SecureTrust
Products
Solutions
Resources
Company
Talk to an Expert

Compliance

CMMC compliance, simplified

Meet the US Department of Defense CMMC 2.0 requirements for protecting CUI and FCI across all maturity levels.

CMMC 2.0NIST SP 800-171NIST SP 800-172

What CMMC requires

CMMC 2.0 requires defense contractors to protect Controlled Unclassified Information (CUI) and Federal Contract Information (FCI) at one of three maturity levels: Foundational, Advanced or Expert. The technical requirements map closely to NIST SP 800-171, and SecureTrust Cyber provides the controls and evidence to demonstrate them.

Requirements mapped

How SecureTrust Cyber helps you meet CMMC

How SecureTrust Cyber helps you meet CMMC
RequirementHow SecureTrust satisfies it
AC.L2: Access control Identity- and context-based least-privilege access to systems holding CUI. → Universal ZTNA
AU.L2: Audit & accountability Centralized log collection and correlation produce a complete audit trail. → SIEM Platform
CM.L2: Configuration management Continuous configuration assessment against CIS benchmarks. → SIEM Platform
SC.L2: System & communications protection Microsegmentation and TLS inspection protect systems and data in transit. → Firewall-as-a-Service
SI.L2: System & information integrity Inline IPS and DLP prevent unauthorized modification and exfiltration of CUI. → Intrusion Prevention System
RA.L2: Risk assessment & vulnerability management Automated patching and vulnerability detection reduce exposure. → Managed Patch Management

Evidence

How SecureTrust helps you demonstrate compliance

Access audit

Records of least-privilege access to CUI and FCI.

Audit logs

Centralized, searchable event logs for audit and accountability.

Configuration evidence

CIS-benchmark assessment reports for configuration management.

Vulnerability evidence

Patch coverage and vulnerability reports for risk assessment.

FAQ

Frequently asked questions

What CMMC level do I need?
It depends on your contract. Level 1 (Foundational) covers FCI, Level 2 (Advanced) covers CUI, and Level 3 (Expert) covers the most sensitive programs. Your contracting officer specifies the required level.
Does SecureTrust Cyber make me CMMC certified?
No, certification comes from a C3PAO (Level 2) or the government (Level 3). The platform provides the technical controls and evidence that make certification achievable.

Prove compliance, not just claim it

See how SecureTrust Cyber maps to your obligations.