Knowledge Base
Plain-language, independently-written explainers on the standards, clauses, and controls behind the DoW Brilliant at the Basics priorities — for the IT lead who is technically capable but not a full-time compliance specialist.
Replay-Resistant vs. Phishing-Resistant Authentication
Replay-resistant and phishing-resistant are different security properties — and phishing-resistant is stronger. Replay resistance is a numbered control in both NIST SP 800-171 Rev 2 (3.5.4) and Rev 3 (03.05.04); phishing-resistant is defined in SP 800-63B and mandated by OMB M-22-09, not by a base 800-171 control.
CMMC vs. NIST SP 800-171: What’s the Difference?
NIST SP 800-171 is the security control set for protecting CUI; CMMC is the DoD program that verifies you actually implemented it. Level 2 CMMC is the same 110 requirements from 800-171 Rev 2 — the difference is who checks, how often, and what proof is required.
DFARS 7012’s 72-Hour Rule: What It Actually Requires
DFARS 252.204-7012 requires contractors to report a discovered cyber incident to DoD within 72 hours via DIBNet, preserve affected media for at least 90 days, and submit malicious software to DC3 — plus flow the clause down to subcontractors. The report itself is only part of the obligation.
GCC High vs. Commercial Microsoft 365: Do You Actually Need It?
GCC High is Microsoft 365 in a US-sovereign, screened-US-persons cloud with FedRAMP High and DoD IL4/IL5 authorization. You need it for ITAR/export-controlled data and CUI Specified; Commercial or GCC may suffice for lighter CUI — but confirm with your prime. It costs more and migration is a real project.
The Top Mistakes DIB Teams Make When Starting the Basics
Most Top 10 programs don't fail on hard technology — they stall on avoidable patterns: boiling the ocean, mistaking 'we bought it' for 'it works,' and never testing recovery. Here are the common mistakes DIB teams make starting out, and the simple fixes.
What Good Looks Like: The IT Top 10 at a Glance
A high-level 'done looks like' for each IT Top 10 practice — the validation test that shows a control actually works, not just that it was purchased. Use it as a quick self-check, then open the full guides for the how-to.
Scoping Your CUI Boundary: Discovery Methods, Remediation Paths, and the Numbers That Decide
Scope size is the master cost driver in a CMMC Level 2 program — it sets how many premium licenses you pay for, how big your assessment is, and how much CUI you're liable for. How you find your CUI (a top-down traceability cascade, staff interviews, or automated digital discovery) determines how accurately you can size the boundary, and four remediation paths — surgical file cleanup, a user-account enclave, program segmentation, or enterprise migration — are chosen mostly by two ratios: what share of users touch CUI, and how sprawled it already is.
What Should a GCC High Migration Cost?
A GCC High migration priced honestly has three parts: a fixed base to stand up and harden the environment (around $15,500), migration tooling like AvePoint (there is no native commercial-to-GCC-High path), and roughly $250 per user to move and validate mail, files, and Teams. Total ≈ $15,500 + tooling + ($250 × users). The cost nobody quotes correctly is the risk in the mapping and cutover — get those wrong and you pay again in spillage, broken permissions, and downtime.
Windows Pro vs. Enterprise for NIST 800-171 Rev 3: The Endpoint Parity Gap
For NIST 800-171 Rev 3, the endpoint controls quietly require Windows Enterprise. Rev 3 sharpened application allowlisting (03.04.08), and the licensed, manageable engine — AppLocker — needs a Windows Enterprise E3/E5 or Education license; Pro isn't entitled. App Control for Business (WDAC) runs on Pro but is the harder engine and no substitute for the rest: Credential Guard (Enterprise-only), Defender for Endpoint EDR (E5), and more. In GCC High, getting those Enterprise licenses onto devices is partner-mediated and portal-fragmented.
Your SPRS Score, Explained: How the DoD Assessment Methodology Works
Your SPRS score is a self-reported number from 110 down to -203 that tells the DoD how much of NIST SP 800-171 you have actually implemented. It starts at 110, and every unmet requirement subtracts a weighted value of 5, 3, or 1 point. Two requirements — multifactor authentication and FIPS-validated encryption — are the only ones that grant partial credit.
CMMC Phase II Is Suspended — What You Still Have to Do
On July 13, 2026 the Department of War suspended the CMMC Phase II transition during a 60-day program review. Third-party (C3PAO) and Level 3 designations are paused and November 10, 2026 is no longer an operative date — but DFARS 252.204-7012, NIST SP 800-171 Rev 2, 72-hour incident reporting, SPRS score accuracy, and the Program Rule at 32 CFR Part 170 all remain in force.
FCI, CUI, CDI — How the Rules Stack Together
The security stack is driven first by the information involved, then by the clauses, assessment level, and contract-specific requirements that apply to the system handling it. FCI, CUI, and CDI are overlapping categories with different triggers — and export-controlled information sits on top as an independent legal overlay.
The Foundation Clauses — FAR 52.204-21 and the DFARS 7012 Family
FAR 52.204-21 and DFARS 252.204-7012, -7019, -7020 and -7021 form the contractual backbone of defense cybersecurity. Each has a distinct trigger, obligation, and flowdown. Alongside them sits an independent supply-chain gate that can exclude an otherwise-compliant technology from a covered contract.
CUI Is Not an Export License — ITAR and EAR as a Separate Overlay
Export control is a separate legal overlay from CUI safeguarding. The controlling authority, classification, destination, end user, nationality, access path, license or exemption, and technical facts determine whether a transfer or release is authorized — none of which is answered by a CUI banner or a CMMC status.
These articles are independent education. They cite the standards and clauses they discuss, but do not by themselves establish compliance, satisfy a contract clause, or confer CMMC certification. Confirm against the official publication that applies to your contract.