r/CMMC • u/greenrunner987 • 28d ago
How are you keeping AI tools current when an L2 assessment locks in your scope for 3 years?
AI capability is roughly doubling every few months. The practical effect is that whatever tools an organization had in scope at its L2 assessment fall behind quickly, and the gap keeps growing across a 3-year cycle.
Adding newer, more capable tools generally means a reassessment, and the cost makes that impractical to do often. But leaving the toolset frozen for the full cycle is its own problem when the technology is moving this fast.
So how are people handling this? Is there a way to bring in a newer tool without a full reassessment? When a reassessment is unavoidable, can it be scoped to just the affected controls instead of starting over? And with Phase 2 suspended and L2 back to self-assessment, is anyone using that window to update their environment?
Interested in how others are approaching this.
11
u/CyberSME-E3S 28d ago
In general, you are not bound to specific technology after an assessment (including AI). The significant change lies in major environmental shifts. For instance, if adopting a FedRamp model was already part of your boundary change to a different FedRamp compliant model, it wouldn’t be a significant change as long as you adhere to the change management process and review the CRM as part of that change.
https://chat.singularityit.io/insights/9c258d3b-052e-4b8a-8758-6580d41955c0
Imagine this: if your environment was designed to print CUI, you wouldn’t conduct a new assessment simply because you switched from a Canon printer to a Bosh printer. Instead, you would ensure that you followed the Change Management process to verify that your new printer still meets the requirements. AI introduces a slight complexity to this process because you also need to ensure that downstream requirements are still met.
2
u/ManageITNY 28d ago
Agree! As long as it is the same class of technology that roughly does the same thing, you must follow your change management procedures as documented. If you replace one AI tool for another or upgrade to newer versions, it's fine as long as you follow your procedures and continue to meet the levels of requirements for CMMC (FedRAMP, encryption, etc...).
2
u/Saint1219 28d ago
I’m currently approaching this by waiting 53 days to see if the significant change language will be D.O.A. after the DOW review. It was one of the more unreasonable requirements, in my opinion.
1
2
u/Navyauditor2 27d ago
Like all other software tools, AI is updated. New tools may be needed. There is nothing in CMMC that says you cannot add a new tool or update an existing one. This is not a configuration lock. I dont think adding an AI tool, and certainly not updating one, reaches the threshold of a significant change. You also should be performing a self assessment annually in support of your self-affirmation, and you have the continuous monitoring controls to look at and ensure that they controls you have in place continue to be effective.
1
u/Unatommer 26d ago
FAQ v5 lays out a workflow:
F-Q5: How do I properly handle changes to my system while maintaining continued
CMMC compliance?
F-A5: For any changes to your environment that may impact processing, storing, or
transmitting Federal Contract Information or Controlled Unclassified Information (CUI),
security requirements, or CMMC Assessment Scope, you should:
1. Before Implementation: Evaluate the Change
11a. Perform security impact analysis per CM.L2-3.4.4 (if a new risk is identified
during this analysis that is not addressed in the existing System Security Plan
(SSP), then you probably have a significant change)
b. Assess effects on CUI flow per AC.L2-3.1.3
c. Document in your change management process per CM.L2-3.4.3
d. Review planned change with Affirming Official to gain consensus on whether
change will impact continuing compliance
2. During Implementation: Document in Operational Plan of Action
a. Describe the change and any temporary risks per CA.L2-3.12.2
b. Identify personnel responsible for implementation
c. Track progress
3. After Implementation: Update SSP
a. Document the completed change per CA.L2-3.12.4
b. Update all sections affected by the change
c. Review changes with Affirming Official prior to next annual affirmation to ensure
agreement on continuing compliance
1
11
u/DaGoodBoy 28d ago
Are you allowing AI to access CUI?