Kieri Reference Architecture
Get the complete blueprint for building a CMMC Level 2 compliant Microsoft 365 GCC or GCC High tenant. Includes architectural diagrams, interoperability guidance, scripts, and procedures.
Download Free Guide
TABLE OF CONTENTS
Building a CMMC Level 2 environment from scratch means hours of architecture decisions, policy research, and tenant configuration that you shouldn’t have to figure out alone.
The Kieri Reference Architecture is a complete blueprint for standing up a compliant Microsoft 365 GCC or GCC High tenant the right way. Inside, you’ll find core network diagrams showing how CUI flows through the environment, interoperability guidance for keeping your commercial network in sync, scripts you can run, and procedures that have already been validated against CMMC Level 2 and NIST SP 800-171 controls.
This isn’t a marketing overview. It’s the technical document we hand to engineering teams when they’re designing or reviewing a CMMC environment.
Who it’s for:
- Defense contractors preparing for CMMC Level 2 assessment
- IT leaders deciding whether to build internally or bring in a specialist
- Architects and engineers who need a known-good reference design
- Compliance officers mapping controls to technical implementation
If you don’t have the in-house talent to implement it, we can point you to CMMC-specialized vendors who do this every day.
Need Hands-On Help Implementing This Architecture?
We can connect you with CMMC-specialized engineering partners who build this environment every day.
What’s Inside the Reference Architecture
The document covers the core systems and design decisions that go into a compliant CMMC Level 2 environment.
- Core Kieri Reference Architecture network diagram
- CUI flow and boundary markings for every asset
- Security Protection Assets, Contractor Risk Managed Assets, and CUI Assets clearly mapped
- Out-of-scope assets and external boundary placement
- Step-by-step technology choices and the reasoning behind each one
Interoperability with Your Commercial Network
The Kieri Reference Architecture is designed to work alongside an on-premises network that doesn’t handle CUI. The boundary controls keep CUI from transitioning into or out of the enclave outside of intentional, audited paths like SharePoint sharing.
The data sheet walks through what your commercial network can and can’t do alongside the reference design, including which Active Directory and domain configurations to avoid so your on-premises network doesn’t accidentally pull itself into scope.
Don't miss these
No one wants to start from blank templates.
No one wants to start from
blank templates.
Stop starting from blank templates. Get documentation proven through actual CMMC Level 2 assessment.


