Compliance
CMMC compliance, simplified
Meet the US Department of Defense CMMC 2.0 requirements for protecting CUI and FCI across all maturity levels.
What CMMC requires
CMMC 2.0 requires defense contractors to protect Controlled Unclassified Information (CUI) and Federal Contract Information (FCI) at one of three maturity levels: Foundational, Advanced or Expert. The technical requirements map closely to NIST SP 800-171, and SecureTrust Cyber provides the controls and evidence to demonstrate them.
Requirements mapped
How SecureTrust Cyber helps you meet CMMC
| Requirement | How SecureTrust satisfies it |
|---|---|
| AC.L2: Access control | Identity- and context-based least-privilege access to systems holding CUI. → Universal ZTNA |
| AU.L2: Audit & accountability | Centralized log collection and correlation produce a complete audit trail. → SIEM Platform |
| CM.L2: Configuration management | Continuous configuration assessment against CIS benchmarks. → SIEM Platform |
| SC.L2: System & communications protection | Microsegmentation and TLS inspection protect systems and data in transit. → Firewall-as-a-Service |
| SI.L2: System & information integrity | Inline IPS and DLP prevent unauthorized modification and exfiltration of CUI. → Intrusion Prevention System |
| RA.L2: Risk assessment & vulnerability management | Automated patching and vulnerability detection reduce exposure. → Managed Patch Management |
Evidence
How SecureTrust helps you demonstrate compliance
Access audit
Records of least-privilege access to CUI and FCI.
Audit logs
Centralized, searchable event logs for audit and accountability.
Configuration evidence
CIS-benchmark assessment reports for configuration management.
Vulnerability evidence
Patch coverage and vulnerability reports for risk assessment.
FAQ
Frequently asked questions
What CMMC level do I need?
Does SecureTrust Cyber make me CMMC certified?
Prove compliance, not just claim it
See how SecureTrust Cyber maps to your obligations.