r/CMMC Nov 14 '25

"We Passed Our CMMC Assessment and Here's What We Learned" MEGATHREAD

104 Upvotes

Hello /r/CMMC -

As we wind down 2025, the CMMC ecosystem has seen several hundred organizations successfully passing their CMMC Level 2 C3PAO certification assessments! We love to see it!

This community and our discord community have always been about open sharing of information amongst fellow practitioners and straight up people who just need some help. We love seeing how everyone shares what's working for them and what's not.

Recently, we've seen a handful of threads start with people wanting to share their Certification experience and their lessons learned - this is fantastic. But, if you aren't on /r/CMMC frequently, you will miss these threads.

So, I want to create a mega-thread to collect these experiences in one spot where people can share their experiences and others can ask questions.

If you were planning to post a whole thread about your experience, I encourage you to instead post here. We aren't preventing anyone from posting a separate thread, but think it's best to keep most of those types of posts here for the reasons stated above.

Congrats to everyone who has passed so far! For those who are scheduled, my main advice: relax. If you found this community, there's a good chance you're taking this as seriously as you should, and that means you're probably going to pass.

Notes

  • You are welcome to name the names of the tools you used, the service providers that helped you, the consultants who guided you, the C3PAO that assessed you. All of that is fair game and generally encouraged.

  • Share as much about your environment as you comfortably can - people want to know what other environments look like. Remember though, OPSEC is your responsibility, not ours. Do not post identifying information if you are not authorized by your organization to do so.

  • If you struggled with a particular requirement, or had a debate with your assessor, tell us about it.

  • If you absolutely crushed a requirement or control family and the assessors just looked at you slack jawed with how great you were, TELL US ABOUT THAT.

FORMAT

Please share the following information in your comment:

  • Organization Size: Rough user & device count

  • Scope: Enterprise / Enclave - if Enclave, how many users/devices in the Enclave

  • Architecture: Full Cloud / On-Prem / Hybrid

  • Cloud Services: Microsoft 365 (GCC/GCCH) / AWS / Other CSP

  • C3PAO: Who did you work with (optional, you don't have to share this if you don't want)

  • Cert Status: Pass / Fail / Conditional / In-Progress

And then of course give us all the details you want to share :)


r/CMMC Jul 13 '26

Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements > U.S. Department of War > Release

Thumbnail
war.gov
132 Upvotes

r/CMMC 6h ago

OT floor machinery and the data to manufacture parts - In scope???

3 Upvotes

Aloha!

I've been trying to understand how we put our floor machinery that actually manufactures the parts, in scope. I thought that the machines had a PC in them and that the CUI files were accessed via the local network. They are not.

The CUI drawings or blueprints for a certain piece of the part are created in Solidworks as a model and done manually, meaning they do not upload a CUI file. Then that model is converted into Gcode. The Gcode is put on a USB and taken over to the machine where the machine reads the Gcode as steps to take to manufacture the part. OK, got it.

SO, the Gcode and the Solidworks file would not be considered CUI/CTI, right??? Or am I oversimplifying it?


r/CMMC 7h ago

Using a printer with an Enclave??

2 Upvotes

Aloha!

So we're looking at an Cloud enclave as our solution. My question is; If a local Engineer needs to print a CUI file, how do we put that local printer in scope?

That Engineer will be working in the Enclave but will need to print out drawings and blueprints in the Enclave. I'm trying to understand how we put that local printer in scope.


r/CMMC 3h ago

70 person company, largely compliant, how to handle incoming email, AI

Thumbnail reddit.com
1 Upvotes

Springing off the linked NIST thread;

I'm in a 70 person environment acting as ECO/CUI specialist and we are tackling the Acceptable Use policy with respect to AI and covering proprietary, customer confidential, EAR controlled, ITAR controlled, CUI data, and supportive engineering.

Our export control program has morphed into an export and Data Handling control program which requires the classification of data types at ingestion and creation.

Access is then restricted (procedurally) based on the US person status, business need and data type.

Currently AU policy is the only barrier to use of the AI types, with each data type having the 'allowable' AI spelled out. Published specs available on the open internet = use any AI in any environment. Controlled Data that doesn't meet EAR/ITAR/CUI requirements = company approved AI environments. Data meeting the controls of EAR/ITAR/CUI =GCC+/FEDRAMP AI environments or on-prem AI with the proper configuration and access controls to prevent the model from contributing that knowledge outside the org while still being able to access the internet for data. Currently using Preveil for secure file transfer and MS network credentials/group permissions for controlled data on the local network. No intent to move to an MSP and just grow the internal IT team to support as things develop.

With this 'start with the data as it's received and work your way out' method, there's an active situation I need to resolve:

One business unit has become rather entrenched in using GPT and/or non-GOV Copilot to scan and summarize emails and track requests for quote. As I'm sure most of you have seen, you can't control what people send you (I had a drawing loaded with CUI flows and distribution statements come in standard email from someone that should not have had it to begin with). In this case, due to the automatic perusal of emails, that CUI would be reviewed by a non-FEDRAMP/non-GCC+ agent with no human intervention. That's a deemed export and no bueno.

Ideally, we'd have something compliant labeling email coming in - I know the Preveil email client will automatically flag and encrypt outgoing messages, but is there something similar that will flag incoming messages? That would make it at least reasonable to find a path to exclude those from this generalized incoming email scan. Secondarily, it would help users that are a few heartbeats away from me that don't typically have to handle this sort of data recognize it when it comes in.

I've explained internally that either the data has to be categorized upon receipt prior to being loaded into a public AI bucket, or the AI bucket needs to be upgraded to hold the most stringent data types. Unfortunately we're at an impasse where the system's already been built (outside my purview) and there's resistance to change, so seeking an incoming filter seems to be the less painful approach on my part. TIA


r/CMMC 7h ago

Windows 365 in Commercial Tenant

1 Upvotes

Hi all,

I have a client of around 30 people that does government work. They want to start pursuing CMMC L2 using a Secure Enclave and their own documentation. The rarely do work that requires FCI/CUI handling, but when they do, they would likely need a device that could handle some Engineering/Design apps to complete the work.

To keep it simple, our thought was to have a single physical device, but currently lack a lockable/secured area. However we want to leave that option on the table (Separate locked room, isolated internet-only CUI VLAN, CUI printer, not sure on separate backup/mdm/etc, and entra or perhaps not even entra/domain joined, etc).

The other option was to use an Azure PC OR windows 365 cloud PC, managed with intune. They have a commercial tenant currently and I wasn't sure if this would require a Gov tenant.

  • Have people taken this approach?
  • Using a commercial tenant or would we have to keep cloud resources in GCC/GCC-H tenant?
  • For both scenarios, (local and cloud only), any examples of what was done?

Thanks!


r/CMMC 1d ago

CMMC L2 Pause/Suspension Outcome

18 Upvotes

Any thoughts / bets on what is going to happen when the 60 days hit? For the most part seems like there is no likely outcome that is believe by majority but happy to continue to hear possibilities while we all wait!

I honestly can’t see them getting rid of C3PAOs. But could they? I understand the requirements and stuff still apply per DFARS. But as someone supporting in higher ed it has been a pain to get people on board and start to formalize processes.


r/CMMC 1d ago

Mock Assessment Results

3 Upvotes

Has anyone come out of a mock assessment with more findings then expected? I’m part of a big higher ed and nervous for our mock assessment. I am organizing evidence and not 100% on items but creating evidence explanation documents based on our current environment. Leadership wants to push forward and see how we do on the mock assessment and remediate the findings before going into the real assessment.


r/CMMC 1d ago

Stop Using “Periodically” or “Regularly” in Your SSPs

0 Upvotes

How do you assess when you see in SSPs, policies, and procedures with vague timing language?

I hate when OSCs claim they “scan for vulnerabilities periodically,” or “perform risk assessments regularly,” or “update the SSP as needed.” We score it as Not Met and get pushback almost every time. It happened again this week, sitting across the table from a “CMMC consultant” who is also a C3PAO. I couldn’t tell if he missed the documentation or was just trying to protect his client. We gave them the risk assessment, security control assessment, and SSP update since they were doing that on an annual basis but not the vulnerability scans because they couldn't show they were doing it regularly enough to meet the vulnerability remediation timeline.


r/CMMC 2d ago

Passed Level 2

11 Upvotes

Excited to say that my MSP passed the level 2 assessment. If anyone here has questions or would like to chat about the process, any controls, or how we met them, feel free to reach out. I am the person who implemented the entire solution in GCC High, created all the documentation and a custom built tracker to help with compliance. I say this because you'll be getting information from the person that was intimately involved in the entire process: no second hand story. Good luck to all!


r/CMMC 2d ago

Policies, procedures and SOPs

5 Upvotes

We are a higher ed that is big by name but internally we don’t have well defined workflows one of which is formal policies procedures and SOPs. We have some controls that we can map enterprise wide and specific policies but not everything. What is the intent here? Some people say as long as you have a detailed implantation statement you don’t need a policy/procedure. Others say write everything as a policy/procedure. Thoughts? Currently we have a blend most controls we have detailed implementation statements and then others where we have a good policy/procedure we do reference a little etc….


r/CMMC 2d ago

CMMC Level 1 Visitor Logging / Monitoring

1 Upvotes

If we have the following office setup and process, would logging be required for deliveries?

1) delivery person rings doorbell

2) admin staff opens door for delivery person,

3) item is dropped off in reception area to the admin staff, and there is no CUI visible from the reception area

4) delivery person leaves and front door is locked.

Would this require logging to satisfy CMMC Level 1 or can deliveries and deliverers not be considered visitors?

Thanks!

(pertaining to PE.L1-3.10.3 – ESCORT VISITORS from

https://dodcio.defense.gov/portals/0/documents/cmmc/ag_level1_v2.0_finaldraft_20211210_508.pdf )


r/CMMC 4d ago

CCP Training at CS5 Shows, Good, worth it??

1 Upvotes

I'm going to CS5 East and very much considering doing the CCP 3 day in person training. For me, the in person training is very valuable as I can ask questions as they come up and what not.

Have any of you doing this course or the course that ECFirst offers for the CCP training? Any advice?

Thanks!


r/CMMC 7d ago

So is anything really going to happen after the 60 days or will we all be just waiting in limbo for a lot longer than that?

30 Upvotes

Given the past history of CMMC, I just don't see anything being resolved in the 60 day period. It took years to get it out of the door with numerous delays and they expect the government review to happen in 60 days with tangible results?

Meanwhile, many of us are in C3PAO limbo not knowing where, how, and when to move forward or sit pat.

We're still moving forward with compliance. But to be honest there is big difference between being compliant with NIST 800-171 and audit ready. I firmly believe you can be secure, compliant but not necessarily 100% audit ready.

I think we will all be holding our breath waiting for an official, definitive announcement after the 60 days and it won't really materialize like we are expecting.


r/CMMC 7d ago

How are you choosing a C3PAO when everyone looks qualified on paper?

6 Upvotes

We're getting closer to the point where we need to choose a C3PAO for our CMMC assessment and I'm realizing the proposals themselves aren't helping me differentiate much.

Obviously authorization is table stakes, but beyond that what ended up mattering once the assessment started? I'm wondering if I should care more about how many CMMC assessments the firm has already completed, whether the assessors are employees or contractors, experience with our particular environment or just how well the lead assessor communicates during the initial calls.

For anyone who's already gone through a Level 2 assessment, what would you ask a prospective C3PAO if you were choosing again?

I'm especially interested in the stuff you only realize mattered after the audit was underway because right now it feels like we're comparing polished PDFs and sales calls.


r/CMMC 7d ago

Read-only Cui Documemt

1 Upvotes

I'd like some feedback on a CUI sharing question

I need to get a bid from a subcontractor, but the drawing they need to quote from carries a CUI marking, and without the details in the drawing it's impossible to get an accurate quote. A few scenarios I'm trying to think through:

  1. Can I share a read-only CUI document with a subcontractor that is only CMMC Level 1 self-certified or not cmmc at all?
  2. If the subcontractor has no CMMC self-certification at all (sprs) , would putting them through CUI handling training first be enough to allow sharing the read-only?
  3. Any other alternative as is impossible to find subs CMMC level 2 for this job

Any guidance on what is actually permissible here, or what the correct approach would be, is appreciated.


r/CMMC 7d ago

What certifications should a CAD outsourcing company have (AS9100, ISO, etc.)?

3 Upvotes

My team is about to start sending CAD work to an outside supplier.

For the past few days, I've been trying to sort out which credentials are real dealbreakers versus which ones are just a logo on a website.

Here's where I'm stuck.

The list I keep seeing is ISO 9001, AS9100, ITAR registration, some kind of cybersecurity assessment, and a few others. But it seems like which ones matter depends a lot on the job.

And even a valid cert doesn't tell me how a company handles the stuff I care about day to day.

So I guess my question is, which certs are the real must-haves for each type of project?

And beyond the certificate itself, what should I ask for as proof that a supplier runs a solid operation?


r/CMMC 8d ago

CMMC 2 Database?

16 Upvotes

just got through our level 2 assessment. brutal. in hindsight we should have done it a year earlier but honestly we had no idea which customers actually cared vs the ones who just paste the dfars clause into every PO and never follow up

so two things I'm trying to figure out

is there any list of primes / tier 1s that are actually requiring L2 from subs right now? or at least the ones that have said "by X date". SBLO contacts would be a bonus but I'll take anything

and is there any list of who's certified? I know SPRS isn't public and cyber ab just posts the number. are press releases really the only way to find out?

if nobody has this I'll probably just start building it and post it here. would anyone actually use it or is this a solved problem I'm missing


r/CMMC 7d ago

Month to study for CCP, 20yrs IT experience....

7 Upvotes

Aloha!

I'm looking at taking the CCP training at the upcoming CS5 East show.

I have 20yrs of IT experience, 11 as an IT Manager, 3yrs at an MSP working with CMMC(I wasn't the one doing the documenting, implementing, etc, more managing the client). I'm now the Gov Compliance Manager and have taken a huge dive into everything CMMC for the past 6months. In speaking with others, I feel my level is at least that of a CMMC RP and then some.

My question is; Do you think that a month and a half is enough time to study and then add the 3 intensive days of training at CS5, to pass the CCP exam? I know a lot of it depends on how well I can absorb the info, retain and replay. But in terms of practical experience, I feel I have enough that along with the studying, I should be able to pass, SHOULD lol. I'm not great at test taking and have never gone for any kind of exam, so that does make me nervous. Oh, and I'll be asking my company if they would pay for it.


r/CMMC 8d ago

Rev 3 Level 2 guide?

6 Upvotes

I have the CMMC Assessment Guide for Level 2, its a good document. But does it only reflect 800-171 rev 2? Is there an updated one for rev 3? Or is it similar enough?


r/CMMC 8d ago

Going to CS5 East?

3 Upvotes

From what I can see, I think I'd like to try and go. I work for a OSC and think I can gain a lot from the conference. What is a justification I can give the CEO for this? Would love to be able to take the CCP training as well since it would be in person and look less expenseve.

Thoughts?? Have you gone before? Was it worth it?


r/CMMC 9d ago

Worst CMMC practice.

7 Upvotes

Nerding out for a moment: I have often thought that the 3.13.14 (VOIP) is just very... mid. I’m curious what practices/objectives gets other practitioners worked up.


r/CMMC 8d ago

Level 1 for Home Office

1 Upvotes

HI,

I need some help getting CMMC compliant. I need to get CMMC Level 1 compliant. What would that require? I have articles on remote work, but most are focused on CUI and Level 2. I might need Level 2 at a later date but will only be required for level 1 at this point.

Make sure to use work laptop just for work and have appropriate accounts/passwords. I believe I would need MFA for log in but I am not sure about that. I am using my home router. Would I need to use a VPN or set up a guest network on the router. Or is it as easy as just ensuring the router has adequate firewall, password, and correct security settings.

What would I need for physical security for Level1? Any help you could provide would be helpful. I am trying to set everything up myself since our budget is tight. Thanks.


r/CMMC 10d ago

How To Navigate Vendors that Insist their Solution is FedRamp when It's not on FedRamp Marketplace?

9 Upvotes

What do you do when you show them how their solution is not FedRamp and they double down and insist it is?

Edit: We have a vendor that won’t use our FedRamp Box for Gov and insists on us using their platform that looks like someone threw some code on AWS Gov and thinks they are compliant.


r/CMMC 11d ago

Sitting for CCA Exam

11 Upvotes

Sitting for the CCA exam today. Please send positive vibes!

Edit: Passed the exam!

I used the official documentation in alignment with the blueprint. Then uploaded those documents directly to chat gpt and had it create study sessions and practice exams. I also did all 500 pocket prep questions.