With the 48 CFR CMMC rule published in the Federal Register and now effective on November 10th, 2025, many defense contractors are seeking CMMC L2 C3PAO assessments to be ready to receive new contract awards with the requirements. When these Read More
Tag: CMMC
Assessing the Assessor – What can you expect as an OSC?
Our DIBCAC re-assessment for the certification we need to remain a C3PAO came at a busy time for Kieri. From November 2024 through February 2025, we nearly doubled in size, from 15 full-time employees to nearly 30 full-time employees with Read More
CMMC 101 – Final Rule Version
The DoD released a “CMMC 101” overview which does a good job of describing the CMMC program at a high level. If you need to review CMMC with your company executives, this might be the best presentation to use. Of Read More
32CFR Final Rule Published – CMMC goes live!
On October 15, 2024, the Federal Register was updated with the CMMC Final Rule (32CFR). This rule will be fully effective on December 15, 2024. Link to Federal Register for CMMC This link goes to the U.S. Government’s Federal Register Read More
Review of CMMC Registered Practitioner Training
This post was originally written in September 2020. It was updated in July 2024. In September 2020, I took the Cyber-AB’s Registered Practitioner training course. We aren’t allowed to reproduce the content, so you won’t learn any secrets from me, Read More
How to become a CMMC assessor or auditor
The latest information about how to become a CMMC auditor or certifier. Registrations are open for assessors, C3PAOs, and CMMC practitioners…
How to get a CMMC Audit or Assessment
You’re in the right place if the US Government or your prime contractor told you that you need to get a CMMC certification. What is CMMC? CMMC is an initialization for the term “Cybersecurity Maturity Model Certification”. This term was Read More
CMMC JSVA program – what you need to know
Some tidbits about CMMC’s Joint Surveillance Voluntary Assessment (JSVA) program that you might not know: JSVA program is intended to train C3PAOs and CMMC Assessors 1) The DoD is essentially using the JSVA program to train and vet our private Read More
CMMC assessment? Don’t let pride take you down
Getting CMMC assessed? Some advice.. Listen to your assessor If we say that your evidence isn’t related to the requirement being inspected, or especially the critical words “I think you have misinterpreted this requirement”, instead of getting mad, take a Read More
CMMC Rule links to text (with December 26 content)!
Here are links to the text of the CMMC Proposed Rule: 32 CFR (CMMC Program) Downloadable PDF of Federal Register text (this version has page numbers): https://public-inspection.federalregister.gov/2023-27280.pdf Federal Register home page for CMMC and comments: https://www.federalregister.gov/documents/2023/12/26/2023-27280/cybersecurity-maturity-model-certification-cmmc-program Docket Information (the rule Read More
Why so few Defense contractors are compliant
??? ???? ???? ?? ???? ? ??????? ?? ?? ???????? ?? ???? ???’? ??? ????? One year? Two? Three? Let me tell you a story about how a system of perverse incentives caused our current cybersecurity situation in the Defense Read More
Podcast – increasing the likelihood of passing CMMC assessments
This podcast by Omnistruct features Amira Armond, John Riley, and George Usi. Recorded in May-June 2023. They discuss the basics of CMMC, the “hardest” requirement (FIPS of course), the aspects that contractors have the most difficulty with, and the status Read More
CMMC Breaking News – July 25, 2023
Today we had two big events in #CMMC and US Federal Contractor Cybersecurity. The Rule for CMMC moved to the Office of Management and Budget. That means a timer has started, 90 days or less, for the review to complete. Expect the Read More
3.13.11 FIPS 140-2 Validated Cryptography
It is time, finally, to talk about the #1 “Other than Satisfied” requirement in 800-171, per historic DIBCAC assessments. ? ? ? ???? 140-2 ????????? ??????? ? ? ? Listen up – I’m going to tell you how to succeed Read More
3.5.3 Multifactor Authentication
Multifactor Authentication: #2 of the top 10 “Other than Satisfied Requirements” for 800-171 assessments by DIBCAC. ??? ??????????? ?????????????? ??? ????? ??? ??????? ?????? ?? ?????????? ???????? ??? ??? ??????? ?????? ?? ???-?????????? ????????. My theory is that most of Read More
What are Spot Checks for?
???? ?????????? ???? ?????? “?? ??????????’? ????-????? ???????? ????????, ??????????, ??? ????????? ????????????? ?? ????? ???????? ????? ????????? ????? ????? ??????, ??? ???????? ??? ??????? ? ??????? ???? ????? ?? ???????? ?????. ??? ??????? ???? ?????(?) ????? ??? ?????????? ???????? ??? Read More
3.14.1 Identify, report, correct system flaws
Continuing the Top 10 “Other than Satisfied Requirements” for 800-171 assessments by DIBCAC. “????????, ??????, ??? ??????? ??????????? ??? ??????????? ?????? ????? ?? ? ?????? ??????.” This is the third most “Other than Satisfied” requirement. 3.14.1 is both misunderstood and Read More
3.11.1 Periodically assess the risk to organizational operations
3.11.1 ???????????? ?????? ????…This is the fourth-most “Other than satisfied” #CMMC requirement. Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or Read More
3.11.2 Scan for Vulnerabilities
Scan for vulnerabilities….This the fifth-most “Other than satisfied” #CMMC requirement with an 18% fail rate. 3.11.2 ???? ??? ??????????????? ?? ?????????????? ??????? ??? ???????????? ???????????? ??? ???? ??? ??????????????? ????????? ????? ??????? ??? ???????????? ??? ??????????. “?????????????? ???????”…This is an example of Read More
3.3.3 Review and Update Logged Events
This is #6 in the series of most common failed requirements as assessed by the DoD’s Cyber Assessment Center. This requirement is another example of misunderstanding == failing (alongside the other top 10 requirements). Most people do not understand what Read More
3.3.4 Audit Logging Process Failure
Continuing the Top 10 Failed Requirements for 800-171! Onward to #7: 3.3.4 “????? ?? ??? ????? ?? ?? ????? ??????? ??????? ???????.” Sit with me while I tell a story… ?? ???????????? ????????? ???? ???? ???? ???????? ??????? ?????????? ??????? Read More
3.3.5 Correlate Audit Processes
NIST SP 800-171 3.3.5 ????????? ????? ?????? ??????, ????????, ??? ????????? ????????? ??? ????????????? ??? ???????? ?? ??????????? ?? ????????, ????????????, ??????????, ?? ??????? ????????. This is the 8th most likely requirement to be “other than satisfied” by defense contractors, according Read More
CMMC Scoping for Level 2
This video is provided by Amira Armond and Jil Wright (CMMC Provisional Assessors and Provisional Instructors) from Kieri Solutions, an Authorized C3PAO. Topics discussed in the video are: This content is way more than the CCP course blueprint covers and more in-depth than what is Read More
CMMC Scoping for Level 1
This video is provided by Amira Armond and Jil Wright (CMMC Provisional Assessors and Provisional Instructors) from Kieri Solutions, an Authorized C3PAO. Topics included are: Enjoy, and don’t forget to subscribe to our YouTube channel for lots of other CMMC Read More
3.6.3 Test the Organizational Incident Response Capability
This was originally posted on LinkedIn. Check the original post and community discussion here! On to the next requirement! 3.6.3 ???? ??? ?????????????? ???????? ???????? ??????????. This is post #5 in my series analyzing the top ten failed / misunderstood Read More
3.4.1 Establish / Maintain Baseline Configurations
This series reviews the top failed (misunderstood) 800-171 and CMMC requirements. Originally posted on LinkedIn – check the start of series here for community conversation and thoughts! 3.4.1 ?????????/???????? ???????? ?????????????? This one is both commonly misunderstood and difficult to implement, even though Read More
When is a FIPS Validated Module required?
This video from Amira Armond and Jillian Wright (both Kieri Solutions Provisional Assessors and Instructors), explains when FIPS 140-2 validated modules are required to be used by CMMC Level 2 / NIST SP 800-171. It also explains when FIPS is Read More
Lessons learned from two (three?) DIBCAC assessments
On behalf of CMMCAudit.org, I’m excited to share this interview with Jake Williams about his lessons learned from two DIBCAC assessments of DFARS 252.204-7012 and NIST SP 800-171 compliance. This video is packed with actionable information about what to expect during assessments. Read More
CMMC Scope – are you ready for an assessment?
This article gives examples and explanations of how to identify your CMMC scope to an assessor when you are planning…
Does CMMC enforce FedRAMP and other CUI protections?
Will CMMC assessors stick to just the CMMC requirements or will they review your compliance to CUI-specified handling and other regulations?






















