top of page

The Big Blog
CMMC Phase 2 Is Paused. CMMC Level 2 Requirements Are Not.
The United States Department of War's July 13 announcement has created understandable confusion across the Defense Industrial Base, but one distinction is critical: The 60-day review pauses the implementation timeline for Phase 2 C3PAO certification requirements; not the cybersecurity requirements for organizations handling Controlled Unclassified Information (CUI). Since the announcement, many defense contractors have understandably asked the same question: Does this mean CM
Jul 153 min read
How Fitz-Thors Achieved CMMC Level 2, Gained a Competitive Edge, and Satisfied Flow-Down Requirements Along the Way
When a prime contractor calls and says, "we need your manufacturing capacity, and we need you CMMC certified," most subcontractors hear a burden. Fitz-Thors heard an opportunity. The Alabama-based engineering and manufacturing firm was newer to the defense space than most. Ownership had long wanted to move into defense contracting, and when they finally committed, they did something a lot of small subcontractors don't: they decided to get ahead of the compliance curve instead
Sep 86 min read
In a Cyber-Fraud CID, the Government Assumes the Worst. The Whole Case Is Proving Otherwise.
Why the decisive battle in a Civil Cyber-Fraud Initiative matter is evidentiary, not legal, and why most defense contractors can't fight it alone. When a defense contractor receives a Civil Investigative Demand tied to the Department of Justice's Civil Cyber-Fraud Initiative, the instinct in the room is to reach for the legal argument. Was the cybersecurity requirement actually material to payment? Was any misrepresentation knowing? Does the implied-certification theory hold
Aug 255 min read
A Secure Safe Doesn't Help if the Valuables Aren't Inside It: The Case for CUI Spillage Management
CMMC has become very good at asking organizations to prove that their declared CUI environment is properly secured. It is far less effective at proving the assumption on which the entire assessment depends: Is the organization's CUI actually where they say (or think) it is? The Fundamental Problem CMMC begins with a declared assessment scope and CUI boundary. 800-171 is pretty clear, scope is wherever you process, store and transmit CUI Assessors then evaluate whether appropr
Aug 183 min read
Cape Endeavors Welcomes Cybersecurity Leader Barry Hensley as Executive Advisor
Cape Endeavors has welcomed cybersecurity leader Barry Hensley as Executive Advisor, bringing nearly four decades of military cyber operations, enterprise security, threat intelligence, and executive risk management experience. Hensley will help guide Cape Endeavors’ strategy for protecting Controlled Unclassified Information, reducing cyber risk, and helping Defense Industrial Base organizations navigate evolving federal cybersecurity requirements.
Aug 112 min read
We've Seen This Movie Before: What Sarbanes-Oxley Tells Us About the CMMC Pause
Terrence McGraw Chief Executive Officer @ Cape Endeavors Inc | CMMC Compliance Experts | CMMC L2/3 Compliant Enclaves | CUI Scanning | Security Operations | Incident Response | vCISO consulting In 2004, serious people were certain Sarbanes-Oxley would destroy American capital markets. The objections to Section 404 went like this: compliance costs came in far above the original estimates, there weren't enough qualified auditors to meet demand, the burden fell hardest on small
Jul 274 min read
Defense Supply Chain Due Diligence: Vetting Subcontractors Under NIST 800-161
Supply chain security remains a critical challenge for organizations operating in the defense industrial base and other regulated sectors. Cyber threats, foreign influence, counterfeit components, and weak cybersecurity practices at any tier can compromise sensitive information and mission systems. Effective management of these risks requires both rigorous assessment of suppliers and the disciplined contractual transfer of requirements, commonly known as flow-down. NIST Speci
Jul 225 min read
How Flow-Down Requirements Will Reshape the Defense Supply Chain
For years, much of the discussion surrounding Cybersecurity Maturity Model Certification (CMMC) has focused on assessment preparation, documentation, and implementing the technical safeguards required by NIST SP 800-171. Those remain essential components of compliance, but another challenge is quickly emerging that could have an even greater impact on the Defense Industrial Base. As CMMC requirements begin appearing in contracts, organizations will not only need to demonstrat
Jul 76 min read
bottom of page
