AIC CMMC Complete™ for defense contractors and their suppliers
Defense contractors can give their subcontractors a working CMMC environment instead of a checklist. A prime pays, through Microsoft, for AIC CMMC Complete™ for the suppliers that handle its Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). Each supplier controls its own enclave, and a Managed Service Provider (MSP) can deploy the same standard enclave for every supplier. Every supplier gets the same tools, the same training, and the same evidence format.
Short answers
Can a prime contractor pay for the kit for its subcontractors?
Yes. The prime pays Microsoft, and each subcontractor's usage is billed to the prime. Primes with an existing Microsoft Azure consumption commitment can often apply that spend, where the offer is eligible for it. We are starting with Azure private offers for our first customers.
Who controls the environment?
Only the subcontractor. Paying for the environment does not give the prime access to it. The subcontractor manages its own encryption keys, identities, and access rules.
Who deploys and runs it?
The subcontractor, or a Managed Service Provider (MSP) the subcontractor gives temporary access to, at its own discretion and in line with government requirements for outside service providers. The kit is the same every time, so one playbook works for every supplier. A prime may also choose to pay for the MSP. An experienced MSP improves the odds of success for a supplier that has never deployed CMMC.
How does a supplier start?
The enclave launches from the Microsoft Azure Commercial Marketplace into the supplier's own Azure subscription.
Is it software as a service?
No. The enclave is infrastructure the subcontractor controls. Analog Informatics does not host the supplier's data. Analog Informatics is a member of the Microsoft AI Cloud Partner Program. Membership reflects a cooperative relationship. It is not an endorsement by Microsoft.
How do people work with CUI?
FCI and CUI move into the enclave and stay there. People work through virtual desktops reached over a secure gateway, and share files through the AIC secure share document vault with classification markings.
What can the prime see?
Only what the supplier chooses to share. Each supplier's Assessment Binder holds records created by the system, and the supplier decides what the prime sees.
What each supplier gets
| Need | What the kit provides | Kit level |
|---|---|---|
| A protected place for FCI | Assessment Binder, Current State Compliance, and the AIC secure share document vault | Level 1 and up |
| A protected place for CUI | Isolated enclave with a secure gateway, identity and access management, and virtual desktops | Level 2 and up |
| Privileged access control | Privileged Identity Management (PIM), Privileged Access Management (PAM), and Privileged User Management (PUM) | Level 2 and up |
| Workforce training | Training and awareness packs, roster, reminders, and signed attestations | Level 2 and up |
| Session recording and enhanced requirements | Isolated Jump with session recording and NIST SP 800-172 mapping | Level 3 |
| Evidence | Assessment Binder shared by the supplier, its MSP, and its assessor | All levels |
The Level 2 kit includes the Level 1 kit. The Level 3 kit includes the Level 2 kit.
How a prime rolls it out
- Pick the suppliers. List the subcontractors that receive FCI or CUI, and the CMMC level each one needs.
- Arrange the purchase. We set up an Azure private offer. The prime pays Microsoft for each supplier enclave at the level that supplier needs.
- Choose the MSP. The supplier grants access to the MSP. It can be your MSP, the supplier's own MSP, or an AIC partner. Resellers and service providers you already work with are welcome. The prime may pay the MSP's fees.
- Launch the enclaves. Each supplier's enclave launches from the Microsoft Azure Commercial Marketplace. The supplier controls its keys, identities, and access rules from day one.
- Move the data. Suppliers move FCI and CUI into the enclave and work there.
- Train and attest. Each supplier's workforce completes training and signs attestations inside the kit.
- Keep the evidence current. Current State Compliance rescans controls, and the Assessment Binder stays up to date.
Built by people who work to the harder standard
Analog Informatics Corporation (AIC) works to NIST SP 800-53, the larger federal control catalog that NIST SP 800-171 is drawn from. From that experience we built simplified enclaves a small supplier can use right away.
Suppliers that handle export-controlled data under the International Traffic in Arms Regulations (ITAR) should confirm with counsel whether a government cloud region is required.
An assessment organization, and in some cases the government, decides whether an organization meets CMMC. The kit gives each supplier the tools, the training, and the records to do the work and to show it.
Screenshots
Talk to us
Ask about subscriptions for your suppliers, MSP partners, and free training. Read more in the blog post The ticking time bomb in the defense supply chain.
Deployment and marketplace availability
Available now: Microsoft Azure Commercial Marketplace is the initial launch partner for AIC CMMC Complete™. All current Level 1, Level 2, and Level 3 kits are listed there. Customers can also install the solution themselves on any cloud they use.
Planned, based on customer demand: Google Cloud, Amazon Web Services (AWS), and Oracle Cloud marketplace support.
Planned, with implementation roadmaps based on customer demand: Government Community Cloud (GCC) and Federal Risk and Authorization Management Program (FedRAMP) environment support across cloud platforms.
Related References
- CMMC: Kits, Level 1, Level 2, Level 3, Defense contractors, C3PAO
- Defense contract requirements: SPRS score, DFARS 252.204-7012, DFARS 252.204-7021, NIST SP 800-171 self-assessment, CUI marking, CMMC Phase 2