Keep your defense contracts. Show your assessor the proof.

AIC CMMC Complete™ runs the controls that Cybersecurity Maturity Model Certification (CMMC) asks for, and each control keeps its own record. Sign-in with multifactor authentication (MFA), privileged access, endpoint elevation, configuration compliance, workforce training, incident records, and the assessment evidence package work as one system, with one roster and one audit trail. When the assessor asks who used an administrator account, who approved it, and who finished training, you open the record.

Explore Level 1 | Explore Level 2 | Explore Level 3 | See how each requirement is met

14982 of 11011
CMMC requirements mapped across Level 1, Level 2, and Level 3 by official identifierLevel 2 requirements the kit performs or directly assistsCapabilities in one kit, shown in the tour below

How the kit solves each level

Each kit includes the one below it. You move up a level on the same system, without rebuilding.

Level 1: protect Federal Contract Information

For companies that handle Federal Contract Information (FCI). 15 requirements from Federal Acquisition Regulation (FAR) clause 52.204-21, with an annual self-assessment.

Named-person sign-in with MFA, and role checks on every page
Configuration compliance that finds flaws, repairs known settings, and can block a failing system
An encrypted document vault, with optional governed mail
The Assessment Binder, which also stores your records for locks, visitors, and media disposal

Kit role: 6 Performs, 2 Assists, 7 Records. Explore how the kit solves Level 1

Level 2: protect Controlled Unclassified Information

For companies that handle Controlled Unclassified Information (CUI). 110 requirements from National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 Rev 2, assessed by your company or by a CMMC Third-Party Assessment Organization (C3PAO), as your contract states.

Everything in Level 1
Privileged credential vault, approved privileged sessions with command restriction, and just-in-time (JIT) endpoint elevation
Training and signed attestation for named people
Tamper-evident audit records, log forwarding, and incident records
CUI marking, governed mail, and the Plan of Action and Milestones (POA&M)

Kit role: 41 Performs, 41 Assists, 28 Records. Explore how the kit solves all 110 Level 2 requirements

Level 3: defend against advanced threats

For companies on priority programs. 24 requirements selected from NIST SP 800-172, added to Level 2, with a government assessment.

Everything in Level 2
An isolated Jump server that separates and records every Secure Shell (SSH), Remote Desktop Protocol (RDP), and Virtual Network Computing (VNC) session
Automated drift detection and repair, and blocking of untrusted systems
Threat feeds at sign-in and an attack report mapped to MITRE ATT&CK
The NIST SP 800-172 map in the Assessment Binder

Kit role: 4 Performs, 17 Assists, 3 Records. Explore how the kit solves the 24 Level 3 requirements

CMMC is already in your contracts

If you handle FCI or CUI for the Department of War (DoW), your prime contractor flows down Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012. That clause requires the 110 requirements of NIST SP 800-171. A senior official at your company affirms the score you post in the Supplier Performance Risk System (SPRS). A score you cannot support with records is a False Claims Act risk.

On July 13, 2026, the Department suspended CMMC Phase 2 third-party certification. The pause changed who verifies compliance and when. It did not remove the requirements, the SPRS affirmation, or the prime's need to know its suppliers are protected.

Sources: Department of War announcement, Final CMMC rule, 89 FR 83092.

The capability tour

Each stop shows a capability, what it does for your CMMC program, the requirements it closes, and the kits that include it.

1. Sign-in, MFA, and conditional access

Every person signs in as a named identity, from your directory or a local account, and passes a second step. Conditional access checks country, network address, and threat feeds before access starts. Repeated failures lock the account.

Sign-in policy covers multifactor authentication, passkeys, password rules, and lockout.

2. Privileged credential vault

Privileged Identity Management (PIM) holds administrator passwords in a vault. People check out an account for a limited time, and the kit rotates the password afterward and pushes the new one to every service that uses it. No one keeps a standing administrator password.

  • Requirements: AC.L2-3.1.5, AC.L2-3.1.6, IA.L2-3.5.7, IA.L2-3.5.9
  • Kits: Level 2 and Level 3
  • Explore:Level 2 Access Control
Privileged credentials are vaulted and rotated. Operators never see the secret.

3. Approved privileged sessions with command restriction

Privileged Access Management (PAM) brokers SSH, RDP, and VNC sessions in the browser. Each session needs approval, uses a vaulted credential without showing it, and ends at its timeout. Command restriction blocks a disallowed command as it is typed.

Command restriction allows or denies SSH commands by rule, with a default deny and a test tool.

4. Just-in-time endpoint elevation

Privileged User Management (PUM) gives a user administrator rights for one approved task and removes them afterward. Users keep no standing administrator rights, and every privileged action is logged with the person's name. Windows is the most complete today.

Just-in-time elevation works with an agent, without an agent, and on air-gapped systems through one-time codes.

5. Configuration compliance and Current State Compliance

Configuration compliance checks each enrolled system against its approved baseline configuration. Fix-It repairs known settings, findings it cannot repair are flagged for IT, and a failing system can be blocked. Current State Compliance rescans each control and records drift, so the evidence stays current between assessments.

Measurement and Mitigation checks the environment against the selected framework and level.

6. Workforce training and signed attestation

The kit assigns training from 53 ready-made templates to named employees and contractors, sends reminders, and stores each signed attestation with the document version and date. Completion reports show who is done and who is late.

The workforce roster tracks who must train, including contractors, and records exclusions.

7. CUI marking, governed mail, and the document vault

Data classification marks FCI and CUI, checks each person's clearance before release, and records every release. Governed mail and the document vault keep CUI on protected paths, encrypted in transit.

One marking catalog ranks CMMC, US government, and NATO markings by sensitivity.

8. Tamper-evident audit records and log forwarding

The kit records sign-in, access, elevation, sessions, configuration changes, and secret actions. Records cannot be edited in place, and exports are hash-chained so a changed record is detectable. Records forward to your security information and event management (SIEM) system as syslog.

Security events forward to your SIEM over RFC 5424 syslog.

9. Incident records and alerts

Incident Response records each incident, runs detections, and alerts the right people by email, text message, and ticket. Each record keeps its status and history through closure.

A live security event feed shows sign-ins, configuration changes, and vault activity as they happen.

10. Assessment Binder, POA&M, and system security plan

The Assessment Binder assembles the evidence from every capability above into one package for your team, your Managed Service Provider (MSP), and your assessor. It holds the POA&M and the risk register, supports the system security plan (SSP) with a narrative wizard, and stores your records for physical, personnel, and policy requirements.

  • Requirements: CA.L2-3.12.1, CA.L2-3.12.2, CA.L2-3.12.4, RA.L3-3.11.4e, and every requirement with the kit role Records
  • Kits: every kit. The NIST SP 800-172 map is in Level 3
  • Explore:Level 2 Security Assessment
The Assessment Binder builds a living evidence package for each framework, shared by the assessor, the MSP, and the customer.

11. Isolated Jump with session recording and threat-informed defense

The Level 3 Jump server separates privileged sessions from the rest of the network and records each SSH, RDP, and VNC session for replay. Threat feeds drive sign-in blocking, and the attack report maps blocked attacks to MITRE ATT&CK.

  • Requirements: SC.L3-3.13.4e, RA.L3-3.11.1e, RA.L3-3.11.2e, SI.L3-3.14.6e
  • Kits: Level 3. Threat feeds at sign-in are in every kit
  • Explore:Level 3 requirements
RDP sessions are recorded as encrypted video, with the same reason-gated, audited playback.

How the kit meets each CMMC requirement

Every requirement on the level pages is listed by its official identifier and short name from 32 CFR 170.14. Each row says how much of the work the kit does, how the feature does it, whether it is available now, and what your team still does by hand.

  • Performs: on the systems the kit manages, the feature carries out the requirement.
  • Assists: the kit supplies the tool, workflow, or record, and your people carry out the requirement.
  • Records: the requirement is physical, personnel, or policy work, such as door locks, visitor escort, and background screening. The Assessment Binder stores your record of it.
LevelRequirementsPerformsAssistsRecordsFull mapping
Level 1 (FAR 52.204-21)15627The 15 Level 1 requirements
Level 2 (NIST SP 800-171 Rev 2)110414128All 110 Level 2 requirements
Level 3 (selected NIST SP 800-172)244173The 24 Level 3 requirements

All three levels on one page: CMMC Level 1, Level 2, and Level 3 requirements.

Evidence the assessor can check

Many CMMC tools help you write about your controls. Assessors also ask to see them work. In AIC CMMC Complete™, the record is created by the control as it runs.

The assessor asksWhere the answer comes from
Who has administrator access, and who approved it?PIM and PAM keep each checkout, approval, and session, by named person
Did everyone with CUI access finish training?Each person's signed attestation, with the document version and date
Are your systems still on the approved baseline?Configuration compliance results and the drift record from each rescan
What happened when an incident was reported?The incident record, from report through alerts to closure
What is still open?The POA&M in the Assessment Binder, linked to each requirement

Buyer checklist

Competitors usually sell one part of the job: a compliance tracker, secure email and files, a password vault, a remote access tool, or an endpoint privilege tool. Each has its own sign-in, its own records, and its own integration to maintain.

What a CMMC program needsUsually bought asIn AIC CMMC Complete™
Requirement mapping, evidence package, and POA&MCompliance trackerIncluded, every kit. All 110 requirements at Level 2 and up
Control rescan and drift recordCompliance trackerIncluded, every kit
Configuration compliance against approved baselinesEndpoint management toolIncluded, wider scope planned
Governed email and a document vault for FCI and CUISecure email and file productsIncluded. Email is optional on Level 1
Sign-in with your identity provider and MFAIdentity productIncluded, every kit
Administrator password vault and rotationPassword vaultIncluded, Level 2 and up
Approved, restricted SSH, RDP, and VNC sessionsRemote access toolIncluded, Level 2 and up
Session recording with replayPrivileged access suiteIncluded, Level 3
Endpoint elevation and least privilegeEndpoint privilege toolIncluded, Level 2 and up
Training assignment and signed attestationLearning management systemIncluded, Level 2 and up
Incident records and alertsIncident toolIncluded, Level 2 and up
Encryption through AWS-LC, which holds a Federal Information Processing Standards (FIPS) 140-3 certificate, with keys you holdKey management productIncluded, every kit

The full list, with the status of each item, is on Capabilities.

What stays with your team

The kit does not lock doors, escort visitors, or screen employees. For those requirements, marked Records on the level pages, your team does the work and the Assessment Binder stores your record of it. Each level page lists what you still do by hand, requirement by requirement.

For subcontractors, primes, and MSPs

  • Subcontractors. You sign for your own SPRS score. The kit gives you working controls and the records to back that score. You keep exclusive control of your keys, identities, and access rules.
  • Primes. Give every supplier the same controls and the same evidence format instead of a questionnaire. You can pay for supplier kits through a Microsoft Azure private offer. You see only what each supplier chooses to share. See CMMC for defense contractors and their suppliers.
  • MSPs. Run one playbook for every customer. The customer grants you scoped, temporary access inside their boundary. See MSP partners.

Where it runs

Initial launch partner: Microsoft Azure Commercial Marketplace. All current AIC CMMC Complete™ kits (Level 1, Level 2, and Level 3) are available now there. The kit launches into your own Azure subscription. You hold the keys and the identities. Microsoft bills Azure usage.

Also Available now: customer installation on any cloud you use (Microsoft Azure, Amazon Web Services, Google Cloud, and Oracle Cloud Infrastructure virtual machines, including Windows and Linux images), on premises, and air-gapped systems. Analog Informatics Corporation (AIC) does not host your data.

Planned, based on customer demand: Google Cloud, Amazon Web Services (AWS), and Oracle Cloud marketplaces, and Government Community Cloud (GCC) and Federal Risk and Authorization Management Program (FedRAMP) environment support.

You can deploy the kit as a separate secure enclave or protect your existing environment in place. See Secure enclaves and Deployment and integrations.

Three kits

FeatureLevel 1Level 2Level 3
ForFCICUICUI on priority programs
IncludesAIC Server, Assessment Binder, Current State Compliance, and the document vault for 5 named usersEverything in Level 1, plus 25 managed systems, PIM, PAM with command restriction, PUM, Identity Governance and Administration (IGA), audit, incident records, and training and attestation for 25 peopleEverything in Level 2, plus the isolated Jump server with session recording and the NIST SP 800-172 mapping
ExploreHow the kit solves Level 1How the kit solves Level 2How the kit solves Level 3

Cloud usage is billed by Microsoft. Add-ons and prepay terms are on AIC CMMC Complete™ pricing.

Frequently asked questions

Which level do we need?

Level 1 if you handle only FCI. Level 2 if you handle CUI. Level 3 if a contract for a priority program requires it. Your contract and the data you receive decide it. See How the kit solves each level.

Do we still need this after the July 2026 pause?

Yes, if you handle CUI. DFARS 252.204-7012 still requires the 110 requirements of NIST SP 800-171, and your company still affirms its SPRS score.

Which kit feature covers which requirement?

The Level 1, Level 2, and Level 3 pages list every requirement by its official identifier, with the kit role, how the feature meets or supports it, its availability, and what your team still does by hand.

Is this software as a service?

No. The kit runs in your own Azure subscription, on another cloud you use, or on premises. AIC does not host your data. You hold the keys.

Can a prime pay for its suppliers?

Yes, through a Microsoft Azure private offer. Each supplier keeps exclusive control of its own system.

Does the kit pass the assessment for us?

No product can. An assessment organization, or for Level 3 the government, decides the outcome. The kit gives you the controls, the training, and the records to do the work and to show it.

See it on your use case

Request a demo