CMMC isn’t always straightforward. Understanding all 110 NIST 800-171 controls can be difficult, and understanding how they apply in your own unique environment can trip organizations up even more. Every other Friday, we host an open CMMC Office Hours for OSCs to join and get compliance answers directly from Certified CMMC Assessors. A handful of […]
Scroll Down to Watch! If you know your organization needs to implement NIST SP 800-171 or achieve CMMC compliance but have no idea where to begin, this webinar is for you. Before you can implement a single security control, you need a clear understanding of your environment. Most organizations underestimate how much foundational work is […]
Scroll Down to Watch! On July 13, the Department of War (DoW) paused CMMC Phase 2 certification requirements for 60 days. If you’re a contractor or sub in the Defense Industrial Base, you’ve probably already seen the headlines, and you’ve probably already had someone tell you “CMMC is dead.” It’s not. Join us for a live, no-fluff […]
On July 13th, 2026, at 3:30PM EST, the Department of War (DoW) released a memorandum for senior Pentagon leadership with a subject of “Implementing Department of War Chief Information Officer’s Suspension of the Advancement to Cybersecurity Maturity Model Certification Phase 2 Requirements” and “Removing Barriers to Defense Industrial Base Expansion: Immediate Suspension and Strategic Review […]
Earning CMMC certification takes a significant investment of time, resources, and effort. Once an organization clears its C3PAO Assessment, there’s a natural sense of relief — even accomplishment. That CMMC Status can last up to three years, but two events bring recertification back onto the calendar sooner: reaching the end of the standard three-year cycle, […]
If your organization handles Controlled Unclassified Information (CUI) and is working toward CMMC Level 2 certification, understanding where organizations most commonly fail is half the battle. In a recent webinar, 112Cyber’s certified CMMC assessors Nick Graning and Jordon Darling broke down five of the most commonly failed control areas — and exactly what you need […]
Scroll Down to Watch! Wondering which CMMC controls organizations fail most often, and how to avoid making the same mistakes? Our Certified CMMC Assessors are back for part two of this highly requested webinar to break down more of the most commonly failed controls and explain what they expect to see in an assessment. Watch […]
Not all C3PAOs are created equal. Before you sign an engagement, these are the questions that separate credible assessors from expensive mistakes — organized by category, with what good answers look like, and what should send you running. 01 Scoping & Environment Understanding Ask “How do you approach defining the CMMC assessment boundary?” “How do […]
In the Defense Industrial Base (DIB), External Service Providers (ESPs) are becoming increasingly common. ESPs, also commonly referred to as Managed Service Providers (MSPs), Managed Security Service Providers (MSSPs), or Cloud Service Providers (CSPs), have become especially beneficial for small and medium-sized businesses where hiring a full-time compliance employee may not be practical. ESP services can range from full system management and support to […]
When handling Controlled Unclassified Information (CUI), compliance with NIST SP 800-171 and the CMMC framework mandates strict data protection measures—including the use of FIPS-validated encryption in specific scenarios. But one requirement that consistently generates questions is exactly what “FIPS-validated” means in practice, where it applies, and how it differs from the looser “FIPS-compliant” language that […]