Compass IT Compliance Blog / CMMC

Plan of Action and Milestones (POA&M): A CMMC Level 2 Essential

Plan of Action and Milestones POA&M - A CMMC Level 2 Essential

Every CMMC Level 2 compliance program involves two documents that work in tandem: the System Security Plan (SSP) and the Plan of Action and Milestones (POA&M). The SSP describes how practices are implemented. The POA&M documents what is not yet implemented and what the organiz …

Read Story

Your CMMC SSP Is Not Just a Checkbox: How to Build One That Works

Your CMMC SSP Is Not Just a Checkbox How to Build One That Works

The System Security Plan (SSP) is the cornerstone document of any CMMC Level 2 compliance program. Yet it is also one of the most underdeveloped artifacts assessors encounter. Organizations preparing for a C3PAO assessment frequently arrive with an SSP that describes their environment …

Read Story

CMMC Scoping Guide: How to Define Your Level 2 Assessment Boundary

CMMC Scoping Guide How to Define Your Level 2 Assessment Boundary

One of the most consequential (and most misunderstood) steps in preparing for CMMC compliance is defining the scope of your assessment boundary. Scope too broadly and you’re burdening your organization with unnecessary controls and cost. Scope too narrowly and you risk leaving Control …

Read Story

How to Reduce CMMC Scope: A Practical Guide for Defense Contractors

How to Reduce Your CMMC Scope: A Practical Guide for Defense Contractors

For defense contractors preparing for Cybersecurity Maturity Model Certification (CMMC), scope is the single biggest lever you have over cost, timeline, and audit complexity. The smaller and more clearly defined your scope, the fewer systems your assessor has to evaluate, the fewer co …

Read Story

CMMC Assessments in Higher Education: What Campus Leaders Are Saying

CMMC Assessments in Higher Education What Campus Leaders Are Saying

I just got back from the EDUCAUSE Cybersecurity and Privacy Professionals Conference in Anaheim last week, and I came home with a notebook full of conversations that I think a lot of provosts, CIOs, and CISOs need to hear. The hallway talk between sessions, the candid moments over cof …

Read Story

CMMC & the False Claims Act: High Stakes for DoD Contractors

CMMC False Claims Act

Cybersecurity compliance for Defense Industrial Base (DIB) organizations has never been purely technical, but the stakes have now escalated into a very real legal and financial risk. With the Department of Defense’s final CMMC rule taking effect on November 10, 2025, and the Departmen …

Read Story

Subscribe by email