NIST 800-171

Five Takeaways from This Week’s CyberAB Town Hall

Over the past few weeks, much of the conversation surrounding CMMC has been driven by headlines following the Department of War’s decision to suspend Phase II implementation while the program is reviewed. Predictably, social media has been filled with speculation ranging from “CMMC is dead” to “everything has changed.” This week’s CyberAB Town Hall painted[…]

How Long Does CMMC Level 2 Actually Take?

Ask five consultants how long CMMC Level 2 certification takes and you’ll get five versions of “it depends.” That’s not wrong, but it’s not useful either. The truth is that timelines follow predictable patterns based on where an organization starts. This article lays out realistic timeframes for mid-size defense contractors (50-250 employees) pursuing Level 2[…]

What to Expect When Engaging a C3PAO: Inside the CMMC Level 2 Assessment Process

For many organizations in the Defense Industrial Base (DIB), achieving Cybersecurity Maturity Model Certification (CMMC) Level 2 is no longer optional — it’s essential for winning and maintaining Department of Defense (DoD) contracts involving Controlled Unclassified Information (CUI). Yet for executives and business owners, the path to certification often feels uncertain. What actually happens during[…]

NIST Finalizes Updated Guidelines for Protecting Sensitive Information

Current regulatory mandates require DIB (defense industrial base) companies with DOD (Department of Defense) CUI (controlled unclassified information) to implement NIST 800-171 security requirements. Timeline estimates based on ongoing federal rule making may add additional requirements to include the potential for CMMC assessments and/or certifications this year. All DIB companies who manage controlled unclassified Information[…]