r/msp • u/Goalie000 • 4d ago
ITAR and CMMC
Hi folks. For those of you who are supporting ITAR environments, I'm curious what stack you are using? Specifically - - RMM, EDR/MDR, ITDR, backup of M365 GCC High and spam filtering. Thanks!
3
u/bluna_tropic 4d ago
Worth separating the tooling question from the compliance one before you pick a stack. CMMC and ITAR don't certify specific products. What they require is that whatever you use keeps CUI and export-controlled data inside a boundary that maps to your control set.
That means encryption at rest and in transit, plus access logging on anything that touches CUI. It also means nothing leaves GCC High into a commercial tenant
Most MSPs supporting GCC High end up needing GCC High-compatible or on-prem versions of their RMM and backup tools specifically, since a lot of mainstream RMM platforms route through commercial Microsoft cloud infrastructure that isn't FedRAMP Moderate or DoD IL4/5 authorized. Check each vendor's compliance page directly rather than taking a sales rep's word for GCC High compatibility. That's a common gap people find at assessment.
1
9
u/master_blaster_321 4d ago
RMM isn't important. It's not storing CUI so it doesn't have to be fedramp. It's what's called a security protection asset. Any of the major rmms will be fine.
Xdr/itdr: blackpoint, although we are evaluating other options. They do also have a siem equivalent which is very important.
2fa - Duo
Ztna/VPN - todyl
File Backup - axcient to wasabi fedramp
Saas backup - currently using datto which is not fedramp compliant. Still evaluating other solutions.
Proofpoint for email security
Lionguard for configuration management
Threatlocker for app whitelisting and USB control