Keep your defense contracts. Show your assessor the proof.
AIC CMMC Complete™ runs the controls that Cybersecurity Maturity Model Certification (CMMC) asks for, and each control keeps its own record. Sign-in with multifactor authentication (MFA), privileged access, endpoint elevation, configuration compliance, workforce training, incident records, and the assessment evidence package work as one system, with one roster and one audit trail. When the assessor asks who used an administrator account, who approved it, and who finished training, you open the record.
Explore Level 1 | Explore Level 2 | Explore Level 3 | See how each requirement is met
| 149 | 82 of 110 | 11 |
|---|---|---|
| CMMC requirements mapped across Level 1, Level 2, and Level 3 by official identifier | Level 2 requirements the kit performs or directly assists | Capabilities in one kit, shown in the tour below |
How the kit solves each level
Each kit includes the one below it. You move up a level on the same system, without rebuilding.
Level 1: protect Federal Contract Information
For companies that handle Federal Contract Information (FCI). 15 requirements from Federal Acquisition Regulation (FAR) clause 52.204-21, with an annual self-assessment.
- Named-person sign-in with MFA, and role checks on every page
- Configuration compliance that finds flaws, repairs known settings, and can block a failing system
- An encrypted document vault, with optional governed mail
- The Assessment Binder, which also stores your records for locks, visitors, and media disposal
Kit role: 6 Performs, 2 Assists, 7 Records. Explore how the kit solves Level 1
Level 2: protect Controlled Unclassified Information
For companies that handle Controlled Unclassified Information (CUI). 110 requirements from National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 Rev 2, assessed by your company or by a CMMC Third-Party Assessment Organization (C3PAO), as your contract states.
- Everything in Level 1
- Privileged credential vault, approved privileged sessions with command restriction, and just-in-time (JIT) endpoint elevation
- Training and signed attestation for named people
- Tamper-evident audit records, log forwarding, and incident records
- CUI marking, governed mail, and the Plan of Action and Milestones (POA&M)
Kit role: 41 Performs, 41 Assists, 28 Records. Explore how the kit solves all 110 Level 2 requirements
Level 3: defend against advanced threats
For companies on priority programs. 24 requirements selected from NIST SP 800-172, added to Level 2, with a government assessment.
- Everything in Level 2
- An isolated Jump server that separates and records every Secure Shell (SSH), Remote Desktop Protocol (RDP), and Virtual Network Computing (VNC) session
- Automated drift detection and repair, and blocking of untrusted systems
- Threat feeds at sign-in and an attack report mapped to MITRE ATT&CK
- The NIST SP 800-172 map in the Assessment Binder
Kit role: 4 Performs, 17 Assists, 3 Records. Explore how the kit solves the 24 Level 3 requirements
CMMC is already in your contracts
If you handle FCI or CUI for the Department of War (DoW), your prime contractor flows down Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012. That clause requires the 110 requirements of NIST SP 800-171. A senior official at your company affirms the score you post in the Supplier Performance Risk System (SPRS). A score you cannot support with records is a False Claims Act risk.
On July 13, 2026, the Department suspended CMMC Phase 2 third-party certification. The pause changed who verifies compliance and when. It did not remove the requirements, the SPRS affirmation, or the prime's need to know its suppliers are protected.
Sources: Department of War announcement, Final CMMC rule, 89 FR 83092.
The capability tour
Each stop shows a capability, what it does for your CMMC program, the requirements it closes, and the kits that include it.
1. Sign-in, MFA, and conditional access
Every person signs in as a named identity, from your directory or a local account, and passes a second step. Conditional access checks country, network address, and threat feeds before access starts. Repeated failures lock the account.
- Requirements: AC.L1-b.1.i, IA.L1-b.1.v, IA.L1-b.1.vi, IA.L2-3.5.3, AC.L2-3.1.12, IA.L3-3.5.3e
- Kits: every kit
- Explore:Level 1 requirements | Level 2 Identification and Authentication
2. Privileged credential vault
Privileged Identity Management (PIM) holds administrator passwords in a vault. People check out an account for a limited time, and the kit rotates the password afterward and pushes the new one to every service that uses it. No one keeps a standing administrator password.
- Requirements: AC.L2-3.1.5, AC.L2-3.1.6, IA.L2-3.5.7, IA.L2-3.5.9
- Kits: Level 2 and Level 3
- Explore:Level 2 Access Control
3. Approved privileged sessions with command restriction
Privileged Access Management (PAM) brokers SSH, RDP, and VNC sessions in the browser. Each session needs approval, uses a vaulted credential without showing it, and ends at its timeout. Command restriction blocks a disallowed command as it is typed.
- Requirements: AC.L2-3.1.2, AC.L2-3.1.12, AC.L2-3.1.15, MA.L2-3.7.5, SC.L2-3.13.4
- Kits: Level 2 and Level 3
- Explore:Level 2 Access Control | Level 2 Maintenance
4. Just-in-time endpoint elevation
Privileged User Management (PUM) gives a user administrator rights for one approved task and removes them afterward. Users keep no standing administrator rights, and every privileged action is logged with the person's name. Windows is the most complete today.
- Requirements: AC.L2-3.1.5, AC.L2-3.1.7, AC.L2-3.1.15
- Kits: Level 2 and Level 3
- Explore:Level 2 Access Control
5. Configuration compliance and Current State Compliance
Configuration compliance checks each enrolled system against its approved baseline configuration. Fix-It repairs known settings, findings it cannot repair are flagged for IT, and a failing system can be blocked. Current State Compliance rescans each control and records drift, so the evidence stays current between assessments.
- Requirements: AC.L1-b.1.iii, SI.L1-b.1.xii, CM.L2-3.4.1, CM.L2-3.4.2, CM.L2-3.4.6, CM.L2-3.4.7, CA.L2-3.12.3, CM.L3-3.4.2e
- Kits: every kit
- Explore:Level 1 requirements | Level 2 Configuration Management | Level 3 requirements
6. Workforce training and signed attestation
The kit assigns training from 53 ready-made templates to named employees and contractors, sends reminders, and stores each signed attestation with the document version and date. Completion reports show who is done and who is late.
- Requirements: AT.L2-3.2.1, AT.L2-3.2.2, AT.L3-3.2.1e, AT.L3-3.2.2e
- Kits: Level 2 and Level 3
- Explore:Level 2 Awareness and Training
7. CUI marking, governed mail, and the document vault
Data classification marks FCI and CUI, checks each person's clearance before release, and records every release. Governed mail and the document vault keep CUI on protected paths, encrypted in transit.
- Requirements: AC.L2-3.1.3, MP.L2-3.8.4, SC.L2-3.13.1, SC.L2-3.13.8, AC.L3-3.1.3e
- Kits: the document vault is in every kit. Governed mail is in Level 2 and Level 3, and optional on Level 1
- Explore:Level 2 Media Protection | Level 2 System and Communications Protection
8. Tamper-evident audit records and log forwarding
The kit records sign-in, access, elevation, sessions, configuration changes, and secret actions. Records cannot be edited in place, and exports are hash-chained so a changed record is detectable. Records forward to your security information and event management (SIEM) system as syslog.
- Requirements: AU.L2-3.3.1, AU.L2-3.3.5, AU.L2-3.3.8
- Kits: Level 2 and Level 3
- Explore:Level 2 Audit and Accountability
9. Incident records and alerts
Incident Response records each incident, runs detections, and alerts the right people by email, text message, and ticket. Each record keeps its status and history through closure.
- Requirements: IR.L2-3.6.1, IR.L2-3.6.2, IR.L3-3.6.1e, IR.L3-3.6.2e
- Kits: Level 2 and Level 3
- Explore:Level 2 Incident Response | Level 3 requirements
10. Assessment Binder, POA&M, and system security plan
The Assessment Binder assembles the evidence from every capability above into one package for your team, your Managed Service Provider (MSP), and your assessor. It holds the POA&M and the risk register, supports the system security plan (SSP) with a narrative wizard, and stores your records for physical, personnel, and policy requirements.
- Requirements: CA.L2-3.12.1, CA.L2-3.12.2, CA.L2-3.12.4, RA.L3-3.11.4e, and every requirement with the kit role Records
- Kits: every kit. The NIST SP 800-172 map is in Level 3
- Explore:Level 2 Security Assessment
11. Isolated Jump with session recording and threat-informed defense
The Level 3 Jump server separates privileged sessions from the rest of the network and records each SSH, RDP, and VNC session for replay. Threat feeds drive sign-in blocking, and the attack report maps blocked attacks to MITRE ATT&CK.
- Requirements: SC.L3-3.13.4e, RA.L3-3.11.1e, RA.L3-3.11.2e, SI.L3-3.14.6e
- Kits: Level 3. Threat feeds at sign-in are in every kit
- Explore:Level 3 requirements
How the kit meets each CMMC requirement
Every requirement on the level pages is listed by its official identifier and short name from 32 CFR 170.14. Each row says how much of the work the kit does, how the feature does it, whether it is available now, and what your team still does by hand.
- Performs: on the systems the kit manages, the feature carries out the requirement.
- Assists: the kit supplies the tool, workflow, or record, and your people carry out the requirement.
- Records: the requirement is physical, personnel, or policy work, such as door locks, visitor escort, and background screening. The Assessment Binder stores your record of it.
| Level | Requirements | Performs | Assists | Records | Full mapping |
|---|---|---|---|---|---|
| Level 1 (FAR 52.204-21) | 15 | 6 | 2 | 7 | The 15 Level 1 requirements |
| Level 2 (NIST SP 800-171 Rev 2) | 110 | 41 | 41 | 28 | All 110 Level 2 requirements |
| Level 3 (selected NIST SP 800-172) | 24 | 4 | 17 | 3 | The 24 Level 3 requirements |
All three levels on one page: CMMC Level 1, Level 2, and Level 3 requirements.
Evidence the assessor can check
Many CMMC tools help you write about your controls. Assessors also ask to see them work. In AIC CMMC Complete™, the record is created by the control as it runs.
| The assessor asks | Where the answer comes from |
|---|---|
| Who has administrator access, and who approved it? | PIM and PAM keep each checkout, approval, and session, by named person |
| Did everyone with CUI access finish training? | Each person's signed attestation, with the document version and date |
| Are your systems still on the approved baseline? | Configuration compliance results and the drift record from each rescan |
| What happened when an incident was reported? | The incident record, from report through alerts to closure |
| What is still open? | The POA&M in the Assessment Binder, linked to each requirement |
Buyer checklist
Competitors usually sell one part of the job: a compliance tracker, secure email and files, a password vault, a remote access tool, or an endpoint privilege tool. Each has its own sign-in, its own records, and its own integration to maintain.
| What a CMMC program needs | Usually bought as | In AIC CMMC Complete™ |
|---|---|---|
| Requirement mapping, evidence package, and POA&M | Compliance tracker | Included, every kit. All 110 requirements at Level 2 and up |
| Control rescan and drift record | Compliance tracker | Included, every kit |
| Configuration compliance against approved baselines | Endpoint management tool | Included, wider scope planned |
| Governed email and a document vault for FCI and CUI | Secure email and file products | Included. Email is optional on Level 1 |
| Sign-in with your identity provider and MFA | Identity product | Included, every kit |
| Administrator password vault and rotation | Password vault | Included, Level 2 and up |
| Approved, restricted SSH, RDP, and VNC sessions | Remote access tool | Included, Level 2 and up |
| Session recording with replay | Privileged access suite | Included, Level 3 |
| Endpoint elevation and least privilege | Endpoint privilege tool | Included, Level 2 and up |
| Training assignment and signed attestation | Learning management system | Included, Level 2 and up |
| Incident records and alerts | Incident tool | Included, Level 2 and up |
| Encryption through AWS-LC, which holds a Federal Information Processing Standards (FIPS) 140-3 certificate, with keys you hold | Key management product | Included, every kit |
The full list, with the status of each item, is on Capabilities.
What stays with your team
The kit does not lock doors, escort visitors, or screen employees. For those requirements, marked Records on the level pages, your team does the work and the Assessment Binder stores your record of it. Each level page lists what you still do by hand, requirement by requirement.
For subcontractors, primes, and MSPs
- Subcontractors. You sign for your own SPRS score. The kit gives you working controls and the records to back that score. You keep exclusive control of your keys, identities, and access rules.
- Primes. Give every supplier the same controls and the same evidence format instead of a questionnaire. You can pay for supplier kits through a Microsoft Azure private offer. You see only what each supplier chooses to share. See CMMC for defense contractors and their suppliers.
- MSPs. Run one playbook for every customer. The customer grants you scoped, temporary access inside their boundary. See MSP partners.
Where it runs
Initial launch partner: Microsoft Azure Commercial Marketplace. All current AIC CMMC Complete™ kits (Level 1, Level 2, and Level 3) are available now there. The kit launches into your own Azure subscription. You hold the keys and the identities. Microsoft bills Azure usage.
Also Available now: customer installation on any cloud you use (Microsoft Azure, Amazon Web Services, Google Cloud, and Oracle Cloud Infrastructure virtual machines, including Windows and Linux images), on premises, and air-gapped systems. Analog Informatics Corporation (AIC) does not host your data.
Planned, based on customer demand: Google Cloud, Amazon Web Services (AWS), and Oracle Cloud marketplaces, and Government Community Cloud (GCC) and Federal Risk and Authorization Management Program (FedRAMP) environment support.
You can deploy the kit as a separate secure enclave or protect your existing environment in place. See Secure enclaves and Deployment and integrations.
Three kits
| Feature | Level 1 | Level 2 | Level 3 |
|---|---|---|---|
| For | FCI | CUI | CUI on priority programs |
| Includes | AIC Server, Assessment Binder, Current State Compliance, and the document vault for 5 named users | Everything in Level 1, plus 25 managed systems, PIM, PAM with command restriction, PUM, Identity Governance and Administration (IGA), audit, incident records, and training and attestation for 25 people | Everything in Level 2, plus the isolated Jump server with session recording and the NIST SP 800-172 mapping |
| Explore | How the kit solves Level 1 | How the kit solves Level 2 | How the kit solves Level 3 |
Cloud usage is billed by Microsoft. Add-ons and prepay terms are on AIC CMMC Complete™ pricing.
Frequently asked questions
Which level do we need?
Level 1 if you handle only FCI. Level 2 if you handle CUI. Level 3 if a contract for a priority program requires it. Your contract and the data you receive decide it. See How the kit solves each level.
Do we still need this after the July 2026 pause?
Yes, if you handle CUI. DFARS 252.204-7012 still requires the 110 requirements of NIST SP 800-171, and your company still affirms its SPRS score.
Which kit feature covers which requirement?
Is this software as a service?
No. The kit runs in your own Azure subscription, on another cloud you use, or on premises. AIC does not host your data. You hold the keys.
Can a prime pay for its suppliers?
Yes, through a Microsoft Azure private offer. Each supplier keeps exclusive control of its own system.
Does the kit pass the assessment for us?
No product can. An assessment organization, or for Level 3 the government, decides the outcome. The kit gives you the controls, the training, and the records to do the work and to show it.