Road to Compliance

The Road to Compliance

A twice-weekly path through compliance essentials. Every Tuesday and Thursday we publish a new article. Follow the road from the program decisions to the controls that prove them.

Tiffiney Groce
Tiffiney Groce Director of Education and Compliance, FutureFeed
Type
Persona
Coming Up
Available This Tuesday Playbook Where CUI Actually Lives
The CMMC Tuesday Playbook - FutureFeed

Playbook·

Where CUI Actually Lives

Tuesday Playbook Executive

Picture an engineering firm whose asset inventory lists forty-seven things, while the environment where controlled information actually moves is several times that size. The gap does not surface in an assessment. It comes out in a forty-five-minute conversation with three department heads, a few weeks before an assessment was scheduled. Three people. Forty-five minutes. That is all it takes to surface controlled information the documentation never mentioned. And if you own the boundary, this is your problem before it is anyone else’s…

Available This TuesdayRead the article
Coming Up
Available This Tuesday Playbook When a Level 1 Contract Quietly Becomes a Level 2 Problem
The CMMC Tuesday Playbook - FutureFeed

Playbook·

When a Level 1 Contract Quietly Becomes a Level 2 Problem

Tuesday Playbook Executive

Somewhere in most compliance folders is a short memo that says, in so many words, we handle FCI, not CUI, so we’re Level 1. It was probably right the day it was written. Someone did the work, made the call, and filed it. Here’s the question I’d ask, and it’s an uncomfortable one for a compliance lead: when did anyone last check whether it’s still true?

Available This TuesdayRead the article
Available This Thursday Controls Delivery Access Control (AC) - 3.1.4
The CMMC Thursday Controls Delivery - FutureFeed

Controls Delivery·

Access Control (AC) – 3.1.4

Thursday Controls Delivery Everyone

One person should never be able to quietly approve their own access, pay their own invoice, or hide their own actions. That’s exactly what separation of duties is designed to prevent, and it comes down to four things. Find the sensitive tasks where one person doing everything would be risky. Split those tasks so it takes more than one person: request versus approve, create versus review. Bring managers and process owners in to decide who does what, not just IT. And write down the split duties, then keep records showing they’re followed…

Available This ThursdayRead the article
Coming Up
Available This Tuesday Playbook The Day Your Spreadsheet Stopped Telling the Truth
The CMMC Tuesday Playbook - FutureFeed

Playbook·

The Day Your Spreadsheet Stopped Telling the Truth

Tuesday Playbook Executive

There’s a tab in a lot of CMMC spreadsheets called something like “Evidence, FINAL, v3, use this one.” It’s usually the tab nobody quite trusts. Somebody made it the source of truth months ago, the environment kept moving, and the tab didn’t. On a quiet Tuesday, that’s a mild annoyance. On the day an assessor sits down, or a big customer asks you to prove something, it’s a real problem. Almost every growing contractor hits a version of this. The spreadsheet that ran the whole compliance program beautifully at the start slowly stops being something you can rely on. The hardest part is that it never announces the change.

Available This TuesdayRead the article
Available This Thursday Controls Delivery Access Control (AC) - 3.1.3
The CMMC Thursday Controls Delivery - FutureFeed

Controls Delivery·

Access Control (AC) – 3.1.3

Thursday Controls Delivery Everyone

If you’re responsible for CMMC compliance, this requirement comes down to four things. Have the business decide where Controlled Unclassified Information (CUI) is allowed to move: between people, departments, systems, suppliers, and service providers. Have IT enforce those decisions with your network tools, so approved routes work and everything else is blocked. Stop CUI from leaving on unapproved routes, like personal email or consumer cloud storage. And keep dated records of the approved flows plus proof they’re enforced.

Available This ThursdayRead the article
This Week
Tuesday Playbook Finishing the Assessment Isn't the Same as Posting It
The CMMC Tuesday Playbook - FutureFeed

Playbook·

Finishing the Assessment Isn’t the Same as Posting It

Tuesday Playbook Executive

A prime asks for your SPRS score. Not eventually. This quarter, in a questionnaire or a portal field, with a due date on it. It is a fair question, and it has a short answer. Either there is a current score posted under your CAGE code, or there is not. That question did not go away in July. The Department of War suspended the Phase 2 certification requirement and put the program under review, and I understand why some people read that as the pressure coming off. What changed is who verifies the work. Self-assessment did not pause, and neither did the expectation that you can show where you stand.

Read the article
Thursday Controls Delivery Access Control (AC) - 3.1.2
The CMMC Thursday Controls Delivery - FutureFeed

Controls Delivery·

Access Control (AC) – 3.1.2

Thursday Controls Delivery Everyone

The last control decided who you trust to come in. This one decides how much you trust them once they’re inside. If the first control is the front door, this one is the set of interior doors: being allowed in the building doesn’t mean you can open every room. In plain terms, each person should be able to do only the tasks their job requires, and no more. Someone who enters invoices doesn’t need to change payroll settings or install software. This is the idea people call “least privilege”…

Read the article
Previous Week
Tuesday Playbook Your Real Deadline Is Your Prime's, Not the Rule
The CMMC Tuesday Playbook - FutureFeed

Playbook·

Your Real Deadline Is Your Prime’s, Not the Rule

Tuesday Playbook Executive

Most of the business owners I talk to are watching the wrong calendar. They’re tracking the federal rule, waiting for the date a CMMC requirement officially lands in their contracts, and pacing themselves to that. It feels responsible. It’s also how a lot of good companies are about to get caught flat-footed. Because there’s a second deadline, and it’s the one that actually decides whether you keep your work. It didn’t come from the government. It came from your biggest customer, and it may already be sitting in your inbox.

Read the article
Thursday Controls Delivery Access Control (AC) - 3.1.1
The CMMC Thursday Controls Delivery - FutureFeed

Controls Delivery·

Access Control (AC) – 3.1.1

Thursday Controls Delivery Everyone

Think of this control as deciding who you trust inside your environment. Every person, every automated process, and every device has to earn that trust before it’s allowed in. The lock on your front door is the familiar image, but the real point is simpler: every connection to your CUI environment should have a reason to be there. At any moment, you should be able to answer two questions about every person, process, and device in your environment…

Read the article
Earlier
Tuesday Playbook Level 1 Looks Easy. That's the Trap.
The CMMC Tuesday Playbook - FutureFeed

Playbook·

Level 1 Looks Easy. That’s the Trap.

Tuesday Playbook Beginner

Level 1 is supposed to be the easy one. Fifteen controls instead of a hundred and ten, a self-assessment instead of an outside auditor. So here’s the question I keep coming back to: if it’s so easy, why do good companies still get into trouble with it? Because they do. Every so often I hear about another capable, well-run contractor that did what it was told, self-assessed, filed the affirmation, felt good about it, and still ended up somewhere it never expected. Fifteen controls. How does that go wrong?

Read the article
Thursday Controls Delivery Security Assessment (CA) - 3.12.1 to 3.12.4
The CMMC Thursday Controls Delivery - FutureFeed

Controls Delivery·

Security Assessment (CA) – 3.12.1 to 3.12.4

Thursday Controls Delivery Everyone

This family is the engine that keeps you compliant after the setup work is done. It’s a loop with four moving parts: assess whether your controls are really working and not just written down; write every gap into a Plan of Action & Milestones (POA&M) with an owner and a due date, then work it; monitor your controls all year so you catch drift before your next assessment does; and keep your System Security Plan (SSP) current as the master record of how you meet each requirement. Run the loop and your program stays honest. Skip it and everything you built quietly falls out of date.

Read the article
Earlier
Tuesday Playbook Does CMMC Even Apply to Me? FCI, CUI, and the Level Question
The CMMC Tuesday Playbook - FutureFeed

Playbook·

Does CMMC Even Apply to Me? FCI, CUI, and the Level Question

Tuesday Playbook Beginner

One of the first questions I ask a company is simple: what CMMC level are you pursuing? The answer I hear surprisingly often is, “We think Level 1.” Then I ask why. That’s usually where the room gets quiet. It isn’t because they’re unprepared. Usually they’re good at what they do and they’ve already invested time and money. The quiet comes because nobody has actually answered the question. They assumed Level 1, built toward it, and never went back to check whether the assumption was true.

Read the article
Thursday Controls Delivery Risk Assessment (RA) - 3.11.1, 3.11.2, 3.11.3
The CMMC Thursday Controls Delivery - FutureFeed

Controls Delivery·

Risk Assessment (RA) – 3.11.1, 3.11.2, 3.11.3

Thursday Controls Delivery Everyone

This family is about knowing what could hurt you and doing something about it, before someone else finds the weak spot first. Three requirements: understand what could hurt your organization and how likely it is, on a regular schedule; scan your systems for weaknesses as new ones show up; and fix what you find, worst first. Keep dated records of all three and you’re well on your way.

Read the article
Earlier
Tuesday Playbook What CMMC Actually Costs: Implementation, Operations, and Verification
The CMMC Tuesday Playbook - FutureFeed

Playbook·

What CMMC Actually Costs: Implementation, Operations, and Verification

Tuesday Playbook Beginner

Implementation builds security. Assessment verifies it. They solve different problems and carry very different price tags, and the cost conversation keeps collapsing them into a single number. Pull the total apart and you find five separate buckets: required protection, architecture and technology choices, internal labor, verification, and avoidable spending. Only one of those is the assessment fee, and most of the rest is yours to control.

Read the article
Thursday Controls Delivery Personnel Security (PS) - 3.9.1, 3.9.2
The CMMC Thursday Controls Delivery - FutureFeed

Controls Delivery·

Personnel Security (PS) – 3.9.1, 3.9.2

Thursday Controls Delivery Everyone

This family is about the two moments that matter most with any employee or contractor: the day they arrive and the day they leave. Before someone gets access to systems that process CUI, make sure they’ve been screened for the role. And when they walk out the door, make sure your systems and information don’t walk out with them: accounts disabled, laptops and badges collected, with dated records to prove it.

Read the article
Earlier
Tuesday Playbook Why Security Is a Business Decision
The CMMC Tuesday Playbook - FutureFeed

Playbook·

Why Security Is a Business Decision

Tuesday Playbook Executive

Security gets filed under IT until the day it decides whether you can bid. The contracts you win, the customers who keep you on their supplier list, the liability you carry when something goes wrong: all of it now runs through whether you can prove your security posture. That makes this a decision for the people who own the business outcome, not one to delegate down the org chart.

Read the article
Thursday Controls Delivery Awareness & Training (AT) - 3.2.1, 3.2.2, 3.2.3
The CMMC Thursday Controls Delivery - FutureFeed

Controls Delivery·

Awareness & Training (AT) – 3.2.1, 3.2.2, 3.2.3

Thursday Controls Delivery Everyone

If you’ve opened NIST SP 800-171, you probably noticed Access Control (3.1) comes before Awareness and Training (3.2). So why start here? Because the control numbers tell you where to find a requirement, not where to begin building your program. I’ve found it’s easier to build the people side first, then layer the technical controls on top.

Read the article
No articles match those filters yet. Try resetting to All.
CMMC: Everything You Need to Know to Get Started, 6th Edition guide cover

CMMC: Everything You Need to Know to Get Started (6th Edition)

Want the full compliance framework and the funding resources available to defense contractors? Our guide has it.