Register:Blog/Tag3 recordsSHA3-256 chainedhead
sha3:ede78584589b47a9cb9202ab401fa6b4e4af09301402ed5cec10ebe30186fc09IntactREC 0000HEADsha3-256
86f372fee9a90f6a538e721bb27995e68c6a98f21e7cc739247bdba4b701a1aaprev:91d799c5429bRegisterBlogTag: defense contractors
Blog entries tagged defense contractors
Every blog entry tagged defense contractors, newest first. Tags group the register by subject so a reader working one requirement can follow it across entries as the rules change. Each entry is sealed on the date shown and amended in place when it is updated; the full register is at the blog index.
7 entries
REC 0001ENTRIESsha3-256
5faaac4ddacc948898f30bfa7656dc0768400311bcd31db4c9dbd10ec7edbc77prev:86f372fee9a9Entries, newest first
- The C3PAO Capacity Math After the CMMC Phase II SuspensionThe Phase II countdown is gone, but C3PAO capacity still matters for contract-specific and voluntary assessment plans.
- CMMC Level 2 Requirements in 2026: The Complete Guide for Defense ContractorsCMMC Phase II is suspended, but the 110-requirement NIST 800-171 Rev. 2 baseline, Phase I self-assessments, and DFARS safeguarding obligations remain active.
- CMMC Level 2 Compliance Costs: The Complete Breakdown for 2026Most defense contractors budget for the C3PAO assessment and forget about everything else.
- NIST 800-171 Cloud Compliance: The Practical Guide for AWS, Azure, and GCPImplementing NIST 800-171 in cloud environments is fundamentally different from on-premises.
- CMMC Phase II Timeline Suspended: What the 60-Day Review ChangesThe Department of War suspended the November 2026 Phase II transition and future milestones.
- The CMMC Level 2 Self-Assessment Trap (And How to Avoid It)Most defense contractors who submit optimistic SPRS scores don't realize they're creating legal exposure, not just compliance risk.
- CMMC 2.0: What Defense Contractors Need to KnowThe CMMC program is officially active with assessments underway.
REC 0002RELATED RECORDSsha3-256
ede78584589b47a9cb9202ab401fa6b4e4af09301402ed5cec10ebe30186fc09prev:5faaac4ddaccRelated records
Guides and articles describe the work. The evidence that work produces is described in three proof pages and one architecture page.
- proof.state
- Proof of State. What the environment was, as of a date someone else picks: point-in-time records, content hashed and chained.
- proof.change
- Proof of Change. Who or what altered the environment, under what authority, with before and after state hashes.
- proof.agency
- Proof of Agency. What a machine was permitted to do before it acted, what it did, and what would have stopped it.
- architecture
- Architecture. How the chain is built and where it lives: inside your tenant, with no egress of evidence.
Read the entries. Then verify the record they describe.