By The Defense Compliance Report Editorial Team Last reviewed: August 2026 · Last verified: August 25, 2026 Evidence depth: Public-document review — not a hands-on product test, customer-interview review, or paid engagement.
Home → CMMC Provider Reviews → Arctic Wolf CMMC Review
Arctic Wolf MDR is not CMMC certification, CMMC readiness consulting, or a compliant place to store CUI. It is a managed detection and response service — outsourced 24/7 security monitoring. For many defense contractors at CMMC Level 2, it can sit inside the compliance architecture without breaking it. But there is a condition, and it is not in the sales deck. It is in the data flow and, for Microsoft GCC and GCC High monitoring, in Arctic Wolf's own contract.
This Arctic Wolf CMMC review is built from Arctic Wolf's current Aurora MDR Supplemental Product Terms (version 2026.08), its subprocessor list (updated July 30, 2026), its public AWS Marketplace listing, 32 CFR Part 170, current DFARS clauses, NIST publications, the DoD Level 2 Scoping Guide, and the Cyber AB assessment process. We read the source language, not just the vendor summaries.
Here is the short version, and then the condition that decides everything.
Arctic Wolf CMMC review verdict: is it a Level 2 fit?
Arctic Wolf MDR can be a legitimate component of a CMMC Level 2 environment, but it is not a CMMC solution and it cannot certify you. Under 32 CFR § 170.19(c), an MDR service on which Security Protection Data resides — logs, alerts, configuration data, vulnerability findings — is inside the assessment scope and assessed as a Security Protection Asset against the Level 2 requirements relevant to the capabilities it provides.
That is workable. The condition is whether CUI ever reaches the service, whether Arctic Wolf is acting as a Cloud Service Provider for that data path, and which contract terms govern the deployment.
For Microsoft GCC and GCC High monitoring specifically, § 4 of Arctic Wolf's current 2026.08 terms says Arctic Wolf is not FedRAMP compliant, Solutions Data may be accessed outside the United States and by non-U.S. citizens, and Arctic Wolf may immediately stop ingesting Solutions Data if CUI is provided. Those clauses are strong evidence, but the section heading and opening sentence expressly limit them to GCC and GCC High monitoring. They cannot be published as universal terms for every Arctic Wolf deployment.
So the answer is conditional, and the condition is a data-flow and contract question you can actually test.
The 30-second decision table
| Shortlist it | Shortlist it only after written answers | Choose a different category first |
|---|---|---|
| You need continuous monitoring you cannot staff internally | Logs may carry CUI in filenames, subjects, alert bodies, or attachments | You need someone to build your SSP, POA&M, policies, and evidence program |
| Someone else already owns your CMMC program | You run Microsoft GCC or GCC High and depend on specific connectors | You need a place to store or isolate CUI |
| You can demonstrate that CUI stays out of the telemetry | Contract, flowdown, or export-control terms may require U.S.-persons-only access | You need the formal Level 2 certification assessment |
| You can contract for retention, evidence export, and assessor support | You need more than the included 90 days of searchable history | Nobody owns scope, remediation, or annual affirmation |
Where Arctic Wolf lands, by your situation
| Your situation | CMMC treatment | What you must do |
|---|---|---|
| FCI only, Level 1 | Level 1 scope turns on whether people, technology, facilities, or ESPs process, store, or transmit FCI. SPD and Table 4 are Level 2 concepts. | Determine whether the service receives FCI. FedRAMP is not a CMMC Level 1 requirement. |
| Level 2, CUI exists, MDR receives only SPD | The service is in scope and assessed as a Security Protection Asset. | Document the service, data flow, responsibilities, and evidence. |
| Level 2, CUI reaches the MDR | If the provider is a CSP, the FedRAMP requirements in DFARS 252.204-7012 apply. If it is not a CSP, the service is assessed as part of your assessment. | Stop treating this as an ordinary MDR purchase. Classify the provider and re-architect if the required conditions cannot be met. |
| Level 3 | Security Protection Assets remain in scope. Level 3 adds 24 selected requirements from the February 2021 edition of NIST SP 800-172 after Final Level 2 (C3PAO) status for the same or a subset scope. | Do not infer Level 3 suitability from a Level 2 MDR map. Current procurement designations requiring Level 3 are suspended with Phase II. |
What we actually verified
Service category reviewed: Managed detection and response (MDR) / managed security service provider (MSSP). The service reviewed is not a readiness engagement, CUI-hosting environment, or CMMC certification assessment.
Marketplace-status rule: We do not turn an unsuccessful name search into a claim that a legal entity has no Cyber AB or FedRAMP status. Verify the exact entity and exact service in the live Cyber AB Marketplace and FedRAMP Marketplace.
Services reviewed: Aurora Managed Detection and Response, Aurora Vulnerability Management, Security Awareness & Training / Managed Security Awareness, Aurora Endpoint Security, Incident Response, and the Incident360 Retainer.
Evaluation depth: Public-document review. We did not deploy the product, interview Arctic Wolf, receive product access, or review a signed Order Form. Arctic Wolf did not review this page.
Commercial relationship on this page: This article contains no Arctic Wolf referral link or Arctic Wolf sponsored placement.
What we could not verify: A customer-specific responsibility matrix, signed Order Form, data-flow diagram, exact Marketplace status for a hypothetical contracting entity and service, or typical scope-normalized defense-contractor pricing beyond the public AWS listing.
Last verified: August 25, 2026.
Disclosure: The Defense Compliance Report is an independent trade publication on CMMC and Defense Industrial Base compliance. We may receive compensation for qualified introductions, sponsorships, or provider referrals when disclosed. Compensation does not control our regulatory analysis or provider-category recommendations. See our Editorial & Advertising Policy and Editorial Standards.
Not affiliated: The Defense Compliance Report is not affiliated with Arctic Wolf, the Cyber AB, DoD/DoW, DCMA DIBCAC, NIST, or any U.S. government agency. This is educational research, not legal, contractual, export-control, or compliance advice. Confirm scope and applicability with a qualified CMMC advisor and, where contract or export-control terms are involved, qualified counsel.
What did we verify—and what did we not test?
We have never deployed Arctic Wolf. We have no relationship with the company, we have never seen a signed Arctic Wolf Order Form, and nobody at Arctic Wolf reviewed a word of this page. If you were hoping for a hands-on review from someone who ran the console for six months, that is not what this is, and we would rather tell you now than let you find out in paragraph forty.
Here is why we think that limitation is actually the point.
Everything in this review comes from public documents you can open yourself. Which means you do not have to trust us. You can check us. And more usefully: these are the records a certification assessment tests — service description, customer responsibility matrix, data flow, contract commitments, evidence exports, and the people who can explain what the provider does.
The Cyber AB CMMC Assessment Process, version 2.0, requires an in-scope ESP's CRM to be available for a Level 2 certification assessment and expects ESP personnel to participate when needed. Nobody is going to certify you because the dashboard felt good. They are going to test what the provider does, what you still do, and whether the evidence supports both stories.
One honest caveat: standard public terms can be overridden by a negotiated Solutions Agreement or Order Form. If your legal team negotiated custom language, your signed agreement governs — not the public version.
Which CMMC provider category do you actually need?
The category you need — C3PAO, RPO or Registered Practitioner, MSSP, GRC platform, or CUI enclave — depends on your required CMMC level, whether you handle FCI or CUI, assessment type, environment, and contract timeline. The solicitation, contract clause, or flowdown sets the required CMMC status; a generic checklist does not.
Use Find My CMMC Path to map your situation before requesting quotes, or start with our provider-category comparison and Who to Hire First guide. Do not submit CUI, drawings, credentials, system diagrams, or sensitive contract details.
Is Arctic Wolf CMMC certified?
No product called Arctic Wolf MDR can certify you, and SOC 2 or ISO 27001 status does not transfer to your assessed environment. Under 32 CFR § 170.19(c)(2)(ii), an ESP may voluntarily undergo a CMMC certification assessment to reduce effort during a customer's assessment. Even then, the provider's status does not certify the contractor. Your scope, evidence, score, status, and affirmation remain yours.
We did not verify a voluntary CMMC status for the exact Arctic Wolf entity and service involved in a hypothetical order. That is not proof none exists. Ask for the exact legal entity, assessed scope, status, and date, then verify them against the live Marketplace and delivered documents.
Arctic Wolf's own compliance page says its products and services are not compliance solutions, but tools that may support a compliance program. That is unusually honest. Take them at their word.
Two checks matter more than the logos:
- ISO edition and certificate. Arctic Wolf's compliance page still says “ISO 27001-2013.” Under IAF Mandatory Document 26, certifications based on ISO/IEC 27001:2013 could not remain valid after October 31, 2025. That does not prove Arctic Wolf lacks a current certificate; it proves the page label cannot establish one. Ask for the current certificate, edition, legal entity, scope, certification body, accreditation, and expiry.
- SOC 2 scope. Ask which systems, entity, period, and Trust Services Criteria the report covers, and whether the MDR components on your Order Form are inside the system boundary. The scope section is where the value is; the logo is not.
Where does Arctic Wolf land in CMMC assessment scope?
An MDR service on which Security Protection Data resides is not outside your assessment just because it never stores a CUI document. Under 32 CFR § 170.19(c)(1), a Security Protection Asset provides security functions or capabilities to the CMMC Assessment Scope. It must be documented in the asset inventory, SSP, and network diagram, and it is assessed against the Level 2 requirements relevant to the capabilities it provides.
The DoD CMMC Level 2 Scoping Guide uses a SIEM service as its worked example. MDR is not identical to SIEM, but the decision logic is the same: when logs or other SPD reside on the provider's assets, the service belongs in the scope analysis.
Table 4, translated
The CMMC definition of an ESP requires CUI or SPD to be processed, stored, or transmitted on the ESP's assets. Table 4 then separates the result by data type and whether the provider is a CSP.
| What the service processes, stores, or transmits | CSP | Not a CSP | MDR decision |
|---|---|---|---|
| CUI, with or without SPD | Must meet the FedRAMP requirements in DFARS 252.204-7012 | Service is in scope and assessed as part of the organization's assessment | Classify the provider and contract before relying on it. |
| SPD without CUI | In scope and assessed as a Security Protection Asset | In scope and assessed as a Security Protection Asset | Intended landing place for a properly bounded MDR deployment. |
| Neither CUI nor SPD | Not a CMMC ESP for that service | Not a CMMC ESP for that service | Unusual for MDR; confirm what is actually monitored and retained. |
Whether Arctic Wolf is a CSP makes no difference to the Table 4 result when the service receives SPD without CUI. The CSP question becomes decisive when CUI reaches the service.
The connecting-infrastructure rule, stated precisely
For a Level 2 self-assessment in which a CSP or non-CSP ESP is used to process, store, or transmit CUI, § 170.16(c)(2)(iii) and § 170.16(c)(3)(iii) put the organization's on-premises infrastructure connecting to that service in scope and require the CRM responsibilities to be documented or referred to in the SSP. The certification provisions contain the corresponding rule in § 170.17(c)(5)(iii) and § 170.17(c)(6)(iii).
That language is tied to the rule's CUI-processing provider scenarios. It does not make every cable and endpoint in scope merely because an MDR sensor exists. In an SPD-only design, categorize each local sensor, collector, agent, identity connection, firewall, and supporting asset under Table 3 according to what it actually does. Many will still be Security Protection Assets. The point is to use the rule's categories, not a slogan.
The Arctic Wolf terms ledger
Arctic Wolf's current public terms contain general MDR provisions and a separate § 4 that applies only when Arctic Wolf monitors applications in Microsoft GCC or GCC High. That limitation controls every finding below.
| Provision | What the public terms state | Applicability | Why it matters |
|---|---|---|---|
| § 1.1 | Unlimited data ingestion and 90-day log retention unless another period is purchased and written on the Order Form | General MDR | Searchable retention is a contract fact, not the CMMC artifact rule. |
| § 2.1 | Solutions Data includes logs, flow, HTTPS/TLS/DNS metadata, inventory, operating systems, AD users and groups, event data, and vulnerability data | General MDR | Shows where CUI can hitchhike into telemetry. |
| § 2.2 | Confidential Information is stored in third-party data centers specified by the Platform location on the Order Form | General MDR | Residency is an Order Form field. |
| § 3 | Confidential Information is destroyed after equipment return or within 120 days after expiration or termination, subject to law | General MDR | Evidence export is an exit requirement. |
| § 4 opening | §§ 4.1–4.7 apply to Microsoft GCC/GCC High monitoring | GCC/GCC High only | Prevents overgeneralizing the clauses below. |
| § 4.1 | “Arctic Wolf is not FedRAMP compliant.” | GCC/GCC High only | Material when CUI would reach a CSP service or government-cloud monitoring was assumed to imply FedRAMP. |
| § 4.2 | Only supported and integrated applications are monitored | GCC/GCC High only | Your enclave may have blind spots. |
| § 4.3 | Solutions Data may be accessed outside the U.S. and by non-U.S. citizens | GCC/GCC High only | Material for flowdown, program, and export-control analysis. |
| § 4.4 | Arctic Wolf does not require CUI and may immediately stop ingestion if CUI is provided | GCC/GCC High only | A CUI spill can create a monitoring gap. |
| § 4.5 | Reasonable cooperation for a breach involving Solutions Data | GCC/GCC High only | Cooperation is not acceptance of the contractor's DFARS duty. |
| § 4.6 | Some Microsoft log sources may be beta with no delivery representation | GCC/GCC High only | Do not build a control narrative on a beta connector. |
| § 4.7 | GCC monitoring stops if consent is withdrawn or changed | GCC/GCC High only | Consent changes need an operational owner and notification path. |
The AWS Marketplace listing shows “No security profile” in its security-credentials panel. That is AWS metadata, not a FedRAMP determination. Use the FedRAMP Marketplace and the exact legal entity, product, package, and authorization boundary for a real status check.
None of this makes Arctic Wolf a bad MDR. It makes Arctic Wolf a commercial MDR being evaluated against a regulated architecture where section headings, data types, and contract boundaries matter.
Map the vendor before you buy the vendor
Use the CMMC External Service Provider assessment guide to identify the Table 4 row and the documents you need before renewal.
→ Check the ESP scope and evidence requirements
Do not submit CUI, drawings, credentials, system diagrams, or contract details.
Can Arctic Wolf touch CUI?
For Microsoft GCC and GCC High monitoring, Arctic Wolf's current public terms state that it does not require access to or delivery of CUI and may immediately stop ingesting Solutions Data if CUI is provided. That is a contractual right in a GCC-specific section. It is not a universal statement that the same clause governs every commercial deployment.
Outside that context, the public 2026.08 supplemental terms do not support the same categorical answer. Put the CUI restriction, detection method, cessation procedure, and liability consequences into the agreement that governs your deployment.
Either way, the practical question remains: can you demonstrate what enters the telemetry stream?
Where CUI leaks into security telemetry anyway
Most contractors picture logs as rows of IP addresses and timestamps. Arctic Wolf's own Solutions Data definition is broader: operational values, event logs, network metadata, inventory, operating-system details, Active Directory users and groups, event data, and vulnerability data.
None is automatically CUI. But CUI can hitchhike in the values. Test these paths first:
- Filenames in endpoint or process telemetry. A filename can reveal controlled program or technical information depending on its content and context.
- Email subject lines captured by identity, messaging, or alert integrations.
- Data-loss-prevention alerts that reproduce matched text in the alert body.
- File samples submitted for malware analysis. The whole point is to send the file.
- Packet capture or network-content inspection where payload becomes evidence.
- Screenshots or excerpts in support tickets uploaded during an investigation.
- Memory, disk, or forensic artifacts collected during incident response.
- Directory group, host, share, or project names that reveal a controlled program.
We are not asserting Arctic Wolf collects all eight in every tier. Coverage depends on products, integrations, configuration, incident actions, and support workflow. These are diligence questions.
Answer one now: can any record your MDR ingests contain a filename, subject line, matched-content excerpt, or attachment? If yes, you have a classification and data-minimization question to resolve before assessment, regardless of vendor.
The GCC High reality check
Arctic Wolf's terms contemplate monitoring supported applications in GCC and GCC High. They also say only supported integrations are monitored and certain Microsoft sources may be beta with no delivery representation.
That is the difference between “our enclave is monitored” and “the production integrations named in our agreement are monitored.” Get the production connector list in writing, dated, with beta sources, exclusions, failure notifications, and responsibility boundaries identified.
Where the published subprocessor list points
Arctic Wolf's subprocessor list, updated July 30, 2026, describes subprocessors used to process personal data for identified products. It is useful evidence, not a complete customer-specific data-flow diagram.
| Published provider | Published purpose | Published location information |
|---|---|---|
| Amazon Web Services | Data center and hosting for MDR and other products | USA, Canada, Germany, Australia |
| Databricks | Data warehouse storage, management, and AI-enabled analysis | USA, Canada, Australia, Germany, based on SOC location |
| AWS Bedrock | Artificial intelligence; product research and development | USA, Canada, Germany, Australia |
| Anthropic | AI-enabled functionality; product research and development | USA |
| Microsoft 365 and SharePoint | Email, office applications, corporate repository | USA |
| Okta Customer Identity Cloud | User authentication | USA |
Arctic Wolf's affiliate table also identifies entities performing “Security Services” in Canada, the United Kingdom, Germany, Australia, India, Ireland, and Japan. That corroborates a multi-country delivery footprint. It does not prove every customer's data is accessed from every listed country.
We did not identify AWS GovCloud or Azure Government as named subprocessors on the reviewed page. That is not proof no government-cloud architecture or U.S.-persons-only tier exists. It is a reason to ask for the customer-specific data-flow and access matrix.
NIST SP 800-171 Revision 2 does not impose a universal U.S.-persons-only rule. Prime flowdowns, export-control restrictions, covered technical-data obligations, and program-specific terms may create separate requirements. Put those questions in front of qualified counsel, not an MDR salesperson and not this publication.
Which NIST SP 800-171 requirements can Arctic Wolf support?
CMMC Level 2 uses NIST SP 800-171 Revision 2 — 110 requirements across 14 families. 32 CFR § 170.14(c)(3) makes those requirements identical for CMMC Level 2.
There is a version trap. NIST superseded Revision 2 with NIST SP 800-171 Revision 3, and replaced the February 2021 SP 800-172 with SP 800-172 Revision 3 in May 2026. Those publication changes did not automatically amend 32 CFR Part 170. The CMMC rule still incorporates Revision 2 for Level 2 and the February 2021 SP 800-172 for Level 3 unless DoD amends the controlling rule. See our Rev. 2 vs. Rev. 3 guide.
The map below is an editorial capability map, not a control-coverage claim. It does not award a requirement as MET or replace the CRM, configuration review, or assessment evidence.
| NIST SP 800-171 Rev. 2 family | What Arctic Wolf can contribute | What the contractor still owns |
|---|---|---|
| 3.1 Access Control | Identity and access telemetry; anomalous-login detection | Policies, authorization, least privilege, account lifecycle |
| 3.2 Awareness and Training | Training, phishing simulation, completion evidence if the module is purchased | Required content, role-based coverage, records, follow-up |
| 3.3 Audit and Accountability | Strongest fit. Collection, correlation, alerting, investigations, retained records | Logging design, review cadence, protection, retention, closure |
| 3.4 Configuration Management | Inventory and identification of some configuration issues | Baselines, change control, least functionality, approved software |
| 3.5 Identification and Authentication | Authentication-event monitoring | MFA, password policy, identifier and device management |
| 3.6 Incident Response | Strong fit. Detection, triage, investigation, escalation, records | Plan, exercises, reporting decision, DFARS submission |
| 3.7 Maintenance | Little direct contribution from base MDR | Maintenance controls, tools, personnel, sanitization |
| 3.8 Media Protection | No direct base-MDR contribution identified | Marking, access, transport, sanitization, removable media |
| 3.9 Personnel Security | No direct base-MDR contribution identified | Screening, termination, transfer, access changes |
| 3.10 Physical Protection | No direct base-MDR contribution identified | Physical access, visitors, monitoring, alternate work sites |
| 3.11 Risk Assessment | Strong fit when vulnerability management is included. Scanning and prioritization | Risk methodology, acceptance, remediation, periodic assessment |
| 3.12 Security Assessment | Reports and investigations that may serve as evidence | SSP, POA&M, control assessment, monitoring program |
| 3.13 System and Communications Protection | Network and boundary telemetry | Architecture, segmentation, encryption, FIPS validation |
| 3.14 System and Information Integrity | Strong fit. Malicious-code detection, monitoring, alerting, threat intelligence | Flaw remediation, patching, protection configuration, closure |
Four families are the strongest capability fit. Three show no direct base-MDR contribution. Seven are partial or conditional. That is a useful buying map, not a score.
We deliberately do not publish an “Arctic Wolf covers 47 of 110” number. No credible count exists without the contracted tier, CRM, configuration, asset boundary, evidence standard, and a method for partial responsibility. Ask anyone who gives you a number to show the methodology requirement by requirement.
Who files the DFARS 72-hour report—you or Arctic Wolf?
The contractor does. DFARS 252.204-7012 requires the contractor to rapidly report a qualifying cyber incident within 72 hours of discovery through DIBNet. Access requires a DoD-approved medium-assurance certificate.
For GCC/GCC High monitoring, Arctic Wolf's § 4.5 promises reasonable cooperation in a breach involving Solutions Data. Cooperation is assistance. It is not the filing, and it is not the clock.
This is the assumption we would most want to break if we could only break one. A contractor buys MDR, gets a 24/7 SOC, and quietly concludes incident reporting is handled. It is not.
- Get the certificate before the incident. You cannot submit through DIBNet without the approved credential.
- Preserve evidence. DFARS 252.204-7012 requires images of affected systems and relevant monitoring data to be preserved for at least 90 days from the rapid report.
- Own the decision. Not every misplaced file or alert is a reportable cyber incident. The clause and facts control.
MDR can provide the timeline, affected systems, indicators, actions, and scope of compromise. That is real value. Do not let it stand in for the obligation.
Ask Arctic Wolf in writing what it will do for DFARS 252.204-7012 paragraphs (c) through (g): who calls whom, which artifacts it preserves, how quickly they export, whether it supports malicious-software submission, and whether it participates in a DoD damage assessment.
How long must Arctic Wolf logs and CMMC evidence be retained?
Arctic Wolf's public MDR terms include 90 days of log retention unless another period is purchased and written into the Order Form. CMMC's six-year rule applies to the artifacts used as assessment evidence, not automatically to every raw operational log.
The correct citations are 32 CFR § 170.16(c)(4) for Level 2 self-assessment artifacts and § 170.17(c)(4) for Level 2 certification artifacts. Both require six-year retention from the CMMC Status Date. Only the certification provision adds hashing and eMASS-upload requirements.
| Retention question | What it means | Owner |
|---|---|---|
| Searchable operational logs | How far back analysts can query telemetry | MDR contract; public Arctic Wolf default is 90 days |
| Cyber-incident preservation | Images and monitoring data preserved at least 90 days from a DFARS report | Contractor, with contracted vendor support |
| CMMC assessment artifacts | Specific files used as assessment evidence, retained six years | Assessed organization |
For a Level 2 self-assessment, retain the evidence artifacts for six years. The rule does not impose the certification hashing workflow on those artifacts.
For a Level 2 certification assessment, § 170.17(c)(4) requires the contractor to hash the artifact files with a NIST-approved algorithm and provide the C3PAO the artifact names, hash values, and algorithm for upload into the CMMC instantiation of eMASS.
If an Arctic Wolf report, case export, or investigation record is used as evidence, you must preserve that exact file even if you do not renew the platform. A 90-day searchable window does not automatically fail the six-year rule. It becomes a gap when the only relied-on artifact or the only source needed to reproduce it disappears.
The public terms add an exit deadline: absent a legal requirement, Arctic Wolf says it will remove or destroy Confidential Information after equipment return or within 120 days after expiration or termination.
Do three things:
- Buy the operational retention you need and put the period, archive behavior, query limits, and export rights on the Order Form.
- Export selected evidence at assessment time. For certification, hash the exact files in the required workflow and store them in a repository you control.
- Build the exit procedure before termination. Name who exports logs, cases, tickets, reports, connector history, and configuration records before deletion.
The AWS page includes marketing-generated summaries that refer to longer storage. The binding supplemental terms say 90 days unless another period is purchased. The Order Form and governing agreement decide your entitlement.
Put the evidence gap on paper
Use the 32-point CMMC readiness checklist to mark the SSP, CRM, retention, incident-evidence, and export items that must be owned before assessment.
→ Open the CMMC readiness checklist
Do not upload CUI or assessment artifacts to a public form.
Why can’t you scope your program from Arctic Wolf’s CMMC page?
As verified August 25, 2026, Arctic Wolf's public compliance page still contains legacy and internally inconsistent CMMC/NIST descriptions. The controlling CMMC rule has three levels, not five, and CMMC Level 2 uses all 14 NIST SP 800-171 Revision 2 families. Vendor compliance pages are reference and marketing assets. They are not the regulation.
| What Arctic Wolf's page says | Current primary-source position | Why it matters |
|---|---|---|
| CMMC has five levels: Performed, Documented, Managed, Reviewed, Optimizing | 32 CFR §§ 170.15–170.18 define three levels | The page describes a legacy model. |
| CMMC support includes “ISO 27001-2013” | IAF's transition rule ended validity of 2013-edition certifications after October 31, 2025 | The label cannot prove a current certificate. |
| The NIST SP 800-171 entry says “Requirements 13” and lists 13 families | Revision 2 has 14 families | The omitted family is 3.2 Awareness and Training — the one most directly tied to Arctic Wolf's awareness product. |
| The page labels 3.9 as Physical Protection and 3.10 as Personnel Security | Revision 2 labels 3.9 Personnel Security and 3.10 Physical Protection | The two families are reversed. |
That last pair is not cosmetic. A control-family map is supposed to prevent category confusion. Swapping Personnel Security and Physical Protection creates it.
The lesson: scope from the regulation and DoD guide; use vendor material for vendor facts; verify those facts against the documents that bind the service. That is true for every vendor in this market, not just Arctic Wolf.
What should you get from Arctic Wolf before signing or renewing?
32 CFR § 170.19(c)(2)(ii) says the use of an ESP, its relationship to the assessed organization, and the services provided must be documented in the SSP and described in the ESP's service description and customer responsibility matrix. For Level 2 certification assessments, the Cyber AB CAP adds an operational test: the CRM must be available, and ESP personnel must participate when needed.
Do not assume those materials are ready because the vendor sells security. Ask early.
The six documents
- ESP service description — exact service, components, legal entity, delivery model, and customer environment covered.
- Customer responsibility matrix — which requirements, objectives, evidence, and actions the provider performs; which you perform; and which are shared.
- Current SOC 2 Type II report and ISO/IEC 27001 certificate — with entity, scope, period, edition, certification body, accreditation, and expiry. Not the logos.
- Written position on DFARS 252.204-7012 paragraphs (c) through (g) — reporting support, malicious-software submission, preservation, forensic access, and damage-assessment cooperation.
- Controlling Order Form and data-flow attachments — Platform location, residency, retention, production connectors, beta sources, support access, subprocessor restrictions, and termination exports.
- Evidence and assessor-support procedure — formats, bulk export, timing, configuration evidence, ticket history, interview participants, and post-termination access.
Twenty questions that separate real answers from sales answers
Entity and status
- Which exact legal entity will contract with us and which entities will deliver the service?
- What current Cyber AB Marketplace role, if any, applies to that exact entity?
- Has the contracted service undergone a voluntary CMMC assessment under § 170.19(c)(2)(ii)? If so, provide the scope, status, and date.
Data flow
- List every field and content type transmitted from each integrated source.
- Can email bodies, attachments, file samples, packet content, memory artifacts, matched-content excerpts, or ticket attachments leave our environment?
- How do you prevent CUI ingestion technically — not just contractually?
- What happens the moment suspected CUI is detected in the stream?
- Can support, incident-response, affiliate, or subprocessor personnel access our source systems, endpoints, files, or case attachments interactively?
Geography and personnel
- In which countries is each category of data stored, backed up, processed, and supported?
- From which countries may analysts, affiliates, and subprocessors access it?
- Can we restrict access contractually to U.S. persons located in the United States?
- What notice and objection rights apply before a subprocessor or delivery location is added?
GCC High and coverage
- Which GCC High sources are fully supported in production today?
- Which are beta, preview, unsupported, or subject to delivery disclaimers?
- What happens — and who is notified — when a required connector stops delivering events?
Operations
- Which containment actions can Arctic Wolf take without approval, which require approval, and which are recommendations only?
- What contractual escalation, investigation, notification, and response-time commitments apply to each severity?
Evidence and exit
- What retention period is on the Order Form, what remains searchable, and what does extending it cost?
- Can we bulk-export logs, alerts, cases, investigations, tickets, configuration history, and reports? In what format and how quickly?
- Will responsible Arctic Wolf personnel participate in a C3PAO interview and explain the CRM, configuration, evidence, and incident workflow?
If a vendor answers all twenty in writing, you have the beginning of an assessable relationship. If it answers twelve and gets vague on data flow, geography, evidence, and assessor participation, you have your finding.
What does Arctic Wolf cost for a defense contractor?
Arctic Wolf's AWS Marketplace listing shows a 12-month “MDR Basic” contract for up to 100 users at $44,000, with a stated saving of up to 6%. The listing also shows a $1,000,000 “Custom Pricing” dimension whose terms and coverage are defined by private offer. That is a private-offer catalog dimension, not a normal Arctic Wolf quote.
What $44,000 tells you: a public MDR Basic contract dimension exists for up to 100 users. At the full 100-user cap, that equals $440 per covered user per year before partner charges, add-ons, and negotiation. It is an anchor, not a forecast.
What it does not tell you: how “user” maps to employees, identities, endpoints, servers, sites, and service accounts; which sources and integrations are included; whether vulnerability management or awareness products are bundled; whether incident response is included; what longer retention costs; or what renewal looks like.
Do not turn “up to 100 users” into an employee-count claim.
| Cost layer | Normalize before comparing quotes |
|---|---|
| MDR subscription | Users, identities, endpoints, servers, sites, sources, integrations |
| Extended retention | Searchable period, archive tier, restore time, query and export rights |
| Vulnerability management | Coverage, bundle status, remediation owner |
| Security awareness | Populations, content, phishing tests, exportable evidence |
| Incident response | Retainer or hourly, exclusions, response SLA |
| GCC High coverage | Supported connectors, beta sources, restrictions, premium |
| Readiness | Scope, SSP, policies, POA&M, evidence, CRM integration |
| Remediation | Technical work required to make requirements MET |
| CUI enclave | Licensing, migration, administration, boundary controls |
| GRC platform | Software, implementation, evidence workflow |
| Assessment | C3PAO fees when certification status is required |
| Internal labor | The line contractors underestimate most |
| Exit | Bulk export, overlap, sensor return, migration, deletion deadline |
Never compare a base MDR quote with an all-in managed-compliance quote. Normalize every proposal to the same scope and deliverables first. Our CMMC Level 2 cost guide separates readiness, remediation, tooling, enclave, assessment, and internal labor.
We do not publish a “typical Arctic Wolf CMMC cost range.” We would need multiple scope-normalized DIB quotes to do that honestly, and we do not have them. The $44,000 listing is verified and dated. The rest belongs in your quote and Order Form.
Who should shortlist Arctic Wolf—and who should walk away?
Arctic Wolf is most defensible for a contractor that needs security operations it cannot staff internally, can keep CUI out of the service or establish the required provider conditions, and already has a qualified owner for the compliance program. It is a weak fit — or the wrong category — for a contractor that needs U.S.-persons-only delivery without a written tier, a CUI home, an SSP author, or a certification assessment.
| Your situation | Our editorial read | Why |
|---|---|---|
| Small machine shop, capable MSP, separate CMMC lead | Conditional candidate | MDR fills a monitoring gap. The MSP and readiness lead own everything else. |
| Mid-market DIB firm, defined CUI enclave, internal compliance staff | Potentially strong component | The organization can control the path, negotiate the CRM, and preserve evidence. |
| GCC High, uncertain connector coverage | Conditional — get it in writing | §§ 4.2 and 4.6 make production connectors the whole conversation. |
| Export-controlled data or U.S.-persons restrictions | Pause and get legal input | GCC-specific § 4.3 and the published delivery footprint require customer-specific analysis. |
| Looking for one vendor to do everything | Wrong expectation | Base MDR is not managed compliance, a CUI enclave, or an assessment. |
| Assessment-ready and only needs the audit | Wrong category | You need an authorized C3PAO. The ecosystem conflict rule bars participation when the same ecosystem member served as readiness consultant within the prior three years. |
| Needs a compliant home for CUI | Wrong category first | You need a properly designed CUI environment and applicable cloud conditions. |
| Already running Arctic Wolf | Do not rip and replace by reflex | Start with data flow, terms, CRM, connectors, exports, and retention. |
Read this part if nobody is accountable
If no one owns the CUI scope, SSP, POA&M, remediation plan, assessment evidence, and annual affirmation, buying MDR is the wrong purchase this quarter. You would be buying monitoring while leaving the compliance program unowned. You will not achieve a CMMC status on the strength of a SOC subscription, and you may spend the budget that should have gone to readiness.
Start with our provider-category comparison or Who to Hire First guide. We would rather lose you from this page than watch you spend $44,000 solving the wrong problem.
What Arctic Wolf MDR does not replace
| What you need | Category | What MDR does not replace |
|---|---|---|
| Determine required level and scope | Qualified readiness advisor / RP / RPO | The scoping decision |
| Write and maintain SSP and POA&M | Readiness provider, vCISO, managed compliance | Governance |
| Remediate technical gaps | MSP, MSSP, internal IT, security engineering | Remediation work |
| Store or isolate CUI | Properly designed CUI enclave or cloud architecture | CUI hosting |
| Manage evidence | GRC platform plus accountable owner | Evidence governance |
| Continuous monitoring | MDR — this is the fit | — |
| Formal Level 2 certification assessment | Authorized C3PAO | Certification — ever |
| NIST score under DFARS 252.204-7019/-7020 | Contractor, with support as needed | Score-posting responsibility |
| CMMC result and annual affirmation under DFARS 252.204-7021 | Assessed organization and affirming official | Legal accountability |
Resolve the category before requesting a quote
Tell us your required level, CUI scope, environment, and timeline. We route to the provider category that matches the decision — not to a vendor just because it bought the ad.
Do not submit CUI, drawings, credentials, system diagrams, or sensitive contract details. Provider matching may generate referral compensation, disclosed at the point of recommendation.
Does the CMMC Phase II suspension change this decision?
No. It changes current procurement rollout, not the technical truth about your MDR data flow, DFARS duties, or Phase I self-assessment requirements.
The DFARS acquisition rule took effect November 10, 2025. Under the original plan, Phase I ran from November 10, 2025 through November 9, 2026, and Phase II was scheduled for November 10, 2026.
On July 13, 2026, the Department of War suspended the transition to Phase II and pending future milestones. The current official CMMC page says all Phase I self-assessment requirements remain in place. The implementation memorandum directs contracting activities not to select new requirements that would require Level 2 C3PAO or Level 3 status while the suspension remains in effect.
That did not erase 32 CFR Part 170, repeal the DFARS clauses, or make NIST SP 800-171 Revision 3 the CMMC Level 2 control set.
- DFARS 252.204-7012 still governs safeguarding, cloud conditions, rapid reporting, and preservation where it applies.
- DFARS 252.204-7019 and 252.204-7020 still govern the legacy NIST SP 800-171 DoD Assessment score and government assessment access where they apply.
- DFARS 252.204-7021 requires the contract-specified CMMC status, applicable self-assessment result, CMMC UID, flowdown, and annual affirmation in SPRS when the clause applies.
The suspension paused expansion of third-party and Level 3 procurement requirements. It did not make an undocumented ESP relationship disappear. We track the policy state on our CMMC Phase II deadline page.
How did we research this Arctic Wolf CMMC review?
This public-document review was conducted by The Defense Compliance Report Editorial Team and verified August 25, 2026. It is not based on a deployment, customer interview, signed Order Form, or communication with Arctic Wolf.
| Source class | What we used it for |
|---|---|
| 32 CFR Part 170, sourced to 89 FR 83214 | Levels, controlling NIST versions, scope, ESP/SPD treatment, artifact retention, hashing, affirmation, conflict rules |
| DoD Level 2 Scoping Guide | Security Protection Asset and SIEM-service examples |
| Cyber AB CAP v2.0 | Level 2 certification process, CRM, ESP participation, no-guarantee rules |
| DFARS 252.204-7012 | Safeguarding, cloud conditions, 72-hour reporting, 90-day preservation |
| DFARS 252.204-7019, 252.204-7020, and 252.204-7021 | DoD Assessment score, SPRS, CMMC status, UID, affirmation, flowdown |
| NIST SP 800-171 Rev. 2, Rev. 3, and SP 800-172 Rev. 3 | Version status and the difference between NIST's current publications and the versions incorporated into CMMC |
| Official CMMC page and July 13, 2026 memorandum | Current Phase I / Phase II status |
| Arctic Wolf MDR terms, subprocessor list, and compliance page | Data, retention, termination, GCC limits, locations, and company claims |
| AWS Marketplace | Public price dimension, user cap, savings statement, private-offer dimension, security metadata |
| IAF MD 26 | ISO/IEC 27001:2013 transition deadline |
What would upgrade this page: a completed questionnaire, customer-specific service description and CRM, signed Order Form, data-flow diagram, exact-entity Marketplace verification, and comparable DIB customer references with similar boundaries.
We do not publish vendor case studies as proof of CMMC outcomes. A quote about sleeping better does not establish that the ESP relationship was scoped, documented, and assessed correctly.
Read our Methodology, Editorial Standards, and Editorial Review Process for how we separate primary-source fact, vendor statement, and editorial judgment.
Frequently asked questions
Is Arctic Wolf CMMC compliant?
A vendor product does not transfer CMMC status to a contractor. Arctic Wolf MDR is monitoring, not certification, readiness, or CUI hosting. Fit depends on the exact service and entity, what CUI or SPD reaches it, CSP status for that path, the governing contract, CRM, and evidence.
Is Arctic Wolf a C3PAO or an RPO?
Do not infer an entity-wide Cyber AB status from a service label, or absence from an unsuccessful name search. The reviewed service is MDR; it is not itself a certification assessment or readiness engagement. Verify the exact legal entity in the live Cyber AB Marketplace.
Is Arctic Wolf FedRAMP authorized?
For GCC/GCC High monitoring, current public § 4.1 says Arctic Wolf is not FedRAMP compliant. AWS shows “No security profile,” but that is not a FedRAMP determination. Verify the exact product, entity, authorization boundary, and status in the FedRAMP Marketplace.
Does using Arctic Wolf put us in CMMC scope?
When SPD resides on the service, yes: Table 4 treats it as a Security Protection Asset in Level 2 scope. Local sensors, agents, collectors, and connections must also be categorized under Table 3 based on what they do.
Can we send CUI to Arctic Wolf?
For GCC/GCC High monitoring, the public terms say Arctic Wolf does not require CUI and may stop ingestion if CUI is provided. Outside that section, get the answer in the governing agreement. If CUI reaches the service, Table 4 requires the CSP/non-CSP analysis.
Can Arctic Wolf monitor Microsoft GCC High?
The terms contemplate supported and integrated applications in GCC and GCC High. They also say some Microsoft sources may be beta with no delivery representation. Get the production connector list and failure-notification process in writing.
Does Arctic Wolf need its own CMMC certification?
Not automatically. An ESP may voluntarily undergo a CMMC assessment to reduce effort during the customer's assessment. Without that, relevant services and evidence are assessed through the customer's assessment. Provider status does not certify the customer.
Who files the DFARS 72-hour report?
The contractor. MDR can gather evidence and cooperate, but DFARS 252.204-7012 places the rapid-reporting obligation on the contractor.
How much log retention comes with Arctic Wolf MDR?
The public terms specify 90 days unless another period is purchased and written on the Order Form. That is separate from six-year retention of the specific artifacts used as CMMC assessment evidence.
Does every CMMC artifact need to be hashed?
No. Level 2 self-assessment artifacts require six-year retention. The Level 2 certification provision adds NIST-approved hashing and delivery of artifact names, hash values, and algorithm to the C3PAO for eMASS upload.
How much does Arctic Wolf cost?
AWS Marketplace shows $44,000 for a 12-month MDR Basic contract covering up to 100 users, verified August 25, 2026. The $1,000,000 Custom Pricing dimension is a private-offer container, not a normal quote.
Is Arctic Wolf enough for CMMC Level 2 on its own?
No. Level 2 uses 110 Revision 2 requirements across 14 families. MDR contributes strongly in a few security-operations families, but it does not own the full scope, SSP, POA&M, policies, remediation, evidence program, or affirmation.
Does NIST SP 800-171 Revision 3 control CMMC Level 2 now?
No. NIST superseded Revision 2 as a publication, but 32 CFR Part 170 still incorporates Revision 2 for CMMC Level 2. Revision 3 does not become controlling unless DoD validly changes the governing requirement.
We already use Arctic Wolf. Should we replace it?
Not automatically. Start with data flow, governing terms, exact entity, Table 4 row, connectors, CRM, exports, incident duties, and retention. Migrate when the facts show the required handling, authorization, evidence, personnel, or contract terms cannot be achieved.
Your next step
Whether Arctic Wolf belongs in your architecture depends on facts only you have: required level, FCI or CUI, assessment type, cloud environment, flowdown and export constraints, and timeline.
Tell us your level, scope, environment, and timeline, and we will match you with source-checked provider-category options.
→ Find My CMMC Path → Request CMMC provider quotes
Do not submit CUI, drawings, credentials, system diagrams, or sensitive contract details. Provider matching may generate referral or lead-routing compensation, disclosed at the point of recommendation.
The Defense Compliance Report publishes no numeric provider scores and no “best provider” awards. Find My CMMC Path resolves the provider category before routing an inquiry; it is not a certification, score, or legal opinion.
Found an error? We correct promptly and document material changes under our Corrections Policy.
