top of page

The Big Blog
How Fitz-Thors Achieved CMMC Level 2, Gained a Competitive Edge, and Satisfied Flow-Down Requirements Along the Way
When a prime contractor calls and says, "we need your manufacturing capacity, and we need you CMMC certified," most subcontractors hear a burden. Fitz-Thors heard an opportunity. The Alabama-based engineering and manufacturing firm was newer to the defense space than most. Ownership had long wanted to move into defense contracting, and when they finally committed, they did something a lot of small subcontractors don't: they decided to get ahead of the compliance curve instead
Sep 86 min read
CMMC Phase 2 Is Paused. CMMC Level 2 Requirements Are Not.
The United States Department of War's July 13 announcement has created understandable confusion across the Defense Industrial Base, but one distinction is critical: The 60-day review pauses the implementation timeline for Phase 2 C3PAO certification requirements; not the cybersecurity requirements for organizations handling Controlled Unclassified Information (CUI). Since the announcement, many defense contractors have understandably asked the same question: Does this mean CM
Jul 153 min read
How Flow-Down Requirements Will Reshape the Defense Supply Chain
For years, much of the discussion surrounding Cybersecurity Maturity Model Certification (CMMC) has focused on assessment preparation, documentation, and implementing the technical safeguards required by NIST SP 800-171. Those remain essential components of compliance, but another challenge is quickly emerging that could have an even greater impact on the Defense Industrial Base. As CMMC requirements begin appearing in contracts, organizations will not only need to demonstrat
Jul 76 min read
CMMC Flow-Down Requirements: Under DFARS 252.204-7021 (NOV 2025) and 32 CFR Part 170
Under CMMC, a prime contractor must flow the applicable safeguarding and certification requirements down to every subcontractor, at any tier, whose systems will process, store, or transmit Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). Suppliers that handle neither, and subcontracts solely for commercially available off-the-shelf (COTS) items, are outside the flow-down. Which requirements flow depends on the information type: FCI triggers the
Jun 2411 min read
CMMC Assessment Scope: Why Most Defense Contractors Get It Wrong
Most defense contractors preparing for CMMC Level 2 certification focus on the wrong problem first. They start evaluating GCC High, comparing compliance providers, pricing licenses, or building documentation. Meanwhile, they skip the single activity that determines the cost, complexity, and timeline of their entire CMMC program: Defining their CMMC assessment scope. That was a central theme during a recent episode of Bytes & Brew, where Cape Endeavors CEO Terry McGraw sat dow
Jun 114 min read
CMMC Implementation: Key Insights from the GAO Report on External Risks Facing Defense Contractors
The Government Accountability Office (GAO) recently released a significant report, titled Defense Contractor Cybersecurity: DOD Should Address External Factors That Could Impede Program Implementation (GAO-26-107955). This report provides a detailed assessment of the Department of Defense’s progress on CMMC implementation and highlights external factors that could slow widespread adoption across the defense industrial base. DOD oversees approximately 200,000 companies in the
May 62 min read
CMMC Assessment Challenges in 2026: Insights from Experts on Trends and Pitfalls
In the evolving landscape of CMMC compliance, staying ahead of the requirements is essential. The latest episode of Cape Endeavors' Bytes & Brew podcast features Terry McGraw, CEO of Cape Endeavors, in conversation with Cole French, Director of Cybersecurity Services at Kratos Defense & Security Solutions . As a leading C3PAO and FedRAMP 3PAO, Kratos provides invaluable perspectives on real-world CMMC Level 2 assessments. This discussion highlights trending topics such as ass
Mar 43 min read
Getting Ahead of CMMC Level 2: How QED Enterprises Turned Early Action into a Competitive Advantage
Executive summary QED Enterprises, Inc. , a Stafford, VA-based government contractor founded in 2007, pursued CMMC Level 2 certification early, well ahead of broad Phase 2 enforcement, after leadership concluded CMMC would become a gating requirement across the defense supply chain. Working with Cape Endeavors, QED built and operationalized an assessment-ready compliance program and achieved CMMC Level 2 certification with a perfect score, demonstrating full implementation of
Feb 163 min read
bottom of page
