Skip to main content
Back to Threat Watch
Compliance

CMMC, FedRAMP & StateRAMP for Public Sector

Published Updated

Government contractors, cloud providers, agencies, and education institutions can face different security obligations. Begin with the information, services, and contracts in scope. There is no single NIST assessment that establishes compliance with all government programs.

This article retains its June 2025 publication date. Framework references were reviewed October 3, 2026; StateRAMP now operates as GovRAMP. Confirm current requirements before making a contract or compliance decision.

CMMC: defense-contract information

The CMMC program rules address the protection of Federal Contract Information and Controlled Unclassified Information on defense-contractor systems. Required levels, assessments, system boundaries, and flow-down obligations depend on the governing requirements.

Level 2 uses NIST SP 800-171 Revision 2 under the program rule; do not assume a different revision applies merely because it is newer. Review the relevant solicitation and contract with your compliance team. A federal grant, public-sector customer, or defense-industry connection does not alone establish the same CMMC requirement for every system.

FedRAMP and GovRAMP: cloud-service assurance

FedRAMP uses security baselines built on NIST SP 800-53. Its Revision 5 transition guidance explains the baseline framework.

GovRAMP's security program also uses NIST SP 800-53 Revision 5. Its security assessment framework identifies the organization as StateRAMP doing business as GovRAMP.

Neither program is a general certification for every system an agency or school operates. Identify the service, program status, impact level, and procurement requirement that the customer actually needs. An NIST SP 800-171 gap assessment does not substitute for an applicable SP 800-53-based cloud assessment.

A practical way to plan

1. Establish applicability. Record the contracts, data types, system boundaries, standards revisions, assessment paths, and deadlines relevant to the work.

2. Map the controls and evidence. Identify what is already implemented, who operates it, and what evidence supports that conclusion. Reuse evidence where appropriate while checking each program's requirements separately.

3. Resolve gaps against the actual deadline. A Plan of Action and Milestones can organize remediation, but it is not a blanket permission to defer required controls. Check the governing program and contract.

For example, CMMC rules place limits on conditional status and POA&Ms.

4. Connect assessment with operations. Assign owners for maintaining controls, handling incidents, and updating evidence when the environment changes.

5. Check state and institution-specific requirements. Confirm relevant procurement, reporting, and data-protection obligations with the responsible office.

Use the Utah Cyber Center and the school cybersecurity guide as starting points for Utah resources.

A useful roadmap is specific enough that the responsible teams know which obligation they are meeting, which system it covers, and what must happen next.

Get the next issue in your inbox

Harborcoat Threat Watch sends concise cybersecurity analysis for business and IT leaders when there is something worth your time.

More from Threat Watch