top of page
Blog Posts


What the 2027 National Defense Authorization Act say about CMMC for Defense Contractors
The National Defense Authorization Act (NDAA) for Fiscal Year 2027 Title XVI, which is working its way through Congress, focuses on cybersecurity requirements and introduces a major shift in how the Department of War (DoW) supports the companies that make up our Defense Industrial Base (DIB). It's great to see Congress addressing the needs of the DIB as CMMC has begun appearing in contracts. For years, the DIB has been moving toward a standardized, verifiable security model t
clairekelley0
Jun 252 min read


What Vendor Agnostic Means for CMMC Advising and Assessment
Being vendor agnostic allows a C3PAO (Certified Third-Party Assessment Organization) or RPO (Registered Provider Organization) to prioritize regulatory integrity and the specific needs of the contractor over the sales of particular products. As an advisor, a vendor’s agnostic approach means that your RPO will select the technology solutions for each project through a vendor-agnostic analysis. Vendor agnosticism allows for immense flexibility. The choice of Microsoft GCC High
clairekelley0
Jun 162 min read


The Jump to Level 2 & Transitioning from 15 to 110 Controls
Transitioning from CMMC Level 1 to Level 2 is a monumental shift that requires moving from 15 basic safeguarding requirements to 110 rigorous security controls. While Level 1 focuses on protecting Federal Contract Information (FCI), Level 2 is specifically designed to safeguard Controlled Unclassified Information (CUI), which requires a much higher level of protection. Level 2 is cumulative, meaning you cannot achieve certification without also demonstrating mastery of all
clairekelley0
Jun 92 min read
bottom of page
