Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

NinjaOne: How MSPs Can Inherit CMMC Controls via FedRAMP

NinjaOne
07/10/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


inherit some of the controls that Ninja has. So, like, their FIPS encryption that they have, the boundary protection around the tools that they have, those types of things. I can inherit those in my SSP and say, okay, because they have their FedRAMP authorization, I can provide that as an example and the assessor will be like, okay, I'm not going to dig further because of the fact that they have that. And so that helps solve a lot of the technical controls around things like that. So, like, for when we put the agents on the client's machine for us to remote in, one of the challenges is obviously you want to make sure your remote access tool has a FIPS validated cryptography that's going to allow the remote access capabilities. And that's something that we leveraged through Ninja, which has been a huge help for us.

TL;DR

  • FedRAMP authorization is the only accreditation whose controls can be inherited during a CMMC assessment, reducing the technical burden on MSPs.
  • MSPs using NinjaOne can reference its FedRAMP status in their SSP, signaling to assessors that key controls like FIPS encryption are already satisfied.
  • Remote access tools must use FIPS-validated cryptography to meet CMMC requirements — NinjaOne's FedRAMP-backed tooling addresses this directly.

Summary

This short clip, drawn from a longer NinjaOne panel featuring MSP leaders from Executech and Axiom, highlights one of the most practical CMMC compliance advantages available to managed service providers: control inheritance through FedRAMP-authorized tooling. The speaker explains that FedRAMP authorization is the only accreditation whose controls can be directly inherited during the CMMC assessment process. Because NinjaOne holds FedRAMP authorization, MSP clients can reference that status in their System Security Plan (SSP) and expect assessors to accept it without requiring further technical scrutiny. Specific examples include FIPS-validated encryption and boundary protection — both critical requirements for DoD-adjacent environments. The speaker also addresses a common MSP challenge: ensuring that remote access agents deployed on client machines use FIPS-validated cryptography. NinjaOne's FedRAMP-backed remote access capability is cited as a direct solution to this requirement, reducing the compliance burden on the MSP and strengthening their overall CMMC posture. For MSPs pursuing or maintaining DoD contracts, this clip underscores the strategic value of selecting tools that carry FedRAMP authorization, as it can meaningfully reduce the scope and complexity of a CMMC assessment.

Chapters

0:00 - FedRAMP & Control Inheritance
0:16 - SSP Documentation & Assessors
0:32 - Remote Access & FIPS Requirements

Key Quotes

0:00 "... the only accreditation that can be inherited during your CMMC process."
0:05 "I can inherit some of the controls that Ninja has. So, like, their FIPS encryption that they have, the boundary protection around the tools that they have, those types of things."
0:16 "... because they have their FedRAMP authorization, I can provide that as an example and the assessor will be like, okay, I'm not going to dig further because of the fact that they have that."
0:41 "... you want to make sure your remote access tool has a FIPS validated cryptography that's going to allow the remote access capabilities. And that's something that we leveraged through Ninja, which has been a huge help for us."

FAQ

What does it mean to 'inherit' controls during a CMMC assessment?

Control inheritance means an MSP can reference a vendor's existing FedRAMP authorization in their System Security Plan to satisfy certain CMMC technical requirements — such as FIPS encryption or boundary protection — without needing to independently demonstrate compliance for those controls.

Why does FedRAMP matter specifically for CMMC compliance?

FedRAMP is the only accreditation recognized for control inheritance in the CMMC process. If an MSP's tooling holds FedRAMP authorization, assessors will generally accept that as evidence for the covered controls and will not dig further into those specific requirements.


Categories:
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Compliance & Governance
  • Security Operations
  • Getting Started
  • Best Practices
  • webinar_clip
  • CMMC compliance
  • FedRAMP authorization
  • control inheritance
  • FIPS-validated cryptography
  • MSP compliance strategy
  • remote access security
  • DoD contracts
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: NinjaOne: How MSPs Can Inherit CMMC Controls via FedRAMP

              XStreaminars (watch here)

              • Oct
                28

                EnvZero: Near-Zero Time to Resolution--Live Agentic Remediation for Failed and Drifted Infrastructure

                10/28/202601:00 PM ET
                More events

                Industry Events (Sponsor Hosted)

                • Oct
                  13

                  Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance

                  10/13/202601:00 PM ET
                  • Oct
                    15

                    Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation

                    10/15/202611:00 AM ET
                    • Oct
                      20

                      Harnessing Data Governance for AI with Cyera and Snowflake

                      10/20/202611:00 AM ET
                      • Oct
                        27

                        Maximize Security, Value, and Returns on Your Microsoft Investment

                        10/27/202611:00 AM ET
                        • Oct
                          27

                          The HUMAN Experience: Real-Time Insights into Page Intelligence

                          10/27/202601:00 PM ET
                          More events

                          Upcoming Webinar Calendar

                          • 10/13/2026
                            01:00 PM
                            10/13/2026
                            Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance
                            https://www.truthinit.com/index.php/channel/2159/transitioning-from-cjis-to-ferpa-essential-audit-evidence-for-compliance/
                          • 10/15/2026
                            11:00 AM
                            10/15/2026
                            Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation
                            https://www.truthinit.com/index.php/channel/1372/risk-in-real-time-demo-series-the-autonomous-era-orchestrating-a-resilient-enterprise/
                          • 10/20/2026
                            11:00 AM
                            10/20/2026
                            Harnessing Data Governance for AI with Cyera and Snowflake
                            https://www.truthinit.com/index.php/channel/2137/harnessing-data-governance-for-ai-with-cyera-and-snowflake/
                          • 10/27/2026
                            11:00 AM
                            10/27/2026
                            Maximize Security, Value, and Returns on Your Microsoft Investment
                            https://www.truthinit.com/index.php/channel/2178/maximize-security-value-and-returns-on-your-microsoft-investment/
                          • 10/27/2026
                            01:00 PM
                            10/27/2026
                            The HUMAN Experience: Real-Time Insights into Page Intelligence
                            https://www.truthinit.com/index.php/channel/2139/the-human-experience-real-time-insights-into-page-intelligence/
                          • 10/28/2026
                            01:00 AM
                            10/28/2026
                            [APAC:] Secure AI Everywhere: Visibility, governance and protection for the agentic era
                            https://www.truthinit.com/index.php/channel/2125/apac-ensuring-comprehensive-security-for-ai-applications/
                          • 10/28/2026
                            06:00 AM
                            10/28/2026
                            [EMEA:] Secure AI Everywhere: Visibility, governance and protection for the agentic era
                            https://www.truthinit.com/index.php/channel/2127/emea-ensuring-ai-security-across-all-platforms/
                          • 10/28/2026
                            01:00 PM
                            10/28/2026
                            [AMERICAS:] Secure AI Everywhere: Visibility, governance and protection for the agentic era
                            https://www.truthinit.com/index.php/channel/2126/securing-ai-across-the-americas-strategies-and-insights/
                          • 10/28/2026
                            01:00 PM
                            10/28/2026
                            EnvZero: Near-Zero Time to Resolution--Live Agentic Remediation for Failed and Drifted Infrastructure
                            https://www.truthinit.com/index.php/channel/2179/envzero-near-zero-time-to-resolution-live-agentic-remediation-for-failed-and-drifted-infrastructure/
                          • 11/04/2026
                            11:00 AM
                            11/04/2026
                            Leveraging CISA’s Zero Trust Maturity Model in an AI-Driven Landscape
                            https://www.truthinit.com/index.php/channel/2149/leveraging-cisas-zero-trust-maturity-model-in-an-ai-driven-landscape/
                          • 11/04/2026
                            11:00 AM
                            11/04/2026
                            Aligning Agentic Intent: Understanding Your Agents' Purpose vs. Their Actions
                            https://www.truthinit.com/index.php/channel/2158/aligning-agentic-intent-understanding-your-agents-purpose-vs-their-actions/
                          • 11/05/2026
                            02:00 PM
                            11/05/2026
                            HUMAN Dialogue: Embracing the Rise of the Agentic Consumer in AI
                            https://www.truthinit.com/index.php/channel/2160/human-dialogue-embracing-the-rise-of-the-agentic-consumer-in-ai/
                          • 11/05/2026
                            02:00 PM
                            11/05/2026
                            Reclaim Your Evenings: Leverage Data Intelligence to Minimize Risk and Boost AI Adoption
                            https://www.truthinit.com/index.php/channel/2172/reclaim-your-evenings-leverage-data-intelligence-to-minimize-risk-and-boost-ai-adoption/
                          • 11/19/2026
                            01:00 PM
                            11/19/2026
                            360View: Govern, Secure & Recover Your Microsoft 365 Environment
                            https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                          Truth in IT
                          • Sponsor
                          • About Us
                          • Terms of Service
                          • Privacy Policy
                          • Contact Us
                          • Preference Management
                          Desktop version
                          Standard version