Free Resources to Help You Figure Out Where You Stand.

Compliance requirements are dense, technical, and often written in a way that makes them hard to act on. These resources are our attempt to fix that. Everything here is free, and none of it requires a sales conversation to be useful.

Free Resources to Help You Figure Out Where You Stand.

Compliance requirements are dense, technical, and often written in a way that makes them hard to act on. These resources are our attempt to fix that. Everything here is free, and none of it requires a sales conversation to be useful.

Start Here

Start Here

Pick the one that matches your situation.

Guide  |  For defense contractors and subcontractors

Top 10 CMMC Misconceptions

The ten assumptions we encounter most often in the Defense Industrial Base (DIB), and why each one puts contracts at risk. Written by CMMC Certified Assessors who have been trained to evaluate compliance programs from the assessment side.

Interactive tool  |  For defense contractors and subcontractors

CMMC Level 2 Readiness Assessment

Answer 40 questions about your organization and receive an instant readiness score, a tier rating, and a section-by-section breakdown of where your gaps are. Takes about 10 minutes.

Checklist  |  For defense contractors and subcontractors

CMMC Level 2 Readiness Checklist

The printable version, organized for leadership and program readiness. Useful if you want something to work through with your team or share internally.

Checklist  |  For insurance agencies and brokerages

Insurance Agency Cybersecurity Compliance Checklist

A quick self-check across the Gramm-Leach-Bliley Act (GLBA), the Federal Trade Commission (FTC) Safeguards Rule, state insurance commissioner requirements, and vendor oversight.

Checklist  |  For RIAs, advisors, and wealth management firms

Financial Firm Cybersecurity Compliance Checklist

A self-check across GLBA, Securities and Exchange Commission (SEC) Regulation S-P, examination readiness, and third-party oversight.

CMMC Webinar

CMMC Webinar

Brian Guenther presented to veteran-owned defense contractors on what the CMMC final rule actually requires, the misconceptions that put contracts at risk, and how to approach a program build. Roughly an hour, aimed at contractors who are trying to get oriented.

Questions We Get Asked

Questions We Get Asked

If your question is not here, ask us directly. We answer these all day and are happy to answer yours.

CMMC and Defense Contracting

If your DoD contracts include DFARS clause 252.204-7012 and you handle Controlled Unclassified Information (CUI), you are subject to NIST 800-171 requirements today and are likely to face CMMC Level 2 requirements. The volume of CUI you handle does not change this. Any CUI triggers the obligation.

For an organization starting from little or nothing, 12 to 18 months is realistic. That timeline reflects the work of scoping your environment, designing the program, building the documentation, and implementing and evidencing the controls.

A self-assessment is your organization evaluating itself and submitting a score to the Supplier Performance Risk System (SPRS). A certification assessment is an independent evaluation by a Certified Third-Party Assessment Organization (C3PAO) verifying every practice against all 320 assessment objectives. They are not interchangeable.

Usually not. CMMC Level 2 requires documented policies, procedures, a System Security Plan, and evidenced implementation of 110 NIST 800-171 practices. That is compliance program work, not IT support work. Unless your provider has specific CMMC expertise, there is likely a gap between what they are delivering and what an assessment requires.

No. Microsoft Government Community Cloud High addresses a subset of technical controls. It does not address your policies, procedures, access management practices, incident response, physical security, or the many non-technical requirements an assessment evaluates. It is a tool, not a program.

It is our methodology for building a CMMC Level 2 compliance program: Compliance, Readiness, Architecture, Framework, and Tracking. It exists because sequencing matters enormously in this work, and doing things out of order creates rework and gaps that surface at the worst possible time.

Insurance Agencies

Yes, if your agency handles nonpublic personal information (NPI). The Gramm-Leach-Bliley Act (GLBA) and the FTC Safeguards Rule apply to financial institutions of every size, and insurance agencies are explicitly included regardless of employee count or revenue.

A Written Information Security Program is the documented security program that federal and state regulators require. It covers your data protection policies, access controls, employee responsibilities, vendor oversight, and incident response. If your agency handles client NPI, you need one.

The National Association of Insurance Commissioners (NAIC) Insurance Data Security Model Law requires licensed insurance entities to maintain an information security program, conduct risk assessments, oversee third-party providers, and report cybersecurity events to your commissioner within defined timeframes. It operates independently of your federal obligations.

No. We frequently work alongside a client’s existing IT provider, delivering the compliance and security layer that general IT support is not built to provide. That co-managed arrangement is something we already do for clients today.

Financial Firms

Recent amendments significantly strengthened the rule, adding explicit requirements for a written incident response program and an obligation to notify affected individuals when their sensitive information is compromised. Firms that have not updated their programs since those amendments are likely out of step.

Commonly: a documented risk assessment, written policies and procedures that reflect actual practice, access controls, vendor oversight, and an incident response plan. The absence of these is a frequent examination finding.

Yes. Neither Regulation S-P nor GLBA has a size exemption, and SEC examinations reach firms of every size.

General

A compromise is unauthorized access to your systems. A breach is confirmed exposure or theft of data, which is what typically triggers notification obligations. A compromise almost always comes first and can go undetected for months. Catching intrusions in that window is what substantially lessens the likelihood of one or more compromises becoming a breach.

We examine your actual environment: where sensitive data lives, how it moves, who can access it, what is exposed, and what a compromise would realistically mean for a business like yours. It is the starting point for every engagement, compliance or otherwise.

Yes. While Exceed Cybersecurity is headquartered in Maryland, we are a fully virtual company with staff in various parts of the country. And, since compliance and managed security work is largely performed remotely, we have many clients across the United States.

Schedule a free 30-minute call. We will learn about your situation and give you an honest read on what you are facing and what it would take to address it. No obligation.

Still Have Questions? Ask Us Directly.

Still Have Questions? Ask Us Directly.

Every one of these resources exists because someone asked us a question. If yours is not answered here, schedule a free call and we will answer it.