The Road to Compliance
A twice-weekly path through compliance essentials. Every Tuesday and Thursday we publish a new article. Follow the road from the program decisions to the controls that prove them.
Where CUI Actually Lives
Picture an engineering firm whose asset inventory lists forty-seven things, while the environment where controlled information actually moves is several times that size. The gap does not surface in an assessment. It comes out in a forty-five-minute conversation with three department heads, a few weeks before an assessment was scheduled. Three people. Forty-five minutes. That is all it takes to surface controlled information the documentation never mentioned. And if you own the boundary, this is your problem before it is anyone else’s…
Available This TuesdayRead the article→When a Level 1 Contract Quietly Becomes a Level 2 Problem
Somewhere in most compliance folders is a short memo that says, in so many words, we handle FCI, not CUI, so we’re Level 1. It was probably right the day it was written. Someone did the work, made the call, and filed it. Here’s the question I’d ask, and it’s an uncomfortable one for a compliance lead: when did anyone last check whether it’s still true?
Available This TuesdayRead the article→Access Control (AC) – 3.1.4
One person should never be able to quietly approve their own access, pay their own invoice, or hide their own actions. That’s exactly what separation of duties is designed to prevent, and it comes down to four things. Find the sensitive tasks where one person doing everything would be risky. Split those tasks so it takes more than one person: request versus approve, create versus review. Bring managers and process owners in to decide who does what, not just IT. And write down the split duties, then keep records showing they’re followed…
Available This ThursdayRead the article→The Day Your Spreadsheet Stopped Telling the Truth
There’s a tab in a lot of CMMC spreadsheets called something like “Evidence, FINAL, v3, use this one.” It’s usually the tab nobody quite trusts. Somebody made it the source of truth months ago, the environment kept moving, and the tab didn’t. On a quiet Tuesday, that’s a mild annoyance. On the day an assessor sits down, or a big customer asks you to prove something, it’s a real problem. Almost every growing contractor hits a version of this. The spreadsheet that ran the whole compliance program beautifully at the start slowly stops being something you can rely on. The hardest part is that it never announces the change.
Available This TuesdayRead the article→Access Control (AC) – 3.1.3
If you’re responsible for CMMC compliance, this requirement comes down to four things. Have the business decide where Controlled Unclassified Information (CUI) is allowed to move: between people, departments, systems, suppliers, and service providers. Have IT enforce those decisions with your network tools, so approved routes work and everything else is blocked. Stop CUI from leaving on unapproved routes, like personal email or consumer cloud storage. And keep dated records of the approved flows plus proof they’re enforced.
Available This ThursdayRead the article→Finishing the Assessment Isn’t the Same as Posting It
A prime asks for your SPRS score. Not eventually. This quarter, in a questionnaire or a portal field, with a due date on it. It is a fair question, and it has a short answer. Either there is a current score posted under your CAGE code, or there is not. That question did not go away in July. The Department of War suspended the Phase 2 certification requirement and put the program under review, and I understand why some people read that as the pressure coming off. What changed is who verifies the work. Self-assessment did not pause, and neither did the expectation that you can show where you stand.
Read the article→Access Control (AC) – 3.1.2
The last control decided who you trust to come in. This one decides how much you trust them once they’re inside. If the first control is the front door, this one is the set of interior doors: being allowed in the building doesn’t mean you can open every room. In plain terms, each person should be able to do only the tasks their job requires, and no more. Someone who enters invoices doesn’t need to change payroll settings or install software. This is the idea people call “least privilege”…
Read the article→Your Real Deadline Is Your Prime’s, Not the Rule
Most of the business owners I talk to are watching the wrong calendar. They’re tracking the federal rule, waiting for the date a CMMC requirement officially lands in their contracts, and pacing themselves to that. It feels responsible. It’s also how a lot of good companies are about to get caught flat-footed. Because there’s a second deadline, and it’s the one that actually decides whether you keep your work. It didn’t come from the government. It came from your biggest customer, and it may already be sitting in your inbox.
Read the article→Access Control (AC) – 3.1.1
Think of this control as deciding who you trust inside your environment. Every person, every automated process, and every device has to earn that trust before it’s allowed in. The lock on your front door is the familiar image, but the real point is simpler: every connection to your CUI environment should have a reason to be there. At any moment, you should be able to answer two questions about every person, process, and device in your environment…
Read the article→Level 1 Looks Easy. That’s the Trap.
Level 1 is supposed to be the easy one. Fifteen controls instead of a hundred and ten, a self-assessment instead of an outside auditor. So here’s the question I keep coming back to: if it’s so easy, why do good companies still get into trouble with it? Because they do. Every so often I hear about another capable, well-run contractor that did what it was told, self-assessed, filed the affirmation, felt good about it, and still ended up somewhere it never expected. Fifteen controls. How does that go wrong?
Read the article→Security Assessment (CA) – 3.12.1 to 3.12.4
This family is the engine that keeps you compliant after the setup work is done. It’s a loop with four moving parts: assess whether your controls are really working and not just written down; write every gap into a Plan of Action & Milestones (POA&M) with an owner and a due date, then work it; monitor your controls all year so you catch drift before your next assessment does; and keep your System Security Plan (SSP) current as the master record of how you meet each requirement. Run the loop and your program stays honest. Skip it and everything you built quietly falls out of date.
Read the article→Does CMMC Even Apply to Me? FCI, CUI, and the Level Question
One of the first questions I ask a company is simple: what CMMC level are you pursuing? The answer I hear surprisingly often is, “We think Level 1.” Then I ask why. That’s usually where the room gets quiet. It isn’t because they’re unprepared. Usually they’re good at what they do and they’ve already invested time and money. The quiet comes because nobody has actually answered the question. They assumed Level 1, built toward it, and never went back to check whether the assumption was true.
Read the article→Risk Assessment (RA) – 3.11.1, 3.11.2, 3.11.3
This family is about knowing what could hurt you and doing something about it, before someone else finds the weak spot first. Three requirements: understand what could hurt your organization and how likely it is, on a regular schedule; scan your systems for weaknesses as new ones show up; and fix what you find, worst first. Keep dated records of all three and you’re well on your way.
Read the article→What CMMC Actually Costs: Implementation, Operations, and Verification
Implementation builds security. Assessment verifies it. They solve different problems and carry very different price tags, and the cost conversation keeps collapsing them into a single number. Pull the total apart and you find five separate buckets: required protection, architecture and technology choices, internal labor, verification, and avoidable spending. Only one of those is the assessment fee, and most of the rest is yours to control.
Read the article→Personnel Security (PS) – 3.9.1, 3.9.2
This family is about the two moments that matter most with any employee or contractor: the day they arrive and the day they leave. Before someone gets access to systems that process CUI, make sure they’ve been screened for the role. And when they walk out the door, make sure your systems and information don’t walk out with them: accounts disabled, laptops and badges collected, with dated records to prove it.
Read the article→Why Security Is a Business Decision
Security gets filed under IT until the day it decides whether you can bid. The contracts you win, the customers who keep you on their supplier list, the liability you carry when something goes wrong: all of it now runs through whether you can prove your security posture. That makes this a decision for the people who own the business outcome, not one to delegate down the org chart.
Read the article→Awareness & Training (AT) – 3.2.1, 3.2.2, 3.2.3
If you’ve opened NIST SP 800-171, you probably noticed Access Control (3.1) comes before Awareness and Training (3.2). So why start here? Because the control numbers tell you where to find a requirement, not where to begin building your program. I’ve found it’s easier to build the people side first, then layer the technical controls on top.
Read the article→
CMMC: Everything You Need to Know to Get Started (6th Edition)
Want the full compliance framework and the funding resources available to defense contractors? Our guide has it.
Never miss a stop on the road
New articles every Tuesday and Thursday. Get The Road to Compliance delivered to your inbox so the essentials come to you.

