Your iPaaS is in your CMMC scope. Here's the boundary math.
Every system that touches CUI lands in your assessment. Samba lands inside the enclave you already have — same boundary, same IAM, same audit evidence — instead of adding a vendor to your System Security Plan.
Scoping is the whole game
A Level 2 assessment forces an honest inventory of every system that processes, stores, or transmits CUI. That inventory is where the cost lives — not in the controls themselves, but in how many systems you have to apply them to and evidence them across.
A multi-tenant integration platform in that inventory is an awkward entry. It transmits CUI by design. It is external. It is a cloud service provider whose own posture you now have to establish, document in your SSP, and defend to an assessor who has seen the same argument fail elsewhere. Depending on the data and the flowdown, it can be a disqualification rather than a finding.
Deploying the integration tier inside your existing enclave does not make the control requirements go away. It makes them the same requirements you are already meeting, on infrastructure already in scope, evidenced by the same mechanisms.
For the assessor
Evidence generated in your enclave, not a questionnaire response
Samba evaluates a catalog of 54 security controls against the cluster it is actually running in. Each carries NIST 800-53 lineage. Your assessor reads the results directly, in your environment, without a vendor in the loop and without waiting on anyone's schedule.
54 controls with 800-53 lineage
Network segmentation, RBAC, secrets management, encryption at rest, pod security, admission policy, service-mesh mTLS, and more — each mapped to its control family rather than described in prose.
Restores proven, not asserted
Backups run daily, and a scheduled job restores one weekly to prove it is actually recoverable. The control fails if the most recent successful restore is more than seven days old. Most vendors can only answer this question with "annually, per policy," which is a materially weaker answer to a recovery control.
Audit the application cannot rewrite
Immutability is enforced by a database trigger rather than application code, so the guarantee survives a compromise of the application tier. That is the distinction an assessor probes for.
Who is responsible for what
The short version of the shared-responsibility split. The detailed control-family mapping against NIST SP 800-171 Rev 2 is available to you and your assessor on request.
| Area | You | Cirrus Tempo |
|---|---|---|
| Physical & environmental | Inherited from your cloud provider | None |
| Cluster & node security | You operate the cluster | Hardened images, security baselines |
| Identity & access management | Your IdP, your groups, your reviews | OIDC integration, RBAC model |
| CUI in transit and at rest | Your keys, your storage, your enclave | Encryption implementation, mTLS |
| Credential custody | Your Vault, your rotation policy | None — we never hold them |
| Audit log retention | Your retention policy and storage | Immutable write path, structured records |
| Incident response | Your plan, your reporting obligations | Vulnerability disclosure, patch delivery |
| Configuration & flows | Your integration logic and reviews | Grammar validation, change records |