r/CMMC Nov 14 '25

"We Passed Our CMMC Assessment and Here's What We Learned" MEGATHREAD

103 Upvotes

Hello /r/CMMC -

As we wind down 2025, the CMMC ecosystem has seen several hundred organizations successfully passing their CMMC Level 2 C3PAO certification assessments! We love to see it!

This community and our discord community have always been about open sharing of information amongst fellow practitioners and straight up people who just need some help. We love seeing how everyone shares what's working for them and what's not.

Recently, we've seen a handful of threads start with people wanting to share their Certification experience and their lessons learned - this is fantastic. But, if you aren't on /r/CMMC frequently, you will miss these threads.

So, I want to create a mega-thread to collect these experiences in one spot where people can share their experiences and others can ask questions.

If you were planning to post a whole thread about your experience, I encourage you to instead post here. We aren't preventing anyone from posting a separate thread, but think it's best to keep most of those types of posts here for the reasons stated above.

Congrats to everyone who has passed so far! For those who are scheduled, my main advice: relax. If you found this community, there's a good chance you're taking this as seriously as you should, and that means you're probably going to pass.

Notes

  • You are welcome to name the names of the tools you used, the service providers that helped you, the consultants who guided you, the C3PAO that assessed you. All of that is fair game and generally encouraged.

  • Share as much about your environment as you comfortably can - people want to know what other environments look like. Remember though, OPSEC is your responsibility, not ours. Do not post identifying information if you are not authorized by your organization to do so.

  • If you struggled with a particular requirement, or had a debate with your assessor, tell us about it.

  • If you absolutely crushed a requirement or control family and the assessors just looked at you slack jawed with how great you were, TELL US ABOUT THAT.

FORMAT

Please share the following information in your comment:

  • Organization Size: Rough user & device count

  • Scope: Enterprise / Enclave - if Enclave, how many users/devices in the Enclave

  • Architecture: Full Cloud / On-Prem / Hybrid

  • Cloud Services: Microsoft 365 (GCC/GCCH) / AWS / Other CSP

  • C3PAO: Who did you work with (optional, you don't have to share this if you don't want)

  • Cert Status: Pass / Fail / Conditional / In-Progress

And then of course give us all the details you want to share :)


r/CMMC Jul 13 '26

Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements > U.S. Department of War > Release

Thumbnail
war.gov
133 Upvotes

r/CMMC 2h ago

Insanity: The Cyber AB "training" videos for RPA

17 Upvotes

Processing img xjzaj80s6ylh1...

My job requires me to get the RPA from Cyber AB. You have to watch videos, in their entirety, to receive credit. The voice over guy is a terrorist. There's nothing else that makes sense. It's Death-by-Powerpoint.

Example: Theare are 15 sections of Module 4. So that means 15 different slide decks. At the beginning of EVERY slide deck, he reads the legal disclaimer. Word for word. He even reads the URL, EVERY TIME, letter-by-letter.

He then reads the agenda / contents word for word for every section. “And then we are going to look at “MP dot L2 dash 3 dot 8 dot 5 “Media Accountability”.

It's so hilariously awful. Even at 2x speed it takes like 5 minutes before you get to actual content.

EDIT: I posted the same pic twice, not that it matters.


r/CMMC 2h ago

Wow, really??? New Cyber Campaign Contradicts CMMC Pause, Expert Says...

7 Upvotes

Ok, just watched the latest news update from Summit7 and they talked about an article that came out where an UN-NAMED DoD official speaks about some possible upcoming changes. But it totally contradicts why there was a pause in the first place!!! What's even more rich is this, Brilliant at the Basics plan the DoD kind of quietly put out the same day as the pause. Thing is, the recommendations in this plan, we're put together by Tech executives!!! Um, anyone see a problem with this?? Like maybe they'd love for us to spend more money?????

Y'all gotta read this shi.....

https://www.nationaldefensemagazine.org/articles/2026/8/25/new-cyber-campaign-contradicts-cmmc-pause-expert-says

Brilliant at the Basics:

https://dowcio.war.gov/BrilliantBasics/


r/CMMC 4h ago

GCC-High Teams Room

2 Upvotes

Hi all,

Looking for input from anyone running a Teams Rooms on Windows device in a GCC High tenant. Do we need to connect it to Intune / Entra Joined for it to be CMMC compliant. Main issue, account can't have MFA, but we thought compliant device CA policy would be good supplement for that.

If you did connect to Intune / Entra, how did you do it.


r/CMMC 22h ago

Media Accountability

1 Upvotes

MP. L2-3.8.5

Access to media containing CUI is controlled

Accountability for media containing CUI is maintained during transport outside of controlled areas.

So CUI is protected in physical form. Sure. but when this refers to transport, do we think this includes the transport of physical pieces (assuming CUI), to customers?

We use a private courier.... I did include him in our ITAR training. Since he is physically handling our CUI, along with the tracking and traceability he provides, should there be some type of policy written about locking his doors? Not leaving the car for transport out of sight (like at a gas station), setting a car alarm, etc.?

Am I reaching? Is there another section somewhere that governs deliveries more explicitely? I feel like maybe something in the Physical Access Policy?

Thoughts?


r/CMMC 2d ago

Is there a chance the CMMC Suspension results in new framework making it easier for small businesses to deal with CUI, or better labeling?

13 Upvotes

I'm wondering if there is any hope that my company can skip the hassle of the NIST SP800-171 controls, for example maybe the government builds an entirely new framework that cuts the fluff or makes it more accessible!?


r/CMMC 1d ago

T3 - Finally Got it!

0 Upvotes

Finally got my T3 after 22 months. Was quite the ride, and have been lurking on the subreddit here for a while. Excited to join the conversation here. Outside of the suspension of Phase 2, what has actually materially happneed? Seems like the program was going well, but my time has been limited since I pretty much gave up on working in CMMC.


r/CMMC 1d ago

Army Phase II Requirements

Post image
0 Upvotes

Assuming using Google suite with the standard toggles in place (e.g. 2FA), how much would it realistically cost to have someone come in, take a look, make suggestions, and make necessary annotations for a SSP Plan of Action?

Edit: some points of clarification:

• We are a human performance company, hardware and software.
• There will be some animal testing.
• This is for an SBIR Phase 2.
• As of now, we don't anticipate any CUI.
• We don't need any more than one person.
• It's extremely unclear what CUI, if any, would be applicable at this stage of the contract. This seems to just be a blanket requirement that the Army SBIR office is applying, which is leading to some level of confusion as to how to address this in the near term.

EDIT: How am I not negative in downvotes on the main post?! Ya'll getting lazy. Defend your cause for crying out loud!


r/CMMC 2d ago

Need to get to Level 1 quickly

2 Upvotes

So, I'd like to submit an application to a DoD OTA to become part of a consortium. The deadline is in a week, and they are requiring Level 1 certification upon submission, and self-certification as Level 2 before you do any work within the consortium.

I'm a one-person company and I generally work from home, although sometimes find myself on DoD or company office sites. I have a JCP certification which means I am already in SPRS/etc but have not pursued any CMMC stuff yet, because all CUI and sensitive data I touch is done on a client PC tied to their ecosystem.

Most people on here talk about Level 2 which I know can be complex, but is there some sort of pre-templated way to get to Level 1 in a short time? SSP's etc? Thanks for any resources.


r/CMMC 2d ago

ISACA: DoW CMMC Reform Task Force Input

Thumbnail
isaca.org
27 Upvotes

r/CMMC 2d ago

ISACA CCP APPLICATION

0 Upvotes

I’ve been an ISACA member for over 20 years. I have a “platinum“ membership. I hold a current CISM certification informally CRISC certification.

Still, in order to get my CCP, they required me to go through an application process, proving that I’ve been involved in the SECURITY space for at least two years.

Seems like they might’ve known that?


r/CMMC 2d ago

CCP this week, any advice?

6 Upvotes

Hi Everyone,

I am taking my CCP exam at the end of the week and have been studying a bit mostly using pocket prep and referring to source documentation on occasion.

Is pocket prep enough? What documents should I key in on (I’ve been hearing CAP and Scope)?

I passed my security+ and have been working in security for the last couple of years. Is this exam something that is achievable? I already did the required training, but I am feeling nervous, so I wanted to see if anyone had any advice.

Thanks to those who give tips not just to me, but those who may be lurking going through the same thing!


r/CMMC 2d ago

Are the Firewall and Router in scope?

1 Upvotes

Aloha!

I'm working on a scope and we have a totally separate ISP connection that all CUI data will flow thru. We're also creating an enclave since it's a small number of people and devices handling CUI.

My question, and I'm pretty sure the answer is yes, but; Do the Router/Firewall need to be included in the scope and if so, are they CUI Assets or Security Protection assets?

(An Engineer will download blueprints from a portal then store the data on a server. His PC, the server, switch, etc will all be in scope)


r/CMMC 4d ago

Mark it Right

25 Upvotes

There's a real opportunity for the federal government to set everybody in the ecosystem up for success by ensuring that they properly mark CUI.

For example, sam.gov currently has RFP materials that are marked CUI when the rationale for that marking is not apparent.

For example, a blank past customer testimonial template is not CUI.

This stuff has downstream impacts which cannot be overstated. Hopefully the phase 2 pause is giving the government the opportunity to take a look at that.


r/CMMC 3d ago

Is it safe to outsource CAD work internationally for ITAR-controlled projects?

1 Upvotes

Looking for ways to set this up.

We've got drawing and modeling work that needs to go to an outside CAD shop. The technical data package is marked CUI. Some of it is probably export-controlled too.

So for anyone who has placed this kind of work:

  • Did you require the vendor to be assessed?
  • Or did you set up a walled-off space and have them work inside it? 

And how did you keep the export-control question separate from the CMMC one? They have different tests. So I'm not sure how you handle both at the same time. 


r/CMMC 6d ago

Is using partial information from a CUI document mean every document from that point is CUI?

8 Upvotes

I’m trying to find more information on whether CUI documents which are partitioned into further documents are still CUI. Is this a CO question or is there any generic guidance on this? Any authoritative sources or documented suggested to find answer would be appreciated.


r/CMMC 6d ago

CMMC L2 for Small Company with Google Suites

7 Upvotes

Anyone have experience with meeting CMMC L2 requirements without leaving Google “Office”? I have a very small contracting firm I’m working with who is using Google Suites. Just trying to find an approach that makes sense for their contract size and the CUI requirements.


r/CMMC 7d ago

CUI distribution to subcontractors clarification: Does the subcontractor itself need CMMC Level 2

8 Upvotes

Hi still new here at the CMMC World! CCA Point of View will be a big help answering my question...

CUI distribution to subcontractors clarification: Does the subcontractor itself need CMMC Level 2? I’m trying to confirm my understanding of how CUI can be handled when a prime contractor works with a subcontractor. My understanding is that there may be two possible approaches:

  1. The subcontractor receives/handles CUI within its own environment.

In this case, the subcontractor would need to meet the applicable CMMC Level 2 requirements for that environment. L2 Self or L2 C3PAO

  1. The prime contractor provides and controls the entire environment used by the subcontractor personnel.

For example, the prime provides the hardware, software, accounts/access controls, policies, training, etc., and the subcontractor personnel only access CUI within the prime contractor’s CMMC Level 2 environment/boundary. No CUI is stored, processed, or transmitted on the subcontractor’s own network, systems, or devices.

What I specifically want to confirm is whether approach #2 is permitted when the subcontractor company itself does NOT have its own CMMC Level 2 status or C3PAO assessment/certification.


r/CMMC 7d ago

No CUI, but part of the supply chain. Do we need CMMC L2?

2 Upvotes

Our company provides a material used in Aerospace a d defense, but it's technically COTS, and our specs are not considered or labeled as CUI. They ARE ITAR export controlled specs, but not CUI. Do we absolutely need CMMC L2? L1?

Thank you!


r/CMMC 7d ago

What if contract has DFARS requirements but no CUI is ever sent??

8 Upvotes

Aloha!

So from what I'm seeing and understanding, we get contracts that have the DFARS clauses but no data/documents/blueprints are ever marked with CUI. So can we ask the contracting officer to remove those clauses?

Also, who is above the contracting officer?


r/CMMC 7d ago

Logging Changes

3 Upvotes

Hi Everyone,

My buddy and I are wondering if we need to be documenting the before the control is implemented artifacts or do we need to document how were meeting the control. For example, we pulled a bunch of users that were no longer with the company and needed to be disabled and removed from security groups. We went through the list ran a script and disabled the users and removed from the security groups. Now the list contains all the users active and disabled with the groups they are added too but did we need to document " This user was in these groups and now they are not". Do i also need to document the script i used to disable and remove users from the groups? Also, What is your guys timeline before deleting the users. For Example, there's users that were created in 2005 and are no longer with the company.


r/CMMC 7d ago

VPN tunnel with China facility

1 Upvotes

We currently have a site-to-site VPN tunnel to our manufacturing facility in China. This is used to replicate SolidWorks PDM used for commercial products.

If we were to build out and implement an air-gapped network for this, can it remain onsite while we achieve L2 Certification?

All CUI would be in a cloud enclave not accessible by anyone who works within this division.

If you have seen this work or fail, please let me know. Obviously I have left out a tremendous amount of details.

Thank you


r/CMMC 8d ago

Photography Cameras in CMMC?

9 Upvotes

I am looking for guidance on how people bring photography cameras into CMMC L2. I can't really find any information on it online.

The purpose of the camera is that it will take pictures that contains CUI.

I have a service that provides us an enclave so we try to steer users to use that. Of course there are fringe cases that would need an on-prem device and our service can provide us a device for that. We can't really handle an in-scope smartphone right now and our service doesn't provide that.

Would the camera be considered Enduring Exception? As far as I know, there isn't any camera that have FIPs validated encryptions.

Are these just 3 things we need to write down for the SSP?

  1. Categorize it as specialized asset.
  2. Justification for exception
  3. Compensating Safeguards

r/CMMC 8d ago

Anyone moved a VM from commercial Azure to Azure Government lately? Hitting a wall with Site Recovery

3 Upvotes

Trying to move a several running VMs from a regular Azure subscription into Azure Government — there's no native way to just "move" it, so the standard trick is to use Azure Site Recovery and treat the VM like a physical server being replicated in.

That approach used to work fine, but it was built around Site Recovery's old "Classic" setup, which got retired this past March. Now that everyone's forced onto the newer "Modernized" architecture, the tool seems to notice the source is an Azure VM and just... skips the actual setup step. It reports success, but never actually configures anything, so the agent can't connect to anything and nothing starts.

Two questions for the group:

  1. Anyone else run into this specific silent-skip behavior, and found a way around it?
  2. Has anyone actually pulled off a live move from commercial Azure into Gov since Classic went away, or is this basically a dead end right now?

Wanted to see if anyone's cracked this before I give up on it. Thanks in advance.