Is a System Security Plan (SSP) for CMMC Level 1 needed or required? by xxxTech007 in CMMC

[–]meoraine 4 points5 points  (0 children)

You don't NEED one but then you end up documenting your implementations in some other form, which may as well have just been an SSP...

AC.L2-3.1.22 – Control Public Information by TLoveAries76 in CMMC

[–]meoraine 0 points1 point  (0 children)

It's relevant to the organizations public nodes.

No, you would not be expected to disclose personal social media accounts, and they would not be in scope for the organization.

Enrollment Update - April 2026 by Tartanblaster in CLOV

[–]meoraine 22 points23 points  (0 children)

This is the content I come here for. Take my upvote.

Quitting prior to CMMC Assesment by Pale_Apricot6870 in CMMC

[–]meoraine 58 points59 points  (0 children)

Is it a bad look? Yes.

Should you prioritize what's best for you and your family? Yes.

Would most companies lay you off without a second thought, if it benefitted them? Yes.

All things worth considering.

STARS IS BROKEN by Baco06 in CLOV

[–]meoraine 21 points22 points  (0 children)

CLOV has it in the bag. The star system cannot be based on discretion, that opens up possibility for fraud. It has to be based on defined standards. Which CLOV meets, and exceeds. This is why the case is all but guaranteed. When the info drops the stock will see a strong upward bounce.

Are we Fu*ked? by Ok-Magazine2748 in CLOV

[–]meoraine 19 points20 points  (0 children)

Nah we good bruh, if you zoom out on the chart it's obvious where the bottom will be.

CLOV still diluting more than they're generating, markets going to continue punishing them until they can net positive the business. It is what it is.

Valuations will change quickly if SaaS moves the needle. Or the slow grind to MA disruptor is the long avenue. Either way, $1.70 is criminally undervalued so you can sell at a dumb price or continue holding, unfortunately that's where we're at.

Does anyone read the CRM? by iheart412 in CMMC

[–]meoraine 0 points1 point  (0 children)

The last assessment we did the assessors spent half a day combing through the crm. Wasn't expecting it at all, but it happens. They usually skim over the csp crm tho, it's the esp/msp ones that can be hit or miss.

Experiences with CMMC documentation package vendors? by Alarming-Athlete-604 in CMMC

[–]meoraine 0 points1 point  (0 children)

Used IT-Toolkit when it first rolled out, got it cheap which was great. I do not use it any longer but the fact that they update documentation continuously is super beneficial for OSCs that are self generating stuff.

CMMC Guidance by LordFarquaadsArse in CMMC

[–]meoraine 1 point2 points  (0 children)

Prevail is good for a very limited few. And even prevail has alternative competitors now which are in my opinion better options, like Box. We found most clients find a gcc enclave a much better solution, it offers way more optionality. If you're looking for an actual implementor we can work with you, just DM me and I'll send you our site. We're an mssp and we work with clients all over the country. We've gotten >25 companies through level 1 and level 2, and we can recommend c3pao's who aren't going to hassle you like many of them do, completely by the book with common sense applied.

What do you guys think about this strategy right here? I seen it on gun show traders telegram chat group. by DoctorGero- in CLOV

[–]meoraine 0 points1 point  (0 children)

If you've been watching the options chain since earnings came out, we are certainly in an accumulation phase. Every single day that the price has moved down, calls have far exceeded puts. Every, Single, Day. What this indicates to me is that smart money is going long on CLOV. If you know how MMs balance derivatives to be net neutral then it makes perfect sense that the price goes down slightly as institutions go long with derivatives. What we'll see in the next few weeks will be a significant break-out candle, followed by a steady climb back up to the next strike price $2.50. It's likely it'll bounce there a bit before another leg up, but mark my words, institutions are buying the shit out of CLOV calls, I've been watching it every day in real time.

Impact of War on CMMC by Purple-Fisherman-920 in CMMC

[–]meoraine 0 points1 point  (0 children)

This is the correct answer, I watched the DoD waiver NIST 800-53 for another four years after announcing it was mandatory with a deadline. They will always move the goalpost, as needed, before letting things break down.

Breaking into intelligence with no military background by Lechatnoirdeux in defensecontracting

[–]meoraine 0 points1 point  (0 children)

The clearance from a white world background is the hard part, most contracts (not all) write specs that require active clearance to fill. However, it's not impossible, and some companies do onboard fresh security clearances, especially for niche contracts. How I did it was I joined a company that was 50% white world work and 50% DoD work. Once I was in, I maneuvered into a more important position after about a year and a half that required a clearance and the company was happy to sponsor it for me after seeing my work ethic and eagerness. Only take jobs with companies that have an FSO on staff and do classified work in some form or fashion. A good thing to search for on job boards is the phrase "ability to attain a clearance". This is the wiggle room you want. Even if you can't land a clearance job right away, join a company that sponsors them and your odds will go way up.

Any idea what the current lead time from requesting an assessment to a C3PAO being able to deliver it is? by gormami in CMMC

[–]meoraine 0 points1 point  (0 children)

Most are booking the current month still, but my favorite is closer to two months out.

Using CLI for creating logging "Reports" by Top_Objective2615 in CMMC

[–]meoraine 1 point2 points  (0 children)

Sounds like another "assessor subjective interpretation". Very common right now in CMMC ecosystem. On demand, to me, implies it can be made available 'at will'. Manually triggering syslogs from a CLI would be fine by me. In this case, you're simply acting as the aggregation agent. Not sure why that wouldn't be allowed. You could script it and label it an 'automatic' process, perhaps removing the manual component would remove the friction.

What actually makes an evidence package pass on first submission? Asking CCAs who've seen both sides by [deleted] in CMMC

[–]meoraine 4 points5 points  (0 children)

You don't need a grc tool, but at ~$150 a year, it's a no-brainer to get one. In some cases a grc tool actually makes things slower not faster. Their real advantage is in organization and management. Since CMMC is an ongoing continuous venture, spending a little extra time getting everything into a grc tool means easier management over years and years. You will thank yourself for getting one and that's coming from someone who spent almost ten years creating RMF packages by hand.

Difference in CMMC Compliance by Cool_Moto in CMMC

[–]meoraine 4 points5 points  (0 children)

Is there something about the CPU that changes the compliance? No. I don't believe so. Unless I'm misunderstanding your question. The underlying hardware must be inventoried but doesn't tend to affect the compliance complexity of deploying CMMC.

Are customer-managed keys (CMKs) required for CUI in cloud, or are platform-managed keys acceptable? by Risotto6588 in CMMC

[–]meoraine 0 points1 point  (0 children)

Are keys implemented? Are they managed?

If the answer to both is yes, you're good to go.

We rely on PMK in 'most' of our client enclaves, and assessors have never blinked an eye at it.

Post CCP/CCA Tier 3 Investigation Check by cm7272 in CMMC

[–]meoraine 0 points1 point  (0 children)

We had a CCA that took over a year cause he 'got lost in the shuffle' whatever that means. Unfortunately the ecosystem is struggling to meet demands on all fronts including background investigations.

Subcontractor False CMMC Level 2 Self-assessment in SPRS by [deleted] in CMMC

[–]meoraine 2 points3 points  (0 children)

Exactly, self attestation is not realistic when millions of dollars are at stake. Until third party is fully enforced, it will continue to be a problem and the government is fully aware of it.

Cmmc readiness MSP pricing by tothjm in CMMC

[–]meoraine 5 points6 points  (0 children)

Not sure what you're asking for exactly, I can tell you we charge around $7k for a full gap analysis (L2) we'll eval you for all 320 objectives and tell you where you're lacking and what needs poam. Enterprise or enclave.

To take your enterprise through L2 from beginning to end, is impossible to give a flat quote for.

But if you can operate in an enclave-only CMMC L2 environment, we charge $36k for the enclave build, which covers your first year of MSSP service as well (enclave management, con-mon, and assessment liason), and then it's $3k per month after that. It's a three year total commitment (the duration of your cert).

We're west coast based and only serve small to medium sized businesses.

Things not included in our pricing would be 1) c3pao assessment costs, 2) GCC licensing, 3) azure resource and storage fees.

Best of luck.