CMMC · ERP Pitfalls
Is Any ERP “CMMC Compliant”?
The Easy-Button Myth and 6 Pitfalls to Avoid
The “Easy Button” Myth
Compliant Hosting Is Not Compliance
- There is no “CMMC-compliant ERP” you can simply buy off the shelf; CMMC certifies how your organization handles CUI and FCI, not a single software product.
- AWS’s own public-sector guidance states it plainly: hosting in a FedRAMP-authorized environment does not automatically satisfy CMMC requirements.[1]
- Level 2 responsibility is shared across three layers — the hosting infrastructure (whether on-premise or in the cloud), the application platform, and your own organization’s people and processes.[2]
- Every control must answer three questions — who implements it, where it operates, and what evidence proves it — none of which hosting alone can resolve.[1]
- DFARS 252.204-7012 puts the burden on the contractor, not the vendor, to “require and ensure” the cloud provider’s compliance.[3]
1 & 2
Pitfall 1 & 2
Misclassifying Data and Over-Granting Access
- Misclassification is consistently cited as the number one stumbling block in Level 2 preparation, and it cuts both ways on cost and risk.[4]
- Tagging everything as CUI over-invests in controls you don’t need; under-protecting true CUI is worse — CUI found on an FCI-only laptop fails the assessment immediately.[5]
- Classify data at the moment it is received or created; retroactively sorting months of accumulated files is far harder and far more error prone.[4]
- The second pitfall is over-granting access: NIST SP 800-171 mandates least privilege, giving each user only the access their specific role requires.[6]
- Convenience-driven broad ERP permissions — where most users can view CUI documents even if they do not need to — violates least privilege.[6]
- Companion controls require routine work to run under non-privileged accounts and require the system to block and log non-privileged users who attempt privileged functions.[6]
3 & 4
Pitfall 3 & 4
Incomplete Audit Logging and Hidden Data Flows
- The third pitfall is audit logging that is switched off or only half-configured: the Audit and Accountability controls require creating, protecting, and retaining logs that trace activity to individual users.[7]
- A system that records logins but not CUI access, exports, or permission changes leaves precisely the gaps an assessor will go looking for.[7]
- The fourth pitfall is parallel data flows that quietly bypass your secure boundary — CUI that ends up in commercial SharePoint, OneDrive, Teams, Outlook, or a personal file-sharing tool.
- The moment CUI lands in commercial Microsoft 365, you have lost control of it, and Microsoft does not claim responsibility for safeguarding that data.[8]
- Because commercial Microsoft 365 cannot satisfy DFARS 7012 for CUI, a single email or shared file routed outside the boundary becomes a non-compliant event.[9]
- Assessors are trained to probe these edges: if your plan says CUI is contained but staff use commercial Teams and SharePoint daily, they will demand technical enforcement rather than a policy statement.[9]
- Data-flow diagrams, data-loss-prevention rules, and spillage detection are what actually prove the boundary holds in practice.[9]
5 & 6
Pitfall 5 & 6
Thin Documentation and Un-Segmented CUI Devices
- The fifth pitfall is failing to document your practices and procedures: the System Security Plan (SSP) is the cornerstone document a C3PAO evaluates.[10]
- Weak documentation or the wrong architecture choice can invalidate the entire compliance story sitting beneath your SSP, no matter how good individual controls look.[9]
- The sixth pitfall is failing to segment CUI-processing devices: a compliant ERP host does nothing to protect the other nodes that touch CUI.
- Engineering workstations, file servers, label printers, and shop-floor PCs that store, process, or transmit CUI all fall into assessment scope and must be protected.[11]
- Network segmentation and CUI enclaves confine sensitive data so that only those systems must meet all 110 controls, shrinking both risk and assessment cost.[11]
- Even with a fully compliant cloud, you remain responsible for ensuring unauthorized people cannot reach CUI on local devices or anywhere on the shop floor.[2]
Evaluation
So How Should You Actually Evaluate an ERP for CMMC?
- Confirm the ERP is hosted in a FedRAMP Moderate (or equivalent) environment — treat this as the baseline entry requirement, not the finish line.[3]
- Ask the vendor for a Customer Responsibility Matrix that spells out exactly which controls they cover and which remain yours to implement.[1]
- Require complete, tamper-resistant audit logs that capture CUI access, edits, and exports — and confirm you can produce them on demand.[7]
- Check that the ERP keeps CUI inside the compliant boundary and connects to compliant collaboration tools rather than commercial SharePoint or email.[8]
- Above all, treat ERP selection as one piece of an organization-wide program spanning people, process, and every CUI-touching device — never as a shortcut to certification.[2]
There’s no easy button — but there is a clear path.
Take a moment to schedule a free 30-minute consultation with our CMMC Compliance principal, Anil Cherian. Use the time to better understand these common pitfalls or potential collaborations. Whether you have an in-house IT department, already work with an MSP, or are completely new to CMMC, we can help you move forward to compliance and success.
References
- [1]CMMC Level 2 on AWS: Why Control Ownership Is Where Organizations Struggle
- [2]CMMC Level 2 Controls: Who Owns What (Shared Responsibility)
- [3]DFARS 252.204-7012 (full clause text)
- [4]CUI vs FCI Under the 48 CFR Final Rule
- [5]FCI vs. CUI: What’s the Difference?
- [6]NIST 800-171 Access Control (Least Privilege) Requirements
- [7]NIST 800-171 Audit & Accountability Requirements
- [8]Why You Need GCC or GCC High for CMMC (Commercial M365 & CUI)
- [9]GCC High vs Microsoft 365 Commercial for CMMC
- [10]CMMC FAQ: Certification, Requirements & the SSP
- [11]CMMC Level 2 Scoping & Asset Categories