Register:Blog/Tag3 recordsSHA3-256 chainedhead
sha3:c196b997ec6906d6661322e0a7dfac33107bb1ddd8d6ca9321e2393885444348IntactREC 0000HEADsha3-256
75fc74d49b9d065451e4d806ea251013eb9c76c3c431e76df348401093cadd46prev:1345b2878023RegisterBlogTag: compliance
Blog entries tagged compliance
Every blog entry tagged compliance, newest first. Tags group the register by subject so a reader working one requirement can follow it across entries as the rules change. Each entry is sealed on the date shown and amended in place when it is updated; the full register is at the blog index.
6 entries
REC 0001ENTRIESsha3-256
8a3852d4e7a38c6f3383dc7a612cae24b3316c7dd776d594ea15c2ff3bbeda77prev:75fc74d49b9dEntries, newest first
- CMMC Level 2 Requirements in 2026: The Complete Guide for Defense ContractorsCMMC Phase II is suspended, but the 110-requirement NIST 800-171 Rev. 2 baseline, Phase I self-assessments, and DFARS safeguarding obligations remain active.
- The CMMC Level 2 Self-Assessment Trap (And How to Avoid It)Most defense contractors who submit optimistic SPRS scores don't realize they're creating legal exposure, not just compliance risk.
- NIST 800-171 Rev 3: Key Changes and How to PrepareNIST SP 800-171 Revision 3 brings significant changes to the security requirements for protecting CUI.
- Why Traditional GRC Tools Fall Short for Cloud-Native OrganizationsLegacy GRC platforms were built for on-premise compliance.
- CMMC 2.0: What Defense Contractors Need to KnowThe CMMC program is officially active with assessments underway.
- What Is Autonomous Cloud Governance?Cloud governance has evolved from manual checklists to autonomous platforms that detect, decide, and remediate in real time.
REC 0002RELATED RECORDSsha3-256
c196b997ec6906d6661322e0a7dfac33107bb1ddd8d6ca9321e2393885444348prev:8a3852d4e7a3Related records
Guides and articles describe the work. The evidence that work produces is described in three proof pages and one architecture page.
- proof.state
- Proof of State. What the environment was, as of a date someone else picks: point-in-time records, content hashed and chained.
- proof.change
- Proof of Change. Who or what altered the environment, under what authority, with before and after state hashes.
- proof.agency
- Proof of Agency. What a machine was permitted to do before it acted, what it did, and what would have stopped it.
- architecture
- Architecture. How the chain is built and where it lives: inside your tenant, with no egress of evidence.
Read the entries. Then verify the record they describe.