r/CMMC • u/Ace-MacAcerson • 5h ago
Worst CMMC practice.
Nerding out for a moment: I have often thought that the 3.13.14 (VOIP) is just very... mid. I’m curious what practices/objectives gets other practitioners worked up.
r/CMMC • u/medicaustik • Nov 14 '25
Hello /r/CMMC -
As we wind down 2025, the CMMC ecosystem has seen several hundred organizations successfully passing their CMMC Level 2 C3PAO certification assessments! We love to see it!
This community and our discord community have always been about open sharing of information amongst fellow practitioners and straight up people who just need some help. We love seeing how everyone shares what's working for them and what's not.
Recently, we've seen a handful of threads start with people wanting to share their Certification experience and their lessons learned - this is fantastic. But, if you aren't on /r/CMMC frequently, you will miss these threads.
So, I want to create a mega-thread to collect these experiences in one spot where people can share their experiences and others can ask questions.
If you were planning to post a whole thread about your experience, I encourage you to instead post here. We aren't preventing anyone from posting a separate thread, but think it's best to keep most of those types of posts here for the reasons stated above.
Congrats to everyone who has passed so far! For those who are scheduled, my main advice: relax. If you found this community, there's a good chance you're taking this as seriously as you should, and that means you're probably going to pass.
Notes
You are welcome to name the names of the tools you used, the service providers that helped you, the consultants who guided you, the C3PAO that assessed you. All of that is fair game and generally encouraged.
Share as much about your environment as you comfortably can - people want to know what other environments look like. Remember though, OPSEC is your responsibility, not ours. Do not post identifying information if you are not authorized by your organization to do so.
If you struggled with a particular requirement, or had a debate with your assessor, tell us about it.
If you absolutely crushed a requirement or control family and the assessors just looked at you slack jawed with how great you were, TELL US ABOUT THAT.
FORMAT
Please share the following information in your comment:
Organization Size: Rough user & device count
Scope: Enterprise / Enclave - if Enclave, how many users/devices in the Enclave
Architecture: Full Cloud / On-Prem / Hybrid
Cloud Services: Microsoft 365 (GCC/GCCH) / AWS / Other CSP
C3PAO: Who did you work with (optional, you don't have to share this if you don't want)
Cert Status: Pass / Fail / Conditional / In-Progress
And then of course give us all the details you want to share :)
r/CMMC • u/DaGoodBoy • Jul 13 '26
r/CMMC • u/Ace-MacAcerson • 5h ago
Nerding out for a moment: I have often thought that the 3.13.14 (VOIP) is just very... mid. I’m curious what practices/objectives gets other practitioners worked up.
r/CMMC • u/babywhiz • 1d ago
What do you do when you show them how their solution is not FedRamp and they double down and insist it is?
Edit: We have a vendor that won’t use our FedRamp Box for Gov and insists on us using their platform that looks like someone threw some code on AWS Gov and thinks they are compliant.
r/CMMC • u/ProNetSec1986 • 2d ago
Sitting for the CCA exam today. Please send positive vibes!
Edit: Passed the exam!
I used the official documentation in alignment with the blueprint. Then uploaded those documents directly to chat gpt and had it create study sessions and practice exams. I also did all 500 pocket prep questions.
I Took the exam yesterday and failed. I've taken many certification exams but have found that CCP and CCA were stressful and very difficult. I never felt that way before. My hands were actually shaking when I was driving there, probably because I want this so badly but didn't feel as confident as with other exams.
Anyway, I have no real clue where I went wrong. Although I have a lot of technical knowledge, I also have a lot of managerial and healthcare IT assessment experience. But I think it had to do with how the questions were phrased, answers provided, ambiguous and bad writing for scenarios. It made me feel stuck on stupid.
I wound up in a fog and second guessing at least half of the questions. My mind was so tired that I had to re-read some questions at least 2 times. So it's back to the drawing board, but I wish ISACA would tell you your weakest domains so that I can focus on those areas.
Tools, I did use pocket prep and the course provided questions. I'm thinking my next strategy is just to focus on CAP, Assessment Guide, and Scoping Guide.
Any thoughts on how I can better prepare?
r/CMMC • u/thegreatcerebral • 4d ago
I read the piece by Allison Giddens. I've asked AI. I've asked CCPs. I've asked MSSPs that deal with CMMC Assessments. I've asked the squirrel outside as it eyeballed my car looking to toss an acorn on it.
There is no clear answer that I have seen. The CNC cannot talk across the network in FIPS mode because it was made before that was even a thought. I can send it over an RS232 software but that isn't encrypted information as it traverses that. I can put it on a USB stick (cough cough) or Compact Flash card for those devices that do not even support USB but my understanding is that it would then need to be encrypted.
Reason I ask is that yes, this is in part why there are compensating controls for SAs however when we have a company that is making their own set of controls they would like us to adhere to and we cannot because of the above.... well... maybe we can if GCODE is CUI or not. If not then we have nothing to worry about right? If it is then we are screwed?! No verbiage for compensating controls in this customer's requirements, everything is binary; pass/fail.
I literally just got off a call with two CCPs, one stated that it cannot be CUI and gave his sound reasoning that yup, sounds right. The other said they believe that it is and should be treated as such and gave their reasoning.
I wish this was the stuff the government would take the time to look at and try to find ways to get rid of the gray areas.
So what is the answer and please provide evidence to support.
r/CMMC • u/mudpupper • 4d ago
Our goal is to have the entire network fall under scope but we have consultants/customers that need access a few our systems that won't have CUI on them.
I don't want to give them VPN access to keep their machines from falling under scope and to just remove all the access permission headaches. Would giving TeamViewer access to selected servers cause CMMC Level 2 compliance issues?
r/CMMC • u/Pale_Apricot6870 • 4d ago
r/CMMC • u/HomeLabDIY • 4d ago
Hey everyone! I have a quick question about 3.8.4 Media Marking. When visiting on-site, do you check whether laptops, servers, printers, and mobile devices have CUI stickers on them? When you respond, please add government documents, CMMC, or some type of authoritative sources for validation. Thanks! 😁
r/CMMC • u/sonofawhatthe • 5d ago
Processing img xjzaj80s6ylh1...

My job requires me to get the RPA from Cyber AB. You have to watch videos, in their entirety, to receive credit. The voice over guy is a terrorist. There's nothing else that makes sense. It's Death-by-Powerpoint.
Example: Theare are 15 sections of Module 4. So that means 15 different slide decks. At the beginning of EVERY slide deck, he reads the legal disclaimer. Word for word. He even reads the URL, EVERY TIME, letter-by-letter.
He then reads the agenda / contents word for word for every section. “And then we are going to look at “MP dot L2 dash 3 dot 8 dot 5 “Media Accountability”.
It's so hilariously awful. Even at 2x speed it takes like 5 minutes before you get to actual content.
EDIT: I posted the same pic twice, not that it matters.
r/CMMC • u/xxxTech007 • 5d ago
Ok, just watched the latest news update from Summit7 and they talked about an article that came out where an UN-NAMED DoD official speaks about some possible upcoming changes. But it totally contradicts why there was a pause in the first place!!! What's even more rich is this, Brilliant at the Basics plan the DoD kind of quietly put out the same day as the pause. Thing is, the recommendations in this plan, we're put together by Tech executives!!! Um, anyone see a problem with this?? Like maybe they'd love for us to spend more money?????
Y'all gotta read this shi.....
Brilliant at the Basics:
I have watched half of the DIB stand up an enclave in a cloud that is expensive and lets them add a second email address to their email signature to do some compliance theater. Presumably their original, and still extant, enterprise or commercial cloud systems still exist and still have all of their CUI prior to today. How many of you with enclaves have moved all of your existing and historical CUI to your enclave?
r/CMMC • u/Cold-Painting3562 • 5d ago
Hi all,
Looking for input from anyone running a Teams Rooms on Windows device in a GCC High tenant. Do we need to connect it to Intune / Entra Joined for it to be CMMC compliant. Main issue, account can't have MFA, but we thought compliant device CA policy would be good supplement for that.
If you did connect to Intune / Entra, how did you do it.
MP. L2-3.8.5
Access to media containing CUI is controlled
Accountability for media containing CUI is maintained during transport outside of controlled areas.
So CUI is protected in physical form. Sure. but when this refers to transport, do we think this includes the transport of physical pieces (assuming CUI), to customers?
We use a private courier.... I did include him in our ITAR training. Since he is physically handling our CUI, along with the tracking and traceability he provides, should there be some type of policy written about locking his doors? Not leaving the car for transport out of sight (like at a gas station), setting a car alarm, etc.?
Am I reaching? Is there another section somewhere that governs deliveries more explicitely? I feel like maybe something in the Physical Access Policy?
Thoughts?
r/CMMC • u/Upstairs_Buffalo_473 • 7d ago
Finally got my T3 after 22 months. Was quite the ride, and have been lurking on the subreddit here for a while. Excited to join the conversation here. Outside of the suspension of Phase 2, what has actually materially happneed? Seems like the program was going well, but my time has been limited since I pretty much gave up on working in CMMC.
r/CMMC • u/tripled21 • 7d ago
I'm wondering if there is any hope that my company can skip the hassle of the NIST SP800-171 controls, for example maybe the government builds an entirely new framework that cuts the fluff or makes it more accessible!?
r/CMMC • u/rotoblueprint • 7d ago
Assuming using Google suite with the standard toggles in place (e.g. 2FA), how much would it realistically cost to have someone come in, take a look, make suggestions, and make necessary annotations for a SSP Plan of Action?
Edit: some points of clarification:
• We are a human performance company, hardware and software.
• There will be some animal testing.
• This is for an SBIR Phase 2.
• As of now, we don't anticipate any CUI.
• We don't need any more than one person.
• It's extremely unclear what CUI, if any, would be applicable at this stage of the contract. This seems to just be a blanket requirement that the Army SBIR office is applying, which is leading to some level of confusion as to how to address this in the near term.
EDIT: How am I not negative in downvotes on the main post?! Ya'll getting lazy. Defend your cause for crying out loud!
r/CMMC • u/brunofone • 7d ago
So, I'd like to submit an application to a DoD OTA to become part of a consortium. The deadline is in a week, and they are requiring Level 1 certification upon submission, and self-certification as Level 2 before you do any work within the consortium.
I'm a one-person company and I generally work from home, although sometimes find myself on DoD or company office sites. I have a JCP certification which means I am already in SPRS/etc but have not pursued any CMMC stuff yet, because all CUI and sensitive data I touch is done on a client PC tied to their ecosystem.
Most people on here talk about Level 2 which I know can be complex, but is there some sort of pre-templated way to get to Level 1 in a short time? SSP's etc? Thanks for any resources.
r/CMMC • u/Necessary-Army-4097 • 7d ago
I’ve been an ISACA member for over 20 years. I have a “platinum“ membership. I hold a current CISM certification informally CRISC certification.
Still, in order to get my CCP, they required me to go through an application process, proving that I’ve been involved in the SECURITY space for at least two years.
Seems like they might’ve known that?
Hi Everyone,
I am taking my CCP exam at the end of the week and have been studying a bit mostly using pocket prep and referring to source documentation on occasion.
Is pocket prep enough? What documents should I key in on (I’ve been hearing CAP and Scope)?
I passed my security+ and have been working in security for the last couple of years. Is this exam something that is achievable? I already did the required training, but I am feeling nervous, so I wanted to see if anyone had any advice.
Thanks to those who give tips not just to me, but those who may be lurking going through the same thing!
r/CMMC • u/xxxTech007 • 8d ago
Aloha!
I'm working on a scope and we have a totally separate ISP connection that all CUI data will flow thru. We're also creating an enclave since it's a small number of people and devices handling CUI.
My question, and I'm pretty sure the answer is yes, but; Do the Router/Firewall need to be included in the scope and if so, are they CUI Assets or Security Protection assets?
(An Engineer will download blueprints from a portal then store the data on a server. His PC, the server, switch, etc will all be in scope)
r/CMMC • u/ResilientTechAdvisor • 9d ago
There's a real opportunity for the federal government to set everybody in the ecosystem up for success by ensuring that they properly mark CUI.
For example, sam.gov currently has RFP materials that are marked CUI when the rationale for that marking is not apparent.
For example, a blank past customer testimonial template is not CUI.
This stuff has downstream impacts which cannot be overstated. Hopefully the phase 2 pause is giving the government the opportunity to take a look at that.
r/CMMC • u/DangerousFishes • 8d ago
Looking for ways to set this up.
We've got drawing and modeling work that needs to go to an outside CAD shop. The technical data package is marked CUI. Some of it is probably export-controlled too.
So for anyone who has placed this kind of work:
And how did you keep the export-control question separate from the CMMC one? They have different tests. So I'm not sure how you handle both at the same time.