Search
Logo
Sign Up
Login
Home
Guides
About
Archive
Federal Cyber Brief

Guides

FCI vs CUI: Which One Does Your Contract Involve?

FCI triggers 15 controls and CMMC Level 1. CUI triggers 110 and Level 2. Here is how to tell which one is on your systems, and who decides.

Aug 3, 2026

•

6 min read

DFARS 252.204-7012 Explained: What "Running 7012" Actually Means

A prime tells you to "run 7012." Here is what the clause actually requires: NIST 800-171, 72-hour incident reporting, a 90-day media hold, and flow-down to your subs.

Jul 25, 2026

•

7 min read

The FAR CUI Rule: NIST 800-171 Rev 3 Comes to Civilian Contracts

The FAR would extend CUI safeguarding to civilian contractors at NIST 800-171 Rev 3, not the Rev 2 DoD requires. What the proposed rule changes, and when.

Jul 17, 2026

•

6 min read

SPRS Scores: How to Calculate and Report Yours

Your SPRS score runs from -203 to +110 and can gate a DoD award. Here's how the scoring works, how to calculate yours, and how to report it correctly.

Jul 9, 2026

•

5 min read

The DFARS Cyber Clauses, Decoded: 7012, 7019, 7020, 7021, and 7025

Five DFARS clauses govern cybersecurity in DoD contracts: 7012, 7019, 7020, 7021, and 7025. Here's what each one requires and how they fit together.

Jul 2, 2026

•

5 min read

The Revolutionary FAR Overhaul: What It Means for Small Federal Contractors

The FAR Overhaul's first proposed rules are out, with comments due July 23. Here's what's confirmed, what's coming, and what it means for contractors.

Jun 29, 2026

•

7 min read

CMMC Self-Assessment vs C3PAO: How the Assessment Actually Works

For CMMC Level 2, your contract assigns one of two paths: a self-assessment you attest to, or a third-party C3PAO certification. Here's how each works.

Jun 27, 2026

•

5 min read

NIST 800-171 Explained: The 110 Controls Behind CMMC Level 2

CMMC Level 2 is built on the 110 NIST SP 800-171 Rev 2 controls, grouped into 14 families. Here's what each one covers and how your SPRS score works.

Jun 24, 2026

•

6 min read

CMMC Level 1 vs 2 vs 3: Which Level Does Your Contract Require?

Your CMMC level is assigned by the government, not chosen by you. FCI points to Level 1, CUI to Level 2 — and Level 2 splits into self-assessment and C3PAO certification. Here's how to tell where you land.

Jun 23, 2026

•

6 min read

2026 Compliance Guide: CMMC 2.0 for Small Businesses

CMMC 2.0 for small businesses, explained: the three levels, what each requires, the phased 2026 rollout timeline, and the steps to stay eligible to bid.

Jun 18, 2026

•

8 min read

Follow on LinkedIn for daily GovCon intelligence

SUBSCRIBE TO OUR NEWSLETTER

Weekly intelligence for federal IT & cybersecurity contractors. Cleared to Bid.

© 2026 Federal Cyber Brief.
beehiivPowered by beehiiv