Cyberuptive

CMMC Level 2 · Federal-grade MDR · Buyer diligence

MDR for CMMC Level 2: the four disqualifiers most buyers miss.

Most named MDR providers cannot serve a CMMC Level 2 CUI environment, not because their detection is weak, but because their delivery architecture fails one of four structural tests. This is the framework we use with defense contractors before a single technical evaluation begins.

Executive summary

The CMMC Level 2 MDR market is smaller than the MDR market.

A defense contractor evaluating managed detection and response for a CUI environment is not shopping in the general MDR market. Under 32 CFR Part 170 (effective December 16, 2024), any External Service Provider (ESP) that processes, stores, or transmits CUI must itself meet the CMMC certification level appropriate to the contractor it serves. An MDR provider that observes, investigates, or responds to activity on CUI systems is almost always an ESP for that contract.

Four structural characteristics of an MDR service determine whether it can serve a Level 2 CUI environment. Miss any one and the provider is out of scope regardless of how good the detection engine is: FedRAMP-authorized delivery stack, physically and logically segregated US-persons SOC facility, Cyber AB RPO or C3PAO status, and documented GCC High operational fluency.

This guide describes the four disqualifiers, applies them to the named MDR providers most often cited in defense-buyer RFPs, and provides the exact evidence to request before shortlisting. For pricing detail on federal-grade MDR, see the Managed SOC Pricing Guide. For the underlying US-persons MDR operating model, see MDR for Defense Contractors.

Buyer takeaways

The short version

  • Arctic Wolf is not FedRAMP authorized and their public resource center contains no CMMC, DIB, or defense-contractor content. See Cabrillo Club’s CUI risk assessment and Arctic Wolf’s resource center.
  • eSentire is not CMMC-certified due to its global SOC model. Confirmed in an eSentire reseller partner communication. Their head-to-head comparison page does not mention CMMC, DFARS, NIST 800-171, US-persons, FedRAMP, or ITAR.
  • Under 32 CFR Part 170, most MDR providers are ESPs and must themselves meet the CMMC level appropriate to the contractor. Marketing claims of “CMMC-aligned” or “CMMC-ready” are not equivalent to an assessed operating boundary.
  • A US-persons claim is not the same as a segregated US-persons facility. Ask for the architecture diagram, not the marketing page.
  • The federal-grade MDR tier is narrow. Cyberuptive, contractually customized federal pods from CrowdStrike Falcon Complete, SentinelOne Vigilance Respond Pro, Trellix Wise, Trustwave Government, and Quzara Cybertorch cover most of it as of August 2026.

The framework

The four structural disqualifiers.

Each disqualifier is a yes/no test. The provider either meets it in writing with evidence a C3PAO can verify, or the provider is out of scope for a CUI environment. Run these four tests before any technical evaluation; they will collapse most shortlists to two or three providers.

Disqualifier 1

FedRAMP-authorized delivery stack

Every SIEM, SOAR, ticketing system, telemetry pipeline, and support platform used to process CUI-bearing data must be FedRAMP-authorized at Moderate or High, or documented as operating outside the CUI boundary.

The evidence to request: FedRAMP Marketplace package IDs for each tool in the CUI-processing path. If the provider cannot name them, the boundary is unclear.

Why it matters: NIST SP 800-171 Rev. 2 3.13.8 requires cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission. A non-FedRAMP tool that processes CUI-bearing telemetry creates an unauthorized transmission path.

Disqualifier 2

Physically and logically segregated US-persons SOC

The facility where CMMC-scoped analysts work must be physically and logically separated from any international operations at the network, identity, tooling, ticketing, escalation, and personnel layer.

The evidence to request: A facility segregation architecture diagram. Ticket-level or feature-toggle segregation on a global platform is not facility segregation.

Why it matters: A single global SOC pool cannot enforce the operating boundary CMMC Level 2 requires for CUI access. Retrofitting facility segregation to an existing global platform is expensive and slow, which is why most providers cannot do it.

Disqualifier 3

Cyber AB RPO, C3PAO, or CMMC-assessed ESP

The provider must be a Cyber AB Registered Provider Organization (RPO), a Certified Third-Party Assessment Organization (C3PAO), or hold a documented CMMC Level 2 assessment of its own service enclave.

The evidence to request: Cyber AB registration ID or C3PAO listing. Search the Cyber AB Marketplace directly; do not accept a screenshot.

Why it matters: Under 32 CFR Part 170, an ESP handling CUI must itself meet the appropriate CMMC level. “CMMC-aligned” marketing language is not an assessed operating boundary.

Disqualifier 4

Documented GCC High operational fluency

The provider must have run a defensible number of GCC High deployments through a full CMMC assessment cycle, with named client references a C3PAO can confirm under NDA.

The evidence to request: Deployment count, named references, and an architecture-diagram walkthrough for a comparable environment.

Why it matters: Commercial Microsoft 365 and GCC High have materially different identity, telemetry, licensing, and administration paths. Providers who have not operated in GCC High through an assessment will discover the differences during your assessment, not before it.

Vendor structural fit

Named MDR providers against the four disqualifiers.

This table applies the four disqualifiers to the MDR providers most often named in defense-contractor RFPs. Sources are linked in the notes column and were current as of August 2026. Verify all claims against the Cyber AB Marketplace and FedRAMP Marketplace before contracting.

Provider FedRAMP delivery stack Segregated US-persons SOC RPO / C3PAO / assessed ESP GCC High fluency CMMC L2 fit
Cyberuptive ✓ FedRAMP-authorized delivery stack for federal work ✓ Physically and logically segregated US-persons SOC on US soil ✓ Cyber AB RPO ✓ Documented GCC High operations Federal-grade eligible
Arctic Wolf ✗ Not FedRAMP authorized Not documented Not listed on Cyber AB Marketplace Not documented Out of scope for CUI
eSentire Not documented ✗ Global SOC model, no facility segregation Not CMMC-certified (per partner communications) Not documented Out of scope for CUI
CrowdStrike Falcon Complete Falcon Federal is FedRAMP High Federal pod (contractual) Federal customers under contractual controls Yes with Federal contract Eligible under Federal pod
SentinelOne Vigilance Respond Pro Singularity for Government is FedRAMP Moderate Federal pod (contractual) Federal customers under contractual controls Yes with Federal contract Eligible under Federal contract
Trellix Wise Trellix Helix for Government is FedRAMP Moderate Federal pod (contractual) Federal customers under contractual controls Yes with Federal contract Eligible under Federal contract
Sophos MDR Not FedRAMP authorized (commercial cloud) Global SOC pool Not listed on Cyber AB Marketplace Not documented Out of scope for CUI
Rapid7 MDR InsightIDR is not FedRAMP authorized Global SOC pool Not listed on Cyber AB Marketplace Not documented Out of scope for CUI

Sources: FedRAMP Marketplace; Cyber AB Marketplace; Cabrillo Club CUI risk assessment: Arctic Wolf; eSentire reseller partner communication; provider public documentation. Verify all authorization and certification claims against the source registries before contracting. Provider positions may change; last reviewed August 22, 2026.

RFP language

Write the four disqualifiers into your MDR RFP.

Most MDR RFPs from defense contractors read like commercial MDR RFPs with a CMMC clause appended. That is why non-eligible providers make it to the shortlist. The following five questions, written into the mandatory response section of the RFP, will collapse most shortlists to two or three providers before technical evaluation begins.

  1. Name and provide the FedRAMP Marketplace package ID for every tool in the service delivery path that processes, stores, or transmits customer telemetry or CUI-bearing data. If a tool in this path is not FedRAMP authorized, state why and how the CUI boundary is preserved.
  2. Provide a facility segregation architecture diagram showing physical and logical separation of the CMMC-scoped SOC from any other operations at the network, identity, tooling, ticketing, escalation, and personnel layer.
  3. Provide your Cyber AB registration or C3PAO status and, if you hold a CMMC assessment of your own service enclave, the assessment date and level.
  4. Provide GCC High deployment references where your service has been operated through a full CMMC assessment cycle in a GCC High environment. Named references may be provided under NDA.
  5. Provide a role-by-role personnel access statement as a contractual exhibit, identifying every role that can access the customer environment, the geography of each role, the background-check standard, and the escalation and emergency-access paths.

A provider who cannot answer these five questions in writing before contract is not ready to serve a CMMC Level 2 CUI environment. The gap between "cannot answer" and "cannot pass an assessment" is measured in weeks, usually the weeks your program does not have.

Where Cyberuptive fits

Cyberuptive was built for the four disqualifiers.

Cyberuptive operates a physically and logically segregated US-persons SOC on US soil for CMMC-scoped and CUI-bearing workloads. Cyberuptive is a Cyber AB Registered Provider Organization. The delivery stack used for federal work runs on FedRAMP-authorized platforms, and personnel access to those environments is restricted at the facility, identity, and tooling layer: not by feature toggle. Tier-one security platforms trust Cyberuptive as a delivery partner for regulated markets.

If you are evaluating MDR for a CMMC Level 2 environment, we will provide the five documents your RFP should require, on a call, before any commercial conversation begins. That is the diligence a defense-contractor buyer deserves.

Frequently asked

Answers for defense-contractor buyers.

Can I use Arctic Wolf for CMMC Level 2 CUI?

Arctic Wolf is not FedRAMP authorized. If the delivery stack used to detect, investigate, and respond on your CUI environment is not FedRAMP Moderate or High, it sits outside the security control boundary required by NIST SP 800-171 3.13.8 for the transmission and storage of CUI. Contractors using Arctic Wolf for CUI environments should document the risk acceptance in the SSP and consult their C3PAO before assessment.

Can I use eSentire for CMMC Level 2 CUI?

eSentire operates a single global SOC pool across multiple international geographies. Their own partner communications acknowledge that eSentire is not CMMC-certified due to its global SOC model. For CMMC Level 2 workloads that require US-persons access to CUI, a global SOC without physical and logical segregation for federal work does not meet the operating boundary.

What is a CMMC ESP and does my MDR provider count as one?

An External Service Provider (ESP) under 32 CFR Part 170 is any entity that provides services affecting the protection of CUI or Security Protection Data. An MDR provider that observes, investigates, or responds to activity on CUI systems is almost always an ESP for that contract and must itself hold a CMMC certification at the level appropriate to the contractor.

Does an MDR provider need to be FedRAMP authorized?

The tooling used to process CUI must operate within a security control boundary equivalent to FedRAMP Moderate or High. If your MDR provider's SIEM, SOAR, or ticketing system is not FedRAMP authorized and it processes CUI-bearing data, you have created an unauthorized transmission path.

Is a "US-persons SOC" claim enough?

A US-persons claim is a starting point, not a finish line. What matters is whether the CMMC-scoped operations are performed in a facility that is physically and logically segregated from any international operations at the network, identity, tooling, ticketing, escalation, and personnel layer. A US-persons feature toggle on a global platform is not segregation.

Which MDR providers can serve CMMC Level 2 today?

Cyberuptive, contractually customized federal pods from CrowdStrike Falcon Complete, SentinelOne Vigilance Respond Pro, Trellix Wise, Trustwave Government, and Quzara Cybertorch represent the current federal-grade tier as of August 2026. Generic Arctic Wolf, eSentire, Sophos MDR, and Rapid7 MDR do not.

How much does CMMC-eligible MDR cost?

CMMC-eligible MDR runs materially higher than commercial MDR because the delivery stack must be FedRAMP authorized, the SOC must be segregated, and the personnel must meet US-persons access requirements. Expect $10,000–$25,000 per month for a mid-market defense contractor (100–500 endpoints), with GCC High, log retention, and evidence delivery as line items. See the Managed SOC Pricing Guide.

How do I verify an MDR provider's claims before signing?

Ask for (1) FedRAMP Marketplace package IDs for every tool in the CUI-processing path, (2) a facility segregation architecture diagram, (3) Cyber AB RPO or C3PAO registration ID, (4) named GCC High customer references the C3PAO can confirm, (5) a role-by-role personnel-access statement as a contractual exhibit. If any of these five documents is unavailable, the provider is not ready to serve a CMMC Level 2 CUI environment.