (3 pts) requires identifying unauthorized system use. Neither is POA&M eligible. Here is what they require and how to satisfy them before your C3PAO assessment.
Read the article →CMMC Registered Practitioners need more than a checklist. This guide covers the software tools RPs use to run gap assessments, build SSPs, track POA&Ms, score SPRS, and package C3PAO-ready evidence across multiple clients — including what 1TEN provides specifically for RP engagements.
Read the article →A complete guide to federal and state programs that offset CMMC Level 2 compliance costs: APEX Accelerators, MEP grants, FAR Part 31 cost recovery, state-specific programs, and proposed tax credits.
Read the article →Calculate your SPRS score across all 110 NIST SP 800-171 requirements. Mark each requirement met or not met, track your score live, and download a full results report.
Read the guide →How end-of-life software creates CMMC Level 2 findings under SI.L2-3.14.1. What EOL means for your SPRS score, how endoflife.date helps track it, and how 1TEN integrates EOL status into your compliance posture.
Read the article →The NVD is the authoritative CVE database behind your CMMC vulnerability scanning obligation. Learn which requirements apply, how SLA-based tracking works, and what tools fix the findings.
Read the article →Only 1% of DIB contractors are fully ready for CMMC Level 2. Here are the most common readiness gaps we see across small defense contractors — and what to do about them.
Read the report →New guides, regulatory breakdowns, and assessment readiness updates, delivered when we publish. No noise.
IA.L2-3.5.4 requires replay-resistant authentication for all network access. Learn what it means, how it differs from MFA, what satisfies it, and how assessors evaluate it.
Read the article →IA.L2-3.5.3 requires MFA in two specific scenarios. This is what applies to VPN users, privileged accounts, and remote workers in a CMMC Level 2 environment.
Read the article →CMMC Level 2 mandates 3 AT domain requirements covering security awareness, role-based training, and social engineering recognition. Here is what your program must include.
Read the article →The DoD published official answers to 25 CMMC questions covering assessments, MSPs, cloud, VDI, subcontractors, and POA&Ms. Here is what the answers actually mean.
Read the article →How to segment CUI from your corporate network for CMMC Level 2. VLANs, firewalls, jump hosts, cloud options, and exactly what C3PAO assessors look for.
Read the article →All six CMMC Level 2 physical security requirements explained, including PE.L2-3.10.6 for remote work. What C3PAO assessors look for and how to satisfy each control.
Read the article →How to account for, recover, and quote CMMC compliance costs under government contracts. Covers FAR allowability, indirect rate treatment, forward pricing, and cost recovery strategies for defense contractors.
Read the article →How SIEM integration directly satisfies CMMC Level 2 requirements across AU, SI, IR, and CA domains. Includes a complete requirement mapping table, minimum log source list, alert rule catalog, and C3PAO assessment evidence checklist.
Read the article →The real cost of CMMC Level 2 compliance: DoD official three-year estimate, what contractors actually spend, C3PAO assessment fees, consultant rates, and how to reduce total cost.
Read the article →For VPs of Operations, Directors of Manufacturing, and COOs at defense contractors: CMMC is not an IT project. The production floor, the contracts it supports, and the people who run it are all in scope.
Read the article →Key takeaways from the DoD CMMC Program Small Business Impacts Roundtable held March 12, 2026. Real cost data, C3PAO capacity concerns, DIB attrition rates, and what small defense contractors need to know.
Read the article →Thousands of defense contractors hold a DD2345 JCP certification but have never mapped it to CMMC. Your authorization to receive militarily critical technical data is not a substitute for protecting it.
Read the article →Complete checklist of all 110 CMMC Level 2 requirements organized by domain, with SPRS point weights (5/3/1) and POA&M eligibility for each control. Free assessment readiness tool for defense contractors.
See the checklist →A comprehensive guide to CMMC Level 2 compliance platforms for small defense contractors: all 110 requirements as an assessment checklist, honest tool comparisons, pricing transparency, and C3PAO assessment insights.
Read the guide →A spreadsheet can document your CMMC posture. It cannot prove continuous operation, trace your SPRS score to a methodology, or survive C3PAO scrutiny. Here is what that difference costs.
Read the guide →The complete C3PAO assessment process explained: the 4 phases, what assessors examine, how scoring works, what causes failures, how to choose a C3PAO, and what happens after certification.
Read the guide →CMMC 2.0 explained for defense contractors: what it requires, who it applies to, the 3 certification levels, how it differs from NIST 800-171, the enforcement timeline, and what a C3PAO assessment involves.
Read the overview →Most CMMC compliance software was built for large primes and scaled down. 1TEN was built from the ground up for small defense contractors: air-gapped, affordable, and designed to be run without a compliance team.
Read the article →1TEN is the GRC platform built specifically for small defense manufacturers navigating CMMC Level 2.
Request a Demo