Register:Blog/Tag3 recordsSHA3-256 chainedhead sha3:324eccf9454a96d15f7d5a328655df4d5123fce0b44f61f32eb6bc3799dfe0d2Intact
REC 0001ENTRIESsha3-25607f98b1da6fe6c2330cffb15a1995225ec0d38bad55373e36907f00f6dbad2c0prev:4e0af546b46b

Entries, newest first

  1. CMMC Phase II Is Suspended: What Defense Contractors Still Have to DoThe Department of War suspended CMMC Phase II on July 13, 2026, but kept Phase I self-assessments, NIST SP 800-171 Rev. 2 enforcement, and DFARS 252.204-7012 obligations in place.7 min
  2. The $507K LOGZONE Settlement: Your SPRS Score Is Now False Claims Act EvidenceDOJ settled with a defense contractor that posted a 110 SPRS score and later received a -170 government assessment.9 min
  3. CMMC Level 2 Requirements in 2026: The Complete Guide for Defense ContractorsCMMC Phase II is suspended, but the 110-requirement NIST 800-171 Rev. 2 baseline, Phase I self-assessments, and DFARS safeguarding obligations remain active.14 min
  4. NIST 800-171 Cloud Compliance: The Practical Guide for AWS, Azure, and GCPImplementing NIST 800-171 in cloud environments is fundamentally different from on-premises.12 min
  5. The CMMC Level 2 Self-Assessment Trap (And How to Avoid It)Most defense contractors who submit optimistic SPRS scores don't realize they're creating legal exposure, not just compliance risk.9 min
  6. Cloud Misconfiguration Statistics 2026: What's Actually Breaking Defense Contractor EnvironmentsData-driven analysis of cloud misconfiguration patterns across the Defense Industrial Base: top finding categories, specific failure modes, and what the numbers tell us about effective remediation.8 min
  7. NIST 800-171 Rev 3: Key Changes and How to PrepareNIST SP 800-171 Revision 3 brings significant changes to the security requirements for protecting CUI.2 min
  8. CMMC 2.0: What Defense Contractors Need to KnowThe CMMC program is officially active with assessments underway.2 min
REC 0002RELATED RECORDSsha3-256324eccf9454a96d15f7d5a328655df4d5123fce0b44f61f32eb6bc3799dfe0d2prev:07f98b1da6fe

Related records

Guides and articles describe the work. The evidence that work produces is described in three proof pages and one architecture page.

proof.state
Proof of State. What the environment was, as of a date someone else picks: point-in-time records, content hashed and chained.
proof.change
Proof of Change. Who or what altered the environment, under what authority, with before and after state hashes.
proof.agency
Proof of Agency. What a machine was permitted to do before it acted, what it did, and what would have stopped it.
architecture
Architecture. How the chain is built and where it lives: inside your tenant, with no egress of evidence.

Read the entries. Then verify the record they describe.

Register colophonRecomputable by a second party
SeqLabelSHA3-256Prev
REC 0000HEAD4e0af546b46bba9928da042c
REC 0001ENTRIES07f98b1da6fe4e0af546b46b
REC 0002RELATED RECORDS324eccf9454a07f98b1da6fe

The record headers on this page are SHA3-256 digests of this page's own copy, chained in sequence from a fixed genesis value. Edit one word of any record's copy above and every digest after it changes. Head of chain: sha3:324eccf9454a. The product does the same thing to your evidence.