The Learning Lab experience is supported by both asynchronous and synchronous components. Each part includes a set of resources, an asynchronous discussion, and an interactive live session, all of which culminate in the development of a project to apply learning to local and specific contexts in support of the learning objectives.
Schedule
Part 1: Scoping Your CMMC Enclave
July 20, 2026 | 3:00–4:30 p.m.ET
This session helps you establish the boundaries of your CMMC enclave so you know exactly what’s in and what’s out of scope. You’ll map key assets, identify sensitive data flows, and set clear parameters that can guide the rest of your readiness journey. By the end, you’ll have a foundational scope outline that stakeholders can understand and approve.
Learning Outcomes:
- Identify and categorize the assets, systems, and data flows within your CMMC enclave.
- Define clear enclave boundaries that balance security requirements with operational realities in higher education.
- Draft a scope outline that communicates rationale and priorities to both technical and non-technical stakeholders.
Part 2: Building a System Security Plan (SSP) That Works
July 22, 2026 | 3:00–4:30 p.m.ET
Your SSP is the heart of your CMMC documentation—it needs to be accurate, readable, and useful for both assessors and leadership. This session breaks down how to structure your SSP, tailor control responses to your higher ed environment, and cross-reference evidence for clarity. You’ll practice creating sections that both pass muster in an audit and help campus leaders see the value of the work.
Learning Outcomes:
- Outline the structure and key content elements of an effective SSP.
- Write clear, concise, and context-appropriate control responses for a higher ed audience.
- Integrate cross-references between controls and evidence sources for improved clarity and audit readiness.
Part 3: Evidence, POA&Ms, and Strategic Storytelling
July 27, 2026 | 3:00–4:30 p.m.ET
Collecting evidence is more than a compliance task—it’s a chance to tell your institution’s cybersecurity story. In this session, you’ll learn how to gather and organize meaningful evidence, use POA&Ms (Plans of Action and Milestones) to track progress, and present findings in a way that builds transparency and trust. You’ll walk away with an evidence plan you can put to work immediately.
Learning Outcomes:
- Identify and organize evidence sources for selected CMMC controls.
- Create a clear and actionable POA&M that tracks progress and communicates next steps.
- Develop short, leadership-ready narratives that contextualize technical evidence.
Part 4: Working with C3PAOs and Sustaining Progress
July 29, 2026 | 3:00–4:30 p.m.ET
Getting ready for a C3PAO assessment means more than just preparing documents—it’s about building a sustainable readiness process. This session covers what to expect from C3PAO interactions, how to prepare your team and artifacts for review, and how to keep your CMMC program healthy long after the initial push. You’ll create a concise readiness brief that sets you up for both assessment and ongoing governance.
Learning Outcomes:
- Describe the role and expectations of a C3PAO in the CMMC assessment process.
- Create a readiness checklist that addresses both immediate assessment needs and long-term governance.
- Summarize your institution’s readiness status and next steps in a brief format for leadership and stakeholders.
Lab Project/Assignments
CMMC Readiness Package:
Each participant will develop a concise CMMC Enclave Readiness Package that integrates key deliverables from each session into a comprehensive, leadership-facing artifact. This package will serve as both a roadmap for formal assessment and a communication tool to secure buy-in and sustain ongoing compliance efforts.
The package will include:
- Enclave scope definition and diagram clearly delineating what is in and out of scope, with rationale.
- Mini System Security Plan (SSP) section including tailored control responses and leadership-facing excerpts.
- Evidence tracking table and POA&M summary showing available evidence, known gaps, and remediation plans.
- Researcher Responsibilities Checklist that provides practical, standardized expectations for PIs and research staff.
- CMMC Readiness Brief summarizing overall readiness, key stakeholders, risks, and next steps for leadership and assessment teams.
Participants will have the option to receive facilitator and/or peer feedback on their package. Upon completion, they will leave with a practical, reusable document designed to guide institutional CMMC readiness and communicate progress clearly to technical and leadership audiences alike.