The Road to Compliance
A twice-weekly path through compliance essentials. Every Tuesday and Thursday we publish a new article. Follow the road from the program decisions to the controls that prove them.
Does CMMC Even Apply to Me? FCI, CUI, and the Level Question
One of the first questions I ask a company is simple: what CMMC level are you pursuing? The answer I hear surprisingly often is, “We think Level 1.” Then I ask why. That’s usually where the room gets quiet. It isn’t because they’re unprepared. Usually they’re good at what they do and they’ve already invested time and money. The quiet comes because nobody has actually answered the question. They assumed Level 1, built toward it, and never went back to check whether the assumption was true.
Read the article→Risk Assessment (RA) – 3.11.1, 3.11.2, 3.11.3
This family is about knowing what could hurt you and doing something about it, before someone else finds the weak spot first. Three requirements: understand what could hurt your organization and how likely it is, on a regular schedule; scan your systems for weaknesses as new ones show up; and fix what you find, worst first. Keep dated records of all three and you’re well on your way.
Read the article→What CMMC Actually Costs: Implementation, Operations, and Verification
Implementation builds security. Assessment verifies it. They solve different problems and carry very different price tags, and the cost conversation keeps collapsing them into a single number. Pull the total apart and you find five separate buckets: required protection, architecture and technology choices, internal labor, verification, and avoidable spending. Only one of those is the assessment fee, and most of the rest is yours to control.
Read the article→Personnel Security (PS) – 3.9.1, 3.9.2
This family is about the two moments that matter most with any employee or contractor: the day they arrive and the day they leave. Before someone gets access to systems that process CUI, make sure they’ve been screened for the role. And when they walk out the door, make sure your systems and information don’t walk out with them: accounts disabled, laptops and badges collected, with dated records to prove it.
Available This ThursdayRead the article→Why Security Is a Business Decision
Security gets filed under IT until the day it decides whether you can bid. The contracts you win, the customers who keep you on their supplier list, the liability you carry when something goes wrong: all of it now runs through whether you can prove your security posture. That makes this a decision for the people who own the business outcome, not one to delegate down the org chart.
Read the article→Awareness & Training (AT) – 3.2.1, 3.2.2, 3.2.3
If you’ve opened NIST SP 800-171, you probably noticed Access Control (3.1) comes before Awareness and Training (3.2). So why start here? Because the control numbers tell you where to find a requirement, not where to begin building your program. I’ve found it’s easier to build the people side first, then layer the technical controls on top.
Read the article→
CMMC: Everything You Need to Know to Get Started (6th Edition)
Want the full compliance framework and the funding resources available to defense contractors? Our guide has it.
Never miss a stop on the road
New articles every Tuesday and Thursday. Get The Road to Compliance delivered to your inbox so the essentials come to you.

