top of page

The Big Blog
A Secure Safe Doesn't Help if the Valuables Aren't Inside It: The Case for CUI Spillage Management
CMMC has become very good at asking organizations to prove that their declared CUI environment is properly secured. It is far less effective at proving the assumption on which the entire assessment depends: Is the organization's CUI actually where they say (or think) it is? The Fundamental Problem CMMC begins with a declared assessment scope and CUI boundary. 800-171 is pretty clear, scope is wherever you process, store and transmit CUI Assessors then evaluate whether appropr
Aug 183 min read
CMMC Assessment Scope: Why Most Defense Contractors Get It Wrong
Most defense contractors preparing for CMMC Level 2 certification focus on the wrong problem first. They start evaluating GCC High, comparing compliance providers, pricing licenses, or building documentation. Meanwhile, they skip the single activity that determines the cost, complexity, and timeline of their entire CMMC program: Defining their CMMC assessment scope. That was a central theme during a recent episode of Bytes & Brew, where Cape Endeavors CEO Terry McGraw sat dow
Jun 114 min read
The Great Heist and the “Self-Attestation Gap”: Why CMMC Isn’t Random Bureaucracy
David R. Shedd didn’t come to the conversation as a commentator. He came as a former Deputy Director and Acting Director of the Defense Intelligence Agency, someone who spent a career watching adversaries play the long game. In a recent virtual discussion with CSIS’s Dr. Seth G. Jones, Shedd walked through the core argument of his new book, The Great Heist: China’s Epic Campaign to Steal America’s Secrets : over the last few decades, China has executed a structured campaign
Jan 214 min read
THE DARK SIDE OF DIY CMMC ENCLAVES
Why Self-Built CMMC Enclaves Fail In the world of defense contracting, achieving compliance with the Cybersecurity Maturity Model Certification (CMMC) is essential for handling Controlled Unclassified Information (CUI). A key component in this process is the CMMC enclave—a secure, isolated environment designed to protect CUI from unauthorized access and cyber threats. However, many organizations, particularly small and medium-sized enterprises (SMEs), opt to build their own C
Dec 6, 20256 min read
CUI vs ITAR(and EAR): Differences, Similarities, and the Critical Role of Export Controlled Information (ECI)
In the defense and national-security world, few compliance topics create more confusion—or more unintentional violations—than Controlled Unclassified Information (CUI) and the International Traffic in Arms Regulations (ITAR). Both involve sensitive information. Both impose strict requirements. Both can burn your organization to the ground if mishandled.
Nov 24, 20255 min read
bottom of page
