Resources
Insights
Guidance on compliance, threats and security engineering from the people who do the work.
September 22, 2026 · 5 min read
CMMC Explained: Levels, Assessments and Timelines for Defense Contractors
What the Cybersecurity Maturity Model Certification requires at each level, where the rollout stands after the Phase 2 suspension, and what defense contractors should be doing now.
Read moreAugust 25, 2026 · 5 min read
Security Control Assessments: What an Independent Assessor Actually Tests
Examine, interview and test. How independent assessors decide whether security controls really work, and how to prepare your people, documents and systems for each method.
Read moreAugust 18, 2026 · 5 min read
CMMC Level 2 Self-Assessment vs. Third-Party Assessment: Which Applies to You?
With the Phase 2 third-party requirement suspended, Level 2 self-assessments carry more weight than ever. How the two paths differ, and how to prepare so either one goes smoothly.
Read moreJuly 21, 2026 · 5 min read
FedRAMP Readiness: What Cloud Providers Need Before Starting
FedRAMP is changing fast under FedRAMP 20x and the 2026 Consolidated Rules. What stays constant for cloud providers, what is new, and how to prepare before engaging an assessor.
Read moreJune 9, 2026 · 5 min read
STIGs Without the Pain: Implementing and Sustaining DISA Baselines
Security Technical Implementation Guides harden systems against real attacks, but applying them by hand, system by system, never lasts. How to build STIG compliance that survives upgrades and inspections.
Read moreMay 26, 2026 · 5 min read
Protecting Critical Program Information: A Program Protection Primer
Some technologies give U.S. forces an edge that adversaries are determined to take. How programs identify critical program information, assess threats to it, and build protection into the system and its supply chain.
Read moreMay 12, 2026 · 5 min read
Preparing for a CORA Inspection
Cyber Operational Readiness Assessments look at whether a network is actually defensible, not only whether it is documented. How to prepare, what inspectors focus on, and how to avoid the most common failures.
Read moreApril 14, 2026 · 5 min read
Continuous Monitoring After the ATO: Staying Authorized
An authorization to operate is a snapshot of risk on one day. Continuous monitoring keeps that picture current, and done well it makes reauthorization far less painful.
Read moreMarch 17, 2026 · 5 min read
From IATT to ATO: Getting a System Authorized Without Delays
Authorization schedules slip for predictable reasons. A practical guide to the path from interim authorization to test through an authority to operate, and how to keep it on track.
Read more
Let's talk
Ready to strengthen your security posture?
Talk with a CDT engineer about your mission, your systems and your deadlines. We'll tell you honestly what it takes.