Register:Blog/Tag3 recordsSHA3-256 chainedhead
sha3:324eccf9454a96d15f7d5a328655df4d5123fce0b44f61f32eb6bc3799dfe0d2IntactREC 0000HEADsha3-256
4e0af546b46b120db85ca7eb8df5ab08826ba2204eb53d15d53e41049c68347eprev:ba9928da042cRegisterBlogTag: NIST 800-171
Blog entries tagged NIST 800-171
Every blog entry tagged NIST 800-171, newest first. Tags group the register by subject so a reader working one requirement can follow it across entries as the rules change. Each entry is sealed on the date shown and amended in place when it is updated; the full register is at the blog index.
8 entries
REC 0001ENTRIESsha3-256
07f98b1da6fe6c2330cffb15a1995225ec0d38bad55373e36907f00f6dbad2c0prev:4e0af546b46bEntries, newest first
- CMMC Phase II Is Suspended: What Defense Contractors Still Have to DoThe Department of War suspended CMMC Phase II on July 13, 2026, but kept Phase I self-assessments, NIST SP 800-171 Rev. 2 enforcement, and DFARS 252.204-7012 obligations in place.
- The $507K LOGZONE Settlement: Your SPRS Score Is Now False Claims Act EvidenceDOJ settled with a defense contractor that posted a 110 SPRS score and later received a -170 government assessment.
- CMMC Level 2 Requirements in 2026: The Complete Guide for Defense ContractorsCMMC Phase II is suspended, but the 110-requirement NIST 800-171 Rev. 2 baseline, Phase I self-assessments, and DFARS safeguarding obligations remain active.
- NIST 800-171 Cloud Compliance: The Practical Guide for AWS, Azure, and GCPImplementing NIST 800-171 in cloud environments is fundamentally different from on-premises.
- The CMMC Level 2 Self-Assessment Trap (And How to Avoid It)Most defense contractors who submit optimistic SPRS scores don't realize they're creating legal exposure, not just compliance risk.
- Cloud Misconfiguration Statistics 2026: What's Actually Breaking Defense Contractor EnvironmentsData-driven analysis of cloud misconfiguration patterns across the Defense Industrial Base: top finding categories, specific failure modes, and what the numbers tell us about effective remediation.
- NIST 800-171 Rev 3: Key Changes and How to PrepareNIST SP 800-171 Revision 3 brings significant changes to the security requirements for protecting CUI.
- CMMC 2.0: What Defense Contractors Need to KnowThe CMMC program is officially active with assessments underway.
REC 0002RELATED RECORDSsha3-256
324eccf9454a96d15f7d5a328655df4d5123fce0b44f61f32eb6bc3799dfe0d2prev:07f98b1da6feRelated records
Guides and articles describe the work. The evidence that work produces is described in three proof pages and one architecture page.
- proof.state
- Proof of State. What the environment was, as of a date someone else picks: point-in-time records, content hashed and chained.
- proof.change
- Proof of Change. Who or what altered the environment, under what authority, with before and after state hashes.
- proof.agency
- Proof of Agency. What a machine was permitted to do before it acted, what it did, and what would have stopped it.
- architecture
- Architecture. How the chain is built and where it lives: inside your tenant, with no egress of evidence.
Read the entries. Then verify the record they describe.