Defense and Aerospace

Every security tool enters your assessment scope.

Schedule a meeting

Primes and cleared contractors under DFARS 7012, CMMC and NISPOM

Security built for the defense industrial base

Keep audit evidence inside your own environment and let assessors check it without us.

Requirements

RequirementShort formPointsARRTECH
3.3.1Create and retain audit logs.5SIEM collection and retention per source. →
3.3.5Correlate review and reporting.5Correlation across sources. →
3.3.8Protect audit information.1Signed chain and console audit log. →
3.6.1Incident handling capability.5SIEM cases with MITRE context. →
3.8.7Control removable media.5DLP device control by serial number. →
3.1.3Control the flow of CUI.Per methodDLP inspection of web, FTP and mail. →
3.14.7Identify unauthorized use.3Detection baselines per user and host. →

32 CFR 170.19

Keep CMMC scope from growing

Under 32 CFR 170.19, security tools count as Security Protection Assets in your CMMC assessment, while an outside cloud service brings its own requirements. ARRTECH runs inside your environment, so it counts as a security tool, not a new cloud provider.

NIST SP 800-171 3.3

Produce audit evidence assessors can verify

NIST SP 800-171 family 3.3 asks you to create, keep, review and protect audit logs. ARRTECH signs every log and exports it with a verification tool, so an assessor can check the record without us.

NIST SP 800-171 3.8.7

Stop technical data leaving on USB or email

Requirement 3.8.7 asks you to control removable media, and it is worth 5 points in your SPRS score. ARRTECH DLP allows or blocks each USB device by serial number and checks files leaving by web or email.

NISPOM 117.7

Support your insider threat program

The NISPOM requires cleared contractors to run an insider threat program. ARRTECH covers part of it: file activity, sign-ins, device use, and behavior compared with each person’s history. It does not record keystrokes or screens.

By rule

3.3.1

Create and retain audit logs. ARRTECH: SIEM collection and retention per source.

3.3.5

Correlate review and reporting. ARRTECH: Correlation across sources.

3.3.8

Protect audit information. ARRTECH: Signed chain and console audit log.

3.6.1

Incident handling capability. ARRTECH: SIEM cases with MITRE context.

3.8.7

Control removable media. ARRTECH: DLP device control by serial number.

3.1.3

Control the flow of CUI. ARRTECH: DLP inspection of web, FTP and mail.

3.14.7

Identify unauthorized use. ARRTECH: Detection baselines per user and host.

Questions

Does it add a cloud provider to our scope?

No. ARRTECH SIEM and ARRTECH DLP run on your servers, and Cyberdroid AI Detection runs in your environment on ordinary CPUs. Each is listed as a security tool in your assessment, not as an outside provider.

Can technical data leave?

ARRTECH DLP controls which USB devices can connect, inspects files leaving by web, FTP or email from any application, and recognizes copies of protected files even when they are partly changed. A screen watermark shows who was viewing and when.

Does it support our insider threat program?

It covers part of it: file and network activity, sign-ins, device use, and behavior compared with each person’s history. It does not record keystrokes or screens.

What stays with you?

Your CMMC assessment, approval of any classified system, and FIPS-validated encryption for CUI. Cyberdroid AI Detection reports about once an hour and never blocks.

Sources

Guide

What is CMMC Level 2?

CMMC Level 2 applies the 110 requirements of NIST SP 800-171 to contractors that handle controlled unclassified information (CUI).

What does DFARS 252.204-7012 require?

Adequate security under NIST SP 800-171, incident reports to DoD within 72 hours, and 90 days of preserved monitoring data.

Do security tools count in CMMC scope?

Yes. Under 32 CFR 170.19, security tools are Security Protection Assets. Tools that run on your own servers avoid adding a cloud provider.

Next steps

Spot unusual behavior early. Learns what normal looks like for every user, computer and application from your SIEM, and flags what changes.

Available now

Get the evidence fast. Investigates each finding with read-only queries and hands a person the evidence. It never approves its own work.

Early access

Keep sensitive data in. Checks email, uploads, USB drives and AI prompts before sensitive data leaves the computer.

Respond with a person in charge. Runs incident response steps through your existing tools, with a person approving each decision.

See every system. Collects and signs logs from more than 500 source types and links related events, with a verification tool for every export.

ARRTECH

© 2026 ARRTECH Corporation. All rights reserved.