December 1, 2025
Industry
Lockheed Martin: Suppliers Must Update CMMC Status in Exostar
Lockheed Martin required all active suppliers to submit their CMMC status via a Cybersecurity Compliance Attestation (CCA) in Exostar. Suppliers handling sensitive information with Moderate or Significant risk ratings should complete their CCRA questionnaire and conduct a CMMC readiness assessment. Cybersec Investments provides CMMC and SCF assessments to help suppliers build a clear compliance roadmap.
November 12, 2025
Event
Fernando Machado Provides Insights on CMMC and Federal Cybersecurity at The Federal Cyber Certification Series
Fernando Machado, CISSP, CISM, CCA, and CCP delivered a presentation covering CMMC and federal cybersecurity compliance — addressing how requirements impact contractors and subcontractors handling CUI, aligning organizational practices with federal standards, and navigating the evolving cybersecurity landscape.
November 10, 2025
Industry
Department of Defense Finalizes CMMC Rule, Making Certification Mandatory for New Contracts
The DoD officially published the final rule for CMMC under 48 CFR, integrating it into federal acquisition regulations. CMMC certification is now a mandatory requirement for new contracts involving CUI, marking a significant milestone in federal cybersecurity standards. Cybersec Investments performs accredited CMMC Level 2 and SCF assessments in alignment with the new requirements.
November 5, 2025
Industry
Elbit Systems of America Issues Supplier Cybersecurity Notice
Elbit America released an important communication to its supplier community: if business requirements necessitate sharing CUI with a supplier, that supplier will be required to achieve CMMC Level 2 certification as defined in CFR § 170.17. Non-COTS technology suppliers must immediately conduct a Level 1 self-assessment and affirmation within the Supplier Performance Risk System (SPRS).
November 3, 2025
Company
Kampi Components Co., Inc. Achieves CMMC Level 2 Certification Following Assessment by Cybersec Investments
Cybersec Investments, a C3PAO, recently completed a CMMC Level 2 certification assessment for Kampi Components Co., Inc. The certification confirms that Kampi Components meets the cybersecurity standards required under CMMC 2.0 Level 2 and DFAR 252.204-7021 for safeguarding CUI within the DIB.
October 28, 2025
Event
Fernando Machado Speaks at TechNet Indo-Pacific 2025 – Honolulu, HI
Managing Principal & CISO Fernando Machado, CISSP, CISM, CCA, CCP, spoke at TechNet Indo-Pacific 2025 in Honolulu, Hawaii — sharing his perspective on cybersecurity and compliance within the DIB. Nicole and Krystiana from the Cybersec Investments team attended alongside Fernando, connecting with peers dedicated to strengthening cybersecurity across the industry.
October 27, 2025
Industry
CMMC Compliance Requirements for RTX Suppliers
RTX required all suppliers supporting applicable DoD contracts to maintain an active CMMC certification with final DFARS clause 252.204-7021 effective November 10, 2025. Suppliers must report certification status in the DoD SPRS, maintain six years of evidence, and keep annual registrations current. Level 1 requires full implementation of 15 controls; Levels 2 & 3 protect CUI with POA&M accepted for certain requirements but must be closed within 180 days.
October 21, 2025
Event
Space Coast Contracting Summit 2025 – Days 1 & 2 Recap
Cybersec Investments sponsored the 2025 Space Coast Contracting Summit at Patrick Space Force Base, FL. Managing Principal & CISO Fernando Machado presented "CMMC Unraveled," and the Cybersec Investments booth served as a hub for industry conversation. Director of Client Engagement Nicole Machado and Contracts Specialist Krystiana Bouchard represented the company throughout both days.
October 16, 2025
Event
Fernando Machado Speaks at CS5 East 2025
Fernando Machado, CISSP, CISM, CCA, CCP, represented Cybersec Investments as a featured speaker at CS5 East 2025 in National Harbor, MD — a premier event bringing together CMMC professionals, cybersecurity leaders, and Defense Industrial Base (DIB) stakeholders to share knowledge on compliance and critical infrastructure protection.
October 14, 2025
Media
ND-ISAC C3PAO Shopping Guide: A Must-Read for SMBs Seeking CMMC Compliance
Cybersec Investments shared the ND-ISAC C3PAO Shopping Guide for Small and Medium-Sized Businesses, designed to help SMBs choose a certified CMMC Third-Party Assessment Organization. The guide provides key tips, questions to ask, and best practices for a successful CMMC Level 2 assessment.
October 10, 2025
Industry
Leonardo DRS Issues Supplier Letter on CMMC 2.0 Rollout
Leonardo DRS released a notice to suppliers about upcoming CMMC 2.0 requirements appearing in select DoD contracts on November 10, 2025. Suppliers with the DFARS 252.204-7012 clause should anticipate a CMMC Level 2 (C3PAO Certified) requirement within two years. Leonardo DRS recommended suppliers close open POAM items, maintain a NIST 800-171 score of 110/110, and engage with authorized C3PAOs through the CyberAB Marketplace.
October 8, 2025
Event
Fernando Machado Speaks on CMMC Compliance at NDIA Tampa Bay
Managing Principal & CISO Fernando Machado participated in a high-profile panel at the NDIA Tampa Bay event discussing CMMC compliance and cybersecurity readiness for the defense industrial base. Fernando and Michael Brooks, CISSP, PMP, MBA shared actionable insights on enhancing cybersecurity maturity, implementing CMMC best practices, and preparing for evolving compliance requirements.
September 29, 2025
Industry
Lockheed Martin Taking Steps to Prepare Suppliers for CMMC Level 2
Lockheed Martin moved to ensure suppliers are prepared for CMMC Level 2 with an effective date of November 9, 2025. Suppliers with Moderate or Significant risk ratings in Exostar's CCRA should complete or update their questionnaire, close NIST 800-171 gaps, and conduct a CMMC readiness assessment. Cybersec Investments provides CMMC and SCF assessments to help suppliers evaluate readiness and build a clear compliance roadmap.
September 26, 2025
Industry
Boeing Issues Supplier Update on CMMC Compliance
Boeing released an official letter to suppliers outlining expectations for CMMC compliance. The notice emphasizes that protecting Controlled Unclassified Information (CUI) is essential and that suppliers must demonstrate CMMC readiness to remain eligible for future contracts. Cybersec Investments performs independent CMMC and SCF assessments to help organizations measure compliance posture and prepare for upcoming contract requirements.
September 24, 2025
Company
Advanced Space Achieves CMMC Level 2 Certification
Advanced Space achieved CMMC Level 2 certification following an assessment by Cybersec Investments. The certification confirms the company meets established cybersecurity standards for handling CUI and FCI under CMMC 2.0 Level 2 and DFAR 252.204-7021.
September 22, 2025
Company
Cybersec Investments Surpasses 50 CMMC Assessments!
Cybersec Investments officially completed over 50 CMMC assessments — a milestone reflecting the trust clients place in the team and dedication to guiding organizations through their CMMC readiness journey. Looking ahead: the team remains committed to delivering top-quality CMMC and SCF assessments, helping organizations stay ahead of requirements and confidently demonstrate readiness.
September 10, 2025
Industry
CMMC Launches: What Businesses Need to Know
The Department of Defense officially rolled out the CMMC program with the DFARS rule published in the Federal Register. Phase 1 starts November 10, 2025. Project Spectrum provides free resources — training, self-assessments, and guidance from cybersecurity experts — to help small and mid-sized defense supply chain companies prepare.
September 10, 2025
Industry
CMMC Final Rule Published – Effective November 10, 2025
The DoD officially published the final DFARS rule integrating CMMC into federal contracts. Key details: published September 10, 2025; effective November 10, 2025; phased rollout across contracts; affects all contractors handling FCI or CUI. Organizations should conduct a readiness assessment, build a compliance roadmap, and prepare for phased implementation.
July 23, 2025
Event
Fernando Machado Speaks at 2025 National HUBZone Conference
Managing Principal & CISO Fernando Machado spoke at the 2025 National HUBZone Conference, hosted by the HUBZone Contractors National Council. Fernando joined the panel "The CMMC HUBZone: The Small Business Guide to Navigating Compliance." Team members Clay Mathews and Krystiana Bouchard also attended, representing Cybersec Investments among professionals dedicated to strengthening compliance in the federal space.
July 22, 2025
Industry
48 CFR CMMC Rule Sent to Office of Management and Budget for Review
The 48 CFR rule, a critical regulation tied to CMMC, was officially sent to the OMB for review — signaling the final stages of rulemaking before CMMC becomes enforceable across DoD contracts. Once OMB completes review and the rule is published in the Federal Register, CMMC requirements will start appearing in new solicitations impacting contractors working with CUI.
July 17, 2025
Company
Cybersec Investments Named Official SCF 3PAO
Cybersec Investments is now an officially certified SCF Third-Party Assessment Organization (3PAO) under the Cyber AB. This designation allows the team to conduct formal SCF and CMMC assessments, helping defense contractors meet compliance with clarity, credibility, and confidence.
June 30, 2025
Industry
Lockheed Martin Press Release to Suppliers on CMMC Assessment
Lockheed Martin released a letter to their supply chain emphasizing the importance of getting in line for a CMMC Assessment. Defense contractors in the Lockheed Martin supply chain should act now to ensure compliance and avoid supply chain disruptions.
Read the Lockheed Martin release →
June 26, 2025
Company
Cybersec Investments Passes DIBCAC Assessment
Cybersec Investments officially passed their Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) assessment — an important step in continued growth as a trusted C3PAO. The team remains focused on delivering high-quality support to the defense industrial base.
June 10, 2025
Company
Cybersec Investments Welcomes Five New Team Members
Cybersec Investments is excited to welcome five new professionals to the growing team: Ryan Gonzalez (CMMC Certified Assessor), Sawyer Jones (CMMC Certified Assessor), James Lancaster (CMMC Certified Assessor), Cristal Rodriguez (Client Success Specialist), and Dan Labus (CMMC Certified Assessor). Each brings valuable expertise and a commitment to supporting organizations across the defense industrial base.
June 6, 2025
Company
Cybersec Investments Completes 25 CMMC Assessments
In just a few short months since beginning CMMC assessments, Cybersec Investments completed 25 assessments for organizations in the defense industrial base — reflecting the team's focus, precision, and commitment to supporting contractors through every step of the compliance process.
May 21, 2025
Event
Fernando Machado Speaks at CEIC West – Las Vegas
Fernando Machado, Managing Principal & CISO, spoke at CEIC West in Las Vegas, where industry leaders and government professionals gathered to discuss CMMC, compliance, and the future of defense cybersecurity.
May 7, 2025
Event
Fernando Machado Speaks at CS2 Reston
Managing Principal & CISO Fernando Machado spoke at CS2 Reston — a key event focused on cybersecurity and compliance in the defense industrial base, hosted by Summit 7. The event brought together leaders across the industry to share CMMC updates and best practices for navigating DoD requirements.
May 5, 2025
Event
Fernando Machado Speaks at CMMC Day
Managing Principal & CISO Fernando Machado joined leaders across the industry for a full day of discussions centered on compliance, implementation, and what's next for the CMMC ecosystem.
April 29, 2025
Event
Fernando Machado Speaks at RSA Conference – San Francisco
Managing Principal & CISO Fernando Machado had the honor of speaking at the RSA Conference in San Francisco. His session, "Turning Breaches into Best Practices," focused on real-world lessons from security incidents and how to use them to strengthen future cyber resilience.
February 27, 2025
Event
Fernando Machado Speaks at CUI-CON – Tampa, FL
Fernando Machado spoke at CUI-CON in Tampa, FL on February 27–28, 2025, held at the Tampa Airport Marriott. He joined other industry leaders to support DoD contractors in implementing NIST SP 800-171 and preparing for CMMC assessments.
January 3, 2025
Company
Cybersec Investments Now an Authorized CMMC Third Party Assessment Organization (C3PAO)
Cybersec Investments received official C3PAO authorization — a milestone allowing the team to perform accredited CMMC Third Party Assessments for defense contractors seeking certification.