Not Every Device Needs to Be FIPS Validated
Encrypted CUI is still CUI, but that does not mean every device in the network path needs to be FIPS validated. Using the OSI model and DoD CMMC FAQ F-Q4, this post explains how to correctly categorize firewalls and network devices, when FIPS actually applies, and how to document your scoping decisions in your SSP.