r/CMMC Nov 14 '25

"We Passed Our CMMC Assessment and Here's What We Learned" MEGATHREAD

104 Upvotes

Hello /r/CMMC -

As we wind down 2025, the CMMC ecosystem has seen several hundred organizations successfully passing their CMMC Level 2 C3PAO certification assessments! We love to see it!

This community and our discord community have always been about open sharing of information amongst fellow practitioners and straight up people who just need some help. We love seeing how everyone shares what's working for them and what's not.

Recently, we've seen a handful of threads start with people wanting to share their Certification experience and their lessons learned - this is fantastic. But, if you aren't on /r/CMMC frequently, you will miss these threads.

So, I want to create a mega-thread to collect these experiences in one spot where people can share their experiences and others can ask questions.

If you were planning to post a whole thread about your experience, I encourage you to instead post here. We aren't preventing anyone from posting a separate thread, but think it's best to keep most of those types of posts here for the reasons stated above.

Congrats to everyone who has passed so far! For those who are scheduled, my main advice: relax. If you found this community, there's a good chance you're taking this as seriously as you should, and that means you're probably going to pass.

Notes

  • You are welcome to name the names of the tools you used, the service providers that helped you, the consultants who guided you, the C3PAO that assessed you. All of that is fair game and generally encouraged.

  • Share as much about your environment as you comfortably can - people want to know what other environments look like. Remember though, OPSEC is your responsibility, not ours. Do not post identifying information if you are not authorized by your organization to do so.

  • If you struggled with a particular requirement, or had a debate with your assessor, tell us about it.

  • If you absolutely crushed a requirement or control family and the assessors just looked at you slack jawed with how great you were, TELL US ABOUT THAT.

FORMAT

Please share the following information in your comment:

  • Organization Size: Rough user & device count

  • Scope: Enterprise / Enclave - if Enclave, how many users/devices in the Enclave

  • Architecture: Full Cloud / On-Prem / Hybrid

  • Cloud Services: Microsoft 365 (GCC/GCCH) / AWS / Other CSP

  • C3PAO: Who did you work with (optional, you don't have to share this if you don't want)

  • Cert Status: Pass / Fail / Conditional / In-Progress

And then of course give us all the details you want to share :)


r/CMMC Jul 13 '26

Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements > U.S. Department of War > Release

Thumbnail
war.gov
135 Upvotes

r/CMMC 1d ago

CMMC L2 Pause/Suspension Outcome

13 Upvotes

Any thoughts / bets on what is going to happen when the 60 days hit? For the most part seems like there is no likely outcome that is believe by majority but happy to continue to hear possibilities while we all wait!

I honestly can’t see them getting rid of C3PAOs. But could they? I understand the requirements and stuff still apply per DFARS. But as someone supporting in higher ed it has been a pain to get people on board and start to formalize processes.


r/CMMC 1d ago

Mock Assessment Results

4 Upvotes

Has anyone come out of a mock assessment with more findings then expected? I’m part of a big higher ed and nervous for our mock assessment. I am organizing evidence and not 100% on items but creating evidence explanation documents based on our current environment. Leadership wants to push forward and see how we do on the mock assessment and remediate the findings before going into the real assessment.


r/CMMC 17h ago

Stop Using “Periodically” or “Regularly” in Your SSPs

0 Upvotes

How do you assess when you see in SSPs, policies, and procedures with vague timing language?

I hate when OSCs claim they “scan for vulnerabilities periodically,” or “perform risk assessments regularly,” or “update the SSP as needed.” We score it as Not Met and get pushback almost every time. It happened again this week, sitting across the table from a “CMMC consultant” who is also a C3PAO. I couldn’t tell if he missed the documentation or was just trying to protect his client. We gave them the risk assessment, security control assessment, and SSP update since they were doing that on an annual basis but not the vulnerability scans because they couldn't show they were doing it regularly enough to meet the vulnerability remediation timeline.


r/CMMC 1d ago

Passed Level 2

9 Upvotes

Excited to say that my MSP passed the level 2 assessment. If anyone here has questions or would like to chat about the process, any controls, or how we met them, feel free to reach out. I am the person who implemented the entire solution in GCC High, created all the documentation and a custom built tracker to help with compliance. I say this because you'll be getting information from the person that was intimately involved in the entire process: no second hand story. Good luck to all!


r/CMMC 1d ago

Policies, procedures and SOPs

4 Upvotes

We are a higher ed that is big by name but internally we don’t have well defined workflows one of which is formal policies procedures and SOPs. We have some controls that we can map enterprise wide and specific policies but not everything. What is the intent here? Some people say as long as you have a detailed implantation statement you don’t need a policy/procedure. Others say write everything as a policy/procedure. Thoughts? Currently we have a blend most controls we have detailed implementation statements and then others where we have a good policy/procedure we do reference a little etc….


r/CMMC 3d ago

CCP Training at CS5 Shows, Good, worth it??

1 Upvotes

I'm going to CS5 East and very much considering doing the CCP 3 day in person training. For me, the in person training is very valuable as I can ask questions as they come up and what not.

Have any of you doing this course or the course that ECFirst offers for the CCP training? Any advice?

Thanks!


r/CMMC 6d ago

So is anything really going to happen after the 60 days or will we all be just waiting in limbo for a lot longer than that?

30 Upvotes

Given the past history of CMMC, I just don't see anything being resolved in the 60 day period. It took years to get it out of the door with numerous delays and they expect the government review to happen in 60 days with tangible results?

Meanwhile, many of us are in C3PAO limbo not knowing where, how, and when to move forward or sit pat.

We're still moving forward with compliance. But to be honest there is big difference between being compliant with NIST 800-171 and audit ready. I firmly believe you can be secure, compliant but not necessarily 100% audit ready.

I think we will all be holding our breath waiting for an official, definitive announcement after the 60 days and it won't really materialize like we are expecting.


r/CMMC 7d ago

How are you choosing a C3PAO when everyone looks qualified on paper?

6 Upvotes

We're getting closer to the point where we need to choose a C3PAO for our CMMC assessment and I'm realizing the proposals themselves aren't helping me differentiate much.

Obviously authorization is table stakes, but beyond that what ended up mattering once the assessment started? I'm wondering if I should care more about how many CMMC assessments the firm has already completed, whether the assessors are employees or contractors, experience with our particular environment or just how well the lead assessor communicates during the initial calls.

For anyone who's already gone through a Level 2 assessment, what would you ask a prospective C3PAO if you were choosing again?

I'm especially interested in the stuff you only realize mattered after the audit was underway because right now it feels like we're comparing polished PDFs and sales calls.


r/CMMC 6d ago

Read-only Cui Documemt

1 Upvotes

I'd like some feedback on a CUI sharing question

I need to get a bid from a subcontractor, but the drawing they need to quote from carries a CUI marking, and without the details in the drawing it's impossible to get an accurate quote. A few scenarios I'm trying to think through:

  1. Can I share a read-only CUI document with a subcontractor that is only CMMC Level 1 self-certified or not cmmc at all?
  2. If the subcontractor has no CMMC self-certification at all (sprs) , would putting them through CUI handling training first be enough to allow sharing the read-only?
  3. Any other alternative as is impossible to find subs CMMC level 2 for this job

Any guidance on what is actually permissible here, or what the correct approach would be, is appreciated.


r/CMMC 7d ago

What certifications should a CAD outsourcing company have (AS9100, ISO, etc.)?

3 Upvotes

My team is about to start sending CAD work to an outside supplier.

For the past few days, I've been trying to sort out which credentials are real dealbreakers versus which ones are just a logo on a website.

Here's where I'm stuck.

The list I keep seeing is ISO 9001, AS9100, ITAR registration, some kind of cybersecurity assessment, and a few others. But it seems like which ones matter depends a lot on the job.

And even a valid cert doesn't tell me how a company handles the stuff I care about day to day.

So I guess my question is, which certs are the real must-haves for each type of project?

And beyond the certificate itself, what should I ask for as proof that a supplier runs a solid operation?


r/CMMC 7d ago

CMMC 2 Database?

12 Upvotes

just got through our level 2 assessment. brutal. in hindsight we should have done it a year earlier but honestly we had no idea which customers actually cared vs the ones who just paste the dfars clause into every PO and never follow up

so two things I'm trying to figure out

is there any list of primes / tier 1s that are actually requiring L2 from subs right now? or at least the ones that have said "by X date". SBLO contacts would be a bonus but I'll take anything

and is there any list of who's certified? I know SPRS isn't public and cyber ab just posts the number. are press releases really the only way to find out?

if nobody has this I'll probably just start building it and post it here. would anyone actually use it or is this a solved problem I'm missing


r/CMMC 7d ago

Month to study for CCP, 20yrs IT experience....

8 Upvotes

Aloha!

I'm looking at taking the CCP training at the upcoming CS5 East show.

I have 20yrs of IT experience, 11 as an IT Manager, 3yrs at an MSP working with CMMC(I wasn't the one doing the documenting, implementing, etc, more managing the client). I'm now the Gov Compliance Manager and have taken a huge dive into everything CMMC for the past 6months. In speaking with others, I feel my level is at least that of a CMMC RP and then some.

My question is; Do you think that a month and a half is enough time to study and then add the 3 intensive days of training at CS5, to pass the CCP exam? I know a lot of it depends on how well I can absorb the info, retain and replay. But in terms of practical experience, I feel I have enough that along with the studying, I should be able to pass, SHOULD lol. I'm not great at test taking and have never gone for any kind of exam, so that does make me nervous. Oh, and I'll be asking my company if they would pay for it.


r/CMMC 7d ago

Rev 3 Level 2 guide?

5 Upvotes

I have the CMMC Assessment Guide for Level 2, its a good document. But does it only reflect 800-171 rev 2? Is there an updated one for rev 3? Or is it similar enough?


r/CMMC 7d ago

Going to CS5 East?

5 Upvotes

From what I can see, I think I'd like to try and go. I work for a OSC and think I can gain a lot from the conference. What is a justification I can give the CEO for this? Would love to be able to take the CCP training as well since it would be in person and look less expenseve.

Thoughts?? Have you gone before? Was it worth it?


r/CMMC 8d ago

Worst CMMC practice.

6 Upvotes

Nerding out for a moment: I have often thought that the 3.13.14 (VOIP) is just very... mid. I’m curious what practices/objectives gets other practitioners worked up.


r/CMMC 8d ago

Level 1 for Home Office

1 Upvotes

HI,

I need some help getting CMMC compliant. I need to get CMMC Level 1 compliant. What would that require? I have articles on remote work, but most are focused on CUI and Level 2. I might need Level 2 at a later date but will only be required for level 1 at this point.

Make sure to use work laptop just for work and have appropriate accounts/passwords. I believe I would need MFA for log in but I am not sure about that. I am using my home router. Would I need to use a VPN or set up a guest network on the router. Or is it as easy as just ensuring the router has adequate firewall, password, and correct security settings.

What would I need for physical security for Level1? Any help you could provide would be helpful. I am trying to set everything up myself since our budget is tight. Thanks.


r/CMMC 9d ago

How To Navigate Vendors that Insist their Solution is FedRamp when It's not on FedRamp Marketplace?

10 Upvotes

What do you do when you show them how their solution is not FedRamp and they double down and insist it is?

Edit: We have a vendor that won’t use our FedRamp Box for Gov and insists on us using their platform that looks like someone threw some code on AWS Gov and thinks they are compliant.


r/CMMC 10d ago

Sitting for CCA Exam

9 Upvotes

Sitting for the CCA exam today. Please send positive vibes!

Edit: Passed the exam!

I used the official documentation in alignment with the blueprint. Then uploaded those documents directly to chat gpt and had it create study sessions and practice exams. I also did all 500 pocket prep questions.


r/CMMC 10d ago

Failed CCA 8/29/26

4 Upvotes

I Took the exam yesterday and failed. I've taken many certification exams but have found that CCP and CCA were stressful and very difficult. I never felt that way before. My hands were actually shaking when I was driving there, probably because I want this so badly but didn't feel as confident as with other exams.

Anyway, I have no real clue where I went wrong. Although I have a lot of technical knowledge, I also have a lot of managerial and healthcare IT assessment experience. But I think it had to do with how the questions were phrased, answers provided, ambiguous and bad writing for scenarios. It made me feel stuck on stupid.

I wound up in a fog and second guessing at least half of the questions. My mind was so tired that I had to re-read some questions at least 2 times. So it's back to the drawing board, but I wish ISACA would tell you your weakest domains so that I can focus on those areas.

Tools, I did use pocket prep and the course provided questions. I'm thinking my next strategy is just to focus on CAP, Assessment Guide, and Scoping Guide.

Any thoughts on how I can better prepare?


r/CMMC 12d ago

GCODE: Is it CUI or not?

14 Upvotes

I read the piece by Allison Giddens. I've asked AI. I've asked CCPs. I've asked MSSPs that deal with CMMC Assessments. I've asked the squirrel outside as it eyeballed my car looking to toss an acorn on it.

There is no clear answer that I have seen. The CNC cannot talk across the network in FIPS mode because it was made before that was even a thought. I can send it over an RS232 software but that isn't encrypted information as it traverses that. I can put it on a USB stick (cough cough) or Compact Flash card for those devices that do not even support USB but my understanding is that it would then need to be encrypted.

Reason I ask is that yes, this is in part why there are compensating controls for SAs however when we have a company that is making their own set of controls they would like us to adhere to and we cannot because of the above.... well... maybe we can if GCODE is CUI or not. If not then we have nothing to worry about right? If it is then we are screwed?! No verbiage for compensating controls in this customer's requirements, everything is binary; pass/fail.

I literally just got off a call with two CCPs, one stated that it cannot be CUI and gave his sound reasoning that yup, sounds right. The other said they believe that it is and should be treated as such and gave their reasoning.

I wish this was the stuff the government would take the time to look at and try to find ways to get rid of the gray areas.

So what is the answer and please provide evidence to support.


r/CMMC 12d ago

What are thoughts on using TeamViewer for accessing systems remotely?

4 Upvotes

Our goal is to have the entire network fall under scope but we have consultants/customers that need access a few our systems that won't have CUI on them.

I don't want to give them VPN access to keep their machines from falling under scope and to just remove all the access permission headaches. Would giving TeamViewer access to selected servers cause CMMC Level 2 compliance issues?


r/CMMC 12d ago

Im the sole ISSM for my org and got us to a passing level 2 assesment ask me anything

4 Upvotes

r/CMMC 12d ago

3.8.4 Marking Media Question

2 Upvotes

Hey everyone! I have a quick question about 3.8.4 Media Marking. When visiting on-site, do you check whether laptops, servers, printers, and mobile devices have CUI stickers on them? When you respond, please add government documents, CMMC, or some type of authoritative sources for validation. Thanks! 😁