We’ve Updated Our Terms. We’ve updated our Terms Of ServicePrivacy Policy, and Data Processing Addendum, effective July 16, 2026. Please review the changes before continuing to use our services.

Compliance

CMMC Level 1 & 2 Compliance Guide: Endpoint Security & Access Control

Tony Lynn
Chief Operating Officer of CurrentWare
Updated on 5 min read
Share this article

What Is CMMC, and Who Needs It?

xdepyhwsq698yez2iiz5

Definition

The Cybersecurity Maturity Model Certification (CMMC) is the DoD’s cybersecurity standard designed to ensure that contractors safeguard sensitive government data.

Why It Matters

CMMC protects two categories of sensitive information:

  • Federal Contract Information (FCI): Basic contract data not meant for public release
  • Controlled Unclassified Information (CUI): Sensitive information that requires stricter protection

Who Must Comply?

Role Requirement Level Data Handled
DoD contractors handling FCI CMMC Level 1 Federal Contract Information
DoD contractors handling CUI CMMC Level 2 Controlled Unclassified Information

Level 1 focuses on foundational safeguards, while Level 2 aligns with the NIST 800-171 standard and requires advanced monitoring, access control enforcement, and evidence-ready auditing.

Also Read: IT Security Compliance Solutions – Ensure Regulatory Readiness

Get Audit-Ready Today

Learn exactly how CurrentWare products map to AC, MP, AU, CM, and SI controls to provide necessary evidence and logs

zzlgasfivzmcxhcqpnkz

How to Meet CMMC Level 1 & Level 2 Requirements

CMMC Level 1

Focus: Protecting FCI
Controls Require:

  • Basic access control
  • Device restrictions
  • Minimal logging and evidence retention

This level ensures only authorized users and devices can access FCI.

CMMC Level 2 (Advanced Safeguards – NIST 800-171 Alignment)

Focus: Protecting CUI with robust security
Controls Require:

  • Comprehensive auditing
  • Endpoint and device monitoring
  • File transfer visibility
  • Advanced access control
  • Evidence retention for assessments

Level 2 typically applies to prime contractors and higher risk subcontractors handling sensitive CUI.

Also Read: Insider Threat Detection Software for Monitoring & Prevention | CurrentWare

Key CMMC Controls That Impact Endpoints

xam7fpxeuzudataugpve

1) Access Control (AC)

Definition: Limit who can access systems and define what actions they can perform.
Risks: Unauthorized access, insider misuse, data exfiltration.

Required Actions

  • Enforce least privilege
  • Limit external system connections
  • Restrict mobile and removable devices
  • Control uploads and data movement

CurrentWare Mapping for Access Control

Control Requirement CurrentWare Solution
AC.L2-3.1.2 Limit functions per user BrowseControl blocks sites, apps, ports
AC.L2-3.1.5 Enforce least privilege AccessPatrol sets per-user USB/device permissions
AC.L2-3.1.18 Control mobile devices Block USB phones & Bluetooth devices
AC.L2-3.1.20 Limit external systems Create device/site allowlists
AC.L2-3.1.22 Control uploads Block risky storage & cloud apps

2) Media Protection (MP)

Definition: Control removable media use (USBs, external drives).
Risks: CUI leakage, unauthorized file transfers, untracked device use.

Required Actions

  • Whitelist authorized USB devices
  • Track file transfers
  • Maintain device accountability logs

CurrentWare Mapping for Media Protection

Control Requirement CurrentWare Solution
MP.L2-3.8.3 Media disposal & traceability USB usage logs for investigators
MP.L2-3.8.5 Media accountability Track files copied to USB
MP.L2-3.8.7 Prevent unauthorized media Device control + hardware allowlisting

3) Audit & Accountability (AU)

Definition: Generate and retain logs that provide visibility into user actions.
Risks: No evidence during audits, inability to investigate incidents, compliance failure.

Required Actions

  • Create audit logs
  • Retain logs for investigations
  • Tie actions to specific users

CurrentWare Mapping for Auditing

Control Requirement CurrentWare Solution
AU.L2-3.3.1 Create / retain logs BrowseReporter + AccessPatrol logs
AU.L2-3.3.2 User-level accountability Unique user activity tracking & reporting

4) Configuration Management (CM)

Definition: Limit systems to essential applications, ports, and services.
Risks: Attack surface expansion, malware, shadow IT.

Required Actions

  • Disable unnecessary applications
  • Block unused ports/services

CurrentWare Mapping for CM

Control Requirement Solution
CM.L2-3.4.6 Enforce least functionality Block apps, sites & categories
CM.L2-3.4.7 Disable nonessential services Block TCP/UDP ports via BrowseControl

5) System Integrity (SI)

Definition: Detect and prevent unauthorized usage or security violations.
Risks: Insider threats, policy violations, unauthorized tool use.

Required Actions

  • Monitor user activity
  • Flag anomalies
  • Provide evidence during assessments

CurrentWare Mapping for System Integrity

Control Required Action Solution
SI.L2-3.14.7 Identify unauthorized use Monitor web, application, and file activity

Also Read: BrowseControl | Web Filtering & Application Blocking Software

f5cth2bbgzvudoxuvquq

How CurrentWare Simplifies CMMC Compliance

CurrentWare provides essential endpoint controls, monitoring, and evidence logs required for both CMMC Level 1 and Level 2, without complex deployments or heavy infrastructure.

Plug-and-Play Deployment

Fast installation for on-premise, hybrid, or air-gapped environments.

Endpoint Security + Monitoring + DLP in One Suite

Protect endpoints handling FCI and CUI with unified controls.

Audit Ready Logs Mapped to CMMC Controls

All user activity logs are mapped to AC, AU, MP, CM, and SI requirements.

USB Whitelisting + File Transfer Tracking

Meet media accountability and prevent unauthorized removable storage.
Products Used for CMMC Compliance

CMMC Compliance Checklist for DoD Contractors

Access Control

  • Enforce least privilege
  • Restrict ports, sites & apps
  • Block mobile phones and removable devices
  • Allowlist trusted systems only

Media Protection

  • Whitelist approved USB devices
  • Track file transfers
  • Store logs for audit investigations

Audit Logs

  • Record user activity across endpoints
  • Retain evidence for assessments

Configuration Management

  • Block nonessential apps and services
  • Limit endpoint functionality

System Integrity

  • Detect unauthorized use
  • Monitor applications, browsing, and file actions

Also Read: AccessPatrol | USB Device Control Software & Endpoint DLP

Monitor with Confidence and Trust

See how you can build a more secure and transparent workplace

Frequently asked

Frequently Asked Questions

The Cybersecurity Maturity Model Certification (CMMC) is a DoD-mandated framework that ensures defense contractors protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). Organizations handling FCI must meet Level 1 baseline controls, while those handling CUI must meet Level 2 requirements.

Level 1 focuses on foundational cyber hygiene controls—primarily access control, basic system protection, and physical safeguards. Level 2 includes all Level 1 practices plus more advanced controls aligned to NIST 800-171, emphasizing audit logging, continuous monitoring, endpoint security, and stronger access control measures.

CMMC Level 1 applies to any contractor that processes or stores Federal Contract Information (FCI), regardless of company size. It includes 15 practices that must be demonstrated and documented for DoD eligibility.

Level 2 adds 93 practices from NIST 800-171, including audit logging, monitoring, device control, access management, system hardening, and incident response documentation. These apply to organizations handling Controlled Unclassified Information (CUI).

Endpoint security reduces unauthorized access, data leakage, malware damage, and insider threats. CMMC Level 1 & 2 explicitly require contractors to manage unauthorized connections, restrict removable media, enforce access control, and monitor system activities—all of which depend on securing endpoints.

CurrentWare provides endpoint security, web filtering, data loss prevention, and user activity monitoring that support core CMMC practices, including removable media control (AccessPatrol), web filtering and content restriction (BrowseControl), user activity monitoring and auditing (BrowseReporter), and endpoint power management and device visibility (enPowerManager). These tools help enforce access control, restrict unauthorized devices, maintain logs, and demonstrate compliance.

AccessPatrol reinforces multiple controls related to removable media and device access, including AC.L1-3.1.20 (control connections of removable media and external devices), MP.L2-3.8.x (media protection and usage restrictions), and SC.L2-3.13.x (system/control boundary protections). It prevents unauthorized USB storage use, limits file transfers, and provides activity logs.

BrowseControl helps meet requirements around limiting access to unsafe or unauthorized websites and cloud applications. It contributes to AC.L1-3.1.5 (limit access to authorized users, processes, and devices), SC.L1-3.13.5 (restrict external system connections), and CM.L2-3.4.x (system configuration and enforcement). It ensures users cannot access risky domains or unapproved cloud storage.

BrowseReporter provides detailed activity logs for endpoints, including websites, applications, bandwidth usage, and user activity timelines. This supports AU.L2-3.3.x audit logging requirements, CM.L2 configuration and activity monitoring, and IR.L2 incident response detection. Log retention helps demonstrate continuous monitoring during assessments.

Yes. AccessPatrol enforces granular policies to block USB storage, monitor device usage, allow approved devices only, and maintain logs of all device connections. This directly supports CMMC Level 1 & 2 media protection practices.

CMMC does not mandate employee surveillance, but it requires contractors to maintain audit logs, detect unauthorized activity, verify access control adherence, and monitor system usage. Tools like BrowseReporter help satisfy these logging and auditing requirements while supporting least-privilege principles.

CurrentWare’s reporting features provide historical logs, device usage reports, endpoint activity audits, and policy configuration details. These artifacts help demonstrate how access control, media restrictions, and monitoring practices are enforced across your environment.

Yes. Many small and mid-size contractors can meet Levels 1 and 2 using commercially available endpoint security, access control, and monitoring solutions. CurrentWare’s lightweight deployment and central console simplify compliance for small teams with limited IT resources.

Not necessarily. CMMC requires controlling device access, not universally banning it. Contractors must limit removable media to authorized devices and maintain oversight. AccessPatrol enables policy-based control so organizations can allow approved media while blocking risky devices.

Implement centralized device control, enforce consistent access policies, maintain detailed audit logs, and continuously monitor endpoint activity. CurrentWare’s platform automates much of this work and generates the documentation auditors request during evaluations.

Keep reading

More articles
Start Free Trial Book a Demo
By clicking “Accept All Cookies”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts. Privacy Policy