CMMC Research &
Whitepapers
Expert research on CMMC preparation, NIST SP 800-171 implementation, and compliance automation for the defense industrial base
Regulatory update · July 13, 2026
CMMC Phase II is paused. Phase I is not.
The Department suspended the transition to Phase II and pending or future CMMC implementation milestones while it reviews the program. Phase I self-assessments remain in place. During the interim, NIST SP 800-171 Rev. 2 will be enforced through self-assessments and selected government-led assessments, and DFARS 252.204-7012 still requires contractors and subcontractors to safeguard covered defense information.
Featured Research
CMMC-focused research from our team and defense compliance practitioners
NIST 800-171 & CMMC Readiness Playbook: From Gap Assessment to Review-Ready Evidence
Step-by-step guide covering CUI boundary scoping, NIST SP 800-171 control implementation, SSP development, evidence collection, self-assessment, government review, and future certification readiness.
Policy-as-Code for NIST 800-171: Automating Evidence Collection Across 110 Requirements
Technical deep dive into how policy-as-code methodology maps to NIST SP 800-171 control families, with implementation patterns for Azure GCC High and AWS GovCloud environments.
Research Categories
CMMC Preparation
NIST Frameworks
Policy-as-Code
Government Cloud
Defense Compliance
Stay Updated
Get notified when we publish new research and whitepapers
No spam. Unsubscribe at any time.