https://www.sikich.com

CMMC 2.0 and Azure: what defense contractors need to know before their next audit

INSIGHT 7 min read

If your organization is part of the Defense Industrial Base and you have not completed a formal CMMC 2.0 readiness assessment, the window to act ahead of your next contract award is narrowing faster than most contractors realize. CMMC Phase 2 begins November 10, 2026, the date after which DoD can condition contract awards on Level 2 C3PAO third-party certification rather than self-attestation. The organizations that built their Azure environments to support CMMC compliance from the start are better positioned for that assessment. The ones that have not will spend the months before their audit in a remediation sprint, at significantly higher cost.

Where CMMC 2.0 stands in 2026

CMMC 2.0 is no longer a future requirement. The final rule took effect November 10, 2025, and DoD contract language now reflects CMMC certification requirements for applicable contracts. Phase 2 begins November 10, 2026, after which Level 2 C3PAO third-party certification becomes a condition of award for priority contracts, replacing the self-attestation that Phase 1 allowed. For defense contractors and subcontractors that process, store, or transmit Controlled Unclassified Information (CUI), the compliance clock is running.

The capacity situation for C3PAO assessments makes the timeline more urgent, not less. Approximately 80 authorized C3PAOs are available to serve an estimated 80,000 contractors requiring Level 2 certification. Wait times are already exceeding 18 months for new clients in some regions, and assessment fees are rising sharply as demand outstrips supply. If you have not engaged a C3PAO yet, the time to do that is now, not after your next contract solicitation includes a CMMC clause.

What CMMC Level 2 requires

CMMC Level 2 maps directly to the 110 security practices in NIST SP 800-171, organized across 14 control families including access control, incident response, audit and accountability, configuration management, identification and authentication, and system and communications protection. To achieve certification, your organization must score a minimum of 88 out of 110 points assessed by a C3PAO.

That is not a documentation exercise. It requires evidence, system logs, policy records, configuration artifacts, access reviews, and incident response documentation, that demonstrates your controls are operating as designed, not just defined on paper. Organizations that have been managing those controls manually are often surprised by how much documentation preparation a C3PAO assessment requires.

The organizations that come through Level 2 assessments efficiently are the ones that built governance into their environments from the start, so that compliance evidence is generated automatically rather than assembled before each audit.

How Azure supports CMMC Level 2 compliance

Azure is not directly certified under CMMC, CMMC assesses the contractor’s implementation, not the cloud platform. However, Microsoft’s Azure compliance documentation for CMMC confirms that both Azure and Azure Government meet the applicable requirements of DFARS Clause 252.204-7012, and an accredited third-party assessment organization has attested to that alignment. Azure is FedRAMP High authorized, which satisfies the minimum FedRAMP Moderate requirement for cloud services used in CMMC-scoped environments.

More practically, Azure’s native tooling directly supports the control families CMMC Level 2 requires:

  • Access control (AC): Microsoft Entra ID with Conditional Access, Privileged Identity Management, and role-based access control enforce least-privilege access across your Azure environment with audit trails generated automatically
  • Audit and accountability (AU): Azure Monitor, Log Analytics, and Microsoft Sentinel provide continuous audit logging with retention configurations aligned to CMMC documentation requirements
  • Configuration management (CM): Azure Policy enforces configuration standards across your environment and flags deviations automatically, the continuous configuration visibility that CMMC assessors expect
  • Incident response (IR): Microsoft Defender for Cloud and Microsoft Sentinel provide automated threat detection and incident response workflows with documented evidence chains
  • System and communications protection (SC): Private Link, network segmentation, and encryption at rest and in transit satisfy CMMC communications protection requirements

Azure Government vs. Azure Commercial for CMMC environments

For most mid-market defense contractors at Level 2, Azure Commercial is an appropriate environment for CUI processing when properly configured. Azure Government offers additional controls for organizations with more sensitive requirements or specific agency relationships, and is required alongside GCC High for Level 3 programs.

The critical variable is not which Azure environment you use, it is whether it is configured correctly. A well-configured Azure Commercial environment with proper CUI boundary definition, access controls, and monitoring satisfies Level 2 requirements. A poorly configured Azure Government environment does not. Configuration and governance are the determining factors, not the environment label.

Configuration drift is a CMMC risk, not just an IT risk

The same configuration drift that creates security and cost risk in any Azure environment creates specific CMMC compliance risk for defense contractors. If your access controls, logging configuration, or network policies have drifted from their CMMC-aligned baseline since your last formal review, your compliance posture has drifted with them.

CMMC assessors are not evaluating your environment at a single point in time. They are looking for evidence of continuous compliance, that your controls were operating as designed throughout the assessment period, not just in the weeks before the C3PAO arrived. An environment that has drifted between assessments generates the kind of audit finding that delays certification and requires remediation under time pressure.

The organizations that maintain clean CMMC compliance posture are the ones with continuous visibility into their Azure configuration, so drift is caught and corrected before it becomes an audit finding.

FAQ: CMMC 2.0 and Azure for defense contractors

When does CMMC Phase 2 take effect and what changes?

CMMC Phase 2 begins November 10, 2026. After that date, DoD can condition contract awards on Level 2 C3PAO third-party certification for priority contracts, rather than accepting self-attestation. Organizations that have been relying on self-attestation under Phase 1 must transition to a certified C3PAO assessment for applicable contracts.

Does Azure Government satisfy CMMC Level 2 requirements?

Both Azure Commercial and Azure Government can support CMMC Level 2 compliance when properly configured. Azure Government is required for Level 3 programs alongside GCC High. For most mid-market defense contractors at Level 2, Azure Commercial is appropriate when CUI boundaries are properly scoped and controls are correctly configured.

How long does CMMC Level 2 certification take?

Most organizations should plan for six to twelve months of structured gap assessment, remediation, and documentation preparation before scheduling a C3PAO assessment. Given current C3PAO capacity constraints and Phase 2 beginning in November 2026, organizations that have not started the process are already behind the optimal timeline.

What is a CUI enclave and why does it matter for CMMC?

A CUI enclave is a logically isolated environment where your Controlled Unclassified Information is processed, stored, and transmitted, separate from your general IT network. Proper enclave design limits the scope of your CMMC assessment boundary, which reduces the number of systems that must be assessed and makes certification more manageable. Scoping is one of the highest-leverage preparation steps available before a C3PAO engagement.

What happens if a subcontractor is not CMMC compliant?

Prime contractors are responsible for ensuring that their subcontractors meet the CMMC requirements specified in the prime contract. A non-compliant subcontractor creates compliance risk for the prime, and starting with Phase 2, prime contractors are expected to validate subcontractor compliance as a condition of maintaining their own contract eligibility. If you are a prime contractor, your subcontractor compliance posture is part of your compliance posture.

Where to start if your organization is behind

The most important first step for defense contractors who are uncertain about their CMMC readiness is a formal gap assessment against NIST SP 800-171. That assessment gives you a current picture of where your controls stand, what remediation is required, and what your realistic timeline to C3PAO certification looks like.

Sikich works with defense contractors to assess Azure environments against CMMC Level 2 requirements, build remediation roadmaps that prioritize based on assessment timelines and contract obligations, and ensure that the documentation trail C3PAOs expect is being generated continuously rather than assembled under pressure.

As a premier Microsoft partner with all six Microsoft Solutions Partner designations, Sikich brings both the Azure technical depth and the CMMC compliance pattern recognition to build environments that are assessment-ready, not just compliant on paper.

Want to understand what CMMC-aligned Azure architecture looks like in practice?

Join our featured speakers, Todd Porter, Sikich Solutions Architect & Azure expert, and Quentin Epps, Microsoft Partner Solutions Architect, for this webinar. One lucky Azure Health Check webinar attendee will win a complimentary Sikich Azure Assessment, a $7,500 value.

Author

Dustin Miller is a principal, who supports the managed services practice in the role of virtual chief information officer (vCIO). Dustin helps business owners and executives understand their current IT assets, create a vision and multi-year roadmap for IT that integrates with business objectives, and align specific technology initiatives within the annual budgeting process. He provides ongoing collaboration and serves as an executive-level technology team member that understands and can speak to both technology and business topics.