Secureframe is the automated compliance platform built by compliance experts. We're transforming how businesses and MSPs manage security & compliance programs.

Joined January 2020
793 Photos and videos
Pinned Tweet
On average, DIB contractors spend $100K–$250K and 6–18 months on CMMC prep. Most can't afford that. Today, we launched Secureframe Defense to help any organization go from zero to CMMC ready in 4–8 weeks. Learn how: secureframe.com/blog/announc…
2
7
19
11,386
Yes, Google Workspace can meet CMMC Level 2 but only Enterprise Plus with Assured Controls Plus gets you there. Business tiers won't. Our new guide breaks down the exact edition, add-on, and configuration the DIB needs: secureframe.com/blog/google-…
50
Do all contractors need CMMC now? How much does certification cost? If you have any CMMC questions, join us, @RedspinInc, and @redsentry_tech for a live AMA tomorrow. No slides or sales pitch. Just real answers to your questions. Register: events.zoom.us/ev/AgGqSRNz6W…
1
38
Secureframe retweeted
1
247
Here's what most of the Defense Industrial Base is getting wrong about CMMC, according to three of the most senior figures in defense cybersecurity that spoke at the Secureframe National Cybersecurity Summit last month. Read the article: hubs.li/Q04k89pP0
31
New interview with @helpnetsecurity on where teams go wrong preparing for CMMC, FedRAMP 20x & SOC 2. The theme: treating compliance like a checkbox instead of trying to continuously achieve the security outcomes behind the requirements. Read it here: helpnetsecurity.com/2026/06/…
30
What does a CMMC C3PAO assessment actually look like? We're joining @prescientsec's webinar this month to break down what to expect before you're in the room with an assessor: 📊Timelines & cost 💥Common pitfalls 🏁Readiness vs assessment Register: airmeet.com/e/13798520-5b48-…
1
23
.@ElbitSystemsLtd: no PO without Level 2. @L3HarrisTech: certified by July 30 or off the program. Recent supplier notices show an acceleration in prime CMMC enforcement. We covered what's driving this and what primes are looking for beyond certification: secureframe.com/hub/cmmc/enf…
34
"Just because you go into GCC High doesn't make you magically compliant with CMMC Level 2." — Richard Wakeman, Microsoft GCC High gets you ~86 of 110 controls. The rest is on you. Our guide answers what's shared responsibility, which license you need, enclave vs. all-in 👇 secureframe.com/blog/microso…
1
42
96% of ransomware victims in this year's Verizon DBIR were small organizations. These attacks don't make headlines but they're happening constantly. Here's what the largest breach dataset in the report's 19-year history means for SMBs & DIB orgs 👉 secureframe.com/blog/2026-ve…
38
This is exactly the kind of threat Retired Gen. Paul Nakasone was describing at this month's National Cybersecurity Summit. His warning: "Our adversaries are ahead of where we're at today, and we have to catch up." Here's what he says to do about it 👇secureframe.com/blog/nsa-pau…
The phishing platform, called Kali365, was first seen in April, according to the FBI. It’s primarily distributed through the messaging app Telegram and allows cyber attackers to bypass multi-factor authentication.8newsnow.com/news/national-n…
53
The CMMC ecosystem hit notable milestones this month, including nearly 1,400 Level 2 certified orgs. But the bigger story from the May Cyber AB Town Hall is that many orgs relying on ESPs & MSPs may be incorrectly scoping their L2 assessment. Recap: cmmc.com/newsroom/cyber-ab-t…
1
28
👩‍🔧What counts as a "significant change" under CMMC? 🔁 What does the latest CMMC FAQ revision clarify about scoping? ✳️ Why is getting and staying certified so important? Find the answers in this month's newsletter: linkedin.com/pulse/may-2026-…
34
FedRAMP 20x changed more than the process. It changed the language too to clarify a common misconception. FedRAMP certification ≠ "blanket approval” for the entire government to use the CSP for whatever they want,” a GSA expert explained at last week’s summit. Recap here: secureframe.com/hub/fedramp/…
31
The 3-year ATO cycle isn't just inefficient. It's a gift to U.S. adversaries, said former @CISAgov CIO at last week's Summit. Adversaries operate continuously, adapt in real time, and stay undetected for months. Defenders need to do the same & AI is how. Recap: secureframe.com/blog/bob-cos…
24
"Significant change" under CMMC came up again and again at last week's Summit, and for good reason. The stakes are high: invalidated certifications, reassessment triggered, FCA exposure. Here's what the CMMC rule says what assessors told us 👇 secureframe.com/blog/cmmc-si…
32
.@FederalNewsNet cited Rob Joyce's keynote from our summit last week. The former NSA Director spoke about how AI is finding vulnerabilities at "industrial scale." Here's what that means for patching deadlines and the CISA KEV catalog: federalnewsnetwork.com/cyber…
50
Asked when orgs should get CMMC compliant, @karringtonsc's reply: "About a year ago." Throughout her keynote, she emphasized why the lack of DIB readiness is not just a compliance issue and how CMMC is a business enabler, not a hindrance. Full recap: secureframe.com/blog/katie-a…
39