Why the DoD Wants Security Protection Data Protected Like CUI

Abstract data network tied to security protection data and CMMC scope assessed by Kieri

The CMMC proposed rule introduces a concept some defense contractors find puzzling. Security protection data. This category includes vulnerability scan results, system security plans, network diagrams, firewall configurations, and endpoint security settings. Under 32 CFR Part 170, when an external service provider handles security protection assets but doesn’t process, store, or transmit CUI directly, those … Read more

Why Your CMMC Gap Analysis Might Be Worthless – 110 Practices vs 320 Assessment Objectives

Cybersecurity professional conducting CMMC gap analysis for a defense contracting organization

If your consultant assessed you against 110 practices instead of 320 assessment objectives, you’re preparing for the wrong test Kieri Solutions has noticed a troubling pattern. Defense contractors approaching us for CMMC assessments have had gap analyses performed by third-party consultants. When we ask about their readiness, they reference those gap analyses with confidence. Then … Read more

Building a CMMC Level 2 Compliant Network You Can Actually Manage

Network architecture visualization for a CMMC Level 2 reference architecture built on Microsoft 365 GCC High

A detailed look at architecture decisions, assessment precedent, and practical implementation Most CMMC solutions on the market share a common problem. They’re designed by people who haven’t been through actual assessments. Kieri Solutions has been on both sides. We’ve helped defense contractors prepare for CMMC, and we’ve been assessed ourselves as a C3PAO. We’ve also … Read more

Why Most CMMC Documentation Fails and How to Fix It

CMMC compliance documentation policies and procedures

The philosophy behind compliance documentation that actually works We’ve assessed companies for CMMC certification. We’ve seen a lot of bad documentation. Documentation that doesn’t help companies pass their assessments. Policies sitting in binders that nobody reads. Procedures so complex that staff can’t follow them. Templates filled with generic language that doesn’t match actual operations. When … Read more

What Passed a DOD Assessment for System Baselining and Inventories

CMMC system inventory and baseline configuration monitoring dashboard

Real evidence from a successful CMMC Level 2 assessment that you can learn from Practice 3.4.1 looks simple on the surface. Establish and maintain baseline configurations and inventories of organizational systems. Then you read the assessment objectives. Hardware, software, firmware, and documentation. For both baselines AND inventories. Maintained over time. Reviewed periodically. Suddenly you’re looking … Read more

How to Implement Mobile Code Requirements for CMMC Level 2

CMMC mobile code security controls and technical implementation

A complete walkthrough showing System Security Plan development, policy creation, and monitoring procedures that satisfy assessors Mobile code appears twice in NIST SP 800-171 Rev 3. Two separate requirements with six assessment objectives between them. Most implementers struggle with these requirements because mobile code is widely misunderstood. They think it means cell phones. They try … Read more

What Does “Monitor” Actually Mean in CMMC Requirements?

CMMC monitoring requirements - access control and password security verification

Why logging isn’t enough and what assessors actually look for The word “monitor” appears approximately 250 times in the CMMC Level 2 assessment guide. That’s twice as many times as “logging.” Yet many defense contractors treat these terms as interchangeable. They capture logs and assume they’re monitoring. They’re not. This distinction matters because assessors specifically … Read more

The Version 20 Problem and How to Avoid It

CMMC compliance documentation sequence - cybersecurity program management

Why most CMMC compliance journeys take twice as long as they should We went through it ourselves in 2020. We call it the “version 20” problem. You start writing a System Security Plan. You mark a bunch of things “not implemented” because you’re just getting started. You do a gap analysis. You make some technical … Read more

Build Your Own CMMC Level 2 Compliant Environment with the Kieri Reference Architecture

CMMC Level 2 compliant environment security controls and access management

A complete blueprint based on the environment Kieri Solutions used to pass their own DIBCAC assessment Most CMMC compliant environments come with enterprise price tags. Dedicated IT staff requirements. Complex managed service arrangements where you lose control of your own systems. Kieri Solutions faced the same problem. They needed a CMMC Level 2 compliant environment … Read more

Inside the KCD – What Makes This Documentation Different

CMMC compliance documentation templates digital security

A walkthrough of actual documents showing pre-written solutions versus empty templates Most CMMC compliance documentation products share a common problem. They give you empty templates and hope you figure out how to fill them in. You open a System Security Plan template. It says “describe your facility security controls.” Blank space. You’re supposed to know … Read more