Go Back Up
cmmc-watchguard-ebook-mockup

MANUFACTURING EBOOK

FIPS 140-3 + CMMC: The On-Premises Guide for Defense Manufacturers

Build a customer-owned CUI enclave, choose the right FIPS validation track, and understand exactly what changes operationally when a WatchGuard Firebox enters FIPS mode.
  • 20+ page guide • CMMC + NIST 800-171 • WatchGuard FIPS 140-3 implementation
Next Section
padlock-shield
110 Security requirements form the current CMMC Level 2 baseline under NIST SP 800-171 Revision 2.
DoD CIO

Security requirements form the current CMMC Level 2 baseline under NIST SP 800-171 Revision 2.
DoD CIO

calendar-time
09/22/26 All FIPS 140-2 validation certificates move to NIST’s Historical List.
NIST

All FIPS 140-2 validation certificates move to NIST’s Historical List.
NIST

star-badge
v12.11 WatchGuard supports FIPS 140-3 on listed Firebox hardware in a compliant configuration.
Watchguard

WatchGuard supports FIPS 140-3 on listed Firebox hardware in a compliant configuration.
Watchguard

fips-manufacturing-cmmc

KEY TAKEAWAYS

CMMC Defines the Controls.
Architecture Defines the Boundary.

CMMC compliance becomes much easier to operate when leaders know where CUI lives, which systems belong inside scope, and how each security component supports that boundary. This guide connects the regulatory requirements to the infrastructure decisions that make them work.

  • CMMC Level 2 currently aligns to 110 NIST SP 800-171 Revision 2 requirements. The controls establish what an in-scope environment must protect.

  • A defined CUI boundary helps contain assessment scope. Users, systems, and workflows that never touch CUI can remain outside the enclave when the architecture and data flows support that separation.

  • WatchGuard FIPS 140-3 requires the right combination of hardware, firmware, and configuration.  Fireware v12.11.x supports the current FIPS 140-3 track on listed Firebox models.

  • FIPS mode changes how the firewall operates. WatchGuard Cloud management, visibility, monitoring, and logging are not supported while the Firebox operates in FIPS mode.

  • Ownership matters after implementation. A customer-owned enclave keeps the environment, credentials, and compliance infrastructure under the contractor’s control if the IT relationship changes.

Watchguard-Compass-Partner
WATCHGUARD PARTNER

Where FIPS Meets the Firewall.

CompassMSP designs, deploys, and manages WatchGuard network security as part of a broader cybersecurity and compliance strategy. From Firebox configuration and FIPS requirements to ongoing policy management, we connect the technology to the controls your environment needs.
What Does CMMC Level 2 Require?

Current Level 2 self-assessment covers 110 NIST SP 800-171 Revision 2 security requirements for environments that process, store, or transmit CUI. The organization must define the assessed boundary and maintain evidence that the requirements operate as documented.

When Does FIPS-Validated Cryptography Matter?

NIST SP 800-171 requires FIPS-validated cryptography when cryptography protects the confidentiality of CUI. That makes the validation status and approved configuration of the cryptographic module part of the technical compliance decision.

What Changes in WatchGuard FIPS Mode?

A WatchGuard Firebox in FIPS mode operates differently from a standard deployment. Administrators use the local Web UI or CLI, WatchGuard Cloud capabilities become unavailable, and the appliance runs required FIPS self-tests at startup.

What Is a CUI Enclave?

A CUI enclave isolates the users, systems, and workflows that handle regulated information from general corporate operations. A properly defined enclave can keep unrelated business systems outside the CMMC boundary and concentrate security investment where CUI actually exists.

CMMC + FIPS 140-3, Side by Side

One defines the security program. The other validates a critical part of the technology protecting it.
CMMC program status is based on current DoD guidance. FIPS descriptions align with NIST’s published standard.

Attribute CMMC FIPS 140-3
What it is Defense cybersecurity program Federal cryptographic module standard
Primary purpose Verify protection of FCI and CUI Establish requirements for validated cryptographic modules
Level 2 foundation 110 NIST SP 800-171 Rev. 2 requirements under the current Phase I model Supports validated cryptography where encryption protects CUI confidentiality
Applies to The defined systems, users, assets, and workflows within the CMMC boundary Cryptographic modules and their approved operating configuration
Evidence Assessment results, documentation, technical evidence, and affirmation Validated module plus operation within its approved security policy
Business question Have we defined and protected the right environment? Are we using validated cryptography correctly inside that environment?
cmmc-watchguard-ebook-mockup-inside

Turn CMMC requirement pressure into a build plan.

The full guide maps the CUI boundary, customer-owned enclave model, WatchGuard hardware and firmware tracks, FIPS-mode limitations, validation steps, client results, and the questions every defense manufacturer should ask an IT partner.

03 THE OPERATING REALITY

Compliance Continues After the Architecture Goes Live..

A compliant environment needs more than an installation project. Defense contractors must maintain controls, evidence, system boundaries, and documented changes as technology and operations evolve.
padlock-shield
110 Security requirements remain in the current CMMC Level 2 baseline.
DoD CIO

Security requirements remain in the current CMMC Level 2 baseline.
DoD CIO

time-lapse
3 Years The current Phase I Level 2 self-assessment cycle runs every three years.
DoD CIO

The current Phase I Level 2 self-assessment cycle runs every three years.
DoD CIO

list-timeline
180Days Permitted Level 2 POA&M items must close within 180 days under the current program.
Watchguard

Permitted Level 2 POA&M items must close within 180 days under the current program.
Watchguard

04 The Playbook

The 6-Step On-Premises CMMC Build Plan.

The guide moves from scope to implementation so IT leaders can see how the individual technical decisions connect.

STEP 01

Define the CUI Boundary

  • Identify where CUI enters, moves, lives, and leaves.

  • Map every user, system, workflow, and third party that touches it.

  • Keep unrelated commercial operations outside the boundary where architecture allows.

STEP 02

Own the Enclave

  • Keep the environment under company control.

  • Retain master credentials and administrative ownership.

  • Build portability into the architecture from the start.

03

Hardware/Firmware

Select supported WatchGuard hardware and the Fireware version that aligns with the required FIPS validation track.

In the full guide

04

Enable FIPS Mode

Understand the CLI process, reboot behavior, startup self-tests, and verification required when activating FIPS mode.

In the full guide

05

Lockdown

Plan around the local management requirements and features that FIPS mode disables before they become a surprise.

In the full guide

06

Validate + Preserve

Verify VPN settings, cryptography, authentication, and certificates, then document changes and retain evidence.

In the full guide

acmt-image-case-study

Customer Success Story

ACMT Achieves a 100% SPRS Score With a Customer-Owned CUI Enclave

ACMT needed an environment that could support defense requirements without handing ownership of its compliance infrastructure to an outside provider. CompassMSP helped ACMT isolate CUI inside a customer-controlled architecture using FIPS-encrypted firewalls, compliant networking, and clearly defined boundaries.
100% ACMT achieved a perfect Supplier Performance Risk System score, validating the strength of its CMMC-aligned security environment.

ACMT achieved a perfect Supplier Performance Risk System score, validating the strength of its CMMC-aligned security environment.

0 External transfers of CUI. All regulated data remained inside ACMT’s controlled environment and under the company's ownership.

External transfers of CUI. All regulated data remained inside ACMT’s controlled environment and under the company's ownership.

1 Customer-owned enclave isolated CUI from general corporate traffic while giving ACMT full control over its compliance environment.

Customer-owned enclave isolated CUI from general corporate traffic while giving ACMT full control over its compliance environment.

Download Your Copy

Free Download

Get the Complete FIPS 140-3 + CMMC Guide

You have seen the architecture. The full guide gives you the implementation details in a format that your IT team, security leaders, and executives can use together.

cmmc-watchguard-ebook-mockup-inside


20+ pages • PDF

Built for defense manufacturers and IT leaders

Build a CUI Enclave You Control

See how to define the boundary around CUI without forcing every corporate system into the same compliance scope. The guide explains what belongs inside the enclave, what can remain outside, and why ownership of the firewall, credentials, and environment matters.

Choose the Correct WatchGuard FIPS Track

See how WatchGuard hardware, Fireware versions, and FIPS validation connect. The guide covers the active FIPS 140-3 path, the legacy FIPS 140-2 track, FIPS-mode limitations, startup testing, zeroization, VPN configuration, and evidence requirements.

Operate Compliance After Assessment

Learn what to evaluate in an ongoing IT and cybersecurity partner, including enclave ownership, documented access, 24/7 coverage, FIPS fluency, CMMC implementation expertise, and a clear transition plan.

Next Section

THE FINE PRINT NEWSLETTER

Compliance Rules Move. Your Program Has to Keep Up.

Subscribe to The Fine Print for practical updates on CMMC, NIST, federal compliance, cybersecurity, and the decisions that affect regulated businesses.

FAQs

Answers to FIPS 140-3, CMMC + WatchGuard Questions

CMMC architecture gets technical quickly. These answers cover the questions that defense manufacturers and IT leaders should resolve before choosing hardware, defining an enclave, or changing a production environment.

What Is FIPS 140-3, and Why Does It Matter for CMMC?

FIPS 140-3 establishes federal security requirements for cryptographic modules. CMMC and NIST SP 800-171 require FIPS-validated cryptography when cryptography protects the confidentiality of CUI, so contractors need to confirm that the cryptographic technology they deploy carries an appropriate validation and operates within its approved configuration.

Does CMMC Level 2 Require FIPS-Validated Cryptography?

Yes, when cryptography protects the confidentiality of CUI. The requirement applies to the cryptographic protection, so simply enabling encryption does not establish compliance. The organization must use validated cryptography where the requirement applies.

Are WatchGuard Firewalls CMMC / NIST SP 800-171 Compliant?

Yes. Certain WatchGuard Firebox models can support CMMC Level 2 and NIST SP 800-171 requirements when they use the correct FIPS-validated hardware, firmware, and configuration. WatchGuard Fireboxes can provide the network segmentation, access controls, logging, VPN protection, and FIPS-validated cryptography needed within a properly designed CUI environment.

For modern deployments, the hardware and firmware combination matters. CompassMSP’s FIPS 140-3 guidance identifies supported WatchGuard Firebox models running Fireware v12.11 and subsequent v12.11.x minor releases as the appropriate validation track. FIPS mode must also be enabled, and the firewall configured with approved cryptographic algorithms, key lengths, VPN settings, and administrative controls.

A WatchGuard firewall alone does not make an organization CMMC or NIST SP 800-171 compliant. Compliance depends on how the entire CUI environment is scoped, configured, documented, monitored, and maintained. For organizations pursuing CMMC Level 2, the firewall often serves as a critical enforcement point for defining and protecting the compliance boundary.

Is FIPS 140-2 Still Valid in 2026?

FIPS 140-2 certificates remain active through September 21, 2026. NIST moves all remaining FIPS 140-2 certificates to the Historical List on September 22, 2026. NIST notes that historical modules may continue in existing systems, while federal agencies determine their transition policies.

Which WatchGuard Fireboxes Support FIPS 140-3?

WatchGuard currently supports FIPS 140-3 with Fireware v12.11.x on the listed Firebox T Series and M Series models. Organizations should confirm the exact hardware model and Fireware version against WatchGuard’s current FIPS support documentation before deployment.

Can I Manage a FIPS-Enabled WatchGuard Firebox Through WatchGuard Cloud?

No. WatchGuard states that FIPS mode does not support WatchGuard Cloud management, visibility, monitoring, or logging. Administrators manage the Firebox locally through the Fireware Web UI or the CLI.

How Do I Enable FIPS Mode on a WatchGuard Firebox?

WatchGuard requires administrators to enable FIPS mode through the Fireware CLI with the fips enable command. The Firebox immediately reboots and runs its required FIPS self-tests. Administrators can verify the operating state with the show fips command.

What Happens if a Firebox Fails a FIPS Startup Self-Test?

The Firebox records an error and shuts down if a required startup self-test fails. WatchGuard does not allow the appliance to continue operating in that failed FIPS state.

What Is a CMMC Compliance Enclave?

A CMMC enclave is a defined environment that isolates CUI-handling users, systems, and workflows from general corporate operations. The architecture helps contractors apply strict controls to the environment where CUI exists, rather than automatically pulling every business system into the same scope.

What Is the Difference Between a Customer-Owned and Provider-Owned CUI Enclave?

A provider-owned model places the compliance environment on infrastructure controlled by the service provider. A customer-owned model places the environment under the contractor’s control, with the contractor retaining the infrastructure, administrative rights, credentials, and portability needed to change providers without surrendering the environment itself.

What Should Be Inside a CMMC Level 2 Boundary?

The boundary should account for systems, users, assets, and workflows that process, store, or transmit CUI, along with relevant security protection assets and services that support that environment. The correct boundary depends on the organization’s architecture and CUI data flows.

What Is the Current CMMC Status in 2026?

DoD suspended implementation of Phase II on July 13, 2026 and currently remains in Phase I. Under the current model, Level 2 uses a self-assessment every three years against the 110 NIST SP 800-171 Revision 2 requirements, with annual affirmation. The suspension did not eliminate the underlying requirement to protect CUI.

What Should I Look for in an MSP Helping With CMMC?

Look for a provider that can connect compliance requirements to the systems your business actually uses. Evaluate who owns the enclave, who holds administrative credentials, how the provider documents privileged access, how it staffs support, whether it understands the correct FIPS validation track, and how it manages evidence and change control. A Cyber AB Registered Practitioner Organization provides implementation consulting but does not conduct certified CMMC assessments.

Featured Resources

Stay Current on CMMC + Defense Cybersecurity

Practical guidance for defense manufacturers working through CUI protection, NIST 800-171, CMMC, and infrastructure decisions.
FIPS 140-3 + CMMC: The On-Premises Guide for Defense Manufacturers

Cybersecurity Manufacturing eBooks

FIPS 140-3 + CMMC: The On-Premises Guide for Defense Manufacturers

Download the FIPS 140-3 + CMMC guide for defense manufacturers. Learn about WatchGuard Firebox requirements, CUI enclave design, and NIST 800-171 scoping.
CMMC Update: The Certification Is Suspended. The Standard Is Not.

Compliance & Risk Manufacturing Articles 7 min read

CMMC Update: The Certification Is Suspended. The Standard Is Not.

CMMC Phase II certification is suspended, but security obligations remain. Companies must continue implementing NIST 800-171 controls to avoid legal risks.
CMMC Rev. 3 Is Coming: What the New Rule Means for Defense Contractors

Compliance & Risk Manufacturing Articles 5 min read

CMMC Rev. 3 Is Coming: What the New Rule Means for Defense Contractors

Prepare for the transition to CMMC Rev. 3. Understand the upcoming changes and learn how to ensure your organization's cybersecurity compliance remains robust.
Where You Store Your CUI Data Matters More Than You Think

Compliance & Risk Manufacturing Articles 7 min read

Where You Store Your CUI Data Matters More Than You Think

Learn why owning your CUI enclave is crucial for compliance & data security. Discover the risks of vendor dependency and how to protect your DoD contracts.