Duffy Compliance 2023 Logo
  • Home
  • About
  • Services
    • Assessments
    • CMMC Compliance
    • Fractional CISO
    • Fractional Compliance Officer
  • MSPs
  • Free Resources
    • Case Studies
    • Cybersecurity Self-assessment
    • FTC Safeguards Rule Checklist
    • Incident Response Checklist
  • Blog
  • Contact
Schedule A Call

Careers

Quiet Warning Signs Most Organizations Miss

Quiet Warning Signs Most Organizations Miss

by Shawn Duffy | Feb 11, 2026 | Cybersecurity, Blog, CMMC, DFARS, MSP, Penetration Testing, Risk assessment, Risk Management, Security, Security Awareness Training, Vulnerability

When people think about cybersecurity breaches, they usually picture a sudden, dramatic moment where the screen goes dark, the ransom note appears, and the phones light up, amplifying the disaster. More times than not, most breaches don’t start that way.  They begin...
CMMC 2.0 Rule Released and Terms Revisited (CUI, CMMC, DFARS, NIST 800-171)

CMMC 2.0 Rule Released and Terms Revisited (CUI, CMMC, DFARS, NIST 800-171)

by Shawn Duffy | Oct 16, 2024 | CMMC, Blog, CMMC 2.0, DFARS

Now that the final rule for CMMC 2.0 was released last Friday and hit the federal register yesterday, understanding CMMC is more important than ever, especially if you’re a government contractor bidding on contracts. 3 years ago, I wrote an article about CMMC Acronym...
How to spot check where you are with DFARS / CMMC

How to spot check where you are with DFARS / CMMC

by Shawn Duffy | Jun 19, 2023 | Blog, CMMC, Compliance, Continuous Monitoring, DFARS, Featured, Security Awareness Training, SPRS

If you are a prime or subcontractor to the DOD, the DFARS compliance requirement is something you already know. We have been discussing “adequate security” from clause 7012 for some time now. Your service provider may not be able to assess how close you...
CMMC 2.0 Has Been Released

CMMC 2.0 Has Been Released

by Shawn Duffy | Nov 9, 2021 | CMMC, Assessments, Blog, CMMC 2.0, Department of Defense, DFARS, DOD, News, POA&M, SPRS, Vulnerability

As you may have seen last week, the new CMMC 2.0 has been released, which reverts us back to the NIST 800-171 set of security controls and families. It also allows for both a Plan of Actions & Milestones (POA&M) and self-assessments. This is great news for...

Recent Articles

  • AI vs. Human Support: What Small Defense Contractors Really Need 
  • 5 Reasons Why Going Cheap with CMMC May Not Be the Cheapest Solution
  • The Cyber Risk Hidden Inside GovCon M&A Deals
  • The Security Gap MSPs Are Being Asked to Fill
  • Why GovCon Companies Can’t Afford to Skip a Fractional CISO During CMMC Readiness

Featured Articles

  • Interview on WBAL-TV: Hackers Steal Sensitive Info From Baltimore SAO
  • Why Experts Hire Fractional CISOs
  • Shawn Duffy Featured in Discover Frederick: Leading Cybersecurity with National Impact
  • How to spot check where you are with DFARS / CMMC
  • How to Reduce Risk
  • Prepare for Compliance

Categories

Archives

  • About
  • Services
  • Fractional CISO
  • Fractional Compliance Officer
  • MSPs
  • Blog
  • In the News
  • Careers
  • Contact

What We Do

IT GovCons can’t compete when they struggle to meet government cybersecurity requirements.

Duffy Compliance makes it easy for them to exceed requirements and stand out in the market.

Schedule A Call
Duffy Compliance Logo

Duffy Compliance Services, LLC
New Market, MD 21774-6266
Info@duffycompliance.com
www.DuffyCompliance.com
301-865-0345

  • Follow
  • Follow

From the Blog

  • AI vs. Human Support: What Small Defense Contractors Really Need 
  • 5 Reasons Why Going Cheap with CMMC May Not Be the Cheapest Solution
  • The Cyber Risk Hidden Inside GovCon M&A Deals
  • The Security Gap MSPs Are Being Asked to Fill
  • Why GovCon Companies Can’t Afford to Skip a Fractional CISO During CMMC Readiness

© 2026 Duffy Compliance Services | All Rights Reserved | Privacy Policy | Accessibility Statement | Web Development by Design Formare Inc.