Out of Scope Assets – What the Final Rule Actually Changed

Abstract data cityscape tied to out of scope assets in a CMMC assessment by Kieri Solutions

Boundaries, VDI clarifications, and the end of SPA chaining Understanding what’s out of scope matters as much as knowing what’s in scope. The final CMMC rule made significant clarifications about boundaries, VDI endpoints, and security protection asset relationships. These changes simplify scoping and eliminate some of the more problematic interpretations from earlier guidance. This article … Read more

CMMC Proposed Rule Analysis – What Defense Contractors Need to Know

Dark cybersecurity image with glowing data illustrating CMMC final rule compliance for defense contractors

Four Certified CMMC Assessors break down the major changes, the harder requirements, and the practical implications. The CMMC rule is final. After years of speculation, interim guidance, and leaked drafts, defense contractors can now read exactly what the Department of War requires. Four Certified CMMC Assessors from Kieri Solutions worked through the rule together: Amira … Read more

CUI Assets – What Assessors Actually Evaluate

Abstract network of nodes tied to CUI assets and CMMC scope assessed by Kieri Solutions

Understanding process, store, and transmit definitions under the final rule CUI assets face the most rigorous assessment in CMMC Level 2. While security protection assets get evaluated only for relevant capabilities, and contractor risk managed assets get SSP review with spot checks, CUI assets get assessed against all 110 security requirements. Understanding what makes something … Read more

Why the DoD Wants Security Protection Data Protected Like CUI

Abstract data network tied to security protection data and CMMC scope assessed by Kieri

The CMMC proposed rule introduces a concept some defense contractors find puzzling. Security protection data. This category includes vulnerability scan results, system security plans, network diagrams, firewall configurations, and endpoint security settings. Under 32 CFR Part 170, when an external service provider handles security protection assets but doesn’t process, store, or transmit CUI directly, those … Read more

Why Your CMMC Gap Analysis Might Be Worthless – 110 Practices vs 320 Assessment Objectives

Cybersecurity professional conducting CMMC gap analysis for a defense contracting organization

If your consultant assessed you against 110 practices instead of 320 assessment objectives, you’re preparing for the wrong test Kieri Solutions has noticed a troubling pattern. Defense contractors approaching us for CMMC assessments have had gap analyses performed by third-party consultants. When we ask about their readiness, they reference those gap analyses with confidence. Then … Read more