CMMC Operator

Mac-first CMMC Level 2 implementation for small DIB contractors

Practical CMMC, NIST 800-171, macOS, MDM, BYOD, and evidence guidance for small Defense Industrial Base teams that need a clear path through Level 2 readiness.

Independent practical guidance for Mac-heavy DIB teams. Educational only; not legal or assessment advice.

Mac-first CMMC Level 2 for small DIB contractors

Practical guidance for taking Apple-first environments through NIST 800-171 and CMMC Level 2, and the Mac-first documentation suite that takes your SSP, policies, procedures, and workbooks off the blank page.

See the Suite - from $450

CMMC Level 2 is 110 requirements and 320 assessment objectives. The Suite is the 54 documents and 7 workbooks that answer them.

Where things stand: July 2026. CMMC Phase 2 was suspended on July 13, 2026 by implementing memo 26-P-1023. While the suspension holds, new solicitations may designate only Level 1 (Self) or Level 2 (Self), and waivers are paused. What did not change: DFARS 252.204-7012, NIST SP 800-171 Rev 2, your SPRS self-assessment score, and the annual affirmation. 32 CFR 170 was not rescinded, and government-led DIBCAC assessments continue. Two dates to keep: the CMMC Reform Task Force RFI closes August 14, 2026, and the task force report is expected around mid-September 2026. Read the full analysis · How to comment on the RFI · Every CMMC date

Start with these

CMMC for macOS: What Defense Contractors Need to Know
Nothing in CMMC requires Windows. Here is where the program stands in 2026, the Mac control map, and the six gaps that actually bite Apple-first contractors.
GCC vs. GCC High vs. Commercial Microsoft 365: What CMMC Level 2 Actually Requires
GCC clears the one bar people check and fails the three they forget: 7012 (c)-(g) commitments, export-controlled CUI, and what the ecosystem treats as the standard of care.
FIPS-Validated Encryption for CUI: Why Enabled Is Not Enough
FileVault on is not a FIPS claim. The module-level facts for macOS, current Apple certificate numbers, the 140-2 sunset, and the SSP language that survives follow-up questions.

Start where you are

You are not sure what is in scope.

Sort the Macs first. CUI asset, Security Protection Asset, CRMA, or out of scope: that call sets the boundary, and everything you write afterward inherits it.

Read the asset classification decision tree →

You have to write the SSP.

What a System Security Plan has to contain, what assessors read first, and how to describe a Mac environment without hand waving.

Read the SSP guide →

You need the documents, not another article.

The documentation system itself: 54 documents, 7 workbooks, and a training deck, written Mac-first and mapped to all 110 Level 2 requirements.

See what is in the Suite →

Not ready to spend anything yet? Start where it costs nothing: the readiness pack is the scoping worksheet, the POA&M prioritization guide, the tabletop, and the macOS checklist, free.

The scope and evidence path

Five free pages, in the order the questions actually come up. Nothing to install, nothing to sign up for, and the classifier runs entirely in your browser.

  1. Which category is this Mac?Four questions, answered in the browser. CUI asset, Security Protection Asset, Contractor Risk Managed Asset, or out of scope.Mac scope classifier
  2. What does that category cost me?The documentation obligation and the assessment consequence for each category, taken from 32 CFR 170.19 Table 3, with the macOS implementation delta called out separately as judgement.Mac scope categories
  3. What evidence does that generate?What an assessor asks to see, at assessment objective level, with the artifact named rather than the activity described.Assessment evidence
  4. How often do I have to refresh it?Why your own policies set the cadence rather than CMMC, and how much recurring work a Level 2 program actually creates once you count it.Continuous monitoring
  5. Which requirement is which?All 110 requirements with SPRS weight, POA&M eligibility, and whether the macOS implementation differs from the Windows one.CMMC Level 2 controls list

These pages are reference and planning material. They are not legal advice, not an assessment finding, and not a substitute for a C3PAO.

Browse by topic

Scoping & CUI

All in this section →

macOS Controls & Baselines

All in this section →

MDM & the Management Plane

All in this section →

Documentation & Assessment

All in this section →

Field Notes

All in this section →

Latest

Every guide, newest first →