Blog

POA&Ms and OPAs: What Are They & When Are They Used? 

If you’ve spent any time preparing for NIST 800-171 or DFARS 70-12 compliance, you’ve probably come across the terms POA&M and OPA. While they may sound similar, they serve very different purposes during the certification or self-attestation process. Knowing when each one applies—and just as importantly, when it doesn’t—can help organizations avoid unnecessary delays, misunderstandings, […]

Blog
Suspension of CMMC Phase II and What It Means for You

Suspension of CMMC Phase II and What It Means for You

On July 13th, 2026, at 3:30PM EST, the Department of War (DoW) released a memorandum for senior Pentagon leadership with a subject of “Implementing Department of War Chief Information Officer’s Suspension of the Advancement to Cybersecurity Maturity Model Certification Phase 2 Requirements” and “Removing Barriers to Defense Industrial Base Expansion: Immediate Suspension and Strategic Review […]

Blog White Papers

CMMC Recertification: What Qualifies as a “Significant Change” Requiring a Second C3PAO Assessment

Earning CMMC certification takes a significant investment of time, resources, and effort. Once an organization clears its C3PAO Assessment, there’s a natural sense of relief — even accomplishment. That CMMC Status can last up to three years, but two events bring recertification back onto the calendar sooner: reaching the end of the standard three-year cycle, […]

Blog

A Guide to External Service Providers (ESP) and CMMC Certifications 

In the Defense Industrial Base (DIB), External Service Providers (ESPs) are becoming increasingly common. ESPs, also commonly referred to as Managed Service Providers (MSPs), Managed Security Service Providers (MSSPs), or Cloud Service Providers (CSPs), have become especially beneficial for small and medium-sized businesses where hiring a full-time compliance employee may not be practical.  ESP services can range from full system management and support to […]

Blog
FIPS Encryption Requirements in CMMC and NIST SP 800-171

FIPS Encryption Requirements in CMMC and NIST SP 800-171 

When handling Controlled Unclassified Information (CUI), compliance with NIST SP 800-171 and the CMMC framework mandates strict data protection measures—including the use of FIPS-validated encryption in specific scenarios. But one requirement that consistently generates questions is exactly what “FIPS-validated” means in practice, where it applies, and how it differs from the looser “FIPS-compliant” language that […]

Blog

Where Can You Store CUI and FCI?

Proper storage of Controlled Unclassified Information (CUI) and Federal Contract Information (FCI) is at the core of a healthy and satisfactory compliance program. The issue? There seems to be ample confusion on what CUI and FCI are, the difference between the two, and where they officially can be stored.   Improper storage of both CUI […]