Who needs to comply?
All contractors are obligated to comply with the NIST Cybersecurity Framework (CSF). For government agencies such as the DoD (Department of Defense), GSA (General Services Administration), and NASA (National Aeronautics and Space Administration), new NIST rules took effect in 2017 that require anyone who works with CUI from those agencies to implement specific security measures for the handling of data.
Continue Reading
July 29, 2026
Five Takeaways from This Week’s CyberAB Town Hall
Over the past few weeks, much of the conversation surrounding CMMC has been driven by headlines following the Department [...]
July 14, 2026
CMMC Phase II Paused: What Defense Contractors Should Do Next
The Department of War recently announced that it is suspending the implementation of CMMC Phase II requirements while it [...]
