What CMMC is
The Cybersecurity Maturity Model Certification (CMMC) is the US Department of Defense program that verifies defense contractors protect sensitive information. It applies across the Defense Industrial Base (DIB), and the level required depends on the data you handle.
| Level | What it covers |
|---|---|
| Level 1 (Foundational) | The 15 basic safeguarding requirements for Federal Contract Information (FCI), from FAR 52.204-21. Self-assessed annually and affirmed in SPRS by a company official. |
| Level 2 (Advanced) | Protection of Controlled Unclassified Information (CUI): the 110 security requirements of NIST SP 800-171 across 14 domains. Where most defense contractors land, assessed every three years, by an accredited C3PAO for most CUI contracts. Limited POA&M items must close within 180 days. |
| Level 3 (Expert) | Level 2 plus selected enhanced requirements from NIST SP 800-172, aimed at advanced persistent threats on the highest-risk programs. Assessed by the government (DIBCAC). |
In short: FCI points you toward Level 1, CUI toward Level 2 and its NIST SP 800-171 control set, and the most sensitive work toward Level 3. The data you hold drives the level you need. CMMC is now phasing into Department of Defense contracts, so the level appears in the contract and an assessor asks for evidence rather than intentions. The CMMC 2.0 guide walks the 14 domains and names which Microsoft 365, Intune and Defender settings become that evidence.
The Microsoft 365 Government clouds
Microsoft runs separate government clouds so regulated data stays in the right boundary. Choosing the right one is a prerequisite for meeting CUI and DoD obligations.
Microsoft also publishes which services and certifications apply in each environment, and a shared-responsibility model: Microsoft secures the platform, and the customer is responsible for how identity, devices, data, and access are configured on top of it.
How it ties together
CMMC says what you must protect and to what standard. The Microsoft 365 Government clouds give you a boundary built for that data. The tenant configuration on top, identity, Conditional Access, device compliance in Intune, Defender, and Purview information protection, is where most of the NIST SP 800-171 control families are actually satisfied or missed.
- Pick the cloud that matches your data: FCI may fit GCC, CUI and ITAR generally point to GCC High.
- Map your CMMC level to the NIST control set: Level 2 to 800-171, Level 3 adds 800-172.
- Configure and prove the technical controls in the tenant, then keep evidence that they stay in place.
Where Senserva is, and where it is headed
Live now, in beta: Senserva Federal Watch. The federal wire, the CMMC rule-making lane pulled from the Federal Register and acquisition.gov, the BOD 22-01 remediation dates from the CISA Known Exploited Vulnerabilities catalog, and those deadlines by email. Free to join, one email address.
Live now, on commercial tenants: deep Microsoft 365, Intune, Defender, Entra ID, and Purview analysis: ranked findings, automated and validated approve-before-apply remediation, and Senserva Trustworthy AI that keeps every answer grounded and every change reviewed. Access Control, Identification and Authentication, Audit and Accountability, and Configuration Management already produce dated evidence an assessor recognises; the CMMC 2.0 guide marks which of the 14 domains those are.
Not yet: Government cloud tenants. When GCC and GCC High access is in place, the plan is to bring that same depth there, with the configuration evidence and remediation mapped to the NIST SP 800-171 and 800-172 control families behind CMMC. The per-practice CMMC mapping is being built now. Senserva for CMMC is where that lands, and where you can ask to be told when it does.
Nothing here is a claim of CMMC certification, Federal authorization, or Government cloud coverage. Federal Watch is an alerting service, not an assessment.
AI governance belongs in the Federal conversation
As AI and Copilot enter government and defense work, AI governance becomes part of the same compliance picture. The standards below are the most relevant to Federal and regulated programs, and Senserva already audits the Microsoft AI surface they care about: agent identities, the permissions agents inherit, and high-risk Graph scopes. That coverage is available on commercial Microsoft 365 today and is part of the same roadmap toward Government cloud support.
See the full AI Governance coverage for how these map to Senserva.
Talk to us about Federal
If CMMC and GCC are on your roadmap, tell us. Joining Senserva Federal Watch above is the fastest way to hear it first, and it is how the federal deadlines reach you in the meantime. The pages below are the rest of the federal set.