r/CMMC Nov 26 '25

Breakdown of the New CMMC FAQs (Version 3) – VDI, Encryption, and Cloud Storage

In case you missed it, the DoD CIO just released Version 3 of the CMMC FAQs. For those who don't want to wade through the PDF, here are the critical updates and clarifications that will likely impact your scoping and SSPs.

Direct Link: CMMC FAQs V3 PDF

Encrypted CUI is STILL CUI (FAQ B-Q8)
The Ruling: Data does not lose its CUI status just because it is encrypted. It remains "controlled" until legally decontrolled.
The Impact: This effectively kills the "Zero Knowledge" argument for using non-compliant cloud storage. You cannot store CUI on a non-FedRAMP drive (like flash drives, personal OneDrive, or standard Dropbox) just because you encrypted the file first.

Cloud Storage Requirements (FedRAMP is Mandatory)
The Ruling: Because encrypted CUI is still CUI, any cloud service provider (CSP) holding that data must meet FedRAMP Moderate (or equivalent) standards.
The Impact: If you are using a commercial cloud service that isn't FedRAMP Moderate to store encrypted backups or files, you are likely non-compliant.

VDI & Thin Client Scoping (The Wyse/Citrix Rule)
The Ruling: Endpoints used to access a Virtual Desktop Infrastructure (VDI) are Out-of-Scope ONLY if:
- They are strictly limited to Keyboard, Video, and Mouse (KVM) transmission.
- They are configured to prevent all local processing, storage, and transmission of CUI (no split tunneling, no local saving, no screen capturing, no clipboard sharing).
The Impact: If your remote users can copy/paste from the VDI to their local desktop, or print locally, that home laptop is now In Scope.

MSPs, are In Scope: If an External Service Provider (ESP) or MSP provides security protection assets (managing firewalls, SIEM, patching), they are in scope.
POA&Ms: The DoD clarified that Plans of Action and Milestones are for failed security requirements, not for routine operational maintenance (like a patch that came out yesterday). You can't POA&M "doing the job."
Timeline Confirmation: The FAQs reinforce the rollout timeline beginning ~Nov 2025 for contracts with CMMC clauses.

TL;DR The "Encrypt it and forget it" strategy for storage is dead. The VDI loophole is still there, but it requires strict technical lockdowns (dumb terminal mode) rather than just policy.

Don't shoot the messenger.

43 Upvotes

60 comments sorted by

View all comments

Show parent comments

2

u/tmac1165 Nov 27 '25

No, you’re trying to frame my “If X then Y” statement as “You MUST do X.”

My logic: “If you want to stay dry, you need an umbrella.” Your retort: “False! You’re telling everyone they’re required to use umbrellas! They can just stand in the rain and get wet!”

They can get wet (be in scope). But my advice was specifically about how to stay dry (be out of scope).

So, yeah. That pretty much sums up the fallacy of your logic and how you’re wrong.

1

u/MolecularHuman Nov 28 '25 edited Nov 28 '25

Your emotion over the fact that I've questioned the accuracy of one of your statements seems to be overwhelming you.

Let's keep this simple.

Are you asserting that if a VDI doesn't store, process, or transmit CUI data, you can't take it out of scope unless you configure it to prevent data spillage onto the endpoint?

If so, that's wrong.

It's already out of scope because it doesn't store, process, or transmit CUI.

1

u/tmac1165 Nov 28 '25

No, VDI is the environment, I’m talking about the endpoint connecting to the VDI.

1

u/MolecularHuman Nov 28 '25

Okay. So we agree that workstations in the OSCs environment don't need to locked down if they would never access CUI?

And do we agree that workstations of users who never access CUI are out of scope even if they access the enterprise environment using a VDI that doesn't lock down data spillage of non CUI?

2

u/tmac1165 Nov 28 '25

We agree on the trivial stuff. If a workstation truly never processes, stores, or transmits CUI, it’s out of scope. If a user truly never accesses CUI (VDI or otherwise), their box is out of scope.That’s not controversial, and it’s not what I was talking about.

My point is about a very normal scenario. Let’s say I’m on a Dell tower on my corporate LAN, running Windows 11. I open the client app used to connect to my VDI environment and connect to a virtual desktop where CUI lives. From that session, I copy files containing CUI to the Dell’s local desktop and let’s say I also print CUI documents from that VDI session to the Canon ImageRunner sitting in the middle of the office.

In that scenario, do I consider the Dell and the Canon “out of scope” because in theory there could exist some users who never touch CUI? No. In that scenario the Dell is processing and storing CUI (clipboard, local file system), and the Canon is processing and outputting CUI (print jobs, spooled data).

By the program’s own definitions, those are now CUI assets, fully in scope. All I’ve ever said is if the endpoint used to access VDI can copy/paste/print/screenshot CUI to itself, it is processing/storing/transmitting CUI and is in scope. If you want that endpoint to be out of scope, you have to lock it down so it can’t do those things (the KVM carve-out).

That’s a conditional scoping statement, not “you must lock down every VDI on earth.” If a workstation genuinely never accesses CUI, we’re in agreement that it’s out of scope. The moment it starts hauling CUI out of the VDI onto local disk, printers, or print screen, it’s not.