There’s no such thing as a CMMC-certified product. CMMC status belongs to a contractor and the systems it has scoped for an assessment. If our machine handles controlled unclassified information (CUI), it becomes one of those systems and has to meet the NIST SP 800-171 requirements that apply to it. What it avoids is sending prompts and files to an outside AI service, which is where most AI tools run into trouble with CUI.
Where CMMC stands in September 2026
On July 13, 2026, the Department of Defense suspended Phase 2 of the CMMC rollout, which had been set to start on November 10. Under the implementation memo, new requirements can only call for Level 1 or Level 2 self-assessments. Third-party (C3PAO) assessments can’t be required for now, and no new date has been set.
The suspension didn’t remove the rules underneath it. DFARS 252.204-7012 still requires contractors that handle CUI to implement NIST SP 800-171. The CMMC contract clause, DFARS 252.204-7021, and the Phase 1 self-assessment and affirmation requirements are also still in force.
Why cloud AI is hard to use with CUI
When someone pastes a spec sheet or a contract clause into a cloud AI tool, it goes to the vendor’s servers. DFARS 7012 says any cloud provider that stores, processes, or transmits covered defense information has to meet security requirements equivalent to the FedRAMP Moderate baseline, and follow the clause’s incident reporting rules.
Don’t assume a regular business AI subscription meets that bar. Some vendors sell government-cloud versions that may. Check the exact product, the agreement, and its authorization before anyone puts CUI into it.
What changes when the AI runs in your office
With On Premises, the model runs on a machine inside the network you already defend. Prompts and files are processed there, and the model doesn’t need the internet to answer. Because the model runs on your hardware, it isn’t an external cloud service, so the FedRAMP requirement doesn’t apply to the model itself.
Anything else the machine connects to, like backups, model downloads, or our remote support, is set up to your rules and written into the deployment scope. Each of those has to be classified on its own. The machine itself is a CUI asset, so it goes in your asset inventory, system security plan (SSP), and network diagram, and it’s assessed like any other.
Who handles what
The system
- Runs the AI model on hardware in your office
- Gives each person their own login and chat history
- Keeps usage records on your system, not ours
- Changes models only when you approve
- Keeps working if the internet connection drops
Your company
- Adding it to your SSP and network diagram
- Deciding who gets an account, and closing accounts when people leave
- Controlling who can get into the room
- Reviewing the usage logs
- Telling staff what they may put into it
Plan the encryption during scoping. If you use encryption to protect CUI, 800-171 requires FIPS-validated cryptography. Decide separately how you’ll protect data on the drives and data moving between staff computers and the machine.
Is On Premises an external service provider?
Under the CMMC rule, an outside company counts as an external service provider when CUI or security protection data, like log or configuration data, is processed, stored, or transmitted on its systems. Our remote monitoring collects hardware health: uptime, temperatures, load, and drive health. It doesn’t collect prompts, documents, or chat history. Whether that counts as security protection data depends on exactly what’s collected, so list the fields and describe the service in your SSP.
Remote access for repairs needs its own decision. If we log in to fix something while CUI is on the machine, that support service comes into your assessment scope, and the rule expects the arrangement and who is responsible for what to be written down. We sign vendor-access terms that describe the service and what support can reach, which gives you that record for your SSP.
ITAR adds another layer. Letting a foreign person see ITAR technical data generally needs State Department authorization unless an exemption applies, and that includes anyone doing support. Our support staff are U.S. persons. If you handle ITAR data, tell us on the first call so it goes into the written scope.
Try it without any CUI
Our pilot runs one of your workflows on a demo machine for half a day. It can run on made-up documents shaped like yours, so no controlled data has to be involved. You get a written report and a go or no-go within two business days.
This page is general information, not legal advice. CMMC timing is changing quickly, so check the current DoD guidance and talk to your compliance lead or a registered provider organization about your own obligations. See our Terms for how site content should be read.
Last updated: September 23, 2026