CMMC vs NIST SP-800.171: Understand the Difference Between Them

The U.S. Department of Defense (DoD) is facing increasingly complex cybersecurity threats that threaten not only the defense industrial base (DIB) but also the security of the entire nation, as well as its allies and partners. To enhance its cybersecurity posture, the DoD migrated away from NIST 800.171 to a new set of cybersecurity standards. […]
NIST SP 800-171r3 Initial Public Draft

We have some big news about protecting Controlled Unclassified Information (CUI) in nonfederal systems and organizations. The much anticipated initial draft of the National Institute of Standards and Technology (NIST) Special Publication 800-171 Revision 3 was released on May 10, 2023. In this article, we will discuss the changes that have been implemented, important dates to remember, […]
CMMC Rulemaking Timeline in 2023

On November 2021, the Department of Defense (DoD) announced its intent to revise the CMMC program. The DoD predicted the rulemaking process could take up to 24 months to complete the rule package (which needs to be sent to the Office of Management and Budget (OMB) for evaluation). But it has been delayed more than […]
How to Implement CMMC Level 2

The Department of Defense (DoD) continues to refine the CMMC 2.0 model, with particular focus on requirements for CMMC Level 2 contractors, as part of its rulemaking process. This delay in CMMC implementation offers a valuable opportunity for contractors and subcontractors working diligently toward compliance. Achieving early compliance can give your company a competitive edge, […]
What is CMMC Compliance? Experts Answer Your Questions

The Department of Defense (DoD) announced in November 2021, that they were going to revamp the Cybersecurity Maturity Model Certification (CMMC) that government contractors need to abide by. The new model will include an updated program structure and requirements. So, why is CMMC compliance important, and what does this update mean for your organization? https://youtu.be/zuXLkiXRjKY?si=O0j1FaiXyJRqvjyi Table of […]
When Will CMMC 2.0 Be Required for DoD Contracts?

When Will CMMC 2.0 be Required for DoD Contracts? Update The Department of Defense has taken its final step toward making CMMC a binding requirement in defense contracts. On September 10, 2025, the 48 CFR final rule entered public inspection in the Federal Register. This rule takes effect on November 10, 2025, officially authorizing contracting […]
Why DFARS 7012 Compliance is Important in 2023

Before the DFARS interim rule was released, government contractors were required to adhere to DFARS 252.204-7012. The interim rule aims to provide adequate security for Covered Defense Information by implementing NIST SP 800-171 and achieving compliance with each of its 110 security controls. In this article, you’ll gain a clear understanding of the interim rule requirements, who […]