Plain-English guides to CMMC and NIST SP 800-171 for small defense contractors — and the latest regulatory updates worth knowing. All free.
DFARS 252.240-7997 deleted the Basic Assessment tier — but the self-assessment and SPRS score moved into the CMMC clause and survived. The clause chain, in plain English.
Read the guide → Update · Jul 2026The Department of War opened a public RFI on CMMC reform — responses due noon ET Aug 14, 2026. What it is, why a small contractor’s voice matters, and exactly how to submit yours before the deadline.
Read the guide → Update · Jul 2026The Department of War paused the Nov 10, 2026 third-party (C3PAO) certification rollout. What was suspended, what still applies — SPRS, self-assessment, annual affirmations — the affirmation trap, and the dates to watch.
Read the guide → Start HereWhat FCI and CUI each are, why CUI requires far more, and how the difference decides whether you owe 15 basic practices (Level 1) or all 110 controls (Level 2).
Read the guide → Level 1If you handle FCI but not CUI, this is your whole job: the 15 FAR 52.204-21 safeguards, the six areas, the annual self-assessment — no C3PAO.
Read the guide → TemplatesWhat a System Security Plan template really contains, why blank ones stall contractors, and how to generate a real SSP draft free — all 110 controls, no signup.
Read the guide → TemplatesWhat a POA&M must contain, which controls are actually eligible, the 180-day close rule, and how to build an accurate one from your real gap list.
Read the guide → Updated · Jul 2026~103 C3PAOs and under 800 assessors for tens of thousands of contractors — the capacity crunch behind why Phase 2's third-party certification was paused in July 2026. The math, the wait times, and what it means now.
Read the guide → After CertificationCertification lasts three years and needs an annual affirmation. How to stay compliant: affirmations, monitoring, scope drift, and the enclave-vs-enterprise question.
Read the guide → UpdatesAll FIPS 140-2 module certificates move to NIST's Historical List on Sept 21, 2026. What it means for CUI encryption and NIST 800-171 control 3.13.11 — especially for new deployments.
Read the guide → FoundationsControlled Unclassified Information explained: where it comes from, CUI Basic vs Specified, common categories, how it's marked, and how contractors must protect it under CMMC.
Read the guide → ComparisonHow they differ, where they overlap, why an ISO 27001 certificate doesn't satisfy CMMC (and the head start it gives), and whether you need one or both.
Read the guide → Start HereThe one question that decides everything: what government data do you handle? FCI vs CUI, Level 1 vs Level 2, flow-down to subs, and how to confirm what you hold.
Read the guide → Updated · Jul 2026Phase 2 would have started Level 2 C3PAO certification in CUI contracts on Nov 10, 2026 — but it was suspended in July 2026. What the phase was, and what still applies now.
Read the guide → ReferenceShort answer: for CMMC today you build to Revision 2, not Rev 3. Why Rev 2 still governs, what changed in Rev 3, and whether to prepare for it now.
Read the guide → AssessmentThe certified organization that performs your CMMC Level 2 assessment: what they do, how they differ from self-assessment, how to find an authorized one, and how to get ready before you book.
Read the guide → SPRS ScoringWhy 110 is the only fully compliant score, what the −203 to 110 range means, the 88-point conditional threshold and POA&M rules, and how to raise your score fastest.
Read the guide → Regulatory UpdateFeb 1, 2026: DFARS 252.204-7020 became 252.240-7997, FAR 52.204-21 became 52.240-93, and 7019 was deleted. What changed, what didn't, and what to do.
Read the guide → Regulatory UpdateShort answer: no. The FAR CUI Rule is a proposed, government-wide rule — updated June 23, 2026, comments due July 23. What it regulates vs. what CMMC requires, the “Basic assessment eliminated” confusion, and why your homework didn't change.
Read the guide → CMMC TimelineThe four-phase rollout from November 2025 to 2028 — what each phase requires, when C3PAO certification kicks in, and what to do now.
Read the guide → AssessmentWho can self-assess vs who needs a certified third-party assessor, by level — and why the standard is the same either way.
Read the guide → ReferenceCUI, FCI, SPRS, SSP, POA&M, C3PAO, DIBCAC, enclave, GCC High — every term defined in plain English, with links.
Read the guide → FundingFAR Part 31 cost recovery, free DoW programs, state grants up to $35K, vendor-sponsored assessments — every program verified, plus a 90-day funding plan.
Read the guide → CMMC CostLevel 1 vs Level 2, the C3PAO assessment fee, total readiness cost, the Department of War's own estimate, and how small contractors keep the bill down.
Read the guide → SPRS ScoringThe scoring math in plain English — point weights, the −203 to +110 range, the SSP gate, and the gaps that cost most contractors the most.
Read the guide → System Security PlanThe document that gates your CMMC assessment, explained: what it is, what goes in it, the POA&M, and how to produce one without a consultant.
Read the guide → POA&MYour plan to close compliance gaps: what goes in it, the CMMC Level 2 rules for what you can and can't defer, and how to build one free.
Read the guide → CMMC BasicsHow the two relate, the CMMC levels, self-assessment vs third-party (C3PAO), and exactly what your business has to do.
Read the guide → Quick WinsNot all 110 requirements are worth the same. The 5-point controls move your score the fastest — here's which heavy ones to fix first, in plain English, with the practical fix for each.
Read the guide → CMMC Level 2Self-assessment vs. third-party (C3PAO), and the step-by-step path through scoping, scoring, your SSP, POA&M rules, and the annual affirmation — in plain English.
Read the guide → ScopingThe five asset categories, how an enclave shrinks your scope, what becomes Not Applicable, and the VDI / GCC High question — the highest-leverage decision in your CMMC effort.
Read the guide → MFA · 3.5.3A plain PIN is single-factor; Windows Hello for Business qualifies. The difference that trips up small contractors — and the safe bar for the MFA control.
Read the guide → Audit · 3.3Along with access control, the most commonly failed area. What to log, retention, protecting logs, and actually reviewing them — the whole audit family in plain English.
Read the guide → Affirmation · FCAYour assessment isn't the finish line. Every year a senior official affirms continued compliance in SPRS — and a stale score now carries real False Claims Act risk.
Read the guide → Incident Response · 3.6The 3.6 family in plain English, plus the DFARS 72-hour Department of War reporting clock most small contractors don't know is ticking — and a workable IR plan.
Read the guide →More guides on the way — media protection, configuration management, and a growing per-control library.