13 Jul 2026CMMC Phase II suspended: no C3PAO assessments can be designated. DFARS 7012 and Rev 2 still apply.What changed, and what did not →
MacZine
The MacTech Solutions Newsletter
Topic · 21 articles

NIST 800-171

Every MacZine article on NIST 800-171, newest first - written, reviewed and versioned in the open.

042Issue Nº

How to Send CUI by Email Without Failing 3.13.8

How to send CUI via email: why default TLS fails 3.13.8, when S/MIME or Purview encryption holds up, and when DoD SAFE is the better road.

September 24, 2026
040Issue Nº

Vulnerability Scanning Under NIST 800-171: How Often Is Enough?

Vulnerability scanning under NIST 800-171 has no fixed cadence. You set it, and 3.11.2 and 3.14.1 assess whether you wrote it down and kept it.

September 22, 2026
039Issue Nº

An Incident Response Tabletop Exercise That Satisfies 3.6.3

An incident response tabletop exercise counts for NIST 800-171 3.6.3 only if it leaves evidence. How to seat, script, and document one an assessor accepts.

September 21, 2026
037Issue Nº

The FAR CUI Rule Is Coming for Contractors Who Never Saw DFARS

The proposed FAR CUI rule would put NIST 800-171 Rev 3, a 72-hour incident clock, and a new standard form into civilian agency contracts.

September 17, 2026
036Issue Nº

NIST 800-171 Rev 3 vs Rev 2: It Depends Who Signed the Contract

NIST 800-171 Rev 3 vs Rev 2: DoD still binds and scores Rev 2 while civilian CUI heads to Rev 3. What changed, the ID trap, and how to map once.

September 16, 2026
035Issue Nº

CMMC Class Deviation: The Phase 2 Pause Is Now in the Rulebook

The CMMC class deviation moved the Phase 2 pause from a policy memo into DFARS. A dated timeline of what each step changed, and what stays in force.

September 15, 2026
032Issue Nº

CUI Sprawl Is the Scope Creep Nobody Diagrams

A correctly scoped CUI enclave still leaks through tickets, meeting transcripts, and test copies. NIST 800-171 3.1.3 closes it - stricter marking can't.

September 3, 2026
029Issue Nº

Home Office CUI Scope Starts at the Kitchen Table

NIST 800-171 physical protection assumes an office, not a house. Keep CUI off the remote endpoint and most of the control problem disappears.

August 28, 2026
028Issue Nº

STIG vs CIS Benchmark: Which Baseline Counts as Evidence

DISA STIGs and CIS Benchmarks compared: who publishes each, who is bound by which, how their severity ratings differ, and what an assessor accepts.

August 27, 2026
025Issue Nº

3.5.3: The MFA Control Most Programs Think They Already Passed

NIST 800-171 3.5.3 requires MFA for three scopes, not one. Most programs cover network logins and miss privileged local access - the one assessors test first.

August 24, 2026
023Issue Nº

What You Can Put on a POA&M, and What You Cannot

Under 32 CFR 170.21 a CMMC POA&M can carry only 1-point requirements, minus six named exclusions, and must close within 180 days. The rules.

August 20, 2026
021Issue Nº

How Many Documents Does CMMC Level 2 Actually Require?

NIST 800-171 names 110 requirements but no document count. Scoping a CMMC Level 2 documentation set is a governance decision - here is what the 110 imply.

August 18, 2026
019Issue Nº

The CMMC Levels Are Not a Ladder, and Only One Requires a Pen Test

Level 1, 2, and 3 test different things on different clocks. Only one requires a penetration test - here is which, and why the other two do not.

August 1, 2026
017Issue Nº

Your Training Records Are Compliance Evidence. Are They?

Three CMMC controls turn security awareness training into an evidence problem. Most organizations do the training and fail the control anyway.

August 13, 2026
014Issue Nº

FIPS 140-3 Is the Control That Fails Quietly

Encryption that is strong is not the same as encryption that is validated. The distinction costs 5 SPRS points and it is invisible until an assessor looks.

August 10, 2026
012Issue Nº

RMF and CMMC Are Not the Same Program. Run Them as One.

RMF authorizes a system, CMMC certifies a contractor. They ask overlapping questions in different vocabularies - and paying twice is the mistake.

August 6, 2026
009Issue Nº

The System Security Plan an Assessor Actually Reads

Most SSPs are written to be filed, not read. Here is how a C3PAO assessor moves through the document, and what they are checking at each stop.

August 3, 2026
008Issue Nº

How Your SPRS Score Is Actually Calculated

The DoD Assessment Methodology scores 110 controls on a 5/3/1 weighting and bottoms out at -203. Here is the arithmetic, and how a CO reads it.

July 31, 2026
005Issue Nº

CMMC Phase 2 Is Paused. Your Compliance Clock Isn't.

DoD paused CMMC Phase 2 certification to review the program - the DFARS and NIST 800-171 obligations under it did not. What to do during the review.

July 28, 2026
003Issue Nº

Freehold: Secure Comms You Hold Outright

Peer-to-peer encrypted chat, calls and 2 GB file transfer for small DIB teams - post-quantum, air-gap ready, 800-171 evidence built in. Free, open source.

July 22, 2026
002Issue Nº

The First 90 Days of a CMMC Level 2 Program

A practitioner's sequence for the first 90 days of CMMC Level 2: scope the CUI boundary, baseline against NIST 800-171, and start evidence discipline early.

July 21, 2026