# Endpoint Security for Defense Contractors: Level 1 Needs Scanning, Level 2 Needs Evidence

> What CMMC and DFARS 252.204-7012 ask of a small defense supplier's endpoints: the three FAR malicious-code practices at Level 1, the monitoring, reporting and 90-day evidence duties at Level 2, and the cloud-console question. Recommendations for an FCI-only shop, a CUI subcontractor and a firm using an MSP.

Endpoint Index research (Industry guide). Published 2026-09-25, updated 2026-09-30, data as of 2026-10-02. Source: https://endpointindex.com/research/endpoint-security-defense-contractors-cmmc/

## Executive summary

**A small defense supplier handling only Federal Contract Information can meet CMMC Level 1 with any centrally managed endpoint product that scans in real time and updates itself; a supplier handling Controlled Unclassified Information should buy EDR that keeps enough monitoring data to satisfy DFARS 252.204-7012's 90-day preservation duty.** The difference matters now. CMMC Phase 1 began on 10 November 2025, and Phase 2, which makes a third-party Level 2 assessment a condition of award for applicable contracts, starts one calendar year later, on 10 November 2026 ([32 CFR 170.3(e)](https://www.law.cornell.edu/cfr/text/32/170.3)).

Across 17 tracked products (vendor data as of 2026-10-02), 6 come from vendors that publish CMMC relevance and 3 have vendors holding FedRAMP authorisation. No product makes a company compliant. The product supplies part of the evidence an assessor examines.

## Level 1: three lines of the FAR

Level 1 applies the 15 basic safeguarding requirements of [FAR 52.204-21](https://www.law.cornell.edu/cfr/text/48/52.204-21). Three are about malicious code, and they read like a specification for business antivirus:

- (b)(1)(xiii): provide protection from malicious code at appropriate locations within organisational information systems;
- (b)(1)(xiv): update malicious code protection mechanisms when new releases are available;
- (b)(1)(xv): perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened or executed.

Any business product in this database with a central console meets those three on the devices where it is installed. The Level 1 work is making sure it is installed on every device in scope and keeping the console export for the annual self-assessment.

## Level 2: what the endpoint has to prove

Level 2 is built on the 110 requirements of NIST SP 800-171, which add audit logging, system monitoring and incident handling. The endpoint product becomes a Security Protection Asset, which under [32 CFR 170.19(c)(1)](https://www.law.cornell.edu/cfr/text/32/170.19) is assessed against the Level 2 requirements relevant to the capabilities it provides. In plain terms, the assessor will look at whether your EDR does what your System Security Plan says it does.

DFARS 252.204-7012, which already sits in contracts involving covered defense information, adds three incident duties ([clause text](https://www.acquisition.gov/dfars/252.204-7012-safeguarding-covered-defense-information-and-cyber-incident-reporting.)):

| Clause | Duty | What the endpoint product must support |
|---|---|---|
| 7012(c)(1)(ii) | Report cyber incidents to DoD within 72 hours of discovery | Fast detection and an incident timeline |
| 7012(e) | Preserve images of affected systems and relevant monitoring and packet capture data for at least 90 days from the report | Retained EDR telemetry, exportable |
| 7012(f) | Give DoD access to information needed for forensic analysis on request | Data you can hand over, not locked in a console you cannot export from |

Antivirus alone keeps almost nothing of use for 7012(e). That, more than any CMMC practice number, is why a CUI supplier needs EDR.

## Which products are positioned for CMMC?

These are the products whose vendors publish CMMC relevance, with their other compliance positions:



<figure class="data-figure"><div class="table-wrap"><table class="data-table"><thead><tr><th scope="col">Product</th><th scope="col">HIPAA BAA</th><th scope="col">Supports PCI DSS</th><th scope="col">CMMC-relevant</th><th scope="col">FedRAMP</th></tr></thead><tbody><tr><td data-label="Product"><span class="cell"><span class="prod-cell"><img class="logo logo-24" src="/logos/crowdstrike.png" alt="" width="24" height="24" loading="lazy" /><a href="/products/crowdstrike-falcon-go/">CrowdStrike Falcon Go</a></span></span></td><td data-label="HIPAA BAA"><span class="cell"><span class="state state-unknown">Unknown</span></span></td><td data-label="Supports PCI DSS"><span class="cell"><span class="state state-included">Yes</span></span></td><td data-label="CMMC-relevant"><span class="cell"><span class="state state-included">Yes</span></span></td><td data-label="FedRAMP"><span class="cell"><span class="mono">authorized</span></span></td></tr><tr><td data-label="Product"><span class="cell"><span class="prod-cell"><img class="logo logo-24" src="/logos/sophos.png" alt="" width="24" height="24" loading="lazy" /><a href="/products/sophos-endpoint/">Sophos Endpoint</a></span></span></td><td data-label="HIPAA BAA"><span class="cell"><span class="state state-unknown">Unknown</span></span></td><td data-label="Supports PCI DSS"><span class="cell"><span class="state state-included">Yes</span></span></td><td data-label="CMMC-relevant"><span class="cell"><span class="state state-included">Yes</span></span></td><td data-label="FedRAMP"><span class="cell"><span class="mono">none</span></span></td></tr><tr><td data-label="Product"><span class="cell"><span class="prod-cell"><img class="logo logo-24" src="/logos/sentinelone.png" alt="" width="24" height="24" loading="lazy" /><a href="/products/sentinelone-singularity-control/">SentinelOne Singularity Control</a></span></span></td><td data-label="HIPAA BAA"><span class="cell"><span class="state state-included">Yes</span></span></td><td data-label="Supports PCI DSS"><span class="cell"><span class="state state-included">Yes</span></span></td><td data-label="CMMC-relevant"><span class="cell"><span class="state state-included">Yes</span></span></td><td data-label="FedRAMP"><span class="cell"><span class="mono">authorized</span></span></td></tr><tr><td data-label="Product"><span class="cell"><span class="prod-cell"><img class="logo logo-24" src="/logos/huntress.png" alt="" width="24" height="24" loading="lazy" /><a href="/products/huntress-managed-edr/">Huntress Managed EDR</a></span></span></td><td data-label="HIPAA BAA"><span class="cell"><span class="state state-not_offered">No</span></span></td><td data-label="Supports PCI DSS"><span class="cell"><span class="state state-unknown">Unknown</span></span></td><td data-label="CMMC-relevant"><span class="cell"><span class="state state-included">Yes</span></span></td><td data-label="FedRAMP"><span class="cell"><span class="mono">none</span></span></td></tr><tr><td data-label="Product"><span class="cell"><span class="prod-cell"><img class="logo logo-24" src="/logos/cynet.png" alt="" width="24" height="24" loading="lazy" /><a href="/products/cynet/">Cynet</a></span></span></td><td data-label="HIPAA BAA"><span class="cell"><span class="state state-unknown">Unknown</span></span></td><td data-label="Supports PCI DSS"><span class="cell"><span class="state state-included">Yes</span></span></td><td data-label="CMMC-relevant"><span class="cell"><span class="state state-included">Yes</span></span></td><td data-label="FedRAMP"><span class="cell"><span class="mono">none</span></span></td></tr><tr><td data-label="Product"><span class="cell"><span class="prod-cell"><img class="logo logo-24" src="/logos/sentinelone.png" alt="" width="24" height="24" loading="lazy" /><a href="/products/sentinelone-singularity-complete/">SentinelOne Singularity Complete</a></span></span></td><td data-label="HIPAA BAA"><span class="cell"><span class="state state-included">Yes</span></span></td><td data-label="Supports PCI DSS"><span class="cell"><span class="state state-included">Yes</span></span></td><td data-label="CMMC-relevant"><span class="cell"><span class="state state-included">Yes</span></span></td><td data-label="FedRAMP"><span class="cell"><span class="mono">authorized</span></span></td></tr></tbody></table></div><figcaption>From each vendor's trust or compliance pages. "Unknown" means the vendor does not publish the fact; follow a product link for sources.</figcaption></figure>



And what each of them includes. The SIEM column matters because Level 2 audit-logging requirements are easier to evidence when endpoint events land in a central log:



<figure class="data-figure"><div class="table-wrap"><table class="data-table"><thead><tr><th scope="col">Product</th><th scope="col">EDR</th><th scope="col">24/7 managed response</th><th scope="col">SIEM integration</th></tr></thead><tbody><tr><td data-label="Product"><span class="cell"><span class="prod-cell"><img class="logo logo-24" src="/logos/crowdstrike.png" alt="" width="24" height="24" loading="lazy" /><a href="/products/crowdstrike-falcon-go/">CrowdStrike Falcon Go</a></span></span></td><td data-label="EDR"><span class="cell"><span class="state state-not_offered">Not offered</span></span></td><td data-label="24/7 managed response"><span class="cell"><span class="state state-not_offered">Not offered</span></span></td><td data-label="SIEM integration"><span class="cell"><span class="state state-not_offered">Not offered</span></span></td></tr><tr><td data-label="Product"><span class="cell"><span class="prod-cell"><img class="logo logo-24" src="/logos/sophos.png" alt="" width="24" height="24" loading="lazy" /><a href="/products/sophos-endpoint/">Sophos Endpoint</a></span></span></td><td data-label="EDR"><span class="cell"><span class="state state-not_offered">Not offered</span></span></td><td data-label="24/7 managed response"><span class="cell"><span class="state state-not_offered">Not offered</span></span></td><td data-label="SIEM integration"><span class="cell"><span class="state state-included">Included</span></span></td></tr><tr><td data-label="Product"><span class="cell"><span class="prod-cell"><img class="logo logo-24" src="/logos/sentinelone.png" alt="" width="24" height="24" loading="lazy" /><a href="/products/sentinelone-singularity-control/">SentinelOne Singularity Control</a></span></span></td><td data-label="EDR"><span class="cell"><span class="state state-included">Included</span></span></td><td data-label="24/7 managed response"><span class="cell"><span class="state state-not_offered">Not offered</span></span></td><td data-label="SIEM integration"><span class="cell"><span class="state state-included">Included</span></span></td></tr><tr><td data-label="Product"><span class="cell"><span class="prod-cell"><img class="logo logo-24" src="/logos/huntress.png" alt="" width="24" height="24" loading="lazy" /><a href="/products/huntress-managed-edr/">Huntress Managed EDR</a></span></span></td><td data-label="EDR"><span class="cell"><span class="state state-included">Included</span></span></td><td data-label="24/7 managed response"><span class="cell"><span class="state state-included">Included</span></span></td><td data-label="SIEM integration"><span class="cell"><span class="state state-included">Included</span></span></td></tr><tr><td data-label="Product"><span class="cell"><span class="prod-cell"><img class="logo logo-24" src="/logos/cynet.png" alt="" width="24" height="24" loading="lazy" /><a href="/products/cynet/">Cynet</a></span></span></td><td data-label="EDR"><span class="cell"><span class="state state-included">Included</span></span></td><td data-label="24/7 managed response"><span class="cell"><span class="state state-included">Included</span></span></td><td data-label="SIEM integration"><span class="cell"><span class="state state-included">Included</span></span></td></tr><tr><td data-label="Product"><span class="cell"><span class="prod-cell"><img class="logo logo-24" src="/logos/sentinelone.png" alt="" width="24" height="24" loading="lazy" /><a href="/products/sentinelone-singularity-complete/">SentinelOne Singularity Complete</a></span></span></td><td data-label="EDR"><span class="cell"><span class="state state-included">Included</span></span></td><td data-label="24/7 managed response"><span class="cell"><span class="state state-not_offered">Not offered</span></span></td><td data-label="SIEM integration"><span class="cell"><span class="state state-included">Included</span></span></td></tr></tbody></table></div><figcaption>From each vendor's product and pricing pages. "Add-on" means available at extra cost. Follow a product link for sources and verification dates.</figcaption></figure>



The FedRAMP column answers a narrower question than it seems to. 7012(b)(2)(ii)(D) requires a cloud service that stores, processes or transmits covered defense information to meet security requirements equivalent to the FedRAMP Moderate baseline. Whether the endpoint vendor's console is such a service depends on what telemetry it holds and how your assessor scopes it. Vendors disagree: Huntress, for example, [argues](https://www.huntress.com/blog/fedramp-alternative-for-defense-contractors) that it operates as a Security Protection Asset and does not need FedRAMP authorisation. Settle the point with your assessor before you buy, not during the assessment.

## What it costs



<figure class="data-figure"><div class="table-wrap"><table class="data-table"><thead><tr><th scope="col">Product</th><th scope="col">Per unit per month</th><th scope="col">10 seats / yr</th><th scope="col">25 seats / yr</th><th scope="col">100 seats / yr</th></tr></thead><tbody><tr><td data-label="Product"><span class="cell"><span class="prod-cell"><img class="logo logo-24" src="/logos/crowdstrike.png" alt="" width="24" height="24" loading="lazy" /><a href="/products/crowdstrike-falcon-go/">CrowdStrike Falcon Go</a></span></span></td><td data-label="Per unit per month"><span class="cell"><span class="num">$5.00</span> <span class="unit">/endpoint/mo</span></span></td><td data-label="10 seats / yr"><span class="cell"><span class="num">$599.90</span></span></td><td data-label="25 seats / yr"><span class="cell"><span class="num">$1,499.75</span></span></td><td data-label="100 seats / yr"><span class="cell"><span class="num">$5,999.00</span></span></td></tr><tr><td data-label="Product"><span class="cell"><span class="prod-cell"><img class="logo logo-24" src="/logos/sentinelone.png" alt="" width="24" height="24" loading="lazy" /><a href="/products/sentinelone-singularity-control/">SentinelOne Singularity Control</a></span></span></td><td data-label="Per unit per month"><span class="cell"><span class="num">$6.67</span> <span class="unit">/endpoint/mo</span></span></td><td data-label="10 seats / yr"><span class="cell"><span class="num">$799.90</span></span></td><td data-label="25 seats / yr"><span class="cell"><span class="num">$1,999.75</span></span></td><td data-label="100 seats / yr"><span class="cell"><span class="num">$7,999.00</span></span></td></tr><tr><td data-label="Product"><span class="cell"><span class="prod-cell"><img class="logo logo-24" src="/logos/sentinelone.png" alt="" width="24" height="24" loading="lazy" /><a href="/products/sentinelone-singularity-complete/">SentinelOne Singularity Complete</a></span></span></td><td data-label="Per unit per month"><span class="cell"><span class="num">$15.00</span> <span class="unit">/endpoint/mo</span></span></td><td data-label="10 seats / yr"><span class="cell"><span class="num">$1,799.90</span></span></td><td data-label="25 seats / yr"><span class="cell"><span class="num">$4,499.75</span></span></td><td data-label="100 seats / yr"><span class="cell"><span class="num">$17,999.00</span></span></td></tr><tr><td data-label="Product"><span class="cell"><span class="prod-cell"><img class="logo logo-24" src="/logos/huntress.png" alt="" width="24" height="24" loading="lazy" /><a href="/products/huntress-managed-edr/">Huntress Managed EDR</a></span></span></td><td data-label="Per unit per month"><span class="cell"><span class="muted">Min 50 seats</span></span></td><td data-label="10 seats / yr"><span class="cell"><span class="muted">Min 50 seats</span></span></td><td data-label="25 seats / yr"><span class="cell"><span class="muted">Min 50 seats</span></span></td><td data-label="100 seats / yr"><span class="cell"><span class="num">$9,588.00</span></span></td></tr></tbody></table></div><figcaption>Annual totals from each vendor's store or calculator at list price. "Quote only" means the vendor publishes no online price at that seat count; "Min N seats" means the vendor's smallest purchase is larger. Not shown because the vendor does not publish a price: <a href="/products/cynet/">Cynet</a>, <a href="/products/sophos-endpoint/">Sophos Endpoint</a>.</figcaption></figure>



The endpoint licence is usually a small part of a Level 2 budget next to assessment and remediation work, so do not choose on licence price alone. For a product this table leaves out, the [SMB endpoint security price index](/research/smb-endpoint-security-price-index/) lists every published price from 5 to 100 seats.

## What should each supplier buy?

**Machine shop or small supplier with FCI only (Level 1).** A centrally managed product on every device that touches contract information, set to update automatically, with a monthly export saved for the self-assessment. CrowdStrike Falcon Go ($59.99 per endpoint per year) is on the CMMC-relevant list with a published price, though it has no EDR; that is acceptable at Level 1.

**Subcontractor of 10 to 50 people handling CUI (Level 2).** EDR with a 24/7 team or an in-house process that meets the 72-hour report, plus a documented way to keep telemetry for 90 days after a report. SentinelOne Singularity Complete ($179.99 per endpoint per year) carries a FedRAMP authorisation, but its 24/7 managed response is not offered, so the 72-hour clock rests on your own staff or an MSP. Huntress Managed EDR ($107.88 per endpoint per year) includes the team; bought direct it starts at 50 endpoints, so a smaller subcontractor gets it through an MSP, where Huntress sets no minimum.

**Supplier whose MSP runs its IT.** If the MSP's services process CUI, 170.19 puts those services inside your assessment scope as an External Service Provider. Ask the MSP for its own evidence pack before Phase 2 solicitations reach you.

**Supplier building a CUI enclave.** Put only enclave devices on the Level 2 product. Fewer devices in scope means a smaller licence bill and a shorter assessment.

## Mistakes defense suppliers make

- **Believing a product is "CMMC certified".** Organisations are assessed; products are not.
- **Buying antivirus for CUI systems.** It cannot supply the 90-day monitoring data 7012(e) requires.
- **Leaving the MSP's console out of the System Security Plan.** An External Service Provider's services are assessed as part of yours.
- **Waiting for Phase 2 to start.** A C3PAO assessment needs evidence gathered over time, and 10 November 2026 is weeks away.

## Frequently asked questions

### What endpoint protection satisfies CMMC Level 1?

Protection from malicious code, updated when new releases are available, with periodic and real-time scanning, per FAR 52.204-21(b)(1)(xiii) to (xv). Any centrally managed business product does this on the devices where it runs.

### When do third-party CMMC assessments start appearing in contracts?

Phase 2 begins on 10 November 2026, one calendar year after Phase 1, and adds Level 2 (C3PAO) status as a condition of award for applicable solicitations (32 CFR 170.3(e)).

### How long must a contractor keep endpoint data after an incident?

At least 90 days from submitting the cyber incident report, covering images of affected systems and relevant monitoring data (DFARS 252.204-7012(e)).

### Does the endpoint vendor need FedRAMP authorisation?

Only if its cloud service handles covered defense information, in which case 7012 requires FedRAMP Moderate equivalence. 3 products here have vendors holding FedRAMP authorisation. Confirm scoping with your assessor.

## Methodology and caveats

On 30 September 2026 we checked FAR 52.204-21 and 32 CFR 170.3 and 170.19 at Cornell's LII, and on acquisition.gov for DFARS 252.204-7012 and 252.204-7021; the 10 November 2025 effective date of the DFARS CMMC rule was confirmed through the Federal Register's API. Tables are filtered to products whose vendors publish CMMC relevance. "CMMC-relevant" is the vendor's own positioning, recorded with its source and date.

A CMMC Registered Practitioner or C3PAO, not a buyer's guide, decides what your assessment will accept.

## Sources

1. Legal Information Institute. [FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems](https://www.law.cornell.edu/cfr/text/48/52.204-21). Checked 30 September 2026.
2. Legal Information Institute. [32 CFR 170.3, Applicability](https://www.law.cornell.edu/cfr/text/32/170.3). Checked 30 September 2026.
3. Legal Information Institute. [32 CFR 170.19, CMMC scoping](https://www.law.cornell.edu/cfr/text/32/170.19). Checked 30 September 2026.
4. Acquisition.gov. [DFARS 252.204-7012](https://www.acquisition.gov/dfars/252.204-7012-safeguarding-covered-defense-information-and-cyber-incident-reporting.). Checked 30 September 2026.
5. Federal Register. DFARS Case 2019-D041, Assessing Contractor Implementation of Cybersecurity Requirements, published 10 September 2025, effective 10 November 2025.
6. Endpoint Index product records for the CMMC-relevant products, with each vendor's own statement (2026-10-02).
