By November 2028, every DoD contract that touches Controlled Unclassified Information will require a CMMC certification. BlastShield addresses 52 of the 110 CMMC Level 2 controls — concentrated in the Access Control, Identification & Authentication, and System & Communications Protection families — without re-architecting your CUI environment.
of 110 controls addressed
directly satisfied
partial or enabled
of 14 families covered
The Cybersecurity Maturity Model Certification (CMMC) is the Department of Defense's mechanism for verifying that the roughly 300,000 companies in the Defense Industrial Base actually protect the Controlled Unclassified Information (CUI) and Federal Contract Information (FCI) flowing through their systems. It converts the long-standing "self-attestation" model into an assessed, contract-gating requirement.
CMMC Level 2 maps directly to all 110 security requirements of NIST SP 800-171 Rev. 2, organized into 14 control families. Contractors must implement the controls, document a System Security Plan (SSP) and Plan of Action & Milestones (POA&M), submit a score to the Supplier Performance Risk System (SPRS), and — for most CUI contracts — pass a third-party assessment conducted by a C3PAO.
The two largest families, Access Control (AC) and System & Communications Protection (SC), together account for 38 of the 110 controls. These are exactly the areas where flat networks, shared credentials, and unencrypted lateral traffic cause the most assessment findings — and exactly where BlastShield was engineered to enforce Zero Trust.
The certification, not just the score: A minimum SPRS score of 88 of 110 supports a conditional (POA&M-based) certification, but every control must ultimately be met. BlastShield closes the highest-weighted technical controls quickly, which both raises your SPRS score and shrinks the POA&M you carry into a C3PAO assessment.
A product enables controls; it does not grant certification. BlastShield satisfies and enables specific technical controls and produces the evidence to prove it. The SSP, POA&M, SPRS submission, and the C3PAO assessment itself remain your responsibility. This page is explicit about that boundary so your assessor sees defensible claims.
BlastShield alone satisfies the control's technical intent and produces the evidence
BlastShield provides substantial coverage; policy or partner tooling closes the gap
BlastShield supplies the enforcement or telemetry; a SIEM, IdP, or process activates the control
CMMC Level 2 organizes 110 controls into 14 families. BlastShield is strongest in the three technical families that govern who can reach CUI, how they authenticate, and how that traffic is protected — the families that also carry the most controls and the most assessment findings.
The largest family and the core of BlastShield. Deny-by-default policy, least privilege, and identity-based access limit CUI systems to authorized users, processes, and devices. BlastShield's "Segment of One" ensures a user or vendor reaches only the specific asset they are authorized to touch — never the surrounding subnet.
Remote access is routed through managed, cryptographically protected access points with no split tunneling, and sessions can be terminated instantly from the Orchestrator.
BlastShield identifies and authenticates every user and non-person entity before a single packet reaches a CUI asset. FIDO2 passwordless, phishing-resistant MFA (biometric plus challenge-response) satisfies the MFA mandate for privileged and network access, and is replay-resistant by design.
Because authentication is passwordless and key-based, entire classes of password-handling controls are satisfied or rendered not-applicable.
BlastShield monitors and controls communications at the boundary of the CUI enclave, denies network traffic by default, and encrypts all CUI in transit in AES-256 tunnels — upgrading legacy clear-text protocols without touching the endpoints. Network cloaking removes publicly reachable attack surface entirely.
Cryptographic key management, session authenticity, and connection termination round out direct coverage of this family.
BlastShield enforces least functionality at the network layer: only explicitly authorized ports, protocols, and services can traverse the enclave, on a deny-by-default / permit-by-exception basis. Baseline and change-control processes remain organizational, but the technical enforcement is BlastShield's.
BlastShield produces high-fidelity, identity-attributed connection records and exports them via Syslog to your SIEM. Every denied connection against a cloaked network is a high-confidence indicator of compromise — turning routine "noise" into an integrity signal. Retention, review, and malware defense are completed by partner tooling.
Nonlocal maintenance sessions are established through MFA-gated, fully logged, time-bounded access and terminated on completion — directly satisfying the maintenance control that most often trips contractors up. For incident response, the BlastShield "Digital Kill Switch" revokes a zone's certificates in milliseconds, logically isolating a compromised segment without dispatching anyone.
Six families are procedural or organizational and are not solved by any network product: Awareness & Training (AT), Media Protection (MP), Personnel Security (PS), Physical Protection (PE), Risk Assessment (RA), and Security Assessment (CA). We state this plainly so your assessor trusts the claims we do make. BlastShield handles the technical enforcement; your GRC program handles the rest.
The table below covers the highest-impact controls where BlastShield has direct or enabling effect. The full 52-control mapping, with assessment-objective notes, is available in the solution brief.
Control
Requirement
How BlastShield Delivers
Coverage
3.1.1 / 3.1.2
Limit Access to Authorized Users & Functions
Restrict CUI system access to authorized users, processes, and devices, and to the transactions they are permitted to execute
BlastShield enforces identity-based, deny-by-default access. A user or process reaches only the assets and functions in policy — the "Segment of One." Unauthorized identities cannot see, ping, or scan CUI systems at all.
Direct
3.1.3
Control the Flow of CUI
Control CUI flow in accordance with approved authorizations
Host-level microsegmentation dictates precisely which systems may exchange data, independent of VLANs or IP scheme. CUI cannot traverse a path that is not explicitly authorized, even on a flat Layer 2 network.
Direct
3.1.12 / 3.1.13 / 3.1.14
Monitor, Encrypt & Route Remote Access
Monitor and control remote sessions, protect them cryptographically, and route them through managed access control points
All remote access runs through BlastShield's authenticated, AES-256-encrypted mesh — no split tunneling, no exposed VPN concentrator. Every session is identity-bound, logged, and terminable from the Orchestrator. Three of the most-cited remote-access controls, satisfied by one architecture.
Direct
3.5.3
Multifactor Authentication
Use MFA for local and network access to privileged accounts and network access to non-privileged accounts
BlastShield enforces FIDO2 passwordless, phishing-resistant MFA at network ingress. No packet reaches a CUI asset until strong authentication completes. Faster than password entry and replay-resistant (3.5.4) by design.
Direct
3.13.6
Deny Network Traffic by Default
Deny network communications traffic by default and allow by exception (deny-all, permit-by-exception)
BlastShield's Zero Trust Default Drop is the foundational policy. Unlike accreted firewall "allow-any" rules, every connection requires explicit identity-to-identity authorization. Anything not in policy is silently dropped and logged.
Direct
3.13.8
Encrypt CUI in Transit
Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission
BlastShield encapsulates traffic leaving the enclave in AES-256 tunnels, upgrading legacy clear-text protocols to strong encryption with no endpoint changes. Physical access to a switch or tap yields nothing usable.
Direct
3.7.5
MFA for Nonlocal Maintenance
Require MFA to establish nonlocal maintenance sessions and terminate them when complete
Third-party maintainers connect through MFA-gated, containerized sessions scoped to a single asset, fully logged, and torn down on completion. A frequent finding for contractors with vendor remote-support, closed architecturally.
Direct
3.14.6
Monitor for Attacks & Indicators
Monitor systems, including inbound and outbound traffic, to detect attacks and indicators of potential attacks
Every denied connection against a cloaked BlastShield network is a high-confidence attack indicator, exported to your SIEM via Syslog. BlastShield supplies the signal; the SIEM performs correlation and alerting.
Enables
3.3.1 / 3.3.2
Audit Records & Individual Accountability
Create and retain audit logs, and ensure actions can be traced to individual users
Because access is identity-bound rather than IP-bound, every BlastShield connection record ties an action to a specific authenticated identity. Records export to your SIEM/log platform, which handles retention and review.
Enables
Most contractors do not fail CMMC on paper; they stall on the cost, downtime, and scope of actually re-architecting a flat network into a segmented, encrypted, authenticated CUI environment. BlastShield was built to make that shift fast and non-disruptive.
The Challenge
The broader your CUI boundary, the more systems fall under all 110 controls and the more expensive the assessment. On a flat network, "everything" is in scope because anything can reach the CUI.
BlastShield Solution
BlastShield carves a cryptographically enforced enclave around only the systems that store, process, or transmit CUI — independent of physical topology. Everything outside the enclave falls out of scope, directly reducing assessment cost and POA&M size.
The Challenge
Traditional microsegmentation means new firewalls, VLAN redesign, IP re-addressing, and downtime that a working shop floor or engineering team cannot absorb.
BlastShield Solution
BlastShield overlays the existing network. Host-level microsegmentation goes live in hours with no IP changes, no re-cabling, and no downtime, satisfying 3.1.3 and 3.13.6 without a network redesign project.
The Challenge
Manufacturing and engineering contractors run legacy workstations, test rigs, and OT that cannot host agents, certificates, or modern MFA — yet still touch CUI and drawings covered by the contract.
BlastShield Solution
The BlastShield Gateway holds certificates and enforces MFA on behalf of assets that cannot themselves. A legacy CNC controller or historian presents to the enclave as a fully authenticated, encrypted node — no firmware changes, no rip-and-replace.
Our team can map exactly which of the 110 controls BlastShield closes in your specific CUI environment, how much it shrinks your assessment scope, and which partner integrations complete the remaining families.
Privacy Policy | Cookie Policy | © 2025 BlastWave, Inc. All Rights Reserved
This website uses cookies to ensure you get the best experience. More Info