Compliance Frameworks and What They Mean for a Firewall
CMMC, CJIS, FISMA and StateRAMP, translated into configuration
Compliance frameworks do not name products, and any vendor claiming their box makes you compliant is telling you something untrue. What frameworks do is specify controls, and controls translate into configuration, logging and evidence.
That translation is the useful part, and it is where most of the cost sits. The firewall is rarely the expensive element of a compliance programme, the log retention, the evidence collection and the change control are.
Below is what each framework tends to drive in a Fortinet deployment. It is guidance, not legal advice, and your assessor's reading governs.
CMMC 2.0, defence contractors
If you handle Controlled Unclassified Information under a DoD contract, CMMC applies. Level 2 aligns to NIST SP 800-171, which is 110 controls, a meaningful number of which are network and boundary controls.
In practice this drives an enclave design: CUI is segmented into a defined boundary with controlled flows in and out, rather than spread across a flat corporate network. That is a firewall and segmentation problem, and doing it well shrinks your assessment scope, which is the single biggest lever on the cost of certification. Logging and retention supply the evidence, and administrative access needs multi-factor.
CJIS, law enforcement
Prescriptive where others are principles-based. Advanced authentication, session lock, specified audit content, defined retention, and encryption requirements are all written down. Segmentation between criminal justice information and everything else is the design centre, and audit retention usually sizes the log platform.
FISMA and NIST SP 800-53, federal systems
Federal information systems are categorised low, moderate or high under FIPS 199, and the control baseline follows from that categorisation. The boundary protection family is where a firewall lives, alongside audit and accountability.
The practical point is that categorisation drives everything downstream, so it is worth settling before hardware is specified. A moderate-baseline system and a high-baseline system have materially different logging and separation requirements, and discovering that after purchase is expensive.
StateRAMP and state frameworks
StateRAMP applies a FedRAMP-like model to state and local cloud services, and a growing number of states require it of suppliers. It matters here mainly if you are consuming cloud-delivered security services rather than running appliances, worth checking your state's position before committing to a SaaS-delivered control.
What the firewall actually contributes
Across all four frameworks the same four things recur, and they are worth designing for once rather than four times.
- Segmentation, a defined, defensible boundary around the regulated data, which shrinks assessment scope more than any other decision.
- Logging with retention, the evidence layer. Almost always sizes the log platform, and almost always under-estimated.
- Authenticated, attributed change control, every policy change attributed, timestamped and reversible, which is what an assessor asks to see and cannot be reconstructed afterwards.
- Multi-factor on administrative access, cheap, universally required, and the most commonly missing control we find.
Straight answers
Does buying Fortinet make us CMMC compliant?
No, and be wary of anyone who says otherwise. CMMC assesses your practices against NIST SP 800-171 controls. Equipment can implement a control well or badly; it cannot satisfy an assessment on its own. What a well-designed Fortinet deployment does is make the boundary and logging controls straightforward to implement and evidence, and shrink the scope you have to assess.
Which controls does a firewall actually address?
Predominantly boundary protection, information flow enforcement, audit generation and retention, and identification and authentication for administrative access. It contributes to others indirectly. We will map a proposed configuration to the specific control set you are being assessed against if you tell us which one it is.
How much log retention do we need?
It depends on the framework and often on your own system security plan, and it is the requirement most likely to be under-sized. The arithmetic is daily log volume multiplied by retention days, and daily volume with full inspection logging is routinely five to ten times what the same firewall generates without it. Measure before sizing the log platform.
Can you provide evidence for our assessor?
We can provide configuration documentation, the change history from FortiManager, and reporting from FortiAnalyzer, the artefacts assessors typically ask for. We are not an assessor and will not tell you those artefacts satisfy your assessment; your assessor decides that.
Tell us the constraint you are working within
The vehicle, the threshold, the fiscal year end, the framework you are assessed against. We will build the quote around it rather than around our own quarter.