top of page

The Big Blog
CMMC Phase 2 Is Paused. CMMC Level 2 Requirements Are Not.
The United States Department of War's July 13 announcement has created understandable confusion across the Defense Industrial Base, but one distinction is critical: The 60-day review pauses the implementation timeline for Phase 2 C3PAO certification requirements; not the cybersecurity requirements for organizations handling Controlled Unclassified Information (CUI). Since the announcement, many defense contractors have understandably asked the same question: Does this mean CM
5 days ago2 min read
CMMC Flow Down Requirements Are About to Reshape the Defense Supply Chain
For years, much of the discussion surrounding Cybersecurity Maturity Model Certification (CMMC) has focused on assessment preparation, documentation, and implementing the technical safeguards required by NIST SP 800-171. Those remain essential components of compliance, but another challenge is quickly emerging that could have an even greater impact on the Defense Industrial Base. As CMMC requirements begin appearing in contracts, organizations will not only need to demonstrat
Jul 76 min read
CMMC Flow Down Responsibilities: Under DFARS 252.204-7021 (NOV 2025) and 32 CFR Part 170
This article summarizes OSC's responsibilities under DFARS and the CMMC Final Rule for flow down requirements. Because an OSC may handle both FCI and CUI and serve as a prime contractor on some contracts or a subcontractor on others, the material is organized around both distinctions. The type of information determines WHAT is required; the contract role determines WHO the obligations are owed to. Authoritative source citations appear throughout, with full references in the f
Jun 247 min read
CMMC Assessment Scope: Why Most Defense Contractors Get It Wrong
Most defense contractors preparing for CMMC Level 2 certification focus on the wrong problem first. They start evaluating GCC High, comparing compliance providers, pricing licenses, or building documentation. Meanwhile, they skip the single activity that determines the cost, complexity, and timeline of their entire CMMC program: Defining their CMMC assessment scope. That was a central theme during a recent episode of Bytes & Brew, where Cape Endeavors CEO Terry McGraw sat dow
Jun 114 min read
CMMC Implementation: Key Insights from the GAO Report on External Risks Facing Defense Contractors
The Government Accountability Office (GAO) recently released a significant report, titled Defense Contractor Cybersecurity: DOD Should Address External Factors That Could Impede Program Implementation (GAO-26-107955). This report provides a detailed assessment of the Department of Defense’s progress on CMMC implementation and highlights external factors that could slow widespread adoption across the defense industrial base. DOD oversees approximately 200,000 companies in the
May 62 min read
CMMC Assessment Challenges in 2026: Insights from Experts on Trends and Pitfalls
In the evolving landscape of CMMC compliance, staying ahead of the requirements is essential. The latest episode of Cape Endeavors' Bytes & Brew podcast features Terry McGraw, CEO of Cape Endeavors, in conversation with Cole French, Director of Cybersecurity Services at Kratos Defense & Security Solutions . As a leading C3PAO and FedRAMP 3PAO, Kratos provides invaluable perspectives on real-world CMMC Level 2 assessments. This discussion highlights trending topics such as ass
Mar 43 min read
Getting Ahead of CMMC Level 2: How QED Enterprises Turned Early Action into a Competitive Advantage
Executive summary QED Enterprises, Inc. , a Stafford, VA-based government contractor founded in 2007, pursued CMMC Level 2 certification early, well ahead of broad Phase 2 enforcement, after leadership concluded CMMC would become a gating requirement across the defense supply chain. Working with Cape Endeavors, QED built and operationalized an assessment-ready compliance program and achieved CMMC Level 2 certification with a perfect score, demonstrating full implementation of
Feb 163 min read
bottom of page
