NIST SP 800-171 Rev 2 vs Rev 3: What Changed, and What It Means for CMMC
NIST finalized SP 800-171 Rev 3 in 2024: 17 families, 97 requirements, and organization-defined parameters. But CMMC still runs on Rev 2. Here's what actually changed and how to prepare.
NIST AI RMF Explained: A Practical Guide to the AI Risk Management Framework
The Govern, Map, Measure, and Manage functions, all 72 subcategories, the maturity tiers, the Generative AI Profile, and how to run your first AI RMF assessment.
How to Run a Free NIST CSF 2.0 Self-Assessment
A step-by-step walkthrough for running a NIST CSF 2.0 self-assessment: scoping, the six functions (including the new GOVERN), a tier-based scoring rubric, reading the gap analysis, and turning gaps into a plan, all in a free browser-based tool.
CMMC Level 2: What It Demands and How to Know Where You Stand
Every DoD contractor handling CUI needs a SPRS score on file. Here's what the 110-requirement CMMC Level 2 assessment entails and how to calculate your score before the assessor arrives.
POA&M Template: The Fields That Matter (and a Free Tracker)
A field-by-field POA&M template mapped to FISMA and FedRAMP expectations (weakness, source, severity, completion dates, milestones, status), plus the severity-based remediation deadlines and a free, browser-based tracker that flags overdue items.
The POA&M: Why Tracking Remediation Is What Keeps Your ATO Alive
An ATO isn't a certificate, it's a risk acceptance with conditions. The POA&M is the document that proves you're honoring those conditions. Let it go stale and your authorization follows.
System Security Plan (SSP) Template: Structure, Sections, and a Free Builder
A practitioner's SSP template mapped to NIST SP 800-18 Rev 1: system identification, FIPS 199 categorization that drives the SP 800-53 Rev 5 baseline, boundary, roles, control narratives, and CM-8 inventory, with a free in-browser builder.
Tracking NIST CSF Maturity Over Time: The Benefits of a Trend, Not a Single Score
A one-time NIST CSF assessment tells you where you are. Tracking maturity across assessments tells you whether your security program is actually improving, and where investments aren't moving the needle.
NIST SP 800-30 Risk Assessment: A Template and Worked Example
A working NIST SP 800-30 Rev. 1 risk assessment template: walk the threat-source-to-risk model, score three risks end to end with the likelihood and impact scales, and read the risk determination matrix. Includes the semi-quantitative scoring bins and qualitative vs. semi-quantitative tradeoffs.
SP 800-53 Control Tailoring: A Daunting Task Made Systematic
SP 800-53 Rev 5 has 20 control families and over 1,000 controls. Tailoring, adjusting the baseline to fit your system, is where most authorization teams stall. Here's the decision framework that makes it tractable.
Why Your Heat Map Doesn't Match Your Risk Score
The NIST SP 800-30 qualitative heat map and your calculated risk score tell two different stories. Here's why that happens, and how RPT's semi-quantitative approach makes them consistent.
RMF Simplified: How the Seven Steps Bring Clarity to System Authorization
The NIST Risk Management Framework's seven steps aren't bureaucracy, they're a decision sequence. Breaking each one down reveals exactly what the framework is trying to accomplish.
What Is Risk? The NIST Definition and Why It Changes How You Assess
Risk has a precise meaning in the NIST framework, and it's not simply "the chance something bad happens." Understanding the real definition transforms how you write and defend assessment findings.