CMMC Resources

Guides for Defense Contractors

Practical CMMC 2.0 compliance guides from Dragonfli Group — a CMMC Registered Practitioner Organization with 18 years of federal cybersecurity experience.

Conditional CertificationPOA&MSPRS Score

CMMC Conditional Certification: What an 88 Gets You, and the 180-Day Clock

You do not need a perfect 110 to win the work. How conditional Level 2 certification works, why 88 is the line, which gaps a POA&M can and cannot cover under 32 CFR 170.21, and the 180-day clock to final status.

June 28, 2026·8 min readRead article →
False Claims ActCMMC EnforcementNIST 800-171

CMMC and the False Claims Act: What the DOJ Cyber-Fraud Crackdown Means

The DOJ Civil Cyber-Fraud Initiative uses the False Claims Act against contractors who misrepresent NIST SP 800-171 compliance or inflate their SPRS score. Here is how enforcement works, the whistleblower risk, recent settlements, and how to protect your company.

June 19, 2026·9 min readRead article →
CUICMMC ScopingCMMC Level 2

What Is CUI? How to Tell If Your Contract Triggers CMMC Level 2

One word decides whether you face 17 cybersecurity practices or all 110: CUI. Learn what Controlled Unclassified Information is, how it differs from FCI, how to tell if you handle it, and how to scope your CMMC environment.

June 19, 2026·8 min readRead article →
SSPPOA&MCMMC Documentation

SSP and POA&M Explained: The Two Documents CMMC Hinges On

Your System Security Plan and Plan of Action & Milestones are the backbone of CMMC. Learn what each is, why no SSP means no SPRS score, and exactly what gaps a POA&M can cover under 32 CFR 170.21.

June 19, 2026·9 min readRead article →
CMMC DeadlineCMMC TimelinePhased Rollout

CMMC Deadlines 2026: When Does Your Contract Actually Require It?

CMMC is live — the 48 CFR rule took effect November 10, 2025. Here is the four-phase rollout through 2028, when C3PAO certification becomes a condition of award, and why readiness takes longer than you think.

June 19, 2026·8 min readRead article →
C3PAOCMMC Level 2Assessment Prep

How to Prepare for a C3PAO Assessment (and Pass the First Time)

A C3PAO will examine, interview, and test your controls against 320 assessment objectives. Here is how the assessment works, the evidence you need, the most common reasons companies fail, and a six-step readiness plan.

June 19, 2026·9 min readRead article →
SubcontractorsFlow-DownCMMC Level 2

Do Subcontractors Need CMMC? How Flow-Down Actually Works

CMMC obligations flow down from primes to subcontractors through DFARS clauses. Learn which CMMC level a subcontractor actually needs, the COTS exception, and exactly what to ask your prime.

June 19, 2026·8 min readRead article →
MFANIST 800-171Access Control

CMMC and MFA: The 5-Point Control You Can’t Fake (IA.L2-3.5.3)

Multi-factor authentication is one of the highest-weight, most-tested CMMC controls. Which accounts need MFA under NIST SP 800-171 3.5.3, how the 5-point partial-credit scoring works, and the coverage gaps that quietly fail assessments.

June 19, 2026·8 min readRead article →
NIST 800-171Rev 3CMMC Compliance

NIST 800-171 Rev 2 vs Rev 3: What CMMC Requires Now (and What’s Coming)

CMMC is assessed against Revision 2 today — a DoD class deviation keeps it in effect until rescinded. What changed in Rev 3 (including ODPs), when the transition is expected, and which version to build for right now.

June 19, 2026·8 min readRead article →
GCC HighCUICMMC Scoping

GCC High, Commercial, or Enclave? Choosing a CUI Environment for CMMC

Do you need GCC High for CMMC? Not always. How DFARS 7012 and FedRAMP requirements shape your cloud choice, when ITAR forces GCC High, and how a CUI enclave shrinks your CMMC scope and cost.

June 20, 2026·8 min readRead article →
DFARS 7012Incident ReportingCMMC

The 72-Hour Rule: Cyber Incident Reporting Under DFARS 252.204-7012

DFARS 7012 requires reporting cyber incidents within 72 hours, preserving forensic images for 90 days, and flowing the duty down to subcontractors. Exactly what the rule requires — and how to be ready before an incident.

June 20, 2026·7 min readRead article →
MSPESPCMMC Scoping

Does My MSP Need to Be CMMC Certified? What the Final Rule Actually Says

The myth that your MSP "being CMMC certified" covers you is wrong on both halves. When an MSP or ESP needs its own assessment, how security providers are scoped, the cloud/FedRAMP path, and why the responsibility never leaves you.

June 20, 2026·8 min readRead article →
CMMC 2.0NIST 800-171Compliance

The Complete CMMC 2.0 Compliance Guide for Defense Contractors

Everything you need to know about CMMC 2.0 requirements, the 14 domains, SPRS scoring, C3PAO assessments, and how to prepare your company for certification.

June 7, 2026·12 min readRead article →
SPRS ScoreNIST 800-171DoW Compliance

How to Calculate Your SPRS Score (NIST SP 800-171)

Step-by-step guide to calculating your Supplier Performance Risk System score, applying the DoW methodology, self-reporting in PIEE, and understanding what your score means for contract awards.

June 7, 2026·10 min readRead article →
CMMC Level 1CMMC Level 2CUI vs FCI

CMMC Level 1 vs Level 2: Which Do You Need?

The difference between FCI and CUI, what each CMMC level actually requires, how to determine which applies to your DoW contracts, and what self-attestation vs. C3PAO assessment means for your business.

June 7, 2026·10 min readRead article →
CMMC CostC3PAOBudget Planning

How Much Does CMMC Certification Cost? (2026)

Complete breakdown of CMMC 2.0 compliance costs: readiness assessments, RPO consulting, technical remediation, C3PAO assessment fees, and annual maintenance — with real numbers and what drives them up or down.

June 7, 2026·11 min readRead article →