Scroll Down to Watch! Is Brilliant at the Basics (BatB) the new CMMC? Short answer: no. But the DoW’s new campaign says a lot about where CMMC is headed and what to prioritize right now.On July 13, 2026, the Department of War paused Phase 2 of CMMC and, the same day, launched a new campaign called […]
Just getting started with CMMC preparation? Before you can implement a single security control, you need a clear understanding of your environment. Most organizations underestimate how much foundational work is required before implementation can even begin, and skipping ahead usually means redoing work later when gaps surface. In this article, we’ll walk you through the […]
CMMC isn’t always straightforward. Understanding all 110 NIST 800-171 controls can be difficult, and understanding how they apply in your own unique environment can trip organizations up even more. Every other Friday, we host an open CMMC Office Hours for OSCs to join and get compliance answers directly from Certified CMMC Assessors. A handful of […]
Scroll Down to Watch! If you know your organization needs to implement NIST SP 800-171 or achieve CMMC compliance but have no idea where to begin, this webinar is for you. Before you can implement a single security control, you need a clear understanding of your environment. Most organizations underestimate how much foundational work is […]
In the Defense Industrial Base (DIB), External Service Providers (ESPs) are becoming increasingly common. ESPs, also commonly referred to as Managed Service Providers (MSPs), Managed Security Service Providers (MSSPs), or Cloud Service Providers (CSPs), have become especially beneficial for small and medium-sized businesses where hiring a full-time compliance employee may not be practical. ESP services can range from full system management and support to […]
Proper storage of Controlled Unclassified Information (CUI) and Federal Contract Information (FCI) is at the core of a healthy and satisfactory compliance program. The issue? There seems to be ample confusion on what CUI and FCI are, the difference between the two, and where they officially can be stored. Improper storage of both CUI […]
A major DoD aerospace engineering partner for manufacturers in the Defense Industrial Base (DIB), was concerned about their lack of a compliance program. Knowing CMMC was advancing in rulemaking stages, it would be a matter of time before contract requirements included CMMC certification. Working with 112Cyber CRC’s team of CMMC consultants, the organization was able […]
Creating a Data Flow Diagram (DFD) is a foundational step in achieving Cybersecurity Maturity Model Certification (CMMC) compliance. DFDs offer a visual representation of how Controlled Unclassified Information (CUI) traverses through an organization’s systems. The process of identifying how FCI and CUI traverse an organization also highlights the people, processes, and technology that come in […]
As defense contractors and manufacturers progress toward CMMC Level 2 compliance, a critical area of ambiguity lies in how Operational Technology (OT) is treated within the current Level 2 Scoping Guide. Specifically, the treatment of OT within the category of “specialized assets” leaves significant room for interpretation — and potential misalignment with the practical realities […]
Identifying how and where Controlled Unclassified Information (CUI) is stored, transmitted, and processed within your organization is a critical first step to achieving CMMC compliance. Many organizations overlook this step, however, leading to gap assessment fatigue, unwanted costs, and a lack of leadership and organizational buy-in. In this article, we’ll break down everything you need […]