While the CMMC Reform Task Force report is pending, one thing hasn't changed: CMMC Level 1 self-assessment requirements are still in effect. And Level 1 is more confusing than "foundational" suggests. Its 15 requirements break down into 59 assessment objectives, and a requirement is only MET when every one of its objectives is satisfied. There's no partial credit and no POA&M. A named Affirming Official signs for the result, which carries False Claims Act liability, and the self-assessment has to be redone every year. Our new guide explains what to actually do for each requirement in plain language, what evidence proves it, and the pitfall that most often trips up small contractors. (It also explains why most Level 1 contractors don't need GCC High.) Read more: https://hubs.li/Q04z6lFC0
Secureframe
Software Development
San Francisco, CA 30,270 followers
Award-winning startup providing security compliance automation and AI
About us
Secureframe is an award-winning security and compliance automation platform trusted by organizations ranging from startups and SMBs to contractors across the defense industrial base, including Nasdaq, Fivetran, Base Power, Hawkeye360, and OpenEvidence. Through 400+ integrations with platforms like Microsoft GCC High, Azure Government, AWS GovCloud, and Google Workspace, Secureframe uses AI to automatically collect and verify audit evidence, monitor security controls, and generate critical documentation like SSPs and POA&Ms. Teams use Secureframe to stay assessment-ready across frameworks including CMMC, FedRAMP 20x, NIST, SOC 2, and ISO 27001. Backed by Kleiner Perkins, Accomplice, and In-Q-Tel.
- Website
-
https://secureframe.com/cmmc
External link for Secureframe
- Industry
- Software Development
- Company size
- 201-500 employees
- Headquarters
- San Francisco, CA
- Type
- Privately Held
- Founded
- 2020
- Specialties
- SOC 2, ISO 27001, Security, Compliance, Audit, HIPAA, PCI DSS, GDPR, NIST 800-53, NIST 800-171, CMMC, NIST CSF, ISO 42001, AI, and FedRAMP
Employees at Secureframe
Locations
-
Primary
Get directions
San Francisco, CA, US
-
Get directions
Toronto, Ontario, CA
-
Get directions
New York City, NY, US
-
Get directions
London, GB
Updates
-
FedRAMP 20x Phase 4 is underway. Comments on RFC-0033 and RFC-0034 close this Friday, Oct 9. The Track 2/3 opt-in window runs Oct 12 to 16, and the full Class D pilot requirements are expected Oct 14. If the new Class A through D certification terminology is still unfamiliar, start here. When FedRAMP Authorization became FedRAMP Certification, Dan Chandler, Cloud Security Engineer at GSA's FedRAMP, explained it's more than a rebrand: "A FedRAMP Certification is not a blanket approval that this service is secure enough for the entire federal government." The program validates, and each agency decides. Our explainer breaks down what each Certification class means for CSPs and agencies, including the new Class A entry point, which needs no agency sponsor and no 3PAO. Read more: https://hubs.li/Q04z6lDX0
-
-
While the industry waits on the CMMC Reform Task Force report, one theme keeps coming up: operational technology. DoW CIO Kirsten Davies put it plainly in June: "Nowhere in CMMC was there even a mention of how to build cyber resilience for a manufacturing line." OT came up again at last week's Cyber AB town hall as one of the areas reform could address. While no OT-specific requirements are currently assessed under CMMC, OT assets can already fall inside your assessment scope if they process, store, or transmit covered defense information. An engineering workstation that receives CUI drawings is a common example. Our new guide covers how DFARS and CMMC apply to OT today, how to segment around mission consequence, and a 90-day OT security roadmap. Read more: https://hubs.li/Q04z6lHt0
-
-
69% of executives say the risks facing their organizations have grown in volume and complexity over the past five years. Only 30% describe their risk oversight as mature. Part of the challenge is choosing a foundation for your risk management program. There are dozens of risk management frameworks, and they're built for very different audiences: federal agencies, boards of directors, AI product teams. Our new guide compares 10 of them side by side, including NIST CSF 2.0, NIST RMF, ISO 31000, ISO 27001, COSO ERM, CIS Controls v8.1, FAIR, and the NIST AI RMF. For each one, it covers what it includes, who it fits, whether you can get certified against it, and which combinations work well together. The short version: most mature programs use more than one. Read more: https://hubs.li/Q04yDNgw0
-
-
Cybersecurity Awareness Month starts today, and this year's breach data makes the case for it. The average U.S. data breach now costs a record $11.5 million, more than double the global average (IBM). The human element was present in 62% of breaches (Verizon). And attackers are shifting channels: voice and SMS phishing led to the highest average breach cost of any initial attack vector, at $5.29 million. Manufacturing was also the most targeted industry for the fifth year in a row. That adds weight to the CMMC and NIST SP 800-171 requirements that government contracting officers and primes are already flowing down to their suppliers. We updated our roundup with 140+ of the latest statistics from IBM, Verizon, CrowdStrike, the ITRC, and more, as well as the biggest trends to watch for heading into the new year. Read more: https://hubs.li/Q04yXtYn0
-
-
Congratulations to VieFUND Corporation on achieving their SOC 2 Type II after completing an audit with Prescient Security. For a team serving mutual fund dealers across Canada, this is a big step in demonstrating a strong commitment to protecting client data. We're proud to have been part of the journey. 🔒 🎉
-
-
When will the CMMC Reform Task Force recommendations go public? At The Cyber AB Town Hall last night, Matt Travis guessed the back half of October at the earliest. Recommendations are being drafted with the DoW CIO, and they still need review from General Counsel, OMB, and the White House. In the meantime, Travis and Michael Snyder of The Cyber EF walked through what a reformed program could look like, which they made clear was their own speculation. Highlights included: • Continuous validation and compliance-as-code • Inclusion of OT coverage and Brilliant at the Basics • A hybrid model where C3PAOs assess a priority subset of controls • Alignment to NIST SP 800-171 Rev 3, FedRAMP, and/or other frameworks Our recap covers it all, plus ISC2 survey results about the pause, Level 2 certification growth, and more. Read it here: https://hubs.li/Q04yMzMV0
-
-
Neither DFARS 252.204-7012 nor CMMC formally requires you to deliver a software bill of materials (SBOM). But your prime or government agency you’re working for might ask for one anyway. SBOM requests are showing up more often across the defense supply chain: in statements of work, subcontracts, and vendor security reviews. Many contractors still aren't sure what to include, which format to use, or when an SBOM is actually a contractual deliverable. Our new guide covers when SBOM requirements apply, what a defense contractor SBOM should include, and how to build SBOM generation into your release process at any pipeline maturity. Read more: https://hubs.li/Q04yC_NW0
-
-
Pentesters found an AI agent with access to internal APIs that no other part of the system could reach. When they asked the agent what APIs it had access to and how to call them, it answered. That is just one example of how AI has introduced new security risks, and therefore changed what a penetration test needs to cover. Sherif Koussa, CEO and founder of Software Secured, breaks down the types of AI functionality that represent an attack surface and the three top security risks they introduce (plus why they're familiar). Read how pen testing is changing and what to do next: https://hubs.li/Q04yrs_C0
-
-
Earlier this month, CISA, NSA, and the FBI issued joint advisory AA26-251A on industrial-scale AI model-distillation campaigns targeting U.S. AI companies. For defense contractors, the nearer CUI problem is still local. A generative AI service processes every prompt. If CUI can reach that prompt, DFARS 252.204-7012 requires FedRAMP Moderate equivalency, and an unauthorized copy can become a 72-hour reportable incident. Our guide walks through acceptable use requirements for AI tools and includes an AI policy template you can tailor for a CUI environment. Read more: https://hubs.li/Q04y3hrj0
-