Catalog · 48 articles
The full run
Every MacZine article, week by week, newest first - written, reviewed and versioned in the open.
Week of Sep 28–Oct 2
Platform Spotlight · AI & Compliance
CMMC MCP Server: Ask Your AI for an SPRS Score or a STIG Rule
A CMMC MCP server makes your AI look up SPRS weights, STIG rules, and award data instead of guessing. Three no-account MacTech servers, tested live.
Explainer · AI and Proposals
AI Proposal Writing for Government Contracts: What's Allowed
AI proposal writing for government contracts is generally allowed. Certifying what the model invented is not. Three scenarios, three controls.
Case in Point · Supply Chain
Subcontractor Cybersecurity: Your Sub's SPRS Score Is a Claim
Primes cannot see a sub's score in SPRS. Subcontractor cybersecurity requirements get verified with evidence - here is what to ask for.
Column · Buying Outside Help
CMMC Consultant, RPO, MSP, or vCISO: Who Owns Your Program?
Hiring a CMMC consultant? An RPO, an MSP, and a vCISO do three different jobs, and none of them can sign for you. What to ask each before you buy.
Explainer · Continuous ATO
Continuous ATO Asks for What a Three-Year ATO Never Did
A continuous ATO (cATO) is not an ATO that never expires. What DoD's cATO memo and evaluation criteria demand instead - telemetry, gates, SBOMs.
Week of Sep 21–Sep 25
Checklist · Cost Accounting
DCAA Compliant Accounting System: What SF 1408 Actually Tests
DCAA does not approve accounting systems. A pre-award survey tests yours against SF 1408. What a DCAA compliant accounting system must show.
Field Guide · CUI Transmission
How to Send CUI by Email Without Failing 3.13.8
How to send CUI via email: why default TLS fails 3.13.8, when S/MIME or Purview encryption holds up, and when DoD SAFE is the better road.
Analysis · Past Performance
No Past Performance? How New Firms Win Government Contracts
No past performance on government contracts earns a neutral rating, not a loss. The rules that let small firms count JV, subcontract, and team records.
Explainer · Vulnerability Management
Vulnerability Scanning Under NIST 800-171: How Often Is Enough?
Vulnerability scanning under NIST 800-171 has no fixed cadence. You set it, and 3.11.2 and 3.14.1 assess whether you wrote it down and kept it.
Field Guide · Incident Response
An Incident Response Tabletop Exercise That Satisfies 3.6.3
An incident response tabletop exercise counts for NIST 800-171 3.6.3 only if it leaves evidence. How to seat, script, and document one an assessor accepts.
Week of Sep 14–Sep 18
Explainer · Federal Capture
SDVOSB Set-Aside Contracts After VetCert: Where the Money Goes
SDVOSB set-aside contracts now require SBA VetCert, and the FAR overhaul made them a contracting officer's choice. What FY2025 data shows for cyber.
Case in Point · Civilian CUI
The FAR CUI Rule Is Coming for Contractors Who Never Saw DFARS
The proposed FAR CUI rule would put NIST 800-171 Rev 3, a 72-hour incident clock, and a new standard form into civilian agency contracts.
Q&A · NIST 800-171
NIST 800-171 Rev 3 vs Rev 2: It Depends Who Signed the Contract
NIST 800-171 Rev 3 vs Rev 2: DoD still binds and scores Rev 2 while civilian CUI heads to Rev 3. What changed, the ID trap, and how to map once.
Follow-up · CMMC Policy
CMMC Class Deviation: The Phase 2 Pause Is Now in the Rulebook
The CMMC class deviation moved the Phase 2 pause from a policy memo into DFARS. A dated timeline of what each step changed, and what stays in force.
Field Guide · Manufacturing Scope
CMMC for Manufacturers: Where the CNC Machine Sits in Scope
CMMC for manufacturers turns on one scoping rule. A tour from the CAD station to the loading dock, classifying CNC machines, OT, and test equipment.
Week of Aug 31–Sep 4
Platform Spotlight · AI & Automation
IBE Decides an AI Agent's Authority Before It Acts
IBE governs what an AI agent may do with no LLM in the decision path - a deterministic autonomy gate that certifies or refuses every action, in writing.
Field Report · CUI Scope
CUI Sprawl Is the Scope Creep Nobody Diagrams
A correctly scoped CUI enclave still leaks through tickets, meeting transcripts, and test copies. NIST 800-171 3.1.3 closes it - stricter marking can't.
Explainer · CUI Basics
What Actually Makes a File CUI
CUI is a government designation, not a judgment you make on a file's contents. How marking, derivative marking, and decontrol actually work.
Buyer's Guide · Capture
Read the Solicitation's Compliance Clauses Before You Bid
Compliance cost gets decided at bid or no-bid, not after award. A front-to-back read of the clauses, DD-254, and Section L/M that actually price it.
Week of Aug 24–Aug 28
Field Report · Remote Work
Home Office CUI Scope Starts at the Kitchen Table
NIST 800-171 physical protection assumes an office, not a house. Keep CUI off the remote endpoint and most of the control problem disappears.
Field Report · Configuration Management
STIG vs CIS Benchmark: Which Baseline Counts as Evidence
DISA STIGs and CIS Benchmarks compared: who publishes each, who is bound by which, how their severity ratings differ, and what an assessor accepts.
Explainer · Quality and Compliance
Your AS9100 QMS Already Runs Half of CMMC
Document control, CAPA, internal audit, and management review already run most of CMMC's governance half. The mapping, and the three gaps that remain.
Buyer's Guide · Cloud and ESPs
GCC High or Not: The External Service Provider Decision
32 CFR 170.19 and DFARS 7012 pull your cloud and your MSP into assessment scope. What decides GCC High versus an enclave, and the matrix to demand first.
Field Report · Access Control
3.5.3: The MFA Control Most Programs Think They Already Passed
NIST 800-171 3.5.3 requires MFA for three scopes, not one. Most programs cover network logins and miss privileged local access - the one assessors test first.
Week of Aug 17–Aug 21
Buyer's Guide · Cost and Pricing
Who Pays for CMMC? It Depends Where You Book It
FAR Part 31 makes most CMMC spending allowable. Whether you ever see the money again depends on booking it direct or indirect - a call made once, by accident.
Explainer · POA&M
What You Can Put on a POA&M, and What You Cannot
Under 32 CFR 170.21 a CMMC POA&M can carry only 1-point requirements, minus six named exclusions, and must close within 180 days. The rules.
Field Report · AI and CUI
Can You Put CUI in an AI Tool? Read the Cloud Clause First
The DFARS clause that governs cloud service providers already answers whether CUI can go into an AI tool - most of the commercial tier fails it.
Governance · CMMC Documentation
How Many Documents Does CMMC Level 2 Actually Require?
NIST 800-171 names 110 requirements but no document count. Scoping a CMMC Level 2 documentation set is a governance decision - here is what the 110 imply.
From the record · Patents pending
MacTech Files Three Provisional Patents Built on Proof, Not Trust
Three provisional patents from MacTech - Trust Codex, IBE, Freehold - on tested systems that prove their claims instead of asking you to trust the operator.
Week of Aug 10–Aug 14
From the field · RMF / ATO
A C3PAO Validates the Evidence Problem Behind Vault-Codex
A CMMC assessor's letter of support confirms the documentation and evidence-management problem is real - and where MacTech Vault-Codex fits.
Explainer · Workforce
Your Training Records Are Compliance Evidence. Are They?
Three CMMC controls turn security awareness training into an evidence problem. Most organizations do the training and fail the control anyway.
Platform Spotlight · Enclave Monitoring
EnclaveWatch: Monitoring a CUI Vault Without Draining It
Continuous monitoring usually means shipping logs somewhere central. Inside a CUI boundary that is the one thing you should not do. EnclaveWatch inverts it.
Platform Spotlight · Capture
CaptureOS: Finding the Work You Are Still Eligible For
Capture tools tell you what is available. Compliance tools tell you what you can hold. CaptureOS puts both in one system, because the answer moves together.
Field Report · Cryptography
FIPS 140-3 Is the Control That Fails Quietly
Encryption that is strong is not the same as encryption that is validated. The distinction costs 5 SPRS points and it is invisible until an assessor looks.
Week of Aug 3–Aug 7
Explainer · Self-Attestation
Who Signs Your Self-Attestation, and What They Are Signing
Self-attestation is not a lighter version of an assessment. It moves the assessment risk onto a named individual - and the False Claims Act is where that lands.
Explainer · RMF and ATO
RMF and CMMC Are Not the Same Program. Run Them as One.
RMF authorizes a system, CMMC certifies a contractor. They ask overlapping questions in different vocabularies - and paying twice is the mistake.
Field Report · Incident Response
The 72-Hour Clock in DFARS 252.204-7012, Hour by Hour
DFARS 7012 gives you 72 hours to report a cyber incident to DoD. Walking the clock hour by hour shows where contractors actually lose the time.
Buyer's Guide · CUI Handling
Enclave or Whole Network? The Scoping Decision, Priced
Scoping CMMC Level 2 to a CUI enclave or to your whole network is a cost decision disguised as an architecture decision. Here is how the two actually compare.
Field Report · CMMC Level 2
The System Security Plan an Assessor Actually Reads
Most SSPs are written to be filed, not read. Here is how a C3PAO assessor moves through the document, and what they are checking at each stop.
Week of Jul 27–Jul 31
Explainer · CMMC Levels
The CMMC Levels Are Not a Ladder, and Only One Requires a Pen Test
Level 1, 2, and 3 test different things on different clocks. Only one requires a penetration test - here is which, and why the other two do not.
Explainer · NIST 800-171
How Your SPRS Score Is Actually Calculated
The DoD Assessment Methodology scores 110 controls on a 5/3/1 weighting and bottoms out at -203. Here is the arithmetic, and how a CO reads it.
Maxine's Pick · Subcontracting
DoD Paused CMMC Phase 2. Your Subcontract Flow-Down Didn't.
DoD suspended CMMC Phase 2's federal clause, but a prime's subcontract requirement is a separate instrument - and it doesn't lift itself.
Vision · Infrastructure, AI & Trust
Building the Trusted Future: Infrastructure, AI, and MacTech
How MacTech combines infrastructure, security, quality, and governance into systems a defense contractor can trust - and where AI is allowed to decide.
From the field · CMMC
CMMC Phase 2 Is Paused. Your Compliance Clock Isn't.
DoD paused CMMC Phase 2 certification to review the program - the DFARS and NIST 800-171 obligations under it did not. What to do during the review.
Platform Spotlight · AI & Automation
MacTech Suite: Running Twenty Platforms Without Twenty Teams
Inside the MacTech Suite: the internal command center that fixes deploys, fixes UI bugs, and now commissions MacZine - every action gated and logged.
Week of Jul 20–Jul 24
Field Report · Secure Communications
Freehold: Secure Comms You Hold Outright
Peer-to-peer encrypted chat, calls and 2 GB file transfer for small DIB teams - post-quantum, air-gap ready, 800-171 evidence built in. Free, open source.
cmmc
The First 90 Days of a CMMC Level 2 Program
A practitioner's sequence for the first 90 days of CMMC Level 2: scope the CUI boundary, baseline against NIST 800-171, and start evidence discipline early.
announcements
Welcome to MacZine
MacZine is the MacTech Solutions newsletter - practitioner-grade articles on CMMC, NIST 800-171, RMF, and defense industrial base compliance.
Suggest a topic
Working through a CMMC, NIST 800-171, or RMF problem we haven’t covered? Tell us what you’re stuck on - it goes straight into the queue.