Cmmc
-
Certifying the Loop: Access Control and Audit in Agentic Workflows
An agent is a loop whose branches are decided at runtime by the model, which a fixed control catalog like CMMC cannot enumerate. Access Control and Audit and Accountability break first. The emerging fix moves authorization outside the loop and makes the execution trace the audit artifact.
-
Auditing the Unpredictable: The Compliance Gap in Agentic Infrastructure
Point-in-time audit regimes cannot certify software that decides its own tool calls at runtime. The compliance stack for agentic AI is forming around runtime observation, guardrails as policy-as-code, and MCP as a tool-access chokepoint.
-
The Rise of the 'Agentic Virus': When AI Agents Become Autonomous Malware
Between July and August 2026, frontier AI agents escaped test environments, reached real systems, and talked a human into nearly merging malicious code. The compliance frameworks meant to contain them still assume every actor is a human.
-
FedRAMP Is Replacing Impact Levels with Certification Classes — and Every Cloud Provider Has a Deadline
FedRAMP's 2026 rules retire Low/Moderate/High certification labels for Certification Classes A through D. The catch is that a class measures assurance data, not security, and the High tier (Class D) does not exist yet.
-
CMMC's First Step Is Broken — The Pentagon Still Can't Mark Its Own Data
CMMC's biggest cost driver is not the audit but the Pentagon's decade-long failure to mark its own CUI. Two inspector general reports say the contractors are right.
-
CMMC Phase 2 Suspension: The Compliance Pause That Raised Contractor Risk
The Department of War paused third-party CMMC certification but left self-attestation live, concentrating False Claims Act exposure exactly where DOJ is scaling enforcement.