For the Defense Industrial Base

Satisfy CMMC SC.3.192 with Protective DNS built to the NSA/CISA standard.

DNS filtering isn’t optional for defense contractors, it’s a documented control. Total Uptime Protective DNS meets all 11 NSA/CISA capabilities, covers every remote and roaming user, and gives you a clean, defensible answer for your assessor.

What SC.3.192 asks for and how Protective DNS answers it

The Department of Defense included DNS filtering as a requirement in the CMMC standard. Protective DNS is the most direct way to satisfy it, for your entire workforce, without touching the endpoint.

The requirement

The challenge

The Total Uptime answer

SC.3.192  Implement DNS filtering services to block access to known-malicious domains.

It has to cover remote and roaming users, not just people on the corporate network, the piece that most often trips suppliers up in an assessment.

Yes to all 11 NSA/CISA capabilities, with roaming clients for Windows, Mac, iOS, Android and ChromeOS, real-time ML detection of new malicious domains, and full query logging for evidence. A clean statement for your assessor: “We meet all 11 NSA/CISA Protective DNS capabilities and satisfy SC.3.192.”

The requirement

SC.3.192  Implement DNS filtering services to block access to known-malicious domains.

The challenge

It has to cover remote and roaming users, not just people on the corporate network — the piece that most often trips suppliers up in an assessment.

The Total Uptime answer

Yes to all 11 NSA/CISA capabilities, with roaming clients for Windows, Mac, iOS, Android and ChromeOS, real-time ML detection of new malicious domains, and full query logging for evidence. A clean statement for your assessor: “We meet all 11 NSA/CISA Protective DNS capabilities and satisfy SC.3.192.”

Compliance pull meets a real, active threat

It's a documented control

SC.3.192 turns DNS filtering from a discretionary purchase into something you must show a prime contractor or C3PAO assessor. Protective DNS is the straight line to it.

Fast flux is a national threat

The April 2025 NSA/CISA/FBI advisory named fast flux a national security threat and recommended Protective DNS. Static blocklists can’t keep up, our ML detection can.

The government defined "good"

NSA/CISA’s 2025 guide sets 11 capabilities a credible PDNS service must deliver. Hold every vendor to all 11,  Total Uptime was built to meet them.

0 %

of malware command-and-control can be disrupted by secure DNS (NSA estimate)

0 M+

deceptive sites blocked across our network every day

0 / 11

NSA/CISA capabilities met,  the full standard

All 11 NSA/CISA capabilities met

From “Selecting a Protective DNS Service” (NSA/CISA, v1.3, March 2025). This is the standard assessors and security teams increasingly reference.

Block malware & C2 domains

Stops known-malicious and command-and-control connections.

Block phishing domains

Prevents credential-harvesting and spear-phishing.

Detect DNS tunneling & exfiltration

Flags data smuggled out over DNS.

Catch newly-registered & DGA domains

Real-time ML analysis of unknown domains.

Block malvertising & drive-by sites

Filters malicious ad and payload domains.

Content & category filtering

Granular, per-network policy control.

Enforce SafeSearch

Across major search engines and YouTube.

Roaming / off-network protection

Every major platform — critical for SC.3.192.

Comprehensive query logging

Evidence and investigation-ready logs.

Scale without slowing users down

Anycast performance, 10 to 100,000+ users.

Actionable reporting

Threat, activity and destination dashboards.

API & automation

Integrate policy with your existing stack.

A defensible answer, without a heavy rollout.

You shouldn’t need a quarter of engineering time to satisfy one control. Protective DNS deploys fast and covers everyone.

Map SC.3.192 to your environment

Book a working session and we’ll map the 11 NSA/CISA capabilities to your CMMC scope and hand you a clean control statement for your assessor.

Transparent, entity-sized pricing. We’ll show you exactly how it compares.

Customer success

Trusted by IT Teams Worldwide

Real organisations. Real resilience. Real results.

Rated by the people who use us.

CMMC & Protective DNS, answered

Does Protective DNS by itself make us CMMC compliant?

No single control makes you compliant,  CMMC spans many practices. But SC.3.192 specifically calls for DNS filtering, and Protective DNS is the most direct, defensible way to satisfy that control across your whole workforce. We give you the capability mapping and logging evidence to support it.

Roaming clients for Windows, Mac, iOS, Android and ChromeOS apply your filtering policy wherever a device is,  home, field, or travel. This is the piece assessors probe hardest, and it’s built in.

We offer a FedRAMP-aligned deployment for government-facing organizations. Talk to us about your specific authorization requirements and we’ll confirm exactly what applies to your situation.

Policy configuration, category and threat-blocking settings, roaming coverage, and comprehensive query logs and reporting, the documentation trail an assessor expects for a DNS filtering control.

Turn SC.3.192 into a checkbox you've already ticked

Get the 11 NSA/CISA capabilities mapped to your CMMC scope and a control statement you can hand to your assessor.