Skip to main content
INS // Insights

CMMC Compliance for Cloud-Based Defense IT Systems

Updated June 2026 · 9 min read

The Cybersecurity Maturity Model Certification (CMMC) program is reshaping how defense contractors approach cybersecurity. For IT companies building cloud-based systems that handle Controlled Unclassified Information (CUI) for the Department of Defense, CMMC compliance is not a checkbox exercise — it is a substantive engineering and process requirement that must be designed into systems from the beginning.

This article covers CMMC compliance for cloud-based defense IT systems — how CMMC Level 2 requirements map to cloud architecture practices, what third-party assessment (C3PAO) evaluates, and how AWS GovCloud services support CMMC compliance implementation.

What Is CMMC and Why Does It Apply to Cloud Systems?

CMMC is the DoD's framework for verifying that defense contractors and subcontractors protect CUI (Controlled Unclassified Information) adequately. CUI includes technical data, export-controlled information, and other sensitive government information that doesn't require classification but still requires protection.

CMMC replaced the self-attestation model of NIST 800-171 compliance with a certification model:

  • CMMC Level 1: 17 basic practices, annual self-attestation. For contracts handling Federal Contract Information (FCI) but not CUI.
  • CMMC Level 2: 110 practices aligned to NIST SP 800-171 Rev 2. Requires third-party assessment (C3PAO) for programs with advanced or critical CUI. Self-attestation acceptable for some Level 2 contracts.
  • CMMC Level 3: 110+ practices including additional NIST 800-172 requirements. Government-conducted assessment. For the most sensitive CUI.

A cloud-based system that processes, stores, or transmits DoD CUI must meet the CMMC level specified in the applicable contract. The cloud environment's configuration — not just the provider's FedRAMP authorization — is what gets assessed.

How CMMC Level 2 Practices Map to Cloud Configuration

CMMC Level 2 is 110 practices organized across 14 domains. For cloud-based systems, key domain mappings:

Access Control (AC): 22 practices covering user access authorization, least privilege, remote access controls, and mobile device management. Cloud mapping: IAM role-based access with least-privilege policies, MFA enforcement via SCPs and IAM password policies, VPN or zero-trust access for remote administration, conditional access policies for all administrative interfaces.

Audit and Accountability (AU): Audit logging of system events, user actions, and security-relevant events. Cloud mapping: CloudTrail for all API calls, CloudWatch Logs for application events with appropriate retention, VPC Flow Logs for network traffic, Security Hub findings aggregation.

Configuration Management (CM): Baseline configurations, change control. Cloud mapping: Infrastructure as Code for all infrastructure (preventing drift from approved baselines), AWS Config Rules for continuous configuration compliance monitoring, approved AMIs and container base images with version control.

Identification and Authentication (IA): User authentication, multi-factor authentication, password management. Cloud mapping: IAM with MFA required for all human users, SCPs preventing MFA bypass, Cognito or federated identity with MFA for application users, no IAM access key usage for EC2 instances (use IAM roles).

Incident Response (IR): Incident response planning, detection, and reporting. Cloud mapping: GuardDuty for automated threat detection, Security Hub for findings aggregation, documented incident response procedures with CMMC reporting requirements addressed, periodic IR testing.

System and Communications Protection (SC): Boundary protection, encryption. Cloud mapping: Network Firewall or WAF at boundary, TLS 1.2+ for all data in transit, encryption at rest for all storage services, VPC segmentation between system components.

System and Information Integrity (SI): Malware protection, system monitoring, security alerts. Cloud mapping: ECR image scanning for containers, AWS Inspector for EC2 vulnerabilities, GuardDuty for behavioral threat detection, CloudWatch Alarms for anomaly detection.

What C3PAO Assessment Evaluates

A Certified Third-Party Assessment Organization (C3PAO) conducts CMMC Level 2 assessments against the 110 practices, evaluating both policy/process documentation and technical implementation evidence. Common assessment activities:

Document review: Evaluators review your System Security Plan (SSP), which must document how each of the 110 practices is implemented. The SSP must accurately reflect your actual configuration — assessors verify claimed implementations.

Technical verification: Assessors check configurations directly — reviewing IAM policies, checking CloudTrail configuration, verifying encryption settings, confirming MFA enforcement, reviewing security group rules, checking log retention settings.

Interview: Assessors interview system administrators and security personnel to verify they understand and can demonstrate the implemented controls.

Deficiency findings and POA&Ms: Practices not fully implemented at time of assessment can be accepted as POA&M (Plan of Action and Milestones) items with a remediation schedule for non-critical findings. Critical practices must be fully implemented for CMMC Level 2 certification.

AWS GovCloud's Role in CMMC Compliance

AWS GovCloud is FedRAMP High authorized, which provides significant inherited security controls for CMMC-relevant systems. AWS's FedRAMP package documents the controls that AWS is responsible for (typically physical security, hypervisor security, managed service security configurations). Your CMMC SSP can inherit these controls and reference the AWS FedRAMP authorization.

However, inherited controls cover only the platform layer. Customer-configured controls — IAM policies, network security groups, encryption configuration, application logging — are your responsibility and must be documented and evidenced in your CMMC assessment. The distinction between AWS responsibility and customer responsibility is formalized in AWS's Shared Responsibility Model documentation.

AWS Config Rules as continuous compliance evidence: AWS Config Rules can be configured to continuously check and report on configuration compliance against specific practices — encrypted storage, MFA enforcement, CloudTrail enablement. Config findings and compliance history are valuable evidence for CMMC assessments and continuous monitoring requirements.


Rutagon helps defense IT firms architect and document cloud systems for CMMC compliance — from system security plan development and AWS GovCloud architecture design to pre-assessment gap analysis and remediation.

Explore Our CMMC Compliance Services →

Related articles: - Cloud Architecture Reviews for Defense Programs - AWS Network Firewall for Government - Technology Evaluation Criteria for DoD IT


Frequently Asked Questions

What is CMMC and who needs to comply?

CMMC is the DoD's Cybersecurity Maturity Model Certification program, requiring defense contractors and subcontractors that handle DoD Controlled Unclassified Information (CUI) to demonstrate cybersecurity practice maturity. CMMC requirements flow down through prime contracts to subcontractors — if your contract or subcontract involves handling CUI, CMMC compliance applies to your systems that process that data.

Does FedRAMP authorization satisfy CMMC requirements?

No. FedRAMP authorization demonstrates that a cloud service provider's platform meets federal security requirements. CMMC assesses the contractor's use of the cloud platform — the IAM configuration, network controls, application security, logging, and incident response implemented on top of the platform. A CMMC assessment evaluates both the platform (inherited from FedRAMP) and the customer-implemented configuration.

What is the difference between CMMC Level 2 and Level 3?

CMMC Level 2 implements the 110 practices of NIST SP 800-171 Rev 2 and requires C3PAO third-party assessment for critical programs. CMMC Level 3 adds practices from NIST SP 800-172 (enhanced security requirements for high-value CUI programs) and requires government-conducted assessment. Most defense IT companies target Level 2; Level 3 applies to the most sensitive programs.

How long does a CMMC Level 2 assessment take?

A CMMC Level 2 assessment typically takes 2–4 weeks for the active assessment phase, preceded by documentation review. Organizations that have conducted thorough self-assessment and gap remediation before engaging a C3PAO move through the formal assessment more efficiently. Certification, once assessed and approved, is valid for 3 years.

Can cloud services themselves be CMMC certified?

CMMC assesses contractor organizations and their systems — not cloud services themselves. Cloud services (like AWS GovCloud) contribute inherited controls through their FedRAMP authorization. The CMMC assessed entity is the organization using the cloud services, not the cloud services provider. A C3PAO assesses whether your organization's use of those services meets the 110 CMMC Level 2 practices.

Ready to discuss your project?

We deliver production-grade software for government, defense, and commercial clients. Let's talk about what you need.

Initiate Contact