Compliance — CMMC 2.0
CMMC Level 2 monitoring — all 110 NIST SP 800-171 practices evidenced
CMMC Level 2 requires implementation and evidence of 110 NIST SP 800-171 practices. ManySignal continuously collects evidence for Audit and Accountability (3.3.x) and System Integrity (3.14.x) families — and generates C3PAO-ready assessment packages with DFARS 72-hour notification support built in.
110
NIST SP 800-171 practices required for CMMC Level 2
72 hrs
DFARS 252.204-7012 cyber incident reporting window to DoD
2025
CMMC Level 2 enforcement beginning in DoD contracts
C3PAO
Third-party assessment organisation — ManySignal evidence reduces assessment burden
Control mapping — NIST SP 800-171 to ManySignal
| Practice ID | Practice Name | ManySignal Capability |
|---|---|---|
| 3.3.1 | Create and retain system audit logs | Log collection and 3-year retention from all CUI-scoped systems — endpoint, network, identity, and application |
| 3.3.2 | Ensure user and system actions are traceable | Entity graph links every event to a specific user identity, device, and session |
| 3.3.3 | Review and update logged events | Automated detection of logging gaps — systems not forwarding logs trigger coverage gap alerts |
| 3.3.5 | Correlate audit record review with alerts | Alert-to-audit-record correlation built into every triage verdict — evidence chain documented automatically |
| 3.3.6 | Reduce audit log volume to relevant information | AI-powered signal-to-noise reduction — 85-95% alert auto-closure with documented rationale |
| 3.14.6 | Monitor systems for attacks and indicators | Continuous monitoring across all CUI system boundary components — IOC matching and behavioural analytics |
| 3.14.7 | Identify unauthorised use of systems | User behaviour analytics — baseline deviation and privilege abuse detection |
| 3.6.1 | Establish an incident response capability | Automated response playbooks with DFARS 252.204-7012 72-hour notification workflow |
| 3.6.2 | Track, document, and report incidents | Case lifecycle management with full timeline, entity list, and DIBNet notification formatting |
Assessment and audit status
ManySignal's CMMC mapping document and System Security Plan (SSP) template are available to defence contractor customers under NDA. The full NIST SP 800-171 evidence package — covering all 110 practices — is generated automatically from the platform for C3PAO assessment submissions. Contact [email protected] for assessment support documentation.
CMMC 2.0 — common questions
Does ManySignal support CMMC Level 2 specifically?
Yes. CMMC Level 2 requires implementation of all 110 NIST SP 800-171 Rev 2 practices. ManySignal addresses the Audit and Accountability (3.3.x) and System and Information Integrity (3.14.x) practice families in full — the two families most directly related to continuous monitoring. The platform provides machine-verifiable evidence for each practice, formatted for C3PAO assessment review.
How does ManySignal support DFARS 252.204-7012 — the 72-hour cyber incident notification?
DFARS 252.204-7012 requires contractors to report cyber incidents to DoD within 72 hours via the DIBNet portal. ManySignal's case management tracks the discovery timestamp, starts the 72-hour countdown, and pre-populates the DIBNet incident report fields — incident date/time, systems affected, CUI categories involved, and the contractor's CAGE code. The report is ready for submission before the deadline.
What is the difference between CMMC Level 2 and Level 3 in terms of monitoring requirements?
CMMC Level 2 requires the 110 practices of NIST SP 800-171. Level 3 adds 24 practices from NIST SP 800-172, which includes enhanced monitoring requirements — specifically EP-2 (employing threat hunting) and EP-3 (employing ML-based anomaly detection). ManySignal's threat hunting capabilities and behavioural analytics address the Level 3 enhanced monitoring practices.
When does CMMC 2.0 become mandatory in DoD contracts?
CMMC 2.0 is being phased into DoD solicitations starting 2025. The rule (32 CFR Part 170) requires CMMC Level 2 certification for contracts involving CUI. Level 2 third-party assessments (C3PAO) are required for critical national security programmes; Level 2 self-assessments are permitted for other contracts. ManySignal provides evidence for both assessment paths.
Can ManySignal be deployed in a self-hosted configuration for CUI environments?
Yes. ManySignal's self-hosted deployment option is designed for CUI environments that require on-premises or government-controlled cloud infrastructure. In self-hosted mode, no data leaves the customer's environment — the detection engine, entity graph, and response automation run entirely within the customer's deployment boundary, with no dependency on ManySignal's cloud services.
Start CMMC Level 2 evidence collection
Deploy ManySignal in your CUI environment — cloud or self-hosted. Begin collecting NIST SP 800-171 evidence from the first day, ready for C3PAO assessment.