38North Security Answers CMMC Questions (08 October 2026)

Andrew Hennigan
Linda Morales | 38North Security | cybersecurity | CMMC | compliance
Linda Morales
Vice President, Corporate Security & Global Compliance

Linda Morales is the Vice President of Corporate Security & Global Compliance at 38North Security. She leads assessments for customers in the healthcare, federal and commercial spaces looking to expand their product offering to meet US and International standard requirements. She specializes in helping organizations prepare for and complete FISMA, FedRAMP, and HIPAA assessments. Linda is also a recognized expert in Healthcare security, helping Health-IT providers secure and defend Protected Health Information (PHI).

Before 38North, Linda served as a Director at Endeavor Systems, where she played a key role in growing the federal security services practice. She also served as Security Manager for the Federal Aviation Administration’s (FAA) enterprise-wide assessment program, responsible for 150+ systems across FAA.

Linda earned a BS in Computer Science and a Masters in Engineering Management, both from George Washington University, focusing on Information Security. She is also a Certified Information Systems Security Professional (CISSP), Project Management Professional (PMP), and a CMMC-Certified Professional (CCP) with the Cyber Advisory Board (Cyber-AB).

Meet the Author

CMMC has no shortage of official guidance, but contractors’ questions keep coming thick and fast, anyway. 

For this episode of the 38North Security Podcast, we went somewhere considerably less formal: Reddit. We pulled some of the CMMC questions people are actually asking right now and brought them to Linda Morales, our Executive Vice President, Chief Security Officer, and CMMC Practice Lead, and Andrew Hennigan, Technical Project Lead and CMMC CCP. 

The questions ranged from what happens after an assessment, to whether organizations should keep pursuing certification during the pause, what a good mock assessment should uncover, and how tools like secure file-sharing platforms affect your CMMC boundary. 

You can watch the full video here:  

You passed your CMMC assessment. Now what? 

Passing an assessment does not put CMMC on a shelf for three years. Organizations still have to maintain the controls they assessed, keep required documentation current, perform ongoing and annual activities, and pay attention to changes in the environment that could affect how those controls are implemented. 

Change management matters here. A new system, architecture change, workflow, or technology may change the way CUI is handled or protected. Security needs to be part of that conversation before the change happens, rather than something the compliance team discovers six months later while updating documentation. 

There is also the looming question of NIST SP 800-171 Rev. 3. Right now, Linda and Andrew’s advice is essentially to be deliberate. The CMMC ecosystem is still built around Rev. 2, and the timing and mechanics of a future transition are still uncertain. Organizations with the time and resources can start familiarizing themselves with Rev. 3, especially if other federal work is already pushing them in that direction.  

For teams still struggling to maintain Rev. 2, however, abandoning the current baseline to race ahead would create its own problems. The immediate job is to keep the environment you assessed defensible. 

Should you keep pursuing CMMC during the pause? 

This is one of the questions we keep seeing because the answer depends heavily on the business. 

A pause in the federal rollout does not necessarily mean your customers have paused their expectations. Prime contractors may still require subcontractors to demonstrate that they are protecting CUI appropriately, and some have continued asking suppliers for independent assessments. 

That leaves contractors with a business decision. What are your customers requiring? How confident is your affirming official in the score you are representing? How much value would independent validation provide when you are pursuing work? 

For some organizations, waiting may make sense. For others, the commercial requirements coming from primes or customers mean very little has changed. The important thing is to avoid treating “pause” as shorthand for “nothing to do.” 

Learn more: The Cyber AB’s Response to the CMMC Pause Tells You Everything About Who Actually Benefits From CMMC Phase 2

If a mock assessment finds more problems than you expected, good 

One Reddit user was nervous about an upcoming mock assessment because they suspected the team might uncover more findings than leadership expected. 

That is pretty much the point. 

A team that lives with its own environment every day can easily develop assumptions about how a requirement is being met. A mock assessment puts someone else in the room to challenge those assumptions, look at the evidence, and ask whether the implementation would actually stand up during an independent assessment. 

It can also expose misunderstandings around assessment objectives, evidence, boundaries, and how employees answer assessor questions. Those are all much cheaper problems to discover during a mock assessment than when the C3PAO is sitting across from you. 

Linda also pointed out that mock assessments help train the organization itself. People learn what evidence they need, how to explain what they do, and, importantly, how to keep the conversation inside the actual CMMC scope. 

More findings during a mock assessment do not mean the exercise went badly. They mean you found the problems while you still had time to fix them. 

A secure tool does not automatically make the rest of your environment secure 

Another question involved platforms such as Box, Kiteworks, and PreVeil and how they affect the CMMC boundary. The question sounds like it is about choosing or configuring a tool, but it very quickly becomes a data-flow question. 

Where does the CUI start? How does it get into the platform? What system touches it first? Can users access the platform outside the controlled environment? Can files be downloaded locally? What happens when CUI arrives on physical media? Where can it go after someone opens it? 

A secure repository can protect data once it is there. It does not erase everything that happens before and after that point. 

Linda gave a particularly useful example: if an employee uploads a CUI file from a local computer into an approved platform, the file existed on that computer first. Now you have to understand what that means for the computer, your boundary, and the controls surrounding it. 

The same applies to physical media. USB devices, removable drives, and even printed paper introduce requirements around inventory, protection, handling, and destruction. 

This is why CMMC scoping conversations tend to begin with data flow. Before choosing the tool, map how the information actually moves through the organization. 

And no, the tool does not do everything for you 

When we asked Linda what organizations commonly assume their security tooling will handle for them, her answer was admirably concise: “Everything.” 

A platform may provide encryption, access controls, secure storage, or other important capabilities. There will still be customer responsibilities around configuration, identity, endpoints, processes, training, incident response, and how users interact with the system. 

Andrew made the same point from the implementation side. Organizations need to understand what the product does, what it does not do, and how that maps to their actual CMMC requirements before deciding that a technology solves the problem. 

That usually requires conversations between people who do not naturally spend much time together: IT, security, compliance, operations, sales, and anyone else who knows where CUI enters the business or where it goes. That’s because that’s usually where the interesting CMMC problems are hiding. 

Keep sending us your questions 

These were only a few of the questions we found, and judging by the state of CMMC right now, we are unlikely to run out anytime soon. 

If there is something you are trying to figure out — assessment readiness, scoping, CUI, tooling, the pause, Rev. 3, or something considerably weirder — send it our way. We’ll do our best to answer it in the next CMMC question roundup! 

Get in touch with the team for help getting CMMC-ready. 38North Security helps contractors with CMMC scoping, gap assessments, remediation planning, mock assessments, evidence readiness, and ongoing compliance support. → https://38northsecurity.com/contact/

About the Authors
Andrew Hennigan
Linda Morales | 38North Security | cybersecurity | CMMC | compliance
Linda Morales
Vice President, Corporate Security & Global Compliance

Linda Morales is the Vice President of Corporate Security & Global Compliance at 38North Security. She leads assessments for customers in the healthcare, federal and commercial spaces looking to expand their product offering to meet US and International standard requirements. She specializes in helping organizations prepare for and complete FISMA, FedRAMP, and HIPAA assessments. Linda is also a recognized expert in Healthcare security, helping Health-IT providers secure and defend Protected Health Information (PHI).

Before 38North, Linda served as a Director at Endeavor Systems, where she played a key role in growing the federal security services practice. She also served as Security Manager for the Federal Aviation Administration’s (FAA) enterprise-wide assessment program, responsible for 150+ systems across FAA.

Linda earned a BS in Computer Science and a Masters in Engineering Management, both from George Washington University, focusing on Information Security. She is also a Certified Information Systems Security Professional (CISSP), Project Management Professional (PMP), and a CMMC-Certified Professional (CCP) with the Cyber Advisory Board (Cyber-AB).

Meet the Author