Skip to main content

Get started with CMMC Defense Navigator

Written by Brady Price

Modules

CMMC Navigator is a guided setup experience in Secureframe Defense. It walks you through the modules needed for CMMC, asks scoping questions up front, and uses your answers to build your System Security Plan (SSP) and map your environment to compliance tests.

CMMC Navigator is broken out into different modules to walk you through getting CMMC compliant.

Note: Later modules can stay locked or disabled until earlier modules and setup steps are complete. See Frequently Asked Questions if a module will not unlock.

Program Details

The Program Details module captures the foundation of your compliance program.

Organization Details

Enter your company information, website, and key contacts. This information will be used throughout your SSP and compliance documentation.

Company Identifiers

  • System Unique Entity Identifier (UEI). Your unique identifier from SAM.gov

  • SAM Registration. Your System for Award Management registration status

  • CAGE Code. Your Commercial and Government Entity code

System Categorization

  • FCI. Federal Contract Information

  • CUI. Controlled Unclassified Information

  • SPD. Security Protection Data

Why this matters: Navigator uses this information to tailor your compliance path and pre-populate your SSP documentation. Accurate details here save time later.

Tech Stack Integration

Connect your systems for automatic evidence collection.

Navigator walks you through connecting your existing infrastructure so Secureframe can automatically validate configurations and collect required evidence:

  • Microsoft GCC High / Azure Government: Full support for government cloud environments

  • Google Workspace: Including CUI organizational unit setup and access controls

  • Secureframe Federal MDM

Each integration includes guided setup with step-by-step instructions, permission requirements, and verification. CMMC Navigator connections are labeled on the Integrations page. Archive is disabled for the federal connections Secureframe uses for ongoing monitoring, so those connections are not removed by accident.

If you need a new Microsoft GCC High tenant before licenses can bind, complete Microsoft GCC High Tenant Eligibility for CMMC first.

Policy Management

The Policies module helps you review and publish the documented policies required for CMMC compliance. These policies define expectations and demonstrate that security requirements are met.

Steps in This Module

  1. Policy Source Selection: Choose to use Secureframe's pre-built CMMC policy templates or upload your own existing policies.

  2. Placeholder Values: Enter organization-specific details (like company name, security contacts, etc.) that will auto-populate across all policies.

  3. Review & Publish: Work through each policy with a guided review workflow. You'll see what's required, what's optional, and what's already covered.

Note: Policies are automatically linked to their corresponding CMMC requirements in your SSP. No manual mapping required.

Complete the remaining Navigator modules in order, including training.

Training

The Training module ensures your personnel complete the security training required for CMMC compliance.

CMMC Navigator supports the following options:

  • Secureframe Training. Built-in courses configured directly through Navigator

  • KnowBe4 Integration. Connect your existing KnowBe4 account for automatic completion tracking

  • Third-Party Vendor. Upload completion records from any training provider

Your personnel will need to complete the following trainings. In the Navigator you will assign specific user groups to each training so that users are only required to complete what is relevant to their role.

  • Security Awareness Training

  • Role-Based Security Training

  • Incident Response Training

  • Handling CUI Training

  • Acceptable Use Training

Background Checks

The Background Checks module guides you through setting up federal background check requirements for your personnel.

What's Included

  • Guided setup for federal background check requirements

  • Integration with supported background check providers, Checkr

  • Ability to upload supporting documentation

  • Tracking for completion status across your organization

If you take advantage of the integration with Checkr, admins can initiate background checks from the Secureframe platform. The personnel will receive an email to start the process.

Invite Personnel

The final module helps you onboard team members with appropriate access and training assignments.

  • Invite personnel to your Secureframe account

  • Assign appropriate access roles

  • Automatically assign required training based on their role


Frequently Asked Questions

Can I complete modules in any order?

  • No. Complete Navigator modules in sequential order. Later modules stay locked until earlier setup or prerequisite steps are finished.

  • Some modules, such as Training, depend on information from earlier modules like Program Details.

What happens if I need to stop and come back later?

  • Your progress is automatically saved. You can return to Navigator at any time and pick up where you left off.

How do I know when I'm done?

  • Each module shows a completion status. When all modules are complete, your Navigator dashboard will reflect your readiness for assessment.

Why can't I archive some CMMC / federal connections on the Integrations page?

  • CMMC Navigator connections are labeled on the Integrations page so they are easier to identify.

  • Archive is disabled for the federal connections Secureframe uses for ongoing monitoring. Archiving those would break evidence collection for your CMMC pipeline.

  • If you need to replace or reconnect a federal integration, contact your CSM or [email protected] before making changes.

Why do I see users I can't select in CMMC Navigator?

  • Navigator now lists all users. Users who are not eligible are greyed out instead of hidden.

  • Hover the greyed-out user to see why they can't be selected.

  • Fix the eligibility issue (for example licensing or group membership), then return to Navigator to assign them.

Why is a Navigator module locked or disabled?

  • Navigator modules are often completed in sequence. A later module can stay locked until earlier modules and required setup steps are complete.

  • Check earlier modules and confirm required setup steps are finished.

  • Look for tooltips or status text. These often indicate what is missing.

  • Wait for provisioning steps to finish. Some modules unlock only after background setup completes.

A module has been stuck as "being set up." What should I do?

  • If a module has been in a "being set up" state for an unusually long time, or the UI indicates setup should have completed but the module never unlocks, contact Support.

  • Include which module is locked, a screenshot of the locked state and any tooltip text, how long it has been in that state, and your company name and environment (commercial vs GCC High).


Related Articles


Need Help?

If you have questions while working through Navigator, contact your Customer Success Manager at [email protected].

Did this answer your question?