Skip to content

CMMC Compliance

GOVERN supports defense contractors operating under CMMC (Cybersecurity Maturity Model Certification) 2.0. GOVERN’s governance capabilities directly support several CMMC practice domains.

CMMC Level 2 — Advanced

Level 2 (110 practices from NIST SP 800-171) is required for contractors handling CUI.

Practices GOVERN Supports

DomainPracticeGOVERN Capability
Access Control (AC)AC.L2-3.1.1RBAC, least privilege enforcement
Access Control (AC)AC.L2-3.1.2Transaction privilege controls
Audit & Accountability (AU)AU.L2-3.3.1System audit events, immutable logs
Audit & Accountability (AU)AU.L2-3.3.2User and admin activity review
Configuration Management (CM)CM.L2-3.4.1Baseline configuration establishment
Identification & Auth (IA)IA.L2-3.5.3MFA for privileged access
Risk Assessment (RA)RA.L2-3.11.2Vulnerability scanning
System & Comm Prot (SC)SC.L2-3.13.8Cryptographic protection in transit
System & Info Integrity (SI)SI.L2-3.14.6Monitor for security alerts
System & Info Integrity (SI)SI.L2-3.14.7Identify unauthorized use

Enabling CMMC Level 2

Terminal window
helm install govern govern/govern \
-f values-federal.yaml \
--set compliance.cmmc.level=2 \
--set compliance.cmmc.cui.enabled=true

This activates:

  • CUI data handling controls
  • Enhanced audit logging (AU.L2 practices)
  • MFA enforcement for all privileged accounts
  • Vulnerability scan scheduling
  • Security event monitoring with alerting

CMMC Level 3 — Expert

Level 3 (110+ practices from NIST SP 800-172) is required for contractors on critical DoD programs.

Additional Practices for Level 3

DomainPracticeGOVERN Capability
Access Control (AC)AC.L3-3.1.3eDynamic access control
Awareness & Training (AT)AT.L3-3.2.1eAdvanced training tracking
Audit & Accountability (AU)AU.L3-3.3.1eCentralized audit analysis
Configuration Management (CM)CM.L3-3.4.1eAutomated config checks
Risk Assessment (RA)RA.L3-3.11.1eRisk assessments with threat intel
System & Info Integrity (SI)SI.L3-3.14.1eThreat intelligence correlation

Enabling CMMC Level 3

Terminal window
helm install govern govern/govern \
-f values-federal.yaml \
-f values-il4.yaml \
--set compliance.cmmc.level=3 \
--set compliance.cmmc.threatIntel.enabled=true \
--set compliance.cmmc.advancedMonitoring.enabled=true

CMMC Assessment Evidence

GOVERN automatically generates evidence packages for CMMC assessments:

Terminal window
# Generate CMMC evidence package
govern compliance export \
--framework cmmc \
--level 2 \
--format pdf \
--output cmmc-evidence-$(date +%Y%m%d).pdf

The evidence package includes:

  • Control implementation statements
  • Audit log samples (last 90 days)
  • Configuration baseline screenshots
  • Vulnerability scan summary
  • Incident response log (if any)
  • User access review records

Third-Party Assessment Support

For CMMC certification assessments (C3PAO), GOVERN can provide:

  • Read-only C3PAO access to audit logs
  • Direct API access for evidence collection
  • Automated evidence export in OSCAL format
  • SSP and CRM documentation

Contact federal@archetypal.ai to coordinate C3PAO access.