Building a CMMC Level 2 Compliant Network You Can Actually Manage

In this article
A detailed look at architecture decisions, assessment precedent, and practical implementation
Most CMMC solutions on the market share a common problem. They’re designed by people who haven’t been through actual assessments.
Kieri Solutions has been on both sides. We’ve helped defense contractors prepare for CMMC, and we’ve been assessed ourselves as a C3PAO. We’ve also conducted joint surveillance assessments and seen what passes and what doesn’t.
The Kieri Reference Architecture reflects that experience. Every design decision comes from watching what works in real assessments.
Why Cloud-Based Architecture
The KRA is built on Microsoft 365 GCC High with secure Windows laptops. Everything runs in the cloud by default.
This keeps physical facilities out of scope. No secure rooms required. No visitor escort procedures. No camera installations. No lock upgrades.
Virtual-only assessments become possible. That means lower assessment costs and no assessor travel expenses.
For small teams handling CUI, this simplicity matters. You’re not rebuilding your office. You’re deploying laptops and cloud services.
Why Laptops Instead of Virtual Desktop Infrastructure
Almost every other CMMC solution promotes virtual desktop infrastructure. Log into a thin client, access a virtual machine in the cloud, keep all CUI there.
The concept makes sense. VDI centralizes data. It’s harder to exfiltrate. The military uses it.
The problem is assessment consistency.
We studied C3PAO assessments from 2022-2023. These are organizations that went through actual CMMC Level 2 assessments by DoD assessors.
The results were concerning.
About 35% of organizations using VDI were told their endpoints (the physical devices in front of users) were CUI assets. Full security was required on those endpoints. Antivirus. Vulnerability scanning. STIGs. Everything.
About 60% required some security on endpoints. What security depended on the assessor.
Only about 5% passed with completely unmanaged endpoints accessing VDI.
That’s significant assessment risk. Organizations set up VDI enclaves thinking their laptops were out of scope. Then assessors arrived and asked about antivirus on those laptops.
Some organizations recovered by deploying secure laptops mid-assessment. Some failed.
We looked at that data and chose laptops. Known quantity. Predictable assessment outcome.
Laptops also offer practical benefits. They work when internet goes down. They support peripherals. They handle digital certificates. They don’t cost $1,000 per month per user in VDI fees.
The Laptop Boundary Design
KRA laptops have aggressive firewalls. Deny by default inbound and outbound.
This creates a strong boundary around each laptop. Even if you connect to an infected network, that infection can’t reach your laptop.
That means KRA laptops can safely connect to your commercial network. Your CUI users don’t need two computers. They use the KRA laptop for everything and reach back to commercial resources when needed.
The key rule: never join KRA laptops to an insecure domain. Don’t let your on-premises domain controllers manage your CUI laptops. The secure environment must always be in charge.
External Service Provider Strategy
The CMMC proposed rule will require external service providers handling security protection data to be CMMC Level 2 certified or FedRAMP authorized.
That’s a problem for most managed service providers. Very few have Level 2 certification.
The KRA solves this by keeping MSPs out of scope.
If your MSP uses their computers to connect to your environment, their stuff is in your boundary. They need certification.
If your MSP uses YOUR laptops, YOUR accounts, and YOUR procedures, they’re just people. Issue them accounts. Give them KRA laptops. They follow your protocols.
Most MSPs don’t like this approach. They want flexibility. They want their tools.
But the alternative is depending on their certification status. The KRA gives you control.
What’s Included in the Architecture
The KRA uses Microsoft 365 GCC High for:
- Email (Outlook)
- File sharing (SharePoint, OneDrive)
- Collaboration (Teams)
- Identity management (Entra ID)
- Security monitoring (Defender for Endpoint, Security Center)
- Audit logging (Sentinel)
- Device management (Endpoint Manager)
Duo provides multifactor authentication for laptop logins.
Users get a Windows laptop with a username, password, and phone code for login. Their experience is familiar if they’ve used Office 365. Fast laptops, web browsing works normally, file sharing through SharePoint.
The laptops are locked down. No admin rights for users. FIPS encryption enabled. Complex passwords required. Screens lock when unattended. Only authorized applications installed.
File Sharing and Email
SharePoint and OneDrive handle file sharing. Users can access files through web browsers or sync to their laptops.
Internal users must use KRA laptops to access SharePoint. This prevents the common scenario where someone logs into SharePoint from their home computer and creates a spillage incident.
External collaboration works through guest accounts. Your prime contractor gets a free account with access to specific SharePoint sites. They upload and download through their browser.
Email runs through Microsoft 365. By default, the KRA keeps CUI out of email entirely. Data loss prevention policies scan outgoing messages and block anything with CUI designation indicators.
If you need to email CUI, you can. It requires S/MIME certificates and user training. But SharePoint sharing is simpler and safer.
BYOD email works through the Outlook app. Containerized security keeps email separate from personal phone content.
Printing Considerations
Printing adds scope. Printers. Physical facilities. Paper storage.
The safest approach is disabling printing entirely. Keep everything digital. Show diagrams on screen. Avoid paper CUI.
This keeps facilities out of scope. Virtual-only assessments remain possible.
If you need printing, the KRA supports it. But now your facility and printers are in scope. More security requirements apply. Assessment complexity increases.
The KCD Foundation
The KRA handles technical implementation. But about 70% of CMMC requirements are non-technical.
User onboarding. Background checks. Training. Change management. Risk assessment. Self-assessment. Evidence generation.
The Kieri Compliance Documentation handles all of this. Policies, procedures, templates, databases, and instructions for everything people need to do.
The KRA assumes you’re using KCD best practices. Technical instructions build on that foundation.
Pricing Reality
The KRA and KCD license together cost about $15,000. That includes build instructions, configuration documentation, 10 hours of support, and training library access.
Building this yourself would take 6-12 months of skilled labor. The license saves 80-90% of that cost.
If you want help building, add $28,000 for 40 hours of engineering assistance.
If you want turnkey delivery where Kieri builds everything, add $28,000. You get a ready-for-assessment system with trained staff.
Ongoing costs include laptops ($900 each), Microsoft 365 E5 licenses ($1,200/user/year), help desk support ($2,000/user/year), and compliance program maintenance ($30,000/year minimum).
That’s significantly less than hiring a full-time cybersecurity person at $150,000+ annually.
Who This Works For
The KRA fits organizations that want to control their own compliance. You own the environment. You own the laptops. You manage the system.
If you want to throw money at someone and hope for the best, other vendors offer that. The KRA requires capable IT staff who can follow procedures.
You need an intermediate to senior sysadmin who can handle the build and maintenance. You need someone who can document properly.
But you don’t need an army. The KRA is designed for part-time IT support. We’ve operated ours for years with about 1.5 IT people.
Kieri Solutions passed our CMMC Level 2 assessment using this architecture. We’ve seen what works in real assessments. The KRA reflects that experience.
Ready to discuss your architecture options? Schedule a consultation
Talk to a CMMC Expert
Tell us where you are with CMMC and we’ll map out the next steps for your team.
Don't miss these
No one wants to start from blank templates.
No one wants to start from
blank templates.
Stop starting from blank templates. Get documentation proven through actual CMMC Level 2 assessment.




























































