Plain-English guides for the small DoD contractor doing this themselves. Every one is written by a working practitioner, not a marketing team — scope it down, document it right, pass for a fraction of the quotes you've been handed. Veteran-run, DIY, built for shops with 5, 15, or 50 people and no dedicated security staff. Below, they're laid out in the order you'd actually work them.
New to CMMC? These four answer the questions everything else depends on — what it is, what data you hold, and which level your contract actually triggers.
The honest on-ramp — SAM.gov, FCI vs CUI, self-assessment, SPRS, and the SBA set-asides — plus what the July 2026 suspension changed in your favor. Start here if you're new to federal work.
Read the guide →No — it's suspended, not repealed. What's paused (the C3PAO cert), what's still the law (NIST 800-171, SPRS, DFARS 7012), and what to do right now. The honest answer to the question everyone's asking.
Read the guide →New to all this? Start here. What CMMC is, why it exists, who needs it, the levels, and the timeline — no jargon, no fear-selling.
Read the guide →Whether you handle Federal Contract Information or Controlled Unclassified Information decides Level 1 vs Level 2. How to tell, and why it drives every cost.
Read the guide →Level 1 protects FCI with 15 basic safeguards you self-assess. Level 2 protects CUI across all 110 controls. Here's how to tell which your contract requires.
Read the guide →Level 1, Level 2 self-assessment, and Level 2 third-party certification — which one your contracts require, and what the Phase 2 suspension changed.
Read the guide →Before you spend a dollar: where you stand today, what this honestly costs, and the single biggest lever for making it cost less.
How the DoD scoring methodology deducts points, why one missed control can cost you five, and what a negative score signals to the prime evaluating your bid.
Read the guide →The real line items behind the $116k–$138k consultant quotes — and the DIY path that gets you 80% of the way there for a fraction of it. No hand-waving.
Read the guide →Stop hardening the whole company. Scope CUI into a small segmented enclave and shrink the assessment boundary — the single biggest cost lever a small shop has.
Read the guide →Assessors grade paperwork and evidence, not intentions. The four documents and records that decide whether your controls count.
The System Security Plan is the document your assessor lives in. What goes in it, what gets shops failed, and how to write yours without a template mill.
Read the guide →Every control family needs a documented policy behind it. The full list, what each one has to say, and why the wording matters more than the length.
Read the guide →A Plan of Action & Milestones buys you time on open controls — but only if it's specific, dated, and credible. How to write one that doesn't sink you.
Read the guide →Turning logging on is one job out of six. What to capture, how long to keep it, protecting logs from tampering, and the review record an assessor actually grades.
Read the guide →The gear and software that carry the technical controls — each one matched to the family it satisfies, with the honest line on what it does and doesn't cover.
Section 889, FASCSA orders, the 1260H list, DFARS 7012 US-hosting, and TAA — how the government screens its suppliers, the rules that bind you, and a 15-minute checklist to vet any tool before you buy.
Read the guide →NIST SP 1326, published July 2026, translated for small contractors — FOCI, provenance, resilience, foundational cyber practices, and supply chain tiers. The method federal buyers use on you, and the one you can borrow for your own vendors.
Read the guide →Firewalla, Protectli/pfSense, or UniFi — matched to your shop size, with the honest line on what a firewall does and doesn't do for FIPS.
Read the guide →The honest answer: usually not — if you scope CUI right and handle encryption with FIPS-validated software. What assessors actually require.
Read the guide →Both are excellent. Only one is FedRAMP authorized — and the authorization sits on a SKU you have to ask for. The trap that costs contractors the thing they paid for.
Read the guide →How phishing-resistant hardware keys satisfy the multifactor controls — a real setup walkthrough: buy, enroll, register a backup, enforce.
Read the guide →The Audit & Accountability controls need real logging — not a filing cabinet of raw logs. The SMB-friendly SIEM a small shop can actually run.
Read the guide →Offsite, immutable, encrypted copies that satisfy Media Protection and survive ransomware — the 3-2-1 rule, done right, for a small shop.
Read the guide →Encrypted, versioned, recoverable backups plus NIST 800-88 media sanitization — the Media Protection gear list for a small shop.
Read the guide →How SPF, DKIM, and DMARC stop attackers from impersonating your domain — the email-authentication layer behind the SC controls and phishing defense.
Read the guide →Phishing training isn't optional — it's a control family. What the Awareness & Training requirements need, and how a small team runs a real program.
Read the guide →Where the requirements come from and how to verify a vendor's claims. Context that turns compliance from arbitrary rules into a chain you can follow.
The July 2026 suspension on one screen — the timeline, the dates that matter (RFI Aug 14, report late Sept), and what each outcome would mean. Updated as it develops.
Read the guide →The C3PAO mandate is paused — but self-assessment, SPRS, and DFARS 7012 aren't. The honest breakdown of what's still required and how to stay audit-ready through the review.
Read the guide →Every cloud tool touching your CUI has to meet a FedRAMP bar. The difference between "Authorized" and "Moderate Equivalent" — and how to verify a vendor before you trust it.
Read the guide →The chain a veteran has watched happen: a White House order becomes a NIST standard, a DFARS clause, a CMMC requirement — and finally the SSP on your desk.
Read the guide →The government went zero trust. You're not an agency — but its five pillars still land on your shop through CMMC. Each one, translated into what you actually do.
Read the guide →The June 2025 order rolled back some software-attestation mandates. But NIST 800-171, DFARS 7012, and CMMC are untouched — here's what actually moved.
Read the guide →