Compliance Scanning

CMMC 2.0 Level 2
Compliance Scanning

Defense contractors and DIB subcontractors need CMMC 2.0 Level 2 compliance to handle Controlled Unclassified Information (CUI). ComplianceLayer maps external scan findings to NIST SP 800-171 controls that underpin CMMC Level 2 practices.

Control Mapping

NIST 800-171 Controls Mapped to ComplianceLayer Modules

CMMC 2.0 Level 2 aligns directly with NIST SP 800-171 Rev 2. The following controls are verified through external scanning.

Control IDControl NameScan ModuleWhat We Check
AC-17Remote AccessOpen PortsMonitor and control remote access sessions. ComplianceLayer detects exposed RDP (3389), SSH (22), and VNC ports.
PR.AC-5Network Integrity ProtectionOpen PortsProtect network integrity with segmentation and access controls. Scans identify exposed administrative services.
PR.AC-7Authentication MechanismsOpen Ports / SSLVerify authentication mechanisms for users, devices, and processes accessing systems.
PR.AC-4Access PermissionsSecurity HeadersManage access permissions incorporating least privilege principles.
SC-8Transmission ConfidentialitySSL/TLSProtect confidentiality and integrity of transmitted CUI. Validates TLS versions, cipher suites, and certificate validity.
SC-13Cryptographic ProtectionSSL/TLSImplement FIPS-validated cryptography. Checks for weak ciphers, deprecated TLS 1.0/1.1, and key strength.
PR.DS-1Data-at-Rest ProtectionSSL/TLS / PortsProtect data-at-rest. Identifies exposed database ports (MySQL 3306, PostgreSQL 5432) lacking encryption.
PR.DS-2Data-in-Transit ProtectionSSL/TLS / EmailProtect data-in-transit. Validates HTTPS enforcement, HSTS headers, SPF, DKIM, and DMARC configuration.
PR.DS-5Data Leak ProtectionSecurity HeadersImplement protections against data leaks. Checks CSP, Referrer-Policy, and Permissions-Policy headers.
PR.DS-6Integrity CheckingSecurity HeadersUse integrity checking mechanisms to verify software and data integrity. Validates Content-Security-Policy.
PR.PT-4Communications ProtectionOpen PortsProtect communications and control networks. Detects exposed SMB (445), Telnet (23), and FTP (21) services.
PR.IP-1Baseline ConfigurationsSecurity HeadersEstablish and maintain baseline configurations. Verifies security header presence and correctness.
DE.CM-8Vulnerability ScansAll ModulesPerform vulnerability scans. ComplianceLayer runs 16 modules covering the external attack surface.
ID.RA-1Risk IdentificationAll ModulesIdentify and document asset vulnerabilities. Aggregated findings with severity ratings and remediation guidance.

CMMC certification requires a formal C3PAO assessment. These are externally observable technical controls that support your CMMC readiness. Full compliance requires organizational policies, training, and internal controls.

How It Works

CMMC Compliance Scanning in 3 Steps

01

Enter your domain

Submit any domain used by your organization. ComplianceLayer scans the full external attack surface.

02

Review NIST 800-171 mapping

Each finding maps to specific NIST 800-171 controls with pass, fail, or partial status.

03

Export for your C3PAO

Download the compliance report as evidence for your CMMC assessment preparation.

FAQ

Common questions

Does ComplianceLayer provide CMMC certification?

No. CMMC certification requires a formal assessment by a C3PAO (Certified Third-Party Assessment Organization). ComplianceLayer maps your external security posture to NIST 800-171 controls that align with CMMC 2.0 Level 2, giving you evidence to support your assessment preparation.

Which CMMC practices does ComplianceLayer cover?

ComplianceLayer covers externally observable technical controls mapped to NIST SP 800-171 families including Access Control (AC), System and Communications Protection (SC), and Risk Assessment (RA). These are the controls verifiable through external scanning.

Can I use ComplianceLayer reports for my CMMC assessment?

Yes. The scan report provides documented evidence for technical controls that a C3PAO assessor can review. It covers encryption in transit, exposed ports, email authentication, and security header configuration — all relevant to CMMC Level 2 practices.

How often should I run compliance scans for CMMC?

CMMC requires continuous monitoring. We recommend weekly scans to catch certificate expirations, new port exposures, or DNS configuration changes. Pro and Enterprise plans include scheduled scanning and alerting.

Other compliance frameworks

Get started

Start scanning your first
domain in 60 seconds.

No credit card. No sales call. No setup. Free tier is permanent.

10 free scans per month, foreverAPI key in 30 secondsCancel anytime

All scans are passive and external — we never access your servers, install agents, or require credentials. View our security practices, live system status, or browse domain reports.