Open navigation menu - Kieri Solutions
Building a CMMC Level 2 Compliant Network You Can Actually Manage

Building a CMMC Level 2 Compliant Network You Can Actually Manage

Network architecture visualization for a CMMC Level 2 reference architecture built on Microsoft 365 GCC High

In this article

A detailed look at architecture decisions, assessment precedent, and practical implementation


Most CMMC solutions on the market share a common problem. They’re designed by people who haven’t been through actual assessments.

Kieri Solutions has been on both sides. We’ve helped defense contractors prepare for CMMC, and we’ve been assessed ourselves as a C3PAO. We’ve also conducted joint surveillance assessments and seen what passes and what doesn’t.

The Kieri Reference Architecture reflects that experience. Every design decision comes from watching what works in real assessments.

Why Cloud-Based Architecture

The KRA is built on Microsoft 365 GCC High with secure Windows laptops. Everything runs in the cloud by default.

This keeps physical facilities out of scope. No secure rooms required. No visitor escort procedures. No camera installations. No lock upgrades.

Virtual-only assessments become possible. That means lower assessment costs and no assessor travel expenses.

For small teams handling CUI, this simplicity matters. You’re not rebuilding your office. You’re deploying laptops and cloud services.

Why Laptops Instead of Virtual Desktop Infrastructure

Almost every other CMMC solution promotes virtual desktop infrastructure. Log into a thin client, access a virtual machine in the cloud, keep all CUI there.

The concept makes sense. VDI centralizes data. It’s harder to exfiltrate. The military uses it.

The problem is assessment consistency.

We studied C3PAO assessments from 2022-2023. These are organizations that went through actual CMMC Level 2 assessments by DoD assessors.

The results were concerning.

About 35% of organizations using VDI were told their endpoints (the physical devices in front of users) were CUI assets. Full security was required on those endpoints. Antivirus. Vulnerability scanning. STIGs. Everything.

About 60% required some security on endpoints. What security depended on the assessor.

Only about 5% passed with completely unmanaged endpoints accessing VDI.

That’s significant assessment risk. Organizations set up VDI enclaves thinking their laptops were out of scope. Then assessors arrived and asked about antivirus on those laptops.

Some organizations recovered by deploying secure laptops mid-assessment. Some failed.

We looked at that data and chose laptops. Known quantity. Predictable assessment outcome.

Laptops also offer practical benefits. They work when internet goes down. They support peripherals. They handle digital certificates. They don’t cost $1,000 per month per user in VDI fees.

The Laptop Boundary Design

KRA laptops have aggressive firewalls. Deny by default inbound and outbound.

This creates a strong boundary around each laptop. Even if you connect to an infected network, that infection can’t reach your laptop.

That means KRA laptops can safely connect to your commercial network. Your CUI users don’t need two computers. They use the KRA laptop for everything and reach back to commercial resources when needed.

The key rule: never join KRA laptops to an insecure domain. Don’t let your on-premises domain controllers manage your CUI laptops. The secure environment must always be in charge.

External Service Provider Strategy

The CMMC proposed rule will require external service providers handling security protection data to be CMMC Level 2 certified or FedRAMP authorized.

That’s a problem for most managed service providers. Very few have Level 2 certification.

The KRA solves this by keeping MSPs out of scope.

If your MSP uses their computers to connect to your environment, their stuff is in your boundary. They need certification.

If your MSP uses YOUR laptops, YOUR accounts, and YOUR procedures, they’re just people. Issue them accounts. Give them KRA laptops. They follow your protocols.

Most MSPs don’t like this approach. They want flexibility. They want their tools.

But the alternative is depending on their certification status. The KRA gives you control.

What’s Included in the Architecture

The KRA uses Microsoft 365 GCC High for:

  • Email (Outlook)
  • File sharing (SharePoint, OneDrive)
  • Collaboration (Teams)
  • Identity management (Entra ID)
  • Security monitoring (Defender for Endpoint, Security Center)
  • Audit logging (Sentinel)
  • Device management (Endpoint Manager)

Duo provides multifactor authentication for laptop logins.

Users get a Windows laptop with a username, password, and phone code for login. Their experience is familiar if they’ve used Office 365. Fast laptops, web browsing works normally, file sharing through SharePoint.

The laptops are locked down. No admin rights for users. FIPS encryption enabled. Complex passwords required. Screens lock when unattended. Only authorized applications installed.

File Sharing and Email

SharePoint and OneDrive handle file sharing. Users can access files through web browsers or sync to their laptops.

Internal users must use KRA laptops to access SharePoint. This prevents the common scenario where someone logs into SharePoint from their home computer and creates a spillage incident.

External collaboration works through guest accounts. Your prime contractor gets a free account with access to specific SharePoint sites. They upload and download through their browser.

Email runs through Microsoft 365. By default, the KRA keeps CUI out of email entirely. Data loss prevention policies scan outgoing messages and block anything with CUI designation indicators.

If you need to email CUI, you can. It requires S/MIME certificates and user training. But SharePoint sharing is simpler and safer.

BYOD email works through the Outlook app. Containerized security keeps email separate from personal phone content.

Printing Considerations

Printing adds scope. Printers. Physical facilities. Paper storage.

The safest approach is disabling printing entirely. Keep everything digital. Show diagrams on screen. Avoid paper CUI.

This keeps facilities out of scope. Virtual-only assessments remain possible.

If you need printing, the KRA supports it. But now your facility and printers are in scope. More security requirements apply. Assessment complexity increases.

The KCD Foundation

The KRA handles technical implementation. But about 70% of CMMC requirements are non-technical.

User onboarding. Background checks. Training. Change management. Risk assessment. Self-assessment. Evidence generation.

The Kieri Compliance Documentation handles all of this. Policies, procedures, templates, databases, and instructions for everything people need to do.

The KRA assumes you’re using KCD best practices. Technical instructions build on that foundation.

Pricing Reality

The KRA and KCD license together cost about $15,000. That includes build instructions, configuration documentation, 10 hours of support, and training library access.

Building this yourself would take 6-12 months of skilled labor. The license saves 80-90% of that cost.

If you want help building, add $28,000 for 40 hours of engineering assistance.

If you want turnkey delivery where Kieri builds everything, add $28,000. You get a ready-for-assessment system with trained staff.

Ongoing costs include laptops ($900 each), Microsoft 365 E5 licenses ($1,200/user/year), help desk support ($2,000/user/year), and compliance program maintenance ($30,000/year minimum).

That’s significantly less than hiring a full-time cybersecurity person at $150,000+ annually.

Who This Works For

The KRA fits organizations that want to control their own compliance. You own the environment. You own the laptops. You manage the system.

If you want to throw money at someone and hope for the best, other vendors offer that. The KRA requires capable IT staff who can follow procedures.

You need an intermediate to senior sysadmin who can handle the build and maintenance. You need someone who can document properly.

But you don’t need an army. The KRA is designed for part-time IT support. We’ve operated ours for years with about 1.5 IT people.


Kieri Solutions passed our CMMC Level 2 assessment using this architecture. We’ve seen what works in real assessments. The KRA reflects that experience.

Ready to discuss your architecture options? Schedule a consultation

Cybersecurity data analysis supporting CMMC Level 2 audit preparation for defense contractors

Talk to a CMMC Expert

Tell us where you are with CMMC and we’ll map out the next steps for your team.

Don't miss these

Is Your Security Plan Telling the Truth?
Server room corridor lined with racks in a data center covered by a System Security Plan
Is Your Security Plan Telling the Truth?
What Does the Government Actually Require of You Today?
A network of yellow lines connecting round nodes against a dark background.
What Does the Government Actually Require of You Today?
NIST SP 800-171 Rev 3, What Changed and What It Means for Your CMMC Timeline
Man at a desk in a dark office reading text on a computer monitor, NIST SP 800-171 Rev 3
NIST SP 800-171 Rev 3, What Changed and What It Means for Your CMMC Timeline
CMMC Backup Requirements and The Myths Worth Ignoring
Server backup drives in a dark data center supporting CMMC backup requirements for a defense contractor
CMMC Backup Requirements and The Myths Worth Ignoring
How to Prepare for a DIBCAC High Assessment
Analyst reviewing evidence on dark dual monitors while preparing for a DIBCAC High assessment
How to Prepare for a DIBCAC High Assessment
Out of Scope Assets - What the Final Rule Actually Changed
Abstract data cityscape tied to out of scope assets in a CMMC assessment by Kieri Solutions
Out of Scope Assets - What the Final Rule Actually Changed
CMMC Proposed Rule Analysis - What Defense Contractors Need to Know
Dark cybersecurity image with glowing data illustrating CMMC final rule compliance for defense contractors
CMMC Proposed Rule Analysis - What Defense Contractors Need to Know
CMMC Phase 2 Suspended and What Defense Contractors Need to Know
Analyst reviewing code while working toward CMMC and NIST 800-171 compliance
CMMC Phase 2 Suspended and What Defense Contractors Need to Know
CUI Assets - What Assessors Actually Evaluate
Abstract network of nodes tied to CUI assets and CMMC scope assessed by Kieri Solutions
CUI Assets - What Assessors Actually Evaluate
Do I Even Have CUI? Understanding What You Need to Protect
Abstract data network tied to finding CUI on a defense contractor network with Kieri
Do I Even Have CUI? Understanding What You Need to Protect
Why the DoD Wants Security Protection Data Protected Like CUI
Abstract data network tied to security protection data and CMMC scope assessed by Kieri
Why the DoD Wants Security Protection Data Protected Like CUI
Why Your CMMC Gap Analysis Might Be Worthless - 110 Practices vs 320 Assessment Objectives
Cybersecurity professional conducting CMMC gap analysis for a defense contracting organization
Why Your CMMC Gap Analysis Might Be Worthless - 110 Practices vs 320 Assessment Objectives
Building a CMMC Level 2 Compliant Network You Can Actually Manage
Network architecture visualization for a CMMC Level 2 reference architecture built on Microsoft 365 GCC High
Building a CMMC Level 2 Compliant Network You Can Actually Manage
Why Most CMMC Documentation Fails and How to Fix It
CMMC compliance documentation policies and procedures
Why Most CMMC Documentation Fails and How to Fix It
What Passed a DOD Assessment for System Baselining and Inventories
CMMC system inventory and baseline configuration monitoring dashboard
What Passed a DOD Assessment for System Baselining and Inventories
How to Implement Mobile Code Requirements for CMMC Level 2
CMMC mobile code security controls and technical implementation
How to Implement Mobile Code Requirements for CMMC Level 2
What Does "Monitor" Actually Mean in CMMC Requirements?
CMMC monitoring requirements - access control and password security verification
What Does "Monitor" Actually Mean in CMMC Requirements?
The Version 20 Problem and How to Avoid It
CMMC compliance documentation sequence - cybersecurity program management
The Version 20 Problem and How to Avoid It
Build Your Own CMMC Level 2 Compliant Environment with the Kieri Reference Architecture
CMMC Level 2 compliant environment security controls and access management
Build Your Own CMMC Level 2 Compliant Environment with the Kieri Reference Architecture
Inside the KCD - What Makes This Documentation Different
CMMC compliance documentation templates digital security
Inside the KCD - What Makes This Documentation Different
How the Kieri Compliance Documentation and Reference Architecture Work Together
Kieri Compliance Documentation and Reference Architecture working together for CMMC Level 2 compliance
How the Kieri Compliance Documentation and Reference Architecture Work Together
What's Actually Inside the Kieri Compliance Documentation? A Complete Walkthrough
CMMC compliance documentation and reference architecture security controls - fingerprint scanning and access management
What's Actually Inside the Kieri Compliance Documentation? A Complete Walkthrough
CMMC Assessments by Kieri Solutions
Global cybersecurity compliance support for defense contractors under DFARS
CMMC Assessments by Kieri Solutions
CMMC Education: User vs Network Session Termination
Secure IT infrastructure design supporting CMMC Level 2 compliance for defense contractors
CMMC Education: User vs Network Session Termination
CMMC Proposed Rule has been released! 
Cybersecurity threat - CMMC compliance
CMMC Proposed Rule has been released! 
Interested in the Kieri Compliance Documentation?
Secure data transmission within CMMC compliant network architecture
Interested in the Kieri Compliance Documentation?
How to fix Outlook missing Friday January 13 2023
Interconnected defense contractor networks requiring CMMC Level 2 cybersecurity certification
How to fix Outlook missing Friday January 13 2023
C3PAO Meeting - July 26, 2021 12-1 pm EDT
C3PAO Meeting - July 26, 2021 12-1 pm EDT
NIST SP 800-171 DoD Self Assessment Services
DFARS 252.204-7012 and NIST SP 800-171 requirements
NIST SP 800-171 DoD Self Assessment Services
vSphere Health detected new issues in your environment 6.7
vcenter 6.7 alarm displays vsphere health detected new issue
vSphere Health detected new issues in your environment 6.7
vCenter Health Warning: External Platform Services Controller
vCenter Health Warning: External Platform Services Controller
Synology storage latency and disconnects on VMware
Synology storage latency and disconnects on VMware
Windows Stuck in Recovery Mode Datto driver signing
Windows Stuck in Recovery Mode Datto driver signing
Office 365 MFA App Password Missing Fix
Office 365 MFA App Password Missing Fix
Microsoft Teams Conference Calls & Dial-In Numbers
Microsoft Teams Conference Calls & Dial-In Numbers
C: Drive Full Exchange
C: Drive Full Exchange
Exchange server very slow, services and network blank
Exchange server very slow, services and network blank
Exchange 2016 DAG - 3 servers 2 sites
Diagram showing mailbox servers with active and passive databases. Each database is only active on one server.
Exchange 2016 DAG - 3 servers 2 sites
Netapp 3rd-party CA certificates expiring DeutscheTelekomRootCA2
Kieri Solutions partnering with defense contractors to achieve CMMC Level 2 certification
Netapp 3rd-party CA certificates expiring DeutscheTelekomRootCA2
vCenter 6.7 Memory Exhaustion and vSphere health (Tiny)
warning vsphere health detected new issue memory exhaustion 6.7 vcenter
vCenter 6.7 Memory Exhaustion and vSphere health (Tiny)
Step by Step: Upgrade vCenter VCSA 6.0 (or 6.5) to 6.7
Step by Step: Upgrade vCenter VCSA 6.0 (or 6.5) to 6.7
How to prepare for a DoD CMMC audit and certification
cybersecurity CMMC DoD NIST 800-171 compliance nist 800-53
How to prepare for a DoD CMMC audit and certification
Fix Expired vCenter Root Password (6.5 & 6.7)
Fix Expired vCenter Root Password (6.5 & 6.7)
How to rename Windows Server 2016 Domain Controller
How to rename Windows Server 2016 Domain Controller
Runtime Error Adding Host in VMware vCenter & ESXi
add host a general runtime error occurred vcenter 6.5 6.7
Runtime Error Adding Host in VMware vCenter & ESXi
How to fix Netapp expired self-signed certificate by creating a new one
netapp certificate expired install site cant be reached
How to fix Netapp expired self-signed certificate by creating a new one
How to register a warranty or service agreement on HPE website
hpe hp register account SAR ID service agreement warranty how accept
How to register a warranty or service agreement on HPE website
How to install vCenter 6.7 (and 6.0 and 6.5) with no DNS, only IP address
vcenter ip address no dns
How to install vCenter 6.7 (and 6.0 and 6.5) with no DNS, only IP address
How to disable continuous scrolling on Kindle - turn on page flip
disable continuous scrolling option displays
How to disable continuous scrolling on Kindle - turn on page flip
17hats how to export or convert to Excel CSV TAB XLS workbook
17hats export convert iff to csv tab excel
17hats how to export or convert to Excel CSV TAB XLS workbook
How to fix "Cannot apply changes to this Internet Shortcut" Windows
cannot apply changes to this internet shortcut 2016 2019
How to fix "Cannot apply changes to this Internet Shortcut" Windows
Best Free Computer Incident Response Templates and Scenarios
best free incident response reporting form cybersecurity IT
Best Free Computer Incident Response Templates and Scenarios
Firmware & System Patching Services | DC & Maryland
poweredge server raid reconfigure add disks 1 5
Firmware & System Patching Services | DC & Maryland
Network hardening near Baltimore MD, Frederick, Rockville, Gaithersburg and DC
Best practice network segmentation and hardening prevents pivot attacks NIST
Network hardening near Baltimore MD, Frederick, Rockville, Gaithersburg and DC
VMware vSphere ESX and vCenter Upgrade 5.5 to 6.0 or 6.5 or 6.7 best practices
Best practices and how to install esxi vsphere vcenter vmware and troubleshooting problems during the migration
VMware vSphere ESX and vCenter Upgrade 5.5 to 6.0 or 6.5 or 6.7 best practices
Disaster Recovery & Business Continuity in DC & Maryland
disaster recovery drp bcp hipaa frederick columbia gaithersburg baltimore rockville
Disaster Recovery & Business Continuity in DC & Maryland
VMWare and Netapp consultant in DC, Baltimore, Columbia, Frederick, and Rockville MD
installation services netapp disk shelf baltimore columbia rockville
VMWare and Netapp consultant in DC, Baltimore, Columbia, Frederick, and Rockville MD
SBDC - Intro to GDPR training - Frederick MD
intro gdpr overall sbdc fitci frederick
SBDC - Intro to GDPR training - Frederick MD
GDPR and Human Resources
cybersecurity cyber security hardening compliance firewall design frederick
GDPR and Human Resources
No, your computer isn't slow.
why slow computer pc repair frederick damascus mt airy md
No, your computer isn't slow.
Why you should consider a credit freeze - EquiFax hack
credit freeze equifax hack how to breach innovis
Why you should consider a credit freeze - EquiFax hack
Virtual Servers, Storage, and SAN - Why your servers are slow
cybersecurity compliance design consulting engineering
Virtual Servers, Storage, and SAN - Why your servers are slow
How to un-freeze your laptop like a pro
pc or computer problem repair damascus lisbon mt airy laytonsville
How to un-freeze your laptop like a pro
Upgrade your IT Services for the New Year
managed services it department outsource company frederick columbia germantown gaithersburg
Upgrade your IT Services for the New Year
Dell PowerEdge R730 PERC RAID online reconfiguration
poweredge server raid reconfigure add disks 1 5
Dell PowerEdge R730 PERC RAID online reconfiguration
Dreamhost HTTP error Wordpress media upload and library
dreamhost http error picture disappear upload shared wordpress
Dreamhost HTTP error Wordpress media upload and library
FortiAnalyzer Configuration problems after initial deploy
FortiAnalyzer 5.4 Storage Quota Limits for ADOM root
FortiAnalyzer Configuration problems after initial deploy
FortiAnalyzer Report: User Web Browsing by Category
fortianalyzer custom report users by category who is browsing web goofing off
FortiAnalyzer Report: User Web Browsing by Category
GDPR Consulting - What you need to know
cybersecurity CMMC DoD NIST 800-171 compliance nist 800-53
GDPR Consulting - What you need to know
The #1 Computer Security Threat Just Evolved - RCE Worm
cybersecurity cyber security compliance firewall frederick md
The #1 Computer Security Threat Just Evolved - RCE Worm
Fix vSphere & vCenter Datastore Size Reverting
security design cybersecurity consulting services compliance
Fix vSphere & vCenter Datastore Size Reverting
HP DL360p g8 ESXi 5.5 to 6.5 upgrade conflicting_vibs_error
conflicting vibs error vsphere upgrade metadata consultant vmware
HP DL360p g8 ESXi 5.5 to 6.5 upgrade conflicting_vibs_error
Is your IT person holding the network hostage?
Server Upgrade Cybersecurity Consultant SAN Netapp Frederick
Is your IT person holding the network hostage?
4 Hiring Mistakes When Choosing an IT Company
mistakes when hire IT consultant MSP managed service provider computer support outsourcing
4 Hiring Mistakes When Choosing an IT Company
What you should know about Cloud Computing and Office 365
cloud IT department migration Office 365 Frederick Baltimore Columbia MD
What you should know about Cloud Computing and Office 365
Can You Make Our Nation Safe from Hackers?
Can You Make Our Nation Safe from Hackers?
The Ultimate Way to Protect Against Computer Theft
Kieri Solutions site icon
The Ultimate Way to Protect Against Computer Theft
Small / medium business security concerns
managed services it department outsource company frederick columbia germantown gaithersburg
Small / medium business security concerns
Approaches to security policy
cybersecurity cyber security hardening compliance firewall design frederick
Approaches to security policy

Article

Is Your Security Plan Telling the Truth?
Server room corridor lined with racks in a data center covered by a System Security Plan

Article

What Does the Government Actually Require of You Today?
A network of yellow lines connecting round nodes against a dark background.

Article

NIST SP 800-171 Rev 3, What Changed and What It Means for Your CMMC Timeline
Man at a desk in a dark office reading text on a computer monitor, NIST SP 800-171 Rev 3

No one wants to start from blank templates.

No one wants to start from
blank templates.

Stop starting from blank templates. Get documentation proven through actual CMMC Level 2 assessment.