Learn
Learn CMMC
Guides from the team that builds CMMC tooling.
The reading aid. All 110 NIST 800-171 requirements in plain language, a CUI worksheet, and Rev. 2 versus Rev. 3 word by word. Free and unofficial.
Open cmmc.foxxcyber.comSeries
The Rev 3 Walkthrough
A weekly walkthrough of NIST SP 800-171 from Revision 2 to Revision 3, one family at a time: what is worth doing now, what is premature, and where every requirement changed. Contractors are still assessed on Rev 2.
Read the series- What is CMMC? A complete guide for defense contractors→CMMC (Cybersecurity Maturity Model Certification) is the DoD's framework requiring defense contractors to prove their cybersecurity posture. Learn what CMMC is, who needs it, the 3 levels, and how to get certified.
- CMMC Level 2 requirements: all 110 NIST 800-171 practices by domain→Complete breakdown of CMMC Level 2 requirements — all 110 NIST SP 800-171 Revision 2 security practices organized by the 14 security domains. Understand what each control family covers and what assessors look for.
- C3PAO assessment guide: how to prepare, what assessors check, how to choose→Complete guide to preparing for your CMMC C3PAO assessment. Learn what assessors look for, how to choose a C3PAO, what documentation you need, and how to avoid common failures.
- The CMMC assessment process: from self-assessment to certification→A practical guide to the CMMC assessment process — from self-assessment and evidence collection to SPRS scoring and preparing for your C3PAO evaluation. Learn what assessors look for at each stage.
- CMMC continuous monitoring: keeping compliance real between assessments→Learn how continuous monitoring (ConMon) works in CMMC — what it requires, how to track evidence review schedules, maintain your SPRS score, and avoid compliance drift between assessments.
- POA&M management for CMMC: the plan of action and milestones→Learn how to create and manage a Plan of Action and Milestones (POA&M) for CMMC compliance. Understand POA&M requirements, the 180-day remediation window, priority tracking, and what assessors expect.
- Managing external service providers for CMMC→Learn how to manage External Service Providers (ESPs) for CMMC compliance. Understand CUI handling, FedRAMP requirements, flow-down clauses, control inheritance, and how to document third-party providers in your SSP.
- CMMC Phase 2 is suspended. Your security obligations are not.→On July 13, 2026 the Department of War suspended CMMC Phase 2 third-party assessment requirements. What was suspended, what still applies — DFARS 7012, NIST 800-171, SPRS affirmations — and what defense contractors should do now.
- The Rev 3 Walkthrough · Part 1NIST 800-171 Rev 2 vs Rev 3: What Actually Changes (and Why You're Still on Rev 2)→Rev 3 cuts 800-171 from 110 requirements to 97, adds three families, and replaces vague wording with fill-in values. Here's the map — and why your contract still says Rev 2.
- The Rev 3 Walkthrough · Part 2800-171 Rev 3 ODPs: The Blanks DoD Already Filled In→DoD's April 2025 memo fills in the blanks Rev 3 leaves open: 16-character passwords, five failed logons in five minutes, a 15-minute device lock. What the values are, what they bind, and which to check first.