Current: Phase II suspended July 13, 2026. Phase I self-assessment requirements remain.Read the update →
Hey, defense contractors — start here.

Compliance
with clarity

Source-first CMMC and NIST 800-171 guidance for small defense contractors that need to scope the right system, build useful evidence, and understand what a solicitation actually requires.

CMMCNIST 800-171DFARS
CMMC FIELD NOTE2026
DATAFCI / CUI
BASELINENIST 800-171
EVIDENCESSP + SPRS
Phase I active • Phase II suspended
BUILDPROOF
HELLO!We read the rules.Independent research desk

Built for teams that need practical answers without vendor-heavy fear marketing. Every guide points back to primary government or NIST material.

  • ✓ Current 2026 status
  • ✓ Small-business scope
  • ✓ Evidence focused
BASED ONPrimary
Sources
~~

WHAT THIS SITE DOES BEST

~~

SCOPING

Trace FCI and CUI so the assessment boundary reflects real data flow.

CONTROLS

Translate NIST requirements into system-specific implementation work.

EVIDENCE

Build artifacts that demonstrate operation, not just policy intent.

AWARD READINESS

Keep SPRS, CMMC UIDs, affirmations, and dates visible to proposal teams.

SOURCE CHECKS

Separate current rules from old phase charts and recycled blog claims.

A CLEAN COMPLIANCE PROCESS

01

READ

Find the current clause, solicitation requirement, and official program status.

02

SCOPE

Trace the information and name the exact system that performs the work.

03

IMPLEMENT

Assign requirements to real people, configurations, providers, and processes.

04

PROVE

Link every implementation claim to fresh, reproducible evidence.

05

MAINTAIN

Refresh records when architecture, contracts, providers, or status dates change.

Make it usable.

Build a compliance
record your team
can actually explain.

Start with the official-status guide, then narrow scope before buying more tooling.

START HEREWhich CMMC level fits the data?Open level finder →
KEEP IT CURRENTTemplates for scope and evidenceOpen templates →