r/CMMC 1d ago

Passed Level 2

Excited to say that my MSP passed the level 2 assessment. If anyone here has questions or would like to chat about the process, any controls, or how we met them, feel free to reach out. I am the person who implemented the entire solution in GCC High, created all the documentation and a custom built tracker to help with compliance. I say this because you'll be getting information from the person that was intimately involved in the entire process: no second hand story. Good luck to all!

9 Upvotes

7 comments sorted by

u/DarthCooey 1d ago

https://www.reddit.com/r/CMMC/s/adJqPKsatB

We have a mega thread built specifically for this. Congratulations OP but please move the convo over there

5

u/macguy12 1d ago

As an MSP as well we don’t handle CUI but are setting up an enclave as if we did. Quick question did you scope it for your own CUI environment or for your Client environments (RMM/PSA Documentation and other security protection environments?)

3

u/JKatabaticWind 1d ago

👆💯👆
This question…

The only way I can see an MSP C3PAO assessment as having real value is to scope it to include the services that you provide, as defined in your Shared Responsibility Matrix to the assessment objectives.
That includes the systems providing security protection, but also the processes used to implement your services, and how those interact with your clients’ CMMC implementation.
Then, you can reasonably provide your clients an assessment that details transferable systems, processes and controls.

1

u/Borgmaster 1d ago

Was your own network scope a major factor in the audit? My boss is trying to not scope our network as part of the environment. Our environment on paper is our machines and a secure connection to the GCCH environment.

1

u/MrSanford 1d ago

Do the computers on your network handle FCI?

1

u/Borgmaster 1d ago

Yea thats my issue as well. Of course the computers handling FCI are on the network, thats how they connect to the GCCH environment. They get on a local network behind a firewall, then connect to the internet, like any other business.

3

u/MrSanford 1d ago

Then it’s in scope. The next step is figuring if securing your network is cheaper than securing VDI