×

The only CMMC solution native to Microsoft

Validates all 110 controls inside your own Microsoft tenant, no migration, no lock-in, no data leaving your environment.

How Can We Help You

Why CMMC Analyzer

Most CMMC tools connect to Microsoft from outside or ask you to move your CUI into a boundary they manage. Neither validates the controls inside the environment you already own. CMMC Analyzer deploys natively inside your Azure tenant and reads across all five control planes using your own APIs.

Platform-Native, Not Bolted On

Built inside Azure with least-privilege permissions. No agent, no external data pipeline. Your data never leaves your tenant.

Automation + Human Validation

The tool surfaces gaps automatically. If you want human depth behind the findings, Aprio’s advisory team brings deep compliance expertise, but the tool works without them.

Compliance analytics and real-time visibility 

Automated policy enforcement and configuration validation

How It Works

Choose the plan that matches your scope: Basic, Professional, or Enterprise

Deploy from Microsoft Marketplace

Purchase through Microsoft Marketplace. One click. No custom infrastructure required.

Run a Scan

CMMC Analyzer evaluates your environment across all five Microsoft control planes in minutes.

Export Your Evidence Bundle

Walk in to your C3PAO assessment prepared.

CMMC Analyzer Plans

Choose the tier that fits your environment. All plans deploy from Microsoft Marketplace in minutes.

FeatureBasic
1 Tenant
Professional
Up to 3 Tenants
Enterprise
Up to 25 Tenants
SCANNING SCOPE
Tenants under one license1Up to 3Up to 25
Cloud environmentsAzure + M365Azure + M365Azure + M365 + AWS GovCloud + AWS Commercial
Cloud-scope picker
CORE COMPLIANCE ENGINE
Five-plan scanning: Entra, Azure ARM, M365, Intune, Defender XDR
320 NIST 800-171 objectives → all 110 CMMC L2 practices
FedRAMP High inheritance – 49 objectives auto-inherit MET with citation
Point-in-time baselines and drift detection
PowerShell sidecar (Exchange, SharePoint, Teams evidence)
Evidence verification shell – re-run the exact Graph/ARM/AWS call
REPORTING & EVIDENCE
Reports in HTML, Excel, Word, and PDF with assessor-readable evidence
Asset inventory with Excel deliverable + CUI boundary data-flow diagram
MONITORING & ALERTS
Continuous monitoring – scheduled scans (ConMon V1, satisfies CMMC 3.12.3)
ConMon V2 – per-(tenant, scan-type) schedules + master-tick queue
Email & webhook notifications (ServiceNow, Jira, PagerDuty, custom)
SIEM forwarder – Log Analytics, Microsoft Sentinel, or Splunk HEC
DOCUMENTATION & COMPLIANCE WORKFLOW
Customer self-attestation workflow with immutable Attestation Package
Deterministic SSP generator
Waiver & exception management with expiry dates and audit trail
Cross-tenant fusion rollups for MSPs and federal integrators
SECURITY & ACCESS
Read-only – no vendor control plane, data never leaves your tenant
Entra ID OIDC SSO + local admin bootstrap
Immutable audit log of every privileged action (CMMC AA family)
Role-based access control (User vs. Admin)
License-bound deployment integrity – tenants lock on first successful scan

CMMC Analyzer Key Capabilities

Continuous monitoring with real-time alerts the moment your CMMC posture drifts

Five-plane scanning across Entra ID, Azure ARM, M365, Intune, and Defender XDR

Scalable integration — from single-tenant Basic deployments to 25-tenant Enterprise rollups

Remediation prioritization: immediately see which failed controls to address first

Audit-ready documentation: SSP content, POA&M, asset inventory, CUI data-flow diagram, and immutable Attestation Package

Need a Dedicated CUI Boundary?
CMMC Enclave with XDR.

For contractors who can’t meet CMMC Level 2 inside their current environment, Securitybricks builds properly configured CUI enclaves on Microsoft GCC High with 24/7 Defender XDR + Sentinel protection built in. You define what’s in scope. We build the boundary and assign every one of the 320 NIST objectives to a named owner so nothing falls through the gap.

Pre-certified CUI boundary on Microsoft GCC High (DFARS, CMMC L2, FedRAMP High)

24/7 Microsoft Defender XDR + Sentinel monitoring

Shared responsibility matrix, every objective assigned, nothing abdicated

Pairs with CMMC Analyzer for continuous validation inside the enclave

Frequently Asked Questions

CMMC Analyzer is a Microsoft-native application available on the Microsoft Marketplace. It validates your technical controls across all five Microsoft control planes, automatically collects and maps evidence to all 110 CMMC Level 2 practices, and produces SSP content, a POA&M, asset inventory, CUI data-flow diagram, and an immutable Attestation Package — all without data ever leaving your tenant.

CMMC Analyzer scans your environment across Entra ID, Azure ARM, Microsoft 365, Intune, and
Defender XDR. It maps 320 NIST 800-171 objectives to all 110 CMMC L2 practices, flags controls as MET, NOT MET, or requiring manual attestation, and provides remediation guidance for failures. FedRAMP High inheritance auto-marks 49 objectives as MET with citation, further reducing manual work.

CMMC Analyzer is designed for Level 2, which applies to contractors that handle Controlled Unclassified Information (CUI) and are subject to triennial C3PAO assessments.

Three plans are available: Basic (1 tenant, Azure + M365), Professional (up to 3 tenants, adds continuous monitoring, PowerShell sidecar for Exchange/SharePoint/Teams, SSP generator, self-attestation workflow, and SIEM integration), and Enterprise (up to 25 tenants, adds AWS GovCloud + AWS Commercial coverage, advanced ConMon scheduling, evidence verification shell, waiver management, and cross-tenant rollups for MSPs and federal integrators).

No. CMMC Analyzer is deployed as a managed application inside your own Azure subscription. It operates read-only with least-privilege permissions. No data is sent to an external vendor control plane. There are no agents and no external data pipelines.

Your initial posture scan completes in minutes after deployment. Achieving full audit readiness depends on your starting environment and remediation backlog, but CMMC Analyzer eliminates the manual evidence collection phase that typically adds weeks to CMMC timelines.

Yes. The Enterprise plan supports AWS GovCloud and AWS Commercial in addition to Azure Government and Azure Commercial, making it suitable for contractors with multi-cloud environments.

The Attestation Package is an immutable, fully auditable record generated through CMMC Analyzer’s self-attestation workflow. It documents your compliance posture at a point in time and is designed to be presented to your C3PAO assessor as evidence of due diligence.

No. CMMC Analyzer is designed to be deployed and operated without external consulting. Deploy from the Microsoft Marketplace in one click, run a scan, and receive your evidence bundle. Aprio’s advisory team brings deep compliance expertise if you want human depth behind the findings, but the tool works without them.

CMMC Analyzer validates the controls inside your existing Microsoft environment, no migration required. CMMC Enclave is for contractors who need to build a dedicated CUI boundary from scratch, hosted on Microsoft GCC High with 24/7 XDR protection. Most contractors start with Analyzer to understand their current posture, then decide whether an Enclave is the right next step.

It depends on where your CUI lives today. If it’s already in Microsoft commercial or government environments, CMMC Analyzer can validate those controls without an Enclave. If your current environment can’t reach Level 2 without major changes, or if you’re starting a new contract and need a clean, compliant boundary, the Enclave is the faster path. A scoping call can tell you which fits.

CMMC Analyzer produces a prioritized gap list alongside your evidence package. From there you have three options: remediate the gaps yourself using the built-in guidance, engage your own implementation team, or reach out to Aprio’s advisory team if you want expertise behind the remediation. The evidence package is ready to load directly into your SSP when you’re done.