top of page

Blog Posts


CMMC Certification: In-House vs. Partnering with an External Provider
In-House vs. Partnering with an External Provider Achieving a CMMC Level 2 certification requires organizations to demonstrate that they meet the security requirements outlined in NIST SP 800-171. While implementing those required controls and safeguards often represents a significant investment in IT, cybersecurity, and organizational processes, every organization pursuing certification faces the same fundamental question: Should you manage the implementation internally, or
clairekelley0
Aug 122 min read


CMMC Pause Explained: What Defense Contractors Should Know
We have used the past week and a half to sit back and watch the CMMC storm online. We have seen the champagne popping contingent that is sure that CMMC is dead, and the CMMC die-hards that don't expect any significant changes exchanging barbs on LinkedIn and other online venues. We expect the truth to be somewhere in the middle, and we want to share our thoughts on what this pause could mean. First, let's clear up some of the facts of the current situation. While the curren
clairekelley0
Jul 244 min read


What the 2027 National Defense Authorization Act say about CMMC for Defense Contractors
The National Defense Authorization Act (NDAA) for Fiscal Year 2027 Title XVI, which is working its way through Congress, focuses on cybersecurity requirements and introduces a major shift in how the Department of War (DoW) supports the companies that make up our Defense Industrial Base (DIB). It's great to see Congress addressing the needs of the DIB as CMMC has begun appearing in contracts. For years, the DIB has been moving toward a standardized, verifiable security model t
clairekelley0
Jun 252 min read
bottom of page