Graphic that reads "CMMC requirements for subcontractors"

What Are the CMMC Requirements for Subcontractors? 

At this point, you probably know that defense contractors will be required to achieve CMMC compliance. But what about subcontractors? In today’s post, we explore this important topic, including what CMMC and other rules say specifically about subcontractors.  CMMC and Defense Contractors CMMC is short for Cybersecurity Maturity Model Certification, a cybersecurity framework designed by…

Details
Graphic that reads "CUI vs FCI."

CUI vs FCI: What Is the Difference? 

While Controlled Unclassified Information (CUI) tends to get all the attention, the Cybersecurity Maturity Model Certification (CMMC) also aims to protect Federal Contract Information (FCI). Read on to learn more about FCI and CUI, including their differences and how to safeguard them according to CMMC.   What Is FCI? The term Federal Contract Information refers to…

Details
Graphic that reads "What Are ITAR and EAR?"

What Are ITAR and EAR? 

ITAR and EAR are two sets of regulations with similar purposes. However, there are also some important differences between them. Keep reading to learn more about ITAR and EAR, including a detailed review of their scope and application.  What Is ITAR? The International Traffic in Arms Regulations (or  ITAR)  is a set of controls administered…

Details
Graphic that reads "Can you self-certify CMMC?"

Can You Self-Certify CMMC? 

Certifications Under CMMC Can you self-certify CMMC? The answer is yes, but only if you aim to achieve CMMC Level 1. In all other cases, self-certification is not possible. CMMC comprises three progressive levels that mandate an increasing number of cybersecurity practices as follows: Level 3 (Expert): 110+ practices Level 2 (Advanced): 110 practices Level…

Details
Graphic that reads "What Is a RPO in CMMC?"

What Is a CMMC RPO? 

When it comes to the Cybersecurity Maturity Model Certification (CMMC), there are many terms you need to be aware of. One of those acronyms is RPO or Registered Provider Organization. Keep reading to take a closer look at this important part of the CMMC ecosystem.  About Registered Provider Organizations (RPOs) Before we delve into the…

Details

CMMC and FISMA 

You probably understand that FISMA is a piece of legislation that defines cybersecurity standards throughout the federal government. But what is FISMA, exactly, and ( what is its relationship with CMMC? Read on to discover the answers to these questions.  About CMMC The Cybersecurity Maturity Model Certification is a framework developed by the Department of…

Details