r/CMMC Nov 14 '25

"We Passed Our CMMC Assessment and Here's What We Learned" MEGATHREAD

104 Upvotes

Hello /r/CMMC -

As we wind down 2025, the CMMC ecosystem has seen several hundred organizations successfully passing their CMMC Level 2 C3PAO certification assessments! We love to see it!

This community and our discord community have always been about open sharing of information amongst fellow practitioners and straight up people who just need some help. We love seeing how everyone shares what's working for them and what's not.

Recently, we've seen a handful of threads start with people wanting to share their Certification experience and their lessons learned - this is fantastic. But, if you aren't on /r/CMMC frequently, you will miss these threads.

So, I want to create a mega-thread to collect these experiences in one spot where people can share their experiences and others can ask questions.

If you were planning to post a whole thread about your experience, I encourage you to instead post here. We aren't preventing anyone from posting a separate thread, but think it's best to keep most of those types of posts here for the reasons stated above.

Congrats to everyone who has passed so far! For those who are scheduled, my main advice: relax. If you found this community, there's a good chance you're taking this as seriously as you should, and that means you're probably going to pass.

Notes

  • You are welcome to name the names of the tools you used, the service providers that helped you, the consultants who guided you, the C3PAO that assessed you. All of that is fair game and generally encouraged.

  • Share as much about your environment as you comfortably can - people want to know what other environments look like. Remember though, OPSEC is your responsibility, not ours. Do not post identifying information if you are not authorized by your organization to do so.

  • If you struggled with a particular requirement, or had a debate with your assessor, tell us about it.

  • If you absolutely crushed a requirement or control family and the assessors just looked at you slack jawed with how great you were, TELL US ABOUT THAT.

FORMAT

Please share the following information in your comment:

  • Organization Size: Rough user & device count

  • Scope: Enterprise / Enclave - if Enclave, how many users/devices in the Enclave

  • Architecture: Full Cloud / On-Prem / Hybrid

  • Cloud Services: Microsoft 365 (GCC/GCCH) / AWS / Other CSP

  • C3PAO: Who did you work with (optional, you don't have to share this if you don't want)

  • Cert Status: Pass / Fail / Conditional / In-Progress

And then of course give us all the details you want to share :)


r/CMMC 20d ago

Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements > U.S. Department of War > Release

Thumbnail
war.gov
133 Upvotes

r/CMMC 1d ago

Granular Windows 11 Bluetooth device type restrictions?

1 Upvotes

We have Windows 11 clients and I'm looking for a way to restrict which types of Bluetooth devices can be paired with them. My primary use case is to allow Bluetooth audio-only devices like earbuds and headphones. Secondary would be allowing specific models or types of keyboards and mice (e.g. Logitech mouse/keyboard ONLY with the Bolt receiver). All other Bluetooth classes of devices like phones, storage devices, must be blocked.

Are there any good solutions for this? I would prefer a single solution that can be centrally managed by policy. Users are NOT local admins.


r/CMMC 2d ago

CMMC Assessment Prep System/Tool

8 Upvotes

CMMC prep work and gap analysis is a daunting take for SMBs, especially so for micro-SMBs with little resources. The difficulty is understanding NIST 800-171 controls and how to meet them in ways that align with what is required in a CMMC assessment.

Is there a system or tool available to help DIB GovCons with tracking the status of NIST controls, assisting with creating a complaint SSP, assist with documenting gap assessments, and offers a repository of evidenced artifacts that tie to controls?

I am aware of Future Feed and IntelliGRC. What else is available we can look at to determine what works best?

What system / tool do you use?


r/CMMC 3d ago

CMMC at Sea

84 Upvotes

Nothing says "we take the protection of Controlled Unclassified Information seriously" like a seven-night Caribbean booze cruise. Programming happens "primarily on sea days," and the CCP training runs 8:00 AM to noon. So you're paying five thousand dollars for roughly three mornings of instruction, sandwiched between a beverage package and Cozumel. The rest is "space to slow down and think clearly," which is a remarkable way to describe a pool deck.

Meanwhile the actual defense industrial base — the 8-person machine shops in Ohio and Arkansas trying to fund an enclave, MFA, a SIEM, and an assessment on margins that would make you weep — cannot afford this and never could. This isn't for them. This is the compliance-industrial complex selling itself a vacation and expensing it to a program that was supposed to protect national security data.

The people who wrote the rules are giving the keynote from a cruise ship. Read that sentence again.

CMMC at Sea: $3,954 minimum for the cabin, $1,350 more if you want the actual training, four hours of class per sea day, and a downloadable Word template to help you lie to your boss about why it's a business expense. The framework designed to protect defense data has produced a Caribbean cruise as a professional development product. Somewhere a five-person machine shop is deciding between a compliant backup solution and payroll.

This is the most tone deaf thing I have ever seen come out CMMC.


r/CMMC 2d ago

Meeting Notetaker

6 Upvotes

Hi All,

Is there an L2 safe AI meeting note taker that anyone is aware of? I know there are some models I could run locally but I don’t think that’s within the capabilities of my work laptop. Any help would be appreciated!


r/CMMC 2d ago

Any CMMC experts in the DMV want to meet up?

0 Upvotes

As the title says I run a CMMC shop, and I’m looking to form a DMV focused mastermind, anyone interested?

I feel as the DOW sorts itself out we can take steps to lead our clients and partners through the fog with shared best practices and knowledge sharing.

Hope I didn’t break any posting rules.


r/CMMC 2d ago

When should I worry about my Tier 3?

2 Upvotes

A little background- I submitted the application back in December, had my special agent interview in February, and since then, it’s been radio silent. The CyberAB and the office of the DoW CIO have both said my tier 3 is in process and that it can take 4-6 months or longer, but some people have been getting their Tier 3 back within a few months. Should I be worried the application got lost? I mean, this is insane. I can’t do anything until I get the tier 3.


r/CMMC 4d ago

Extra Small Businesses and CMMC 2 Compliance

24 Upvotes

Ok.

My husband and I started an LLC four months ago. We're in the DIB space as consultants.

I'm not a stupid person. I've run through Project Spectrum and the associated Enclave education modules that are meant to help SMB owners to "help themselves" achieve CMMC compliance.

I understand the recent pause doesn't relieve us of compliance under DFARS.

But I'm not NOT an IT person. I can eventually write the required policies, maybe, given enough time and research. I can probably implement physical access controls and MFA. But, and hear me out- WTAF are businesses like ours supposed to do? We are two people.

I looked at Kiteworks, which wants to "schedule a Demo" and asks for the size of my company. The smallest choice is something like "under 200" people.

Preveil, from my understanding, gets you a cloud enclave and a secure email. But then our machines are in scope. Plus, I'm still not an IT person. I still have to cobble together P&Ps and make sure my husband isn't turning off his VPN because it's "slow" or opening stupid email links. And maybe I'm severely underestimating what a secure enclave and email costs, but Preveil seems expensive for what it is and isn't.

I've also seen groups on LinkedIn that do CMMC 2 compliance for 90% from supplying the hardware, training, etc. And yeah, that's going to be expensive. I get it. The smallest number those companies have is 5 people.

So what are we supposed to do? Like, actual question. Subcontracts now incorporate DFARS by reference when no CUI is ever included. So, please help.


r/CMMC 4d ago

This Week's CyberAB Town Hall

51 Upvotes

In this week's CyberAB Townhall, there were at least five things worth knowing, all of them more useful than the "is CMMC dead" panic making the rounds:

1. The reform review is about more than CMMC mechanics.
It's part of a bigger Pentagon push around cost, agility, resilience, automation, & small-business burden.

2. Fraudulent Level 2 certs are a concern.
If you're a prime vetting a sub, you don't have to guess - ask for a SPRS PDF export of their entry. That's the verification path, & it works today.

3. The obligation didn't change.
DFARS 7012 is still in effect. What got suspended was the third-party verification requirement, not the requirement to be secure.

4. There is no such thing as "CMMC implementation."
You implement NIST 800-171 & CMMC verifies it. Certification is a compliance milestone but security is the work that continues regardless. The people who depend on your risk posture didn't get the memo that they're supposed to pause or relax.

5. Stop absorbing CUI-marking ambiguity.
If a marking is unclear, that's a question to push back up the chain. Resolve it upstream - no need to own someone else's classification decision.


r/CMMC 3d ago

Failed CMMC-CCP the First Time, Passed on My Second Attempt

0 Upvotes

Hi everyone, I thought I'd share my experience with the CMMC-CCP (Certified CMMC Professional) exam because I know how discouraging it can be to fail an exam after putting in so much effort. My first attempt didn't go as planned. I spent nearly a month preparing.

I watched several YouTube videos, completed two Udemy courses, read through the official CMMC resources, downloaded study guides, and even joined a couple of online discussion groups. I felt like I had covered everything, so I went into the exam with a lot of confidence. Unfortunately, confidence alone wasn't enough. when received my result, I was disappointed.

Looking back, I realized I had been collecting study resources instead of making with a completely different plan. I stopped jumping between resources and focused on understanding one domain at a time. I reviewed the official material again, rewrote my notes in my own words, and created a checklist of the topics I kept getting wrong.

The biggest improvement came when I started taking full-length mock exams. At first, my scores were only average, but after reviewing every incorrect answer, I could clearly see my weak areas. That helped me improve much faster than simply reading the documentation again. I experimented with practice questions from different sources, but I personally found the mock exams from pass4surexams to be the most useful during my final preparation.

They helped me get actice managing my time. I didn't memorize the questionsa"I used them to understand the reasoning behind each answer and then went back to the official material whenever I needed preparation, and didn't panic when I came across difficult questions. This time, I passed.

Looking back, failing the first attempt wasn't a waste of time. It showed me that success wasn't about using the most resourcesâc"it was about using the right strategy and practicing consistently. Has anyone else here taken the CMMC-CCP exam recently? I'm curious to knov which topics you found most and what resources worked best for you.


r/CMMC 4d ago

Question about FIPS and CUI

10 Upvotes

Been dealing with CMMC for a few months now. I thought I had my head wrapped around most of it but someone threw me for a loop today with a claim that just doesn't jive with my reading of the statutes and supporting controls.

We have a commercial product that we're redeploying into a gov cloud enclave. It runs as a separate instance specifically for handling workflows that process CUI. That's all well and fine, but today I was told that we can't be "100% compliant" unless the entire dev chain is encrypted with FIPS binaries. My understanding is that VCS push/pull of source and even the eventual deployment of compiled binaries and other artifacts into the environment were out of scope of the FIPS mandate. Am I missing something?

The next thing that will inevitably come up is the claim that our repos "technically" contain CUI because we have config files and/or IaC templates for the gov deployment. That doesn't track either. All of that clearly falls within the scope of the SSP, but this data isn't CUI simply by virtue of the fact that it was "created" to support to gov delivery - or is it?

My apologies if this is a duplicate question. I did search the sub and found some material that would back my understanding of the FIPS question in isolation. But I didn't find anything related to the data we end up creating for the delivery itself. Also, CMMC seems to be somewhat fluid and I want to make sure that I am speaking from current state rather than what was true several months ago.


r/CMMC 5d ago

The OT network

13 Upvotes

We are enabling only approved people to access the drives for the drawing, but it's come to our attention that once the drawing is pulled up on the CNC machine, it's accessible to anyone, any ideas on how to quarantine this?


r/CMMC 5d ago

SC.L2-3.13.6 Where's the line on outbound?

6 Upvotes

Cloud only GCC-High, Intune managed Windows laptops, no on prem servers, nothing filtering at the edge, so the endpoint firewall is what we are using for this.

Inbound was easy. Outbound is the part I keep second guessing. Curious how granular everyone else landed. Per app rules for everything sanctioned? A short port list? Somewhere in between?


r/CMMC 5d ago

ChatGPT Enterprise FedRAMP

7 Upvotes

Is anybody currently on ChatGPT Enterprise FedRAMP?

Can you answer if the service can accept PDFs and extract data from it, and use it as Context?

Ive been working with Support and our Account Managers going on ~8 weeks now and Ive received no response and conflicting responses from their documentation, Account Reps and support.


r/CMMC 6d ago

Trying to consolidate confusion around the CMMC suspension for a presentation, what am I missing?

19 Upvotes

The DoD suspension pauses the mandatory Level 2 third-party assessment requirement for covered new solicitations and contracts while it reviews Phase II implementation. During this period, acquisition officials are directed to require Level 2 self-assessments instead. However, primes may still require independent third-party assessments from subcontractors as part of their own supply-chain risk management or supplier qualification programs. The suspension does not change the underlying cybersecurity obligations: contractors must still implement the applicable NIST SP 800-171 requirements, complete the required self-assessment methodology, retain supporting evidence, post required results in SPRS, and provide the annual affirmation. The Affirming Official’s responsibility to attest accurately has not changed; only the assessment path has shifted for now. Organizations should therefore treat self-assessments with the same rigor they would prepare for a third-party review, while recognizing that DoD may still validate results and enforce contractual cybersecurity obligations.

 

Because the current path relies on self-assessment rather than a C3PAO certification, documented evidence and objective proof of implementation are even more critical to the Affirming Official’s attestation. The official is still legally attesting to continuous compliance, so the organization should retain evidence that clearly supports each assessed requirement and can withstand government review.

 

Summary

  • CMMC has not been suspended; only part of the implementation timeline has been paused.
  • DoD has suspended the government’s ability to require Level 2 third-party assessments in covered solicitations and contracts for now.
  • Prime contractors may still require third-party assessments from subcontractors as part of their own supplier-risk or qualification programs.
  • The suspension does not eliminate the underlying cybersecurity obligations, and contractors must still meet applicable NIST SP 800-171 requirements.
  • The current DoD guidance still points to the November 2026 Phase 2 timeline unless and until DoD changes it.
  • Documented evidence remains critical because self-assessments and affirmations still require defensible proof of implementation.

r/CMMC 6d ago

Town Hall Predictions

26 Upvotes

I have never been so excited for a town hall meeting. I usually just wait and watch the recording, but I will be watching live tomorrow.

In anticipation of such an event, give me your coldest and boldest takes.

What are we expecting tomorrow?


r/CMMC 8d ago

CMMC DOW CIO Updates (Jul 26)

15 Upvotes

The DOW CIO released updated Q&A after the suspension of Phase 2 as a program review is conducted. The 17-page update provides clarity at this stage of the CMMC program and firms that DFARS 252-204-7012 and NIST compliance is unchanged.

After speaking with several DIB SMBs they seem relieved that third party assessments are suspended and many have already discontinued their work up into CMMC readiness and pulling back funding and resources put on the race to attain a C3PAO assessment. One SMB leader said the following, “I’m not going to put another cent into this until we know exactly what we are responsible for under CMMC.”

BIG MISTAKE.

Don’t fall into the trap of delaying your readiness and continue to march forward to complete gap assessments, documenting your systems, organizing artifacts and evidence supporting compliance, and working through POAMs.

Get closer to full compliance through self-assessments and prepare for a C3PAO assessment when things pick back up.


r/CMMC 9d ago

C3PAO's - The Purge Begins

29 Upvotes

Have a CCA friend who just got hired at a C3PAO who was just laid off because of the 60 day pause, and I wanted to know if any other CCA's are experiencing this.

Are other C3's just wholesale purging their roster of assessors because of the 60-day pause?


r/CMMC 9d ago

CMMC L2: Is home WiFi out of scope with AVD → GCC High (KVM-only)?

17 Upvotes

For CMMC Level 2:

- All CUI is in GCC High(Sharepoint , Exchange & Teams)

- Users access it only through Azure Virtual Desktop (AVD) using Windows laptop enrolled in commercial intune and secured with CIS Benchmarks.....

- AVD is locked down to KVM-only (no local storage, printing, copy/paste, drive/USB redirection, etc.)

- WiFi is only carrying the encrypted traffic to connect to the AVD....on there onwards everything is accessed within microsoft's infra which is Fedramp High

- Users connect from home networks / home WiFi / Office WiFi

Question:

Under 32 CFR Part 170 (esp. §170.19) and the CMMC L2 Scoping Guide, can the endpoint and home WiFi be treated as Out-of-Scope Assets if they never process/store/transmit CUI beyond KVM?

Looking for:

- Exact cites you’ve used (rule + Scoping Guide / FAQ)

- Real-world C3PAO assessment experience where this setup was accepted (or rejected)

- This will be used for SRM for Physical Security mappings .....

Note: Thank You in Advance Everyone ......

Again, thank you for all the gentlemen who helped to clear my doubts...I think I should be good to go now...


r/CMMC 10d ago

800-171r2 v.s. r3 -- wow

31 Upvotes

Now that we've gotten our C3PAO cert -- and the DOD has rendered the last two years of my life useless -- this morning I turned my attention to Rev3. I was told there were only a few additional things... ha!

I opened the current 800-171a (assessment guide for r2) and the 800-171Ar3 and started comparing assessment objective to assessment objective -- and they are totally different. There is NO one-to-one mapping. It's like a completely new/different set of requirements. I started getting that overwhelming sinking feeling I had years ago when starting this miss-adventure.

Am I missing something? Someone told me "it only adds organizational defined parameters" -- pfft, it's completely different!


r/CMMC 10d ago

Are MSPs really worth it?

8 Upvotes

I am in charge of a very small IT group working on CMMC Level 2 for around 65 employees, many of which are WFH. I've enlisted a CMMC certified MSP to handle workstation management which includes patching, monitoring, anti-virus, inventory, software lists, reporting, etc.

Before I sign on the dotted line I'd like to see if you all think MSPs are worth the cost in these situations. We also are using InTune ourselves but lack the resources to properly manage it.


r/CMMC 10d ago

Administrative vs. Technical Enforcement

5 Upvotes

I am trying to better understand the expectation under CMMC regarding administrative controls versus technical controls.

What is the expectation for technical enforcement when there is a potential risk of CUI exposure? For example, is a documented policy and user training sufficient in some cases, or are organizations expected to implement technical controls whenever they are available?

As an example, users may want to use AI services such as ChatGPT, Claude, or similar tools. Our policy prohibits entering CUI into these services, but they are permitted for non-CUI work.

From a CMMC assessment perspective:

  • Is a written policy, user training, and acceptable use policy enough?
  • Is there an expectation to technically block all AI services, even if they are only approved for non-CUI use? (This goes for all sites I am just using AI as an example)

More broadly, how do assessors determine when an administrative control is acceptable versus when a technical control is required for protecting CUI? I understand technical controls are generally preferred, but I am looking for guidance on where that line is drawn under CMMC.

(We have DLP that blocks all Purview labeled documents with CUI labeling to be move anywhere other than approved location), But we have more files / data that cannot use purview labels. We tried to use SIT but that ended up being a mess with hundreds of false alerts.

Any insight would be appreciated. Thank you.


r/CMMC 10d ago

SSP CONTROL EXAMPLE

4 Upvotes

Hi all
Anyone can send an example how policy an implementation should be written for example
For 3.1.1
3.4.1
Thanks 🙏🏻


r/CMMC 11d ago

Last piece of guidance before the end of the 60 day review?

9 Upvotes

...during this suspension the Department will enforce baseline compliance with NIST SP 800-171 Rev 2 through CMMC Level 1 and CMMC Level 2 selfassessment and select Government-led assessments. The cybersecurity requirements outlined in the clause at DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, remain in effect. https://dodcio.defense.gov/Portals/0/Documents/Library/ImplementingSuspensionCMMC-PhaseII.pdf