COMPLIANCE STARTS HERE

cmmc space onboarding guide

Building Your Environment

Before we can provide you and your organization access to CMMC Space, we need to complete the following steps:

  • Verify DNS records

  • Identify Authorized Users

  • Conduct Background Checks

  • Sign Policy Agreements

In this guide, you’ll find links to all of our required documentation, as well as email templates you can provide to your organization to help guide them along the onboarding process.

If you feel like there are any places we could improve this process, please feel free to reach out. We want this to be as quick and easy as possible for you and your team.

verifying your domain

The first step to creating your domain is verifying your new domain. Don’t worry, we’ll handle this step. We’ll set up your new domain with SPF, DKIM, and DMARC.

While we’re setting up your domain, please follow the next few steps so that when your environment is up and running, you can log in immediately.

identifying authorized users

An “Authorized User” is any appropriately qualified individual you identify with a requirement to access CUI/FCI within CMMC Space for performing or assisting in a lawful Government purpose, according to the scope of their assigned duties. More information here about qualifying Authorized Users. 

Please feel free to use our provided Authorized User Template below. It contains an example of the required information we need. Once this is complete, please email this form to onboarding@atxdefense.com or upload it here.

ATX Defense will assume any name you add to the Authorized User List is an Authorized User.

Note: Any passwords provided will be temporary; all users will be required to reset their passwords upon first login.

background checks

Once you’ve identified who the users are going to be, CMMC requires these users to have undergone a background check. ATX Defense is happy to provide this service for your organization for $79 per user.

The only information we need is the name of the user(s), their email address(es), and their state of residence. They’ll receive an email from our background check service provider requesting further information.

If you’re interested in this service, please reach out to us at onboarding@atxdefense.com or use the form below.

policy agreements

All Authorized User must sign our CMMC Space policy agreements. Your organization’s signing authority will need to sign our Authorized Executive Policy Agreement. This affirms that an authorized executive will enforce our policies and procedures within CMMC Space.

The majority of your organization’s users will need to sign our Client User Policy Agreement. This agreement references other policies and agreements required for access to CMMC Space.

Consider identifying a “Power User” for your CMMC Space. Power Users receive free secondary accounts with limited administrative rights. Power Users are responsible for creating, modifying, and deleting Google Groups within your environment. They also have the ability to see the Security Panel in your CMMC Space Admin Console. They will need to sign our Power User Agreement.

We’ve created an email template containing instructions and links that you can send out to your organization if desired. All of the policies, procedures, and agreements mentioned in our CMMC Space User Agreements can be found here.

what’s next?

We will provision Google Workspace accounts and harden your tenant once everything mentioned previously is complete. We spin up new environments every Thursday

Once you can operate within CMMC Space, the next steps will be to:

  • Schedule a meeting to review your SSP and your responsibilities to review content on publicly accessible systems (if applicable) to ensure that it does not include CUI

  • Inventory all devices that will connect to your environment (we’ll cover this with your SSP)

  • Schedule quarterly meetings to update risk assessments and test incident response

This is the entirety of the client responsibility in our Shared Responsibility Matrix

Once your environment is complete, please direct your team to our New User Guide.

If you would like to schedule any training for your team, please reach out to us at onboarding@atxdefense.com. We’ll be more than happy to assist.

Send us your logo and we’ll add it to your environment, too!