CMMC · ERP Pitfalls

Is Any ERP “CMMC Compliant”?

The Easy-Button Myth and 6 Pitfalls to Avoid

The “Easy Button” Myth

Compliant Hosting Is Not Compliance
  • There is no “CMMC-compliant ERP” you can simply buy off the shelf; CMMC certifies how your organization handles CUI and FCI, not a single software product.
  • AWS’s own public-sector guidance states it plainly: hosting in a FedRAMP-authorized environment does not automatically satisfy CMMC requirements.[1]
  • Level 2 responsibility is shared across three layers — the hosting infrastructure (whether on-premise or in the cloud), the application platform, and your own organization’s people and processes.[2]
  • Every control must answer three questions — who implements it, where it operates, and what evidence proves it — none of which hosting alone can resolve.[1]
  • DFARS 252.204-7012 puts the burden on the contractor, not the vendor, to “require and ensure” the cloud provider’s compliance.[3]
1 & 2

Pitfall 1 & 2

Misclassifying Data and Over-Granting Access
  • Misclassification is consistently cited as the number one stumbling block in Level 2 preparation, and it cuts both ways on cost and risk.[4]
  • Tagging everything as CUI over-invests in controls you don’t need; under-protecting true CUI is worse — CUI found on an FCI-only laptop fails the assessment immediately.[5]
  • Classify data at the moment it is received or created; retroactively sorting months of accumulated files is far harder and far more error prone.[4]
  • The second pitfall is over-granting access: NIST SP 800-171 mandates least privilege, giving each user only the access their specific role requires.[6]
  • Convenience-driven broad ERP permissions — where most users can view CUI documents even if they do not need to — violates least privilege.[6]
  • Companion controls require routine work to run under non-privileged accounts and require the system to block and log non-privileged users who attempt privileged functions.[6]
3 & 4

Pitfall 3 & 4

Incomplete Audit Logging and Hidden Data Flows
  • The third pitfall is audit logging that is switched off or only half-configured: the Audit and Accountability controls require creating, protecting, and retaining logs that trace activity to individual users.[7]
  • A system that records logins but not CUI access, exports, or permission changes leaves precisely the gaps an assessor will go looking for.[7]
  • The fourth pitfall is parallel data flows that quietly bypass your secure boundary — CUI that ends up in commercial SharePoint, OneDrive, Teams, Outlook, or a personal file-sharing tool.
  • The moment CUI lands in commercial Microsoft 365, you have lost control of it, and Microsoft does not claim responsibility for safeguarding that data.[8]
  • Because commercial Microsoft 365 cannot satisfy DFARS 7012 for CUI, a single email or shared file routed outside the boundary becomes a non-compliant event.[9]
  • Assessors are trained to probe these edges: if your plan says CUI is contained but staff use commercial Teams and SharePoint daily, they will demand technical enforcement rather than a policy statement.[9]
  • Data-flow diagrams, data-loss-prevention rules, and spillage detection are what actually prove the boundary holds in practice.[9]
5 & 6

Pitfall 5 & 6

Thin Documentation and Un-Segmented CUI Devices
  • The fifth pitfall is failing to document your practices and procedures: the System Security Plan (SSP) is the cornerstone document a C3PAO evaluates.[10]
  • Weak documentation or the wrong architecture choice can invalidate the entire compliance story sitting beneath your SSP, no matter how good individual controls look.[9]
  • The sixth pitfall is failing to segment CUI-processing devices: a compliant ERP host does nothing to protect the other nodes that touch CUI.
  • Engineering workstations, file servers, label printers, and shop-floor PCs that store, process, or transmit CUI all fall into assessment scope and must be protected.[11]
  • Network segmentation and CUI enclaves confine sensitive data so that only those systems must meet all 110 controls, shrinking both risk and assessment cost.[11]
  • Even with a fully compliant cloud, you remain responsible for ensuring unauthorized people cannot reach CUI on local devices or anywhere on the shop floor.[2]

Evaluation

So How Should You Actually Evaluate an ERP for CMMC?
  • Confirm the ERP is hosted in a FedRAMP Moderate (or equivalent) environment — treat this as the baseline entry requirement, not the finish line.[3]
  • Ask the vendor for a Customer Responsibility Matrix that spells out exactly which controls they cover and which remain yours to implement.[1]
  • Require complete, tamper-resistant audit logs that capture CUI access, edits, and exports — and confirm you can produce them on demand.[7]
  • Check that the ERP keeps CUI inside the compliant boundary and connects to compliant collaboration tools rather than commercial SharePoint or email.[8]
  • Above all, treat ERP selection as one piece of an organization-wide program spanning people, process, and every CUI-touching device — never as a shortcut to certification.[2]
There’s no easy button — but there is a clear path.

Take a moment to schedule a free 30-minute consultation with our CMMC Compliance principal, Anil Cherian. Use the time to better understand these common pitfalls or potential collaborations. Whether you have an in-house IT department, already work with an MSP, or are completely new to CMMC, we can help you move forward to compliance and success.

References

  • [1]CMMC Level 2 on AWS: Why Control Ownership Is Where Organizations Struggle
  • [2]CMMC Level 2 Controls: Who Owns What (Shared Responsibility)
  • [3]DFARS 252.204-7012 (full clause text)
  • [4]CUI vs FCI Under the 48 CFR Final Rule
  • [5]FCI vs. CUI: What’s the Difference?
  • [6]NIST 800-171 Access Control (Least Privilege) Requirements
  • [7]NIST 800-171 Audit & Accountability Requirements
  • [8]Why You Need GCC or GCC High for CMMC (Commercial M365 & CUI)
  • [9]GCC High vs Microsoft 365 Commercial for CMMC
  • [10]CMMC FAQ: Certification, Requirements & the SSP
  • [11]CMMC Level 2 Scoping & Asset Categories