CMMC 2.0 is Coming Ahead of Schedule

CMMC 2.0 rulemaking has drawn to a close earlier than expected, with the Department of Defense sending its proposed rules to the Congressional Budget Office earlier this month. This development occurred ahead of the expected timeline, putting CMMC on track for enforcement before the end of 2024. For some time, companies that contract with the […]
What Is CUI?

The average person has some idea what classified information is. This is information that the government keeps secret from the general public and which only people with the necessary clearance can access. But even material that isn’t classified isn’t necessarily for public consumption. Some information has a connection to classified information, but isn’t sensitive enough […]
CMMC 2.0 – Key Points to Know

In November of 2023, following multiple troubling cyber attacks on key players in the defense industry, the federal government updated the Defense Federal Acquisition Regulation Supplement (DFARS). The DOD has implemented CMMC 2.0 in order to close some of the gaps it has found in compliance among the Defense Industrial Base. Many organizations, both public […]
Security Threats to Defense Contractors: Are You Protected?

Every year, Microsoft releases a Defense Report about the primary security threats to defense contractors tracked in the previous year. These reports cover which actors on the world stage have been responsible for a variety of cyber attacks. The 2023 report shows that China, Russia, and Iran have ramped up attacks and spread into new […]
Difference between FedRAMP Moderate Certified and FedRAMP Moderate Equivalency

In the context of the Federal Risk and Authorization Management Program (FedRAMP), both “FedRAMP Moderate Certified” and “FedRAMP Moderate Equivalency” refer to security compliance levels for cloud service providers (CSPs) who offer services to U.S. federal agencies. However, there are distinctions between the two: FedRAMP Moderate Certified This indicates that a cloud service provider has […]
Queen Consulting and Technologies Announces the Launch of Mission Compliant: A New Cybersecurity Compliance Training and Consultancy Business

As cybersecurity threats continue to evolve, contractors for the U S federal government face increasing pressure to comply with stringent cybersecurity standards. To address this critical need, Queen Consulting & Technologies, Inc. is launching Mission Compliant, a cybersecurity compliance training and consultancy brand dedicated to assisting government contractors in becoming compliant with federal cyber and quality requirements. […]
CMMC Certification Applicability to External Service Providers Such as MSPs or MSSPs

The evolving Cybersecurity Maturity Model Certification (CMMC) framework introduces a critical dialogue among government contractors, particularly about the role and eligibility of Managed Service Providers (MSPs) and Managed Security Service Providers (MSSPs) within this new regulatory environment. As we delve into this discussion, it’s essential to consider the nuanced perspectives and interpretations of current regulations and their implications for service providers in the defense sector.
When Will CMMC Likely Be Finalized?

The Cybersecurity Maturity Model Certification (CMMC) stands as a pivotal framework for enhancing the cybersecurity posture of the Defense Industrial Base (DIB). As government contractors, especially Operations and Contract Managers, navigate through the evolving landscape of defense contracting, understanding the timeline for CMMC’s finalization is crucial. This insight not only aids in strategic planning but also ensures readiness for compliance, helping gain a competitive edge in securing government contracts.
Public Comment Period for CMMC: Key Questions and Insights

Public Comment Period for CMMC: Key Questions and Insights
30 Essential Questions to Ask an IT Service Provider for Assisting with CMMC Compliance

Navigating the Cybersecurity Maturity Model Certification (CMMC) landscape requires a knowledgeable and reliable IT or consulting partner. For government contractors, especially those in operations and contract management, selecting the right partner is crucial. Here are 30 critical questions to guide you in choosing a partner that aligns with your compliance needs.