Secureframe is the automated compliance platform built by compliance experts. We're transforming how businesses and MSPs manage security & compliance programs.
On average, DIB contractors spend $100K–$250K+ and 6–18 months on CMMC prep. Most can't afford that.
Today, we launched Secureframe Defense to help any organization go from zero to CMMC ready in 4–8 weeks.
Learn how: https://t.co/WaCtnUJqgP
What does a CMMC C3PAO assessment actually look like?
We're joining @prescientsec's webinar this month to break down what to expect before you're in the room with an assessor:
����Timelines & cost
💥Common pitfalls
🏁Readiness vs assessment
Register: https://t.co/9UCC0GM6SM
.@ElbitSystemsLtd: no PO without Level 2.
@L3HarrisTech: certified by July 30 or off the program.
Recent supplier notices show an acceleration in prime CMMC enforcement.
We covered what's driving this and what primes are looking for beyond certification: https://t.co/232igKRDEq
"Just because you go into GCC High doesn't make you magically compliant with CMMC Level 2." — Richard Wakeman, Microsoft
GCC High gets you ~86 of 110 controls. The rest is on you.
Our guide answers what's shared responsibility, which license you need, enclave vs. all-in 👇
https://t.co/mHFoAIe0Ql
96% of ransomware victims in this year's Verizon DBIR were small organizations.
These attacks don't make headlines but they're happening constantly.
Here's what the largest breach dataset in the report's 19-year history means for SMBs & DIB orgs 👉 https://t.co/ILEWgcPTpV
This is exactly the kind of threat Retired Gen. Paul Nakasone was describing at this month's National Cybersecurity Summit.
His warning: "Our adversaries are ahead of where we're at today, and we have to catch up."
Here's what he says to do about it 👇https://t.co/UJP7FnpkHm
The phishing platform, called Kali365, was first seen in April, according to the FBI. It’s primarily distributed through the messaging app Telegram and allows cyber attackers to bypass multi-factor authentication.https://t.co/23TEBKz3y5
The CMMC ecosystem hit notable milestones this month, including nearly 1,400 Level 2 certified orgs.
But the bigger story from the May Cyber AB Town Hall is that many orgs relying on ESPs & MSPs may be incorrectly scoping their L2 assessment.
Recap: https://t.co/pQDvpIzgho
👩🔧What counts as a "significant change" under CMMC?
🔁 What does the latest CMMC FAQ revision clarify about scoping?
✳️ Why is getting and staying certified so important?
Find the answers in this month's newsletter: https://t.co/VDn8pMRkPL
FedRAMP 20x changed more than the process. It changed the language too to clarify a common misconception.
FedRAMP certification ≠ "blanket approval” for the entire government to use the CSP for whatever they want,” a GSA expert explained at last week’s summit.
Recap here: https://t.co/WyhrqYxNwr
The 3-year ATO cycle isn't just inefficient. It's a gift to U.S. adversaries, said former @CISAgov CIO at last week's Summit.
Adversaries operate continuously, adapt in real time, and stay undetected for months. Defenders need to do the same & AI is how.
Recap: https://t.co/PWqK1wqEqD
"Significant change" under CMMC came up again and again at last week's Summit, and for good reason.
The stakes are high: invalidated certifications, reassessment triggered, FCA exposure.
Here's what the CMMC rule says + what assessors told us 👇
https://t.co/WHa6Abwjbf
.@FederalNewsNet cited Rob Joyce's keynote from our summit last week.
The former NSA Director spoke about how AI is finding vulnerabilities at "industrial scale."
Here's what that means for patching deadlines and the CISA KEV catalog: https://t.co/SMUsrMySJL
Asked when orgs should get CMMC compliant, @karringtonsc's reply: "About a year ago."
Throughout her keynote, she emphasized why the lack of DIB readiness is not just a compliance issue and how CMMC is a business enabler, not a hindrance.
Full recap: https://t.co/ZbucnG9Ju9
@karringtonsc@RGB_Lights Missed any of these keynotes or sessions?
You can still register to be notified when on-demand recordings are available.
Sign up at https://t.co/r9NUHTbF6s
Our first National Cybersecurity Summit wrapped yesterday.
Over three days, government and security leaders came together virtually to tackle the most pressing challenges at the intersection of AI, federal compliance, and evolving threats.
Here's what we took away 🧵
@karringtonsc 🤖 AI is no longer optional for defenders.
@RGB_Lights closed us out with a clear message: "The people using AI will outperform those who aren't. So start adopting it now."
Read the full summit highlights here: https://t.co/klp9F4aCMc