top of page
Blog Posts


What Vendor Agnostic Means for CMMC Advising and Assessment
Being vendor agnostic allows a C3PAO (Certified Third-Party Assessment Organization) or RPO (Registered Provider Organization) to prioritize regulatory integrity and the specific needs of the contractor over the sales of particular products. As an advisor, a vendor’s agnostic approach means that your RPO will select the technology solutions for each project through a vendor-agnostic analysis. Vendor agnosticism allows for immense flexibility. The choice of Microsoft GCC High
clairekelley0
Jun 162 min read


The Jump to Level 2 & Transitioning from 15 to 110 Controls
Transitioning from CMMC Level 1 to Level 2 is a monumental shift that requires moving from 15 basic safeguarding requirements to 110 rigorous security controls. While Level 1 focuses on protecting Federal Contract Information (FCI), Level 2 is specifically designed to safeguard Controlled Unclassified Information (CUI), which requires a much higher level of protection. Level 2 is cumulative, meaning you cannot achieve certification without also demonstrating mastery of all
clairekelley0
Jun 92 min read


Why Waiting to Book Your C3PAO Assessment is a High-Stakes Gamble
Data from the Cyber AB town halls reveals a massive acceleration in the certification ecosystem as contractors race to solidify their standing before the November 10th deadline this year. A new report from ISI found that just 18% of defense contractors demonstrated readiness across all foundational CMMC areas. As more organizations achieve Level 2 (L2) status, companies that secured early certification will continue to be eligible for Department of War (DoW) contracts and s
clairekelley0
May 122 min read
bottom of page
