For cloud / hybrid teams
Identities in Entra ID, devices in Intune, workloads in Azure or SaaS, and logs that someone actually reviews—scope and evidence live across those boundaries.
Beacon is Canopy Harbor’s plain-language guide for modern cloud and hybrid shops that handle Federal contract information (FCI) or Controlled Unclassified Information (CUI). We translate the official framework into readable orientation—without replacing the primary sources or a formal assessment.
NIST SP 800-171 is NIST’s catalog of security requirements for protecting CUI in nonfederal systems. CMMC (Cybersecurity Maturity Model Certification) is the DoD program that assesses whether contractors meet those (and related) requirements at defined levels, with results used in contracting.
Identities in Entra ID, devices in Intune, workloads in Azure or SaaS, and logs that someone actually reviews—scope and evidence live across those boundaries.
Most CUI conversations center on CMMC Level 2, which aligns to the NIST SP 800-171 Rev. 2 security requirements as incorporated in 32 CFR Part 170.
Beacon helps you ask better questions and organize work. It is not legal advice, not a certification, and not a substitute for official guides or qualified assessors.
CMMC has three levels. Assessment type (self vs third-party / government) matters as much as the level number. Always read your solicitation and the current Code of Federal Regulations—not a blog summary.
Aligned to the 15 basic safeguarding requirements in FAR 52.204-21. Typically a self-assessment path for Federal contract information (not CUI).
110 security requirements from NIST SP 800-171 Revision 2. May be self or C3PAO certification assessment, depending on what the contract requires.
Selected enhanced requirements from NIST SP 800-172 for higher-sensitivity programs. Government (DIBCAC) assessment path as defined in the rule.
Expect gap work (and assessors) to look at Entra ID (MFA, Conditional Access, privileged roles), Intune / endpoint compliance and encryption, Azure / M365 configuration and logging, SIEM or Defender review practices, and how SaaS boundaries are drawn (shared responsibility, CRM excerpts, encryption, process controls). “It’s in the cloud” is not a control—evidence is.
Program status changes. Confirm current expectations on dodcio.defense.gov/CMMC before planning contractual milestones (including any published phase / implementation notices).
A practical outline many teams follow. Durations vary widely with scope size, legacy debt, and staffing— treat timelines as planning ranges, not promises.
Rough planning ranges heard from industry (illustrative only): focused enclave remediation can be months; enterprise-wide lifts often run longer. C3PAO scheduling itself can add wait time. Build contingency—do not bid the best case.
Do not confuse your company’s CMMC status with individual ecosystem credentials. Official role definitions live in 32 CFR Part 170 and with the Cyber AB / CAICO.
| Who | What it is | Notes |
|---|---|---|
| Organization (OSA / OSC) | CMMC Status at Level 1 (Self), Level 2 (Self), Level 2 (C3PAO), or Level 3 (DIBCAC), as applicable | Driven by contract requirements and assessment results entered for DoD use (e.g., SPRS / program systems). Not the same as an individual’s CCP/CCA. |
| CCP — CMMC Certified Professional | Foundational individual credential in the assessment ecosystem | Training via an Approved Training Provider, exam, application requirements, and DoD Tier 3 determination as required by the program / Cyber AB pathway. |
| CCA — CMMC Certified Assessor | Assessor who conducts Level 2 certification assessments with a C3PAO | Requires active CCP path plus additional experience, 8140-aligned baseline qualification, training/exam, and other 32 CFR § 170.11 requirements. |
| C3PAO | Organization authorized/accredited to perform Level 2 certification assessments | Companies seeking certification hire a C3PAO; they do not “become” a C3PAO by passing CCP. |
Start here: Cyber AB — Assessing and Certification · 32 CFR § 170.11 (CCA) · ISACA CCP overview (exam delivery partner materials; confirm against Cyber AB for current requirements).
Prefer .gov and primary publishers. Re-check URLs before citing in contracts.
Multi-page PDF covering company readiness, NIST SP 800-171 family evidence reminders for cloud/hybrid shops, journey milestones, and a documentation pack checklist. Free to use internally; still not an assessment.
© Canopy Harbor LLC. Beacon content is for general informational purposes only and does not create an attorney–client, assessor–client, or consulting relationship. Official requirements control in the event of any conflict. Not legal advice.