Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗

Resource Library

In-depth knowledge base articles plus authoritative DoW, NIST, CISA, NSA, DC3, and Project Spectrum sources — identified, dated, and linked to the original publisher.

Looking across everything at once? Search practices, guides, articles, downloads, and mappings →

KNOWLEDGE BASE

In-depth articles

Independent, plain-language explainers on the standards and controls behind the Top 10.

Browse the knowledge base →
Identity & Authentication8 MIN READ

Replay-Resistant vs. Phishing-Resistant Authentication

Replay-resistant and phishing-resistant are different security properties — and phishing-resistant is stronger. Replay resistance is a numbered control in both NIST SP 800-171 Rev 2 (3.5.4) and Rev 3 (03.05.04); phishing-resistant is defined in SP 800-63B and mandated by OMB M-22-09, not by a base 800-171 control.

UPDATED 2026-07-21Read the article →
Compliance Frameworks9 MIN READ

CMMC vs. NIST SP 800-171: What’s the Difference?

NIST SP 800-171 is the security control set for protecting CUI; CMMC is the DoD program that verifies you actually implemented it. Level 2 CMMC is the same 110 requirements from 800-171 Rev 2 — the difference is who checks, how often, and what proof is required.

UPDATED 2026-07-28Read the article →
Incident Response & DFARS8 MIN READ

DFARS 7012’s 72-Hour Rule: What It Actually Requires

DFARS 252.204-7012 requires contractors to report a discovered cyber incident to DoD within 72 hours via DIBNet, preserve affected media for at least 90 days, and submit malicious software to DC3 — plus flow the clause down to subcontractors. The report itself is only part of the obligation.

UPDATED 2026-07-21Read the article →
Cloud & Architecture9 MIN READ

GCC High vs. Commercial Microsoft 365: Do You Actually Need It?

GCC High is Microsoft 365 in a US-sovereign, screened-US-persons cloud with FedRAMP High and DoD IL4/IL5 authorization. You need it for ITAR/export-controlled data and CUI Specified; Commercial or GCC may suffice for lighter CUI — but confirm with your prime. It costs more and migration is a real project.

UPDATED 2026-07-21Read the article →
Getting Started6 MIN READ

The Top Mistakes DIB Teams Make When Starting the Basics

Most Top 10 programs don't fail on hard technology — they stall on avoidable patterns: boiling the ocean, mistaking 'we bought it' for 'it works,' and never testing recovery. Here are the common mistakes DIB teams make starting out, and the simple fixes.

UPDATED 2026-07-21Read the article →
Getting Started5 MIN READ

What Good Looks Like: The IT Top 10 at a Glance

A high-level 'done looks like' for each IT Top 10 practice — the validation test that shows a control actually works, not just that it was purchased. Use it as a quick self-check, then open the full guides for the how-to.

UPDATED 2026-07-21Read the article →
Scoping & Architecture14 MIN READ

Scoping Your CUI Boundary: Discovery Methods, Remediation Paths, and the Numbers That Decide

Scope size is the master cost driver in a CMMC Level 2 program — it sets how many premium licenses you pay for, how big your assessment is, and how much CUI you're liable for. How you find your CUI (a top-down traceability cascade, staff interviews, or automated digital discovery) determines how accurately you can size the boundary, and four remediation paths — surgical file cleanup, a user-account enclave, program segmentation, or enterprise migration — are chosen mostly by two ratios: what share of users touch CUI, and how sprawled it already is.

UPDATED 2026-07-28Read the article →
Cloud & Architecture10 MIN READ

What Should a GCC High Migration Cost?

A GCC High migration priced honestly has three parts: a fixed base to stand up and harden the environment (around $15,500), migration tooling like AvePoint (there is no native commercial-to-GCC-High path), and roughly $250 per user to move and validate mail, files, and Teams. Total ≈ $15,500 + tooling + ($250 × users). The cost nobody quotes correctly is the risk in the mapping and cutover — get those wrong and you pay again in spillage, broken permissions, and downtime.

UPDATED 2026-07-21Read the article →
Cloud & Architecture9 MIN READ

Windows Pro vs. Enterprise for NIST 800-171 Rev 3: The Endpoint Parity Gap

For NIST 800-171 Rev 3, the endpoint controls quietly require Windows Enterprise. Rev 3 sharpened application allowlisting (03.04.08), and the licensed, manageable engine — AppLocker — needs a Windows Enterprise E3/E5 or Education license; Pro isn't entitled. App Control for Business (WDAC) runs on Pro but is the harder engine and no substitute for the rest: Credential Guard (Enterprise-only), Defender for Endpoint EDR (E5), and more. In GCC High, getting those Enterprise licenses onto devices is partner-mediated and portal-fragmented.

UPDATED 2026-07-21Read the article →
Compliance Frameworks9 MIN READ

Your SPRS Score, Explained: How the DoD Assessment Methodology Works

Your SPRS score is a self-reported number from 110 down to -203 that tells the DoD how much of NIST SP 800-171 you have actually implemented. It starts at 110, and every unmet requirement subtracts a weighted value of 5, 3, or 1 point. Two requirements — multifactor authentication and FIPS-validated encryption — are the only ones that grant partial credit.

UPDATED 2026-07-21Read the article →
Compliance Frameworks11 MIN READ

CMMC Phase II Is Suspended — What You Still Have to Do

On July 13, 2026 the Department of War suspended the CMMC Phase II transition during a 60-day program review. Third-party (C3PAO) and Level 3 designations are paused and November 10, 2026 is no longer an operative date — but DFARS 252.204-7012, NIST SP 800-171 Rev 2, 72-hour incident reporting, SPRS score accuracy, and the Program Rule at 32 CFR Part 170 all remain in force.

UPDATED 2026-07-28Read the article →
Compliance Frameworks10 MIN READ

FCI, CUI, CDI — How the Rules Stack Together

The security stack is driven first by the information involved, then by the clauses, assessment level, and contract-specific requirements that apply to the system handling it. FCI, CUI, and CDI are overlapping categories with different triggers — and export-controlled information sits on top as an independent legal overlay.

UPDATED 2026-07-28Read the article →
Compliance Frameworks12 MIN READ

The Foundation Clauses — FAR 52.204-21 and the DFARS 7012 Family

FAR 52.204-21 and DFARS 252.204-7012, -7019, -7020 and -7021 form the contractual backbone of defense cybersecurity. Each has a distinct trigger, obligation, and flowdown. Alongside them sits an independent supply-chain gate that can exclude an otherwise-compliant technology from a covered contract.

UPDATED 2026-07-28Read the article →
Export Controls11 MIN READ

CUI Is Not an Export License — ITAR and EAR as a Separate Overlay

Export control is a separate legal overlay from CUI safeguarding. The controlling authority, classification, destination, end user, nationality, access path, license or exemption, and technical facts determine whether a transfer or release is authorized — none of which is answered by a CUI banner or a CMMC status.

UPDATED 2026-07-28Read the article →
Compliance Frameworks14 MIN READ

NIST SP 800-171 Rev. 3: Fewer Requirements, More Work

NIST SP 800-171 Rev. 3 reduced the requirement count from 110 to 97, but consolidation, organization-defined parameters, three new families, and a larger assessment-procedure catalog mean the burden went up, not down. Where the work concentrates — supply chain, ODPs, planning and acquisition, monitoring, identity, and shared responsibility — with OSC and ESP guidance for each.

UPDATED 2026-08-07Read the article →
Compliance Frameworks16 MIN READ

The Three New Rev. 3 Families: SR, PL, and SA, Requirement by Requirement

Rev. 3's three new families — Planning, System and Services Acquisition, and Supply Chain Risk Management — hold the nine requirements that concentrate the revision's new work. What each asks, its organization-defined parameters, and its operating evidence, from the OSC and ESP seats.

UPDATED 2026-08-07Read the article →
Compliance Frameworks13 MIN READ

A Prioritized Rev. 3 Remediation Roadmap, From Where You Actually Are

Three honest starting profiles — a paper program, an operating Rev. 2 program, and a provider-dependent one — mapped to the site's maturity ladder, each with a phased Rev. 3 preparation sequence (now / 60 / 90 / 180 days) split for OSCs and ESPs.

UPDATED 2026-08-07Read the article →
Compliance Frameworks13 MIN READ

The ESP Rev. 3 Readiness Guide: What Service Providers Owe Every Client

NIST SP 800-171 Rev. 3 puts service providers inside every client's assessable scope: the new SR family names you as a supplier, ODPs collide with your standardized baselines, and your technicians hold the highest-privilege accounts in every tenant. A readiness guide for MSPs and MSSPs — one standing evidence package, authored responsibility matrices, and per-client parameter discipline.

UPDATED 2026-08-07Read the article →
Compliance Frameworks12 MIN READ

What to Ask Your MSP For: The Evidence a Provider Should Hand You

The specific evidence a contractor should receive from its MSP or MSSP: a standing package delivered on a cadence, a per-service responsibility matrix with the evidence hand-off named, contract terms covering notification, data return, and offboarding — plus the red-flag answers that signal trouble. Written to the buyer, with the provider's view in every toggle.

UPDATED 2026-08-07Read the article →
SOURCE REGISTRY

Authoritative sources

Official campaign, framework, and program links — each with its publisher, provenance, and most recent verification date.

22 RESOURCES

DoD Zero Trust Strategy

The department-level target architecture that the IT Top 10 supports.

OFFICIAL SOURCEITDoD CIO · Strategy · IT-01 IT-05

NIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal Systems

The 110 security requirements for protecting Controlled Unclassified Information in nonfederal systems. Published February 2020; includes update 1 (January 2021). Withdrawn by NIST and superseded by Rev. 3 — publication status is separate from contractual applicability, and many DFARS-based contracts still reference Rev. 2; read your contract. Basis of this site's Rev. 2 requirement pages.

OFFICIAL SOURCEWITHDRAWN — SEE SUMMARYITOTNIST · Publication · IT-01 IT-02 IT-05

NIST SP 800-171A — Assessing Security Requirements for CUI

The assessment procedures companion to Rev. 2 (published June 2018): the determination statements and assessment objects behind each requirement — the closest thing to knowing what an assessor will actually examine.

OFFICIAL SOURCEITOTNIST · Publication · IT-02 IT-09

NIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal Systems

The current revision (published May 2024): 97 requirements across 17 families, aligned to SP 800-53 Rev. 5, with organization-defined parameters and three new families — Planning, System and Services Acquisition, and Supply Chain Risk Management. Basis of this site's Rev. 3 requirement pages. NIST's analysis-of-changes supplemental material on the same page documents the official Rev. 2 to Rev. 3 differences.

OFFICIAL SOURCEITOTNIST · Publication · IT-01 IT-03 IT-08

NIST Cybersecurity Framework (CSF) 2.0

The framework of cybersecurity outcomes (published February 2024) that several practice mappings reference — governance, identify, protect, detect, respond, recover. Describes outcomes, not testable compliance controls.

OFFICIAL SOURCEITOTNIST · Framework · OT-02 OT-04 OT-07 IT-09

NIST SP 800-161 Rev. 1, Update 1 — C-SCRM Practices

Cybersecurity supply chain risk management practices for systems and organizations. Update 1 (November 2024) supersedes the May 2022 edition — cite the update, not the original.

OFFICIAL SOURCEITOTNIST · Publication · OT-09

NIST SP 1800-45 — Secure Remote Access for OT

Demonstrated secure remote-access architectures for operational technology (final, June 2026) — the brokered, authenticated, time-bound pattern the OT-06 practice builds, shown as implemented example builds.

OFFICIAL SOURCEOTNIST NCCoE · Practice guide · OT-06

NIST SP 1339 — OT Backup Quick Start Guide

Quick-start guidance for OT backups (final, June 2026): regular backups, integration with change management, testing, and recovery exercises — directly supporting the OT resiliency and recovery practices.

OFFICIAL SOURCEOTNIST · Guide · OT-08 OT-04

IEC 62443-2-1:2024 — Security Program Requirements for IACS Asset Owners

The 2024 edition restructures the asset-owner security program into Security Program Elements and adds a maturity model. Replaces the withdrawn 2010 edition — cite the 2024 edition.

OFFICIAL SOURCEOTIEC · Standard · OT-02 OT-04 OT-10

Normative text is licensed; exact Security Program Element identifiers pend verification against a licensed copy.

IEC TR 62443-2-3:2015 — Patch Management in the IACS Environment

Patch management guidance specific to industrial automation and control systems — the reference behind OT-05's patch-or-compensate discipline.

OFFICIAL SOURCEOTIEC · Technical report · OT-05

A Technical Report (informative), not an International Standard; text is licensed.

IEC 62443-3-2:2020 — Security Risk Assessment for System Design

The part of the 62443 series that requires defining the system under consideration, partitioning it into zones and conduits, assessing risk per zone and conduit, and setting target security levels — the primary zones-and-conduits reference for OT-03.

OFFICIAL SOURCEOTIEC · Standard · OT-03

Normative text is licensed.

IEC 62443-3-3:2013 — System Security Requirements and Security Levels

Technical system security requirements and security levels applied to zones and conduits once IEC 62443-3-2 has defined them. Companion to, not a substitute for, the zones-and-conduits design standard.

OFFICIAL SOURCEOTIEC · Standard · OT-01 OT-06 OT-07 OT-08

Normative text is licensed; individual SR identifiers cited on practice pages pend verification against a licensed copy.

Project Spectrum

No-cost cybersecurity readiness resources for DIB small businesses.

OFFICIAL SOURCEITOTDoW OSBP · Program · IT-10

Teramis — Automated CUI Discovery

A commercial tool that automatically discovers and continuously monitors CUI across files and endpoints — including formats many scanners miss, like CAD drawings, PDFs, and scanned images — and flags CUI that has drifted outside its authorized boundary. Useful for the digital-discovery step of scoping.

VENDOR TOOLITTeramis · Tool · IT-02