<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>Wrightbrained Security</title>
  <link>https://wrightbrainedsecurity.com/blog/</link>
  <atom:link href="https://wrightbrainedsecurity.com/feed.xml" rel="self" type="application/rss+xml"/>
  <description>Plain-English posts on CMMC, NIST SP 800-171, healthcare ransomware and supplier risk.</description>
  <language>en-us</language>
  <item>
    <title>CMMC Phase II Is Paused: Five Things Defense Contractors Should Work on Now</title>
    <link>https://wrightbrainedsecurity.com/cmmc-phase-ii-is-paused-five-things-defense-contractors-should-work-on-now/</link>
    <guid isPermaLink="true">https://wrightbrainedsecurity.com/cmmc-phase-ii-is-paused-five-things-defense-contractors-should-work-on-now/</guid>
    <pubDate>Fri, 11 Sep 2026 13:40:53 +0000</pubDate>
    <description>On July 13, 2026, the Department of War suspended the transition to CMMC Phase II. The third-party assessment requirement that was scheduled to take effect on November 10, 2026 is on hold while a CMMC Reform Task Force conducts a 60-day review, and recommendations are expected to surface around early October. A lot of contractors</description>
  </item>
  <item>
    <title>Is CMMC Dead?</title>
    <link>https://wrightbrainedsecurity.com/is-cmmc-dead/</link>
    <guid isPermaLink="true">https://wrightbrainedsecurity.com/is-cmmc-dead/</guid>
    <pubDate>Wed, 22 Jul 2026 19:05:59 +0000</pubDate>
    <description>This article reflects publicly available guidance as of July 2026 and is intended for informational purposes, not legal advice. Contract-specific questions should be discussed with qualified legal counsel. The headline in the ecosystem the past 2 weeks has been that CMMC is &quot;suspended&quot;. If you are like me, your group chat and voicemail lit up,</description>
  </item>
  <item>
    <title>Is Your CMMC Scope Correct? Try the Free Scope Checker Tool</title>
    <link>https://wrightbrainedsecurity.com/is-your-cmmc-scope-correct-try-the-free-scope-checker-tool/</link>
    <guid isPermaLink="true">https://wrightbrainedsecurity.com/is-your-cmmc-scope-correct-try-the-free-scope-checker-tool/</guid>
    <pubDate>Fri, 08 May 2026 15:41:06 +0000</pubDate>
    <description>Struggling to scope your CMMC Level 2 assessment? The new CMMC Scope Checker from Wrightbrained Security&#x27;s CMMC Compliance Engine can help change that. This free tool analyzes your assets against DoD guidelines, ensuring you focus controls only where CUI lives, saving time and money. For many defense contractors, the most stressful part of CMMC isn&#x27;t</description>
  </item>
  <item>
    <title>How to Write a CMMC Level 2 SSP: What Assessors Actually Look For</title>
    <link>https://wrightbrainedsecurity.com/how-to-write-a-cmmc-level-2-ssp-what-assessors-actually-look-for/</link>
    <guid isPermaLink="true">https://wrightbrainedsecurity.com/how-to-write-a-cmmc-level-2-ssp-what-assessors-actually-look-for/</guid>
    <pubDate>Fri, 27 Mar 2026 14:33:19 +0000</pubDate>
    <description>System Security Plans Your SSP Is Your Organization&#x27;sSecurity Story.It&#x27;s Your Security Program on Paper. A field guide to writing implementation statements that actually hold up under assessment. If your cybersecurity program had a pulse, the System Security Plan would be it. Without it, your organization cannot begin a CMMC Level 2 assessment. With a weak</description>
  </item>
  <item>
    <title>Introducing the CMMC Compliance Engine: A Practical System for Getting Assessment-Ready</title>
    <link>https://wrightbrainedsecurity.com/introducing-the-cmmc-compliance-engine-a-practical-system-for-getting-assessment-ready/</link>
    <guid isPermaLink="true">https://wrightbrainedsecurity.com/introducing-the-cmmc-compliance-engine-a-practical-system-for-getting-assessment-ready/</guid>
    <pubDate>Wed, 18 Mar 2026 17:30:54 +0000</pubDate>
    <description>During almost every CMMC readiness engagement, there is a moment when the organization realizes something important. They have many of the right security tools in place. The network is segmented. Multifactor authentication is deployed. Logging exists. Endpoint protection is running. But when it comes time to show how all of that supports the CMMC requirements,</description>
  </item>
  <item>
    <title>CMMC – You Probably Think You Meet 3.13.6. Your Assessor Might Not Agree.</title>
    <link>https://wrightbrainedsecurity.com/deny-by-default/</link>
    <guid isPermaLink="true">https://wrightbrainedsecurity.com/deny-by-default/</guid>
    <pubDate>Mon, 02 Feb 2026 16:37:49 +0000</pubDate>
    <description>SC.L2-3.13.6 is a commonly missed practice in CMMC Level 2 assessments. Not because organizations ignore it, but because they genuinely believe they’ve satisfied it when they haven’t. 3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception). What this means: Both inbound AND outbound network traffic</description>
  </item>
  <item>
    <title>When ITAR Data Is CUI and When It Is Not</title>
    <link>https://wrightbrainedsecurity.com/when-itar-data-is-cui-and-when-it-is-not/</link>
    <guid isPermaLink="true">https://wrightbrainedsecurity.com/when-itar-data-is-cui-and-when-it-is-not/</guid>
    <pubDate>Thu, 23 Oct 2025 15:24:24 +0000</pubDate>
    <description>If you handle defense work, you already know that ITAR (International Traffic in Arms Regulations) and CUI (Controlled Unclassified Information) often come up in the same conversation. They overlap, but they are not the same thing. This post explains when ITAR-controlled information must also be handled as CUI and when it stands alone under export control. Oh yeah — I</description>
  </item>
  <item>
    <title>Oh Shit, I Need CMMC – A Subcontractor’s Survival Guide</title>
    <link>https://wrightbrainedsecurity.com/oh-shit-i-need-cmmc-a-subcontractors-survival-guide/</link>
    <guid isPermaLink="true">https://wrightbrainedsecurity.com/oh-shit-i-need-cmmc-a-subcontractors-survival-guide/</guid>
    <pubDate>Wed, 01 Oct 2025 20:45:27 +0000</pubDate>
    <description>If you are reading this, you are probably a subcontractor in the Defense Industrial Base (DIB), and there is a good chance your prime contractor has dropped a bombshell: you need to be compliant with CMMC. Maybe they asked for your System Security Plan (SSP). Maybe they requested your Supplier Performance Risk System (SPRS) score.</description>
  </item>
  <item>
    <title>CMMC IS a Real Boy!</title>
    <link>https://wrightbrainedsecurity.com/cmmc-is-a-real-boy/</link>
    <guid isPermaLink="true">https://wrightbrainedsecurity.com/cmmc-is-a-real-boy/</guid>
    <pubDate>Mon, 15 Sep 2025 14:25:13 +0000</pubDate>
    <description>What Contractors Need to Know About the 48 CFR Final Rule On November 10, 2025, the Department of Defense will cross the line from policy to enforcement. The 48 CFR Final Rule will go into effect, and the Cybersecurity Maturity Model Certification (CMMC) will be a contractual requirement. If you want to win or extend</description>
  </item>
  <item>
    <title>Signal, Not Noise:  AU 3.3.3</title>
    <link>https://wrightbrainedsecurity.com/signal-not-noise-au-3-3-3/</link>
    <guid isPermaLink="true">https://wrightbrainedsecurity.com/signal-not-noise-au-3-3-3/</guid>
    <pubDate>Mon, 05 May 2025 19:54:43 +0000</pubDate>
    <description>Let’s talk about practice 3.3.3. – Review and update logged events. Table of Contents Toggle Let’s cut through the confusion.Here’s the plan. We are going to:Quick BasicsA specific action or occurrence within a systemA record of one or more events stored in a file or systemA notification triggered by specific conditions in logs Step 1: Make</description>
  </item>
  <item>
    <title>Automation: Comparing Account Inventory to Active Directory Accounts</title>
    <link>https://wrightbrainedsecurity.com/automation-comparing-account-inventory-to-active-directory-accounts/</link>
    <guid isPermaLink="true">https://wrightbrainedsecurity.com/automation-comparing-account-inventory-to-active-directory-accounts/</guid>
    <pubDate>Tue, 11 Mar 2025 13:52:37 +0000</pubDate>
    <description>This is the first time I have shared something like this. I&#x27;ve actually created a ton of python scripts to automate things that need to be done at a certain frequency. It just speeds up the process. If you like this kind of info, let me know in the comments and I will share more.</description>
  </item>
  <item>
    <title>Microsoft Defender vs. Mobile Code</title>
    <link>https://wrightbrainedsecurity.com/microsoft-defender-vs-mobile-code/</link>
    <guid isPermaLink="true">https://wrightbrainedsecurity.com/microsoft-defender-vs-mobile-code/</guid>
    <pubDate>Wed, 05 Feb 2025 20:57:04 +0000</pubDate>
    <description>How Defender blocks mobile code. CMMC Practice SC L2 3.13.13 - Configure attack surface reduction, setup WDAC, setup real-time protection.</description>
  </item>
  <item>
    <title>Security Protection Assets and Security Protection Data in CMMC</title>
    <link>https://wrightbrainedsecurity.com/security-protection-assets-and-security-protection-data-in-cmmc/</link>
    <guid isPermaLink="true">https://wrightbrainedsecurity.com/security-protection-assets-and-security-protection-data-in-cmmc/</guid>
    <pubDate>Fri, 10 Jan 2025 23:36:14 +0000</pubDate>
    <description>What Are Security Protection Assets (SPAs)? SPAs are the tools, systems, and personnel that provide security functions or capabilities within the CMMC assessment scope of an Organization Seeking Certification (OSC). They protect CUI assets and the broader infrastructure that supports them. A Few Examples of SPAs: Firewalls: Devices or software that regulate network traffic, blocking</description>
  </item>
  <item>
    <title>CMMC Practice 3.4.7 – Ports, Protocols, Programs Functions, and Services</title>
    <link>https://wrightbrainedsecurity.com/cmmc-practice-3-4-7-ports-protocols-programs-functions-and-services/</link>
    <guid isPermaLink="true">https://wrightbrainedsecurity.com/cmmc-practice-3-4-7-ports-protocols-programs-functions-and-services/</guid>
    <pubDate>Fri, 20 Dec 2024 21:31:19 +0000</pubDate>
    <description>TL;DR: Simplifying Essential Features for Compliance The Goal: Restrict and disable nonessential programs, ports, protocols, functions, and services to reduce your system’s attack surface and improve security. Challenges: Documentation—not implementation—is where most companies fall short. You must define “essential” clearly and apply it consistently. What to Do: • Inventory: Identify everything running on your systems.</description>
  </item>
  <item>
    <title>CMMC Level 2 Self-Assessment or Assessment by a CMMC Third Party Assessment Organization?</title>
    <link>https://wrightbrainedsecurity.com/cmmc-level-2-self-assessment-or-assessment-by-a-cmmc-third-party-assessment-organization/</link>
    <guid isPermaLink="true">https://wrightbrainedsecurity.com/cmmc-level-2-self-assessment-or-assessment-by-a-cmmc-third-party-assessment-organization/</guid>
    <pubDate>Tue, 15 Oct 2024 13:08:46 +0000</pubDate>
    <description>Given the choice, most companies would choose a self-assessment over a third party assessment. Isn&#x27;t that what CMMC was trying to get away from? The decision of whether a company can self-assess for a Level 2 assessment or if a contract requires a third-party C3PAO assessment is determined by the specific requirements stated in the</description>
  </item>
  <item>
    <title>The CMMC Rule and Plans of Action &amp; Milestones (POA&amp;M)</title>
    <link>https://wrightbrainedsecurity.com/the-cmmc-rule-and-plans-of-action-milestones-poam/</link>
    <guid isPermaLink="true">https://wrightbrainedsecurity.com/the-cmmc-rule-and-plans-of-action-milestones-poam/</guid>
    <pubDate>Mon, 14 Oct 2024 17:09:58 +0000</pubDate>
    <description>One of the things that I wanted to see in the CMMC Rule was more clarity on utilizing Plans of Action and Milestones (POA&amp;M) for companies that do not fully meet all 110 requirements during their assessment. I’m continuing to dive into the CMMC rule…it’s freaking long. Here is what it says about POA&amp;Ms, the</description>
  </item>
  <item>
    <title>The CMMC Rule is FINAL!</title>
    <link>https://wrightbrainedsecurity.com/the-cmmc-rule-is-final/</link>
    <guid isPermaLink="true">https://wrightbrainedsecurity.com/the-cmmc-rule-is-final/</guid>
    <pubDate>Fri, 11 Oct 2024 19:56:20 +0000</pubDate>
    <description>Woooohoooo, the long awaited CMMC Rule will be published on the Federal Register on October 15, 2024. The Wrightbrained team has spent some time looking at the document. Clarifications are a big theme. Everyone in the CMMC ecosystem had a lot of questions and there were several that stood out as the most common. I</description>
  </item>
  <item>
    <title>FIPS 140-2 and CMMC Compliance</title>
    <link>https://wrightbrainedsecurity.com/fips-140-2-and-cmmc-compliance/</link>
    <guid isPermaLink="true">https://wrightbrainedsecurity.com/fips-140-2-and-cmmc-compliance/</guid>
    <pubDate>Mon, 29 Jul 2024 15:57:56 +0000</pubDate>
    <description>What is FIPS 140-2? Federal Information Processing Standards Publication 140-2 is a standard for the cryptographic modules used in software and hardware to protect sensitive data. The key difference between FIPS-validated modules and others is the rigorous testing and verification process they undergo. This process can take years, ensuring these modules meet strict security protocols.</description>
  </item>
  <item>
    <title>The CrowdStrike Outage: Risk Assessments &amp; Single Points of Failure</title>
    <link>https://wrightbrainedsecurity.com/the-crowdstrike-outage-mitigating-risks-of-single-points-of-failure/</link>
    <guid isPermaLink="true">https://wrightbrainedsecurity.com/the-crowdstrike-outage-mitigating-risks-of-single-points-of-failure/</guid>
    <pubDate>Sun, 21 Jul 2024 01:43:31 +0000</pubDate>
    <description>On July 19, 2024, what should have been a routine update meant to improve CrowdStrike’s Falcon Sensor software ended up causing chaos. Instead of…</description>
  </item>
  <item>
    <title>VerySecure UAV’s On-Site CMMC Assessment – Physical Security &amp; related domains</title>
    <link>https://wrightbrainedsecurity.com/verysecure-uavs-on-site-cmmc-assessment-physical-security-related-domains/</link>
    <guid isPermaLink="true">https://wrightbrainedsecurity.com/verysecure-uavs-on-site-cmmc-assessment-physical-security-related-domains/</guid>
    <pubDate>Tue, 16 Jul 2024 18:20:57 +0000</pubDate>
    <description>Disclaimer: This story is entirely fictional. Any resemblance to actual persons, living or dead, or actual events, or actual companies is purely coincidental and unintended. The characters, companies, and events portrayed are purely a work of fiction. Jil Wright, a Certified CMMC Assessor, has provided this narrative to offer organizations seeking certification an example of what</description>
  </item>
</channel>
</rss>
