Related RRCoP Content:
UCF's Approach to CMMC Level 1: with the processes & tools that also support CMMC Level 2
Presented By: Tammie McClellan, University of Central Florida
CMMC Level 1 may only require a subset of the controls found in Level 2, but institutions still face important decisions about processes, documentation, governance, and technical implementation. In this session, the University of Central Florida shares how it approached CMMC Level 1 as a campus capability rather than a one-time compliance exercise, intentionally selecting processes and tools that also support future CMMC Level 2 requirements. Whether your institution is preparing for its first Level 1 assessment or thinking longer-term, this session offers practical ideas for building once and maturing over time.
Poll Question: How is your institution approaching CMMC Level 1 / Federal Contract Information (FCI) [see community results]
Lessons Learned - NC State’s Journey to CMMC Level 2 Compliance
Presented by: Adria Snead, Cybersecurity Research Analyst, Doug Lewis, Cybersecurity Risk and Compliance Specialist, and Damon Armour, Director of Information Security, Risk & Assurance
Alright, buckle up for the CMMC Level 2 assessment rollercoaster! NC State University jumped into the deep end to conquer the giant known as CUI certification. Come join us as NC State discusses our journey through the belly of the beast. We learned it’s NOT just 110 controls, N/A is a rarity, and some things are not POA&M eligible. It’s all about the objectives. This rigorous assessment with our C3PAO was a high stakes test of our policies, implementation and documentation. NC State forged a path forward so you can navigate it with confidence. You’ve got this!
Poll Question: Have you started planning a CMMC Level 2 assessment? [see community results]
[Presentation | Q&A + Office Hours Transcript | Recording]
Related RRCoP Content:
Presented By: Winston Armstrong and Sandeep Chandra, University of California, San Diego
UC San Diego collaborated with the CyberAB in August 2023 to complete a CMMC L2 learning assessment. In this session, the team reflects on that experience from the other side of certification, sharing what proved valuable, what surprised them during the official assessment, and how they are thinking about sustaining the program moving forward.
Poll Question: Have you started planning a CMMC Level 2 assessment? [see community results]
Debrief of first ever - CMMC Learning Assessment
Presented By:
Winston Armstrong, San Diego Supercomputing Center
Kira Dunn, UC San Diego
Carolyn Ellis, UC San Diego
Lillian Maestas, UC San Diego
Mike Snyder, Cyber-AB
UC San Diego will present on their Learning Assessment handled with the lead assessor also being Cyber-AB's curriculum manager. The primary goal here was to address how Research Institutions are different from the standard assessment. [Q&A | Presentation | Meeting Recording ]
C3PAO Perspective on Sponsorship and Governance
Facilitated by: Barb Schnell, University of Colorado, Boulder, Associate Director Secure Research Computing
Panel:
Thomas Graham, Ph.D., VP and CISO at Redspin, a division of Clearwater, CCA, CCI
Fernando Machado, CISO Cybersec Investments, CCA, CCP
Mike Snyder, Director of Training and Credentialing, The Cyber AB, CISM, CCA, CPI
Mathew Titcombe, CEO and founder at Peak InfoSec, CCA
Effective sponsorship and governance for compliance-related policies, Organizational Defined Parameters (ODPs) and organizational roles and responsibilities can be challenging in a highly distributed and consensus-oriented culture such as that found in higher education institutions. Yet it is a requirement for a solid research cybersecurity program and an enabling factor for certifications.
This panel discussion engages this topic from the perspective of CMMC 3rd Party Assessment Organizations (C3PAO’s) in terms of what an auditor may consider in their assessment and the impact of an organization’s governance and related processes on achieving certification.
U Colorado, Boulder - CMMC Gap Analysis Lessons Learned
Presented By: Barbara Schnell & Silas Korb, University of Colorado, Boulder
University of Colorado, Boulder, will share the lessons learned from their recent C3PAO gap assessment of their enclave.
Poll Questions:
How would you describe the effectiveness of your institution’s governance and sponsorship model for regulated research? [see community results]
Describe your relationship with your institution’s governance model? [see community results]
[Q&A | Presentation | Meeting Recording]
May '25 - CMMC & Higher Education with Wendy Epley (podcast)
February '24 CMMC and R1 Research Universities with Laura Raderman by Aspire Cyber (podcast)
October '24 Regulated Research Security and Compliance Planning for CMMC/CUI with Don DuRousseau (Video)
July '25 - NIST SP 800-171 – Guidance for Research Computing and Data Centers [download]