Blog
Writing for people who have to defend the score.
No listicles and no vendor theatre — just the rule text, the arithmetic, and the artifacts an assessor will actually ask you for.
- Playbook
Scope your CUI boundary before you buy a single tool
Asset categorization drives cost more than any product decision. How to split CUI assets, security protection assets, and out-of-scope systems first.
Read · 5 min - Playbook
A 72-hour incident report playbook you can actually run
DFARS 252.204-7012 gives you 72 hours to report a cyber incident affecting CUI. Here is the clock, the decisions, and the artifacts to capture.
Read · 6 min - CMMC rule
The SPRS score math that actually matters
How the 110-point NIST SP 800-171 self-assessment score is calculated, which controls cost you 5 points, and why partial credit is a trap.
Read · 7 min