Related RRCoP Content:
UCF's Approach to CMMC Level 1: with the processes & tools that also support CMMC Level 2
Presented By: Tammie McClellan, University of Central Florida
CMMC Level 1 may only require a subset of the controls found in Level 2, but institutions still face important decisions about processes, documentation, governance, and technical implementation. In this session, the University of Central Florida shares how it approached CMMC Level 1 as a campus capability rather than a one-time compliance exercise, intentionally selecting processes and tools that also support future CMMC Level 2 requirements. Whether your institution is preparing for its first Level 1 assessment or thinking longer-term, this session offers practical ideas for building once and maturing over time.
Poll Question: How is your institution approaching CMMC Level 1 / Federal Contract Information (FCI) [see community results]
Lessons Learned - NC State’s Journey to CMMC Level 2 Compliance
Presented by: Adria Snead, Cybersecurity Research Analyst, Doug Lewis, Cybersecurity Risk and Compliance Specialist, and Damon Armour, Director of Information Security, Risk & Assurance
Alright, buckle up for the CMMC Level 2 assessment rollercoaster! NC State University jumped into the deep end to conquer the giant known as CUI certification. Come join us as NC State discusses our journey through the belly of the beast. We learned it’s NOT just 110 controls, N/A is a rarity, and some things are not POA&M eligible. It’s all about the objectives. This rigorous assessment with our C3PAO was a high stakes test of our policies, implementation and documentation. NC State forged a path forward so you can navigate it with confidence. You’ve got this!
Poll Question: Have you started planning a CMMC Level 2 assessment? [see community results]
[Presentation | Q&A + Office Hours Transcript | Recording]
Related RRCoP Content:
Presented By: Winston Armstrong and Sandeep Chandra, University of California, San Diego
UC San Diego collaborated with the CyberAB in August 2023 to complete a CMMC L2 learning assessment. In this session, the team reflects on that experience from the other side of certification, sharing what proved valuable, what surprised them during the official assessment, and how they are thinking about sustaining the program moving forward.
Poll Question: Have you started planning a CMMC Level 2 assessment? [see community results]
Debrief of first ever - CMMC Learning Assessment
Presented By:
Winston Armstrong, San Diego Supercomputing Center
Kira Dunn, UC San Diego
Carolyn Ellis, UC San Diego
Lillian Maestas, UC San Diego
Mike Snyder, Cyber-AB
UC San Diego will present on their Learning Assessment handled with the lead assessor also being Cyber-AB's curriculum manager. The primary goal here was to address how Research Institutions are different from the standard assessment. [Q&A | Presentation | Meeting Recording ]
C3PAO Perspective on Sponsorship and Governance
Facilitated by: Barb Schnell, University of Colorado, Boulder, Associate Director Secure Research Computing
Panel:
Thomas Graham, Ph.D., VP and CISO at Redspin, a division of Clearwater, CCA, CCI
Fernando Machado, CISO Cybersec Investments, CCA, CCP
Mike Snyder, Director of Training and Credentialing, The Cyber AB, CISM, CCA, CPI
Mathew Titcombe, CEO and founder at Peak InfoSec, CCA
Effective sponsorship and governance for compliance-related policies, Organizational Defined Parameters (ODPs) and organizational roles and responsibilities can be challenging in a highly distributed and consensus-oriented culture such as that found in higher education institutions. Yet it is a requirement for a solid research cybersecurity program and an enabling factor for certifications.
This panel discussion engages this topic from the perspective of CMMC 3rd Party Assessment Organizations (C3PAO’s) in terms of what an auditor may consider in their assessment and the impact of an organization’s governance and related processes on achieving certification.
U Colorado, Boulder - CMMC Gap Analysis Lessons Learned
Presented By: Barbara Schnell & Silas Korb, University of Colorado, Boulder
University of Colorado, Boulder, will share the lessons learned from their recent C3PAO gap assessment of their enclave.
Poll Questions:
How would you describe the effectiveness of your institution’s governance and sponsorship model for regulated research? [see community results]
Describe your relationship with your institution’s governance model? [see community results]
[Q&A | Presentation | Meeting Recording]
In the realm of cybersecurity, the Cybersecurity Maturity Model Certification (CMMC) framework can be likened to an apartment complex, where each unit’s security is managed individually yet contributes to the overall safety and integrity of the entire structure. Each entity must customize its cybersecurity measures to its contract’s requirements, maintain ongoing vigilance through scoping, and ensure focused documentation and access control, all under the guidance of the overarching CMMC governance.
No One-Size-Fits-All: Just as every apartment reflects its inhabitants' different needs and preferences, the CMMC framework must be customized to fit the unique requirements of each contract.
Ongoing Scoping Process: Scoping is akin to the continuous maintenance and updates needed in an apartment building. It begins before the assessment (or ‘move-in’) and is a constant process to ensure security measures are up to date.
Building Blocks for Foundation: The CMMC program provides the foundational ‘building blocks’ much like the infrastructure of an apartment building. Each contract, or ‘apartment’, then builds upon this to create a secure environment tailored to its specific needs.
Controlled Access: The flow of people in and out of the apartment building represents data and network traffic. It’s essential to ensure that only authorized individuals (owners and their guests) have access to any given ‘apartment’ (contract).
Varied Sizes and Features: Apartments come in different sizes and with various features, paralleling the diverse nature of contracts within the CMMC framework. Each requires a different approach to security, reflecting its unique characteristics.
Focused Documentation: In the same way that residents wouldn’t provide a stranger a detailed tour of their home, it’s important to avoid volunteering unnecessary information to assessors. Stick to what is required by the controls and point to the exact sections of policy that apply.
Efficient Scoping/Documentation: Effective scoping and documentation are like having an organized apartment; the better they are, the more time you save, which translates to saving money.
May '25 - CMMC & Higher Education with Wendy Epley (podcast)
February '24 CMMC and R1 Research Universities with Laura Raderman by Aspire Cyber (podcast)
October '24 Regulated Research Security and Compliance Planning for CMMC/CUI with Don DuRousseau (Video)
July '25 - NIST SP 800-171 – Guidance for Research Computing and Data Centers [download]