Certifying a whole company against 110 practices and certifying a bounded environment where the sensitive data lives are the same standard at wildly different prices. That boundary decision comes before any control work and is where most of the money is won or lost. This covers drawing it, the categories an assessor sorts your systems into, and one cryptographic requirement that cannot be retrofitted.

CMMC Level 2: the US Department of Defense certification that requires a contractor handling Controlled Unclassified Information to implement the 110 security practices of NIST SP 800-171 and, at most levels, prove it to a third-party assessor. Unlike a self-attestation, somebody else decides whether you passed.

Accuracy note. CMMC's rollout, level definitions and assessment requirements have been revised repeatedly and contract clauses vary. This covers the structure and what infrastructure has to deliver, which is stable, rather than restating phase dates or clause numbers that may have moved. Confirm your required level and assessment type against your contract and current DoD rulemaking. This is not legal advice.

Scope Is the Whole Game

The single decision that determines what CMMC costs you is how much of your estate is in scope, and that follows from where CUI goes.

Certify everything and you are applying 110 practices to your whole company, including laptops belonging to people who will never see a defence contract. Build an enclave, a deliberately bounded environment where CUI lives and nothing else does, and the practices apply to that environment plus the people with access to it.

The enclave approach is why this is a hosting question rather than only a policy one. A separate environment with controlled access, its own identity boundary, its own logging and its own backup path is a smaller thing to secure and a much smaller thing to assess.

Map the data flows before choosing an approach. CUI arriving by email means the mail system is in scope; CUI in an engineering file share means that share and everything with access to it. Most first attempts miss at least one path, and an assessor finding it is worse than finding it yourself.

The Four Asset Categories

The assessment guidance divides your environment, and knowing which category a system falls into tells you what is required of it.

CategoryWhat it isObligation
CUI assetsProcess, store or transmit CUIAll applicable practices, assessed
Security protection assetsProvide security for the aboveAssessed, because they protect CUI
Contractor risk managed assetsCould touch CUI but are not intended toDocumented and policy-controlled
Specialized assetsTest equipment, OT, IoTDocumented, with a risk-based plan

The second row catches people out and it matters for hosting decisions. Your logging platform, your identity provider and your backup system protect CUI, so they are in scope even if no CUI is stored in them. Putting a SIEM outside the boundary does not put it out of scope.

What the Practices Ask of Infrastructure

Of the 110 practices, a substantial share are satisfied by how the environment is built rather than by what anybody does daily.

Access control. Least privilege, role separation, session locking, and controlled remote access with multi-factor authentication on every path into the enclave.

Identification and authentication. MFA for privileged accounts and for network access, unique identities with no shared accounts, and password requirements you can evidence rather than assert.

Audit and accountability. Logs of who did what, protected from modification, retained for a defined period, reviewed by a named function, with clocks synchronised so the timeline holds up.

System and communications protection. Boundary protection, network segmentation between the enclave and everything else, and encryption of CUI in transit and at rest.

Configuration management. Baselines, change control, least functionality, and an inventory that is current rather than annual.

Media protection and incident response. Encrypted media, controlled disposal, and a documented response capability that has been exercised.

None of this is unusual, and it overlaps heavily with the Saudi and GCC frameworks a contractor operating in both regions is likely to face. Our explainer on NCA Essential Cybersecurity Controls and our guide to mapping one control set across GCC frameworks cover building the shared implementation once rather than twice.

The Cryptography Requirement People Underestimate

Where 800-171 calls for cryptographic protection of CUI, it means FIPS-validated cryptography, and validated is a narrower claim than strong.

AES-256 is the right algorithm. Whether your particular implementation of it carries a FIPS 140 validation certificate is a separate fact about the module, and an assessor may ask for the certificate number. A platform that encrypts with AES-256 in a non-validated module has good security and a finding.

Establish this early with any provider, because it is not something you can retrofit by changing a setting. Ask specifically whether the modules protecting data at rest and in transit are validated, and get the answer in writing rather than inferring it from a marketing page.

The Documents That Are Actually Assessed

Two artefacts carry disproportionate weight, and both are yours regardless of who hosts what.

The System Security Plan describes the boundary, the assets in each category, and how each practice is met. An assessor works from it. A vague SSP produces an assessment that goes looking, which is slower and finds more.

The Plan of Action and Milestones records practices not yet met, with owners and dates. Note that not every practice may be deferred and there are limits on what a POA&M can carry, so it is a mechanism for finishing rather than for indefinite exceptions.

Write both against reality rather than intent. The most common assessment failure is not a missing control; it is documentation describing an environment that no longer matches.

Cloud, and the Provider Question

Where CUI is processed or stored by a cloud service, the DoD clause requires that service to meet a defined security baseline, and demonstrating that is on you, not on the provider.

So the questions to ask are specific. What security authorisations or equivalencies does the service hold, and can you see the documentation? Where is data stored and processed, including backups and replicas? Who has administrative access, from where, and how is it logged? Which subprocessors are involved? What incident notification commitment exists, since your own reporting obligation depends on being told?

The honest position for a non-US provider is that a US federal authorisation is a US programme, so what you are buying is a control environment with independent audit coverage that you map to the practices yourself, plus the ability to place the enclave where your contract permits. That is a real and defensible position; presenting it as an authorisation it is not would be the mistake.

Where MassiveGRID Fits

Against the infrastructure practices, MassiveGRID operates an ISO 27001 certified control environment with SOC 2 Type II audit coverage, which is the independent evidence that shortens your own due diligence. The platform enforces MFA on management interfaces with role-based access control, applies AES-256 encryption at rest and TLS 1.3 in transit with customer-managed key options, captures audit trails with tamper-evident storage and configurable retention, and provides network segmentation and firewalling for the enclave boundary. Dedicated instances and private cloud give the isolation an enclave implies, and SOC and NOC services supply the log review and monitoring that the audit practices require a named function for.

On placement, MassiveGRID deploys into partner facilities operated by Equinix, Digital Realty, Sparkle and NTT, a published footprint of more than 700 datacenters across 85 metros, 30 countries and six continents, and infrastructure can be ordered in any of them, with auto-provisioning in New York, London, Frankfurt and Singapore. Where a contract restricts CUI to US soil or to US persons, confirm both the facility and the support model in writing before committing, since support delivered from elsewhere is an access path.

Scope definition, the SSP, the POA&M and the assessor relationship stay with you. See the CMMC alignment for the gap assessment and turnkey enclave paths, including the SSP and POA&M templates.

Further Reading