The Defense Compliance ReportCMMC 2.0 & the Defense Industrial Base

CMMC Compliant Ticketing System: What Qualifies and What Your Tickets Must Prove

By The Defense Compliance Report Editorial Team — an independent trade publication on CMMC 2.0 and DIB compliance · Last verified September 2026

No ticketing system is "CMMC compliant" by itself — CMMC assesses your environment, not software. It depends on what lands in tickets and what the system protects. For Level 2, a cloud offering that processes, stores, or transmits controlled unclassified information (CUI) needs FedRAMP Moderate or higher, or DoD equivalency. Security protection data without CUI keeps the relevant service in scope but does not, by itself, require FedRAMP. (§170.19, Tables 3–4; §170.16(c)(2))

The tricky part is what actually reaches the tool. A help desk that was never meant to hold CUI can receive it one forwarded email at a time. Below: a table that sorts your help desk's next step, a dated list of exact offerings listed at FedRAMP Moderate or higher alongside lower-baseline comparisons, and free ticket templates built around assessment evidence.

Status as of September 24, 2026: The Department of War (DoW) — the name official sites now use for the Department of Defense (DoD) — suspended the move to CMMC Phase II on July 13, 2026. Its current program page still states that Phase I self-assessment requirements remain in place; no replacement Phase II date was located in the official materials checked. The implementation direction preserves safeguarding obligations, including DFARS 252.204-7012. Check your actual contract and modifications: an announcement is not itself a contract modification. What the suspension changed

Three terms, once. CMMC is the Cybersecurity Maturity Model Certification program. FedRAMP is the Federal Risk and Authorization Management Program, the government's security review for cloud services. DFARS is the Defense Federal Acquisition Regulation Supplement, where DoD contract clauses live.

This page is for you if you choose, run, or pay for the help desk at a defense contractor that handles CUI — or you're a managed service provider (MSP) whose ticketing system serves defense clients.

It's not for you if you only handle federal contract information (FCI), the basic contract data covered by CMMC Level 1. Start with our guide to the 15 basic safeguards in FAR 52.204-21 instead. Choosing a remote monitoring and management tool as well? Check its role alongside the help desk in our MSP requirements guide. Need the distinction between the two programs? See CMMC vs. FedRAMP.

Three quick checks before the table:

  1. Does your contract or subcontract require DFARS 252.204-7012? Check the clause, incorporated terms, flow-downs, and modifications—not just whether a PDF search finds "7012."
  2. Could anyone — a machinist, an engineer, a customer — email your support address a drawing, spec, or screenshot that contains CUI? Coming from a CUI system does not make every screenshot CUI.
  3. Does your help desk use a cloud service, including infrastructure you rent even when you administer the application yourself?

Three yeses mean you need to investigate the CUI-cloud row below before approving that use. An unknown answer stays unresolved; it is not evidence that the data is CUI—or that the service is safe for it.

CMMC compliant ticketing system: which path fits your tickets?

Your help desk's CMMC treatment turns on what it handles, what security functions it provides, and where the tool runs. The rules are in 32 CFR 170.19, the CMMC scoping section, and DFARS 252.204-7012. Find your row, then read the three rules under the table.

One more term first. Security protection data (SPD) is the rule's name for information used to protect your assessed environment: security-asset configuration data, logs generated by security protection assets, vulnerability status of in-scope systems, and passwords that grant access to that environment (32 CFR 170.4). Check whether your tickets hold it; ordinary IT information is not automatically SPD.

What your tickets handle — Where the tool runs — What the rule makes it — What you have to do
What your tickets handleWhere the tool runsWhat the rule makes itWhat you have to do
CUIA vendor's cloud (software as a service)A cloud service provider handling CUI (§170.19(c)(2), Table 4)The exact offering must be FedRAMP Authorized at Moderate or higher on the FedRAMP Marketplace, or meet DoD's equivalency standard (§170.16(c)(2)). The vendor must also meet the applicable incident duties in DFARS 7012 paragraphs (c)–(g). Document the customer responsibility matrix in your system security plan (SSP). Do not approve CUI use without that evidence; address any CUI already there under your incident procedure.
CUIServers you run inside your CUI boundaryA CUI asset (§170.19(c)(1), Table 3)Assess against all 110 Level 2 requirements across the system; they are not all native help desk features. No FedRAMP question for a genuinely on-premises app, but you own patching, backups, access, and logs — and any cloud hosting underneath still counts.
CUIAn MSP's own system that isn't a cloud serviceAn external service provider (ESP) handling CUIIts services are assessed inside your scope against all Level 2 requirements (§170.16(c)(3)). Document it in your SSP with the provider's service description and responsibility matrix.
Only SPD — no CUIAny cloud, or an MSP's systemThe provider's services are assessed as Security Protection Assets (Table 4); relevant contractor assets use Table 3They stay in scope and are assessed against the requirements relevant to the capabilities provided. FedRAMP is not required for SPD alone. Document the service description, responsibility matrix, SSP treatment, actual data use, and controls that keep CUI out.
Can handle CUI, but is not intended to because security policies, procedures, and practices are in placeA contractor assetPossibly a Contractor Risk Managed Asset (Table 3)Still in scope: document it in your inventory, SSP, and network diagram. The assessor reviews the SSP and may make a limited check when the documentation or other findings raise questions. A policy alone does not establish this category, and it is not a workaround for a cloud service actually handling CUI.
Neither CUI nor SPD (for example, facilities requests), with no security-protection roleA separated system or outside serviceThe outside service is not an ESP under Table 4; the contractor asset may be out of scope under Table 3For an out-of-scope contractor asset, justify that it cannot process, store, or transmit CUI, provides no security protection for CUI assets, and is physically or logically separated. No-CUI content alone does not establish all of that.
FCI only, and your contract points to Level 1AnywhereIn Level 1 scope if FCI goes into tickets (§170.19(b))The 15 Level 1 requirements come from FAR 52.204-21(b)(1). The DFARS 7012 cloud requirement concerns covered defense information, not FCI-only use.
Unknown data or security roleAnywhereUnresolved—not automatically CUI, SPD-only, or out of scopeTrace the data paths, determine the data's status and the service's role, and assign an owner to every missing answer. Do not approve an unresolved service for CUI use.

Rule 1: Not sure stays unresolved. Until you've traced where ticket data actually goes (two sections down), don't treat "we don't know" as "no CUI." Don't turn it into a legal finding that CUI is present, either. Use the trace to establish the facts, keep unapproved CUI flows closed, and put an owner and a due date on each missing answer. That's our practical decision method, not a new asset category in the rule.

Rule 2: Encrypting CUI doesn't change the answer. The DoW's CMMC FAQ says encrypted CUI keeps its CUI status (B-A8). It also says a cloud offering that isn't FedRAMP Moderate or equivalent can't store encrypted CUI (E-A2).

Rule 3: "No CUI" isn't "out of scope." The rule counts an outside provider as an ESP when either CUI or security protection data sits on its systems (§170.4). A help desk holding those passwords or security configurations for your assessed environment is doing security work. Document its relevant services in your SSP.

Here's how the first row sneaks up on people. Say you run a 40-person machine shop. Your email lives in a CUI-approved environment. Your help desk is a commercial cloud tool with no FedRAMP Moderate-or-higher record or established DoD equivalency. A machinist emails support: "This program won't load," with the part drawing attached — and the drawing is marked CUI. The help desk's email-to-ticket feature copies that drawing into the vendor's cloud. Your email system did its job. Your help desk just became a CUI system, and nobody chose it.

The fix isn't always a new help desk. You might stop importing attachments, route engineering questions to a queue inside your CUI environment, or move only those tickets. The next sections show how to tell which. Blocking attachments alone is not enough if CUI can still arrive in a subject line, pasted text, or quoted reply.

The right fix for your help desk isn't the same for every contractor. Whether you need a CUI enclave, a government cloud tenant such as Microsoft 365 Government Community Cloud High (GCC High), an MSP or managed security service provider (MSSP) that runs the tool and documents its responsibilities, or a Registered Provider Organization (RPO) to help document your scope depends on your required CMMC level, whether you handle FCI or CUI, your assessment type, your cloud and IT environment, and your contract timeline. The contract clause sets your level, not a checklist. Because a general answer can't resolve those for you, use The Defense Compliance Report's Find My CMMC Path tool to map your situation to the right kind of help before you request quotes — and do not submit CUI, drawings, or sensitive contract details.

Answer a few questions about your contract, CUI, environment, timeline, and budget, and see which path and kind of help fit your situation.

See which kind of help your setup points to →

Which help desks hold FedRAMP Moderate or higher? (checked September 24, 2026)

As of September 24, 2026, government offerings from ServiceNow, Atlassian, Ivanti, BMC, OpenText, Oracle, Salesforce, Microsoft, and Halo hold FedRAMP Class C (Moderate) or Class D (High) on the FedRAMP Marketplace. Zendesk's help desk is certified too, but only at Class B (Low), which is below the Moderate baseline DFARS 7012 names for CUI.

How to read the labels. FedRAMP now uses "Certified" for the status its current definitions recognize as meeting FedRAMP-authorization requirements. Its February 2026 notice NTC-0004 introduced Class B for Low and the old LI-SaaS (Low-Impact Software as a Service) baseline, Class C for Moderate, and Class D for High. The live records below still show the baseline in parentheses. FedRAMP also says the 20x Class C baseline replaces 20x Moderate. Read the exact offering's certification, baseline, and boundary—not just its letter class. A Class C or D listing is not, by itself, proof that your deployment meets CMMC or the provider meets every DFARS 7012 duty.

How we built this table. We checked the 14 individual FedRAMP Marketplace pages linked below on September 24, 2026, comparing the offering name, package ID, certification status, class, and "Certified Since" date. The table is unranked and alphabetical by vendor. It is a selected comparison, not a complete Marketplace census; it includes the help desks and adjacent alerting or workflow tools identified in the last column. A listing covers only that exact offering — never the vendor's other products. "Certified Since" records the offering's certification history; it is not necessarily the date it achieved its current class.

Vendor — Exact offering on the Marketplace — Package ID — Class — Certified since — What it means for a help desk that may hold CUI
VendorExact offering on the MarketplacePackage IDClassCertified sinceWhat it means for a help desk that may hold CUI
AtlassianAtlassian Government Cloud (Jira, Jira Service Management, Confluence)FR2412062433C (Moderate)Mar 14, 2025Meets the FedRAMP bar for this offering. Atlassian says its commercial cloud apps are not FedRAMP Moderate compliant.
BMCBMC HelixF1510057481C (Moderate)May 5, 2016Meets the bar for this offering.
HaloHaloFR2621445678C (Moderate), through the newer FedRAMP 20x pathMay 6, 2026See the 20x note below the table.
IvantiIvanti Neurons for ITSM (Formerly Service Manager)FR1816364586C (Moderate)Nov 19, 2019Meets the bar for this offering.
MicrosoftAzure Government (includes Dynamics 365)F1603087869D (High)Apr 29, 2020Relevant to Dynamics 365 customer-service use only after you confirm the proposed application and features are within this offering.
MicrosoftMicrosoft 365 Government Community Cloud-HighFR1824057433D (High)Dec 26, 2024A tenant-built help desk needs each service, add-on, and data destination checked; a tenant name does not establish that every component is included. Compare tenants in GCC vs GCC High.
MicrosoftMicrosoft 365 Government Community Cloud & Supporting ServicesMSO365MTC (Moderate)Nov 20, 2014The same component checks apply. Confirm the permitted CUI category and contractual commitments; GCC and GCC High are not interchangeable.
OpenTextITMX Platform featuring Service & Asset Management, Universal Discovery, CMDB and Project & Portfolio ManagementFR2215946050C (Moderate)Aug 21, 2024Meets the bar for this offering.
OracleOracle Service Cloud (OSvC)F1206061351C (Moderate)Dec 5, 2014Meets the bar for this offering.
PagerDutyPagerDuty Operations CloudFR2310974411B (Low)Mar 10, 2025On-call alerting, not a help desk. Below Moderate — keep CUI out of alerts.
SalesforceSalesforce Government Cloud PlusFR2003061248D (High)May 27, 2020Confirm the case-management features you use sit inside this package. More in Salesforce and CMMC.
ServiceNowGovernment Community CloudF1305072116D (High)Aug 12, 2019Meets the bar for this offering. A commercial ServiceNow instance is a different offering.
SmartsheetSmartsheet GovFR1730866868C (Moderate)Aug 12, 2019Not a help desk; evaluate it only as a request-tracking workflow alternative, with the required evidence and controls.
ZendeskZendesk Customer Support and Help Desk PlatformFR1821856903B (Low; formerly LI-SaaS)May 14, 2020Below Moderate. Not a CUI home on this certification.

"Meets the bar" in this table means the listed offering meets the FedRAMP status/baseline portion of the cloud check—not that you can place CUI in any configuration under that brand. The other duties in DFARS 7012(b)(2)(ii)(D) and (c)–(g) still matter. Microsoft also documents CUI-category differences between its government services.

Checking another help desk? For Freshworks (Freshservice, Freshdesk), Zoho, ManageEngine, SolarWinds, SysAid, TOPdesk, TeamDynamix, ConnectWise, Kaseya (including Autotask and Datto), Atera, Syncro, SuperOps, monday.com, or HubSpot, ask for the exact cloud offering and current Marketplace package ID. Absence from this selected table is not a finding that an offering lacks authorization. A vendor may instead claim DoD equivalency for a specific offering — if so, ask for the evidence package described in our FedRAMP equivalency guide.

Five traps the table can't show you

1. Same brand, different offering. Atlassian says its commercial cloud apps are not FedRAMP Moderate compliant. Government Cloud runs in a separate environment, and moving to it means migrating your data. The same logic applies to every vendor with a commercial and a government edition.

2. Add-ons don't inherit coverage. Atlassian's own licensing page says compatible Marketplace apps work with its Government Cloud but are not FedRAMP Moderate authorized, and you may need to assess them yourself. Treat every vendor's app store, plug-in, and integration the same way.

3. Class B isn't Moderate. Zendesk's certification is Class B (Low). Zendesk's own compliance-scope page says that to stay inside its FedRAMP environment, customers must use U.S.-only data locality and must not store personal data, cardholder data, or business-sensitive information in the service. That published scope does not establish a CUI-capable offering. For a help desk with SPD only, FedRAMP isn't required for that alone — but security configurations, passwords, and vulnerability details may be business-sensitive information. Confirm the permitted data and applicable controls before treating Zendesk as an SPD-only option; a responsibility matrix does not override its service terms.

4. The 20x path is new—but a certification is not a pending application. Halo's Marketplace record lists Class C (Moderate) through FedRAMP 20x. FedRAMP's current definitions recognize Certified status for FedRAMP-authorization requirements, and its July 30 update identifies 20x Class C as the replacement for 20x Moderate. We did not locate DoD CMMC guidance specifically addressing 20x packages in the official materials reviewed. Do not dismiss the certification because it uses 20x; obtain evidence for the exact offering and its DFARS 7012 commitments, and resolve any remaining contract-specific question with qualified assessment or contracting help.

5. Self-hosting Jira has a purchasing cutoff. Atlassian stopped selling the affected Data Center subscriptions to new customers after March 30, 2026, and those Data Center products reach end of life on March 28, 2029. Existing customers have different purchasing provisions; Bitbucket Data Center is excluded from this end-of-life announcement. If "run Jira on our own servers" was your plan, check that it's still open to you.

The license is only part of the bill

A government edition can change what you pay more than any feature list suggests. Atlassian publishes one example: Jira Service Management tiers in its Government Cloud start at 26+ agents, and the lowest row in its published price table is 50 agents at USD 49,000 per year (effective October 15, 2025). If you have two technicians, ask what the smallest subscription you can actually buy is, and whether you're eligible — Atlassian limits Government Cloud to U.S. government agencies and organizations using it for government-related work.

That one published price is not a quote, and it isn't total cost. When you compare options, use the same time period for each. Separate recurring subscriptions, add-ons, support, and ongoing staff time from one-time migration and setup; do not count the same implementation work twice. We don't publish "typical" price ranges, because we haven't found a reliable public source for them.

Where does ticket data go after someone clicks Submit?

A help desk can copy ticket content to more places than the ticket screen shows: notifications, integrations, AI features, search indexes, exports, backups, and vendor support. Trace every enabled path to establish where information can go; separately determine whether the real information using those paths is CUI or SPD. Do it with made-up test data — never with real CUI.

Think of it like tracking a certified letter. You don't just check that it left your desk. You check every hand it passed through.

Where ticket data can go — Test it with a fake ticket — Common fix — Proof to keep
Where ticket data can goTest it with a fake ticketCommon fixProof to keep
Email-to-ticket (forwarded threads, attachments, inline images)Send a test email marked "TEST — NOT CUI" with an attachment and a pasted imageStop importing attachments where appropriate, and address pasted text and quoted replies; route CUI-bearing questions to a system inside your approved CUI environmentSettings export plus the resulting test ticket
Portal form fields and uploadsSubmit a fake screenshot through the formUse upload restrictions and warnings as supporting controls, not proof of exclusion; handle CUI in free-text fields and titles tooForm settings plus the test result
Chat, virtual agent, mobile appPaste fake text into each channelTurn off channels you don't need, or keep them inside an approved boundaryChannel settings
Notifications (email, text, Teams, Slack)Open the notification the test ticket triggersUse a non-sensitive reference and approved link instead of the body; check that the reference and URL do not disclose CUINotification template settings
AI features (summaries, suggested replies, smart search)Ask where processing, storage, and support access occur and what offering covers themDisable unapproved processing; verify the relevant boundary or separately qualifying destination before enabling it for CUIFeature list plus your setting
Integrations, webhooks, add-onsList every connection the tool hasApply requirements to the data and security role at each destination; a CUI destination needs the CUI protections for its deploymentIntegration inventory
Search, previews, reports, exportsRun an export of the test ticketLimit who can export and where exports goRole list plus export log
Knowledge base articlesCheck whether technicians turn tickets into articlesAdd a review step before anything is publishedReview record
Vendor or MSP support access, diagnostic bundlesAsk who can see your tenant and what support can pullPut limits in the contract and the responsibility matrixResponsibility matrix plus support procedure
Backups, archives, deletionDelete the test ticket; ask what remains and whereKnow the retention period and restore locationRetention settings plus vendor statement

How to run the trace:

  1. Create a fake ticket that is obviously fake ("TEST — NOT CUI") with a fake attachment.
  2. Submit it every way a user can: email, portal, chat, phone app.
  3. Follow it to every place in the table and write down what you found.
  4. Mark each path enabled, disabled, or unknown. "Disabled" needs a settings screenshot or export, not a memory.
  5. Anything unknown stays open, with a named owner and a date.

This isn't a new rule. It's how you gather proof for requirements you already have: controlling where CUI flows (National Institute of Standards and Technology (NIST) SP 800-171 Rev. 2, 3.1.3), controlling connections to outside systems (3.1.20), and describing your system accurately in your SSP (3.12.4). Its Special Publication 800-171 Revision 2 sets the 110 requirements CMMC Level 2 uses. The June 2018 SP 800-171A supplies the incorporated assessment procedures. Publication of Revision 3 did not, by itself, replace the CMMC baseline in 32 CFR Part 170.

What should you ask a vendor before you buy or renew?

Ask the vendor to prove the configuration you'll actually use, not a different edition's feature list. A feature list, a FedRAMP badge, and an MSP's assurance answer different questions, and none of them replaces your evidence. The checklist below maps each question to the requirement it supports. The numbered requirements are from NIST SP 800-171 Rev. 2.

These are buying questions, not a complete list of Level 2 requirements. Some controls may come from your wider environment instead of the help desk itself. Record each answer as supplied, missing, not applicable (with a reason), or unknown. Don't add them up into a score.

Ask the vendor to show you — Why it matters
Ask the vendor to show youWhy it matters
For cloud use with CUI: the exact offering name and hosting, matched to its Marketplace package ID — or its full equivalency evidence§170.16(c)(2); DFARS 7012(b)(2)(ii)(D)
Its customer responsibility matrix and service description§170.19(c)(2)(ii); document the provider relationship and services in your SSP
A role test: requester, technician, admin, guest, and vendor support each see only what they shouldNIST 800-171 Rev. 2: 3.1.1, 3.1.2, 3.1.5 (least privilege)
Where multifactor authentication is enforced for local and network access to privileged accounts and network access to nonprivileged accounts; how emergency access and nonhuman and application-programming-interface credentials are controlled3.5.3 defines the multifactor-authentication access categories; do not assume every automated credential must perform an interactive MFA challenge
One change record from request to closed, with a history export3.4.3, 3.4.4
Audit logs: who did what and when, how long they're kept, how they're protected and exported3.3.1, 3.3.2, 3.3.8
Its incident commitments if CUI is involved: notice, preserving images, forensic accessDFARS 7012(b)(2)(ii)(D) requires the cloud provider to meet paragraphs (c)–(g)
Protection of CUI in transit and at rest, and FIPS-validated cryptography when cryptography protects CUI confidentiality3.13.8, 3.13.11, 3.13.16 (FIPS = Federal Information Processing Standards); not a blanket requirement that every cryptographic use be FIPS-validated
How you leave: a full export with history, approvals, and attachments3.3.1 supports audit-record retention; for Level 2 self-assessment, retain the artifacts used as evidence for six years from the CMMC Status Date (§170.16(c)(4)), not automatically every routine ticket

A missing answer on a vendor questionnaire isn't an official finding. It is a reason to slow down before you sign. If an MSP runs the tool for you, pair this with our guide to checking whether your MSP is actually CMMC compliant.

Keep, fix, split, or replace?

Four practical options are to keep the help desk for SPD only, move CUI tickets to a qualifying cloud offering, self-host inside your CUI boundary, or split the work between two systems. Each has a real cost, and none of them is automatically the safe choice.

Option — Fits when — The honest downside
OptionFits whenThe honest downside
Keep it for security data onlyThe trace and your documented controls support no-CUI use, the vendor permits the data, and its service description, responsibility matrix, and relevant control evidence are availableA policy alone won't hold up. Re-test the affected paths when settings, integrations, or features change; unexpected CUI needs an incident decision, not a retroactive assumption that the service was approved.
Move to a qualifying cloud offeringCUI needs to be in tickets, and the exact offering has Moderate-or-higher FedRAMP status or DoD equivalency plus the required DFARS 7012 commitmentsCost, minimum purchase sizes, and migration work. Government editions may lag commercial features — Atlassian says some capabilities aren't yet available in its Government Cloud.
Self-host inside your CUI boundaryYou have staff who can run, patch, back up, and monitor itYou are responsible for running the system and showing its controls work, including the responsibilities shared with outside providers. Some self-hosted products are closing to new buyers (see the Atlassian trap above).
SplitMost tickets are ordinary, and only a few involve CUITwo doors. People must know which one to use, and you must test and enforce the separation, routing, and handling controls—not rely on a queue label.

Your current help desk may be fine. No web page — including this one — can tell you that without seeing its settings and your evidence. What can tell you is the trace above, the vendor's answers, and someone who knows your contract.

If the trace or the vendor's answers point toward splitting or replacing, the help desk is usually one piece of a bigger decision: a CUI enclave, a government cloud tenant, or a managed provider that runs the tool and documents its part. Sorting out which kind of help you need first keeps you from buying the wrong thing twice.

Map my CMMC path before I buy →

What your ticket trail has to prove

Tickets can supply evidence for requirements covering incidents, changes, maintenance, offboarding, and fixing flaws. Under the CMMC scoring rule, the ten requirements grouped below carry 30 of Level 2's 110 points. Twenty-six of those points sit on requirements that cannot be deferred on a Level 2 Plan of Action and Milestones (POA&M), the limited remediation list allowed for Conditional status. These are not points awarded for owning a ticketing system.

The point values come from the scoring rule, 32 CFR 170.24. The POA&M limits come from 32 CFR 170.21. At Level 2, eligible requirements generally must be worth only 1 point, with six specifically barred requirements and a narrow exception for 3.13.11 when encryption is used but is not FIPS-validated. Which ten requirements lean on tickets is our grouping, not the rule's. The requirement summaries come from NIST SP 800-171 Rev. 2.

NIST SP 800-171 Rev. 2 requirement — In plain English — Points — Can it go on a POA&M? — What the tickets should show
NIST SP 800-171 Rev. 2 requirementIn plain EnglishPointsCan it go on a POA&M?What the tickets should show
3.6.1Have a working incident-handling process5NoPreparation, detection, analysis, containment, recovery, and user-response steps, with times
3.6.2Track, document, and report incidents5NoWho was told and when, including any DoD report number
3.6.3Test your incident response1YesExercise tickets with results and follow-ups
3.4.3Track, review, approve or reject, and log changes1YesRequest, approver, decision, implementation, verification
3.4.4Check security impact before a change1YesAn impact review recorded before implementation
3.7.1Perform maintenance3NoWork records for each maintenance job
3.9.2Protect systems when people leave or transfer5NoTimes accounts were disabled and equipment returned
3.14.1Find, report, and fix flaws on time5NoFlaw or patch tickets with due and fixed dates
3.11.3Fix vulnerabilities based on risk1YesScan findings tied to risk ratings and fixes
3.12.2Plan and track fixes for deficiencies3NoOpen deficiencies with reviews and progress
Total3026 points can't be deferred

"Yes" means eligible only if all the other Level 2 POA&M conditions are met; it is not automatic permission to defer the requirement. The six barred requirements are 3.1.20, 3.1.22, 3.12.4, 3.10.3, 3.10.4, and 3.10.5. None is in this ten-row total.

Here's the math that matters. If all ten requirements—not merely their tickets—were scored NOT MET, a perfect 110 would fall to 80. The rule requires at least 88 — a score of 0.8 or higher out of 110 — before Conditional status is even possible (§170.21(a)(2)(i)). That threshold is necessary, not sufficient: the non-deferrable requirements must also be met. Missing ticket records are not automatic deductions; other valid evidence may demonstrate a requirement. But a failed process with no adequate supporting evidence can sink the assessment. (§170.24; SP 800-171A)

Tickets also support other requirements, such as approving access (3.1.1, 5 points), supervising maintenance staff without required access authorization (3.7.6, 1 point), and acting on security alerts (3.14.3, 5 points). We left those out of the total to keep this an explicitly bounded example, not a second assessment methodology.

What a closed ticket can't prove. A ticket shows that something was recorded. The assessor also checks that the safeguard works, that the right people did the work, and that your SSP matches what happened. The rule says evidence must be final — not drafts or working papers (§170.24(b)(1)). A typed approver name in a free-text box is weaker than an approval the system records under that person's own login.

Your ticket queue can double as your fix list. The rule lets you pick the format of your "operational plan of action" — the running list of qualifying temporary deficiencies you're fixing (§170.4). A database counts. But logging a gap does not make an unimplemented requirement MET. The rule's temporary-deficiency definition requires feasible remediation and a known fix that is available or in process and ordinarily excludes initial implementation, apart from its stated equipment-rollout exception. Qualifying temporary deficiencies documented in an operational plan with reviews and progress fall under §170.24(b)(1)(ii). That's different from a formal POA&M for Conditional status, which needs a closeout assessment within 180 days of the Conditional CMMC Status Date (§170.21(b); FAQ C-Q9). No fixed operational-plan deadline in Part 170 means no universal 180-day timer—not permission to ignore timely flaw correction or risk-based remediation.

Incidents run on a contract clock. When DFARS 252.204-7012 applies, its reporting trigger includes a cyber incident affecting a covered contractor information system, covered defense information residing there, or your ability to provide contract-designated operationally critical support. It is not limited to confirmed CUI theft. Covered defense information is the clause's defined category, not a label to apply to every business document. Report a qualifying incident to DoD at DIBNet within 72 hours of discovery. You need a DoD-approved medium assurance certificate to file, and you must preserve images of all known affected systems and all relevant monitoring or packet-capture data for at least 90 days after submitting the report. Subcontractors must send the DoD report number to the prime or next-higher-tier subcontractor as soon as practicable (7012(a), (c), (e), (m)). An unresolved alert needs prompt triage; don't delay a required report while waiting to confirm exfiltration. The incident template below builds those fields in. Our DFARS 7012 incident reporting guide covers the full process.

Keep the evidence current between assessments. For a Final Level 2 (Self) status, the assessment cycle is three years, with an affirmation after assessment and annually thereafter in the Supplier Performance Risk System (SPRS) (§170.16). That is not permission to leave a changed ticketing workflow unreviewed until renewal. The DoW FAQ, F-A5, directs contractors to review planned changes with the affirming official, follow change control, and update the SSP as needed.

Free templates: change and incident tickets

These two blank templates organize evidence for the relevant requirements in your ticket forms; they are not government-prescribed forms. Copy them into your own help desk. Fill them in only inside your approved system — a completed ticket can itself hold security protection data or CUI.

Free ticket templates

These templates are blank. Fill them in only inside your own approved system. Don't paste CUI, drawings, or sensitive contract details into this page or send them to us.

Change ticket

CHANGE TICKET — BLANK TEMPLATE
Complete only in a system approved for this ticket's data and connected destinations.
If the help desk is not approved for CUI, use non-sensitive references to the approved CUI repository instead of copying CUI.
Do not put credentials or secrets in this ticket.

Ticket ID:
Queue / record owner:
Data in this ticket: CUI / security protection data / other / not yet determined
Who decided that, and where the reasoning is recorded:
Safe title (no sensitive technical or contract details):
System or asset (inventory reference):
What is changing, and why:
Related procedure / requirement (e.g., 3.4.3, 3.4.4):
Security impact review done BEFORE implementation (yes / no / not yet determined):
  Reviewer, time, and where the review is recorded:
  Does this change how CUI moves or where it's stored? (yes / no / unsure):
Decision: approved / rejected / pending
  Decided by (recorded by the system, not typed) and time:
Implementer and planned window:
Implemented (time) and result:
Validation performed and result:
Rollback or exception notes:
Evidence pointers (approved repository; no credentials or secrets; no copied CUI in a help desk not approved for it):
SSP, inventory, or network diagram update needed? (yes / no / not yet determined — what):
Planned change reviewed with affirming official (who, when, outcome / not yet reviewed):
Closed by and closure time:
Open items and owner:
Retention category, governing requirement, and record owner:
Assessment artifact? yes / no / not yet determined; applicable CMMC Status Date:
Protected audit-history / export reference:

Incident ticket

INCIDENT TICKET — BLANK TEMPLATE
Complete only in a system approved for this ticket's data and connected destinations.
If the help desk is not approved for CUI, use non-sensitive references to the approved CUI repository instead of copying CUI.
Do not put credentials or secrets in this ticket.

Ticket ID:
Record owner and authorized queue:
Data in this record: CUI / SPD / other / not yet determined
Applicable incident-response plan / preparation reference:
Discovered (date, time, time zone):
Discovered by / how (alert, user report, vendor notice):
Systems and accounts affected (inventory references only):
Covered contractor information system affected? yes / no / unknown
Covered defense information residing there affected? yes / no / unknown
Ability to perform contract-designated operationally critical support affected? yes / no / unknown
DFARS 252.204-7012 applies? yes / no / unresolved
Reportability decision, responsible official, time, and rationale:
  Unknown requires prompt triage; do not wait for confirmed theft or reset a running reporting clock.
  Record the earliest applicable discovery time and any uncertainty. This template does not decide reportability.
DFARS 7012 deadline for a qualifying incident (discovery date/time + 72 hours, with time zone):
Reporting owner and DoD-approved medium assurance certificate readiness:
Review for compromise started (who, when):
Containment steps (who, when):
Eradication and recovery steps (who, when):
User-facing actions and notices:
Internal officials notified (name, role, time):
DIBNet report submitted (time):
DoD incident report number:
Report number sent to prime or next-higher-tier contractor (time; as soon as practicable), if you are a subcontractor:
Malicious software isolated and submitted to DC3 as instructed? yes / no / not applicable
Images of all known affected systems and all relevant monitoring/packet-capture data preserved:
Minimum preservation point (report submission date/time + 90 days, with time zone):
Other holds, preservation owner, and authorized release decision (do not auto-delete at 90 days):
Evidence pointers (approved repository only):
Follow-up changes (link change tickets):
Lessons learned recorded (where):
Closed by and closure time:

Where does ticket data go after someone clicks Submit?

A help desk can copy ticket content to more places than the ticket screen shows: notifications, integrations, AI features, search indexes, exports, backups, and vendor support. Trace every enabled path to establish where information can go; separately determine whether the real information using those paths is CUI or SPD. Do it with made-up test data — never with real CUI.

Think of it like tracking a certified letter. You don't just check that it left your desk. You check every hand it passed through.

Where ticket data can go — Test it with a fake ticket — Common fix — Proof to keep
Where ticket data can goTest it with a fake ticketCommon fixProof to keep
Email-to-ticket (forwarded threads, attachments, inline images)Send a test email marked "TEST — NOT CUI" with an attachment and a pasted imageStop importing attachments where appropriate, and address pasted text and quoted replies; route CUI-bearing questions to a system inside your approved CUI environmentSettings export plus the resulting test ticket
Portal form fields and uploadsSubmit a fake screenshot through the formUse upload restrictions and warnings as supporting controls, not proof of exclusion; handle CUI in free-text fields and titles tooForm settings plus the test result
Chat, virtual agent, mobile appPaste fake text into each channelTurn off channels you don't need, or keep them inside an approved boundaryChannel settings
Notifications (email, text, Teams, Slack)Open the notification the test ticket triggersUse a non-sensitive reference and approved link instead of the body; check that the reference and URL do not disclose CUINotification template settings
AI features (summaries, suggested replies, smart search)Ask where processing, storage, and support access occur and what offering covers themDisable unapproved processing; verify the relevant boundary or separately qualifying destination before enabling it for CUIFeature list plus your setting
Integrations, webhooks, add-onsList every connection the tool hasApply requirements to the data and security role at each destination; a CUI destination needs the CUI protections for its deploymentIntegration inventory
Search, previews, reports, exportsRun an export of the test ticketLimit who can export and where exports goRole list plus export log
Knowledge base articlesCheck whether technicians turn tickets into articlesAdd a review step before anything is publishedReview record
Vendor or MSP support access, diagnostic bundlesAsk who can see your tenant and what support can pullPut limits in the contract and the responsibility matrixResponsibility matrix plus support procedure
Backups, archives, deletionDelete the test ticket; ask what remains and whereKnow the retention period and restore locationRetention settings plus vendor statement

What should you ask a vendor before you buy or renew?

Ask the vendor to prove the configuration you'll actually use, not a different edition's feature list. A feature list, a FedRAMP badge, and an MSP's assurance answer different questions, and none of them replaces your evidence. The checklist below maps each question to the requirement it supports. The numbered requirements are from NIST SP 800-171 Rev. 2.

These are buying questions, not a complete list of Level 2 requirements. Some controls may come from your wider environment instead of the help desk itself. Record each answer as supplied, missing, not applicable (with a reason), or unknown. Don't add them up into a score.

Ask the vendor to show you — Why it matters
Ask the vendor to show youWhy it matters
For cloud use with CUI: the exact offering name and hosting, matched to its Marketplace package ID — or its full equivalency evidence§170.16(c)(2); DFARS 7012(b)(2)(ii)(D)
Its customer responsibility matrix and service description§170.19(c)(2)(ii); document the provider relationship and services in your SSP
A role test: requester, technician, admin, guest, and vendor support each see only what they shouldNIST 800-171 Rev. 2: 3.1.1, 3.1.2, 3.1.5 (least privilege)
Where multifactor authentication is enforced for local and network access to privileged accounts and network access to nonprivileged accounts; how emergency access and nonhuman and application-programming-interface credentials are controlled3.5.3 defines the multifactor-authentication access categories; do not assume every automated credential must perform an interactive MFA challenge
One change record from request to closed, with a history export3.4.3, 3.4.4
Audit logs: who did what and when, how long they're kept, how they're protected and exported3.3.1, 3.3.2, 3.3.8
Its incident commitments if CUI is involved: notice, preserving images, forensic accessDFARS 7012(b)(2)(ii)(D) requires the cloud provider to meet paragraphs (c)–(g)
Protection of CUI in transit and at rest, and FIPS-validated cryptography when cryptography protects CUI confidentiality3.13.8, 3.13.11, 3.13.16 (FIPS = Federal Information Processing Standards); not a blanket requirement that every cryptographic use be FIPS-validated
How you leave: a full export with history, approvals, and attachments3.3.1 supports audit-record retention; for Level 2 self-assessment, retain the artifacts used as evidence for six years from the CMMC Status Date (§170.16(c)(4)), not automatically every routine ticket

Source URLs

  • https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171r2.pdf
  • https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-G/part-170/subpart-D/section-170.16
  • https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-G/part-170/subpart-D/section-170.19

Change ticket (blank):

Incident ticket (blank):

DC3 is the DoD Cyber Crime Center, where DFARS 7012 sends isolated malicious software (7012(d)).

Other ticket types — the fields to require:

Ticket type — Fields to require — Requirement it supports (points)
Ticket typeFields to requireRequirement it supports (points)
Access request or removalUser, access level, business reason, approver, date granted, date removed3.1.1 (5)
MaintenanceAsset, work done, who did it, remote or on-site, tools used, supervision of personnel without required access authorization, equipment sanitized before leaving the site3.7.1 (3), 3.7.6 (1), 3.7.3 (1)
Offboarding or transferLast day, time each account was disabled, tokens and devices returned, shared authenticators changed where needed3.9.2 (5)
Flaw or vulnerabilitySource (scan or advisory), asset, risk rating, due date, fixed date, verified by3.14.1 (5), 3.11.3 (1), 3.14.3 (5)
Temporary deficiency (operational plan of action item)What is wrong, why it meets the temporary-deficiency definition, known/in-process fix, owner, review dates, progress notes3.12.2 (3); §170.4 and §170.24(b)(1)(ii)

These are suggested evidence fields, not a separate government form requirement. Match them to the actual Rev. 2 requirement and assessment objectives; for example, 3.7.6 concerns supervision of maintenance personnel without the required access authorization, not every outside technician.

Worked example: a small shop's access-policy change

Here's a filled-in change ticket for a fictional 30-person machine shop with two technicians and a separate CUI environment. Assume the help desk provides security support for that environment and handles SPD but no CUI anywhere in the service—not just in this one ticket. It therefore follows the SPD-only row of the first table. It shows how the record should read — not that this shop's help desk passes an assessment.

Ticket ID: DEMO-014
Queue / record owner: Fictional IT change queue
Data in this ticket: security protection data; no CUI
Who decided that: Fictional security lead / review record DEMO-A
Safe title: Scheduled access-policy update
System or asset: DEMO-SYS-01 (fictional)
What is changing, and why: Apply an approved access-policy revision
Related procedure / requirement: Internal change procedure; 3.4.3, 3.4.4
Security impact review done BEFORE implementation: yes
  Reviewer, time, record: Fictional security lead, 2026-09-21 13:30 UTC, DEMO-B
  Does this change how CUI moves or where it's stored? no
Decision: approved — recorded by the workflow, 2026-09-21 14:00 UTC
Implementer and window: Fictional technician, 2026-09-22 15:00–15:30 UTC
Implemented and result: 2026-09-22 15:12 UTC, applied without errors
Validation: authorized access works; a fake unauthorized login is denied
Evidence pointers: DEMO-C in the approved internal repository
SSP / inventory update needed: configuration record updated; SSP reviewed, no change
Affirming official review: Fictional official reviewed the planned change, 2026-09-21 14:15 UTC; no change to the documented scope or required safeguards
Closed by: Fictional security lead, 2026-09-22 16:00 UTC
Open items: none
Retention category / owner: internal change record; fictional security lead
Assessment artifact: not yet determined; CMMC Status Date not assigned in this example
Protected audit-history / export reference: DEMO-D in the approved internal repository

Now change one fact. A user replies to DEMO-014 with a screenshot that shows a CUI drawing. The ticket is no longer security-data only. Reopen the first table: the help desk has just held CUI, and every copy counts — notifications, integrations, backups, and any export. Treat it as a possible incident under your incident procedure and any DFARS 7012 duties. Don't quietly delete it; deleting can destroy evidence you're required to keep.

If your MSP runs the help desk

If your MSP's ticketing system holds your passwords, configurations, logs, or vulnerability details, the MSP is an external service provider, and its services are assessed inside your CMMC scope. It does not need a separate CMMC assessment merely to serve as your non-cloud or SPD-only ESP; its own contracts may create separate obligations. If CUI reaches its system, stricter rules apply.

The DoW's CMMC FAQ says an MSP running your IT and an MSSP running your security tools are both ESPs — even when no CUI goes to either — and both are assessed within your scope without needing their own certification (E-A4). An MSP that stores your CUI on a system that isn't a cloud service also doesn't need its own assessment, but its services are assessed in your scope against all Level 2 requirements (E-A3; §170.16(c)(3)). If the MSP's ticketing platform is a cloud service and CUI lands in it, the FedRAMP rule from the first table applies.

An MSP may run tickets in a PSA — professional services automation — platform that serves many clients at once. Watch one path closely: your employees emailing the MSP's support address. That email can carry the same attachments that caused trouble in the machine-shop example. Ask the MSP how its PSA handles attachments from your users, and get the answer in its responsibility matrix.

Who counts as the cloud provider turns on the subscription. If your company holds the cloud tenant and the MSP only administers it, the MSP is not the cloud service provider. If the MSP contracts with the cloud provider and modifies the service, it may be (E-A5). For the full provider-side checklist, see CMMC requirements for MSPs and is my MSP actually CMMC compliant?

Questions before you migrate, renew, or sign

Is Jira CMMC compliant? No software is CMMC compliant by itself. For CUI, Jira Service Management is available in Atlassian Government Cloud, whose Marketplace record lists Class C (Moderate). Atlassian says its commercial cloud apps are not FedRAMP Moderate compliant. Commercial Jira may be usable for SPD-only support when CUI stays out and the relevant controls, permitted data, and provider responsibilities are established—not merely because someone calls it "no CUI."

Is Zendesk FedRAMP authorized? The Zendesk offering in the table is Certified at Class B (Low), below the Moderate baseline needed for the CUI-cloud path. Its scope page still describes LI-SaaS Tailored and prohibits personal data, cardholder data, and business-sensitive information in that scoped service. That record does not establish Moderate status or DoD equivalency; any separate equivalency claim needs evidence for the exact offering.

Is ServiceNow CMMC compliant? ServiceNow's Government Community Cloud record lists Class D (High), above the Moderate baseline for that exact offering. A commercial ServiceNow instance is a different offering. Confirm the modules and integrations you'll use sit inside the government boundary, and establish the applicable DFARS 7012 commitments; the listing alone is not your CMMC result.

Can we use Freshservice, ConnectWise, Autotask, or another help desk with no Marketplace record? Possibly for SPD-only use, when the actual data use, relevant controls, permitted data, and provider responsibilities support it; a responsibility matrix alone is not enough (§170.19). For cloud use with CUI, establish the exact offering's Moderate-or-higher status or DoD equivalency and its required DFARS 7012 commitments—or move that workflow to a qualifying system. Recheck the Marketplace before you decide; absence from this article is not a finding that an offering has no record.

Does encrypting ticket attachments get around FedRAMP? No. The DoW's CMMC FAQ says encrypted CUI is still CUI, and a cloud that isn't FedRAMP Moderate or equivalent can't store it even encrypted (B-A8, E-A2).

Is "FedRAMP In Process" or "FedRAMP Ready" good enough? Not on its own. The CMMC rule points to offerings FedRAMP Authorized at Moderate or higher in the Marketplace, or proven equivalency (§170.16(c)(2)). A pending or legacy readiness label alone does not prove either route; a separate equivalency claim must stand on its evidence.

How long should we keep ticket records? For a Level 2 self-assessment, artifacts you used as evidence must be kept six years from the CMMC Status Date (§170.16(c)(4)). That doesn't mean every routine ticket needs six years. Separate assessment evidence from everyday records, and keep incident holds on their own clock — at least 90 days from report submission for DFARS 7012 images and monitoring data. Check your contract for other retention terms.

Can we migrate old tickets into a new system? First find out what the old tickets contain. If any hold CUI, the destination has to qualify for CUI before they move, and the export file is itself a copy you have to protect. Test with fake records that history, approvals, and access limits survive the move.

Does every open ticket get a 180-day CMMC deadline? No. The 180-day clock applies to closing a formal POA&M through a closeout assessment within 180 days of the Conditional CMMC Status Date (§170.21(b)). An operational plan of action has no universal remediation deadline in Part 170, but that does not cancel timely flaw correction, risk-based remediation, or other contract requirements (FAQ C-Q9; Rev. 2, 3.14.1 and 3.11.3). For formal POA&M tracking, see CMMC POA&M software.

We only handle FCI. Does any of this apply? Lightly. At Level 1, your help desk is in scope if FCI goes into tickets, and the 15 basic safeguards apply (§170.19(b); FAR 52.204-21). The FedRAMP cloud rule in DFARS 7012 is about covered defense information, not FCI-only work. Your contract sets your level — see CMMC levels and our FCI vs. CUI guide.

What we verified

We checked on September 24, 2026:

  • 32 CFR Part 170 on the eCFR, including §§170.2, 170.4, 170.16, 170.19, 170.21, and 170.24; the retrieved eCFR display was current through September 22, 2026. We also consulted the published final rule.
  • DFARS 252.204-7012 (May 2024 clause text) and FAR 52.204-21 on Acquisition.gov, plus NIST SP 800-171 Rev. 2 and the incorporated June 2018 SP 800-171A assessment procedures.
  • The DoW CMMC FAQ, the current program page, and the July 13, 2026 implementation memorandum. The official acquisition index identifies Class Deviation 2026-O0025, Revision 3, dated September 3, 2026; we could not retrieve its complete signed attachment and do not interpret its unread provisions here. No published task-force outcome or replacement Phase II date was located in the official materials reviewed.
  • The 14 individual FedRAMP offering pages linked in the table, FedRAMP notice NTC-0004, its current 2026 definitions, and its July 30 certification-path update. We did not complete a whole-Marketplace absence search.
  • Atlassian's Government Cloud licensing FAQ and Data Center end-of-life page, Zendesk's compliance-scope page, and Halo's FedRAMP page (company-stated). We also read Microsoft's government-cloud CMMC guidance and the Find My CMMC Path landing page.

We did not: test any product hands-on, review any vendor's private FedRAMP package or equivalency evidence, or see any reader's contract or configuration. We did not complete the Find My CMMC Path input/result flow or test its contact, privacy, or tracking behavior. No tool timing, provider match, introduction, or follow-up is promised here. The DoD materials reviewed did not resolve a 20x-specific contract question; the existing FedRAMP certification and the separate DFARS obligations should not be conflated.

Still not sure which CMMC path fits your company? Use The Defense Compliance Report's Find My CMMC Path tool to see which path and kind of help fit your contract, CUI, environment, and timeline — before you hire anyone.

Find my CMMC path →

Sources

Checked September 24, 2026 unless noted.


About The Defense Compliance Report. The Defense Compliance Report is the independent trade publication and decision resource for CMMC and Defense Industrial Base compliance — explaining the CMMC Final Rule with primary-source citation on every claim and mapping a contractor's level, CUI scope, assessment type, and timeline to the right provider category, so DIB contractors choose the right CMMC path before they spend six figures. We are not affiliated with the Cyber AB, the Department of Defense, the Defense Contract Management Agency's Defense Industrial Base Cybersecurity Assessment Center (DCMA DIBCAC), NIST, or any U.S. government agency. This page is educational research, not legal, contractual, or compliance advice. Confirm scope and applicability with a CMMC Registered Practitioner (RP) or a qualified federal-contracts attorney. See our Editorial & Advertising Policy.

Map my CMMC path →