Topic

Compliance

6 posts.

Defense Aug 11, 2026 · 11 min read

CMMC Phase 2 Is Suspended. Your Legal Exposure Went Up.

The certification deadline is gone. The obligations are not, and the one government mechanism that used to catch a bad SPRS score before a lawyer did is paused. Here is what defense contractors should actually be working on.

CMMC 2.0NIST 800-171DFARS
Federal Aug 11, 2026 · 10 min read

FedRAMP 20x Turns Compliance Into Code

20x is not a version bump. It replaces narrative control descriptions with automated Key Security Indicators, replaces the annual audit with continuous validation, and replaces documents with machine-readable data. Here is what that actually demands of a cloud service provider.

FedRAMPFedRAMP 20xOSCAL
State Aug 11, 2026 · 9 min read

Florida Gave You the Mandate, Vetoed the Safe Harbor, and Just Funded the Fix

Florida is one of the few states that mandates a cybersecurity framework by statute. The alignment deadlines have already passed, the liability safe harbor was vetoed, and as of July 1 there is finally state money on the table. Here is what actually applies to Florida agencies, counties, and cities.

FloridaState GovernmentNIST CSF
Federal Aug 11, 2026 · 7 min read

Your FedRAMP Package Has to Be Machine-Readable by September 30

RFC-0024's machine-readable package requirements were confirmed in NTC-0009 and finalized in the Consolidated Rules for 2026, with initial compliance due September 30, 2026. They apply to existing Rev 5 certifications, not just new applicants, and most providers have not started.

FedRAMPFedRAMP 20xOSCAL
Healthcare Apr 14, 2026 · 11 min read

Five HIPAA SRA Mistakes That Get Practices Fined

Most security risk assessments fail on the same handful of gaps. We walk through the findings HHS OCR flags most often and how to close them before an audit.

HIPAARisk AssessmentHealthcare
Defense Mar 14, 2026 · 9 min read

CMMC Level 2 for Small Businesses: What Actually Changed

The final rule is live. Here is what small defense contractors need to know about scoping, POA&M timelines, and what assessors are actually looking for.

CMMC 2.0NIST 800-171Defense