Regulation — federal / defense
CMMC 2.0 Level 2 + Level 3 — Cybersecurity Maturity Model Certification for DIB contractors
CMMC 2.0 is the DoD's tiered cybersecurity framework for contractors handling Federal Contract Information (FCI) + Controlled Unclassified Information (CUI). It governs how sensor-side data + audit-record retention are handled during a Snapshot engagement, and it is the alignment statement in the signed declaration.
What the framework actually says
"Level 1 (Foundational): Basic safeguarding of FCI. 15 requirements from FAR 52.204-21.
Level 2 (Advanced): Broad protection of CUI. 110 requirements aligned with NIST SP 800-171 rev2.
Level 3 (Expert): Higher-level protection of CUI against Advanced Persistent Threats. NIST SP 800-171 rev2 + subset of NIST SP 800-172."
32 CFR Part 170 — CMMC 2.0 Program (Final Rule, 2024)
What this means in plain English for a Snapshot engagement
The Snapshot itself runs on data the buyer submits. Three CMMC-relevant choices apply:
- Data classification. The buyer decides what to submit. Anonymized decision records are sufficient; classified / CUI / ITAR-controlled data is NOT required to run the Snapshot.
- Sensor-side handling. contrarianAI infrastructure is CMMC 2.0 Level 2 aligned; Level 3 path available on engagement scope requiring it. That alignment is stated in the signed declaration.
- Retention pipeline. Retention is distinct from the buyer's production stack; retention horizon is stated in the declaration + supports NIST SP 800-53 rev5 AU-11 + DoD 8570.01-M audit-record-retention.
The Snapshot pattern is deliberately structured so buyers with strict data-handling constraints can run it below the CUI threshold by scoping submitted data to anonymized decision records.
What triggers the exposure in the sample
The SAMPLE Snapshot uses entirely synthetic data. No classified, CUI, or ITAR-controlled information was used, retained, or transmitted. This is stated in the signed declaration. The pattern demonstrates that a defensible independent-verifier record can be produced without the buyer having to expose sensitive data outside their own perimeter.
What the $499 Snapshot shows against this framework
- CMMC 2.0 Level 2 alignment statement — part of the signed declaration
- Data-handling scope statement — anonymized decision records sufficient; no CUI required
- Retention pipeline distinct from buyer production stack — independence of the record from the actor being recorded
- Level 3 path available on engagement scope requiring it — not gated on new infrastructure
See where the CMMC 2.0 alignment statement lives in the declaration →
$499 Snapshot. 3 business days.
CMMC 2.0 Level 2 aligned. Level 3 path available. No CUI / ITAR-controlled data required — anonymized records are sufficient.
Buy $499
Snapshot credit applies to Baseline ($2,500) or Enterprise Attestation ($35-55K) upgrade within 30 days.