# Secureframe

> Secure CUI with CMMC-compliant virtual desktops. Reduce assessment scope & costs in minutes with Azure Government.

canonical: https://secureframe.com/secureframe-virtual-desktops

## Reduce your CMMC assessment 
scope and costs *in minutes*

- THE CHALLENGE — #### Limiting CUI flow and scope creep — Any device, system, or vendor that may handle CUI falls within CMMC assessment scope. This forces organizations to either stand up their own government virtual desktop environment or apply CMMC controls to their current laptops and workstations. Both options are highly complex, expensive, and time-intensive.
- THE GAP — #### Cannot use current devices to access CUI — Understanding the required CMMC controls to enforce on CUI-handling devices requires subject matter expertise. Using a consultant to implement controls across your current fleet of laptops and workstations could cost months, thousands of dollars, and leave you responsible for keeping them compliant.
- THE SOLUTION — #### CMMC-compliant workspaces — With Secureframe Virtual Desktops, users can spin up secure, isolated workspaces in Azure Government in minutes. These ready-to-use, compliant workspaces allow employees and subcontractors to handle CUI securely without needing to manage physical hardware, rebuild their IT environment, or depend on consultants.

## How Secureframe Virtual Desktops works

- CUI is accessed through compliant virtual desktops — Secureframe Virtual Desktops create secure, isolated Windows environments where users can securely access CUI. By using a Secureframe virtual desktop, local endpoints and corporate networks are removed from CMMC assessment scope.
- Virtual desktops are provisioned and configured automatically — Each virtual desktop is provisioned in Azure Government meeting the FedRAMP Moderate equivalency requirements of DFARS 252.204-7012. These desktops are preconfigured with the technical safeguards required for CMMC Level 2, including logging, antivirus, session controls, and access restrictions.
- Compliance is monitored, reducing ongoing IT overhead — Secureframe monitors compliance drift for the auto-provisioned virtual desktops. This provides visibility into compliance gaps and reduces the operational burden typically associated with custom virtual desktop deployments.
- Virtual desktops built into your broader CMMC cybersecurity program — Secureframe Virtual Desktops integrates with Secureframe Comply Platform, so users can access and store CUI securely inside virtual devices while managing policies, training, documentation, and evidence all within Secureframe

### Secureframe Virtual Desktops is for

- #### DIB organizations without the in-house resources to build and manage compliant virtual desktop infrastructure (VDI)
- #### Teams that need an out-of-the-box solution to meet CMMC Level 2 requirements without disrupting their workflows
- #### Primes, subcontractors, and MSPs that want to keep CUI activities clearly separated from non-CUI operations

### Benefits of Secureframe Virtual Desktops

- #### Scope reduction — By isolating CUI access to virtual desktops, you remove local endpoints and local networks from your CMMC assessment scope.
- #### Instant provisioning — Spin up secure, compliant virtual desktops for company employees or subcontractors in minutes.
- #### Seamless user experience — Users get a familiar Windows 11 desktop experience that’s accessible from any browser or device, so there’s no learning curve for virtual desktops.
- #### Automated enforcement — The necessary logging, antivirus, and session timeout policies required by NIST 800-171 are automatically enforced on every virtual desktop.

#### Using virtual desktops allows you to access CUI from an isolated workspace, removing your underlying laptops and workstations from CMMC scope. I recommend to all of our customers to reduce CMMC scope where possible, and using virtual desktops is one of the most effective and cost efficient ways of doing so.

## What’s next?

Secureframe Virtual Desktops is a core capability within Secureframe Defense, where DIB organizations can manage the infrastructure, controls, and evidence they need to achieve and maintain CMMC readiness in one system.
