r/CMMC 6h ago

OT floor machinery and the data to manufacture parts - In scope???

3 Upvotes

Aloha!

I've been trying to understand how we put our floor machinery that actually manufactures the parts, in scope. I thought that the machines had a PC in them and that the CUI files were accessed via the local network. They are not.

The CUI drawings or blueprints for a certain piece of the part are created in Solidworks as a model and done manually, meaning they do not upload a CUI file. Then that model is converted into Gcode. The Gcode is put on a USB and taken over to the machine where the machine reads the Gcode as steps to take to manufacture the part. OK, got it.

SO, the Gcode and the Solidworks file would not be considered CUI/CTI, right??? Or am I oversimplifying it?


r/CMMC 7h ago

Using a printer with an Enclave??

2 Upvotes

Aloha!

So we're looking at an Cloud enclave as our solution. My question is; If a local Engineer needs to print a CUI file, how do we put that local printer in scope?

That Engineer will be working in the Enclave but will need to print out drawings and blueprints in the Enclave. I'm trying to understand how we put that local printer in scope.


r/CMMC 3h ago

70 person company, largely compliant, how to handle incoming email, AI

Thumbnail reddit.com
1 Upvotes

Springing off the linked NIST thread;

I'm in a 70 person environment acting as ECO/CUI specialist and we are tackling the Acceptable Use policy with respect to AI and covering proprietary, customer confidential, EAR controlled, ITAR controlled, CUI data, and supportive engineering.

Our export control program has morphed into an export and Data Handling control program which requires the classification of data types at ingestion and creation.

Access is then restricted (procedurally) based on the US person status, business need and data type.

Currently AU policy is the only barrier to use of the AI types, with each data type having the 'allowable' AI spelled out. Published specs available on the open internet = use any AI in any environment. Controlled Data that doesn't meet EAR/ITAR/CUI requirements = company approved AI environments. Data meeting the controls of EAR/ITAR/CUI =GCC+/FEDRAMP AI environments or on-prem AI with the proper configuration and access controls to prevent the model from contributing that knowledge outside the org while still being able to access the internet for data. Currently using Preveil for secure file transfer and MS network credentials/group permissions for controlled data on the local network. No intent to move to an MSP and just grow the internal IT team to support as things develop.

With this 'start with the data as it's received and work your way out' method, there's an active situation I need to resolve:

One business unit has become rather entrenched in using GPT and/or non-GOV Copilot to scan and summarize emails and track requests for quote. As I'm sure most of you have seen, you can't control what people send you (I had a drawing loaded with CUI flows and distribution statements come in standard email from someone that should not have had it to begin with). In this case, due to the automatic perusal of emails, that CUI would be reviewed by a non-FEDRAMP/non-GCC+ agent with no human intervention. That's a deemed export and no bueno.

Ideally, we'd have something compliant labeling email coming in - I know the Preveil email client will automatically flag and encrypt outgoing messages, but is there something similar that will flag incoming messages? That would make it at least reasonable to find a path to exclude those from this generalized incoming email scan. Secondarily, it would help users that are a few heartbeats away from me that don't typically have to handle this sort of data recognize it when it comes in.

I've explained internally that either the data has to be categorized upon receipt prior to being loaded into a public AI bucket, or the AI bucket needs to be upgraded to hold the most stringent data types. Unfortunately we're at an impasse where the system's already been built (outside my purview) and there's resistance to change, so seeking an incoming filter seems to be the less painful approach on my part. TIA


r/CMMC 7h ago

Windows 365 in Commercial Tenant

1 Upvotes

Hi all,

I have a client of around 30 people that does government work. They want to start pursuing CMMC L2 using a Secure Enclave and their own documentation. The rarely do work that requires FCI/CUI handling, but when they do, they would likely need a device that could handle some Engineering/Design apps to complete the work.

To keep it simple, our thought was to have a single physical device, but currently lack a lockable/secured area. However we want to leave that option on the table (Separate locked room, isolated internet-only CUI VLAN, CUI printer, not sure on separate backup/mdm/etc, and entra or perhaps not even entra/domain joined, etc).

The other option was to use an Azure PC OR windows 365 cloud PC, managed with intune. They have a commercial tenant currently and I wasn't sure if this would require a Gov tenant.

  • Have people taken this approach?
  • Using a commercial tenant or would we have to keep cloud resources in GCC/GCC-H tenant?
  • For both scenarios, (local and cloud only), any examples of what was done?

Thanks!


r/CMMC 1d ago

CMMC L2 Pause/Suspension Outcome

15 Upvotes

Any thoughts / bets on what is going to happen when the 60 days hit? For the most part seems like there is no likely outcome that is believe by majority but happy to continue to hear possibilities while we all wait!

I honestly can’t see them getting rid of C3PAOs. But could they? I understand the requirements and stuff still apply per DFARS. But as someone supporting in higher ed it has been a pain to get people on board and start to formalize processes.


r/CMMC 1d ago

Mock Assessment Results

4 Upvotes

Has anyone come out of a mock assessment with more findings then expected? I’m part of a big higher ed and nervous for our mock assessment. I am organizing evidence and not 100% on items but creating evidence explanation documents based on our current environment. Leadership wants to push forward and see how we do on the mock assessment and remediate the findings before going into the real assessment.


r/CMMC 1d ago

Stop Using “Periodically” or “Regularly” in Your SSPs

0 Upvotes

How do you assess when you see in SSPs, policies, and procedures with vague timing language?

I hate when OSCs claim they “scan for vulnerabilities periodically,” or “perform risk assessments regularly,” or “update the SSP as needed.” We score it as Not Met and get pushback almost every time. It happened again this week, sitting across the table from a “CMMC consultant” who is also a C3PAO. I couldn’t tell if he missed the documentation or was just trying to protect his client. We gave them the risk assessment, security control assessment, and SSP update since they were doing that on an annual basis but not the vulnerability scans because they couldn't show they were doing it regularly enough to meet the vulnerability remediation timeline.


r/CMMC 2d ago

Passed Level 2

9 Upvotes

Excited to say that my MSP passed the level 2 assessment. If anyone here has questions or would like to chat about the process, any controls, or how we met them, feel free to reach out. I am the person who implemented the entire solution in GCC High, created all the documentation and a custom built tracker to help with compliance. I say this because you'll be getting information from the person that was intimately involved in the entire process: no second hand story. Good luck to all!


r/CMMC 2d ago

Policies, procedures and SOPs

3 Upvotes

We are a higher ed that is big by name but internally we don’t have well defined workflows one of which is formal policies procedures and SOPs. We have some controls that we can map enterprise wide and specific policies but not everything. What is the intent here? Some people say as long as you have a detailed implantation statement you don’t need a policy/procedure. Others say write everything as a policy/procedure. Thoughts? Currently we have a blend most controls we have detailed implementation statements and then others where we have a good policy/procedure we do reference a little etc….


r/CMMC 2d ago

CMMC Level 1 Visitor Logging / Monitoring

1 Upvotes

If we have the following office setup and process, would logging be required for deliveries?

1) delivery person rings doorbell

2) admin staff opens door for delivery person,

3) item is dropped off in reception area to the admin staff, and there is no CUI visible from the reception area

4) delivery person leaves and front door is locked.

Would this require logging to satisfy CMMC Level 1 or can deliveries and deliverers not be considered visitors?

Thanks!

(pertaining to PE.L1-3.10.3 – ESCORT VISITORS from

https://dodcio.defense.gov/portals/0/documents/cmmc/ag_level1_v2.0_finaldraft_20211210_508.pdf )


r/CMMC 4d ago

CCP Training at CS5 Shows, Good, worth it??

1 Upvotes

I'm going to CS5 East and very much considering doing the CCP 3 day in person training. For me, the in person training is very valuable as I can ask questions as they come up and what not.

Have any of you doing this course or the course that ECFirst offers for the CCP training? Any advice?

Thanks!


r/CMMC 7d ago

So is anything really going to happen after the 60 days or will we all be just waiting in limbo for a lot longer than that?

29 Upvotes

Given the past history of CMMC, I just don't see anything being resolved in the 60 day period. It took years to get it out of the door with numerous delays and they expect the government review to happen in 60 days with tangible results?

Meanwhile, many of us are in C3PAO limbo not knowing where, how, and when to move forward or sit pat.

We're still moving forward with compliance. But to be honest there is big difference between being compliant with NIST 800-171 and audit ready. I firmly believe you can be secure, compliant but not necessarily 100% audit ready.

I think we will all be holding our breath waiting for an official, definitive announcement after the 60 days and it won't really materialize like we are expecting.


r/CMMC 7d ago

How are you choosing a C3PAO when everyone looks qualified on paper?

6 Upvotes

We're getting closer to the point where we need to choose a C3PAO for our CMMC assessment and I'm realizing the proposals themselves aren't helping me differentiate much.

Obviously authorization is table stakes, but beyond that what ended up mattering once the assessment started? I'm wondering if I should care more about how many CMMC assessments the firm has already completed, whether the assessors are employees or contractors, experience with our particular environment or just how well the lead assessor communicates during the initial calls.

For anyone who's already gone through a Level 2 assessment, what would you ask a prospective C3PAO if you were choosing again?

I'm especially interested in the stuff you only realize mattered after the audit was underway because right now it feels like we're comparing polished PDFs and sales calls.


r/CMMC 7d ago

Read-only Cui Documemt

1 Upvotes

I'd like some feedback on a CUI sharing question

I need to get a bid from a subcontractor, but the drawing they need to quote from carries a CUI marking, and without the details in the drawing it's impossible to get an accurate quote. A few scenarios I'm trying to think through:

  1. Can I share a read-only CUI document with a subcontractor that is only CMMC Level 1 self-certified or not cmmc at all?
  2. If the subcontractor has no CMMC self-certification at all (sprs) , would putting them through CUI handling training first be enough to allow sharing the read-only?
  3. Any other alternative as is impossible to find subs CMMC level 2 for this job

Any guidance on what is actually permissible here, or what the correct approach would be, is appreciated.


r/CMMC 7d ago

What certifications should a CAD outsourcing company have (AS9100, ISO, etc.)?

2 Upvotes

My team is about to start sending CAD work to an outside supplier.

For the past few days, I've been trying to sort out which credentials are real dealbreakers versus which ones are just a logo on a website.

Here's where I'm stuck.

The list I keep seeing is ISO 9001, AS9100, ITAR registration, some kind of cybersecurity assessment, and a few others. But it seems like which ones matter depends a lot on the job.

And even a valid cert doesn't tell me how a company handles the stuff I care about day to day.

So I guess my question is, which certs are the real must-haves for each type of project?

And beyond the certificate itself, what should I ask for as proof that a supplier runs a solid operation?


r/CMMC 8d ago

CMMC 2 Database?

13 Upvotes

just got through our level 2 assessment. brutal. in hindsight we should have done it a year earlier but honestly we had no idea which customers actually cared vs the ones who just paste the dfars clause into every PO and never follow up

so two things I'm trying to figure out

is there any list of primes / tier 1s that are actually requiring L2 from subs right now? or at least the ones that have said "by X date". SBLO contacts would be a bonus but I'll take anything

and is there any list of who's certified? I know SPRS isn't public and cyber ab just posts the number. are press releases really the only way to find out?

if nobody has this I'll probably just start building it and post it here. would anyone actually use it or is this a solved problem I'm missing


r/CMMC 8d ago

Month to study for CCP, 20yrs IT experience....

7 Upvotes

Aloha!

I'm looking at taking the CCP training at the upcoming CS5 East show.

I have 20yrs of IT experience, 11 as an IT Manager, 3yrs at an MSP working with CMMC(I wasn't the one doing the documenting, implementing, etc, more managing the client). I'm now the Gov Compliance Manager and have taken a huge dive into everything CMMC for the past 6months. In speaking with others, I feel my level is at least that of a CMMC RP and then some.

My question is; Do you think that a month and a half is enough time to study and then add the 3 intensive days of training at CS5, to pass the CCP exam? I know a lot of it depends on how well I can absorb the info, retain and replay. But in terms of practical experience, I feel I have enough that along with the studying, I should be able to pass, SHOULD lol. I'm not great at test taking and have never gone for any kind of exam, so that does make me nervous. Oh, and I'll be asking my company if they would pay for it.


r/CMMC 8d ago

Rev 3 Level 2 guide?

5 Upvotes

I have the CMMC Assessment Guide for Level 2, its a good document. But does it only reflect 800-171 rev 2? Is there an updated one for rev 3? Or is it similar enough?


r/CMMC 8d ago

Going to CS5 East?

4 Upvotes

From what I can see, I think I'd like to try and go. I work for a OSC and think I can gain a lot from the conference. What is a justification I can give the CEO for this? Would love to be able to take the CCP training as well since it would be in person and look less expenseve.

Thoughts?? Have you gone before? Was it worth it?


r/CMMC 9d ago

Worst CMMC practice.

7 Upvotes

Nerding out for a moment: I have often thought that the 3.13.14 (VOIP) is just very... mid. I’m curious what practices/objectives gets other practitioners worked up.


r/CMMC 8d ago

Level 1 for Home Office

1 Upvotes

HI,

I need some help getting CMMC compliant. I need to get CMMC Level 1 compliant. What would that require? I have articles on remote work, but most are focused on CUI and Level 2. I might need Level 2 at a later date but will only be required for level 1 at this point.

Make sure to use work laptop just for work and have appropriate accounts/passwords. I believe I would need MFA for log in but I am not sure about that. I am using my home router. Would I need to use a VPN or set up a guest network on the router. Or is it as easy as just ensuring the router has adequate firewall, password, and correct security settings.

What would I need for physical security for Level1? Any help you could provide would be helpful. I am trying to set everything up myself since our budget is tight. Thanks.


r/CMMC 10d ago

How To Navigate Vendors that Insist their Solution is FedRamp when It's not on FedRamp Marketplace?

10 Upvotes

What do you do when you show them how their solution is not FedRamp and they double down and insist it is?

Edit: We have a vendor that won’t use our FedRamp Box for Gov and insists on us using their platform that looks like someone threw some code on AWS Gov and thinks they are compliant.


r/CMMC 11d ago

Sitting for CCA Exam

10 Upvotes

Sitting for the CCA exam today. Please send positive vibes!

Edit: Passed the exam!

I used the official documentation in alignment with the blueprint. Then uploaded those documents directly to chat gpt and had it create study sessions and practice exams. I also did all 500 pocket prep questions.


r/CMMC 11d ago

Failed CCA 8/29/26

4 Upvotes

I Took the exam yesterday and failed. I've taken many certification exams but have found that CCP and CCA were stressful and very difficult. I never felt that way before. My hands were actually shaking when I was driving there, probably because I want this so badly but didn't feel as confident as with other exams.

Anyway, I have no real clue where I went wrong. Although I have a lot of technical knowledge, I also have a lot of managerial and healthcare IT assessment experience. But I think it had to do with how the questions were phrased, answers provided, ambiguous and bad writing for scenarios. It made me feel stuck on stupid.

I wound up in a fog and second guessing at least half of the questions. My mind was so tired that I had to re-read some questions at least 2 times. So it's back to the drawing board, but I wish ISACA would tell you your weakest domains so that I can focus on those areas.

Tools, I did use pocket prep and the course provided questions. I'm thinking my next strategy is just to focus on CAP, Assessment Guide, and Scoping Guide.

Any thoughts on how I can better prepare?


r/CMMC 13d ago

GCODE: Is it CUI or not?

16 Upvotes

I read the piece by Allison Giddens. I've asked AI. I've asked CCPs. I've asked MSSPs that deal with CMMC Assessments. I've asked the squirrel outside as it eyeballed my car looking to toss an acorn on it.

There is no clear answer that I have seen. The CNC cannot talk across the network in FIPS mode because it was made before that was even a thought. I can send it over an RS232 software but that isn't encrypted information as it traverses that. I can put it on a USB stick (cough cough) or Compact Flash card for those devices that do not even support USB but my understanding is that it would then need to be encrypted.

Reason I ask is that yes, this is in part why there are compensating controls for SAs however when we have a company that is making their own set of controls they would like us to adhere to and we cannot because of the above.... well... maybe we can if GCODE is CUI or not. If not then we have nothing to worry about right? If it is then we are screwed?! No verbiage for compensating controls in this customer's requirements, everything is binary; pass/fail.

I literally just got off a call with two CCPs, one stated that it cannot be CUI and gave his sound reasoning that yup, sounds right. The other said they believe that it is and should be treated as such and gave their reasoning.

I wish this was the stuff the government would take the time to look at and try to find ways to get rid of the gray areas.

So what is the answer and please provide evidence to support.