What a router can (and can't) do for CMMC Level 2
Last updated October 6, 2026. General information for small defense contractors, not legal or compliance advice.
The short answer
A router can help with a few of the 110 NIST SP 800-171 Rev 2 requirements behind CMMC Level 2: mainly boundary protection, segmentation and wireless access control. It cannot handle the policies, training, endpoint security, identity and logging that make up most of the work. No router makes a company CMMC compliant, and that includes Rio.
Where CMMC stands in October 2026
The CMMC program rule (32 CFR Part 170) set four phases, starting when the DFARS contract rule took effect on November 10, 2025:
- Phase 1, November 10, 2025: self-assessments.
- Phase 2, November 10, 2026: Level 2 certification by a third-party assessor (C3PAO) in applicable contracts.
- Phase 3, November 10, 2027: Level 3 where required, and C3PAO requirements for option periods.
- Phase 4, November 10, 2028: full implementation.
That schedule has changed. On July 13, 2026, the Department of War suspended the move to Phase 2, put later milestones on hold and set up a CMMC Reform Task Force. On September 3, 2026, a class deviation directed contracting officers to remove third-party assessment requirements from solicitations and contracts. The task force's report was due to the DoD CIO in September but had not been made public as of early October.
What did not change: DFARS 252.204-7012 still requires NIST SP 800-171, self-assessments still apply where contracts call for them, and your SPRS score and annual affirmation must be accurate. C3PAO assessments remain available voluntarily. The deadline moved. The 110 requirements did not, and work you do now still counts if third-party assessments return.
Which NIST SP 800-171 requirements live at the network layer
CMMC Level 2 assesses against NIST SP 800-171 Rev 2, not the May 2024 Rev 3. These are the requirements a router can realistically touch, with Rio's rating from its published control mapping. Your assessor, or you in a self-assessment, decides whether each is met.
| Requirement | What it asks for | What a router can do | Rio's rating |
|---|---|---|---|
| 3.13.5 Subnetworks | Separate publicly accessible components from internal networks | Put systems in separate segments | Supports (SecureRooms) |
| 3.1.16 Wireless authorization | Authorize wireless access before allowing connections | Hold new devices until approved | Supports (device approval) |
| 3.13.1 Boundary protection | Monitor and control communications at the external boundary | Firewall at the internet edge | Partial. Firewall blocks unsolicited inbound traffic; monitoring is limited to the app's activity log |
| 3.13.6 Deny by default | Deny traffic by default, allow by exception | Block inbound by default | Partial. Inbound blocked by default; outbound allowed by default |
| 3.1.17 Wireless protection | Protect wireless access with authentication and encryption | Wi-Fi encryption and access control | Partial. WPA2 Personal plus device approval; FIPS validation not confirmed |
| 3.1.18 Mobile device connection | Control connection of mobile devices | Hold phones and laptops until approved | Partial. Managing the devices themselves needs other tools |
| 3.1.20 External connections | Verify and control connections to external systems | Firewall and approval help | Partial. Also needs policy and other tools |
| 3.13.7 Split tunneling | Prevent remote devices from split tunneling | Only with a remote-access VPN | Not addressed |
| 3.1.14 Managed access points | Route remote access through managed control points | Only with a remote-access solution | Not addressed |
Overall, Rio's mapping rates it as supporting 2 of the 110 requirements and partially covering 13 more, all at the network layer. Encryption protecting CUI must be FIPS-validated (3.13.8 and 3.13.11). FIPS validation of Rio's Wi-Fi and of Rio VPN is not confirmed, so do not rely on Rio for those requirements. Rio VPN is also an outbound privacy VPN for the rooms you assign, not a remote-access VPN.
What still needs policies, endpoints and training
Most of NIST SP 800-171 has nothing to do with your router. These need other tools, written procedures or an outside provider:
- Accounts, least privilege and multi-factor authentication (3.1.1, 3.1.2, 3.5.3)
- Training (3.2) and audit logging (3.3)
- Baseline configurations and patching (3.4, 3.14.1)
- Malware protection on computers (3.14.2)
- Incident response, including DFARS 7012's 72-hour reporting (3.6)
- Media, personnel and physical protection (3.8 to 3.10)
- Risk assessment, your System Security Plan and a plan of action (3.11, 3.12)
How SecureRooms map to a CUI enclave
Scoping decides how much of your business gets assessed. DoD's Level 2 scoping guide sorts assets into categories such as CUI assets, security protection assets and out-of-scope assets. Out-of-scope assets must be physically or logically separated from the systems that handle CUI. A CUI enclave is a segment that holds those systems, with a clear boundary around it.
SecureRooms give you that logical separation at the network layer. Put CUI computers in their own room with its own password, approve each device that joins, and keep guests, phones, printers and smart devices elsewhere. Here is how SecureRooms work.
- The router enforcing the boundary is itself a security protection asset, so it is in scope.
- Separation only holds if CUI stays inside it. Email, USB drives and cloud services that carry CUI are in scope too.
- Write the boundary into your SSP and network diagram.
A network-layer checklist
- Confirm what your contracts require: DFARS 7012, a CMMC level, self-assessment or C3PAO.
- List where CUI lives and draw your current network, including Wi-Fi.
- Move CUI systems into their own segment.
- Require approval for new devices and give the CUI segment its own Wi-Fi password.
- Confirm the firewall blocks unsolicited inbound traffic.
- Confirm the encryption protecting CUI in transit is FIPS-validated, and handle remote access with a solution built for it.
- Write the network section of your SSP, record gaps in your plan of action and keep evidence such as device lists and screenshots.
- Score yourself honestly in SPRS. A self-assessment you affirm still has to be true.
Where Rio for Defense fits
Rio for Defense is $599. It includes the Rio router, a Quickstart guide, the SSP Documentation Pack, the SSP Builder, a network diagram, an Assessor Reference Sheet, 2 years of Rio VPN, the Assessor Guarantee, priority support and one free replacement in the first year. It is meant for small shops that need the network layer in place and written up, without an enterprise security stack.
The Assessor Guarantee covers the controls Rio lists as "Supports." If your C3PAO assessment, your SPRS self-assessment, or a prime contractor or DCMA review finds one of them not met, and the cause is that Rio, set up as described in the Quickstart and SSP Documentation Pack, does not provide the capability described, Rio will work with you to fix it or refund the full purchase price. Claims are due within 90 days of the assessment, for assessments within 24 months of purchase.
To be plain about it: Rio does not make you CMMC compliant. It does not provide multi-factor authentication, endpoint protection, audit logging, training or policies. If an MSP already runs managed firewalls and VLANs for you, you may not need it. If you are starting from a flat office network, it covers the network piece. See how Rio maps to NIST SP 800-171.
Frequently asked questions
Will a router make my company CMMC compliant?
No. A router can help with a few network-layer requirements in NIST SP 800-171, such as boundary protection, segmentation and wireless access control. CMMC Level 2 covers 110 requirements, and most involve policies, training, endpoints, identity and logging. Rio does not make you CMMC compliant.
Is CMMC Phase 2 still starting on November 10, 2026?
No. On July 13, 2026, the Department of War suspended the move to Phase 2 and put later milestones on hold pending a review. A September 3, 2026 class deviation directed contracting officers to remove third-party assessment requirements from solicitations and contracts. Check the DoD CIO CMMC website for updates.
If Phase 2 is suspended, do I still need to do anything?
Yes. DFARS 252.204-7012 still requires NIST SP 800-171, self-assessments still apply where contracts call for them, and your SPRS score must be accurate. C3PAO assessments remain available.
Does network segmentation reduce CMMC scope?
It can. Assets that are physically or logically separated from systems that handle CUI may be treated as out of scope. The device enforcing the separation stays in scope, as does any other path CUI travels, such as email. Document the boundary in your System Security Plan.
Is Rio CMMC certified?
No product is CMMC certified. Organizations are assessed, not routers. Rio's published control mapping rates it as supporting 2 NIST SP 800-171 requirements and partially covering 13 more, all at the network layer.
Can I use Rio VPN to protect CUI?
Do not rely on it for that. FIPS validation of Rio VPN is not confirmed, it only encrypts outbound traffic for the rooms you assign, and it is not a remote-access VPN.
Sources
- 32 CFR Part 170, CMMC Program (eCFR), phases in section 170.3(e)
- DoD Office of Industrial Base Growth: It's Official, CMMC Has Landed, Sept 2025
- DoD CIO: Cybersecurity Maturity Model Certification, checked Oct 6, 2026
- DoD CIO memo 26-P-1023: Implementing Suspension of CMMC Phase II, July 13, 2026
- DoD Office of Industrial Base Growth: Department of War Suspends CMMC Phase II Requirements, July 2026
- Greenberg Traurig: DoD Suspends CMMC Deadlines and Seeks to Reassess Requirements, July 15, 2026
- Washington Technology: CMMC's Phase 2 suspension locked in with binding regulation, Sept 9, 2026
- Covington, Inside Government Contracts: CMMC Reform Task Force Updates, September 2026, Sept 21, 2026
- Smith Currie: Class Deviation Memorandum Codifies CMMC Phase 2 Suspension, Sept 22, 2026
- Cyber AB: Statement on the Department of War's Suspension of CMMC Phase II Requirements (via Yahoo Finance), July 15, 2026
- NIST SP 800-171 Rev 2, Feb 2020, updated Jan 28, 2021
- NIST SP 800-171 Rev 3, May 2024
- DoD CIO: CMMC Scoping Guide, Level 2
- Rio for Defense: NIST SP 800-171 control mapping (download on this page)
