Plain-English answers to the questions every small DoD sub is asking right now.
Rebuilt and relaunched September 9: one dashboard for Level 1, Level 2 and SPRS, read-only Microsoft 365 and Google Workspace evidence, interview prep from your answers, a Readiness Report, and client workspaces for consultants. The assessment stays free.
The Reform Task Force delivers its recommendations in mid-September. The three plausible outcomes, what primes are doing meanwhile, and the five moves that win under all of them.
Phase 2 is paused, but your self-assessment is still being reviewed — by primes, DIBCAC, and DOJ. The six-step checklist reviewers actually use, so you can run it on yourself first.
One is you telling the government where you stand; the other is the government checking. Same 110 controls, different rules — including the POA&M trap that lets a 98 pass SPRS and still fall short of CMMC.
There is no certificate and no assessor. Level 1 is 15 safeguards answered honestly, a record in SPRS, and an annual affirmation — days of work, not months. The whole path, and the four mistakes to skip.
Someone has already pasted contract data into a chatbot. No install, no purchase, no ticket — and NIST 800-171 already covers it. How to inventory it, write the rule, and handle a spill.
The crosswalk everyone searches for doesn’t need to exist: CMMC Level 2 IS the 110 controls, verbatim. What actually differs — and how to decode CMMC control IDs.
Why the submission is required, how SPRS differs from CMMC, whether Level 1 or 2 applies to you, what must be true before you log in, and the exact portal steps — PIEE quirks included.
The standard behind every DoD cybersecurity requirement: what it protects, who must comply, the 14 families, how it’s scored, and where CMMC and SPRS fit.
Every Rev 2 control in one plain-English sentence, organized by family, with its SPRS point value. The reference page to bookmark.
The certification ceremony is on hold; the homework isn't. What the suspension actually paused, the DFARS stack still in force, and the five steps from here to a posted, defensible score.
SPRS wants one number — but the number is only defensible with an SSP, assessment record, POA&M, and evidence behind it. The complete stack, in build order.
The columns a defensible POA&M needs, filled example rows, and the two rulebooks people mix up — including which controls can never sit on a POA&M and the 180-day clock.
You can get to a legitimate SPRS score without spending a dollar. Every genuinely free path — official guides, community workbooks, free software — and where each one runs out.
One question decides everything: what government information do you hold? FCI means 15 basic safeguards. CUI means all 110 NIST controls and a scored SPRS submission. Here's how to tell.
Rev 3 exists; Rev 2 governs. Why DoD formally kept Revision 2 for DFARS and SPRS, what Rev 3 changed, and the only sensible strategy right now.
The anatomy of a defensible System Security Plan — with example implementation statements, good and bad, and the honesty rule for gaps.
The Department of War paused third-party certification on July 13 pending a 60-day review. Here's exactly what changed, what didn't, and why your SPRS score matters more now — not less.
The certification ceremony is paused; the contract clauses aren't. The full stack — NIST 800-171, DFARS 7012/7019/7020, and SPRS — explained plainly, with the path from zero to a posted score.
From confirming the clause applies through posting your score and keeping it defensible — twelve steps in the order that saves the most time and money.
Scoping quietly decides how hard your whole CMMC effort will be. Here are the 5 asset categories every device falls into — and how a CUI enclave keeps most of your company out of scope.
Yes — Level 2 requires multi-factor authentication for anyone accessing CUI. Here's exactly where it applies, what counts as MFA, and why this 5-point control can't wait for a POA&M.
A C3PAO is the certified organization that runs your official Level 2 assessment — but not every contractor needs one. Here's what it does, when it's required, and what it costs.
Not every CMMC requirement means hiring an assessor. Here's when you can self-assess, the step-by-step process for all 110 controls, and how to score and affirm it in SPRS.
What CMMC compliance software actually does, how it differs from enterprise GRC tools, and how small contractors should choose the right one before committing.
Your prime is asking about your CMMC status. Here's the rule that determines whether you actually need it, what level applies, and what happens if you can't comply.
Passing your assessment isn't the finish line. Every CMMC status requires a senior executive to re-attest in SPRS every year — here's the cadence, who signs it, and what a missed deadline costs you.
"FIPS-compliant" isn't the same as FIPS-validated — and only one of them satisfies CMMC. Here's what's actually required, where it applies, and a September 2026 deadline to know about.
If your managed service provider touches your CUI environment, they're inside your assessment boundary. Here's what that means, the three MSP scenarios, and what to do before your C3PAO shows up.
Three AT controls, no certified vendor needed. Here's exactly what CMMC Level 2 demands for security training — and what assessors look for in your records.
14 required policies, one per control family. Here's what each one must contain, what assessors look for, and why generic boilerplate will get you flagged.
Your score starts at 110 and drops for every unmet control. Here's the exact formula, which controls hurt the most, and how to improve your score before your assessment.
Commercial M365 can't hold CUI — DFARS 7012 has required a FedRAMP-authorized cloud since 2017. Here's how GCC, GCC High, and overlay solutions compare for small DoD subs.
Most CMMC tools are built for enterprises with security teams. Here's how to evaluate your options as a small contractor — and what actually matters vs. what's just impressive demos.
The real numbers on gap assessment, technology remediation, documentation, and the C3PAO audit — and where DIY vs. consultant makes the biggest difference.
All 14 control families, 110 controls — explained in plain English without the regulation-speak. What each family actually requires and where small contractors typically struggle.
Your SPRS score isn't a future CMMC requirement — it's required right now under DFARS 7019/7020. Here's how it's calculated, what a bad score costs you, and how to improve it.
The plain-English starting guide for small defense contractors facing CMMC for the first time — a 6-step roadmap without the enterprise consultancy pitch.
A POA&M lets you pass Level 2 with some controls unmet — but only under strict rules. Here's what's allowed on it, the 88/110 threshold, and the 180-day clock.
The SSP is the master document of your whole CMMC effort — the one an assessor reads first. Here's what it is, who needs one, and what goes in it.
Updated: Phase 2 and the November 10 milestone were suspended on July 13, 2026. What was paused, what is still required, and why your SPRS score now carries more weight, not less.
A spreadsheet can track controls. It can't generate your SSP, prove your evidence is adequate, or tell you where your gaps are. Here's what auditors actually look at.
The difference between CUI and FCI determines your CMMC level — and most small subs don't know which one they have. Here's how to figure it out before your prime asks.