Skip to content

Compliance & frameworks

CMMC

Cybersecurity Maturity Model Certification (CMMC)

CMMC (Cybersecurity Maturity Model Certification) is how the US Department of Defense verifies that the companies in its supply chain actually protect the information they are trusted with. Built on NIST SP 800-171, the program sets tiered requirements — Level 1 for Federal Contract Information (FCI) and Level 2 for Controlled Unclassified Information (CUI) — and adds independent verification on top of the self-attestation that governed the past, tying award and renewal to demonstrable practice. As of 2026 the requirement is phasing into DoD solicitations, so for a cloud-native defense supplier it has moved from future planning to a gate on winning and keeping work.

Who it applies to

CMMC applies to any contractor or subcontractor in the defense industrial base that handles FCI or CUI on the DoD's behalf — primes and every tier of the supply chain beneath them, because the requirement flows down. Level 1 covers the fifteen basic safeguarding requirements for FCI; Level 2 covers the full 110 requirements of NIST SP 800-171 for CUI, verified by self-assessment or by an authorized third party (a C3PAO) depending on the contract. If a DoD solicitation names a CMMC level, or your contracts reference DFARS 252.204-7012, you are in scope.

Cloud control themes

What CMMC asks of your cloud

  • Access control (AC) — least privilege, separation of duties, and limiting CUI access to authorized users and devices
  • Identification & authentication (IA) — multi-factor authentication and FIPS-validated authenticators for privileged and remote access
  • Audit & accountability (AU) — creating, protecting, and retaining audit records so activity on CUI systems can be reviewed
  • Configuration management (CM) — enforced baselines, least functionality, and control of changes to CUI-handling systems
  • System & communications protection (SC) — boundary protection, network segmentation, and FIPS-validated encryption for CUI in transit and at rest
  • Cloud service provider equivalence — DFARS 252.204-7012 requires cloud services holding CUI to meet FedRAMP Moderate (or equivalent), which shapes GovCloud and region choices

Domain × framework

Which assessment domains produce CMMC evidence

Assessment domainHow it maps
Identity & accessIAM findings map to the Access Control (AC) and Identification & Authentication (IA) families — least privilege, MFA enforcement, and control of remote and privileged access to CUI systems.
Data securityEncryption and storage-exposure findings support Media Protection (MP) and System & Communications Protection (SC.L2-3.13.11) — CUI protected at rest with FIPS-validated cryptography and not left publicly reachable.
Network exposureBoundary and segmentation findings evidence System & Communications Protection (SC) — monitored boundaries, subnetwork isolation of CUI, and no unnecessary public exposure of managed services.
Logging & monitoringLog coverage and retention findings map to Audit & Accountability (AU) — audit records exist, are protected from unauthorized change, and are retained long enough to support review and incident reconstruction.
Configuration & postureBaseline-drift findings support Configuration Management (CM) and least-functionality practices — enforced secure baselines across accounts, with changes controlled rather than ad hoc.
Framework mappingEvery finding is tied back to the specific NIST SP 800-171 requirement and CMMC level it affects, so the report reads directly against the assessment objectives you will be measured on.

What you get

A findings report organized so it feeds your CMMC readiness: each cloud gap tied to the specific NIST SP 800-171 requirement and family it affects, scoped to the level your contracts require, ranked by risk, with a remediation order your team and your assessor can both follow. It maps to the same requirements behind your SPRS score, so the picture of where you actually stand comes from evidence rather than a checklist. It is read-only readiness work — it does not certify you or change your production environment.

Most relevant to: FinTech, Commercial real estate

Questions

Which CMMC level do you assess against?

We scope to the level your contracts require. For Level 1 that is the fifteen basic FCI safeguards; for Level 2 it is the cloud-technical requirements within the full 110 of NIST SP 800-171. We concentrate on the requirements your cloud configuration actually determines, and flag where a gap would lower your SPRS score.

Is this a C3PAO assessment — does it certify us?

No. Level 2 certification is performed by an authorized C3PAO (or by self-assessment where a contract permits), and higher assurance is assessed by the government. The health check is readiness work: it finds and prioritizes the cloud gaps that would otherwise surface during that assessment, so you go in prepared. It does not certify you.

We run in a cloud — doesn't that make us compliant?

No. Under DFARS 252.204-7012, a cloud service that stores or processes CUI must meet FedRAMP Moderate or equivalent — which is why GovCloud and region choices matter — but the platform meeting that bar does not satisfy 800-171 for you. The access, encryption, logging, and configuration practices still live in how your environment is set up, and that is what we assess.

Framework work in practice

Evidence rooms and compliance tables

Mapping is for auditors and operators — shown in the spaces where evidence is reviewed.

Take free readiness check