CMMC Personnel Security: The Two PS Controls That Fail on the HR-to-IT Handoff
The two CMMC personnel security PS controls, screening and termination, and the five HR-to-IT handoff failures that get them marked NOT MET.
Articles about cmmc level 2 readiness compliance requirements, frameworks, and audit preparation.
The two CMMC personnel security PS controls, screening and termination, and the five HR-to-IT handoff failures that get them marked NOT MET.
How to sort every asset into the five CMMC asset categories: CUI Assets, Security Protection Assets, CRMAs, Specialized, and out-of-scope.
DoD suspended CMMC Phase 2 on July 13, 2026. What still applies: Phase 1 SPRS checks, self-assessments, affirmations, and DFARS 7012.
Six System and Communications Protection (SC) mistakes that fail CMMC assessments: weak boundaries, permit-by-default rules, and non-FIPS encryption.
The 6 CMMC Maintenance (MA) controls explained: maintenance logs, tool and personnel control, MFA for remote sessions, equipment sanitization, escorts.
DFARS 252.204-7012 and 7021 explained: what each clause requires, how they differ, and what receiving 7021 in a contract actually means.
The 14 CMMC control families explained: requirement counts, SPRS point exposure, which domains fail most in C3PAO assessments, and where to focus first.
CMMC Level 2 requires FIPS-validated cryptographic modules, not just AES-256. Which SC controls apply, where validation is required, and how to verify.
CMMC Level 2 MFA requirements: which accounts need it, why SMS fails the replay-resistance test, and what authentication methods qualify under IA.L2-3.5.3.
CMMC incident response plan requirements explained: the three IR controls, the 72-hour DFARS reporting rule, and why testing is where teams fail.
9 CMMC myths that trip up small defense contractors, from 'we're too small' to 'we'll pass the C3PAO' — and what each misconception actually costs.
CMMC network segmentation done right: how to build a CUI enclave that reduces scope and survives a C3PAO assessment — and why a VLAN isn't enough.
CMMC compliance for manufacturers: why small shops start with 40-70 NIST 800-171 gaps and the scoping, enclave, and SSP moves that close them.
CMMC annual affirmation explained: who signs as affirming official, when it is due each year, and the False Claims Act risk behind the signature.
CMMC Audit and Accountability requirements: seven logging mistakes in the AU control family that fail assessments, and how to fix each one.
CMMC vs ISO 27001: what an existing ISO 27001 certification covers toward CMMC Level 2, where it leaves gaps, and how to plan the crossover.
How the Customer Responsibility Matrix splits CMMC controls between you and your cloud, plus FedRAMP Moderate vs equivalency for holding CUI.
CMMC Phase 2 requires C3PAO certification after Nov 10, 2026. A month-by-month plan to prepare, and what to do if the deadline is too close.
What CMMC assessors look for in your System Security Plan, and the 8 SSP mistakes that turn a Level 2 assessment into a stack of findings.
The CMMC Configuration Management family: baselines, change control, least functionality, and the CM controls that trip up small defense contractors.
Does your MSP or external service provider fall inside your CMMC assessment scope? Three factors decide it, including who handles Security Protection Data.
Your SPRS score is below 88? That blocks conditional CMMC status and POA&Ms. How to read the number and sequence remediation to cross the 88-point line.
FedRAMP Authorized vs Moderate Equivalency for cloud holding CUI: what each path requires under CMMC, who holds the evidence, and which fits your contract.
Got a CMMC flow-down email from your prime? How to tell which level you need, what the prime owes you, and how to respond as a subcontractor.
CMMC media protection at Level 2: the 9 MP controls, CUI marking and sanitization rules people get wrong, and the evidence assessors ask for.
CMMC risk assessment and vulnerability scanning: the three RA controls, how often you really need to scan, and the evidence assessors expect at Level 2.
CMMC physical protection requirements: the 6 PE controls and the alternate-work-site rule (3.10.6) that puts remote workers' home offices in scope.
CMMC security awareness training: the 3 AT controls, the insider-threat piece most teams miss, and what assessors ask your staff to prove it.
CMMC System and Information Integrity: the 7 SI controls for flaw remediation, malware defense, and monitoring, and how SI chains to RA and CM.
How to submit your NIST 800-171 self-assessment score to SPRS via the DISA portal: PIEE roles, assessment entry, and the senior-official affirmation.
The controls that cause most CMMC assessment failures: SPRS point values, root causes, and how to prove implementation before the C3PAO arrives.
What your CMMC evidence package needs to pass C3PAO assessment: documentation types, recency requirements, and what assessors reject.
A CUI enclave can cut CMMC assessment scope 50-70%. Decision tree with three factors that determine whether an enclave fits your operations.
CMMC Level 2 access control has 22 requirements and produces the most C3PAO findings. Six failures account for 70-80%, with remediation steps.
POA&Ms cover only 1-point CMMC controls when your SPRS score is 88+, and items must close within 180 days. Worked example with eligibility rules.
Rev 3 has 97 controls and 422 objectives. CMMC stays on Rev 2 via DoD class deviation. Side-by-side comparison and Rev 3 prep guidance.
Timeline-aware CMMC audit prep: 12-18 month, 6-12 month, and 90-day plans. Evidence checklist + the 5 mistakes that fail C3PAO assessments.
Level 1 protects FCI with 17 controls; Level 2 protects CUI with 110. How to tell which CMMC level your DoD contract actually requires.
How long does CMMC certification take? 12-18 months from kickoff for most defense contractors. Phase-by-phase timeline by starting maturity.
A free CMMC readiness quiz online estimates your SPRS score in 15 minutes. What it can and can't tell you about C3PAO assessment readiness.
CMMC for subcontractors: small defense companies still face all 110 controls when they handle CUI. Flow-down rules, scope strategy, and real costs.
CMMC system security plan (SSP) templates fail when narratives stay generic. Here is what assessors look for, the structure, and the common failures.
What to expect during a CMMC C3PAO assessment: pre-assessment, the 5-day on-site week (Examine, Interview, Test), and the post-assessment report.
CMMC timeline 2026: Phase 2 enforcement begins November 10, 2026. The four phases, what each triggers, and a realistic prep track at each stage.
Self-assessment or C3PAO? Your DFARS clauses determine the path. Compare cost, timeline, and verification requirements for both CMMC Level 2 paths.
Calculate your SPRS score before submitting to DISA. Worked example with NIST 800-171 point values, the 88 threshold, and POA&M eligibility rules.
CMMC Level 2 requires 110 controls from NIST 800-171 Rev 2. Use this per-domain checklist to map gaps before your gap analysis or SPRS submission.
CUI vs FCI: how to determine which CMMC level your DoD contracts require. Decision steps, contract clause guide, and what each level costs.
CMMC gap analysis step by step: scope CUI, assess all 110 controls, calculate your SPRS score, and build a prioritized remediation plan.
CMMC compliance costs for small defense contractors: what the $138K-$285K range covers, worked cost example, and how scope reduction cuts the bill.
Free gap assessment with actionable findings, prioritized by risk. Get your report in minutes.
Start your assessment