Register:Blog/Tag3 recordsSHA3-256 chainedhead
sha3:68e39160624b8d1901ad205cd1834fa89675431b5c53b706f77ce5b32bd0b4e2IntactREC 0000HEADsha3-256
238e488f53abf2b29935f1bfb0ea7e8fc9b521f79c9fa102368438b200070178prev:126cfbf35b46RegisterBlogTag: CMMC
Blog entries tagged CMMC
Every blog entry tagged CMMC, newest first. Tags group the register by subject so a reader working one requirement can follow it across entries as the rules change. Each entry is sealed on the date shown and amended in place when it is updated; the full register is at the blog index.
11 entries
REC 0001ENTRIESsha3-256
016dc35e1230091ea7fa78dbea653b2e68254d8bd3036184446b593376b65b24prev:238e488f53abEntries, newest first
- CMMC Phase II Is Suspended: What Defense Contractors Still Have to DoThe Department of War suspended CMMC Phase II on July 13, 2026, but kept Phase I self-assessments, NIST SP 800-171 Rev. 2 enforcement, and DFARS 252.204-7012 obligations in place.
- The $507K LOGZONE Settlement: Your SPRS Score Is Now False Claims Act EvidenceDOJ settled with a defense contractor that posted a 110 SPRS score and later received a -170 government assessment.
- The C3PAO Capacity Math After the CMMC Phase II SuspensionThe Phase II countdown is gone, but C3PAO capacity still matters for contract-specific and voluntary assessment plans.
- CMMC Level 2 Requirements in 2026: The Complete Guide for Defense ContractorsCMMC Phase II is suspended, but the 110-requirement NIST 800-171 Rev. 2 baseline, Phase I self-assessments, and DFARS safeguarding obligations remain active.
- The Safety Sandwich: How PolicyCortex Gives AI Safe Write Access to Cloud EnvironmentsGiving AI autonomous write access to production cloud environments sounds dangerous.
- CMMC Level 2 Compliance Costs: The Complete Breakdown for 2026Most defense contractors budget for the C3PAO assessment and forget about everything else.
- NIST 800-171 Cloud Compliance: The Practical Guide for AWS, Azure, and GCPImplementing NIST 800-171 in cloud environments is fundamentally different from on-premises.
- The Alert Queue That Never Empties: Why CSPM Visibility Isn't EnoughYour CSPM tool is finding everything. Your queue is growing anyway.
- CMMC Phase II Timeline Suspended: What the 60-Day Review ChangesThe Department of War suspended the November 2026 Phase II transition and future milestones.
- The CMMC Level 2 Self-Assessment Trap (And How to Avoid It)Most defense contractors who submit optimistic SPRS scores don't realize they're creating legal exposure, not just compliance risk.
- CMMC 2.0: What Defense Contractors Need to KnowThe CMMC program is officially active with assessments underway.
REC 0002RELATED RECORDSsha3-256
68e39160624b8d1901ad205cd1834fa89675431b5c53b706f77ce5b32bd0b4e2prev:016dc35e1230Related records
Guides and articles describe the work. The evidence that work produces is described in three proof pages and one architecture page.
- proof.state
- Proof of State. What the environment was, as of a date someone else picks: point-in-time records, content hashed and chained.
- proof.change
- Proof of Change. Who or what altered the environment, under what authority, with before and after state hashes.
- proof.agency
- Proof of Agency. What a machine was permitted to do before it acted, what it did, and what would have stopped it.
- architecture
- Architecture. How the chain is built and where it lives: inside your tenant, with no egress of evidence.
Read the entries. Then verify the record they describe.