CyberSheath

CyberSheath CyberSheath has a long track record of helping our customers with NIST SP 800-171, DFARS and now CMMC

AI is changing the cybersecurity calculus fast. Attackers are using AI to automate reconnaissance, personalize phishing ...
08/31/2026

AI is changing the cybersecurity calculus fast. Attackers are using AI to automate reconnaissance, personalize phishing at scale, and develop malware that adapts in real time. For defense contractors handling Controlled Unclassified Information, the stakes are higher.

At CMMC CON 2026, Microsoft Chief Security Advisor Kevin Thomas will dig deeper into the new era of cyber threats in a session titled, โ€œSecurity risks in the age of AI,โ€ on Sept. 23 at 12 p.m. ET.

Thomasโ€™ session will cover four areas, each with actionable steps contractors can take with existing resources:

๐Ÿ”ธHow the threat model has changed
๐Ÿ”ธWhere risk profiles are moving
๐Ÿ”ธFighting AI with AI while getting the basics right
๐Ÿ”ธA 90-day start with the team you have

Register now for CMMC CON 2026 > https://bit.ly/3Ut9MzE

-171

The 2026 State of the DIB Report found that the average Supplier Performance Risk System (SPRS) score rose to a five-yea...
08/28/2026

The 2026 State of the DIB Report found that the average Supplier Performance Risk System (SPRS) score rose to a five-year high of +51, up from +33 in 2025.

Yet confidence in those scores fell 24 percentage points. Only 65% of contractors say theyโ€™re extremely or very confident that their score is accurate, down from 89% last year and 94% in 2024.

So, can you trust your SPRS score?

Download the full report to see how your organization compares and what the data reveals about cybersecurity readiness across the DIB: https://bit.ly/45ELeWH

โ€œAs we've seen in many leading cyber cases that have been brought forth by the government, it comes back to the evidence...
08/27/2026

โ€œAs we've seen in many leading cyber cases that have been brought forth by the government, it comes back to the evidence and documentation." ๐Ÿง‘โ€โš–๏ธ๐Ÿ›๏ธ

That point from Michael Gruden, Partner at Steptoe, gets to the heart of the compliance challenge facing the Defense Industrial Base: Can you prove that your cybersecurity claims match reality?

Defense contractors are responsible for accurately representing their cybersecurity posture. That means ensuring representations to the government are accurate and supportable โ€” or risk legal exposure and enforcement.

In a new episode of Mission: Cyber, host Emil Sayegh sits down with Michael, a leading cybersecurity and incident-response attorney whose career spans the Pentagon, DHS, and private practice.

In this episode, they cover:

๐Ÿ”ธ Why protecting CUI remains a fundamental obligation
๐Ÿ”ธ How inaccurate attestations can create legal exposure
๐Ÿ”ธ What DOJ enforcement means for contractors of all sizes
๐Ÿ”ธ How organizations can pressure-test their cybersecurity posture

Whether you're a CEO, CIO, CISO, or compliance leader, this conversation offers a practical perspective on navigating cybersecurity requirements while protecting both the mission and your organization.

๐ŸŽง Listen on Apple Podcasts: https://podcasts.apple.com/us/podcast/michael-gruden-on-cui-protection-legal-exposure-and/id6788538904?i=1000786064026
๐ŸŽ™๏ธ Listen on Spotify: https://open.spotify.com/episode/2qQqGpT7WRkKcijpKlPbHJ?si=zDXjnWXJR6Ot6aNwtuRzNw

Pentagon leader James R. Mismash, Deputy Assistant Secretary of War for Industrial Base Growth and Director of Small Bus...
08/26/2026

Pentagon leader James R. Mismash, Deputy Assistant Secretary of War for Industrial Base Growth and Director of Small Business Programs, will keynote CMMC CON 2026 on Sept. 24 at 9 a.m. ET.

Cybersecurity and industrial base readiness are inseparable. In his keynote, Mismash will share the governmentโ€™s perspective on strengthening DIB cybersecurity, reducing unnecessary burden, eliminating barriers, accelerating capability delivery, and expanding participation across the defense supply chain.

Read the blog and register for the free virtual event (Sept. 23โ€“24) > https://bit.ly/4d0tIjC

SEP started its path to CMMC certification with an enterprise-wide gap assessment that revealed the need for a dedicated...
08/25/2026

SEP started its path to CMMC certification with an enterprise-wide gap assessment that revealed the need for a dedicated enclave.

Leadership then brought in outside expertise to help interpret the requirements and implement a solution that fit its existing operations. The result was a purpose-built enclave for its defense work that allowed commercial work to continue without disruption.

The company ultimately earned a perfect 110 on its CMMC Level 2 assessment.

Read the full case study: https://bit.ly/4xDbBrX

Prime contractors are not waiting on CMMC timelines to raise the bar on supplier cybersecurity.They are tightening flowd...
08/21/2026

Prime contractors are not waiting on CMMC timelines to raise the bar on supplier cybersecurity.

They are tightening flowdowns, asking for clearer evidence, and making supplier readiness part of sourcing and program risk decisions.

At CMMC CON 2026, the session โ€œHow Primes Are Prioritizing CMMC Readiness (and What They Expect from Subcontractors)โ€ featuring Doug Cherry (Monterey Technologies, Inc.) and Megan Downie (Spirit Electronics) will unpack what that looks like in practice.

Hear directly from prime contractors on what requirements are becoming increasingly non-negotiable, the most common gaps they see across small and mid-sized suppliers, how they validate alignment to NIST SP 800-171 and what evidence they expect.

Register now: https://bit.ly/4qs5Lau

The 2026 State of the Defense Industrial Base Report is here and this yearโ€™s findings reveal a critical shift in the DIB...
08/20/2026

The 2026 State of the Defense Industrial Base Report is here and this yearโ€™s findings reveal a critical shift in the DIB.

Defense contractors are making measurable cybersecurity progress but their confidence in that progress is falling. Our fifth annual study, conducted by Merrill Research, found:

๐Ÿ”ธ SPRS scores hit +51, the highest in the studyโ€™s history
๐Ÿ”ธ Confidence in those scores fell to 65%, down sharply from 89% last year
๐Ÿ”ธ Only 1% of contractors say theyโ€™re fully ready for CMMC
๐Ÿ”ธ Average annual compliance budgets reached $155,204

The numbers tell a complicated story. Investment is up, documentation is improving, and compliance scores are rising. But proving that reported compliance reflects operational reality โ€” and that an Affirming Official can stand behind it โ€” is becoming one of the DIBโ€™s biggest challenges.

This yearโ€™s report also breaks down:

๐Ÿ”น The impact of the Pentagonโ€™s CMMC Phase 2 pause
๐Ÿ”น Ongoing DOJ and DIBCAC enforcement
๐Ÿ”น Thirdโ€‘party risk across the supply chain
๐Ÿ”น What defense contractors want improved

Get the full picture of where the DIB stands today and what it will take to stay compliant, competitive, and contractโ€‘ready.

Download the 2026 State of the DIB Report:

By completing this form, I consent to receiving calls, texts and/or emails from CyberSheath regarding services and programs. Cybersecurity investment is

Congratulations to Gemini Industries on achieving CMMC Level 2 certification with a perfect 110/110 score. ๐Ÿ‘With the sup...
08/18/2026

Congratulations to Gemini Industries on achieving CMMC Level 2 certification with a perfect 110/110 score. ๐Ÿ‘

With the support of CyberSheath, Gemini strengthened and sustained a mature cybersecurity program across a complex environment that includes multiple sites, ITAR-controlled programs, and ISO compliance requirements. The third-party assessment validated that investment and gives Geminiโ€™s U.S. government and national security customers added confidence in how CUI is protected.

Read the full announcement to learn why Gemini chose to certify now and how the program was validated through third-party assessment >

Gemini Industries strengthened its cybersecurity program and achieved CMMC Level 2 certification with the support of CyberSheath.

If youโ€™ve spoken to a Microsoft 365 reseller recently, you were likely told you need GCC High, without an assessment of ...
08/17/2026

If youโ€™ve spoken to a Microsoft 365 reseller recently, you were likely told you need GCC High, without an assessment of your environment, a review of your contracts, or a conversation about the types of data you handle.

Hereโ€™s what to consider before choosing the right environment for your organization to avoid unnecessary cost and complexity:

Choose GCC vs GCC High for DFARS, NIST 800-171 and CMMC based on contracts and CUI. Learn when ITAR/EAR requires GCC High and enclave options.

SEP, one of Indiana's largest software development companies, recognized that independently verified CMMC compliance cou...
08/14/2026

SEP, one of Indiana's largest software development companies, recognized that independently verified CMMC compliance could strengthen its position in the defense market.

Their approach offers several lessons for defense contractors:

๐Ÿ”ธ ๐—•๐˜‚๐—ถ๐—น๐—ฑ ๐˜๐—ต๐—ฒ ๐—ฏ๐˜‚๐˜€๐—ถ๐—ป๐—ฒ๐˜€๐˜€ ๐—ฐ๐—ฎ๐˜€๐—ฒ ๐—ฏ๐—ฒ๐—ณ๐—ผ๐—ฟ๐—ฒ ๐˜๐—ต๐—ฒ ๐˜๐—ฒ๐—ฐ๐—ต๐—ป๐—ถ๐—ฐ๐—ฎ๐—น ๐—ฐ๐—ฎ๐˜€๐—ฒ. SEPโ€™s leadership started by identifying the expected outcomes of certification โ€” not just continued eligibility for defense work, but market distinction and new business development opportunities. That clarity on benefits informed every subsequent decision, from scoping to partner selection.

๐Ÿ”ธ ๐—จ๐—ป๐—ฑ๐—ฒ๐—ฟ๐˜€๐˜๐—ฎ๐—ป๐—ฑ ๐˜†๐—ผ๐˜‚๐—ฟ ๐˜๐—ผ๐˜๐—ฎ๐—น ๐—ถ๐—ป๐˜ƒ๐—ฒ๐˜€๐˜๐—บ๐—ฒ๐—ป๐˜, ๐—ป๐—ผ๐˜ ๐—ท๐˜‚๐˜€๐˜ ๐˜๐—ต๐—ฒ ๐˜‚๐—ฝ๐—ณ๐—ฟ๐—ผ๐—ป๐˜ ๐—ฐ๐—ผ๐˜€๐˜. Assessment fees and implementation costs are only part of the picture. CMMC certification operates on a three-year cycle, and the ongoing cost of maintaining compliance should factor into the business case from the beginning.

๐Ÿ”ธ ๐—”๐˜€๐˜€๐—ฒ๐˜€๐˜€ ๐˜๐—ต๐—ฒ ๐—บ๐—ฎ๐˜๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—ผ๐—ณ ๐˜†๐—ผ๐˜‚๐—ฟ ๐˜€๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—ฝ๐—ฟ๐—ผ๐—ณ๐—ถ๐—น๐—ฒ ๐—ฒ๐—ฎ๐—ฟ๐—น๐˜†. A realistic understanding of your current security posture leads to a meaningful gap analysis, which in turn provides reliable cost projections and a defensible implementation timeline. Starting from assumptions rather than evidence creates risk on both fronts.

๐Ÿ”ธ ๐—ฆ๐—ฒ๐—น๐—ฒ๐—ฐ๐˜ ๐—ฎ ๐—ฝ๐—ฎ๐—ฟ๐˜๐—ป๐—ฒ๐—ฟ ๐—ฏ๐—ฎ๐˜€๐—ฒ๐—ฑ ๐—ผ๐—ป ๐˜†๐—ผ๐˜‚๐—ฟ ๐—ผ๐˜„๐—ป ๐—ผ๐—ฝ๐—ฒ๐—ฟ๐—ฎ๐˜๐—ถ๐—ผ๐—ป๐—ฎ๐—น ๐—ป๐—ฒ๐—ฒ๐—ฑ๐˜€. SEPโ€™s team invested time in understanding how it operates before evaluating partners, which allowed it to assess fit against defined criteria rather than relying on reputation or sales conversations alone.

Read the full story to see how SEP approached its path to CMMC certification: https://bit.ly/4xDbBrX

Address

11710 Plaza America Drive, Suite 2000
Reston, VA

Alerts

Be the first to know and let us send you an email when CyberSheath posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share