CMMC solutions by level, stage, and use case

Cybersecurity Maturity Model Certification (CMMC) is a program, not a single purchase. An organization scopes its environment, closes gaps, prepares evidence, is assessed, closes open items, and affirms every year. Analog Informatics Corporation (AIC) provides tools for each of those stages, at Level 1, Level 2, and Level 3. A secure enclave is one of many ways to use them. The same tools protect an existing environment in place, a hybrid environment, air-gapped systems, and every supplier in a prime contractor's supply chain.

The grids below show which tool does which job. The organization and its assessor decide whether a requirement is satisfied.

One kit across the CMMC lifecycleA circle of eight labeled stages - scope, gap, remediate, document, assess, close out, affirm, monitor - around a center box labeled one kit, one roster, one audit trail.ScopeGapRemediateDocumentAssessClose outAffirmMonitorOne kitOne rosterOne audit trail
Eight stages - scope, gap, remediate, document, assess, close out, affirm, monitor - run on the same kit and the same records.

By level

FeatureLevel 1Level 2Level 3
ProtectsFederal Contract Information (FCI)Controlled Unclassified Information (CUI)CUI with enhanced requirements
Requirement set15 requirements of FAR 52.204-21110 requirements of NIST SP 800-171 Rev 2Level 2 plus selected NIST SP 800-172 requirements
AssessmentAnnual self-assessment and affirmationSelf-assessment or third-party assessment, plus annual affirmationGovernment assessment, plus annual affirmation
AIC toolsAIC Server, Assessment Binder, Current State Compliance, document vault, sign-in with MFA, system component inventoryLevel 1 tools plus Privileged Identity Management (PIM), Privileged Access Management (PAM) with command restriction, Privileged User Management (PUM), Identity Governance and Administration (IGA) for kit accounts, configuration compliance, incident records, training and attestationLevel 2 tools plus isolated Jump with session recording and NIST SP 800-172 mapping
Move upSame roster and recordsSame roster and recordsSame roster and records

By stage

StageWhat the organization must doAIC toolRecord produced
1. ScopeFind where FCI and CUI live and which systems and people touch itDiscovery of systems and accounts, system component inventory, classification marking, roster with a recorded scope basis per personInventory, scoped roster, data markings
2. Gap assessmentCompare current state against every requirementCurrent State Compliance against the 15, 110, or Level 3 requirement setFinding per requirement with Live, Partial, or Absent status
3. RemediateClose technical gapsCredential vaulting and rotation, brokered sessions, endpoint elevation, configuration compliance with repair where a repair path exists, MFA, conditional accessRotation history, session records, elevation records, configuration drift findings
4. DocumentWrite the System Security Plan (SSP) and the Plan of Action and Milestones (POA&M)Assessment Binder narrative sections per requirement, POA&M items, and a risk registerBinder sections, POA&M items with owners
5. Train the workforceTrain named people and collect attestationsTraining assignments, welcome letters, reminders, and signed attestationsAttestation per person and document version
6. AssessShow the assessor the evidenceRead-only assessor access and the Assessment Binder exportBinder built from live records
7. Close outClose POA&M items within 180 days of a conditional statusPOA&M tracking and Current State Compliance rescanRescan result per closed item
8. AffirmA senior official affirms compliance every yearCurrent State Compliance status and Binder history as the basis for the affirmationDated status history
9. MonitorKeep controls working between assessmentsContinuous rescan, alerts, and forwarding to a security information and event management (SIEM) systemDrift record and alerts
10. Report incidentsReport cyber incidents under DFARS 252.204-7012Incident records, notices, and evidence exportIncident record with timeline

By use case

Use caseWho it fitsHow the kit is used
Secure enclaveOrganizations that want CUI in one isolated environmentPre-configured enclave with isolated network, secure gateway, governed mail, and document vault
In-place environmentOrganizations that keep CUI on their existing systemsAgents and agentless management on existing Windows, macOS, and Linux systems and directories
HybridOrganizations with some CUI in an enclave and some in placeOne server manages both, with one roster
Air-gapped systemsLabs, test benches, and classified-adjacent systemsThe full product runs with no internet connection
Managed Service Provider (MSP)MSPs serving many defense contractorsOne playbook and one design for every customer. Each customer grants the MSP scoped, revocable access
Prime contractor supply chainPrimes that need their suppliers protectedEvery supplier runs the same kit. The prime can pay for supplier kits
Assessor accessThird-party assessors and government assessorsRead-only access to the Assessment Binder and records
Operational Technology (OT)Plants and test equipment in scopeInventory and credential management for industrial devices
Workforce trainingEvery person in scopeAssignments, reminders, and signed attestations
Incident reportingEvery organization handling CUIIncident records, notices, and evidence
Physical and personnel securityFacilities and screeningPolicy templates, checklists, attestations, and attachment slots for outside records

By role

RoleWhat they get
Senior official who affirmsDated status per requirement and Binder history
IT administratorOne console for credentials, sessions, elevation, configuration compliance, and findings
Workforce memberAssigned training and a simple attestation, with no console account needed
MSPOne design for every customer, scoped access inside each customer boundary
Prime contractorThe same kit across suppliers, with only what each supplier chooses to share
AssessorRead-only access to live evidence

Frequently asked questions

Is AIC only a CMMC enclave?

No. An enclave is one use case. The same kit protects in-place, hybrid, and air-gapped environments, and supports MSPs and prime contractor supply chains.

Does AIC cover Level 1, Level 2, and Level 3?

Yes. There is one kit per level. Each level includes the one below it, on the same roster and records.

Where can I get the kits?

Available now: all current CMMC solutions on the Microsoft Azure Commercial Marketplace, and customer installation on any cloud you use. Planned, based on customer demand: Amazon Web Services (AWS), Google Cloud, and Oracle Cloud marketplace listings. Planned, with implementation roadmaps based on customer demand: Government Community Cloud (GCC) and Federal Risk and Authorization Management Program (FedRAMP) environment support across cloud platforms. See Deployment and integrations.

Does the kit certify an organization?

No. The kit provides the tools and records. The assessor decides whether each requirement is satisfied.

Next step

See the kit on your own use case. Request a demo.