MacZine
The MacTech Solutions Newsletter
Topic · 23 articles

CMMC

Every MacZine article on CMMC, newest first - written, reviewed and versioned in the open.

032Issue Nº

CUI Sprawl Is the Scope Creep Nobody Diagrams

A correctly scoped CUI enclave still leaks through tickets, meeting transcripts, and test copies. NIST 800-171 3.1.3 closes it - stricter marking can't.

September 3, 2026
027Issue Nº

Your AS9100 QMS Already Runs Half of CMMC

Document control, CAPA, internal audit, and management review already run most of CMMC's governance half. The mapping, and the three gaps that remain.

August 26, 2026
026Issue Nº

GCC High or Not: The External Service Provider Decision

32 CFR 170.19 and DFARS 7012 pull your cloud and your MSP into assessment scope. What decides GCC High versus an enclave, and the matrix to demand first.

August 25, 2026
024Issue Nº

Who Pays for CMMC? It Depends Where You Book It

FAR Part 31 makes most CMMC spending allowable. Whether you ever see the money again depends on booking it direct or indirect - a call made once, by accident.

August 21, 2026
023Issue Nº

What You Can Put on a POA&M, and What You Cannot

A POA&M restores no SPRS points and cannot carry the highest-weight controls. Here are the rules that decide what actually belongs on one.

August 20, 2026
021Issue Nº

How Many Documents Does CMMC Level 2 Actually Require?

NIST 800-171 names 110 requirements but no document count. Scoping a CMMC Level 2 documentation set is a governance decision - here is what the 110 imply.

August 18, 2026
020Issue Nº

MacTech Files Three Provisional Patents Built on Proof, Not Trust

Three provisional patents from MacTech - Trust Codex, IBE, Freehold - on tested systems that prove their claims instead of asking you to trust the operator.

August 17, 2026
019Issue Nº

The CMMC Levels Are Not a Ladder, and Only One Requires a Pen Test

Level 1, 2, and 3 test different things on different clocks. Only one requires a penetration test - here is which, and why the other two do not.

August 1, 2026
018Issue Nº

A C3PAO Validates the Evidence Problem Behind Vault-Codex

A CMMC assessor's letter of support confirms the documentation and evidence-management problem is real - and where MacTech Vault-Codex fits.

August 14, 2026
017Issue Nº

Your Training Records Are Compliance Evidence. Are They?

Three CMMC controls turn security awareness training into an evidence problem. Most organizations do the training and fail the control anyway.

August 13, 2026
016Issue Nº

EnclaveWatch: Monitoring a CUI Vault Without Draining It

Continuous monitoring usually means shipping logs somewhere central. Inside a CUI boundary that is the one thing you should not do. EnclaveWatch inverts it.

August 12, 2026
015Issue Nº

CaptureOS: Finding the Work You Are Still Eligible For

Capture tools tell you what is available. Compliance tools tell you what you can hold. CaptureOS puts both in one system, because the answer moves together.

August 11, 2026
014Issue Nº

FIPS 140-3 Is the Control That Fails Quietly

Encryption that is strong is not the same as encryption that is validated. The distinction costs 5 SPRS points and it is invisible until an assessor looks.

August 10, 2026
013Issue Nº

Who Signs Your Self-Attestation, and What They Are Signing

Self-attestation is not a lighter version of an assessment. It moves the assessment risk onto a named individual - and the False Claims Act is where that lands.

August 7, 2026
012Issue Nº

RMF and CMMC Are Not the Same Program. Run Them as One.

RMF authorizes a system, CMMC certifies a contractor. They ask overlapping questions in different vocabularies - and paying twice is the mistake.

August 6, 2026
011Issue Nº

The 72-Hour Clock in DFARS 252.204-7012, Hour by Hour

DFARS 7012 gives you 72 hours to report a cyber incident to DoD. Walking the clock hour by hour shows where contractors actually lose the time.

August 5, 2026
010Issue Nº

Enclave or Whole Network? The Scoping Decision, Priced

Scoping CMMC Level 2 to a CUI enclave or to your whole network is a cost decision disguised as an architecture decision. Here is how the two actually compare.

August 4, 2026
009Issue Nº

The System Security Plan an Assessor Actually Reads

Most SSPs are written to be filed, not read. Here is how a C3PAO assessor moves through the document, and what they are checking at each stop.

August 3, 2026
008Issue Nº

How Your SPRS Score Is Actually Calculated

The DoD Assessment Methodology scores 110 controls on a 5/3/1 weighting and bottoms out at -203. Here is the arithmetic, and how a CO reads it.

July 31, 2026
007Issue Nº

DoD Paused CMMC Phase 2. Your Subcontract Flow-Down Didn't.

DoD suspended CMMC Phase 2's federal clause, but a prime's subcontract requirement is a separate instrument - and it doesn't lift itself.

July 30, 2026
006Issue Nº

Building the Trusted Future: Infrastructure, AI, and MacTech

How MacTech combines infrastructure, security, quality, and governance into systems a defense contractor can trust - and where AI is allowed to decide.

July 29, 2026
005Issue Nº

CMMC Phase 2 Is Paused. Your Compliance Clock Isn't.

DoD paused CMMC Phase 2 certification to review the program - the DFARS and NIST 800-171 obligations under it did not. What to do during the review.

July 28, 2026
002Issue Nº

The First 90 Days of a CMMC Level 2 Program

A practitioner's sequence for the first 90 days of CMMC Level 2: scope the CUI boundary, baseline against NIST 800-171, and start evidence discipline early.

July 21, 2026