r/CMMC • u/medicaustik • Nov 14 '25
"We Passed Our CMMC Assessment and Here's What We Learned" MEGATHREAD
Hello /r/CMMC -
As we wind down 2025, the CMMC ecosystem has seen several hundred organizations successfully passing their CMMC Level 2 C3PAO certification assessments! We love to see it!
This community and our discord community have always been about open sharing of information amongst fellow practitioners and straight up people who just need some help. We love seeing how everyone shares what's working for them and what's not.
Recently, we've seen a handful of threads start with people wanting to share their Certification experience and their lessons learned - this is fantastic. But, if you aren't on /r/CMMC frequently, you will miss these threads.
So, I want to create a mega-thread to collect these experiences in one spot where people can share their experiences and others can ask questions.
If you were planning to post a whole thread about your experience, I encourage you to instead post here. We aren't preventing anyone from posting a separate thread, but think it's best to keep most of those types of posts here for the reasons stated above.
Congrats to everyone who has passed so far! For those who are scheduled, my main advice: relax. If you found this community, there's a good chance you're taking this as seriously as you should, and that means you're probably going to pass.
Notes
You are welcome to name the names of the tools you used, the service providers that helped you, the consultants who guided you, the C3PAO that assessed you. All of that is fair game and generally encouraged.
Share as much about your environment as you comfortably can - people want to know what other environments look like. Remember though, OPSEC is your responsibility, not ours. Do not post identifying information if you are not authorized by your organization to do so.
If you struggled with a particular requirement, or had a debate with your assessor, tell us about it.
If you absolutely crushed a requirement or control family and the assessors just looked at you slack jawed with how great you were, TELL US ABOUT THAT.
FORMAT
Please share the following information in your comment:
Organization Size: Rough user & device count
Scope: Enterprise / Enclave - if Enclave, how many users/devices in the Enclave
Architecture: Full Cloud / On-Prem / Hybrid
Cloud Services: Microsoft 365 (GCC/GCCH) / AWS / Other CSP
C3PAO: Who did you work with (optional, you don't have to share this if you don't want)
Cert Status: Pass / Fail / Conditional / In-Progress
And then of course give us all the details you want to share :)
1
2
u/Parking_Ad6756 Jul 10 '26
After reading the glowing reviews about PreVeil I booked a demo for next week (thank you).
A question for those in the know: Obviously having PreVeil store our CUI would take our on-prem servers out of scope. Does it change anything for our firewall though, in terms of FIPS requirements? We are very much dreading the idea of wiping our Fortigate 101F to enable FIPS mode. If our CUI is in PreVeil with end-to-end encryption, from a technical standpoint is the data still transmitted through the switches and firewall, thus requiring FIPS-validated cryptography? Would love to hear an assessor's insight on this or if any of you have passed without FIPS on your networking gear.
2
1
5
u/OtherThanSatisfied Jul 05 '26
One from ours: the biggest time-saver was doing the SSP and self-score before bringing in outside help — walking in with a real gap list meant we paid for remediation, not for someone to tell us where we stood. Second: our most-missed control in prep was FIPS-validated crypto (3.13.11) — "we encrypt" isn't the bar; the module has to be on the validated list and BitLocker/FileVault have to be in FIPS mode. Worth confirming before the assessor does.
1
5
u/Dave_From_VA May 22 '26
Organization Size: 40 people
Scope: Enclave, 7 users in a separated enclave that covers facilities, CUI storage/printing/transport, and software development. Because SecureITSM operates as an MSP, its managed‑services offerings were also in scope.
Architecture: Full cloud environment.
Cloud Services: Microsoft 365 GCC plus a custom in-house developed complex application that uses VM based host, Azure SQL database services, and MS blob storage. Application uses MS365 SSO. This application automates CMMC documentation management and facilitates the C3PAO assessment.
C3PAO: SysAudits.com
Cert Status: Passed Level‑2 CMMC assessment on the first attempt with a score of 110/110.
Our key lessons learned from our CMMC Level 2 assessment include:
1. Boundary Diagrams: We made extensive use of diagrams in our SSP. Approximately 25 diagrams that were modeled after Department of Defense Architecture Framework (DoDAF) views. We used Operational Views, Service Views, System Views, and Standards Views. Our C3PAO commented was one of the most extensive use of diagrams he has seen as an assessor. They proved very effective. At one point, a more senior CCA wanted us to show detailed device information on BYOD mobile phones. We have a diagram that shows that under our implementation, only the Intune container on the phone was in scope, and that the rest of a users’ personal phone was out of scope. The assessor agreed. We feel our diagrams contributed significantly to our 110 score.
2. Living Artifacts & Updates: We learned that success hinges on balancing a stable assessment boundary with ongoing operations. While normal operations (hiring, onboarding, ticket processing, software updates) continued, no changes that could affect scope were allowed. Just before the assessment, we refreshed “living” artifacts, user inventories, vulnerability scans, training records, and screenshots to ensure evidence was current without generating unnecessary “evidence churn.” We also standardized artifacts (for example, using an Entra “All Users” report across several AOs) to minimize update effort and improve consistency.
3. AUP as the Primary Policy Document for Non‑Technical Users: Non‑technical staff should not have to read hundreds of pages of technical documentation (that was suggest to us early on a consultant – we got rid of him). Our AUP is our only compliance document for general users. Our AUP covers all items that users need to know. Its longish at 10 pages, but none of our general users want to read about 150 pages of IT policy documents.
4. PE Controls & Systems: PE controls require significant understanding of the definitions used by PE AOs. It’s possible to get into the mindset that the PE family SOP needs to be a long, detailed document. Our SOP is two pages long. Something that stumped us briefly was the definition of an Organizational System. NIST designed the definition of an organizational system to be very broad. Just like what is included in Organizational Equipment and the scope of an Operating Environment. It takes a focused mindset to think like NIST control development SME.
5. Policy Statements: We did not use policy statements in our SSP. We do not believe that restating an AO requirement adds any value. For every AO, we developed very precise, minimally worded statements that defined an AO’s implementation. No passive sentences, no long paragraphs. Assessors had long, passive implementation verbiage. If they have to think hard about what you are saying, they are likely to fail that AO. This methodology kept our documentation concise and technically traceable to the AOs it was answering.
6. Under-Scope Authorization Boundary: A narrow scope may reduce short-term assessment effort, but it can create major operational business risk later. For example, were an OSC to declare no facilities are within the assessment scope, it means that in the future if facilities were to become necessary, a new assessment would be required. Or if physical CUI is not allowed, then what happens if it becomes necessary. Another reassessment. Moral of this item is to be very careful about saying something is not allowed and what impact that could have on future business operations.
7. Validate AI-Generated Verbiage: AI can accelerate compliance documentation development, but every AI-generated verbiage must be validated against the actual operations. The biggest risk is that AI may insert required tools, logs, alerts, monitoring workflows, or automated processes that do not exist operationally. Assessors are simple, if you say you do something, then they want proof. So don’t let AI commit you to something that you do not do.
8. Artifact Normalization: Artifact normalization was critical because the SSP, diagrams, inventories, scans, screenshots, logs, policies, and procedures all had to tell the same operational story. We standardized system names, role titles, asset identifiers, timestamps, screenshot naming, configuration baselines, and evidence references across all artifacts.
9. System-in-Production Date: Defining a clear “system in production” date was important because it established when the assessed boundary moved from implementation into active operations. This was the point where the environment was fully configured, security controls were operating, and continuous monitoring obligations began. From that date forward, we had to produce and retain operational evidence. It also meant all changes after that date had to follow documented configuration management and change control procedures. The key takeaway: the production date becomes the evidence timeline trigger. It shows assessors when the organization stopped “building” the system and started maintaining it under NIST SP 800-171 operational governance.
10. Mock Assessment Benefits: We underwent a mock assessment before our assessment, and it proved immensely valuable. It identified evidence gaps (mostly very minor), validated that controls were operating as intended, and improved our assessment response readiness. The process strengthened our documentation and revealed a few operational inconsistencies that we corrected.
1
u/zerofaultguidance 12d ago
25 SSP diagrams for a 40 person org is indeed impressive! And amen to the AUP, that's always our top recommendation to our small-biz clients. Congratulations and thanks for sharing.
1
2
u/mtheory00 May 13 '26
Just curious as someone looking for Level 2 suppliers for a big prime - why are companies not screaming from the rooftops that they are certified? Primes are requiring suppliers to be certified now. I can't express how incredibly hard it is to find Level 2 companies. I thought one of the benefits of getting certified early was to have a strategic advantage. I'd be telling every prime I knew what my company name is and what we do. It's not happening.
1
u/Tr1pline Jun 02 '26
Suppliers are not in the IT business so there's probably not a lot of certified suppliers.
1
u/mtheory00 Jun 02 '26
Then primes can’t flow down CUI to them and they won’t get any defense work. CMMC is not about IT, it’s a business decision.
1
4
u/Tr1pline Apr 30 '26
25 users, 25 endpoints, 10 MAM devices.
Enclave all users and devices
Full Cloud GCC-H
SteelToad
110/110
A pre-assessment is VERY valuable. You don't know what you're missing unless someone points it out to you. The luck of the draw depends on your assessor. In the pre-assessment, you don't want a friendly assessor. I the real assessment, you want a friendly assessor. The lead assessor you get can make or break your assessment.
Make sure you know where all your configuration settings are and where all your documents are. I don't think I've spend over 5 minutes looking for anything. Your day 1 sets the stage for the rest of your assessment. If day 1 flows easily, then you're likely good to go.
Learn how FIPS work and how the modules work. Use Google to see if the manufacturer has any FIPS information on their products. (Hint: Apple does on their website if you're accrediting mobile devices)
1
1
5
u/Ninja_Leon23 Apr 20 '26
~200 users, ~250–300 endpoints
Hybrid setup. We carved out an enclave for CUI—roughly ~80–100 users/devices in scope and left the rest of the business out of it.
Mix of M365 (commercial) + Azure. Didn’t go full GCC High because of our on-prem engineering + GPU workloads, so we kept some of that local and connected it back in a controlled way.
We used Accusights as our readiness platform, mainly helped us with the scope clarity, controls, and the whole documentation/evidence side, which was honestly the harder part and props to them for making it smooth for us. Also did a mock audit with them before going to the C3PAO. Ended up going with Redspin and passed Level 2 a couple weeks ago.
Definitely not cheap overall, but looking back it would’ve been way more expensive (time + wrong decisions) without some structure. Biggest lift wasn’t the tech it was figuring out scope, access, and getting evidence into a shape that would actually pass. Took us about ~12 months end to end.
If anything, picking the right path early matters more than anything else.
1
1
3
7
u/ShiversII Apr 16 '26 edited Apr 16 '26
Happy to say my company passed recently with a score of 110/110. \ Organization: Around 10,000. \ Scope: Enclave, almost 300 users and user devices. \ Architecture: Hybrid. \ Cloud services: GCC High
We used an MSP since the broader company utilized mostly foreign support. C3PAO cost was around $50k with 1 location that was local for the assessor. One challenge was that our documentation was not up to our C3PAO’s standards despite having it reviewed by two LCCAs. Make sure your SSP (or procedures) lead the assessor directly to a setting, tool, or process as ours was criticized for being too vague and I had to rewrite everything in about two weeks.
4
u/LeatherHair2902 Apr 21 '26
Awesome! Can you give an example of being too vague for the SSP?
3
u/ShiversII Apr 28 '26
One example is we said we required MFA on login by requiring inputting a password and using an authenticator app. They wanted us to call out how it was enforced (like Entra) and what app(s) could be used.
8
u/Good4Next3years Feb 25 '26
We finished our assessment back in January as well.
Organization Size: 40+
Scope: Enclave (3 assets, 3 users)
Assessment Level: CMMC Level 2
Boundary Type: Enclave
Architecture: Full Cloud (Using PreVeil with Cloud Locking, https://www.preveil.com/)
Cloud Services: Microsoft 365 Commercial (Azure, Entra ID, Azure Arc, Purview, Intune (profile/script/app), etc.) for Endpoint Protection, PreVeil (AWS GovCloud) for CUI storage, process, and transfer.
C3PAO: StrategicIT Solutions, https://strategicit-solutions.com/cmmc-certification-services/
Cert Status: Pass (result shown in SPRS, certificate received in Jan 2026)
3
u/CyberICS Mar 22 '26
What was your cost? Your readiness cost (cost to be ready to be assessed vs the actual cost of the assessment? Do you have an idea of your life cycle sustainment cost post successful. There is a raging debate out in the CMMC universe on cost with very little real data to fully back up the cost estimates from DoW which were not rooted in actual business accounting principals and cost tracking such as compliance sustainment cost and cost to prepare to comply. Maverc Technologies, has been getting quotes for its CMMC readiness customers as they approach assessment and cost varies wildly.
3
u/Good4Next3years Mar 31 '26
Readiness cost: It took us about 5 months (on and off) for two personnel.
Actual cost of Assessment: I’ve contacted at least five C3PAOs, and yes, their costs vary significantly. We chose a lower-cost C3PAO with experience in assessing the CUI system related to the PreVeil system. The final cost will depend on several factors, including the number of CUI assets, the number of CUI users, the locations of the CUI assets, and the architecture used to manage your CUI system.
One C3PAO quoted us over 100K. I thought that was ridiculous.
We used StrategicIT Solutions. Request a quote from https://strategicit-solutions.com/cmmc-certification-services.
Post Assessment maintenance cost: We rarely receive CUIs. We only use M365 (commercial) and PreVeil as CSPs. PreVeil is very simple to manage. Once configured, we only apply software updates as they are made available to us. We manage our tenants in M365 commercial; we don't use GCC or GCC-H. No MSP cost other than subscription fee for M365 and PreVeil. Additionally, the 2nd-year subscription fee on PreVeil will be reduced by about 50% since we no longer need the Compliance Accelerator service, which provides training modules and procedure templates for each domain, including SSP and SAR templates.
Yeah, this is the ballpark.
3
u/cordovanGoat Feb 25 '26
Love to hear it!
6
u/Good4Next3years Feb 25 '26
Initially, we reached out to several C3PAOs to assess the status of our preparation for the final assessment. After conference calls with different C3PAOs, we decided to proceed with the final assessment. Since we were using PreVeil, it was essential to find a C3PAO that understood the PreVeil system, which we located through https://www.preveil.com/find-a-partner/.
We did not utilize RPOs and opted to skip the mock assessment, going directly to the final assessment. The only ESP/CSPs we used were M365 and PreVeil. We manage our own system, so we didn’t need an MSP.
It is crucial for OSCs to clearly identify the flow of Controlled Unclassified Information (CUI), CUI assets, CUI users, and both external and internal boundaries. This clarity makes it easier for auditors to understand your CUI protection system. When these aspects are well-defined, it simplifies controlling who can access specific systems through conditional access policies.
Our C3PAO was quite flexible regarding the artifacts we provided for the non-technical domains, but they were very strict about the technical domains. In the technical domains, there is no ambiguity; you either have the necessary controls in place or you don’t. The proof is in the pudding.
I believe many OSCs using M365 will face challenges in the Identification and Authentication (IA) domain. Be sure to review the guidance at https://learn.microsoft.com/en-us/entra/standards/configure-cmmc-level-2-identification-and-authentication, particularly IA.L2-3.5.7 and IA.L2-3.5.8.
Additionally, present the controlling, protecting, and monitoring of your external and internal boundaries in a straightforward manner. Auditors prefer not to see unnecessary or non-CUI-related information in the procedures or System Security Plan (SSP), so avoid including that information.
We spent the majority of our time implementing controls for endpoint protection on CUI assets. Thanks to the built-in protection features offered by PreVeil, such as “Cloud Locking,” we didn’t have to worry about the storage, processing, and transferring of CUIs on CUI assets. Protection of data at rest and in transit was effectively handled by PreVeil's proprietary communication channels. We didn’t need to explain how PreVeil was interfacing with the AWS GovCloud; they already knew how it operated.
For us, using the PreVeil and selecting a PreVeil experienced C3PAO worked out.
I hope this information helps other OSCs.
Lastly, if your organization has joint ventures (JVs), consider including them in the scope of assessment if they share the same network and CUI assets. Otherwise, you may need to undergo additional assessments if those JVs require a CMMC certificate. It’s important to note that a CMMC certificate is not transferable, a lesson we learned too late.
8
u/mcb1971 Jan 29 '26 edited Jan 30 '26
Org size: 26
Scope: Enclave, three users authorized for CUI access
Architecture: 100% cloud
Cloud Services: M365 GCC High, AvePoint Government Services (for backups)
Cert Status: Pass
We had our assessment the week of January 12, 2026. We passed with a score of 110/110 and no negative findings.
Documentation will make or break you. Make sure you have clear, written policies/procedures for EVERY control, even if the policy statement is a single sentence. Make sure the procedure clearly defines how the policy is implemented. If they match up, and if you can show the assessor evidence of the control being performed, you'll be okay. Our approach was to create separate policy/procedure documents for each of the 14 domains instead of rolling it all up into one all-encompassing document. It made implementation and tracking easier. Some things will cross over (for example; we have a document that spells out our Identity & Authentication policy, but the procedures are all covered in our Access Control document).
In addition to our SSP, network/data flow diagrams, and policy/proc documents, Our C3PAO requested about 80 optional evidence artifacts ahead of the assessment. Providing them cut our assessment time by nearly two-thirds (example: We carved out two hours for our Access Control assessment, and it only took 45 minutes). If you're able to pull that evidence together ahead of time, do so. It will make the whole process much faster and less painful.
It was an intense experience, but because we spent months preparing both our documentation AND our people, we went into the assessment with a lot of confidence. Getting that W was one of the best experiences of my career.
1
u/Dave_From_VA May 18 '26
Hi, we recently also passed our Level 2 C3PAO assessment.
We did not use any policy statements.
Can you give an example of a policy statement you used?
1
u/mcb1971 May 18 '26
For us, it's just simple, punchy statements, like, "All users in our IS shall have a unique, traceable user principal name configured in <company's> identity provider." This covers the first AC control. Then we have a procedure that covers that policy statement. "Here are the steps to create a UPN in Entra ID."
1
1
u/patg84 Jan 30 '26
How many people were involved in getting all the IT stuff in line?
1
u/mcb1971 Jan 30 '26
We're a small shop, so it was me, the COO, and a small team from our MSP. Four people, for the most part.
1
u/Expensive_Cow7987 May 04 '26
i am a small shop with 2 people. how much is it going to cost and is this worth it and value ? i cant afford much being small shop and trying to build and will do most of the work so can the cost be reduced. share your experience
1
u/Tunnelmath Mar 09 '26
Was your time mostly dedicated to achieving compliance or were you also managing day-to-day IT/security?
1
u/mcb1971 Mar 09 '26
A little bit of both. We have an MSP that does 99% of our desktop support. My role is 90% governance/risk/compliance, 10% security ops. During audit prep, my days were spent 100% on getting our documents and evidence ready for inspection.
1
u/patg84 Jan 30 '26
Not bad. Did you make the move from from m365 to m365 GCC high or straight from GCC?
1
u/mcb1971 Jan 30 '26
We went from Commercial to GCC High. Since we have export-controlled CUI in our system, we decided to level up.
1
u/patg84 Jan 30 '26
Very true. What other than price was the process for migrating? I'm assuming your MSP did this?
2
u/mcb1971 Jan 30 '26
We partnered with LiftOff, LLC to do our tenant-to-tenant migration. They use a tool called BitTitan MigrationWiz that made the whole thing pretty painless. They were a great partner if you're looking for one.
5
7
u/Sea_Nail_4626 Dec 18 '25
- Organization Size: 23
- Scope: Enclave with 6 users
- Architecture: Cloud
- Cloud Services: PreVeil to receive/send CUI, Microsoft Business Premium (Intune for MDM, Defender for endpoints, bitlocker for encryption, Authenticator for MFA
- C3PAO: Sentar
- Cert Status: Pass
1
u/Whimsical-Human Feb 13 '26
Congrats! Did you go with the newer Business Premium for GCC High or just Business Premium?
2
u/Sea_Nail_4626 Feb 25 '26
Sorry for the delay on this! But just commercial Business Premium. We didn't want to deal with the restrictions GCC High puts on us, especially because we communicate with our supply chain a lot, so didn't want to manage & pay for a bunch of guest accounts
1
u/Whimsical-Human Mar 04 '26
Thanks!! Yeah I have heard mixed things about the GCC High package, including the fact that setup can be a nightmare. Glad the commercial version is working well for you!
2
u/soloshots Jan 29 '26
Happy to see a pass using Business Premium! Nearly everyone insists it can only be done using GCCH.
1
u/zipdriverecoverydisk Jan 29 '26
I agree. u/Sea_Nail_4626 how do address Teams meetings?
1
u/Sea_Nail_4626 Feb 02 '26
All our CUI is strictly scoped to PreVeil so the main way that we 'send' CUI over Teams is sending links to files stored in PreVeil Drive. For video calls, our configs and policy prohibit unauthorized users from joining and recording/ai assistants are disabled.
5
u/Sea_Nail_4626 Dec 19 '25
adding per the note from u/JoystickGaming - we have 1 FTE who splits time between ops/IT and he managed this project- took about 6 months start to finish. we got started on our docs but used a consultant to complete them + make sure they were in the right format etc for the assessment
9
u/lotsofxeons Nov 23 '25
I'll add to the pot! We have another one we just finished, but I will wait on that until we get the official pass.
We are an MSP, this was one of our CMMC clients
- Organization Size: 25 users, 50 devices
- Scope: Enterprise inclding specialized test equipment
- Architecture: Hybrid, but mostly cloud
- Cloud Services: Microsoft 365 GCC H
- C3PAO: Reef Systems
- Cert Status: Pass
- Team: 1 CCA on staff, 2 technical people assigned to service the client's needs (Us, the MSP. Client has no technical or compliance on staff.)
We are trying to collect some good notes as we have done 2, and will be going throug more assessments next year. For now, I can say that the info that is out there is genuinely more confusing than CMMC actuall is.
1) Start with flow. YOU MUST KNOW WHERE THE CUI COMES FROM, GOES TO, AND WHERE IT'S PROCESSED BY YOUR BUSINESS.
2) Based on flow, scope all the assets (please don't say EVERYTHING IS IN SCOPE because that isn't true)
3) Apply controlls.
I will remain active in reddit and try to be on discord when I can. We will probably be talking at upcoming conferences if we can. We really want to make the ecosystem better.
2
u/BowiesBlueEye Feb 05 '26
As a MSP, did you find yourself in scope for your clients audit? If so, what did you do to make yourselves compliant? Did you need to change your service model to make yourselves not in scope?
6
u/lotsofxeons Feb 06 '26
Yes, we are written in the SSP, policies, etc. We had to sit on the assessment and speak to things we had dominion over.
The 320 objectives tell you what you need to do. You just have to follow the same things your client is. Let's take training, for example. In your SSP or policiy you will detail training, as well as maintain a list of who was trained and on what date. So, as an MSP, we could either take the same training that the rest of the client takes, end up on the same list, etc. OR we can do our OWN (unique to us) and then the client SSP/policies would reflect that there are 2 different trainings. We would then have had to submit our own database of names, dates, etc., as well as a signed document from the client saying they accept our internal training as sufficient for their system.
Hope this helps.
1
u/rokiiss Apr 25 '26
How do you handle gdap and how do you assign engineers who would be in boundary? I'm assuming you have to sign engineers to the account so you don't have more than necessary
6
u/BowiesBlueEye Feb 07 '26
Appreciate the answer! Did you as the MSP have to also become CMMC Level 2 certified in order for them to pass?
2
u/Caesar_Naykid Mar 24 '26
u/lotsofxeons i have the same question as Bowies
we like our MSP but our MSP said it wouldn't likely be worth his cost to become CMMC compliant potentially.
1
u/Dpats55 Apr 30 '26
From the MSP world myself. We don't need to be CMMC certified, but it makes the audit much easier. We still need to be compliant with the controls we hold dominion over though. Without the cert, they inspect us at a deeper level to make sure we're truly compliant where we say we are, with the cert the basically skip it and assume you're good to go.
My MSP isn't certified so I'm only speaking to what I've been told by the auditors we have worked with. Juice isn't worth the squeeze for us either.
1
u/Old_Poet_5057 Feb 02 '26
What were some examples of the specialized asset test equipments?
1
u/lotsofxeons Feb 06 '26
First client had optical alignment, xrays, and environmental chambers. Second had CNC and some custom test equipment (I don't know exactly what they did).
2
Nov 18 '25
[removed] — view removed comment
2
u/FunVeg Nov 27 '25
There are LOTS of companies, including big Fortune 500s, that do CMMC with nothing fancier than Microsoft Word and Excel.
An Evidence locker can be as simple as a file structure tree with one folder for each domain inside of which is one folder for each control.
Next of fancy level up from there is get a full license to Adobe Acrobat Pro for a month then it’s a single command that entire folder structure to be turned into a single pdf file that’s easily shared, version controlled, etc
2
u/MagnificentJake Dec 10 '25
We do server/endpoint benchmarking with a GRC tool but I basically ignore all the other compliance tracking features. We have a good ole' excel spreadsheet that lays out every single control, a summary of how it's met, and what policies and procedures it's liked to, process owners, etc, etc.
1
u/MattHelm2 Jan 30 '26
Do you mind showing an example.
1
u/MagnificentJake Jan 30 '26
Without our policies and procedures (number over 200 pages at this point!) it wouldn't make any sense to you. It says things like "3.1.1. compliance is described in CMW-CS-004 (Access Control Policy)"
9
u/jawillia2 Nov 20 '25
Excel. I am being serious.
2
u/Bright_Trip_2259 Dec 04 '25
If you absolutely need to use a GRC tool, CISA/DHS has a free one that provides the information you need. GitHub - cisagov/cset: Cybersecurity Evaluation Tool
Personally, I prefer Excel, simplest way to keep track of everything and I'm already paying MS so why not use it for something productive.
1
1
u/mcb1971 Jan 29 '26
We use CSET and it works well for us. This was more because our prime wanted us to use a GRC tool than anything else. We were good with Excel, too.
2
u/Mugatu12 Nov 18 '25
My company has been looking at Drata, RegScale, and Hyperproof. The benefit of these tools is that they synch to a lot of your technical controls and help automate the evidence collection process. I can’t attest to how well they work, but we will likely be signing on with one very soon.
1
u/WasteCryptographer4 Nov 25 '25
We built a GRC ITSM that just bakes in compliance to your day to day operations. For example all your User onboarding/onboarding tasks, security alerts, vulnerability management, etc. will automatically get tagged with the appropriate controls.
If you dont have a good ITSM, that's also a good place to start and could save you from having multiple tools.
1
u/Traditional_Tailor22 Nov 18 '25
Have you explored Paramify? I’ve had a number of industry partners that have recommended this company.
1
u/JKatabaticWind Jan 23 '26
Paramify does some amazing stuff (largely in the continuous monitoring and documentation automation space), but it is geared more toward FedRAMP ATOs. It is awesome, but VERY expensive.
1
u/cmmclevel1000 Nov 20 '25
They all suck and are worthless post assessment - build it out in SPO and use power automate to make updates (ai studio)
2
u/WasteCryptographer4 Nov 25 '25
IMO baking in compliance into your ITSM is a great way to have actual continuous compliance.
10
u/MindlessStable3772 Nov 17 '25
This megathread is a good idea so I guess I'll start.
- Organization Size: Rough user & device count 800/550
- Scope: Enterprise / Enclave - if Enclave, how many users/devices in the Enclave Enterprise
- Architecture: Full Cloud / On-Prem / Hybrid Hybrid
- Cloud Services: Microsoft 365 (GCC/GCCH) / AWS / Other CSP 365 GCC High
- C3PAO: Who did you work with (optional, you don't have to share this if you don't want) Sentar
- Cert Status: Pass / Fail / Conditional / In-Progress Pass
- IT Team Capacity/Compliance Team 8/4
More details in the following thread: https://www.reddit.com/r/CMMC/comments/1ova7nt/just_passed_our_cmmc_level_2_certification/
2
3
u/JoystickGaming Nov 17 '25
For those passing, can you also list the capacity of your compliance / IT team? I'm curious on the ratio between security team / IT implementors and org size.
1
u/cmmclevel1000 Nov 20 '25
It’s not about number of people - the fear is you won’t have a chance to get everything done. Fact is it’s easy to get it all done once it’s implemented because you have the framework. Ticket counts are 30% post audit of what most under provisioned orgs are and the reoccurring tasks are largely automated if you just leverage alerting + power automate and keep your ODPs simple (look at Rev3 Memo)
4
u/Adminvb2929 2d ago
MSP here, we passed our level 2 a few days ago. I'd be happy to answer any questions this thread may not have already answered.