CMMC Level 2 WiFi Without Shared Passwords
802.1X, EAP-TLS certificates and RADIUS accounting for contractors handling CUI. Built so the wireless practices in NIST SP 800-171 Rev. 2 are implemented, documented in your SSP, and evidenced on demand. CMMC certifies your organization; IronWiFi covers the wireless half of the file.
CMMC Level 2 maps one-to-one to NIST SP 800-171 Rev. 2, which requires defense contractors to authorize wireless access (AC.L2-3.1.16), protect it with authentication and encryption (AC.L2-3.1.17), apply multi-factor authentication to network access (IA.L2-3.5.3), and retain audit records of who connected. IronWiFi provides the cloud RADIUS, EAP-TLS certificates, MFA integration and authentication logging that implement those practices, along with the evidence an assessor asks for. CMMC certification is held by the contractor, not by a SaaS vendor.
What IronWiFi Is, and What It Is Not
The same rule we apply to our FedRAMP status: state what is true, and state plainly what is not being claimed
Not a vendor badge
Customer Status
IronWiFi is not CMMC certified and holds no CMMC assessment of its own. CMMC Level 2 certifies the organization that handles CUI, so the status belongs to your company, not to a service provider in your supply chain. Any vendor selling you a CMMC badge is selling you a finding.
NIST SP 800-171 wireless practices
Controls Mapped
What we do provide is the wireless authentication, certificate lifecycle, MFA integration and RADIUS accounting that implement the 800-171 practices in your scope, and the records that evidence them. The mapping table below names each practice and what stays your responsibility.
Independent assurance we do hold
Attested
SOC 2 Type II, unqualified opinion, issued 7 May 2026 by Johanson Group LLP and renewed annually. Listed in the FedRAMP Marketplace under ID FR2631154499 in the Initial Implementation Phase since 12 August 2026. The offering is not FedRAMP Authorized or Certified today. See our published FedRAMP data.
Who This Is For
Organizations whose contracts already carry DFARS 252.204-7012
Primes and large subs
Multi-site contractors who need one wireless story across every facility in scope, and a single console that produces the connection records per site
Small subcontractors on a flat network
Shops running one shared WPA2 password for everyone. This is the most commonly failed practice in the whole wireless section, and the cheapest one to fix
MSPs and consultants supporting the DIB
Providers standing up CUI networks for multiple clients, who need per-tenant isolation and per-client evidence rather than one shared configuration
What CMMC Actually Requires From Your WiFi
The certification checkpoint moved. The contract clauses behind it did not.
On the current status. The Department of War suspended CMMC Phase 2 on 13 July 2026, pausing the stage that would have written third-party assessment requirements into new contracts. What was suspended is the checkpoint where somebody verifies your security. DFARS 252.204-7012 still requires the NIST SP 800-171 safeguards as a condition of contracts you have already signed, DFARS 252.204-7019 and -7020 still require a current self-assessment score in SPRS, and Phase 1 self-assessment requirements remain in effect. A posted SPRS score is a representation to the federal government, so a wireless gap is still a live exposure. We wrote this up in full in CMMC Phase 2 Is Suspended. Your WiFi Requirements Aren't.
The two practices that name wireless. AC.L2-3.1.16 requires you to authorize wireless access before allowing the connection, which means every SSID exists on purpose and is listed in your system security plan. AC.L2-3.1.17 requires you to protect wireless access using authentication and encryption. A shared WPA2 password encrypts the traffic but authenticates nobody in particular, which is where the classic small-contractor setup fails. Assessment guidance points to 802.1X, where each user or device presents its own credential against a RADIUS server.
Reference Architecture: Three SSIDs
Scope is the cheapest control you own. Segmentation keeps the lobby network out of your assessment entirely.
Staff and CUI devices
WPA2/WPA3-Enterprise · EAP-TLS
In scope. Every device carries its own certificate, so access follows the directory and there is no shared secret to inherit.
Privileged and admin
MFA via Entra ID, Okta or PIV/CAC
In scope, with the second factor enforced in your identity provider and RADIUS device-admin login for the network gear itself.
Guest
Isolated VLAN · internet only
Out of scope, provided the isolation is real. Captive portal login, no route to anything that stores or transmits CUI.
No pre-shared key on a CUI SSID
Certificates issued by cloud PKI and enrolled over SCEP, so there is no password to share and no credential to rotate when someone leaves. Disabling the account in your directory cuts network access the same minute.
Guest and public SSIDs stay outside the CUI boundary
Its own SSID and VLAN, routed straight to the internet, provably unable to reach anything that stores or transmits CUI. Done properly, the guest network leaves your assessment scope.
Every connection lands in an audit record
RADIUS authentication and accounting logs who connected, when, from which device, through which access point. Exportable to Splunk, Elastic or your SIEM by webhook and syslog.
Vendor-neutral, across 200+ wireless vendors
Keep the access points you have. IronWiFi supplies the authentication, policy and monitoring layer; nothing on the CUI network needs replacing to move off a shared password.
Wireless Control Mapping for Your SSP
What an assessor looks for, what IronWiFi provides, and what stays yours. Nothing in the right-hand column is something we can do for you.
| Practice | What assessors look for | What IronWiFi provides | What you still own |
|---|---|---|---|
| AC.L2-3.1.16 | Wireless access authorized before connection, and documented | Named SSIDs and network policies, per-tenant configuration, admin RBAC over who can change them | The SSP list of every SSID, its purpose, and who authorizes access |
| AC.L2-3.1.17 | Wireless protected by authentication and encryption | 802.1X with EAP-TLS, WPA2/WPA3-Enterprise, RadSec for RADIUS over TLS | Access point configuration, and no pre-shared key left on a CUI SSID |
| IA.L2-3.5.3 | Multi-factor authentication for network access | Integration with your IdP's MFA, certificate-based access, PIV/CAC support | Enforcing the MFA policy in the identity provider itself |
| IA.L2-3.5.4 | Replay-resistant authentication mechanisms | EAP-TLS, which is replay-resistant by construction | Certificate lifecycle policy: issuance, renewal, revocation |
| AU family (3.3.x) | Records of who connected, when, and from where | RADIUS authentication and accounting records, on-demand reports, SIEM export by webhook and syslog | Retention period, log review process, and ownership of the SIEM |
| SC.L2-3.13.8 | Cryptographic protection of information in transit | TLS 1.2/1.3 in transit and AES-256 at rest, using FIPS-validated modules; no plaintext credential traverses the network | FIPS module selection on the access point side, and your own crypto policy |
This mapping covers the wireless and identity practices only. It is not an assessment, and it is not a claim that IronWiFi satisfies any practice on your behalf. Your assessor scopes your system, not ours. Our SSP wireless section template turns this table into the paragraphs and evidence list your plan needs, free and without a form. The shared-responsibility matrix takes each practice above and says who performs which half, and no row is inherited from us.
FedRAMP and CMMC Are Different Questions
They get conflated constantly, and the difference decides whether CUI may traverse the service at all
CMMC applies to your organization
It certifies that the contractor handling CUI has implemented NIST SP 800-171. No SaaS vendor can hold it for you, and no vendor's certificate transfers into your scope.
FedRAMP applies to the cloud service
DFARS 252.204-7012(b)(2) is the clause that governs whether a cloud service may store, process or transmit covered defense information. That is a question about us, and we answer it in public on our FedRAMP page: Initial Implementation Phase, ID FR2631154499, not authorized today.
Where that leaves most contractors today
Plenty of DIB networks run IronWiFi on staff and guest wireless outside the CUI boundary while the FedRAMP question is settled. If CUI itself would traverse the service, raise it with your ISSO and contracting officer first and we will support the review with what we have published.
How to Buy
Contractors and integrators buy on commercial terms. The fixed-price federal pilot is for agencies buying directly. Which one applies follows the service boundary, not the end customer.
Contractors and Subs: Commercial Terms
A DIB contractor securing its own CUI network buys the standard commercial plan: employee and device 802.1X at $5 per user per month billed annually ($6.50 monthly), or guest WiFi at $10 per access point per month billed annually ($13 monthly), $65 per month per venue minimum. An 80-user CUI SSID is $4,800 a year. Volume discounts apply at scale, and there is a free trial before any of it.
Marketplaces & Contract Vehicles
SAM.gov Active (UEI TB1XW4HNNUG9, CAGE issued). Listed on the AWS, Cisco, and Oracle marketplaces. SEWP and OMNIA available through an approved federal reseller on named opportunities. Section 889 compliant service. Contractors buying commercially transact on standard commercial terms.
Federal Pilot, Under the Micro-Purchase Threshold
For federal, state and local agencies buying directly. $14,400 fixed for 12 months, one site: up to 80 users on 802.1X, or up to 40 access points on guest WiFi. Includes EAP-TLS / 802.1X and RADIUS device-admin login, Entra ID, Okta or Google Workspace integration, certificate enrollment, onboarding, standard support, and a 120-day WiFi ITDR evaluation for up to 1,000 identities. Below the $15,000 federal micro-purchase threshold (FAR 2.101). Ships with the SOC 2 Type II report and our FedRAMP public certification data for your ISSO or CMMC lead. One pilot per agency.
Request the pilot · Download the capability statement (PDF) · Full government pricing
Evidence Pack for Your Assessor
Start with the free SSP wireless section template: SSID inventory, a statement per practice, and the evidence to attach to each. No form. The shared-responsibility matrix is free too. On request we add the SOC 2 Type II report under NDA.
Questions From CMMC Leads
What CMMC leads and their assessors ask first
Is IronWiFi CMMC certified?
No. CMMC Level 2 is an organizational status for the company that handles CUI, and third-party certification under Phase 2 has been suspended since 13 July 2026 in any case. IronWiFi maps the WiFi-relevant NIST SP 800-171 practices and can sit inside a customer's shared-responsibility model as a service provider. We are not a C3PAO-assessed organization, and no vendor certificate transfers into your scope.
Can we put CUI through IronWiFi?
Only if your contract and your assessor accept the cloud path. DFARS 252.204-7012 requires a cloud service that stores, processes or transmits covered defense information to meet FedRAMP Moderate or a documented equivalency determination, and IronWiFi is in the FedRAMP Marketplace Initial Implementation Phase rather than authorized today. Guest and public SSIDs stay outside the CUI boundary. Staff and device 802.1X on a CUI network must be scoped, logged and isolated, so raise the cloud question with your ISSO before you assume either answer.
What evidence can we hand an assessor?
RADIUS authentication and accounting records showing who connected, when, from which device and through which access point, exportable on demand or streamed to your SIEM. Plus the SSID and policy configuration that documents how wireless access is authorized, and the certificate enrollment records behind EAP-TLS.
Does the Phase 2 suspension mean we can wait?
The clauses in your existing contracts did not pause, and a self-assessment score posted in SPRS is a representation to the federal government. When certification requirements return, the queue will be roughly 120,000 contractors against about 100 approved assessment organizations, so the companies that closed gaps during the pause are the ones that walk in ready.
Related Reading
Defense and CMMC resources
CMMC Phase 2 Is Suspended. Your WiFi Requirements Aren't.
What the July 2026 memoranda changed, what they did not, and the wireless practices still in force.
Federal WiFi Authentication Compliance in 2026
The wider federal picture: 800-171, FedRAMP, CJIS and what each one actually asks of wireless.
Zero Trust WiFi
Certificates, MFA and CoA quarantine, and how they map to the identification and access control families.
SCEP Certificate Enrollment
How EAP-TLS certificates get issued and renewed without anyone touching a device.
Government & Public Sector
Agency-side frameworks, procurement vehicles and the full government rate card.
Shared Responsibility Matrix
Practice by practice: what we perform, what stays yours, and the evidence each side produces.
SSP Wireless Section Template
Fill-in-the-blanks structure for the wireless part of your System Security Plan, with the evidence list.
Security & Compliance
Certifications, data residency, audit trail and the agreements available for regulated industries.
Close the Wireless Gap Before the Checkpoint Returns
Per-user 802.1X, certificates instead of shared passwords, segmented guest WiFi, and the authentication records your SSP points to. Start on a trial, or tell us your sites and we'll scope it.
