Endpoint Index
Research / Industry guide

Endpoint Security for Defense Contractors: Level 1 Needs Scanning, Level 2 Needs Evidence

Updated · data as of · 6 min read

Contents
  1. Executive summary
  2. Level 1: three lines of the FAR
  3. Level 2: what the endpoint has to prove
  4. Which products are positioned for CMMC?
  5. What it costs
  6. What should each supplier buy?
  7. Mistakes defense suppliers make
  8. Frequently asked questions
  9. Methodology and caveats
  10. Sources

Executive summary

A small defense supplier handling only Federal Contract Information can meet CMMC Level 1 with any centrally managed endpoint product that scans in real time and updates itself; a supplier handling Controlled Unclassified Information should buy EDR that keeps enough monitoring data to satisfy DFARS 252.204-7012's 90-day preservation duty. The difference matters now. CMMC Phase 1 began on 10 November 2025, and Phase 2, which makes a third-party Level 2 assessment a condition of award for applicable contracts, starts one calendar year later, on 10 November 2026 (32 CFR 170.3(e)).

Across 17 tracked products (vendor data as of 2026-10-02), 6 come from vendors that publish CMMC relevance and 3 have vendors holding FedRAMP authorisation. No product makes a company compliant. The product supplies part of the evidence an assessor examines.

Level 1: three lines of the FAR

Level 1 applies the 15 basic safeguarding requirements of FAR 52.204-21. Three are about malicious code, and they read like a specification for business antivirus:

  • (b)(1)(xiii): provide protection from malicious code at appropriate locations within organisational information systems;
  • (b)(1)(xiv): update malicious code protection mechanisms when new releases are available;
  • (b)(1)(xv): perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened or executed.

Any business product in this database with a central console meets those three on the devices where it is installed. The Level 1 work is making sure it is installed on every device in scope and keeping the console export for the annual self-assessment.

Level 2: what the endpoint has to prove

Level 2 is built on the 110 requirements of NIST SP 800-171, which add audit logging, system monitoring and incident handling. The endpoint product becomes a Security Protection Asset, which under 32 CFR 170.19(c)(1) is assessed against the Level 2 requirements relevant to the capabilities it provides. In plain terms, the assessor will look at whether your EDR does what your System Security Plan says it does.

DFARS 252.204-7012, which already sits in contracts involving covered defense information, adds three incident duties (clause text):

Clause Duty What the endpoint product must support
7012(c)(1)(ii) Report cyber incidents to DoD within 72 hours of discovery Fast detection and an incident timeline
7012(e) Preserve images of affected systems and relevant monitoring and packet capture data for at least 90 days from the report Retained EDR telemetry, exportable
7012(f) Give DoD access to information needed for forensic analysis on request Data you can hand over, not locked in a console you cannot export from

Antivirus alone keeps almost nothing of use for 7012(e). That, more than any CMMC practice number, is why a CUI supplier needs EDR.

Which products are positioned for CMMC?

These are the products whose vendors publish CMMC relevance, with their other compliance positions:

ProductHIPAA BAASupports PCI DSSCMMC-relevantFedRAMP
CrowdStrike Falcon GoUnknownYesYesauthorized
Sophos EndpointUnknownYesYesnone
SentinelOne Singularity ControlYesYesYesauthorized
Huntress Managed EDRNoUnknownYesnone
CynetUnknownYesYesnone
SentinelOne Singularity CompleteYesYesYesauthorized
From each vendor's trust or compliance pages. "Unknown" means the vendor does not publish the fact; follow a product link for sources.

And what each of them includes. The SIEM column matters because Level 2 audit-logging requirements are easier to evidence when endpoint events land in a central log:

ProductEDR24/7 managed responseSIEM integration
CrowdStrike Falcon GoNot offeredNot offeredNot offered
Sophos EndpointNot offeredNot offeredIncluded
SentinelOne Singularity ControlIncludedNot offeredIncluded
Huntress Managed EDRIncludedIncludedIncluded
CynetIncludedIncludedIncluded
SentinelOne Singularity CompleteIncludedNot offeredIncluded
From each vendor's product and pricing pages. "Add-on" means available at extra cost. Follow a product link for sources and verification dates.

The FedRAMP column answers a narrower question than it seems to. 7012(b)(2)(ii)(D) requires a cloud service that stores, processes or transmits covered defense information to meet security requirements equivalent to the FedRAMP Moderate baseline. Whether the endpoint vendor's console is such a service depends on what telemetry it holds and how your assessor scopes it. Vendors disagree: Huntress, for example, argues that it operates as a Security Protection Asset and does not need FedRAMP authorisation. Settle the point with your assessor before you buy, not during the assessment.

What it costs

ProductPer unit per month10 seats / yr25 seats / yr100 seats / yr
CrowdStrike Falcon Go$5.00 /endpoint/mo$599.90$1,499.75$5,999.00
SentinelOne Singularity Control$6.67 /endpoint/mo$799.90$1,999.75$7,999.00
SentinelOne Singularity Complete$15.00 /endpoint/mo$1,799.90$4,499.75$17,999.00
Huntress Managed EDRMin 50 seatsMin 50 seatsMin 50 seats$9,588.00
Annual totals from each vendor's store or calculator at list price. "Quote only" means the vendor publishes no online price at that seat count; "Min N seats" means the vendor's smallest purchase is larger. Not shown because the vendor does not publish a price: Cynet, Sophos Endpoint.

The endpoint licence is usually a small part of a Level 2 budget next to assessment and remediation work, so do not choose on licence price alone. For a product this table leaves out, the SMB endpoint security price index lists every published price from 5 to 100 seats.

What should each supplier buy?

Machine shop or small supplier with FCI only (Level 1). A centrally managed product on every device that touches contract information, set to update automatically, with a monthly export saved for the self-assessment. CrowdStrike Falcon Go ($59.99 per endpoint per year) is on the CMMC-relevant list with a published price, though it has no EDR; that is acceptable at Level 1.

Subcontractor of 10 to 50 people handling CUI (Level 2). EDR with a 24/7 team or an in-house process that meets the 72-hour report, plus a documented way to keep telemetry for 90 days after a report. SentinelOne Singularity Complete ($179.99 per endpoint per year) carries a FedRAMP authorisation, but its 24/7 managed response is not offered, so the 72-hour clock rests on your own staff or an MSP. Huntress Managed EDR ($107.88 per endpoint per year) includes the team; bought direct it starts at 50 endpoints, so a smaller subcontractor gets it through an MSP, where Huntress sets no minimum.

Supplier whose MSP runs its IT. If the MSP's services process CUI, 170.19 puts those services inside your assessment scope as an External Service Provider. Ask the MSP for its own evidence pack before Phase 2 solicitations reach you.

Supplier building a CUI enclave. Put only enclave devices on the Level 2 product. Fewer devices in scope means a smaller licence bill and a shorter assessment.

Mistakes defense suppliers make

  • Believing a product is "CMMC certified". Organisations are assessed; products are not.
  • Buying antivirus for CUI systems. It cannot supply the 90-day monitoring data 7012(e) requires.
  • Leaving the MSP's console out of the System Security Plan. An External Service Provider's services are assessed as part of yours.
  • Waiting for Phase 2 to start. A C3PAO assessment needs evidence gathered over time, and 10 November 2026 is weeks away.

Frequently asked questions

What endpoint protection satisfies CMMC Level 1?

Protection from malicious code, updated when new releases are available, with periodic and real-time scanning, per FAR 52.204-21(b)(1)(xiii) to (xv). Any centrally managed business product does this on the devices where it runs.

When do third-party CMMC assessments start appearing in contracts?

Phase 2 begins on 10 November 2026, one calendar year after Phase 1, and adds Level 2 (C3PAO) status as a condition of award for applicable solicitations (32 CFR 170.3(e)).

How long must a contractor keep endpoint data after an incident?

At least 90 days from submitting the cyber incident report, covering images of affected systems and relevant monitoring data (DFARS 252.204-7012(e)).

Does the endpoint vendor need FedRAMP authorisation?

Only if its cloud service handles covered defense information, in which case 7012 requires FedRAMP Moderate equivalence. 3 products here have vendors holding FedRAMP authorisation. Confirm scoping with your assessor.

Methodology and caveats

On 30 September 2026 we checked FAR 52.204-21 and 32 CFR 170.3 and 170.19 at Cornell's LII, and on acquisition.gov for DFARS 252.204-7012 and 252.204-7021; the 10 November 2025 effective date of the DFARS CMMC rule was confirmed through the Federal Register's API. Tables are filtered to products whose vendors publish CMMC relevance. "CMMC-relevant" is the vendor's own positioning, recorded with its source and date.

A CMMC Registered Practitioner or C3PAO, not a buyer's guide, decides what your assessment will accept.

Sources

  1. Legal Information Institute. FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems. Checked 30 September 2026.
  2. Legal Information Institute. 32 CFR 170.3, Applicability. Checked 30 September 2026.
  3. Legal Information Institute. 32 CFR 170.19, CMMC scoping. Checked 30 September 2026.
  4. Acquisition.gov. DFARS 252.204-7012. Checked 30 September 2026.
  5. Federal Register. DFARS Case 2019-D041, Assessing Contractor Implementation of Cybersecurity Requirements, published 10 September 2025, effective 10 November 2025.
  6. Endpoint Index product records for the CMMC-relevant products, with each vendor's own statement (2026-10-02).

Related research

All research ›

Methodology · Report an error · Vendor not listed? Get listed