Microsoft 365 Business Premium is now available in GCC High, which changes the licensing math for smaller defense contractors. Here is how it compares against G3 and G5, what Windows Enterprise actually adds, and why the right license depends on your CUI architecture rather than your CMMC level.
Expert IT Leadership Blogs |
Encrypting CUI at rest sounds like a solved problem. Turn on BitLocker, move on. Then a C3PAO assessor opens a laptop, looks at how the key is protected and where the recovery password lives, and the control falls apart. Here is how to deploy BitLocker so it stands as CMMC evidence rather than an assessment finding.
With CMMC Phase 2 enforcement beginning November 10, 2026, contractors who have not yet moved CUI workloads into a FedRAMP-authorized environment are running out of time to do it deliberately.
The decisions made in the first few hours after a security incident determine most of what follows, how far the damage spreads, whether data is recoverable, what your legal exposure looks like, and whether your insurer pays out. This playbook covers what needs to happen in the first 72 hours: how to contain without destroying evidence, who to call and in what order, what your notification obligations actually are, and the mistakes that turn a manageable incident into a much worse one.
CMMC is no longer a future requirement. Phase 1 enforcement began November 2025. Phase 2, mandatory C3PAO third-party assessments, begins November 2026. This guide covers who needs certification, what each level requires, how assessment works, what it costs, and how to prepare without losing bids while you do it.
Cyber insurance underwriting is now a technical audit. Insurers verify controls with external scans, require evidence not attestations, and deny claims when forensic review finds gaps that were attested away.
Most defense contractors need CMMC Level 2 certification before competing for DoD contracts. Phase 1 is live as of November 10, 2025, SPRS scores are required now. Phase 2, when C3PAO third-party assessments become mandatory, begins November 2026. For small contractors starting from scratch, 12 to 18 months is a realistic preparation timeline. This guide covers what CMMC actually requires, what the path costs, and where most organizations go wrong before they ever reach an assessment.
For DoD contractors, the difference between CMMC Level 2 and Level 3 is not incremental, it directly affects contract eligibility, audit scrutiny, and security program maturity. Level 2 applies to most contractors handling CUI and maps to NIST SP 800-171's 110 controls, assessed by a C3PAO. Level 3 adds controls from NIST SP 800-172, targets organizations supporting higher-risk defense programs, and requires a government-led assessment rather than a C3PAO assessment.
The HIPAA Security Rule requires two separate activities that organizations routinely conflate: a risk analysis under 45 CFR 164.308(a)(1)(ii)(A) that identifies and rates threats and vulnerabilities to ePHI, and risk management under 164.308(a)(1)(ii)(B) that implements controls to reduce those risks. OCR's enforcement initiative expanded in 2026 to target risk management failures, not just absent risk analyses. A third activity, the breach notification risk assessment under 164.402, is a separate incident-specific obligation.
DoD contractors handling CUI are required to submit a NIST SP 800-171 self-assessment score into the Supplier Performance Risk System (SPRS). That score is the foundation CMMC readiness is built on, and under the False Claims Act, knowingly submitting an inflated score is a legal liability.