Resources
Insights
Guidance on compliance, threats and security engineering from the people who do the work.
February 10, 2026 · 5 min read
The Risk Management Framework, Step by Step
The Risk Management Framework governs how federal and Department of War systems are secured and authorized. A plain-language walk through its seven steps, with the artifacts and decisions at each one.
Read moreJanuary 13, 2026 · 5 min read
POA&Ms Done Right: Turning Gaps into a Credible Remediation Plan
A Plan of Action and Milestones is where compliance programs prove they are serious. How to write POA&M items that assessors and authorizing officials trust, and what CMMC allows.
Read moreDecember 9, 2025 · 6 min read
Scoping CUI: How to Shrink Your Compliance Boundary
The single biggest lever on the cost of NIST SP 800-171 and CMMC compliance is scope. How to find where CUI really lives, categorize assets, and design an enclave that is smaller, cheaper and easier to defend.
Read moreNovember 18, 2025 · 6 min read
Writing a System Security Plan That Survives Assessment
The System Security Plan is the first document an assessor reads and the one most often found wanting. Here is what a strong SSP contains and how to keep it true.
Read moreOctober 28, 2025 · 5 min read
DFARS 252.204-7012 Incident Reporting: The 72-Hour Clock
Defense contractors must report cyber incidents affecting covered defense information within 72 hours, preserve evidence, and support investigation. What triggers the clock, what to report, and how to be ready before it starts.
Read moreOctober 14, 2025 · 5 min read
The 14 NIST SP 800-171 Families in Plain Language
A practical tour of the 110 requirements that protect Controlled Unclassified Information: what each control family asks for, what assessors look for, and where organizations most often fall short.
Read more
Let's talk
Ready to strengthen your security posture?
Talk with a CDT engineer about your mission, your systems and your deadlines. We'll tell you honestly what it takes.