top of page

The Big Blog
CMMC Phase 2 Is Paused. CMMC Level 2 Requirements Are Not.
The United States Department of War's July 13 announcement has created understandable confusion across the Defense Industrial Base, but one distinction is critical: The 60-day review pauses the implementation timeline for Phase 2 C3PAO certification requirements; not the cybersecurity requirements for organizations handling Controlled Unclassified Information (CUI). Since the announcement, many defense contractors have understandably asked the same question: Does this mean CM
Jul 153 min read
We've Seen This Movie Before: What Sarbanes-Oxley Tells Us About the CMMC Pause
Terrence McGraw Chief Executive Officer @ Cape Endeavors Inc | CMMC Compliance Experts | CMMC L2/3 Compliant Enclaves | CUI Scanning | Security Operations | Incident Response | vCISO consulting In 2004, serious people were certain Sarbanes-Oxley would destroy American capital markets. The objections to Section 404 went like this: compliance costs came in far above the original estimates, there weren't enough qualified auditors to meet demand, the burden fell hardest on small
Jul 274 min read
Defense Supply Chain Due Diligence: Vetting Subcontractors Under NIST 800-161
Supply chain security remains a critical challenge for organizations operating in the defense industrial base and other regulated sectors. Cyber threats, foreign influence, counterfeit components, and weak cybersecurity practices at any tier can compromise sensitive information and mission systems. Effective management of these risks requires both rigorous assessment of suppliers and the disciplined contractual transfer of requirements, commonly known as flow-down. NIST Speci
Jul 225 min read
How CMMC Flow-Down Will Reshape the Defense Supply Chain
For years, much of the discussion surrounding Cybersecurity Maturity Model Certification (CMMC) has focused on assessment preparation, documentation, and implementing the technical safeguards required by NIST SP 800-171. Those remain essential components of compliance, but another challenge is quickly emerging that could have an even greater impact on the Defense Industrial Base. As CMMC requirements begin appearing in contracts, organizations will not only need to demonstrat
Jul 76 min read
CMMC Flow-Down Requirements: Under DFARS 252.204-7021 (NOV 2025) and 32 CFR Part 170
Under CMMC, a prime contractor must flow the applicable safeguarding and certification requirements down to every subcontractor, at any tier, whose systems will process, store, or transmit Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). Suppliers that handle neither, and subcontracts solely for commercially available off-the-shelf (COTS) items, are outside the flow-down. Which requirements flow depends on the information type: FCI triggers the
Jun 2411 min read
Beyond Compliance: What NIST's Victoria Pillitteri Wants Defense Contractors to Understand About CMMC and NIST SP 800-171
For many organizations in the Defense Industrial Base (DIB), conversations about CMMC and NIST SP 800-171 often revolve around assessments, documentation, and compliance requirements. Yet according to Victoria Pillitteri, Supervisory Computer Scientist at NIST and co-author of NIST SP 800-171 and NIST SP 800-172, that perspective misses the larger purpose behind the framework. During a recent episode of Bytes & Brew, Pillitteri joined Cape Endeavors CEO Terry McGraw to discus
Jun 238 min read
CMMC Assessment Scope: Why Most Defense Contractors Get It Wrong
Most defense contractors preparing for CMMC Level 2 certification focus on the wrong problem first. They start evaluating GCC High, comparing compliance providers, pricing licenses, or building documentation. Meanwhile, they skip the single activity that determines the cost, complexity, and timeline of their entire CMMC program: Defining their CMMC assessment scope. That was a central theme during a recent episode of Bytes & Brew, where Cape Endeavors CEO Terry McGraw sat dow
Jun 114 min read
Cape Endeavors Partners with Teramis to Deliver Precise CUI Discovery and Segmentation for Defense Contractors
Executive Summary Cape Endeavors, a leading provider of managed CMMC secure enclaves for the Defense Industrial Base (DIB), partnered with Teramis to solve one of the most persistent challenges in CMMC compliance: accurately identifying and segmenting Controlled Unclassified Information (CUI). By integrating Teramis’ precision CUI discovery and continuous monitoring capabilities into its core offerings, Cape Endeavors transformed CUI identification from a manual, assumption-d
May 122 min read
bottom of page
