Solutions
CMMC 2.0 Solutions for Defense Contractors
CMMC certifies organizations, never products — no purchase confers certification on its own. What a supplier can do is assemble the stack the controls run on: FIPS-validated (CMVP-listed) storage, boundary firewalls, PIV/CAC readers and segmentation switches, the licensing above them, and the integration work that puts both in service — quoted against the SSP you already have.

- Levels
- 1 / 2 / 3 — 15 / 110 / 110+24 requirements
- Status
- Phase 1 in force · later phases under DoD review
- Framework
- NIST SP 800-171 Rev 2
- Boundary
- The capability behind the control — never a certification we hold
CMMC certifies organizations — we assemble the stack the controls run on
No purchase — hardware, license or service — confers certification on its own, and there is no CMMC-certified SKU. What a supplier can do is put the whole stack behind the controls: the equipment, the software licensing that governs it, and the configuration, imaging, integration and lifecycle work that turns a bill of materials into something running. CMMC 2.0 is the Department of Defense program that verifies how a contractor protects two kinds of government information — Federal Contract Information and Controlled Unclassified Information — across three levels. The program rule at 32 CFR Part 170 took effect December 16, 2024, and the acquisition rule that puts clause 252.204-7021 into contracts took effect November 10, 2025. Everything Uniqcli supplies against it is sourced through authorized US distribution: the capability behind the control — never a certification we hold. We are not an assessor, a C3PAO or an RPO, and we hold no CMMC level ourselves.
What each level actually asks for
Level 1 covers Federal Contract Information and carries 15 requirements taken from FAR 52.204-21, self-assessed with no POA&Ms permitted. Level 2 covers Controlled Unclassified Information and carries 110 requirements mapped one-to-one to NIST SP 800-171 Rev 2, assessed against 320 objectives — self-assessed or C3PAO-certified depending on what the solicitation specifies. Level 3 starts from a Final Level 2 and adds 24 enhanced requirements from NIST SP 800-172, assessed by DIBCAC. The technical baseline across all three is still Rev 2, pinned by DoD Class Deviation 2024-O0013.
The level-by-level detail — scoping, assessment routes, SPRS scoring — is set out in our CMMC explainer. Family by family, what each of the fourteen NIST SP 800-171 control families behind the CMMC Level 2 requirements actually asks for — and what is genuinely quotable against each, in hardware, licensing or integration work — is set out further down this page.
Where the program stands right now
The rollout schedule is moving. The safeguarding obligation underneath it is not.
Phase 1 is in force
Since November 10, 2025, new solicitations have carried the CMMC clause at Phase 1 terms: a self-assessment at the level the solicitation names, with the senior-official affirmation posted in SPRS. That requirement is contractual today, and it did not pause.
Phases 2–4 are suspended
On July 13, 2026 the Department suspended the remaining rollout phases pending a CMMC Reform Task Force review, with a report expected around September 2026 and no replacement dates announced. Contracts already carrying Level 2 C3PAO or Level 3 requirements are to have those clauses removed by modification.
What doesn't change
DFARS 252.204-7012 has required contractors handling CUI to implement NIST SP 800-171 since 2017. CMMC is the verification layer on top of that obligation, not the obligation itself — so the equipment, licensing and deployment work behind the 110 requirements is the same regardless of how the review lands.
What you can actually quote against each control family
Each card names the requirement the line serves — hardware, software licensing, or the integration work that puts either into service. Naming a control is not a coverage claim: configuration, procedure and evidence stay inside your program, and no purchase closes a requirement on its own. Naming a manufacturer describes the market, not a Uniqcli partnership or endorsement.
Access control (3.1.x)
The access-control family is where segmentation lives: managed switches to separate a CUI enclave from the rest of the network by VLAN, and firewalls at the zone edges. Managed switches are stocked across the major networking lines and quoted with the optics, stacking modules and licensing the design calls for. The remote-access and zero-trust subscription terms that enforce the design — Sophos, Citrix, SonicWall, WatchGuard and others — are sourced through the same distribution and quoted against your renewal date, and the switching can arrive imaged and configured to your build sheet rather than factory-default.
Audit and accountability (3.3.x)
The audit family needs somewhere for records to live, and the retention window you wrote into the SSP decides how much. NAS and storage arrays sized to that window, and disks in volume, are quoted alongside the log platform your team already runs — plus the console hardware that gets records off the box and the log-forwarding and reporting subscriptions on the gear producing them. We do not sell SIEM platforms and we say so; the correlation and the review cadence stay yours.
Identification and authentication (3.5.3)
3.5.3 requires multifactor authentication for network and privileged access, replay-resistant. PIV/CAC smart-card readers — the desktop and USB models a credentialed workstation needs — are a thin shelf: a handful of models are in stock at any moment, so this is a quote-and-source line with a real lead time. Multifactor licensing rides alongside them, sourced rather than stocked. Hardware security keys for FIDO2 deployments are quote-based: name the model and quantity and we will tell you what can actually be sourced and on what lead time.
Media protection (3.8.x)
Media protection covers what CUI travels on. FIPS-validated encrypted USB drives and portable SSDs, hardware-encrypted external storage and write-protected media give you a defensible answer for transport, courier and backup media. Apricorn, iStorage and Kanguru stock moves regularly, with a thinner Kingston presence; quantities are confirmed on the quote. Device-encryption management is licensing rather than hardware — Sophos, Trend Micro and Bitdefender lines are quoted per seat — and the disposal leg runs through our lifecycle lane where a refresh is driving it.
Physical protection (3.10.x)
Physical protection is the family that tends to go unbudgeted: privacy filters for screens in shared or public-facing space, cable locks and port blockers, lockable racks and secured enclosures for the equipment holding CUI. Ordinary hardware, quoted per site and per headcount — with the camera and access-control software above it licensed through the same distribution, and per-site staging so each building receives a labeled kit rather than a share of a pallet.
Endpoint and boundary protection (3.13.1, 3.14.2)
The deepest software line we carry sits here. Endpoint, extended-detection, email and web-gateway platforms — Sophos Intercept X and its detection tiers, McAfee, Trend Micro, Bitdefender, Proofpoint, Check Point, Barracuda and ThreatLocker's application control — are priced across our licensing catalog and quoted per seat against your renewal date. Underneath them, SonicWall and WatchGuard boundary appliances are stocked; the other appliance lines are priced but not stocked, so treat those as lead-time. Deployment, policy build-out and a hardening pass against CIS or your STIG baseline are scoped on the same order.
Cryptographic protection (3.13.11, 3.13.16)
3.13.11 requires FIPS-validated cryptography wherever cryptography protects CUI, and 3.13.16 covers CUI at rest. The product-level fact that matters is the CMVP listing. Hardware-encrypted drives and removable media from Apricorn, iStorage, Kanguru and Rocstor are stocked, with Kingston quote-and-source, alongside self-encrypting drives for endpoints and servers. Where a refresh is what triggers this, the imaging, staging and reverse-logistics legs are quoted with it rather than left to a second conversation. Ask for the CMVP certificate on any line where the module is the point and we will confirm it before you commit — every remaining FIPS 140-2 certificate moves to Historical status on September 21, 2026, which is worth knowing before a refresh.
Explore every control family
All fourteen NIST SP 800-171 Rev 2 families — the 110 CMMC Level 2 requirements, plus the six families Level 1 touches through FAR 52.204-21. Each page states what the family asks for, what is genuinely quotable against it in hardware, licensing or services, and what stays yours to run.
Access Control (3.1 AC)
22 requirements, Level 1 in scope — segmentation switches, boundary firewalls, secure KVM, plus zero-trust and remote-access licensing.
Awareness & Training (3.2 AT)
3 requirements, Level 2 only — we don't teach, but the awareness and simulation platform is a license we source and quote.
Audit & Accountability (3.3 AU)
9 requirements, Level 2 only — retention capacity, console plumbing and forwarding subscriptions; correlation stays your platform's.
Configuration Management (3.4 CM)
9 requirements, Level 2 only — you author the baseline; we build to it, and quote the allowlisting, patch and inventory tooling.
Identification & Authentication (3.5 IA)
11 requirements, Level 1 in scope — CAC and PIV readers, multifactor licensing and the rollout; hardware tokens stay quote-and-source.
Incident Response (3.6 IR)
3 requirements, Level 2 only — the plan and the rehearsal are yours; backup and detection subscriptions either side of them are ours.
Maintenance (3.7 MA)
6 requirements, Level 2 only — OEM support and maintenance coverage, out-of-band access at 3.7.5, and refresh planning.
Media Protection (3.8 MP)
9 requirements, Level 1 in scope — encrypted media, self-encrypting drives and encryption-management licensing, plus an honest answer on destruction.
Personnel Security (3.9 PS)
2 requirements, Level 2 only — genuinely nothing to quote against it. Screening is not a product, and we say so.
Physical Protection (3.10 PE)
6 requirements, Level 1 in scope — privacy filters, cable locks and lockable enclosures, camera and access-control licensing, per-site staging.
Risk Assessment (3.11 RA)
3 requirements, Level 2 only — scanning licenses and the work of standing them up; we never run the scan or write the assessment.
Security Assessment (3.12 CA)
4 requirements, Level 2 only — SSP, POA&M and SPRS. Assessor turf: we are not one, and no GRC tooling sits in our catalog either.
System & Communications Protection (3.13 SC)
16 requirements, Level 1 in scope — boundary devices and segmentation, their subscription terms, FIPS-validated (CMVP-listed) cryptography and the hardening pass.
System & Information Integrity (3.14 SI)
7 requirements, Level 1 in scope — the deepest licensing family we carry; the timeline and the act of patching stay yours.
What stays yours to run
The program is yours. Every policy, every procedure, every scoping decision, the SSP and the POA&M, the senior official's affirmation in SPRS and the evidence an assessor actually reads — none of that is a purchase, and no supplier can hand it to you. What we put behind it is the tooling, the licensing and the integration work, sourced through authorized US distribution and quoted against the plan you already wrote.
Two families really do have nothing to quote. Personnel security is screening and offboarding: no product exists for it, we carry none, and we would rather say so on this page than in a debrief. Security assessment is the other honest refusal — we are not a C3PAO, an RPO or an assessor, we run no assessments and offer no readiness services, and governance-risk-and-compliance platforms are not in our catalog either. Incident response sits between the two: the plan and the rehearsal are yours, while the backup and detection subscriptions either side of them are ordinary line items.
Elsewhere the split is sharper than "process, so nothing to sell" suggests. Awareness and training is a program people complete — but the platform it runs on is a subscription we source. Configuration management turns on a baseline your engineers author — but building machines to that baseline is what our OEM lane does. Maintenance is authorization and supervision — and also OEM support contracts, one of the largest priced categories we carry. Naming what is quotable in each is not a coverage claim, and nothing we sell closes a requirement on its own.
How contractors buy with us
We quote against the system security plan you already have, not a generic bundle assembled around a level number — hardware, licensing and the work around them on one order.
- Send the SSP section, the POA&M item you are closing, or the enclave bill of materials — the quote is built against that
- Hardware, software licensing and subscription terms quoted together, so one order stands up the whole environment rather than three procurement threads
- Ask for the CMVP certificate on any line where the module is the point — including whether it is 140-2 or 140-3 — and we confirm it before you commit
- TAA (FAR 52.225-5) and NDAA §889 screening performed before the quote goes out, with alternates for anything that fails — publishers screened the same way makers are
- Off-catalog and enclave-specific parts sourced by RFQ through authorized US distribution; if a requirement runs past our on-catalog set, the answer is usually to source and quote it
- Imaging, rack integration, kitting, asset tagging and burn-in available through our OEM-integration lane, quoted per order
- Authenticity questions answered before you commit — the genuine-hardware check under Tools is open to anyone
- GPC / P-Card accepted up to your cardholder threshold; purchase orders otherwise, with volume and refresh quotes on request
CMMC solutions questions
Does buying hardware or software make us CMMC compliant?
No. CMMC certifies organizations, not purchases, and no purchase — hardware, license or service — confers certification on its own. What a supplier can do is make the controls implementable. An assessment looks at your system security plan, your configurations, your procedures and your evidence. We supply the capability behind the control, never a certification we hold, and we are not an assessor, a C3PAO or an RPO.
Is there such a thing as CMMC-certified hardware?
There is not. No device, appliance or drive carries a CMMC level, because the program certifies organizations rather than products. The product-level fact that does matter is FIPS validation: a cryptographic module either holds a current CMVP certificate or it does not, and NIST SP 800-171 3.13.11 requires FIPS-validated cryptography where cryptography protects CUI. When a seller puts CMMC compliant on a part, there is no certificate behind the phrase. Ask instead for the CMVP certificate number — that is a claim with an issuing body.
What is the status of CMMC enforcement right now?
Phase 1 has been in force since November 10, 2025: new solicitations carry the clause, and self-assessments with a senior-official affirmation in SPRS are contractually required. On July 13, 2026 the Department suspended Phases 2 through 4 pending a CMMC Reform Task Force review, with a report expected around September 2026 and no replacement dates announced; contracts already carrying Level 2 C3PAO or Level 3 requirements are to have those clauses removed by modification. The underlying DFARS 252.204-7012 obligation to implement NIST SP 800-171 for CUI is unaffected by the pause.
How many practices is Level 1?
Fifteen. 32 CFR 170.15 sets Level 1 at 15 requirements, drawn from FAR 52.204-21, assessed annually by self-assessment with a senior-official affirmation in SPRS and no POA&Ms permitted. The “17 practices” figure still circulating online comes from the 2021 framing of the program and is out of date.
What does the FIPS 140-2 sunset mean for our devices?
On September 21, 2026 every remaining FIPS 140-2 certificate moves to the CMVP Historical list, with FIPS 140-3 as the successor program. A device does not stop working on that date, but a Historical certificate is weaker ground when an assessor asks how 3.13.11 is being met, and some programs will not accept it for new deployments. If you are refreshing encrypted storage or crypto-bearing appliances anyway, buying to 140-3 now is the cheaper order of operations. Ask for the CMVP certificate on any line where the module is the point and we will confirm it before you commit.
Can you help us scope what to buy?
Yes — against your own documents. Send the relevant SSP sections, the POA&M items you are closing, or the enclave design, and we quote what those call for line by line: the equipment, the software licensing and subscription terms that run on it, and any imaging, integration or lifecycle work the rollout needs, with TAA and §889 screening performed before the quote goes out. We do not write your SSP, run your assessment or certify anything. We price the stack the plan you already have depends on.
Do you quote software and licensing, or only hardware?
Both, on the same order. Endpoint and extended-detection platforms, email and web-gateway filtering, encryption management, backup, boundary and zero-trust subscriptions, awareness-training seats and OEM support contracts are all sourced through authorized US distribution and quoted against your seat count, term and renewal date. Software is sourced rather than shelved, so availability language never applies to it — and the publisher and its affiliates are screened against the §889 covered list exactly as a hardware maker is.
Can you configure and deploy what you sell, or does it ship factory-default?
Units can ship configured. Through our OEM-integration lane we load your OS images, firmware versions and configuration files and validate against your baseline before burn-in, with rack integration, kitting and asset tagging available on the same order, and lifecycle and refresh planning alongside. We deliver and maintain within the frameworks your program is held to; we do not hold those authorizations on your behalf, and we do not advertise a manned operations center or a guaranteed response time.
Procurement
Quoted against your SSP, not a bundle.
FIPS-validated (CMVP-listed) storage, boundary firewalls, PIV/CAC readers and segmentation switches, the licensing that runs on them and the integration work that puts them in service — screened for TAA and §889, priced line by line against the plan your program already wrote.
Get a CMMC estimate — CMMC 2.0
Tell us where to reach you and a Uniqcli specialist follows up by email to scope what you need across hardware, software licensing and integration, then comes back with pricing and availability — quoted against the SSP you already have, not a generic bundle.
An estimate for the capability behind the control — never a certification we hold. No purchase — hardware, license or service — confers a CMMC level on its own; what you buy makes the controls implementable.
The solutions atlas
Every solution, one accountable partner.
UniQ platforms
By technology
By customer
- TAA & NDAA-889 Compliance Screening
- CMMC & CUI SolutionsThis page
- Federal & DoD
- State, Local & Education
- Healthcare
- Enterprise
- Rapid Procurement & GPC Buys
- Multi-Vendor Integration Projects
- eProcurement & Custom Catalogs
- FISMA Modernization
- CJIS-Compliant Justice Cloud & Local AI
- Federal Storage Modernization
- Government ERP & Business Systems Infrastructure
- Managed Procurement
- Secure AV & Conferencing
- Fiber Network Infrastructure
- Satellite & Resilient Connectivity
- Wavelength & Optical Transport
- Decentralized Data Centers
- Data Center Design & Build
Talk to us about your CMMC scope
Send the SSP section, the POA&M item or the bill of materials you are buying against. We return one consolidated quote across hardware, licensing and the work around them — TAA (FAR 52.225-5) and NDAA §889 screening performed before it goes out, CMVP certificates confirmed on request where the module is the point, and nothing claimed about certification that a purchase cannot deliver.