The Road to Compliance
A twice-weekly path through compliance essentials. Every Tuesday and Thursday we publish a new article. Follow the road from the program decisions to the controls that prove them.
Level 1 Looks Easy. That’s the Trap.
Level 1 is supposed to be the simple one: fifteen controls instead of a hundred and ten, a self-assessment instead of an outside auditor. So why do good companies still get into trouble with it? The answer isn’t in the controls. It’s in what the signature underneath them actually means, the moment CMMC stops being an IT deliverable and becomes a question of whether your organization can stand behind what it’s claiming.
Read the article→Risk Assessment (RA) – 3.11.1, 3.11.2, 3.11.3
This family is about knowing what could hurt you and doing something about it, before someone else finds the weak spot first. Three requirements: understand what could hurt your organization and how likely it is, on a regular schedule; scan your systems for weaknesses as new ones show up; and fix what you find, worst first. Keep dated records of all three and you’re well on your way.
Read the article→Does CMMC Even Apply to Me? FCI, CUI, and the Level Question
One of the first questions I ask a company is what CMMC level they’re pursuing. The answer I hear surprisingly often is “we think Level 1.” Then I ask why, and the room gets quiet. Your level isn’t something you pick, it’s something you discover. It’s decided by the information you handle: FCI alone puts you at Level 1, and the moment CUI lands in your environment you’re at Level 2.
Read the article→Personnel Security (PS) – 3.9.1, 3.9.2
This family is about the two moments that matter most with any employee or contractor: the day they arrive and the day they leave. Before someone gets access to systems that process CUI, make sure they’ve been screened for the role. And when they walk out the door, make sure your systems and information don’t walk out with them: accounts disabled, laptops and badges collected, with dated records to prove it.
Read the article→Why Security Is a Business Decision
Security gets filed under IT until the day it decides whether you can bid. The contracts you win, the customers who keep you on their supplier list, the liability you carry when something goes wrong: all of it now runs through whether you can prove your security posture. That makes this a decision for the people who own the business outcome, not one to delegate down the org chart.
Read the article→Awareness & Training (AT) – 3.2.1, 3.2.2, 3.2.3
If you’ve opened NIST SP 800-171, you probably noticed Access Control (3.1) comes before Awareness and Training (3.2). So why start here? Because the control numbers tell you where to find a requirement, not where to begin building your program. I’ve found it’s easier to build the people side first, then layer the technical controls on top.
Available This ThursdayRead the article→
CMMC: Everything You Need to Know to Get Started (6th Edition)
Want the full compliance framework and the funding resources available to defense contractors? Our guide has it.
Never miss a stop on the road
New articles every Tuesday and Thursday. Get The Road to Compliance delivered to your inbox so the essentials come to you.

