By The Defense Compliance Report Editorial Team Last reviewed: August 2026 · Last verified: August 28, 2026
The bottom line
Here's the short version of this NeQter Labs CMMC review: NeQter Labs sells a primarily on-premises cybersecurity and compliance appliance, a GRC layer, and related readiness support. It is not a C3PAO, and buying the product does not give your company a CMMC status. Its own published control-by-control guide addresses 38 of the 110 Level 2 security requirements. The guide discusses all nine Audit and Accountability requirements, but it describes only four individual practices as fully met. It addresses none of Awareness and Training, Maintenance, Physical Protection, or Personnel Security. Published pricing runs $325 to $1,890 per month depending on device count and contract term.
That is a real product with an honest, narrow job. It is not 82% of your CMMC program, no matter how the marketing page reads.
We'll show you where the 38 number comes from, why NeQter's own website contains two versions of the same coverage claim that mean wildly different things, and the three data-path questions that decide whether NeQter is only an in-scope Security Protection Asset or whether an external service provider relationship also enters your assessment scope.
Which contractor this fits
Good fit if: you handle Controlled Unclassified Information (CUI), run under roughly 100 devices, have no centralized logging today, and need Audit and Accountability evidence you can actually put in front of an assessor.
Not the fit if: you expected one product to get you to 110. None does. Start with our CMMC Readiness Checklist so you can see the whole board before you buy a piece of it.
Wrong page entirely if: you need someone to implement controls, operate the stack, and write your policies. That is readiness and managed-service work, not a software purchase. Find My CMMC Path will point you to the provider category that fits the problem.
How we evaluated this
This is a documentary review of NeQter Labs' published position on CMMC — its product pages, pricing pages, public documentation, change log, case studies, and terms — read against the current CMMC Program Rule at 32 CFR Part 170, the applicable DFARS clauses, and the NIST publications incorporated by the rule on August 28, 2026.
We did not install the product. We did not interview the company. We did not receive product access, a demo environment, or unpublished evidence from NeQter for this review.
Disclosure: The Defense Compliance Report is an independent trade publication on CMMC and Defense Industrial Base compliance. This page contains no paid NeQter link, sponsored NeQter placement, or NeQter referral button. We may receive compensation for clearly disclosed qualified introductions elsewhere on the site. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification. There is no NeQter button here, because we haven't earned the right to put one here.
Read our methodology, editorial standards, and editorial and advertising policy.
The Defense Compliance Report is an independent decision resource for CMMC and Defense Industrial Base compliance — explaining the rule with primary-source citation and mapping a contractor's level, CUI scope, assessment type, and timeline to the right provider category, so DIB contractors choose the right path before they spend six figures.
Before we go further: the handoff
The right CMMC provider is not the same for every contractor. The category you need — a C3PAO, an RPO or other readiness consultant, an MSSP, a GRC platform, or a CUI enclave — depends on the required CMMC status written into your solicitation or contract, whether you handle FCI or CUI, your assessment type, your cloud and IT environment, and your contract timeline.
Because a general product review cannot resolve those facts for you, use The Defense Compliance Report's Find My CMMC Path tool before you request quotes. Do not submit CUI, drawings, credentials, network diagrams, or sensitive contract details.
Quick definitions, since we'll use these terms throughout:
- CMMC — the Cybersecurity Maturity Model Certification program established in regulation at 32 CFR Part 170, effective December 16, 2024.
- C3PAO — a CMMC Third-Party Assessment Organization authorized or accredited to conduct Level 2 certification assessments. A software vendor cannot issue that status by selling you a product.
- RPO / RP — Registered Provider Organization and Registered Practitioner, Cyber AB readiness designations. They can help you prepare. They do not certify you.
- CUI — Controlled Unclassified Information. FCI — Federal Contract Information, a lower-sensitivity category.
- SPRS — the Supplier Performance Risk System, where applicable NIST SP 800-171 assessment results and CMMC records are stored and where required annual affirmations are submitted.
- DIBCAC — the Defense Contract Management Agency's Defense Industrial Base Cybersecurity Assessment Center, which conducts Level 3 assessments and other government assessments.
- Security Protection Asset (SPA) — an asset that provides security functions or capabilities to the CUI environment. Under 32 CFR 170.19, SPAs are in scope and are assessed against the Level 2 requirements relevant to the capabilities they provide. A SIEM normally fits that definition.
- Controlling NIST versions — CMMC Level 2 still uses NIST SP 800-171 Revision 2, February 2020, and Level 3 uses the rule's selected requirements from NIST SP 800-172, February 2021. NIST has published newer revisions, and DoD has listed a future transition rulemaking, but those newer publications do not control CMMC unless and until the regulation is amended.
Is NeQter Labs a CMMC provider, a C3PAO, or software?
NeQter Labs is primarily a software and appliance vendor. It also advertises readiness support and partner introductions. It is not a C3PAO, and buying NeQter does not issue or guarantee a CMMC status. A tool can help you implement capabilities, organize evidence, and calculate a score. It cannot grant the status your contract requires.
That distinction matters more than it sounds, because a lot of CMMC marketing across this whole industry blurs it.
NeQter Labs, LLC publishes a Swansea, Massachusetts address, and its terms specify Rhode Island governing law. Its public team page listed ten named people when we checked. That is a public roster, not a verified employee count. We are not going to turn ten profile cards into a headcount claim or use that number to predict support capacity.
Keep the distinction in mind — the visible team is small, but the exact employee number is not published in a source strong enough to carry a buying conclusion.
The Cyber AB Marketplace question
A Cyber AB member profile page for NeQter Labs exists at cyberab.org/Member/APOSCF-66334-Neqter-Labs. We fetched it on August 28, 2026. The page is JavaScript-rendered and returned no role designation to our text request, so we are not going to tell you what role that listing represents. We do not know, and guessing at ecosystem status is exactly the kind of thing that gets repeated across the internet until it becomes fake fact.
If ecosystem status matters to your decision, check the Cyber AB Marketplace in a browser and save a dated screenshot. That is a five-minute task, and it is the only version of that answer worth having.
The three products
NeQter sells three products, and buyers routinely conflate them:
| Product | What it is | Who operates it | Public status |
|---|---|---|---|
| NeQter Core | The appliance: SIEM, vulnerability scanning, asset inventory, and compliance functions | Your IT staff or your MSP | Generally available |
| NeQter Comply | The GRC layer: System Security Plan (SSP), Plan of Action and Milestones (POA&M), evidence, task tracking, and scoring | Your compliance lead | Generally available |
| NeQter Central | Multi-tenant management console for MSPs and multi-site enterprises | Your MSP or corporate IT | Public page still invites early-access registration as of August 2026 |
One useful lineage detail from NeQter's own April 2026 client story: Comply is described as the SSP module, relaunched. It grew out of Core rather than arriving as a disconnected platform.
There is also a commercial inconsistency you should settle before the demo ends. NeQter's pricing page presents Comply as a separately priced product. Another current NeQter article says Comply is included with Core. The order form controls. Ask whether Comply is included in your Core quote, what edition you receive, how long inclusion lasts, and what happens at renewal.
One capability boundary worth knowing before you get on a demo: NeQter's user manual says the CMMC SSP framework offers Level 1 and Level 2. That means the documentation workflow is not a complete Level 3 management path today. NeQter Core could still serve as an in-scope logging or security asset in a Level 3 environment, but the product's published CMMC framework does not manage the full Level 3 requirement set.
NeQter Labs CMMC review: now the part where we admit what we can't tell you
We have not run this product. We have no login, no sandbox, no demo recording, and no customer of ours to interview. We cannot tell you whether the dashboards are fast, whether support picks up the phone, or whether the vulnerability scanner throws false positives at 2 a.m.
If you want a hands-on verdict, this isn't it, and anyone who claims to have one after reading the same public pages we did is selling you something.
Here's what we did instead, and why we think it is more useful.
NeQter publishes a control-by-control CMMC Compliance Guide on its documentation site. It is far more specific than the product-page claim because it identifies which practices and assessment objectives NeQter says it can assist, which it calls partial, and which it leaves to the contractor.
We read all of it and counted every line.
How many of the 110 CMMC Level 2 requirements does NeQter Labs cover?
NeQter's published CMMC Compliance Guide addresses 38 of the 110 Level 2 security requirements. Inside those 38 practices are 153 assessment objectives; the guide describes some NeQter assistance for 96 and states that NeQter does not define the policy or process for 57. Four practices are described as met with NeQter assistance, and all four are in Audit and Accountability.
CMMC Level 2 is built on the 110 requirements in NIST SP 800-171 Revision 2, organized into 14 families and assessed through the objectives in NIST SP 800-171A. Revision 3 is newer NIST guidance, but it is not the CMMC-controlling baseline as of this verification date.
Here is the family-level picture. This table did not exist anywhere before we built it.
The NeQter Coverage Ledger
Source: NeQter CMMC Compliance Guide, Version 2.1, November 2022, read and counted August 28, 2026. Requirement counts per family are from NIST SP 800-171 Revision 2.
| Control family | Level 2 requirements | Requirements addressed in NeQter's guide | Guide address rate |
|---|---|---|---|
| AU — Audit and Accountability | 9 | 9 | 100% |
| RA — Risk Assessment | 3 | 2 | 67% |
| IR — Incident Response | 3 | 2 | 67% |
| SI — System and Information Integrity | 7 | 4 | 57% |
| CA — Security Assessment | 4 | 2 | 50% |
| AC — Access Control | 22 | 10 | 45% |
| CM — Configuration Management | 9 | 4 | 44% |
| SC — System and Communications Protection | 16 | 3 | 19% |
| MP — Media Protection | 9 | 1 | 11% |
| IA — Identification and Authentication | 11 | 1 | 9% |
| AT — Awareness and Training | 3 | 0 | 0% |
| MA — Maintenance | 6 | 0 | 0% |
| PE — Physical Protection | 6 | 0 | 0% |
| PS — Personnel Security | 2 | 0 | 0% |
| Total | 110 | 38 | 35% |
Do not read 100% in the AU row as “the product satisfies the family.” It means the guide addresses all nine AU requirements. The guide still labels several AU practices partial and describes only four practices as met.
And the objective-level view, which is the level an assessor actually works at:
| Measure | Count |
|---|---|
| Assessment objectives inside the 38 documented practices | 153 |
| Objectives where the guide describes some NeQter assistance | 96 |
| Objectives where the guide says NeQter does not define the policy or process | 57 |
| Practices described as met with NeQter assistance | 4 |
| Which four | AU.L2-3.3.5, AU.L2-3.3.6, AU.L2-3.3.8, AU.L2-3.3.9 |
Read that last row again. Every practice the guide describes as met is an Audit and Accountability practice: correlating audit records, generating on-demand audit reports, protecting audit information from modification and deletion, and limiting who can manage audit logging.
That is the buying case, stated more clearly than NeQter states it itself. This is a logging and audit-evidence tool. Audit and Accountability is the only family the guide addresses end to end, and it is the only family where the guide describes any individual practices as met. If your gap is “we have no centralized logging and no way to prove we review it,” this product was built for you.
About the four zeroes
Awareness and Training, Maintenance, Physical Protection, and Personnel Security get no mention in the guide at all. That is not a knock. Those four families are dominated by people, process, and physical safeguards — security awareness records, maintenance controls, personnel screening, visitor control, and protected facilities. No SIEM can satisfy them by itself. Any vendor implying otherwise should worry you more than this silence does.
But it does mean 17 of your 110 requirements sit in families this guide does not touch, and you need a plan and a budget for them that has nothing to do with software.
One fairness point, and one caution
The fairness point: most software pages give you a coverage number and little evidence behind it. NeQter published an objective-by-objective document that repeatedly admits where the contractor still owns the policy or process. That is unusually specific, and those limitation statements are more useful than a glossy percentage.
The caution: the guide is stamped Version 2.1, November 2022. That predates the CMMC Final Rule, the DFARS implementation rule, and multiple documented product releases. The product has changed since then; the public control mapping may or may not have. Ask NeQter for the current version of the guide before you rely on the 38, 96, or 57 numbers in a purchasing decision.
See what 38 of 110 leaves behind
NeQter can be a real answer to a logging gap without being the answer to the whole program. Use the CMMC Readiness Checklist to mark the families you still own, then use the CMMC scoping guide to draw the boundary the appliance will protect.
Do not enter CUI, drawings, credentials, or a real network diagram into any public web form.
The two numbers on NeQter's website that don't mean the same thing
On the same NeQter product page, the body says “90+ Assessment Objectives,” while the FAQ says the product helps meet “90+ controls.” Those are not the same claim. CMMC Level 2 has 110 requirements and 320 assessment objectives. Ninety objectives are about 28% of the objective set; ninety requirements would imply about 82% of the requirement set.
Here is where each wording appeared when we checked on August 28, 2026:
| Page | Location | Published wording |
|---|---|---|
/cmmc-compliance-software/ | Body, under “Implement NeQter Core” | “90+ Assessment Objectives” |
/neqter-central/ | Core section | “90+ Assessment Objectives” |
/cmmc-compliance-software/ | FAQ block | “90+ controls” |
Two out of three say objectives. One says controls.
Our count supports the objective version: NeQter's compliance guide describes some assistance for 96 assessment objectives. Ninety-six is “90+.” The body copy aligns with the guide. The FAQ noun is the outlier.
Now — why does one word matter enough to build a section around?
Because the FAQ wording can be repeated without the context that separates requirements from assessment objectives. A buyer who anchors on “90+ of 110 controls” can budget as though only about 20 requirements remain. The vendor's own detailed guide leaves 72 requirements outside the mapping entirely, plus 57 objectives inside mapped requirements where NeQter says the policy or process still belongs elsewhere.
That is not a small budgeting error. It is the difference between buying a tool for a defined gap and assuming the tool erased most of the program.
Here's the pivot, and we mean it: the correct number still describes a genuinely useful product. An appliance whose guide addresses all nine Audit and Accountability requirements, describes four AU practices as met, and assists pieces of seven other families for $325 a month can be a legitimate answer for a small shop that today has zero log retention and no way to prove anything. The tool is not the problem. The noun is. Fix your budget, then decide on the tool.
How much does NeQter Labs cost?
NeQter Core's visible published pricing runs from $325 per month for up to 10 devices to $1,575 per month for 750 or more devices on a three-year term. The same visible tiers on a one-year term run $390 to $1,890 — exactly 20% more at every tier. NeQter Comply is shown at $150 per month billed annually or $250 per month billed monthly, with a one-month free trial. Hardware is quoted separately and is not published.
Publishing real prices at all is unusual in this market. So let's do the arithmetic the page does not do for you.
NeQter Core: the full visible price table
Source: NeQter pricing, verified August 28, 2026. The table below uses the two visible term labels — Three Year and One Year. The order form controls.
| Tier | Devices | 3-year term, monthly | 1-year term, monthly | Annual cost, 3-year term | Total 3-year commitment | Cost per device/month at tier ceiling |
|---|---|---|---|---|---|---|
| Nano | Up to 10 | $325 | $390 | $3,900 | $11,700 | $32.50 |
| Micro | Up to 35 | $475 | $570 | $5,700 | $17,100 | $13.57 |
| Small | Up to 100 | $625 | $750 | $7,500 | $22,500 | $6.25 |
| Medium | Up to 350 | $975 | $1,170 | $11,700 | $35,100 | $2.79 |
| Large | Up to 750 | $1,325 | $1,590 | $15,900 | $47,700 | $1.77 |
| Enterprise | 750+ | $1,575 | $1,890 | $18,900 | $56,700 | $2.10 or less |
NeQter Comply: $150 per month billed annually ($1,800 per year), or $250 per month billed monthly ($3,000 per year). The page states a one-month free trial.
Three things this table tells you that the pricing page doesn't
1. The one-year term costs exactly 20% more. Every visible tier. No exceptions.
Not approximately. Every one-year price is precisely 1.2× the three-year price: $325 → $390, $475 → $570, $625 → $750, $975 → $1,170, $1,325 → $1,590, $1,575 → $1,890.
Flip it around and the three-year term is 16.7% less than paying the one-year rate for the same period. On the Nano tier, the difference is $780 a year. That is the price of avoiding a 36-month commitment while NeQter Central is still presented as early access and a major 3.0 release is in preparation. It is not an obviously bad trade. It is a trade you should make on purpose.
2. The smallest buyers pay roughly 18 times more per device than a 750-device buyer.
A ten-device shop pays $32.50 per device per month. A 750-device firm on the Large tier pays about $1.77. Same software.
This is not a scandal — tiered pricing often puts more fixed cost on the smallest deployment. But it reframes “affordable” honestly. NeQter is affordable in absolute dollars for a small shop. It is expensive per device for a small shop. If you are at eight devices and growing toward 40, the economics improve dramatically as you go.
3. The device-band cliff: one device can raise the visible monthly price by 56%.
| Crossing this line | Monthly price change | Increase |
|---|---|---|
| 10 → 11 devices | $325 → $475 | 46% |
| 35 → 36 devices | $475 → $625 | 32% |
| 100 → 101 devices | $625 → $975 | 56% |
| 350 → 351 devices | $975 → $1,325 | 36% |
| 750 → 751 devices | $1,325 → $1,575 | 19% |
Before you quote yourself a tier, ask NeQter what counts as a billable device. Is it an installed agent, a log source, a monitored endpoint, a network device, or something else? Then reconcile that commercial count to your CMMC asset inventory. They are related questions, but they are not automatically the same definition.
One inconsistency worth flagging: a NeQter article published in February 2026 says the platform starts “at just $300 per month.” No visible Core tier on the pricing page matches $300. The $250 figure that circulates is the Comply monthly rate, not Core. Get the complete quote in writing.
The costs that aren't on the pricing page
The subscription is not the cost of ownership. NeQter's documentation specifies substantial virtual-machine resources for the appliance, hardware is quoted separately, and NeQter's own customer story describes about an hour a day of ongoing compliance work after certification. For a small contractor, the labor line can be larger than the software line.
The VM requirement nobody expects
NeQter's user manual publishes virtual-machine specifications by storage tier — and an unusual warning attached to them.
Source: NeQter system specifications, verified August 28, 2026.
| Resource | 500 GB tier | 1 TB tier | 2 TB tier | 4 TB tier | 8 TB tier |
|---|---|---|---|---|---|
| CPU | 6–8 cores | 6–8 cores | 6–8 cores | 8–12 cores | 8–12 cores |
| RAM | 32 GB | 64 GB | 64 GB | 128 GB | 128 GB |
| Storage | 500 GB SSD | 1 TB SSD | 2 TB SSD | 4 TB SSD | 8 TB SSD |
NeQter's documentation warns that allocating less or more than the listed specification can cause data corruption, boot failure, or other problems.
The “or more” is the part that catches people. Do not assume generous over-provisioning is harmless. Use NeQter's current sizing instructions for the build you are buying and have the vendor confirm the allocation in writing.
Practically, the entry tier needs a host that can dedicate 6 to 8 cores, 32 GB of RAM, and a 500 GB SSD to one appliance. That is real infrastructure, and it is not included in the $325 subscription. If you do not have spare capacity, you are buying a server or buying NeQter's hardware — and the public documentation directs hardware questions to sales, which means there is no published hardware price to plan against.
The labor line, from NeQter's own customer
This is the most useful number on this page for anyone modeling total cost, and it comes from NeQter's own published case study.
In an April 2026 client story, NeQter describes Trevor Peters at OKSI, formerly Opto-Knowledge, who joined through a DoD SkillBridge internship after service as a U.S. Army Military Police Officer and led the company to CMMC Level 2 certification in 16 months. NeQter reports that post-certification compliance is about an hour a day for Peters, with a small team supporting ongoing maintenance.
Take that for what it is: a vendor-published, named client example, not an independently measured benchmark. It is still more useful than pretending the software runs the program by itself.
An hour a workday is roughly 250 hours a year. At an illustrative fully loaded internal rate of $50 an hour, that is about $12,500 annually. Against a $3,900 Nano subscription, the labor is more than three times the software.
That ratio is not a criticism of NeQter. It is the shape of compliance work everywhere, and it is a line small contractors routinely leave out of the business case. The right conclusion is not “do not buy the tool.” It is “the tool is the cheap part — make sure you staffed the expensive part.”
We'll say plainly what the case study implies: if nobody in your company has time to run this, buying software will not fix your CMMC problem. It will give you a well-instrumented record of not doing the work. If that is you, the honest next step is a managed compliance provider, not a subscription.
Price the whole program, not just the subscription
Software is one line of a Level 2 budget. Policy work, training, physical controls, personnel screening, implementation, assessment preparation, and the labor to run all of it are the other lines — and they are the ones that blow up.
See the complete CMMC Level 2 cost model →
Not sure whether you need software, an operator, or an assessor? Find My CMMC Path maps your level, CUI scope, assessment type, and timeline to the right provider category. Do not submit CUI or contract details.
Does NeQter Labs expand your CMMC assessment scope?
NeQter Core expands your asset inventory because a logging and security appliance protecting a CUI environment is a Security Protection Asset. Whether NeQter Labs also becomes an external service provider is a separate question. That answer turns on what NeQter-delivered services or personnel process, store, or transmit — not merely on where the appliance sits.
This is the most consequential correction on the page.
An on-premises design can keep raw logs and evidence in your environment and can simplify the external-service-provider analysis. But “on prem” is not a magic sentence that removes the vendor from scope. Remote support, hosted Comply, NeQter Central, cloud hosting, update telemetry, and any other service that can reach CUI or Security Protection Data still need to be mapped.
The deployment matrix
The matrix below applies the asset and external-service-provider categories in 32 CFR 170.19 to NeQter's published deployment options.
| Deployment | Core's asset category | External service provider question | What the contractor should document |
|---|---|---|---|
| NeQter hardware appliance on your network, administered only by your staff | In-scope Security Protection Asset | NeQter is not an ESP for the appliance alone if no NeQter service or person processes CUI or Security Protection Data | Asset inventory, SSP entry, network diagram, relevant Level 2 requirements, update/licensing data flows |
| Virtual appliance in your own VM environment | Same | Same data-path test; the hypervisor/hosting operator may add another service provider | Same, plus VM owner, host boundary, backup path, and administrator roles |
| Appliance hosted in your own cloud tenant | Security Protection Asset in a cloud environment | The cloud provider is an ESP; whether it is also a CSP processing CUI decides the FedRAMP question. NeQter's own status still depends on its access and data flows | Cloud service description, CRM, CUI/SPD determination, FedRAMP evidence if the CSP processes CUI |
| Disconnected enclave with offline updates | Security Protection Asset | Strongest case for keeping NeQter-delivered services outside ESP scope, if no CUI or Security Protection Data leaves and no remote support path is used | Offline update procedure, media handling, support exception process, version evidence |
| Comply running locally in your environment | Security Protection Asset or capability of Core | No separate NeQter ESP relationship solely from local operation if the vendor cannot process CUI or Security Protection Data | Data location, administrator roles, backup/export path, relevant security requirements |
| Comply hosted by NeQter | Core remains an SPA; the hosted GRC service is a separate external service | Potentially an ESP if hosted artifacts, configuration data, or telemetry include Security Protection Data or CUI; CSP requirements apply if the cloud service processes CUI | SSP service description, CRM, data-location answer, CUI/SPD determination, FedRAMP evidence if CUI is processed by a CSP |
| NeQter Central | Core remains an SPA; Central adds a cross-tenant service | NeQter says raw logs stay local, but displayed alerts, health data, configuration, or metadata may still be Security Protection Data | What leaves the appliance, who can see it, tenant isolation, support access, CRM if SPD or CUI is processed |
The rule creates three questions that end most of the confusion:
- Does an external provider process, store, or transmit CUI? If yes, determine whether it is a cloud service provider or another ESP and apply the corresponding assessment and contract requirements.
- If no CUI leaves, does the provider process Security Protection Data? If yes, the ESP service is assessed as a Security Protection Asset. Your SSP needs the provider, service description, and Customer Responsibility Matrix.
- If the provider processes neither CUI nor Security Protection Data, is it an ESP for CMMC? No. The appliance can still be your in-scope SPA, but the vendor service is outside the CMMC ESP definition for that data path.
The 60-second version: a box on your rack can be a genuine architectural advantage because it lets you keep security data local. But you earn the “no ESP” answer by proving the external party processes neither CUI nor Security Protection Data. You do not earn it by pointing at the rack.
But there's a door in the wall, and it's documented
NeQter's FAQ publishes the appliance's port requirements. Buried in the table is the answer to a question many product pages leave vague: can NeQter personnel access the appliance?
The documentation says inbound port 22, SSH, only needs to be open when a support remote session requires backend access and can otherwise remain closed.
Read that plainly. NeQter support can obtain backend access when you open the port for a support session. That is normal appliance support, and NeQter deserves credit for documenting it instead of hiding it.
It is also a service path you must classify. If support personnel can view or manipulate Security Protection Data or CUI during the session, that support service can enter the ESP analysis even though the appliance is on premises. Your record should show that the port stays closed by default, access is requested and approved, the session is supervised where appropriate, activity is logged, and the vendor's data access is understood.
Two outbound paths are also documented — updates.neqterlabs.com for licensing and updates and feed.neqterlabs.com for vulnerability-scanner feeds. Record what leaves through each path. An offline deployment should document exactly how those functions are replaced.
Two more things in that port table worth your attention
Plaintext syslog is still on the list. The documentation lists inbound port 514 for syslog and 6514 for secure syslog. Do not default to 514 because it is easy. If logs can expose CUI or Security Protection Data, use secure syslog where the source supports it or document the segmentation, compensating protection, and accepted limitation for any legacy plaintext path.
And this one deserves a hard stop. NeQter's FAQ addresses remote workers who do not connect to the company VPN and describes port-forwarding ports 5000, 5001, and 5045 from a public address to the appliance. NeQter itself recommends VPN and warns that port forwarding exposes appliance ports to the internet.
Take their advice. Directly exposing the web and agent interfaces of an in-scope Security Protection Asset creates a public attack surface you will have to defend and explain. Use a controlled remote-access path instead.
Map the data path before the demo
Start with the CMMC scoping guide, then use the external service provider assessment guide to classify support, cloud hosting, Comply, and Central.
Your SSP should name the appliance, its asset category, its administrators, every external data path, and the provider responsibilities that remain outside the box.
Which NeQter version do you need? The CMMC feature timeline
NeQter's public change log shows that several capabilities contractors buy this product for arrived at specific, datable versions — GCC High authentication support in March 2021, CMMC 2.0 frameworks in April 2022, secure syslog on port 6514 in August 2024, SPRS-style scoring for CMMC Level 2 SSPs in February 2025, and native password-policy controls in December 2025. If you are evaluating a quote, inheriting an existing deployment, or buying used hardware, the version number is a compliance fact, not an IT detail.
We read the full public NeQter change log back to Q1 2019 and pulled the entries that change a CMMC answer. Nobody had assembled this timeline before this page.
| Version | Released | What arrived, and why it matters for CMMC |
|---|---|---|
| 2.10.0 / 2.10.1 | March 2021 | GCC High and Government-domain authentication for Office 365 subscriptions. If you are a Microsoft 365 GCC High shop, this is the published floor for that authentication support. |
| 2.13.1 | April 2022 | NIST SP 800-171 with assessment objectives and CMMC 2.0 frameworks added to the compliance tool. |
| 2.14.0 / 2.14.1 | June 2022 | SSP framework conversion, SPRS-style scoring on the NIST SP 800-171-with-objectives framework, and a “Needs Review” flag on converted controls. |
| 2.15.5 | June 2023 | Offline update installation through update files — the mechanism behind the disconnected-enclave option. |
| 2.17.0 | December 2023 | Multi-factor authentication introduced through an email passcode for all user types. |
| 2.19.0 | June 2024 | PreVeil log collection and dashboard. |
| 2.19.1–2.19.3 | August 2024 | Secure syslog ingestion on port 6514. |
| 2.20.0 | October 2024 | SentinelOne integration. CrowdStrike support appeared in the August 2024 release group. |
| 2.20.1 → 2.21.0 | February 2025 | SPRS-style scoring added to CMMC v2.0 Level 2 SSPs. Before this, the score lived on NIST-framework SSPs. |
| 2.23.0 | July 2025 | Fix for a TLS vulnerability that the change log says was introduced when secure syslog ingestion was enabled. |
| 2.24.0 | December 2025 | Password-reuse, expiration, and minimum-complexity settings; temporary passwords; forced change on first login. |
| 2.25.0 / 2.25.1 | February 2026 | Events and alerts for failed and successful logins to NeQter itself; Microsoft Graph API email support. |
| 2.26.0 | August 2026 | Current public release when checked: vulnerability-tool refresh plus preparation guidance and a confirmation step for the coming NeQter 3.0.0 update. |
Four things this timeline tells a buyer
Version 2.24.0 changed the appliance's native password-control story. NIST SP 800-171 Revision 2 requires minimum password complexity at 3.5.7, prohibits reuse for a defined number of generations at 3.5.8, and requires an immediate change from a temporary password at 3.5.9. It does not contain a standalone password-expiration requirement. Version 2.24 added native settings for all of those product functions, including an expiration option.
That does not mean every pre-2.24 appliance automatically fails CMMC. Security Protection Assets are assessed against requirements relevant to the capabilities they provide, and an organization may use external identity controls or inherited enforcement. It does mean an older build lacks the appliance-native settings and evidence now available in 2.24.0. That is a version-gated question precise enough to check in five seconds.
The published multifactor method is email passcode. Email-delivered codes are not phishing-resistant and depend on the security of the mailbox and the independence of the authentication path. Ask what MFA options exist in the current release, whether privileged accounts are forced to use them, and what is planned for 3.0. This is a fair question, not an accusation — plenty of appliances started here.
NeQter disclosed a TLS vulnerability in its own change log. Secure syslog arrived in August 2024. The July 2025 notes say a TLS vulnerability introduced when secure syslog was enabled was resolved. That is roughly an eleven-month interval between the feature release and the documented fix. We would rather see a public fix note than a silent patch, and we will say so — but if you are on an older build, update it and record the version in change-management evidence.
Version 3.0 is coming, and the current release exists partly to prepare for it. That is real, dated, and worth negotiating around. Before you sign a 36-month term, ask what 3.0 changes for hardware requirements, migration, downtime, integrations, support, and contracted price. Get the answer in the order form, not the demo.
One thing the timeline says in NeQter's favor, and it is not nothing: the public change log shows releases every year since 2019, with a steady cadence through August 2026. For a visibly small vendor, years of public release notes are genuine evidence of a maintained product. A lot of small vendors go quiet. This one has not.
What it's actually like to run
NeQter's own documentation discloses several operational realities that shape what the product can and cannot do for an assessment: Microsoft 365 log retrieval is periodic rather than real-time, the appliance ships with documented default credentials that must be changed, and the POA&M output is a filtered export rather than a magical “build it for me” button. None of these is disqualifying. All of them should change what you expect.
Log collection is not real-time, and NeQter says so
NeQter's FAQ says Office 365 event logs are retrieved by periodically querying Microsoft APIs rather than in real time, with lag ranging from several minutes to multiple days. Newly created subscriptions may take up to 12 hours to begin populating. Google Workspace audit logs are also retrieved periodically, with lag that varies by report type.
This is honest, and much of the delay comes from the upstream platforms. It has two practical consequences you should write down now:
- Do not build an incident response plan that assumes every cloud event reaches NeQter in minutes. If your plan promises near-real-time detection while the documented source can arrive days later, the plan and the system do not match.
- The DFARS 252.204-7012 reporting clock starts when the contractor discovers a reportable cyber incident. API lag can delay discovery and response, but it does not retroactively consume the 72-hour window before discovery. Once the incident is discovered, the contractor must rapidly report it within 72 hours. Record how discovery time is established, who reviews delayed events, and who owns the report.
There is also a data-handling asymmetry worth putting on your vendor list. NeQter's FAQ expressly says its service cannot view the Google Workspace logs retrieved by the appliance. The Office 365 answer describes local credential storage and revocation but does not make the same no-view statement. That may be nothing. Ask anyway.
Change the default credentials on day one
NeQter's public FAQ documents the appliance's administrative recovery procedure and, in doing so, identifies default credentials for both the web interface and the console terminal. We are not reproducing them here.
Every appliance needs a recovery path. But this appliance is an in-scope Security Protection Asset holding security event data, and leaving default credentials in place is the kind of preventable finding that ends a good assessment day badly.
Do this in your first hour:
- Change the web-interface administrator credentials.
- Change the console-terminal credentials — they are separate, and changing one does not change the other.
- NeQter says the self-service administrator-restore path only works if the console password has not been changed. Once you harden it properly, document an alternate recovery path: where the credential is held, who can retrieve it, and how you recover the appliance without the default process.
- Record the change as evidence.
- On 2.24.0 or later, configure minimum complexity, reuse limits, temporary-password change, and any organization-defined expiration setting. Use expiration because your policy or risk decision calls for it, not because Revision 2 contains a standalone expiration requirement.
That is a few minutes of work and may be the highest-value few minutes in the deployment.
The POA&M is a filtered export, not a button
NeQter's marketing says you can build a POA&M. The user manual describes a more precise workflow: export to PDF, filter controls for Partially Implemented, Planned, and Not Implemented, filter tasks for To Do and In Progress, and exclude controls without tasks.
That is the second time on this page that the engineering documentation is more precise than the marketing. The capability is real. The shortcut implied by the noun is oversold.
Here is the useful part, and consider it a gift: that recipe is your POA&M export procedure. Put it into the compliance runbook so the person doing this next quarter does not have to rediscover it.
The SPRS score has a version gate and a framework gate
NeQter's user manual says an SSP using the NIST SP 800-171 framework displays an SPRS-style score. The change log says scoring was added to CMMC v2.0 Level 2 SSPs in the February 2025 release.
The manual and change log are describing different eras of the product, and both remain public. The practical answer: on 2.20.1/2.21.0 or later, a CMMC-framework SSP should have the score feature. On an older build, a CMMC-framework SSP may not.
Do not blur the product's calculation with the government's record:
- Under DFARS 252.204-7019, the offeror needs a current NIST SP 800-171 DoD Assessment in SPRS when the clause applies.
- DFARS 252.204-7020 governs assessment access, current-result obligations, and flowdown.
- DFARS 252.204-7021 governs the required CMMC status and annual affirmation when that clause applies.
NeQter can calculate from the implementation statuses you enter. It does not make the government posting, validate the underlying evidence, perform the affirmation, or assume liability for the answer. You remain responsible for what is entered, what is posted, and what is affirmed. For the operational distinction between a local score, a NIST assessment result, and the government record, use our SPRS score guide.
The framework conversion tool tells on itself, appropriately
If you are migrating an existing SSP between frameworks, NeQter's manual carries a disclaimer worth reading before you rely on it: responses and implementation statuses are assigned using a best-fit approach, all converted controls require review, and artifacts are not imported and must be manually reinserted.
Credit where it is due — the tool flags converted controls with a Needs Review status so you can track what has been checked. That is thoughtful design. Just do not budget the migration as an afternoon.
Who should buy NeQter Labs — and who should not
NeQter fits a specific contractor profile: small, CUI-handling, no centralized logging today, cost-constrained, and with at least one person who can give the appliance real time every week. It does not fit anyone expecting a single product to reach 110 requirements, anyone expecting turnkey 24/7 human monitoring, or anyone without an operator.
These are our editorial conclusions, drawn from the verified facts above. They are not a CMMC status, a guaranteed outcome, or a vendor endorsement.
| Your situation | Our read |
|---|---|
| 10–35 devices, no SIEM, no log retention, CUI in scope | Strongest case on this list. You are buying a product whose guide addresses every Audit and Accountability requirement at the price point where the alternative may be no centralized evidence at all. Confirm what counts as a licensed device. |
| 100–350 devices with an MSP already in place | Workable, but settle ownership first. Who buys the license, administers Core, accesses Central, reviews alerts, and holds the credentials? Put it in the MSP agreement, not only the SSP. |
| Microsoft 365 GCC High shop | GCC High authentication has been supported since March 2021. Confirm the exact log sources covered in your tenant and set detection expectations around documented retrieval lag. |
| Air-gapped or disconnected enclave | This is NeQter's most distinctive architecture. Offline updates have existed since June 2023, and the case for keeping vendor services outside ESP scope is cleanest when no CUI or Security Protection Data leaves. Document the update and support exceptions. |
| FCI only, Level 1 | You probably do not need this product to satisfy Level 1. Level 1 uses 15 safeguarding requirements derived from FAR 52.204-21 and requires annual self-assessment and affirmation. Start with the readiness checklist, not a SIEM purchase. |
| Pursuing Level 3 | Core may still be useful as a Security Protection Asset, but the published SSP builder offers Level 1 and Level 2, not a complete Level 3 workflow. Level 3 applies 24 selected requirements from the February 2021 NIST SP 800-172 publication and is assessed by DIBCAC when required. |
| No internal IT and no MSP | Do not buy software first. You will own an appliance nobody operates. You need a managed compliance or security provider. Compare provider categories → |
| You already have Microsoft Sentinel, Wazuh, or an MSSP SIEM | You may need the documentation layer more than another logging stack. Ask for a Comply-only quote and settle the public bundling conflict in the order form. |
| You want turnkey 24/7 human monitoring | We found no published evidence that around-the-clock analyst monitoring is included in the base subscription. If a human watching and escalating alerts is the requirement, that is a managed-service purchase. |
| You need certification, not readiness | No software issues a CMMC status. You need an authorized or accredited C3PAO for a Level 2 certification assessment. Keep conflict screening exact: under 32 CFR 170.11(a)(2)(iii)(A), an assessor who served as a consultant preparing the same organization for a CMMC assessment within the prior three years cannot participate in that assessment. |
We would rather lose the wrong reader here than have them spend $11,700 discovering this in month four.
NeQter Labs alternatives, and what the comparison pages get wrong
The useful comparison is not “which CMMC product is best.” It is which operating model you are buying: a self-run appliance, a cloud SIEM you configure, a managed service with humans watching, a documentation-only GRC platform, or a bounded CUI enclave. NeQter spans the first and fourth of those.
A lot of automated “alternatives” pages mix unrelated software categories because they are matching tags, not solving the contractor's problem. That is how an employee-engagement platform or consumer automation tool ends up next to a CMMC appliance.
If you have been comparison-shopping and felt like the internet had nothing useful on this vendor, that is because most pages compare logos instead of responsibility.
Here is the comparison that actually helps:
| What you are really choosing | Self-run appliance: NeQter Core | Cloud SIEM you configure | Managed detection and response | GRC platform only | CUI enclave |
|---|---|---|---|---|---|
| Who watches alerts | You or your MSP | You or your MSP | The provider | Nobody — not its job | Depends on service |
| Where log data lives | Primarily your hardware and network | Provider cloud | Provider cloud | Usually no full log store | Inside enclave |
| ESP analysis | Depends on support, hosting, Central, and data paths; appliance alone can remain local | Yes if provider processes Security Protection Data or CUI | Yes | Depends on hosting and data | Yes for the enclave provider |
| SSP and POA&M workflow | Available through Comply; quote controls bundling | Usually separate | Varies | Core function | Varies |
| Ongoing labor on you | High — plan for it | High unless managed | Lower operational burden, not zero governance | Moderate | Moderate |
| Cost shape | Device tier + hardware/VM + your labor | Ingest volume + licenses + labor | Recurring service fee | Organization or user subscription | User/license fee + migration |
| Best when | You want security data local and have an operator | You have cloud expertise and can tune it | Nobody internally can monitor | Your security stack already works | You can isolate CUI into a small boundary |
We are deliberately not putting competitor price checkmarks in that table. Every one of those prices and feature claims needs its own current verification pass. A half-verified comparison is worse than none.
What we could not verify about NeQter Labs
Several facts a buyer needs are not published anywhere we could find. That is not automatically a mark against the vendor. It does mean you ask in writing before you sign a 36-month term.
Here is our honest ledger as of August 28, 2026:
| What we could not confirm | Why it matters |
|---|---|
| SOC 2, ISO 27001, or FedRAMP status | No listing or certificate surfaced in the public sources we checked. It matters most if a NeQter-hosted component processes your data. |
| Whether every Comply deployment is local, hosted, or buyer-selectable | The answer determines data location and whether NeQter enters the ESP/CSP analysis. |
| The precise Central data model | NeQter says raw logs stay local, but a buyer still needs the fields, metadata, alerts, and administrator capabilities that leave the appliance. |
| FIPS 140 validated cryptographic modules | Ask for module and certificate numbers, FIPS 140-2 vs 140-3, and the post-September 21, 2026 status or applicable federal-use guidance. |
| Support SLA, response targets, and included hours | This is operating risk, not a nice-to-have. |
| Current log-retention defaults and maximums | The 2022 guide references at least 90 days of raw-log storage by default, but current limits and storage-tier behavior need confirmation. |
| Backup destination and disaster-recovery model | Your SSP, evidence, and security logs may live here. |
| Whether support personnel who can access customer systems are U.S. persons | A common DIB contractual and data-handling question; no public answer found. |
| Hardware pricing | Public documentation sends hardware questions to sales. |
| NeQter Central pricing and tenant-isolation evidence | The public page still presents early access and does not publish a complete commercial/security model. |
| A current CMMC Compliance Guide | The public guide is Version 2.1, November 2022. |
| The Cyber AB Marketplace role attached to the member profile | The profile exists, but its role did not render in our text request. |
| Whether Comply is included in a specific Core quote | Current NeQter pages conflict. The order form must answer it. |
The 15 questions to send before you sign
Copy this. Send it to your rep. Keep the reply with your vendor due-diligence file and SSP support records. A dated written answer is evidence. A demo conversation is not.
Scope and architecture
- In our proposed deployment, which NeQter-delivered services or personnel can process, store, or transmit CUI or Security Protection Data? For each one that qualifies as an ESP, will you provide a Customer Responsibility Matrix?
- Does NeQter Comply run locally, in our tenant, or in infrastructure controlled by NeQter? Where does its data reside?
- Under what circumstances does NeQter support access the backend through SSH? How is access requested, approved, supervised, logged, and terminated on both sides?
- Confirm every inbound and outbound network path for our deployment, including licensing, updates, vulnerability feeds, Central, support, and the offline-update path.
- Are support and engineering personnel who could access customer systems U.S. persons? If not, what restrictions and contractual controls apply?
Security posture of the appliance
- Which cryptographic modules does the appliance use? Provide each FIPS 140 validation certificate number, module version, and operational environment.
- What MFA options are available now beyond email passcode? Which accounts are forced to use MFA, and what is on the 3.0 roadmap?
- Provide the current hardening guide, including all default accounts, credential changes, recovery, service accounts, secure syslog, and recommended network exposure.
- Do you hold SOC 2 Type 2, ISO 27001, or another independent security attestation? May we review it under NDA?
Data and evidence
- What are the default and maximum raw-log, archive, and evidence-retention periods at our storage tier?
- Where do backups go by default, who can access them, and how do we export all SSP content, artifacts, configuration, and logs if we terminate?
- Provide the current control-by-control CMMC Compliance Guide and identify what changed from Version 2.1.
Commercial and lifecycle
- Give us the complete first-year and three-year cost, including software tier, device-count definition, hardware or VM infrastructure, storage, implementation, training, support, and any monitoring.
- What does NeQter 3.0.0 change for hardware, migration, downtime, integrations, support, and our contracted price? Is the upgrade included?
- Is NeQter Comply included in this quote or billed separately? Put the answer in the order form, including renewal treatment.
Take the questions with you
We built that list from the exact gaps we hit in NeQter's public documentation. Every question exists because a contractor needs the answer before committing.
Already know your required level and timeline? Request source-checked CMMC provider options →
We may receive compensation for qualified introductions. The routing form is not a secure channel. Do not submit CUI, drawings, credentials, network diagrams, or sensitive contract details.
The current CMMC and DFARS rule stack NeQter buyers need to understand
NeQter does not replace any of the four DFARS clauses that commonly shape the contractor's cybersecurity obligations. The clauses do different jobs, and collapsing them into “CMMC” is how contractors miss a current SPRS assessment, an incident-reporting duty, a flowdown, or an annual affirmation.
Here is the clean version as of August 28, 2026.
| Authority | What it does | What NeQter can help with | What NeQter cannot do for you |
|---|---|---|---|
| DFARS 252.204-7012 | Requires adequate security for covered contractor information systems, rapid cyber-incident reporting within 72 hours of discovery, preservation of images/data, and other cooperation when the clause applies | Centralize records, preserve event evidence, support investigation and response workflows | Decide reportability, make the report, preserve every required artifact automatically, or assume the contractor's legal duty |
| DFARS 252.204-7019 | Pre-award notice requiring a current NIST SP 800-171 DoD Assessment in SPRS when applicable | Calculate an internal score from entered statuses | Validate the implementation or post the assessment result for you |
| DFARS 252.204-7020 | Requires access for DoD assessments, governs current assessment results and subcontractor checks, and contains flowdown obligations | Organize evidence and records that support an assessment | Satisfy access, currency, or flowdown obligations by itself |
| DFARS 252.204-7021 | Requires the CMMC status specified in the solicitation or contract and an annual affirmation of continued compliance when the clause applies | Support readiness, evidence, and ongoing control operation | Issue the status, perform an authorized assessment, submit the affirmation, or guarantee award eligibility |
The applicable contract language controls. A contractor can have a current NIST assessment obligation before it has a CMMC certification requirement on a particular procurement. It can also carry incident-reporting and safeguarding obligations regardless of what a product dashboard calls the program.
That is why your first question is not “Which tool should we buy?” It is “Which clauses, CMMC status, assessment type, and date actually apply to this opportunity?” Use the CMMC Levels guide and the 32 CFR Part 170 guide before you turn a product feature into a contractual conclusion.
What SPRS posting means in this context
A NeQter score is not an SPRS record.
For the legacy NIST SP 800-171 DoD Assessment process under DFARS 252.204-7019 and -7020, an authorized government assessment result or a Basic Assessment submitted through the prescribed process must be current in SPRS when required. For CMMC under -7021 and 32 CFR Part 170, the required CMMC status and affirmation are recorded through the CMMC ecosystem and SPRS workflow established by DoD.
The contractor is responsible for the truth of the underlying implementation and the annual affirmation. A calculator can show arithmetic. It cannot turn unsupported statuses into a defensible government record.
What CMMC phase is in effect now?
Phase 1 began November 10, 2025. Its original first-year window runs through November 9, 2026. On July 13, 2026, the Department suspended the planned Phase 2 expansion and later milestones while a task force conducts a 60-day review. Phase 1 remains in effect.
The distinction matters because “CMMC was paused” is false and “Phase 2 is proceeding normally on November 10, 2026” is also no longer a safe planning assumption.
The original 32 CFR Part 170 implementation plan established four phases:
| Original phase | Original timing | Original scope |
|---|---|---|
| Phase 1 | November 10, 2025–November 9, 2026 | DoD begins including Level 1 and Level 2 self-assessment requirements in applicable solicitations and contracts, with discretionary inclusion of Level 2 certification |
| Phase 2 | Originally November 10, 2026–November 9, 2027 | Broader inclusion of Level 2 certification requirements, with discretionary Level 3 |
| Phase 3 | Originally November 10, 2027–November 9, 2028 | Broader Level 3 inclusion and remaining rollout |
| Phase 4 | Originally beginning November 10, 2028 | Full implementation |
On July 13, 2026, the Department announced an immediate suspension of Phase II and pending/future milestones, while leaving Phase I in effect. The task force was directed to report within 60 days, which places the review deadline around September 11, 2026. As of this page's August 28 verification date, that deadline had not arrived.
What should a contractor do with that?
- Do not assume an existing or new Phase 1 clause disappeared.
- Read the actual solicitation and contract.
- Do not build a November 2026 certification schedule on the original Phase 2 date without checking the Department's next action.
- Do not stop implementing NIST SP 800-171 Revision 2. The safeguarding and assessment clauses remain real, and Phase 1 remains in force.
- Treat a product purchase as one workstream, not a substitute for the contract and scoping decision.
We will update this page when the Department publishes the task-force result or changes the rollout.
Does CMMC use NIST SP 800-171 Revision 2 or Revision 3?
Revision 2 controls CMMC today. Revision 3 does not become the CMMC baseline merely because NIST published it. DoD must amend the CMMC rule or otherwise change the governing requirements through the applicable rulemaking and contract process.
The current eCFR incorporates:
- NIST SP 800-171 Revision 2, February 2020 for Level 2.
- NIST SP 800-171A, June 2018 for Level 2 assessment procedures.
- The selected requirements from NIST SP 800-172, February 2021 for Level 3.
NIST published SP 800-171 Revision 3 in May 2024 and has since updated related assessment publications. DoD's regulatory agenda identifies a future rulemaking to transition the CMMC program to Revision 3, with a projected notice of proposed rulemaking in December 2026. A projected rulemaking date is not an effective date, and a proposed rule is not a final rule.
So when a vendor says “we support Revision 3,” that can be useful for future-proofing. It cannot replace evidence against the current Revision 2 baseline on an assessment controlled by today's rule.
This matters here because NeQter's public 38-requirement guide is mapped to the current Revision 2 structure. Its age is a product-documentation problem, but the revision number itself is still the correct controlling baseline.
A practical NeQter deployment sequence
The clean implementation order is scope first, contract and data path second, hardening third, evidence fourth. Installing the appliance before those decisions creates rework and can produce a beautifully documented wrong boundary.
Use this sequence:
1. Confirm the requirement before buying
Pull the solicitation, contract, and flowdowns. Identify the required CMMC level, assessment type, date, and applicable DFARS clauses. Do not infer the answer from the type of work your company usually performs.
2. Draw the CUI and Security Protection Data paths
Show where CUI enters, where it is stored, who can access it, and which assets protect it. Add NeQter Core, Comply, Central, support access, cloud hosting, backups, and update paths. Classify each asset under 32 CFR 170.19.
3. Decide the operating model
Name the person or provider who will:
- administer the appliance;
- review alerts and logs;
- maintain integrations;
- respond to failures;
- update the SSP and POA&M;
- collect evidence;
- preserve incident records; and
- approve vendor support sessions.
A role written as “IT” is not a decision. Put a name, a company, or a contracted function beside each task.
4. Put the commercial definitions in the order form
Get the device-count definition, Comply inclusion, term, renewal, hardware, storage, implementation, support, 3.0 migration, export rights, and termination assistance in writing.
5. Harden before ingesting production data
Change every default credential, configure MFA, restrict support access, close unneeded ports, use secure syslog where supported, patch to the approved current release, and document the baseline. Build the recovery procedure after you invalidate the default recovery path.
6. Map the 38 addressed requirements without pretending they are 38 completed requirements
For every mapped practice, record:
- the NeQter capability;
- the policy or procedure the organization still owns;
- the responsible role;
- the evidence source;
- inherited or shared responsibilities;
- the relevant configuration;
- the test procedure; and
- the remaining gap.
Use NIST SP 800-171A, not marketing copy, to determine what an assessor will examine, interview, and test.
7. Build the other 72 requirements into the program
The guide does not address 72 requirements. That is not a rounding error. Assign each to an internal owner, an MSP/MSSP, a readiness provider, a physical-security action, HR, training, or another technology.
8. Test incident discovery and evidence preservation
Simulate a delayed cloud event, a local alert, and a support-session event. Record who recognizes the event, when discovery occurs, how the 72-hour DFARS decision is escalated, and what images/logs are preserved.
9. Reconcile the dashboard to the government's record
Make sure the score, SSP, POA&M, assessment status, SPRS record, and annual affirmation are not being treated as one thing. They are different records with different owners and legal consequences.
10. Freeze the evidence package before the assessment
Export the SSP and POA&M, preserve configuration, capture version and licensing, collect logs showing operation, document unresolved limitations, and keep the vendor's written answers. Your assessor should see a system you understand, not a box your vendor understands for you.
NeQter Labs CMMC review FAQ
Is NeQter Labs a C3PAO?
No. NeQter is a software/appliance vendor and advertises related readiness support. It cannot issue a CMMC certification status by selling you Core or Comply. For a Level 2 certification assessment, use an authorized or accredited C3PAO and verify the organization in the Cyber AB Marketplace.
Is NeQter Labs an RPO?
A Cyber AB member profile for NeQter exists, but the role attached to that profile did not render in our text retrieval on August 28, 2026. We will not guess. Check the Cyber AB Marketplace directly and save a dated screenshot before relying on a role designation.
How many CMMC Level 2 requirements does NeQter cover?
NeQter's public November 2022 guide addresses 38 of 110 Revision 2 requirements. It describes some product assistance for 96 of the 153 assessment objectives inside those 38 practices and says 57 objectives still depend on policies or processes NeQter does not define. It describes four individual practices as met, all in Audit and Accountability.
That is a documentary count, not a certification claim. Your actual implementation and assessment results depend on configuration, scope, people, policies, evidence, and shared responsibilities.
Does NeQter fully cover Audit and Accountability?
Its guide addresses all nine Audit and Accountability requirements, but “addresses” is not the same as “fully satisfies.” The guide describes four AU practices as met and labels or explains the remaining work across the other AU practices. Treat the family as the product's strongest coverage area, not as an automatic pass.
How much does NeQter Core cost?
Published three-year-term pricing starts at $325 per month for up to 10 devices and reaches $1,575 per month for 750 or more. Published one-year pricing is 20% higher at every visible tier, from $390 to $1,890 per month. Hardware, implementation labor, infrastructure, and managed operation are additional.
Is NeQter Comply included with Core?
NeQter's public materials conflict. The pricing page lists Comply separately, while another current company article says it is included with Core. Get the exact answer, edition, term, renewal treatment, and export rights in your order form.
Is NeQter on premises?
Core is published as a physical or virtual appliance that can run in the contractor's environment, including disconnected deployments. Comply and Central require separate data-location questions. “On premises” does not by itself prove NeQter is outside ESP scope; remote support and hosted services still need a data-path analysis.
Does NeQter need FedRAMP?
The appliance running in your own environment does not need FedRAMP merely because it is a security asset. If a NeQter-hosted cloud service processes CUI, the cloud service provider requirements in 32 CFR 170.19 apply, including FedRAMP Moderate or equivalent requirements. If the service processes Security Protection Data but not CUI, it can still be an in-scope ESP/SPA relationship without FedRAMP being triggered solely by that data.
We did not find a public FedRAMP Marketplace listing for NeQter when checked on August 28, 2026. Confirm the proposed architecture rather than treating that search as a universal conclusion about every deployment.
Does NeQter submit an SPRS score?
No public documentation we found says NeQter makes the government submission or affirmation for the contractor. The product can calculate a score from entered implementation statuses. The contractor remains responsible for the truth of those statuses, the applicable SPRS process, the CMMC record, and annual affirmation.
Does NeQter support CMMC Level 3?
The public SSP framework documentation lists CMMC Levels 1 and 2. Core could still provide logging and other security capabilities in a Level 3 environment, but the published workflow is not a complete Level 3 management system. Level 3 uses 24 selected requirements from NIST SP 800-172, February 2021, in addition to the Level 2 baseline.
Does NeQter monitor alerts for you 24/7?
We found no public evidence that 24/7 human analyst monitoring is included in the base published subscription. The product centralizes and analyzes security data; your organization or MSP still needs to own review and response unless your quote includes a separately defined managed service.
Can NeQter guarantee CMMC certification?
No. No tool can. CMMC status comes from the required self-assessment, C3PAO assessment, or DIBCAC assessment process and the associated affirmation. A vendor can support an implementation. It cannot control your scope, evidence, people, other systems, or assessor findings.
Does NeQter support NIST SP 800-171 Revision 3?
NeQter may add or advertise Revision 3 support, but CMMC still controls against Revision 2 as of August 28, 2026. Do not replace your current assessment baseline with Revision 3 unless DoD amends the program and the applicable contract requirement changes.
Is NeQter worth it for a small contractor?
It can be, especially when the alternative is no centralized logging, no vulnerability-management evidence, and no person with a workable audit trail. The Nano tier is affordable in absolute dollars but expensive per device, and the public VM requirement plus labor can exceed the subscription. It is worth considering when you have an operator and a defined logging gap. It is not worth buying as a substitute for an operator or for the other 72 requirements outside the public guide.
What should I ask for before signing?
Ask for the current control map, complete architecture and data-flow description, CRM for any ESP service, Comply hosting and bundling, FIPS certificate numbers, current hardening guide, support SLA, retention and backup model, all-in cost, 3.0 migration terms, and complete export/termination rights. The 15-question list above is designed to be sent as written.
Final verdict: a real answer to a narrow problem
NeQter Labs is not the all-in-one CMMC answer. It is a defensible, relatively transparent answer to a narrower problem: putting centralized logging, vulnerability data, asset visibility, and audit evidence inside the contractor's environment at a published price.
The vendor's strongest evidence is not the “90+” claim. It is the document underneath it:
- 38 of 110 Level 2 requirements addressed in the public guide;
- all nine Audit and Accountability requirements discussed;
- four individual AU practices described as met;
- 96 assessment objectives with some product assistance;
- 57 objectives in those same practices where the guide says policy or process still belongs elsewhere;
- 72 requirements outside the guide entirely;
- published pricing from $325 to $1,890 per month;
- a public change log that exposes version gates instead of pretending the product has always done everything; and
- a deployment architecture that can keep raw security data local when it is actually configured that way.
The damaging admission is also the decision:
You can buy the right tool and still be nowhere near ready.
If your problem is no SIEM, no log retention, no vulnerability evidence, and no way to show Audit and Accountability operation, NeQter belongs on the shortlist. If your problem is “we do not know our CUI boundary, nobody owns the controls, our policies are templates, and we need a certificate,” the appliance is downstream of the real problem.
There is no NeQter affiliate button here. There is a path decision.
- Still unsure which category you need? Use Find My CMMC Path.
- You know your level, scope, and timeline and want qualified provider options? Request a quote / Get Matched.
- You need to separate readiness, managed security, GRC, enclave, and assessment work first? See CMMC provider categories, Who to Hire First, and the CMMC provider directory.
We may receive compensation for qualified introductions. That does not make the routing form a secure channel. Do not submit CUI, drawings, credentials, network diagrams, or sensitive contract details.
Primary sources and vendor documents checked
CMMC rule and contract clauses
- 32 CFR Part 170 — Cybersecurity Maturity Model Certification Program
- 32 CFR 170.19 — CMMC scoping
- 32 CFR 170.3 — Implementation plan
- DFARS 252.204-7012 — Safeguarding Covered Defense Information and Cyber Incident Reporting
- DFARS 252.204-7019 — Notice of NIST SP 800-171 DoD Assessment Requirements
- DFARS 252.204-7020 — NIST SP 800-171 DoD Assessment Requirements
- DFARS 252.204-7021 — Cybersecurity Maturity Model Certification Requirements
NIST publications
NeQter Labs sources
- NeQter CMMC Compliance Guide
- NeQter pricing
- NeQter change log
- NeQter system specifications
- NeQter frequently asked questions
- NeQter CMMC compliance software
- NeQter Central
Verification boundary: Vendor features, prices, documentation, marketplace status, and government rollout actions can change. We verified the linked material on August 28, 2026. The signed solicitation, contract, order form, current eCFR, current Acquisition.gov clause text, and current Cyber AB Marketplace entry control over this page if they conflict.
Editorial and legal disclosures
This page is educational information, not legal, contractual, cybersecurity, audit, or compliance advice. CMMC applicability and status depend on the solicitation, contract, information handled, asset scope, assessment type, implementation evidence, and government or assessor determinations.
The Defense Compliance Report is not affiliated with, endorsed by, or acting for the U.S. Department of Defense, DCMA DIBCAC, NIST, the Cyber AB, or NeQter Labs. Product and organization names belong to their respective owners.
We do not claim that any product, consultant, MSP, RPO, C3PAO, enclave, or implementation guarantees a CMMC status, contract award, or continued eligibility. Verify Cyber AB ecosystem roles in the current Marketplace and screen independence conflicts for the assessment you plan to buy.
Found an error or a source that changes this analysis? Use our Corrections Policy. We publish material corrections and update the verification date when the evidence changes.
