Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
KNOWLEDGE BASEEDITOR REVIEWED

Knowledge Base

Plain-language, independently-written explainers on the standards, clauses, and controls behind the DoW Brilliant at the Basics priorities — for the IT lead who is technically capable but not a full-time compliance specialist.

14 ARTICLES
Identity & Authentication8 MIN READ

Replay-Resistant vs. Phishing-Resistant Authentication

Replay-resistant and phishing-resistant are different security properties — and phishing-resistant is stronger. Replay resistance is a numbered control in both NIST SP 800-171 Rev 2 (3.5.4) and Rev 3 (03.05.04); phishing-resistant is defined in SP 800-63B and mandated by OMB M-22-09, not by a base 800-171 control.

UPDATED 2026-07-21Read the article →
Compliance Frameworks9 MIN READ

CMMC vs. NIST SP 800-171: What’s the Difference?

NIST SP 800-171 is the security control set for protecting CUI; CMMC is the DoD program that verifies you actually implemented it. Level 2 CMMC is the same 110 requirements from 800-171 Rev 2 — the difference is who checks, how often, and what proof is required.

UPDATED 2026-07-28Read the article →
Incident Response & DFARS8 MIN READ

DFARS 7012’s 72-Hour Rule: What It Actually Requires

DFARS 252.204-7012 requires contractors to report a discovered cyber incident to DoD within 72 hours via DIBNet, preserve affected media for at least 90 days, and submit malicious software to DC3 — plus flow the clause down to subcontractors. The report itself is only part of the obligation.

UPDATED 2026-07-21Read the article →
Cloud & Architecture9 MIN READ

GCC High vs. Commercial Microsoft 365: Do You Actually Need It?

GCC High is Microsoft 365 in a US-sovereign, screened-US-persons cloud with FedRAMP High and DoD IL4/IL5 authorization. You need it for ITAR/export-controlled data and CUI Specified; Commercial or GCC may suffice for lighter CUI — but confirm with your prime. It costs more and migration is a real project.

UPDATED 2026-07-21Read the article →
Getting Started6 MIN READ

The Top Mistakes DIB Teams Make When Starting the Basics

Most Top 10 programs don't fail on hard technology — they stall on avoidable patterns: boiling the ocean, mistaking 'we bought it' for 'it works,' and never testing recovery. Here are the common mistakes DIB teams make starting out, and the simple fixes.

UPDATED 2026-07-21Read the article →
Getting Started5 MIN READ

What Good Looks Like: The IT Top 10 at a Glance

A high-level 'done looks like' for each IT Top 10 practice — the validation test that shows a control actually works, not just that it was purchased. Use it as a quick self-check, then open the full guides for the how-to.

UPDATED 2026-07-21Read the article →
Scoping & Architecture14 MIN READ

Scoping Your CUI Boundary: Discovery Methods, Remediation Paths, and the Numbers That Decide

Scope size is the master cost driver in a CMMC Level 2 program — it sets how many premium licenses you pay for, how big your assessment is, and how much CUI you're liable for. How you find your CUI (a top-down traceability cascade, staff interviews, or automated digital discovery) determines how accurately you can size the boundary, and four remediation paths — surgical file cleanup, a user-account enclave, program segmentation, or enterprise migration — are chosen mostly by two ratios: what share of users touch CUI, and how sprawled it already is.

UPDATED 2026-07-28Read the article →
Cloud & Architecture10 MIN READ

What Should a GCC High Migration Cost?

A GCC High migration priced honestly has three parts: a fixed base to stand up and harden the environment (around $15,500), migration tooling like AvePoint (there is no native commercial-to-GCC-High path), and roughly $250 per user to move and validate mail, files, and Teams. Total ≈ $15,500 + tooling + ($250 × users). The cost nobody quotes correctly is the risk in the mapping and cutover — get those wrong and you pay again in spillage, broken permissions, and downtime.

UPDATED 2026-07-21Read the article →
Cloud & Architecture9 MIN READ

Windows Pro vs. Enterprise for NIST 800-171 Rev 3: The Endpoint Parity Gap

For NIST 800-171 Rev 3, the endpoint controls quietly require Windows Enterprise. Rev 3 sharpened application allowlisting (03.04.08), and the licensed, manageable engine — AppLocker — needs a Windows Enterprise E3/E5 or Education license; Pro isn't entitled. App Control for Business (WDAC) runs on Pro but is the harder engine and no substitute for the rest: Credential Guard (Enterprise-only), Defender for Endpoint EDR (E5), and more. In GCC High, getting those Enterprise licenses onto devices is partner-mediated and portal-fragmented.

UPDATED 2026-07-21Read the article →
Compliance Frameworks9 MIN READ

Your SPRS Score, Explained: How the DoD Assessment Methodology Works

Your SPRS score is a self-reported number from 110 down to -203 that tells the DoD how much of NIST SP 800-171 you have actually implemented. It starts at 110, and every unmet requirement subtracts a weighted value of 5, 3, or 1 point. Two requirements — multifactor authentication and FIPS-validated encryption — are the only ones that grant partial credit.

UPDATED 2026-07-21Read the article →
Compliance Frameworks11 MIN READ

CMMC Phase II Is Suspended — What You Still Have to Do

On July 13, 2026 the Department of War suspended the CMMC Phase II transition during a 60-day program review. Third-party (C3PAO) and Level 3 designations are paused and November 10, 2026 is no longer an operative date — but DFARS 252.204-7012, NIST SP 800-171 Rev 2, 72-hour incident reporting, SPRS score accuracy, and the Program Rule at 32 CFR Part 170 all remain in force.

UPDATED 2026-07-28Read the article →
Compliance Frameworks10 MIN READ

FCI, CUI, CDI — How the Rules Stack Together

The security stack is driven first by the information involved, then by the clauses, assessment level, and contract-specific requirements that apply to the system handling it. FCI, CUI, and CDI are overlapping categories with different triggers — and export-controlled information sits on top as an independent legal overlay.

UPDATED 2026-07-28Read the article →
Compliance Frameworks12 MIN READ

The Foundation Clauses — FAR 52.204-21 and the DFARS 7012 Family

FAR 52.204-21 and DFARS 252.204-7012, -7019, -7020 and -7021 form the contractual backbone of defense cybersecurity. Each has a distinct trigger, obligation, and flowdown. Alongside them sits an independent supply-chain gate that can exclude an otherwise-compliant technology from a covered contract.

UPDATED 2026-07-28Read the article →
Export Controls11 MIN READ

CUI Is Not an Export License — ITAR and EAR as a Separate Overlay

Export control is a separate legal overlay from CUI safeguarding. The controlling authority, classification, destination, end user, nationality, access path, license or exemption, and technical facts determine whether a transfer or release is authorized — none of which is answered by a CUI banner or a CMMC status.

UPDATED 2026-07-28Read the article →