INSIGHTS

Notes From the Team

Short, practical notes on security, privacy, architecture, and IT strategy, no fluff, no gated whitepapers.

Written by the same fractional CISO, CPO, CTO, and CIO team — often searched as a vCISO or virtual CIO — who staff the retainer itself, not a marketing team publishing under their byline.

The CMMC Deadline That Wasn't: What Actually Changed in July 2026

CMMC Phase 2 enforcement was suspended in July 2026, and a lot of the urgency-driven advice built around it went stale overnight. Worth being precise about what actually changed: the C3PAO/DIBCAC assessment requirements are suspended, but NIST SP 800-171 self-assessment and DFARS obligations remain fully in place.

The practical takeaway for most organizations we talk to hasn't changed: the underlying security work still matters, the deadline pressure was never the real reason to do it well.

Why We Split CTO and CIO the Way We Do

The cleanest distinction we've found: CTO owns what gets built for the future, architecture, platform decisions, portfolio bets. CIO owns what runs today, operations, budget, vendor relationships. Most confusion between the two roles comes from blurring that line, not from the roles themselves being unclear.