Defense Navigator
The Defense Navigator is the guided setup experience for your Cybersecurity Maturity Model Certification (CMMC) program. Getting to CMMC Level 2 means standing up a compliant environment, writing policies, training people, screening personnel, and documenting all of it. Navigator turns that into a sequence of modules you complete in order: you answer questions about your organization, set up your environment, and review what Secureframe builds.
Modules are completed in sequential order, and later modules stay locked until their prerequisites are finished. Your progress is automatically saved, so you can leave at any point and pick up exactly where you stopped.
Good to know:
Modules are completed in sequential order. Later modules stay locked until their prerequisites are finished, and a locked module always tells you what unlocks it.
Your progress saves automatically. Leave at any point and pick up where you stopped.
As you complete modules, your System Security Plan (SSP) is filled in for you in the background, based on your connected technology, scoping answers, published policies, and training.
Organization Details
Available from the start, this module captures the basic company information used throughout your CMMC documentation. Navigator uses it to tailor your compliance path and pre-populate your SSP documentation, so accurate details here save time later.
Company information: Your organization name, address, and website.
Federal identifiers: Your Unique Entity Identifier (UEI), Commercial and Government Entity (CAGE) code, and North American Industry Classification System (NAICS) code. Secureframe auto-fills these from SAM.gov; you confirm them.
System description and data handling: Describe your business and how Controlled Unclassified Information (CUI) flows through it. Secureframe drafts the system description from your website for you to review.
CMMC Scoping
Available from the start, scoping asks yes/no questions about how your organization operates. Your answers determine which CMMC requirements apply to you:
Not Applicable requirements: Requirements that do not apply to your environment are marked Not Applicable, each with an assessor-ready justification.
Tests: Automated tests tied to requirements that do not apply are turned off, so your dashboard tracks only what applies to you.
Policies and SSP language: Both adapt to match your answers.
Learn more: CMMC Scoping
CUI Enclave Setup
Once scoping is complete, Navigator walks you through connecting your existing infrastructure so Secureframe can automatically validate configurations and collect required evidence:
Microsoft GCC High / Azure Government: Full support for Microsoft's government cloud environments (GCC High is Microsoft's Government Community Cloud High).
Google Workspace: Including CUI organizational unit setup and access controls.
Secureframe Virtual Desktops: CMMC-compliant virtual desktops in your Azure Government environment, so CUI work stays inside the enclave and your team's own computers stay out of scope.
Secureframe Federal MDM: Federally hosted mobile device management (MDM) for your endpoints.
As you connect technology, your SSP's implementation statements adapt to reflect what is actually in your environment.
Note: New to GCC High? You need a GCC High tenant before licenses can be purchased and applied to your organization. Start with Microsoft GCC High Tenant Eligibility for CMMC, which walks you through Microsoft's eligibility approval process.
Learn more: CUI Enclave Setup
Service Providers & Vendors
Available anytime, this module is where you list the vendors and service providers that sit alongside your enclave and affect your CMMC boundary.
Background Checks
Once your cloud environment is connected, the Background Checks module guides you through setting up federal background check requirements for your personnel. It supports the Checkr integration, lets you upload supporting documentation from any other provider, and tracks completion status across your organization.
If you take advantage of the Checkr integration, admins can initiate background checks from the Secureframe platform, and personnel receive an email to start the process.
Learn more: FAQs: Background checks
Personnel Training
Once your cloud environment is connected, the Training module ensures your personnel complete the security training required for CMMC compliance: Security Awareness, Role-Based Security, Incident Response, Handling CUI, and Acceptable Use. You assign specific user groups to each training, so users are only required to complete what is relevant to their role.
CMMC Navigator supports the following options:
Secureframe Training: Built-in courses configured directly through Navigator.
KnowBe4 Integration: Connect your existing KnowBe4 account for automatic completion tracking.
Third-Party Vendor: Upload completion records from any training provider.
Policies
Once your cloud environment is connected, the Policies module helps you review and publish the documented policies required for CMMC compliance. These policies define expectations and demonstrate that security requirements are met.
Your policies are customized to your environment automatically. Policy content adapts to the technology you connected for your CUI enclave and to your scoping answers, so your policies describe what you actually run and never claim something you scoped out.
Policy source selection: Choose to use Secureframe's pre-built CMMC policy templates or upload your own existing policies. Secureframe's templates are fully editable, so you can tailor them to how your organization operates.
Placeholder values: Enter organization-specific details (like company name and security contacts) that auto-populate across all policies.
Review and publish: Work through each policy with a guided review workflow. You will see what is required, what is optional, and what is already covered.
Note: Policies are automatically linked to their corresponding CMMC requirements in your SSP. No manual mapping required.
Learn more: CMMC Policies in Defense Navigator
Invite Personnel
The final module, available once your cloud environment is connected, helps you onboard your team:
Invite personnel: Bring your team members into your Secureframe account.
Access roles: Assign each person the appropriate level of access.
Training assignment: Required training is automatically assigned based on each person's role.
After you complete Navigator
Once you have completed the Navigator modules, your ongoing CMMC work happens in the main Secureframe platform:
Review your implementation statements: Your SSP contains an implementation statement for each CMMC requirement, describing how your organization meets it. Secureframe automatically generates these based on your connected technology, scoping answers, policies, and training. Review them, edit anything that does not match how you operate, and fill in any that need your input. See Building and Managing a System Security Plan (SSP).
Get your tests passing: Your dashboard shows the automated tests for every requirement in scope. For any test that is failing, open it and follow its remediation guidance. These will primarily be upload tests that still need evidence.
Stay compliant: Secureframe continuously monitors your environment and flags anything that drifts out of compliance. Keep an eye on your dashboard to capture any changes.
Frequently Asked Questions (FAQ)
Can I complete modules in any order?
No. Complete Navigator modules in sequential order. Later modules stay locked until earlier setup or prerequisite steps are finished.
A locked module tells you what unlocks it.
What happens if I need to stop and come back later?
Your progress is automatically saved. You can return to Navigator at any time and pick up where you left off.
How do I know when I am done?
Each module shows a completion status. When all modules are complete, continue in the main platform with SSP review and tests.
Why can't I archive some CMMC / federal connections on the Integrations page?
CMMC Navigator connections are labeled on the Integrations page so they are easier to identify.
Archive is disabled for the federal connections Secureframe uses for ongoing monitoring. Archiving those would break evidence collection for your CMMC pipeline.
If you need to replace or reconnect a federal integration, contact your CSM or [email protected] before making changes.
Why do I see users I can't select in CMMC Navigator?
Navigator lists all users. Users who are not eligible are greyed out instead of hidden.
Hover the greyed-out user to see why they can't be selected.
Fix the eligibility issue (for example licensing or group membership), then return to Navigator to assign them.
Why is a Navigator module locked or disabled?
Navigator modules are often completed in sequence. A later module can stay locked until earlier modules and required setup steps are complete.
Check earlier modules and confirm required setup steps are finished.
Look for tooltips or status text. These often indicate what is missing.
Wait for provisioning steps to finish. Some modules unlock only after background setup completes.
A module has been stuck as "being set up." What should I do?
If a module has been in a "being set up" state for an unusually long time, or the UI indicates setup should have completed but the module never unlocks, contact Support.
Include which module is locked, a screenshot of the locked state and any tooltip text, how long it has been in that state, and your company name and environment (commercial vs GCC High).
Need help?
If you have questions while working through Navigator, contact your Customer Success Manager or [email protected].
