CMMC Compliance

CMMC, understood by your operations agent

Hyphen Agent maps CMMC 2.0 Level 2 controls from NIST SP 800-171, automates technical safeguards, and produces evidence reports to support your assessment. It does not certify your organization.

110 Level 2 controls · 14 automated · 46 reported · 50 remain with your team

CMMC 1.0, 1.02, and 2.0

Agent follows the current program, not the retired five-level model.

Defense contractors still hear all three names. Only CMMC 2.0 is in force. Agent maps the 110 requirements from NIST SP 800-171 Rev. 2 that make up Level 2 of that program and treats Level 1 as the subset of those practices that protect Federal Contract Information.

Retired

CMMC 1.0

Five levels, unique practices.

Released in 2020. Levels 1–5 mixed NIST SP 800-171 with CMMC-only practices and separate process-maturity scoring. Level 3 required 130 practices. Certification was third-party only, and POA&Ms were not allowed.

Not a separate program

CMMC 1.02

The revision people call 1.5.

DoD never published CMMC 1.5. 1.02 (March 2020) was an errata pass on 1.0 and still used five levels. Teams that say "1.5" usually mean 1.02 or the 2021 pause before 2.0. Agent does not map the retired unique practices.

Current program

CMMC 2.0

Three levels, aligned to NIST.

The live program under 32 CFR Part 170. Level 1 is the 15 FAR 52.204-21 practices for FCI. Level 2 is the 110 NIST SP 800-171 Rev. 2 requirements for CUI. Level 3 adds a subset of NIST SP 800-172, assessed by DIBCAC. This is the catalog Agent uses.

How Agent works the catalog

Map. Automate. Report. Attest.

  1. 01

    Map the live catalog

    Agent works from CMMC 2.0 Level 2, which covers the 110 NIST SP 800-171 Rev. 2 requirements in 32 CFR §170.14. The five-level 1.0 model is retired.

  2. 02

    Automate the technical controls

    Where a safeguard can be enforced in identity, logging, malware protection, or network policy, Agent applies it through connected systems, with approval for sensitive changes.

  3. 03

    Collect evidence and report

    For controls it cannot fully enforce, Agent gathers configuration, access, and activity evidence into a control-by-control report your assessor can read.

  4. 04

    You attest. Agent does not certify.

    Approvals, POA&Ms, and the annual affirmation stay with your team. Hyphen is not a C3PAO. Agent is the operational layer underneath the assessment.

What Agent covers

Honest about the scope.

CMMC has 110 Level 2 requirements. Agent classifies each as automate, report, or human so you can start a C3PAO conversation with evidence for your SSP.

  • Knows all 110 Level 2 requirements

    Every control is named, family-mapped, and tagged for what Agent can automate, report, or leave with your people and facilities.

  • Automates technical safeguards

    14 controls can be enforced in software, covering authentication, MFA, audit logging, default-deny communications, and malicious-code protection.

  • Builds the evidence pack

    46 controls get monitoring, configuration evidence, or partial implementation. The report shows what is in place, what is partial, and what still needs a person.

  • Leaves the human work honest

    50 requirements stay with training, personnel, physical access, media handling, and incident process. Agent will not pretend a visitor log is a software problem.

Control catalog

110 Level 2 requirements. Tagged for what Agent will do with each one.

Sourced from NIST SP 800-171 Rev. 2 as incorporated by CMMC 2.0. Agent coverage is a planning view of what it can automate or put in an evidence report. It does not make a certification decision.

  • 110controls
  • 14automate
  • 46report
  • 50human
CMMC 2.0 Level 2 families and how Agent covers each one
FamilyAutomateReportHumanTotal
Access Control211922
Awareness and Training33
Audit and Accountability279
Configuration Management459
Identification and Authentication6511
Incident Response33
Maintenance246
Media Protection189
Personnel Security22
Physical Protection66
Risk Assessment123
Security Assessment224
System and Communications Protection110516
System and Information Integrity3317

Agent automates14

Technical safeguards Agent can enforce through identity, logging, malware protection, and network policy.

Access Control2
  • AC.L2-3.1.7Privileged Functions

    Block non-privileged users from privileged functions, and record every execution of privileged functions in audit logs.

  • AC.L2-3.1.8Unsuccessful Logon Attempts

    Set and enforce limits on failed login attempts to reduce unauthorized access attempts.

Audit and Accountability2
  • AU.L2-3.3.1System Auditing

    Generate and retain sufficient audit records to support monitoring, analysis, investigation, and reporting of unauthorized system activity.

  • AU.L2-3.3.2User Accountability

    Record system activity so each user's actions can be uniquely attributed and reviewed for accountability.

Identification and Authentication6
  • IA.L2-3.5.2Authentication [CUI Data]

    Verify the identity of every user, process, or device before granting system access.

  • IA.L2-3.5.3Multifactor Authentication

    Require multifactor authentication for privileged local and network access and for non-privileged network access.

  • IA.L2-3.5.4Replay-Resistant Authentication

    Use authentication methods that prevent captured credentials or authentication messages from being successfully replayed.

  • IA.L2-3.5.7Password Complexity

    Enforce minimum password complexity and require new passwords to differ sufficiently from previous passwords.

  • IA.L2-3.5.8Password Reuse

    Prevent users from reusing passwords within the organization-defined password history.

  • IA.L2-3.5.9Temporary Passwords

    Require users to replace temporary login passwords immediately with permanent passwords.

System and Communications Protection1
  • SC.L2-3.13.6Network Communication by Exception

    Block network traffic by default and permit only explicitly authorized communications.

System and Information Integrity3
  • SI.L2-3.14.2Malicious Code Protection [CUI Data]

    Deploy and maintain malicious-code protection at designated system entry points, endpoints, and other needed locations.

  • SI.L2-3.14.4Update Malicious Code Protection [CUI Data]

    Update malicious-code protection tools and detection information promptly whenever supported new releases become available.

  • SI.L2-3.14.5System & File Scanning [CUI Data]

    Scan systems periodically and scan externally sourced files in real time when downloaded, opened, or executed.

Agent reports46

Controls Agent can evidence, monitor, or help implement, with people and process still in the loop.

Access Control11
  • AC.L2-3.1.1Authorized Access Control [CUI Data]

    Allow only authorized users, approved processes, and permitted devices to access systems handling organizational information.

  • AC.L2-3.1.2Transaction & Function Control [CUI Data]

    Restrict each authorized user to only the system transactions and functions approved for their role.

  • AC.L2-3.1.4Separation of Duties

    Divide sensitive duties among separate people or roles so no individual can perform incompatible critical activities alone.

  • AC.L2-3.1.5Least Privilege

    Grant users, processes, and privileged accounts only the access necessary to perform their authorized responsibilities.

  • AC.L2-3.1.6Non-Privileged Account Use

    Require users to perform ordinary, nonsecurity work through non-privileged accounts or roles.

  • AC.L2-3.1.9Privacy & Security Notices

    Display approved privacy and security notices before users access systems that handle CUI.

  • AC.L2-3.1.12Control Remote Access

    Monitor remote access activity and enforce approved controls throughout each remote session.

  • AC.L2-3.1.13Remote Access Confidentiality

    Protect the confidentiality of remote access sessions with approved cryptographic safeguards.

  • AC.L2-3.1.15Privileged Remote Access

    Require explicit authorization before remotely executing privileged commands or accessing security-relevant information.

  • AC.L2-3.1.20External Connections [CUI Data]

    Verify external systems meet defined security conditions, then restrict and monitor their connections and use.

  • AC.L2-3.1.22Control Public Information [CUI Data]

    Review publicly accessible systems and prevent CUI from being posted or processed there without authorization.

Audit and Accountability7
  • AU.L2-3.3.3Event Review

    Periodically review which events are logged and update logging requirements as risks and systems change.

  • AU.L2-3.3.4Audit Failure Alerting

    Generate timely alerts whenever an audit logging process stops, fails, or operates incorrectly.

  • AU.L2-3.3.5Audit Correlation

    Correlate audit reviews, analyses, and reports to investigate and respond to unlawful, unauthorized, suspicious, or unusual activity.

  • AU.L2-3.3.6Reduction & Reporting

    Enable audit records to be filtered, summarized, and reported for on-demand analysis and investigation.

  • AU.L2-3.3.7Authoritative Time Source

    Synchronize system clocks with an authoritative time source so audit records receive consistent, accurate timestamps.

  • AU.L2-3.3.8Audit Protection

    Prevent unauthorized access, alteration, or deletion of audit records and the tools used to create them.

  • AU.L2-3.3.9Audit Management

    Restrict administration of audit logging settings and functions to specifically authorized privileged users.

Configuration Management4
  • CM.L2-3.4.5Access Restrictions for Change

    Define, document, approve, and enforce who may physically or logically access systems when making changes.

  • CM.L2-3.4.6Least Functionality

    Configure systems to provide only capabilities essential for authorized business and security functions.

  • CM.L2-3.4.7Nonessential Functionality

    Identify and disable or restrict unnecessary software, functions, ports, protocols, and services across organizational systems.

  • CM.L2-3.4.8Application Execution Policy

    Define and enforce software execution rules that block unauthorized software or permit only explicitly authorized software.

Identification and Authentication5
  • IA.L2-3.5.1Identification [CUI Data]

    Assign and manage unique identities for system users, user-initiated processes, and devices requiring access.

  • IA.L2-3.5.5Identifier Reuse

    Prevent previously assigned user, process, or device identifiers from being reassigned during a defined period.

  • IA.L2-3.5.6Identifier Handling

    Disable user, process, and device identifiers after a defined period without activity.

  • IA.L2-3.5.10Cryptographically-Protected Passwords

    Protect all stored and transmitted passwords using approved cryptographic methods at all times.

  • IA.L2-3.5.11Obscure Feedback

    Hide passwords and other authentication secrets from display while users enter them.

Maintenance2
  • MA.L2-3.7.1Perform Maintenance

    Perform and document routine and corrective maintenance to keep organizational systems secure and operational.

  • MA.L2-3.7.2System Maintenance Control

    Authorize and control the maintenance tools, methods, equipment, and personnel used to service organizational systems.

Media Protection1
  • MP.L2-3.8.9Protect Backups

    Protect backup copies of CUI against unauthorized access at every on-site and off-site storage location.

Risk Assessment1
  • RA.L2-3.11.2Vulnerability Scan

    Scan systems and applications for vulnerabilities regularly and whenever newly identified vulnerabilities may affect them.

Security Assessment2
  • CA.L2-3.12.1Security Control Assessment

    Periodically evaluate whether implemented security controls operate correctly and achieve their intended protection.

  • CA.L2-3.12.3Security Control Monitoring

    Continuously monitor security controls and address changes or failures that could reduce their effectiveness.

System and Communications Protection10
  • SC.L2-3.13.1Boundary Protection [CUI Data]

    Monitor, control, and protect communications at external connections and important internal network boundaries.

  • SC.L2-3.13.2Security Engineering

    Design, develop, and engineer systems using principles and techniques that build effective security into their architecture.

  • SC.L2-3.13.3Role Separation

    Clearly separate everyday user functions from privileged system administration and management functions.

  • SC.L2-3.13.5Public-Access System Separation [CUI Data]

    Place publicly accessible system components on networks physically or logically isolated from internal networks.

  • SC.L2-3.13.7Split Tunneling

    Prevent remote devices from using organizational systems and external networks simultaneously through split tunneling.

  • SC.L2-3.13.8Data in Transit

    Encrypt CUI during transmission unless approved physical safeguards provide equivalent protection against unauthorized disclosure.

  • SC.L2-3.13.9Connections Termination

    End network sessions when users finish or after an organization-defined period of inactivity.

  • SC.L2-3.13.10Key Management

    Establish procedures to generate, store, distribute, rotate, revoke, and destroy cryptographic keys securely.

  • SC.L2-3.13.11CUI Encryption

    Use only FIPS-validated cryptography whenever encryption protects the confidentiality of CUI.

  • SC.L2-3.13.16Data at Rest

    Protect stored CUI from unauthorized disclosure using safeguards appropriate to its location and risk.

System and Information Integrity3
  • SI.L2-3.14.3Security Alerts & Advisories

    Monitor relevant security alerts and advisories, evaluate their impact, and take timely corrective action.

  • SI.L2-3.14.6Monitor Communications for Attacks

    Monitor systems and inbound and outbound communications to detect attacks and indicators of potential attacks.

  • SI.L2-3.14.7Identify Unauthorized Use

    Monitor and investigate system activity to identify unauthorized use of organizational systems.

Your team still owns50

Training, personnel, physical access, media handling, and incident process require human oversight.

Access Control9
  • AC.L2-3.1.3Control CUI Flow

    Permit CUI to move only between approved sources, destinations, systems, and users according to documented authorizations.

  • AC.L2-3.1.10Session Lock

    Lock inactive sessions after a defined interval and conceal previously displayed information while locked.

  • AC.L2-3.1.11Session Termination

    Automatically end user sessions when defined inactivity periods, security events, or other approved conditions occur.

  • AC.L2-3.1.14Remote Access Routing

    Route every remote access connection through organizationally managed and controlled access points.

  • AC.L2-3.1.16Wireless Access Authorization

    Approve each wireless access method and connection before permitting it to connect to organizational systems.

  • AC.L2-3.1.17Wireless Access Protection

    Require authenticated users and devices and encrypted communications for wireless access to organizational systems.

  • AC.L2-3.1.18Mobile Device Connection

    Authorize, restrict, and manage which mobile devices may connect to organizational systems.

  • AC.L2-3.1.19Encrypt CUI on Mobile

    Encrypt CUI stored on or accessed through mobile devices and mobile computing platforms.

  • AC.L2-3.1.21Portable Storage Use

    Define and enforce restrictions on using organizational portable storage devices with external systems.

Awareness and Training3
  • AT.L2-3.2.1Role-Based Risk Awareness

    Educate managers, administrators, and users about system security risks and the policies, standards, and procedures governing their activities.

  • AT.L2-3.2.2Role-Based Training

    Train personnel to perform the specific information security duties and responsibilities assigned to their roles.

  • AT.L2-3.2.3Insider Threat Awareness

    Train personnel to recognize and promptly report behavioral or technical indicators of potential insider threats.

Configuration Management5
  • CM.L2-3.4.1System Baselining

    Document and maintain approved baseline configurations and complete inventories of system hardware, software, firmware, and related documentation.

  • CM.L2-3.4.2Security Configuration Enforcement

    Define and enforce approved security configuration settings for all technology products used within organizational systems.

  • CM.L2-3.4.3System Change Management

    Record, review, and formally approve or reject proposed and completed changes to organizational systems.

  • CM.L2-3.4.4Security Impact Analysis

    Assess and document the security consequences of each proposed system change before implementation.

  • CM.L2-3.4.9User-Installed Software

    Establish and enforce controls for approving, tracking, and monitoring software installed by users.

Incident Response3
  • IR.L2-3.6.1Incident Handling

    Maintain an operational incident response capability covering preparation, detection, analysis, containment, recovery, and user response.

  • IR.L2-3.6.2Incident Reporting

    Record each security incident, track its status and details, and report it promptly to the appropriate internal and external authorities.

  • IR.L2-3.6.3Incident Response Testing

    Regularly test the incident response plan and team through exercises, then correct weaknesses found.

Maintenance4
  • MA.L2-3.7.3Equipment Sanitization

    Remove or securely sanitize all CUI from equipment before sending it off-site for maintenance.

  • MA.L2-3.7.4Media Inspection

    Scan diagnostic and test media for malicious code before connecting or using it on organizational systems.

  • MA.L2-3.7.5Nonlocal Maintenance

    Require multifactor authentication for remote maintenance over external networks, and disconnect each session immediately when maintenance ends.

  • MA.L2-3.7.6Maintenance Personnel

    Directly supervise maintenance performed by personnel who do not have the required system access authorization.

Media Protection8
  • MP.L2-3.8.1Media Protection

    Physically control and securely store paper and digital media containing CUI to prevent unauthorized access or loss.

  • MP.L2-3.8.2Media Access

    Restrict access to CUI stored on paper or digital media to specifically authorized users.

  • MP.L2-3.8.3Media Disposal [CUI Data]

    Sanitize or destroy media containing CUI before disposal, transfer, or reuse so the information cannot be recovered.

  • MP.L2-3.8.4Media Markings

    Apply required CUI markings and distribution restrictions to all paper and digital media containing CUI.

  • MP.L2-3.8.5Media Accountability

    Authorize, track, and protect media containing CUI whenever it is transported outside controlled areas.

  • MP.L2-3.8.6Portable Storage Encryption

    Encrypt CUI on digital media during transport unless approved physical safeguards provide equivalent protection.

  • MP.L2-3.8.7Removable Media

    Define, enforce, and monitor approved uses of removable media on organizational system components.

  • MP.L2-3.8.8Shared Media

    Block portable storage devices from use unless the device has a known, identifiable owner.

Personnel Security2
  • PS.L2-3.9.1Screen Individuals

    Complete appropriate personnel screening before granting anyone access to organizational systems that process, store, or transmit CUI.

  • PS.L2-3.9.2Personnel Actions

    Promptly protect systems and revoke or adjust CUI access when personnel are terminated, transferred, or reassigned.

Physical Protection6
  • PE.L2-3.10.1Limit Physical Access [CUI Data]

    Restrict physical access to systems, equipment, and operating environments to approved individuals with a legitimate need.

  • PE.L2-3.10.2Monitor Facility

    Use safeguards and monitoring to protect facilities and supporting infrastructure that house or serve organizational systems.

  • PE.L2-3.10.3Escort Visitors [CUI Data]

    Escort visitors in controlled areas and monitor their activity throughout each visit.

  • PE.L2-3.10.4Physical Access Logs [CUI Data]

    Record and retain physical access events so entries, exits, and access attempts can be reviewed.

  • PE.L2-3.10.5Manage Physical Access [CUI Data]

    Issue, track, secure, and revoke physical access devices such as badges, keys, and access cards.

  • PE.L2-3.10.6Alternative Work Sites

    Apply equivalent CUI safeguarding requirements at home offices, temporary locations, and other alternate work sites.

Risk Assessment2
  • RA.L2-3.11.1Risk Assessments

    Periodically assess risks that CUI systems create for operations, assets, individuals, mission, and organizational reputation.

  • RA.L2-3.11.3Vulnerability Remediation

    Prioritize and remediate identified vulnerabilities within timeframes based on documented risk assessments.

Security Assessment2
  • CA.L2-3.12.2Operational Plan of Action

    Create, maintain, and execute plans of action to correct security deficiencies and reduce identified vulnerabilities.

  • CA.L2-3.12.4System Security Plan

    Maintain and periodically update a system security plan covering boundaries, environments, requirement implementation, and system interconnections.

System and Communications Protection5
  • SC.L2-3.13.4Shared Resource Control

    Prevent data left in shared system resources from being exposed to unauthorized users or processes.

  • SC.L2-3.13.12Collaborative Device Control

    Disable remote activation of cameras and microphones, and clearly indicate when any collaborative device is active.

  • SC.L2-3.13.13Mobile Code

    Authorize, restrict, and monitor mobile code such as scripts, browser content, and downloaded applications.

  • SC.L2-3.13.14Voice over Internet Protocol

    Authorize, secure, and monitor Voice over Internet Protocol technologies used within organizational systems.

  • SC.L2-3.13.15Communications Authenticity

    Verify communications session identities and integrity to prevent impersonation, hijacking, or unauthorized alteration.

System and Information Integrity1
  • SI.L2-3.14.1Flaw Remediation [CUI Data]

    Identify system flaws, report them to responsible personnel, and correct them within risk-based timeframes.

Frequently Asked Questions

Does Hyphen Agent certify my company for CMMC?

No. Hyphen is not a CMMC Third-Party Assessment Organization (C3PAO), and Agent does not issue a CMMC status. It maps controls, automates technical safeguards, and produces evidence your team can use in a self-assessment or hand to a C3PAO or DIBCAC assessor. Your organization still owns the System Security Plan, POA&Ms, and the affirmation of continued compliance.

Does Agent follow CMMC 1.0, 1.5, or 2.0?

CMMC 2.0, specifically the Level 2 catalog of 110 NIST SP 800-171 Revision 2 requirements incorporated by 32 CFR §170.14. CMMC 1.0 used five levels and extra CMMC-only practices; that model is retired. There is no official CMMC 1.5. The name is informal for CMMC 1.02 or the transition period before 2.0. NIST has published 800-171 Revision 3, but Level 2 assessments remain on Revision 2 until the regulation changes.

What can Agent automate versus only report?

Agent can automate 14 Level 2 controls that are enforced in software: privileged-function restrictions, failed-logon limits, audit generation, user attribution, authentication and MFA, password policy, default-deny network communication, and malicious-code protection and scanning. It reports on 46 more, including access policy, logging review, vulnerability scanning, encryption, and similar controls where it can collect evidence or help implement but cannot close the requirement alone. The remaining 50, including physical protection, personnel screening, awareness training, and most media handling, stay with your people and facilities.

Does this cover CMMC Level 1 and Level 3 as well?

Level 1 (Foundational) is the 15 FAR 52.204-21 practices for Federal Contract Information. Those basic safeguards sit inside the Level 2 catalog, so Agent’s technical automation and evidence still apply if you only handle FCI. Level 3 (Expert) requires a Final Level 2 C3PAO status plus 24 enhanced requirements from NIST SP 800-172, assessed by DIBCAC. Agent does not currently map the 800-172 overlay.

Will Agent change production systems to satisfy a control?

Not without approval. Agent starts read-only, proposes the change with evidence, and waits for a decision on sensitive work. Repository changes go through pull requests. Every action is logged, which is itself evidence for audit and accountability controls.

Can I use the report for a Level 2 self-assessment or a C3PAO engagement?

Yes, as supporting evidence for the assessment. It does not replace the assessment. Level 2 (Self) still requires your organization to score the 110 requirements and submit in SPRS. Level 2 (C3PAO) still requires an accredited assessor. Agent’s report is a control-by-control view of what is automated, what has evidence, and what remains a human process, which is the package those assessments ask you to walk through.

Put the catalog in Agent's hands.

Connect your infrastructure. Agent maps CMMC Level 2, automates the technical controls, and reports evidence for the rest.