Start Here: CMMC on Mac
If you run Macs and you have a DFARS 252.204-7012 clause, a NIST SP 800-171 self-assessment score to post in SPRS, or a prime asking about CMMC Level 2 (DFARS 252.204-7021), this page is the map. Everything on this site exists to answer one question: how do you take an Apple-first environment through CMMC Level 2 without translating Windows guidance all day?
CMMC in brief: which level, which clock
CMMC is how the Department of War verifies that contractors actually protect the sensitive information they handle. The level that applies to you is set by the contract, not by preference:
| CMMC Level | Protects | Requirements | Assessment type |
|---|---|---|---|
| Level 1 | Federal Contract Information (FCI) | 15 FAR 52.204-21 requirements | Annual self-assessment |
| Level 2 | Controlled Unclassified Information (CUI) | 110 NIST SP 800-171 Rev. 2 requirements | Self-assessment or C3PAO, per the solicitation |
| Level 3 | Higher-risk CUI against advanced threats | Level 2 plus 24 selected NIST SP 800-172 requirements | Government-led DIBCAC assessment |
The assessment-type column reflects the rule as written. During the July 2026 suspension, new solicitations designate self-assessment only.
The short version: Level 1 if you handle FCI but no CUI; Level 2 if you process, store, or transmit CUI - the 110 requirements, and the case this whole site is built for; Level 3 only for select high-risk programs. The July 2026 Phase 2 suspension paused third-party certification, but the underlying 800-171 obligations are unchanged. Dates live on the key dates page, the acronyms in the glossary, and the full source list on References.
1. Orient yourself (15 minutes)
- CMMC for macOS: what defense contractors need to know - the lay of the land: what Level 2 actually requires, what is different on Apple hardware, and where Mac shops typically get surprised.
- mSCP vs. CIS vs. STIG - which macOS baseline to anchor on and why the macOS Security Compliance Project is usually the right answer for 800-171 work.
2. Get the management plane right
- Apple Business Manager + MDM - supervised Automated Device Enrollment is the foundation nearly every Mac control implementation stands on.
- Jamf vs. Intune vs. Kandji for CMMC Mac fleets - choosing (or defending) your MDM with compliance in mind.
- BYOD Macs in a CMMC environment - the honest options when personal devices touch your boundary.
3. Work the controls that bite Mac shops first
- FIPS-validated encryption for CUI - why “FileVault is on” is not the end of the conversation.
- MFA that actually satisfies IA.L2-3.5.3 - identity on macOS without hand-waving.
- Boundary protection on a Mac fleet - applying “control vs. protect” thinking to macOS.
4. Take the free resources
The free resources library collects worksheets, checklists, and reference material as they are released - free, in exchange for an email address, so you also get new guides as they publish.
Guides get you oriented; assessment preparation eventually means producing an SSP, policies, procedures, forms, workbooks, and evidence references that hold together. The CMMC Operator Suite is that documentation system, written Mac-first: 1 SSP, 14 policies, 15 procedures, 8 forms, 6 workbooks, a 5-document Mac implementation overlay, and 7 premium specialty documents, cross-referenced by artifact ID. One-time purchase from $499 with 12 months of updates.
Educational content, not legal or assessment advice. CMMC Operator is independent and not affiliated with Apple, Jamf, Microsoft, the DoD, Cyber AB, NIST, or any C3PAO.