# Organizations Implement CMMC Level 2 Compliance

Government contractors and MSPs are actively working to meet Cybersecurity Maturity Model Certification (CMMC) Level 2 requirements within tight deadlines, focusing on Controlled Unclassified Information (CUI) scoping, technical controls, and operational policies. Small software firms face challenges achieving compliance rapidly without dedicated security teams or experienced Managed Security Providers (MSPs). MSPs supporting GCC High environments must carefully manage access and responsibilities to minimize their compliance scope and risk exposure. Effective use of Virtual Desktop Infrastructure (VDI) and Azure Virtual Desktop (AVD) enclaves is recommended to limit CUI exposure and streamline certification efforts.

- **CMMC Level 2 compliance requires detailed scoping of CUI data flows and rapid adoption of policies and procedures, with a 90-day readiness challenge for smaller firms without dedicated security resources.**
- **Personal mobile devices can be managed out of CUI scope through documented data flow diagrams, administrative policies, and technical controls like Mobile Device Management (MDM), avoiding unnecessary operational restrictions.**
- **MSPs must implement strict access controls, use client-controlled virtual environments, and clearly delineate responsibilities to avoid being fully "in scope" for CUI, which is critical for sustaining business growth and compliance.**
- **VDI and AVD solutions, such as those potentially offered by vendors like ATX Defense, are key tools for reducing compliance scope and maintaining developer workflow usability.**

**Jurisdictions:** federal
**Industries:** Information Technology, Defense & Military
**Topics:** Cybersecurity
**Published:** May 12, 2026

### Government Entities
- Department of Defense (DoD)
- Cybersecurity Maturity Model Certification (CMMC)
- Certified Cybersecurity Provider (CCP)
- Cybersecurity Third Party Assessment Organization (C3PAO)

### Vendors
- ATX Defense (potential VDI solution provider)

### Key Quotes
> The only way to truly accomplish what you want is to do staff augmentation. That means your staff are using your clients machines and signing their policies and essentially acting as a contractor for your client.
> — Anonymous community member

> If CUI data exists on developer machines, an enclave isn't going to work for you. The VDI environment will be too locked down for developers' needs. The body will reject the transplant.
> — community member

> If your orgs data flow diagrams and scoping is documented well enough combined with the administrative and technical controls you mentioned, you should have no issue justifying to an assessor that those mobile devices are out of scope from your CUI environment.
> — Community commenter

### Sources
- [CMMC Decision point](https://www.reddit.com/r/CMMC/comments/1t5b9t1/cmmc_decision_point) - reddit-cmmc
- [Understanding Personal Mobile Device Policies for CMMC](https://www.reddit.com/r/CMMC/comments/1t6sui3/understanding_personal_mobile_device_policies_for) - reddit-cmmc
- [Best practices for MSPs managing GCC High enclaves without being "in scope" for CUI?](https://www.reddit.com/r/CMMC/comments/1tbdywo/best_practices_for_msps_managing_gcc_high) - reddit-cmmc