MANUFACTURING EBOOK
FIPS 140-3 + CMMC: The On-Premises Guide for Defense Manufacturers
-
20+ page guide • CMMC + NIST 800-171 • WatchGuard FIPS 140-3 implementation
DoD CIO 110
Security requirements form the current CMMC Level 2 baseline under NIST SP 800-171 Revision 2.
DoD CIO
All FIPS 140-2 validation certificates move to NIST’s Historical List.
NIST
Watchguard v12. 11
WatchGuard supports FIPS 140-3 on listed Firebox hardware in a compliant configuration.
Watchguard
KEY TAKEAWAYS
CMMC Defines the Controls.
Architecture Defines the Boundary.
CMMC compliance becomes much easier to operate when leaders know where CUI lives, which systems belong inside scope, and how each security component supports that boundary. This guide connects the regulatory requirements to the infrastructure decisions that make them work.
- CMMC Level 2 currently aligns to 110 NIST SP 800-171 Revision 2 requirements. The controls establish what an in-scope environment must protect.
- A defined CUI boundary helps contain assessment scope. Users, systems, and workflows that never touch CUI can remain outside the enclave when the architecture and data flows support that separation.
- WatchGuard FIPS 140-3 requires the right combination of hardware, firmware, and configuration. Fireware v12.11.x supports the current FIPS 140-3 track on listed Firebox models.
- FIPS mode changes how the firewall operates. WatchGuard Cloud management, visibility, monitoring, and logging are not supported while the Firebox operates in FIPS mode.
- Ownership matters after implementation. A customer-owned enclave keeps the environment, credentials, and compliance infrastructure under the contractor’s control if the IT relationship changes.
Where FIPS Meets the Firewall.
01 THE CURRENT STATE
Phase II Moved. Your CUI Protection Requirements Did Not.
CMMC changed again in 2026, but defense contractors still need a defensible security environment. The current Phase I model keeps NIST SP 800-171 Revision 2 at the center of Level 2 protection.
The 110 Controls Still Apply
Current CMMC Level 2 self-assessments evaluate the 110 security requirements in NIST SP 800-171 Revision 2. Defense contractors still need the technical controls, documentation, and evidence to support them.
Scope Drives Complexity
CUI scattered across email, shared drives, workstations, cloud platforms, and production systems expands the environment that must meet the standard. A deliberate enclave keeps regulated workflows contained.
The FIPS Transition Is Here
NIST places all FIPS 140-2 certificates on its Historical List September 22, 2026. WatchGuard already directs new FIPS deployments to supported FIPS 140-3 hardware and Fireware.
02 THE STANDARDS
CMMC Sets the Security Requirement.
FIPS Validates the Cryptography.
The two standards solve different parts of the same problem. CMMC defines cybersecurity requirements for protecting federal information in contractor environments. FIPS 140-3 establishes security requirements for cryptographic modules used to protect sensitive federal information.
What Is CMMC?
The Cybersecurity Maturity Model Certification program establishes cybersecurity requirements for organizations in the defense supply chain that handle Federal Contract Information or Controlled Unclassified Information. Current Level 2 requirements incorporate the 110 security requirements from NIST SP 800-171 Revision 2.
What Is FIPS 140-3?
FIPS 140-3 is the current federal security standard for cryptographic modules. It defines requirements across areas such as cryptographic interfaces, authentication, firmware security, physical security, sensitive parameter management, and self-tests.
What Does CMMC Level 2 Require?
Current Level 2 self-assessment covers 110 NIST SP 800-171 Revision 2 security requirements for environments that process, store, or transmit CUI. The organization must define the assessed boundary and maintain evidence that the requirements operate as documented.
When Does FIPS-Validated Cryptography Matter?
NIST SP 800-171 requires FIPS-validated cryptography when cryptography protects the confidentiality of CUI. That makes the validation status and approved configuration of the cryptographic module part of the technical compliance decision.
What Changes in WatchGuard FIPS Mode?
A WatchGuard Firebox in FIPS mode operates differently from a standard deployment. Administrators use the local Web UI or CLI, WatchGuard Cloud capabilities become unavailable, and the appliance runs required FIPS self-tests at startup.
What Is a CUI Enclave?
A CUI enclave isolates the users, systems, and workflows that handle regulated information from general corporate operations. A properly defined enclave can keep unrelated business systems outside the CMMC boundary and concentrate security investment where CUI actually exists.
CMMC + FIPS 140-3, Side by Side
| Attribute | CMMC | FIPS 140-3 |
|---|---|---|
| What it is | Defense cybersecurity program | Federal cryptographic module standard |
| Primary purpose | Verify protection of FCI and CUI | Establish requirements for validated cryptographic modules |
| Level 2 foundation | 110 NIST SP 800-171 Rev. 2 requirements under the current Phase I model | Supports validated cryptography where encryption protects CUI confidentiality |
| Applies to | The defined systems, users, assets, and workflows within the CMMC boundary | Cryptographic modules and their approved operating configuration |
| Evidence | Assessment results, documentation, technical evidence, and affirmation | Validated module plus operation within its approved security policy |
| Business question | Have we defined and protected the right environment? | Are we using validated cryptography correctly inside that environment? |
Turn CMMC requirement pressure into a build plan.
03 THE OPERATING REALITY
Compliance Continues After the Architecture Goes Live..
A compliant environment needs more than an installation project. Defense contractors must maintain controls, evidence, system boundaries, and documented changes as technology and operations evolve.DoD CIO 110
Security requirements remain in the current CMMC Level 2 baseline.
DoD CIO
The current Phase I Level 2 self-assessment cycle runs every three years.
DoD CIO
Watchguard 180 Days
Permitted Level 2 POA&M items must close within 180 days under the current program.
Watchguard
04 The Playbook
The 6-Step On-Premises CMMC Build Plan.
The guide moves from scope to implementation so IT leaders can see how the individual technical decisions connect.STEP 01
Define the CUI Boundary
- Identify where CUI enters, moves, lives, and leaves.
- Map every user, system, workflow, and third party that touches it.
- Keep unrelated commercial operations outside the boundary where architecture allows.
STEP 02
Own the Enclave
- Keep the environment under company control.
- Retain master credentials and administrative ownership.
- Build portability into the architecture from the start.
03
Hardware/Firmware
Select supported WatchGuard hardware and the Fireware version that aligns with the required FIPS validation track.
In the full guide
04
Enable FIPS Mode
Understand the CLI process, reboot behavior, startup self-tests, and verification required when activating FIPS mode.
In the full guide
05
Lockdown
Plan around the local management requirements and features that FIPS mode disables before they become a surprise.
In the full guide
06
Validate + Preserve
Verify VPN settings, cryptography, authentication, and certificates, then document changes and retain evidence.
In the full guide
Customer Success Story
ACMT Achieves a 100% SPRS Score With a Customer-Owned CUI Enclave
ACMT needed an environment that could support defense requirements without handing ownership of its compliance infrastructure to an outside provider. CompassMSP helped ACMT isolate CUI inside a customer-controlled architecture using FIPS-encrypted firewalls, compliant networking, and clearly defined boundaries.ACMT achieved a perfect Supplier Performance Risk System score, validating the strength of its CMMC-aligned security environment.
External transfers of CUI. All regulated data remained inside ACMT’s controlled environment and under the company's ownership.
Customer-owned enclave isolated CUI from general corporate traffic while giving ACMT full control over its compliance environment.
Download Your Copy
Free Download
Get the Complete FIPS 140-3 + CMMC Guide
20+ pages • PDF
Built for defense manufacturers and IT leaders
Build a CUI Enclave You Control
See how to define the boundary around CUI without forcing every corporate system into the same compliance scope. The guide explains what belongs inside the enclave, what can remain outside, and why ownership of the firewall, credentials, and environment matters.
Choose the Correct WatchGuard FIPS Track
See how WatchGuard hardware, Fireware versions, and FIPS validation connect. The guide covers the active FIPS 140-3 path, the legacy FIPS 140-2 track, FIPS-mode limitations, startup testing, zeroization, VPN configuration, and evidence requirements.
Operate Compliance After Assessment
Learn what to evaluate in an ongoing IT and cybersecurity partner, including enclave ownership, documented access, 24/7 coverage, FIPS fluency, CMMC implementation expertise, and a clear transition plan.
THE FINE PRINT NEWSLETTER
Compliance Rules Move. Your Program Has to Keep Up.
FAQs
Answers to FIPS 140-3, CMMC + WatchGuard Questions
CMMC architecture gets technical quickly. These answers cover the questions that defense manufacturers and IT leaders should resolve before choosing hardware, defining an enclave, or changing a production environment.
What Is FIPS 140-3, and Why Does It Matter for CMMC?
FIPS 140-3 establishes federal security requirements for cryptographic modules. CMMC and NIST SP 800-171 require FIPS-validated cryptography when cryptography protects the confidentiality of CUI, so contractors need to confirm that the cryptographic technology they deploy carries an appropriate validation and operates within its approved configuration.
Does CMMC Level 2 Require FIPS-Validated Cryptography?
Yes, when cryptography protects the confidentiality of CUI. The requirement applies to the cryptographic protection, so simply enabling encryption does not establish compliance. The organization must use validated cryptography where the requirement applies.
Are WatchGuard Firewalls CMMC / NIST SP 800-171 Compliant?
Yes. Certain WatchGuard Firebox models can support CMMC Level 2 and NIST SP 800-171 requirements when they use the correct FIPS-validated hardware, firmware, and configuration. WatchGuard Fireboxes can provide the network segmentation, access controls, logging, VPN protection, and FIPS-validated cryptography needed within a properly designed CUI environment.
For modern deployments, the hardware and firmware combination matters. CompassMSP’s FIPS 140-3 guidance identifies supported WatchGuard Firebox models running Fireware v12.11 and subsequent v12.11.x minor releases as the appropriate validation track. FIPS mode must also be enabled, and the firewall configured with approved cryptographic algorithms, key lengths, VPN settings, and administrative controls.
A WatchGuard firewall alone does not make an organization CMMC or NIST SP 800-171 compliant. Compliance depends on how the entire CUI environment is scoped, configured, documented, monitored, and maintained. For organizations pursuing CMMC Level 2, the firewall often serves as a critical enforcement point for defining and protecting the compliance boundary.
Is FIPS 140-2 Still Valid in 2026?
FIPS 140-2 certificates remain active through September 21, 2026. NIST moves all remaining FIPS 140-2 certificates to the Historical List on September 22, 2026. NIST notes that historical modules may continue in existing systems, while federal agencies determine their transition policies.
Which WatchGuard Fireboxes Support FIPS 140-3?
WatchGuard currently supports FIPS 140-3 with Fireware v12.11.x on the listed Firebox T Series and M Series models. Organizations should confirm the exact hardware model and Fireware version against WatchGuard’s current FIPS support documentation before deployment.
Can I Manage a FIPS-Enabled WatchGuard Firebox Through WatchGuard Cloud?
No. WatchGuard states that FIPS mode does not support WatchGuard Cloud management, visibility, monitoring, or logging. Administrators manage the Firebox locally through the Fireware Web UI or the CLI.
How Do I Enable FIPS Mode on a WatchGuard Firebox?
WatchGuard requires administrators to enable FIPS mode through the Fireware CLI with the fips enable command. The Firebox immediately reboots and runs its required FIPS self-tests. Administrators can verify the operating state with the show fips command.
What Happens if a Firebox Fails a FIPS Startup Self-Test?
The Firebox records an error and shuts down if a required startup self-test fails. WatchGuard does not allow the appliance to continue operating in that failed FIPS state.
What Is a CMMC Compliance Enclave?
A CMMC enclave is a defined environment that isolates CUI-handling users, systems, and workflows from general corporate operations. The architecture helps contractors apply strict controls to the environment where CUI exists, rather than automatically pulling every business system into the same scope.
What Is the Difference Between a Customer-Owned and Provider-Owned CUI Enclave?
A provider-owned model places the compliance environment on infrastructure controlled by the service provider. A customer-owned model places the environment under the contractor’s control, with the contractor retaining the infrastructure, administrative rights, credentials, and portability needed to change providers without surrendering the environment itself.
What Should Be Inside a CMMC Level 2 Boundary?
The boundary should account for systems, users, assets, and workflows that process, store, or transmit CUI, along with relevant security protection assets and services that support that environment. The correct boundary depends on the organization’s architecture and CUI data flows.
What Is the Current CMMC Status in 2026?
DoD suspended implementation of Phase II on July 13, 2026 and currently remains in Phase I. Under the current model, Level 2 uses a self-assessment every three years against the 110 NIST SP 800-171 Revision 2 requirements, with annual affirmation. The suspension did not eliminate the underlying requirement to protect CUI.
What Should I Look for in an MSP Helping With CMMC?
Look for a provider that can connect compliance requirements to the systems your business actually uses. Evaluate who owns the enclave, who holds administrative credentials, how the provider documents privileged access, how it staffs support, whether it understands the correct FIPS validation track, and how it manages evidence and change control. A Cyber AB Registered Practitioner Organization provides implementation consulting but does not conduct certified CMMC assessments.
Featured Resources
Practical guidance for defense manufacturers working through CUI protection, NIST 800-171, CMMC, and infrastructure decisions.
Cybersecurity Manufacturing eBooks
FIPS 140-3 + CMMC: The On-Premises Guide for Defense Manufacturers
Download the FIPS 140-3 + CMMC guide for defense manufacturers. Learn about WatchGuard Firebox requirements, CUI enclave design, and NIST 800-171 scoping.
Compliance & Risk Manufacturing Articles 7 min read
CMMC Update: The Certification Is Suspended. The Standard Is Not.
CMMC Phase II certification is suspended, but security obligations remain. Companies must continue implementing NIST 800-171 controls to avoid legal risks.
Compliance & Risk Manufacturing Articles 5 min read
CMMC Rev. 3 Is Coming: What the New Rule Means for Defense Contractors
Prepare for the transition to CMMC Rev. 3. Understand the upcoming changes and learn how to ensure your organization's cybersecurity compliance remains robust.
Compliance & Risk Manufacturing Articles 7 min read

