A Windows desktop application for handling Controlled Unclassified Information — AES-256-GCM encryption under Windows FIPS mode(*), CAC/PIV and MFA sign-in, role-based access, and a hash-chained audit trail that records who did what, to which file, and when. Everything stays on the workstation. One-time license fee, no subscription, no cloud round-trip.
For federal contractors, compliance officers, and program managers responsible for CUI under CMMC.
One-time fee. No subscription. $599 per desktop.
Under CMMC you have to show how Controlled Unclassified Information was protected at rest, who was allowed to touch it, and what they did with it. Most teams can describe the intent and then reconstruct the proof afterward from screenshots, folder permissions, and spreadsheet logs — which is exactly the part that falls apart under review.
CUIVault does both in one step, on the workstation. It enforces the technical control — encryption, authentication, least privilege, session lock, marking — and writes a tamper-evident record of every action as it happens. The evidence is a by-product of doing the work, not a project you run the week before an assessment.
Every CUI action — open, create, read, share, export, burn, key use — routes through one enforcement point. That is what makes the policy real and the audit trail complete.
Authenticated encryption for CUI files, with stored keys protected by a versioned PBKDF2-SHA256 format rather than left in the clear. When policy requires FIPS mode, operations fail closed on a workstation that isn’t running it.
Certificate chain validation with CRL/OCSP revocation checking, plus TOTP multi-factor. The authenticated principal is resolved once and carried through the session, so every audited action knows who performed it — and records when identity assurance was lower.
Vault Admin, Vault User, and Auditor roles gate privileged functions — policy administration, key management, vault administration, audit review and export — and can be mapped to Windows or domain groups. Denied attempts are recorded, not silently dropped.
Idle auto-lock conceals CUI across attached displays and requires re-authentication. Inactivity terminates the session, failed sign-ins trigger a timed lockout with backoff, and a CUI handling notice is presented and acknowledged at startup.
Structured records chained by hash — identity, action, target, outcome, sequence, previous hash — with built-in chain verification, HMAC-signed bundles, Windows Event Log anchoring, and CEF export to your SIEM. Deployments that need it can fail closed when the audit cannot be written.
A CUI banner in the workspace, label sidecars written alongside exported files, approved-destination allowlists, removable-media export blocking, and secure burn for files and vault extents.
CMMC Level 2 assessments align to NIST SP 800-171 Rev. 2, and that is the baseline CUIVault maps to. Rev. 3 has been published and we track it for forward readiness — we don’t claim it as your assessment baseline.
No product makes an organization compliant. Compliance is a property of your system and your security program, not a feature you can buy.
So the useful question isn’t whether CUIVault “covers” 800-171. It’s which requirements it enforces technically, which it detects and records, which it merely supplies evidence for, and which stay entirely yours. CUIVault classifies every claim it makes into exactly those four buckets — and ships that classification as a file, so your assessor can check our work instead of taking our word for it.
The product technically prevents the thing. Encryption at rest, FIPS fail-closed, role gating, session lock, export destination allowlists.
The product records it and can show tampering. Hash-chained audit, integrity-failure alerts, denied-access records, chain verification.
The product produces an artifact your SSP or POA&M can cite. Audit exports, SBOM, build integrity, cryptographic inventory, control evidence map.
Yours, not ours. Policy, training, personnel, physical security, incident response, and assessment stay with your security program — CUIVault can feed them, not own them.
| Rev. 2 family | What CUIVault contributes |
|---|---|
| 3.1 — Access Control | Role-based least privilege and privileged-function gating, idle lock and session termination, failed-logon lockout, CUI handling notice, controlled CUI flow, and approved-destination limits on export. |
| 3.3 — Audit & Accountability | Identity-tagged records of what happened and when, protected against alteration by hash chaining, restricted to privileged roles for review and export, with NTP-backed timestamps. |
| 3.4 — Configuration Management | A signed, integrity-checked security baseline for the application, plus a hardened mode that disables nonessential functionality. Your wider system configuration management stays organizational. |
| 3.5 — Identification & Authentication | CAC/PIV certificate authentication with revocation checking, multi-factor, passphrase complexity and reuse history, and stored keys protected by a salted key-derivation function rather than kept in the clear. |
| 3.8 — Media Protection | CUI marking on screen and on exported files, chain-of-custody records for exports, removable-media handling controls, and secure burn of files and vault extents. |
| 3.11 — Risk Assessment | A CycloneDX SBOM to feed vulnerability scanning, and signed-build evidence supporting timely remediation. Running the risk assessment itself remains yours. |
| 3.13 — System & Communications Protection | AES-256-GCM protection of CUI at rest, policy-enforced FIPS-mode operation with key material zeroized after use, and strict TLS with no certificate bypass on the DoD SAFE path. |
| 3.14 — System & Information Integrity | Integrity-failure alerting on encryption and manifest verification, optional antivirus scan before ingest, and code-signing evidence for the binaries you deployed. |
“Contributes” is deliberate. CUIVault enforces technical controls, records what happened, and produces evidence — your organization still implements, documents, and assesses the requirement.
About 50 of the 110 Rev. 2 requirements are organizational and cannot be satisfied by any product: awareness and training, most configuration management, the incident response process, most maintenance, personnel security, physical protection, risk assessment, and security assessment. CUIVault can feed several of them — audit data into incident response, for example — but ownership stays with your security program.
A single-fee desktop license — not a subscription. Optional update and support plans are available. Once payment is received, we’ll send the download key required to install the software.
Bring a real CUI workflow and the requirements you’re worried about to the 30-minute call. We’ll show the enforcement, the audit record it produces, and the evidence you could hand an assessor — and we’ll tell you plainly which of your gaps this doesn’t close, before you spend the $599.