Compass IT Compliance Blog / Government

Plan of Action and Milestones (POA&M): A CMMC Level 2 Essential

Plan of Action and Milestones POA&M - A CMMC Level 2 Essential

Every CMMC Level 2 compliance program involves two documents that work in tandem: the System Security Plan (SSP) and the Plan of Action and Milestones (POA&M). The SSP describes how practices are implemented. The POA&M documents what is not yet implemented and what the organiz …

Read Story

Your CMMC SSP Is Not Just a Checkbox: How to Build One That Works

Your CMMC SSP Is Not Just a Checkbox How to Build One That Works

The System Security Plan (SSP) is the cornerstone document of any CMMC Level 2 compliance program. Yet it is also one of the most underdeveloped artifacts assessors encounter. Organizations preparing for a C3PAO assessment frequently arrive with an SSP that describes their environment …

Read Story

CMMC Scoping Guide: How to Define Your Level 2 Assessment Boundary

CMMC Scoping Guide How to Define Your Level 2 Assessment Boundary

One of the most consequential (and most misunderstood) steps in preparing for CMMC compliance is defining the scope of your assessment boundary. Scope too broadly and you’re burdening your organization with unnecessary controls and cost. Scope too narrowly and you risk leaving Control …

Read Story

CMMC & the False Claims Act: High Stakes for DoD Contractors

CMMC False Claims Act

Cybersecurity compliance for Defense Industrial Base (DIB) organizations has never been purely technical, but the stakes have now escalated into a very real legal and financial risk. With the Department of Defense’s final CMMC rule taking effect on November 10, 2025, and the Departmen …

Read Story

CMMC Final Rule Compliance: A Guide for Defense Contractors

CMMC Final Rule

Since its publication nearly two months ago, the Cybersecurity Maturity Model Certification (CMMC) Final Rule has moved from anticipation to implementation. For defense contractors, compliance is no longer theoretical. The rule is now shaping how the Department of Defense (DoD) manage …

Read Story

Shipbuilders Council of America Spring Membership Meeting Takeaways

Shipbuilders Council of America

Earlier this month, I had the opportunity to attend the Shipbuilders Council of America (SCA) Spring Membership Meeting in Washington, D.C. The room was filled with national security leaders, lawmakers, and key players from across the U.S. shipbuilding ecosystem. What united everyone? …

Read Story

Subscribe by email