Defense industrial base

Your iPaaS is in your CMMC scope. Here's the boundary math.

Every system that touches CUI lands in your assessment. Samba lands inside the enclave you already have — same boundary, same IAM, same audit evidence — instead of adding a vendor to your System Security Plan.

Scoping is the whole game

A Level 2 assessment forces an honest inventory of every system that processes, stores, or transmits CUI. That inventory is where the cost lives — not in the controls themselves, but in how many systems you have to apply them to and evidence them across.

A multi-tenant integration platform in that inventory is an awkward entry. It transmits CUI by design. It is external. It is a cloud service provider whose own posture you now have to establish, document in your SSP, and defend to an assessor who has seen the same argument fail elsewhere. Depending on the data and the flowdown, it can be a disqualification rather than a finding.

Deploying the integration tier inside your existing enclave does not make the control requirements go away. It makes them the same requirements you are already meeting, on infrastructure already in scope, evidenced by the same mechanisms.

Evidence generated in your enclave, not a questionnaire response

Samba evaluates a catalog of 54 security controls against the cluster it is actually running in. Each carries NIST 800-53 lineage. Your assessor reads the results directly, in your environment, without a vendor in the loop and without waiting on anyone's schedule.

54 controls with 800-53 lineage

Network segmentation, RBAC, secrets management, encryption at rest, pod security, admission policy, service-mesh mTLS, and more — each mapped to its control family rather than described in prose.

Restores proven, not asserted

Backups run daily, and a scheduled job restores one weekly to prove it is actually recoverable. The control fails if the most recent successful restore is more than seven days old. Most vendors can only answer this question with "annually, per policy," which is a materially weaker answer to a recovery control.

Audit the application cannot rewrite

Immutability is enforced by a database trigger rather than application code, so the guarantee survives a compromise of the application tier. That is the distinction an assessor probes for.

Who is responsible for what

The short version of the shared-responsibility split. The detailed control-family mapping against NIST SP 800-171 Rev 2 is available to you and your assessor on request.

Area You Cirrus Tempo
Physical & environmental Inherited from your cloud provider None
Cluster & node security You operate the cluster Hardened images, security baselines
Identity & access management Your IdP, your groups, your reviews OIDC integration, RBAC model
CUI in transit and at rest Your keys, your storage, your enclave Encryption implementation, mTLS
Credential custody Your Vault, your rotation policy None — we never hold them
Audit log retention Your retention policy and storage Immutable write path, structured records
Incident response Your plan, your reporting obligations Vulnerability disclosure, patch delivery
Configuration & flows Your integration logic and reviews Grammar validation, change records

Note what is absent from the right-hand column: we do not operate your deployment, hold your credentials, or process your CUI. That is the point of the model — it is also why our row in your SSP is short.

Working with a C3PAO or CMMC consultant?

Bring them. The scoping conversation is the one that matters, and it goes better with the person who will assess you in the room. We are glad to walk the control evidence with them directly.