The Defense Compliance ReportCMMC 2.0 & the Defense Industrial Base

Cloud security review · primary-sourced · last reviewed August 2026

CrowdStrike CMMC Review: What Falcon Covers, What It Doesn't, and Which Cloud You Actually Need

Last updated:

Last verified: against CMMC rules, DFARS, NIST publications, DoD implementation materials, FedRAMP records, and CrowdStrike product, authorization, pricing, and incident materials.

CrowdStrike CMMC review illustration showing six cloud regions, separated CUI and security telemetry paths, and a protected contractor boundary

By The Defense Compliance Report Editorial Team Last reviewed: August 2026 · Last verified: August 27, 2026


Here is the short version of this CrowdStrike CMMC review, before you scroll another inch.

CrowdStrike is not a CMMC assessment or readiness provider, and no software product can receive a CMMC Status. Under 32 CFR § 170.4, a CMMC Status belongs to an Organization Seeking Assessment's information system and is officially stored in SPRS. That is separate from the NIST SP 800-171 DoD Assessment score that contractors post to SPRS under DFARS 252.204-7019 and 252.204-7020.

What CrowdStrike actually holds is a current FedRAMP Marketplace record for CrowdStrike Falcon Platform for Government, the offering CrowdStrike associates with GovCloud-1, at Class D (High). CrowdStrike also states that its GovCloud-2 offering has a DoD Impact Level 5 provisional authorization. Neither record describes the commercial US-1, US-2, US-3, or EU-1 Falcon regions.

That's the part almost nobody checks.

For a typical Level 2 deployment in which Falcon provides security functions and processes Security Protection Data without CUI, Falcon belongs in the assessment scope as a Security Protection Asset under 32 CFR § 170.19. The answer changes when CUI—or, for the DFARS cloud-service clause, covered defense information—enters the service. There are several common ways that can happen. We'll get to all of them.

First, the thing that decides everything else.


How we produced this analysis

Evaluation depth: documentary review. On August 27, 2026 we read CrowdStrike's published product pages, press releases, developer documentation, government data sheets, current public pricing, and current FedRAMP Marketplace record. We checked regulatory claims against 32 CFR Part 170 on the eCFR, the DFARS clauses on Acquisition.gov, the controlling NIST publications on CSRC, and the Department of War's current CMMC implementation materials. We did not test Falcon hands-on, inspect a customer tenant, obtain a private government quote, review a nonpublic FedRAMP security package, or interview CrowdStrike.

The Defense Compliance Report has no compensation relationship with CrowdStrike, Coalfire, or Coalfire Federal. We publish no score, no star rating, and no ranking. Nothing on this page routes to CrowdStrike.

We are an independent trade publication on CMMC and Defense Industrial Base compliance. We are not affiliated with the Cyber AB, the Department of War, DCMA DIBCAC, NIST, FedRAMP, or any U.S. government agency. This page is educational and is not legal, contractual, cybersecurity, or compliance advice.

Our review process is documented in our Methodology, Editorial Standards, and Corrections Policy.

The Defense Compliance Report is the independent decision resource for CMMC and Defense Industrial Base compliance—explaining the controlling rule and contract clauses, separating regulatory fact from operational judgment, and mapping a contractor's level, CUI scope, assessment type, and timeline to the right provider category before the contractor spends six figures.


The verdict, on one screen

Bottom line — Best fit — Not a fit — The qualifier that changes everything
Bottom lineBest fitNot a fitThe qualifier that changes everything
Falcon can carry real weight inside a CMMC environment. It is not the compliance program, and buying it creates no CMMC Status or SPRS score.Contractors that need serious endpoint, identity, vulnerability, logging, or managed-detection capability and have someone—internal or contracted—who will operate it and preserve evidence.Contractors hoping one vendor will scope the boundary, write the SSP and POA&M, host the CUI, operate every requirement, and perform the assessment.Which Falcon cloud your tenant uses, which modules are inside the quoted authorization boundary, and whether CUI or covered defense information enters the service.

Which CrowdStrike cloud are you actually in?

CrowdStrike's current public automation and developer materials identify six Falcon cloud regions: US-1, US-2, US-3, EU-1, US-GOV-1, and US-GOV-2. Any five-cloud comparison is now out of date.

The public federal records reviewed for this page describe the government offerings, not the four commercial regions. You can identify several regions from the console hostname and all six from the API base URL shown in your tenant. For US-3 and GovCloud-2, confirm the console hostname rather than guessing it.

We assembled this table from CrowdStrike's own developer and deployment documentation, the current FedRAMP Marketplace record, its government pages, and its public pricing.

Falcon cloud — Console indicator — API base URL — Current public authorization evidence — What it means for your CMMC decision
Falcon cloudConsole indicatorAPI base URLCurrent public authorization evidenceWhat it means for your CMMC decision
US-1 (commercial)falcon.crowdstrike.comapi.crowdstrike.comThe current Falcon Platform for Government FedRAMP record does not identify this commercial region.If Falcon handles only Security Protection Data, assess it as a Security Protection Asset. Do not describe this tenant as covered by the GovCloud-1 FedRAMP record.
US-2 (commercial)falcon.us-2.crowdstrike.comapi.us-2.crowdstrike.comThe current Falcon Platform for Government FedRAMP record does not identify this commercial region.Same CMMC scoping lane as US-1 when it handles only SPD. Analyze any CUI or covered-defense-information data flow separately.
US-3 (commercial)Confirm in your tenantapi.us-3.crowdstrike.comThe current Falcon Platform for Government FedRAMP record does not identify this commercial region.This is a current CrowdStrike region that older five-cloud comparisons omit. Do not infer a federal authorization from the CrowdStrike name alone.
EU-1 (commercial)falcon.eu-1.crowdstrike.comapi.eu-1.crowdstrike.comThe current Falcon Platform for Government FedRAMP record does not identify this commercial region.Same SPD-versus-CUI analysis, plus a data-residency question you should resolve before the assessor asks.
GovCloud-1 (US-GOV-1)falcon.laggar.gcw.crowdstrike.comapi.laggar.gcw.crowdstrike.comFedRAMP Marketplace lists CrowdStrike Falcon Platform for Government, package FR1807853629A, as FedRAMP Certified, Rev5, Class D (High), certified since March 12, 2025.This is the public High record that matters to most DIB buyers evaluating a CrowdStrike government environment. You still need the exact module boundary, service description, CRM, and contract terms.
GovCloud-2 (US-GOV-2)Confirm in your tenantapi.us-gov-2.crowdstrike.milCrowdStrike states that the Falcon platform has a DoD Impact Level 5 provisional authorization and positions this offering for DoW and National Security Systems work.IL5 can be decisive when the contract, agency, or data requires it. CMMC Level 2 by itself does not automatically require GovCloud-2.

The 60-second check

Log into your Falcon console. Then open the API-client screen and copy the base URL exactly.

  • api.crowdstrike.com = US-1
  • api.us-2.crowdstrike.com = US-2
  • api.us-3.crowdstrike.com = US-3
  • api.eu-1.crowdstrike.com = EU-1
  • api.laggar.gcw.crowdstrike.com = GovCloud-1
  • api.us-gov-2.crowdstrike.mil = GovCloud-2

If your tenant is US-1, US-2, US-3, or EU-1, CrowdStrike's GovCloud-1 FedRAMP record does not describe that tenant.

That is not a trick question or a technicality. It is the difference between offerings that share a logo but do not share the same public authorization record.

Now here's the part that makes this worth checking. On August 27, 2026, CrowdStrike's public pricing page displayed Falcon Go at $59.99 per device per year, Falcon Pro at $99.99, and Falcon Enterprise at $184.99, each with a self-service purchase path. The page did not display a GovCloud SKU or GovCloud price. A commercial checkout is not evidence that you bought the authorized government offering.

The failure mode is easy to create: buy a commercial Falcon bundle with a corporate card, deploy it across an in-scope environment, then write "FedRAMP High" into the SSP because the vendor brand has a High record somewhere. Every word in that sentence can look defensible except the one that matters: which offering and boundary actually serve your tenant.


Before you go further

The right CMMC provider is not the same for every contractor. The category you need—a C3PAO, readiness provider, MSSP, GRC platform, CUI enclave, or some combination—depends on your required level, whether you handle FCI or CUI, your assessment type, your existing stack, and your contract timeline. The solicitation and contract set the required status; a generic checklist does not.

Use Find My CMMC Path before you request quotes, and do not submit CUI, drawings, credentials, or sensitive contract details.

Jump to the CrowdStrike evidence request: 15 questions to ask before you buy or renew


Is CrowdStrike CMMC compliant?

No—and neither is any other product, because "CMMC compliant" is not a status a product can hold. Under 32 CFR § 170.4, a CMMC Status is the result of a CMMC assessment of an OSA's information system, officially stored in SPRS. Software and cloud services can support security requirements, generate artifacts, and sit inside an assessed boundary. They cannot receive your status for you.

Do not collapse that status into a second SPRS record. A NIST SP 800-171 DoD Assessment score is posted under DFARS 252.204-7019 and -7020. A CMMC Status and CMMC UID are used under 32 CFR Part 170 and DFARS 252.204-7021. Same system of record. Different assessment records. Different contract consequences.

This distinction is not pedantry. It is the single most expensive misunderstanding in the CMMC market, and it creates two predictable failures.

The first: a contractor buys a well-regarded security platform, checks a mental box, and later discovers nobody wrote the System Security Plan, nobody owns the Plan of Action and Milestones, and nobody can show that the technical setting was reviewed, exceptions were handled, and corrective actions were closed at the required cadence.

The second comes from vendor and reseller pages that compress a platform authorization, a contractor implementation, the shared-responsibility split, and an organization-level assessment outcome into one green checkmark. A page can call an offering "CUI compliant" or report "zero gaps." The rule does not create that product-level result. If the page cannot show the exact offering, scope, responsibility matrix, implementation, and assessment evidence behind the claim, close the tab.

Here's what is actually supportable:

  • Nothing in the public CrowdStrike materials reviewed for this page establishes that buying Falcon buys a C3PAO assessment or an RPO readiness engagement.
  • A Falcon subscription does not, by itself, define your CUI boundary, write your SSP or POA&M, operate every applicable security requirement, make your annual affirmation, or perform your formal assessment.
  • The Cyber AB Marketplace is the authoritative place to verify current CMMC ecosystem roles. It was unavailable during final verification, so this page does not publish a definitive claim that CrowdStrike—or the author of any applicability report—currently holds or lacks a Marketplace role.
  • What CrowdStrike does have is a current government cloud certification record, a broad module catalog, commercial and government deployment options, and managed security services. Those are real. They answer a different question than the one your contract asks.

Where does CrowdStrike land in your CMMC Level 2 scope?

When Falcon provides a security function to in-scope assets and the external service processes Security Protection Data without CUI, it lands in the Security Protection Asset lane under 32 CFR § 170.19. That means the relevant Falcon components and service relationship belong in your asset inventory, SSP, and network diagram, and the Security Protection Assets are assessed against the Level 2 security requirements relevant to the capabilities they provide.

Let's unpack that with the actual rule, because this is where most vendor pages hand-wave.

Security Protection Data (SPD) is defined in 32 CFR § 170.4 as data stored or processed by Security Protection Assets and used to protect the OSA's assessed environment. The definition expressly includes log files generated by or ingested by a Security Protection Asset, data about the configuration or vulnerability status of in-scope assets, and passwords that grant access to the assessed environment.

Falcon commonly works with exactly those kinds of records: endpoint telemetry, detections, policy configuration, vulnerability findings, identity signals, and security-event data. That does not make every field harmless. It establishes why the service belongs inside the scope analysis even when it is not handling CUI.

Table 3 at § 170.19(c)(1) puts Security Protection Assets in the Level 2 assessment scope. The rule requires an asset inventory, SSP treatment, and network-diagram treatment, then says those assets are assessed against the requirements relevant to the capabilities they provide. Not all 110 automatically. The relevant ones.

Table 4 at § 170.19(c)(2)(i) is the row that surprises people. When an External Service Provider processes SPD without CUI, the outcome is Security Protection Asset treatment whether or not the provider is a Cloud Service Provider.

Read that again, because it defuses most of the FedRAMP argument you're about to have with a sales engineer. If your Falcon service only handles SPD, the existence of a FedRAMP record does not change the Table 4 scoping outcome.

FedRAMP can still matter to risk management, procurement, customer requirements, and the quality of the evidence package. It just does not move an SPD-only service into a different Table 4 row.

Section 170.19(c)(2)(ii) tells you what documentation you owe: document the service in the SSP, obtain a service description from the provider, and document the Customer Responsibility Matrix. Note the first word. The rule says Customer Responsibility Matrix. Vendors frequently ship a "Shared Responsibility Matrix." Ask whether the document supplied for your offering satisfies the rule's CRM requirement, and get that answer in writing.

The Department's Level 2 scoping materials use monitoring services as the type of external security service this rule is designed to capture. Falcon is not exempt because it is familiar. Familiar security tooling is still in scope.

For the broader boundary analysis, use our CMMC Scoping Guide and verify the level your solicitation actually requires on CMMC Levels: Level 1 vs. Level 2 vs. Level 3.


Does CrowdStrike's FedRAMP authorization actually help you?

If Falcon handles SPD without CUI, the FedRAMP certification does not change the CMMC Table 4 result. If the cloud service stores, processes, or transmits CUI or covered defense information, the authorization becomes materially important.

So the operative question is not simply "is CrowdStrike FedRAMP authorized." It is:

Which CrowdStrike offering am I using, and what information enters it in my actual configuration?

Do not reduce this to exactly three paths. These are common paths a contractor should test, not an exhaustive list:

1. Real Time Response retrieval or collection. An authorized analyst can retrieve a file or artifact from an endpoint during an investigation. If that item is a drawing, technical data package, export-controlled artifact, or other CUI, the data-flow analysis changes. This is a workflow decision, not a product defect, but it needs policy, role, and evidence.

2. Data Protection workflows. A data-protection function may inspect content locally, create metadata, create excerpts, or send event details to the cloud depending on architecture and configuration. Do not assume that enabling the product automatically transfers the full CUI file. Ask CrowdStrike exactly what leaves the endpoint for the modules and policies you will use.

3. Telemetry and log fields. Filenames, paths, command lines, process arguments, usernames, email subjects, and event context can contain CUI or reveal CUI. The quiet path is often the field nobody put on the data-flow diagram.

4. Next-Gen SIEM ingestion. Once Falcon ingests logs from file servers, email, identity systems, firewalls, cloud workloads, or business applications, the content universe can be much larger than endpoint telemetry. Your source-by-source ingest plan matters.

5. Malware samples, sandbox submissions, support bundles, and case attachments. An operator can upload or submit an artifact that contains sensitive contract information even when the ordinary sensor telemetry does not. Restrict, train, and document these paths.

There can be others: integrations, APIs, automated workflows, analyst notes, exports, or custom fields. The correct answer comes from the actual architecture, not from the product category.

The two governing sources use related but different language:

  • CMMC Table 4 asks whether the external service processes CUI.
  • DFARS 252.204-7012(b)(2)(ii)(D) applies when a cloud service used in contract performance stores, processes, or transmits covered defense information. The CSP must meet security requirements equivalent to the FedRAMP Moderate baseline and comply with paragraphs (c) through (g) of the clause.

Do not treat every abstract CUI scenario as automatically identical to the clause's defined covered-defense-information scenario. Do not use that distinction to avoid the analysis either. Map the data to the contract, marking, source, and clause.

This is where GovCloud-1 stops being marketing and becomes a viable answer—not an automatic answer. The current FedRAMP Marketplace record is real, at High, and attached to a named government offering. But the brand-level sentence "CrowdStrike is FedRAMP High" still does not tell you:

  • whether your quoted modules are in the certified boundary;
  • whether your tenant is the certified offering;
  • what data the service stores or processes;
  • what you must implement under the CRM; or
  • whether CrowdStrike's contract accepts the DFARS incident, preservation, forensic-access, and damage-assessment obligations that apply to your use.

High is stronger than Moderate as a baseline. It is not permission to skip the boundary and contract.


Commercial Falcon, GovCloud-1, or GovCloud-2—which one do you buy?

These are different purchases with different authorization stories, deployment details, module availability, and pricing. Treating "CrowdStrike Falcon" as one undifferentiated product is the mistake that can force a second procurement cycle. The right environment depends on your data flow, contract clause, agency requirements, existing architecture, and actual modules—not on the platform's reputation.

Buyer question — Commercial Falcon (US-1 / US-2 / US-3 / EU-1) — GovCloud-1 — GovCloud-2
Buyer questionCommercial Falcon (US-1 / US-2 / US-3 / EU-1)GovCloud-1GovCloud-2
Intended audienceCommercial organizations and customers not buying the government offeringFederal, defense, public-sector, and DIB buyers requiring the Falcon Platform for Government offeringDoW, Intelligence Community, and National Security Systems use cases identified by CrowdStrike
Current public authorization evidenceCurrent public FedRAMP record reviewed does not identify these commercial regionsFedRAMP Certified, Rev5, Class D (High), package FR1807853629A, certified since March 12, 2025CrowdStrike states DoD IL5 P-ATO; verify the exact service and authorization record with the account team
CUI / covered-defense-information decisionDo not attribute the GovCloud authorization. Determine whether the service handles only SPD or whether CUI/CDI enters it.A strong candidate when the exact certified offering, modules, data flow, CRM, and DFARS terms line upA specialized candidate where IL5, NSS, agency, or contract requirements justify it
Module availabilityCommercial catalog varies by bundle and regionVerify each quoted module inside the current certified boundaryVerify each quoted module, service, personnel model, and boundary
Public pricingCommercial list prices are publishedNo self-service GovCloud price identified on the public pricing pageNo self-service GovCloud price identified on the public pricing page
Proof to collectOrder form, region, service terms, data locations, retention, subprocessor and integration detailsFedRAMP Marketplace record, package/boundary confirmation, service description, CRM, module list, DFARS termsIL5 authorization evidence, boundary, service description, CRM, module list, personnel and support model, DFARS terms

The authorization chronology—not a module inventory

CrowdStrike's public announcements are useful, but they are not a substitute for the live authorization boundary. We built this chronology to show why buyers get confused:

Date — Public event — What a buyer should conclude
DatePublic eventWhat a buyer should conclude
September 2018CrowdStrike says the government offering first received FedRAMP authorization at Moderate.Historical authorization matters, but it does not define today's boundary or baseline.
January 8, 2025CrowdStrike announced additional GovCloud availability for Falcon Next-Gen SIEM, Falcon for IT, and Falcon Data Protection.Availability announcements do not replace the current package and dependent-product review.
March 12, 2025FedRAMP Marketplace records Falcon Platform for Government as FedRAMP Certified, Class D (High).This is the current public certification record to start from.
March 19, 2025CrowdStrike announced that 26 products and services were authorized at the High baseline.Treat 26 as a dated vendor statement, not a perpetual module count.
March 18, 2026CrowdStrike announced Falcon for XIoT and additional government capabilities, including new AI, sandbox, attack-surface, and Flex offerings.Ask whether each quoted capability is inside the current certified boundary and available in your region.
August 27, 2026The FedRAMP Marketplace product page shows 38 authorizations.That number means ATO and/or ATU letters, not 38 modules. Do not use it as a product-count claim.

The takeaway for a buyer: "CrowdStrike is FedRAMP High" is accurate only when you are talking about the certified Falcon Platform for Government offering and the capabilities inside its current boundary. Ask per module. Ask per region. Ask which baseline. Get it in writing.


What this CrowdStrike CMMC review found in CrowdStrike's own numbers

CrowdStrike publishes multiple CMMC coverage figures across its own live pages, and they do not reconcile with one another or with the current rule structure. The most consequential stale page tells a contractor that CMMC has five levels and that handling CUI requires Level 3. The current rule has three levels. Level 2 is the broad-protection baseline for CUI; Level 3 adds 24 selected NIST SP 800-172 requirements for programs the Department designates. Handling CUI alone does not make every contractor Level 3.

This is the uncomfortable part of the page, and we're putting it here on purpose, before we tell you anything good about the platform.

CrowdStrike source — Current page claim — What the controlling rule says
CrowdStrike sourceCurrent page claimWhat the controlling rule says
Falcon Platform Applicability for CMMC white-paper page (accessed August 27, 2026)Falcon meets or supports 11 Level 1, 71 Level 2, and 90 Level 3 requirements.Level 1 has 15 requirements. Level 2 has 110 NIST SP 800-171 Rev. 2 requirements. Level 3 adds 24 selected NIST SP 800-172 requirements. The rule does not define a standalone set of 90 Level 3 requirements.
Compliance and certifications page (accessed August 27, 2026)Up to 11 of 17 Level 1 requirements and 80 of 110 Level 2 requirements.The "17" denominator is not the current CMMC Level 1 count. Current Level 1 is 15, drawn from FAR 52.204-21(b)(1)(i) through (xv). The 80 also conflicts with the 71 on CrowdStrike's white-paper page.
Corporate blog published June 21, 2021118 of 171 requirements; five maturity levels; CUI contractors need Level 3.That describes the retired CMMC 1.0 structure. The current rule has three levels; Level 2 uses 110 Rev. 2 requirements, and Level 3 adds 24 selected requirements for designated programs.
Department of War solutions page (accessed August 27, 2026)CMMC is based on five levels and a contractor needs certification "Level 1 through 5."The current 32 CFR Part 170 model has three levels. The page routes the exact defense buyer most likely to rely on it, which makes the stale statement material.

Every current-rule count in the right-hand column comes from 32 CFR § 170.4 and § 170.14: 15 Level 1 requirements, 110 Level 2 requirements from NIST SP 800-171 Revision 2, and 24 selected Level 3 requirements from the February 2021 NIST SP 800-172.

Here's the damaging admission, and here's why it shouldn't change your shortlist

CrowdStrike's own published CMMC materials are the weakest evidence on this page. Numbers that do not agree. A retired five-level model on a current defense page. A 2021 blog post that would route a CUI contractor to the wrong level. If we were grading the marketing, this would not go well.

Now the part that matters more.

None of that changes the certified offering's actual FedRAMP posture. A FedRAMP certification lives in a named Marketplace product record and security package. An IL5 provisional authorization lives in an authorization record. Neither lives in a content-marketing denominator, and neither gets worse because a page went stale.

So the finding is not "CrowdStrike is careless." The finding is you cannot use the public CMMC pages to identify the current requirement count, module boundary, or customer responsibility split—and that is genuinely useful, because it tells you exactly what to request.

Stop reading the coverage headline. Ask for four things:

  1. The complete current product-applicability report, with its version, date, assumed modules, assumed cloud, and assumed architecture.
  2. The Customer Responsibility Matrix for the exact offering and subscription you are buying.
  3. The current FedRAMP Marketplace record and certified boundary, including the quoted modules or dependent products.
  4. A written explanation of why the live pages say 71 and 80, which report is current, and what each number counts.

One note on the applicability report, because it is widely misread. A vendor-commissioned product guide can be useful analysis of what a product may support. It is not your assessment, not your CMMC Status, not your SPRS score, and not evidence that your configuration satisfies all applicable assessment objectives. The current Cyber AB role of the report's author does not convert collateral into an organization-level finding.

Use the 15-question evidence request below before your next CrowdStrike call


Which Level 2 requirements can Falcon actually support?

Depending on the modules you license and the government-region availability of those modules, Falcon can contribute to endpoint protection, detection and response, asset visibility, vulnerability management, identity defense, logging, workflow automation, cloud workload security, data protection, and managed detection. Those capabilities become CMMC-relevant only once they are scoped, configured, operated, documented, reviewed, and backed by retained evidence. A tool supports requirements. It does not replace a program.

The table below is our own construction. We deliberately built it around a different question than CrowdStrike's coverage counts, because "how many controls does it cover" is the wrong question. The right one is: what can this module give an assessor, and what do I still have to do myself?

Falcon capability — Candidate CMMC role — Evidence it can contribute — What remains yours — Question that prevents a bad purchase
Falcon capabilityCandidate CMMC roleEvidence it can contributeWhat remains yoursQuestion that prevents a bad purchase
Prevent / endpoint policyMalware prevention, policy enforcement, endpoint coveragePolicy export, assignment, sensor coverage, prevention events, exception recordsPolicy approval, exception governance, coverage reconciliation, response and reviewIs this exact capability included in the quoted government boundary and enabled on every in-scope asset class?
Endpoint Detection and Response / Real Time ResponseDetection, investigation, containment, responseDetection records, process trees, commands, analyst actions, containment events, case historyAuthority model, incident-response plan, approval path, review, evidence retention, CUI retrieval restrictionsCan RTR move CUI or covered defense information into the service, and how is that action restricted and logged?
Device ControlRemovable-media policy and event visibilityDevice-control policy, approved-device data, exceptions, event historyDefine allowed media, approve exceptions, investigate violations, preserve approvalsIs the module included and enabled in the certified offering you were quoted?
FileVantage / file integrity monitoringMonitor selected file changesMonitored-path configuration, change events, alert and investigation recordsIdentify critical paths, approve baselines, review changes, escalate exceptionsIs FileVantage in the quoted government SKU and boundary?
Discover / asset visibilityEndpoint and software inventory supportHost and software inventory, unmanaged-asset reports, sensor-coverage trendsReconcile to authoritative inventory, resolve missing agents, cover servers, VDI and specialty assetsDoes the deployment cover every in-scope asset type—not just user laptops?
Spotlight / Exposure ManagementVulnerability visibility and prioritizationFindings, scan or observation cadence, aging, remediation ticketsPatch, remediate, document risk decisions, validate closureIs vulnerability data retained and exportable in the proposed tenant?
Identity ProtectionIdentity-threat detection and responseIdentity inventory, connector configuration, detections, response historySource-of-truth governance, MFA, privilege management, reviews, lifecycleWhich identity integrations and response actions are available in this government region?
Next-Gen SIEM and Fusion workflowsLog ingestion, correlation, cases, automationSource inventory, retention settings, parsers, rules, case history, workflowsConnect every required source, own retention and use cases, review and investigateWhat ingest, retention, export, data residency, parser, and integration limits apply?
Falcon Complete / managed detectionManaged detection, hunting, and authorized responseService description, SLA, escalation paths, analyst actions, cases, containment recordsDecision rights, contacts, incident plan, after-action review, retained evidenceWhich team, location, tenant, response authority, and government boundary apply to the quoted service?
Cloud SecurityWorkload, container, and cloud-security visibilityCoverage data, findings, runtime policy, response recordsDeploy integrations, own IAM and cloud configuration, remediate findingsIs the exact AWS GovCloud or Azure Government capability in the current certified boundary?
Data ProtectionData activity monitoring and loss-prevention supportPolicy, endpoint coverage, exceptions, data eventsDefine data classes, approve policy, investigate events, govern CUI, validate data flowsWhat content, metadata, excerpts, or artifacts leave the endpoint, and under which boundary and terms?

Read this table as candidate roles, not satisfied requirements. Actual support depends on your licensed modules, cloud region, configuration, operation, data flows, and CRM assignments.

The 110 Level 2 requirements are organized across 14 security requirement families in NIST SP 800-171 Revision 2. The assessment does not stop at a 110-item feature checklist: the rule requires all applicable assessment objectives in the incorporated NIST SP 800-171A procedures to be met for a requirement to count as MET.

That gap is where self-assessment scores quietly inflate.


Can Falcon output become assessment-ready evidence?

Falcon generates genuinely useful artifacts, but a dashboard screenshot does not prove a requirement was implemented and operated at the required frequency, across the full scope, with reviewed exceptions and corrective action. Assessment-ready evidence connects the technical configuration to the responsible person, operating record, review cadence, exception handling, remediation, and SSP narrative. Tools produce artifacts. People turn those artifacts into evidence.

Two questions repeatedly surface when contractors operationalize security tooling: how do you turn raw output into a POA&M or corrective-action record, and what do you show when an assessor asks where the provider's responsibility stops and yours begins? Both are workflow problems. Both remain yours to solve.

Here's the chain an assessor is actually walking:

  1. The policy or contractual requirement
  2. The technical configuration implementing it
  3. Scope and coverage—did it apply everywhere it should?
  4. The operating record over the relevant period and cadence
  5. Human or authorized-service review of that record
  6. Exceptions and findings
  7. Corrective action and closure
  8. Management confirmation where required
  9. The SSP reference
  10. The retained artifact and retrieval path

Falcon can contribute strongly to steps 2, 3, 4, and part of 6. That's real value. The remaining steps do not disappear because the product is good.

Evidence task — Falcon platform — Falcon Complete / MDR — You or your MSSP — GRC / readiness owner
Evidence taskFalcon platformFalcon Complete / MDRYou or your MSSPGRC / readiness owner
Generate telemetryPrimaryConsumes and acts on itVerifies coverageReferences it
Configure technical policySupportsMay assist under service termsAccountableDocuments approval and scope
Investigate an alertSupportsMay performAccountable under the contract and IR planTracks case evidence
Remediate root causeLimited to available actionsLimited by delegated authorityAccountableTracks closure
Write the SSP narrativeNoUsually not part of MDRSupplies facts and ownershipPrimary
Map implementation to assessment objectivesProduct report may assistMay assistValidates realityPrimary
Preserve the assessment artifactExport and case capabilitiesMay retain casesAccountable for availabilityOrganizes and indexes
Reconcile the CRMSupplies provider responsibilitiesSupplies service responsibilitiesAccepts customer dutiesMaps duties to owners and evidence

Notice how much of that table is bold in one column. That column is you.

Use the CMMC Readiness Checklist before you treat a product demo as an implementation plan


What CrowdStrike does not replace

CrowdStrike does not determine the CMMC status required by your solicitation, define your CUI boundary, author and maintain your SSP and POA&M, host your business collaboration, operate every NIST SP 800-171 requirement, make your annual affirmation, or perform the formal assessment. Most contractors still need internal owners plus at least one readiness, operations, enclave, evidence, or assessment provider.

Provider or product category — Primary job — Implements or operates technical controls? — Owns SSP / POA&M work? — Hosts or isolates CUI? — Performs the formal assessment?
Provider or product categoryPrimary jobImplements or operates technical controls?Owns SSP / POA&M work?Hosts or isolates CUI?Performs the formal assessment?
CrowdStrike / security platformEndpoint, identity, exposure, logging, data, cloud, and response capabilitiesYes, within licensed and configured capabilitiesNo, not through the product purchaseNot as the contractor's primary collaboration enclaveNo
MSSP / managed security providerOperate security systems and response workflowsOftenSometimes, if explicitly scopedSometimesNo
Readiness provider / RPO or RP-led practiceScope, gap analysis, remediation plan, documentation, evidence preparationMay implement or coordinateOftenUsually noNo
CUI enclave / managed compliant environmentIsolate and operate a narrower CUI environmentOften inside enclaveMay provide templates and evidenceYesNo
GRC platformMap requirements, owners, evidence, findings, POA&MNo or limited integrationsOrganizes and tracksNoNo
C3PAOConduct the Level 2 certification assessment when that assessment type appliesNo remediation for the same certification engagementReviews, does not author for youNoYes
Internal OSA ownerAccept accountability, make decisions, affirm continuing complianceOwns or delegates operationUltimately accountableOwns the boundary decisionParticipates; does not replace independent assessment

There is a hard independence line here. 32 CFR § 170.8(c)(3) says a CMMC ecosystem member that consulted to prepare an OSA for any CMMC assessment may not participate in that OSA's Level 2 certification assessment process for three years.

In plain English: you cannot use the same CMMC ecosystem member to prepare you for assessment and then have it participate in your Level 2 certification assessment inside that three-year window. Preserve that line in writing when you select providers. Do not expand it into a claim that every security vendor or every preliminary assessment activity is prohibited; use the exact rule and the current assessment process.

If this is the section where you realized you're in the wrong aisle

Start with Who to Hire First for CMMC, then compare the CMMC Provider Categories. The expensive mistake is not choosing CrowdStrike over another endpoint product. It is hiring a product, assessor, readiness firm, and operator in the wrong order.


What does CrowdStrike cost in a CMMC environment?

The commercial list price is public. The government-environment price, module mix, services, migration, and implementation cost are not. A commercial endpoint price is useful as an anchor and dangerous as a budget.

CrowdStrike's public pricing page displayed the following on August 27, 2026:

Public commercial bundle — Monthly price — Annual price — Public buying note — What it does not tell a CMMC buyer
Public commercial bundleMonthly priceAnnual pricePublic buying noteWhat it does not tell a CMMC buyer
Falcon Go$7.99 per device$59.99 per deviceSelf-service; purchases limited to 100 devicesGovernment-cloud availability, certified boundary, CUI/CDI terms, exact CMMC evidence scope
Falcon Pro$14.99 per device$99.99 per deviceSelf-service commercial bundleGovernment-cloud price, modules in boundary, managed-operation cost
Falcon Enterprise$19.99 per device$184.99 per deviceSelf-service commercial bundle; public page describes EDRGovernment-cloud price, exact module equivalence, retention, migration and implementation
Falcon Complete Next-Gen MDRContact salesContact salesManaged-service quoteGovernment tenant, personnel model, response authority, boundary, SLA and evidence retention
GovCloud-1Not publicly listedNot publicly listedWritten quote requiredEvery material budget line below
GovCloud-2Not publicly listedNot publicly listedWritten quote requiredEvery material budget line below

A defensible quote needs more than "price per endpoint." Ask for separate line items for:

  • workstation, server, VDI, container, mobile, and cloud-workload metering;
  • every module you intend to rely on;
  • GovCloud environment and region;
  • implementation, migration, policy design, and integrations;
  • data ingestion and retention;
  • Falcon Complete or other managed services;
  • support tier and service-level commitments;
  • training and administrator enablement;
  • contract term, renewal escalator, minimums, true-ups, and termination;
  • exports, offboarding, and evidence retention.

Then put three totals side by side:

  1. CrowdStrike subscription and implementation
  2. The rest of the CMMC operating stack
  3. The people who will run, document, review, and preserve evidence

That third number is where the budget stops being a product quote and becomes a compliance program.

For a broader benchmark, use our CMMC Level 2 Cost Guide.


Is the July 2024 outage a CMMC problem?

Not by itself. It is a change-governance, resilience, recovery, and vendor-management question—not an automatic CMMC disqualifier.

The facts matter because bad shorthand creates the wrong control lesson.

On July 19, 2024 at 04:09 UTC, CrowdStrike released a Rapid Response Content configuration update that affected Windows sensors version 7.11 and above. CrowdStrike reverted the defective content at 05:27 UTC. CrowdStrike's own preliminary review says Rapid Response Content is stored in a proprietary binary file containing configuration data and is not code or a kernel driver. The problematic Channel File 291 caused an out-of-bounds memory read and Windows crashes.

That is materially different from saying CrowdStrike pushed a new executable kernel driver through every customer's change-control process. It did not.

The incident still belongs in your due-diligence file because it exposed a dependency capable of changing endpoint behavior at operational speed. Under CM.L2-3.4.3, an assessor can reasonably ask how you track, review, approve or govern system changes—including vendor-managed update channels—within the responsibility you actually control. The incident does not map cleanly to CM.L2-3.4.9's user-installed-software requirement, so this page does not force that control citation.

One distinction matters:

  • Sensor Update Policies govern customer deployment of sensor releases, including N, N-1, and N-2 versions.
  • Rapid Response Content was a separate dynamic content mechanism. Pinning a sensor version did not, by itself, prevent the July 2024 event.

CrowdStrike committed after the incident to stronger validation, canary and staged deployment for Rapid Response Content, improved monitoring, release notes, and greater customer control over when and where content updates deploy. Do not accept the commitment as evidence. Ask what is live in the exact government offering you will use.

Your evidence packet should answer:

  1. Which Falcon update and content channels can change endpoint behavior?
  2. Which channels can you stage, delay, scope, or block?
  3. Which host groups receive canary deployment?
  4. Who reviews release and incident notices?
  5. What is your tested recovery procedure for a failed update?
  6. Are BitLocker recovery keys and out-of-band recovery paths available?
  7. How quickly can you isolate a bad policy or content change?
  8. Which records prove the process was reviewed and tested?

Credit where it is due: CrowdStrike published a detailed public incident review, distinguished sensor code from content configuration, identified the deployment failure, and laid out corrective actions. That transparency is useful evidence about the vendor. It does not remove your obligation to test whether the corrective controls exist in your environment.


Who is CrowdStrike right for—and who should walk away?

CrowdStrike belongs on the shortlist when the technical capability justifies a separate platform and someone is ready to operate it. It should leave the shortlist when the buyer is using the product to avoid the harder work of scope, documentation, evidence, and operations.

Contractor profile — Fit — Why
Contractor profileFitWhy
Level 2 contractor with a capable internal security teamStrong fitThe team can exploit the platform's depth, own configurations and evidence, and integrate it with the rest of the program.
Contractor using a mature MSSP that already operates FalconStrong fit if the contract is preciseOperations, escalation, evidence, tenant, module, and response authority can be made explicit.
Contractor that needs GovCloud-1 and can verify the exact certified boundaryStrong candidateThe current High certification is real and relevant when CUI/CDI data flows require it.
Contractor whose agency or contract requires IL5 / NSS alignmentGovCloud-2 candidateThe specialized authorization may be decisive; verify the exact service and boundary.
Microsoft GCC High contractor already paying for overlapping security capabilitiesCompare before addingA second platform can be worth it, but only after licensing, integration, staffing, and evidence duplication are priced.
Small FCI-only Level 1 contractor with no dedicated security operatorUsually too much platformThe 15 Level 1 requirements and business risk may not justify a complex enterprise security stack.
Contractor hoping Falcon Complete will write the SSP and run the whole CMMC programWrong purchaseManaged detection is not an organization-wide CMMC program.
Contractor buying a commercial bundle because the vendor has a government authorization somewhereWalk away from the assumptionThe authorization belongs to a named offering and boundary, not the logo.

Let us disqualify CrowdStrike clearly where it does not belong.

If you need one company to create the boundary, host the CUI collaboration, configure the Microsoft environment, write the SSP and POA&M, operate the security stack, preserve every artifact, and prepare you for assessment, CrowdStrike is not that company. It may be one layer inside that solution. It is not the solution by itself.


CrowdStrike vs. Microsoft Defender in a GCC High environment

There is no universal winner. The right question is whether CrowdStrike adds enough distinct capability and operational value to justify a second security stack inside your actual GCC High architecture.

A GCC High tenant is not automatically a complete CUI environment. The exact Microsoft services, licenses, configurations, device estate, supporting Azure resources, contracts, operators, and evidence still matter. But a contractor already paying for Microsoft security may have meaningful overlap.

Decision factor — CrowdStrike path — Microsoft-first path
Decision factorCrowdStrike pathMicrosoft-first path
Endpoint platformSeparate Falcon sensor, console, policy and evidence modelDefender capabilities integrated with the Microsoft tenant and identity stack
Government authorizationVerify Falcon GovCloud offering, region, modules and boundaryVerify the exact GCC High / Azure Government services and authorizations in use
IdentityFalcon Identity can add independent detections and responseEntra ID and Microsoft identity-security capabilities may reduce tool sprawl
SIEMFalcon Next-Gen SIEM creates a separate ingest, parser, retention and case modelMicrosoft Sentinel or other Microsoft-native logging may already be licensed or integrated
OperationsInternal team or Falcon/MSSP service modelInternal team or Microsoft-focused MSSP
EvidenceStrong product artifacts; separate CRM and responsibility mappingNative Microsoft records may align more directly with an existing Microsoft SSP, but still need mapping and review
CostAdded subscription, integration, training, retention and operationsPotential licensing efficiency, but only if required capabilities are actually licensed, configured and operated
ResilienceIndependent vendor and telemetry can reduce single-stack dependencyFewer platforms can simplify administration but increase dependency concentration
Best reason to chooseDistinct security capability, independent telemetry, mature Falcon operation, or service modelExisting investment, integration, simpler operations, and enough implemented capability to meet the requirement

CrowdStrike can win where an organization deliberately wants independent telemetry, Falcon-specific capabilities, or an operating partner built around Falcon. Microsoft can win where the licensed Microsoft stack already covers the needed functions and the organization can operate it without creating a second control plane.

Do not compare product logos. Compare the actual licensed capability, authorized environment, operator, responsibility split, evidence path, and three-year cost.

For the Microsoft side of that decision, use our GCC High for CMMC analysis.


Does NIST SP 800-171 Revision 3 change this CrowdStrike CMMC review?

No. As of August 27, 2026, CMMC still controls to NIST SP 800-171 Revision 2 for Level 2 unless the Department amends the rule or a future contract action changes the governing requirement.

This matters because NIST's publication page is now ahead of the CMMC incorporation:

  • NIST published SP 800-171 Revision 3 in May 2024.
  • NIST withdrew the February 2021 SP 800-172 publication in May 2026 and published SP 800-172 Revision 3.
  • 32 CFR Part 170 still incorporates NIST SP 800-171 Revision 2, including the January 28, 2021 errata, for Level 2.
  • 32 CFR Part 170 still incorporates the February 2021 NIST SP 800-172 for the 24 selected Level 3 requirements.

A newer NIST publication does not silently amend an incorporated regulation.

That means a CrowdStrike applicability matrix mapped only to SP 800-171 Rev. 3 cannot substitute for the current CMMC Level 2 mapping. Ask the vendor to identify the exact standard version, assessment procedure, modules, and environment behind every coverage claim.

Prepare for Rev. 3 if it helps your long-term program. Assess and affirm against the version the rule and contract actually require.


Does the CMMC Phase 2 suspension change this answer?

No. It changes the near-term assessment gate. It does not change CrowdStrike's role, your data-flow analysis, DFARS 252.204-7012, the current Rev. 2 requirement set, or the need to preserve evidence.

The original CMMC rollout put Phase 1 from November 10, 2025 through November 9, 2026, with Phase 2 scheduled to begin November 10, 2026. On July 13, 2026, the Department of War immediately suspended the transition to Phase 2 and pending and future CMMC implementation milestones while a reform task force conducts a 60-day review.

The Department's current CMMC page now says the program is paused in Phase 1 and may require:

  • Level 1 Self: annual self-assessment and affirmation against the 15 FAR requirements.
  • Level 2 Self: self-assessment every three years, annual affirmation, and the 110 NIST SP 800-171 Rev. 2 requirements.

The Department also says it will enforce Rev. 2 through self-assessments and select government-led assessments during the suspension. Its implementation memo directs contracting officials not to designate Level 2 C3PAO or Level 3 requirements during the suspension and to keep Level 1 Self and Level 2 Self available.

What did not disappear:

  • DFARS 252.204-7012 safeguarding and cyber-incident obligations;
  • DFARS 252.204-7019 and -7020 SPRS score requirements where those clauses apply;
  • the current CMMC Phase 1 self-assessment and affirmation obligations where the contract requires them;
  • the 110 Rev. 2 requirements for current Level 2;
  • your SSP, scope, CRM, evidence, and operating responsibilities;
  • the need to buy the correct CrowdStrike offering if sensitive data enters the service.

The honest read is not "CMMC is gone." It is the private third-party certification expansion is suspended while the Department reviews the model, but the cybersecurity baseline and Phase 1 contract machinery remain live.

Do not use the pause to buy the wrong tenant. Do not use it to buy a product instead of a program. Do not sign an affirmation you cannot support.


What to ask CrowdStrike before you buy or renew

The public pages answer the brand question. They do not answer the tenant, boundary, module, contract, data-flow, or evidence questions that decide your assessment. Put these in one written request and require the response to identify the date, offering, region, and subscription.

  1. Which Falcon cloud region will host our tenant? Provide the console hostname and API base URL.
  2. What is the exact name and package ID of the FedRAMP-certified offering serving our tenant? Confirm whether it is CrowdStrike Falcon Platform for Government, FR1807853629A.
  3. Which quoted modules and services are inside the current certified boundary? Identify dependent products, exclusions, and any capability delivered from another environment.
  4. If GovCloud-2 is proposed, what IL5 authorization applies? Provide the authorization evidence, exact boundary, covered services, and expiration or continuous-monitoring status.
  5. Where is our tenant data stored, processed, backed up, and replicated? Include telemetry, case data, log ingest, malware samples, support bundles, and exports.
  6. Provide the service description and Customer Responsibility Matrix for this exact subscription. Include any applicable interconnection or security agreement, but do not substitute an unrelated generic shared-responsibility brochure.
  7. If the service stores, processes, or transmits covered defense information, does CrowdStrike contractually accept the DFARS 252.204-7012(c) through (g) obligations applicable to the cloud service?
  8. What is the retention period for detections, raw telemetry, cases, RTR records, audit records, vulnerability data, identity data, SIEM data, and exports?
  9. Who can access our tenant and data? Identify personnel locations, support model, privileged-access controls, and—where our contract, export-control, or agency requirements impose it—citizenship or U.S.-person restrictions. CMMC alone does not create a universal U.S.-person rule.
  10. Can Real Time Response retrieve a CUI or covered-defense-information file into CrowdStrike-controlled infrastructure? Show the controls, approvals, logs, and restrictions.
  11. For cryptography we rely on to satisfy SC.L2-3.13.11, provide the CMVP certificate number, module name, version, operational environment, validation status, and FIPS 140-2 or 140-3 standard.
  12. Provide the current SOC 2 report, relevant ISO certificates, penetration-test summary, subprocessor list, incident-notification terms, and business-continuity evidence. These do not replace CMMC; they inform vendor risk.
  13. Which update channels can change endpoint behavior? Identify what we can stage, delay, scope, approve, or block, and how Rapid Response Content is controlled after the July 2024 incident.
  14. What evidence can we export without opening a support ticket? Include policy, assignment, coverage, audit history, detections, cases, analyst actions, retention settings, vulnerability findings, and identity events.
  15. Why do CrowdStrike's current pages report 71 and 80 Level 2 requirements, and which report should we rely on? Require the answer to identify modules, environment, CMMC version, NIST version, assumptions, and publication date.

Do not accept "CrowdStrike is FedRAMP High" as the answer to any of those. It answers one field.


What we verified, and what we couldn't

Verified from primary or first-party public records on August 27, 2026

  • The current CMMC model has 15 Level 1 requirements, 110 Level 2 requirements from NIST SP 800-171 Revision 2, and 24 selected Level 3 requirements from the February 2021 NIST SP 800-172.
  • The 110 Level 2 requirements span 14 security requirement families and are assessed through the applicable NIST SP 800-171A objectives.
  • CMMC still controls to Rev. 2 for Level 2. NIST's newer Rev. 3 publication does not silently amend 32 CFR Part 170.
  • CMMC Status belongs to the assessed OSA information system and is officially stored in SPRS.
  • The NIST SP 800-171 DoD Assessment score under DFARS 252.204-7019/-7020 is a separate SPRS record from the CMMC Status/UID used under 252.204-7021.
  • The Level 2 scoping rule treats an external service that processes SPD without CUI as a Security Protection Asset and requires SSP documentation, a service description, and a CRM.
  • A CSP used in contract performance that stores, processes, or transmits covered defense information is subject to DFARS 252.204-7012(b)(2)(ii)(D).
  • CrowdStrike's current public deployment materials identify six cloud regions, including the newer US-3 and GovCloud-2 API endpoints.
  • FedRAMP Marketplace lists CrowdStrike Falcon Platform for Government, package FR1807853629A, as FedRAMP Certified, Rev5, Class D (High), certified since March 12, 2025.
  • CrowdStrike states that its Falcon platform has DoD IL5 provisional authorization and positions GovCloud-2 for DoW and NSS use.
  • CrowdStrike's public commercial prices displayed $59.99, $99.99, and $184.99 per device per year for Go, Pro, and Enterprise; Falcon Go purchases are capped at 100 devices.
  • CrowdStrike's live CMMC pages still publish conflicting 71-versus-80 Level 2 coverage numbers, a 17-item Level 1 denominator, and retired five-level language.
  • CrowdStrike's July 2024 incident involved Rapid Response Content configuration data, not code or a kernel driver; the incident window began at 04:09 UTC and the defective content was reverted at 05:27 UTC.
  • The Department suspended Phase 2 on July 13, 2026, kept Phase 1 self-assessment requirements in place, and continues to enforce Rev. 2 and DFARS 252.204-7012.

Not verifiable from the public material reviewed

  • Your GovCloud-1 or GovCloud-2 price.
  • The exact government-region module list and certified boundary for your quote.
  • A public console hostname for US-3 or GovCloud-2 in the sources used for this review.
  • The architecture-level answer to whether every Data Protection, SIEM, RTR, sample, or support workflow sends CUI into CrowdStrike infrastructure.
  • Your tenant's data residency, backup location, subprocessor path, retention, support-personnel model, and privileged-access design.
  • The Customer Responsibility Matrix and service description for your subscription.
  • The exact CMVP certificates and operational environments for cryptography you intend to rely on.
  • The Cyber AB Marketplace role status of CrowdStrike, Coalfire, or Coalfire Federal during final verification; the Marketplace was unavailable from our audit environment.
  • Any customer-specific claim that a CrowdStrike deployment caused a contractor to pass, fail, or receive a particular CMMC result.

Those unknowns are not footnotes. They are the procurement work.

This page follows our Methodology and Editorial Standards. Send verified corrections through our Corrections Policy.


Frequently asked questions

Is CrowdStrike CMMC certified?

No. A product does not receive a CMMC Status. An Organization Seeking Assessment receives a status for an assessed information system, and the status is stored in SPRS. CrowdStrike can support implementation and evidence inside that system.

Does CrowdStrike give me an SPRS score?

No. Your organization conducts or undergoes the applicable NIST SP 800-171 DoD Assessment, and the summary score is posted to SPRS under DFARS 252.204-7019 and -7020. CrowdStrike can provide artifacts that support parts of the assessment.

Is CrowdStrike FedRAMP High?

CrowdStrike Falcon Platform for Government is currently listed in FedRAMP Marketplace as FedRAMP Certified, Rev5, Class D (High), package FR1807853629A, certified since March 12, 2025. That record does not automatically describe a commercial Falcon tenant or every module in a quote.

How many CrowdStrike cloud regions are there?

Current CrowdStrike deployment materials identify six: US-1, US-2, US-3, EU-1, US-GOV-1, and US-GOV-2. Any five-cloud answer is out of date.

What is the difference between GovCloud-1 and GovCloud-2?

GovCloud-1 is the offering associated with the current public FedRAMP High product record. CrowdStrike positions GovCloud-2 around its DoD Impact Level 5 provisional authorization and National Security Systems use. The right choice depends on the contract, agency, data, modules, and boundary—not CMMC Level 2 alone.

Do I need CrowdStrike GovCloud for CMMC Level 2?

Not automatically. If Falcon processes SPD without CUI, CMMC Table 4 treats it as a Security Protection Asset. If the cloud service stores, processes, or transmits CUI or covered defense information, the authorization, boundary, and DFARS terms become central.

Can I use commercial Falcon with CUI?

Do not answer from the product name. Determine whether the service stores, processes, or transmits the data, whether the data is covered defense information under the contract, what authorization or equivalency evidence applies to the exact service, and whether the contract accepts the DFARS obligations.

How many Level 2 requirements does CrowdStrike support?

CrowdStrike's live pages currently say 71 and 80. Those figures conflict. A reliable answer requires the current applicability report, exact modules, cloud region, configuration assumptions, CMMC version, NIST version, and CRM. Product support is not the same as meeting an organization-level requirement.

Does CMMC Level 1 have 17 requirements?

No. The current rule defines 15 Level 1 requirements drawn from FAR 52.204-21(b)(1)(i) through (xv). CrowdStrike's current 17-item denominator is stale.

Does handling CUI mean I need CMMC Level 3?

No. Level 2 is the broad-protection level built on the 110 Rev. 2 requirements. Level 3 adds 24 selected SP 800-172 requirements for programs the Department designates. The contract sets the required status.

Is CrowdStrike a C3PAO or RPO?

The public product materials reviewed do not establish that buying Falcon buys either service. Verify any current ecosystem credential in the Cyber AB Marketplace before relying on it. The Marketplace was unavailable during final verification, so this page does not publish a definitive absence claim.

Does Falcon Complete replace an MSSP or CMMC readiness provider?

It can replace or reduce some managed detection and response work, depending on the service contract. It does not automatically replace scope analysis, SSP and POA&M work, evidence management, enclave operations, annual affirmation, or formal assessment.

Can Falcon Next-Gen SIEM satisfy the logging requirements?

It can contribute log collection, correlation, cases, retention, and evidence. You still must connect the required sources, define time synchronization and retention, review activity, investigate findings, control access, preserve evidence, and map the implementation to the applicable assessment objectives.

Will CrowdStrike write my SSP and POA&M?

Not through the product subscription. A separately scoped readiness or professional-services engagement may assist with documentation, but buying Falcon does not transfer the OSA's accountability.

Does the July 2024 outage make CrowdStrike unsuitable for CMMC?

No. It creates legitimate questions about vendor-managed content, staged rollout, recovery, change governance, and resilience. It is not an automatic CMMC failure.

What does CrowdStrike cost for CMMC?

Commercial list prices are public. GovCloud pricing, module mix, managed services, implementation, retention, and migration require a written quote. Budget the operator and evidence program, not just the endpoint subscription.

Does the July 2026 Phase 2 suspension make this page obsolete?

No. Phase 2's expansion was suspended, but Phase 1 self-assessment requirements, Rev. 2, DFARS 252.204-7012, SPRS score clauses, scope, evidence, and current contract obligations remain.

Does NIST SP 800-171 Rev. 3 control CMMC now?

No. As of August 27, 2026, 32 CFR Part 170 still incorporates Rev. 2 for Level 2. NIST's newer publication does not amend the rule by itself.

What should I collect before an assessment?

At minimum: tenant and region confirmation, asset and sensor coverage, policy and assignment exports, review records, cases and corrective actions, service description, CRM, data-flow diagram, retention evidence, privileged-access evidence, authorization/boundary evidence, and the SSP mapping to applicable objectives.


What to do next

If you already use CrowdStrike, do not start by replacing it. Start by proving what you actually bought.

  1. Copy the tenant's console hostname and API base URL.
  2. Map every Falcon data path, integration, module, analyst action, sample upload, and support workflow.
  3. Decide which paths carry SPD only and which can carry CUI or covered defense information.
  4. Obtain the service description, CRM, authorization evidence, module boundary, retention, and contract terms.
  5. Map the technical capabilities to the applicable Rev. 2 objectives and retained evidence.
  6. Identify the work Falcon does not cover and assign it to an internal owner or the right provider category.

Then choose the next route:

Relationship disclosure: A request submitted through our matching form may be routed to independent providers with which The Defense Compliance Report has a commercial, referral, sponsored, or partner relationship. Any provider relationship should be labeled at the point of referral. CrowdStrike is not a destination from this page.

The right question is not "does CrowdStrike help with CMMC?"

It does.

The question is whether the exact Falcon cloud, modules, data flow, operator, responsibility matrix, contract, and evidence chain fit the expensive decision your company has to make next.


Primary sources

CMMC rule, DFARS, and Department implementation

NIST publications controlling or relevant to the version question

CrowdStrike authorization, cloud, product, pricing, and incident records