Cybersecurity Insights
CMMC & Cybersecurity Blog
Practical guidance on CMMC compliance, NIST 800-171, CUI handling, and DoD cybersecurity — written by assessors who do this every day.
CMMC Compliance Requirements for RTX Suppliers
RTX required all suppliers supporting applicable DoD contracts to maintain an active CMMC certification with final DFARS clause 252.204-7021 effective November 10, 2025. Suppliers must report certification status in the DoD SPRS, maintain six…
Read ArticleLeonardo DRS released a notice to suppliers about upcoming CMMC 2.0 requirements appearing in select DoD contracts on November 10, 2025. Suppliers…
Lockheed Martin moved to ensure suppliers are prepared for CMMC Level 2 with an effective date of November 9, 2025. Suppliers with…
Boeing released an official letter to suppliers outlining expectations for CMMC compliance. The notice emphasizes that protecting Controlled Unclassified Information (CUI) is…
The Department of Defense officially rolled out the CMMC program with the DFARS rule published in the Federal Register. Phase 1 starts…
The DoD officially published the final DFARS rule integrating CMMC into federal contracts. Key details: published September 10, 2025; effective November 10,…
The 48 CFR rule, a critical regulation tied to CMMC, was officially sent to the OMB for review — signaling the final…
Lockheed Martin released a letter to their supply chain emphasizing the importance of getting in line for a CMMC Assessment. Defense contractors…
CMMC 2.0 completed its 60-day Congressional Review period without any changes. Rulemaking is now complete and the new program is in effect.…
The Department of Defense (DoD) 48 CFR proposed CMMC rule was published in the Federal Register. Comments on the proposed rule should…