← All industries
Industry deep dive

US defense industrial base — CMMC 2.0 and DFARS 7012

For DoD prime contractors and subcontractors that handle CUI: continuous testing of the NIST SP 800-171 requirements a C3PAO will assess, with pentest data and evidence kept inside your enclave on an on-premise appliance running private AI.

The CMMC program rule, 32 CFR Part 170, took effect on December 16, 2024, and the DFARS rule that puts CMMC into contracts took effect on November 10, 2025, starting Phase 1. Phase 2 begins on November 10, 2026: DoD then intends to require Level 2 (C3PAO) status, a third-party assessment of the 110 security requirements of NIST SP 800-171 Rev. 2, as a condition of award in applicable solicitations and contracts. Part 170 caps "periodically" at one year, so scans, risk assessments and control assessments each need a written frequency and proof it was kept. The security tools are in scope too: vulnerability data on in-scope assets, and the passwords that reach them, are Security Protection Data (§170.4).

What is on the DIB CISO's desk

Phase 2: Level 2 (C3PAO) as a condition of award

From November 10, 2026, DoD intends to require Level 2 (C3PAO) status in applicable solicitations, and may defer it to an option period. The hashed artifacts used as assessment evidence must be kept for six years (§170.17(c)(4)), and the Affirming Official re-affirms continuing compliance every year (§170.22).

Scanning cannot wait for a POA&M

RA.L2-3.11.2 vulnerability scanning is a 5-point requirement, and a Conditional status allows no POA&M item worth more than 1 point, the only exception being encryption that is used but not FIPS-validated (§170.21, §170.24). Scanning at a defined frequency, and when new vulnerabilities are identified, has to be working on assessment day.

DFARS 252.204-7012 and the FedRAMP Moderate bar

An external cloud provider that stores, processes or transmits covered defense information must meet security requirements equivalent to the FedRAMP Moderate baseline, plus the clause's incident and forensic duties. A cloud testing platform that only receives vulnerability data is still an External Service Provider in your CMMC scope.

72 hours from discovery, 90 days of preservation

Cyber incidents affecting a covered contractor information system or the covered defense information on it are reported to DoD through DIBNet within 72 hours of discovery, and images of affected systems plus relevant monitoring and packet capture data are preserved for at least 90 days from the report.

How Zero Hunt fits a defense contractor

Pillar 1 — Generative Pentest

Scanning and exploit validation inside the enclave

The 10-agent swarm runs black-box campaigns from outside a segment and gray-box campaigns with a standard user's access, at the frequency you define and when new vulnerabilities are published. It shows which findings are exploitable, so remediation follows risk (3.11.2, 3.11.3), and whether segmentation and authentication hold (3.12.1). Five autonomy levels decide what waits for an operator's approval, and exploit proofs of concept are held for review when the campaign level does not allow them.

Pillar 3 — Automatic Compliance

Evidence mapped to CMMC and NIST SP 800-171

The engine maps findings to CMMC Level 2 practices across the 14 NIST SP 800-171 families, cross-mapped to NIST SP 800-53 and NIST CSF. Every attack attempt is an Ed25519-signed entry in a SHA-256 hash chain, verifiable offline, and exported reports are ECDSA-signed. That supports the artifacts your assessor reviews; Zero Hunt is not a C3PAO and does not issue or predict a CMMC status.

Pillar 2 — AI Traffic Analysis

Traffic analysis for the 72-hour report

AI traffic analysis on the appliance GPU monitors inbound and outbound traffic on CUI segments (3.14.6) and flags exfiltration, command-and-control and lateral movement, with a signed timeline of what was seen and when. That is material for the DIBNet report and the 90-day preservation duty; the 72 hours run from discovery, and the call is yours.

Capability emphasis for the defense industrial base

  • ▸Runs inside the CUI enclave: models, findings and test credentials stay on the appliance, with no external AI API
  • ▸One appliance to document as a Security Protection Asset in your SSP, not a cloud provider to add to your scope
  • ▸Air-gapped mode: updates on physical media in ECDSA-signed bundles, OSINT and public source downloads disabled
  • ▸Findings mapped to CMMC Level 2, NIST SP 800-53 and NIST CSF: evidence for the assessment, not a certification
  • ▸Signed, hash-chained records of every test, verifiable offline

Who buys this in the defense industrial base

CISO or IT security lead sponsoring; the Affirming Official co-signing, because the annual affirmation of continuing compliance carries their name; the facility security officer and contracts team confirming that no new External Service Provider enters the CMMC scope; the program manager authorizing because Level 2 (C3PAO) status decides eligibility for award.

Frameworks mapped for this sector, worldwide

The same on-premise appliance serves regulated organizations in every region. For this sector, findings and evidence are mapped out of the box to:

Global / cross-industry
  • NIST Cybersecurity Framework
  • ISO/IEC 27001:2022
  • CIS Critical Security Controls v8
United States
  • CMMC
  • NIST SP 800-53

Why this sector runs its AI red team on-premise, on private AI →

Go deeper on the regulations

Want to see this against your environment?

A 30-minute technical demo runs Zero Hunt against a recorded slice of your stack, scoped to the regulatory regime you operate under.