WEBINAR | CMMC ROLE BASED TRAINING
Coming Soon: CMMC is a team responsibility. Discover what your role requires and the actions you can take to support compliance.
Stay ahead of changing compliance requirements with SecureITSM’s collection of blogs, videos, webinars, and upcoming events. Discover actionable insights, best practices, and expert guidance for CMMC, NIST 800-171, and federal cybersecurity programs.
Our blog covers all aspects of cybersecurity, compliance, and IT security with expert analysis and practical insights.
Discover upcoming webinars, workshops and cybersecurity events hosted by SecureITSM.
Coming Soon: CMMC is a team responsibility. Discover what your role requires and the actions you can take to support compliance.
Watch expert insights, cybersecurity explainers and compliance guidance from the SecureITSM team.
In this video, David Fraley, CTO of SecureITSM, shares practical recommendations for improving the Cybersecurity Maturity Model Certification (CMMC) program following the Department of War's Request for Information (RFI). The video discusses NIST SP 800-171 compliance, System Security Plans (SSPs), AI-assisted SPRS reviews, CMMC certification recommendations, assessment improvements, and technical considerations for future program enhancements. Watch to understand SecureITSM's perspective on making compliance more practical while maintaining strong cybersecurity standards.
The DoW has paused the implementation of mandatory CMMC certification requirements, but what does this mean for your annual SPRS submission and cybersecurity obligations? In this on-demand webinar, David Fraley, CTO of SecureITSM, explains what has changed, what hasn't changed, and the practical steps defense contractors should take moving forward. In This Webinar You'll Learn: ✅ What the CMMC certification pause actually means ✅ What cybersecurity requirements still remain in effect ✅ Annual SPRS submission responsibilities ✅ NIST SP 800-171 Rev. 2 compliance expectations ✅ False Claims Act considerations ✅ Self-assessment accountability ✅ Documentation and evidence best practices ✅ Practical recommendations for defense contractors
Defense contractors face growing False Claims Act risk when SPRS scores, NIST SP 800-171 implementation, and cybersecurity documentation don't match reality. See what recent DOJ cases mean for contractors.
This blog serves as a focused reference guide to NIST SP 800-171 and 800-171A by presenting each control alongside its corresponding assessment objectives and considerations. The content is structured in a clear, tabular format that maps controls to their verification criteria, enabling readers to understand not just what is required, but how compliance is evaluated. Each entry also identifies whether the control aligns to CMMC Level 1 or Level 2 and includes the associated SPRS point deduction if the control is not met. The result is a practical, audit-aligned resource designed to support organizations in preparing for assessments and understanding the measurable impact of compliance gaps.
Government contractors face a growing challenge: protecting sensitive federal information from unauthorized access or disclosure. Two key data types — CUI and FCI — carry distinct safeguarding requirements that directly impact compliance and contract eligibility. This blog explains what CUI and FCI are, how they differ, why they matter, how to identify them within your environment, and how CMMC requirements apply to each. Understanding these distinctions is essential for building a compliant, defensible cybersecurity program.
National Clean Out Your Computer Day 2026 highlights how digital hygiene supports CMMC compliance, protects CUI, and keeps defense contractors audit-ready.
CMMC compliance has rapidly become one of the most demanding compliance frameworks facing Defense Industrial Base contractors. For small and mid-size organizations—particularly manufacturers, engineering firms, and service providers—the effort required to successfully undergo and obtain CMMC Level 2 authorization is profoundly expensive.
Strong security starts with knowing who and what is allowed into your environment—and limiting everything else. Organizations must identify users, devices, and systems; verify identities; control physical and network access; protect data boundaries; and quickly fix vulnerabilities. By clearly defining access, monitoring activity, and enforcing protections, you reduce risk, protect CUI, and strengthen overall compliance.
The DoD has finalized the CMMC rule, making cybersecurity compliance mandatory...
The DoD has finalized the CMMC rule, making cybersecurity compliance mandatory for defense contractors. Here’s what it means for your business and how to prepare.
A detailed comparison of NIST SP 800-171 and CMMC requirements to help organizations understand their compliance obligations
With cyber threats evolving rapidly, organizations must prioritize cybersecurity and continuously monitor their security posture. A Security Operations Center (SOC) plays a crucial role in detecting, analyzing, responding to, and mitigating cyber threats. However, not all businesses can afford to establish an in-house SOC due to resource constraints. Fortunately, they can still benefit from a Managed SOC (or SOC as a Service).
Microsoft GCC and GCC High are Microsoft cloud environments designed to meet the security and compliance needs of Government agencies, contractors, and suppliers. Contrary to popular belief, BOTH GCC and GCC High are compliant with DFARS 7012 and CMMC 2.0. This means that you will have to consider your overall security and compliance needs when deciding between these two options. To help you decide between these two environments, let’s take a look at the primary differences between these two platforms.
An Effective License Position (ELP) reconciles software entitlements with actual usage to identify compliance risks and eliminate wasted spend. By analyzing purchases, deployments, and usage data, organizations can correct under- or over-licensing. SecureITSM’s four-step methodology helps optimize renewals, reduce audit exposure, and ensure cost-effective, well-governed software investments.
Achieving CMMC Level 2 certification is a critical requirement for defense contractors handling Controlled Unclassified Information (CUI). However, the cost of compliance can be a significant burden, especially for small to mid-sized businesses. The total expense varies based on company size, existing cybersecurity maturity, and IT infrastructure.
Never miss important cybersecurity updates. Get weekly insights, analysis, and practical guidance delivered directly to your inbox.
While our blog provides valuable insights, every organization's cybersecurity needs are unique. Contact us for personalized guidance and solutions.