AI RMF Integration: SOC 2 Risk Management with Lazarus Alliance

In today’s rapidly evolving regulatory landscape, organizations in highly regulated industries face mounting pressure to integrate advanced technologies like artificial intelligence while maintaining robust compliance postures. The NIST AI Risk Management Framework (AI RMF 1.0) offers a structured approach to managing AI-specific risks, and when combined with SOC 2 risk management practices, it creates a… Read More

HIPAA Security Updates: Ransomware Compliance Audits Today

In the rapidly evolving landscape of healthcare cybersecurity, organizations face mounting pressure to address HIPAA security updates while mitigating ransomware threats. Decision-makers in regulated industries must prioritize proactive measures to protect sensitive patient data and maintain operational resilience. Continuum GRC specializes in delivering comprehensive GRC audit services that help enterprises navigate these challenges with precision… Read More

The November 2026 CMMC Deadline and What to Expect in the Next 9 Months

With all the shifts in cybersecurity, one framework has been steadily solidifying requirements and expectations: CMMC. With the revision of CMMC 2.0 and the following feedback from vendors and the industry, it has been a years-long process to get this framework in place. Now, contractors in the DIB are seeing that framework become concrete requirements. … Read More

Preparing Personnel and Policy for CMMC

To meet CMMC requirements, organizations need a security strategy that integrates technology, people, and policies. It is important to know when to use IT solutions and when to involve HR and leadership so everyone works toward the same goals. If you are a Department of Defense contractor preparing for CMMC certification, remember that people and… Read More

Using Your MSP to FedRAMP Authorization Time Through Control Inheritance

A FedRAMP Moderate baseline, now classified as Class C under the updated FedRAMP 20x framework, requires documentation and validation of over 300 controls–not an insignificant number, regardless of the enterprise.  Modern IT, however, rests on a network of digital infrastructure and vendor-supplied applications. If your app runs on a FedRAMP-authorized infrastructure provider, you benefit from… Read More

Using FedRAMP To Fast Track Your GovRAMP Market Entry

The barrier between federal and state cloud procurement has effectively dissolved for authorized providers. With StateRAMP’s rebranding to GovRAMP and the FedRAMP RFC-0024 mandate for authorization packages, the opportunity to pursue a more unified compliance strategy has never been more practical.  Organizations that have already invested the time, money, and engineering effort required to earn… Read More

Navigating FedRAMP’s Move to Certification Classes 

Anchored by the FedRAMP Authorization Act and OMB Memo M-24-15, FedRAMP is undergoing a major change that affects virtually every aspect of how cloud service providers pursue, achieve, and maintain federal authorization. Named FedRAMP 20x, this program is meant to streamline compliance and make it easier for cloud products to enter the federal marketplace. The… Read More

CIRCIA And The Future Of Federal Cyber Incident Reporting

For years, federal visibility into large-scale cyber incidents has depended on voluntary disclosure tied to regulations. The result has been delayed response coordination and inconsistent data quality. The Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) changes that model by establishing a uniform reporting framework to provide CISA with near-real-time insight into major… Read More

What is the Duty of Care in Cybersecurity?

Data privacy and security are often framed as organizational requirements, and as such include discussions of ROI, staffing, compliance, and so on. However, the obligations enterprises and agencies face in protecting data extend beyond liability, because the data they protect often represents someone’s life and well-being.  As a result, duty of care is evolving from… Read More

CMMC Waivers and the Potential for Strategic Certification

As the CMMC program evolves in 2026, following the solidification of the final rule and the timelines for required certification, the Cyber AB wrestles with the need to streamline adoption across contractors while maintaining strict rigor in compliance and audits. That’s where waivers come in.  Now, across the DIB, executives have to decide whether these… Read More

NIST CSF 2.0 and Universalizing Cybersecurity

Over the past decade, the proliferation of standards, controls, and sector-specific frameworks has created a paradox where the more guidance exists, the harder it is to weed through the complexity and build secure systems that comply with that guidance. This is where NIST Cybersecurity Framework (CSF) 2.0 comes in. CSF functions as a translation layer,… Read More

FedRAMP Ready, Class A Certification, and Breaking Into the Federal Market

The updates and expansion of FedRAMP make a few things clear, the most significant of which is that government agencies are counting on cloud tools to help them do their work. But they also want certainty. The FedRAMP Ready designation was meant to bridge the gap between agencies seeking audited platforms and SaaS providers seeking… Read More

FedRAMP and the Data Broker Loophole

A new congressional report recommending a FedRAMP-style framework for commercial data brokers has reignited a long-running debate in Washington: whether federal agencies should be able to buy sensitive personal data on the open market without the same legal scrutiny required for traditional surveillance. Supporters of reform argue that the rapid growth of the data brokerage… Read More

MSPs, CMMC, and FedRAMP in 2026

For MSPs supporting defense contractors, federal agencies, and cloud service providers, 2026 marks a turning point when most regulatory bodies expect architecture, compliance, and service delivery to align. This is made even more readily apparent with changes in federal requirements. The DoD’s phased rollout of CMMC and FedRAMP 20x are clear signal that the government… Read More

Continuous Controls Monitoring and Real-Time Compliance

The move to continuous controls monitoring is quickly becoming the baseline expectation for how security and compliance programs operate, particularly in cloud-first, identity-driven environments. What was once framed as “continuous compliance” or “real-time assurance” has now become a necessity driven by how risk and regulations actually function.  

IAL, Compliance, and MSPs

This shift to identity-based security has had major implications for compliance. Frameworks like FedRAMP, CMMC, and NIST 800-series controls all rely on strong identity practices. Yet areas like Identity Assurance remain a consistent challenge. Many organizations assume that if a user can log in with MFA, their identity is secure. In reality, authentication only proves… Read More

MSPs and Supporting Modern Compliance

As regulatory scrutiny is increasing, customers are more demanding, and security failures carry reputational and financial consequences that far outweigh the cost of prevention. In response, Managed Service Providers are redefining their role. Instead of offering compliance as a one-off consulting engagement, they are transforming it into a repeatable, scalable managed service. This is an… Read More

Passwordless Authentication and the Identity Perimeter

Passwordless authentication is a potential lynchpin for organizations struggling with identity as their security perimeter. While neither FedRAMP nor CMMC explicitly mandates passwordless technologies, both frameworks set requirements and outcomes that passwordless authentication can meet. For organizations operating in regulated environments, especially those handling government data or CUI, passwordless authentication is no longer an emerging… Read More