CMMC 2.0 (Cybersecurity Maturity Model Certification) requires defense contractors handling Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) to demonstrate cybersecurity practices across 3 levels — 17 practices at Level 1 through 110+ practices at Level 3. Skyhigh tabletop exercises validate your Incident Response (IR) domain practices and generate assessment-ready evidence across all 14 CMMC 2.0 practice domains.
| CMMC Practice Domain | Key Practices | Skyhigh Coverage | Evidence Generated |
|---|---|---|---|
| IR — Incident Response | 3.6.1 IR capability, 3.6.2 Incident tracking/reporting | Core | Exercise = direct IR capability test; AAR = 3.6.2 tracking/documentation evidence |
| AT — Awareness & Training | 3.2.1 Awareness training, 3.2.2 Role-based training | Core | Each exercise = AT training event evidence; role-specific scenario design |
| CA — Security Assessment | 3.12.1 Assess periodically, 3.12.3 Remediate deficiencies | Direct | Post-exercise gap analysis; remediation tracking from AAR findings |
| RA — Risk Assessment | 3.11.1 Risk assessment, 3.11.2 Vulnerability scan | Direct | Threat scenario mapping validates risk assessment; attack vector identification |
| CM — Configuration Mgmt | 3.4.1 Baseline, 3.4.2 Config changes | Supporting | Configuration gap findings from scenarios (default passwords, unpatched systems) |
| SC — System & Comms | 3.13.1 Comms monitoring, 3.13.3 Network segmentation | Direct | Lateral movement scenarios test segmentation; network segmentation gap analysis |
| AC — Access Control | 3.1.1 Authorized users, 3.1.2 Privileged users | Direct | Credential theft and insider threat scenarios test access control practices |
| SI — System & Info Integrity | 3.14.1 Flaw remediation, 3.14.6 Security alerting | Supporting | Alert effectiveness validation; flaw response testing in scenarios |
Skyhigh exercise evidence maps to multiple frameworks simultaneously. One exercise program — complete regulatory coverage.
CMMC IR domain requires an operational incident-handling capability. Demonstrate it with documented exercises. Free to start.