Brilliant at the Basics Cybersecurity ↗
The authoritative campaign page and source for the IT and OT Top 10 practices.
In-depth knowledge base articles plus authoritative DoW, NIST, CISA, NSA, DC3, and Project Spectrum sources — identified, dated, and linked to the original publisher.
Looking across everything at once? Search practices, guides, articles, downloads, and mappings →
Independent, plain-language explainers on the standards and controls behind the Top 10.
Replay-resistant and phishing-resistant are different security properties — and phishing-resistant is stronger. Replay resistance is a numbered control in both NIST SP 800-171 Rev 2 (3.5.4) and Rev 3 (03.05.04); phishing-resistant is defined in SP 800-63B and mandated by OMB M-22-09, not by a base 800-171 control.
NIST SP 800-171 is the security control set for protecting CUI; CMMC is the DoD program that verifies you actually implemented it. Level 2 CMMC is the same 110 requirements from 800-171 Rev 2 — the difference is who checks, how often, and what proof is required.
DFARS 252.204-7012 requires contractors to report a discovered cyber incident to DoD within 72 hours via DIBNet, preserve affected media for at least 90 days, and submit malicious software to DC3 — plus flow the clause down to subcontractors. The report itself is only part of the obligation.
GCC High is Microsoft 365 in a US-sovereign, screened-US-persons cloud with FedRAMP High and DoD IL4/IL5 authorization. You need it for ITAR/export-controlled data and CUI Specified; Commercial or GCC may suffice for lighter CUI — but confirm with your prime. It costs more and migration is a real project.
Most Top 10 programs don't fail on hard technology — they stall on avoidable patterns: boiling the ocean, mistaking 'we bought it' for 'it works,' and never testing recovery. Here are the common mistakes DIB teams make starting out, and the simple fixes.
A high-level 'done looks like' for each IT Top 10 practice — the validation test that shows a control actually works, not just that it was purchased. Use it as a quick self-check, then open the full guides for the how-to.
Scope size is the master cost driver in a CMMC Level 2 program — it sets how many premium licenses you pay for, how big your assessment is, and how much CUI you're liable for. How you find your CUI (a top-down traceability cascade, staff interviews, or automated digital discovery) determines how accurately you can size the boundary, and four remediation paths — surgical file cleanup, a user-account enclave, program segmentation, or enterprise migration — are chosen mostly by two ratios: what share of users touch CUI, and how sprawled it already is.
A GCC High migration priced honestly has three parts: a fixed base to stand up and harden the environment (around $15,500), migration tooling like AvePoint (there is no native commercial-to-GCC-High path), and roughly $250 per user to move and validate mail, files, and Teams. Total ≈ $15,500 + tooling + ($250 × users). The cost nobody quotes correctly is the risk in the mapping and cutover — get those wrong and you pay again in spillage, broken permissions, and downtime.
For NIST 800-171 Rev 3, the endpoint controls quietly require Windows Enterprise. Rev 3 sharpened application allowlisting (03.04.08), and the licensed, manageable engine — AppLocker — needs a Windows Enterprise E3/E5 or Education license; Pro isn't entitled. App Control for Business (WDAC) runs on Pro but is the harder engine and no substitute for the rest: Credential Guard (Enterprise-only), Defender for Endpoint EDR (E5), and more. In GCC High, getting those Enterprise licenses onto devices is partner-mediated and portal-fragmented.
Your SPRS score is a self-reported number from 110 down to -203 that tells the DoD how much of NIST SP 800-171 you have actually implemented. It starts at 110, and every unmet requirement subtracts a weighted value of 5, 3, or 1 point. Two requirements — multifactor authentication and FIPS-validated encryption — are the only ones that grant partial credit.
On July 13, 2026 the Department of War suspended the CMMC Phase II transition during a 60-day program review. Third-party (C3PAO) and Level 3 designations are paused and November 10, 2026 is no longer an operative date — but DFARS 252.204-7012, NIST SP 800-171 Rev 2, 72-hour incident reporting, SPRS score accuracy, and the Program Rule at 32 CFR Part 170 all remain in force.
The security stack is driven first by the information involved, then by the clauses, assessment level, and contract-specific requirements that apply to the system handling it. FCI, CUI, and CDI are overlapping categories with different triggers — and export-controlled information sits on top as an independent legal overlay.
FAR 52.204-21 and DFARS 252.204-7012, -7019, -7020 and -7021 form the contractual backbone of defense cybersecurity. Each has a distinct trigger, obligation, and flowdown. Alongside them sits an independent supply-chain gate that can exclude an otherwise-compliant technology from a covered contract.
Export control is a separate legal overlay from CUI safeguarding. The controlling authority, classification, destination, end user, nationality, access path, license or exemption, and technical facts determine whether a transfer or release is authorized — none of which is answered by a CUI banner or a CMMC status.
NIST SP 800-171 Rev. 3 reduced the requirement count from 110 to 97, but consolidation, organization-defined parameters, three new families, and a larger assessment-procedure catalog mean the burden went up, not down. Where the work concentrates — supply chain, ODPs, planning and acquisition, monitoring, identity, and shared responsibility — with OSC and ESP guidance for each.
Rev. 3's three new families — Planning, System and Services Acquisition, and Supply Chain Risk Management — hold the nine requirements that concentrate the revision's new work. What each asks, its organization-defined parameters, and its operating evidence, from the OSC and ESP seats.
Three honest starting profiles — a paper program, an operating Rev. 2 program, and a provider-dependent one — mapped to the site's maturity ladder, each with a phased Rev. 3 preparation sequence (now / 60 / 90 / 180 days) split for OSCs and ESPs.
NIST SP 800-171 Rev. 3 puts service providers inside every client's assessable scope: the new SR family names you as a supplier, ODPs collide with your standardized baselines, and your technicians hold the highest-privilege accounts in every tenant. A readiness guide for MSPs and MSSPs — one standing evidence package, authored responsibility matrices, and per-client parameter discipline.
The specific evidence a contractor should receive from its MSP or MSSP: a standing package delivered on a cadence, a per-service responsibility matrix with the evidence hand-off named, contract terms covering notification, data return, and offboarding — plus the red-flag answers that signal trouble. Written to the buyer, with the provider's view in every toggle.
Official campaign, framework, and program links — each with its publisher, provenance, and most recent verification date.
The authoritative campaign page and source for the IT and OT Top 10 practices.
The department-level target architecture that the IT Top 10 supports.
The foundational reference for securing industrial control systems.
The 110 security requirements for protecting Controlled Unclassified Information in nonfederal systems. Published February 2020; includes update 1 (January 2021). Withdrawn by NIST and superseded by Rev. 3 — publication status is separate from contractual applicability, and many DFARS-based contracts still reference Rev. 2; read your contract. Basis of this site's Rev. 2 requirement pages.
The assessment procedures companion to Rev. 2 (published June 2018): the determination statements and assessment objects behind each requirement — the closest thing to knowing what an assessor will actually examine.
The current revision (published May 2024): 97 requirements across 17 families, aligned to SP 800-53 Rev. 5, with organization-defined parameters and three new families — Planning, System and Services Acquisition, and Supply Chain Risk Management. Basis of this site's Rev. 3 requirement pages. NIST's analysis-of-changes supplemental material on the same page documents the official Rev. 2 to Rev. 3 differences.
Assessment procedures for Rev. 3 (published May 2024), restructured around the revised requirements and their organization-defined parameters.
The framework of cybersecurity outcomes (published February 2024) that several practice mappings reference — governance, identify, protect, detect, respond, recover. Describes outcomes, not testable compliance controls.
Cybersecurity supply chain risk management practices for systems and organizations. Update 1 (November 2024) supersedes the May 2022 edition — cite the update, not the original.
Demonstrated secure remote-access architectures for operational technology (final, June 2026) — the brokered, authenticated, time-bound pattern the OT-06 practice builds, shown as implemented example builds.
Quick-start guidance for OT backups (final, June 2026): regular backups, integration with change management, testing, and recovery exercises — directly supporting the OT resiliency and recovery practices.
The 2024 edition restructures the asset-owner security program into Security Program Elements and adds a maturity model. Replaces the withdrawn 2010 edition — cite the 2024 edition.
Normative text is licensed; exact Security Program Element identifiers pend verification against a licensed copy.
Patch management guidance specific to industrial automation and control systems — the reference behind OT-05's patch-or-compensate discipline.
A Technical Report (informative), not an International Standard; text is licensed.
Security capabilities expected of integrators and service providers to control systems. The 2023 edition replaces the withdrawn 2015/2017 edition — cite the current edition.
Normative text is licensed.
The part of the 62443 series that requires defining the system under consideration, partitioning it into zones and conduits, assessing risk per zone and conduit, and setting target security levels — the primary zones-and-conduits reference for OT-03.
Normative text is licensed.
Technical system security requirements and security levels applied to zones and conduits once IEC 62443-3-2 has defined them. Companion to, not a substitute for, the zones-and-conduits design standard.
Normative text is licensed; individual SR identifiers cited on practice pages pend verification against a licensed copy.
A right-sized starting point for organizations without a security team.
Guidance for building and maintaining a defensible OT asset inventory.
No-cost cybersecurity readiness resources for DIB small businesses.
Free threat-informed services for DIB companies, including protective DNS.
Reporting, analysis, and no-cost tools for defense contractors.
A commercial tool that automatically discovers and continuously monitors CUI across files and endpoints — including formats many scanners miss, like CAD drawings, PDFs, and scanned images — and flags CUI that has drifted outside its authorized boundary. Useful for the digital-discovery step of scoping.