Guides & Resources

Plain-English guides to CMMC and NIST SP 800-171 for small defense contractors — and the latest regulatory updates worth knowing. All free.

New · Flagship reference

The Control Implementation Library

Every NIST 800-171 requirement in plain English — what it means, what an assessor actually looks for, where teams trip up, and the evidence you need. The implementation guide the standard doesn't give you.

All 110 controls · all 14 families · free, no signup
Open the Control Library →

Guides

Update · Jul 2026

The “Basic Assessment” Is Gone — So Why Do I Still Need an SPRS Score?

DFARS 252.240-7997 deleted the Basic Assessment tier — but the self-assessment and SPRS score moved into the CMMC clause and survived. The clause chain, in plain English.

Read the guide →
Update · Jul 2026

How to Respond to the CMMC Reform RFI

The Department of War opened a public RFI on CMMC reform — responses due noon ET Aug 14, 2026. What it is, why a small contractor’s voice matters, and exactly how to submit yours before the deadline.

Read the guide →
Update · Jul 2026

CMMC Phase 2 Suspended: What It Actually Means

The Department of War paused the Nov 10, 2026 third-party (C3PAO) certification rollout. What was suspended, what still applies — SPRS, self-assessment, annual affirmations — the affirmation trap, and the dates to watch.

Read the guide →
Start Here

FCI vs CUI — the Distinction That Sets Your Level

What FCI and CUI each are, why CUI requires far more, and how the difference decides whether you owe 15 basic practices (Level 1) or all 110 controls (Level 2).

Read the guide →
Level 1

CMMC Level 1 Self-Assessment (the 15 Practices)

If you handle FCI but not CUI, this is your whole job: the 15 FAR 52.204-21 safeguards, the six areas, the annual self-assessment — no C3PAO.

Read the guide →
Templates

NIST 800-171 SSP Template — or Skip the Blank Page

What a System Security Plan template really contains, why blank ones stall contractors, and how to generate a real SSP draft free — all 110 controls, no signup.

Read the guide →
Templates

CMMC POA&M Template & the 180-Day Clock

What a POA&M must contain, which controls are actually eligible, the 180-day close rule, and how to build an accurate one from your real gap list.

Read the guide →
Updated · Jul 2026

The CMMC Assessor Shortage & the Suspended Nov 10, 2026 Deadline

~103 C3PAOs and under 800 assessors for tens of thousands of contractors — the capacity crunch behind why Phase 2's third-party certification was paused in July 2026. The math, the wait times, and what it means now.

Read the guide →
After Certification

You Passed CMMC Level 2 — Now What?

Certification lasts three years and needs an annual affirmation. How to stay compliant: affirmations, monitoring, scope drift, and the enclave-vs-enterprise question.

Read the guide →
Updates

FIPS 140-2 → 140-3: The Sept 21, 2026 Sunset

All FIPS 140-2 module certificates move to NIST's Historical List on Sept 21, 2026. What it means for CUI encryption and NIST 800-171 control 3.13.11 — especially for new deployments.

Read the guide →
Foundations

What Is CUI? Markings & How to Handle It

Controlled Unclassified Information explained: where it comes from, CUI Basic vs Specified, common categories, how it's marked, and how contractors must protect it under CMMC.

Read the guide →
Comparison

CMMC vs ISO 27001

How they differ, where they overlap, why an ISO 27001 certificate doesn't satisfy CMMC (and the head start it gives), and whether you need one or both.

Read the guide →
Start Here

Do I Need CMMC? FCI vs CUI and Which Level

The one question that decides everything: what government data do you handle? FCI vs CUI, Level 1 vs Level 2, flow-down to subs, and how to confirm what you hold.

Read the guide →
Updated · Jul 2026

CMMC Phase 2: What It Was — and Why It's Suspended

Phase 2 would have started Level 2 C3PAO certification in CUI contracts on Nov 10, 2026 — but it was suspended in July 2026. What the phase was, and what still applies now.

Read the guide →
Reference

NIST 800-171 Rev 2 vs Rev 3: Which CMMC Uses

Short answer: for CMMC today you build to Revision 2, not Rev 3. Why Rev 2 still governs, what changed in Rev 3, and whether to prepare for it now.

Read the guide →
Assessment

What Is a C3PAO — and How to Find One

The certified organization that performs your CMMC Level 2 assessment: what they do, how they differ from self-assessment, how to find an authorized one, and how to get ready before you book.

Read the guide →
SPRS Scoring

What Is a Good SPRS Score?

Why 110 is the only fully compliant score, what the −203 to 110 range means, the 88-point conditional threshold and POA&M rules, and how to raise your score fastest.

Read the guide →
Regulatory Update

The 2026 FAR Overhaul & CMMC Clause Renumbering

Feb 1, 2026: DFARS 252.204-7020 became 252.240-7997, FAR 52.204-21 became 52.240-93, and 7019 was deleted. What changed, what didn't, and what to do.

Read the guide →
Regulatory Update

Does the FAR CUI Rule Change Your CMMC?

Short answer: no. The FAR CUI Rule is a proposed, government-wide rule — updated June 23, 2026, comments due July 23. What it regulates vs. what CMMC requires, the “Basic assessment eliminated” confusion, and why your homework didn't change.

Read the guide →
CMMC Timeline

CMMC Timeline & Deadlines (2026)

The four-phase rollout from November 2025 to 2028 — what each phase requires, when C3PAO certification kicks in, and what to do now.

Read the guide →
Assessment

CMMC Self-Assessment vs C3PAO

Who can self-assess vs who needs a certified third-party assessor, by level — and why the standard is the same either way.

Read the guide →
Reference

CMMC & NIST 800-171 Glossary

CUI, FCI, SPRS, SSP, POA&M, C3PAO, DIBCAC, enclave, GCC High — every term defined in plain English, with links.

Read the guide →
Funding

CMMC Grants & Funding: Every Real Program (2026)

FAR Part 31 cost recovery, free DoW programs, state grants up to $35K, vendor-sponsored assessments — every program verified, plus a 90-day funding plan.

Read the guide →
CMMC Cost

How Much Does CMMC Cost? (2026)

Level 1 vs Level 2, the C3PAO assessment fee, total readiness cost, the Department of War's own estimate, and how small contractors keep the bill down.

Read the guide →
SPRS Scoring

How to Calculate Your SPRS Score (2026)

The scoring math in plain English — point weights, the −203 to +110 range, the SSP gate, and the gaps that cost most contractors the most.

Read the guide →
System Security Plan

What Is an SSP — and How to Write One

The document that gates your CMMC assessment, explained: what it is, what goes in it, the POA&M, and how to produce one without a consultant.

Read the guide →
POA&M

What Is a POA&M — and How to Write One

Your plan to close compliance gaps: what goes in it, the CMMC Level 2 rules for what you can and can't defer, and how to build one free.

Read the guide →
CMMC Basics

NIST 800-171 vs CMMC: What Small Contractors Need to Know

How the two relate, the CMMC levels, self-assessment vs third-party (C3PAO), and exactly what your business has to do.

Read the guide →
Quick Wins

The 5-Point SPRS Controls to Fix First

Not all 110 requirements are worth the same. The 5-point controls move your score the fastest — here's which heavy ones to fix first, in plain English, with the practical fix for each.

Read the guide →
CMMC Level 2

CMMC Level 2 Self-Assessment: The Complete Guide

Self-assessment vs. third-party (C3PAO), and the step-by-step path through scoping, scoring, your SSP, POA&M rules, and the annual affirmation — in plain English.

Read the guide →
Scoping

CMMC Asset Scoping: What's In Scope (and What's Not)

The five asset categories, how an enclave shrinks your scope, what becomes Not Applicable, and the VDI / GCC High question — the highest-leverage decision in your CMMC effort.

Read the guide →
MFA · 3.5.3

Does a Microsoft PIN Count as MFA?

A plain PIN is single-factor; Windows Hello for Business qualifies. The difference that trips up small contractors — and the safe bar for the MFA control.

Read the guide →
Audit · 3.3

Audit Logging for CMMC: The 3.3 Family Made Simple

Along with access control, the most commonly failed area. What to log, retention, protecting logs, and actually reviewing them — the whole audit family in plain English.

Read the guide →
Affirmation · FCA

The CMMC Annual Affirmation — What You're Signing

Your assessment isn't the finish line. Every year a senior official affirms continued compliance in SPRS — and a stale score now carries real False Claims Act risk.

Read the guide →
Incident Response · 3.6

Incident Response — and the 72-Hour Rule

The 3.6 family in plain English, plus the DFARS 72-hour Department of War reporting clock most small contractors don't know is ticking — and a workable IR plan.

Read the guide →

More guides on the way — media protection, configuration management, and a growing per-control library.

Stop reading, start scoring

Both tools are free and run in your browser.

SPRS Calculator → SSP Generator → POA&M Generator →