Talk to an Expert
CMMC Solutions

CMMC Level 2 with the smallest boundary in the DIB.

Your CUI stays inside a purpose-built enclave, and the enclave carries the proof. Start with a repository, or collapse your whole assessment into an enclave.

Why now

CMMC is already in contracts

Phase 1 is underway: self-assessments in new DoD solicitations, affirmed annually in SPRS. Getting assessment-ready typically takes 6 to 12 months. Starting your pre-assessment now is on time, not early.

Phase 1 · Nov 2025

Underway now

Level 1 and 2 self-assessments required in new DoD solicitations, affirmed annually in SPRS.

Phase 2 · Nov 2026

C3PAO required

Most contracts involving CUI require third-party Level 2 certification.

Rollout currently suspended
Phase 3 · Nov 2027

Options included

Certification requirements extend to option exercises on existing contracts.

Phase 4 · Nov 2028

Full rollout

CMMC requirements in all applicable solicitations and contracts.

The Phase 2 timeline is suspended as of July 2026. The direction is not. The contractors who keep moving own the queue when it restarts.

Know your level

Three levels. Most of the DIB needs Level 2.

CMMC applies to the unclassified networks of an estimated 300,000+ organizations that process, store, or transmit Federal Contract Information or CUI. Which level you owe depends on what you handle.

Level 1 · Foundational

You handle FCI

15 basic safeguarding requirements from FAR 52.204-21, met through an annual self-assessment affirmed by a senior official in SPRS.

Level 2 · Advanced

You handle CUI

The 110 practices of NIST SP 800-171. Most contracts involving CUI point here, with third-party assessment by a C3PAO on the horizon for many.

Level 3 · Expert

Highest-sensitivity programs

Level 2 plus selected enhanced requirements from NIST SP 800-172, assessed by the government rather than a C3PAO.

The catch people miss: even with no CUI anywhere on your network, handling FCI alone still obligates an annual Level 1 self-assessment with a senior official's affirmation filed in SPRS. Almost nobody in the defense supply chain is fully outside this program.

The requirement

What Level 2 actually requires

110 practices, assessed against 320 objectives. One score. Proof, not promises. And all of it applies only to systems inside your assessment scope, which is why everything on this page starts with scope.

NIST SP 800-171

110 practices

Security controls across 14 families, decomposed into 320 assessment objectives, implemented, not just written down.

SPRS

Your score, on file

A self-assessment score and an annual affirmation posted to the DoD's SPRS.

SSP + POA&M

Documentation

A System Security Plan for scoped systems, with open gaps tracked and closed.

PausedC3PAO

Independently assessed

A certified third party assesses the systems that touch CUI every three years. Currently paused by the Department of War.

The decision

Traditional. Point tools. Or RegDOX.

The GCC High re-platform with virtual desktops and an MSP contract, a stack of point tools stitched together, or one enclave. We put them side by side so you don't have to.

The MSP Route vs. RegDOX · CMMC 2.0
The MSP Approach
Resold cloud. Billed management. The meter always running.
Resold Secure CloudGovernment certified collaboration suite · at markup
Full Tenant MigrationA billed services project
Virtual DesktopsPer user · per month
Endpoint HardeningManaged agents on every device
Ongoing MSP AdministrationHours billed · forever
Provisioned Partner AccountsLicensed seats for outsiders
THE MSP RUNS IT · YOU PAY FOR EVERY HOURIntegration · patching · access · their schedule
VS.
The RegDOX Approach
One service. One platform. Built for CMMC 2.0.

RegDOX CCE

One platform · everything built in
  • Secure hosting & infrastructure
  • Identity · MFA · access built in
  • CUI protection · no endpoint agents
  • Logging · audit trail · reporting
  • Compliance documentation included
One vendor · one contract
The difference that matters
The MSP plus their vendor stackVendors1: RegDOX
A migration projectDeploymentDays to onboard
Their meter, always runningOperationsSimple web administration
Prove it yourselfAudit postureReady out of the box
The mechanism

See why devices stay out of scope

The enclave holds the data and the applications. Devices get a live session: frames down, keystrokes up, and nothing else. Watch what happens when a file tries to leave.

CCE · The Data Never LeavesLive Session
SESSION · K·V·M SESSION · K·V·M SESSION · K·V·M CUI LIVES HERE CUI BOUNDARY BLOCKED BLOCKED ENCLAVE VIEWER VIEW ONLY OFFICE PC OUT OF SCOPE ENCLAVE VIEWER VIEW ONLY REMOTE LAPTOP OUT OF SCOPE ENCLAVE VIEWER VIEW ONLY BYOD OUT OF SCOPE
Session encrypted · FIPS 140-3 validated cryptography 0 bytes at rest on any endpoint Every event written to the immutable audit trail
Your people see the work. The data never leaves.
Where assessments fall apart

One rogue email puts your whole mail stack in the assessment scope. Not with RegDOX CCE.

Scope diagrams obsess over file shares and ERP systems, then wave email through as "just communication." That assumption is where assessments quietly fall apart. The instant CUI reaches a mailbox, the inbox, the platform behind it, and every account that sends or receives the data are in scope.

Encrypted email does not escape this. It relocates it. Encryption is a confidentiality control, not a scope-reduction mechanism. A mailbox that holds CUI still stores and transmits CUI, and in the sync model, so does every endpoint the tool touches.

The only way to keep email out of scope is to keep CUI out of email. In the CCE model, CUI lives in the enclave and never lands in a mailbox. The lockdown that keeps it there isn't a project you assemble and defend. It's the engineered default, running on the right.

Your CUI stays put. Your people come to it.
CCE Session · EnclaveLive

Nothing lands on the device. Everything lands in the audit trail.

One product suite

The CMMC Solution

Compliant Computing Enclave

Data, applications, and teams in one boundary

A secure virtual workspace where users, applications, and CUI operate together inside a single compliant boundary. Work on Office documents, CAD files, and databases in the cloud, with your endpoints documented Out-of-Scope.

Explore CCE
Standalone SDR

Protect, control, and track CUI

A purpose-built CUI repository: end-to-end encryption, MFA, secure viewer with watermarking, and tamper-proof audit trails. Supports DFARS 7019 reporting and improves your SPRS score.

Explore SDR
What you get

The Benefits of CCE

Inheritance
96%/100%

of assessment objectives inherited

308 of 320 NIST SP 800-171A assessment objectives are addressed by the RegDOX solution. 100% when you implement based on our documentation library, ready for your SSP on day one.

Speed

Live in days. Productive in weeks. Fast assessments.

The enclave and Secure Data Room provision within 3 business days of signature, live training included. Most teams are uploading and working within 1 to 2 weeks.

Scope

Reduced assessment scope

CUI never touches your corporate network or devices, so endpoints are documented Out-of-Scope under 32 CFR §170.19 and your boundary collapses to the enclave.

Controls

Technical controls, handled

Encrypted storage, MFA, immutable audit logging, watermarked viewing, and downloads, clipboard, and printing blocked by engineered default.

Support

Expert Services, three tiers

A Registered Practitioner, proven templates, and SSP support at whatever depth you want, from a sanity check to an end-to-end partnership.

Proof

Proven in formal assessment

Dozens of defense industrial contractors rely on RegDOX. The enclave approach has carried them through formal CMMC Level 2 assessments, with the boundary independently confirmed.

Validated, not asserted

The security standards any vendor should meet

Grounded in regulation, confirmed by third parties, and proven in the field. Here is ours. Ask your other candidates for the same.

FedRAMP Moderate Equivalency
Independently attested
ISO 27001 Certified
Independently audited security management
FIPS 140-3 Validated Cryptography
Encryption at rest and in transit
CMMC L2 Certified Customers
Certified on this exact model
Patented Technology
The enclave architecture
AWS GovCloud
US-hosted, built for regulated compliance
Straight answers

CMMC questions we hear every week

Does using RegDOX make us CMMC certified?

No vendor can sell you certification. What the platform does is collapse your assessment boundary and carry a large share of the control burden, while our Audit & Assessment team supports your SSP and drives you toward a passing assessment.

Do our laptops really stay out of scope?

When CUI never reaches the endpoint, the endpoint can be documented Out-of-Scope under 32 CFR §170.19. That is the engineered default of the enclave model.

What happens to our existing Microsoft 365 or Google?

They stay out of your CUI assessment scope.

How fast can we be assessment-ready?

The enclave provisions on your timeline rather than an infrastructure projects. The pacing item is usually your documentation and process work, which is what our team helps carry.

Next step

Start with a readiness review.

Bring your contract clauses and your current scope diagram. We will show you exactly what falls away in the enclave model.

(800) 517-3171 · Nashua, NH · U.S. data centers & personnel