Firms serving defense contractors have historically fielded a question their commercial peers rarely hear: what security framework has your platform been assessed against? It is not a preference question. Under DFARS 252.204-7012, any cloud service handling Controlled Unclassified Information (CUI) must meet the FedRAMP Moderate baseline. That requirement has quietly decided platform selection for federal-focused practices for years, and it kept most modern engagement platforms out of the running. So while commercial practices moved to AI-native engagement work, federal teams kept running CMMC readiness and assessment work the old way: spreadsheets, email threads, and point tools that generate documents but leave the testing and evidence review entirely manual.
Fieldguide's federal environment closes that gap and and is now live, certified to FedRAMP Moderate through our managed services provider relationship with Knox Systems, whose boundary is one of the largest and longest-running FedRAMP clouds.
Meet the government's security bar without a multi-year build
FedRAMP Moderate is one of the more rigorous security compliance frameworks a SaaS provider can undergo, and it is the standard the government itself uses to evaluate cloud security. Fieldguide's federal environment runs inside Knox Systems' FedRAMP Moderate–certified boundary, and everything that touches CUI stays inside that certified, continuously monitored perimeter. Every subprocessor is in-boundary or FedRAMP certified, and CUI workloads run on approved, in-boundary AI models only.
Just as important is what firms do not need: GovCloud or GCC High. Those environments add a personnel-and-residency guarantee built for ITAR and NOFORN data. Standard CUI requires a FedRAMP Moderate boundary, which the federal environment delivers without that cost or complexity. The environment is also fully isolated from Fieldguide's commercial deployment, so CUI stays separate from a firm's SOC 2, PCI, and HITRUST work.
Run CMMC engagements the way you already run SOC 2 and HITRUST
CMMC Level 2 is the 110 security requirements of NIST 800-171 expanded into 320 assessment objectives across 14 control families. Every objective demands evidence review, a written control narrative, and testing. If that profile sounds familiar, it should: it is the same documentation- and testing-heavy shape as PCI DSS and HITRUST, work that firms already run on Fieldguide every day.
The federal environment is built on the same platform and agent framework Fieldguide uses today, with the federal specifics handled: pre-built CMMC templates covering Level 1 and Level 2 control sets linked to all 320 assessment objectives and kept current as 800-171 moves to Rev 3, NIST-family cross-mapping (800-171 ↔ 800-53 ↔ CMMC) so testing and evidence are reused across a firm's federal work, centralized evidence requests aligned to each practice family, POA&M tracking for remediation, and schema-validated, eMASS-ready submission packages in the DoD CMMC data standard.
Expand federal capacity without expanding headcount
The operating model does not change at the boundary line. On every engagement. Field Agents test the assessment objectives, draft control narratives, review and summarize evidence, and flag gaps and inconsistencies, with citations tracing every output back to source documents. Practitioners review the work and own every professional judgment and conclusion. Every procedure is agent executed and human reviewed, with a human in the loop by design.
That design matters most in exactly this market, because in federal work the work product itself is scrutinized, and cited, consistent documentation at volume is not an efficiency gain so much as the deliverable itself.
And the firm's standing in the CMMC ecosystem stays intact. Your firm keeps its credential and Fieldguide powers the work: RPO for readiness and advisory engagements, C3PAO for certification assessments. Because client CUI lives in Fieldguide's environment, firms receive the shared-responsibility matrix and NIST 800-171 control-inheritance artifacts they need for their own SSP.
The deadline moved, but the obligation didn't
The timing of this launch invites an obvious question. On July 13, the DoD suspended CMMC Phase 2, the third-party assessment mandate that had been scheduled for November 2026, while a task force conducts a 60-day review of the program's verification model.
But the DoD did not suspend the obligation itself. DFARS 252.204-7012 remains fully in effect. NIST 800-171 remains the standard. Phase 1 self-assessments remain in force, and the DoD is enforcing compliance through 800-171 Rev 2 self-assessments and select government-led assessments during the review. Roughly 80,000 organizations, by the DoD's own estimate, will eventually have to demonstrate Level 2 security under whichever verification model emerges. In other words, the review may change how compliance gets verified, but it does not change what contractors are obligated to protect.
For firms, that means readiness, gap assessment, and remediation work continues, and the firms that keep their clients ready through the review will be first in line under whatever assessment regime comes out of it. A platform decision anchored to a deadline was always going to be fragile, while one anchored to the underlying obligation holds up regardless of how the review lands.
A federal practice you could not build before
The constraint on federal compliance practices has never been demand but capacity, and since the profession's talent math is not going to improve, the operating model is what has to change. Until now, federal-focused firms could not bring the new model to their most security-sensitive work, because the environment that carries it could not clear the government's own bar, and with the federal environment live, that is no longer the constraint.
Fieldguide's federal environment is live today. Book a demo and walk through the federal environment with your firm's CMMC practice in mind, or reach out to your Fieldguide account team.

Angela Han
Senior Product Manager


