Catalog · 19 articles
The full run
Every MacZine article, week by week, newest first - written, reviewed and versioned in the open.
Week of Aug 10–Aug 14
From the field · RMF / ATO
A C3PAO Validates the Evidence Problem Behind Vault-Codex
A CMMC assessor's letter of support confirms the documentation and evidence-management problem is real - and where MacTech Vault-Codex fits.
Explainer · Workforce
Your Training Records Are Compliance Evidence. Are They?
Three CMMC controls turn security awareness training into an evidence problem. Most organizations do the training and fail the control anyway.
Platform Spotlight · Enclave Monitoring
EnclaveWatch: Monitoring a CUI Vault Without Draining It
Continuous monitoring usually means shipping logs somewhere central. Inside a CUI boundary that is the one thing you should not do. EnclaveWatch inverts it.
Platform Spotlight · Capture
CaptureOS: Finding the Work You Are Still Eligible For
Capture tools tell you what is available. Compliance tools tell you what you can hold. CaptureOS puts both in one system, because the answer moves together.
Field Report · Cryptography
FIPS 140-3 Is the Control That Fails Quietly
Encryption that is strong is not the same as encryption that is validated. The distinction costs 5 SPRS points and it is invisible until an assessor looks.
Week of Aug 3–Aug 7
Explainer · Self-Attestation
Who Signs Your Self-Attestation, and What They Are Signing
Self-attestation is not a lighter version of an assessment. It moves the assessment risk onto a named individual - and the False Claims Act is where that lands.
Explainer · RMF and ATO
RMF and CMMC Are Not the Same Program. Run Them as One.
RMF authorizes a system, CMMC certifies a contractor. They ask overlapping questions in different vocabularies - and paying twice is the mistake.
Field Report · Incident Response
The 72-Hour Clock in DFARS 252.204-7012, Hour by Hour
DFARS 7012 gives you 72 hours to report a cyber incident to DoD. Walking the clock hour by hour shows where contractors actually lose the time.
Buyer's Guide · CUI Handling
Enclave or Whole Network? The Scoping Decision, Priced
Scoping CMMC Level 2 to a CUI enclave or to your whole network is a cost decision disguised as an architecture decision. Here is how the two actually compare.
Field Report · CMMC Level 2
The System Security Plan an Assessor Actually Reads
Most SSPs are written to be filed, not read. Here is how a C3PAO assessor moves through the document, and what they are checking at each stop.
Week of Jul 27–Jul 31
Explainer · CMMC Levels
The CMMC Levels Are Not a Ladder, and Only One Requires a Pen Test
Level 1, 2, and 3 test different things on different clocks. Only one requires a penetration test - here is which, and why the other two do not.
Explainer · NIST 800-171
How Your SPRS Score Is Actually Calculated
The DoD Assessment Methodology scores 110 controls on a 5/3/1 weighting and bottoms out at -203. Here is the arithmetic, and how a CO reads it.
Maxine's Pick · Subcontracting
DoD Paused CMMC Phase 2. Your Subcontract Flow-Down Didn't.
DoD suspended CMMC Phase 2's federal clause, but a prime's subcontract requirement is a separate instrument - and it doesn't lift itself.
Vision · Infrastructure, AI & Trust
Building the Trusted Future: Infrastructure, AI, and MacTech
How MacTech combines infrastructure, security, quality, and governance into systems a defense contractor can trust - and where AI is allowed to decide.
From the field · CMMC
CMMC Phase 2 Is Paused. Your Compliance Clock Isn't.
DoD paused CMMC Phase 2 certification to review the program - the DFARS and NIST 800-171 obligations under it did not. What to do during the review.
Platform Spotlight · AI & Automation
MacTech Suite: Running Twenty Platforms Without Twenty Teams
Inside the MacTech Suite: the internal command center that fixes deploys, fixes UI bugs, and now commissions MacZine - every action gated and logged.
Week of Jul 20–Jul 24
Field Report · Secure Communications
Freehold: Secure Comms You Hold Outright
Peer-to-peer encrypted chat, calls and 2 GB file transfer for small DIB teams - post-quantum, air-gap ready, 800-171 evidence built in. Free, open source.
cmmc
The First 90 Days of a CMMC Level 2 Program
A practitioner's sequence for the first 90 days of CMMC Level 2: scope the CUI boundary, baseline against NIST 800-171, and start evidence discipline early.
announcements
Welcome to MacZine
MacZine is the MacTech Solutions newsletter - practitioner-grade articles on CMMC, NIST 800-171, RMF, and defense industrial base compliance.
Suggest a topic
Working through a CMMC, NIST 800-171, or RMF problem we haven’t covered? Tell us what you’re stuck on - it goes straight into the queue.