Deploy CMMC-Compliant Infrastructure in Weeks

A complete Microsoft 365 GCC-High architecture with scripts, technician procedures, and baseline configurations. Built for CUI, ITAR, and CMMC Level 2, designed to be managed with part-time IT support.

Building Compliant Infrastructure From Scratch Is Complex

A Proven Architecture Based on Our Own CMMC Certification

Why Kieri
Reference Architecture

Built by the team that passed their own CMMC Level 2 assessment using this design

Deploy Compliant Systems Fast

Complete blueprints with step-by-step procedures, scripts, and baseline configurations. Build infrastructure in weeks instead of spending months on design and testing.

Architecture Proven in Assessment

We used this design to pass CMMC Level 2 certification with DIBCAC. You implement infrastructure validated through actual DoD evaluation.

Maintain It Yourself

Designed for part-time IT support and a monthly virtual CISO meeting. You manage your systems without ongoing consulting dependencies or managed service contracts.

Implementation in Days

We Develop Your CMMC Roadmap Together

  • Immediate download of all policies, procedures, System Security Plans, and templates.
  • Everything mapped to CMMC and NIST SP 800-171 requirements.

Documentation That Passes Real Assessments

  • Pre-written policies, procedures, and System Security Plans based on our own CMMC Level 2 certification
  • Built for organizations under 1,000 users, not downsized enterprise frameworks
Kieri Compliance Documentation features including NIST SP 800-171 and identity verification

From Preparation to Certification

  • Gap analysis, consulting, documentation leading to CMMC Level 2 assessment
  • Every engagement led by certified CMMC assessors with real assessment experience
NIST SP 800-171 compliance solutions for small defense contractors

We Develop Your CMMC Roadmap Together

  • Immediate download of all policies, procedures, System Security Plans, and templates.
  • Everything mapped to CMMC and NIST SP 800-171 requirements.

Documentation That Passes Real Assessments

  • Pre-written policies, procedures, and System Security Plans based on our own CMMC Level 2 certification
  • Built for organizations under 1,000 users, not downsized enterprise frameworks
Kieri Compliance Documentation features including NIST SP 800-171 and identity verification

From Preparation to Certification

  • Gap analysis, consulting, documentation leading to CMMC Level 2 assessment
  • Every engagement led by certified CMMC assessors with real assessment experience
NIST SP 800-171 compliance solutions for small defense contractors

What's Inside the Kieri Reference Architecture

Network Architecture Diagrams

Security Baseline Configurations

Implementation Procedures

Step-by-step technician guides for every component. Detailed instructions with screenshots and command examples.

Configuration Scripts

Automation scripts for common deployment tasks. PowerShell scripts for Microsoft 365 configuration.

System Documentation Templates

Pre-written system descriptions for your System Security Plan. Network diagrams ready to customize.

System Documentation Templates

Ongoing operations procedures for system administration. Patch management workflows. Change control processes.

Validation Checklists

Testing procedures to verify correct implementation.

Validation steps for every major component.

Who the KRA Is Built For

Small Defense Contractors

Organizations with 50-500 users needing a compliant network without enterprise complexity. Designed to be managed with part-time IT support.

Mid-Sized Manufacturers

Manufacturing organizations handling CUI with limited compliance resources. Compatible with on-premises equipment and operational technology environments.

IT Service Providers

Technology companies serving defense contractors who need to build compliant enclaves for their clients. A repeatable architecture you can deploy across multiple organizations.

Research Institutions

Universities and labs partnering with DoD on sensitive programs. Academic environments requiring flexible but compliant approaches.

Small Defense
Contractors

Organizations with 50-500 users needing complete documentation without enterprise complexity. Perfect for companies with part-time IT support.

Mid-Sized Manufacturers

Manufacturing organizations handling CUI with limited compliance resources. Documentation that works for operational environments.

Research Institutions

Universities and labs partnering with DoD on sensitive programs. Academic environments requiring flexible but compliant approaches.

IT Service Providers

Technology companies serving defense contractors who need their own CMMC certification. Scalable documentation that grows with your business.

What Makes KRA Different

Designed for Operational
Reality

This isn’t theoretical architecture.

It’s infrastructure built for real defense contractors with actual business requirements and budget constraints.

No Vendor Lock-In

You own and manage your systems. No ongoing consulting fees.

No managed service requirements. Complete operational independence.

Part-Time IT Friendly

You don’t need full-time security specialists.

Our procedures are written for IT generalists who can follow detailed instructions.

Battle-Tested Design

This architecture passed CMMC Level 2 assessment.

You implement infrastructure proven to meet DoD standards, not untested concepts.

“In our own compliance journey of trying to figure out what we are required to do, even with consultants that helped us along the way, the MOST useful resource that we have found to date has been the KCD.”

Melissa Kimball

, Director

University of Maine

“My team and I have been using the KCD for about a week now, and I have to say, it’s been a breath of fresh air compared to our previous approach. It has made several processes much easier for us, and for that, we’re truly grateful. You have a fantastic product that far exceeds our expectations.”

Daniel Martinez

, Director of Cybersecurity

nDepth Security

“In our own compliance journey of trying to figure out what we are required to do, even with consultants that helped us along the way, the MOST useful resource that we have found to date has been the KCD.”

Melissa Kimball

, Director

University of Maine

“My team and I have been using the KCD for about a week now, and I have to say, it’s been a breath of fresh air compared to our previous approach. It has made several processes much easier for us, and for that, we’re truly grateful. You have a fantastic product that far exceeds our expectations.”

Daniel Martinez

, Director of Cybersecurity

nDepth Security

Architecture Investment

Lifetime access to all architecture documentation and implementation procedures. Future updates included as the architecture evolves.

 

FAQ

The KRA includes network architecture diagrams, security baseline configurations, PowerShell configuration scripts, step-by-step technician implementation procedures, system documentation templates, and validation checklists. Everything you need to build a Microsoft 365 GCC-High environment designed for CUI, ITAR, and CMMC Level 2 compliance.

No. The KRA is designed to be operated with a part-time system administrator and a virtual CISO meeting once a month at minimum. All procedures are written for IT generalists who can follow detailed instructions, not security specialists.

No. The KRA is designed for organizations that want to own and operate their own compliant environment. We provide everything you need to build it yourself – detailed implementation guides, scripts, baseline configurations, and supporting documentation – so your team stays in control from day one.
If you need hands-on help getting started, our consulting team can work alongside you during implementation. But the keys stay with you.

Yes. The architecture is compatible with on-premises equipment and manufacturing networks. It’s built on Microsoft 365 GCC-High and Windows 10/11, and designed to support real business operations including remote and in-office laptops, BYOD email, and calendar access.

Kieri Solutions used this architecture and documentation to pass our own CMMC Level 2 assessment with DCMA DIBCAC. It’s the same design we presented during that evaluation, not a theoretical framework.

The KRA includes system documentation templates and network diagrams you can incorporate into your SSP. For a complete compliance documentation package including policies, procedures, and a full System Security Plan, the Kieri Compliance Documentation (KCD) is designed to work alongside the KRA.

Organizations that deploy Kieri

Stop designing your network from scratch.

Stop designing your network from scratch.

Get a proven architecture based on the infrastructure that passed our own CMMC Level 2 assessment.