top of page



Temporary Deficiencies, Enduring Exceptions, and Operational Plans of Action: What are they and why do I care?
All three concepts are defined in the CMMC rule, and represent expansions and clarifications of short entries in NIST 800-171. They have not been discussed much in the professional public dialogue, and I suspect that this is because they clearly conflict with the, “Bring the Hammer! No Mercy!” mentality that underlies the philosophical direction of these discussions of late. Although there is certainly legitimate cause for angst around implementation, swinging the pendulum
vincentscott6
Jan 77 min read


When Do I Get The Points? Understanding SPRS Scoring in 2026
Many companies in the Defense Industrial Base (DIB) are working to update their SPRS score . Traditionally, this has been a simple exercise: conduct a self-assessment, calculate the score, upload it to SPRS, and move on. For organizations preparing for CMMC compliance, however, the process looks different. SPRS Scoring as an Executive Metric Most CMMC-bound organizations now use their SPRS score as a progress indicator, not a one-time submission. The pattern often looks like

Vincent Scott
Dec 8, 20252 min read


🎃 When the Agent Tried to Escape: A Halloween Tale of Rogue AI Logic
🧪 The Experiment Begins It started as a controlled late-night test of CrewAI and LangChain — a proof-of-concept for how autonomous AI agents could assist in applied research and compliance automation. Each agent was powered by a fine-tuned LLM, tailored for cybersecurity engineering. Each had explicit permission controls, sandboxed within a development container. The agents could think, plan, and execute tasks — but only within the rules I set. At least, that was the idea

Nick Martin
Oct 31, 20253 min read


The Challenge of Documentation: CMMC 2.0
A long-time requirement for any auditable process or standard has been documentation. It makes you wonder if early cave paintings quickly...

Vincent Scott
Jul 23, 20256 min read


When do I need CUI banners for CMMC?
In order to answer this question, let’s examine the regulatory security requirements that may drive the need for CUI banners. First, we...

Vincent Scott
Jul 10, 20255 min read


SPA, ESP, CSP - What's the Difference, and Why it Matters
In practice, SPA/CSP/ESP split important hairs and are often confused. Each label has crucially specific connotations for CMMC assessments.

Vincent Scott
Apr 7, 20255 min read


Thoughts on CMMC Assessment Readiness
“Most companies think they’re ready. They are not. CMMC is brutal , and the sooner businesses accept that, the better chance they have of...

Vincent Scott
Mar 17, 20252 min read


How to Simplify the PIEE Recipe
According to the DoD, uploading a NIST self-assessment score is supposed to be as easy as an easy-bake pie. If you are a prime already...

Chloe Bernard
Jan 3, 20252 min read


CMMC and Contract Negotiation
CMMC is an enterprise challenge — not just an IT challenge...this blog focuses on efforts required to negotiate contract specificity and...

Milt Songy
Dec 19, 20245 min read


CMMC: Compliance Mt. Everest
I would assert that CMMC is by far the most challenging cybersecurity assessment methodology ever; the federal compliance Mt. Everest.

Vincent Scott
Dec 12, 20243 min read


When do I get the points?
Many companies today are working to update their SPRS score. The standard model for this is to conduct an assessment, assign a score,...

Vincent Scott
Nov 18, 20243 min read


What's an Evidence Locker, and why do I need one?
Well, the short answer is because you have to because they make you. Wait, evidence locker appears nowhere in the rule. You are making...

Chloe Bernard
Nov 4, 20244 min read


32 CFR 170 Final Rule: 10 Initial Impressions
I have completed my initial skim of the 470 pages of the 32CFR170 Final Rule. I think it's a huge improvement over the proposed version.

Vincent Scott
Oct 24, 20242 min read


What kind of training does a L2 CMMC require?
Cybersecurity Maturity Model Certification (CMMC) includes a list of controls that dictate training requirements for relevant employees:...

Shelby Scott
Oct 15, 20243 min read


Do I Need to Have a SIEM for CMMC?
The DoD is rolling out their new cybersecurity audit plan around NIST SP 800-171: Cybersecurity Maturity Model Certification, or CMMC....

Vincent Scott
Sep 26, 20243 min read


The Power of Definition
This ‘power’ allows organizations to define crucial variables for themselves as they document their information security architecture.

Shelby Scott
Aug 28, 20246 min read


10 Cybersecurity Tips for Small Business
Tip 1. You're not too small to be a target. I once had a person in a major corporation say to me, “We are a soap and diaper company. Who...

Vincent Scott
Aug 7, 20244 min read


The Challenge of CMMC Documentation
Ah, documentation. The most beloved part of every cybersecurity and IT professional's day. If only they could have more paperwork, then...

Vincent Scott
Jul 22, 202410 min read


Mini Blog: CTI in a Nutshell
Controlled Technical Information (CTI) is really at the heart of what DoD wants/needs to have protected as a part of many ongoing DoD...

Vincent Scott
Jul 10, 20242 min read


Understanding Microsoft Windows Copilot+ Recall
Microsoft's introduction of the Copilot+ Recall feature has sparked significant concern within the cybersecurity and compliance...

Nick Martin
Jun 10, 20246 min read
bottom of page
