CMMC Level 2 Enabler Framing

United States CMMC Level 2 practice mapping without certification claims.

Trustholm supports AC, AU, and SI themes via RBAC, audit export, and signing policy-CMMC assessment remains the customer enclave outcome.

CMMC Level 2 Enabler Framing

Framework evidence framing before detailed tables below.

Cybersecurity professional analyzing threat and script governance posture

Compliance framing

CMMC Level 2 Enabler Framing

Map Trustholm capabilities to your assessor program with honest Shipped/Gap rows-not vendor certification claims.

  • Reproduce audit export in trial
  • Download trust pack for binders
  • Regional hub cross-links
Gaprows published openly
Download trust pack

This page describes product capabilities for your control matrix. Trustholm does not hold SOC 2, ISO 27001, IRAP, Essential Eight, CMMC, Cyber Essentials, NIS2, or framework certification badges.

CMMC Level 2 assessments evaluate defense contractor and supply chain environments. Trustholm may appear as an ICT subprocess that orchestrates signed PowerShell across MSP customer tenants. We do not claim CMMC certification, C3PAO assessment outcomes, or certified enclave status for the product.

Practices Trustholm touches most directly

Access Control (AC): Portal RBAC, MFA for administrators, JWT tenant binding, and separation between script authors and approvers where workflows require it. Agent paths use polling credentials scoped to tenant and agent identity-not shared portal passwords on endpoints.

Audit and Accountability (AU): Security audit export records who ran what script, where, and under which signing policy. Export supports assessor review windows. Pair with your log retention and review procedures-Trustholm does not operate your SOC on your behalf.

System and Communications Protection (SC): TLS for portal and API traffic; tenant-scoped data paths in application design. Network segmentation between your MSP operations center and customer environments remains your architecture decision.

System and Information Integrity (SI): Code signing enforcement before script execution reduces unsigned tampering risk. Platform script catalog supports centralized built-in operations with reserved tags.

Consumer vs provider split

Provider: Application features, tenant isolation architecture, audit APIs, subprocessors transparency, honest gap tables on trust hub.

Consumer (MSP or prime): SSP content, incident response execution, endpoint baseline, vulnerability remediation cadence, personnel screening, physical security, and CMMC assessment scope definition across your enclave boundary.

MSP positioning for US defense supply chain customers

Government-facing MSPs attach Trustholm vendor evidence to customer SSP packages. The prime or agency assessor evaluates the customer system-Trustholm is one vendor among many. Avoid procurement language implying product-level CMMC Level 2 certification.

When customers request POA&M templates, supply our limitations block and gap rows alongside your compensating controls for backlog items (SIEM connector, WORM audit). Trial pilots should demonstrate signed execution and audit export within the first session.

Contact security@trustholm.com for trust pack materials during enterprise evaluation. This page frames honest enabler contributions-not certification marketing.

Trial evidence checklist: Export one audit slice, capture MFA settings screenshot, and attach Shipped/Gap table to your POA&M draft before customer submission deadlines.

TopicEvidenceStatusNotes
Access control (AC)RBAC, MFA, tenant-scoped administrationShipped-
Audit and accountability (AU)Security audit plane with export; execution attributionShipped-
System integrity (SI)Signed PowerShell policy before executionShipped-
CMMC Level 2 certificationEnabler artifacts only-not a certified enclave or C3PAO outcomeGap-

Frequently asked questions

Is Trustholm CMMC Level 2 certified?

No. We provide enabler artifacts for access control, audit, and integrity themes. Certification is an organizational assessment outcome.

Which CMMC domains touch Trustholm most?

Access Control, Audit and Accountability, and System and Information Integrity via portal IAM, audit export, and signing enforcement.

Can defense MSPs attach this to customer SSPs?

Yes-as vendor evidence in customer packages. The prime or agency assessor evaluates the customer system boundary.

Do you support CUI enclave isolation?

Tenant isolation is application-layer schema separation. Dedicated database profiles exist for enterprise tiers-enclave design remains customer architecture.

What about incident reporting for CMMC?

Customers execute IR procedures. Trustholm documents support and notification terms in enterprise contracts-not in marketing copy alone.

Should we list Trustholm on the POA&M?

Include honest gap rows for backlog items (SIEM connector, WORM audit) with compensating controls your security team accepts.