The Defense Compliance ReportCMMC 2.0 & the Defense Industrial Base

Managed security review · public-source evidence profile · last reviewed August 2026

Blackpoint Cyber CMMC Review: Privacy Mode, MDR Scope, and the MSP Problem

Last updated:

Last verified: against CMMC rules, DFARS, NIST publications, DoD guidance, Cyber AB records, and Blackpoint public, trust-center, reseller, and LogIC materials.

Blackpoint Cyber CMMC review illustration showing separate CUI and security telemetry flows across a contractor, MSP, and security operations center

Current CMMC status — verified August 27, 2026: Phase I began November 10, 2025. Its original first-year window ran through November 9, 2026, but the Department suspended the planned Phase II transition on July 13, 2026. During the suspension, solicitations and contracts may designate CMMC Level 1 (Self) or Level 2 (Self); they are not to require Level 2 (C3PAO) or Level 3 as part of the phased rollout. The suspension did not erase DFARS 252.204-7012 duties, applicable SPRS requirements, contract-specific cybersecurity obligations, or the need to protect CUI now.

By The Defense Compliance Report Editorial Team

Independent educational analysis. This page is not legal, contractual, assessment, or compliance advice. The Defense Compliance Report is not affiliated with the Department of Defense, the Cyber AB, Blackpoint Cyber, Huntress, or Arctic Wolf. Some providers may compensate us for an introduction; any paid relationship is labeled and does not change the regulatory framework or the conclusions below. See our Methodology, Editorial Standards, and Corrections Policy.

This Blackpoint Cyber CMMC review has one answer you can use immediately:

Blackpoint Cyber can support parts of a CMMC Level 2 program. It cannot make your company compliant, its software cannot hold a CMMC Status, and Privacy Mode does not automatically remove Blackpoint or your MSP from the assessment conversation.

That does not make Blackpoint a bad product. It makes the buying decision more specific.

Blackpoint's managed detection and response, identity monitoring, security telemetry, and log capabilities can help produce useful evidence and shorten incident-detection time. Its published CMMC Privacy Mode can also reduce one serious problem: sending CUI content into a third-party SOC when the SOC does not need that content to detect threats.

But your assessment boundary is not decided by the name of a feature. It is decided by the actual data flow, the service relationship, the contract, the system security plan, and the customer responsibility matrix.

The practical verdict:

  • Good reason to consider it: you want MSP-delivered MDR and can prove that Blackpoint receives only the security data it needs.
  • Bad reason to buy it: someone said the tool is "CMMC compliant."
  • The make-or-break document: a three-party responsibility map showing what your organization, your MSP, and Blackpoint each operate, protect, retain, escalate, and evidence.
  • The make-or-break technical test: inspect real alerts, tickets, case notes, log fields, exports, and support workflows—not just a diagram—to verify whether CUI reaches Blackpoint.
  • The make-or-break contract test: confirm incident-notice timing, preservation support, log export, data location, subprocessors, termination access, and who supplies assessment evidence.

If you are not yet sure whether you need an RPO, MSP, MSSP, C3PAO, enclave provider, or GRC platform, start with Who to Hire First or the CMMC Provider Categories guide. An MDR quote cannot solve a category mistake.

Blackpoint Cyber CMMC review: the verdict

Our verdict: Blackpoint is potentially useful CMMC infrastructure, not a CMMC outcome. Buy it only after the MSP converts the product into a documented, assessable service design.

Buyer question — Answer — What must exist before you rely on it
Buyer questionAnswerWhat must exist before you rely on it
Is the Blackpoint product CMMC certified?No. Products do not receive a CMMC Status.Accurate product language in the proposal and SSP.
Can Blackpoint Cyber itself hold a CMMC Status?An external service provider may voluntarily undergo an assessment for its own scoped information system. We did not verify a public Blackpoint CMMC Status under that name.Current Cyber AB Marketplace evidence or an assessment record tied to the exact legal entity and service scope.
Does Privacy Mode remove Blackpoint from scope?Not by itself. It may change the CUI data flow, while Blackpoint still handles security protection data.Field-level data-flow validation plus an SSP and CRM that match production.
Does Blackpoint need FedRAMP?Only when the relevant cloud service is acting as a cloud service provider that stores, processes, or transmits CUI under the DFARS 252.204-7012 cloud requirement. SPD-only handling is a different path.A written classification of every data flow and the exact hosted service.
Does MDR satisfy the 110 Level 2 requirements?No. It can support evidence and operation for a subset of the 110 requirements across 14 families.A requirement-by-requirement ownership and evidence map.
Does 365-day log storage solve CMMC retention?No. CMMC does not impose one blanket log-retention period, and logs are not the same as the images and monitoring data covered by the 90-day incident-preservation duty.Retention rules tied to each evidence type, contract, incident plan, and assessment artifact.
Is the MSP responsible for everything?No. The contractor remains responsible for its CMMC Status, affirmation, contract compliance, and accurate system description.Named owners at the contractor, MSP, and any sub-tier ESP.
Is the current Phase II suspension a reason to wait?No. It changes the rollout of mandatory C3PAO and Level 3 requirements; it does not cancel current contract duties or make weak architecture cheaper to fix later.A plan tied to the contracts you have and the bids you intend to pursue.

The 12 buyer checks on this page are designed to answer a more expensive question than "Does Blackpoint have MDR?"

They answer: Can your organization defend the way Blackpoint is deployed when an assessor, prime, customer, incident responder, or contracting officer asks who had the data and who owned the requirement?

Is Blackpoint Cyber CMMC compliant?

No product is "CMMC compliant" in the same way an organization can hold a CMMC Status.

The controlling definition in 32 CFR §170.4 attaches CMMC Status to an organization seeking assessment. The CMMC Program evaluates the information system inside a defined assessment scope. It does not certify an MDR logo, an endpoint agent, a SIEM dashboard, or a software feature.

That distinction is not word games. It changes what you can safely write in a proposal, SSP, procurement memo, or board presentation.

The accurate way to describe Blackpoint

Use language like this:

Blackpoint Cyber is an external cybersecurity service used within our CMMC assessment scope. Its capabilities support specified requirements and evidence activities. Our organization remains responsible for its CMMC Status, its contract obligations, and the operation of requirements assigned to us in the system security plan and customer responsibility matrix.

Do not write:

Blackpoint makes us CMMC compliant.

And do not replace one overstatement with another:

Blackpoint can never have a CMMC assessment.

Under 32 CFR §170.19, an external service provider may voluntarily undergo its own CMMC assessment. If it does, that status applies to the provider's assessed scope—not automatically to your environment, your MSP's services, every Blackpoint product, or your contractual obligations.

What we found in the public registries

A search of the public Cyber AB Marketplace on August 27, 2026 did not surface a Blackpoint Cyber entry under that name that established a current C3PAO, RPO, or assessed-provider status.

That is a dated public-record finding, not proof that no separately named affiliate, reseller, employee credential, private assessment, or later listing exists. Ask for the exact legal entity, listing URL, status type, scope, and expiration date if a salesperson makes a status claim.

We also did not find a public FedRAMP Marketplace authorization under the Blackpoint Cyber name during the same verification pass. That does not decide whether Blackpoint is usable. It decides what you must verify if anyone proposes sending CUI into a Blackpoint-hosted cloud service.

Buyer check 1: Ask every seller to separate four things in writing:

  1. the product's features;
  2. the provider's own organizational status, if any;
  3. your organization's CMMC Status;
  4. the assessment evidence the service will produce for your environment.

A seller who collapses those four into "CMMC compliant" has not answered the question.

A separate provider-status boundary matters when assessment language enters the sale. An MSP, RPO, consultant, or product vendor can help with readiness only within the work it is qualified and contracted to perform. A Level 2 certification assessment must be performed through an authorized C3PAO, and the current Cyber AB CMMC Assessment Process and ecosystem rules govern assessor independence and conflicts. Do not turn the accurate principle—assessment personnel must remain independent of work that compromises their objectivity—into the inaccurate claim that every readiness relationship and every assessment organization must be commercially unrelated in all circumstances. Verify the current C3PAO listing, assessment team, affiliates, prior work, and conflict determination for the planned engagement.

What does Blackpoint Cyber actually do for a defense contractor?

Blackpoint is best understood as a security operations component delivered through an MSP-centered channel. Its public materials describe managed detection and response, endpoint and identity telemetry, threat hunting and response, and centralized log capabilities through the CompassOne platform and LogIC offering.

Those capabilities can matter to CMMC. They are not interchangeable with CMMC.

Publicly stated capability — What it can contribute — What it does not prove
Publicly stated capabilityWhat it can contributeWhat it does not prove
Managed detection and responseContinuous monitoring, alert triage, escalation, and response actions within the contracted serviceThat every Level 2 requirement is met or that your incident-reporting clock is contractually protected
Identity and cloud telemetryDetection of suspicious sign-ins, privilege abuse, and identity-based attack patternsThat your access-control and identification requirements are fully implemented
Endpoint telemetryDetection evidence, investigation context, and some response actionsThat every CUI asset is covered or correctly configured
LogIC and extended encrypted log storageCentralized evidence, search, correlation, and a provider-stated 365-day included storage periodA universal CMMC log-retention rule, complete source coverage, or 90-day preservation of every required incident artifact
CMMC Privacy ModeA provider-stated way to keep CUI content away from Blackpoint's SOC while retaining MDR functionsThat no CUI enters alerts, tickets, notes, attachments, screenshots, exports, support sessions, or downstream systems
Compliance-oriented reportsFaster evidence collection and operational reportingAn assessor's acceptance, a CMMC score, or an SPRS submission

The strongest public product claim we found is not "CMMC compliant." It is narrower and more useful: Blackpoint's February 23, 2026 CMMC Privacy Mode announcement says the tenant-level feature can maintain MDR while keeping CUI away from Blackpoint's SOC.

That is a company statement. We did not receive a production tenant, packet capture, data-processing exhibit, or independent test showing how every field behaves. Treat it as a design claim to validate, not a conclusion to paste into the SSP.

Buyer check 2: Get a current service diagram that names every agent, collector, API, cloud tenant, SOC console, ticketing system, notification path, log store, subprocessor, and human support path. "Blackpoint is our MDR" is not a data-flow diagram.

Does CMMC Privacy Mode keep Blackpoint out of scope?

No. Privacy Mode may reduce CUI exposure. It does not make the service relationship disappear.

The rule draws an important line between:

  • CUI, the information your contract requires you to protect; and
  • security protection data (SPD), the data generated or used by security protection assets to protect the assessed environment.

Under the Level 2 external-service-provider treatment in 32 CFR §170.19, an ESP that handles SPD without handling CUI is still relevant to the assessment. The service and its assets are addressed as Security Protection Assets, and the relationship must be documented.

That is why "we turned on Privacy Mode" is not the end of the scoping analysis.

The data-flow decision that matters

Data leaving the contractor environment — Likely treatment — What to verify
Data leaving the contractor environmentLikely treatmentWhat to verify
Email body, drawing, specification, export-controlled technical content, or file content marked or determined to be CUICUIWhether content is transmitted, rendered, cached, attached to an alert, copied into a ticket, or accessible during support
Endpoint event, process tree, hash, device identifier, alert metadata, firewall record, authentication event, vulnerability record, or detection rule used to protect the enclaveUsually SPD when generated or used by Security Protection AssetsExact fields, retention, access, location, export, and deletion
Screenshot or analyst note containing visible CUICUIWhether screenshots, screen sharing, case notes, or copied text can bypass the intended filter
Username, email address, device name, IP address, tenant ID, or system metadataMay be SPD, other controlled data, or non-CUI depending on contextClassification and combination risk; do not label all metadata harmless
Password, secret, token, private key, or credential contentSensitive authentication information; may also be CUI depending on contextWhether the service receives secrets or only login-event telemetry
Incident image, memory image, packet capture, or forensic collectionClassification follows its contents; it may contain CUIWho collects it, where it is stored, who can access it, and how long it is preserved
Alert email, webhook, PSA ticket, chat message, or exported reportDepends on the fields and narrative includedEvery downstream destination—not only Blackpoint's SOC

The original buying mistake is to classify the vendor instead of the data.

A vendor can say "we do not need CUI" and still receive CUI because:

  • an analyst pastes source content into a case;
  • an alert includes a command line, document name, email subject, or file path that reveals controlled work;
  • a support session exposes a CUI screen;
  • the MSP's PSA or ticketing platform receives the full event;
  • an incident artifact contains CUI;
  • a user sends CUI in an email asking for help;
  • a default integration transmits more fields than the privacy setting suppresses.

Privacy Mode is useful only when the production configuration and operating behavior match the claim.

A five-part Privacy Mode acceptance test

Do not accept a screenshot of the toggle as evidence. Have the MSP demonstrate:

  1. Normal detection: Trigger a benign test event on a CUI asset and inspect every field visible to Blackpoint.
  2. Case escalation: Open the alert, create a case, add notes, generate notifications, and inspect the MSP's PSA and email path.
  3. Investigation: Test remote response, process-tree review, file metadata, identity context, and any analyst-requested collection.
  4. Support: Simulate a support session and show what an analyst can access when troubleshooting the service.
  5. Export and termination: Export the case and logs, then show the retention, deletion, and offboarding path.

Record the date, tenant, product version, settings, data sources, test events, observed fields, exceptions, and approver. That evidence is more valuable than a brochure because it can be repeated after a platform change.

Buyer check 3: Make Privacy Mode an acceptance criterion in the MSP statement of work, not an optional feature mentioned in a sales call.

Is Blackpoint an external service provider under 32 CFR 170.19?

Blackpoint can be an ESP, and your MSP can also be an ESP. The rule does not force you to pretend the chain has only one provider.

32 CFR §170.4 defines an external service provider broadly enough to cover external people, technology, or facilities used to provide or manage IT or cybersecurity services for the organization seeking assessment.

In a common Blackpoint deployment, the actual chain looks like this:

Defense contractor → MSP or MSSP → Blackpoint platform and SOC → Blackpoint subprocessors and integrated services

The contractual seller may be the MSP. The technical operator may be the MSP, Blackpoint, or both. The data may pass through systems owned by more than one party. The assessor cares about the service that exists, not the simplified logo on the invoice.

"ESP of record" is not a term defined in Part 170. Do not use it to hide sub-tier providers.

Three possible deployment patterns

Pattern — What it means for scope — Main risk
PatternWhat it means for scopeMain risk
Blackpoint handles SPD only; the MSP and contractor prevent CUI from reaching itBlackpoint's service remains relevant as an ESP/Security Protection Asset relationshipThe SSP or CRM omits the sub-tier service because "no CUI" was mistaken for "out of scope"
Blackpoint stores, processes, or transmits CUI through a non-cloud or mixed service pathThe CUI-handling ESP requirements must be applied to the exact serviceSales language does not match the real alert, support, or forensic workflow
A Blackpoint cloud service acts as a CSP for CUIThe DFARS 252.204-7012 cloud requirement, including the applicable FedRAMP Moderate-equivalent path, becomes centralThe buyer assumes Privacy Mode or an MDR label substitutes for cloud authorization evidence

The OSA cannot outsource the truth of the architecture. The MSP cannot make Blackpoint disappear by calling it a tool. Blackpoint cannot make the contractor compliant by supplying MDR.

Each party can still be useful. Each party needs a named responsibility.

Buyer check 4: Require the MSP to identify every sub-tier ESP and every platform used to receive, process, store, transmit, investigate, or discuss your security data. Put the answer in the SSP and CRM.

Does Blackpoint need FedRAMP for CMMC?

Not merely because Blackpoint is cloud-based, and not merely because it handles SPD. The FedRAMP question turns on whether the relevant cloud service stores, processes, or transmits CUI.

DFARS 252.204-7012(b)(2)(ii)(D) applies when the contractor uses an external cloud service provider to store, process, or transmit covered defense information. The clause requires the cloud service to meet security requirements equivalent to the FedRAMP Moderate baseline and the other clause requirements applicable to that service.

That is not a universal "every cybersecurity SaaS must be FedRAMP" rule.

It is also not a loophole invitation. You cannot avoid the cloud requirement by renaming CUI "telemetry" when the service actually receives CUI content.

Use this decision sequence:

  1. Is this exact service a cloud computing service?
  2. Does it store, process, or transmit CUI—not just SPD?
  3. What fields, artifacts, support workflows, and exports create that answer?
  4. If yes, what evidence establishes the required FedRAMP Moderate-equivalent security and DFARS terms?
  5. If no, what tested configuration and contract keep CUI out?

Our August 27, 2026 public-record search did not locate a FedRAMP Marketplace authorization under the Blackpoint Cyber name. A missing public authorization does not automatically disqualify an SPD-only design. It does mean you should not let a seller imply that a FedRAMP status exists without showing the exact package and legal entity.

Privacy Mode is not a FedRAMP bypass

A verified no-CUI architecture may mean the Blackpoint service is evaluated under the SPD/Security Protection Asset path rather than as a CSP storing CUI. That is a legitimate scoping result.

The result must come from facts, not intent.

A setting that filters file contents but still sends CUI in case notes, forensic images, packet captures, support screenshots, or ticket attachments does not establish a no-CUI architecture. A contract that says "do not send CUI" while the integration sends it is not a control.

Buyer check 5: Ask the MSP to sign a data-flow statement that identifies which Blackpoint services receive CUI, which receive SPD only, and how the conclusion was tested.

What must be documented in the SSP and customer responsibility matrix?

Document the entire service relationship, not just the Blackpoint agent.

Part 170 requires an OSA using ESP services to describe the relationship and account for responsibilities in its system security plan. For Level 2 self-assessment scoping, the current customer-responsibility-matrix language is in 32 CFR §170.16(c)(3)(iii). The six-year retention provision for Level 2 self-assessment evidence is in §170.16(c)(4).

Those paragraph references matter. The older draft references to §170.16(a)(1)(iii) and §170.16(a)(4) did not point to the current Level 2 self-assessment provisions.

Your SSP and CRM should answer at least these questions:

  • What Blackpoint service and tier are deployed?
  • Which legal entity contracts with your company?
  • Which MSP entity operates the service?
  • Which Blackpoint and subprocessor systems receive data?
  • Which CUI assets and Security Protection Assets supply telemetry?
  • Which fields leave the environment?
  • Which requirements are operated by the contractor, MSP, Blackpoint, or jointly?
  • Who supplies evidence for each assigned requirement?
  • Who detects and who decides that a DFARS-reportable cyber incident has been discovered?
  • Who preserves system images, monitoring data, packet captures, and other evidence?
  • Who controls log source coverage, time synchronization, retention, search, and export?
  • Who approves changes to Privacy Mode and integrations?
  • What happens when the MSP, Blackpoint, or a subprocessor changes?
  • What data is returned, exported, retained, or deleted at termination?

A usable three-party responsibility map

Responsibility — Defense contractor / OSA — MSP or MSSP — Blackpoint
ResponsibilityDefense contractor / OSAMSP or MSSPBlackpoint
Define the assessment scopeAccountableSupports inventory and diagramsSupplies service architecture and data-flow facts
Determine CUI and SPD treatmentAccountableImplements and documents routingDocuments fields and service behavior
Maintain the SSPAccountableDrafts or updates assigned sections if contractedSupplies service description and evidence
Maintain the CRMAccountable for completenessIntegrates all provider and customer responsibilitiesSupplies its role and sub-tier dependencies
Configure agents, integrations, and Privacy ModeApproves and verifiesUsually responsible for deployment and change controlProvides platform capability and service-side configuration
Monitor alertsMaintains governance and escalation contactsOften first-line operational ownerPerforms contracted SOC/MDR functions
Decide whether a reportable cyber incident was discoveredContractor remains contractually accountableEscalates facts under a defined SLAEscalates detections and investigation facts
Submit the 72-hour reportContractorMay assist; do not assume authorityMay assist through MSP
Preserve 90-day incident artifactsAccountable for clause performanceCollects and preserves assigned evidencePreserves only what the service contract and platform support
Post applicable SPRS records and affirmationsContractor / Affirming OfficialMay prepare evidence; cannot replace the officialNo product-level posting
Produce assessment evidenceAccountable for the packageProduces service and configuration evidenceProduces provider/platform evidence available under the contract
Manage termination and data returnAccountableCoordinates export, transition, and deletionPerforms contracted export/deletion functions

A CRM that says "MSP responsible" in twenty rows is not a responsibility matrix. It is a deferral.

The assessor still needs to know which MSP staff, which Blackpoint function, which configuration, which evidence, and which customer action make the requirement work.

Decision point: If your current SSP does not identify the MSP-to-Blackpoint chain, stop asking whether the product is compliant and fix the architecture record first. Use the CMMC Readiness Checklist to collect the missing inputs, or find the right provider category before paying for another overlapping service.

Which CMMC Level 2 requirements can Blackpoint support?

Blackpoint can support several Level 2 requirements, especially around audit evidence, incident detection, risk visibility, and system integrity. It does not own all 110 requirements.

32 CFR §170.14 currently ties Level 2 to all 110 requirements in NIST SP 800-171 Revision 2 across 14 requirement families.

NIST has published Revision 3 and withdrawn Revision 2 from its current publications set. That does not make Revision 3 the CMMC-controlling version. Part 170 still incorporates Revision 2. Do not silently rewrite an assessment against Revision 3 unless and until the Department changes the governing rule or contract requirement.

The same version boundary matters at Level 3. Part 170 adds 24 selected requirements from the February 2021 edition of NIST SP 800-172. NIST later superseded that publication, but the CMMC rule does not automatically update because NIST published a newer revision.

Blackpoint support map across the 14 Level 2 families

NIST SP 800-171 Rev. 2 family — Potential Blackpoint contribution — What remains outside the product or shared
NIST SP 800-171 Rev. 2 familyPotential Blackpoint contributionWhat remains outside the product or shared
Access Control (AC)Detects suspicious authentication, privilege use, and some anomalous access eventsAccount provisioning, least privilege design, remote-access rules, session controls, wireless, mobile, and policy enforcement
Awareness and Training (AT)Incident examples may improve training contentTraining program, role-based training, completion records, and user accountability
Audit and Accountability (AU)Centralizes, correlates, searches, and retains covered logs; supports alert reviewLog-source inventory, event selection, time synchronization, failure handling, review procedures, and complete asset coverage
Configuration Management (CM)Detects some unauthorized changes or malicious activityBaselines, approved configurations, change control, software restrictions, inventories, and configuration governance
Identification and Authentication (IA)Identity telemetry and suspicious-sign-in detectionMFA architecture, authenticator management, password rules, service accounts, device identity, and lifecycle control
Incident Response (IR)Detection, triage, escalation, investigation context, and contracted response actionsContractor incident plan, reportability decision, DoD reporting, tabletop exercises, communications, and lessons learned
Maintenance (MA)May detect malicious maintenance activityMaintenance authorization, tools, personnel, remote maintenance controls, and records
Media Protection (MP)Little direct contributionMedia marking, access, sanitization, transport, storage, and disposal
Personnel Security (PS)Little direct contributionScreening, termination, transfer, access removal, and personnel procedures
Physical Protection (PE)Little direct contribution to customer facilitiesFacility access, visitors, physical monitoring, alternate work sites, and physical records
Risk Assessment (RA)Threat intelligence and security findings can inform risk decisionsFormal risk assessments, vulnerability scanning scope, remediation governance, and risk acceptance
Security Assessment (CA)Reports and retained evidence can support control assessment and monitoringAssessment independence, POA&M governance, security plans, continuous-monitoring strategy, and official scoring
System and Communications Protection (SC)Detects some network and communications threatsBoundary design, segmentation, cryptography, key management, CUI transmission, DNS, VoIP, mobile code, and architecture
System and Information Integrity (SI)Strongest alignment: malicious-code detection, monitoring, alerting, response, and threat informationPatch management, flaw remediation, spam protection, complete monitoring coverage, and organizational response decisions

This table is a support map, not a scoring worksheet. A Blackpoint report may be evidence that a process occurred. It is not automatically evidence that every part of a requirement is met.

For example, collecting logs does not prove AU.L2-3.3.1 through 3.3.9 are all satisfied. You still need to show which events are logged, who reviews them, how timestamps are synchronized, what happens when logging fails, how audit information is protected, and whether the sources cover the assessed system.

Buyer check 6: Before signing, make the MSP map each promised CMMC outcome to the exact Rev. 2 requirement, operating owner, evidence artifact, frequency, and exception path. Reject a generic "supports all 110 controls" claim.

Can Blackpoint help with the 72-hour report and 90-day preservation duty?

It can help you detect, investigate, and preserve evidence. It cannot move the DFARS duty off the contractor by itself.

DFARS 252.204-7012(c) requires rapid reporting within 72 hours of discovery of a cyber incident affecting a covered contractor information system or covered defense information as described by the clause.

Paragraph (e)—not paragraph (d)—requires the contractor to preserve and protect images of affected systems and relevant monitoring or packet-capture data for at least 90 days from submission of the cyber-incident report so DoD can request the information.

Those are different jobs:

  • MDR can help discover suspicious activity.
  • The contractor must have a process to determine whether the facts meet the contract's reporting trigger.
  • The contractor submits the report unless a properly authorized arrangement says otherwise.
  • The contractor must ensure the required evidence exists and is preserved.
  • A log-retention promise is not the same as preserving system images, memory, packet captures, malware, and the investigation record.

The contract terms that protect the clock

Ask for all of these in the MSP agreement or statement of work:

Term — Minimum question the contract must answer
TermMinimum question the contract must answer
Initial notificationHow quickly after Blackpoint or the MSP detects a potentially reportable event will the contractor receive notice?
Escalation availabilityIs a qualified human reachable around the clock, including weekends and holidays?
Discovery and handoffWhat facts, severity thresholds, and evidence are delivered so the contractor can make the reportability decision?
Evidence holdWho can place a legal/contractual hold on logs, images, packet captures, malware, and case data?
90-day preservationWhich required artifacts can Blackpoint or the MSP preserve, and which must the contractor collect elsewhere?
Malware submissionWho isolates and transfers malicious software without sending unrelated proprietary data?
DoD follow-upWho responds when DoD asks for additional information or equipment access?
Sub-tier cooperationIs Blackpoint contractually required to support the MSP and contractor during a DFARS investigation?
Export formatCan the contractor obtain readable, timestamped, integrity-protected evidence without the vendor's proprietary console?
Termination survivalDo incident-cooperation and evidence-access duties survive cancellation or MSP replacement?

A beautiful dashboard does not stop the 72-hour clock.

An "unlimited retention" phrase does not preserve a disk image the service never collected.

A 24/7 SOC does not protect you if the reseller agreement lets the alert sit in an MSP queue until Monday.

Buyer check 7: Put the notification and preservation workflow through a tabletop exercise before relying on it in a proposal or assessment.

Does Blackpoint have an SPRS score?

Do not confuse a Blackpoint security posture score with a DoD assessment result in SPRS.

The draft's earlier sentence that an SPRS score "is not an assessment result" was inaccurate. Under DFARS 252.204-7019 and 252.204-7020, the contractor's NIST SP 800-171 DoD Assessment result is posted in SPRS. That is an assessment result.

CMMC records also use SPRS, but they are not the same record.

Item — What it is — Who or what it belongs to
ItemWhat it isWho or what it belongs to
Blackpoint Security Posture Rating or similar vendor scoreA vendor-created operational metricThe monitored environment as represented inside the Blackpoint service
NIST SP 800-171 DoD Assessment scoreA Basic, Medium, or High DoD Assessment result under the DFARS methodologyThe contractor system and scope identified in the assessment
CMMC Level 2 (Self) result and statusThe organization's Level 2 self-assessment record under Part 170The OSA and its assessed scope
CMMC Level 2 (C3PAO) result and statusA certified third-party assessment result and resulting statusThe OSA and the certified assessment scope
Annual CMMC affirmationAn Affirming Official's attestation required to maintain the applicable statusThe OSA
Product dashboard scoreA product measurementNo independent regulatory status unless the governing rule expressly says so

Blackpoint does not give your company an SPRS score. Your CMMC consultant does not "own" your SPRS score. Your MSP may help assemble evidence, but the contractor must ensure the official record is accurate, current, tied to the right scope, and affirmed by the right person.

The current DFARS and CMMC ecosystem creates multiple records with similar vocabulary. Label each one by authority, date, scope, methodology, and expiration.

Buyer check 8: Any proposal using the words "SPRS score" must state whether it means a DFARS DoD Assessment, a CMMC self-assessment, a C3PAO result, or a private vendor rating.

How long should Blackpoint retain CMMC logs?

There is no single CMMC rule that says every log must be retained for one universal number of days.

Retention has to be derived from the evidence need, the contract, the incident plan, the requirement being implemented, and any other law or customer obligation that applies.

Blackpoint's current public LogIC material states that the service includes 365 days of encrypted log storage and supports compliance-oriented reporting. That is materially more useful than an old page that speaks loosely about every CMMC level. It still does not answer the entire retention question.

The four clocks buyers keep mixing together

Clock — Source — What it actually governs
ClockSourceWhat it actually governs
72 hoursDFARS 252.204-7012(c)Rapid reporting after discovery of a covered cyber incident
At least 90 days after report submissionDFARS 252.204-7012(e)Preservation of affected-system images and relevant monitoring or packet-capture data
Three-year CMMC Level 2 status period, subject to required annual affirmation32 CFR Part 170The life of a final Level 2 status, not a universal log-retention period
Six years32 CFR §170.16(c)(4)Retention of artifacts used as evidence for a Level 2 self-assessment
365 days, as currently advertised for LogICBlackpoint product statementThe provider's included encrypted log-storage period for that offering, subject to the actual quote and contract

The six-year assessment-evidence rule does not mean every raw event must remain searchable in Blackpoint for six years. It means the evidence artifacts used for the Level 2 self-assessment must be retained as required. Some of those artifacts may be exported reports, screenshots, configurations, tickets, approvals, test records, or other evidence—not the entire raw log corpus.

The 90-day incident-preservation rule does not mean 90 days of ordinary logs is always sufficient. It starts from report submission and includes specific evidence types. If a threat was present for months before discovery, you may need historical data well beyond 90 days to investigate it.

A defensible retention decision

For each source, document:

  • why the source is collected;
  • which requirement or incident need it supports;
  • minimum searchable period;
  • archive period;
  • integrity and access controls;
  • export format;
  • deletion process;
  • storage location;
  • cost above the included tier;
  • who can place a hold;
  • what happens after termination.

Buyer check 9: Normalize the quote around evidence needs, not the most impressive retention number on the page.

What did we verify in Blackpoint's public documents?

Blackpoint publishes more useful trust material than the original draft credited—but not enough to replace your MSP's contract package.

We reviewed public materials available on August 27, 2026 and separated what the company states from what the public record does not establish.

Public source — What we verified — What it does not establish
Public sourceWhat we verifiedWhat it does not establish
CMMC Privacy Mode announcement, dated February 23, 2026Blackpoint describes a tenant-level Privacy Mode intended to maintain MDR while keeping CUI away from its SOCIndependent validation of every integration, field, support path, or production tenant
Blackpoint Trust Center and current SOC 2 announcementBlackpoint states it completes annual SOC 2 Type II work; its current announcement identifies a May 1, 2025–April 30, 2026 observation period, zero exceptions, and the security, availability, and confidentiality criteriaThe report contents, because the detailed report is available under an MNDA rather than fully public; a SOC 2 report is also not a CMMC Status
Public subprocessor informationA public subprocessor list is availableThat every MSP integration, ticketing platform, or customer-specific downstream provider appears in Blackpoint's list
Public reseller agreementBlackpoint has a documented channel/reseller modelThat Blackpoint can only be purchased through an MSP; the agreement preserves direct and other distribution rights
Public GDPR/data-transfer materialBlackpoint states that data may be transferred to AWS in the United States and vetted third partiesA customer-specific CUI data-location commitment, U.S.-person-only operations promise, or complete data-flow answer for the quoted service
Current LogIC materialsBlackpoint currently advertises 365 days of included encrypted log storage and CMMC/compliance reporting supportExact source coverage, overage pricing, export rights, evidentiary sufficiency, or assessor acceptance
Cyber AB Marketplace search, August 27, 2026No public Blackpoint entry surfaced under that name in our searchAbsence of every credential, affiliate, later listing, or private assessment
FedRAMP Marketplace search, August 27, 2026No public authorization surfaced under the Blackpoint Cyber name in our searchThat an SPD-only deployment is unusable or that no separately named underlying service has relevant evidence
Public website and legal materialsEnough information to ask better questions about privacy, subprocessors, channel terms, and retentionThe signed customer SLA, MSP-specific CRM, complete incident terms, tenant configuration, or end-to-end CUI flow

Three corrections follow from this review.

First, the subprocessor list is not hidden. It is publicly linked.

Second, the public record is not limited to website terms. A public reseller agreement exists.

Third, saying Blackpoint sells "exclusively through MSPs" is too absolute. The public model is plainly MSP-centered, but the agreement preserves other distribution paths. The accurate buying conclusion is simpler: most defense contractors should expect the MSP to be a critical contractual and operational layer, and they must evaluate that layer—not assume direct contracting is impossible.

The documents you still need from the actual seller

Public trust pages are not your assessment package. Request:

  • the signed statement of work;
  • service-level and incident-notification terms;
  • the exact service description;
  • the contractor–MSP–Blackpoint CRM;
  • the current data-flow and architecture diagrams;
  • Blackpoint and MSP subprocessor disclosures;
  • the SOC 2 report and relevant bridge letter under the required NDA;
  • Privacy Mode configuration and test evidence;
  • data-location and personnel-access commitments;
  • log-source, retention, export, and deletion terms;
  • incident-preservation support;
  • offboarding and transition assistance;
  • evidence deliverables by CMMC requirement;
  • current insurance and breach-notification terms;
  • any public or private status claim tied to the exact legal entity.

A SOC 2 report can help you assess the provider. It does not score your Level 2 environment.

A subprocessor list can help you trace the chain. It does not prove the integration sends no CUI.

A Privacy Mode announcement can help you design a test. It is not the test.

Buyer check 10: Make document delivery a condition of purchase, with due dates and named owners. "Available after onboarding" is too late for documents that decide whether you should onboard.

What do Blackpoint's current LogIC claims change?

The current 365-day storage claim improves the evidence proposition. It does not turn LogIC into a complete CMMC platform.

Older product pages and support language can survive in search long after the service changes. One older Blackpoint page used loose language about supporting CMMC Levels 1, 2, and 3 and contained a "HIPPA" typo. That page should not be the basis for a current regulatory conclusion.

The current decision should use the current product statement, the quote, the contract, and the actual tenant.

What 365 days can help with

  • investigating activity that predates discovery;
  • showing recurring log review;
  • supporting threat hunting and trend analysis;
  • preserving searchable operational evidence across an assessment cycle;
  • reducing the chance that a needed event aged out after a short default period;
  • consolidating evidence for selected Audit and Accountability, Incident Response, Risk Assessment, and System and Information Integrity activities.

What 365 days does not prove

  • every CUI asset and Security Protection Asset sends the required events;
  • timestamps are synchronized;
  • logging failures are detected and escalated;
  • audit records are protected from unauthorized access and deletion;
  • the contractor reviewed the right events at the right frequency;
  • packet captures, disk images, memory images, malware, and case evidence are preserved;
  • assessment artifacts are retained for six years;
  • the customer can export evidence after changing MSPs;
  • the storage period applies to every source without a volume cap or extra charge;
  • the data is stored in an acceptable location for the contractor's requirements.

Version-control the claim inside your procurement file:

Verified August 27, 2026: Blackpoint's public LogIC page advertises 365 days of included encrypted log storage. Contract applicability, source limits, overage terms, export, location, deletion, and service changes require verification in the quote and agreement.

That sentence can survive product-page drift because it records what was verified, when, and what remains open.

Who owns what when an MSP resells Blackpoint?

The MSP is not a pass-through invoice. It is often the point where the CMMC design succeeds or fails.

The MSP may select the tier, install the agents, enable integrations, configure Privacy Mode, route alerts, create PSA tickets, decide who receives escalation, maintain the documentation, export reports, and negotiate the Blackpoint contract.

Two contractors can use the same Blackpoint platform and have materially different CMMC outcomes because their MSPs operate it differently.

The operating chain must match the written chain

Compare these two versions.

Weak version:

Blackpoint provides 24/7 MDR. The environment is monitored.

Assessable version:

The MSP deploys and manages the Blackpoint endpoint and identity integrations on the assets listed in Appendix A. Privacy Mode is enabled for the designated CUI tenant under change-control record CM-042. Blackpoint receives the SPD fields listed in Data Flow DF-07 and does not receive file content in the tested normal-alert path. The MSP reviews Critical and High alerts continuously, notifies the contractor's incident lead within the contracted threshold, and exports monthly AU and SI evidence to the contractor repository. The contractor makes DFARS reportability decisions and maintains the six-year self-assessment evidence archive. Exceptions and support sessions follow IR-06.

The second version is longer because reality is longer.

Watch the MSP's own tools

Even when Blackpoint Privacy Mode works as intended, the MSP may route data into:

  • a professional services automation platform;
  • a remote monitoring and management platform;
  • email;
  • chat;
  • a documentation vault;
  • a password manager;
  • a backup system;
  • a ticketing portal;
  • a remote-access tool;
  • a separate SIEM;
  • an AI summarization tool;
  • the MSP's own analyst notes.

Those services can create additional ESP relationships and additional CUI or SPD paths. The Blackpoint review is incomplete until the MSP toolchain is included.

This is also why you should not map a password-manager "login event" as if Blackpoint received the password itself. A login event can be SPD. An actual password, token, or secret is a different and more serious data object. Name the field you observed.

MSP replacement risk

Ask what survives if the MSP relationship ends:

  • Can you keep the Blackpoint tenant?
  • Can another MSP assume it?
  • Can you export raw logs and cases?
  • In what format?
  • How long is access available after termination?
  • Who deletes agents and revokes integrations?
  • Who provides final evidence and deletion confirmation?
  • Does the incident-cooperation duty survive?
  • Does the new MSP receive historical data?
  • Is the license portable, or must you rebuild?

The cheapest quote can become the most expensive option when it traps the only copy of your evidence behind the seller you are replacing.

Decision point: If your MSP cannot explain its own tools, sub-tier providers, and exit process, Blackpoint is not yet the buying decision. The MSP is.

What should you ask the MSP before buying Blackpoint?

Send the questions below before the demonstration. A real answer should name a document, setting, owner, frequency, or contract term.

The 12-question Blackpoint CMMC evidence request

  1. What exact Blackpoint services and license tiers are included?

List MDR, identity, cloud, LogIC, retention, response, vulnerability, reporting, and optional modules separately.

  1. Who are the contracting and operating entities?

Name our legal counterparty, the MSP entity performing the work, Blackpoint's legal entity, and every material sub-tier provider.

  1. Which systems and assets are covered?

Provide endpoint, server, identity, network, cloud, and log-source counts; identify exclusions and the process for discovering missed assets.

  1. What data reaches Blackpoint?

Supply the field-level data-flow diagram for normal alerts, investigations, tickets, notifications, support, exports, and forensic collection.

  1. How is Privacy Mode configured and verified?

State the tenant, setting, change owner, default behavior, exceptions, update process, and latest test results.

  1. Where can CUI or SPD appear outside Blackpoint?

Include the MSP's PSA, RMM, ticketing, email, chat, documentation, backup, AI, and remote-support systems.

  1. Which CMMC requirements do you operate or support?

Map each promise to the exact NIST SP 800-171 Rev. 2 requirement, responsible party, procedure, frequency, and evidence artifact.

  1. What are the incident-notification and cooperation terms?

Give the initial alert threshold, maximum notification time, 24/7 escalation path, investigation support, evidence hold, malware handling, and DoD follow-up duties.

  1. What evidence can be preserved for DFARS 252.204-7012(e)?

Separate logs from packet captures, system images, memory images, malware, case records, and other monitoring data.

  1. What are the retention, export, and termination terms?

State included days, source and volume limits, archive pricing, hold capability, export format, access after cancellation, and deletion certification.

  1. What assurance documents will we receive?

Include the current SOC 2 report/bridge letter, subprocessor list, data-location statement, personnel-access commitments, penetration-test summary, vulnerability-management evidence, insurance, SLA, service description, SSP language, and CRM.

  1. Who owns SPRS and assessment support?

Identify who prepares the DoD Assessment evidence, who posts the official record, who serves as Affirming Official, and who supports a future C3PAO assessment. Do not use "we manage your SPRS score" as the answer.

Copy-and-paste request

We are evaluating Blackpoint Cyber for a CMMC Level 2 environment. Before pricing approval, please provide the exact service tier, asset and log-source scope, end-to-end data-flow diagram, Privacy Mode configuration and test evidence, list of all ESPs/subprocessors, customer responsibility matrix, SSP service language, incident-notification and DFARS preservation workflow, retention/export/termination terms, current assurance documents, and a Rev. 2 requirement-to-evidence map. Please label each statement as contractually committed, currently configured, provider-stated, or proposed.

That last sentence matters. It stops a seller from blending future design, current production, and marketing claims into one answer.

How much does Blackpoint Cyber cost for CMMC?

Blackpoint does not publish one standardized end-customer CMMC price that a defense contractor can rely on. Expect an MSP quote shaped by service scope.

We did not retain an employee-count claim in this review. Headcount changes, is not a useful proxy for assessment readiness, and no current primary company filing was needed to make the buying decision.

The quote can vary with:

  • number of endpoints and servers;
  • number of identities and cloud tenants;
  • endpoint operating systems;
  • log sources and daily ingestion volume;
  • included searchable retention;
  • archive requirements;
  • MDR and response tier;
  • vulnerability or exposure modules;
  • network or cloud integrations;
  • after-hours escalation;
  • onboarding and tuning;
  • evidence reporting;
  • documentation and CRM work;
  • incident-response hours;
  • MSP management fee;
  • support and project labor;
  • contract length;
  • minimum commitments;
  • export, transition, or termination charges.

Normalize every quote before comparing it

Quote field — Vendor A — Vendor B — Vendor C
Quote fieldVendor AVendor BVendor C
Covered endpoints
Covered servers
Covered identities
Included log sources
Included daily ingestion
Searchable retention
Archive retention
24/7 human monitoring
Response actions included
Initial incident-notice commitment
DFARS evidence-preservation support
Privacy Mode configuration/testing
SSP/CRM documentation
Monthly evidence package
Onboarding fee
Recurring platform fee
Recurring MSP labor
Overage formula
Export fee
Termination assistance
Minimum term
Total first-year cost
Total three-year cost

A low per-endpoint number can hide log ingestion, MSP labor, project work, documentation, or incident support. A higher number can include work you would otherwise buy separately.

Compare the total architecture cost, not just the agent.

For broader budgeting, use our CMMC Level 2 Cost guide. If you are deciding between a full-service MSP, a consultant-led internal program, or a secure enclave, compare the entire delivery model before comparing MDR prices.

Buyer check 11: Require a three-year total, an assumptions page, and a list of excluded work. CMMC projects go over budget in the nouns the quote leaves undefined.

Who is Blackpoint a good fit for?

Blackpoint is most attractive when the MSP relationship is already the operating model and the contractor is willing to verify the data boundary.

Stronger fit

Blackpoint may fit well when:

  • your contractor environment is managed by an MSP that already operates Blackpoint competently;
  • you want 24/7 managed detection rather than building an internal SOC;
  • the MSP will produce a real SSP service description and integrated CRM;
  • Privacy Mode can be enabled, tested, monitored, and contractually protected;
  • you need longer searchable log history than a short default platform provides;
  • the product covers the actual CUI assets and Security Protection Assets;
  • incident-notification and preservation duties are written into the contract;
  • you can obtain evidence and exports without depending on a salesperson;
  • the MSP discloses its PSA, RMM, ticketing, remote-support, and other sub-tier tools;
  • the total price replaces multiple tools or internal staffing costs.

Weaker fit

Blackpoint is a weaker fit when:

  • the seller's entire CMMC answer is "our stack is compliant";
  • the MSP will not disclose sub-tier providers or data flows;
  • CUI reaches a Blackpoint cloud service but no one can produce the required cloud-security evidence;
  • Privacy Mode is mentioned but not included, configured, tested, or monitored;
  • the contractor needs direct control of the tenant, contract, evidence, and exit path but the MSP will not provide it;
  • the quote covers MDR but excludes SSP, CRM, evidence, log engineering, incident planning, and assessment support that the buyer assumed were included;
  • the environment uses unsupported assets or log sources;
  • the contractor expects Blackpoint to replace access control, configuration management, training, physical security, media protection, personnel security, or governance;
  • no one at the contractor will own the CMMC program;
  • the MSP cannot support a future assessor without improvising.

A green-yellow-red decision rule

Status — Meaning — Next action
StatusMeaningNext action
GreenData flow is tested; CUI is handled only where intended; SPD path is documented; CRM is complete; incident and evidence terms are signed; quote is normalizedProceed subject to ordinary procurement and security review
YellowProduct appears suitable, but data fields, sub-tier providers, CRM, retention, or contract terms remain openHold signature; close the evidence gaps in writing
RedSeller claims the tool makes you compliant, refuses architecture details, cannot explain CUI handling, or will not commit to incident/evidence dutiesDo not rely on the service for the claimed CMMC outcome

Buyer check 12: Do not convert a yellow architecture into a green purchase because the assessment deadline feels close. The Phase II suspension removed that excuse anyway.

How should you compare Blackpoint with Huntress or Arctic Wolf for CMMC?

Do not compare the three vendors on brand familiarity or an alerting demonstration. Make each seller answer the same CMMC evidence request.

A feature-by-feature bake-off becomes misleading when the contracted MSP, service tier, asset coverage, data path, retention, and response terms are different. The public record also changes too quickly to present an unverified checkbox table as fact.

Use a controlled comparison instead.

Decision criterion — Blackpoint proposal — Huntress proposal — Arctic Wolf proposal
Decision criterionBlackpoint proposalHuntress proposalArctic Wolf proposal
Exact legal seller and service operator
Direct contract or MSP/reseller chain
Exact services and tiers
CUI path
SPD path
Published CUI-separation feature and tested result
CSP/FedRAMP evidence if CUI enters cloud service
Endpoints, identities, cloud, and network coverage
Log sources and ingestion limits
Searchable and archived retention
Initial incident-notice commitment
90-day preservation support
Human response actions
Customer/MSP/provider CRM
SSP-ready service description
Rev. 2 requirement-to-evidence map
SOC 2 and other assurance evidence
Data location and personnel access
Subprocessors and MSP toolchain
Export, portability, and termination
Three-year total cost

Blackpoint has a distinct public CMMC talking point in Privacy Mode. That gives it a useful question to answer. It does not let Blackpoint skip the rest of the table.

A competitor without an identically named feature may still produce a defensible no-CUI architecture. A competitor with stronger marketing may still fail the contract test. An assessor will not award points for the slogan.

For more vendor research, use the CMMC Provider Reviews hub. For software that manages evidence and workflows rather than replacing the MDR service, see our CMMC software guide.

Does the Phase II suspension change this Blackpoint decision?

It changes the near-term procurement rollout. It does not make the architecture, DFARS duties, or Level 2 self-assessment work optional.

Phase I began November 10, 2025. The original phased plan placed Phase II from November 10, 2026 through November 9, 2027. On July 13, 2026, the Department suspended the Phase II transition.

During the suspension, the official direction allows CMMC Level 1 (Self) and Level 2 (Self) designations in the phased implementation and stops the move to mandatory Level 2 (C3PAO) and Level 3 requirements under that transition.

That is material. A page that still says Phase II will automatically begin November 10, 2026 is outdated.

It is not a cancellation of CMMC.

What remains live

  • contract clauses already in your awards;
  • DFARS 252.204-7012 safeguarding and incident duties where included;
  • DFARS 252.204-7019 and -7020 DoD Assessment/SPRS requirements where included;
  • DFARS 252.204-7021 requirements where included and applicable under current implementation;
  • Level 1 and Level 2 self-assessment requirements used during the suspension;
  • subcontract flowdowns;
  • prime-contractor and customer cybersecurity demands;
  • SPRS accuracy and applicable affirmations;
  • the cost of redesigning a weak provider chain later;
  • voluntary C3PAO assessments and provider assessments that organizations choose to pursue.

What changed

  • the planned mandatory transition to Phase II did not proceed on July 13, 2026;
  • contracting activity under the phased rollout is not to designate Level 2 (C3PAO) or Level 3 during the suspension;
  • schedules, procurement assumptions, and readiness plans tied to the old November 10, 2026 Phase II start need updating.

What to do now

  1. Read the actual clauses in your current and target contracts.
  2. Confirm the CMMC level and assessment type designated for each procurement.
  3. Keep implementing the Rev. 2 requirements that control the current Level 2 program.
  4. Use the pause to repair provider contracts, data flows, SSP language, and evidence—not to postpone them.
  5. Track official Department and acquisition updates rather than vendor countdown pages.

The suspension gives buyers more time to ask Blackpoint and the MSP the hard questions. It does not make those questions less expensive.

What we actually verified—and what we did not

This review uses three evidence labels.

Regulation-stated

A claim appears in the controlling rule, clause, or incorporated publication. Examples:

  • Level 2 currently uses 110 NIST SP 800-171 Rev. 2 requirements.
  • ESP and Security Protection Asset treatment is addressed in 32 CFR §170.19.
  • 72-hour reporting is in DFARS 252.204-7012(c).
  • 90-day preservation is in DFARS 252.204-7012(e).
  • DFARS DoD Assessment results are posted in SPRS under 7019/7020.
  • CMMC status and affirmation duties are addressed in Part 170 and DFARS 7021.
  • Level 2 self-assessment CRM and evidence-retention provisions appear in §170.16(c).

Provider-stated

Blackpoint publishes the claim, but we have not independently tested every implementation. Examples:

  • Privacy Mode keeps CUI away from the SOC while maintaining MDR.
  • LogIC includes 365 days of encrypted log storage.
  • current SOC 2 Type II details stated by the company;
  • data-transfer and subprocessor descriptions;
  • product support for compliance reporting.

Operationally verified

The buyer has tested the specific production tenant, contract, data flow, and process. We did not perform that level of verification.

We did not:

  • operate a Blackpoint tenant;
  • inspect a defense contractor's Blackpoint configuration;
  • run packet captures against Privacy Mode;
  • inspect a customer alert, case, PSA ticket, support session, or export;
  • obtain the detailed SOC 2 report under MNDA;
  • review a signed customer SLA or MSP-specific statement of work;
  • verify a contractor's CRM or SSP;
  • interview Blackpoint analysts under a customer engagement;
  • inspect the FedRAMP evidence for an exact CUI-handling service;
  • conduct a C3PAO assessment;
  • confirm that every current reseller deploys the product the same way.

Those are not minor caveats. They are the line between a public-source review and a production security decision.

Our public-document review was last verified August 27, 2026. Product pages, legal terms, marketplace listings, and CMMC implementation can change. Send corrections with the source and effective date through our Corrections Policy.

Blackpoint Cyber CMMC FAQ

Does Blackpoint Cyber make a contractor CMMC compliant?

No. Blackpoint can support selected security and evidence activities. The contractor's CMMC Status applies to the contractor's assessed scope and depends on the full implementation, not one tool.

Can Blackpoint Cyber itself be CMMC assessed?

An ESP may voluntarily undergo a CMMC assessment for its own scoped information system. That would not certify the Blackpoint product or automatically transfer status to a customer. We did not verify a public Blackpoint status under that name in the Cyber AB Marketplace on August 27, 2026.

Is Privacy Mode required by CMMC?

No named Blackpoint feature appears in the CMMC rule. Privacy Mode is a provider feature that may help create a defensible no-CUI data path. The requirement is to protect and accurately scope the data and service—not to buy a named feature.

Does Privacy Mode remove Blackpoint from the assessment scope?

Not automatically. If Blackpoint handles SPD, the service remains relevant under the Security Protection Asset/ESP treatment. Privacy Mode may change whether Blackpoint also handles CUI.

Is Blackpoint a cloud service provider under DFARS 252.204-7012?

That depends on the exact service and whether it provides cloud computing services that store, process, or transmit covered defense information. Do not classify the entire company from the logo. Classify the actual service and data flow.

Does Blackpoint need FedRAMP Moderate?

The FedRAMP Moderate-equivalent requirement becomes central when the contractor uses an external cloud service provider to store, process, or transmit covered defense information under DFARS 252.204-7012. An SPD-only service path is different. The no-CUI conclusion must be tested and documented.

Can my MSP leave Blackpoint out of the SSP because Blackpoint is a sub-tier vendor?

No. The SSP must accurately describe the external service relationship and the requirements allocated through it. A sub-tier provider does not disappear because the MSP is the seller.

Is Blackpoint's 365-day storage enough for CMMC?

Not by itself. It may be useful, but there is no single universal CMMC log-retention number. You still need source coverage, review, integrity, export, incident preservation, six-year self-assessment evidence retention where applicable, and any contract-specific period.

Does Blackpoint satisfy the 72-hour cyber-incident reporting rule?

Blackpoint can help detect and escalate an event. The contractor remains responsible for complying with DFARS 252.204-7012 when the clause applies. The contract must provide enough notification and evidence for the contractor to act.

Is the 90-day preservation requirement in DFARS 252.204-7012(d)?

No. The current preservation language is in paragraph (e). Paragraph (d) addresses submission of malicious software.

Is an SPRS score an assessment result?

A NIST SP 800-171 DoD Assessment score posted under DFARS 7019/7020 is an assessment result. A Blackpoint product posture rating is not that result. A CMMC self-assessment or C3PAO record is another distinct record.

Does CMMC Level 2 now use NIST SP 800-171 Revision 3?

No. NIST has published Revision 3, but the current CMMC rule still incorporates Revision 2 for Level 2. Rev. 3 does not become controlling merely because NIST published it.

Does CMMC Level 3 now use the newest NIST SP 800-172 revision?

Not under the current rule. Part 170 identifies 24 selected requirements from the February 2021 SP 800-172 publication. A later NIST revision does not silently amend the CMMC rule.

Did the July 2026 suspension cancel CMMC?

No. It suspended the planned Phase II transition. Level 1 and Level 2 self-assessment designations remain available during the suspension, and applicable DFARS, SPRS, contract, and safeguarding obligations remain.

Can I buy Blackpoint directly?

Blackpoint's public model is MSP-centered, and many buyers will contract through an MSP. Its public reseller agreement does not support the absolute claim that every sale must be indirect. Ask Blackpoint and the proposed seller about the current channel for your account.

Is Blackpoint better than Huntress or Arctic Wolf for CMMC?

The answer depends on the exact service tier, seller, data flow, asset coverage, retention, response contract, CRM, evidence package, and total cost. Run each proposal through the same evidence request rather than relying on a generic brand ranking.

Where should you go from here?

Blackpoint deserves a serious look when you need managed detection and your MSP can turn the product into a documented service.

It does not deserve a shortcut.

Before signing:

  1. Map the data. Separate CUI, SPD, credentials, forensic artifacts, tickets, and support access.
  2. Map the parties. Name the contractor, MSP, Blackpoint, and every sub-tier service.
  3. Map the requirements. Use NIST SP 800-171 Rev. 2, not a marketing control list and not Rev. 3 as though it already controls CMMC.
  4. Map the evidence. Identify the artifact, owner, frequency, repository, and retention period for every promised outcome.
  5. Map the contract. Protect the 72-hour escalation, 90-day preservation support, data location, Privacy Mode, export, and termination path.
  6. Test production. Prove the real tenant behaves like the diagram.
  7. Update the record. Put the final service relationship into the SSP, CRM, incident plan, asset inventory, data-flow diagrams, and applicable SPRS process.

Then make the buying decision.

Not before.

Choose the next expensive decision, not another generic call

  • Use Find My CMMC Path to identify the provider category that matches your actual gap.
  • Review the CMMC Levels guide if your level or assessment type is still unclear.
  • Work through the CMMC Readiness Checklist before asking a provider to price undefined scope.
  • See the CMMC Level 2 Cost guide before comparing a platform quote with a full-service engagement.
  • Browse CMMC Provider Categories when you need to separate consultants, MSPs, MSSPs, C3PAOs, enclave providers, and GRC software.
  • Request a matched provider path when the scope, provider category, and buying criteria are clear enough for a useful introduction.

The right question is not whether Blackpoint has a CMMC page.

It is whether the Blackpoint deployment your MSP is selling can survive contact with your contract, your data, your incident clock, your assessor, and your next MSP.


Primary sources and verification record

CMMC program and current implementation

DFARS and SPRS

NIST publications

Blackpoint public materials

Public-source review completed: August 27, 2026 Next scheduled factual review: when the Department lifts or changes the Phase II suspension, Part 170 is amended, the controlling NIST incorporation changes, or Blackpoint materially changes Privacy Mode, LogIC, its assurance documents, or its service terms.

Change log

  • August 27, 2026: Corrected the Phase II status; distinguished product capability from provider and OSA CMMC Status; corrected §170.16 CRM and evidence-retention paragraph references; corrected DFARS 252.204-7012 preservation from paragraph (d) to paragraph (e); separated private posture ratings from DFARS and CMMC SPRS records; updated Rev. 2/Rev. 3 and SP 800-172 version boundaries; corrected public-document, subprocessor, reseller, data-transfer, and LogIC statements; added the three-party responsibility map, four-clock retention table, quote-normalization worksheet, Privacy Mode acceptance test, and current verification labels.