Home / Guides

CMMC without the six-figure consultant.

Plain-English guides for the small DoD contractor doing this themselves. Every one is written by a working practitioner, not a marketing team — scope it down, document it right, pass for a fraction of the quotes you've been handed. Veteran-run, DIY, built for shops with 5, 15, or 50 people and no dedicated security staff. Below, they're laid out in the order you'd actually work them.

01

Start here

New to CMMC? These four answer the questions everything else depends on — what it is, what data you hold, and which level your contract actually triggers.

cmmc for small businessRead now

CMMC for Small Business: How to Break Into DoD Contracting

The honest on-ramp — SAM.gov, FCI vs CUI, self-assessment, SPRS, and the SBA set-asides — plus what the July 2026 suspension changed in your favor. Start here if you're new to federal work.

Read the guide →
is cmmc cancelledRead now

Is CMMC Cancelled? What the July 2026 Suspension Actually Means

No — it's suspended, not repealed. What's paused (the C3PAO cert), what's still the law (NIST 800-171, SPRS, DFARS 7012), and what to do right now. The honest answer to the question everyone's asking.

Read the guide →
what is cmmcRead now

What Is CMMC? A Plain-English Guide for Contractors

New to all this? Start here. What CMMC is, why it exists, who needs it, the levels, and the timeline — no jargon, no fear-selling.

Read the guide →
cui vs fciRead now

CUI vs FCI: Which Data Triggers Which CMMC Level

Whether you handle Federal Contract Information or Controlled Unclassified Information decides Level 1 vs Level 2. How to tell, and why it drives every cost.

Read the guide →
cmmc level 1 vs level 2Read now

CMMC Level 1 vs Level 2: Which Do You Need?

Level 1 protects FCI with 15 basic safeguards you self-assess. Level 2 protects CUI across all 110 controls. Here's how to tell which your contract requires.

Read the guide →
c3pao self assessmentRead now

C3PAO vs Self-Assessment: Which Does Your Contract Require?

Level 1, Level 2 self-assessment, and Level 2 third-party certification — which one your contracts require, and what the Phase 2 suspension changed.

Read the guide →
04

Build the stack

The gear and software that carry the technical controls — each one matched to the family it satisfies, with the honest line on what it does and doesn't cover.

supply chain risk managementRead now

Vet Your Vendors for Supply-Chain Risk & Foreign Ownership

Section 889, FASCSA orders, the 1260H list, DFARS 7012 US-hosting, and TAA — how the government screens its suppliers, the rules that bind you, and a 15-minute checklist to vet any tool before you buy.

Read the guide →
nist sp 1326 due diligenceRead now

How the Government Researches a Vendor: The Federal Due-Diligence Method

NIST SP 1326, published July 2026, translated for small contractors — FOCI, provenance, resilience, foundational cyber practices, and supply chain tiers. The method federal buyers use on you, and the one you can borrow for your own vendors.

Read the guide →
best firewall for cmmcRead now

Best Firewall for CMMC (Without a $30k Consultant)

Firewalla, Protectli/pfSense, or UniFi — matched to your shop size, with the honest line on what a firewall does and doesn't do for FIPS.

Read the guide →
fips firewall cmmcRead now

Do You Need a FIPS-Validated Firewall for CMMC?

The honest answer: usually not — if you scope CUI right and handle encryption with FIPS-validated software. What assessors actually require.

Read the guide →
keeper vs 1password cmmcRead now

Keeper vs 1Password for CMMC: The FedRAMP Line

Both are excellent. Only one is FedRAMP authorized — and the authorization sits on a SKU you have to ask for. The trap that costs contractors the thing they paid for.

Read the guide →
cmmc mfa yubikeyRead now

Hardware MFA for CMMC: The YubiKey Setup Guide

How phishing-resistant hardware keys satisfy the multifactor controls — a real setup walkthrough: buy, enroll, register a backup, enforce.

Read the guide →
cmmc siem loggingRead now

Best SIEM & Logging for CMMC (Audit & Accountability)

The Audit & Accountability controls need real logging — not a filing cabinet of raw logs. The SMB-friendly SIEM a small shop can actually run.

Read the guide →
cmmc cloud backupRead now

Best Cloud Backup for CMMC (Offsite Media Protection)

Offsite, immutable, encrypted copies that satisfy Media Protection and survive ransomware — the 3-2-1 rule, done right, for a small shop.

Read the guide →
cmmc backup nasRead now

Best NAS & Backup for CMMC Media Protection

Encrypted, versioned, recoverable backups plus NIST 800-88 media sanitization — the Media Protection gear list for a small shop.

Read the guide →
cmmc email security dmarcRead now

Email Security & DMARC for CMMC (Stop Phishing)

How SPF, DKIM, and DMARC stop attackers from impersonating your domain — the email-authentication layer behind the SC controls and phishing defense.

Read the guide →
cmmc security awareness trainingRead now

Security Awareness Training for CMMC (the AT Controls)

Phishing training isn't optional — it's a control family. What the Awareness & Training requirements need, and how a small team runs a real program.

Read the guide →
05

Federal policy

Where the requirements come from and how to verify a vendor's claims. Context that turns compliance from arbitrary rules into a chain you can follow.

cmmc reformLiving tracker

CMMC Reform Tracker: The Suspension Timeline & What to Watch

The July 2026 suspension on one screen — the timeline, the dates that matter (RFI Aug 14, report late Sept), and what each outcome would mean. Updated as it develops.

Read the guide →
cmmc phase 2 suspendedRead now

CMMC Phase 2 Suspended: What Contractors Still Have to Do

The C3PAO mandate is paused — but self-assessment, SPRS, and DFARS 7012 aren't. The honest breakdown of what's still required and how to stay audit-ready through the review.

Read the guide →
fedramp cmmcRead now

FedRAMP for CMMC: Authorized vs Equivalent Explained

Every cloud tool touching your CUI has to meet a FedRAMP bar. The difference between "Authorized" and "Moderate Equivalent" — and how to verify a vendor before you trust it.

Read the guide →
executive order cmmcRead now

From Executive Order to CMMC: How Federal Cyber Policy Flows Down to You

The chain a veteran has watched happen: a White House order becomes a NIST standard, a DFARS clause, a CMMC requirement — and finally the SSP on your desk.

Read the guide →
zero trust dod contractorRead now

Zero Trust for Small DoD Contractors: What M-22-09 Means for You

The government went zero trust. You're not an agency — but its five pillars still land on your shop through CMMC. Each one, translated into what you actually do.

Read the guide →
eo 14306 contractorsRead now

EO 14306: What the 2025 Cyber Order Changed for Contractors — and What Didn't

The June 2025 order rolled back some software-attestation mandates. But NIST 800-171, DFARS 7012, and CMMC are untouched — here's what actually moved.

Read the guide →