<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>APT Security Management</title><description>Writing on offensive security, CMMC and NIST 800-171 obligations, and building a security program, from the practitioner doing the work.</description><link>https://www.aptsecuritymanagement.com/</link><language>en-us</language><item><title>FCI vs CUI: Which Type of Data Are You Handling?</title><link>https://www.aptsecuritymanagement.com/blog/fci-vs-cui/</link><guid isPermaLink="true">https://www.aptsecuritymanagement.com/blog/fci-vs-cui/</guid><description>FCI or CUI decides your CMMC level. The difference in plain English, how to read your contract clauses, and what each one still requires in 2026.</description><pubDate>Wed, 12 Nov 2025 00:00:00 GMT</pubDate><category>Compliance</category><author>Cody D. Martin</author></item><item><title>PTaaS for SOC 2 and PCI DSS: What Auditors Want</title><link>https://www.aptsecuritymanagement.com/blog/ptaas-soc-2-pci-dss-auditor-requirements/</link><guid isPermaLink="true">https://www.aptsecuritymanagement.com/blog/ptaas-soc-2-pci-dss-auditor-requirements/</guid><description>Auditors care about scope, methodology, dates, independence and remediation evidence. What that means, and where subscription testing trips people up.</description><pubDate>Tue, 04 Nov 2025 00:00:00 GMT</pubDate><category>Offensive</category><author>Cody D. Martin</author></item><item><title>Seven Things Every Pen Test Report Needs</title><link>https://www.aptsecuritymanagement.com/blog/what-should-be-in-pen-test-report/</link><guid isPermaLink="true">https://www.aptsecuritymanagement.com/blog/what-should-be-in-pen-test-report/</guid><description>The report is the deliverable and everything else is process. Seven things a good one contains, and the tells that separate testing from scanner output.</description><pubDate>Tue, 21 Oct 2025 00:00:00 GMT</pubDate><category>Offensive</category><author>Cody D. Martin</author></item><item><title>What Is Penetration Testing as a Service?</title><link>https://www.aptsecuritymanagement.com/blog/what-is-penetration-testing-as-a-service/</link><guid isPermaLink="true">https://www.aptsecuritymanagement.com/blog/what-is-penetration-testing-as-a-service/</guid><description>PTaaS replaces the annual PDF with continuous findings, retesting and a platform. Useful for some buyers, oversold to others. How to tell which you are.</description><pubDate>Thu, 02 Oct 2025 00:00:00 GMT</pubDate><category>Offensive</category><author>Cody D. Martin</author></item><item><title>How Often Should You Run a Penetration Test?</title><link>https://www.aptsecuritymanagement.com/blog/how-often-should-you-run-a-penetration-test/</link><guid isPermaLink="true">https://www.aptsecuritymanagement.com/blog/how-often-should-you-run-a-penetration-test/</guid><description>Annual testing is the common answer, usually driven by an audit cycle. Change is the better trigger. How to decide on evidence rather than habit.</description><pubDate>Thu, 18 Sep 2025 00:00:00 GMT</pubDate><category>Offensive</category><author>Cody D. Martin</author></item><item><title>When You Can Stop at CMMC Level 1</title><link>https://www.aptsecuritymanagement.com/blog/cmmc-stop-at-level-1/</link><guid isPermaLink="true">https://www.aptsecuritymanagement.com/blog/cmmc-stop-at-level-1/</guid><description>Handling FCI without touching CUI keeps you at Level 1. How to know that is genuinely true, and how to keep it true as contracts change.</description><pubDate>Tue, 02 Sep 2025 00:00:00 GMT</pubDate><category>Compliance</category><author>Cody D. Martin</author></item><item><title>Your SSP and POA&amp;M: What Assessors Want</title><link>https://www.aptsecuritymanagement.com/blog/ssp-poam-cmmc/</link><guid isPermaLink="true">https://www.aptsecuritymanagement.com/blog/ssp-poam-cmmc/</guid><description>The SSP is the document everything else hangs off, and most are a template with a company name in it. What assessors actually read, and what fails.</description><pubDate>Thu, 14 Aug 2025 00:00:00 GMT</pubDate><category>Compliance</category><author>Cody D. Martin</author></item><item><title>How CMMC Level 1 Self-Attestation Works</title><link>https://www.aptsecuritymanagement.com/blog/cmmc-level-1-self-attestation/</link><guid isPermaLink="true">https://www.aptsecuritymanagement.com/blog/cmmc-level-1-self-attestation/</guid><description>Self attestation means a senior company official signs that 15 requirements are met. What that signature carries, what to keep, and the False Claims Act risk.</description><pubDate>Tue, 05 Aug 2025 00:00:00 GMT</pubDate><category>Compliance</category><author>Cody D. Martin</author></item><item><title>The 15 CMMC Level 1 Requirements in Plain English</title><link>https://www.aptsecuritymanagement.com/blog/cmmc-level-1-practices/</link><guid isPermaLink="true">https://www.aptsecuritymanagement.com/blog/cmmc-level-1-practices/</guid><description>Level 1 covers 15 basic safeguarding requirements from FAR 52.204-21. What each one actually asks for, and the ones companies get wrong.</description><pubDate>Tue, 22 Jul 2025 00:00:00 GMT</pubDate><category>Compliance</category><author>Cody D. Martin</author></item><item><title>Level 1 or Level 2? How to Tell Which You Need</title><link>https://www.aptsecuritymanagement.com/blog/cmmc-level-1-or-level-2/</link><guid isPermaLink="true">https://www.aptsecuritymanagement.com/blog/cmmc-level-1-or-level-2/</guid><description>Your CMMC level is set by the data you handle and the clauses in your contract. How to read them, plus what changed for Level 2 after the 2026 suspension.</description><pubDate>Tue, 15 Jul 2025 00:00:00 GMT</pubDate><category>Compliance</category><author>Cody D. Martin</author></item><item><title>Do I Need CMMC? A Checklist for Subcontractors</title><link>https://www.aptsecuritymanagement.com/blog/do-i-need-cmmc-checklist/</link><guid isPermaLink="true">https://www.aptsecuritymanagement.com/blog/do-i-need-cmmc-checklist/</guid><description>Five questions that tell you whether CMMC applies to your company, which level, and what to do if your prime has not told you what data you handle.</description><pubDate>Tue, 08 Jul 2025 00:00:00 GMT</pubDate><category>Compliance</category><author>Cody D. Martin</author></item><item><title>NIST 800-171 and CMMC Level 2: How Controls Map</title><link>https://www.aptsecuritymanagement.com/blog/nist-800-171-cmmc-level-2-mapping/</link><guid isPermaLink="true">https://www.aptsecuritymanagement.com/blog/nist-800-171-cmmc-level-2-mapping/</guid><description>CMMC Level 2 is NIST SP 800-171 with an assessment process attached. How the 110 practices map, how SPRS scoring works, and where the two differ.</description><pubDate>Tue, 24 Jun 2025 00:00:00 GMT</pubDate><category>Compliance</category><author>Cody D. Martin</author></item><item><title>What Is CMMC? A Plain English Guide</title><link>https://www.aptsecuritymanagement.com/blog/what-is-cmmc-2-0/</link><guid isPermaLink="true">https://www.aptsecuritymanagement.com/blog/what-is-cmmc-2-0/</guid><description>CMMC in plain language, updated for the July 2026 Phase 2 suspension. What the levels mean, what is paused, and what defense contractors still owe today.</description><pubDate>Tue, 10 Jun 2025 00:00:00 GMT</pubDate><category>Compliance</category><author>Cody D. Martin</author></item><item><title>RP, RPO and C3PAO: The CMMC Ecosystem</title><link>https://www.aptsecuritymanagement.com/blog/rp-rpo-c3pao-explained/</link><guid isPermaLink="true">https://www.aptsecuritymanagement.com/blog/rp-rpo-c3pao-explained/</guid><description>Who does what in the CMMC ecosystem, why the roles are separated, and what the July 2026 suspension did to the assessment side of it.</description><pubDate>Tue, 27 May 2025 00:00:00 GMT</pubDate><category>Compliance</category><author>Cody D. Martin</author></item><item><title>What to Expect From a CMMC Gap Assessment</title><link>https://www.aptsecuritymanagement.com/blog/what-to-expect-cmmc-gap-assessment/</link><guid isPermaLink="true">https://www.aptsecuritymanagement.com/blog/what-to-expect-cmmc-gap-assessment/</guid><description>What actually happens during a gap assessment, how long it takes, what you need to have ready, and what you should receive at the end of it.</description><pubDate>Tue, 13 May 2025 00:00:00 GMT</pubDate><category>Compliance</category><author>Cody D. Martin</author></item><item><title>What Happens After Your CMMC Gap Assessment</title><link>https://www.aptsecuritymanagement.com/blog/after-cmmc-gap-assessment/</link><guid isPermaLink="true">https://www.aptsecuritymanagement.com/blog/after-cmmc-gap-assessment/</guid><description>A gap assessment tells you where you stand. Turning that into compliance is the harder part. A realistic roadmap for the twelve months that follow.</description><pubDate>Tue, 29 Apr 2025 00:00:00 GMT</pubDate><category>Compliance</category><author>Cody D. Martin</author></item><item><title>How Long Does CMMC Prep Take?</title><link>https://www.aptsecuritymanagement.com/blog/cmmc-prep-timeline/</link><guid isPermaLink="true">https://www.aptsecuritymanagement.com/blog/cmmc-prep-timeline/</guid><description>A realistic timeline for Level 1 and Level 2 preparation, what drives the variance, and how the July 2026 suspension changes the planning picture.</description><pubDate>Tue, 15 Apr 2025 00:00:00 GMT</pubDate><category>Compliance</category><author>Cody D. Martin</author></item><item><title>Choosing a CMMC Advisory Partner</title><link>https://www.aptsecuritymanagement.com/blog/choosing-cmmc-advisory-partner/</link><guid isPermaLink="true">https://www.aptsecuritymanagement.com/blog/choosing-cmmc-advisory-partner/</guid><description>Questions worth asking before you hire CMMC help, including the ones that separate a real advisor from a template vendor, and what the suspension revealed.</description><pubDate>Tue, 01 Apr 2025 00:00:00 GMT</pubDate><category>Compliance</category><author>Cody D. Martin</author></item></channel></rss>