Skip to content
Totem Support Center
  • Guides
  • ResourcesExpand
    • Request a Feature
    • Workshop Cohort FAQs
    • Release Notes
    • Billing
  • Contact Support
Totem Support Center

Workshop Cohort FAQs

The following is a non-exhaustive list of frequently asked questions by our CMMC workshop participants. If you have a question not listed here, please send your question to [email protected].

What is a process acting on behalf of an authorized user?

Refer to our blog on this topic: https://www.totem.tech/processes-acting-on-behalf-of-authorized-users/. 


What does it mean to sanitize FCI/CUI, and how do I do it?

Refer to our blog on this topic: https://www.totem.tech/cui-sanitization-and-destruction-requirements-for-cmmc/. 


What is device authentication in CMMC?

Refer to our blog on this topic: https://www.totem.tech/device-authentication-cmmc/. 


How do I perform and report my CMMC Level 1 self-assessment?

Refer to our blog on this topic: https://www.totem.tech/cmmc-level-1-self-assessment-reporting/.


How do I perform and report my NIST 800-171/CMMC Level 2 self-assessment (SPRS) score?

Refer to our blog on this topic: https://www.totem.tech/how-to-generate-and-report-your-dod-self-assessment-score/. 


Is there a difference between FAR 52.204-21 and CMMC Level 1?

Refer to our blog on this topic: https://www.totem.tech/cmmc-level-1/.


How do I know if CMMC is not applicable to me?

Refer to our blog on this topic: https://www.totem.tech/when-is-cmmc-not-applicable/. 


What is the difference between CMMC and FedRAMP?

Refer to our blog on this topic: https://www.totem.tech/what-the-heck-is-the-difference-between-fedramp-and-cmmc/.


What is an enclave?

Refer to our blog on the topic: https://www.totem.tech/cmmc-enclave/.


I use a VPN, am I good?

Bottom line: NO.  Commercial Virtual Private Networks (VPNs), like NordVPN, VPNpro, CyberGhost, Express VPN, etc. are simply an encrypted tunnel through the Internet that mask your workstation’s IP address and make it look like your workstation is physically somewhere else.  None of the features of any of these commercial VPNs fully satisfy any of the NIST 800-171 assessment objectives.  

A corporate-controlled VPN on the other hand may satisfy some of the assessment objectives, but it depends on the purpose of the VPN, how it is setup and managed by your organization, the encryption protocols used, and so on.  But simply turning on a VPN is not even necessarily a best security practice, let alone a practice that conforms to the FAR/DFARS/CMMC requirements. 


What are the consequences for failing to comply? 

Below is list of organizations the DoJ has fined for cybersecurity False Claims Act (FCA) violations:

OrganizationNumber of EmployeesDateSettlement / FineKey Violation & CUI ContextInformation Source
LOGZONE, Inc.<30June 2026$507,144Falsely certified NIST SP 800-171 compliance by self-attesting a perfect score of 110 in the DoD Supplier Performance Risk System (SPRS). A subsequent Defense Contract Audit Agency (DCAA) assessment revealed their actual score was -170.https://www.justice.gov/opa/pr/alabama-defense-contractor-agrees-pay-507144-resolve-false-claims-act-liability-relating
Aero Turbine Inc. (ATI) & Gallant Capital Partners<100July 2025$1,750,000Failed to implement mandatory NIST SP 800-171 security controls on an Air Force contract. Crucially leaked CUI by providing technical files to an unauthorized software firm based in Egypt. Private equity owner held jointly liable.https://www.justice.gov/opa/pr/california-defense-contractor-and-private-equity-firm-agree-pay-175m-resolve-false-claims
Illumina, Inc.9000+July 2025$9,800,000Sold genomic sequencing systems to federal agencies while falsely representing that the underlying software adhered to required government data security and cybersecurity standards.https://www.justice.gov/opa/pr/illumina-inc-pay-98m-resolve-false-claims-act-allegations-arising-cybersecurity
MORSECORP, Inc.<150March 2025$4,600,000Submitted inaccurate basic assessment scores to the SPRS database regarding CUI security controls. Continued to leave the false scores uncorrected after a third-party gap analysis explicitly proved they only met 22% of required NIST controls.https://www.justice.gov/opa/pr/defense-contractor-morsecorp-inc-agrees-pay-46-million-settle-cybersecurity-fraud
Swiss Automation, Inc.<300March 2025$421,234Precision machining subcontractor failed to safeguard ITAR-controlled technical blueprints and military drawings (CUI), resulting in unauthorized access by foreign nationals.https://www.justice.gov/opa/pr/illinois-precision-machining-company-agrees-pay-421234-resolve-alleged-false-claims-act
Pennsylvania State University35,000+October 2024$1,514,355Settled False Claims Act whistleblower allegations that it failed to implement required NIST SP 800-171 cybersecurity controls on contracts performed for the Department of Defense (DoD) and NASA between 2018 and 2023.https://www.justice.gov/usao-edpa/pr/penn-state-agrees-pay-125-million-resolve-false-claims-act-allegations-relating-non
Raytheon Company185,000+Post-2021$8,400,000Resolved liability under the False Claims Act for failing to implement mandatory cybersecurity controls and maintain secure systems as required by multiple federal contracts.https://www.justice.gov/opa/pr/raytheon-companies-and-nightwing-group-pay-84m-resolve-false-claims-act-allegations-relating
Comprehensive Health Services LLC (CHS)2000+March 2022$930,000Failed to store confidential medical records on a secure, firewalled server required by State Department and DoD contracts, instead hosting them on an unencrypted internal drive accessible to unauthorized staff.https://www.justice.gov/archives/opa/pr/medical-services-contractor-pays-930000-settle-false-claims-act-allegations-relating-medical
BAE Systems110,000+August 2026$36,000,000Multiple categories of ITAR violations, including BAE’s unauthorized exports of technical data to multiple countries, including in one instance to China; violations of terms, conditions, and provisos of several Directorate of Defense Trade Controls authorizations involving various countries; and unauthorized exports of defense articles, including technical data, designated as Significant Military Equipment.https://www.state.gov/releases/bureau-of-political-military-affairs/2026/08/u-s-department-of-state-concludes-36-million-settlement-resolving-export-violations-by-bae-systems-inc-bae/


  • Contact Support
  • Privacy Policy
  • Terms & Conditions

© 2026 Totem Support Center - WordPress Theme by Kadence WP

  • Guides
  • Resources
    • Request a Feature
    • Workshop Cohort FAQs
    • Release Notes
    • Billing
  • Contact Support