Stealth Technology Group

External Service Providers Under CMMC: What Counts as an ESP and What That Means for Your MSP

External Service Providers Under CMMC: What Counts as an ESP and What That Means for Your MSP

A defense contractor going through readiness prep almost always asks the same question at some point: does our IT company […]

Employee Offboarding Under CMMC: Why Access Revocation Timing Is a Scored Control

Employee Offboarding Under CMMC: Why Access Revocation Timing Is a Scored Control

A former subcontractor employee’s Office 365 account sat active for eleven days after his last shift. Nobody used it maliciously. […]

Physical Security Under CMMC: Protecting CUI When the Threat Isn’t Digital

Physical Security Under CMMC: Protecting CUI When the Threat Isn’t Digital

A contractor spends eighteen months hardening firewalls, deploying endpoint detection, and rewriting incident response plans, then fails a Level 2 […]

The Five CMMC Asset Categories: How Scoping Actually Sorts Your Environment

The Five CMMC Asset Categories: How Scoping Actually Sorts Your Environment

A defense contractor calls us with a network diagram that looks reasonable on paper — a flat topology, one domain, […]

Audit Logging Under CMMC: What AU.L2 Requires and How Long You Actually Have to Keep Logs

Audit Logging Under CMMC: What AU.L2 Requires and How Long You Actually Have to Keep Logs

Ask five compliance leads at defense contractors how long they need to retain audit logs, and you’ll get five different […]

Configuration Management Under CMMC: Why “It Works” Isn’t the Same as a Documented Baseline

Configuration Management Under CMMC: Why “It Works” Isn’t the Same as a Documented Baseline

A network engineer at a manufacturing subcontractor once told us his configuration management program was “in his head, and it’s […]

How Winning More DoD Contracts Starts With a Stronger Cybersecurity Posture – Not Just a Lower Bid

How Winning More DoD Contracts Starts With a Stronger Cybersecurity Posture – Not Just a Lower Bid

A contracting officer doesn’t reject a proposal because the price was too high. Most of the time, they never get […]

The Complete CUI Lifecycle: How to Store, Share, Access, and Dispose of Controlled Unclassified Information Under CMMC

The Complete CUI Lifecycle: How to Store, Share, Access, and Dispose of Controlled Unclassified Information Under CMMC

Most CMMC gaps we find during a readiness assessment have nothing to do with a missing firewall rule or an […]

Microsoft 365 GCC vs GCC High: Which One Does Your CMMC Program Actually Need?

Microsoft 365 GCC vs GCC High: Which One Does Your CMMC Program Actually Need?

A prime contractor sends over a flow-down clause referencing DFARS 252.204-7012, someone on the compliance team googles “CMMC cloud requirements,” […]

CMMC Incident Response Requirements: Why a Policy Document Is Not a Plan and What IR.L2 Actually Demands

CMMC Incident Response Requirements: Why a Policy Document Is Not a Plan and What IR.L2 Actually Demands

Every defense contractor we onboard hands us a binder. It has a cover page, a revision history, a section on […]

Zero Trust Architecture and CMMC: How a Zero Trust Approach Accelerates Level 2 Compliance

Zero Trust Architecture and CMMC: How a Zero Trust Approach Accelerates Level 2 Compliance

A contractor calls us three weeks before their scheduled C3PAO assessment and asks whether “adding some zero trust stuff” can […]

What the DFARS 252.204-7012 Clause Actually Requires and Why Most Contractors Misread It

What the DFARS 252.204-7012 Clause Actually Requires and Why Most Contractors Misread It

Ask ten defense contractors what DFARS 252.204-7012 requires and you’ll get ten different answers, most of them wrong in the […]

1 2 3 4 5 6 28

Subscribe to our newsletter!

Be The First To Know Blog & News by signing up in our newsletter!

    Insights on IT, Cybersecurity, Compliance & AI

    Scroll to Top