Updated 12 Aug 2026 CMMC Phase 2 was suspended on July 13. Your SPRS self-assessment was not. What this means →

CMMC & NIST 800-171 Guides for Small Defense Contractors

Plain-English answers to the questions every small DoD sub is asking right now.

🚀

The New CMMC Map Is Live. Here Is What Changed and Why.

Rebuilt and relaunched September 9: one dashboard for Level 1, Level 2 and SPRS, read-only Microsoft 365 and Google Workspace evidence, interview prep from your answers, a Readiness Report, and client workspaces for consultants. The assessment stays free.

🗓️

The CMMC Task Force Reports in September. Be Ready for Every Outcome.

The Reform Task Force delivers its recommendations in mid-September. The three plausible outcomes, what primes are doing meanwhile, and the five moves that win under all of them.

🔎

What a Prime (or an Assessor) Actually Checks in Your Self-Assessment

Phase 2 is paused, but your self-assessment is still being reviewed — by primes, DIBCAC, and DOJ. The six-step checklist reviewers actually use, so you can run it on yourself first.

⚖️

SPRS Score vs CMMC Level 2: What’s the Difference?

One is you telling the government where you stand; the other is the government checking. Same 110 controls, different rules — including the POA&M trap that lets a 98 pass SPRS and still fall short of CMMC.

How to Get CMMC Level 1: The Small Contractor’s Walkthrough

There is no certificate and no assessor. Level 1 is 15 safeguards answered honestly, a record in SPRS, and an annual affirmation — days of work, not months. The whole path, and the four mistakes to skip.

👤

Shadow AI and CUI: The Gap Nobody Approved

Someone has already pasted contract data into a chatbot. No install, no purchase, no ticket — and NIST 800-171 already covers it. How to inventory it, write the rule, and handle a spill.

🧩

NIST 800-171 to CMMC Mapping, Explained

The crosswalk everyone searches for doesn’t need to exist: CMMC Level 2 IS the 110 controls, verbatim. What actually differs — and how to decode CMMC control IDs.

🗂️

How to Submit Your SPRS Score: The Complete Guide

Why the submission is required, how SPRS differs from CMMC, whether Level 1 or 2 applies to you, what must be true before you log in, and the exact portal steps — PIEE quirks included.

📖

What Is NIST SP 800-171? The Plain-English Guide

The standard behind every DoD cybersecurity requirement: what it protects, who must comply, the 14 families, how it’s scored, and where CMMC and SPRS fit.

📚

All 110 NIST 800-171 Controls, Explained in Plain English

Every Rev 2 control in one plain-English sentence, organized by family, with its SPRS point value. The reference page to bookmark.

📋

CMMC Is Paused. Your SPRS Score Is Still Due.

The certification ceremony is on hold; the homework isn't. What the suspension actually paused, the DFARS stack still in force, and the five steps from here to a posted, defensible score.

📄

The SPRS Self-Assessment Walkthrough: The Score, and the Documentation Behind It

SPRS wants one number — but the number is only defensible with an SSP, assessment record, POA&M, and evidence behind it. The complete stack, in build order.

📋

CMMC POA&M Template: Columns, Example Rows, and the Rules

The columns a defensible POA&M needs, filled example rows, and the two rulebooks people mix up — including which controls can never sit on a POA&M and the 180-day clock.

🧰

Free SPRS Self-Assessment Tools and Resources, Compared

You can get to a legitimate SPRS score without spending a dollar. Every genuinely free path — official guides, community workbooks, free software — and where each one runs out.

🧭

CMMC Level 1 vs Level 2: FCI, CUI, and Which One Applies to You

One question decides everything: what government information do you hold? FCI means 15 basic safeguards. CUI means all 110 NIST controls and a scored SPRS submission. Here's how to tell.

⚖️

NIST 800-171 Rev 2 vs Rev 3: Which Applies in 2026?

Rev 3 exists; Rev 2 governs. Why DoD formally kept Revision 2 for DFARS and SPRS, what Rev 3 changed, and the only sensible strategy right now.

📝

CMMC SSP Template: What Goes in Each Section, With Examples

The anatomy of a defensible System Security Plan — with example implementation statements, good and bad, and the honesty rule for gaps.

🏛️

CMMC Phase 2 Is Suspended. Your Cybersecurity Obligations Are Not.

The Department of War paused third-party certification on July 13 pending a 60-day review. Here's exactly what changed, what didn't, and why your SPRS score matters more now — not less.

📊

NIST 800-171 and SPRS: The Obligations That Never Went Away

The certification ceremony is paused; the contract clauses aren't. The full stack — NIST 800-171, DFARS 7012/7019/7020, and SPRS — explained plainly, with the path from zero to a posted score.

NIST 800-171 Compliance Checklist: 12 Steps

From confirming the clause applies through posting your score and keeping it defensible — twelve steps in the order that saves the most time and money.

🎯

CMMC Scoping Explained: The 5 Asset Categories and How to Shrink Your Scope

Scoping quietly decides how hard your whole CMMC effort will be. Here are the 5 asset categories every device falls into — and how a CUI enclave keeps most of your company out of scope.

🔑

Does CMMC Require MFA? What Small Contractors Must Do

Yes — Level 2 requires multi-factor authentication for anyone accessing CUI. Here's exactly where it applies, what counts as MFA, and why this 5-point control can't wait for a POA&M.

🏛️

What Is a C3PAO? CMMC Assessors Explained for Small Contractors

A C3PAO is the certified organization that runs your official Level 2 assessment — but not every contractor needs one. Here's what it does, when it's required, and what it costs.

CMMC Self-Assessment Guide: How to Do It Right in 2026

Not every CMMC requirement means hiring an assessor. Here's when you can self-assess, the step-by-step process for all 110 controls, and how to score and affirm it in SPRS.

💻

CMMC Compliance Software: What It Does and What You Actually Need

What CMMC compliance software actually does, how it differs from enterprise GRC tools, and how small contractors should choose the right one before committing.

🔗

CMMC Subcontractor Requirements: Does Your Sub Actually Need CMMC?

Your prime is asking about your CMMC status. Here's the rule that determines whether you actually need it, what level applies, and what happens if you can't comply.

✍️

What Is the CMMC Annual Affirmation Requirement?

Passing your assessment isn't the finish line. Every CMMC status requires a senior executive to re-attest in SPRS every year — here's the cadence, who signs it, and what a missed deadline costs you.

🔐

Does CMMC Require FIPS-Validated Encryption?

"FIPS-compliant" isn't the same as FIPS-validated — and only one of them satisfies CMMC. Here's what's actually required, where it applies, and a September 2026 deadline to know about.

🤝

Does My MSP Need to Be CMMC Compliant? (What the Rules Actually Say)

If your managed service provider touches your CUI environment, they're inside your assessment boundary. Here's what that means, the three MSP scenarios, and what to do before your C3PAO shows up.

🎓

CMMC Security Awareness Training: What AT.L2 Actually Requires

Three AT controls, no certified vendor needed. Here's exactly what CMMC Level 2 demands for security training — and what assessors look for in your records.

📑

CMMC Policy Templates: What Goes in All 14 — and What Assessors Actually Check

14 required policies, one per control family. Here's what each one must contain, what assessors look for, and why generic boilerplate will get you flagged.

🧮

How to Calculate Your SPRS Score — Step by Step

Your score starts at 110 and drops for every unmet control. Here's the exact formula, which controls hurt the most, and how to improve your score before your assessment.

☁️

Do You Need GCC High for CMMC? Microsoft 365 Options for Small Contractors

Commercial M365 can't hold CUI — DFARS 7012 has required a FedRAMP-authorized cloud since 2017. Here's how GCC, GCC High, and overlay solutions compare for small DoD subs.

🏆

Best CMMC Compliance Software for Small Defense Contractors (2026)

Most CMMC tools are built for enterprises with security teams. Here's how to evaluate your options as a small contractor — and what actually matters vs. what's just impressive demos.

💰

How Much Does CMMC Certification Cost in 2026? (Realistic Budget Guide)

The real numbers on gap assessment, technology remediation, documentation, and the C3PAO audit — and where DIY vs. consultant makes the biggest difference.

📋

CMMC Level 2 Requirements: Plain-English Breakdown for Small Contractors

All 14 control families, 110 controls — explained in plain English without the regulation-speak. What each family actually requires and where small contractors typically struggle.

📈

What Is an SPRS Score — and Why It Matters Now

Your SPRS score isn't a future CMMC requirement — it's required right now under DFARS 7019/7020. Here's how it's calculated, what a bad score costs you, and how to improve it.

🚀

CMMC for Small Business: Where to Start in 2026

The plain-English starting guide for small defense contractors facing CMMC for the first time — a 6-step roadmap without the enterprise consultancy pitch.

🗂️

CMMC POA&M Explained: What It Is and How to Write One

A POA&M lets you pass Level 2 with some controls unmet — but only under strict rules. Here's what's allowed on it, the 88/110 threshold, and the 180-day clock.

📄

What Is an SSP (System Security Plan) for CMMC — and Do You Need One?

The SSP is the master document of your whole CMMC effort — the one an assessor reads first. Here's what it is, who needs one, and what goes in it.

The November 2026 CMMC Deadline Was Suspended — What Applies Now

Updated: Phase 2 and the November 10 milestone were suspended on July 13, 2026. What was paused, what is still required, and why your SPRS score now carries more weight, not less.

📊

Why Your CMMC Spreadsheet Will Fail You (And What To Do Instead)

A spreadsheet can track controls. It can't generate your SSP, prove your evidence is adequate, or tell you where your gaps are. Here's what auditors actually look at.

🔒

Do You Actually Handle CUI? Most Small Defense Contractors Get This Wrong

The difference between CUI and FCI determines your CMMC level — and most small subs don't know which one they have. Here's how to figure it out before your prime asks.

Your SPRS score is the number that matters now.

Free to assess · No credit card · Documents from $49/mo