Certification · US

CMMC, without the spreadsheets.

Protect Controlled Unclassified Information and stay eligible for defence contracts.

What is CMMC?

CMMC verifies that defence contractors protect Federal Contract Information and Controlled Unclassified Information. Level 2, the level most contractors handling CUI need, aligns with the 110 security requirements of NIST SP 800-171.

Who needs it

  • Contractors and subcontractors in the US defence industrial base
  • Suppliers that store or process CUI
  • Companies bidding on DoD contracts with CMMC clauses

What CMMC looks at

Access control and identification

Limit system access to authorised users and authenticate them, including MFA.

Audit and accountability

Create and retain logs that can trace actions to individual users.

Configuration and incident response

Baseline configurations, change control and an operational incident-handling capability.

System and communications protection

Boundary protection and cryptography for CUI.

How Beviso gets you there

  • Level 2 practices pre-loaded with evidence from identity, logging and endpoint tools
  • Shared evidence with NIST 800-53 and NIST CSF
  • Policy templates for the documented plans assessors ask for

11 CMMC controls, ready on day one

These controls are loaded when you enable CMMC, each with the tools that can supply its evidence automatically. You can add your own controls alongside them.

AC.L2-3.1.1

Authorized Access Control

Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems).

Evidence from

  • Okta
  • AWS
  • Microsoft Azure
  • Google Workspace
  • JumpCloud
  • HashiCorp Vault

AC.L2-3.1.2

Transaction and Function Control

Limit system access to the types of transactions and functions that authorized users are permitted to execute.

Evidence from

  • Okta
  • AWS
  • HashiCorp Vault
  • Microsoft Azure

AC.L2-3.1.5

Least Privilege

Employ the principle of least privilege, including for specific security functions and privileged accounts.

Evidence from

  • AWS
  • Okta
  • HashiCorp Vault
  • GitHub
  • Microsoft Azure

AU.L2-3.3.1

System Auditing

Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.

Evidence from

  • Datadog
  • AWS
  • Okta
  • Splunk
  • HashiCorp Vault

CM.L2-3.4.1

Baseline Configuration

Establish and maintain baseline configurations and inventories of organizational systems.

Evidence from

  • Terraform Cloud
  • AWS
  • Doppler
  • GitHub
  • Jamf
  • Kandji

IA.L2-3.5.3

Multi-Factor Authentication

Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.

Evidence from

  • Okta
  • Duo
  • Microsoft Azure
  • JumpCloud
  • 1Password

IR.L2-3.6.1

Incident Handling

Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.

Evidence from

  • PagerDuty
  • ServiceNow
  • Jira
  • CrowdStrike

RA.L2-3.11.1

Risk Assessment

Periodically assess the risk to organizational operations, organizational assets, and individuals resulting from the operation of organizational systems.

Evidence from

  • Snyk
  • Wiz
  • Qualys
  • Rapid7
  • AWS

SC.L2-3.13.3

Role Separation

Separate the duties of individuals to reduce the risk of malevolent activity without collusion.

Evidence from

  • Okta
  • GitHub
  • GitLab
  • AWS

SI.L2-3.14.1

Flaw Remediation

Identify, report, and correct information and information system flaws in a timely manner.

Evidence from

  • Snyk
  • SonarCloud
  • GitHub
  • Wiz
  • Rapid7

SI.L2-3.14.6

Security Alert Monitoring

Monitor organizational systems including inbound and outbound communications traffic to detect attacks and indicators of potential attacks.

Evidence from

  • CrowdStrike
  • SentinelOne
  • AWS
  • Datadog
  • Splunk
  • Lacework

CMMC questions

Is Beviso FedRAMP authorised for storing CUI?
No. Beviso helps you manage your CMMC programme and evidence. Do not upload CUI itself into Beviso.

Start your CMMC programme today.

Free while Beviso is in beta. No credit card required.

Get started free