CMMC solutions by level, stage, and use case
Cybersecurity Maturity Model Certification (CMMC) is a program, not a single purchase. An organization scopes its environment, closes gaps, prepares evidence, is assessed, closes open items, and affirms every year. Analog Informatics Corporation (AIC) provides tools for each of those stages, at Level 1, Level 2, and Level 3. A secure enclave is one of many ways to use them. The same tools protect an existing environment in place, a hybrid environment, air-gapped systems, and every supplier in a prime contractor's supply chain.
The grids below show which tool does which job. The organization and its assessor decide whether a requirement is satisfied.
By level
| Feature | Level 1 | Level 2 | Level 3 |
|---|---|---|---|
| Protects | Federal Contract Information (FCI) | Controlled Unclassified Information (CUI) | CUI with enhanced requirements |
| Requirement set | 15 requirements of FAR 52.204-21 | 110 requirements of NIST SP 800-171 Rev 2 | Level 2 plus selected NIST SP 800-172 requirements |
| Assessment | Annual self-assessment and affirmation | Self-assessment or third-party assessment, plus annual affirmation | Government assessment, plus annual affirmation |
| AIC tools | AIC Server, Assessment Binder, Current State Compliance, document vault, sign-in with MFA, system component inventory | Level 1 tools plus Privileged Identity Management (PIM), Privileged Access Management (PAM) with command restriction, Privileged User Management (PUM), Identity Governance and Administration (IGA) for kit accounts, configuration compliance, incident records, training and attestation | Level 2 tools plus isolated Jump with session recording and NIST SP 800-172 mapping |
| Move up | Same roster and records | Same roster and records | Same roster and records |
By stage
| Stage | What the organization must do | AIC tool | Record produced |
|---|---|---|---|
| 1. Scope | Find where FCI and CUI live and which systems and people touch it | Discovery of systems and accounts, system component inventory, classification marking, roster with a recorded scope basis per person | Inventory, scoped roster, data markings |
| 2. Gap assessment | Compare current state against every requirement | Current State Compliance against the 15, 110, or Level 3 requirement set | Finding per requirement with Live, Partial, or Absent status |
| 3. Remediate | Close technical gaps | Credential vaulting and rotation, brokered sessions, endpoint elevation, configuration compliance with repair where a repair path exists, MFA, conditional access | Rotation history, session records, elevation records, configuration drift findings |
| 4. Document | Write the System Security Plan (SSP) and the Plan of Action and Milestones (POA&M) | Assessment Binder narrative sections per requirement, POA&M items, and a risk register | Binder sections, POA&M items with owners |
| 5. Train the workforce | Train named people and collect attestations | Training assignments, welcome letters, reminders, and signed attestations | Attestation per person and document version |
| 6. Assess | Show the assessor the evidence | Read-only assessor access and the Assessment Binder export | Binder built from live records |
| 7. Close out | Close POA&M items within 180 days of a conditional status | POA&M tracking and Current State Compliance rescan | Rescan result per closed item |
| 8. Affirm | A senior official affirms compliance every year | Current State Compliance status and Binder history as the basis for the affirmation | Dated status history |
| 9. Monitor | Keep controls working between assessments | Continuous rescan, alerts, and forwarding to a security information and event management (SIEM) system | Drift record and alerts |
| 10. Report incidents | Report cyber incidents under DFARS 252.204-7012 | Incident records, notices, and evidence export | Incident record with timeline |
By use case
| Use case | Who it fits | How the kit is used |
|---|---|---|
| Secure enclave | Organizations that want CUI in one isolated environment | Pre-configured enclave with isolated network, secure gateway, governed mail, and document vault |
| In-place environment | Organizations that keep CUI on their existing systems | Agents and agentless management on existing Windows, macOS, and Linux systems and directories |
| Hybrid | Organizations with some CUI in an enclave and some in place | One server manages both, with one roster |
| Air-gapped systems | Labs, test benches, and classified-adjacent systems | The full product runs with no internet connection |
| Managed Service Provider (MSP) | MSPs serving many defense contractors | One playbook and one design for every customer. Each customer grants the MSP scoped, revocable access |
| Prime contractor supply chain | Primes that need their suppliers protected | Every supplier runs the same kit. The prime can pay for supplier kits |
| Assessor access | Third-party assessors and government assessors | Read-only access to the Assessment Binder and records |
| Operational Technology (OT) | Plants and test equipment in scope | Inventory and credential management for industrial devices |
| Workforce training | Every person in scope | Assignments, reminders, and signed attestations |
| Incident reporting | Every organization handling CUI | Incident records, notices, and evidence |
| Physical and personnel security | Facilities and screening | Policy templates, checklists, attestations, and attachment slots for outside records |
By role
| Role | What they get |
|---|---|
| Senior official who affirms | Dated status per requirement and Binder history |
| IT administrator | One console for credentials, sessions, elevation, configuration compliance, and findings |
| Workforce member | Assigned training and a simple attestation, with no console account needed |
| MSP | One design for every customer, scoped access inside each customer boundary |
| Prime contractor | The same kit across suppliers, with only what each supplier chooses to share |
| Assessor | Read-only access to live evidence |
Frequently asked questions
Is AIC only a CMMC enclave?
No. An enclave is one use case. The same kit protects in-place, hybrid, and air-gapped environments, and supports MSPs and prime contractor supply chains.
Does AIC cover Level 1, Level 2, and Level 3?
Yes. There is one kit per level. Each level includes the one below it, on the same roster and records.
Where can I get the kits?
Available now: all current CMMC solutions on the Microsoft Azure Commercial Marketplace, and customer installation on any cloud you use. Planned, based on customer demand: Amazon Web Services (AWS), Google Cloud, and Oracle Cloud marketplace listings. Planned, with implementation roadmaps based on customer demand: Government Community Cloud (GCC) and Federal Risk and Authorization Management Program (FedRAMP) environment support across cloud platforms. See Deployment and integrations.
Does the kit certify an organization?
No. The kit provides the tools and records. The assessor decides whether each requirement is satisfied.
Next step
See the kit on your own use case. Request a demo.