AIC CMMC Complete™ for defense contractors and their suppliers

Defense contractors can give their subcontractors a working CMMC environment instead of a checklist. A prime pays, through Microsoft, for AIC CMMC Complete™ for the suppliers that handle its Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). Each supplier controls its own enclave, and a Managed Service Provider (MSP) can deploy the same standard enclave for every supplier. Every supplier gets the same tools, the same training, and the same evidence format.

Short answers

Can a prime contractor pay for the kit for its subcontractors?

Yes. The prime pays Microsoft, and each subcontractor's usage is billed to the prime. Primes with an existing Microsoft Azure consumption commitment can often apply that spend, where the offer is eligible for it. We are starting with Azure private offers for our first customers.

Who controls the environment?

Only the subcontractor. Paying for the environment does not give the prime access to it. The subcontractor manages its own encryption keys, identities, and access rules.

Who deploys and runs it?

The subcontractor, or a Managed Service Provider (MSP) the subcontractor gives temporary access to, at its own discretion and in line with government requirements for outside service providers. The kit is the same every time, so one playbook works for every supplier. A prime may also choose to pay for the MSP. An experienced MSP improves the odds of success for a supplier that has never deployed CMMC.

How does a supplier start?

The enclave launches from the Microsoft Azure Commercial Marketplace into the supplier's own Azure subscription.

Is it software as a service?

No. The enclave is infrastructure the subcontractor controls. Analog Informatics does not host the supplier's data. Analog Informatics is a member of the Microsoft AI Cloud Partner Program. Membership reflects a cooperative relationship. It is not an endorsement by Microsoft.

How do people work with CUI?

FCI and CUI move into the enclave and stay there. People work through virtual desktops reached over a secure gateway, and share files through the AIC secure share document vault with classification markings.

What can the prime see?

Only what the supplier chooses to share. Each supplier's Assessment Binder holds records created by the system, and the supplier decides what the prime sees.

What each supplier gets

NeedWhat the kit providesKit level
A protected place for FCIAssessment Binder, Current State Compliance, and the AIC secure share document vaultLevel 1 and up
A protected place for CUIIsolated enclave with a secure gateway, identity and access management, and virtual desktopsLevel 2 and up
Privileged access controlPrivileged Identity Management (PIM), Privileged Access Management (PAM), and Privileged User Management (PUM)Level 2 and up
Workforce trainingTraining and awareness packs, roster, reminders, and signed attestationsLevel 2 and up
Session recording and enhanced requirementsIsolated Jump with session recording and NIST SP 800-172 mappingLevel 3
EvidenceAssessment Binder shared by the supplier, its MSP, and its assessorAll levels

The Level 2 kit includes the Level 1 kit. The Level 3 kit includes the Level 2 kit.

How a prime rolls it out

  1. Pick the suppliers. List the subcontractors that receive FCI or CUI, and the CMMC level each one needs.
  2. Arrange the purchase. We set up an Azure private offer. The prime pays Microsoft for each supplier enclave at the level that supplier needs.
  3. Choose the MSP. The supplier grants access to the MSP. It can be your MSP, the supplier's own MSP, or an AIC partner. Resellers and service providers you already work with are welcome. The prime may pay the MSP's fees.
  4. Launch the enclaves. Each supplier's enclave launches from the Microsoft Azure Commercial Marketplace. The supplier controls its keys, identities, and access rules from day one.
  5. Move the data. Suppliers move FCI and CUI into the enclave and work there.
  6. Train and attest. Each supplier's workforce completes training and signs attestations inside the kit.
  7. Keep the evidence current. Current State Compliance rescans controls, and the Assessment Binder stays up to date.

Built by people who work to the harder standard

Analog Informatics Corporation (AIC) works to NIST SP 800-53, the larger federal control catalog that NIST SP 800-171 is drawn from. From that experience we built simplified enclaves a small supplier can use right away.

Suppliers that handle export-controlled data under the International Traffic in Arms Regulations (ITAR) should confirm with counsel whether a government cloud region is required.

An assessment organization, and in some cases the government, decides whether an organization meets CMMC. The kit gives each supplier the tools, the training, and the records to do the work and to show it.

Screenshots

The Assessment Binder builds a living evidence package for each framework, shared by the assessor, the MSP, and the customer.
The document sharing vault stores and shares FCI and CUI with classification markings.
53 training templates are built in and mapped to the clauses they address.

Talk to us

Ask about subscriptions for your suppliers, MSP partners, and free training. Read more in the blog post The ticking time bomb in the defense supply chain.

Deployment and marketplace availability

Available now: Microsoft Azure Commercial Marketplace is the initial launch partner for AIC CMMC Complete™. All current Level 1, Level 2, and Level 3 kits are listed there. Customers can also install the solution themselves on any cloud they use.

Planned, based on customer demand: Google Cloud, Amazon Web Services (AWS), and Oracle Cloud marketplace support.

Planned, with implementation roadmaps based on customer demand: Government Community Cloud (GCC) and Federal Risk and Authorization Management Program (FedRAMP) environment support across cloud platforms.

See it on your use case

Request a demo