What a router can (and can't) do for CMMC Level 2

An engineer reviewing CAD drawings at her desk in a small manufacturing shop

Last updated October 6, 2026. General information for small defense contractors, not legal or compliance advice.

The short answer

A router can help with a few of the 110 NIST SP 800-171 Rev 2 requirements behind CMMC Level 2: mainly boundary protection, segmentation and wireless access control. It cannot handle the policies, training, endpoint security, identity and logging that make up most of the work. No router makes a company CMMC compliant, and that includes Rio.

Where CMMC stands in October 2026

The CMMC program rule (32 CFR Part 170) set four phases, starting when the DFARS contract rule took effect on November 10, 2025:

  • Phase 1, November 10, 2025: self-assessments.
  • Phase 2, November 10, 2026: Level 2 certification by a third-party assessor (C3PAO) in applicable contracts.
  • Phase 3, November 10, 2027: Level 3 where required, and C3PAO requirements for option periods.
  • Phase 4, November 10, 2028: full implementation.

That schedule has changed. On July 13, 2026, the Department of War suspended the move to Phase 2, put later milestones on hold and set up a CMMC Reform Task Force. On September 3, 2026, a class deviation directed contracting officers to remove third-party assessment requirements from solicitations and contracts. The task force's report was due to the DoD CIO in September but had not been made public as of early October.

What did not change: DFARS 252.204-7012 still requires NIST SP 800-171, self-assessments still apply where contracts call for them, and your SPRS score and annual affirmation must be accurate. C3PAO assessments remain available voluntarily. The deadline moved. The 110 requirements did not, and work you do now still counts if third-party assessments return.

Which NIST SP 800-171 requirements live at the network layer

CMMC Level 2 assesses against NIST SP 800-171 Rev 2, not the May 2024 Rev 3. These are the requirements a router can realistically touch, with Rio's rating from its published control mapping. Your assessor, or you in a self-assessment, decides whether each is met.

Requirement What it asks for What a router can do Rio's rating
3.13.5 Subnetworks Separate publicly accessible components from internal networks Put systems in separate segments Supports (SecureRooms)
3.1.16 Wireless authorization Authorize wireless access before allowing connections Hold new devices until approved Supports (device approval)
3.13.1 Boundary protection Monitor and control communications at the external boundary Firewall at the internet edge Partial. Firewall blocks unsolicited inbound traffic; monitoring is limited to the app's activity log
3.13.6 Deny by default Deny traffic by default, allow by exception Block inbound by default Partial. Inbound blocked by default; outbound allowed by default
3.1.17 Wireless protection Protect wireless access with authentication and encryption Wi-Fi encryption and access control Partial. WPA2 Personal plus device approval; FIPS validation not confirmed
3.1.18 Mobile device connection Control connection of mobile devices Hold phones and laptops until approved Partial. Managing the devices themselves needs other tools
3.1.20 External connections Verify and control connections to external systems Firewall and approval help Partial. Also needs policy and other tools
3.13.7 Split tunneling Prevent remote devices from split tunneling Only with a remote-access VPN Not addressed
3.1.14 Managed access points Route remote access through managed control points Only with a remote-access solution Not addressed

Overall, Rio's mapping rates it as supporting 2 of the 110 requirements and partially covering 13 more, all at the network layer. Encryption protecting CUI must be FIPS-validated (3.13.8 and 3.13.11). FIPS validation of Rio's Wi-Fi and of Rio VPN is not confirmed, so do not rely on Rio for those requirements. Rio VPN is also an outbound privacy VPN for the rooms you assign, not a remote-access VPN.

What still needs policies, endpoints and training

Most of NIST SP 800-171 has nothing to do with your router. These need other tools, written procedures or an outside provider:

  • Accounts, least privilege and multi-factor authentication (3.1.1, 3.1.2, 3.5.3)
  • Training (3.2) and audit logging (3.3)
  • Baseline configurations and patching (3.4, 3.14.1)
  • Malware protection on computers (3.14.2)
  • Incident response, including DFARS 7012's 72-hour reporting (3.6)
  • Media, personnel and physical protection (3.8 to 3.10)
  • Risk assessment, your System Security Plan and a plan of action (3.11, 3.12)

How SecureRooms map to a CUI enclave

Scoping decides how much of your business gets assessed. DoD's Level 2 scoping guide sorts assets into categories such as CUI assets, security protection assets and out-of-scope assets. Out-of-scope assets must be physically or logically separated from the systems that handle CUI. A CUI enclave is a segment that holds those systems, with a clear boundary around it.

SecureRooms give you that logical separation at the network layer. Put CUI computers in their own room with its own password, approve each device that joins, and keep guests, phones, printers and smart devices elsewhere. Here is how SecureRooms work.

  • The router enforcing the boundary is itself a security protection asset, so it is in scope.
  • Separation only holds if CUI stays inside it. Email, USB drives and cloud services that carry CUI are in scope too.
  • Write the boundary into your SSP and network diagram.

A network-layer checklist

  1. Confirm what your contracts require: DFARS 7012, a CMMC level, self-assessment or C3PAO.
  2. List where CUI lives and draw your current network, including Wi-Fi.
  3. Move CUI systems into their own segment.
  4. Require approval for new devices and give the CUI segment its own Wi-Fi password.
  5. Confirm the firewall blocks unsolicited inbound traffic.
  6. Confirm the encryption protecting CUI in transit is FIPS-validated, and handle remote access with a solution built for it.
  7. Write the network section of your SSP, record gaps in your plan of action and keep evidence such as device lists and screenshots.
  8. Score yourself honestly in SPRS. A self-assessment you affirm still has to be true.

Where Rio for Defense fits

Rio for Defense is $599. It includes the Rio router, a Quickstart guide, the SSP Documentation Pack, the SSP Builder, a network diagram, an Assessor Reference Sheet, 2 years of Rio VPN, the Assessor Guarantee, priority support and one free replacement in the first year. It is meant for small shops that need the network layer in place and written up, without an enterprise security stack.

The Assessor Guarantee covers the controls Rio lists as "Supports." If your C3PAO assessment, your SPRS self-assessment, or a prime contractor or DCMA review finds one of them not met, and the cause is that Rio, set up as described in the Quickstart and SSP Documentation Pack, does not provide the capability described, Rio will work with you to fix it or refund the full purchase price. Claims are due within 90 days of the assessment, for assessments within 24 months of purchase.

To be plain about it: Rio does not make you CMMC compliant. It does not provide multi-factor authentication, endpoint protection, audit logging, training or policies. If an MSP already runs managed firewalls and VLANs for you, you may not need it. If you are starting from a flat office network, it covers the network piece. See how Rio maps to NIST SP 800-171.

Frequently asked questions

Will a router make my company CMMC compliant?

No. A router can help with a few network-layer requirements in NIST SP 800-171, such as boundary protection, segmentation and wireless access control. CMMC Level 2 covers 110 requirements, and most involve policies, training, endpoints, identity and logging. Rio does not make you CMMC compliant.

Is CMMC Phase 2 still starting on November 10, 2026?

No. On July 13, 2026, the Department of War suspended the move to Phase 2 and put later milestones on hold pending a review. A September 3, 2026 class deviation directed contracting officers to remove third-party assessment requirements from solicitations and contracts. Check the DoD CIO CMMC website for updates.

If Phase 2 is suspended, do I still need to do anything?

Yes. DFARS 252.204-7012 still requires NIST SP 800-171, self-assessments still apply where contracts call for them, and your SPRS score must be accurate. C3PAO assessments remain available.

Does network segmentation reduce CMMC scope?

It can. Assets that are physically or logically separated from systems that handle CUI may be treated as out of scope. The device enforcing the separation stays in scope, as does any other path CUI travels, such as email. Document the boundary in your System Security Plan.

Is Rio CMMC certified?

No product is CMMC certified. Organizations are assessed, not routers. Rio's published control mapping rates it as supporting 2 NIST SP 800-171 requirements and partially covering 13 more, all at the network layer.

Can I use Rio VPN to protect CUI?

Do not rely on it for that. FIPS validation of Rio VPN is not confirmed, it only encrypts outbound traffic for the rooms you assign, and it is not a remote-access VPN.

Sources

Share: Twitter Facebook LinkedIn Email