Scroll to top
CMMC LEVEL 3 — COMING SOON

Advanced CUI Protection Is Coming to Watchtower

Level 3 readiness, continuous security visibility, and DIBCAC preparation — being developed for defense contractors facing the highest cybersecurity requirements.

Watchtower CMMC Level 3 Readiness is being developed for defense contractors supporting high-priority programs that require enhanced protection against advanced persistent threats. The planned service will build on the Level 2 foundation of NIST SP 800-171 and address the additional Level 3 requirements selected from NIST SP 800-172 — supported by continuous security visibility, structured evidence tracking, and preparation for a government-led DIBCAC assessment.

In development · No launch date announced · Final service scope subject to current CMMC program requirements

WHY LEVEL 3 IS DIFFERENT

More Than an Expanded Checklist

CMMC Level 3 is intended for organizations requiring higher-level protection of Controlled Unclassified Information against advanced persistent threats. An organization pursuing Level 3 must first achieve Final Level 2 status. Level 3 then adds 24 selected requirements from NIST SP 800-172 and requires assessment by the Defense Industrial Base Cybersecurity Assessment Center rather than a self-assessment or C3PAO assessment.

Final Level 2 First

The applicable environment must first achieve Final Level 2 status.

24 Enhanced Requirements

Level 3 adds selected enhanced safeguards derived from NIST SP 800-172.

Government-Led Assessment

Level 3 assessments are conducted by DCMA DIBCAC.

Ongoing Affirmation

Assessment status is supported by annual affirmation of continued compliance.

PLANNED WATCHTOWER SERVICE

Built for Operational Readiness, Not Just Point-in-Time Answers

Watchtower's planned Level 3 service is being designed to help organizations organize complex requirements, connect technical observations to assessment objectives, identify evidence gaps, and maintain visibility between formal assessment activities.

Level 2 foundation and dependency tracking

Coverage of the 24 Level 3 requirements

Objective-level readiness findings

DIBCAC preparation workflow

Enhanced evidence-reference indexing

Technical observation mapping

Remediation and milestone tracking

Executive readiness reporting

Continuous security-event visibility

Wazuh SIEM integration

Historical readiness and control-status trends

AI-assisted requirement explanations and investigation guidance

Planned features remain subject to change as development progresses and the CMMC program evolves.

CONTINUOUS SECURITY VISIBILITY

From Periodic Readiness Reviews to Ongoing Awareness

Level 3 readiness requires more than completing a questionnaire shortly before an assessment. Organizations need mature security operations, dependable technical records, repeatable processes, and evidence that enhanced safeguards operate as intended.

Because Level 3 readiness depends on mature, repeatable security operations and sustained evidence — not merely a point-in-time questionnaire — the planned Watchtower enterprise tier will combine structured CMMC readiness records with Wazuh-based SIEM integration to help organizations monitor security events, investigate findings, and preserve derived reporting history over time.

Centralized Event Visibility

Bring relevant endpoint, server, network, and security-tool events into a unified monitoring workflow.

Continuous Technical Observations

Identify changes and events that may affect previously recorded readiness findings.

Assessment Traceability

Map relevant observations and reports to Level 2 and Level 3 requirements.

Management Reporting

Translate technical activity into readiness trends, unresolved risks, and leadership-level reporting.

SOC 2-ALIGNED CONTROLS

Enterprise Governance Beyond CMMC Tracking

The enterprise architecture is being designed with SOC 2-aligned operational and security principles in mind — including areas like security monitoring, access oversight, change awareness, incident handling, and evidence traceability.

These capabilities are intended to strengthen the reliability of the Watchtower service and support enterprise customer expectations.

SOC 2 is separate from CMMC. SOC 2 alignment does not satisfy CMMC Level 3 requirements, replace a DIBCAC assessment, or represent a SOC 2 examination or attestation.

WHO IT'S FOR

Watchtower Level 3 Is Being Designed For

Being Designed For
  • Defense contractors pursuing contracts that specify Level 3
  • Organizations already operating at or preparing for Final Level 2
  • Enterprises handling high-priority CUI
  • Organizations facing advanced persistent-threat risk
  • Security teams needing continuous event visibility
  • Contractors preparing for government-led DIBCAC review
  • Enterprises needing structured coordination between compliance, IT, security, and leadership
Not Intended For
  • Organizations that only handle FCI
  • Contractors needing only Level 1 self-assessment support
  • Organizations that have not begun implementing Level 2
  • Businesses seeking an automated substitute for DIBCAC
  • Companies looking for a software-generated certification
DEVELOPMENT ROADMAP

What We Are Building

01
Level 2 Foundation

Requirement mapping, readiness findings, evidence references, remediation workflows, and executive reporting.

02
SIEM Integration

Wazuh integration, normalized security-event intake, endpoint visibility, alert correlation, and technical trend reporting.

03
Level 3 Readiness

Mapping of the 24 enhanced requirements, DIBCAC preparation workflows, advanced evidence traceability, and enterprise readiness reporting.

04
Operational Validation

Pilot deployments, technical testing, workflow validation, customer feedback, and refinement before general availability.

Program Update

The Department announced a suspension of CMMC Phase II requirements in July 2026 while it conducts a broader program review. Watchtower is continuing development but will align the final Level 3 service with the requirements in effect when the service becomes available.

HELP SHAPE WATCHTOWER LEVEL 3

Help Shape Watchtower Level 3

We are speaking with defense contractors, compliance professionals, managed service providers, and security teams to understand what organizations need from a practical Level 3 readiness and monitoring platform.

Join the interest list to receive:

  • Development updates
  • Early product previews
  • Pilot-program opportunities
  • Level 3 readiness resources
  • Notification when the service becomes available
Please fill in your name, company, and a valid business email.
Thank you — you're on the list. We'll be in touch as development progresses.

Watchtower CMMC Level 3 Readiness is currently under development and is not available for purchase or deployment. Features, integrations, timelines, and service scope may change before release. KnightHawk Cybersecurity is not DCMA DIBCAC, does not issue CMMC status, and cannot guarantee that an organization will pass a government assessment. Wazuh integration and SOC 2-aligned practices are planned Watchtower capabilities and are not substitutes for implementing the applicable CMMC requirements.