MacZine
Field copies from the compliance frontier
Practitioner-grade articles on CMMC 2.0, NIST 800-171, RMF, and what it actually takes to operate secure systems in the defense industrial base - written, reviewed and versioned in the open. Published from Git, reviewed like code.
Throwback Article
Explainer · Quality and Compliance
Your AS9100 QMS Already Runs Half of CMMC
Document control, CAPA, internal audit, and management review already run most of CMMC's governance half. The mapping, and the three gaps that remain.
This week
New issue Mon–Fri · 8:00 AM Eastern
Platform Spotlight · AI & Automation
IBE Decides an AI Agent's Authority Before It Acts
IBE governs what an AI agent may do with no LLM in the decision path - a deterministic autonomy gate that certifies or refuses every action, in writing.
Field Report · CUI Scope
CUI Sprawl Is the Scope Creep Nobody Diagrams
A correctly scoped CUI enclave still leaks through tickets, meeting transcripts, and test copies. NIST 800-171 3.1.3 closes it - stricter marking can't.
Explainer · CUI Basics
What Actually Makes a File CUI
CUI is a government designation, not a judgment you make on a file's contents. How marking, derivative marking, and decontrol actually work.
Buyer's Guide · Capture
Read the Solicitation's Compliance Clauses Before You Bid
Compliance cost gets decided at bid or no-bid, not after award. A front-to-back read of the clauses, DD-254, and Section L/M that actually price it.
Field Report · Remote Work
Home Office CUI Scope Starts at the Kitchen Table
NIST 800-171 physical protection assumes an office, not a house. Keep CUI off the remote endpoint and most of the control problem disappears.
Last week
Aug 31 – Sep 4
Every issue, 33 articles and counting→
Suggest a topic
Working through a CMMC, NIST 800-171, or RMF problem we haven’t covered? Tell us what you’re stuck on - it goes straight into the queue.