Our pick for the enclave · Verified 18 August 2026
Bitdefender GravityZone — the endpoint layer for a CUI enclave, not a compliance shortcut
Per-device annual licensing — see current offer
Once you have drawn an enclave boundary around your controlled work, a handful of NIST 800-171 requirements land squarely on the endpoint agent: malicious code protection and its updating, periodic and real-time scanning, monitoring for indicators of attack, application and device control, host firewalling, disk-encryption management and the audit records that show any of it was actually running. Bitdefender GravityZone covers that band from a single console, scales down to the twenty or thirty machines a real enclave usually contains rather than assuming an enterprise fleet, and — unlike the Microsoft-bundled route — does not require you to relicense the whole institution to protect a small scoped estate. It places consistently at or near the top of the independent AV-Comparatives and AV-TEST evaluations, which is the only vendor-neutral evidence available in this category. What it will not do is produce an SSP, a POA&M or an assessment result. Buy it as one input to a control set you have already designed.
See GravityZone pricing Opens on the vendor’s site · CASRAI referral link
Read the GravityZone review → — Detail on the modules, the console and what the tiers actually change.
Editorial disclosure: CASRAI has commercial referral arrangements with some of the vendors named on this page, and may earn a commission if you subscribe to them. We name them here regardless of whether a link is present. We only recommend tools our editorial team has independently researched. Read our full disclosure policy.
In summary
- CMMC does not create new security requirements. It adds verification to obligations that already existed under DFARS 252.204-7012 and NIST SP 800-171.
- Level 1 applies where you hold only Federal Contract Information — 15 basic safeguarding requirements, self-assessed and annually affirmed.
- Level 2 applies where the award involves Controlled Unclassified Information — all 110 NIST SP 800-171 requirements, and often a third-party assessment.
- Scoping decides everything. Most institutions can enclave CUI into a small defined environment rather than assessing the whole campus.
- Bitdefender GravityZone has no public list price — it is quoted at checkout by endpoint count. Verified 18 August 2026.
- No product produces compliance. Without a system security plan, a POA&M and retained evidence, tooling buys you nothing at assessment.
What an endpoint platform does and does not cover
Mapped against the NIST SP 800-171 control families, 18 August 2026
| Dimension | Endpoint tooling contributes | Still entirely on you |
|---|---|---|
| SI — System & Information Integrity | Malicious code protection, signature updating, periodic and real-time scanning, attack monitoring | Acting on vendor security advisories, defining what counts as unauthorised use |
| AU — Audit & Accountability | Endpoint event records, retention, tamper protection on the agent logs | Deciding which events are auditable, reviewing them, correlating across systems, time synchronisation |
| CM — Configuration Management | Application control, blocking unapproved software, device and USB control, drift reporting | The baseline configuration itself, change control, the approved-software list |
| SC — System & Communications Protection | Host firewalling, encryption-at-rest management, web and network attack filtering on the endpoint | Boundary architecture, network segmentation, the cryptography validation question |
| RA — Risk Assessment | Vulnerability and misconfiguration scanning of covered endpoints | Periodic risk assessment, remediation decisions and their documented timelines |
| MP — Media Protection | Removable-media control and encryption enforcement | Marking, handling, sanitisation and disposal procedures |
| IR — Incident Response | Detection, the forensic timeline, containment actions | The plan, the trained roles, the exercises, DoD incident reporting inside the contract deadline |
| AC / IA — Access Control, Identification & Authentication | Marginal — console access control only | Nearly all of it: least privilege, separation of duties, MFA, session controls, remote access |
| AT / PS / PE / MA — Training, Personnel, Physical, Maintenance | Nothing | All of it. These are policy, HR and facilities requirements |
| CA — Security Assessment | Evidence feeds only | The SSP, the POA&M, the assessment itself, the annual affirmation |
Treat any vendor claim of the form “covers 80 of the 110 controls” as marketing. The number depends entirely on your architecture, and an assessor scores your implementation, not your purchase order.
What CMMC compliance actually obligates your institution to do
The most common misreading in a research office is that CMMC introduced a new security standard. It did not. The Cybersecurity Maturity Model Certification programme is a verification mechanism bolted onto requirements that have been in your awards for years. DFARS 252.204-7012 already required contractors handling covered defense information to implement NIST SP 800-171 and report cyber incidents to the Department of Defense; the 7019 and 7020 clauses added a self-assessment against that standard, scored and posted to the Supplier Performance Risk System. What DFARS 252.204-7021 adds is certification: that the assertion be at a stated level, affirmed by a named senior official, and in defined circumstances checked by somebody other than you.
That shift from “implement” to “attest and be assessed” is what changes the work. The affirmation is a representation to the federal government made by a named individual on the institution’s behalf, so universities that have treated 800-171 as an IT aspiration rather than an institutional commitment should involve general counsel before anybody affirms anything.
Three practical obligations follow. First, you must know which awards carry the relevant clauses — which means research administration, not IT, owns the trigger. Second, you need a system security plan describing the environment and how each applicable requirement is met, plus a plan of action and milestones for anything that is not. Third, you must produce evidence that the described controls were operating, not merely configured once. The phase-in is staged, and which stage an award falls into governs whether a self-assessment suffices, so read the clauses in the solicitation rather than a summary — including ours.
Which awards pull you into Level 1 versus Level 2
The level is set by the information the award causes you to hold, not by its size or sponsor.
Level 1 applies where you hold only Federal Contract Information — information provided by or generated for the government under a contract, not intended for public release, and nothing more sensitive. A great deal of ordinary contracted work sits at that bar. The requirement set is the fifteen basic safeguarding controls from FAR 52.204-21: limit access to authorised users, authenticate them, sanitise media before disposal, control physical access, protect your network boundary, keep malicious code protection current. It is self-assessed and annually affirmed, and for most institutions ordinary IT already meets all fifteen — the work is documenting that rather than building anything.
Level 2 applies where the award involves Controlled Unclassified Information. In a research setting CUI typically arrives as export-controlled technical data, controlled technical information within a defence-adjacent programme, certain critical-infrastructure or nuclear-adjacent categories, or occasionally privacy-category CUI. Level 2 means all 110 requirements of NIST SP 800-171, and depending on the criticality of the acquisition it may require assessment by an accredited third-party assessment organisation on a triennial cycle rather than self-assessment.
Two traps recur in university settings. The first is assuming fundamental research is out of scope: that concept concerns publication restrictions on results, and does not exempt you from protecting CUI a sponsor furnishes so you can do the work. Read what is coming in, not only what is going out. The second is flowdown — as a subrecipient on a defence-adjacent prime award the clauses reach you, and your own subawards carry them onward. Every serious university CMMC programme begins by searching the awards database for the clause numbers, and it routinely turns up projects nobody in research security knew were in scope.
How this relates to NIST 800-171 and its 110 controls
CMMC Level 2 is not a parallel standard. It is NIST SP 800-171, assessed. The 110 requirements sit in fourteen families, and the distribution tells you where the effort goes: Access Control is much the largest at 22, then System and Communications Protection at 16, Identification and Authentication at 11, and Audit and Accountability, Configuration Management and Media Protection at nine each. The remaining eight families — integrity, physical, maintenance, assessment, training, incident response, risk and personnel — account for barely a third of the total between them.
Read that distribution as a budget. Nearly a third of the standard is identity and access: who can reach what, with which privileges, over which connections, with what authentication. That is architecture and directory work, it is where the hard money goes, and endpoint tooling barely touches it.
The SPRS score most institutions have already posted derives from this set: you begin at 110 and subtract weighted points for each unimplemented requirement, so a weak environment can score well below zero. A negative score is not a scandal — plenty of first honest assessments are negative — but it is a number the government can see, and the gap between it and 110 is your programme plan.
Note also that NIST has revised 800-171, and the revision reorganises and reduces the requirement count. Which revision applies is set by the clause in your award and the programme documentation in force when you are assessed, not by which version is newest — so if you are being sold a gap analysis, get that answer in writing.
Scoping is the entire game
Here is the single most valuable thing on this page: the assessment covers the environment you define, and you get to define it. Scope badly and you assess a campus. Scope well and you assess a room, a rack and thirty laptops. That is the difference between a project a research office can run and one that quietly consumes the IT department for two years.
The mechanism is the enclave: a bounded environment where CUI is stored, processed and transmitted, separated from the campus network, with access restricted to named personnel on named projects. Everything outside it that cannot reach CUI is out of scope. In practice that means a dedicated network segment or compliant cloud tenancy, dedicated managed endpoints, its own identity groups and logging, and hard rules that CUI never leaves — not into institutional email, not into the departmental file share, not onto a personal laptop for the weekend.
The CMMC scoping guidance formalises this with asset categories, two of which matter enormously in research. Security protection assets — your endpoint console, log collector and identity provider — are in scope because they protect the enclave, which is why the tooling you buy is itself assessed. And specialised assets, covering test equipment, operational technology and government-furnished equipment, finally gives you somewhere to put an instrument controller running an operating system unsupported for a decade: documented in the asset inventory, shown on the network diagram, described in the SSP, managed by risk-based measures rather than assessed against every requirement. That is the difference between replacing the mass spectrometer PC and isolating it. Check the current guidance version before relying on the detail.
The honest trade-off: enclaving imposes a real usability cost. A separate login, a separate machine, no personal-device access, friction every time data moves. Principal investigators push back, and some will simply work outside the boundary if you make it painful enough — at which point your carefully drawn scope is fiction and your affirmation is false. Budget for the enclave being usable, not merely compliant: if the compliant path is harder than the non-compliant one, you have built a control that documents a risk rather than reducing it.
Which controls tooling satisfies, and which it cannot touch
Endpoint tooling does real work here, concentrated in the SI, AU, CM, SC and RA families as the table above sets out. That is the band we recommend Bitdefender GravityZone for — and if your enclave holds CUI you want the detection-and-response layer rather than plain anti-malware, as EDR versus antivirus explains: the forensic timeline changes what you can tell a contracting officer after an incident.
Now the part vendors do not print on the datasheet. Roughly half the standard is policy, process and people, and no product touches it: awareness and training, personnel screening and transfer procedures, physical protection of the enclave, maintenance controls, media marking and sanitisation, incident response planning and exercises, separation of duties, the periodic risk assessment. And access control, the largest family, is identity architecture rather than endpoint software.
And the requirement that catches institutions out: an assessor scores implementation, not procurement. You need an SSP describing how each requirement is met; a POA&M for gaps, remembering that conditional status is permitted only for a defined subset of lower-weighted requirements within a time-limited closeout window; and retained evidence that the controls actually operated — configuration exports, log samples, training records, review minutes, ticket histories. Buying an excellent product in March and being assessed in November with no evidence of its operation in between produces a finding, not a pass.
Do not buy an endpoint platform yet if you have not drawn your enclave boundary. You will license the wrong machines, have no answer when the assessor asks which assets are in scope, and spend budget that belonged with the identity and segmentation work. Equally, do not buy this if your enclave already runs on a Microsoft government cloud tenancy with an E5-class licence — the bundled endpoint protection is credible, already inside your assessment boundary, and a second agent buys duplication rather than coverage. Bitdefender is the right answer when you are protecting a small scoped estate without relicensing the institution, or want a platform independent of the identity stack it defends.
A defensible order of work
For a research office starting from nothing, this sequence keeps you from spending money in the wrong order.
- Find the clauses. Search your awards for DFARS 252.204-7012, -7019, -7020 and -7021, including subawards where you are the subrecipient. This is a research administration task, and the only way to learn your true exposure.
- Classify what you hold. For each in-scope award, determine whether the information is FCI or CUI and where it currently lives. Expect unpleasant answers involving shared drives and personal machines.
- Decide the scope before the architecture. For almost every university the answer is an enclave, and making that decision late is the most expensive mistake available.
- Write the SSP as you build, not afterwards. It is the deliverable an assessor reads first, and retrofitting it is how gap analyses turn into rewrites.
- Do the identity and segmentation work. The two largest families, and the ones with the longest lead times.
- Then the endpoint layer, sized to the enclave — see our endpoint security guide for research groups for how to handle instrument controllers no agent will ever run on.
- Then evidence collection as routine. Scheduled log reviews, retained exports, training records, dated POA&M updates. The trail is what gets assessed.
One last honest position: if a single modest award is the only thing pulling you into Level 2, do the arithmetic on the enclave, the assessment and the ongoing evidence burden before accepting it. Declining, partnering with an already-certified organisation, or restructuring so CUI never reaches you are all legitimate answers — and considerably cheaper than an accidental compliance programme.
Price it against the enclave, not the campus
GravityZone has no public per-device list price — it is quoted at checkout by endpoint count. Count only the machines inside your CUI boundary, plus the security protection assets that manage them, and get the quote against that number rather than your institutional headcount. Verified 18 August 2026.
Per-device annual licensing — see current offer
See GravityZone pricing Opens on the vendor’s site · CASRAI referral link
Frequently asked questions
What is CMMC compliance, in plain terms?
CMMC compliance means your institution has implemented a defined set of security requirements across a defined environment, documented it in a system security plan, and formally affirmed that fact to the US Department of Defense — with an independent assessment where the acquisition requires one. It introduces no new security standard; it verifies the NIST SP 800-171 obligations DFARS 252.204-7012 already imposed.
Does CMMC apply to universities and academic medical centres?
It applies to any organisation holding Federal Contract Information or Controlled Unclassified Information under a Department of Defense award, and that includes universities, affiliated research institutes and academic medical centres. The trigger is the clause in the award, not the sector. Subrecipients are pulled in by flowdown, which is why institutions routinely discover in-scope projects research security had never reviewed.
What is the difference between CMMC Level 1 and Level 2?
Level 1 covers Federal Contract Information only: fifteen basic safeguarding requirements from FAR 52.204-21, self-assessed and affirmed annually. Level 2 applies where the work involves Controlled Unclassified Information and covers all 110 NIST SP 800-171 requirements, with a triennial third-party assessment rather than self-assessment for the more critical acquisitions.
Does the fundamental research exclusion exempt us from CMMC?
Not by itself. The concept concerns restrictions on publishing research results; it does not exempt you from protecting controlled information a sponsor furnishes so that you can perform the work. A project can produce openly publishable outputs while still receiving controlled technical data as an input, and that input is what pulls the environment into scope.
Can we limit CMMC to part of the campus?
Yes, and for most institutions it is the only viable approach. By enclaving CUI into a bounded environment — its own network segment or compliant cloud tenancy, its own managed endpoints and identity groups — everything that cannot reach CUI falls out of scope. The discipline required is absolute: the moment controlled data reaches institutional email or a personal laptop, your defined scope no longer describes reality.
Will buying a security product make us CMMC compliant?
No, and this is the most expensive misunderstanding in the category. Tooling contributes materially to a handful of families — system and information integrity, audit records, configuration and device control, some communications protection — but roughly half the standard is policy, training, personnel and process, and the largest family, access control, is identity architecture. An assessor scores implementation and evidence, not your purchase order.
What happens if we have gaps at assessment time?
Gaps are recorded in a plan of action and milestones. Conditional status is permitted only for a defined subset of lower-weighted requirements within a time-limited closeout period — the heavily-weighted controls must genuinely be implemented at the time of assessment. A POA&M schedules the remaining minor items; it does not defer the hard ones.







