The ITNETCS Blog
Practical, plain-language guidance on federal assessments, cybersecurity, and ISO — organized by the frameworks we help clients navigate.
Federal Assessments
CMMC Self-Assessment, SPRS Scores, and the False Claims Act Risk
CMMC self-assessment for Level 1 (FCI) and Level 2 (CUI): how SPRS scoring and the management affirmation work, and why a fudged score risks False Claims Act liability.
CMMC & NIST SP 800-171: What Every Defense Contractor Needs to Know
How CMMC and NIST SP 800-171 work together, who needs them, the 110 controls, the 2026 landscape, and how defense contractors can prepare.
AS9100 to IA9100: What Contractors and Subcontractors Should Expect
AS9100 is becoming IA9100. The timeline, what is changing (including new cybersecurity clauses), and what contractors and subcontractors should expect.
Where IA9100 and CMMC Overlap: One System, Two Frameworks
Where IA9100 aerospace quality and CMMC cybersecurity overlap - a clause-by-clause map and how to run one integrated management system.
CMMC and DFARS: How They Work Together
How DFARS and CMMC work together - clauses 7012 to 7021, the similarities and differences, and the key 2016 to 2026 regulatory shifts.
FedRAMP: Authorizing Cloud Services for Federal Use
What FedRAMP is: impact levels, the authorization path and Marketplace, the 2025-2026 modernization, and how it differs from CMMC.
GovRAMP (formerly StateRAMP): Security for State & Local Government
GovRAMP (formerly StateRAMP) explained - security assessment for state, local and education government, verified statuses, and how it compares to FedRAMP.
Cybersecurity
ISO
We are a CMMC RPO providing assessments, vCISO leadership, and training for defense contractors and growing businesses.