Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Huntress: CMMC Compliance Explained for Defense Contractors

Huntress
10/06/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


CMMC, the Cyber Security Maturity Model Certification, is really the verification method that the Department of Defense is using to understand whether their contractors are meeting requirements that have been in contracts for quite some time now. And really what the DOD is looking to do here is to have third party assessment organizations visit or work with these defense contractors to really grade and score them and how they are meeting not only all 110 requirements that are in a NIST document written for that purpose, but all of the assessment objectives for those requirements. When we think about the overlap that exists between the Department of Defense and its contractors and then managed service providers, you start to see that a lot of the industries who are defense contractors are also small businesses and small businesses across the board rely heavily on managed service providers for help with IT and security and monitoring. So it's no surprise that there's a big overlap there. And it's also not a surprise that when so many of the requirements that are in NIST's Special Publication 800-171, which is what CMMC verifies, are very technology specific, that you're going to need to rely heavily on MSPs in order to be able to meet these requirements if you don't have all of that in-house IT expertise yourself. Who is required to pass a Level 2 audit versus like a Level 1 or a Level 3? Level 2 will be for the organizations who are actually handling controlled unclassified information or CUI. The difference now becomes whether or not at Level 2, you're going to want to pursue a C-3PAO assessment where a third party assessment organization comes in and checks all the boxes and confirms you meet requirements. Or if you're going to self-certify and self-assess that you meet those requirements yourself. The DoD has indicated that if you're handling CUI categories of information that are in their defense index grouping, you're going to want to lean more towards getting that C-3PAO assessment sooner rather than later before future contracts start to require it as just a hard stop deal breaker requirement. And what about the changes between like CUI assets versus security protection assets and contractor risk assets? The big thing that both contractors and MSPs and anyone involved in the CUI effort need to understand is that there are these asset categories created by the CMMC program. So even though you have the original requirements from NIST 800-171, you still need to think about how all of your in-scope technologies get categorized because that's going to have a big impact on whether they are assessed in the first place in a CMMC assessment. And if they are assessed, to what degree? What are we interested in those assets for? Is it the CUI they handle or is it the security they provide or is it something else? Why is documentation so important when it comes to CMMC? The reason you're going to see documentation featured so prominently in a CMMC assessment is because of the way that NIST, the National Institute for Standards and Technology, wrote the original requirements that we all now have to meet. They did so by giving us all these objectives where we have to define things and specify things before we act so that there's always a sort of an assurance case there. Here's what I said I was going to do. Now I'm going to prove that I did it. Punch has decided to invest in all of the CMMC documentation that we are providing to our clients because we understand the importance that documentation makes to the ease and speed of your audit. Without the proper documentation, what you're left with is guessing how to best apply these controls into your environment in a way that will satisfy the auditors. When we think about what auditors or assessors are going to be looking for in a CMMC Level 2 assessment, they want visual evidence that you've written down to define something. Some of the main things we wanted to make sure were available in this initial set of documentation were, of course, the core requirements laid out by the CMMC program itself. So having this idea of a shared responsibility matrix that shows everyone what their responsibilities are in meeting a specific NIST 800171A objective that took into account not only what Huntress is doing, but potentially even what a partner might be doing for the benefit of a defense contractor. We built things like security approval forms so that a client working with a partner can sit down with these forms and understand exactly what their MSP or partner is going to do for them. We also thought about some of the most difficult documents to create from scratch and tried to create those things like small supplemental documents that might help you get through an annual security assessment. What we tried to do in the way that we built out all of the follow on activities that would would come from your shared responsibility matrix was to think about like what's the most decision ready document I could put in front of a stakeholder to help guide these decision processes. I think what you'll see Huntress doing inside of a CMMC assessment scope is providing some of the most distinct security capabilities that you need in order to meet a handful of really difficult requirements in NIST 800171, things around system monitoring, the ability to collect logs and other information, having a strong strategy for identifying or detecting and then containing incidents and recovering from those. Huntress decided to take a position on how to meet a lot of these requirements using the Huntress managed platform.

TL;DR

  • CMMC is the DoD's verification framework ensuring defense contractors actually meet NIST 800-171 cybersecurity requirements, not just claim compliance on paper.
  • Level 2 applies to organizations handling CUI and may require a formal C3PAO third-party audit, especially for contractors in the DoD's defense index grouping.
  • Documentation is the cornerstone of CMMC audit success — assessors require written evidence that controls were defined before implementation and consistently followed.
  • Huntress maps its managed platform capabilities — endpoint detection, log collection, and incident response — directly to the most difficult NIST 800-171 requirements.

Summary

This explainer video breaks down the Cybersecurity Maturity Model Certification (CMMC) — the Department of Defense's framework for verifying that defense contractors are genuinely meeting cybersecurity requirements, not simply self-attesting. The video covers all three CMMC levels, with particular focus on Level 2, which applies to organizations handling Controlled Unclassified Information (CUI) and may require a formal third-party C3PAO audit. A key theme is the role of MSPs in helping small defense contractors meet the 110 requirements outlined in NIST Special Publication 800-171, since most of those requirements are technology-specific and demand expertise that smaller businesses rarely maintain in-house. The video also emphasizes that CMMC asset categorization — distinguishing CUI assets, security protection assets, and contractor risk assets — directly determines what gets assessed and how deeply. Documentation is positioned as the single most critical factor in audit readiness: NIST's framework requires organizations to define their controls before acting and then prove they followed through. Huntress has developed a suite of compliance documentation — including shared responsibility matrices and security approval forms — designed to accelerate audit preparation. The video closes by mapping Huntress platform capabilities, including managed endpoint detection, log collection, and incident response, directly to the hardest-to-meet requirements in NIST 800-171, framing Huntress as a purpose-built compliance enabler for the defense industrial base.

Chapters

0:00 - What Is CMMC?
1:28 - CMMC Levels and C3PAO Audits
2:31 - Asset Categories and Scope
3:25 - Why Documentation Matters
5:40 - Huntress and CMMC Requirements

Key Quotes

0:01 "CMMC, the Cyber Security Maturity Model Certification, is really the verification method that the Department of Defense is using to understand whether their contractors are meeting requirements that have been in contracts for quite some time now."
1:19 "You're going to need to rely heavily on MSPs in order to be able to meet these requirements if you don't have all of that in-house IT expertise yourself."
2:13 "If you're handling CUI categories of information that are in their defense index grouping, you're going to want to lean more towards getting that C-3PAO assessment sooner rather than later before future contracts start to require it as just a hard stop deal breaker requirement."
3:55 "Here's what I said I was going to do. Now I'm going to prove that I did it."
5:42 "I think what you'll see Huntress doing inside of a CMMC assessment scope is providing some of the most distinct security capabilities that you need in order to meet a handful of really difficult requirements in NIST 800171."

FAQ

Does every defense contractor need a C3PAO audit for CMMC Level 2?

Not necessarily. Level 2 allows for self-certification in some cases, but the DoD has signaled that contractors handling CUI categories in the defense index grouping should pursue a C3PAO third-party assessment sooner rather than later, as future contracts are expected to make it a hard requirement.

How does Huntress help with CMMC compliance?

Huntress provides managed security capabilities — including endpoint detection, log collection, and incident response — that map directly to some of the most difficult requirements in NIST 800-171. The platform also offers compliance documentation such as shared responsibility matrices and security approval forms to streamline audit preparation.

Categories:
  • » Webinar Library » Huntress
  • » Data Protection » Backup & Recovery
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Compliance & Governance
  • Security Operations
  • Data Protection
  • Best Practices
  • Getting Started
  • CMMC compliance
  • NIST 800-171
  • Controlled Unclassified Information
  • CUI
  • C3PAO third-party assessment
  • Defense contractor cybersecurity
  • MSP compliance support
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Huntress: CMMC Compliance Explained for Defense Contractors

              Industry Events (Sponsor Hosted)

              • Oct
                13

                Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance

                10/13/202601:00 PM ET
                • Oct
                  15

                  Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation

                  10/15/202611:00 AM ET
                  • Oct
                    20

                    Harnessing Data Governance for AI with Cyera and Snowflake

                    10/20/202611:00 AM ET
                    More events

                    Upcoming Webinar Calendar

                    • 10/13/2026
                      01:00 PM
                      10/13/2026
                      Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance
                      https://www.truthinit.com/index.php/channel/2159/transitioning-from-cjis-to-ferpa-essential-audit-evidence-for-compliance/
                    • 10/15/2026
                      11:00 AM
                      10/15/2026
                      Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation
                      https://www.truthinit.com/index.php/channel/1372/risk-in-real-time-demo-series-the-autonomous-era-orchestrating-a-resilient-enterprise/
                    • 10/20/2026
                      11:00 AM
                      10/20/2026
                      Harnessing Data Governance for AI with Cyera and Snowflake
                      https://www.truthinit.com/index.php/channel/2137/harnessing-data-governance-for-ai-with-cyera-and-snowflake/
                    • 10/27/2026
                      01:00 PM
                      10/27/2026
                      The HUMAN Experience: Real-Time Insights into Page Intelligence
                      https://www.truthinit.com/index.php/channel/2139/the-human-experience-real-time-insights-into-page-intelligence/
                    • 11/04/2026
                      11:00 AM
                      11/04/2026
                      Leveraging CISA’s Zero Trust Maturity Model for an AI-Driven Landscape
                      https://www.truthinit.com/index.php/channel/2149/leveraging-cisas-zero-trust-maturity-model-for-an-ai-driven-landscape/
                    • 11/04/2026
                      11:00 AM
                      11/04/2026
                      Aligning Agentic Intent: Understanding Your Agents' Purpose vs. Their Actions
                      https://www.truthinit.com/index.php/channel/2158/aligning-agentic-intent-understanding-your-agents-purpose-vs-their-actions/
                    • 11/05/2026
                      01:00 PM
                      11/05/2026
                      HUMAN Dialogue: Redefining Authentic Trust in the Agentic Internet
                      https://www.truthinit.com/index.php/channel/2160/human-dialogue-redefining-authentic-trust-in-the-agentic-internet/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version