News
News and updates
Short, frequent notes on CMMC and government compliance, cyber security and managed IT. For the longer researched pieces, see the blog.
-
Why Phase II paused, according to the announcement
The Department of War cited compliance costs and burden on small business, not assessor capacity. The obligations did not pause with the assessments.
-
Backups rarely fail in a ransomware event. Recovery does.
The backup job is green. The restore is what breaks — usually on recovery order, an encrypted backup server, or a restore time nobody measured.
-
Your contract decides the assessment. Scope decides the effort.
About $593,800 with a third-party assessment, or $388,600 self-assessed. Which applies is set by your contract's requirement, not by how you are configured.
-
MFA is not the finish line it used to be
Modern attacks do not defeat multi-factor authentication. They wait for it — through prompt fatigue and stolen session tokens.
-
With C3PAO assessments paused, the affirmation carries the weight
Third-party certification is suspended, but select government-led assessments continue — and one named person still signs that your requirements are met.