The Defense Compliance ReportCMMC 2.0 & the Defense Industrial Base

Managed security review · primary-sourced · last reviewed August 2026

Huntress CMMC Review: What It Covers, What It Doesn't

Last updated:

Last verified: against Huntress documentation, pricing, blocked-extension data, CMMC rules, and DFARS sources.

Huntress CMMC review illustration showing a managed security telemetry boundary around protected defense-contractor data

Public-source evidence profile — not a hands-on product test

By The Defense Compliance Report Editorial Team · Last reviewed: August 2026 · Last verified: August 25, 2026 Evaluation depth: Public Huntress documentation, published pricing, and primary regulatory sources · Compensation relationship with Huntress: none


If you searched for a Huntress CMMC review, here is the short answer. Huntress can sit inside a CMMC Level 2 environment without FedRAMP authorization — but only if the actual data flow keeps Controlled Unclassified Information out of Huntress. With Sensitive Data Mode enabled and that boundary holding, Huntress can be assessed as a Security Protection Asset under 32 CFR § 170.19. If CUI reaches the cloud service, the FedRAMP Moderate requirement in DFARS 252.204-7012 can attach.

But "Security Protection Asset" does not mean out of scope. It means in scope, in a different row of the table.

That distinction is where most contractors get hurt, and it is not the only thing the marketing language smooths over. Sensitive Data Mode is off by default. It blocks a published list of 134 file extensions — and after testing 41 plausible CUI-bearing formats used across engineering, manufacturing, software, program administration, archives, and design, we found none of them on that list. Huntress currently says its platform maps to 55 of the 110 NIST SP 800-171 Revision 2 requirements, up from 37 after adding Managed ISPM, while a separate live Huntress page still says it “satisfies 51.” ISPM is a separate paid product, and Huntress's current documentation excludes GCC and GCC High tenants from it.

None of that makes Huntress the wrong choice. Several of these gaps can be addressed through one support ticket. But you need to know which ones, and you need to know before an assessor — or the person signing your self-assessment affirmation — asks.

We read Huntress's own support documentation, its published price list, its blocked-extension table, and the controlling CMMC and DFARS sources. Here is what actually holds up.


Current CMMC status — verified August 25, 2026. CMMC Phase 1 began November 10, 2025 and was planned to run through November 9, 2026. On July 13, 2026, the Department of War suspended the transition to Phase II, which had been scheduled to begin November 10, 2026. During the suspension, program managers and requiring activities may designate Level 1 (Self) or Level 2 (Self) only — not Level 2 (C3PAO) or Level 3 (DIBCAC). Phase I self-assessment requirements remain, DFARS 252.204-7012 remains in effect, and the Department says it will enforce NIST SP 800-171 Rev. 2 through self-assessments and select government-led assessments. This changes the CMMC assessment status the Department may require. It does not remove the duty to protect CUI or maintain evidence. See what the suspension changes for this decision →


The verdict, before you scroll

Decision point — Verdict
Decision pointVerdict
OverallConditional fit — not blanket approval
What Huntress is, under the ruleAn External Service Provider and cloud service provider that can be assessed as a Security Protection Asset when the service handles Security Protection Data without CUI. Sensitive Data Mode is part of that boundary; it is not proof that the boundary holds.
Best fitSmall and mid-size contractors, and the MSPs running them, that need managed detection, logging, identity monitoring, and training — and whose CUI lives in documents, spreadsheets, and CAD files.
Poor fitContractors whose CUI lives in source code, scripts, firmware, or compiled binaries; anyone expecting one platform to close all 110 requirements.
Biggest strengthReal managed security at published prices, with a CMMC documentation package included at no charge.
Biggest limitationSensitive Data Mode buys a cleaner CUI boundary by deliberately removing investigative capability — and it still permits analysts to retrieve executables and scripts.
Company-stated coverageThe newest Huntress mapping says 55 of 110 after adding Managed ISPM, up from 37; another live Huntress page says 51. Confirm the current matrix, modules, tenant compatibility, and customer responsibilities.
The one thing to check todayWhether Sensitive Data Mode is enabled on every organization in your tenant, when it was enabled, and whether your actual CUI file types are blocked.

The Defense Compliance Report is an independent trade publication and decision resource for CMMC and Defense Industrial Base compliance. We explain regulatory claims with primary-source citations and map a contractor's level, CUI scope, assessment type, and timeline to the right provider category, so DIB contractors choose the right CMMC path before they spend six figures. See our Methodology and Editorial Standards.


What we actually verified

Most of what has been written about Huntress and CMMC is either written by Huntress or rewritten from a Huntress press release. We wanted to see whether the claims survive contact with the rule text. Here is exactly what we did and did not do, so you can weigh this accordingly.

Evidence category — Checked? — Limit
Evidence categoryChecked?Limit
32 CFR § 170.19 scoping tablesYes — eCFR, verified August 25, 2026Applied editorially to Huntress's stated behavior; actual classification depends on your data flow.
DoD CIO CMMC Level 2 Scoping GuideYesGuidance document, not the rule itself.
Current CMMC phase statusYes — DoW CIO announcement and July 2026 implementing memorandumProgram under active review; recheck before relying on the phase status.
Controlling NIST versionsYesCMMC Level 2 still incorporates SP 800-171 Rev. 2 and the June 2018 SP 800-171A; Rev. 3 is not the CMMC-controlling version unless DoD amends the rule.
Huntress support documentationYes — “Huntress and CMMC” updated January 5, 2026; “Huntress Sensitive Data Mode” updated June 17, 2026Public help-center articles; no backend or source access.
The blocked-extension listYes — all 134 entries counted and categorizedReflects the list published June 17, 2026.
Huntress published pricingYes — August 25, 2026Uses the displayed 50–99 unit band; not a customer quote.
Managed ISPM statusYes — GA, separately billable, Microsoft 365 onlyCurrent public documentation excludes GCC and GCC High.
Huntress CMMC marketing pagesYesCompany-stated claims are attributed as such.
Current Shared Responsibility Matrix contentsNoThe current matrix is not publicly readable without Trust Center or partner access; obtain and version it yourself.
Hands-on deployment or detection testingNoWe did not run the product.
Customer or assessor interviewsNoNo independent outcome evidence.
FedRAMP Marketplace statusYes — official Marketplace searched August 25, 2026We found no Huntress offering; the analysis still turns on the actual data relationship, not the listing alone.

Disclosure: The Defense Compliance Report is an independent trade publication on CMMC and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification. We have no affiliate, referral, sponsorship, or partner relationship with Huntress or DEFCERT, and no Huntress link on this page is a paid placement.

We are not affiliated with the Cyber AB, the Department of War or Defense, DCMA DIBCAC, NIST, or any U.S. government agency.


The right CMMC provider isn't the same for every contractor — the category you need, whether a C3PAO, RPO, MSSP, GRC platform, or CUI enclave, depends on your required CMMC level, whether you handle FCI or CUI, your assessment type, your cloud and IT environment, and your contract timeline. The contract clause sets your level, not a checklist. Use Find My CMMC Path to map your situation to the right provider category before you request quotes — and do not submit CUI, drawings, or sensitive contract details.


Is Huntress CMMC compliant?

No security product is “CMMC compliant” — organizations achieve a CMMC status, tools do not. The accurate statement is that Huntress can be deployed inside a Level 2 environment and assessed as a Security Protection Asset without triggering the FedRAMP requirement, provided Sensitive Data Mode is enabled, the actual data flow keeps CUI out of the service, and the relationship is documented in your System Security Plan. Sensitive Data Mode alone does not establish that result. Huntress's own support documentation states the intended position more precisely than some of its marketing pages do.

That gap between the support docs and the marketing copy is the single most useful thing we found, and it runs through this entire review.

Here is the distinction that matters when someone tells you a tool is “CMMC compliant.” There are four separate things people mean, and vendors collapse them constantly:

  1. Capability support. The product performs a security function — it detects malware, it collects logs.
  2. Implementation support. The product is configured and operated in a way that satisfies part of an assessment objective.
  3. Evidence support. You can prove the implementation with an artifact.
  4. Requirement satisfaction. Every applicable assessment objective for that requirement is met across your entire environment.

A tool can deliver #1 and #2. It can help you produce #3. It essentially never delivers #4 on its own, because NIST SP 800-171A, June 2018 breaks the 110 requirements into multiple determination statements, and many depend on organization-specific policies, frequencies, roles, records, and evidence. A vendor cannot define and operate all of that for you. That is your policy, and your policy is your homework.

Controlling-version check. CMMC Level 2 currently incorporates NIST SP 800-171 Rev. 2 and the June 2018 SP 800-171A. NIST SP 800-171 Rev. 3 is the newer NIST publication, but it is not the CMMC-controlling version unless DoD amends 32 CFR Part 170. CMMC Level 3 likewise still points to selected requirements from the February 2021 SP 800-172, even though NIST withdrew that publication and superseded it with SP 800-172 Rev. 3 in May 2026.

Who likely has a viable Huntress path

  • Existing Huntress customers with a well-mapped CUI boundary
  • Small and mid-size contractors whose CUI lives in Office documents, PDFs, and CAD files
  • MSP-managed environments with the discipline to configure and evidence every tenant
  • Organizations willing to accept the investigative tradeoffs we cover below

Who should stop and look harder

  • Contractors whose CUI can exist in source code, scripts, firmware, or compiled binaries
  • Anyone who cannot produce an inventory of the file types their CUI lives in
  • Anyone counting on the “55 requirements” figure without checking which products and customer responsibilities it assumes
  • Anyone expecting a security platform to replace readiness work, an SSP, or a CUI enclave

Is Huntress FedRAMP authorized?

We found no Huntress offering in the official FedRAMP Marketplace as of August 25, 2026, and Huntress says openly that its position is that it does not need authorization for this use case. Under 32 CFR § 170.19(c)(2)(i), the FedRAMP requirement attaches to a cloud service provider that processes, stores, or transmits CUI. A cloud service handling only Security Protection Data — logs, configurations, alerts, credentials, and vulnerability status — lands in a different row of the same table and is assessed as a Security Protection Asset instead.

This is the argument the whole product rests on, so let's look at the actual table rather than anyone's summary of it.

The rule, as written

Table 4 to § 170.19(c)(2)(i) has exactly three rows. Everything turns on which one you're in:

What the External Service Provider handles — If it is a cloud service provider — If it is not a cloud service provider
What the External Service Provider handlesIf it is a cloud service providerIf it is not a cloud service provider
CUI — with or without Security Protection DataThe CSP shall meet the FedRAMP requirements in 48 CFR 252.204-7012.The services are in your assessment scope and are assessed as part of your assessment.
Security Protection Data only — no CUIThe services are in your assessment scope and are assessed as Security Protection Assets.The services are in your assessment scope and are assessed as Security Protection Assets.
Neither CUI nor Security Protection DataNot an External Service Provider under the CMMC definition.Not an External Service Provider under the CMMC definition.

Source: 32 CFR § 170.19(c)(2)(i), Table 4, verified August 25, 2026.

Huntress is a cloud service. So the entire question is whether the actual service relationship sits in row one or row two. Sensitive Data Mode exists to help keep it in row two. Your data-flow evidence decides whether it succeeds.

A few definitions, since they do real work here. Controlled Unclassified Information (CUI) is government-created or government-controlled information requiring safeguarding under law, regulation, or government-wide policy — engineering drawings, test reports, and technical data with military application are common examples. Security Protection Data (SPD) is security-relevant information used to protect your environment, including configuration data, log files, vulnerability status, and passwords that grant access to the in-scope environment. Under 32 CFR § 170.4, an External Service Provider (ESP) is external people, technology, or facilities used to provide or manage IT or cybersecurity services where CUI or SPD is processed, stored, or transmitted on the ESP's assets. A C3PAO is a CMMC Third-Party Assessment Organization — note that the rule says Assessment, not “Assessor.”

Why Huntress went this route

Ryan Bonner, writing on the Huntress blog in June 2026, lays out the reasoning plainly: SOC analysts need to pull suspicious files into cloud infrastructure to analyze them, and if those files contain CUI, that infrastructure enters the CUI-handling row. Huntress's alternative is to block the file types that could contain CUI, keep the SOC out of that lane, and remain in the SPD-only row.

It is a legitimate rule-based design if the boundary holds. We want to say that plainly, because the rest of this review gets specific about where the execution has holes. The question is whether it holds in your environment.

What you give up by not having FedRAMP

You are trading a federal authorization process and independent assessment against an applicable baseline for a vendor-defined technical control and your own evidence that the boundary holds. Sensitive Data Mode means Huntress maintains and enforces a published list, plus any additional extensions Huntress confirms active through support. Those are not the same kind of assurance. If your prime or your customer specifically requires a FedRAMP-authorized service, “we use Sensitive Data Mode” is not a responsive answer.


Does Huntress keep you out of scope? No — and this is the mistake that costs money

Sensitive Data Mode does not remove Huntress from your CMMC assessment scope. It can change which row the service falls into. Under 32 CFR § 170.19(c)(1), Table 3, Security Protection Assets are listed among the assets that are in the Level 2 CMMC Assessment Scope, and they carry four affirmative documentation obligations plus an assessment requirement. The benefit is staying in the Security-Protection-Data-only row instead of the CUI-handling row — not avoiding the assessment.

Huntress's marketing language says Sensitive Data Mode lets customers use the platform “while limiting their Level 2 assessment scope” and “without expanding your assessment scope.” We understand what they mean. But a contractor who writes that sentence into an SSP is going to have a bad meeting.

Here is what the rule actually requires for a Security Protection Asset:

Your obligations

  • Document it in the asset inventory
  • Document asset treatment in the System Security Plan
  • Document it in the network diagram of the CMMC Assessment Scope
  • Prepare to be assessed against CMMC Level 2 security requirements

The assessment requirement

  • Assess it against the Level 2 security requirements relevant to the capabilities provided

Source: 32 CFR § 170.19(c)(1), Table 3.

That is not a lighter touch than a CUI Asset in every respect — it is a narrower one. The assessor tests the requirements relevant to what Huntress does, not all 110. But “narrower” and “gone” are different words.

The DoD CIO's CMMC Level 2 Scoping Guide uses a managed SIEM delivered by an External Service Provider as its worked example: the SIEM may be logically separated and may not process CUI, but it still contributes to meeting CMMC requirements inside the assessment scope. That is the Huntress Managed SIEM arrangement in one sentence.

The sentence to put in your SSP

Do not write “out of scope.” Do not write “scope-limited.” Write something closer to this, adapted to your environment and supported by your actual data-flow evidence:

The Huntress Managed Security Platform is an External Service Provider and cloud service provider that provides security capabilities to our CMMC Assessment Scope. No CUI is authorized or intended to be processed, stored, or transmitted by Huntress. Sensitive Data Mode has been enabled for all in-scope organizations as of [date], blocking Huntress SOC retrieval of the file extensions listed in [attachment], including any additional extensions Huntress confirmed active in [ticket/evidence]. Based on the verified data flow, Huntress processes Security Protection Data without CUI and is treated as a Security Protection Asset under 32 CFR § 170.19. Huntress is documented in our asset inventory, SSP, and network diagram. The current service description and customer responsibility matrix are maintained at [location]. This classification will be reevaluated if the service configuration or data flow changes.

Also required, and routinely missed

Section 170.19(c)(2)(ii) requires that the ESP relationship and services be documented in your SSP and described in the ESP's service description and customer responsibility matrix (CRM). Huntress publishes a “Shared Responsibility Matrix.” Those may be the same document under two names, but the rule uses CRM, and the Cyber AB CMMC Assessment Process tells the assessment team to confirm that the CRM will be available and that ESP personnel will participate where applicable. Ask Huntress in writing whether its current Shared Responsibility Matrix is intended to satisfy the CRM requirement, and keep the answer.

The same paragraph says an ESP may voluntarily undergo a CMMC certification assessment to reduce the ESP's effort during the customer's assessment. We found no public indication that Huntress has done so. That is a fair question to ask, not a criticism.


Check your file types against the published block list

Sensitive Data Mode blocks a published list of extensions plus any additional extensions Huntress confirms active through support. Compare your CAD, PLM, office, archive, database, source-code, firmware, and media formats against the 134-entry list and the 41 near-misses below before you write the boundary into your SSP.

Compare your formats with the list →

Do not enter or send CUI, drawings, part numbers, source code, or contract details. Work from file extensions and system inventories only.


What Sensitive Data Mode actually blocks

While enabled, Sensitive Data Mode blocks the Huntress Security Operations Center from retrieving 134 published file extensions from hosts running the Huntress agent, and blocks Huntress portal mail-read operations during identity investigations. It is not enabled by default — it is turned on per organization through a support request. Huntress says SOC analysts and front-line support personnel cannot disable it; disabling requires a support ticket and leadership review.

That last part is genuinely good control design, and worth telling your assessor about. A technical control that front-line operators cannot switch off is stronger evidence than a policy statement.

We counted and categorized the full published list. Here is the shape of it, as published June 17, 2026. The categories are our editorial grouping; the extensions are Huntress's.

Category — Extensions — Category — Extensions
CategoryExtensionsCategoryExtensions
CAD and engineering34Data and archives12
Documents19Images8
Unlabeled / mixed use15Email4
Spreadsheets14Custom-labeled4
Presentations123D graphics3
Video, project, metadata, other9
Total134

Our read: the weighting is aimed squarely at defense manufacturing. Thirty-four CAD entries — CATIA, SolidWorks, Parasolid, IGES, STEP, AutoCAD, ACIS — is a list written for that environment, not for a generic SMB. Huntress explicitly invites customers to request additions, and four published entries are labeled “custom.” Do not assume an extension is active for your tenant until Huntress confirms it in writing.

<strong>View the full 134-extension list as published June 17, 2026</strong>

.3dm .3dmxl .3mf .7zip .asc .asm .bak .bmp .catdrawing .catpart .catproduct .cgr .csv .ctb .dbf .dcs .dif .doc .docm .docx .dot .dotm .dotx .drw .dwf .dwg .dws .dwt .dxf .easm .edrw .eft .emf .eml .ems .eprt .esp .espbak1 .espbak2 .espbak3 .espbak4 .esprit .etl .fpt .gdml .gif .html .iges .igs .ipl .jpg .jt .lck .lib .lin .model .mp4 .mpp .mpx .msg .nc .neu .odp .ods .odt .ost .pak .pc3 .pdf .png .pot .potm .potx .ppa .ppam .pps .ppsm .ppsx .ppt .pptm .pptx .prn .prt .pst .rtf .sab .sat .sec .session .shx .sim .sldasm .sldprt .slk .stb .step .stl .stp .sv$ .tap .tar .thmx .tif .tl .tpl .tsc .vcproject .vda .vdf .wmf .wmv .wps .wrl .wrz .x3d .xb .xt .xla .xlam .xls .xlsb .xlsm .xlsx .xlt .xltm .xltx .xlw .xml .xmpbin .xmptxt .xmtbin .xmttxt .xps .zip

Reproduced from Huntress's Sensitive Data Mode support documentation for verification purposes. Confirm the current list at source before relying on it — this list changes.


The file types it doesn't block

We tested 41 plausible CUI-bearing formats used across engineering, manufacturing, software, program administration, archives, databases, and design against the published list. None of the 41 appeared on it. Huntress explicitly invites customers to request additional extensions when enabling the mode, so this is a gap you can ask Huntress to close through one support ticket — but only if you know which ones to name and receive written confirmation.

This is the most useful table on this page. We found no public table combining these near-matches and missing families when we verified it.

Missing from the list — What creates it — Why it matters
Missing from the listWhat creates itWhy it matters
.slddrwSolidWorks 2D drawing.sldprt and .sldasm are blocked. The human-readable drawing deliverable, which may carry distribution or export-control markings, is not.
.ipt / .iam / .idwAutodesk Inventor part, assembly, drawingThe core Inventor family, common in smaller manufacturing environments.
.par / .psm / .dftSolid Edge part, sheet metal, draftThe core Solid Edge family.
.dgnBentley MicroStationUsed in infrastructure and facilities work.
.rvt / .f3d / .skpRevit, Fusion 360, SketchUpFacility drawings and rapid-prototype models.
.mcam / .gcodeMastercam, raw toolpath.nc and .tap are blocked; these are not. Toolpath files can encode geometry.
.7z7-Zip archiveThe list shows .7zip; the standard 7-Zip extension is .7z.
.epsEncapsulated PostScriptThe list shows .esp, described as an Encapsulated PostScript image file. EPS files normally use .eps.
.jpeg / .tiff / .htmCommon variants.jpg, .tif, and .html are blocked. These close variants are not.
.txt / .log / .json / .mdPlain text and dataA text or structured-data file can contain CUI as easily as a Word document.
.accdb / .mdb / .sqliteAccess and SQLite databases.dbf and .fpt are blocked; these modern database formats are not.
.vsd / .vsdx / .pub / .oneVisio, Publisher, OneNoteDiagrams and notebooks can contain network, program, or technical CUI.
.rar / .gz / .iso / .cabArchives and disc images.zip and .tar are blocked; these are not.
.psd / .ai / .svg / .webp / .heicDesign and modern image formatsDrawings, screenshots, and marked-up graphics can move through these formats.
.mov / .mbox / .wpdQuickTime, mailbox archives, WordPerfect.mp4 and .wmv are blocked; .mov is not. Mailbox archives can contain CUI-bearing messages and attachments.

Method: we transcribed all 134 published entries and tested 41 candidate formats against them programmatically. Verified August 25, 2026.

Two of these deserve a phone call, not a ticket. The .7zip entry and the .esp entry described as Encapsulated PostScript both look like they may be transcription errors in the published list — the real-world extensions are .7z and .eps. We are not asserting that they are errors. We are saying that if your environment produces either format, you should confirm coverage explicitly rather than assume the near-match is doing the work.

One thing we could not determine from public documentation: whether extension matching is case-insensitive, and how the system treats files with double extensions (drawing.dwg.bak) or no extension at all. Those belong on your question list, not in anyone's SSP as an assumption.

The support ticket to send today

Copy this, fill in your formats, and send it through the Huntress support portal:

Please enable Sensitive Data Mode for the following organizations: [list every organization ID in our CMMC assessment scope].

Please add the following extensions to the blocked list for these organizations: [.slddrw, .ipt, .iam, .idw, .par, .psm, .dft, .dgn, .mcam, .gcode, .7z, .eps, .jpeg, .tiff, .htm, .txt, .log, .json, .md, .accdb, .mdb, .sqlite, .vsd, .vsdx, .rar, .gz — edit to match our environment].

Please also confirm in writing: (1) the date Sensitive Data Mode was enabled for each organization, (2) whether extension matching is case-insensitive, (3) how files with multiple extensions or no extension are handled, and (4) confirmation once the additional extensions are active.

We require this confirmation as evidence for our CMMC Level 2 assessment and self-assessment records.

That last line matters. You are not asking for a favor; you are creating an artifact.


What you give up — the honest tradeoff

Sensitive Data Mode is not a free compliance toggle. It buys a cleaner CUI boundary by deliberately removing investigative capability, and it still permits Huntress analysts to retrieve executables, scripts, and other file types outside the blocked set. That trade is reasonable for many defense manufacturers. It is not reasonable for everyone, and the deciding factor is what your CUI is made of.

This is the part of the review we'd want if we were buying.

What turns off when you turn it on:

Capability — Standard mode — With Sensitive Data Mode
CapabilityStandard modeWith Sensitive Data Mode
Endpoint retrieval of documents, spreadsheets, CADSOC can pull files for analysisPublished extensions and additions Huntress confirms active are blocked.
Retrieval of executables and scriptsSOC can pull themSOC can still pull them.
SOC review of email contents during identity investigationsAvailable through mail-read permissionsBlocked; Huntress says the portal cannot perform mail-read operations.
Mass outbound spam detectionAvailable where supportedUnavailable.
Configuration scopeStandardEnabled separately for each organization.
Turning it back offN/ARequires a support ticket and leadership review.

Source: Huntress, “Huntress Sensitive Data Mode”, updated June 17, 2026.

Huntress states that analysts can still deliver incident reports at 99% accuracy under this configuration. That is a company-stated figure we did not independently verify, and accuracy of reporting and completeness of forensic context are different things.

The reason executables matter more than people think

Huntress's design premise, stated plainly on its blog, is that there is “little to no overlap” between the file types a SOC needs to analyze — executables, scripts, installers — and the file types that contain CUI, which it characterizes as Office documents, PDFs, and CAD drawings.

For many machine shops, that premise is directionally right. Their CUI often lives in drawings and specifications. Blocking those formats costs the SOC comparatively little.

For a software, firmware, or embedded-systems contractor, that premise breaks. If you're delivering software with military application, your CUI may be the source code, build artifacts, firmware image, or compiled binary. Sensitive Data Mode is architected around the assumption that those are the file types analysts should still be able to pull.

That is not a universal flaw in Huntress. It's a mismatch between the product design and a particular kind of customer.

If your CUI lives in code, scripts, firmware, or binaries, this configuration does not solve your problem, and adding .exe, .dll, .py, or similar extensions to the blocked list could gut the product's core function. You need a different architecture: a CUI enclave that keeps development artifacts out of the monitored boundary, or a security stack whose cloud services meet the contractual and CMMC requirements for any CUI they process. Start with our CMMC scoping guide instead of treating this as a product-setting problem.

For everyone else — and that is much of the manufacturing DIB — the trade can be defensible. But defensible is a thing you have to write down. An assessor asking why your MDR provider cannot investigate a business email compromise deserves a documented answer and an implemented alternative control where needed.


Get the evidence questions answered before you commit

We assembled 14 Huntress evidence questions covering everything that public documentation does not resolve cleanly: extension matching behavior, what CUI could reach SIEM log content, incident-response acquisition, product-specific retention, whether the Shared Responsibility Matrix satisfies the CRM requirement in § 170.19(c)(2)(ii), and who can disable Sensitive Data Mode.

Open the 14-question evidence request →

Send the questions to Huntress, your MSP, and whoever is reading your SSP. Their written answers become your assessment artifacts.


Why the number moved from 37 to 55

Huntress currently states that its platform maps to 55 of the 110 NIST SP 800-171 Revision 2 requirements, up from 37, and attributes the increase to Managed Identity Security Posture Management. The 37 figure came from the November 2025 launch materials and still appears on a live Huntress CMMC page. Huntress's July 24, 2026 update says the revised Shared Responsibility Matrix moved the company-stated mapping to 55 after ISPM was added. A separate live June 25, 2026 Huntress page says the platform “satisfies 51 of the 110 controls.” We found no public explanation reconciling 51 with 55.

The practical takeaway is not that anyone is being dishonest. It's that the number is product-, tenant-, configuration-, and responsibility-dependent. Fifty-five is not your number unless your deployment includes the products and environment the current matrix assumes, and you perform the customer-owned work next to them.

Huntress moved ISPM from Early Access to general availability on July 1. Its current release note says ISPM is a standalone product with no ITDR license required, and Huntress publishes it as a separately priced product. But ISPM is still Microsoft 365-specific, and the current rollout guide says the tenant must not be GCC or GCC High.

So the honest version of the number is:

Figure — Verified origin — What the buyer must confirm
FigureVerified originWhat the buyer must confirm
37 of 110November 5, 2025 Huntress launch materials; the figure remains on a live Huntress CMMC pageWhich modules, determination statements, and customer responsibilities the older matrix assumed.
51 of 110June 25, 2026 Huntress blog page using the stronger verb “satisfies”Why this figure differs from both 37 and 55, and which matrix version it reflects.
55 of 110July 24, 2026 Huntress update after Managed ISPM was added to the mappingCurrent module set, Microsoft 365 compatibility, tenant type, matrix version, and the exact meaning of “maps to.”

If your identity platform is not Microsoft 365, or your tenant is GCC or GCC High, the path from 37 to 55 is a number about somebody else's environment.

Ask for the verb, not the number

When a vendor tells you it “covers” a requirement, make it pick one of these:

  • Maps to — the product is related to this requirement
  • Supports — the product helps, but you still implement
  • Implements — the product performs the technical function
  • Provides evidence for — the product produces an artifact relevant to an assessor
  • Satisfies — every applicable determination statement for this requirement is met by the product alone

Those five verbs describe wildly different amounts of work. NIST SP 800-171A decomposes the 110 requirements into determination statements, and a single requirement can fail on something the product never touches — such as whether you defined a review frequency, assigned an owner, performed the review, and retained evidence.

Errors on Huntress's own pages you should not inherit

We flag these not to score points but because contractors copy vendor language into SSPs, and these specific items will not survive review. Verified on live Huntress pages August 25, 2026:

What a Huntress page says — What the primary source says
What a Huntress page saysWhat the primary source says
Huntress’s controls guide lists 14 domains including Situational Awareness and Recovery, and omits Awareness and Training and Maintenance.The 14 families in NIST SP 800-171 Rev. 2 are AC, AT, AU, CM, IA, IR, MA, MP, PE, PS, RA, CA, SC, and SI. Situational Awareness and Recovery were CMMC 1.0 domains, not Level 2 families.
The same controls guide says “CMMC Level 1 controls consist of 17 practices.”32 CFR § 170.4 defines Level 1 as the 15 requirements in FAR 52.204-21.
Huntress’s CMMC solution page uses control IDs AC.2.007, AU.2.041, IA.2.081, IR.2.092.Those are retired CMMC 1.0 identifiers. 32 CFR Part 170 uses the Level-prefixed format, such as AC.L2-3.1.5.
The same solution page says Level 2 requires a C3PAO assessment every three years “with annual self-assessments in between.”The in-between obligation under DFARS 252.204-7021 is an annual affirmation by an affirming official, which is a different artifact with different legal weight.
The solution page says “A passing CMMC Level 2 assessment requires a score of 110 out of 110.”110 of 110 is required for Final status. Conditional status is available at a qualifying score with a compliant POA&M under 32 CFR § 170.21.
Huntress’s C3PAO guide expands C3PAO as “Certified Third-Party Assessor Organization.”32 CFR § 170.4: CMMC Third-Party Assessment Organization.
Huntress’s CMMC-vs.-FedRAMP guide says “55 of the 100 CMMC Level 2 controls.”32 CFR § 170.4 incorporates 110 Level 2 requirements from NIST SP 800-171 Rev. 2.

Small things. But an SSP that says “we are pursuing Situational Awareness domain controls” is an SSP that tells an assessor nobody read the rule.


What Huntress costs for a CMMC environment

Huntress publishes list pricing, which is unusual in this market and genuinely to its credit. As displayed on August 25, 2026 at the 50–99 unit band: Managed EDR $8.99 per endpoint per month, Managed ITDR $4.80 per identity, Managed SIEM $4.00 per data source, Managed SAT $2.08 per learner, and Managed ISPM $4.00 per identity. Direct and reseller purchases carry a 50-unit minimum per product. Huntress says MSP-delivered purchases have no Huntress-required minimum seat count.

That minimum is where small contractors get surprised, so let's do the arithmetic the pricing page does not put in one row.

What the 50-unit minimum means for a 25-person shop

Company size — EDR — ITDR — ISPM — SAT — Effective monthly — Effective annual
Company sizeEDRITDRISPMSATEffective monthlyEffective annual
25 people buying direct or through a reseller — billed at the 50 minimum$449.50$240.00$200.00$104.00$993.50$11,922
50 people buying direct or through a reseller$449.50$240.00$200.00$104.00$993.50$11,922

Computed from Huntress's published 50–99 unit prices, verified August 25, 2026. Assumes one endpoint, one identity, and one learner per employee. Excludes Managed SIEM, which is billed per data source; add $4.00 per source per month. Not a quote.

Read the two rows again. A 25-person machine shop buying direct or through a reseller pays the same product minimum as a 50-person shop. That's roughly $12,000 a year before SIEM sources, deployment, integration, portal operations, readiness work, or any Microsoft licensing your selected identity controls require. The MSP route is worth pricing because it removes Huntress's minimum and can include the day-to-day work the published software price excludes.

What the price does not include

Huntress states this directly on its pricing page: the published prices include the 24/7 SOC but do not include deployment, integration, or the day-to-day operational and portal management a Huntress partner can provide. Standard term is 12 months. Huntress says it does not offer standard multi-year price protection, and overages are processed manually rather than automatically billed.

And then there's the part the software price never touches. Even under the company-stated 55-requirement mapping, at least 55 requirements sit outside that mapping, and the mapped requirements still contain customer-owned policy, implementation, evidence, and operational work. Your CUI boundary, System Security Plan, POA&M, physical security, personnel screening, configuration baselines, media protection, and recurring evidence tasks do not disappear because a product maps to a requirement.

Cheap tooling plus no program is not a compliance strategy. It's a faster way to fail.

See our full breakdown of CMMC Level 2 cost before comparing software quotes as though they were program quotes.


Find out what fills the other half

Huntress may solve part of your technology layer at a published price. The gap it leaves is usually readiness, documentation, architecture, and evidence operations — which are different provider categories, and the wrong one costs six figures to fix later.

Tell us your level, scope, and timeline, and we'll match you with source-checked CMMC provider options.

Use Find My CMMC Path →

The CMMC Path Framework maps your required level, FCI vs. CUI handling, assessment type, cloud environment, and contract timeline to the right provider category — not a named provider. It is not a score, ranking, or compliance determination. Do not submit CUI, drawings, or sensitive contract details.


Does Huntress work in GCC High?

Some Huntress capabilities have documented GCC High integration paths — Managed ITDR and the Microsoft Defender for Endpoint integration do — but “works with GCC High” is not a platform-wide yes. Huntress says mass outbound spam detection is unavailable in GCC High because the platform does not hold the mail-read permissions used for that capability. More importantly, Huntress's current Managed ISPM rollout guide says the organization must not be a GCC or GCC High environment.

That means a GCC High buyer cannot assume the public 55-of-110 mapping applies. The product that Huntress says moved the number from 37 to 55 is not available to that tenant type under the current public requirements.

Two things to confirm before you rely on the stack:

One: the email limitation is real in that environment. It applies regardless of whether Sensitive Data Mode is on. If business email compromise detection is a meaningful part of your threat model — and for a company whose people email controlled drawings or technical data, it often is — document the gap and the alternative control.

Two: obtain a GCC High-specific mapping in writing. Do not let a reseller apply the commercial Microsoft 365 control count to a GCC High tenant by verbal shorthand. Send this:

Please provide the current GCC High-specific Shared Responsibility Matrix or NIST SP 800-171 Rev. 2 mapping for our proposed Huntress products. Identify which requirements or evidence claims in the public 55-of-110 figure depend on Managed ISPM and therefore do not apply to GCC High. Also confirm the GCC High feature limitations for Managed ITDR, Microsoft Defender for Endpoint, mail-read operations, mass outbound spam detection, and any other proposed module.


What Huntress does not do

Huntress supplies detection, response, log collection, identity monitoring, posture management, and awareness training. It does not define your CUI boundary, write and own your System Security Plan, manage your POA&M, submit your NIST SP 800-171 DoD Assessment score, post your CMMC self-assessment results and affirmation, make your 72-hour cyber-incident report to DIBNet, or sign your annual affirmation. Those are the tasks that fail assessments, and no security platform performs all of them.

Task — Huntress — MSP / readiness provider — Your organization
TaskHuntressMSP / readiness providerYour organization
Detect and respond to endpoint threatsDeploys, integrates, and acts on escalationsOwns business response and decisions.
Collect and retain security logs✅ for configured sourcesConfigures sources and workflowsDefines retention, review, and evidence requirements.
Identify and mark CUI in your environmentMay adviseOwns the determination.
Define the CMMC assessment boundaryAdvisesOwns and approves it.
Write and maintain the System Security PlanProvides product inputsMay draft or maintainOwns accuracy and implementation.
Maintain the POA&MMay draft or operateOwns closure and truthfulness.
Submit the NIST SP 800-171 DoD Assessment score under 7019/7020May assistContractor responsibility.
Submit CMMC self-assessment results and annual affirmation under 7021May assistAffirming official responsibility.
72-hour cyber-incident report to DIBNetProduces incident informationMay assistContractual duty.
Preserve images and relevant monitoring or packet-capture data for at least 90 daysMay preserve product evidenceMay assistContractual duty.

That right-hand column is the one that gets contractors in trouble.

Note especially DFARS 252.204-7012 paragraphs (c) through (g). They cover cyber-incident reporting within 72 hours of discovery, submitting discovered malicious software to the DoD Cyber Crime Center, preserving images of affected systems and relevant monitoring or packet-capture data for at least 90 days, granting government access for forensic analysis, and supporting damage assessment. A Huntress incident report is an input to that process. It is not the process. The clock starts when you discover the incident, not when a vendor emails you.

Do not blur two different SPRS duties. DFARS 252.204-7019 and 252.204-7020 deal with the current NIST SP 800-171 DoD Assessment score and its posting in SPRS. DFARS 252.204-7021 deals with the contractually required CMMC status, self-assessment results where applicable, annual affirmation, and flowdown. One number does not substitute for the other record.

There is also a data-flow point worth being precise about, because it is where “we never see your CUI” gets shaky at the edges. Sensitive Data Mode governs agent file retrieval by extension and portal mail-read operations. Huntress's routinely collected telemetry — file paths, file metadata, process parameters, user accounts, Microsoft 365 audit events, and session details — is a separate stream, and a file path can be revealing on its own. \\Engineering\Programs\F-XX\WingSparToleranceRevC.slddrw tells a story before anyone opens the file.

Huntress's public Data Collected by Huntress page says that, unless otherwise noted, the documented EDR and ITDR data is held indefinitely in U.S.-based data centers. Huntress separately documents expanded forensic acquisition initiated manually by SOC analysts or automatically by playbooks, with agent tasks and retrieved artifacts available in portal audit logs. Its public Sensitive Data Mode article says blocked extensions cannot be retrieved through the Huntress agent; the public material does not map those two workflows step by step. Ask Huntress to confirm in writing that the extension block governs every expanded acquisition path you will rely on. Confirm product-specific retention, SIEM retention, deletion terms, subprocessors, incident-response acquisition, and contract language for the exact services you buy.

We are not saying Huntress mishandles this. We are saying that “what files can the SOC pull” and “what information leaves my environment” are two different questions, and the answer to the second one belongs in your SSP. Ask it directly.


The documentation question worth asking

Huntress publishes a free CMMC documentation library — a Shared Responsibility Matrix, Operations Plan, Interconnection Security Agreement, editable baseline configurations, a Security Operations Approvals document, and checklists and scheduled-review templates — developed with the CMMC consulting firm DEFCERT. The material is a real head start on drafting work most small contractors dread. But it is an input to your System Security Plan, not third-party validation of your implementation, and the distinction matters more than it sounds.

Ryan Bonner is DEFCERT's founder and CEO. His Huntress author bio says he was among the first CMMC Provisional Assessors and has led DFARS and CMMC projects for more than 150 DIB manufacturers; DEFCERT's team page says he contributed to the CMMC Assessment Guides through a Cyber AB industry working group. We checked the core Security Protection Asset analysis attributed to him against the rule text, and it held up.

Here is the relationship context a buyer should have, drawn from what the parties have publicly disclosed:

  • Huntress announced the DEFCERT collaboration in November 2025, describing DEFCERT as the firm helping produce assessment-preparation documentation.
  • The June 2026 post “Why Huntress Doesn't Need FedRAMP” is published on Huntress's website and authored by Bonner.
  • In March 2026, IntelliGRC announced a $3.5 million seed round co-led by Huntress co-founder and CEO Kyle Hanslovan and Blu Ventures, with participating investors including Huntress co-founder John Ferrell, former Huntress CFO Marcos Torres, and Ryan Bonner of DEFCERT.

Nothing here is hidden and nothing here is improper. Everyone involved put their name on it. The relationships do not invalidate the documentation. They are relevant context when a buyer weighs vendor-supported analysis and decides whether to obtain an independent read for its own environment.

The practical point is narrow. Your assessor is not going to test Huntress's position in the abstract. They are going to test yours. The Shared Responsibility Matrix tells you what Huntress says it supports; your SSP has to say what you actually implemented, who owns each determination statement, and what evidence proves it. Get the matrix, record its version and date, note which modules and tenant types it assumes, and have someone who works for you — an RP/RPO, qualified internal owner, or federal-contracts counsel where the issue is contractual — read it against your environment.

Also: the current matrix is not publicly readable without Huntress Trust Center or partner access. If you're evaluating Huntress before buying, ask for the current version during evaluation. Do not accept a control count while the document behind the count stays unavailable to your reviewer.

For the broader rule, see our guide to how External Service Providers are scoped under CMMC.


Will an assessor accept Huntress?

No source can promise universal assessor acceptance of any product, because a CMMC assessment evaluates your organization's scope, implementation, and evidence — not a vendor's product. The Cyber AB Code of Professional Conduct prohibits guarantees or promises about assessment or certification results. Huntress has published one attributable case in which a managed service provider completed a Level 2 assessment with Huntress in scope, and that case should be read as one data point rather than a typical result.

The case, as Huntress reported it in November 2025: a managed service provider achieved a Level 2 result with Huntress in scope in nine hours over two days, with a score of 110. The engagement was guided by Scott Lumpkin, a CMMC Certified Professional and Director of Quantum AI Security, LLC, who is quoted saying the Huntress implementation and documentation met CMMC and NIST SP 800-171 expectations.

What we did not do: inspect the assessment record, scope, environment, evidence, certificate, or C3PAO work papers. This is a vendor-published account with a named practitioner attached — better than an anonymous testimonial, and still not independent verification. Huntress did not publish enough scope detail to use nine hours as a planning benchmark. Do not build your assessment schedule around it.

What a C3PAO examines in a Level 2 certification assessment:

  • Your asset inventory and where Huntress appears in it
  • Your network diagram showing the Huntress data flow
  • SSP treatment of Huntress as a Security Protection Asset
  • Evidence that Sensitive Data Mode is enabled — and when
  • The blocked-extension list as applied to your organizations
  • The service description and current customer responsibility matrix
  • Configuration evidence and operational records over time, not a screenshot from last week
  • Whether your people can explain the arrangement in an interview

That last one can sink an otherwise solid implementation. If your controller cannot explain why the security vendor cannot read email, you have a documentation and training problem, not a product problem.


What the Phase II suspension changes

The July 13, 2026 suspension changes the CMMC assessment status the Department may require during the review. It does not remove the underlying work needed to protect CUI. Phase 1 began November 10, 2025 and was planned to run through November 9, 2026. Phase II was scheduled for November 10, 2026. The Department's implementing memorandum now directs program managers and requiring activities to use only Level 1 (Self) or Level 2 (Self) designations during the suspension, not Level 2 (C3PAO) or Level 3 (DIBCAC), and directs contracting officers to amend or modify affected solicitations and contracts on the stated schedule.

The same memorandum says DFARS 252.204-7012 remains in effect and that the Department will enforce NIST SP 800-171 Rev. 2 through self-assessments and select government-led assessments. 32 CFR Part 170 remains on the books. The memorandum pauses new Department designations of the two certification-assessment types; it does not amend the rule text.

Here is what that means for a Huntress decision specifically, and it runs against the intuition.

Under a Level 2 self-assessment, there is no C3PAO in the loop to accept or reject your Security Protection Asset argument before you submit the result. Your organization defines the scope, conducts the assessment, submits the required record, and the affirming official signs the annual affirmation. Your award eligibility can ride on the accuracy of that work.

Keep the two government records separate:

  • DFARS 252.204-7019 and 252.204-7020: the current NIST SP 800-171 DoD Assessment score in SPRS.
  • DFARS 252.204-7021: the CMMC status required by the contract, self-assessment results where applicable, the annual affirmation, and flowdown.

The documentation burden did not disappear. A vendor's marketing page is not a defense. A scope assertion underlying a result you submit to a government system and use in support of contract eligibility is the kind of thing that can be examined later by a government assessment team, a prime's diligence process, or in a contract dispute. The SSP you write this year is still the one you will have to explain.

There is also a flowdown wrinkle. The suspension directs Department acquisition personnel and requires changes to affected government solicitations and contracts. It does not automatically rewrite every existing subcontract term between a prime and a supplier. DFARS 252.204-7021 contains flowdown requirements, and a prime may also impose separately negotiated cybersecurity conditions. Confirm any change to your subcontract terms in writing before you change your plan.

Our read, stated as editorial judgment: the suspension is a window to fix your scope and evidence properly rather than a reason to stop. Use it.


Who Huntress fits, and who should look elsewhere

Huntress fits smaller and mid-size contractors and MSP-managed environments that need managed security at a workable price and can maintain a documented Security-Protection-Data-only boundary. It fits poorly where CUI lives in file types the platform still retrieves, where the coverage number depends on an unavailable module, or where the buyer expects one platform to complete a CMMC program.

Your situation — Editorial fit — What to do
Your situationEditorial fitWhat to do
CUI is drawings, specifications, and Office documents; Microsoft 365 commercialStrong candidateEnable Sensitive Data Mode, request and confirm your missing extensions, and document the boundary.
Existing Huntress customer; Sensitive Data Mode never enabledFix this weekSend the support ticket above and record the enablement date as evidence.
MSP standardizing multiple DIB clientsStrong, with disciplinePer-organization configuration means per-organization evidence. Build and enforce a checklist.
GCC High tenantConditionalUse the GCC High-specific product set and mapping. Do not apply the 55 figure because current ISPM documentation excludes GCC High.
Under 50 employees, buying direct or through a resellerCheck the mathThe 50-unit minimum per product means you pay for 50. Price the MSP route before deciding.
CUI in source code, firmware, scripts, or binariesNot the right architectureEvaluate CUI enclave options; Sensitive Data Mode does not solve this.
Expecting one platform to close all 110 requirementsWrong expectationStart with the CMMC readiness checklist, not a product.
No one owns recurring evidence tasksNot assessment-ready at any priceAssign owners before you buy anything.
Ready for a formal certification assessmentDifferent question entirelyReadiness and assessment must stay independent. See Who to Hire First and CMMC Provider Categories.

What to verify before you buy or keep Huntress

Do not make this decision from a demo, a control count, or the phrase “CMMC compliant.” Fourteen items, ordered by how much damage getting them wrong can do:

  1. Is Sensitive Data Mode enabled on every organization in your assessment scope, and on what date?
  2. Which file types hold your CUI — do you have an actual inventory, or an assumption?
  3. Do the blocked extensions cover them — and have you requested additions in writing?
  4. Can CUI exist in executables, scripts, source code, firmware, or build artifacts in your environment?
  5. Which Huntress modules do you actually have — and does your requirement mapping match them?
  6. Is extension matching case-insensitive, and how are double-extension or extensionless files handled?
  7. What CUI could reach SIEM or telemetry content — file paths, document titles, command parameters, error strings?
  8. What happens during incident response — can expanded forensic acquisition reach beyond the blocked list, who authorizes it, and is it logged?
  9. Do you have the current Shared Responsibility Matrix — with its version, date, modules, and tenant assumptions recorded?
  10. Does Huntress intend that document to satisfy the CRM requirement in 32 CFR § 170.19(c)(2)(ii), and will Huntress personnel support an assessment where required?
  11. Who can disable Sensitive Data Mode, what approval is required, and is the action logged and reviewable?
  12. What are the exact retention, deletion, residency, and subprocessor terms for each product? Huntress publicly says most documented EDR and ITDR data is held indefinitely in U.S.-based data centers unless otherwise noted; obtain the product- and contract-specific answer.
  13. If GCC High: what is the applicable requirement mapping without Managed ISPM, and which email, ITDR, MDE, or portal features differ?
  14. What is the full-year cost including minimums, Microsoft licensing, deployment, integration, portal management, and the readiness work Huntress does not do?

Answers one through four you can get today. The rest belong in a written exchange you keep with your SSP.


If Huntress isn't the fit

The right alternative depends entirely on why it failed. A boundary problem needs different architecture; an implementation problem needs a readiness provider; an evidence problem may need a GRC platform; and an assessment-ready organization needs something else again. We route to provider categories rather than publishing a ranked vendor list, because a category is a decision you can verify and a ranking is a decision someone sold you.

Why Huntress didn't fit — Category to evaluate — What to verify first
Why Huntress didn't fitCategory to evaluateWhat to verify first
CUI can reach the security cloud serviceCUI enclave / secure collaborationBoundary design, migration path, and what stays outside.
Nobody implements or operates the requirementsCMMC-focused MSP / MSSP / managed complianceWho owns each determination statement and what evidence they produce.
SSP, scoping, and remediation are incompleteRPO / RPMethodology, deliverables, conflicts, and current Cyber AB Marketplace status.
Evidence is scattered across tools and inboxesGRC platformDetermination-statement-level mapping and export — as a supporting layer, never the whole solution.
Lost detection capability creates a real gapAlternative or supplemental MDR / SIEMData flow first, features second.
Genuinely ready for a formal assessmentC3PAOCurrent Cyber AB authorization, availability, price, and independence.

On that last row, one rule is not optional. The Cyber AB Code of Professional Conduct prohibits the C3PAO organization and its assessment-team members from participating in a Level 2 certification assessment when they served as a consultant to prepare that organization for any CMMC assessment within the previous three years. The prohibition covers preparatory, advisory, and consulting activities. The same Code of Professional Conduct also prohibits guarantees or promises about assessment or certification results.

Keep readiness and assessment separate. If a provider offers to prepare you and certify the same scope without addressing that three-year rule, that is your signal to walk, not a convenience.


Huntress CMMC review: frequently asked questions

Is Huntress CMMC certified? No, and no product is. A CMMC status applies to an organization for a defined CMMC Assessment Scope through the assessment and affirmation processes in 32 CFR Part 170. Huntress is a technology and managed-security component that may support specific requirements within that scope.

Is Huntress FedRAMP authorized? We found no Huntress offering in the official FedRAMP Marketplace as of August 25, 2026. Huntress's stated position is that authorization is not required for a deployment in which the service processes Security Protection Data without CUI. If CUI reaches the cloud service, the analysis changes.

Does Sensitive Data Mode take Huntress out of my assessment scope? No. Security Protection Assets are explicitly listed among assets that are in the Level 2 CMMC Assessment Scope under 32 CFR § 170.19(c)(1), Table 3. They must appear in your asset inventory, SSP, and network diagram and are assessed against the Level 2 requirements relevant to the capabilities provided.

How many CMMC requirements does Huntress cover? Huntress's newest public mapping says 55 of the 110 NIST SP 800-171 Rev. 2 requirements, up from 37 after Managed ISPM was added; another live Huntress page says 51. Treat every count as company-stated mapping language, not a compliance score. Obtain the current Shared Responsibility Matrix and confirm modules, tenant compatibility, and customer-owned work.

Is Sensitive Data Mode on by default? No. It is enabled per organization through a Huntress support request. Huntress says SOC analysts and front-line support cannot disable it; disabling requires a ticket and leadership review.

What file types does Sensitive Data Mode block? Huntress published 134 extensions on June 17, 2026, weighted heavily toward CAD and engineering formats, documents, spreadsheets, presentations, and archives. Customers can request additional extensions.

Does it block every file type that could contain CUI? No list can. We tested 41 plausible CUI-bearing formats — including SolidWorks drawing files, the Autodesk Inventor and Solid Edge families, .txt, .json, .accdb, .vsdx, .7z, and .rar — and found none of them on the published list.

Can Huntress still retrieve executables and scripts? Yes. Huntress says analysts can still retrieve and analyze executables, scripts, and other file types outside the blocked set. If your CUI can exist in those formats, this configuration does not solve your boundary problem.

Does Sensitive Data Mode disable any features? Yes. It blocks SOC review of email contents during identity investigations, and mass outbound spam detection becomes unavailable. That detection is also unavailable in GCC High.

Does Huntress work with GCC High? Managed ITDR and the Microsoft Defender for Endpoint integration have documented GCC High paths. Mass outbound spam detection is unavailable there. Huntress's current Managed ISPM requirements exclude GCC and GCC High, so obtain a GCC High-specific mapping rather than relying on the 55-requirement figure.

How much does Huntress cost? At the 50–99 unit band as of August 25, 2026: EDR $8.99 per endpoint, ITDR $4.80 per identity, SIEM $4.00 per source, SAT $2.08 per learner, and ISPM $4.00 per identity, monthly. Direct and reseller purchases carry a 50-unit minimum per product; Huntress says MSP purchases have no Huntress-required seat minimum. Deployment, integration, and portal management are excluded.

Will a C3PAO accept Huntress? No universal answer is supportable, and a C3PAO cannot guarantee the result. Assessments evaluate your scope, implementation, evidence, and documentation — not a vendor's product. Huntress has published one attributable case of a Level 2 assessment completed with Huntress in scope; it should not be treated as typical.

Does the Phase II suspension mean we can stop preparing? No. The suspension blocks new Level 2 (C3PAO) and Level 3 designations by Department program offices during the review, but Phase I self-assessment requirements remain, DFARS 252.204-7012 remains in effect, and the Department says it will enforce NIST SP 800-171 Rev. 2 through self-assessments and select government-led assessments.

Can Huntress replace an RPO, a GRC platform, a CUI enclave, or a C3PAO? No. Those categories solve implementation, evidence, architecture, and assessment problems respectively. A managed security platform addresses part of the technical layer.


Methodology and corrections

We built this page by reading primary sources rather than summarizing vendor marketing. On August 25, 2026 we verified 32 CFR Part 170, including § 170.4, § 170.19, § 170.21, and § 170.24; the DoD CIO CMMC Level 2 Scoping Guide; DFARS 252.204-7012, 252.204-7019, 252.204-7020, and 252.204-7021; the Department's July 13, 2026 Phase II suspension announcement and implementing memorandum; NIST SP 800-171 Rev. 2, the June 2018 SP 800-171A, the February 2021 SP 800-172, and the May 2026 SP 800-172 Rev. 3; and the Cyber AB CMMC Assessment Process and Code of Professional Conduct.

We then reviewed Huntress's CMMC solution page, controls guide, C3PAO guide, and CMMC-vs.-FedRAMP guide; “Huntress and CMMC”; “Huntress Sensitive Data Mode”; Data Collected by Huntress; the November 2025 launch release; the June 2026 FedRAMP post; the July 2026 37-to-55 update; the live 51-of-110 page; current Managed ISPM release and rollout materials; GCC High ITDR and MDE documentation; the public pricing page; expanded incident-response data collection; the DEFCERT collaboration; the published assessment case; and the IntelliGRC funding announcement. We transcribed all 134 blocked extensions and tested 41 candidate CUI-bearing formats against them.

Claims on this page fall into three classes, and we keep them visibly separate: regulatory facts cited to the issuing authority; company-stated product, price, availability, and outcome claims attributed to Huntress and dated; and editorial judgments derived from those verified facts and labeled as our read.

What we could not verify: the contents and exact version of the current Shared Responsibility Matrix; whether extension matching is case-sensitive; how files with multiple or absent extensions are handled; the Huntress case study's underlying assessment record and scope; contract-specific retention, deletion, and subprocessor terms for every product; and whether Huntress has undergone a voluntary CMMC assessment as permitted by 32 CFR § 170.19(c)(2)(ii). Each appears in the verification checklist rather than as an assertion.

Prices, availability, product mappings, and blocked-extension lists change. The CMMC program is also under active review. If something on this page is out of date or wrong, tell us and we will investigate, correct it, and note the change under our Corrections Policy.


This article is educational research, not legal, contractual, or compliance advice. The clauses in your contract and your actual FCI/CUI handling set your obligations — not a checklist and not a vendor's mapping. Confirm scope and applicability with a qualified CMMC practitioner and, where contract interpretation is involved, a qualified federal-contracts attorney.

The Defense Compliance Report is an independent trade publication on CMMC and DIB compliance. We are not affiliated with the Cyber AB, the Department of War or Defense, DCMA DIBCAC, NIST, FedRAMP, or any U.S. government agency, and we have no compensation relationship with Huntress or DEFCERT.


Need help deciding what type of CMMC provider you need?

Tell us your level, scope, and timeline, and we'll match you with source-checked CMMC provider options.

Find My CMMC Path →

Do not submit CUI, drawings, source code, contract numbers, network diagrams, vulnerability details, or export-controlled information.