Regulation — federal / defense

CMMC 2.0 Level 2 + Level 3 — Cybersecurity Maturity Model Certification for DIB contractors

CMMC 2.0 is the DoD's tiered cybersecurity framework for contractors handling Federal Contract Information (FCI) + Controlled Unclassified Information (CUI). It governs how sensor-side data + audit-record retention are handled during a Snapshot engagement, and it is the alignment statement in the signed declaration.

What the framework actually says

"Level 1 (Foundational): Basic safeguarding of FCI. 15 requirements from FAR 52.204-21.

Level 2 (Advanced): Broad protection of CUI. 110 requirements aligned with NIST SP 800-171 rev2.

Level 3 (Expert): Higher-level protection of CUI against Advanced Persistent Threats. NIST SP 800-171 rev2 + subset of NIST SP 800-172." 32 CFR Part 170 — CMMC 2.0 Program (Final Rule, 2024)

What this means in plain English for a Snapshot engagement

The Snapshot itself runs on data the buyer submits. Three CMMC-relevant choices apply:

  1. Data classification. The buyer decides what to submit. Anonymized decision records are sufficient; classified / CUI / ITAR-controlled data is NOT required to run the Snapshot.
  2. Sensor-side handling. contrarianAI infrastructure is CMMC 2.0 Level 2 aligned; Level 3 path available on engagement scope requiring it. That alignment is stated in the signed declaration.
  3. Retention pipeline. Retention is distinct from the buyer's production stack; retention horizon is stated in the declaration + supports NIST SP 800-53 rev5 AU-11 + DoD 8570.01-M audit-record-retention.

The Snapshot pattern is deliberately structured so buyers with strict data-handling constraints can run it below the CUI threshold by scoping submitted data to anonymized decision records.

What triggers the exposure in the sample

The SAMPLE Snapshot uses entirely synthetic data. No classified, CUI, or ITAR-controlled information was used, retained, or transmitted. This is stated in the signed declaration. The pattern demonstrates that a defensible independent-verifier record can be produced without the buyer having to expose sensitive data outside their own perimeter.

What the $499 Snapshot shows against this framework

See where the CMMC 2.0 alignment statement lives in the declaration →

How does this help me?

CMMC 2.0 alignment removes a routine procurement objection to running an independent-verifier engagement with a small firm. The Snapshot pattern was built with this specifically in mind.

Read: CMMC 2.0 -- what an aligned independent-verifier engagement saves →

$499 Snapshot. 3 business days.

CMMC 2.0 Level 2 aligned. Level 3 path available. No CUI / ITAR-controlled data required — anonymized records are sufficient.

Buy $499
Snapshot credit applies to Baseline ($2,500) or Enterprise Attestation ($35-55K) upgrade within 30 days.