Brilliant at the Basics Cybersecurity ↗
The authoritative campaign page and source for the IT and OT Top 10 practices.
In-depth knowledge base articles plus authoritative DoW, NIST, CISA, NSA, DC3, and Project Spectrum sources — identified, dated, and linked to the original publisher.
Independent, plain-language explainers on the standards and controls behind the Top 10.
Replay-resistant and phishing-resistant are different security properties — and phishing-resistant is stronger. Replay resistance is a numbered control in both NIST SP 800-171 Rev 2 (3.5.4) and Rev 3 (03.05.04); phishing-resistant is defined in SP 800-63B and mandated by OMB M-22-09, not by a base 800-171 control.
NIST SP 800-171 is the security control set for protecting CUI; CMMC is the DoD program that verifies you actually implemented it. Level 2 CMMC is the same 110 requirements from 800-171 Rev 2 — the difference is who checks, how often, and what proof is required.
DFARS 252.204-7012 requires contractors to report a discovered cyber incident to DoD within 72 hours via DIBNet, preserve affected media for at least 90 days, and submit malicious software to DC3 — plus flow the clause down to subcontractors. The report itself is only part of the obligation.
GCC High is Microsoft 365 in a US-sovereign, screened-US-persons cloud with FedRAMP High and DoD IL4/IL5 authorization. You need it for ITAR/export-controlled data and CUI Specified; Commercial or GCC may suffice for lighter CUI — but confirm with your prime. It costs more and migration is a real project.
Most Top 10 programs don't fail on hard technology — they stall on avoidable patterns: boiling the ocean, mistaking 'we bought it' for 'it works,' and never testing recovery. Here are the common mistakes DIB teams make starting out, and the simple fixes.
A high-level 'done looks like' for each IT Top 10 practice — the validation test that shows a control actually works, not just that it was purchased. Use it as a quick self-check, then open the full guides for the how-to.
Scope size is the master cost driver in a CMMC Level 2 program — it sets how many premium licenses you pay for, how big your assessment is, and how much CUI you're liable for. How you find your CUI (a top-down traceability cascade, staff interviews, or automated digital discovery) determines how accurately you can size the boundary, and four remediation paths — surgical file cleanup, a user-account enclave, program segmentation, or enterprise migration — are chosen mostly by two ratios: what share of users touch CUI, and how sprawled it already is.
A GCC High migration priced honestly has three parts: a fixed base to stand up and harden the environment (around $15,500), migration tooling like AvePoint (there is no native commercial-to-GCC-High path), and roughly $250 per user to move and validate mail, files, and Teams. Total ≈ $15,500 + tooling + ($250 × users). The cost nobody quotes correctly is the risk in the mapping and cutover — get those wrong and you pay again in spillage, broken permissions, and downtime.
For NIST 800-171 Rev 3, the endpoint controls quietly require Windows Enterprise. Rev 3 sharpened application allowlisting (03.04.08), and the licensed, manageable engine — AppLocker — needs a Windows Enterprise E3/E5 or Education license; Pro isn't entitled. App Control for Business (WDAC) runs on Pro but is the harder engine and no substitute for the rest: Credential Guard (Enterprise-only), Defender for Endpoint EDR (E5), and more. In GCC High, getting those Enterprise licenses onto devices is partner-mediated and portal-fragmented.
Your SPRS score is a self-reported number from 110 down to -203 that tells the DoD how much of NIST SP 800-171 you have actually implemented. It starts at 110, and every unmet requirement subtracts a weighted value of 5, 3, or 1 point. Two requirements — multifactor authentication and FIPS-validated encryption — are the only ones that grant partial credit.
On July 13, 2026 the Department of War suspended the CMMC Phase II transition during a 60-day program review. Third-party (C3PAO) and Level 3 designations are paused and November 10, 2026 is no longer an operative date — but DFARS 252.204-7012, NIST SP 800-171 Rev 2, 72-hour incident reporting, SPRS score accuracy, and the Program Rule at 32 CFR Part 170 all remain in force.
The security stack is driven first by the information involved, then by the clauses, assessment level, and contract-specific requirements that apply to the system handling it. FCI, CUI, and CDI are overlapping categories with different triggers — and export-controlled information sits on top as an independent legal overlay.
FAR 52.204-21 and DFARS 252.204-7012, -7019, -7020 and -7021 form the contractual backbone of defense cybersecurity. Each has a distinct trigger, obligation, and flowdown. Alongside them sits an independent supply-chain gate that can exclude an otherwise-compliant technology from a covered contract.
Export control is a separate legal overlay from CUI safeguarding. The controlling authority, classification, destination, end user, nationality, access path, license or exemption, and technical facts determine whether a transfer or release is authorized — none of which is answered by a CUI banner or a CMMC status.
Official campaign, framework, and program links — each with its publisher, provenance, and most recent verification date.
The authoritative campaign page and source for the IT and OT Top 10 practices.
The department-level target architecture that the IT Top 10 supports.
The foundational reference for securing industrial control systems.
A right-sized starting point for organizations without a security team.
Guidance for building and maintaining a defensible OT asset inventory.
No-cost cybersecurity readiness resources for DIB small businesses.
Free threat-informed services for DIB companies, including protective DNS.
Reporting, analysis, and no-cost tools for defense contractors.
A commercial tool that automatically discovers and continuously monitors CUI across files and endpoints — including formats many scanners miss, like CAD drawings, PDFs, and scanned images — and flags CUI that has drifted outside its authorized boundary. Useful for the digital-discovery step of scoping.