DNS filtering isn’t optional for defense contractors, it’s a documented control. Total Uptime Protective DNS meets all 11 NSA/CISA capabilities, covers every remote and roaming user, and gives you a clean, defensible answer for your assessor.
The Department of Defense included DNS filtering as a requirement in the CMMC standard. Protective DNS is the most direct way to satisfy it, for your entire workforce, without touching the endpoint.
SC.3.192 Implement DNS filtering services to block access to known-malicious domains.
It has to cover remote and roaming users, not just people on the corporate network, the piece that most often trips suppliers up in an assessment.
Yes to all 11 NSA/CISA capabilities, with roaming clients for Windows, Mac, iOS, Android and ChromeOS, real-time ML detection of new malicious domains, and full query logging for evidence. A clean statement for your assessor: “We meet all 11 NSA/CISA Protective DNS capabilities and satisfy SC.3.192.”
SC.3.192 Implement DNS filtering services to block access to known-malicious domains.
It has to cover remote and roaming users, not just people on the corporate network — the piece that most often trips suppliers up in an assessment.
Yes to all 11 NSA/CISA capabilities, with roaming clients for Windows, Mac, iOS, Android and ChromeOS, real-time ML detection of new malicious domains, and full query logging for evidence. A clean statement for your assessor: “We meet all 11 NSA/CISA Protective DNS capabilities and satisfy SC.3.192.”
SC.3.192 turns DNS filtering from a discretionary purchase into something you must show a prime contractor or C3PAO assessor. Protective DNS is the straight line to it.
The April 2025 NSA/CISA/FBI advisory named fast flux a national security threat and recommended Protective DNS. Static blocklists can’t keep up, our ML detection can.
NSA/CISA’s 2025 guide sets 11 capabilities a credible PDNS service must deliver. Hold every vendor to all 11, Total Uptime was built to meet them.
of malware command-and-control can be disrupted by secure DNS (NSA estimate)
deceptive sites blocked across our network every day
NSA/CISA capabilities met, the full standard
From “Selecting a Protective DNS Service” (NSA/CISA, v1.3, March 2025). This is the standard assessors and security teams increasingly reference.
Stops known-malicious and command-and-control connections.
Prevents credential-harvesting and spear-phishing.
Flags data smuggled out over DNS.
Real-time ML analysis of unknown domains.
Filters malicious ad and payload domains.
Granular, per-network policy control.
Across major search engines and YouTube.
Every major platform — critical for SC.3.192.
Evidence and investigation-ready logs.
Anycast performance, 10 to 100,000+ users.
Threat, activity and destination dashboards.
Integrate policy with your existing stack.
You shouldn’t need a quarter of engineering time to satisfy one control. Protective DNS deploys fast and covers everyone.
Book a working session and we’ll map the 11 NSA/CISA capabilities to your CMMC scope and hand you a clean control statement for your assessor.
Transparent, entity-sized pricing. We’ll show you exactly how it compares.
Real organisations. Real resilience. Real results.
Our team found that implementation went very smoothly, and Total Uptime support staff was always ready and willing to help within minutes.
Director, Product Operations, Informatica
We chose Total Uptime for its advanced functionality, cost effective pricing and superb pre-sales experience. The intuitive configuration and ‘dead-easy’ deployment were also significant factors in our purchasing decision.
Senior Systems Analyst, MIC
Yes, the load balancer rocks. But for us, the stand-out feature is the team behind it. Edgenexus support is fast, responsive, and deeply knowledgeable, a true extension of our IT department.
IT System and Asset Manager, 4D Interactive Ltd
Having technically reviewed the solutions available in the market place, we felt that Total Uptime hit all the functionality of the big players, at a very reasonable price point for the feature set available.
IT Operations Manager,
UNITE Group
No single control makes you compliant, CMMC spans many practices. But SC.3.192 specifically calls for DNS filtering, and Protective DNS is the most direct, defensible way to satisfy that control across your whole workforce. We give you the capability mapping and logging evidence to support it.
Roaming clients for Windows, Mac, iOS, Android and ChromeOS apply your filtering policy wherever a device is, home, field, or travel. This is the piece assessors probe hardest, and it’s built in.
We offer a FedRAMP-aligned deployment for government-facing organizations. Talk to us about your specific authorization requirements and we’ll confirm exactly what applies to your situation.
Policy configuration, category and threat-blocking settings, roaming coverage, and comprehensive query logs and reporting, the documentation trail an assessor expects for a DNS filtering control.
Get the 11 NSA/CISA capabilities mapped to your CMMC scope and a control statement you can hand to your assessor.