The only CMMC solution native to Microsoft
Validates all 110 controls inside your own Microsoft tenant, no migration, no lock-in, no data leaving your environment.
How Can We Help You
Why CMMC Analyzer
Most CMMC tools connect to Microsoft from outside or ask you to move your CUI into a boundary they manage. Neither validates the controls inside the environment you already own. CMMC Analyzer deploys natively inside your Azure tenant and reads across all five control planes using your own APIs.
Platform-Native, Not Bolted On
Built inside Azure with least-privilege permissions. No agent, no external data pipeline. Your data never leaves your tenant.
Automation + Human Validation
The tool surfaces gaps automatically. If you want human depth behind the findings, Aprio’s advisory team brings deep compliance expertise, but the tool works without them.
Compliance analytics and real-time visibility
Automated policy enforcement and configuration validation
How It Works
Choose the plan that matches your scope: Basic, Professional, or Enterprise
Deploy from Microsoft Marketplace
Purchase through Microsoft Marketplace. One click. No custom infrastructure required.
Run a Scan
CMMC Analyzer evaluates your environment across all five Microsoft control planes in minutes.
Export Your Evidence Bundle
Walk in to your C3PAO assessment prepared.
CMMC Analyzer Plans
Choose the tier that fits your environment. All plans deploy from Microsoft Marketplace in minutes.
| Feature | Basic 1 Tenant | Professional Up to 3 Tenants | Enterprise Up to 25 Tenants |
| SCANNING SCOPE | |||
| Tenants under one license | 1 | Up to 3 | Up to 25 |
| Cloud environments | Azure + M365 | Azure + M365 | Azure + M365 + AWS GovCloud + AWS Commercial |
| Cloud-scope picker | — | — | |
| CORE COMPLIANCE ENGINE | |||
| Five-plan scanning: Entra, Azure ARM, M365, Intune, Defender XDR | |||
| 320 NIST 800-171 objectives → all 110 CMMC L2 practices | |||
| FedRAMP High inheritance – 49 objectives auto-inherit MET with citation | |||
| Point-in-time baselines and drift detection | |||
| PowerShell sidecar (Exchange, SharePoint, Teams evidence) | — | ||
| Evidence verification shell – re-run the exact Graph/ARM/AWS call | — | — | |
| REPORTING & EVIDENCE | |||
| Reports in HTML, Excel, Word, and PDF with assessor-readable evidence | |||
| Asset inventory with Excel deliverable + CUI boundary data-flow diagram | |||
| MONITORING & ALERTS | |||
| Continuous monitoring – scheduled scans (ConMon V1, satisfies CMMC 3.12.3) | — | ||
| ConMon V2 – per-(tenant, scan-type) schedules + master-tick queue | — | — | |
| Email & webhook notifications (ServiceNow, Jira, PagerDuty, custom) | — | ||
| SIEM forwarder – Log Analytics, Microsoft Sentinel, or Splunk HEC | — | ||
| DOCUMENTATION & COMPLIANCE WORKFLOW | |||
| Customer self-attestation workflow with immutable Attestation Package | — | ||
| Deterministic SSP generator | — | ||
| Waiver & exception management with expiry dates and audit trail | — | — | |
| Cross-tenant fusion rollups for MSPs and federal integrators | — | — | |
| SECURITY & ACCESS | |||
| Read-only – no vendor control plane, data never leaves your tenant | |||
| Entra ID OIDC SSO + local admin bootstrap | |||
| Immutable audit log of every privileged action (CMMC AA family) | |||
| Role-based access control (User vs. Admin) | — | ||
| License-bound deployment integrity – tenants lock on first successful scan | — |
CMMC Analyzer Key Capabilities
Continuous monitoring with real-time alerts the moment your CMMC posture drifts
Five-plane scanning across Entra ID, Azure ARM, M365, Intune, and Defender XDR
Scalable integration — from single-tenant Basic deployments to 25-tenant Enterprise rollups
Remediation prioritization: immediately see which failed controls to address first
Audit-ready documentation: SSP content, POA&M, asset inventory, CUI data-flow diagram, and immutable Attestation Package
Need a Dedicated CUI Boundary?
CMMC Enclave with XDR.
For contractors who can’t meet CMMC Level 2 inside their current environment, Securitybricks builds properly configured CUI enclaves on Microsoft GCC High with 24/7 Defender XDR + Sentinel protection built in. You define what’s in scope. We build the boundary and assign every one of the 320 NIST objectives to a named owner so nothing falls through the gap.
Pre-certified CUI boundary on Microsoft GCC High (DFARS, CMMC L2, FedRAMP High)
24/7 Microsoft Defender XDR + Sentinel monitoring
Shared responsibility matrix, every objective assigned, nothing abdicated
Pairs with CMMC Analyzer for continuous validation inside the enclave
Frequently Asked Questions
CMMC Analyzer is a Microsoft-native application available on the Microsoft Marketplace. It validates your technical controls across all five Microsoft control planes, automatically collects and maps evidence to all 110 CMMC Level 2 practices, and produces SSP content, a POA&M, asset inventory, CUI data-flow diagram, and an immutable Attestation Package — all without data ever leaving your tenant.
CMMC Analyzer scans your environment across Entra ID, Azure ARM, Microsoft 365, Intune, and
Defender XDR. It maps 320 NIST 800-171 objectives to all 110 CMMC L2 practices, flags controls as MET, NOT MET, or requiring manual attestation, and provides remediation guidance for failures. FedRAMP High inheritance auto-marks 49 objectives as MET with citation, further reducing manual work.
CMMC Analyzer is designed for Level 2, which applies to contractors that handle Controlled Unclassified Information (CUI) and are subject to triennial C3PAO assessments.
Three plans are available: Basic (1 tenant, Azure + M365), Professional (up to 3 tenants, adds continuous monitoring, PowerShell sidecar for Exchange/SharePoint/Teams, SSP generator, self-attestation workflow, and SIEM integration), and Enterprise (up to 25 tenants, adds AWS GovCloud + AWS Commercial coverage, advanced ConMon scheduling, evidence verification shell, waiver management, and cross-tenant rollups for MSPs and federal integrators).
No. CMMC Analyzer is deployed as a managed application inside your own Azure subscription. It operates read-only with least-privilege permissions. No data is sent to an external vendor control plane. There are no agents and no external data pipelines.
Your initial posture scan completes in minutes after deployment. Achieving full audit readiness depends on your starting environment and remediation backlog, but CMMC Analyzer eliminates the manual evidence collection phase that typically adds weeks to CMMC timelines.
Yes. The Enterprise plan supports AWS GovCloud and AWS Commercial in addition to Azure Government and Azure Commercial, making it suitable for contractors with multi-cloud environments.
The Attestation Package is an immutable, fully auditable record generated through CMMC Analyzer’s self-attestation workflow. It documents your compliance posture at a point in time and is designed to be presented to your C3PAO assessor as evidence of due diligence.
No. CMMC Analyzer is designed to be deployed and operated without external consulting. Deploy from the Microsoft Marketplace in one click, run a scan, and receive your evidence bundle. Aprio’s advisory team brings deep compliance expertise if you want human depth behind the findings, but the tool works without them.
CMMC Analyzer validates the controls inside your existing Microsoft environment, no migration required. CMMC Enclave is for contractors who need to build a dedicated CUI boundary from scratch, hosted on Microsoft GCC High with 24/7 XDR protection. Most contractors start with Analyzer to understand their current posture, then decide whether an Enclave is the right next step.
It depends on where your CUI lives today. If it’s already in Microsoft commercial or government environments, CMMC Analyzer can validate those controls without an Enclave. If your current environment can’t reach Level 2 without major changes, or if you’re starting a new contract and need a clean, compliant boundary, the Enclave is the faster path. A scoping call can tell you which fits.
CMMC Analyzer produces a prioritized gap list alongside your evidence package. From there you have three options: remediate the gaps yourself using the built-in guidance, engage your own implementation team, or reach out to Aprio’s advisory team if you want expertise behind the remediation. The evidence package is ready to load directly into your SSP when you’re done.
Securitybricks combines automation and human insight to simplify complex cybersecurity cloud compliance challenges. Our mission is to deliver robust, automated security compliance solutions for the Defense Industrial Base (DIB), technology enterprises, and other regulated industries. With cloud and cybersecurity certified experts and assessor experience across frameworks like FedRAMP®, GOVRAMP, CMMC, FISMA, ISO, SOC, HITRUST, and PCI, we understand the nuances of compliance and provide a clear, proven path to certification and continuous monitoring.
securitybricks.io
© 2025 Securitybricks. All rights reserved. Privacy Policy
