The Department of Defense’s (DoD) Cybersecurity Maturity Model Certification (CMMC 2.0) framework requires prime contractors, subcontractors, and communication service providers (CSPs) across the Defense Industrial Base (DIB) to meet strict cybersecurity standards. Beyond physical hardware, organizations must secure every layer of their network stack, including the software platforms that provision, bill, and manage network connections.

What is CMMC 2.0?

The Cybersecurity Maturity Model Certification was established by the Department of Defense to safeguard sensitive federal information across the Defense Industrial Base. Evolving from the original CMMC 1.0 framework, CMMC 2.0 streamlines maturity levels and directly aligns cybersecurity requirements with National Institute of Standards and Technology guidelines, specifically NIST SP 800-171 and NIST SP 800-172.

It enforces compliance through DFARS clauses (such as DFARS 252.204-7012) and 48 CFR regulations, requiring contractors to upload scores to the Supplier Performance Risk System (SPRS).

CMMC 2.0 is structured into three distinct compliance levels:

  • Level 1: Applies to companies handling Federal Contract Information (FCI) governed by FAR 52.204-21. Requires basic cyber hygiene across 17 security controls verified through an annual self-assessment.
  • Level 2: Applies to defense contractors handling Controlled Unclassified Information (CUI). Enforces all 110 NIST SP 800-171 security controls. For prioritized programs handling critical CUI, a third-party assessment conducted by a Certified Third-Party Assessment Organization (C3PAO) is mandatory to achieve third-party certification.
  • Level 3: Designed for the highest-priority national security programs handling CUI. Requires advanced controls from NIST SP 800-172 and direct government-led audits by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC).

For telecommunications carriers, prime contractors, and subcontractors bidding on DoD solicitations, achieving CMMC 2.0 compliance is essential to managing cellular contract line items (CLINs) and federal subscriber data without risking contract loss.

Unlock lightning-fast 5G internet almost anywhere

Why CMMC 2.0 compliance matters for federal 5G networks

As federal field operations, tactical units, and defense contractors replace legacy wireline links with cellular 5G and LEO satellite solutions, the attack surface expands. Wireless endpoints and subscriber platforms introduce unique risks that require a comprehensive System Security Plan (SSP) and proactive risk assessment:

  1. Protecting Controlled Unclassified Information (CUI): Telemetry, subscriber hierarchies, network configurations, and billing data tied to military bases or research labs fall under CUI protections. Unsecured subscriber management platforms expose contractors to regulatory enforcement, mandatory Plan of Action and Milestones (POA&M) remediations, or disqualification from DoD awards.
  2. Supply chain integrity: Federal mandates (including NDAA Section 889) restrict reliance on foreign telecommunications gear and unvetted SaaS platforms. Agencies demand fully compliant U.S.-developed software and hardware.
  3. Managing CMMC certification cost and complexity: Performing a readiness assessment, undergoing a security assessment, and building a custom, compliant Business Support System (BSS) from scratch can push CMMC certification cost into millions of dollars. CSPs and contractors need turnkey, certified solutions to satisfy DoD cybersecurity standards immediately.

What Inseego Subscribe does to achieve CMMC 2.0 compliance

In July 2026, Inseego Subscribe achieved official CMMC 2.0 certification (Level 2), validating its complete implementation of all 110 cmmc controls specified in NIST SP 800-171.

To meet these stringent DoD requirements, the Inseego Subscribe platform satisfies controls across all key security domains:

  • Isolated federal infrastructure: Operates on AWS GovCloud, restricting platform hosting to U.S. soil and credentialed U.S. citizens to safeguard fci and cui under strict media protection policies.
  • FIPS 140-3 validated encryption: Enforces cryptographic safeguards for data-at-rest and data-in-transit, satisfying system and communications protection as well as system and information integrity requirements to protect subscriber profiles and provisioning feeds.
  • Granular access controls & MFA: Enforces strict Identity and Access Management (IAM) policies with mandatory multi-factor authentication (MFA), role-based access control, and session timeouts. Operations are backed by ongoing team awareness training to prevent unauthorized administrative changes.
  • Continuous system auditing & incident response: Maintains centralized, tamper-evident audit logs and automated monitoring to satisfy continuous visibility, incident response, and rapid forensic logging mandates.
  • Automated federal billing & CLIN mapping: Integrates native capabilities for mapping complex Federal Acquisition Regulation (FAR) billing structures directly into a compliant SaaS billing engine, satisfying configuration management and operational maintenance controls without relying on unverified third-party tools.

The complete end-to-end solution: Hardware to cloud

Software compliance is only one piece of the puzzle. An enterprise-grade federal 5G deployment requires complete alignment across the physical router, the cloud management console, and the subscriber platform.

Inseego bridges this gap with an integrated, U.S.-designed ecosystem across three core pillars:

  • Inseego Subscribe (SaaS BSS Platform): Delivers CMMC Level 2-certified subscriber lifecycle management, subscriber billing, and CLIN tracking hosted securely on AWS GovCloud with FIPS 140-3 encryption.
  • Inseego Connect (Cloud Fleet Management): Provides centralized device telemetry, remote configuration controls, zero-touch provisioning, and custom APN routing within secure cloud environments.
  • Inseego wireless hardware: Delivers U.S.-designed, TAA-compliant endpoints, such as the Wavemaker FX4200 FWA cellular routers and MiFi PRO M4 mobile hotspots, built with enterprise VPN, WPA3 encryption, and cellular IP passthrough.

By pairing TAA-compliant 5G hardware with Inseego Subscribe on AWS GovCloud, defense agencies, prime contractors, and telecom partners gain a complete, fully compliant wireless network architecture.

Accelerate your federal 5G deployments

Navigating CMMC 2.0 requirements does not have to delay your wireless WAN initiatives. With Inseego Subscribe's Level 2 certification, defense contractors and telecom carriers can deploy federal 5G services with confidence.

Learn more about Inseego Subscribe