112Cyber Resource Center
Guidance from Certified CMMC Assessors
POA&Ms and OPAs: What Are They & When Are They Used?
If you’ve spent any time preparing for NIST 800-171 or DFARS 70-12 compliance, you’ve probably come across the terms POA&M and OPA. While they may
Suspension of CMMC Phase II and What It Means for You
On July 13th, 2026, at 3:30PM EST, the Department of War (DoW) released a memorandum for senior Pentagon leadership with a subject of “Implementing Department
CMMC Recertification: What Qualifies as a “Significant Change” Requiring a Second C3PAO Assessment
Earning CMMC certification takes a significant investment of time, resources, and effort. Once an organization clears its C3PAO Assessment, there’s a natural sense of relief
How to Pass the Most Failed CMMC Controls
If your organization handles Controlled Unclassified Information (CUI) and is working toward CMMC Level 2 certification, understanding where organizations most commonly fail is half the
C3PAO Interview Checklist: 10 Evaluation Criteria
Not all C3PAOs are created equal. Before you sign an engagement, these are the questions that separate credible assessors from expensive mistakes — organized by
A Guide to External Service Providers (ESP) and CMMC Certifications
In the Defense Industrial Base (DIB), External Service Providers (ESPs) are becoming increasingly common. ESPs, also commonly referred to as Managed Service Providers (MSPs), Managed Security Service Providers (MSSPs), or
FIPS Encryption Requirements in CMMC and NIST SP 800-171
When handling Controlled Unclassified Information (CUI), compliance with NIST SP 800-171 and the CMMC framework mandates strict data protection measures—including the use of FIPS-validated encryption
CMMC Compliance in 2026: How Did We Get Here and What’s Coming Next
2025 was the year CMMC stopped being theoretical and started impacting contracts, costs, and careers. For defense contractors, certification is no longer just compliance; it’s a competitive edge, a risk mitigation strategy, and
Top 10 CMMC Resources:What OSCs Found Most Helpful
2025 was a year of undeniable progress when it came to the establishment and enforcement of CMMC (Cybersecurity Maturity Model Certification). As we left 2025 and CMMC moved
Where Can You Store CUI and FCI?
Proper storage of Controlled Unclassified Information (CUI) and Federal Contract Information (FCI) is at the core of a healthy and satisfactory compliance program. The issue?