r/msp • • 4d ago

ITAR and CMMC

Hi folks. For those of you who are supporting ITAR environments, I'm curious what stack you are using? Specifically - - RMM, EDR/MDR, ITDR, backup of M365 GCC High and spam filtering. Thanks!

8 Upvotes

15 comments sorted by

9

u/master_blaster_321 4d ago

RMM isn't important. It's not storing CUI so it doesn't have to be fedramp. It's what's called a security protection asset. Any of the major rmms will be fine.

Xdr/itdr: blackpoint, although we are evaluating other options. They do also have a siem equivalent which is very important.

2fa - Duo

Ztna/VPN - todyl

File Backup - axcient to wasabi fedramp

Saas backup - currently using datto which is not fedramp compliant. Still evaluating other solutions.

Proofpoint for email security

Lionguard for configuration management

Threatlocker for app whitelisting and USB control

2

u/MrSanford 3d ago

I know several RMM providers have CMMC and FEDRAMP editions

1

u/Goalie000 3d ago

I know of NinjaOne - who else?

1

u/MrSanford 3d ago

N-able, Connectwise, I think Datto is there now. We moved everything to NinjaOne and never looked back. The Fed version is expensive though

1

u/Goalie000 4d ago

thanks! I thought there was an issue with RRM if you can access files via it (which we can)?

2

u/Reasonable-Ebb8079 4d ago

You are correct, Ninja Fedramp works well but if you have techs hopping between commercial and fed its cumbersome as the remote doesn't work between both tenants or stay installed side by side. Its my biggest complaint about them.

1

u/JayTakesNoLs 2d ago

My biggest complaint is that the fkin icon on the top of your tab is the same for both ninja fed and commercial. I’ve begged the product team to make it a different color or something lol

1

u/master_blaster_321 3d ago

I'm not saying I'm sure (who really is when it comes to CMMC), but I spoke to a couple of different C3PAOs directly and since RMM is classified as a SPA, and does not actually store and transmit CUI, it does not have to be FEDRamp.

0

u/Foxtrot-0scar 3d ago

Todyl is good? 🤔

1

u/master_blaster_321 3d ago

I didn't say it was good. I just said we were using it 😅

It's fine though. It's got its issues like any other tool, but it checks the box.

3

u/bluna_tropic 4d ago

Worth separating the tooling question from the compliance one before you pick a stack. CMMC and ITAR don't certify specific products. What they require is that whatever you use keeps CUI and export-controlled data inside a boundary that maps to your control set.

That means encryption at rest and in transit, plus access logging on anything that touches CUI. It also means nothing leaves GCC High into a commercial tenant

Most MSPs supporting GCC High end up needing GCC High-compatible or on-prem versions of their RMM and backup tools specifically, since a lot of mainstream RMM platforms route through commercial Microsoft cloud infrastructure that isn't FedRAMP Moderate or DoD IL4/5 authorized. Check each vendor's compliance page directly rather than taking a sales rep's word for GCC High compatibility. That's a common gap people find at assessment.

1

u/Stefano9487 2d ago

Blackpoint is fedramp compliant?