Defense Industrial Base

CMMC Level 2 WiFi Without Shared Passwords

802.1X, EAP-TLS certificates and RADIUS accounting for contractors handling CUI. Built so the wireless practices in NIST SP 800-171 Rev. 2 are implemented, documented in your SSP, and evidenced on demand. CMMC certifies your organization; IronWiFi covers the wireless half of the file.

SOC 2 Type II Attested · FedRAMP Marketplace FR2631154499 · SAM.gov Active

CMMC Level 2 maps one-to-one to NIST SP 800-171 Rev. 2, which requires defense contractors to authorize wireless access (AC.L2-3.1.16), protect it with authentication and encryption (AC.L2-3.1.17), apply multi-factor authentication to network access (IA.L2-3.5.3), and retain audit records of who connected. IronWiFi provides the cloud RADIUS, EAP-TLS certificates, MFA integration and authentication logging that implement those practices, along with the evidence an assessor asks for. CMMC certification is held by the contractor, not by a SaaS vendor.

What IronWiFi Is, and What It Is Not

The same rule we apply to our FedRAMP status: state what is true, and state plainly what is not being claimed

Not a vendor badge

Customer Status

IronWiFi is not CMMC certified and holds no CMMC assessment of its own. CMMC Level 2 certifies the organization that handles CUI, so the status belongs to your company, not to a service provider in your supply chain. Any vendor selling you a CMMC badge is selling you a finding.

NIST SP 800-171 wireless practices

Controls Mapped

What we do provide is the wireless authentication, certificate lifecycle, MFA integration and RADIUS accounting that implement the 800-171 practices in your scope, and the records that evidence them. The mapping table below names each practice and what stays your responsibility.

Independent assurance we do hold

Attested

SOC 2 Type II, unqualified opinion, issued 7 May 2026 by Johanson Group LLP and renewed annually. Listed in the FedRAMP Marketplace under ID FR2631154499 in the Initial Implementation Phase since 12 August 2026. The offering is not FedRAMP Authorized or Certified today. See our published FedRAMP data.

Who This Is For

Organizations whose contracts already carry DFARS 252.204-7012

Primes and large subs

Multi-site contractors who need one wireless story across every facility in scope, and a single console that produces the connection records per site

Small subcontractors on a flat network

Shops running one shared WPA2 password for everyone. This is the most commonly failed practice in the whole wireless section, and the cheapest one to fix

MSPs and consultants supporting the DIB

Providers standing up CUI networks for multiple clients, who need per-tenant isolation and per-client evidence rather than one shared configuration

What CMMC Actually Requires From Your WiFi

The certification checkpoint moved. The contract clauses behind it did not.

On the current status. The Department of War suspended CMMC Phase 2 on 13 July 2026, pausing the stage that would have written third-party assessment requirements into new contracts. What was suspended is the checkpoint where somebody verifies your security. DFARS 252.204-7012 still requires the NIST SP 800-171 safeguards as a condition of contracts you have already signed, DFARS 252.204-7019 and -7020 still require a current self-assessment score in SPRS, and Phase 1 self-assessment requirements remain in effect. A posted SPRS score is a representation to the federal government, so a wireless gap is still a live exposure. We wrote this up in full in CMMC Phase 2 Is Suspended. Your WiFi Requirements Aren't.

The two practices that name wireless. AC.L2-3.1.16 requires you to authorize wireless access before allowing the connection, which means every SSID exists on purpose and is listed in your system security plan. AC.L2-3.1.17 requires you to protect wireless access using authentication and encryption. A shared WPA2 password encrypts the traffic but authenticates nobody in particular, which is where the classic small-contractor setup fails. Assessment guidance points to 802.1X, where each user or device presents its own credential against a RADIUS server.

Reference Architecture: Three SSIDs

Scope is the cheapest control you own. Segmentation keeps the lobby network out of your assessment entirely.

Staff and CUI devices

WPA2/WPA3-Enterprise · EAP-TLS

In scope. Every device carries its own certificate, so access follows the directory and there is no shared secret to inherit.

Privileged and admin

MFA via Entra ID, Okta or PIV/CAC

In scope, with the second factor enforced in your identity provider and RADIUS device-admin login for the network gear itself.

Guest

Isolated VLAN · internet only

Out of scope, provided the isolation is real. Captive portal login, no route to anything that stores or transmits CUI.

No pre-shared key on a CUI SSID

Certificates issued by cloud PKI and enrolled over SCEP, so there is no password to share and no credential to rotate when someone leaves. Disabling the account in your directory cuts network access the same minute.

Guest and public SSIDs stay outside the CUI boundary

Its own SSID and VLAN, routed straight to the internet, provably unable to reach anything that stores or transmits CUI. Done properly, the guest network leaves your assessment scope.

Every connection lands in an audit record

RADIUS authentication and accounting logs who connected, when, from which device, through which access point. Exportable to Splunk, Elastic or your SIEM by webhook and syslog.

Vendor-neutral, across 200+ wireless vendors

Keep the access points you have. IronWiFi supplies the authentication, policy and monitoring layer; nothing on the CUI network needs replacing to move off a shared password.

Wireless Control Mapping for Your SSP

What an assessor looks for, what IronWiFi provides, and what stays yours. Nothing in the right-hand column is something we can do for you.

CMMC Level 2 practices, per NIST SP 800-171 Rev. 2, that bear on wireless access
PracticeWhat assessors look forWhat IronWiFi providesWhat you still own
AC.L2-3.1.16 Wireless access authorized before connection, and documented Named SSIDs and network policies, per-tenant configuration, admin RBAC over who can change them The SSP list of every SSID, its purpose, and who authorizes access
AC.L2-3.1.17 Wireless protected by authentication and encryption 802.1X with EAP-TLS, WPA2/WPA3-Enterprise, RadSec for RADIUS over TLS Access point configuration, and no pre-shared key left on a CUI SSID
IA.L2-3.5.3 Multi-factor authentication for network access Integration with your IdP's MFA, certificate-based access, PIV/CAC support Enforcing the MFA policy in the identity provider itself
IA.L2-3.5.4 Replay-resistant authentication mechanisms EAP-TLS, which is replay-resistant by construction Certificate lifecycle policy: issuance, renewal, revocation
AU family (3.3.x) Records of who connected, when, and from where RADIUS authentication and accounting records, on-demand reports, SIEM export by webhook and syslog Retention period, log review process, and ownership of the SIEM
SC.L2-3.13.8 Cryptographic protection of information in transit TLS 1.2/1.3 in transit and AES-256 at rest, using FIPS-validated modules; no plaintext credential traverses the network FIPS module selection on the access point side, and your own crypto policy

This mapping covers the wireless and identity practices only. It is not an assessment, and it is not a claim that IronWiFi satisfies any practice on your behalf. Your assessor scopes your system, not ours. Our SSP wireless section template turns this table into the paragraphs and evidence list your plan needs, free and without a form. The shared-responsibility matrix takes each practice above and says who performs which half, and no row is inherited from us.

FedRAMP and CMMC Are Different Questions

They get conflated constantly, and the difference decides whether CUI may traverse the service at all

CMMC applies to your organization

It certifies that the contractor handling CUI has implemented NIST SP 800-171. No SaaS vendor can hold it for you, and no vendor's certificate transfers into your scope.

FedRAMP applies to the cloud service

DFARS 252.204-7012(b)(2) is the clause that governs whether a cloud service may store, process or transmit covered defense information. That is a question about us, and we answer it in public on our FedRAMP page: Initial Implementation Phase, ID FR2631154499, not authorized today.

Where that leaves most contractors today

Plenty of DIB networks run IronWiFi on staff and guest wireless outside the CUI boundary while the FedRAMP question is settled. If CUI itself would traverse the service, raise it with your ISSO and contracting officer first and we will support the review with what we have published.

How to Buy

Contractors and integrators buy on commercial terms. The fixed-price federal pilot is for agencies buying directly. Which one applies follows the service boundary, not the end customer.

Contractors and Subs: Commercial Terms

A DIB contractor securing its own CUI network buys the standard commercial plan: employee and device 802.1X at $5 per user per month billed annually ($6.50 monthly), or guest WiFi at $10 per access point per month billed annually ($13 monthly), $65 per month per venue minimum. An 80-user CUI SSID is $4,800 a year. Volume discounts apply at scale, and there is a free trial before any of it.

Full pricing and the calculator · Start a trial

Marketplaces & Contract Vehicles

SAM.gov Active (UEI TB1XW4HNNUG9, CAGE issued). Listed on the AWS, Cisco, and Oracle marketplaces. SEWP and OMNIA available through an approved federal reseller on named opportunities. Section 889 compliant service. Contractors buying commercially transact on standard commercial terms.

Federal Pilot, Under the Micro-Purchase Threshold

For federal, state and local agencies buying directly. $14,400 fixed for 12 months, one site: up to 80 users on 802.1X, or up to 40 access points on guest WiFi. Includes EAP-TLS / 802.1X and RADIUS device-admin login, Entra ID, Okta or Google Workspace integration, certificate enrollment, onboarding, standard support, and a 120-day WiFi ITDR evaluation for up to 1,000 identities. Below the $15,000 federal micro-purchase threshold (FAR 2.101). Ships with the SOC 2 Type II report and our FedRAMP public certification data for your ISSO or CMMC lead. One pilot per agency.

Request the pilot · Download the capability statement (PDF) · Full government pricing

Evidence Pack for Your Assessor

Start with the free SSP wireless section template: SSID inventory, a statement per practice, and the evidence to attach to each. No form. The shared-responsibility matrix is free too. On request we add the SOC 2 Type II report under NDA.

Questions From CMMC Leads

What CMMC leads and their assessors ask first

Is IronWiFi CMMC certified?

No. CMMC Level 2 is an organizational status for the company that handles CUI, and third-party certification under Phase 2 has been suspended since 13 July 2026 in any case. IronWiFi maps the WiFi-relevant NIST SP 800-171 practices and can sit inside a customer's shared-responsibility model as a service provider. We are not a C3PAO-assessed organization, and no vendor certificate transfers into your scope.

Can we put CUI through IronWiFi?

Only if your contract and your assessor accept the cloud path. DFARS 252.204-7012 requires a cloud service that stores, processes or transmits covered defense information to meet FedRAMP Moderate or a documented equivalency determination, and IronWiFi is in the FedRAMP Marketplace Initial Implementation Phase rather than authorized today. Guest and public SSIDs stay outside the CUI boundary. Staff and device 802.1X on a CUI network must be scoped, logged and isolated, so raise the cloud question with your ISSO before you assume either answer.

What evidence can we hand an assessor?

RADIUS authentication and accounting records showing who connected, when, from which device and through which access point, exportable on demand or streamed to your SIEM. Plus the SSID and policy configuration that documents how wireless access is authorized, and the certificate enrollment records behind EAP-TLS.

Does the Phase 2 suspension mean we can wait?

The clauses in your existing contracts did not pause, and a self-assessment score posted in SPRS is a representation to the federal government. When certification requirements return, the queue will be roughly 120,000 contractors against about 100 approved assessment organizations, so the companies that closed gaps during the pause are the ones that walk in ready.

Related Reading

Defense and CMMC resources

CMMC Phase 2 Is Suspended. Your WiFi Requirements Aren't.

What the July 2026 memoranda changed, what they did not, and the wireless practices still in force.

Federal WiFi Authentication Compliance in 2026

The wider federal picture: 800-171, FedRAMP, CJIS and what each one actually asks of wireless.

Zero Trust WiFi

Certificates, MFA and CoA quarantine, and how they map to the identification and access control families.

SCEP Certificate Enrollment

How EAP-TLS certificates get issued and renewed without anyone touching a device.

Government & Public Sector

Agency-side frameworks, procurement vehicles and the full government rate card.

Shared Responsibility Matrix

Practice by practice: what we perform, what stays yours, and the evidence each side produces.

SSP Wireless Section Template

Fill-in-the-blanks structure for the wireless part of your System Security Plan, with the evidence list.

Security & Compliance

Certifications, data residency, audit trail and the agreements available for regulated industries.

Close the Wireless Gap Before the Checkpoint Returns

Per-user 802.1X, certificates instead of shared passwords, segmented guest WiFi, and the authentication records your SSP points to. Start on a trial, or tell us your sites and we'll scope it.