Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

NinjaOne: How MSPs Can Inherit CMMC Controls via FedRAMP

NinjaOne
07/10/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


inherit some of the controls that Ninja has. So, like, their FIPS encryption that they have, the boundary protection around the tools that they have, those types of things. I can inherit those in my SSP and say, okay, because they have their FedRAMP authorization, I can provide that as an example and the assessor will be like, okay, I'm not going to dig further because of the fact that they have that. And so that helps solve a lot of the technical controls around things like that. So, like, for when we put the agents on the client's machine for us to remote in, one of the challenges is obviously you want to make sure your remote access tool has a FIPS validated cryptography that's going to allow the remote access capabilities. And that's something that we leveraged through Ninja, which has been a huge help for us.

TL;DR

  • FedRAMP authorization is the only accreditation whose controls can be inherited during a CMMC assessment, reducing the technical burden on MSPs.
  • MSPs using NinjaOne can reference its FedRAMP status in their SSP, signaling to assessors that key controls like FIPS encryption are already satisfied.
  • Remote access tools must use FIPS-validated cryptography to meet CMMC requirements — NinjaOne's FedRAMP-backed tooling addresses this directly.

Summary

This short clip, drawn from a longer NinjaOne panel featuring MSP leaders from Executech and Axiom, highlights one of the most practical CMMC compliance advantages available to managed service providers: control inheritance through FedRAMP-authorized tooling. The speaker explains that FedRAMP authorization is the only accreditation whose controls can be directly inherited during the CMMC assessment process. Because NinjaOne holds FedRAMP authorization, MSP clients can reference that status in their System Security Plan (SSP) and expect assessors to accept it without requiring further technical scrutiny. Specific examples include FIPS-validated encryption and boundary protection — both critical requirements for DoD-adjacent environments. The speaker also addresses a common MSP challenge: ensuring that remote access agents deployed on client machines use FIPS-validated cryptography. NinjaOne's FedRAMP-backed remote access capability is cited as a direct solution to this requirement, reducing the compliance burden on the MSP and strengthening their overall CMMC posture. For MSPs pursuing or maintaining DoD contracts, this clip underscores the strategic value of selecting tools that carry FedRAMP authorization, as it can meaningfully reduce the scope and complexity of a CMMC assessment.

Chapters

0:00 - FedRAMP & Control Inheritance
0:16 - SSP Documentation & Assessors
0:32 - Remote Access & FIPS Requirements

Key Quotes

0:00 "... the only accreditation that can be inherited during your CMMC process."
0:05 "I can inherit some of the controls that Ninja has. So, like, their FIPS encryption that they have, the boundary protection around the tools that they have, those types of things."
0:16 "... because they have their FedRAMP authorization, I can provide that as an example and the assessor will be like, okay, I'm not going to dig further because of the fact that they have that."
0:41 "... you want to make sure your remote access tool has a FIPS validated cryptography that's going to allow the remote access capabilities. And that's something that we leveraged through Ninja, which has been a huge help for us."

FAQ

What does it mean to 'inherit' controls during a CMMC assessment?

Control inheritance means an MSP can reference a vendor's existing FedRAMP authorization in their System Security Plan to satisfy certain CMMC technical requirements — such as FIPS encryption or boundary protection — without needing to independently demonstrate compliance for those controls.

Why does FedRAMP matter specifically for CMMC compliance?

FedRAMP is the only accreditation recognized for control inheritance in the CMMC process. If an MSP's tooling holds FedRAMP authorization, assessors will generally accept that as evidence for the covered controls and will not dig further into those specific requirements.


Categories:
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Compliance & Governance
  • Security Operations
  • Getting Started
  • Best Practices
  • webinar_clip
  • CMMC compliance
  • FedRAMP authorization
  • control inheritance
  • FIPS-validated cryptography
  • MSP compliance strategy
  • remote access security
  • DoD contracts
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: NinjaOne: How MSPs Can Inherit CMMC Controls via FedRAMP

              XStreaminars (watch here)

              • Aug
                27

                Becoming Agent Ready with Cyera: Essential Strategies and Insights

                08/27/202601:00 PM ET
                • Sep
                  03

                  Verge.io: Can You Afford Your Next Storage Refresh?

                  09/03/202601:00 PM ET
                  More events

                  Industry Events (Sponsor Hosted)

                  • Aug
                    27

                    Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration

                    08/27/202601:00 PM ET
                    • Sep
                      23

                      Invisible Data: Understanding What Needs Protection

                      09/23/202601:00 PM ET
                      • Sep
                        29

                        Embrace AI Adoption While Maintaining Robust Security Measures

                        09/29/202612:00 PM ET
                        More events

                        Upcoming Webinar Calendar

                        • 08/27/2026
                          01:00 PM
                          08/27/2026
                          Becoming Agent Ready with Cyera: Essential Strategies and Insights
                          https://www.truthinit.com/index.php/channel/2081/becoming-agent-ready-with-cyera-essential-strategies-and-insights/
                        • 08/27/2026
                          01:00 PM
                          08/27/2026
                          Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration
                          https://www.truthinit.com/index.php/channel/2086/summer-of-satori-funfonefarms-transformation-of-fraud-into-seamless-integration/
                        • 09/02/2026
                          12:00 PM
                          09/02/2026
                          Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                          https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                        • 09/03/2026
                          01:00 PM
                          09/03/2026
                          Verge.io: Can You Afford Your Next Storage Refresh?
                          https://www.truthinit.com/index.php/channel/2082/verge-io-can-you-afford-your-next-storage-refresh/
                        • 09/23/2026
                          01:00 PM
                          09/23/2026
                          Invisible Data: Understanding What Needs Protection
                          https://www.truthinit.com/index.php/channel/2087/invisible-data-understanding-what-needs-protection/
                        • 09/29/2026
                          12:00 PM
                          09/29/2026
                          Embrace AI Adoption While Maintaining Robust Security Measures
                          https://www.truthinit.com/index.php/channel/2092/embrace-ai-adoption-while-maintaining-robust-security-measures/
                        • 09/30/2026
                          04:00 AM
                          09/30/2026
                          AI Command Center: Optimizing Visibility and Control in Your Operations
                          https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                        • 11/19/2026
                          01:00 PM
                          11/19/2026
                          360View: Govern, Secure & Recover Your Microsoft 365 Environment
                          https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version