Zero Trust Architecture under CMMC 2.0

Compliance-aligned zero trust architecture meeting CMMC 2.0 requirements

Overview

JaMaxwell implements zero trust architectures aligned with NIST SP 800-207 and OMB M-22-09 requirements. We design and deploy identity-centric access controls, micro-segmentation, continuous authentication, encrypted communications between all endpoints, and real-time threat detection. Implementations integrate with existing agency identity providers, PIV/CAC infrastructure, and ICAM platforms.

CMMC 2.0 Requirements

CMMC 2.0 (Cybersecurity Maturity Model Certification) establishes cybersecurity requirements for the Defense Industrial Base. Level 1 requires 17 practices based on FAR 52.204-21. Level 2 requires 110 practices aligned with NIST SP 800-171 Rev 2, protecting Controlled Unclassified Information (CUI). Level 3 requires additional controls from NIST SP 800-172 for critical programs. JaMaxwell helps defense contractors assess their current maturity, remediate gaps, prepare documentation for C3PAO assessments, and maintain ongoing compliance.

Why JaMaxwell

  • SBA-certified Woman-Owned Small Business (WOSB)
  • Primary NAICS: 541512 (Computer Systems Design Services)
  • Security-cleared staff with active federal engagements
  • Headquartered in Fairfax, VA, 20 miles from the Pentagon
  • Demonstrated CMMC 2.0 assessment and implementation capability

Technologies

ZscalerPalo Alto PrismaOktaAzure ADCrowdStrike