Security & Compliance Intelligence

CMMC.
Intelligence.

Guides, regulatory breakdowns, and assessment readiness resources for defense contractors.

Last updated August 4, 2026

66 Guides & Articles
14 CMMC Domains Covered
110 Requirements Referenced
CMMC
2026-08-04 · 10 min read

Department of War Suspends CMMC Phase 2: What Changed, What Didn't, What to Do

On July 13, 2026 the Department of War (formerly the DoD) immediately suspended CMMC Phase 2 third-party certification and stood up a 60-day reform task force. The certification mechanism is under review. DFARS 252.204-7012, NIST 800-171, self-assessment, and SPRS scores are not. Here is exactly what changed and what contractors should do.

Read the article →
1%
of Defense Industrial Base contractors are fully prepared for a CMMC Level 2 assessment.
CyberSheath State of the DIB Report, 2025
REG CA
2026-07-01 · 12 min read

CMMC Is Becoming the New SOC 2 — And That's Bigger Than Defense

CMMC Level 2 is more prescriptive than SOC 2, independently verified, and increasingly recognized by cyber insurance underwriters. Here is why that matters even if you never touch a DoD contract.

Read the analysis →
SC MP PE
2026-06-30 · 12 min read

BitLocker, the TPM, and CUI at Rest: Securing Disk Encryption Against the Latest Exploits

BitLocker protects CUI at rest under CMMC, but default TPM-only mode is broken by bitpixie, YellowKey, and TPM bus sniffing. Learn how to harden BitLocker, where FIPS mode matters, and which alternatives qualify.

Read the guide →
SC AC MP
2026-06-16 · 8 min read

Acceptable Methods for Sending and Receiving CUI (2026)

Which methods are actually acceptable for transmitting CUI? Email, file transfer, remote access, and physical media: requirements, approved tools, and common assessment failures explained.

Read the guide →
What used to take our team three weeks to pull together for an assessment we now produce in an afternoon. The SSP and evidence matrix come out ready to hand to the C3PAO.
IT Director, Tier 2 Defense Manufacturer
MP SC AC
2026-04-30 · 13 min read

CUI//SP-CTI: Controlled Technical Information in the Defense Supply Chain

What Controlled Technical Information (CTI) is, how distribution statements B through F make your data CUI, where CTI hides in contractor environments, and what CMMC Level 2 requires to protect it.

Read the guide →
$488K
estimated by the DoD for a small business to achieve and sustain CMMC Level 2 over three years.
DoD CMMC Regulatory Impact Analysis (32 CFR Part 170)
AT AC MP PE SC IR SI
2026-04-20 · 7 min read

CUI Awareness Training for Defense Contractors | Free CUI Training Template

Free CUI awareness training template for defense contractors. Covers what CUI is, markings, handling, transmission, incident reporting, and the CMMC domains this training supports.

Read the guide →
CA SI
2026-04-15 · 2 min read

The Complete CUI Guide for DoD Contractors (2026)

Everything a defense contractor needs to know about Controlled Unclassified Information: what CUI is, how to identify and scope it, storage and transmission rules, DFARS 7012 obligations, incident reporting, training, subcontractor flow-down, and how to build a compliant program.

Read the guide →
We had a consultant quoted at $180K to get us assessment-ready. 1TEN got us there for a fraction of that. The guided questions alone saved us months of back-and-forth.
VP of Operations, Aerospace Subcontractor
SI AC
2026-04-09 · 10 min read

End-of-Life Software and CMMC Compliance — SI.L2-3.14.1 and the EOL Risk Every DIB Contractor Carries

How end-of-life software creates CMMC Level 2 findings under SI.L2-3.14.1. What EOL means for your SPRS score, how endoflife.date helps track it, and how 1TEN integrates EOL status into your compliance posture.

Read the article →
Nov 2026
Phase 2 begins. The DoD can start requiring a Level 2 third-party certification in new solicitations. The binding constraint is assessment capacity, not the date.
32 CFR Part 170 phased rollout
Our SPRS score went from -67 to +98 in four months. Having every requirement mapped to evidence in one place made the difference — our assessor commented on how organized the documentation was.
Program Manager, Defense Electronics Contractor
REG
2026-03-23 · 6 min read

NIST SP 800-171 Rev 3 Coming to 1TEN — Updated Requirements Live by July 31, 2026

1TEN is rolling out full support for NIST SP 800-171 Revision 3 with a target completion date of July 31, 2026. Learn what changes in Rev 3, how it affects your CMMC compliance posture, and what 1TEN is doing to make the transition seamless.

Read the guide →
SC AC
2026-03-20 · 23 min read

CUI Scoping for CMMC Level 2 — Best Practices for Defining Your Assessment Boundary

A complete guide to CUI scoping for CMMC Level 2. Learn the five asset categories, how to define and document your CUI boundary, common scoping mistakes that create findings, and how proper scoping reduces your assessment cost and complexity.

Read the guide →
320
assessment objectives in NIST SP 800-171A support the 110 security requirements evaluated during a CMMC Level 2 assessment.
NIST SP 800-171A
3 Years
is the standard validity period of a successful CMMC Level 2 certification.
32 CFR Part 170
IR
2026-03-03 · 12 min read

CMMC Incident Response Requirements (2026) — 72-Hour Reporting Guide

CMMC incident response requirements explained: what triggers the 72-hour DIBNet reporting clock, what constitutes a cyber incident under DFARS 7012, evidence preservation obligations, and how to build an IR program that satisfies assessors.

Read the article →
REG
2026-03-02 · 14 min read

CMMC Requirements for Subcontractors (2026) — Do I Need CMMC?

Do subcontractors need CMMC certification? Who the flow-down obligation applies to, what primes must require, how to determine if your subcontract triggers CMMC, and what happens if you ignore it.

Read the guide →
REG
2026-02-27 · 14 min read

CUI Handling Requirements for Defense Contractors (2026)

What Controlled Unclassified Information (CUI) is, how to identify it in your environment, what DFARS 7012 and NIST SP 800-171 require for protecting it, and how to build a compliant CUI handling program.

Read the guide →
REG
2026-02-27 · 14 min read

DFARS 252.204-7012 Compliance Guide for Defense Contractors (2026)

DFARS 252.204-7012 explained: what it requires, who it applies to, how it connects to CMMC, NIST SP 800-171, and SPRS scoring, and what happens if you are not compliant.

Read the guide →
110
security requirements from NIST SP 800-171 Rev 2 form the foundation of every CMMC Level 2 assessment.
NIST SP 800-171 Rev. 2
REG
2026-02-23 · 3 min read

NIST SP 800-171 Explained — 110 Requirements Across 14 Domains

A complete guide to NIST SP 800-171 Rev 2: all 110 security requirements, the 14 domain structure, requirement numbering, and its relationship to CMMC Level 2 certification.

Read the guide →
CMMC
2026-02-01 · 17 min read

What is CMMC 2.0? A Plain-English Guide for Defense Contractors (2026)

CMMC 2.0 explained for defense contractors: what it requires, who it applies to, the 3 certification levels, how it differs from NIST 800-171, the enforcement timeline, and what a C3PAO assessment involves.

Read the overview →
14
security domains organize the 110 CMMC Level 2 requirements, from Access Control to System & Information Integrity.
NIST SP 800-171 Rev. 2
AC CA CM IA RA SC SI
2025-06-15 · 8 min read

NIST SP 800-171 Rev 2 vs Rev 3: What Changed (2025)

A side-by-side breakdown of NIST SP 800-171 Rev 2 and Rev 3: requirement count changes, new controls, removed controls, and what the transition means for CMMC Level 2 contractors.

Read the guide →

Engineered for the DIB.

1TEN tracks your control implementation, calculates your live SPRS score, and organizes your evidence package. On-premises, air-gapped.

Request a Demo