top of page
Blog Posts


CMMC Compliance Imperatives from the CMMC Northeast Summit
The CMMC Northeast Summit, hosted at Rhode Island College’s Institute for Cybersecurity and Emerging Technologies with AXIOTROP, their partner sponsor. This event was specifically designed to support Organizations Seeking Assessment (OSAs) by bridging the gap between dense Department of War (DoW) policy and the boots-on-the-ground CMMC execution. Joe Devine, President of AXIOTROP, & Senator Jim Langevin, Former United States Representative, giving opening remarks. Photo by
clairekelley0
Mar 184 min read


The CMMC Readiness Reality
The debate over whether the Cybersecurity Maturity Model Certification (CMMC) will show up in defense contracts is officially over. With the Title 48 final rule published and taking effect November 10, 2025, it requires your immediate attention. If you wait until you see CMMC requirements in solicitations, you have waited too long. Organizations must now align their CMMC preparation with the reality of the implementation phases and their appropriate level. The CMMC Level 2
clairekelley0
Oct 22, 20252 min read


What is the POA&M Process for Final CMMC Certification?
If an Organization Seeking Certification (OSC) has met most, but not all, security requirements, it may be eligible for a Conditional Certificate of CMMC Status. This is possible if the unmet requirements are documented on an existing and valid POA&M that complies with the regulations in 32 CFR §170.21. However, if an OSC has unmet security requirements and a valid POA&M is not attainable, the C3PAO will recommend that no certificate be issued. The details of how POA&Ms work
clairekelley0
Sep 17, 20253 min read
bottom of page
