πŸ•ΈοΈ Ada Research Browser

index.md
← Back

CMMC Intelligence Database

Last Updated: 2026-03-14 Scope: CMMC 2.0 Level 2 assessments β€” real-world intel, templates, vendors, per-control notes Status: 🟒 Active β€” nightly updates running


Quick Reference: Key Takeaways

  1. Documentation is 70% of the work β€” technical controls matter, but policy/procedure backing is what assessors verify
  2. Start with CUI flow β€” know where it comes from, goes, and is processed before anything else
  3. Scope tightly β€” small enclaves (3-6 users) are assessable in weeks vs months
  4. GCC High inheritance is your biggest lever β€” 30-40% of controls fully inherited; use Appendix J
  5. Pre-submit evidence to your C3PAO β€” dramatically cuts assessment time
  6. Prepare your people, not just your systems β€” assessors interview staff

Files

Reddit Research

By Control Domain

File Domain Richness
AC.md Access Control ⭐⭐⭐ β€” session termination, scoping, evidence tips
AT.md Awareness & Training ⭐ β€” stub
AU.md Audit & Accountability ⭐⭐ β€” SIEM options, DoD ODPs
CM.md Configuration Management ⭐⭐⭐ β€” app execution policy, baselines, firewall
IA.md Identification & Authentication ⭐⭐⭐ β€” password complexity, MFA, FedRAMP password mgrs
IR.md Incident Response ⭐ β€” basic notes
MA.md Maintenance ⭐ β€” remote maintenance notes
MP.md Media Protection ⭐⭐ β€” sanitization, BitLocker
PE.md Physical Protection ⭐ β€” stub
PS.md Personnel Security ⭐ β€” stub
RA.md Risk Assessment ⭐⭐ β€” POA&M, GRC tools
CA.md Security Assessment ⭐⭐⭐ β€” SSP, mock assessments, SPRS
SC.md System & Communications Protection ⭐⭐⭐ β€” split tunneling, CUI email, FIPS
SI.md System & Information Integrity ⭐⭐ β€” EDR, patch mgmt, continuous monitoring
SR.md Supply Chain Risk Management ⭐⭐ β€” MSP in-scope, CAGE codes, false SPRS

Vendors

Templates

Lessons Learned


Assessment Cost Ranges (2025-2026)

Org Size Architecture Total Range
<10 users, cloud enclave GCC H or PreVeil $20K–$40K
20-30 users, cloud GCC H $30K–$50K
SMB any size, consulting only Cloud $45K–$80K
Enterprise hybrid 500+ endpoints $100K+
C3PAO assessment alone Any $30K+ minimum

Vendors to Avoid


Research Gaps (To Fill)


Changelog

2026-03-12 β€” Nightly Update Pass

2026-03-13 β€” Nightly Update Pass

2026-03-14 β€” Nightly Update Pass