Updated September 30, 2026
PreVeil's own matrix says PreVeil handles 37 of the 110 CMMC Level 2 requirements for you. You share 65 with it, and 8 are yours alone. The "supports 102 of 110 controls" line in PreVeil's marketing is the 37 plus the 65.
CMMC Level 2 is the Pentagon's list of 110 security requirements for any company holding CUI (controlled unclassified information: the drawings, specs, and technical data the government marks as sensitive). PreVeil is an encrypted email and file-sharing service many small defense suppliers use instead of Microsoft's government cloud. "Supports" is marketing language. Only the 37 come off your plate, and only when three conditions hold. The other 73 still have your name on them.
Where the numbers come from
PreVeil publishes its matrix inside a sales guide, Guide to Achieving CMMC Compliance: A Proven Path to 110, September 2025 edition. Appendix A, pages 25–50, is the Shared Responsibility Matrix, which is PreVeil's name for a Customer Responsibility Matrix: the provider's list of who does each requirement. PreVeil says it built the matrix with a certified C3PAO (one of the firms licensed to run CMMC assessments). It covers PreVeil Email and Drive, with one stated assumption: all CUI is sent and stored in PreVeil and nowhere else.
We counted every row. The earlier June 2023 whitepaper prints the same totals on page 37: 37 inherited, 65 shared, 8 customer.
| Family | What it covers | PreVeil | Shared | You |
|---|---|---|---|---|
| AC | Who can log in and what they reach | 8 | 11 | 3 |
| AT | Security training | 0 | 3 | 0 |
| AU | Audit logs | 3 | 6 | 0 |
| CM | Settings and software control | 0 | 9 | 0 |
| IA | Passwords and multi-factor login | 2 | 9 | 0 |
| IR | Incident response | 0 | 1 | 2 |
| MA | Maintenance | 5 | 1 | 0 |
| MP | Media: drives, USB sticks, paper | 0 | 9 | 0 |
| PE | Physical security | 6 | 0 | 0 |
| PS | Personnel screening | 0 | 2 | 0 |
| RA | Risk assessment and scanning | 0 | 3 | 0 |
| CA | Security assessment and your SSP | 0 | 3 | 1 |
| SC | Network and encryption | 10 | 4 | 2 |
| SI | Patching and malware | 3 | 4 | 0 |
| Total | 37 | 65 | 8 |
"Inherited" now has an asterisk
The 2025 matrix no longer uses the word "inherited" in its status column. The 37 are marked Shared*, and each one carries the same note: "This control can be considered PreVeil Inherited provided that" three things are true (page 25):
- Every computer that processes, stores, or sends CUI is secured to CMMC standards.
- All CUI is stored and sent inside PreVeil and nowhere else. If CUI lives anywhere outside PreVeil, you have to secure that system too.
- Every policy, procedure, and piece of evidence an assessor needs for that requirement is in place.
That is honest of PreVeil, and it is the whole story. The 37 are real, but they are conditional, and condition two is where most small shops fail.
Why the count is per control, and what hides underneath
Assessors don't grade a requirement in one piece. They grade its objectives, the specific statements that each have to be true, and CMMC Level 2 has 320 of them. PreVeil's 2023 matrix marks every objective, and the 2025 edition keeps only the control-level status.
Take the first requirement, "limit system access to authorized users, processes, and devices" (3.1.1). PreVeil's 2023 matrix (page 31) marks three objectives shared: knowing who your authorized users are, limiting access to them, and limiting access to authorized devices. It marks the other three inherited: identifying the processes that act for users, identifying connecting devices, and limiting access to those processes. PreVeil's software handles the second half. The first half is your user list and your laptops.
One shared objective is enough to make the whole requirement "shared." A requirement counts as inherited only when every one of its objectives is. So the per-control count hides how much sits inside each shared row. Counted by objective, the same matrix gives PreVeil 113 of 320, shared 147, and you 60 (page 37). Its "260 of 320 objectives" is again inherited plus shared.
The objective view also shows rows that are mostly yours. Multi-factor login (3.5.3) is "shared," but three of its four objectives are marked Customer Responsibility: multi-factor for local admin logins, for network admin logins, and for every other user's network login (page 33). PreVeil's part is identifying privileged accounts inside PreVeil. The rest, on every laptop and every other system, is yours.
The matrix isn't perfectly consistent either. Creating and keeping audit logs (3.3.1) is marked inherited at the control level, yet its last objective, "audit records are retained as defined," is marked Shared (page 32). If your assessor reads objective by objective, and a good one will, plan to own the retention period.
The condition that breaks in a machine shop
Condition two says all CUI stays inside PreVeil. In an office that emails contracts, it can. In a shop that edits drawings all day, it usually doesn't.
PreVeil's own guide for CAD users says PreVeil Drive "cannot host a relational database," so a PDM system (the database that tracks parts, assemblies, and revisions) has to be secured separately. It also says SolidWorks and AutoCAD write scratch copies to the Windows temp folder, which is why every CAD workstation needs BitLocker. Add the CAM program on the machine-side PC and the printed traveler on the inspection bench. Each is CUI outside PreVeil.
That doesn't sink PreVeil. It means the Shared* rows only stay inherited if you also secure those workstations and that PDM server, which is exactly what condition two says. The GCC High decision guide for shops covers when a file service fits and when it gets leaky.
Seven rows people get wrong
Idle screens lock (3.1.10), yours. PreVeil can't lock a Windows laptop. Set a screen lock through Intune, Group Policy, or whatever manages your computers. Pick a number, such as 15 minutes, and write the same number into your policy.
Multi-factor login (3.5.3), shared, mostly yours. Turn on multi-factor for every Windows admin account, every remote login, and every cloud account that touches CUI. PreVeil's own login doesn't cover your Microsoft 365 or your laptops.
Reporting an incident to DoD (3.6.2), yours. PreVeil tells you about a breach on its side. Reporting a cyber incident to DoD within 72 hours through DC3 is your job under DFARS 252.204-7012. Testing your response plan (3.6.3) is also marked yours. A one-page plan and a tabletop exercise cover both.
Your System Security Plan (3.12.4), yours. PreVeil's Compliance Accelerator includes a pre-written SSP and 14 procedures. They are a head start. Your boundary, your assets, and your people are yours to describe.
Your network boundary (3.13.1), shared. PreVeil's 2023 matrix marks defining your external boundary and your key internal boundaries as Customer Responsibility (page 36). That means your firewall, your Wi-Fi, and the line between the office network and the shop floor. Wireless access (3.1.16) is marked yours outright.
Malware and patching (3.14.1, 3.14.2, 3.14.4), inherited with conditions. PreVeil patches and protects PreVeil. Its own row for updating malware protection (3.14.4) says you are responsible for "all systems and endpoints within the organization" outside PreVeil (page 50). Your antivirus, whether Defender or CrowdStrike, and your Windows updates are still your evidence.
Physical security (all six PE rows), inherited. This includes protecting CUI at home offices (3.10.6). PreVeil marks them inherited under its standing assumption that CUI lives only in PreVeil. The moment a drawing prints, or sits unencrypted on a laptop, your building, your locked cabinet, and your visitor log are back in play. The media and printers guide covers the paper side.
What PreVeil doesn't touch
Eight requirements are marked Customer Responsibility and PreVeil has no role in them: posting to public websites (3.1.22), session lock (3.1.10), wireless (3.1.16), incident tracking and reporting (3.6.2), incident-response testing (3.6.3), your SSP (3.12.4), collaborative devices like conference-room cameras (3.13.12), and internet phone systems (3.13.14).
Beyond those eight, the shared rows lean on things no file service can do. Training your people (all three AT rows), screening new hires and shutting off leavers (PS), keeping a baseline for every laptop and approving changes to it (all nine CM rows), and scanning your own systems for vulnerabilities (RA) are marked shared because PreVeil does its part for PreVeil. Your part covers everything else in the building.
The FedRAMP question
DFARS 7012 requires any cloud holding CUI to meet FedRAMP Moderate or be equivalent to it. PreVeil is not listed on the FedRAMP Marketplace; it doesn't appear in the GSA marketplace data as of the May 2026 update. PreVeil claims FedRAMP Moderate equivalency instead. It says independent 3PAOs assess it each year, and that DIBCAC, DoD's own assessment team, reviewed its evidence (PreVeil's FedRAMP story). Its data sits on AWS GovCloud, which is FedRAMP High (page 13 of the guide).
Equivalency is a legitimate route. DoD's December 2023 memo puts the burden on you to have the provider's body of evidence available for your assessor. Ask PreVeil for the current 3PAO report and customer matrix before you sign, and file both with your SSP. What "equivalent" means in practice.
Common questions
How many CMMC controls does PreVeil cover? PreVeil handles 37 of 110 on the condition that all CUI stays in PreVeil and your computers are secured. It shares 65 and leaves 8 to you. "102 of 110" counts the shared rows as covered.
Is PreVeil CMMC compliant? No product is CMMC compliant. Companies are. PreVeil can carry 37 requirements for you and part of 65 more. Your company still passes or fails its own assessment.
Where is PreVeil's customer responsibility matrix? Appendix A of PreVeil's September 2025 CMMC guide, pages 25–50. The June 2023 whitepaper has the objective-by-objective version. PreVeil's Compliance Accelerator includes a pre-filled copy. Ask for the current one and cite it in your SSP.
Does PreVeil cover more than GCC High? By count, no. Microsoft's placemat marks 52 requirements inherited for GCC High (GCC High breakdown). Google Workspace Enterprise Plus is at 42 (Workspace breakdown). The better question is which one your people will actually keep every drawing inside.
What about PreVeil's virtual desktop? PreVeil sells a separate virtual desktop product and says it brings the count to 79 fully inherited and 23 shared. That is a different offering with its own matrix. Don't cite it for Email and Drive.
Before you write "PreVeil" in your SSP
List every place a drawing goes after it leaves PreVeil: the CAD workstation, the PDM server, the CAM PC, the printer, the traveler. Each one is outside condition two, and each one needs its own row in your plan. If the list is short, PreVeil's 37 are yours to claim. If it's long, you are running two systems, and the matrix only speaks for one of them.
