r/CMMC 6h ago

Worst CMMC practice.

2 Upvotes

Nerding out for a moment: I have often thought that the 3.13.14 (VOIP) is just very... mid. I’m curious what practices/objectives gets other practitioners worked up.


r/CMMC 1d ago

How To Navigate Vendors that Insist their Solution is FedRamp when It's not on FedRamp Marketplace?

7 Upvotes

What do you do when you show them how their solution is not FedRamp and they double down and insist it is?

Edit: We have a vendor that won’t use our FedRamp Box for Gov and insists on us using their platform that looks like someone threw some code on AWS Gov and thinks they are compliant.


r/CMMC 2d ago

Sitting for CCA Exam

8 Upvotes

Sitting for the CCA exam today. Please send positive vibes!

Edit: Passed the exam!

I used the official documentation in alignment with the blueprint. Then uploaded those documents directly to chat gpt and had it create study sessions and practice exams. I also did all 500 pocket prep questions.


r/CMMC 2d ago

Failed CCA 8/29/26

5 Upvotes

I Took the exam yesterday and failed. I've taken many certification exams but have found that CCP and CCA were stressful and very difficult. I never felt that way before. My hands were actually shaking when I was driving there, probably because I want this so badly but didn't feel as confident as with other exams.

Anyway, I have no real clue where I went wrong. Although I have a lot of technical knowledge, I also have a lot of managerial and healthcare IT assessment experience. But I think it had to do with how the questions were phrased, answers provided, ambiguous and bad writing for scenarios. It made me feel stuck on stupid.

I wound up in a fog and second guessing at least half of the questions. My mind was so tired that I had to re-read some questions at least 2 times. So it's back to the drawing board, but I wish ISACA would tell you your weakest domains so that I can focus on those areas.

Tools, I did use pocket prep and the course provided questions. I'm thinking my next strategy is just to focus on CAP, Assessment Guide, and Scoping Guide.

Any thoughts on how I can better prepare?


r/CMMC 4d ago

GCODE: Is it CUI or not?

13 Upvotes

I read the piece by Allison Giddens. I've asked AI. I've asked CCPs. I've asked MSSPs that deal with CMMC Assessments. I've asked the squirrel outside as it eyeballed my car looking to toss an acorn on it.

There is no clear answer that I have seen. The CNC cannot talk across the network in FIPS mode because it was made before that was even a thought. I can send it over an RS232 software but that isn't encrypted information as it traverses that. I can put it on a USB stick (cough cough) or Compact Flash card for those devices that do not even support USB but my understanding is that it would then need to be encrypted.

Reason I ask is that yes, this is in part why there are compensating controls for SAs however when we have a company that is making their own set of controls they would like us to adhere to and we cannot because of the above.... well... maybe we can if GCODE is CUI or not. If not then we have nothing to worry about right? If it is then we are screwed?! No verbiage for compensating controls in this customer's requirements, everything is binary; pass/fail.

I literally just got off a call with two CCPs, one stated that it cannot be CUI and gave his sound reasoning that yup, sounds right. The other said they believe that it is and should be treated as such and gave their reasoning.

I wish this was the stuff the government would take the time to look at and try to find ways to get rid of the gray areas.

So what is the answer and please provide evidence to support.


r/CMMC 4d ago

What are thoughts on using TeamViewer for accessing systems remotely?

3 Upvotes

Our goal is to have the entire network fall under scope but we have consultants/customers that need access a few our systems that won't have CUI on them.

I don't want to give them VPN access to keep their machines from falling under scope and to just remove all the access permission headaches. Would giving TeamViewer access to selected servers cause CMMC Level 2 compliance issues?


r/CMMC 4d ago

Im the sole ISSM for my org and got us to a passing level 2 assesment ask me anything

4 Upvotes

r/CMMC 4d ago

3.8.4 Marking Media Question

2 Upvotes

Hey everyone! I have a quick question about 3.8.4 Media Marking. When visiting on-site, do you check whether laptops, servers, printers, and mobile devices have CUI stickers on them? When you respond, please add government documents, CMMC, or some type of authoritative sources for validation. Thanks! 😁


r/CMMC 5d ago

Insanity: The Cyber AB "training" videos for RPA

30 Upvotes

Processing img xjzaj80s6ylh1...

My job requires me to get the RPA from Cyber AB. You have to watch videos, in their entirety, to receive credit. The voice over guy is a terrorist. There's nothing else that makes sense. It's Death-by-Powerpoint.

Example: Theare are 15 sections of Module 4. So that means 15 different slide decks. At the beginning of EVERY slide deck, he reads the legal disclaimer. Word for word. He even reads the URL, EVERY TIME, letter-by-letter.

He then reads the agenda / contents word for word for every section. “And then we are going to look at “MP dot L2 dash 3 dot 8 dot 5 “Media Accountability”.

It's so hilariously awful. Even at 2x speed it takes like 5 minutes before you get to actual content.

EDIT: I posted the same pic twice, not that it matters.


r/CMMC 5d ago

Wow, really??? New Cyber Campaign Contradicts CMMC Pause, Expert Says...

12 Upvotes

Ok, just watched the latest news update from Summit7 and they talked about an article that came out where an UN-NAMED DoD official speaks about some possible upcoming changes. But it totally contradicts why there was a pause in the first place!!! What's even more rich is this, Brilliant at the Basics plan the DoD kind of quietly put out the same day as the pause. Thing is, the recommendations in this plan, we're put together by Tech executives!!! Um, anyone see a problem with this?? Like maybe they'd love for us to spend more money?????

Y'all gotta read this shi.....

https://www.nationaldefensemagazine.org/articles/2026/8/25/new-cyber-campaign-contradicts-cmmc-pause-expert-says

Brilliant at the Basics:

https://dowcio.war.gov/BrilliantBasics/


r/CMMC 5d ago

Did you move all the CUI?

0 Upvotes

I have watched half of the DIB stand up an enclave in a cloud that is expensive and lets them add a second email address to their email signature to do some compliance theater. Presumably their original, and still extant, enterprise or commercial cloud systems still exist and still have all of their CUI prior to today. How many of you with enclaves have moved all of your existing and historical CUI to your enclave?


r/CMMC 5d ago

GCC-High Teams Room

5 Upvotes

Hi all,

Looking for input from anyone running a Teams Rooms on Windows device in a GCC High tenant. Do we need to connect it to Intune / Entra Joined for it to be CMMC compliant. Main issue, account can't have MFA, but we thought compliant device CA policy would be good supplement for that.

If you did connect to Intune / Entra, how did you do it.


r/CMMC 6d ago

Media Accountability

2 Upvotes

MP. L2-3.8.5

Access to media containing CUI is controlled

Accountability for media containing CUI is maintained during transport outside of controlled areas.

So CUI is protected in physical form. Sure. but when this refers to transport, do we think this includes the transport of physical pieces (assuming CUI), to customers?

We use a private courier.... I did include him in our ITAR training. Since he is physically handling our CUI, along with the tracking and traceability he provides, should there be some type of policy written about locking his doors? Not leaving the car for transport out of sight (like at a gas station), setting a car alarm, etc.?

Am I reaching? Is there another section somewhere that governs deliveries more explicitely? I feel like maybe something in the Physical Access Policy?

Thoughts?


r/CMMC 7d ago

T3 - Finally Got it!

2 Upvotes

Finally got my T3 after 22 months. Was quite the ride, and have been lurking on the subreddit here for a while. Excited to join the conversation here. Outside of the suspension of Phase 2, what has actually materially happneed? Seems like the program was going well, but my time has been limited since I pretty much gave up on working in CMMC.


r/CMMC 7d ago

Is there a chance the CMMC Suspension results in new framework making it easier for small businesses to deal with CUI, or better labeling?

13 Upvotes

I'm wondering if there is any hope that my company can skip the hassle of the NIST SP800-171 controls, for example maybe the government builds an entirely new framework that cuts the fluff or makes it more accessible!?


r/CMMC 7d ago

Army Phase II Requirements

Post image
0 Upvotes

Assuming using Google suite with the standard toggles in place (e.g. 2FA), how much would it realistically cost to have someone come in, take a look, make suggestions, and make necessary annotations for a SSP Plan of Action?

Edit: some points of clarification:

• We are a human performance company, hardware and software.
• There will be some animal testing.
• This is for an SBIR Phase 2.
• As of now, we don't anticipate any CUI.
• We don't need any more than one person.
• It's extremely unclear what CUI, if any, would be applicable at this stage of the contract. This seems to just be a blanket requirement that the Army SBIR office is applying, which is leading to some level of confusion as to how to address this in the near term.

EDIT: How am I not negative in downvotes on the main post?! Ya'll getting lazy. Defend your cause for crying out loud!


r/CMMC 7d ago

Need to get to Level 1 quickly

3 Upvotes

So, I'd like to submit an application to a DoD OTA to become part of a consortium. The deadline is in a week, and they are requiring Level 1 certification upon submission, and self-certification as Level 2 before you do any work within the consortium.

I'm a one-person company and I generally work from home, although sometimes find myself on DoD or company office sites. I have a JCP certification which means I am already in SPRS/etc but have not pursued any CMMC stuff yet, because all CUI and sensitive data I touch is done on a client PC tied to their ecosystem.

Most people on here talk about Level 2 which I know can be complex, but is there some sort of pre-templated way to get to Level 1 in a short time? SSP's etc? Thanks for any resources.


r/CMMC 8d ago

ISACA: DoW CMMC Reform Task Force Input

Thumbnail
isaca.org
26 Upvotes

r/CMMC 7d ago

ISACA CCP APPLICATION

0 Upvotes

I’ve been an ISACA member for over 20 years. I have a “platinum“ membership. I hold a current CISM certification informally CRISC certification.

Still, in order to get my CCP, they required me to go through an application process, proving that I’ve been involved in the SECURITY space for at least two years.

Seems like they might’ve known that?


r/CMMC 8d ago

CCP this week, any advice?

5 Upvotes

Hi Everyone,

I am taking my CCP exam at the end of the week and have been studying a bit mostly using pocket prep and referring to source documentation on occasion.

Is pocket prep enough? What documents should I key in on (I’ve been hearing CAP and Scope)?

I passed my security+ and have been working in security for the last couple of years. Is this exam something that is achievable? I already did the required training, but I am feeling nervous, so I wanted to see if anyone had any advice.

Thanks to those who give tips not just to me, but those who may be lurking going through the same thing!


r/CMMC 8d ago

Are the Firewall and Router in scope?

1 Upvotes

Aloha!

I'm working on a scope and we have a totally separate ISP connection that all CUI data will flow thru. We're also creating an enclave since it's a small number of people and devices handling CUI.

My question, and I'm pretty sure the answer is yes, but; Do the Router/Firewall need to be included in the scope and if so, are they CUI Assets or Security Protection assets?

(An Engineer will download blueprints from a portal then store the data on a server. His PC, the server, switch, etc will all be in scope)


r/CMMC 9d ago

Mark it Right

25 Upvotes

There's a real opportunity for the federal government to set everybody in the ecosystem up for success by ensuring that they properly mark CUI.

For example, sam.gov currently has RFP materials that are marked CUI when the rationale for that marking is not apparent.

For example, a blank past customer testimonial template is not CUI.

This stuff has downstream impacts which cannot be overstated. Hopefully the phase 2 pause is giving the government the opportunity to take a look at that.


r/CMMC 8d ago

Is it safe to outsource CAD work internationally for ITAR-controlled projects?

1 Upvotes

Looking for ways to set this up.

We've got drawing and modeling work that needs to go to an outside CAD shop. The technical data package is marked CUI. Some of it is probably export-controlled too.

So for anyone who has placed this kind of work:

  • Did you require the vendor to be assessed?
  • Or did you set up a walled-off space and have them work inside it? 

And how did you keep the export-control question separate from the CMMC one? They have different tests. So I'm not sure how you handle both at the same time. 


r/CMMC 11d ago

Is using partial information from a CUI document mean every document from that point is CUI?

8 Upvotes

I’m trying to find more information on whether CUI documents which are partitioned into further documents are still CUI. Is this a CO question or is there any generic guidance on this? Any authoritative sources or documented suggested to find answer would be appreciated.


r/CMMC 12d ago

CMMC L2 for Small Company with Google Suites

8 Upvotes

Anyone have experience with meeting CMMC L2 requirements without leaving Google “Office”? I have a very small contracting firm I’m working with who is using Google Suites. Just trying to find an approach that makes sense for their contract size and the CUI requirements.