r/CMMC

▲ 13 r/CMMC

Failed mock because all SPAs were subject to all 110 security controls

We failed our mock audit because we didn’t document in the SSP how every control applied to every SPA in our environment. My question is, is this standard? I’ve talked to another auditor briefly who said the SPAs should only be assessed against controls that that SPA is used to make compliant.
https://www.theneteffect.com/cmmc/20251112.php#relevant
See my example below.

In 3.1.8, limit unsuccessful logon attempts, we defined how we limited logon attempts onto the windows machine. We were not compliant because the SSP didn’t document how we limited logon attempts onto the Threatlocker cloud portal. Upon looking at the SRM for threatlocker, it states that the limiting of logon attempts is the customers responsibility. In the threatlocker settings, there is no way to increase the lockout timer or number of failed logons before account lockout. The only thing I could find is the ability to federate it to a domain in which threatlocker would inherit the windows group policy. We would prefer not to do this because the “fractional IT employee” is completely remote and this small business would prefer to not pay for their new computer and GCCH license. Regardless, does anyone else have experience or guidance on whether SPAs are subject to all 110 security controls or not? And if not, is this something we could push back on the auditor against or do we need to cut our losses and find another C3PAO?

reddit.com
u/ManagerOk6785 — 1 day ago
▲ 3 r/CMMC

I don't want to leave my MSP, any suggestions?

I run a mid-sized manufacturing company and our prime contractor has been pushing us to show our CMMC progress. Our IT is handled by a local MSP that we have worked with for years and they manage all of our other compliance needs. They have never done CMMC, but we really don't want to lose that relationship with our MSP. Do i have to replace them or is there another company that can help advise them with CMMC work. Specially a help with guidance on a SSP, to help them know what controls and steps to have in place. Thanks

reddit.com
u/Mary_Rebeca — 1 day ago
▲ 7 r/CMMC

Summit7’s competitors

I’m trying to find the largest 5 players in this space. Who are Summit7’s closest competitors? Who is servicing the largest companies out there?

reddit.com
u/Aromatic_Walrus1560 — 1 day ago
▲ 3 r/CMMC

Does the continuous vetting program keep your current clearance active? I’m trying to see if working as a CCP/CCA will keep my TS/SCI active or will I have to work for a cleared company to keep it active

reddit.com
u/Jolly-Noise6392 — 1 day ago
▲ 4 r/CMMC

Screensharing CUI Alternatives?

Current stack:
Microsoft 365 Business Premium
PreVeil

We are preparing for CMMC Level 2 and trying to define a compliant path for meetings where CUI may be displayed through screensharing.

My current understanding is that using commercial Microsoft Teams for screensharing CUI is risky/not supportable for CMMC Level 2 unless the full environment, configuration, and inherited controls can be justified.

The three main alternatives I keep seeing are:

  1. Webex for Government
  2. Zoom for Government
  3. Microsoft GCC High / Teams in GCC High

My understanding is that GCC High is a separate Microsoft cloud/tenant environment, not something that can simply be merged into our existing commercial M365 tenant. We have only about 15 CUI handlers from the 150-employee workforce. My initial answer was zoom for government because I know that zoom has integration with m365 so it may be easier for the end users. I'm trying to balance headache and price basically. I would appreciate any advice.

reddit.com
u/Certain-Gap6204 — 1 day ago
▲ 5 r/CMMC

How are you all actually handling AI tool usage in your CMMC environment?

F500 cyber guy here (CISSP, not defense though so apologies if I'm late to the party). Been helping a couple buddies who run small defense subs prep for L2 and I can't find a clean answer on this from anyone.

Their people use AI for everything now. Copilot, ChatGPT, some are messing with agents. But the CMMC docs don't really address it. DFARS doesn't mention AI. 800-171 r3 has some adjacent stuff but nothing direct. NIST AI RMF exists but try handing that to a C3PAO and see how that goes.

Are you guys treating sanctioned AI tools as ESPs and doing the full categorization, or just bolting on AUP language and calling it good?

What about the analyst who pastes a CUI spec sheet into ChatGPT to summarize it because they're behind on a deliverable? You can't realistically watch every keyboard.

Has a C3PAO actually asked about AI tool usage in an assessment for any of you, or is it still flying under?

And for the workflows where you do let some AI tool touch CUI, how are you proving it's not training on your data beyond what the EULA says?

Feeling like a lot of folks are just kinda hoping it doesn't come up. Would love to know if I'm wrong about that.

reddit.com
u/TheTylerboltz — 2 days ago
▲ 5 r/CMMC

CMMC Scoping Question: Commercial CRM Storing FCI Outside GCC High

Long time lurker, first time posting. 🙂

I think I know the answer to this but wanted to bounce it off the experts here. While I want to say we are a unique situation, I feel like everyone in this subreddit has their own unique architecture/story.

Here is the scenario:

We operate two completely separate Microsoft tenants.

  • ABC Cyber = standard commercial/non-FedRAMP tenant
  • ABC Public = subsidiary operating in GCC High

ABC Public was stood up specifically to store, process, and transmit CUI. No connections between the two tenants at all. Separate accounts, separate systems, separate managed assets, etc. This setup existed before my time.

We are preparing for a CMMC Level 2 third-party assessment for early June.

ABC Public is very “vanilla”:

  • Native Microsoft cloud stack only
  • No on-prem
  • No external hosted systems/tools
  • No integrations

Because of that, some business functions still rely on ABC Cyber systems, mainly a CRM platform (think HubSpot, Pipedrive, Attio, etc.). The CRM itself is a standard commercial SaaS platform and is not FedRAMP authorized.

Important detail:
Users access the CRM using their ABC Cyber accounts and ABC Cyber-managed assets only. They do NOT access the CRM from ABC Public accounts/systems/devices.

There is no identity federation, trust relationship, synchronization, mail flow, or system integration between the environments.

The CRM may contain what I would classify as FCI related to federal contracts/customers, though I am digging deeper into that now to better understand exactly what data exists there. No CUI is supposed to exist in the CRM.

So my understanding of scoping is this:

During a CMMC Level 2 assessment, if the assessor asks:
“Where does your FCI live?”
…and the answer is:
“The ABC Cyber CRM”

Then that CRM environment is still in scope at least from a Level 1/FAR 52.204-21 perspective, even though:

  • it is not part of the GCC High enclave
  • it does not handle CUI
  • it is completely separate from the Level 2 environment

In other words:
The CRM does not need full Level 2/800-171 controls, but it would still need to satisfy the Level 1 safeguarding requirements because it stores/processes/transmits FCI.

My concern is that if the CRM is determined to be in scope for FCI and is not meeting the FAR 52.204-21 / Level 1 requirements, then we may have a larger readiness issue before even moving forward with the Level 2 assessment.

Am I thinking about that correctly?

reddit.com
u/ArtifactHoarder — 1 day ago
▲ 6 r/CMMC

Need Help!!

Hey everyone,
I have an interview coming up for the Information Security Intern (CMMC) role.
The role involves:
Security monitoring and alert review

Assisting with investigations/incident response

Vulnerability management & patching

Working with ITS Operations and enterprise systems

Learning cybersecurity operations in a professional environment

Background: I’m currently pursuing an M.S. in Information Science at with hands-on experience in Splunk, OpenVAS/Nessus, networking, IT support, and security labs.
For anyone who interviewed with similar security internships:
What technical questions did they ask?

Was it more behavioral or technical?

Any focus on networking, Windows, SIEM, troubleshooting, or compliance/CMMC concepts?

What should I prepare most for?

Any tips or experiences would really help. Thanks!

reddit.com
u/ShelterFantastic2114 — 2 days ago
▲ 7 r/CMMC+1 crossposts

CMMC Level 2: Is the WatchGuard Compliance Package worth it if we use PreVeil + M365 Business Premium?

We are mid-journey on our CMMC Level 2 compliance and looking for some feedback on our tooling strategy.

Our Current Stack / Scope:

  • CUI/FCI Enclave: PreVeil (storing/sharing all CUI and FCI).
  • Identity & Endpoint: M365 Business Premium (utilizing Intune and Defender for Business).
  • Network & Perimeter: WatchGuard T45 firewall with Total Security Suite, AuthPoint for MFA, and Advanced EPDR on the endpoints.

The Dilemma: We are looking at the WatchGuard Compliance Package (which includes automated NIST 800-171 control reports).

Is it actually worth paying extra for these automated compliance reports? Or should we just save the money and capitalize entirely on our Microsoft 365 Business Premium (Intune/Defender) capabilities and manually gather the firewall logs/evidence?

My gut tells me that since PreVeil is handling the CUI itself, the WatchGuard environment is essentially acting as a security domain that protects the endpoints accessing the enclave. Do automated reports from WatchGuard actually move the needle during a C3PAO assessment, or are they just expensive shelfware that duplicates what we can pull manually or through Microsoft?

Would love to hear from anyone who has gone through an assessment with a similar hybrid WatchGuard/Microsoft/PreVeil stack. Thanks!

reddit.com
u/OemNerd2K — 3 days ago
▲ 13 r/CMMC+1 crossposts

CMMC Level 2 Compliance - Using a service like Greypike

My company is dipping their toes into government work, and we're discovering the incredible amounts of red tape that lay in our path. Currently, we plan to submit proposals for some SBIR opportunities, but we're ultimately going to need to be CMMC L2 compliant. There is a service called Greypike that can guide us to compliance, but they also offer an 'enclave' which appears to be a workspace that they host, where CUIs and other info will live. There's a monthly cost for them to maintain the workspace. My understanding is that this is a decent alternative to transforming our current internal cybersecurity infrastructure ourselves (hiring more staff, buying hardware, and creating all the policies involved).

Has anybody used a service like this before? The service is costly, but it's also costly to do it ourselves. We come from an entirely different industry, but feel we have something unique to offer for DoD work. When I look at our current cybersecurity structure and methods, and compare them to what CMMC L2 requires...it gives me a migraine. I'm struggling to justify the costs for using a service like Greypike. Any advice is highly appreciated! Thanks all!

reddit.com
u/Unlikely_Fig_3123 — 3 days ago
▲ 3 r/CMMC

New to CMMC

I’m looking to get into CMMC auditing part time. I currently work full time as an information security analyst in cybersecurity. What steps should I take to get started and is the rate of pay worth it from your experience.

reddit.com
u/Specialist-Owl3522 — 3 days ago
▲ 2 r/CMMC

IDE Plug-ins

Hello,

I have recently started a new position wherein I am working on doing risk assessments. Recently, I had CCStudio come across my desk, which uses OpenVSX's plug-in marketplace to support its IDE environment. I hadn't really thought about it until this point, but how are these plug-ins controlled under CMMC? I'm fairly new to compliance so apologies if this seems like an obvious question.

As far as I can tell from my limited research, they wouldn't require individual assessments for every plug-in a developer may want, but we would be required to establish a list and perform regular vulnerability checks for each plug-in. Am I correct in that assumption?

If anyone has anything they can say to help, please do! Everything is greatly appreciated. Like I said, I'm new to the field, so anything is helpful for me!

reddit.com
u/Starmonster09 — 2 days ago
▲ 1 r/CMMC

Clearance

I currently hold an active U.S. Secret clearance with a completed Tier 3 investigation. Could you please advise what additional steps are required in the Cyber AB portal for CCA personnel screening compliance?

reddit.com
u/Prize_Assignment6691 — 3 days ago
▲ 7 r/CMMC

Why would any OSC say they need to reassess?

According to the new FAQs, "significant change" and the need for a reassessment are being left in the hands of the OSCs. Wondering what the thought process is here. If you're a student of game theory, you would probably conclude that the decision will more often than not be "I don't need a reassessment."

ETA: here's a link to the May 2026 FAQs https://dowcio.war.gov/Portals/0/Documents/CMMC/CMMC-FAQsv5.pdf

reddit.com
u/ResilientTechAdvisor — 5 days ago
▲ 4 r/CMMC

How to source clients?

I am a GRC professional with 10+ years of experience. One area of expertise is gap analysis and assessments, I have done this for years with many frameworks/standards.

I am interested in providing consulting for small to medium size companies who need cmmc compliance. I am struggling with lead generation and looking for some advice on how to get my firs clients.

I am studying for the CCP but hold both CISA and CISSP today.

Appreciate any insight.

reddit.com
u/Mici_429 — 5 days ago
▲ 8 r/CMMC

Anyone with an active clearance apply for their tier 3 recently? If so how long did it take to get your tier 3 back from cyberAB? I’ve been waiting 2 weeks and I’m ready to be certified. We go through the studying, the training, and then we finally pass the exams just to wait to be official.

I just got my TS/SCI after waiting for over a year. I hope I don’t have to wait a long time for DCSA once again

reddit.com
u/Jolly-Noise6392 — 5 days ago
▲ 26 r/CMMC

Subcontractor experiences lately

I work with a lot of subcontractors. Lately I've noticed the following with them:

  1. No idea CMMC is a thing - which leads me having to go into my speech and presentation about it.

  2. Struggling to achieve CMMC status - they've hired a consultant or MSP who never achieved CMMC status so it's the blind leading the blind.

It's gotten so bad that I have one internal employee here giving out my personal cell number to subs and telling them to call me immediately and I'll "get them situated", which is especially aggravating.

reddit.com
u/HeyHelpDeskGuy — 7 days ago
▲ 33 r/CMMC

New hire tasked with CMMC compliance despite no experience

Hey guys, I'm a new university co-op hired by a small manufacturing company last week to get them CMMC compliant/certified. They know I don't know anything about CMMC and told me to research everything and tell them what they need to do to get certified by Nov. 1st. They also want to avoid hiring any third-parties as much as possible, so I figured I'd ask some questions here on an anonymous account.

For some background, one of the companies that contract us, is requiring us to get a least some level of CMMC by Nov. 5th. We currently only deal with FCI from them, but after reading and writing down the requirements, Level 1 seems really bare/minimal, so we were thinking about maybe doing the Level 2 self-assessment instead just so we're more prepared if we ever end up handling CUI later on.

Now for my questions:

  1. Even though we only need Level 1, can we still choose to do the Level 2 self-assessment anyways?
  2. If we do Level 2, are we still supposed to separately do/get Level 1 too? From what I've researched, it seems like the Level 1 stuff (FAR) is already included in the Level 2 requirements (NIST) one way or another.
  3. How are we actually supposed to determine the scope for the self-assessment? I read through the scoping guide but I'm still confused on how you practically determine what's in scope and what isn't.
  4. If I researched correctly, the self-assessment gets submitted through SPRS, and Level 2 self-assessments are valid for 3 years with annual affirmations/checks annually, right?
  5. What exactly are CAGE(s)? I noticed the SPRS guide showed them in a submission box in some screenshots but I still don't really understand what they are and how we're supposed to obtain them.

Also, if possible, it'd be really helpful if you could provide documentation for your answers since I also have to make a write-up for our contracting company explaining why we chose whatever route we end up taking.

Sorry if these seem like dumb questions. I've been looking into this stuff for like a week and some of it is flying over my head. I'm just trying to get a better understanding

reddit.com
u/No_Painting_5871 — 7 days ago
▲ 3 r/CMMC+1 crossposts

Identrust ECA and Yubikey

Anyone else use Yubikeys with the yubikey driver and have trouble with ECA?

My experience - yubikey minidriver does not work with HIDActiveClient. I need the minidriver since I have over 2 PIV certs loaded in it.

So I uninstall the active client, and yubikey works - but now I can’t use my ECA!

reddit.com
u/mtspsu258 — 6 days ago