Managed IT and Managed Security · Leesburg, VA

Blog

CMMC Questions, Answered From the Rule Itself.

Short, direct answers for defense contractors and their IT teams. CMMC engagements are delivered by our Compliance Division, Capital Cyber Compliance.

Each answer cites the regulation it comes from and carries the date we last checked it. Threat news is at Capital Cyber News.

CMMC Articles

6 ARTICLES

What Should Your Business Do When an AI Chat Asks You to Paste a Command?

An IT team reported a ChatGPT chat that sent a user to a fake OpenAI check asking them to paste a command into Windows. Endpoint protection stopped it. The three layers that keep a business safe.

Is CMMC Phase 2 Paused, and What Still Applies?

Yes. On 2026-07-13 the Department of War suspended the November 2026 move to CMMC Phase 2. Level 1 and Level 2 self-assessments, SPRS, NIST SP 800-171 Rev 2 and DFARS 252.204-7012 still apply.

What Is the Difference Between CMMC Level 1 and Level 2?

CMMC Level 1 protects Federal Contract Information with the 15 requirements of FAR 52.204-21. Level 2 protects Controlled Unclassified Information with the 110 requirements of NIST SP 800-171 Rev 2. The data in your contract decides which applies.

How Is a CMMC Level 2 Score Calculated?

A CMMC Level 2 score starts at 110 and loses 5, 3 or 1 points for each requirement not met. A conditional status with a POA&M needs at least 80 percent of 110, and the POA&M must close within 180 days.

Can an MSP Help With CMMC, and Is the MSP in Scope?

Yes, and the MSP's services come into your CMMC scope. Under 32 CFR 170.16 an external service provider must be documented in your SSP and its services assessed against all Level 2 requirements. Cloud services that hold CUI need FedRAMP Moderate or equivalent.

What Does DFARS 252.204-7012 Require of a Defense Contractor?

DFARS 252.204-7012 requires adequate security under NIST SP 800-171 for covered defense information, cyber incident reports to DoD within 72 hours, 90 days of image preservation, FedRAMP Moderate equivalence for cloud providers, and flow-down to subcontractors.

Talk it through in 30 minutes.

A call is a conversation, not a pitch. Tell us how your business runs and we will tell you what we would manage.

Looking for CMMC? Our Compliance Division, Capital Cyber Compliance, delivers it.

Under 25 people? Apply for an in-kind cybersecurity grant from Cyber Grants Alliance, a nonprofit. No cost to you.

Book a 30-Minute Call