AvePoint Is CMMC Level 2 Certified

A secure, audited environment for sharing Controlled Unclassified Information (CUI)

AvePoint has achieved Cybersecurity Maturity Model Certification (CMMC) Level 2, enabling us to securely support U.S. Department of Defense customers and members of the Defense Industrial Base with stringent CUI protection requirements. 

What CMMC Level 2 Certification Means for You

CMMC Level 2 certification confirms that AvePoint has implemented and independently validated security controls aligned to NIST SP 800‑171 for the protection of CUI.

For customers, this means: 

  • A dedicated CUI environment, isolated from AvePoint’s corporate systems
  • Access restricted, trained personnel supporting CMMC scoped engagements
  • Audited technical and administrative safeguards
  • Clear, documented processes for handling, transmitting, and retaining CUI 

This certification supports compliance obligations under DFARS 252.204‑7012 and related DoD requirements. 

Our CMMC Secure Environment

To support CMMC Level 2 requirements, AvePoint operates a separate, secure environment specifically designed for Controlled Unclassified Information.

This environment: 

  • Is logically and administratively isolated from our corporate tenant 
  • Limits access to approved, trained personnel only 
  • Uses dedicated identities and systems 
  • Prevents unauthorized data movement outside the enclave 

Communication and collaboration with CMMC-scoped customers occurs only within the CMMC-compliant environment. Standard AvePoint non-account specific communications may be sent outside of the CMMC-compliant environment. Account information usually stored in CRM, or captured in the ticketing systems is intentionally segregated from their non-CMMC counterparts to preserve compliance boundaries.

Why this matters:
This scoped approach reduces risk, limits audit exposure, and ensures CUI is handled according to federal requirements—not corporate convenience.

Who Should Use This Environment

You should opt in to the CMMC secure environment if:

  • You have an engagement with AvePoint in which AvePoint has an appropriate need to acces  Controlled Unclassified Information (CUI); 
  • You operate under Department of Defense prime contracts or subcontracting requirements; 
  • Your organization must comply with CMMC Level 2 or NIST SP 800‑171; or
  • You have been advised by your contracting officer or prime contractor to do so. 

If you are unsure whether your data qualifies as CUI, our compliance team can help guide you.

Opt In to Share CUI Securely

Submit Your Request

Submit Your Request

Complete the opt‑in form to indicate that your engagement creates an appropriate need to share CUI with AvePoint.

We’ll ask for: 

  • Organization name 
  • Program or contract reference 
  • Primary security or compliance contact 
  • Description of anticipated CUI
Review & Confirmation

Review & Confirmation

Our team will review your request to confirm scope, access requirements, and onboarding steps.

Secure Onboarding

Secure Onboarding

Once approved: 

  • All communication  with AvePoint will transition to the CMMC secure environment; 
  • Authorized users will receive onboarding instructions; and
  • Primary security or compliance contact 
  • CUI handling procedures will be enforced.

Questions?

Sales & Commercial Inquiries

CMMC, Security, or Audit Questions

Frequently Asked Questions

AvePoint does not process all company data within its CMMC-compliant environment. AvePoint operates a dedicated, logically and administratively segregated CMMC Level 2/GCC High enclave for the storage, processing, and transmission of Controlled Unclassified Information (CUI) and other in-scope government-related data. Non-CUI commercial business activities continue within AvePoint's standard corporate environment. Data subject to CMMC requirements is required to remain within the designated enclave and is not permitted to be processed through standard corporate systems or communication channels.