CMMC Level 2 Explained: Protecting CUI for Defence Contractors
What's covered:
Where the CMMC rollout stands and what Phase 2 (November 2026) means for your contracts
How to determine whether you truly need Level 2 certification
How to scope and locate your CUI across email, shared drives, and endpoints
CMMC control areas: audit and accountability, FIPS 140-2 encryption, FedRAMP requirements, and incident response
How StreamScan and Virtru together can cover a significant portion of your CMMC controls, reducing assessment burden and consulting costs
Key pitfalls around encryption validation, FedRAMP equivalency vs. authorization, and Microsoft GCC/GCC High eligibility
Considerations specific to Canadian suppliers working with U.S. primes
Who should watch: Defence contractors, IT and compliance teams, and any organization in the Defence Industrial Base navigating CMMC Level 2, including Canadian companies in the U.S. supply chain.