Partially Ready — CMMC Level 2

72% NIST 800-171 coverage. 4 control gaps identified.

CMMC Status

Partially Ready

Target Level

Level 2

NIST Coverage

72%

ERP & Finance

IFS Government

by IFS

Overview

IFS Government by IFS is an ERP & finance solution pursuing FedRAMP authorization targeting CMMC Level 2 compliance. It provides 72% coverage of NIST 800-171 controls for defense contractors handling CUI.

What This Means for Defense Contractors

IFS Government meets the architectural requirements for CMMC Level 2. However, CMMC compliance depends on your entire system boundary — not just individual tools. There are 4 NIST 800-171 control gaps that need remediation before assessment. Defense contractors using IFS Government should verify that their System Security Plan (SSP) documents how this tool fits within their authorization boundary.

NIST 800-171 Coverage

72% of 110 controls covered4 gaps

Control Gaps

Using IFS Government without addressing these NIST 800-171 controls may result in findings during a CMMC assessment:

Strengths

Dedicated government data centers
Role-based access controls
Multi-factor authentication support

Using IFS Government in a CMMC Environment

Defense contractors using IFS Government should be aware that its 72% NIST 800-171 coverage leaves 28% of controls unaddressed. While IFS Government can be part of your CMMC environment, you will need compensating controls and supplementary tools to close the 4 identified gaps before a C3PAO assessment. Document all compensating controls in your POA&M and ensure your SSP accurately reflects the shared responsibility model.

Need a Compliant Alternative?

IFS Governmentdoesn't meet CMMC Level 2. Get real-time alerts when compliant alternatives become available, plus AI-matched contract opportunities for your NAICS codes.

CMMC Compliance Analysis for IFS Government

IFS Government demonstrates strong foundational security with dedicated government data centers and robust access controls, positioning it well for CMMC Level 2 environments handling CUI. In typical defense contractor workflows, the platform excels in Access Control (AC) and Identification & Authentication (IA) families through role-based permissions and MFA support, making it suitable for financial and project management CUI processing. The system's government-dedicated infrastructure aligns with CMMC's enclave requirements. However, critical gaps in controls 3.1.2 (limiting information system access), 3.1.5 (separation of duties), 3.1.12 (session controls), and 3.1.20 (external connections) present significant compliance risks. During C3PAO assessment, evaluators will scrutinize these missing System and Communications Protection (SC) controls, particularly session management and network boundary protections. The pending FedRAMP authorization indicates strong security posture but doesn't guarantee CMMC compliance without addressing specific gaps. IFS Government can remain within the CMMC authorization boundary if properly configured with compensating controls. Compared to competitors like Deltek Costpoint or SAP NS2, IFS Government's 72% NIST coverage is competitive but trailing leaders at 85-90% coverage. The dedicated government cloud infrastructure provides advantages over commercial ERP solutions, but the SC family gaps require immediate attention before C3PAO assessment.

Remediation Plan

Phase 1 (4-6 weeks): Address 3.1.12 session controls by implementing automatic session termination, concurrent session limits, and session lock mechanisms within IFS Government's user management module. Configure maximum idle timeout periods and document session monitoring procedures. Phase 2 (6-8 weeks): Remediate 3.1.2 and 3.1.5 by implementing principle of least privilege through granular role definitions and separation of duties workflows. Create approval matrices for sensitive functions and document privileged access procedures. Phase 3 (8-10 weeks): Establish 3.1.20 external connection controls by implementing network boundary protections, documenting authorized interfaces, and creating connection approval processes. Deploy network monitoring for unauthorized connections. Compensating controls must include enhanced logging, manual approval processes for privileged operations, and documented security procedures in the SSP. Continuous monitoring should include quarterly access reviews, monthly session audit reports, and real-time connection monitoring. Prepare evidence including configuration screenshots, access control matrices, session timeout logs, network boundary documentation, and procedural evidence for C3PAO review. Timeline assumes dedicated ISSO and IFS support engagement.

Remediation Checklist

  1. 1ISSO: Document current IFS Government access control matrix identifying all user roles and permissions in SSP AC-2
  2. 2Sysadmin: Configure automatic session termination settings in IFS Government to comply with 3.1.12 requirements
  3. 3ISSO: Create separation of duties workflow documentation for financial and sensitive operations per 3.1.5
  4. 4Sysadmin: Implement concurrent session limits and session lock mechanisms in user management module
  5. 5ISSO: Develop and document external connection authorization procedures for 3.1.20 compliance
  6. 6Sysadmin: Deploy network monitoring tools to detect unauthorized connections to IFS Government
  7. 7ISSO: Update POA&M entries for each remediated control with implementation evidence and testing results
  8. 8Contracts: Engage IFS professional services for CMMC-specific configuration guidance and validation
  9. 9ISSO: Conduct pre-assessment testing of all remediated controls with documented evidence collection
  10. 10C3PAO: Schedule validation testing of implemented controls during formal CMMC assessment readiness review

Frequently Asked Questions

Is IFS Government CMMC compliant?

IFS Government partially meets CMMC requirements with 72% coverage. 4 control gaps need remediation.

What NIST 800-171 controls does IFS Government cover?

IFS Government covers 72% of the 110 NIST 800-171 controls, with 4 gaps primarily in 3.1.2 and 3.1.5 control families.

What are the CMMC compliance gaps for IFS Government?

The primary gaps are in controls 3.1.2, 3.1.5, 3.1.12, 3.1.20. These require supplementary tools or process controls to achieve full CMMC Level 2 compliance.

Check Your Full Tech Stack

See CMMC readiness scores for 80+ enterprise vendors.

Open CMMC Readiness Check

Turn this gap analysis into a remediation plan

This IFS Government readiness check is the start, not the answer. Book a 25-minute compliance assessment — you leave with a prioritized roadmap and a fixed-fee implementation quote.

Book a 25-min assessment

Related: how much CMMC certification costs — DoD’s own priced figures