Personam maps to the monitoring and detection requirements within CMMC Level 2, assessed against the published assessment objectives for each requirement rather than the requirement title alone.
Direct monitoring: 3.14.6 requires monitoring to detect attacks and indicators of potential attacks, inbound and outbound. Personam addresses each objective in that requirement.
Direct monitoring: 3.14.7 requires that unauthorized use of the system be identified. Behavioral baselining establishes the authorized pattern and deviation detection surfaces the departure from it.
Direct monitoring: 3.3.6 requires a record reduction capability supporting on-demand analysis and a report generation capability supporting on-demand reporting. Personam's query builder provides field selection, time range and condition filtering with CSV and JSON export.
Supporting evidence: 3.1.12 covers remote access sessions being permitted, identified, controlled and monitored. Personam addresses the monitoring, and control of those sessions stays with the remote access gateway.
Supporting evidence: 3.13.1 covers monitoring, control and protection of communications at boundaries. Personam addresses the monitoring at external and internal boundaries.
Supporting evidence: 3.5.1 requires identification of users, processes and devices. Personam identifies users and devices from observed traffic. Process level identity requires host instrumentation.
Supporting evidence: 3.6.1 covers preparation, detection, analysis, containment, recovery and user response. Personam addresses detection and analysis, and the response stages remain human actions by design.
Supporting evidence: 3.3.1 and 3.3.2 cover audit record creation and traceability to individual users. Personam adds attributable network records alongside the system of record.
Supporting evidence: 3.4.1 covers baseline configuration and system inventory. Passive discovery maintains an inventory of network connected assets, including systems endpoint tooling does not reach.
| Requirement | How Personam Addresses It | How Personam Helps |
|---|---|---|
| 3.3.6 Audit Reduction and Reporting | Lets a reviewer narrow the record set by field, condition and time window on demand, and export the result as CSV or JSON for analysis or for an assessor. | Direct monitoring |
| 3.14.6 Monitor for Attacks | Monitors internal, inbound and outbound traffic against established behavior for users, devices and systems that cannot host an agent, including activity that produces no log entry and matches no signature. | Direct monitoring |
| 3.14.7 Identify Unauthorized Use | Learns the authorized pattern of use for each monitored user and device and identifies use that departs from it, including misuse of valid credentials. | Direct monitoring |
| 3.1.1 Limit System Access | Identifies the devices and systems communicating on the network, including unmanaged and legacy equipment that cannot host an agent, and attributes sessions to the account and machine that produced them. | Supporting evidence |
| 3.1.3 Control CUI Flow | Records observed sources and destinations of traffic, including internal segment crossings and external destinations by domain and country, so observed flows can be compared against approved ones. | Supporting evidence |
| 3.1.12 Monitor Remote Access | Monitors remote access sessions against the established behavioral pattern for that user and device, and flags deviation from it. | Supporting evidence |
| 3.1.18 Mobile Device Connections | Identifies mobile and personally owned devices as they connect, without requiring an agent, and keeps per connection records of their activity. | Supporting evidence |
| 3.1.20 External System Connections | Identifies connections to external systems by destination, resolved domain and country, giving reviewers a record of what crossed the boundary. | Supporting evidence |
| 3.3.1 Audit Log Creation and Retention | Generates per connection records with second level timestamps and user, device and destination attribution, adding network evidence alongside host and application logs. | Supporting evidence |
| 3.3.2 Traceability to Individual Users | Attributes network sessions to the account and machine that produced them, which supports tracing activity to individuals in environments where credentials are shared. | Supporting evidence |
| 3.3.5 Audit Record Correlation | Correlates activity across users, devices and sessions to surface unusual or unauthorized behavior for investigation. | Supporting evidence |
| 3.4.1 Baseline Configuration and Inventory | Builds and maintains a discovered inventory of network connected assets through passive observation, including devices that endpoint tooling does not reach. | Supporting evidence |
| 3.5.1 Identify Users and Devices | Identifies users and devices active on the network from observed traffic and maintains a behavioral profile for each one it sees. | Supporting evidence |
| 3.6.1 Incident Handling | Provides the detection and analysis stages of incident handling. Containment and recovery remain human decisions and human actions. | Supporting evidence |
| 3.6.2 Incident Tracking and Reporting | Retains the detection and the session record behind it so responders can document what happened, when, and which accounts and devices were involved. | Supporting evidence |
| 3.13.1 Boundary Communications | Monitors communications at the external boundary and at internal segment boundaries, including east-west traffic that perimeter tooling does not see. | Supporting evidence |
| 3.13.5 Publicly Accessible Subnetworks | Identifies which internal systems communicate with public networks and flags traffic that crosses an expected segmentation boundary. | Supporting evidence |
| 3.13.12 Collaborative Computing Devices | Identifies collaborative computing devices such as cameras and conferencing units by their network behavior and records when they are active. | Supporting evidence |
| 3.13.14 VoIP Monitoring | Identifies VoIP endpoints and monitors their traffic against an established behavioral baseline. | Supporting evidence |
| 3.14.3 Security Alert Monitoring | Generates behavioral alerts for review and retains the supporting session detail for each one, so the team can decide what action to take. | Supporting evidence |
Personam addresses the monitoring and detection requirements within this framework. Full compliance requires controls beyond any detection platform.
Assessed against NIST SP 800-171A assessment objectives
CMMC Level 2 is built on the security requirements in NIST SP 800-171. SP 800-171A splits each requirement into discrete assessment objectives, and an assessor scores each objective separately. Under the DoD Assessment Methodology there is no partial credit within a requirement, so a requirement appears here as direct monitoring only where Personam addresses each of its objectives. Where Personam addresses some but not others, the requirement is listed as supporting evidence and the gap is named rather than absorbed.
NIST has since published Revision 3 of SP 800-171. The requirements above follow Revision 2, because DoD operates under a class deviation that keeps CMMC assessments on Revision 2. Anyone comparing this page against the current NIST publication will see different numbering.
Level 1 covers the basic safeguarding requirements in FAR 52.204-21. Most of those requirements are physical, procedural or media handling controls, and Personam's contribution at Level 1 is limited to monitoring communications at system boundaries and identifying the devices connected to the network. Level 2 is where behavioral detection does the work, which is why the mapping above is drawn against Level 2.
The first phase of the CMMC program became enforceable in DoD contracts when the acquisition rule took effect in November 2025. Later phases remain subject to revision, so nothing on this page assumes a particular certification deadline. Contractors should confirm current requirements against their contracting officer and the DoD program office.
Book a 30-minute live demo showing behavioral detection mapped to your specific regulatory requirements.
Schedule a Demo