Guides, regulatory breakdowns, and assessment readiness resources for defense contractors.
Last updated August 4, 2026
Practical CUI best practices across access control, network protection, system configuration, and audit logging. What CMMC assessors verify and how to be ready.
Read the guide →On July 13, 2026 the Department of War (formerly the DoD) immediately suspended CMMC Phase 2 third-party certification and stood up a 60-day reform task force. The certification mechanism is under review. DFARS 252.204-7012, NIST 800-171, self-assessment, and SPRS scores are not. Here is exactly what changed and what contractors should do.
Read the article →CMMC Level 2 is more prescriptive than SOC 2, independently verified, and increasingly recognized by cyber insurance underwriters. Here is why that matters even if you never touch a DoD contract.
Read the analysis →BitLocker protects CUI at rest under CMMC, but default TPM-only mode is broken by bitpixie, YellowKey, and TPM bus sniffing. Learn how to harden BitLocker, where FIPS mode matters, and which alternatives qualify.
Read the guide →Which methods are actually acceptable for transmitting CUI? Email, file transfer, remote access, and physical media: requirements, approved tools, and common assessment failures explained.
Read the guide →What Controlled Technical Information (CTI) is, how distribution statements B through F make your data CUI, where CTI hides in contractor environments, and what CMMC Level 2 requires to protect it.
Read the guide →Free CUI awareness training template for defense contractors. Covers what CUI is, markings, handling, transmission, incident reporting, and the CMMC domains this training supports.
Read the guide →Everything a defense contractor needs to know about Controlled Unclassified Information: what CUI is, how to identify and scope it, storage and transmission rules, DFARS 7012 obligations, incident reporting, training, subcontractor flow-down, and how to build a compliant program.
Read the guide →How end-of-life software creates CMMC Level 2 findings under SI.L2-3.14.1. What EOL means for your SPRS score, how endoflife.date helps track it, and how 1TEN integrates EOL status into your compliance posture.
Read the article →New guides, regulatory breakdowns, and assessment readiness updates, delivered when we publish. No noise.
1TEN is rolling out full support for NIST SP 800-171 Revision 3 with a target completion date of July 31, 2026. Learn what changes in Rev 3, how it affects your CMMC compliance posture, and what 1TEN is doing to make the transition seamless.
Read the guide →A complete guide to CUI scoping for CMMC Level 2. Learn the five asset categories, how to define and document your CUI boundary, common scoping mistakes that create findings, and how proper scoping reduces your assessment cost and complexity.
Read the guide →CMMC incident response requirements explained: what triggers the 72-hour DIBNet reporting clock, what constitutes a cyber incident under DFARS 7012, evidence preservation obligations, and how to build an IR program that satisfies assessors.
Read the article →Do subcontractors need CMMC certification? Who the flow-down obligation applies to, what primes must require, how to determine if your subcontract triggers CMMC, and what happens if you ignore it.
Read the guide →What Controlled Unclassified Information (CUI) is, how to identify it in your environment, what DFARS 7012 and NIST SP 800-171 require for protecting it, and how to build a compliant CUI handling program.
Read the guide →DFARS 252.204-7012 explained: what it requires, who it applies to, how it connects to CMMC, NIST SP 800-171, and SPRS scoring, and what happens if you are not compliant.
Read the guide →A complete guide to NIST SP 800-171 Rev 2: all 110 security requirements, the 14 domain structure, requirement numbering, and its relationship to CMMC Level 2 certification.
Read the guide →CMMC 2.0 explained for defense contractors: what it requires, who it applies to, the 3 certification levels, how it differs from NIST 800-171, the enforcement timeline, and what a C3PAO assessment involves.
Read the overview →A side-by-side breakdown of NIST SP 800-171 Rev 2 and Rev 3: requirement count changes, new controls, removed controls, and what the transition means for CMMC Level 2 contractors.
Read the guide →1TEN tracks your control implementation, calculates your live SPRS score, and organizes your evidence package. On-premises, air-gapped.
Request a Demo