CMMC for Mac: Level 2 Guide for Defense Contractors
Home/Start Here
CMMC for Mac, explained: a practical Level 2 path through scoping, MDM, FileVault, MFA, NIST 800-171 controls, and required documentation.
If you run Macs and you have a DFARS 252.204-7012 clause, a NIST SP 800-171 self-assessment score to post in SPRS, or a prime asking about CMMC Level 2 (DFARS 252.204-7021), this page is the map. It is drawn from the contractor side of the table: the author supported a successful CMMC Level 2 assessment in 2024. Everything on this site exists to answer one question: how do you take an Apple-first environment through CMMC Level 2 without translating Windows guidance all day?
CMMC in brief: which level, which clock
CMMC is how the Department of War verifies that contractors actually protect the sensitive information they handle. The level that applies to you is set by the contract, not by preference:
| CMMC Level | Protects | Requirements | Assessment type |
|---|---|---|---|
| Level 1 | Federal Contract Information (FCI) | 15 FAR 52.204-21 requirements | Annual self-assessment |
| Level 2 | Controlled Unclassified Information (CUI) | 110 NIST SP 800-171 Rev. 2 requirements | Self-assessment or C3PAO, per the solicitation |
| Level 3 | Higher-risk CUI against advanced threats | Level 2 plus 24 selected NIST SP 800-172 requirements | Government-led DIBCAC assessment |
The assessment-type column reflects the rule as written. During the July 2026 suspension, new solicitations designate self-assessment only.
The short version: Level 1 if you handle FCI but no CUI; Level 2 if you process, store, or transmit CUI - the 110 requirements, and the case this whole site is built for; Level 3 only for select high-risk programs. The July 2026 Phase 2 suspension paused third-party certification, but the underlying 800-171 obligations are unchanged. Dates live on the key dates page, the acronyms in the glossary, and the full source list on References.
Orient yourself (15 minutes)
Get the management plane right
Work the controls that bite Mac shops first
Take the free resources
Begin with the free Mac-first CMMC Level 2 Readiness Pack: a scoping worksheet, POA&M prioritization guide, tabletop exercise, and macOS checklist that turns the guidance above into a working first pass.
Open the free readiness packNeed the source library too? Browse references and free resources.
Choose the boundary before the tool stack
A CMMC for Mac architecture is a scoping decision before it is a product decision. Start with where Controlled Unclassified Information enters, moves, and stops. Then identify which Macs and services can store, process, or transmit it - and which systems protect those assets. Do not call something "out of scope" because the diagram looks cleaner.
| What is true today | Defensible starting pattern | Scope consequence | Evidence to have before claiming it |
|---|---|---|---|
| FCI only | Level 1 environment | Systems handling FCI remain in Level 1 scope. First confirm that the contract and data do not require Level 2. | Contract-clause review, data-flow notes, asset inventory, and FAR safeguard records. |
| CUI stays in a segregated cloud or VDI service | Enclave-first architecture | Do not assume the Mac is out of scope. Classify it from what it can display, cache, copy, print, upload, or protect. | Data-flow and connection diagrams, download and clipboard rules, device-posture records, access logs, and shared-responsibility mapping. |
| CUI is handled on work Macs | Managed Mac CUI environment | The Macs are CUI Assets. MDM, identity, endpoint protection, and logging services may also be in scope. | MDM exports, FileVault and recovery-key records, MFA settings, logs, review records, and a current inventory. |
| CUI is restricted to dedicated Macs | Dedicated Mac enclave | The dedicated Macs are CUI Assets. The general fleet is out of scope only when separation is real and enforceable. | Separate device groups, restrictions, labels, baselines, diagrams, and evidence that data does not spill into the general fleet. |
| Nobody can say where CUI lives | Discovery before architecture | There is no defensible boundary yet. | Contracts, marked files, data-owner interviews, email and SaaS inventory, and a CUI flow map. |
Once the pattern is chosen, classify each asset as a CUI Asset, Security Protection Asset, Contractor Risk Managed Asset, Specialized Asset, or Out-of-Scope Asset. The label must follow the asset's actual role - not the label you would prefer it to have.
Next, use the technical CMMC guidance for Macs to map the boundary to controls, then document it in an assessment-ready System Security Plan.
CMMC for Mac: five direct answers
1. Can Macs meet CMMC Level 2 requirements?
Yes. CMMC and NIST SP 800-171 define security requirements, not an approved endpoint brand. A Mac environment still needs a defensible scope, hardened configuration, identity and MFA, logging, incident response, documentation, and evidence.
2. Does FileVault alone make a Mac CMMC compliant?
No. FileVault addresses only part of data-at-rest protection. You still need to validate the cryptographic module and configuration, manage recovery keys, and implement the rest of the applicable Level 2 requirements.
3. Does every Mac in the company need to be in scope?
No. Scope follows CUI and the systems that protect it. A Mac is out of scope only when its actual role and the technical separation support that conclusion.
4. Can CUI stay in a cloud or VDI service while employees use Macs?
Yes, but the Mac is not out of scope by assertion. Determine whether it can display, cache, download, copy, print, upload, or protect CUI; then enforce, classify, and document the resulting boundary.
5. What should a Mac-based contractor do first?
Map the CUI flow and choose the boundary. Then inventory and classify assets, map all 110 requirements and their assessment objectives to mechanisms and evidence, record gaps, and write the SSP. Choose tools after scoping. For Mac fleets, the Mac SSP narrative template supplies the macOS sections.
Source basis: 32 CFR Part 170 and the DoD CMMC Level 2 Assessment Guide. Confirm the clauses and requirements in your own contract. Last verified: August 2026.
Guides get you oriented. Assessment prep means producing the documents.
An SSP, policies, procedures, forms, workbooks, and evidence references that hold together. The CMMC Operator Suite is that documentation system, written Mac-first: 1 SSP, 14 policies, 15 procedures, 8 forms, 6 workbooks, a 5-document Mac implementation overlay, a finishing guide, and 10 premium specialty documents, cross-referenced by artifact ID. One-time purchase from $299 with 12 months of updates.
See the SuiteGet new guides by emailEducational content, not legal or assessment advice. CMMC Operator is independent and not affiliated with Apple, Jamf, Microsoft, the DoD, Cyber AB, NIST, or any C3PAO.