If Federal Contract Information or CUI touches your Dynamics 365 or Dataverse environment, that system is in your assessment scope. Assessors ask system-level questions about it: who can access what, whether privileged access is limited, whether changes to sensitive data are logged. Pathix answers those with deterministic, control-mapped evidence from a read-only scan inside your own tenant.
The Dataverse application tier: the CRM or ERP-adjacent business system where contract, customer and program data lives. Pathix builds a complete graph of what writes every field, what each plugin and flow actually does, and what every principal is granted, including application and integration accounts.
Pathix does not assess endpoints, networks, identity infrastructure, or the wider Microsoft 365 estate. It is not a certification or scoring tool. It reads what principals are granted; it does not observe what anyone did with that access.
CMMC levels are nested requirement sets. Level 1 is 15 basic safeguarding requirements from FAR 52.204-21, for FCI. Level 2 adds the rest of NIST SP 800-171's 110 requirements, which CMMC currently assesses against Rev 2. Level 3 is all 110 plus 24 enhanced requirements from NIST SP 800-172. Because the sets nest, a practice marked Level 1 below also applies at Levels 2 and 3. In total Pathix produces evidence for 2 of the 15 Level 1 practices and 12 of the 110 Level 2 practices. The 24 Level 3 additions from 800-172 are outside its scope, and this page does not claim them.
At Level 1, CMMC formally labels the first two practices AC.L1-b.1.i and AC.L1-b.1.ii. They are the same requirements as 3.1.1 and 3.1.2 and are shown once above rather than twice. Mappings are indicative: Pathix detects conditions relevant to these practices, and assessment conclusions rest with your assessor and your organization.
A current, accurate description of the Dataverse system's access model and logic surface, generated from the environment itself rather than from memory.
“Show me everyone who can modify contract records” or “prove changes to that field are audited” becomes a lookup rather than a week of manual tracing.
Every finding carries severity, the affected components, and concrete remediation steps.
Every scan produces a what-changed delta, so drift is caught when it happens rather than at the next assessment.
Pathix deploys into your own Azure subscription. The scanner is a read-only application user whose security role you can audit before you assign it: 32 read privileges, with no write, create, delete or share. It reads metadata and configuration only, never business record values, and no data leaves your tenant. AI features are optional, off by default, and run on your own key. Sovereign-cloud deployment for GCC High and Azure Government is scoped per engagement.
CMMC Phase 1, the self-assessment requirements in new DoD solicitations, has been in effect since November 10, 2025. Later phases are under DoD review as of July 2026. Independent of CMMC's phasing, NIST SP 800-171 compliance and SPRS scoring are already contractual obligations for contractors handling CUI under DFARS 252.204-7012, 7019 and 7020, and primes flow these requirements down to subcontractors. The evidence obligation exists today.
One read-only scan produces the access graph, the control-mapped findings and the deltas, from inside your own tenant.
Pathix is not a CMMC compliance platform and does not assess the rest of your environment. A finding is not an assessment outcome. This page is informational and is not compliance, legal, or assessment advice.