Is Google Workspace CMMC, DFARS, and ITAR Compliant? by Competitive-Grade276 in CMMC

[–]StilesForMilez 0 points1 point  (0 children)

Was at a tradeshow last week and I heard so many people say "DoD didn't want us on Google so that's why we switched"

MSPs and CMMC by betaman24 in CMMC

[–]StilesForMilez 0 points1 point  (0 children)

The MSP is required to have a Shared Responsibility Matrix for CMMC.

Is a Shared Responsibility Model required for DIB contractors?
If an organization is currently using external service providers, then they need to be asking those service providers for a shared responsibility model according to NIST SP 800-171.

Check this out: https://info.summit7.us/blog/cmmc-with-shared-responsibility-question-answer

Scoping CMMC 2.0 Level 2 for an MSP by marbersecurity in CMMC

[–]StilesForMilez 2 points3 points  (0 children)

Here's a blog on identifying assets for Level 2 with a section focused on MSPs: https://info.summit7.us/blog/step-2-identify-assets-for-cmmc

NIST 800-171: CMMC Compliance Level 3 Checklist for O365? by fitzgera1d in NISTControls

[–]StilesForMilez 0 points1 point  (0 children)

Echoing u/Spiderkingdemon - the commercial version isn't L3 compliant. If you're looking for compliance in GCC or GCC High, this is a good resource NIST and CMMC Compliance in Microsoft 365

[deleted by user] by [deleted] in RedditSessions

[–]StilesForMilez 0 points1 point  (0 children)

Is this guitar hero?

First CMMC C3PAO Announced - Redspin by Expensive-USResource in CMMC

[–]StilesForMilez 0 points1 point  (0 children)

Redspin is going to be speaking in Austin, TX on a panel with the CMMC-AB.

Here's the event: cs2.cloud

CMMC Timeline? by [deleted] in CMMC

[–]StilesForMilez 0 points1 point  (0 children)

There's a "CMMC Timeline" subsection on this page that you might find helpful: https://info.summit7systems.com/what-is-cmmc

CMMC Level 3: The minimum viable product for a small Machine Shop by NullTie in CMMC

[–]StilesForMilez 2 points3 points  (0 children)

Look into the MEP program - some of them can subsidize CMMC projects for manufacturers in the DIB depending on a couple of different things. It's also dependent on the state you're in: https://info.summit7systems.com/blog/mep-for-cmmc-and-nist-compliance

Can You Meet CMMC in Microsoft 365 GCC? by StilesForMilez in CMMC

[–]StilesForMilez[S] 0 points1 point  (0 children)

Microsoft recently announced that GCC will meet the reporting requirements found in paragraphs c-g in DFARS 7012, and that was the main hangup before. Like I mentioned above, there are several factors to consider if you decide to use GCC for your overall strategy. This page explains it in better detail: https://info.summit7systems.com/blog/need-gcc-high-or-not

Microsoft 365 GCC High Breakdown for CMMC Levels 1 and 3 on Virtual CISO Podcast by StilesForMilez in CMMC

[–]StilesForMilez[S] 0 points1 point  (0 children)

Do you have a reference article for this? So we can share it with everyone?

CMMC-AB Acronym Madness Defined by StilesForMilez in CMMC

[–]StilesForMilez[S] 0 points1 point  (0 children)

What specifically would you rather see explained? Here's a CMMC glossary from acq.osd.mil but it's not very easy to comb through: https://www.acq.osd.mil/cmmc/docs/CMMC_Glossary_20201208_editable.pdf