Security & Compliance Intelligence

CMMC.
Intelligence.

Guides, regulatory breakdowns, and assessment readiness resources for defense contractors.

Last updated August 4, 2026

66 Guides & Articles
14 CMMC Domains Covered
110 Requirements Referenced
1%
of Defense Industrial Base contractors are fully prepared for a CMMC Level 2 assessment.
CyberSheath State of the DIB Report, 2025
What used to take our team three weeks to pull together for an assessment we now produce in an afternoon. The SSP and evidence matrix come out ready to hand to the C3PAO.
IT Director, Tier 2 Defense Manufacturer
$488K
estimated by the DoD for a small business to achieve and sustain CMMC Level 2 over three years.
DoD CMMC Regulatory Impact Analysis (32 CFR Part 170)
We had a consultant quoted at $180K to get us assessment-ready. 1TEN got us there for a fraction of that. The guided questions alone saved us months of back-and-forth.
VP of Operations, Aerospace Subcontractor
PLAN
2026-04-10 · 1 min read

SPRS Self-Assessment Scoring Tool: Calculate Your CMMC Score

Calculate your SPRS score across all 110 NIST SP 800-171 requirements. Mark each requirement met or not met, track your score live, and download a full results report.

Read the guide →
Nov 2026
Phase 2 begins. The DoD can start requiring a Level 2 third-party certification in new solicitations. The binding constraint is assessment capacity, not the date.
32 CFR Part 170 phased rollout
Our SPRS score went from -67 to +98 in four months. Having every requirement mapped to evidence in one place made the difference — our assessor commented on how organized the documentation was.
Program Manager, Defense Electronics Contractor
320
assessment objectives in NIST SP 800-171A support the 110 security requirements evaluated during a CMMC Level 2 assessment.
NIST SP 800-171A
PLAN
2026-03-04 · 6 min read

SPRS Score Explained: How DoD Scoring Works & How to Improve It

Your SPRS score ranges from −203 to 110 and is visible to DoD contracting officers. Learn how it

Read the guide →
3 Years
is the standard validity period of a successful CMMC Level 2 certification.
32 CFR Part 170
110
security requirements from NIST SP 800-171 Rev 2 form the foundation of every CMMC Level 2 assessment.
NIST SP 800-171 Rev. 2
14
security domains organize the 110 CMMC Level 2 requirements, from Access Control to System & Information Integrity.
NIST SP 800-171 Rev. 2

Air-gapped. On-premises.

1TEN is a GRC platform built for the security posture CMMC demands. No cloud. No subscriptions. No data leaving your environment.

Request a Demo