<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>grc.engineering</title>
  <link>https://signalplane.co/posts/</link>
  <description>Engineering notes on CMMC, OSCAL, and compliance-as-code for the defense industrial base.</description>
  <language>en-us</language>
  <atom:link href="https://signalplane.co/posts/feed.xml" rel="self" type="application/rss+xml"/>
  <item>
    <title>The SSP is code. Stop treating it like a Word document.</title>
    <link>https://signalplane.co/posts/ssp-as-code.html</link>
    <description>Why grc.engineering delivers CMMC L2 System Security Plans as Goal Structuring Notation assurance cases, assembled from a signed pipeline.</description>
    <pubDate>Sat, 12 Apr 2026 00:00:00 +0000</pubDate>
    <guid>https://signalplane.co/posts/ssp-as-code.html</guid>
  </item>
  <item>
    <title>Why CMMC L2 breaks every general-purpose GRC platform.</title>
    <link>https://signalplane.co/posts/why-not-vanta-for-cmmc.html</link>
    <description>Vanta, Drata, Hyperproof are built for SOC 2 and ISO 27001. CMMC L2 is a different problem — not because the controls differ but because of where the controls run.</description>
    <pubDate>Sat, 12 Apr 2026 00:00:00 +0000</pubDate>
    <guid>https://signalplane.co/posts/why-not-vanta-for-cmmc.html</guid>
  </item>
</channel>
</rss>
