GUIDE
CMMC FAQ for IT professionals
Your technical guide to understanding CMMC and leveraging Nerdio Manager
GUIDE
Your technical guide to understanding CMMC and leveraging Nerdio Manager
The Cybersecurity Maturity Model Certification (CMMC) is a compliance framework developed by the Department of Defense (DoD) to enhance the cybersecurity posture of its supply chain. It mandates specific security practices and third-party certification to protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).
CMMC defines three levels of cybersecurity maturity, each building on the last:
Each level has specific technical requirements IT professionals must meet to achieve certification.
Your prime contractors or subcontractors should address this, and it should also be specified by your contract in the DFARS 7012 clause. If a document contains CUI, it will be clearly marked with CUI in bold at the top.
IT professionals are responsible for implementing the technical controls required for CMMC compliance. Without proper implementation, organizations risk losing DoD contracts and exposing sensitive data. CMMC compliance also strengthens overall security posture and aligns organizations with industry best practices.
After due diligence, it’s often realized that not all employees handle CUI. For the portion of the organization that does, it is much more straightforward to implement resources to secure CUI by placing those workers in a VDI enclave. This approach makes the assessment scope much smaller and reduces the amount of resources required to go through an audit.
Building this infrastructure on top of the GCC/GCC High tenant and an Azure Gov Cloud subscription allows you to inherit all the security already put in place by Microsoft to handle CUI. This can often result in a shorter implementation ranging from 12 to 18 months down to just a few months.
“An endpoint hosting a VDI client configured to not allow any processing, storage, or transmission of CUI beyond the Keyboard/Video/Mouse sent to the VDI client is considered an Out-of-Scope Asset”
CMMC Scoping Guide Level 2, v. 2.13
Short answer: Now.
On October 15, the DoD published the CMMC Final Rule, which kicked off a 60-day congressional review period. The current period as of this writing is the CMMC prep period. Prime contractors and subcontractors are rushing to figure out what to do. Now to Q2, 2025. After 10 years of delays, DIB primes and subs are now on high alert.
Phase 1 (Q2, 2025 to Q1, 2026): Self-assessments in applicable contracts • Level 1 and Level 2 selfassessment requirements will be included in all applicable* solicitations and contracts. At its discretion, the DoD may require certification instead of self-assessment.
Phase 2 (Q2, 2026 to Q2, 2027): Level 2 certification in applicable contracts • In addition to Phase 1 requirements, CMMC Level 2 certification requirements will be included in all applicable* solicitations and contracts.
Phase 3 (Q3, 2027 and beyond): Level 2 expands; Level 3 begins • Level 2 certification requirements expand to existing contracts exercising an option period. Contractors with existing contracts should expect CMMC requirements upon renewal. Level 3 certification requirements will appear in all applicable* solicitations and contracts.
CMMC focuses on 14 domains, including:
An SSP documents your organization’s security infrastructure, controls, and configurations. It is a foundational requirement for CMMC certification and must include details, such as:
Nerdio Manager provides IT professionals with the tools needed to meet CMMC requirements efficiently, including:
Yes, Nerdio Manager includes features to address Level 2 and Level 3 requirements, such as:
Yes, Nerdio is already used by top Microsoft ASO-G (Microsoft Agreement for Online Services - Government program) to serve up secure VDI enclaves by leveraging Azure Virtual Desktops in GCC High and Azure GovCloud regions.
While Nerdio does not handle or have access to any CUI, we have taken additional steps to set up support for our partners and customers who are looking to comply with ITAR requirements by having US personnel that support our DIB/CMMC 2.0 customers using our solutions.
IT professionals can leverage Nerdio Manager for:
☐ Conduct a detailed gap analysis against NIST SP 800-171 or SP 800-172 controls.
☐ Develop a system security plan (SSP) and plan of action & milestones (POA&M).
☐ Implement technical controls, such as MFA, data encryption, and logging.
☐ Establish continuous monitoring for vulnerabilities and compliance drift.
☐ Schedule an audit with a Certified Third-Party Assessment Organization (C3PAO).
☐ Use automation tools, such as Nerdio Manager, to streamline policy enforcement and
reporting.
CMMC certification is no longer optional for DoD contractors and supply chain organizations. By adhering to CMMC standards, IT professionals ensure the protection of sensitive data, maintain eligibility for government contracts, and enhance their organizations’ overall cybersecurity resilience.
For more information about Nerdio Manager and how it supports your CMMC compliance journey, visit getnerdio.com.