CMMC 2.0 Level 2
Compliance Scanning
Defense contractors and DIB subcontractors need CMMC 2.0 Level 2 compliance to handle Controlled Unclassified Information (CUI). ComplianceLayer maps external scan findings to NIST SP 800-171 controls that underpin CMMC Level 2 practices.
NIST 800-171 Controls Mapped to ComplianceLayer Modules
CMMC 2.0 Level 2 aligns directly with NIST SP 800-171 Rev 2. The following controls are verified through external scanning.
| Control ID | Control Name | Scan Module | What We Check |
|---|---|---|---|
| AC-17 | Remote Access | Open Ports | Monitor and control remote access sessions. ComplianceLayer detects exposed RDP (3389), SSH (22), and VNC ports. |
| PR.AC-5 | Network Integrity Protection | Open Ports | Protect network integrity with segmentation and access controls. Scans identify exposed administrative services. |
| PR.AC-7 | Authentication Mechanisms | Open Ports / SSL | Verify authentication mechanisms for users, devices, and processes accessing systems. |
| PR.AC-4 | Access Permissions | Security Headers | Manage access permissions incorporating least privilege principles. |
| SC-8 | Transmission Confidentiality | SSL/TLS | Protect confidentiality and integrity of transmitted CUI. Validates TLS versions, cipher suites, and certificate validity. |
| SC-13 | Cryptographic Protection | SSL/TLS | Implement FIPS-validated cryptography. Checks for weak ciphers, deprecated TLS 1.0/1.1, and key strength. |
| PR.DS-1 | Data-at-Rest Protection | SSL/TLS / Ports | Protect data-at-rest. Identifies exposed database ports (MySQL 3306, PostgreSQL 5432) lacking encryption. |
| PR.DS-2 | Data-in-Transit Protection | SSL/TLS / Email | Protect data-in-transit. Validates HTTPS enforcement, HSTS headers, SPF, DKIM, and DMARC configuration. |
| PR.DS-5 | Data Leak Protection | Security Headers | Implement protections against data leaks. Checks CSP, Referrer-Policy, and Permissions-Policy headers. |
| PR.DS-6 | Integrity Checking | Security Headers | Use integrity checking mechanisms to verify software and data integrity. Validates Content-Security-Policy. |
| PR.PT-4 | Communications Protection | Open Ports | Protect communications and control networks. Detects exposed SMB (445), Telnet (23), and FTP (21) services. |
| PR.IP-1 | Baseline Configurations | Security Headers | Establish and maintain baseline configurations. Verifies security header presence and correctness. |
| DE.CM-8 | Vulnerability Scans | All Modules | Perform vulnerability scans. ComplianceLayer runs 16 modules covering the external attack surface. |
| ID.RA-1 | Risk Identification | All Modules | Identify and document asset vulnerabilities. Aggregated findings with severity ratings and remediation guidance. |
CMMC certification requires a formal C3PAO assessment. These are externally observable technical controls that support your CMMC readiness. Full compliance requires organizational policies, training, and internal controls.
CMMC Compliance Scanning in 3 Steps
Enter your domain
Submit any domain used by your organization. ComplianceLayer scans the full external attack surface.
Review NIST 800-171 mapping
Each finding maps to specific NIST 800-171 controls with pass, fail, or partial status.
Export for your C3PAO
Download the compliance report as evidence for your CMMC assessment preparation.
Common questions
Does ComplianceLayer provide CMMC certification?
No. CMMC certification requires a formal assessment by a C3PAO (Certified Third-Party Assessment Organization). ComplianceLayer maps your external security posture to NIST 800-171 controls that align with CMMC 2.0 Level 2, giving you evidence to support your assessment preparation.
Which CMMC practices does ComplianceLayer cover?
ComplianceLayer covers externally observable technical controls mapped to NIST SP 800-171 families including Access Control (AC), System and Communications Protection (SC), and Risk Assessment (RA). These are the controls verifiable through external scanning.
Can I use ComplianceLayer reports for my CMMC assessment?
Yes. The scan report provides documented evidence for technical controls that a C3PAO assessor can review. It covers encryption in transit, exposed ports, email authentication, and security header configuration — all relevant to CMMC Level 2 practices.
How often should I run compliance scans for CMMC?
CMMC requires continuous monitoring. We recommend weekly scans to catch certificate expirations, new port exposures, or DNS configuration changes. Pro and Enterprise plans include scheduled scanning and alerting.
Start scanning your first
domain in 60 seconds.
No credit card. No sales call. No setup. Free tier is permanent.
All scans are passive and external — we never access your servers, install agents, or require credentials. View our security practices, live system status, or browse domain reports.