PathixDataverse Forensics
CMMC readiness

CMMC evidence for Dynamics 365 and Dataverse.

If Federal Contract Information or CUI touches your Dynamics 365 or Dataverse environment, that system is in your assessment scope. Assessors ask system-level questions about it: who can access what, whether privileged access is limited, whether changes to sensitive data are logged. Pathix answers those with deterministic, control-mapped evidence from a read-only scan inside your own tenant.

2 of 15
LEVEL 1 PRACTICES
12 of 110
LEVEL 2 PRACTICES
18
MAPPED FINDINGS
Where Pathix fits

One system in your scope, covered properly.

WHAT IT COVERS

The Dataverse application tier: the CRM or ERP-adjacent business system where contract, customer and program data lives. Pathix builds a complete graph of what writes every field, what each plugin and flow actually does, and what every principal is granted, including application and integration accounts.

WHAT IT DOES NOT

Pathix does not assess endpoints, networks, identity infrastructure, or the wider Microsoft 365 estate. It is not a certification or scoring tool. It reads what principals are granted; it does not observe what anyone did with that access.

The crosswalk

12 practices, and the evidence for each.

CMMC levels are nested requirement sets. Level 1 is 15 basic safeguarding requirements from FAR 52.204-21, for FCI. Level 2 adds the rest of NIST SP 800-171's 110 requirements, which CMMC currently assesses against Rev 2. Level 3 is all 110 plus 24 enhanced requirements from NIST SP 800-172. Because the sets nest, a practice marked Level 1 below also applies at Levels 2 and 3. In total Pathix produces evidence for 2 of the 15 Level 1 practices and 12 of the 110 Level 2 practices. The 24 Level 3 additions from 800-172 are outside its scope, and this page does not claim them.

AC.L2-3.1.1
L1L2L3
Level 1 label: AC.L1-b.1.i
Limit system access to authorized users, processes and devices.

The full granted-access graph for every principal on the system, including application and integration accounts, plus shared-role and business-unit default-team exposure and HTTP-triggered flows open to unauthenticated callers.

AC.L2-3.1.2
L1L2L3
Level 1 label: AC.L1-b.1.ii
Limit access to the transactions and functions authorized users may execute.

Effective permissions per principal down to field level, with over-broad and write-capable grants surfaced and ranked.

Produced by the engine rather than by a single finding, so this practice carries no finding chips.

AC.L2-3.1.3
L2L3
Control the flow of CUI in line with approved authorizations.

Secured-column values landing in unsecured columns through attribute mappings and formula propagation: an uncontrolled flow of deliberately gated data, detected deterministically.

AC.L2-3.1.4
L2L3
Separate duties so no individual can act without collusion.

Roles and teams that mix human users with integration identities, flagged with the affected principals.

AC.L2-3.1.5
L2L3
Employ least privilege, including for privileged accounts and security functions.

Integration accounts holding System Administrator, security-model write privileges held by integrations or non-admin users, and privilege escalation paths.

AC.L2-3.1.7
L2L3
Prevent non-privileged users from executing privileged functions, and log it when they do.

Role-management and act-on-behalf privileges held outside the admin population.

AU.L2-3.3.1
L2L3
Create and retain audit records sufficient to investigate unauthorized activity.

Audit coverage gaps: field-secured columns whose changes are not being logged, with the exact org, table and column switch that is off, plus an audit-configuration tampering signal.

AU.L2-3.3.2
L2L3
Ensure the actions of individual users can be uniquely traced to them.

Fixed-identity impersonation and delegation configurations that would obscure who acted, found before an investigator hits them.

CM.L2-3.4.3
L2L3
Track, review, approve and log changes to the system.

Scan-over-scan deltas: every new grant, new writer and new finding since the last scan, with a per-deployment pivot.

Produced by the engine rather than by a single finding, so this practice carries no finding chips.

IA.L2-3.5.10
L2L3
Store and transmit only cryptographically protected passwords.

Credential-shaped secrets embedded in plugin step configuration, reported as neutralized labels and never the value itself.

PS.L2-3.9.2
L2L3
Protect systems containing CUI during and after personnel actions such as termination.
SC.L2-3.13.8
L2L3
Use cryptographic mechanisms to prevent disclosure of CUI in transmission.

Integration endpoints and webhooks sending outbound payloads over plaintext HTTP or with no authentication.

At Level 1, CMMC formally labels the first two practices AC.L1-b.1.i and AC.L1-b.1.ii. They are the same requirements as 3.1.1 and 3.1.2 and are shown once above rather than twice. Mappings are indicative: Pathix detects conditions relevant to these practices, and assessment conclusions rest with your assessor and your organization.

In practice

How teams use it.

System Security Plan

A current, accurate description of the Dataverse system's access model and logic surface, generated from the environment itself rather than from memory.

Assessor questions in minutes

“Show me everyone who can modify contract records” or “prove changes to that field are audited” becomes a lookup rather than a week of manual tracing.

POA&M inputs

Every finding carries severity, the affected components, and concrete remediation steps.

Posture between assessments

Every scan produces a what-changed delta, so drift is caught when it happens rather than at the next assessment.

Before you deploy it

Built to survive your own security review.

Pathix deploys into your own Azure subscription. The scanner is a read-only application user whose security role you can audit before you assign it: 32 read privileges, with no write, create, delete or share. It reads metadata and configuration only, never business record values, and no data leaves your tenant. AI features are optional, off by default, and run on your own key. Sovereign-cloud deployment for GCC High and Azure Government is scoped per engagement.

The full security architecture →Every check, control-mapped →
Program status

CMMC Phase 1, the self-assessment requirements in new DoD solicitations, has been in effect since November 10, 2025. Later phases are under DoD review as of July 2026. Independent of CMMC's phasing, NIST SP 800-171 compliance and SPRS scoring are already contractual obligations for contractors handling CUI under DFARS 252.204-7012, 7019 and 7020, and primes flow these requirements down to subcontractors. The evidence obligation exists today.

See what your Dataverse scope looks like.

One read-only scan produces the access graph, the control-mapped findings and the deltas, from inside your own tenant.

Talk about your scope

Pathix is not a CMMC compliance platform and does not assess the rest of your environment. A finding is not an assessment outcome. This page is informational and is not compliance, legal, or assessment advice.

© 2026 Pathix L.L.C. · self-hosted · metadata-only
Not affiliated with Microsoft. Dynamics 365, Dataverse, and Power Platform are trademarks of Microsoft Corporation.π